summaryrefslogtreecommitdiffstats
path: root/sys/lib/libsa
AgeCommit message (Collapse)AuthorFilesLines
2021-03-12spellingjsg3-6/+6
2020-12-09Use daddr_t and not daddr32_t in boot media.krw1-2/+2
At a minimum, amd64/i386 should now boot from 4TB GPT formatted disks. More daddr32_t terminations with extreme prejudice to follow. Tested by various, in snaps for a few days. ok deraadt@
2020-10-26Remove an unneeded variable.visa1-3/+3
OK kettenis@
2020-07-09Fix a warning false positive from clang 10.millert1-2/+2
blf_enc() takes a number of 64-bit blocks to encrypt, but using sizeof(uint64_t) in the calculation triggers a warning from clang 10 because the actual data type is uint32_t. Pass BCRYPT_WORDS / 2 for the number of blocks like libc bcrypt(3) does. OK kettenis@
2020-05-19If we pass a packet length larger than 2^16, we should panic() insteadpatrick1-5/+3
of returning -1. With a return type of u_int16_t, -1 is not different to a valid checksum. For incoming packets, the header lengths don't exceed that size anyway, but for outgoing packets it's better to see if our bootloader crafts a broken one. Discussed with gerhard@ ok deraadt@ procter@
2020-05-18Sync in_cksum.c to the same version ospfd has. This fixes problemspatrick2-30/+29
with odd packet lengths, which can happen when using TFTP to load a file with an odd length. ospfd actually took dvmrpd's version in 2006 to fix the same issue, and both daemons implementations are the same. For the bootloader we keep the consts from the previous version and replace the fatal with a print and return. ok deraadt@
2020-02-29Next step in prepping for ffs2 installs: introduce a new install script varotto1-0/+1
MDFSOPT and add a missing prototype.
2019-11-29Add an element to the marks array to store the virtual address of thekettenis2-3/+5
entry point. ok mlarkin@, deraadt@
2019-11-28Implement a hexdump command in the boot loader. This helps tobluhm2-1/+54
inspect the memory layout that the firmware has created. It is especially useful for UEFI debugging. OK deraadt@ kettenis@
2019-11-01Reduce BOOTRANDOM_MAX to 256. naddy pointed out there's no point havingderaadt1-2/+2
it larger than RC4STATE. A long discussion ensued. In conclusion all entropy inputs are either satisfactory enough, or just as shitty at 512.
2019-10-29Use arc4 to bit-spread the 512-byte random buffer over the .openbsd.randomdataderaadt1-9/+8
section, which has grown a fair bit with the introduction of retguard. Mortimer discovered the repeated 512-byte sequence as retguard keys, and this resolves the issue. (Chacha does not fit on the media, so 1.5K early drop RC4 is hopefully sufficient in our KARL link universe) Version crank the bootblocks. sysupgrade -s will install new bootblocks. ok djm mortimer
2019-10-29add arc4 cipher to the bootblocksderaadt2-0/+118
ok djm mortimer
2019-08-03In the bootblocks, after discovering and opening /bsd.upgrade, fchmod -xderaadt6-6/+176
so the file cannot be re-executed upon the next boot. This provides a stronger one-shot-upgrade model than the upgrade script's rm /bsd.upgrade. Now various forms of upgrade failure will reboot into /bsd, which is probably more recoverable. Performing fchmod -x depends on (1) use of MI boot.c (not alpha/macppc/sparc64/sgi/octeon) and (2) "can write blocks" functionality in the IO layer. Most architectures have this support now. Two diagnostics "fchmod a-x %s: failed" and "/bsd.upgrade is not u+x" will remain in the tree while refinements happen for some of the laggard architectures. based upon a discussion florian tested in snapshots for more than a week without any complaints
2019-05-11we have never built without %b supportderaadt2-7/+2
2019-04-20libsa's memcpy() is actually memmove(). make a proper memmove(), and givederaadt4-13/+63
memcpy() correct behaviour. This also brings the bcopy() macro into line.
2019-04-10change marks[] array to uint64_t, so the code can track full 64-bitderaadt3-9/+9
details from the ELF header instead of faking it. Proposal from mlarkin, tested on most architectures already
2018-12-16Make the freelist best fit code a tiny bit smarter to not use a block ifotto1-2/+2
half or more would be wasted. Causes more effective re-use of blocks. ok jsing@
2018-08-10Retry on incorrect passphrase for softraid crypto boot.jsing2-72/+122
Historically, the softraid crypto support in the boot loaders has only given one attempt to provide the correct passphrase. There were a few reasons for this, including the fact that pkcs5_pbkdf2() allows an empty passphrase and that returning EPERM allowed for another attempt. With the event of KARL and the need for bsd.booted with hibernate resumption, this becomes much more of an issue - if you get the passphrase wrong you fail to resume. There are also other situations like using /etc/boot.conf to switch serial console, but an incorrect passphrase results in the config not being read. Also, bcrypt_pbkdf() does not permit empty passphrases. This reworks the softraid crypto support in the boot loaders so that it loops requesting a valid passphrase until one is provided, or an empty passphrase is entered (at which point it will abort). ok mortimer@ tb@
2018-05-23Align libsa ctime output with libc ctime output.cheloha1-3/+2
Use zero-padding to get double-digit HH:MM:SS and space-padding for the DOM. ok visa@
2018-03-31Stop converting UDP and IP header values from network endianness to hostpatrick1-10/+7
endianness for convenience reasons. Especially in code pathes like TFTP where the source port is read from the received UDP packet and used as destination port in a new UDP packet this can be very harmful. Luckily this issue has had no effect on our architectures since they never use any of the code paths that could be harmful. ok visa@
2018-01-17Implement basic padding support in libsa so we can do zero-paddingpatrick1-18/+55
in bootloader printfs. Feedback from and ok gerhard@
2017-11-10"unknown KDF type 2" -> "keydisk not found".sunil1-1/+4
Inputs and ok jsing@.
2017-10-08Revert: libsa lacks memmove currently; a more thorough rename/change isguenther1-2/+2
needed problem noted by naddy@
2017-10-07bcopy() is expected to be overlap safe, so it implement it with memmove()guenther1-2/+2
not memcpy(). 'oh oh' deraadt@
2017-09-08If you use sys/param.h, you don't need sys/types.hderaadt1-2/+1
2017-05-31make the AES-XTS mode a little more constant-time, though the AESdjm1-5/+4
implementation that it depends on currently isn't. ok mikeb tom
2017-05-27move sha224_initial_hash_value[] under !SHA2_SMALL; ok deraadt@ millert@naddy1-13/+13
2017-05-08Guard debug printf with NFS_DEBUG ifdef like the other debug prints.patrick1-1/+3
ok tom@
2016-11-27Add missing OpenBSD CVS tagsreyk2-0/+4
2016-11-25Fix signedness warnings with careful casts and replace a re-defined variable.reyk2-17/+17
OK krw@
2016-09-18Add bcrypt pbkdf support to the softraid crypto boot loader code.jsing1-5/+28
Based on a diff from djm@
2016-09-18Correctly handle short read()s in the libsa gzip handling lseek(). Alsojsing1-5/+8
avoid masking the errno from a failed read(). ok guenther@ tom@
2016-09-17move the .SUNW_ctf section name definition to exec_elf.h and document it in elf(5)jasper1-2/+2
feedback from guenther@ ok guenther@ kettenis@
2016-09-16unifdef SAVE_MEMORY which is no longer set nor usedjasper1-9/+1
ok deraadt@ millert@
2016-09-13when loading the kernel binary, also load the .SUNW_ctf section when present,jasper1-2/+3
which holds the CTF data. ok mpi@
2016-09-11Provide initial libsa softraid - this is currently just the data structuresjsing2-0/+260
and softraid crypto key handling code.
2016-09-10Add bcrypt_pbkdf to libsa, from libutil. This will soon allow the bootjsing2-0/+189
loader to support softraid crypto volumes using bcrypt pbkdf.
2016-09-10Add blowfish to libsa, taken from libc - needed for bcrypt_pbkdf.jsing2-0/+767
2016-09-10Add sha2 to libsa, taken from libc - needed for bcrypt_pbkdf.jsing2-0/+1107
2016-09-10Rename libsa pbkdf2.c to pkcs5_pbkdf2.c so that we match libutil.jsing2-15/+13
2016-09-10Sync libsa pkcs5_pbkdf2() with libutil.jsing2-12/+14
2016-08-27Declare lseek() instead of assuming it'll be provided elsewhereguenther1-1/+2
ok deraadt@
2016-03-14Change a bunch of (<blah> *)0 to NULL.krw4-15/+15
ok beck@ deraadt@
2015-11-16Replace unbounded gets() in libsa with getln() which takes a buffer size,miod4-16/+22
and convert all gets() users. ok deraadt@
2015-10-26(char *)0 -> NULLmmcc1-2/+2
ok tedu@
2015-10-26Cast isdigit()'s argument to unsigned char.mmcc1-2/+2
ok guenther@
2015-09-18Remove orphaned files.miod3-239/+1
2015-09-14unify free(NULL,size) behaviour by allowing passing NULLsemarie1-3/+7
ok millert@ jasper@
2015-09-02Initial commit of uefi boot loader of OpenBSD.yasuoka2-4/+4
ok deraadt yuo
2015-08-15When sendrecv() returns -1, have rpc_call() return -1 as well. Otherwise, duemiod1-2/+2
to the cast to unsigned, it fails the error test and returns a bogus partial read to the caller, which is painful to debug.