Disable the -fomit-frame-pointer optimisation by default.
The frame-pointer is needed to have good backtraces from e.g ddb or
ptrace / btrace. Many other distros did something like this as well since
the benfit of havving easy to work with backtraces outweights the little
overall speedup gained by having an extra register.
Also disable -mno-omit-leaf-frame-pointer by default on llvm.
OK kettenis@
libssl: ensure server selected ALPN was advertised
Per RFC 7301, section 3.2, "In the event that the server supports no
protocols that the client advertises, then the server SHALL respond
with a fatal "no_application_protocol" alert.
If a server does not do that and chooses a protocol that we have not
advertised, we should abort the handshake. The RFC does not specify
an alert for this case. BoringSSL chose illegal_parameter and OpenSSL
decode_error. I slightly prefer illegal_parameter, so went with that.
Reported by Acts1631 with a similar diff.
ok jsing kenjiro
tlsext_alpn_client_process(): rename list and proto
Use server_list and selected instead of list and proto to reduce noise
in the next commit.
ok jsing kenjiro
Make sure to build kernel files with -fno-pie; this had been forgotten while
switching the m88k toolchain to PIE by default, and I am quite impressed
kernels built with PIE objects run without problems.
Remove replaying of the 88100 data pipeline in sigreturn().
This had been added during the r1.18->r1.22 changes to let the testcases from
the devel/libsigsegv run.
Contrary to what I wrote then, the pipeline gets replayed when returning to
userland to invoke the signal handler, so there is no need to do this once more
in sigreturn.
The real fix needed for these testcases to run reliably, was to make sure that
the address used to spill the sigcontext on the process stack would not get
modified while running data_access_emulation(); this logic was eventually
fixed in r1.21, and nothing more is needed.
Thanks to Andrew Griffiths for pointing to my attention that the data fed to
sigreturn() was partially user-controllable, and that carefully crafted
signal handlers could use this behaviour as unprivileged kernel memory read
and write operations.