Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Adjust references for sysctl(3) to sysctl(2) | deraadt | 2018-01-12 | 1 | -4/+4 |
| | |||||
* | Add the missing STANDARDS section (kettenis@ noticed that these are | schwarze | 2017-11-28 | 1 | -6/+14 |
| | | | | | POSIX functions) and turn the weird DIAGNOSTICS section into a normal RETURN VALUES section while here. | ||||
* | update the little endian processor list to give it a chance of matching | tedu | 2017-07-08 | 2 | -6/+6 |
| | | | | what the reader is using. | ||||
* | make the description strings match the code | deraadt | 2017-05-03 | 1 | -10/+10 |
| | |||||
* | Remove "len < 0" check; len is socklen_t (uint32_t) so can't be | millert | 2017-04-27 | 1 | -2/+2 |
| | | | | negative. Quiets a warning from clang. OK bluhm@ | ||||
* | size is unsigned so using ==0 not <=0 when checking for buffer exhaustion | millert | 2017-03-06 | 1 | -4/+4 |
| | |||||
* | Pull in a change from the bind 8 resolver that fixes a potential | millert | 2017-03-06 | 1 | -10/+16 |
| | | | | | crash when given a large hex number as part of the dotted quad. OK deraadt@ jsg@ | ||||
* | Add support for RES_USE_DNSSEC | jca | 2017-02-27 | 1 | -5/+2 |
| | | | | | | | | | | | | RES_USE_DNSSEC is implemented by setting the DNSSEC DO bit in outgoing queries. The resolver is then supposed to set the AD bit in the reply if it managed to validate the answer through DNSSEC. Useful when the application doesn't implement validation internally. This scheme assumes that the validating resolver is trusted and that the communication channel between the validating resolver and and the client is secure. ok eric@ gilles@ | ||||
* | Add EDNS0 support. | jca | 2017-02-18 | 1 | -4/+3 |
| | | | | | | | EDNS allows for various DNS extensions, among which UDP DNS packets size bigger than 512 bytes. The default is still to not advertize anything. ok eric@ | ||||
* | in resolver(3), document that _EDNS0 and _DNSSEC are no ops; | jmc | 2017-01-24 | 1 | -6/+17 |
| | | | | | | | diff from kirill miazine while here, bump all the no op texts to one standard blurb; help/ok jca | ||||
* | Eliminate some gcc warnings about 'unused variables', mostly by | krw | 2016-12-16 | 1 | -2/+2 |
| | | | | | | adding appropriate #ifdef's around declarations. ok millert@ (with a tweak I will commit separately) | ||||
* | Nuke some trailing tabs. | krw | 2016-12-15 | 1 | -3/+3 |
| | |||||
* | Fix regressions introduce in the fix for CVE-2016-6559. | millert | 2016-12-08 | 1 | -6/+5 |
| | | | | From FreeBSD (glebius) | ||||
* | Fix a typo, decrement rem, don't increment for single digit hex bytes. | millert | 2016-12-07 | 1 | -2/+2 |
| | | | | From Henri Kemppainen | ||||
* | CVE-2016-6559: fix potential buffer overflow(s) in link_ntoa(3). | millert | 2016-12-06 | 1 | -19/+35 |
| | | | | | | | A specially crafted struct sockaddr_dl argument can trigger a stack overflow of a static buffer in libc. An attacker may be able to use this to write to arbitrary locations in the data segment. From FreeBSD (glebius); OK deraadt@ mestre@ | ||||
* | Delete casts to off_t and size_t that are implied by assignments | guenther | 2016-09-21 | 4 | -11/+10 |
| | | | | | | | or prototypes. Ditto for some of the char* and void* casts too. verified no change to instructions on ILP32 (i386) and LP64 (amd64) ok natano@ abluhm@ deraadt@ millert@ | ||||
* | Obvious minor fixes: | schwarze | 2016-08-05 | 2 | -36/+57 |
| | | | | | | | | * Add missing .Dv, .Ev, and .Fa macros. * Delete deprecated .Tn macros. * Mark up global variable names with .Va, not with .Fa or .Li. * Mark up config file commands with .Ic, not with .Fa. * Fix HISTORY, trivial to verify from the CSRG archive CD. | ||||
* | Make RES_OPTIONS point directly to resolv.conf(5) instead of going through | martijn | 2016-08-05 | 1 | -3/+3 |
| | | | | | | resolver(3). OK jmc@ | ||||
* | Prefer AF_* over PF_* and 'address family' over 'protocol family' | guenther | 2016-05-29 | 1 | -9/+9 |
| | | | | ok jung@ | ||||
* | rcmd(3) and rcmdsh(3) use getaddrinfo(3) not gethostbyname(3). | millert | 2016-05-28 | 2 | -9/+9 |
| | |||||
* | Use getaddrinfo() instead of the non-standard gethostbyname2(). | millert | 2016-05-28 | 1 | -5/+14 |
| | | | | OK deraadt@ jca@ jung@ florian@ | ||||
* | Remove iruserok(_sa)? and __ivaliduser(sa)? | guenther | 2016-05-23 | 2 | -90/+20 |
| | | | | ok millert@ deraadt@ | ||||
* | Eliminate __check_rhosts_file and __rcmd_errstr: they were only used by | guenther | 2016-05-23 | 1 | -5/+1 |
| | | | | | | rlogind and rshd (remember them?) ok deraadt@ | ||||
* | Remove old NeXT-specific cruft. From mmcc@ | millert | 2016-05-01 | 1 | -13/+1 |
| | |||||
* | Prefer _MUTEX_*LOCK over _THREAD_PRIVATE_MUTEX_*LOCK() when thread-specific | guenther | 2016-04-05 | 1 | -4/+4 |
| | | | | | | data isn't necessary. ok mpi@, ok&tweak natano@ | ||||
* | for some time now mandoc has not required MLINKS to function | jmc | 2016-03-30 | 1 | -54/+1 |
| | | | | | | | | | | | | correctly - logically complete that now by removing MLINKS from base; authors need only to ensure there is an entry in NAME for any function/ util being added. MLINKS will still work, and remain for perl to ease upgrades; ok nicm (curses) bcook (ssl) ok schwarze, who provided a lot of feedback and assistance ok tb natano jung | ||||
* | un-vax; | jmc | 2016-03-10 | 1 | -3/+3 |
| | |||||
* | Remove NULL-checks before free() and a few related dead assignments. | mmcc | 2015-12-28 | 1 | -3/+2 |
| | | | | ok and valuable input from millert@ | ||||
* | gethostbyname2() and gethostbyaddr() need <sys/socket.h>; discussed with | tim | 2015-12-19 | 1 | -6/+8 |
| | | | | millert@ | ||||
* | tweak previous; | jmc | 2015-12-16 | 2 | -4/+5 |
| | |||||
* | Remove support for HOSTALIASES from the resolver. This "open and parse | deraadt | 2015-12-16 | 2 | -15/+6 |
| | | | | | | | | any file indicated by an environment variable" feature inside the resolver is incompatible with what pledge "dns" is trying to be. It is a misguided "feature" added way back in history which almost noone uses, but everyone has to assume the risk from. ok eric florian kettenis | ||||
* | s/begining/beginning/g | mmcc | 2015-12-14 | 1 | -2/+2 |
| | |||||
* | syslog() here is pointless; ok millert | deraadt | 2015-11-25 | 1 | -2/+0 |
| | |||||
* | Use reentrant versions of getpw{nam,uid} and getgr{nam,gid} within | millert | 2015-11-24 | 2 | -7/+10 |
| | | | | | | | libc to avoid reusing the static buffers returned by the non-reentrant versions. Since this is inside libc we can use constants for the buffer sizes instead of having to call sysconf(). OK guenther@ deraadt@ | ||||
* | point to netintro(4) rather than (now removed) networking(4); | jmc | 2015-11-21 | 2 | -6/+6 |
| | |||||
* | update NAME section to include all documented functions, | jmc | 2015-11-10 | 4 | -12/+12 |
| | | | | | | or otherwise change Dt to reflect the name of an existing function; feedback/ok schwarze | ||||
* | inet(4), not inet(3); | jmc | 2015-11-08 | 1 | -3/+3 |
| | |||||
* | delete old lint ARGSUSED comments | guenther | 2015-11-01 | 1 | -2/+1 |
| | |||||
* | Switch if_nameindex(3) to use the new NET_RT_IFNAMES sysctl to get the | claudio | 2015-10-23 | 3 | -88/+73 |
| | | | | | | | | list of interface names. At the same time switch if_nametoindex(3) and if_indextoname(3) to use if_nameindex(3) instead of getifaddrs(3). if_nameindex(3) exposes much less then getifaddrs(3) and is allowed by pledge(2). With and OK deraadt@ | ||||
* | Use waitpid() instead of wait() to avoid returning early from another child | guenther | 2015-10-23 | 1 | -2/+3 |
| | | | | | | exiting, and loop the waitpid() on EINTR ok deraadt@ millert@ | ||||
* | Cast ctype function arguments to unsigned char. | mmcc | 2015-10-22 | 1 | -2/+2 |
| | | | | ok guenther@ | ||||
* | Wrap <resolv.h> so that internal calls go direct | guenther | 2015-10-05 | 3 | -5/+11 |
| | | | | ok millert@ | ||||
* | wrap __ivaliduser_sa() so the internal call is direct (at least until we | guenther | 2015-10-04 | 1 | -0/+2 |
| | | | | stop exporting it) | ||||
* | recv() and send() aren't overriden by libpthread (vs recvfrom() and sendto()!) | guenther | 2015-10-04 | 2 | -2/+4 |
| | | | | so wrap them to make internal calls go direct | ||||
* | Wrap <ifaddrs.h>, <netinet/in.h>, and <netinet/if_ether.h> so internal | guenther | 2015-09-14 | 3 | -3/+7 |
| | | | | calls go direct and all the symbols are weak | ||||
* | Wrap <net/if.h> and <net/if_dl.h> so internal calls go direct and all the | guenther | 2015-09-14 | 2 | -2/+4 |
| | | | | symbols are weak | ||||
* | Finish wrapping <netdb.h> so that calls go direct and the symbols are all weak | guenther | 2015-09-14 | 9 | -9/+24 |
| | |||||
* | Wrap <arpa/inet.h> and <arpa/nameser.h> so that calls go direct and the | guenther | 2015-09-13 | 5 | -5/+11 |
| | | | | symbols without underbar prefix are all weak | ||||
* | Wrap <unistd.h> so that internal calls go direct and they're all weak symbols | guenther | 2015-09-12 | 4 | -2/+6 |
| | | | | Delete unused 'fd' argument from internal function oldttyname() | ||||
* | _getnetbyaddr and _getnetbyname appear to be historical accidents in | deraadt | 2015-09-11 | 3 | -103/+2 |
| | | | | our tree. ok guenther miod |