Page MenuHomeFreeBSD

netchild (Alexander Leidinger)
User

Projects

User Details

User Since
Jul 25 2015, 10:06 AM (508 w, 4 d)

Recent Activity

Yesterday

netchild added a comment to D49976: svcj: correctly handle kernels without INET or INET6.
In D49976#1139747, @des wrote:

Wouldn't it be better to check at point of use rather than at point of initialization?

Wed, Apr 23, 11:43 AM
netchild requested changes to D49976: svcj: correctly handle kernels without INET or INET6.
Wed, Apr 23, 10:31 AM

Mon, Apr 21

netchild added a comment to D49843: jail: add allow.routing jail permission.
In D49843#1138774, @zec wrote:
In D49843#1138771, @zec wrote:

...

No, the host is gone as well, since the attacker has control over network connectivity.

You go to the keyboard of the host, delete the jail, and the attacker is gone.

Sounds pretty much as a very deep redefinition of the jail contract to me.

Mon, Apr 21, 8:30 PM
netchild added a comment to D49843: jail: add allow.routing jail permission.
In D49843#1138771, @zec wrote:
In D49843#1138763, @ivy wrote:
In D49843#1138751, @zec wrote:

Consider an exploit in BIRD which would allow routing tables to be manipulated

consider an exploit in BIRD which would allow an attacker to run code as root.

running BIRD in a jail -> only the jail is compromised.

No, the host is gone as well, since the attacker has control over network connectivity.

Mon, Apr 21, 3:59 PM
netchild added a comment to D49843: jail: add allow.routing jail permission.
In D49843#1138751, @zec wrote:

Repeating that someone might have his mind set on running BIRD in a swiss-cheese-jail is far from providing arguments on what real security benefit would this provide compared to running it in a plain system (or in a chrooted tree).

Consider an exploit in BIRD which would allow routing tables to be manipulated so that only the attacker would retain connectivity to the compromised host, while to the others the whole system would appear to be dead. What exactly does running BIRD in a service jail bring us, compared to running it in the base system?

Mon, Apr 21, 2:22 PM

Thu, Apr 17

netchild added a comment to D49843: jail: add allow.routing jail permission.
In D49843#1137302, @lexi_le-fay.org wrote:

i have been mulling over how we can add more restrictions to svcj. i don't think "just use nullfs" is the answer here because that makes everything more complicated, but i don't yet have another proposal. i don't think this is impossible to fix in principle though.

Thu, Apr 17, 8:06 PM
netchild added a comment to D49843: jail: add allow.routing jail permission.

The svcj documentation in rc.conf.5 doesn't say anything about why one might want to run a service in a service jail, and what benefits that confers. I think that's a bug, especially given that the feature uses the term "jail" and not "container", and the former has specific connotations relating to security, at least in FreeBSD. And frankly I'm not sure what added security is obtained from having a privileged daemon run in a jail with path=/.

Thu, Apr 17, 7:07 PM

Tue, Apr 15

netchild added a comment to D49845: rc.subr: add 'settime' to svcj options.

The kernel side (PRIV) of this patch is missing (compared to to the github pull request).
The svcj part is OK.

Tue, Apr 15, 7:02 PM

Mon, Apr 14

netchild committed rG6fbd1bed6e7b: rc.subr: add ${svc}_svcj_ipaddrs option (authored by ivy).
rc.subr: add ${svc}_svcj_ipaddrs option
Mon, Apr 14, 1:25 PM

Wed, Apr 2

netchild committed R11:d4664d6d7631: misc/openhab: Update to 4.3.4. (authored by netchild).
misc/openhab: Update to 4.3.4.
Wed, Apr 2, 10:52 AM

Mar 12 2025

netchild committed R11:c5a94e997e8d: www/piwigo: Update to 15.5.0. (authored by netchild).
www/piwigo: Update to 15.5.0.
Mar 12 2025, 3:03 PM

Feb 22 2025

netchild committed R11:da1daad73d9f: misc/openhab: Update to 4.3.3. (authored by netchild).
misc/openhab: Update to 4.3.3.
Feb 22 2025, 2:13 PM
netchild committed R11:e66b9ac1325d: www/piwigo: Update to 15.4.0. (authored by netchild).
www/piwigo: Update to 15.4.0.
Feb 22 2025, 2:13 PM
netchild added a comment to D49100: inpcb: Fix reuseport lbgroup array resizing.

In my case I got
panic: invalid local group size 16 and count 16

Feb 22 2025, 11:02 AM

Feb 14 2025

netchild committed R11:353e24e2753c: biology/linux-foldingathome: Update to 8.4.9. (authored by netchild).
biology/linux-foldingathome: Update to 8.4.9.
Feb 14 2025, 8:25 AM

Jan 31 2025

netchild closed D48724: Limit the use of stack clash protection and zeroregs based upon compiler features.
Jan 31 2025, 12:17 PM
netchild committed rG1c2ae9233b0e: Limit some cc options based upon features (authored by netchild).
Limit some cc options based upon features
Jan 31 2025, 12:17 PM

Jan 30 2025

netchild requested review of D48724: Limit the use of stack clash protection and zeroregs based upon compiler features.
Jan 30 2025, 9:26 AM

Jan 29 2025

netchild committed rGe91117fa8ed2: Improve the stack clash protection description. (authored by netchild).
Improve the stack clash protection description.
Jan 29 2025, 1:40 PM

Jan 27 2025

netchild committed rG582c8de016f8: Fix the date for the ROCKCHIP option. (authored by netchild).
Fix the date for the ROCKCHIP option.
Jan 27 2025, 7:59 PM

Jan 25 2025

netchild added a comment to D48651: Add stack clash protection to the WITH_SSP flag.

Man page changed as suggested.

Jan 25 2025, 1:13 PM
netchild committed rGf934e629dc22: Add stack clash protection to the WITH_SSP flag (authored by netchild).
Add stack clash protection to the WITH_SSP flag
Jan 25 2025, 1:09 PM
netchild closed D48651: Add stack clash protection to the WITH_SSP flag.
Jan 25 2025, 1:09 PM

Jan 24 2025

netchild abandoned D48427: Add option to clear caller-used registers on function return.

Committed

Jan 24 2025, 10:01 AM
netchild updated the diff for D48426: increase security/safety FORTIFY.

Separate review for SSP, add man page info for FORTIFY.

Jan 24 2025, 9:55 AM
netchild requested review of D48651: Add stack clash protection to the WITH_SSP flag.
Jan 24 2025, 9:24 AM
netchild added a comment to D48426: increase security/safety FORTIFY.

I'll split the two parts up and try to come up with something for the docs.

Jan 24 2025, 7:57 AM

Jan 22 2025

netchild committed rG2a44cccd404d: Add option to clear caller-used registers on function return. (authored by netchild).
Add option to clear caller-used registers on function return.
Jan 22 2025, 6:39 PM

Jan 17 2025

netchild committed R11:ee2cd2e45eae: misc/openhab: update to 4.3.2 (authored by netchild).
misc/openhab: update to 4.3.2
Jan 17 2025, 11:52 AM

Jan 11 2025

netchild added inline comments to D48427: Add option to clear caller-used registers on function return.
Jan 11 2025, 7:25 PM
netchild requested review of D48427: Add option to clear caller-used registers on function return.
Jan 11 2025, 2:17 PM
netchild requested review of D48426: increase security/safety FORTIFY.
Jan 11 2025, 2:15 PM

Jan 3 2025

netchild committed R11:b105f4e8fe90: misc/openhab: update to 4.3.1. (authored by netchild).
misc/openhab: update to 4.3.1.
Jan 3 2025, 4:02 PM

Dec 27 2024

netchild added a comment to D47932: sound: Refactor the format conversion framework.

Thanks for your input. I agree that we should keep an eye on performance, but I'd like to clarify: In our current refactoring of the format conversion we're not touching anything that changes the buffer sizes. And that's the only thing that could possibly affect audio latency. If latency really is of concern, then we'd have to look at smaller buffer sizes and how to make timers and scheduling more reliable. Also I doubt that we ever had the lowest overall latency, if you count in ASIO on Windows. I suspect that was about the latency introduced by the resampler.

Dec 27 2024, 5:42 PM
netchild added a comment to D47932: sound: Refactor the format conversion framework.

FYI: at some point we had the sound system with the lowest latency. Ariff was comparing MS, OS X and Linux. I do not know if they have catched-up since then, but it may be worth the effort to check the performance / latency for such changes. Unfortunately I haven't found the info about the latency stuff he did, only his resampling quality comparison with other resampler implementations (https://people.freebsd.org/~ariff/z_comparison/). In https://people.freebsd.org/~ariff/old/ he has some old low latency diffs, so some interested soul could check which parts he modified to get lower latency.

Dec 27 2024, 12:22 PM

Dec 20 2024

netchild committed R11:9b24ea32dbf5: devel/sonarqube-community: Update plugins. (authored by netchild).
devel/sonarqube-community: Update plugins.
Dec 20 2024, 10:58 AM
netchild committed R11:b33518558f08: www/piwigo: Update to 15.3.0. (authored by netchild).
www/piwigo: Update to 15.3.0.
Dec 20 2024, 10:58 AM
netchild committed R11:17c406bb8e2a: misc/openhab: Update to 4.3.0. (authored by netchild).
misc/openhab: Update to 4.3.0.
Dec 20 2024, 10:58 AM

Dec 11 2024

netchild committed R11:34275b043466: devel/sonarqube-community: Update plugins. (authored by netchild).
devel/sonarqube-community: Update plugins.
Dec 11 2024, 9:49 AM
netchild committed R11:ec4007708a00: www/nginx-ultimate-bad-bot-blocker: Update to a recent version. (authored by netchild).
www/nginx-ultimate-bad-bot-blocker: Update to a recent version.
Dec 11 2024, 9:49 AM

Dec 4 2024

netchild committed R11:8d2da9c9f473: devel/sonarqube-community: Update to 24.12.0.100206. (authored by netchild).
devel/sonarqube-community: Update to 24.12.0.100206.
Dec 4 2024, 12:55 PM

Nov 28 2024

netchild committed R11:2561368e80e5: devel/sonarqube-community: Update plugins (authored by netchild).
devel/sonarqube-community: Update plugins
Nov 28 2024, 12:19 PM
netchild committed R11:cebb6bf7ae58: misc/openhab: Update to 4.2.3. (authored by netchild).
misc/openhab: Update to 4.2.3.
Nov 28 2024, 12:19 PM

Nov 22 2024

netchild committed R11:aff61c1df832: devel/sonar-scanner-cli: Disable kubernetes scanning. (authored by netchild).
devel/sonar-scanner-cli: Disable kubernetes scanning.
Nov 22 2024, 2:45 PM

Nov 20 2024

netchild committed R11:ddde60e9d441: devel/sonarqube-community: Update plugins. (authored by netchild).
devel/sonarqube-community: Update plugins.
Nov 20 2024, 12:58 PM
netchild committed R11:a9237f43dd8c: devel/sonar-scanner-cli: Fix scanning on FreeBSD (authored by netchild).
devel/sonar-scanner-cli: Fix scanning on FreeBSD
Nov 20 2024, 12:57 PM

Nov 13 2024

netchild committed R11:8daef9684c6b: devel/sonarqube-community: Update plugins. (authored by netchild).
devel/sonarqube-community: Update plugins.
Nov 13 2024, 2:33 PM
netchild committed R11:bed46e48db89: www/piwigo: Update to 15.1.0. (authored by netchild).
www/piwigo: Update to 15.1.0.
Nov 13 2024, 2:33 PM

Oct 30 2024

netchild accepted D47329: rc: Use check_jail to check values of security.jail MIBs.

Looks good (not run tested).

Oct 30 2024, 10:10 AM · rc

Oct 27 2024

netchild committed R11:9329f4aedfd9: www/piwigo: Update to 15.0.0. (authored by netchild).
www/piwigo: Update to 15.0.0.
Oct 27 2024, 6:12 PM

Oct 21 2024

netchild added a comment to D47203: loader: Change this BIOS tradeoff: Add back zip and use text only.

FYI, I added this to src.conf:

grep LOADER /etc/src.conf

LOADER_GZIP_SUPPORT=no
LOADER_BZIP2_SUPPORT=no
LOADER_BIOS_TEXTONLY=no
LOADER_NFS_SUPPORT=no
LOADER_TFTP_SUPPORT=no
LOADER_CD9660_SUPPORT=no

Oct 21 2024, 5:00 PM

Oct 20 2024

netchild added a comment to D47203: loader: Change this BIOS tradeoff: Add back zip and use text only.

While I agree with the rationale and the change:

Oct 20 2024, 9:28 AM

Oct 2 2024

netchild committed R11:abcda100615b: devel/sonar-scanner-cli: Update to 6.2.1. (authored by netchild).
devel/sonar-scanner-cli: Update to 6.2.1.
Oct 2 2024, 8:39 AM

Oct 1 2024

netchild committed R11:f3ccfb0ce91e: misc/openhab: update to 4.2.2. (authored by netchild).
misc/openhab: update to 4.2.2.
Oct 1 2024, 10:56 AM

Sep 28 2024

netchild committed R11:19ca7ec56ef8: devel/sonarqube-community: Update to 10.7. (authored by netchild).
devel/sonarqube-community: Update to 10.7.
Sep 28 2024, 2:07 PM

Sep 25 2024

netchild committed R11:3053245be0f7: devel/sonarqube-community: Update plugins. (authored by netchild).
devel/sonarqube-community: Update plugins.
Sep 25 2024, 9:11 AM

Sep 23 2024

netchild committed R11:c3747a51d7d4: www/lua-resty-session3: fix PKGBASE/PKGNAME (authored by netchild).
www/lua-resty-session3: fix PKGBASE/PKGNAME
Sep 23 2024, 9:38 AM

Sep 18 2024

netchild committed R11:858c9f19409a: security/crowdsec: update to 1.6.3 (authored by marco <marco@crowdsec.net>).
security/crowdsec: update to 1.6.3
Sep 18 2024, 4:58 PM
netchild committed R11:dfd76d00018c: www/lua-resty-session3: port sticking to version 3 (authored by Baptiste Grenier <baptiste@bapt.name>).
www/lua-resty-session3: port sticking to version 3
Sep 18 2024, 4:03 PM
netchild committed R11:11c3e44bb172: security/lua-resty-openidc: switch to lua-resty-session3 (authored by netchild).
security/lua-resty-openidc: switch to lua-resty-session3
Sep 18 2024, 4:03 PM
netchild committed R11:054362e3cf4e: devel/sonar-scanner-cli: Update to 6.2.0. (authored by netchild).
devel/sonar-scanner-cli: Update to 6.2.0.
Sep 18 2024, 8:50 AM
netchild committed R11:aaf6d80976ae: devel/sonarqube-community: Update plugins. (authored by netchild).
devel/sonarqube-community: Update plugins.
Sep 18 2024, 8:50 AM

Sep 17 2024

netchild added a comment to D40972: libbe: recursively promote deep BE datasets.

I just bumped into this and I wonder what's the rationale to perform promotion during bectl activate.
I want to keep the BE snapshot I'm creating a new BE from, but activating new BE removes the snapshot (well, transfers it to the new BE's dataset).

Sep 17 2024, 1:27 PM

Aug 24 2024

netchild committed R11:c9f63c5c714c: dns/acme-dns: make service jails aware (authored by netchild).
dns/acme-dns: make service jails aware
Aug 24 2024, 12:55 PM
netchild committed R11:983fb349a918: devel/sonarqube-community: Update to 10.6.0. (authored by netchild).
devel/sonarqube-community: Update to 10.6.0.
Aug 24 2024, 12:54 PM

Aug 21 2024

netchild committed R11:067f47a48d5f: devel/sonarqube-community: Update plugins. (authored by netchild).
devel/sonarqube-community: Update plugins.
Aug 21 2024, 5:18 PM

Aug 17 2024

netchild committed R11:c81b36005c04: security/vuxml: Add an antry for dovecot. (authored by netchild).
security/vuxml: Add an antry for dovecot.
Aug 17 2024, 7:49 AM

Aug 13 2024

netchild committed R11:9b291bf2c4e1: devel/sonarqube-community: Update plugins. (authored by netchild).
devel/sonarqube-community: Update plugins.
Aug 13 2024, 10:03 AM
netchild committed R11:94def2b58042: misc/openhab: update to 4.2.1 (authored by netchild).
misc/openhab: update to 4.2.1
Aug 13 2024, 10:03 AM

Jul 17 2024

netchild committed R11:11f8d796db82: misc/openhab: Update to 4.2.0. (authored by netchild).
misc/openhab: Update to 4.2.0.
Jul 17 2024, 10:23 AM

Jul 16 2024

netchild committed R11:a92c0c36bf39: www/piwigo: Update to 14.5.0. (authored by netchild).
www/piwigo: Update to 14.5.0.
Jul 16 2024, 10:13 AM
netchild closed D45897: Emphasize the file naming convention and why, add a section about "instancing".
Jul 16 2024, 10:11 AM
netchild committed R9:e9bc86f962c2: rc scripting article: file naming convention and "instancing" (authored by netchild).
rc scripting article: file naming convention and "instancing"
Jul 16 2024, 10:11 AM

Jul 15 2024

netchild committed R11:9f7909680e5d: devel/sonarqube-community: Update plugins. (authored by netchild).
devel/sonarqube-community: Update plugins.
Jul 15 2024, 2:17 PM
netchild committed R11:4fd42b96e56c: devel/sonar-scanner-cli: Update to 6.1.0. (authored by netchild).
devel/sonar-scanner-cli: Update to 6.1.0.
Jul 15 2024, 2:17 PM

Jul 10 2024

netchild committed R11:cec4e0f97b48: dns/encrypted-dns-server: make the rc script service jails aware (authored by netchild).
dns/encrypted-dns-server: make the rc script service jails aware
Jul 10 2024, 1:49 PM
netchild committed R11:c751a4589501: ftp/smbftpd: make the rc script service jails aware (authored by netchild).
ftp/smbftpd: make the rc script service jails aware
Jul 10 2024, 1:40 PM
netchild committed R11:73648ddbeca9: ftp/vsftpd-ext: make the rc script service jails aware (authored by netchild).
ftp/vsftpd-ext: make the rc script service jails aware
Jul 10 2024, 1:40 PM
netchild committed R11:69c8b49c8087: ftp/fastdfs: make the rc scripts service jails aware (authored by netchild).
ftp/fastdfs: make the rc scripts service jails aware
Jul 10 2024, 1:40 PM
netchild committed R11:86318c06c0ed: dns/opendnssec2: make the rc script service jails aware (authored by netchild).
dns/opendnssec2: make the rc script service jails aware
Jul 10 2024, 1:40 PM
netchild committed R11:de0101d77391: dns/radns: make the rc script service jails aware (authored by netchild).
dns/radns: make the rc script service jails aware
Jul 10 2024, 1:40 PM
netchild committed R11:19e09d9174ac: dns/noip: make the rc script service jails aware (authored by netchild).
dns/noip: make the rc script service jails aware
Jul 10 2024, 1:40 PM
netchild committed R11:ced215b217ab: dns/dnsreflector: make the rc script service jails aware (authored by netchild).
dns/dnsreflector: make the rc script service jails aware
Jul 10 2024, 1:40 PM
netchild committed R11:a1d70f266cbd: dns/adsuck: make the rc script service jails aware (authored by netchild).
dns/adsuck: make the rc script service jails aware
Jul 10 2024, 1:40 PM
netchild committed R11:abb53891c6b3: www/oauth2-proxy: make the start script service jails ready (authored by netchild).
www/oauth2-proxy: make the start script service jails ready
Jul 10 2024, 1:40 PM

Jul 7 2024

netchild updated subscribers of D45897: Emphasize the file naming convention and why, add a section about "instancing".
Jul 7 2024, 2:50 PM

Jul 6 2024

netchild updated the diff for D45897: Emphasize the file naming convention and why, add a section about "instancing".
Jul 6 2024, 11:06 AM
netchild requested review of D45897: Emphasize the file naming convention and why, add a section about "instancing".
Jul 6 2024, 10:02 AM

Jun 26 2024

netchild committed R11:ae22632fb14b: devel/sonarqube-community: update plugins (authored by netchild).
devel/sonarqube-community: update plugins
Jun 26 2024, 11:36 AM
netchild committed R11:8bd6f5e0782d: net/keycloak: update to 25.0.1 (authored by netchild).
net/keycloak: update to 25.0.1
Jun 26 2024, 11:36 AM

Jun 23 2024

netchild committed R11:d81ae4eeae51: dns/knot-resolver: make the rc scripts service jails aware (authored by netchild).
dns/knot-resolver: make the rc scripts service jails aware
Jun 23 2024, 4:47 PM
netchild committed R11:a9db013f20d0: dns/hetzner_ddns: make the rc script service jails aware (authored by netchild).
dns/hetzner_ddns: make the rc script service jails aware
Jun 23 2024, 4:47 PM

Jun 19 2024

netchild committed R11:0ee3d6012f2a: dns/yadifa: make the rc script service jails aware (authored by netchild).
dns/yadifa: make the rc script service jails aware
Jun 19 2024, 8:15 AM

Jun 18 2024

netchild committed R11:31b17db3c47d: devel/sonarqube-community: Update plugins. (authored by netchild).
devel/sonarqube-community: Update plugins.
Jun 18 2024, 10:17 AM

Jun 14 2024

netchild committed rG2d08f6b577e9: rc.subr: add some sanity checks for service jails (authored by netchild).
rc.subr: add some sanity checks for service jails
Jun 14 2024, 6:16 PM
netchild committed rGa70ecfb11757: rc.subr: add new sysv option for service jails (authored by netchild).
rc.subr: add new sysv option for service jails
Jun 14 2024, 6:16 PM
netchild committed R11:305de2d99a1a: ftp/wzdftpd: make the rc script service jails aware (authored by netchild).
ftp/wzdftpd: make the rc script service jails aware
Jun 14 2024, 4:02 PM

Jun 12 2024

netchild committed R11:d668aa55341f: www/tt-rss: make the rc script service jails aware (authored by netchild).
www/tt-rss: make the rc script service jails aware
Jun 12 2024, 6:41 AM
netchild committed R11:62e35a033a54: dns/powerdns-recursor: make the rc script service jails aware (authored by netchild).
dns/powerdns-recursor: make the rc script service jails aware
Jun 12 2024, 6:35 AM
netchild committed R11:fae91b2a5047: dns/powerdns: make the rc script service jails aware (authored by netchild).
dns/powerdns: make the rc script service jails aware
Jun 12 2024, 6:35 AM