summaryrefslogtreecommitdiffstats
path: root/lib/libfido2/src
AgeCommit message (Collapse)AuthorFilesLines
2021-02-15Back-out USB data toggle fix for HID devices, since we received multiplemglocker1-0/+66
reports about broken devices, e.g. for ukbd(4) and fido(4). ok mpi@
2021-02-05Remove the terrible_ping_kludge() workaround. We have committed a fix tomglocker1-66/+0
the USB stack in the meantime for uhidev(4) and ugen(4) to resolve the data toggle issue in relation to xhci(4). ok gnezdo@, djm@
2020-09-07sync a couple of minor fixes (no API/ABI change) to bring libfido2djm2-2/+2
in line with upstream 1.5.0
2020-08-23check errno against EINTR; not return value from poll()djm1-1/+1
spotted by Pedro Martelletto
2020-08-23update to libfido2 46710ac06, picking up a few API changesdjm5-32/+29
ok tb@ deraadt@ NB. major crank
2020-08-11sync with upstream libfido2 rev 2fa20b889, picking up ~7 monthsdjm28-183/+748
of fixes and a few new APIs that we'd like to use in OpenSSH ok deraadt@
2020-02-07It appears we have come full-circle, where source code starts to usederaadt1-4/+2
clang / "super new gcc" ism's, in particular ones which are totally pointless as far as language goes. Delete them.
2020-02-07update to upstream libfido2 780ad3c25 (20120123)djm35-1020/+1712
install manual pages crank major feedback & ok jmc@ and naddy@
2019-12-17Add fido(4), a HID driver for FIDO/U2F security keysreyk1-74/+10
While FIDO/U2F keys were already supported by the generic uhid(4) driver, this driver adds the first step to tighten the security of FIDO/U2F access. Specifically, users don't need read/write access to all USB/HID devices anymore and the driver also improves integration with pledge(2) and unveil(2): It is pledge-friendly because it doesn't require any ioctls to discover the device and unveil-friendly because it uses a single /dev/fido/* directory for its device nodes. It also allows to support FIDO/U2F in firefox without further weakening the "sandbox" of the browser. Firefox does not have a proper privsep design and many operations, such as U2F access, are handled directly by the main process. This means that the browser's "fat" main process needs direct read/write access to all USB HID devices, at least on other operating systems. With fido(4) we can support security keys in Firefox under OpenBSD without such a compromise. With this change, libfido2 stops using the ioctl to query the device vendor/product and just assumes "OpenBSD" "fido(4)" instead. The ioctl is still supported but there was no benefit in obtaining the vendor product or name; it also allows to use libfido2 under pledge. With feedback from deraadt@ and many others OK kettenis@ djm@ and jmc@ for the manpage bits
2019-11-14import libfido2 (git HEAD). This library allows communication withdjm38-0/+10429
U2F/FIDO2 devices over USB. feedback and "start the churn" deraadt@