www/caddy-custom: Fix build with BUILD_AS_NON_ROOT=yes
Two fixes:
1. Establish a GOCACHE and GOPATH for BUILD_AS_NON_ROOT so it doesn't
try to use /nonexistant/go (patch by Brad Ackerman).
2. Reset PORTREVISION (Vick Khera). I added a note in caddy/Makefile
so maybe I'll remember in the future.
PR: 295182
www/caddy: Update to 2.11.6
Changes: https://github.com/caddyserver/caddy/releases/tag/v2.11.6
There are some breaking changes in this release, so you should read
that list. They are primarily security-tightening changes and should
be invisible to most users. If you were relying on uploading files in
headers rather than the body, you'll want to make some changes.
sendfile: keep the lowat hack more conservative
First, record the original lowat value and later in the wait/EAGAIN loop
look at the original value, rather than on the value that we just faked.
This eliminates some blank syscalls, where socket was reported as writable
and immediate write instantly fails. In my testing the ratio of such
syscalls was really small, under 2%, however in a different scenario this
negative effect can be more profound.
Second, cap the lowat growth to 1/2 of original socket buffer size, rather
than to current size. The problem was there before, but it became more
profound after 587c6c121504.
Note: we are considering to evaluate if the lowat hack is needed at all.
Reviewed by: tuexen
Differential Revision: https://reviews.freebsd.org/D60106
tcp: use SB_AUTOSIZE flag to tell if socket buffer was set
The check against V_tcp_sendspace is not a correct one, as a buffer may
grow larger than the initial value. The conjunction was always false up
until 587c6c121504, and only after it the bug surfaced.
If we already grow our buffer past the value stored in the hostcache,
prefer our value.
Reviewed by: tuexen
Differential Revision: https://reviews.freebsd.org/D60105
vt: Fix timer race between vtterm_splash() and vt_flush()
Current code leads to console text being drawn over the splash image.
vt_flush() draws while holding the vtbuf lock. Have it check VDF_SPLASH
under it too, and make vtterm_splash() take the vtbuf lock when setting
it, before drawing the splash.
Sponsored by: Defenso
Signed-off-by: Quentin Thébault <quentin.thebault at defenso.fr>
Reviewed by: vexeduxr
Differential Revision: https://reviews.freebsd.org/D59928
stand/images: remove translucent pixels around orb
Remove semi-transparent pixels around the orb. These become more
pronounced when the orb is used as the spash screen image.
While here also strip metadata.
MFC after: 3 days
Reviewed by: tsoome
Differential Revision: https://reviews.freebsd.org/D60163
crypto/openssl: upgrade to 3.0.22
All of the security content from 3.0.22 has been merged to this branch
already; this follows through with the remainder of the changes to
finish off the version update -- in part to make future updates easier.
This is a direct commit to :stable/14.
See commit 3180d4d82f5 a description of the content update done between
the two versions, as well as the update methodology used when importing
OpenSSL 3.0.22.
net-mgmt/harica: [NEW PORT] Go client for the HARICA API
harica is a Go package for interacting with the HARICA API - the current
TLS certificate service provider for the GÉANT community
PR: 299024
Sponsored by: PANS Jarosław
mountpoint(1): new utility, implemented as a stat(1) hardlink
Add mountpoint(1), a simple utility to tell whether the file pointed
to by the argument is a mount point. It prints whether it is, unless
-q is given, and exits 0 if it is, 1 if it is not, and 2 on error.
The answer comes from the kernel with a single stat(2): the root vnode
of a mounted file system is reported with SFBSD_MNTPOINT in
st_bsdflags. Unlike comparing realpath(3) of the argument with that
of statfs(2)'s f_mntonname, this works for arbitrarily deep
hierarchies, and after chroot(2) or inside a jail. A chroot or jail
root is reported as a mount point only if it is one.
The argument does not have to be a directory: file systems such as
nullfs(5) can be mounted over regular files and sockets, and stat(2)
reports those mount points as well.
Since all that is needed is one stat(2) call, make mountpoint a
hardlink to stat(1), the same way readlink(1) is, and document it in
[11 lines not shown]