<feed xmlns='http://www.w3.org/2005/Atom'>
<title>wireguard-openbsd/lib/libfido2, branch master</title>
<subtitle>WireGuard implementation for the OpenBSD kernel</subtitle>
<id>https://git.zx2c4.com/wireguard-openbsd/atom/lib/libfido2?h=master</id>
<link rel='self' href='https://git.zx2c4.com/wireguard-openbsd/atom/lib/libfido2?h=master'/>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/'/>
<updated>2021-02-15T11:26:00Z</updated>
<entry>
<title>Back-out USB data toggle fix for HID devices, since we received multiple</title>
<updated>2021-02-15T11:26:00Z</updated>
<author>
<name>mglocker</name>
<email>mglocker@openbsd.org</email>
</author>
<published>2021-02-15T11:26:00Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=65f50905169ac9865a865e567e90c5d9c01d42c1'/>
<id>urn:sha1:65f50905169ac9865a865e567e90c5d9c01d42c1</id>
<content type='text'>
reports about broken devices, e.g. for ukbd(4) and fido(4).

ok mpi@
</content>
</entry>
<entry>
<title>Remove the terrible_ping_kludge() workaround.  We have committed a fix to</title>
<updated>2021-02-05T14:19:21Z</updated>
<author>
<name>mglocker</name>
<email>mglocker@openbsd.org</email>
</author>
<published>2021-02-05T14:19:21Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=3e8238778f4be74f6fcf9204f0109c054d55136b'/>
<id>urn:sha1:3e8238778f4be74f6fcf9204f0109c054d55136b</id>
<content type='text'>
the USB stack in the meantime for uhidev(4) and ugen(4) to resolve the data
toggle issue in relation to xhci(4).

ok gnezdo@, djm@
</content>
</entry>
<entry>
<title>sync a couple of minor fixes (no API/ABI change) to bring libfido2</title>
<updated>2020-09-07T01:09:47Z</updated>
<author>
<name>djm</name>
<email>djm@openbsd.org</email>
</author>
<published>2020-09-07T01:09:47Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=6558ed23a80af04730a90ecefd3d20a45942ede5'/>
<id>urn:sha1:6558ed23a80af04730a90ecefd3d20a45942ede5</id>
<content type='text'>
in line with upstream 1.5.0
</content>
</entry>
<entry>
<title>check errno against EINTR; not return value from poll()</title>
<updated>2020-08-23T10:31:27Z</updated>
<author>
<name>djm</name>
<email>djm@openbsd.org</email>
</author>
<published>2020-08-23T10:31:27Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=774a2b88723926f241a358c2f01dedfb652bd267'/>
<id>urn:sha1:774a2b88723926f241a358c2f01dedfb652bd267</id>
<content type='text'>
spotted by Pedro Martelletto
</content>
</entry>
<entry>
<title>update to libfido2 46710ac06, picking up a few API changes</title>
<updated>2020-08-23T03:34:57Z</updated>
<author>
<name>djm</name>
<email>djm@openbsd.org</email>
</author>
<published>2020-08-23T03:34:57Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=8b51a2b13e7075d5cbacf4b960d2ea4c9d08c6b2'/>
<id>urn:sha1:8b51a2b13e7075d5cbacf4b960d2ea4c9d08c6b2</id>
<content type='text'>
ok tb@ deraadt@

NB. major crank
</content>
</entry>
<entry>
<title>sync with upstream libfido2 rev 2fa20b889, picking up ~7 months</title>
<updated>2020-08-11T08:44:53Z</updated>
<author>
<name>djm</name>
<email>djm@openbsd.org</email>
</author>
<published>2020-08-11T08:44:53Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=739189a35a238815a54c8f21927a51f4ca78fa67'/>
<id>urn:sha1:739189a35a238815a54c8f21927a51f4ca78fa67</id>
<content type='text'>
of fixes and a few new APIs that we'd like to use in OpenSSH

ok deraadt@
</content>
</entry>
<entry>
<title>It appears we have come full-circle, where source code starts to use</title>
<updated>2020-02-07T06:24:08Z</updated>
<author>
<name>deraadt</name>
<email>deraadt@openbsd.org</email>
</author>
<published>2020-02-07T06:24:08Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=fb4bfcc27556e683088a1041869f4ba19e42a1df'/>
<id>urn:sha1:fb4bfcc27556e683088a1041869f4ba19e42a1df</id>
<content type='text'>
clang / "super new gcc" ism's, in particular ones which are totally
pointless as far as language goes.
Delete them.
</content>
</entry>
<entry>
<title>update to upstream libfido2 780ad3c25 (20120123)</title>
<updated>2020-02-07T00:57:49Z</updated>
<author>
<name>djm</name>
<email>djm@openbsd.org</email>
</author>
<published>2020-02-07T00:57:49Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=32a20e26b20487bf19bb6208590b368c9fa99453'/>
<id>urn:sha1:32a20e26b20487bf19bb6208590b368c9fa99453</id>
<content type='text'>
install manual pages

crank major

feedback &amp; ok jmc@ and naddy@
</content>
</entry>
<entry>
<title>Add fido(4), a HID driver for FIDO/U2F security keys</title>
<updated>2019-12-17T13:08:54Z</updated>
<author>
<name>reyk</name>
<email>reyk@openbsd.org</email>
</author>
<published>2019-12-17T13:08:54Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=1ba9f8e24a930839b47e1417a70ad7b6ffac57d7'/>
<id>urn:sha1:1ba9f8e24a930839b47e1417a70ad7b6ffac57d7</id>
<content type='text'>
While FIDO/U2F keys were already supported by the generic uhid(4)
driver, this driver adds the first step to tighten the security of
FIDO/U2F access.  Specifically, users don't need read/write access to
all USB/HID devices anymore and the driver also improves integration
with pledge(2) and unveil(2): It is pledge-friendly because it doesn't
require any ioctls to discover the device and unveil-friendly because
it uses a single /dev/fido/* directory for its device nodes.

It also allows to support FIDO/U2F in firefox without further
weakening the "sandbox" of the browser.  Firefox does not have a
proper privsep design and many operations, such as U2F access, are
handled directly by the main process.  This means that the browser's
"fat" main process needs direct read/write access to all USB HID
devices, at least on other operating systems.  With fido(4) we can
support security keys in Firefox under OpenBSD without such a
compromise.

With this change, libfido2 stops using the ioctl to query the device
vendor/product and just assumes "OpenBSD" "fido(4)" instead.  The
ioctl is still supported but there was no benefit in obtaining the
vendor product or name; it also allows to use libfido2 under pledge.

With feedback from deraadt@ and many others
OK kettenis@ djm@ and jmc@ for the manpage bits
</content>
</entry>
<entry>
<title>sync upstream commit with manpage fixes from jmc@</title>
<updated>2019-11-27T05:07:21Z</updated>
<author>
<name>djm</name>
<email>djm@openbsd.org</email>
</author>
<published>2019-11-27T05:07:21Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=d69e40a200165f17da76d46da5e21cae93ed1693'/>
<id>urn:sha1:d69e40a200165f17da76d46da5e21cae93ed1693</id>
<content type='text'>
&gt; commit 437896dcafc67d9596774c3bb9f97bfdb4810bb1
&gt; Author: pedro martelletto &lt;pedro@yubico.com&gt;
&gt; Date:   Wed Nov 20 09:38:22 2019 +0100
&gt;
&gt;     man: mop up dangling .Xr's; Jason McIntyre &lt;jmc@openbsd.org&gt;
</content>
</entry>
</feed>
