allanjude (Allan Jude)Administrator
User

Projects

User Details

User Since
May 19 2014, 3:05 PM (149 w, 3 d)
Roles
Administrator

Recent Activity

Today

allanjude added inline comments to D10210: loader(8) doesn't have "cat", but it has "more"; add a pointer to it..
Fri, Mar 31, 12:10 AM
allanjude committed rS316312: sys/geom/eli: Switch bzero() to explicit_bzero() for sensitive data.
sys/geom/eli: Switch bzero() to explicit_bzero() for sensitive data
Fri, Mar 31, 12:07 AM
allanjude closed D9809: sys/geom/eli: Switch bzero() to explicit_bzero() for sensitive data by committing rS316312: sys/geom/eli: Switch bzero() to explicit_bzero() for sensitive data.
Fri, Mar 31, 12:07 AM
allanjude committed rS316311: Add explicit_bzero() to libstand, and switch GELIBoot to using it.
Add explicit_bzero() to libstand, and switch GELIBoot to using it
Fri, Mar 31, 12:06 AM
allanjude closed D9798: Add explicit_bzero() to libstand by committing rS316311: Add explicit_bzero() to libstand, and switch GELIBoot to using it.
Fri, Mar 31, 12:06 AM

Yesterday

allanjude added inline comments to D10202: Add a new parameter to restrict jails from binding to privileged ports.
Thu, Mar 30, 11:29 PM
allanjude updated the diff for D10202: Add a new parameter to restrict jails from binding to privileged ports.

Fix style nits from smh@

Thu, Mar 30, 11:08 PM
allanjude added inline comments to D10202: Add a new parameter to restrict jails from binding to privileged ports.
Thu, Mar 30, 11:08 PM
allanjude accepted D10206: Remove OLD_NFSV2 from loader and libstand.
Thu, Mar 30, 7:29 PM
allanjude accepted D10206: Remove OLD_NFSV2 from loader and libstand.

Looks like a good cleanup to me

Thu, Mar 30, 6:51 PM
allanjude accepted D10198: loader: simplify efi_zfs_probe and avoid double probing for zfs..

Approved By: allanjude

Thu, Mar 30, 4:02 PM
allanjude added a comment to D10203: loader: zfs reader should check all labels.

even just reading the 2nd label is a big improvement. Thank you.

Thu, Mar 30, 4:00 PM
allanjude added a comment to D10198: loader: simplify efi_zfs_probe and avoid double probing for zfs..

Does this change which pool might be booted from if you have more than 1 pool?

Thu, Mar 30, 3:50 PM
allanjude accepted D10197: loader: efipart should check disk size from partition table.

Approved By: allanjude

Thu, Mar 30, 3:47 PM
allanjude created D10202: Add a new parameter to restrict jails from binding to privileged ports.
Thu, Mar 30, 3:20 PM
allanjude added inline comments to D10170: Capsicumize cpuset_*.
Thu, Mar 30, 12:36 AM
allanjude updated the diff for D10170: Capsicumize cpuset_*.

Update based on feedback

Thu, Mar 30, 12:36 AM

Wed, Mar 29

allanjude added a reviewer for D10188: Use 256 run queues, with 1 priority per queue: mjg.
Wed, Mar 29, 9:16 PM
allanjude added inline comments to D10170: Capsicumize cpuset_*.
Wed, Mar 29, 2:28 AM
allanjude created D10170: Capsicumize cpuset_*.
Wed, Mar 29, 2:23 AM

Tue, Mar 28

allanjude accepted D10058: loader: move bios getsecs into time.c.

approved by: allanjude

Tue, Mar 28, 9:35 PM
allanjude accepted D10066: loader: ls command should display file types properly.

approved by: allanjude

Tue, Mar 28, 9:35 PM

Mon, Mar 20

allanjude accepted D8492: Verify the value from dhcp.interface-mtu and use snprintf to set mtu..

Approved By: allanjude

Mon, Mar 20, 9:54 PM
allanjude added inline comments to D10066: loader: ls command should display file types properly.
Mon, Mar 20, 8:24 PM
allanjude accepted D8491: libstand: verify value provided by nfs.read_size.

Approved by: allanjude

Mon, Mar 20, 6:37 PM
allanjude accepted D10056: loader: pxe.h constants have wrong values.

Good Catch

Mon, Mar 20, 6:10 PM
allanjude accepted D10060: loader: disk_cleanup was left in userboot_disk.c.

Approved By: allanjude

Mon, Mar 20, 5:53 PM

Sat, Mar 18

allanjude added a comment to D10048: Replace the kernel RC4 with Chacha20..

There may also be features worth looking at in this older diff from @delphij https://github.com/freebsd/freebsd/compare/master...delphij:featurefork/chacha20

Sat, Mar 18, 8:32 PM

Fri, Mar 17

allanjude added inline comments to D9030: First attempt at a new fexecve() variant that allows the interpreter to be specified explicitly with a file descriptor..
Fri, Mar 17, 3:38 PM
allanjude updated the diff for D9809: sys/geom/eli: Switch bzero() to explicit_bzero() for sensitive data.

Address feedback from delphij

Fri, Mar 17, 1:33 AM
allanjude added inline comments to D9809: sys/geom/eli: Switch bzero() to explicit_bzero() for sensitive data.
Fri, Mar 17, 1:30 AM
allanjude committed rS315435: Add ZFS compressed ARC stats to top(1).
Add ZFS compressed ARC stats to top(1)
Fri, Mar 17, 12:47 AM
allanjude closed D9829: Add a summary line of the ZFS Compressed ARC to top(1) by committing rS315435: Add ZFS compressed ARC stats to top(1).
Fri, Mar 17, 12:47 AM
allanjude accepted D9547: libstand/dosfs: cache FAT32 in 128 Kb blocks to save loader memory.

Approved By: allanjude

Fri, Mar 17, 12:11 AM

Thu, Mar 16

allanjude accepted D10032: loader: biosdisk should report IO error from INT13.

Approved By: allanjude (mentor)

Thu, Mar 16, 8:02 PM

Wed, Mar 15

allanjude added reviewers for D8492: Verify the value from dhcp.interface-mtu and use snprintf to set mtu.: bapt, brd.
Wed, Mar 15, 8:55 PM
allanjude added reviewers for D8491: libstand: verify value provided by nfs.read_size: bapt, brd, cperciva.
Wed, Mar 15, 8:54 PM
allanjude added a comment to D7600: The experiment to consolidate some crypto functions, shared between zfs/geli..

If you have time, could you refresh this, I'd like to look at it again.

Wed, Mar 15, 8:54 PM
allanjude accepted D9757: loader: remove open_disk cache.

Approved By: allanjude

Wed, Mar 15, 8:40 PM
allanjude accepted D9870: PR216964: boot1.efi: can't boot from ZFS on 4kn HDD.

Approved By: allanjude

Wed, Mar 15, 6:07 PM

Tue, Mar 14

allanjude accepted D9985: Move tests/sys/geom/eli/... to tests/sys/geom/class/eli/....

Thank you for finding the time to do this for me.

Tue, Mar 14, 5:08 AM
allanjude added inline comments to D9563: Introduce libxo to arp(8).
Tue, Mar 14, 4:32 AM

Sun, Mar 12

allanjude awarded Dev Summit Attendee to recipient: editor_callfortesting.org.
Sun, Mar 12, 2:17 PM

Sat, Mar 11

allanjude accepted D9935: Add the capability to refresh the gpart label without need a reboot..
Sat, Mar 11, 8:39 AM

Fri, Mar 3

allanjude added a comment to D2448: give bhyve the ability to parse a libucl guest configuration file.

Thanks for keeping this going Allan.

I'd like this not to be committed as-is. While this isn't really implemented how I'd like, that can always be fixed, However, the format of the config file is going to live for a long time and I think some things in the proposal need to be fixed up somewhat.

Ideally I'd like all features that are and will be available in bhyve to be expressed in this file, even those not available as options. While this seems opposite to the goal of having a file that is simple for users to create, I'm hoping that features of UCL such as includes and macro expansion can be used to create templates to hide a lot of the complexity.

I'll commit to coming up with the additions I'd like to see.

Fri, Mar 3, 4:21 AM

Thu, Mar 2

allanjude updated the diff for D2448: give bhyve the ability to parse a libucl guest configuration file.

Catch up to more changes so the code actually compiles

Thu, Mar 2, 3:54 AM
allanjude updated the diff for D2448: give bhyve the ability to parse a libucl guest configuration file.

Bring my patch forward by 30,000 revisions

Thu, Mar 2, 3:43 AM
allanjude reclaimed D2448: give bhyve the ability to parse a libucl guest configuration file.
Thu, Mar 2, 3:42 AM
allanjude retitled D2448: give bhyve the ability to parse a libucl guest configuration file from Bring the capability to bhyveload and bhyve to parse and use a guest configuration file to load the vm. to give bhyve the ability to parse a libucl guest configuration file.
Thu, Mar 2, 3:41 AM
allanjude commandeered D2448: give bhyve the ability to parse a libucl guest configuration file.

I am reviving this project

Thu, Mar 2, 3:40 AM
allanjude updated D9829: Add a summary line of the ZFS Compressed ARC to top(1).
Thu, Mar 2, 2:46 AM
allanjude updated D9829: Add a summary line of the ZFS Compressed ARC to top(1).
Thu, Mar 2, 2:46 AM
allanjude updated the diff for D9829: Add a summary line of the ZFS Compressed ARC to top(1).

Update the output to fit within 80 columns

Thu, Mar 2, 2:43 AM

Wed, Mar 1

allanjude accepted D9846: loader: r314112 did introduce dereference freed pointer entry.

Approved By: allanjude

Wed, Mar 1, 6:46 PM

Feb 28 2017

allanjude added a comment to D9829: Add a summary line of the ZFS Compressed ARC to top(1).
In D9829#202940, @smh wrote:

Some may find it useful if it was bit shorter, currently its 82 chars in the example.

May be change "Compressed ARC:" to just "ARC:" as the detail gives whats compressed and whats not?

Edit: Or not as I just spotted the line above is already just ARC :(

Feb 28 2017, 8:41 PM
allanjude added a comment to D9829: Add a summary line of the ZFS Compressed ARC to top(1).

I considered putting it behind a flag, but, decided against it.

Feb 28 2017, 1:19 PM
allanjude retitled D9829: Add a summary line of the ZFS Compressed ARC to top(1) from to Add a summary line of the ZFS Compressed ARC to top(1).
Feb 28 2017, 5:33 AM

Feb 26 2017

allanjude retitled D9809: sys/geom/eli: Switch bzero() to explicit_bzero() for sensitive data from to sys/geom/eli: Switch bzero() to explicit_bzero() for sensitive data.
Feb 26 2017, 5:40 PM

Feb 25 2017

allanjude retitled D9798: Add explicit_bzero() to libstand from to Add explicit_bzero() to libstand.
Feb 25 2017, 5:08 AM

Feb 24 2017

allanjude closed D9782: Remove control+r handling from geliboot's pwgets() by committing rS314213: Remove control+r handling from geliboot's pwgets().
Feb 24 2017, 4:53 PM
allanjude committed rS314213: Remove control+r handling from geliboot's pwgets().
Remove control+r handling from geliboot's pwgets()
Feb 24 2017, 4:53 PM
allanjude retitled D9782: Remove control+r handling from geliboot's pwgets() from to Remove control+r handling from geliboot's pwgets().
Feb 24 2017, 5:52 AM

Feb 23 2017

allanjude added a reviewer for D9759: amdtemp driver update: jkim.
Feb 23 2017, 9:55 PM · x86
allanjude added inline comments to D9759: amdtemp driver update.
Feb 23 2017, 9:54 PM · x86

Feb 22 2017

allanjude added reviewers for D9757: loader: remove open_disk cache: avg, smh.
Feb 22 2017, 11:01 PM
allanjude accepted D9723: Properly restrict lam.

This is a better fix.

Feb 22 2017, 4:05 PM
allanjude committed rS314098: lam(1): Failing to restrict stdin/stdout/stderr should not be fatal.
lam(1): Failing to restrict stdin/stdout/stderr should not be fatal
Feb 22 2017, 3:31 PM
allanjude accepted D9706: loader: update symlink support in zfs reader.

Approved By: allanjude

Feb 22 2017, 2:57 PM

Feb 21 2017

allanjude added reviewers for D9706: loader: update symlink support in zfs reader: avg, jpaetzel, smh.
Feb 21 2017, 9:03 PM
allanjude added a comment to D9700: Add new option to bsdinstall hardening menu to disable insecure console.

I am not sure turning this one on by default in the future makes much sense.

Feb 21 2017, 5:00 PM
allanjude accepted D9588: Fix usr.bin/sockstat/sockstat.c style(9).

Approved By: allanjude

Feb 21 2017, 2:48 AM
allanjude added a reviewer for D9685: bnxt: propagate RSS hash type to the network stack.: adrian.
Feb 21 2017, 12:12 AM

Feb 20 2017

allanjude accepted D9603: Add auto resize sysctl..

We'll consider changing the default as a separate issue.

Feb 20 2017, 11:34 PM
allanjude added inline comments to D9603: Add auto resize sysctl..
Feb 20 2017, 11:27 PM
allanjude added a reviewer for D9681: improve ipfw rule creation for blacklist-helper script: allanjude.
Feb 20 2017, 1:19 AM
allanjude added inline comments to D9681: improve ipfw rule creation for blacklist-helper script.
Feb 20 2017, 1:16 AM
allanjude accepted D9680: Increase EFI MSDOSFS image size to 512Kib.

This is more of a project-wide question, hopefully @emaste or something can answer it:

Feb 20 2017, 12:16 AM

Feb 19 2017

allanjude accepted D9678: Allow to setting a fd for netrc in advance to allow dropping privileges.

lgtm

Feb 19 2017, 9:56 PM
allanjude added inline comments to D9575: Boot-time Key Intake Metadata.
Feb 19 2017, 9:40 PM
allanjude added a comment to D9575: Boot-time Key Intake Metadata.
In D9575#199104, @cem wrote:

The parse_cmd change appears entirely unrelated? We prefer to keep individual changes to their own smaller individual commits.

One of the added includes defines a function named "parse". Thus, it was necessary to rename this function.

Feb 19 2017, 9:37 PM
allanjude accepted D9303: Capsicumize traceroute.

tested fine here

Feb 19 2017, 8:33 PM
allanjude added a comment to D9603: Add auto resize sysctl..

I too find this feature annoying, so would like to have a sysctl to disable it.

Feb 19 2017, 7:52 PM
allanjude committed rS313962: improve PBKDF2 performance.
improve PBKDF2 performance
Feb 19 2017, 7:30 PM
allanjude closed D8236: improve PBKDF2 performance by committing rS313962: improve PBKDF2 performance.
Feb 19 2017, 7:30 PM
allanjude added inline comments to D9575: Boot-time Key Intake Metadata.
Feb 19 2017, 4:59 PM
allanjude abandoned D9324: tcpdump: Add BGP LARGE_COMMUNITY support.

Overcome by events, tcpdump was updated by secteam due to vulnerabilities, and this support came in as part of the import of the newer version.

Feb 19 2017, 6:08 AM
allanjude committed rS313938: Capsicum-ize lam(1).
Capsicum-ize lam(1)
Feb 19 2017, 6:03 AM
allanjude closed D8076: Capsicum-ize lam(1) by committing rS313938: Capsicum-ize lam(1).
Feb 19 2017, 6:03 AM
allanjude updated the diff for D8236: improve PBKDF2 performance.

Switch the bzero's in pkcs5v2_genkey to explicit_bzero because they are wiping sensitive data

Feb 19 2017, 5:54 AM

Feb 16 2017

allanjude accepted D7461: Add shortcuts to hardening menu.

Approved By: allanjude

Feb 16 2017, 7:54 PM
allanjude added reviewers for D9640: cpufreq for rpi3: brd, gonzo.
Feb 16 2017, 7:44 PM

Feb 14 2017

allanjude accepted D9152: Fix usage().

Approved By: allanjude

Feb 14 2017, 9:06 PM
allanjude added a comment to D9152: Fix usage().

The synopsis lists -C, but it is not described in the man page anywhere.

Feb 14 2017, 8:48 PM
allanjude accepted D9510: usr.sbin/ndp/ndp.c: Fix style(9).

Approved By: allanjude

Feb 14 2017, 6:01 PM
allanjude added a comment to D9575: Boot-time Key Intake Metadata.

An observation: as presently implemented, this would bypass the password check for any GELI volume that was detached and later attached again. This is probably not desirable, as it could break security models.

One way to deal with this is to disable the keys after they are used to decrypt a volume. However, it warrants discussion.

I think we should explicit_bzero the keys/password as soon as we are done with them. GELI should already be doing this everything before the patch.

One slight caveat if that is adopted: there needs to be a single entry in the key buffer for each GELI volume, even if two volumes happen to have the same keys. If you deduplicate the keys and then zero out a key after it's used, you'll end up missing the key for some of the volumes.

So if that solution's adopted, the loader-side needs to make sure not to deduplicate keys.

There also may be a potential scenario where a key ends up in the intake buffer for a volume that for some reason doesn't get attached right away. I can't think offhand how this would happen in normal operation (maybe someone has a USB stick that they pull after the boot loader?)

Feb 14 2017, 5:16 PM
allanjude added a comment to D9575: Boot-time Key Intake Metadata.

An observation: as presently implemented, this would bypass the password check for any GELI volume that was detached and later attached again. This is probably not desirable, as it could break security models.

One way to deal with this is to disable the keys after they are used to decrypt a volume. However, it warrants discussion.

Feb 14 2017, 4:37 PM
allanjude added reviewers for D9575: Boot-time Key Intake Metadata: pjd, oshogbo, cem, tsoome.
Feb 14 2017, 12:59 AM
allanjude added inline comments to D9575: Boot-time Key Intake Metadata.
Feb 14 2017, 12:57 AM

Feb 13 2017

allanjude added inline comments to D7538: Correct adaptation ZFS ARC memory pressure to FreeBSD.
Feb 13 2017, 7:42 PM · ZFS
allanjude added reviewers for D7538: Correct adaptation ZFS ARC memory pressure to FreeBSD: mav, mahrens, pjd, avg, jpaetzel.
Feb 13 2017, 7:41 PM · ZFS