rpki-client: rework handling of the expire time
The expire time for certificates was added as a hack for filemode and has
been unused in normal mode. We can use it to track the expiry time along
the validating chain of all objects by setting it when validating CAs.
TAs expire with their not after, intermediate CAs and EE certs expire at
the minimum of their notafter, their CRL's nextupdate and their issuer's
expire time. Signed objects inherit the expire time from their EE cert
(this can be handled more cleanly later on).
This way we do not need to grab a lock to determine the expire time of any
object and we can stop walking up the validation chain and look up the same
CRLs over and over again.
ok job
Randonly, when starting a daemon that sets rc_bg=YES, we may end up with:
/etc/rc.d/foo: kill: 123456: no such process
There's a race in the rc.subr(8) system where we can end up killing a non
existing process (which PID may already be reused by another one).
The reason is that rc_alarm timer sends a SIGALRM to all children of rc_cmd to
detach rc_start. But the timer is also a child... and can then die while
rc_cmd() is about to kill it; that's when you get the error (as it's already
gone).
Re-implement so the timer ignore SIGALRM and let it get killed by rc_cmd.
My tests confirm this fixes the issue, so commit it early in the release
process to make sure this does not introduce any regression.
reported on bugs@ by adfsilva at gmail dot com
ok kn@
In pf(4) check AH header length.
pf_walk_header() advances the packet offset for each AH extension
header. It was not checked that this does not exceed the packet
length if no next header was processed. Fix it like in IPv6.
OK henning@ sashan@
minor polishing of macro use for consistency with port-modules(5)
and bsd.port.mk(5), no text change:
.Cm for make(1) targets, module names, and keywords/fixed strings
.Ev for make(1) variables .Pa for file names .Fl for command line flags
OK sthen@
Implement MT7925 specific mcu_set_rts_thresh and mac_tx_free functions.
With this MT7925 can associate to open APs in 11a/b/g modes. In my tests
11a works well, 2GHz 11g is very slow which is maybe because of all the
2GHz noise on that channel.
Committed over my MT7925.
vmd(8): better virtio vq validation
add some queue size checks and reject malformed descriptor chains.
also make viornd consume all pending buffers from last_avail.
ok dv
Add truncation detection to vmd's instruction decoder.
vmd(8) ultimately needs a way to deal with instructions that cross
page boundaries. This is a baby step to get there by fixing up the
decoder logic to detect when we're out of fetched instruction bytes
but not done decoding an instruction. Next steps will be to add in
cross-page fetching and injecting #PF if the next page is paged out
and we weren't able to decode with just the bytes from the first page.
These state machine changes uncovered some issues with 16-bit
addressing and decoding that got fixed along the way.
ok mlarkin@