summaryrefslogtreecommitdiffstats
path: root/secure
Commit message (Collapse)AuthorAgeFilesLines
* MFC r314658:ngie2017-05-306-11/+11
| | | | | | crypto: normalize paths using SRCTOP-relative paths or :H when possible This simplifies make logic/output
* DIRDEPS_BUILD: Update dependencies.bdrewery2017-05-091-2/+0
| | | | | | This is a direct commit since MFCing these changes is impractical. Sponsored by: Dell EMC Isilon
* MFC r311585:ngie2017-02-041-1/+6
| | | | | | | | | | Conditionalize building libwrap support into sshd Only build libwrap support into sshd if MK_TCP_WRAPPERS != no This will unbreak the build if libwrap has been removed from the system PR: 210141
* MFC: r312825jkim2017-01-26369-5188/+3725
| | | | Merge OpenSSL 1.0.2k.
* MFC r311140:ngie2017-01-163-3/+3
| | | | | | | | | | | | Only bake krb5_config.h support in to ssh(3), etc if both MK_GSSAPI and MK_KERBEROS_SUPPORT != no This fixes the odd case where someone specified MK_GSSAPI=no and MK_KERBEROS_SUPPORT=yes (which admittedly, probably doesn't make sense, but the build system doesn't prevent this case today, and it didn't when I filed the bug back in 2011 either). PR: 159745
* MFC: r306342jkim2016-09-26367-368/+368
| | | | Merge OpenSSL 1.0.2j.
* MFC: r306193jkim2016-09-22374-1134/+1480
| | | | Merge OpenSSL 1.0.2u.
* MFC r305065: Add refactored blacklist support to sshdlidl2016-09-062-0/+8
| | | | | | | | | | | | | | | | | | Change the calls to of blacklist_init() and blacklist_notify to be macros defined in the blacklist_client.h file. This avoids the need for #ifdef USE_BLACKLIST / #endif except in the blacklist.c file. Remove redundent initialization attempts from within blacklist_notify - everything always goes through blacklistd_init(). Added UseBlacklist option to sshd, which defaults to off. To enable the functionality, use '-o UseBlacklist=yes' on the command line, or uncomment in the sshd_config file. Approved by: des Sponsored by: The FreeBSD Foundation
* MFC: r304638, r304640jkim2016-08-3159-126/+126
| | | | Fix white spaces and prefer C-style comments in assembly sources.
* MFC: r304636jkim2016-08-3113-0/+12100
| | | | Build OpenSSL assembly sources for arm.
* MFC: r304320jkim2016-08-3110-62/+80
| | | | | | Disable assembly sources when compiler/assembler cannot compile certain instructions. For example, GCC 4.2.1 + binutils 2.17.50 does not support AVX instructions.
* Revert r301551, which added blacklistd(8) to sshd(8).gjb2016-06-242-8/+0
| | | | | | | | | | This change has functional impact, and other concerns raised by the OpenSSH maintainer. Requested by: des PR: 210479 (related) Approved by: re (marius) Sponsored by: The FreeBSD Foundation
* DIRDEPS_BUILD: Update dependenciesbdrewery2016-06-141-0/+1
| | | | | Approved by: re (gjb) Sponsored by: EMC / Isilon Storage Division
* Add blacklist support to sshdlidl2016-06-071-0/+7
| | | | | | | | Reviewed by: rpaulo Approved by: rpaulo (earlier version of changes) Relnotes: YES Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D5915
* Regen x86 assembly files for r299480.jkim2016-05-1148-125/+37788
|
* Set CC environment variable for Perl scripts. This is for detectingjkim2016-05-111-4/+4
| | | | assembler/compiler capabilities, e.g., AVX instructions.
* Refine comments to add its origin.jkim2016-05-111-21/+27
|
* libcrypto: add "Do not modify" comment to generated source filesemaste2016-05-111-1/+4
| | | | | Reviewed by: jkim Differential Revision: https://reviews.freebsd.org/D6237
* Enable linker error if libcrypto.so contains a relocation against text. Itjkim2016-05-111-1/+0
| | | | | | is position independent on all platforms since r299389. Submitted by: kib
* Make libcrypto.so position independent on i386.jkim2016-05-1046-33345/+66749
|
* Revert r299139: these are generated filesemaste2016-05-062-9/+1
| | | | | | We'll need to properly generate PIC/non-PIC from the source .pl files. Reported by: jkim
* Make libcrypto position independent on i386emaste2016-05-052-1/+9
| | | | | | | | | | Prior to this change libcrypto ended up with a .text relocation. Submitted by: Rafael EspĂ­ndola (earlier version) Reviewed by: kib Approved by: so (glebius) Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D6164
* Merge ^/user/ngie/release-pkg-fix-tests to unbreak how test files are installedngie2016-05-045-40/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | after r298107 Summary of changes: - Replace all instances of FILES/TESTS with ${PACKAGE}FILES. This ensures that namespacing is kept with FILES appropriately, and that this shouldn't need to be repeated if the namespace changes -- only the definition of PACKAGE needs to be changed - Allow PACKAGE to be overridden by callers instead of forcing it to always be `tests`. In the event we get to the point where things can be split up enough in the base system, it would make more sense to group the tests with the blocks they're a part of, e.g. byacc with byacc-tests, etc - Remove PACKAGE definitions where possible, i.e. where FILES wasn't used previously. - Remove unnecessary TESTSPACKAGE definitions; this has been elided into bsd.tests.mk - Remove unnecessary BINDIRs used previously with ${PACKAGE}FILES; ${PACKAGE}FILESDIR is now automatically defined in bsd.test.mk. - Fix installation of files under data/ subdirectories in lib/libc/tests/hash and lib/libc/tests/net/getaddrinfo - Remove unnecessary .include <bsd.own.mk>s (some opportunistic cleanup) Document the proposed changes in share/examples/tests/tests/... via examples so it's clear that ${PACKAGES}FILES is the suggested way forward in terms of replacing FILES. share/mk/bsd.README didn't seem like the appropriate method of communicating that info. MFC after: never probably X-MFC with: r298107 PR: 209114 Relnotes: yes Tested with: buildworld, installworld, checkworld; buildworld, packageworld Sponsored by: EMC / Isilon Storage Division
* Merge OpenSSL 1.0.2h.jkim2016-05-03377-463/+1077
| | | | Relnotes: yes
* Fix including Kyuafile in packaged base system.gjb2016-04-295-5/+10
| | | | | | | | | | | | Fix a related typo while here. Note, this change results in the Kyuafile inclusion in the runtime package, which needs to be fixed, however addresses the PR as far as I can tell in my tests. PR: 209114 Submitted by: ngie Sponsored by: The FreeBSD Foundation
* MFHgjb2016-04-041-2/+0
|\ | | | | | | Sponsored by: The FreeBSD Foundation
| * Remove the old depend (mkdep) code and make FAST_DEPEND the one true way.bdrewery2016-03-301-2/+0
| | | | | | | | | | | | | | Reviewed by: emaste, hselasky (partial), brooks (brief) Discussed on: arch@ Sponsored by: EMC / Isilon Storage Division Differential Revision: https://reviews.freebsd.org/D5742
* | MFHgjb2016-03-1412-42/+7
|\ \ | |/ | | | | Sponsored by: The FreeBSD Foundation
| * Upgrade to OpenSSH 7.2p2.des2016-03-1112-42/+7
| |
* | MFHgjb2016-03-105-0/+55
|\ \ | |/ | | | | Sponsored by: The FreeBSD Foundation
| * DIRDEPS_BUILD: Connect MK_TESTS.bdrewery2016-03-095-0/+55
| | | | | | | | Sponsored by: EMC / Isilon Storage Division
* | MFHgjb2016-03-02391-1212/+1948
|\ \ | |/ | | | | Sponsored by: The FreeBSD Foundation
| * Merge OpenSSL 1.0.2g.jkim2016-03-01390-1209/+1948
| | | | | | | | Relnotes: yes
| * DIRDEPS_BUILD: Regenerate without local dependencies.bdrewery2016-02-241-3/+0
| | | | | | | | | | | | | | | | These are no longer needed after the recent 'beforebuild: depend' changes and hooking DIRDEPS_BUILD into a subset of FAST_DEPEND which supports skipping 'make depend'. Sponsored by: EMC / Isilon Storage Division
* | MFHgjb2016-02-181-0/+1
|\ \ | |/ | | | | Sponsored by: The FreeBSD Foundation
| * DIRDEPS_BUILD: Update dependencies.bdrewery2016-02-161-0/+1
| | | | | | | | Sponsored by: EMC / Isilon Storage Division
* | More 'tests' packaging fixes.gjb2016-02-031-0/+5
| | | | | | | | Sponsored by: The FreeBSD Foundation
* | First pass to fix the 'tests' packages.gjb2016-02-024-0/+20
| | | | | | | | Sponsored by: The FreeBSD Foundation
* | MFHgjb2016-01-29365-758/+951
|\ \ | |/ | | | | Sponsored by: The FreeBSD Foundation
| * Merge OpenSSL 1.0.2f.jkim2016-01-28365-758/+951
| | | | | | | | Relnotes: yes
* | MFHgjb2016-01-271-0/+254
|\ \ | |/ | | | | Sponsored by: The FreeBSD Foundation
| * Add the openssl header for RISC-V.br2016-01-261-0/+254
| | | | | | | | Copied from aarch64 as we can't generate it yet.
* | MFHgjb2016-01-251-2/+2
|\ \ | |/ | | | | Sponsored by: The FreeBSD Foundation
| * Upgrade to OpenSSH 7.0p1.des2016-01-201-2/+2
| |
* | MFHgjb2016-01-202-12/+15
|\ \ | |/ | | | | Sponsored by: The FreeBSD Foundation
| * List source files (foo.c) instead of object files in SRCS.jhb2016-01-201-1/+1
| | | | | | | | Reviewed by: bdrewery
| * Upgrade to OpenSSH 6.8p1.des2016-01-192-14/+15
| |
| * Upgrade to OpenSSH 6.7p1, retaining libwrap support (which has been removeddes2016-01-191-1/+3
| | | | | | | | | | | | upstream) and a number of security fixes which we had already backported. MFC after: 1 week
* | MFH r289384-r293170gjb2016-01-04439-11829/+36156
|\ \ | |/ | | | | Sponsored by: The FreeBSD Foundation
| * Build engines in parallel.bdrewery2015-12-151-1/+1
| | | | | | | | Sponsored by: EMC / Isilon Storage Division
OpenPOWER on IntegriCloud