aboutsummaryrefslogtreecommitdiff
path: root/etc
Commit message (Collapse)AuthorAgeFilesLines
* Fix devfs rules not applied by default for jails.Xin LI2014-04-301-1/+1
| | | | | | | | | | | | | | | | | Fix OpenSSL use-after-free vulnerability. Fix TCP reassembly vulnerability. Security: FreeBSD-SA-14:07.devfs Security: CVE-2014-3001 Security: FreeBSD-SA-14:08.tcp Security: CVE-2014-3000 Security: FreeBSD-SA-14:09.openssl Security: CVE-2010-5298 Approved by: so Notes: svn path=/releng/10.0/; revision=265124
* MF10 r259974 (MFC r259973):Xin LI2013-12-271-9/+25
| | | | | | | | | | Tighten default restrictions for ntpd(8) server and provide a link to NTP access restriction documentation. Approved by: re (gjb) Notes: svn path=/releng/10.0/; revision=259975
* MFC r258894: Make rc(8) re-source rc.conf upon receipt of SIGALRM.Colin Percival2013-12-061-0/+5
| | | | | | | | | | | | The rc system aggressively caches the contents of /etc/rc.conf in order to improve boot performance; this produces arguably astonishing (non-)results if /etc/rc.conf is modified during the boot process. This commit provides a mechanism for explicitly requesting that rc.conf be reloaded. Approved by: re (rodrigc) Notes: svn path=/stable/10/; revision=259040
* MFC r258664:Xin LI2013-11-301-1/+1
| | | | | | | | | | | | Create /var/cache with mode 0755 instead of 0750. This directory is used by many third party applications and having permission 0750 makes it impossible to drop group privileges. Approved by: re (glebius) Notes: svn path=/stable/10/; revision=258762
* MFC r258227 (bapt):Glen Barber2013-11-281-1/+1
| | | | | | | | | | Enabled should be a boolean, not a string Approved by: re (glebius) Sponsored by: The FreeBSD Foundation Notes: svn path=/stable/10/; revision=258710
* Merge r256769 by des from head:Gleb Smirnoff2013-11-221-6/+0
| | | | | | | | | Last few remnants of BIND (hopefully...) Approved by: re (kib) Notes: svn path=/stable/10/; revision=258481
* Merge r257694 from head:Gleb Smirnoff2013-11-1416-896/+4
| | | | | | | | | | | | Remove remnants of BIND from /etc, since there is no BIND in base now. Sorry, that would break users running head and BIND from ports, since ports rely on these scripts. The ports will be fixed soon. Approved by: re (kib) Notes: svn path=/stable/10/; revision=258121
* MFC r257668:Bryan Drewery2013-11-071-1/+1
| | | | | | | | | | Use proper capitalization for FreeBSD.org Approved by: bapt Approved by: re (gjb) Notes: svn path=/stable/10/; revision=257797
* MFC r257667:Bryan Drewery2013-11-071-1/+1
| | | | | | | | | | | Enable fingerprint checking as the currently known fingerprint has an uploaded signature on all mirrors. Approved by: bapt Approved by: re (gjb) Notes: svn path=/stable/10/; revision=257794
* MFC r257344,r257403:Bryan Drewery2013-11-038-35/+9
| | | | | | | | | | Move /etc/keys to /usr/share/keys where users are less likely to modify them. Approved by: bapt Approved by: re (gjb) Notes: svn path=/stable/10/; revision=257572
* MFC r257361:Jeremie Le Hen2013-11-011-2/+2
| | | | | | | | | | | | | | | Fix compatibility function for old daily_status_security_${name}_enable variables. PR: conf/183137 MFC r257364: Fix indentation. Approved by: re (gjb) Notes: svn path=/stable/10/; revision=257508
* MFC: r256770,r257142,r257145,r257146,r257147,r257148,Bryan Drewery2013-10-298-0/+57
| | | | | | | | | | | | | | | | | | | | | | | | r257149,r257150,r257158,r257159,r257164,r257168, r257193 - Support checking signature for pkg bootstrap from remote and for 'pkg add ./pkg.txz' - Be verbose on where pkg is being bootstrapped from. - Add support for reading configuration files from /etc/pkg. For now only /etc/pkg/FreeBSD.conf is supported. - Add test package signing key fingerprint into /etc/keys/pkg/trusted. - Disable fingerprint checking by default for now as the official packages are not yet signed. Approved by: bapt Approved by: re (glebius) Notes: svn path=/stable/10/; revision=257353
* MFC r256773:John-Mark Gurney2013-10-233-0/+142
| | | | | | | | | | | Enable the automatic creation of a certificate (if one does not exists) and enable the usage by sendmail if sendmail is enabled. Reviewed by: gshapiro Approved by: re (gjb) Notes: svn path=/stable/10/; revision=256982
* MFC r256775,r256776:Colin Percival2013-10-222-2/+25
| | | | | | | | | | | | | Add support for "first boot" rc.d scripts. Document this new functionality in rc.conf(5) and rc(8). Bump __FreeBSD_version so that ports can make use of this. Approved by: re (gjb) Notes: svn path=/stable/10/; revision=256916
* MFC 256716,256835:Hiroki Sato2013-10-221-38/+83
| | | | | | | | | | | | | - Fix jail_parallel_start="YES". - Fix ip[46].addr when interface parameter is not defined. - Fix a bug which prevented jails from starting when $jail_conf was used and no jail name was specified. - Display error messages when start/stop fails. Approved by: re (glebius) Notes: svn path=/stable/10/; revision=256874
* MFC 256440, 256498:Hiroki Sato2013-10-171-31/+72
| | | | | | | | | | | | | | | - Normalize jailname. "example.com" is converted to "example_com". - Fix a bug that some $jail_{jname}_foo variables did not work. - Fix a bug which prevented $jail_devfs_ruleset from working[1]. - Move $jail_parameters to the last of the configuraiton lines[1]. - Fix "ifname|addr" syntax support in jail_{jname}_ip. - Create /var/run/jail_{jname}.id because ezjail-admin depends on it. Reported by: jase [1] Approved by: re (gjb) Notes: svn path=/stable/10/; revision=256668
* MFC 256385:Hiroki Sato2013-10-121-3/+2
| | | | | | | | | | | | | | - Add mount.fdescfs parameter to jail(8). This is similar to mount.devfs but mounts fdescfs. The mount happens just after mount.devfs. - rc.d/jail now displays whole error message from jail(8) when a jail fails to start. Approved by: re (gjb) Notes: svn path=/stable/10/; revision=256387
* Merge from project branch via main. Uninteresting commits are trimmed.Mark Murray2013-10-122-34/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Refactor of /dev/random device. Main points include: * Userland seeding is no longer used. This auto-seeds at boot time on PC/Desktop setups; this may need some tweeking and intelligence from those folks setting up embedded boxes, but the work is believed to be minimal. * An entropy cache is written to /entropy (even during installation) and the kernel uses this at next boot. * An entropy file written to /boot/entropy can be loaded by loader(8) * Hardware sources such as rdrand are fed into Yarrow, and are no longer available raw. ------------------------------------------------------------------------ r256240 | des | 2013-10-09 21:14:16 +0100 (Wed, 09 Oct 2013) | 4 lines Add a RANDOM_RWFILE option and hide the entropy cache code behind it. Rename YARROW_RNG and FORTUNA_RNG to RANDOM_YARROW and RANDOM_FORTUNA. Add the RANDOM_* options to LINT. ------------------------------------------------------------------------ r256239 | des | 2013-10-09 21:12:59 +0100 (Wed, 09 Oct 2013) | 2 lines Define RANDOM_PURE_RNDTEST for rndtest(4). ------------------------------------------------------------------------ r256204 | des | 2013-10-09 18:51:38 +0100 (Wed, 09 Oct 2013) | 2 lines staticize struct random_hardware_source ------------------------------------------------------------------------ r256203 | markm | 2013-10-09 18:50:36 +0100 (Wed, 09 Oct 2013) | 2 lines Wrap some policy-rich code in 'if NOTYET' until we can thresh out what it really needs to do. ------------------------------------------------------------------------ r256184 | des | 2013-10-09 10:13:12 +0100 (Wed, 09 Oct 2013) | 2 lines Re-add /dev/urandom for compatibility purposes. ------------------------------------------------------------------------ r256182 | des | 2013-10-09 10:11:14 +0100 (Wed, 09 Oct 2013) | 3 lines Add missing include guards and move the existing ones out of the implementation namespace. ------------------------------------------------------------------------ r256168 | markm | 2013-10-08 23:14:07 +0100 (Tue, 08 Oct 2013) | 10 lines Fix some just-noticed problems: o Allow this to work with "nodevice random" by fixing where the MALLOC pool is defined. o Fix the explicit reseed code. This was correct as submitted, but in the project branch doesn't need to set the "seeded" bit as this is done correctly in the "unblock" function. o Remove some debug ifdeffing. o Adjust comments. ------------------------------------------------------------------------ r256159 | markm | 2013-10-08 19:48:11 +0100 (Tue, 08 Oct 2013) | 6 lines Time to eat crow for me. I replaced the sx_* locks that Arthur used with regular mutexes; this turned out the be the wrong thing to do as the locks need to be sleepable. Revert this folly. # Submitted by: Arthur Mesh <arthurmesh@gmail.com> (In original diff) ------------------------------------------------------------------------ r256138 | des | 2013-10-08 12:05:26 +0100 (Tue, 08 Oct 2013) | 10 lines Add YARROW_RNG and FORTUNA_RNG to sys/conf/options. Add a SYSINIT that forces a reseed during proc0 setup, which happens fairly late in the boot process. Add a RANDOM_DEBUG option which enables some debugging printf()s. Add a new RANDOM_ATTACH entropy source which harvests entropy from the get_cyclecount() delta across each call to a device attach method. ------------------------------------------------------------------------ r256135 | markm | 2013-10-08 07:54:52 +0100 (Tue, 08 Oct 2013) | 8 lines Debugging. My attempt at EVENTHANDLER(multiuser) was a failure; use EVENTHANDLER(mountroot) instead. This means we can't count on /var being present, so something will need to be done about harvesting /var/db/entropy/... . Some policy now needs to be sorted out, and a pre-sync cache needs to be written, but apart from that we are now ready to go. Over to review. ------------------------------------------------------------------------ r256094 | markm | 2013-10-06 23:45:02 +0100 (Sun, 06 Oct 2013) | 8 lines Snapshot. Looking pretty good; this mostly works now. New code includes: * Read cached entropy at startup, both from files and from loader(8) preloaded entropy. Failures are soft, but announced. Untested. * Use EVENTHANDLER to do above just before we go multiuser. Untested. ------------------------------------------------------------------------ r256088 | markm | 2013-10-06 14:01:42 +0100 (Sun, 06 Oct 2013) | 2 lines Fix up the man page for random(4). This mainly removes no-longer-relevant details about HW RNGs, reseeding explicitly and user-supplied entropy. ------------------------------------------------------------------------ r256087 | markm | 2013-10-06 13:43:42 +0100 (Sun, 06 Oct 2013) | 6 lines As userland writing to /dev/random is no more, remove the "better than nothing" bootstrap mode. Add SWI harvesting to the mix. My box seeds Yarrow by itself in a few seconds! YMMV; more to follow. ------------------------------------------------------------------------ r256086 | markm | 2013-10-06 13:40:32 +0100 (Sun, 06 Oct 2013) | 11 lines Debug run. This now works, except that the "live" sources haven't been tested. With all sources turned on, this unlocks itself in a couple of seconds! That is no my box, and there is no guarantee that this will be the case everywhere. * Cut debug prints. * Use the same locks/mutexes all the way through. * Be a tad more conservative about entropy estimates. ------------------------------------------------------------------------ r256084 | markm | 2013-10-06 13:35:29 +0100 (Sun, 06 Oct 2013) | 5 lines Don't use the "real" assembler mnemonics; older compilers may not understand them (like when building CURRENT on 9.x). # Submitted by: Konstantin Belousov <kostikbel@gmail.com> ------------------------------------------------------------------------ r256081 | markm | 2013-10-06 10:55:28 +0100 (Sun, 06 Oct 2013) | 12 lines SNAPSHOT. Simplify the malloc pools; We only need one for this device. Simplify the harvest queue. Marginally improve the entropy pool hashing, making it a bit faster in the process. Connect up the hardware "live" source harvesting. This is simplistic for now, and will need to be made rate-adaptive. All of the above passes a compile test but needs to be debugged. ------------------------------------------------------------------------ r256042 | markm | 2013-10-04 07:55:06 +0100 (Fri, 04 Oct 2013) | 25 lines Snapshot. This passes the build test, but has not yet been finished or debugged. Contains: * Refactor the hardware RNG CPU instruction sources to feed into the software mixer. This is unfinished. The actual harvesting needs to be sorted out. Modified by me (see below). * Remove 'frac' parameter from random_harvest(). This was never used and adds extra code for no good reason. * Remove device write entropy harvesting. This provided a weak attack vector, was not very good at bootstrapping the device. To follow will be a replacement explicit reseed knob. * Separate out all the RANDOM_PURE sources into separate harvest entities. This adds some secuity in the case where more than one is present. * Review all the code and fix anything obviously messy or inconsistent. Address som review concerns while I'm here, like rename the pseudo-rng to 'dummy'. # Submitted by: Arthur Mesh <arthurmesh@gmail.com> (the first item) ------------------------------------------------------------------------ r255319 | markm | 2013-09-06 18:51:52 +0100 (Fri, 06 Sep 2013) | 4 lines Yarrow wants entropy estimations to be conservative; the usual idea is that if you are certain you have N bits of entropy, you declare N/2. ------------------------------------------------------------------------ r255075 | markm | 2013-08-30 18:47:53 +0100 (Fri, 30 Aug 2013) | 4 lines Remove short-lived idea; thread to harvest (eg) RDRAND enropy into the usual harvest queues. It was a nifty idea, but too heavyweight. # Submitted by: Arthur Mesh <arthurmesh@gmail.com> ------------------------------------------------------------------------ r255071 | markm | 2013-08-30 12:42:57 +0100 (Fri, 30 Aug 2013) | 4 lines Separate out the Software RNG entropy harvesting queue and thread into its own files. # Submitted by: Arthur Mesh <arthurmesh@gmail.com> ------------------------------------------------------------------------ r254934 | markm | 2013-08-26 20:07:03 +0100 (Mon, 26 Aug 2013) | 2 lines Remove the short-lived namei experiment. ------------------------------------------------------------------------ r254928 | markm | 2013-08-26 19:35:21 +0100 (Mon, 26 Aug 2013) | 2 lines Snapshot; Do some running repairs on entropy harvesting. More needs to follow. ------------------------------------------------------------------------ r254927 | markm | 2013-08-26 19:29:51 +0100 (Mon, 26 Aug 2013) | 15 lines Snapshot of current work; 1) Clean up namespace; only use "Yarrow" where it is Yarrow-specific or close enough to the Yarrow algorithm. For the rest use a neutral name. 2) Tidy up headers; put private stuff in private places. More could be done here. 3) Streamline the hashing/encryption; no need for a 256-bit counter; 128 bits will last for long enough. There are bits of debug code lying around; these will be removed at a later stage. ------------------------------------------------------------------------ r254784 | markm | 2013-08-24 14:54:56 +0100 (Sat, 24 Aug 2013) | 39 lines 1) example (partially humorous random_adaptor, that I call "EXAMPLE") * It's not meant to be used in a real system, it's there to show how the basics of how to create interfaces for random_adaptors. Perhaps it should belong in a manual page 2) Move probe.c's functionality in to random_adaptors.c * rename random_ident_hardware() to random_adaptor_choose() 3) Introduce a new way to choose (or select) random_adaptors via tunable "rngs_want" It's a list of comma separated names of adaptors, ordered by preferences. I.e.: rngs_want="yarrow,rdrand" Such setting would cause yarrow to be preferred to rdrand. If neither of them are available (or registered), then system will default to something reasonable (currently yarrow). If yarrow is not present, then we fall back to the adaptor that's first on the list of registered adaptors. 4) Introduce a way where RNGs can play a role of entropy source. This is mostly useful for HW rngs. The way I envision this is that every HW RNG will use this functionality by default. Functionality to disable this is also present. I have an example of how to use this in random_adaptor_example.c (see modload event, and init function) 5) fix kern.random.adaptors from kern.random.adaptors: yarrowpanicblock to kern.random.adaptors: yarrow,panic,block 6) add kern.random.active_adaptor to indicate currently selected adaptor: root@freebsd04:~ # sysctl kern.random.active_adaptor kern.random.active_adaptor: yarrow # Submitted by: Arthur Mesh <arthurmesh@gmail.com> Submitted by: Dag-Erling Smørgrav <des@FreeBSD.org>, Arthur Mesh <arthurmesh@gmail.com> Reviewed by: des@FreeBSD.org Approved by: re (delphij) Approved by: secteam (des,delphij) Notes: svn path=/stable/10/; revision=256381
* MFC 256365Rui Paulo2013-10-129-81/+0
| | | | | | | | | Remove most of the ATF tools and the _atf user. Approved by: re Notes: svn path=/stable/10/; revision=256366
* - Remove debugging from GENERIC* kernel configurationsGlen Barber2013-10-101-1/+1
| | | | | | | | | | | | | - Enable MALLOC_PRODUCTION - Default dumpdev=NO - Remove UPDATING entry regarding debugging features - Bump __FreeBSD_version to 1000500 Approved by: re (implicit) Sponsored by: The FreeBSD Foundation Notes: svn path=/stable/10/; revision=256283
* - Update rc.d/jail to use a jail(8) configuration file instead ofHiroki Sato2013-10-103-623/+297
| | | | | | | | | | | | | | | command line options. The "jail_<jname>_*" rc.conf(5) variables for per-jail configuration are automatically converted to /var/run/jail.<jname>.conf before the jail(8) utility is invoked. This is transparently backward compatible. - Fix a minor bug in jail(8) which prevented it from returning false when jail -r failed. Approved by: re (glebius) Notes: svn path=/head/; revision=256256
* Add support for "vnet jname" argument in ifconfig_IF. The vnet keywordHiroki Sato2013-10-102-14/+100
| | | | | | | | | | | | | | is ignored except for "rc.d/netif vnet{up,down} ifn" because a jail is usually created after interface initialization on boot time. "rc.d/netif vnetup ifn" moves ifn into the specified jail. It is designed to be used in other scripts like rc.d/jail, not automatically invoked during the interface initialization. Approved by: re (kib) Notes: svn path=/head/; revision=256255
* Reduce priority of host key exists message in sshd startupXin LI2013-10-071-1/+1
| | | | | | | | | script to info. Approved by: re (gjb) Notes: svn path=/head/; revision=256126
* Add _atf and unbound and move smmsp and mailnull to where they belong.Dag-Erling Smørgrav2013-10-071-2/+4
| | | | | | | Approved by: re (kib) Notes: svn path=/head/; revision=256097
* Do not attempt to do AF-specific configurations on a interface whenHiroki Sato2013-10-041-7/+12
| | | | | | | | | | | | | noafif() is true. The following warning message was displayed when pflog0 interface existed, for example: ifconfig: ioctl(SIOCGIFINFO_IN6): Protocol family not supported Reported by: bz Approved by: re (gjb) Notes: svn path=/head/; revision=256040
* Add epair(4) support in $cloned_interfaces. One should be specifiedHiroki Sato2013-10-042-47/+118
| | | | | | | | | | | | | | | | | as "epair0" in $cloned_interfaces and "epair0[ab]" in the others in rc.conf like the following: cloned_interfaces="epair0" ifconfig_epair0a="inet 192.168.1.1/24" ifconfig_epair0b="inet 192.168.2.1/24" /etc/rc.d/netif now accepts both "netif start epair0" and "netif start epair0a". Approved by: re (kib) Notes: svn path=/head/; revision=256039
* Do not install bluetooth rc(8) scripts if MK_BLUETOOTH = no.Glen Barber2013-10-031-3/+6
| | | | | | | | | Approved by: re (glebius) MFC after: 3 days Sponsored by: The FreeBSD Foundation Notes: svn path=/head/; revision=256022
* Fix up typos from r255963 in mtree Makefile. BSD.debug.dist should beMatthew D Fleming2013-10-031-2/+2
| | | | | | | | | iterated if present, and remove a stray .endif. Approved by: re (gjb) Notes: svn path=/head/; revision=256013
* Odds and ends left over from BIND and unnoticed because they didn'tDag-Erling Smørgrav2013-10-012-13/+1
| | | | | | | | | affect 'make universe'. Approved by: re (gjb) Notes: svn path=/head/; revision=255963
* Remove /usr/include/lwresDag-Erling Smørgrav2013-09-301-2/+0
| | | | | | | Approved by: re (gjb) Notes: svn path=/head/; revision=255953
* Remove BIND.Dag-Erling Smørgrav2013-09-304-81/+0
| | | | | | | Approved by: re (gjb) Notes: svn path=/head/; revision=255949
* Now that the portsnap buildbox is generating the raw bits for INDEX-10,Colin Percival2013-09-261-0/+1
| | | | | | | | | | add it to the set of INDEX files built by portsnap. Approved by: re (marius), portmgr (erwin) MFC after: 3 days Notes: svn path=/head/; revision=255878
* Forgotten in r255825: NETWORKING requires local_unbound.Dag-Erling Smørgrav2013-09-241-1/+1
| | | | | | | Approved by: re (blanket) Notes: svn path=/head/; revision=255843
* Replace the unused /etc/unbound directory with a symlink to /var/unbound.Dag-Erling Smørgrav2013-09-242-2/+5
| | | | | | | Approved by: re (blanket) Notes: svn path=/head/; revision=255841
* Move local_unbound up in the rc order.Dag-Erling Smørgrav2013-09-231-1/+1
| | | | | | | Approved by: re (blanket) Notes: svn path=/head/; revision=255825
* Add a setup script for unbound(8) called local-unbound-setup. ItDag-Erling Smørgrav2013-09-234-1/+105
| | | | | | | | | | | | | | | | | | | | | | | | | | | | generates a configuration suitable for running unbound as a caching forwarding resolver, and configures resolvconf(8) to update unbound's list of forwarders in addition to /etc/resolv.conf. The initial list is taken from the existing resolv.conf, which is rewritten to point to localhost. Alternatively, a list of forwarders can be provided on the command line. To assist this script, add an rc.subr command called "enabled" which does nothing except return 0 if the service is enabled and 1 if it is not, without going through the usual checks. We should consider doing the same for "status", which is currently pointless. Add an rc script for unbound, called local_unbound. If there is no configuration file, the rc script runs local-unbound-setup to generate one. Note that these scripts place the unbound configuration files in /var/unbound rather than /etc/unbound. This is necessary so that unbound can reload its configuration while chrooted. We should probably provide symlinks in /etc. Approved by: re (blanket) Notes: svn path=/head/; revision=255809
* Fix indentation.Dag-Erling Smørgrav2013-09-221-1/+1
| | | | | | | Approved by: re (blanket) Notes: svn path=/head/; revision=255794
* Ditch the random seeding code, which never really worked as intended.Dag-Erling Smørgrav2013-09-211-66/+39
| | | | | | | | | | | Add config variables to enable / disable individual host key algorithms. Clean up the host key generation code. Approved by: re (gjb) MFC after: 3 weeks Notes: svn path=/head/; revision=255766
* - Fix pidfile handling in sendmail_msp_queue. The pidfile was ignoredHiroki Sato2013-09-171-5/+2
| | | | | | | | | | | | and multiple instances were invoked by start/stop cycles. - Remove redundant start_cmd rewrite. Approved by: re (gjb) Tested by: jmg Notes: svn path=/head/; revision=255654
* Fix parsing lines of ifconfig output which include \t in the case ofHiroki Sato2013-09-171-7/+8
| | | | | | | | | inet and inet6. Approved by: re (delphij) Notes: svn path=/head/; revision=255653
* Build and install the Unbound caching DNS resolver daemon.Dag-Erling Smørgrav2013-09-154-0/+6
| | | | | | | Approved by: re (blanket) Notes: svn path=/head/; revision=255597
* Bring in the new iSCSI target and initiator.Edward Tomasz Napierala2013-09-145-0/+69
| | | | | | | | | Reviewed by: ken (parts) Approved by: re (delphij) Sponsored by: FreeBSD Foundation Notes: svn path=/head/; revision=255570
* ipfilter 5.1.2 no longer supports sysctl. Use ipf -V to determine ifCy Schubert2013-09-103-6/+4
| | | | | | | | | | available (the kernel module is loaded or compiled into the kernel). Approved by: glebius (mentor) Approved by: re (blanket) Notes: svn path=/head/; revision=255450
* The correct variable is apparently MACHINE_ARCH, not TARGET_ARCH.Dag-Erling Smørgrav2013-09-091-1/+1
| | | | | | | Approved by: re (blanket) Notes: svn path=/head/; revision=255425
* Remove unneeded mappings from libmap32.conf. Move it up one level andDag-Erling Smørgrav2013-09-092-4/+2
| | | | | | | | | | install it on powerpc64 in addition to amd64. Reviewed by: kib Approved by: re (blanket) Notes: svn path=/head/; revision=255413
* Add a stock libmap32.conf for amd64. The first two lines have no effectDag-Erling Smørgrav2013-09-082-0/+8
| | | | | | | | | | | | | | except to document the hardcoded standard library search path for 32-bit binaries. The third line performs the equivalent substitution for the private library directory. Ironically, these entries rely on functionality which is only available in the COMPAT_32BIT version of rtld-elf. Approved by: re (blanket) Notes: svn path=/head/; revision=255385
* Create a private library directory (LIBPRIVATEDIR) for libraries whichDag-Erling Smørgrav2013-09-081-0/+4
| | | | | | | | | | | | | | | | | we don't want to expose but which can't or shouldn't be static. To mark a library as private, define PRIVATELIB in its Makefile. It will be installed in LIBPRIVATEDIR, which is normally /usr/lib/private (or /usr/lib32/private for 32-bit libraries on 64-bit platforms). To indicate that a program or library depends on a private library, define USEPRIVATELIB in its Makefile. The correct version of LIBPRIVATEDIR will be added to its run-time library search path. Approved by: re (blanket) Notes: svn path=/head/; revision=255384
* authpf needs /var/authpf to exist and be writable by group authpf.Dag-Erling Smørgrav2013-09-051-0/+2
| | | | Notes: svn path=/head/; revision=255243
* Add a c++/v1/tr1 include directory containing symlinks to all of the standardDavid Chisnall2013-09-041-0/+2
| | | | | | | | | | | | headrs. Lots of third-party code expects to find C++03 headers under tr1 because that's where GNU decided to hide them. This should fix ports that expect them there. MFC after: 1 week Notes: svn path=/head/; revision=255206
* Since r254974, periodic scripts' period can be configuredJeremie Le Hen2013-09-031-66/+70
| | | | | | | | | independently. There is no reason to leave their options with the daily ones, so move them to their own section. Move periodic scripts' options into their own section. Since r254974, Notes: svn path=/head/; revision=255169