sys/uvm: unwind failed amap copies
A PR_NOWAIT chunk allocation in amap_copy() may fail after earlier
chunks already contain copied anons; amap_free() requires an empty amap,
so direct cleanup trips its diagnostic assertion or leaves copied anon
references orphaned which may end who knows how.
Uuse amap_wipeout() instead to reverse the partial copy, release the
shared lock, and free the temporary amap.
OK: kettenis@
When an escape sequence that requires an argument occurs at the end of an
input line and the argument is missing, abort parsing the line and report
an "incomplete escape sequence" error.
This fixes a read buffer overrun that Josiah Frentsos <jfrent at tilde.team>
sent a different patch for. Instead of always entering the argument
parsing code and detecting that there is no argument at two places in
the middle of that code, as Josiah proposed, i chose to instead check
up front that there is anything that can be parsed to begin with.
Also reminded by deraadt@, thanks!
devel/cargo module: add MODCARGO_LIBTEST_ARGS variable
in order to pass arguments to LIBTEST (cargo test subsystem) and not to cargo
itself, provides a specific variable.
from Andrew Kloet (.net)
Restore the OCSP no-check extension method
The conversion of X509V3_EXT_get_nid() from a table to a switch
omitted the OCSP no-check extension method.
Add the missing accessor declaration and switch case.
ok tb@
Improve imsg code, switch to imsgbuf_get and use more imsg_get_data
Switch the IMSG_HOST_DNS call to use imsg_add_strbuf and imsg_get_strbuf.
Also use NI_MAXHOST for the name length.
Also rework IMSG_PW_ENTRY and IMSG_GRP_ENTRY to use imsg_get_len()
and imsg_get_data() to fetch the record. Ensure that the data length
is large enough but not too large to fit into &ir.
ok jmatthew@
The previous fix to bus_dmamap_load() wasn't quite right. We do need
virtual address continuity when we're bouncing. So a !bounce check
was correct, but only in the case when DMA is cache coherent. Note that
this becomes identical to the amd64 equivalent of this code when one
considers that on amd64 DMA is always cache coherent.
ok deraadt@, jca@
pkgconf: simplify unveil handling
Instead of giving fine-grained read access by iterating, use a simple
unveil("/", "r"). pkgconf runs with pledge "stdio rpath wpath cpath unveil"
with closed unveil, and only /dev/null and an optional log file have "rwc".
discussed with deraadt a long time ago, agreement by claudio
ok sthen
relayd: allow setting log level from relayd.conf
Add "log level (brief|verbose)" which sets or clears RELAYD_OPT_VERBOSE
just like relayctl log verbose|brief does at runtime.
This makes sense now because the recent DPRINTF removal turned all
DPRINTF calls into real log_debug calls. Some debug logs moved to
warning. Some remained DPRINF().
Before that change the toggle had almost nothing to gate. All debug
output was compiled out unless relayd was built with DEBUG > 1. So
"log verbose" in relayctl was practically a no-op for users.
It was impossible for the user to work out why the setup/config wasn't
working.
Now the toggle actually does what its name suggests. Pinning the
level in the config file lets it survive restarts and SIGHUP reloads.
OK kirill@
add some options to allow setting or clearing the touch-required
and verify-required flags on FIDO private keys when resetting
the passphrase.
feedback/ok tb@
Allow session-bind at openssh.com requests when the agent is locked,
otherwise forwarding sessions established with an agent was locked
will be treated as local, rather than remote.
Reported by sn0x-sharma
avoid potential realloc use-after-free in the client if a remote
forwarding is added via the local session multiplexing socket
while a remote forwarding open request is pending with the server.
Report and fix from Brian Mingus of Cognatory