how to use the new rc.d system to start the daemon with systrace?

2011-10-20 Thread johnw
after upgrade to current, now /etc/rc use the new rc.d system. my question is how to start the daemon(ntpd, named etc ..) with systrace? before upgrade to new rc.d system, i can edit /etc/rc like this echo 'starting named'; named $named_flags to echo 'starting named'; systrace -Ua named

can not use the up key to last command at root?

2011-12-20 Thread johnw
my system is i386/current, i do not know why and when, today, i noticed i can not use the up key to last command at root anymore. i can use the up key to last command at non root user, both is use ksh. any idea? please help and thank you.

all libc of my openbsd/i386

2011-07-29 Thread johnw
(23:24:04) john@pdc:[~]$ du -sh /usr/lib/libc.so.* 704K /usr/lib/libc.so.34.2 704K /usr/lib/libc.so.35.0 704K /usr/lib/libc.so.35.1 704K /usr/lib/libc.so.36.0 720K /usr/lib/libc.so.37.0 720K /usr/lib/libc.so.38.0 720K /usr/lib/libc.so.38.1 688K /usr/lib/libc.so.38.2 688K /usr/lib/libc.so.38.3 3.8M

dmesg: write fail ??

2011-09-21 Thread johnw
Hi, i see it in dmesg bsdbox /bsd: pid 9648 (mlnet): user write of 4096@0x202d4000 at 5328 failed: 14 what is this mean? thanks.

回覆: how to viewing packet data?

2010-09-21 Thread johnw
you are looking for -X option to tcpdump(8). Read the man page for more details. Yes, i tried it before (-X). but that is not what i want to get. I want to get is something like that Data: Post /from.php?q=123 abc.com Can tcpdump -X do that? if yes, can you give me one example? Thank you.

how to enable ipv6?

2011-03-01 Thread johnw
I search google, and all howto is assert isp not support ipv6 and use tunnel/gif. but I know my isp is support ipv6, how can i enable ipv6 with dhclient? thank you.

Re: how to enable ipv6?

2011-03-02 Thread johnw
I cp /usr/local/share/examples/wide-dhcpv6/dhcp6c.conf.sample to /etc/dhcp6c.conf interface fxp0 { send ia-na 0; send rapid-commit; send domain-name-servers; }; id-assoc na { };

can i tune the bind/resolver timeout time?

2012-06-17 Thread johnw
HI, i use openbsd/i386, and use /usr/sbin/bind act as dns server. can i tune the gethostbyname timeout time? (tunning system or bind) and can i config the resolver do not search the local domain? man resolv.conf say i can config the domain and search option in /etc/resolv.conf but can i tell the

after upgrade to current(25-06-2012), can not login ssh

2012-06-25 Thread johnw
I attached the server side error message (photo) please help, thank you. ssh - 192.168.168.1 OpenSSH_6.0p1 Debian-2, OpenSSL 1.0.1c 10 May 2012 debug1: Reading configuration data /home/john/.ssh/config debug1: /home/john/.ssh/config line 1: Applying options for 192.168.168.1 debug1: Reading

Re: after upgrade to current(25-06-2012), can not login ssh

2012-06-25 Thread johnw
I upload the photo to here http://www1.picturepush.com/photo/a/8571544/640/8571544.jpg 2012/6/25 johnw johnw.m...@gmail.com I attached the server side error message (photo) please help, thank you. ssh - 192.168.168.1 OpenSSH_6.0p1 Debian-2, OpenSSL 1.0.1c 10 May 2012 debug1: Reading

Re: after upgrade to current(25-06-2012), can not login ssh

2012-06-25 Thread johnw
The sshd_config like this: ListenAddress 192.168.168.1 PermitRootLogin yes PubkeyAuthentication yes AuthorizedKeysFile .ssh/authorized_keys PasswordAuthentication yes UsePrivilegeSeparation sandbox Subsystem sftp /usr/libexec/sftp-server 2012/6/25 johnw johnw.m...@gmail.com I attached

Re: after upgrade to current(25-06-2012), can not login ssh

2012-06-25 Thread johnw
I change UsePrivilegeSeparation sandbox to UsePrivilegeSeparation yes, then i can login now. maybe the sandbox feature has something broken. thank you. 2012/6/25 Fred Crowson fred.crow...@gmail.com On 25 June 2012 10:03, johnw johnw.m...@gmail.com wrote: The sshd_config like

Re: after upgrade to current(25-06-2012), can not login ssh

2012-06-26 Thread johnw
, SYSTR_POLICY_NEVER }, + { SYS_mquery, SYSTR_POLICY_NEVER }, { SYS___sysctl, SYSTR_POLICY_PERMIT }, { SYS_close, SYSTR_POLICY_PERMIT }, 2012/6/25 Fred Crowson fred.crow...@gmail.com On 25 June 2012 12:41, johnw johnw.m...@gmail.com wrote: I change UsePrivilegeSeparation sandbox to UsePrivilegeSeparation

xsystrace do not exit

2012-08-09 Thread johnw
I run the command systrace chrome, then close the chrome, after that I still can see the xsystrace process here. why the xsystrace process do not follow the systrace process exit? is it normal? thank you.

Re: Signatures for distribution sets and packages?

2012-09-05 Thread johnw
Just a curious, why openbsd do not support scp/sftp to download packages, like the anoncvs does?

Re: Signatures for distribution sets and packages?

2012-09-05 Thread johnw
2) Because nobody understands what you mean. Sorry, my english is so bad. anyway, i want to say is ... below pkg_add does support scp for downloading packages, though there aren't any mirrors that use it. See pkg_add(1): Yes, why those mirrors do not support scp/sftp (package files) transfer?

Re: Major dhclient(8) changes - no more dhclient-script

2012-11-10 Thread johnw
file bind after upgrade, my /etc/resolv.conf (only one line) lookup file bind 由 johnw 透過 Google 閱讀器傳送給您: Major dhclient(8) changes - no more dhclient-script 經由 gmane.os.openbsd.tech Kenneth R Westerback 著 (日期為 2012/11/9) Those of you following -current

Re: Major dhclient(8) changes - no more dhclient-script

2012-11-10 Thread johnw
Today, OpenBSD 5.2-current (GENERIC) #77: Fri Nov 9 13:54:32 MST 2012 grep dhclient /var/log/daemon: Nov 10 20:41:54 pdc dhclient[25385]: DHCPREQUEST on fxp0 to 255.255.255.255 port 67 Nov 10 20:41:55 pdc dhclient[25385]: DHCPACK from 183.179.12.1 (00:13:7f:98:89:80) Nov 10 20:41:55 pdc

/etc/daily report error/warning message

2014-08-17 Thread johnw
Hi, I noticed my system(5.6current/amd64) daily report with error/warning message -- Running security(8): /bin/sh: /.cshrc[8]: syntax error: `(' unexpected -- I did not edit /.cshrc or /etc/daily why

Re: /etc/daily report error/warning message

2014-08-17 Thread johnw
On 08/17/2014 03:46 PM, Philip Guenther wrote: I'm 95% certain that this was the result of a bug in /usr/libexec/security fixed in late June. Philip Guenther Hello Philip Guenther, my system /usr/libexec/security is version 1.31. My system version is: OpenBSD 5.6 (GENERIC.MP) #325: Tue

Re: /etc/daily report error/warning message

2014-08-17 Thread johnw
On 08/17/2014 05:06 PM, Philip Guenther wrote: Heh, good thing I had that 5% hedge when making a guess based on fading memory of an email thread and the possibility that you were running an old snapshot. :-/ If no one else speaks up, the next step for tracking this down may be to ktrace

Re: /etc/daily report error/warning message

2014-08-17 Thread johnw
On 08/17/2014 05:06 PM, Philip Guenther wrote: On Sun, Aug 17, 2014 at 1:02 AM, johnw johnw.m...@gmail.com mailto:johnw.m...@gmail.com wrote: On 08/17/2014 03:46 PM, Philip Guenther wrote: I'm 95% certain that this was the result of a bug in /usr/libexec/security fixed

sleep with tame(2)?

2015-09-30 Thread johnw
Hi all, After upgrade to 30-Sep-2015 12:20 snapshot (AMD64), (download from http://ftp.openbsd.org) I noticed /bin/sleep with run tame(2) call, but I can not find any tame call in source code (cvsweb.openbsd.org). when I run sleep: john@pdc:[~]$ sleep Killed then I run dmesg, the last line

tame(2) will by pass systrace rules

2015-09-20 Thread johnw
Hi all, I run my program will systrace, I noticed the program can by pass systrace, If I add the tame(2) call to my program. my program will connect to inet, if I run my program will systrace, I need to add systrace rule like this "native-connect: permit", I noticed, if I add the

Fwd: about rc.subr

2016-04-28 Thread johnw
Hi, dbus also not working after upgrade to today current. CVSROOT: /cvs Module name: src Changes by: ajacou...@cvs.openbsd.org 2016/04/28 03:15:16 Modified files: etc/rc.d : rc.subr sndiod Log message: Experiment on matching on the daemon_user is over. It needs more work. portmap isn't happy

Re: L2TP/IPSec via npppd won't work with Android 5.x

2016-04-14 Thread johnw
Hi Renaud and the lists, Did you tried to use iked/ikev2 for android (+5.x) client? I checked my note3 is support ikev2 psk/rsa, I want to setup my home OpenBSD router act as vpn/nat router for my note3, Thanks. Renaud Allard allard.it> writes: > > > I can't get android to connect with modp >

Logging/backup .ksh_history

2016-08-08 Thread johnw
Hi, I use /bin/ksh as a console/terminal shell program, I want to log/backup all command, run on console/terminal/ksh, Any idea how to do this? Thanks. -- Key ID: 0xCF2C80AC Key fingerprint: CDB3 6C62 254B C088 1E5D DD32 182C 97DB CF2C 80AC 0xCF2C80AC.asc Description: application/pgp-keys

Re: Logging/backup .ksh_history

2016-08-08 Thread johnw
On 08/08/2016 04:33 PM, David Dahlberg wrote: > Am Montag, den 08.08.2016, 14:39 +0800 schrieb johnw: >> Hi, I use /bin/ksh as a console/terminal shell program, I want to >> log/backup all command, run on console/terminal/ksh, >> >> Any idea how to do this? >

Re: traceroute and pf

2016-09-28 Thread johnw
On 09/28/2016 07:05 PM, Janne Johansson wrote: > Apart from PF failing the syntax, what would one expect to achieve with > >=0 ? > > That would always cover all users, since its never a negative number. > /usr/include/sys/types.h:typedef__uid_t uid_t; > /* user id */ >

traceroute and pf

2016-09-28 Thread johnw
Hi, I have some problem setup pf, to pass out traceroute with user keyword. below rule do WORK. pass out quick on $ext_if inet proto udp from ($ext_if) to any or below one also WORK. pass out quick on $ext_if inet proto udp from ($ext_if) to any user != 1 but below one, do NOT WORK. pass

Re: httpd, SlowCGI, POST_MAX and 413 Payload Too Large

2016-11-27 Thread johnw
I have this inherit problem too. (explain below) Is it possible config "max request" sub domain independence? Thanks. https://marc.info/?l=openbsd-misc=144080241519699=2 - There seems to be an inherit problem with httpd.conf.

vmd: /dev/vmm: Operation not supported by device

2016-10-31 Thread johnw
Hi, I know my cpu (Intel E8400) support vt-x/vt-d, but when I run vmd, vmd: /dev/vmm: Operation not supported by device What is this mean? I did run kvm/qemu/linux on this machine before, and just checked my bios setting, the "Intel® Virtualization Technology" is enabled. Is this cpu support

Re: vmd: /dev/vmm: Operation not supported by device

2016-10-31 Thread johnw
On 10/31/2016 06:09 PM, Stefan Sperling wrote: > It seems the current implementation only supports a CPU if dmesg displays > "VMX/EPT", not just "VMX" (the vmmopen() function only succeeds if EPT > support is present). > > As for if or when this will change, I cannot say. > > Keep in mind that

pf tagged rule not work/match

2017-05-19 Thread johnw
After upgrade to last day current, pf tagged rule not work/match any more, it work before. ( below rules not match/work any more ) pass in quick on $int_if from any flags any tag HOME pass out quick on $ext_if from any nat-to ($ext_if:0) flags any tagged HOME if change pass out quick on

Re: pf tagged rule not work/match

2017-05-20 Thread johnw
Hi, this one fixed my problem, thanks http://marc.info/?l=openbsd-cvs=149532101008885=2 On 2017年5月19日 GMT+08:00下午10時00分32秒, johnw <johnw.m...@gmail.com> wrote: >After upgrade to last day current, pf tagged rule not work/match any >more, >it work before. > >( below rules no

/usr/sbin/httpd and chunked transfer encoding

2017-05-07 Thread johnw
Hi, After installed owncloud/nextcloud on my openbsd, I noticed android client do not support "chunked transfer encoding" (https://github.com/owncloud/android/issues/1128; Is it possible to disable this feature with "/usr/sbin/httpd"? Any idea how to solve it? Thanks. signature.asc

Re: /usr/sbin/httpd and chunked transfer encoding

2017-05-08 Thread johnw
On 05/08/2017 01:32 PM, Reyk Floeter wrote: > Hi, > > you cannot disable it and this Android client is broken. > > "A recipient MUST be able to parse and decode the chunked > transfer coding." > > https://tools.ietf.org/html/rfc7230#section-4.1 > > Reyk > Agreed, this Android client is broken, but

Re: /usr/sbin/httpd and chunked transfer encoding

2017-05-08 Thread johnw
com/nextcloud/android > >Maybe the nextcloud one fixed the bug? > > >On Mon, May 8, 2017 at 8:10 AM, johnw <johnw.m...@gmail.com> wrote: > >> On 05/08/2017 01:32 PM, Reyk Floeter wrote: >> > Hi, >> > >> > you cannot disable it and this Androi

smtpctl spf walk [-4|-6]

2018-01-25 Thread johnw
Hi Gilles, Is it possible add ipv4|ipv6 parameter to smtpctl spf walk [-4|-6] Thanks. Index: smtpctl.c === RCS file: /cvs/src/usr.sbin/smtpd/smtpctl.c,v retrieving revision 1.155 diff -u -r1.155 smtpctl.c --- smtpctl.c 6 Jan

/var/www/tmp permission

2018-12-13 Thread johnw
Hi, I want to run php-fpm as other did than www, but non www uid, cannot write session file to /var/www/tmp. (Is it good or bad, to run different uid?) Why the /var/www/tmp permission is 1700? Is it possible make /var/www/tmp permission 1777 by default? Thanks. Key fingerprint: CDB3 6C62 254B

vlan problem

2019-01-28 Thread johnw
hi, I want create vlan network, I create two files hostname.vio0 up hostname.vlan0 inet 10.10.10.101 255.255.255.0 10.10.10.255 parent vio0 vnetid 10 then reboot I can not ping 10.10.10.1 If I create bridge0, and add vio0 and vlan0 to bridge0, then I can ping 10.10.10.1 Or if I just use

Re: vlan problem

2019-01-28 Thread johnw
My system is: OpenBSD 6.4-current (GENERIC.MP) #639: Sun Jan 27 14:27:05 MST 2019 dera...@amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/GENERIC.MP Thanks. On 2019年1月28日 19:57:01 [GMT+08:00], johnw wrote: >hi, I want create vlan network, I create two files > >hostname

Re: vlan problem

2019-01-28 Thread johnw
tagged to achieve it, right? I am wondering, how people setup home network, to serve dlna (all Iot/computer on one subnet)? Thank you, thanks all. Zé Loff 於 2019-01-28 16:29 寫到: On Mon, Jan 28, 2019 at 07:57:01PM +0800, johnw wrote: hi, I want create vlan network, I create two files hostname.vio0

Re: vlan problem

2019-01-29 Thread johnw
Hi, finally, I following to https://wiki.debian.org/NetworkConfiguration, make both openbsd and debian support vlan, then I can ping/connect both side now. Thanks. On 2019年1月29日 09:53:07 [GMT+08:00], johnw wrote: >Hi, thank you first, and I think I totally misunderstand vlan. > >I wa