<feed xmlns='http://www.w3.org/2005/Atom'>
<title>wireguard-openbsd/libexec/spamd/spamd.8, branch jd/simplify-queueing</title>
<subtitle>WireGuard implementation for the OpenBSD kernel</subtitle>
<id>https://git.zx2c4.com/wireguard-openbsd/atom/libexec/spamd/spamd.8?h=jd%2Fsimplify-queueing</id>
<link rel='self' href='https://git.zx2c4.com/wireguard-openbsd/atom/libexec/spamd/spamd.8?h=jd%2Fsimplify-queueing'/>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/'/>
<updated>2019-07-24T18:41:05Z</updated>
<entry>
<title>Ever since I introduced pledge(2) on spamd(8) the chroot'ed process, if running</title>
<updated>2019-07-24T18:41:05Z</updated>
<author>
<name>mestre</name>
<email>mestre@openbsd.org</email>
</author>
<published>2019-07-24T18:41:05Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=fd9fa3ac1b409c700bd4b6768bfcd3ad46ac29e6'/>
<id>urn:sha1:fd9fa3ac1b409c700bd4b6768bfcd3ad46ac29e6</id>
<content type='text'>
in default, cannot get anywhere near the filesystem since its only promises are
"stdio inet". Furthermore, in blacklist mode this same codepath is not
chroot'ed but once again it gets the same pledge(2).

Therefore we can remove the BUGS section from spamd(8)'s manpage.

OK millert@ deraadt@
</content>
</entry>
<entry>
<title>note that some hosts never generate tuples and are ignored;</title>
<updated>2017-04-02T18:14:34Z</updated>
<author>
<name>jmc</name>
<email>jmc@openbsd.org</email>
</author>
<published>2017-04-02T18:14:34Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=c57e657f8f02eb3d1248e2aed512a8bac1c2cd97'/>
<id>urn:sha1:c57e657f8f02eb3d1248e2aed512a8bac1c2cd97</id>
<content type='text'>
ok beck
</content>
</entry>
<entry>
<title>define the role of spamd-setup a little better;</title>
<updated>2017-03-16T15:16:21Z</updated>
<author>
<name>jmc</name>
<email>jmc@openbsd.org</email>
</author>
<published>2017-03-16T15:16:21Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=18b3c5b8f73c693c8171ed87f6ba36e40e19b634'/>
<id>urn:sha1:18b3c5b8f73c693c8171ed87f6ba36e40e19b634</id>
<content type='text'>
</content>
</entry>
<entry>
<title>use one way to show filter rules, not two. the bits and pieces of the</title>
<updated>2017-03-16T15:07:45Z</updated>
<author>
<name>jmc</name>
<email>jmc@openbsd.org</email>
</author>
<published>2017-03-16T15:07:45Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=53028453fb9a9a3bf2c9514e3ab1fd10fcf36372'/>
<id>urn:sha1:53028453fb9a9a3bf2c9514e3ab1fd10fcf36372</id>
<content type='text'>
spamd setup are complex enough without freestyling the pf rules;

while here, Bk/Ek no longer required
</content>
</entry>
<entry>
<title>start replacing some \*([GL]t;</title>
<updated>2015-08-12T14:41:37Z</updated>
<author>
<name>jmc</name>
<email>jmc@openbsd.org</email>
</author>
<published>2015-08-12T14:41:37Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=f77456993a08f35cb48736e083e72dd08b81ad64'/>
<id>urn:sha1:f77456993a08f35cb48736e083e72dd08b81ad64</id>
<content type='text'>
</content>
</entry>
<entry>
<title>divert-to a table needs an address family;</title>
<updated>2015-08-12T14:36:47Z</updated>
<author>
<name>jmc</name>
<email>jmc@openbsd.org</email>
</author>
<published>2015-08-12T14:36:47Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=46ddce193739833ca1ae95072b501b4832753f41'/>
<id>urn:sha1:46ddce193739833ca1ae95072b501b4832753f41</id>
<content type='text'>
from steve shockley

ok sthen
</content>
</entry>
<entry>
<title>use file system path (.Pa) semantic markup macros where appropriate.</title>
<updated>2015-07-27T17:28:38Z</updated>
<author>
<name>sobrado</name>
<email>sobrado@openbsd.org</email>
</author>
<published>2015-07-27T17:28:38Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=b9170857bcc7a01a0c7526d7965c4c9339fbceb9'/>
<id>urn:sha1:b9170857bcc7a01a0c7526d7965c4c9339fbceb9</id>
<content type='text'>
ok jmc@
</content>
</entry>
<entry>
<title>Change spamd to use divert-to instead of rdr-to.</title>
<updated>2015-05-18T16:04:21Z</updated>
<author>
<name>reyk</name>
<email>reyk@openbsd.org</email>
</author>
<published>2015-05-18T16:04:21Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=0f849a0c7750c78fae43b22e6fdc50f4867c3474'/>
<id>urn:sha1:0f849a0c7750c78fae43b22e6fdc50f4867c3474</id>
<content type='text'>
divert-to has many advantages over rdr-to for proxies.  For example,
it is much easier to use, requires less code, does not depend on
/dev/pf, works in-band without the asynchronous lookup (DIOCNATLOOK
ioctl), saves us from additional port allocations by the rdr/NAT code,
and even avoids potential collisions and race conditions that could
theoretically happen with the lookup.

Heads up: users will have to update their spamd PF rules from rdr-to
to divert-to.  spamd now also listens to 127.0.0.1 instead of "any"
(0.0.0.0) by default which should be fine with most setups but has to
be considered for some special configurations.

Based on a diff is almost two years old but got delayed several times
... beck@: "now is the time to get it in" :)

Tested by many
With help from okan@
OK okan@ beck@ millert@
</content>
</entry>
<entry>
<title>wrap a long line</title>
<updated>2015-04-14T17:29:06Z</updated>
<author>
<name>deraadt</name>
<email>deraadt@openbsd.org</email>
</author>
<published>2015-04-14T17:29:06Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=f90b2e2aa0aa43edffc8b80488c3137ade0f4749'/>
<id>urn:sha1:f90b2e2aa0aa43edffc8b80488c3137ade0f4749</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Don't use Aq macros when &lt;&gt; is intended; they are not the same thing.</title>
<updated>2015-02-15T22:27:51Z</updated>
<author>
<name>bentley</name>
<email>bentley@openbsd.org</email>
</author>
<published>2015-02-15T22:27:51Z</published>
<link rel='alternate' type='text/html' href='https://git.zx2c4.com/wireguard-openbsd/commit/?id=18891bf9726ee2885a1670934c9d38f6c689007e'/>
<id>urn:sha1:18891bf9726ee2885a1670934c9d38f6c689007e</id>
<content type='text'>
ok schwarze@
</content>
</entry>
</feed>
