I strongly suspect these tools will work with unveil "/etc" "r" and
pledge "stdio rpath getpw inet dns". might even be able to
remove something after some observation.
Abort enhanced capability loop if reading all ones from the device instead
of looping infinitely; this value isn't allowed by the spec, but there are
devices behaving that way, from Intel no less.
ok deraadt@
vmd(8): add extra mmio region
this adds a no-op (reads return FFs, writes discarded) mmio region between the
end of guest RAM and 4GB. specifically recent i686 linux bootloaders/kernels do
what appear to be errant probes of high PAs in the > 0xc0000000 range, and
vmd treats all mmio accesses to unmapped regions as fatal.
this diff adds a region to cover any gap, such that accesses to those addresses
trap to vmd, which then does what real hw would do. other hypervisors do
similar things.
this allieviates the need to assign 4GB ram to these VMs which was previously
needed to work around the problem.
ok dv
rpki-client: rework handling of the expire time
The expire time for certificates was added as a hack for filemode and has
been unused in normal mode. We can use it to track the expiry time along
the validating chain of all objects by setting it when validating CAs.
TAs expire with their not after, intermediate CAs and EE certs expire at
the minimum of their notafter, their CRL's nextupdate and their issuer's
expire time. Signed objects inherit the expire time from their EE cert
(this can be handled more cleanly later on).
This way we do not need to grab a lock to determine the expire time of any
object and we can stop walking up the validation chain and look up the same
CRLs over and over again.
ok job