vmm(4): handle proper injection during mov ss/sti shadow on vmx
arm the interrupt window when we have something to inject but are in a mov ss
or sti interrupt shadow
ok dv
rpki-client: don't treat a duplicate CCR MFT as fatal
It is possible to concoct situations where two PPs serve byte identical
manifests. Then CCR generation errors with "CCR MFT tree corrupted".
Handle this situation gracefully and only warn about the weird situation.
There are more problems in the vicinity that need fixing but that's for
after the release.
Reported by eur1ka qq com. Diff is a tweaked version of the suggested fix.
ok job
sys/qwz: unwind cold startup failures
Based on sys/dev/ic/qwx.c,v 1.134
Track powerup and completed core initialization so failed cold starts
reset hardware before reclaiming initialized DMA resources. Release
partial TX allocations and RX rings; ordinary interface down and up
continues to retain firmware.
OK: stsp@
sys/qwz: skip uninitialized CE polling
Based on sys/dev/ic/qwx.c,v 1.135
Track successful CE initialization to decide whether completion
polling is valid; provide dircet TX buffer reclamation for cold
cleanup after hardware reset, when ring polling is no longer safe.
OK: stsp@
sys/qwz: retain HAL allocations on resume
Based on sys/dev/ic/qwx.c,v 1.97 and sys/dev/ic/qwx.c,v 1.136
Preserve HAL allocation pointers across reinitialization: reuse qwz
allocated ring configuration and claer retained pointer memory. On
failure, free only allocations made by the current attempt.
OK: stsp@
For allocations between half a page and a page (which are moved
towards the end) we don't clear the proper region with freezero().
Instead, the clearing is done from the start of the page. So fix that.
Reported by Acts1631
ok deraadt@
Fix softraid rebuild on disks with 4096-byte sectors.
Problem found, suggested diffs, and testing by Dariusz Swiderski.
ok claudio@ "makes release" deraadt@
set_dist_point_name(): tiny tweak to restore previous behavior
Allocate fnm before allocating *pdp. This way a second call to to
set_dist_point_name() has a tiny little chance of succeeding.
ok beck ("I strongly suspect this will never matter anywhere.")
libcrypto: remove support for nameRelativeToCRLIssuer
Drop support for nameRelativeToCRLIssuer from the CRL Distribution Point
extension. Per RFC 5280, 4.2.1.13, conforming CAs SHOULD not use it, which
is sound advice since this garbage was eating memory for breakfast before
signature thanks to the wonderful gem that is the extension cache.
One has to wonder why this was needed in libcrypto... This isn't worth
fixing so off to the bit bucket it goes.
from tb, ok beck jsing
libssl: Avoid potential overread on interrupted retransmission in DTLS
from OpenSSL via jsing
this is errata/7.8/060_libressl.patch.sig
libcrypto: remove support for nameRelativeToCRLIssuer
Drop support for nameRelativeToCRLIssuer from the CRL Distribution Point
extension. Per RFC 5280, 4.2.1.13, conforming CAs SHOULD not use it, which
is sound advice since this garbage was eating memory for breakfast before
signature thanks to the wonderful gem that is the extension cache.
One has to wonder why this was needed in libcrypto... This isn't worth
fixing so off to the bit bucket it goes.
from tb, ok beck jsing
libssl: Avoid potential overread on interrupted retransmission in DTLS
from OpenSSL via jsing
this is errata/7.9/024_libressl.patch.sig
libcrypto: remove support for nameRelativeToCRLIssuer
Drop support for nameRelativeToCRLIssuer from the CRL Distribution Point
extension. Per RFC 5280, 4.2.1.13, conforming CAs SHOULD not use it, which
is sound advice since this garbage was eating memory for breakfast before
signature thanks to the wonderful gem that is the extension cache.
One has to wonder why this was needed in libcrypto... This isn't worth
fixing, so off to the bit bucket it goes.
ok beck jsing