relayd: do not treat a missing Host header as a url match
Return RES_BAD if the request has no Host header, consistent with the
handling of empty or malformed Host values.
Spotted by Acts1631 (with diff), OK kirill@
When converting a section identifier (for example, "1" or "1m") to
a volume title (for example, "General Commands Manual" or "Maintenance
Commands") and no exact match is found for the identifier, retry
using only the first character of the identifier before giving up.
For example, when using OpenBSD to format the Oracle Solaris ipmitool(1m)
manual, which contains the line '.TH ipmitool 1m "29 June 2012"',
use the section 1 volume title "General Commands Manual" rather
than finding no title at all. In general, this improves formatting
of the page header line of manual pages using session suffixes that
are not declared in msec.in on the formatting system. That's useful
everywhere for formatting foreign manual pages, but also for
formatting native manuals on systems using many suffixes.
I had this idea for a small improvement while looking at how FreeBSD
customizes the companion file msec.in in their freebsd-src/contrib/mandoc
directory.
sys/usb: validate USB endpoint and configuration lengths
Reject undersized endpoint descriptors before accessing wMaxPacketSize;
require wTotalLength to cover the configuration header and match the
allocated size after the full fetch.
Reported by Stuart Thomas
OK: deraadt@
Instead of redrawing the entire pane or scene when moving or redrawing a
pane, add damage rectangles and redraw only the affected spans. From
Michael Grant.
pf(4): pfr_insert_kentry() always needs PF_LOCK()
pfr_insert_kentry() inserts an IP address into a table. The table's
consistency is protected by PF_LOCK(). Unfortunately, PF_LOCK()
protection is missing for the code path executed on behalf
of the overload action in a pf rule. The overload action instructs
the firewall to insert the packet's source address into the table specified
as the overload action parameter. That particular code path in
pf_test() function runs without any lock protection.
The bug was introduced in revision 1.1074 and remained unnoticed
until now, when it was kindly reported by alf (a.schlichting () lemarit ! com>)
OK henning@, OK dlg@, OK jmatthew@
httpd: add header block/drop rules for request filtering
With this incoming requests can also be rejected based on the value of a
request header. Valid options are:
header block name value code [arg]
Close the connection with an error response when a
request header matches. Both name and value are shell-
style patterns and are matched case-insensitively against
the header name and value. code must be a valid HTTP
status code. For codes in the 3xx range, arg is required
and sent as the "Location" header. It must start with
"http://" or "https://". For all other codes, arg is
optional and used as the log message identifying the
rule.
header drop name value
Silently close the connection without sending a response
when a request header matches, using the same pattern
[10 lines not shown]
relayd: apply the header length limit to chunk size and trailer lines
Chunk size and trailer lines were not limited, so a line without line
ending could be buffered without bound. Limit each chunk size line and
the whole trailer to the configured header length and close the
session if they exceed it.
Spotted by Acts1631 (with diff), OK kirill@
relayd: apply the header length limit to unterminated lines
The limit was only checked for complete lines, so a header line
without line ending could be buffered without bound. Reject such
lines with 413 as soon as they exceed the limit.
Spotted by Acts1631 (with diff), OK kirill@
don't access the DE_CFG MSR when running on a hypervisor
Sebastian Albert encountered a KVM hosting provider where trying
to access the MSR resulted in a protection fault.
DE_CFG is not documented in AMD's 'AMD64 Architecture Programmer's Manual'.
ok brynet@ mlarkin@