Re: Boot panic with bsd.mp on a Compaq ProLiant 2500

2006-11-28 Thread François Chambaud
"Riccardo Giuntoli" <[EMAIL PROTECTED]> writes:

> Hi there,
> 
> i've got the same problem of Frangois with Proliant 2500, i've choosen
> all the possible so with compaq configuration utility but nothing
> change.
> I've tried with 3.8, 3.9 and 4.0 -release and the error is the same on
> all of them.
> 
> Any suggestion? Someone knows if in -current this bug was fixed?
> Frangois have you found the solution?
> 
> Best regards, RG.
> 
> -- 
> Name: Riccardo Giuntoli
> Email: [EMAIL PROTECTED]
> Homepage: http://www.luxoro.org/
> Location: Genova, Italy
> PGP Key: 0x67123739
> PGP Fingerprint: CE75 16B5 D855 842FAB54 FB5C DDC6 4640 6712 3739
> Key server: hkp://wwwkeys.eu.pgp.net

Riccardo,

I'm still using OpenBSD 3.9 on this server and I'm a little disappointed
with the result of your last 4.0-release installation. I've differed my
4.0 upgrade and now I think seriously waiting the next 4.1 version.

Can somebody please tell us if this problem can be solved? It will be
wonderful to use our old Compaq ProLiant 2500 with the two processors
installed.

My initial post:
http://archives.neohapsis.com/archives/openbsd/2006-07/1113.html

Thank you again.

Francois
-- 
http://www.chambaud.org



munin

2006-11-28 Thread Marian Hettwer
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Hi Folks,

does anybody use munin on OpenBSD?
If not, I'll try do create a port...
If somebody else already tried this and has an old port flying around,
I'd be glad to use this one :)

Background: We're using munin in our Datacenter to monitor all servers.
Recently I installed some OpenBSD boxes and those need to be monitored
by munin too...

any hints?

best regards,
Marian

PS.: Ah, yes, it's OpenBSD 4.0 and thanks to the maintainer of Nagios
nrpe :-) (we need that one too)
iD8DBQFFa/6HgAq87Uq5FMsRAmr2AKDcgH+L7AV+tU9UBG1ehILWrJcNewCdGQYU
RPy6YNmZGsovrprfhibmA6E=
=pQAL
-END PGP SIGNATURE-



Re: SFTP only access to sshd

2006-11-28 Thread Joachim Schipper
On Mon, Nov 27, 2006 at 03:36:17PM +0100, Ingo Schwarze wrote:
> Jim Razmus wrote on Sun, Nov 26, 2006 at 07:41:42PM -0500:
> > Ingo Schwarze <[EMAIL PROTECTED]> [061125 18:51]:
> >> Jim Razmus wrote:
> 
> >>> Anyone have a clever hack to get sftp chroot'ed too?
> >> 
> >> In my original post to this thread, i mentioned
> >>   http://sublimation.org/scponly/wiki
> >> Disclaimed: I neither tested nor audited scponly.
> >> A port has just been submitted to ports@ (not by me).
> > 
> > Sorry, I meant in conjunction with ForceCommand.
> 
> And without any additional helper binary like scponly,
> if i understand your intention correctly?
> 
> I deem that rather improbable.
 
> Still, i neither claim it's impossible to do right nor do i think
> your question is completely unreasonable.

In fact, I suppose systrace might do this without requiring you to hack
up very much at all. It wouldn't actually chroot sftp-server, but
preventing any file system activity outside of /home would go a long
way.

Joachim



Re: Correct dev config for apache chroot? OpenBSD 4.0

2006-11-28 Thread Joachim Schipper
On Mon, Nov 27, 2006 at 07:06:51PM +, Conrad Winchester wrote:
> On 27 Nov 2006, at 18:22, Tom Cosgrove wrote:
> >Conrad Winchester 27-Nov-06 08:23
> >>Secondly, an apology: I am not following the standard way of doing
> >>things, but to be honest thats the way I am.
> >>
> >>I am tryng to chroot apache 2.2 (yes I like apache 2 and have loads
> >>of experience with it, I have very little apache 1.3 experience). I
> >>have got it working in debug mode

> >>lovely, but when I try to run it normally

> >>it fails to daemonize itself and throws the following error
> >>
> >>[Mon Nov 27 08:09:40 2006] [crit] (6)Device not configured:
> >>apr_proc_detach failed
> >>Pre-configuration failed

> >>I am pretty sure this is due to incorrect /dev nodes in my chrooted
> >>file system.

> >Try using ktrace(1) and kdump(1) to see what it's try to do.

> thanks for that. I have identified a problem with /dev/crypto. I make  
> it with
> 
> #mknod /server/web/dev/crypto c 70 0
> #chmod 666 /server/web/dev/crypto
> 
> but I get the following output from kdump
> 
> 2603 httpdNAMI  "/dev/crypto"
> 2603 httpdRET   open -1 errno 6 Device not configured
> 
> What is the proper way to create a /dev/crypto node?

Pretty much this, but /dev/crypto is only for hardware-accelerated
crypto. Are you really sure you should use it?

Also, check for the nodev mount flag.

Finally, doing things differently isn't always a good idea, but I'm sure
you are aware of this.

Joachim



Re: Boot panic with bsd.mp on a Compaq ProLiant 2500

2006-11-28 Thread Riccardo Giuntoli

On 27 Nov 2006 21:29:44 +0100, FranC'ois Chambaud
<[EMAIL PROTECTED]> wrote:

"Riccardo Giuntoli" <[EMAIL PROTECTED]> writes:

> Hi there,
>
> i've got the same problem of Frangois with Proliant 2500, i've choosen
> all the possible so with compaq configuration utility but nothing
> change.
> I've tried with 3.8, 3.9 and 4.0 -release and the error is the same on
> all of them.
>
> Any suggestion? Someone knows if in -current this bug was fixed?
> Frangois have you found the solution?
>
> Best regards, RG.
>
> --
> Name: Riccardo Giuntoli
> Email: [EMAIL PROTECTED]
> Homepage: http://www.luxoro.org/
> Location: Genova, Italy
> PGP Key: 0x67123739
> PGP Fingerprint: CE75 16B5 D855 842FAB54 FB5C DDC6 4640 6712 3739
> Key server: hkp://wwwkeys.eu.pgp.net

Riccardo,


Hi FranC'ois


I'm still using OpenBSD 3.9 on this server and I'm a little disappointed
with the result of your last 4.0-release installation. I've differed my
4.0 upgrade and now I think seriously waiting the next 4.1 version.


Also with 4.0-current the error is the same.


Can somebody please tell us if this problem can be solved? It will be
wonderful to use our old Compaq ProLiant 2500 with the two processors
installed.


I think we can use sendbug(1) to tell openbsd guro's about our problem.


My initial post:
http://archives.neohapsis.com/archives/openbsd/2006-07/1113.html

Thank you again.


Thank you too.


Francois


Best regards, RG.

--
Name: Riccardo Giuntoli
Email: [EMAIL PROTECTED]
Homepage: http://www.luxoro.org/
Location: Genova, Italy
PGP Key: 0x67123739
PGP Fingerprint: CE75 16B5 D855 842FAB54 FB5C DDC6 4640 6712 3739
Key server: hkp://wwwkeys.eu.pgp.net



GENERIC ou GENERIC.MP for a SuperMicro SC513 ?

2006-11-28 Thread Bruno Carnazzi

 Hi misc,

I've installed (without a problem, as always, thank you devs !)
OpenBSD/i386 4.0-release on a SuperMicro SC513. This server is powered
by an Intel Dual-core Pentium 3.0GHz. When I boot whith bsd.mp, I've
got a "ioapic0: pin 16 shares different IPL interrupts (40..50),
degraded performance" kernel notification on boot. So, should I use
bsd or bsd.mp for this machine ? This machine is intended to be a HTTP
proxy (squid).

Note: in case of mp, what's the notions of "boot processor" and
"application processor" ?

Thank you,

Bruno.


Here are the 2 dmesg :

OpenBSD 4.0 (GENERIC) #1107: Sat Sep 16 19:15:58 MDT 2006
   [EMAIL PROTECTED]:/usr/src/sys/arch/i386/compile/GENERIC
cpu0: Intel(R) Pentium(R) D CPU 3.00GHz ("GenuineIntel" 686-class) 3 GHz
cpu0: 
FPU,V86,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,SBF,SSE3,MWAIT,DS-CPL,VMX,EST,CNXT-ID
,CX16
cpu0: Enhanced SpeedStep disabled by BIOS
real mem  = 2145865728 (2095572K)
avail mem = 1949339648 (1903652K)
using 4256 buffers containing 107397120 bytes (104880K) of memory
mainbus0 (root)
bios0 at mainbus0: AT/286+(ad) BIOS, date 04/17/06, BIOS32 rev. 0 @
0xfd470, SMBIOS rev. 2.51 @ 0x7feea000 (33 entries)
bios0: Supermicro PDSMi
pcibios0 at bios0: rev 2.1 @ 0xfd470/0xb90
pcibios0: PCI BIOS has 20 Interrupt Routing table entries
pcibios0: PCI Interrupt Router at 000:31:0 ("Intel 82801GB LPC" rev 0x00)
pcibios0: PCI bus #10 is the last bus
bios0: ROM list: 0xc/0x8000 0xc8000/0x1000 0xc9000/0x1000
ipmi at mainbus0 not configured
cpu0 at mainbus0
pci0 at mainbus0 bus 0: configuration mode 1 (no bios)
pchb0 at pci0 dev 0 function 0 "Intel E7230 MCH" rev 0x81
ppb0 at pci0 dev 1 function 0 "Intel E7230 PCIE" rev 0x81
pci1 at ppb0 bus 1
ppb1 at pci0 dev 28 function 0 "Intel 82801GB PCIE" rev 0x01
pci2 at ppb1 bus 2
ppb2 at pci2 dev 0 function 0 "Intel PCIE-PCIE" rev 0x09
pci3 at ppb2 bus 3
"Intel IOxAPIC" rev 0x09 at pci2 dev 0 function 1 not configured
ppb3 at pci0 dev 28 function 4 "Intel 82801G PCIE" rev 0x01
pci4 at ppb3 bus 4
em0 at pci4 dev 0 function 0 "Intel PRO/1000MT (82573E)" rev 0x03: irq
10, address 00:30:48:5c:64:52
ppb4 at pci0 dev 28 function 5 "Intel 82801G PCIE" rev 0x01
pci5 at ppb4 bus 5
em1 at pci5 dev 0 function 0 "Intel PRO/1000MT (82573L)" rev 0x00: irq
11, address 00:30:48:5c:64:53
uhci0 at pci0 dev 29 function 0 "Intel 82801GB USB" rev 0x01: irq 5
usb0 at uhci0: USB revision 1.0
uhub0 at usb0
uhub0: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub0: 2 ports with 2 removable, self powered
uhci1 at pci0 dev 29 function 1 "Intel 82801GB USB" rev 0x01: irq 10
usb1 at uhci1: USB revision 1.0
uhub1 at usb1
uhub1: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub1: 2 ports with 2 removable, self powered
uhci2 at pci0 dev 29 function 2 "Intel 82801GB USB" rev 0x01: irq 11
usb2 at uhci2: USB revision 1.0
uhub2 at usb2
uhub2: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub2: 2 ports with 2 removable, self powered
uhci3 at pci0 dev 29 function 3 "Intel 82801GB USB" rev 0x01: irq 10
usb3 at uhci3: USB revision 1.0
uhub3 at usb3
uhub3: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub3: 2 ports with 2 removable, self powered
ehci0 at pci0 dev 29 function 7 "Intel 82801GB USB" rev 0x01: irq 5
usb4 at ehci0: USB revision 2.0
uhub4 at usb4
uhub4: Intel EHCI root hub, rev 2.00/1.00, addr 1
uhub4: 8 ports with 8 removable, self powered
ppb5 at pci0 dev 30 function 0 "Intel 82801BA AGP" rev 0xe1
pci6 at ppb5 bus 10
vga1 at pci6 dev 0 function 0 "ATI Rage XL" rev 0x27
wsdisplay0 at vga1 mux 1: console (80x25, vt100 emulation)
wsdisplay0: screen 1-5 added (80x25, vt100 emulation)
ichpcib0 at pci0 dev 31 function 0 "Intel 82801GB LPC" rev 0x01: PM disabled
pciide0 at pci0 dev 31 function 2 "Intel 82801GB SATA" rev 0x01: DMA,
channel 0 configured to native-PCI, channel 1 configured to native-PCI
pciide0: using irq 10 for native-PCI interrupt
wd0 at pciide0 channel 0 drive 0: 
wd0: 16-sector PIO, LBA48, 114473MB, 234441648 sectors
wd0(pciide0:0:0): using PIO mode 4, Ultra-DMA mode 5
ichiic0 at pci0 dev 31 function 3 "Intel 82801GB SMBus" rev 0x01: irq 10
iic0 at ichiic0
lm1 at iic0 addr 0x2d: W83627HF
lm2 at iic0 addr 0x2f: W83792D rev D
isa0 at ichpcib0
isadma0 at isa0
pckbc0 at isa0 port 0x60/5
pckbd0 at pckbc0 (kbd slot)
pckbc0: using irq 1 for kbd slot
wskbd0 at pckbd0: console keyboard, using wsdisplay0
pmsi0 at pckbc0 (aux slot)
pckbc0: using irq 12 for aux slot
wsmouse0 at pmsi0 mux 0
pcppi0 at isa0 port 0x61
midi0 at pcppi0: 
spkr0 at pcppi0
lpt0 at isa0 port 0x378/4 irq 7
lm0 at isa0 port 0x290/8: W83627HF
lm1 detached
npx0 at isa0 port 0xf0/16: using exception 16
pccom0 at isa0 port 0x3f8/8 irq 4: ns16550a, 16 byte fifo
pccom1 at isa0 port 0x2f8/8 irq 3: ns16550a, 16 byte fifo
fdc0 at isa0 port 0x3f0/6 irq 6 drq 2
biomask ef65 netmask ef65 ttymask ffe7
pctr: user-level cycle counter enabled
dkcsum: wd0 matches BIOS drive 0x80
root on wd0a
rootdev=0x0 rrootdev=0x300 rawdev=0x302

And

Ope

Re: iwi0 connection frustration

2006-11-28 Thread Der Engel

Did you install the firmware?

On 11/28/06, Vim Visual <[EMAIL PROTECTED]> wrote:

Hi,

I am still testing a "crashbox" (not bad, from zero to a full OpenBSD
system including port trees in less than a week, my first OpenBSD system :) )
but I have now an issue with the wlan connection. The card is an Intel
PRO/Wireless
2200BG

First of all: I have read the man pages (good boy, good boy! arf, arf!)

My net:

nwid: pepitogrillo

nwkey: eltrenloco

(hahaha!)

I have pkg_add'ed the damien firmware.

But still I cannot connect. My command line is

sudo ifconfig iwi0 nwkey eltrenloco nwid pepitogrillo

(I hope that the order of the factors doesn't alter the product! Is
iwi an abelian group? )

and then

sudo dhclient iwi0

After the first DHCPDISCOVER on iwi0 to 255.255.255.255 I get
"send_packet: No buffer space available", this goes on some 12 times
and then No DHCPOFFERS received and No working leases in presistent
database - sleeping

I cannot show you dmesg because, as a matter of fact, the crashbox
doesn't have connection :) And I don't feel like typping everything!

Trying it via /etc/hostname.iwi0 doesn't help

Any hint? (I am sure yes!)

thanks in advance,

Pau

PS: The "send_packet: No buffer space available" disappears after a
sudo ifconfig iwi0 down, sudo ifwonfig iwi0 up




Re: GENERIC ou GENERIC.MP for a SuperMicro SC513 ?

2006-11-28 Thread Theo de Raadt
> I've installed (without a problem, as always, thank you devs !)
> OpenBSD/i386 4.0-release on a SuperMicro SC513. This server is powered
> by an Intel Dual-core Pentium 3.0GHz. When I boot whith bsd.mp, I've
> got a "ioapic0: pin 16 shares different IPL interrupts (40..50),
> degraded performance" kernel notification on boot. So, should I use
> bsd or bsd.mp for this machine ? This machine is intended to be a HTTP
> proxy (squid).

Don't worry about that message.  Make your decision on how well it works.

> Note: in case of mp, what's the notions of "boot processor" and
> "application processor" ?

It is a part of the architecture, and google will tell you.



Re: iwi0 connection frustration

2006-11-28 Thread Vim Visual

As I wrote in the previous email, I have pkg_add'ed the damien firmware.

this means that I did

sudo pkg_add 
http://damien.bergamini.free.fr/packages/openbsd/iwi-firmware-3.0.tgz

the files

/etc/firmware/iwi-license
/etc/firmware/iwi-boot
/etc/firmware/iwi-bss
/etc/firmware/iwi-ibss
/etc/firmware/iwi-monitor
/etc/firmware/iwi-ucode-bss
/etc/firmware/iwi-ucode-ibss
/etc/firmware/iwi-ucode-monitor

are there and dmesg | grep iwi tells me that the adpater has been
recognized during the boot process; what's more, I get *something*
like

# ifconfig iwi0
iwi0: flags=8802 mtu 1500
   address: xx:xx:xx:xx:xx:xx
   nwid ""
   media: IEEE802.11 autoselect
   status: no network

but I am missing the "powersave" line. I don't know whether this is
related to the problem.

It cannot be a hardware problem because the crashbox with the debian
variant ubuntu recognised the chip and I was able to connect to my
nwid

I am wondering whether this has something to do with the encryption
bit rate... I see that the maximum is 104-bit and I don't remember
which rate I chose (the wlan modem is at home, I am in the office now)

Mmmh... maybe I should try to switch off the wep and see what happens...

2006/11/28, Der Engel <[EMAIL PROTECTED]>:

Did you install the firmware?

On 11/28/06, Vim Visual <[EMAIL PROTECTED]> wrote:
> Hi,
>
> I am still testing a "crashbox" (not bad, from zero to a full OpenBSD
> system including port trees in less than a week, my first OpenBSD system :) )
> but I have now an issue with the wlan connection. The card is an Intel
> PRO/Wireless
> 2200BG
>
> First of all: I have read the man pages (good boy, good boy! arf, arf!)
>
> My net:
>
> nwid: pepitogrillo
>
> nwkey: eltrenloco
>
> (hahaha!)
>
> I have pkg_add'ed the damien firmware.
>
> But still I cannot connect. My command line is
>
> sudo ifconfig iwi0 nwkey eltrenloco nwid pepitogrillo
>
> (I hope that the order of the factors doesn't alter the product! Is
> iwi an abelian group? )
>
> and then
>
> sudo dhclient iwi0
>
> After the first DHCPDISCOVER on iwi0 to 255.255.255.255 I get
> "send_packet: No buffer space available", this goes on some 12 times
> and then No DHCPOFFERS received and No working leases in presistent
> database - sleeping
>
> I cannot show you dmesg because, as a matter of fact, the crashbox
> doesn't have connection :) And I don't feel like typping everything!
>
> Trying it via /etc/hostname.iwi0 doesn't help
>
> Any hint? (I am sure yes!)
>
> thanks in advance,
>
> Pau
>
> PS: The "send_packet: No buffer space available" disappears after a
> sudo ifconfig iwi0 down, sudo ifwonfig iwi0 up




Re: Correct dev config for apache chroot? OpenBSD 4.0

2006-11-28 Thread Conrad Winchester
Hi

the /dev/crypto requirement seems to come for free when you build apache on
openBSD. Reading up on it it should fall over gracefully to software when
you don't have hardware support.

I don't think this is the problem anymore because I can still run chrooted
apache in non-daemon mode.

Very frustrating :-(

Conrad

On 11/27/06, Joachim Schipper <[EMAIL PROTECTED]> wrote:
>
> On Mon, Nov 27, 2006 at 07:06:51PM +, Conrad Winchester wrote:
> > On 27 Nov 2006, at 18:22, Tom Cosgrove wrote:
> > >Conrad Winchester 27-Nov-06 08:23
> > >>Secondly, an apology: I am not following the standard way of doing
> > >>things, but to be honest thats the way I am.
> > >>
> > >>I am tryng to chroot apache 2.2 (yes I like apache 2 and have loads
> > >>of experience with it, I have very little apache 1.3 experience). I
> > >>have got it working in debug mode
>
> > >>lovely, but when I try to run it normally
>
> > >>it fails to daemonize itself and throws the following error
> > >>
> > >>[Mon Nov 27 08:09:40 2006] [crit] (6)Device not configured:
> > >>apr_proc_detach failed
> > >>Pre-configuration failed
>
> > >>I am pretty sure this is due to incorrect /dev nodes in my chrooted
> > >>file system.
>
> > >Try using ktrace(1) and kdump(1) to see what it's try to do.
>
> > thanks for that. I have identified a problem with /dev/crypto. I make
> > it with
> >
> > #mknod /server/web/dev/crypto c 70 0
> > #chmod 666 /server/web/dev/crypto
> >
> > but I get the following output from kdump
> >
> > 2603 httpdNAMI  "/dev/crypto"
> > 2603 httpdRET   open -1 errno 6 Device not configured
> >
> > What is the proper way to create a /dev/crypto node?
>
> Pretty much this, but /dev/crypto is only for hardware-accelerated
> crypto. Are you really sure you should use it?
>
> Also, check for the nodev mount flag.
>
> Finally, doing things differently isn't always a good idea, but I'm sure
> you are aware of this.
>
> Joachim



Re: Boot panic with bsd.mp on a Compaq ProLiant 2500

2006-11-28 Thread François Chambaud
"Riccardo Giuntoli" <[EMAIL PROTECTED]> writes:


> 
> I think we can use sendbug(1) to tell openbsd guro's about our problem.
> >

Done.

I've sent a bug report to [EMAIL PROTECTED]

Francois
-- 
http://www.chambaud.org



[EMAIL PROTECTED]: ET1310 Documentation]

2006-11-28 Thread Jonathan Gray
This is an example of us trying to talk to a vendor and
being totally shut down. Not only did they license the PCI express and
MAC portions, but they don't want to help us to support their products
at all. No information, no people to talk to, nothing.

- Forwarded message from "Ubowski, Richard M (Richard)" <[EMAIL PROTECTED]> 
-

From: "Ubowski, Richard M (Richard)" <[EMAIL PROTECTED]>
Date: Tue, 28 Nov 2006 09:41:36 -0500
To: [EMAIL PROTECTED]
Cc: "Soriano, Victor John (Vic)" <[EMAIL PROTECTED]>
Subject: ET1310 Documentation


 
Hi Jason,
I forwarded your request to the Agere ET1310 Product Manager and a
decision was made to not release the ET1310 documentation at this time.
Appreciate your interest in developing an OpenBSD driver for the ET1310.


The ET1310 GigE PHY is an Agere design and the Agere MAC was licensed
from a 3rd party.

Rgds,
Rich Ubowski
PCS Applications Manager

-- Forwarded Message
From: Jonathan Gray <[EMAIL PROTECTED]>
Date: Wed, 29 Nov 2006 00:31:36 +1100
To: Victor Soriano <[EMAIL PROTECTED]>
Subject: Re: ET1310 datasheet

On Mon, Nov 13, 2006 at 12:44:51PM -0500, Victor Soriano wrote:
> Hi John,
> 
> I'm Vic Soriano, a Sr. Software Engineer for Agere and the 
> author/maintainer of the Linux driver source code for the ET1310
Gigabit MAC/PHY.
> 
> I've copied our Applications Engineering Manager for the ET1310, Rich 
> Ubowski, on this email. He is currently looking into obtaining the 
> datasheets you've requested.
> 
> In addition to documentation, I'm attaching the last release of the 
> ET1310 Linux driver for reference, as this might also help in your 
> porting or development efforts.

Have you had a chance to find the documentation yet?
I can't seem to manage to get MII access to return non zero values.

It appears that the ET1310 design was initially based around a National
cassini+ design?

Jonathan

-- End of Forwarded Message

- End forwarded message -



trouble with IPv6 address with pkg_add(1)

2006-11-28 Thread Bruno Carnazzi

  Hi all,

When using 
PKG_PATH=ftp://ftp.freenet.de/pub/ftp.openbsd.org/pub/OpenBSD/snapshots/packages/i386
with pkg_add(1), updating package with "sudo pkg_add -ui -F update -F
updatedepends" fails, saying "no package in PKG_PATH". When using
PKG_PATH=ftp://ftp.openbsd.org/pub/OpenBSD/snapshots/packages/i386,
everything work fine. As both path includes exactly the same packages,
I expect there is a trouble with IPv6 adress (I go through a IPv4
NAT-box, and my LAN is IPv4-only) :

$ host ftp.freenet.de
ftp.freenet.de is an alias for ftp-0.freenet.de.
ftp-0.freenet.de has address 194.97.2.67
ftp-0.freenet.de has address 194.97.2.68
ftp-0.freenet.de has address 194.97.2.69
ftp.freenet.de is an alias for ftp-0.freenet.de.
ftp-0.freenet.de has IPv6 address 2001:748:100:50::3
ftp-0.freenet.de has IPv6 address 2001:748:100:50::4
ftp-0.freenet.de has IPv6 address 2001:748:100:50::5
ftp.freenet.de is an alias for ftp-0.freenet.de.

and

$ host ftp.openbsd.org
ftp.openbsd.org is an alias for openbsd.sunsite.ualberta.ca.
openbsd.sunsite.ualberta.ca has address 129.128.5.191
ftp.openbsd.org is an alias for openbsd.sunsite.ualberta.ca.
ftp.openbsd.org is an alias for openbsd.sunsite.ualberta.ca.

I don't want' to waste OpenBSD mainsite bandwidth :)

I suppose I can find a work-around with FETCH_CMD, but it's against
OpenBSD "it-just-works" spirit...

Note : uname -a is OpenBSD beasty.etherspace.run 4.0 GENERIC#1237 i386

Best regards,

Bruno.



We grant you Post of A Representative in our Company. Financial Corporation.

2006-11-28 Thread Athens Financial Group
Dear Applicant,
 
We did have a vacancy for you in our Reputable organisation as a Financial 
Manager working with private Individuals. (Athens Financial Group). 

Athens Financial Group was registered far back as 1997. Our primary focus of 
AFG is international finances services, mainly through the Internet and other 
communication channels .The corporation is interested in working on the markets 
of all countries without exceptions and sees promotion of its services through 
the network of representatives (Independent Investment Consultants) working as 
private individuals or resident company employees as most effective. We also 
provide a full range of financial services to companies and to individuals as 
well. In Addition we grant credits to individual and companies on the 
international level, and this list of our services and opportunity is far to be 
complete. 

We are glad to offer you to : 
* Become a part of our company
* Join a team of highly qualified specialists
* Get a prestigious part time job while you dont loose your present job
* Earn a real fortune 

The main advantages of working as a Financial Manager dealing with private 
individuals are: 
* You dont need any experience or specifice knowledge
* You dont need to make any advance payment or pay for any fees.
* This job wont take much of your time. Its between 2 - 3 hours in one week. 

Your range of duties will include :
* Receiving payment for the ordered stocks and bonds from AFG clients
  ( Private Individuals) to your Bank Account. 
* Withdrawing the funds and transfering them further to our brokers in one of 
the 
  countries where the desirable stocks and bonds be bought. 
* The transfer should be done by the means of Western Union Money Transfer to 
  fasten the process of the delivery of the funds. 
* Your salary is 8-9 % commission out of every deposit that you receive to your 
Bank 
  Account. 

If you are interested in this offer you can get more information on our website 
at : 
www.athens-financial-group.com/ 

We look forward to working with you !!! 

Athina Ioannou
Vacancy Department 
Athens Financial Group.
E-mail : [EMAIL PROTECTED]



Re: trouble with IPv6 address with pkg_add(1)

2006-11-28 Thread Marcus Popp
On 2006-11-28T19:40, Bruno Carnazzi wrote:
>   Hi all,
> 
> When using 
> PKG_PATH=ftp://ftp.freenet.de/pub/ftp.openbsd.org/pub/OpenBSD/snapshots/packages/i386
> with pkg_add(1), updating package with "sudo pkg_add -ui -F update -F
> updatedepends" fails, saying "no package in PKG_PATH". When using
> PKG_PATH=ftp://ftp.openbsd.org/pub/OpenBSD/snapshots/packages/i386,
> everything work fine. As both path includes exactly the same packages,
> I expect there is a trouble with IPv6 adress (I go through a IPv4
> NAT-box, and my LAN is IPv4-only) :
I don't think this problem is caused by IPv6.
Have you tried adding a slash, as stated in man 1 pkg_add, to the
PKG_PATH?
like 
PKG_PATH=ftp://ftp.freenet.de/pub/ftp.openbsd.org/pub/OpenBSD/snapshots/packages/i386/

so long,

Marcus.



Re: OpenBSD with Yahoo DSL

2006-11-28 Thread Emilio Perea
On Tue, Nov 21, 2006 at 09:13:30AM -0800, Pawel S. Veselov wrote:
> I was wondering if anyone was able to create Yahoo login/password without
> running their CD. As I understand, the DSL installation CD just knows which
> servers to go to to associate the phone line with the account information, 
> lets
> you create the user/password, and then stores user/password into the modem
> (it's a new modem that handles pppoe internally). I guess this shouldn't be
> impossible, as long as one knows which web site to go to for that account
> creation part...

You have probably been online for a week now, but just in case somebody
else runs into this problem, you can use https://sbcreg.sbcglobal.net/
to pick a user name and password to "register" the DSL line.  It will
then attempt to install their software, at which point you bail out.

That does not have to be done on the DSL line, but if that's the only
connection you have and it's pppoe, you can use the temporary
registration-only user name and password which is probably already in
your modem:

 Username: [EMAIL PROTECTED]
 Password: sbcyahooreg

After the line is registered go back and put in the username and
password you chose.

Emilio



Re: iwi0 connection frustration

2006-11-28 Thread Bruno Carnazzi

2006/11/28, Vim Visual <[EMAIL PROTECTED]>:

As I wrote in the previous email, I have pkg_add'ed the damien firmware.

this means that I did

sudo pkg_add 
http://damien.bergamini.free.fr/packages/openbsd/iwi-firmware-3.0.tgz

the files

/etc/firmware/iwi-license
/etc/firmware/iwi-boot
/etc/firmware/iwi-bss
/etc/firmware/iwi-ibss
/etc/firmware/iwi-monitor
/etc/firmware/iwi-ucode-bss
/etc/firmware/iwi-ucode-ibss
/etc/firmware/iwi-ucode-monitor

are there and dmesg | grep iwi tells me that the adpater has been
recognized during the boot process; what's more, I get *something*
like

# ifconfig iwi0
iwi0: flags=8802 mtu 1500
address: xx:xx:xx:xx:xx:xx
nwid ""
media: IEEE802.11 autoselect
status: no network


Maybe
# ifconfig iwi0 up
?



but I am missing the "powersave" line. I don't know whether this is
related to the problem.

It cannot be a hardware problem because the crashbox with the debian
variant ubuntu recognised the chip and I was able to connect to my
nwid

I am wondering whether this has something to do with the encryption
bit rate... I see that the maximum is 104-bit and I don't remember
which rate I chose (the wlan modem is at home, I am in the office now)

Mmmh... maybe I should try to switch off the wep and see what happens...

2006/11/28, Der Engel <[EMAIL PROTECTED]>:
> Did you install the firmware?
>
> On 11/28/06, Vim Visual <[EMAIL PROTECTED]> wrote:
> > Hi,
> >
> > I am still testing a "crashbox" (not bad, from zero to a full OpenBSD
> > system including port trees in less than a week, my first OpenBSD system :) 
)
> > but I have now an issue with the wlan connection. The card is an Intel
> > PRO/Wireless
> > 2200BG
> >
> > First of all: I have read the man pages (good boy, good boy! arf, arf!)
> >
> > My net:
> >
> > nwid: pepitogrillo
> >
> > nwkey: eltrenloco
> >
> > (hahaha!)
> >
> > I have pkg_add'ed the damien firmware.
> >
> > But still I cannot connect. My command line is
> >
> > sudo ifconfig iwi0 nwkey eltrenloco nwid pepitogrillo
> >
> > (I hope that the order of the factors doesn't alter the product! Is
> > iwi an abelian group? )
> >
> > and then
> >
> > sudo dhclient iwi0
> >
> > After the first DHCPDISCOVER on iwi0 to 255.255.255.255 I get
> > "send_packet: No buffer space available", this goes on some 12 times
> > and then No DHCPOFFERS received and No working leases in presistent
> > database - sleeping
> >
> > I cannot show you dmesg because, as a matter of fact, the crashbox
> > doesn't have connection :) And I don't feel like typping everything!
> >
> > Trying it via /etc/hostname.iwi0 doesn't help
> >
> > Any hint? (I am sure yes!)
> >
> > thanks in advance,
> >
> > Pau
> >
> > PS: The "send_packet: No buffer space available" disappears after a
> > sudo ifconfig iwi0 down, sudo ifwonfig iwi0 up




Jacek Artymiak

2006-11-28 Thread Siju George

Hi,

If anyone is in touch with Jacek Artymiak ( the PF book author ) or
know anything about his health Please let me know.

Thank you so much

Kind Regards

Siju



ftp-proxy clarification

2006-11-28 Thread Ryan Corder
Greetings misc@

I'm hoping this hasn't been answered before, but I need a little
clarification as to the operation of ftp-proxy.

We all know that ftp-proxy, when properly configured in your
firewall, will redirect all traffic to a remote server on port 21 to
localhost 8021 (by default) and actually establish the connection to the
remote server from itself on the firewall.  What I'm not clear on is the
connection(s) to the remote FTP server on the high ports for a passive
FTP transfer.

I don't implicitely allow either inbound or outbound traffic, so
what I need to know is where the traffic for the high ports of FTP
(49151 - 65535) originate.  Do they 1) originate from ftp-proxy thus
needing a rule to allow 49151-65535 from the IP address of the firewall,
or 2) originate from the client machine and therefore need a rule to
allow 49151-65535 from the IP address of the client machine?

While the PF User Guide is truly an excellent document, it seems to
assume that you allow all outound traffic, so it only instructs you to
add a couple of anchors and a redirect rule.  Do I need an additional
outbound 'pass' rule for FTP high ports, or does ftp-proxy handle all of
that via the anchors?

thanks in advance.
ryanc

--
Ryan Corder <[EMAIL PROTECTED]>
Systems Engineer, NovaSys Health LLC.
501-219- ext. 646

[demime 1.01d removed an attachment of type application/pgp-signature which had 
a name of signature.asc]



Re: trouble with IPv6 address with pkg_add(1)

2006-11-28 Thread Bruno Carnazzi

2006/11/28, Marcus Popp <[EMAIL PROTECTED]>:

On 2006-11-28T19:40, Bruno Carnazzi wrote:
>   Hi all,
>
> When using
> 
PKG_PATH=ftp://ftp.freenet.de/pub/ftp.openbsd.org/pub/OpenBSD/snapshots/packages/i386
> with pkg_add(1), updating package with "sudo pkg_add -ui -F update -F
> updatedepends" fails, saying "no package in PKG_PATH". When using
> PKG_PATH=ftp://ftp.openbsd.org/pub/OpenBSD/snapshots/packages/i386,
> everything work fine. As both path includes exactly the same packages,
> I expect there is a trouble with IPv6 adress (I go through a IPv4
> NAT-box, and my LAN is IPv4-only) :
I don't think this problem is caused by IPv6.
Have you tried adding a slash, as stated in man 1 pkg_add, to the
PKG_PATH?


I'm updating... :)

But I don't think the backslash is the problem, as in second case,
everything works fine (without backslash)...


like 
PKG_PATH=ftp://ftp.freenet.de/pub/ftp.openbsd.org/pub/OpenBSD/snapshots/packages/i386/

so long,

Marcus.




Re: Jacek Artymiak

2006-11-28 Thread Henning Brauer
* Siju George <[EMAIL PROTECTED]> [2006-11-28 17:56]:
> If anyone is in touch with Jacek Artymiak ( the PF book author ) or
> know anything about his health Please let me know.

apparently he's fine, mailed me a few days ago

-- 
Henning Brauer, [EMAIL PROTECTED], [EMAIL PROTECTED]
BS Web Services, http://bsws.de
Full-Service ISP - Secure Hosting, Mail and DNS Services
Dedicated Servers, Rootservers, Application Hosting - Hamburg & Amsterdam



Re: Correct dev config for apache chroot? OpenBSD 4.0

2006-11-28 Thread Joachim Schipper
On Tue, Nov 28, 2006 at 02:15:58PM +, Conrad Winchester wrote:
> On 11/27/06, Joachim Schipper <[EMAIL PROTECTED]> wrote:
> > On Mon, Nov 27, 2006 at 07:06:51PM +, Conrad Winchester wrote:
> > > >Conrad Winchester 27-Nov-06 08:23
> > > >>I am tryng to chroot apache 2.2
> > > What is the proper way to create a /dev/crypto node?
> >
> > /dev/crypto is only for hardware-accelerated crypto. Are you really
> > sure you should use it?
> >
> > Also, check for the nodev mount flag.

> the /dev/crypto requirement seems to come for free when you build apache on
> openBSD. Reading up on it it should fall over gracefully to software when
> you don't have hardware support.
> 
> I don't think this is the problem anymore because I can still run chrooted
> apache in non-daemon mode.

I wouldn't know about that, but would like to point you to the second
item from my earlier post.

Joachim



Re: trouble with IPv6 address with pkg_add(1)

2006-11-28 Thread Marcus Popp
On 2006-11-28T20:58, Bruno Carnazzi wrote:
...
> >I don't think this problem is caused by IPv6.
> >Have you tried adding a slash, as stated in man 1 pkg_add, to the
> >PKG_PATH?
> 
> I'm updating... :)
> 
> But I don't think the backslash is the problem, as in second case,
> everything works fine (without backslash)...
very likely these are different ftp-servers (application) with differnt
configurations => different behavior.

so long,

Marcus.



Re: Carp source routing ?

2006-11-28 Thread Pedro Hugo
Hello,

> - Don't configure an address on the carp device's parent interface (only
>   applies if the carp devices is then the route to the other endpoint)

This one worked the way I wanted !
I finally have a working carp to carp High Availabity & Synchronized ipsec
tunnel :)

And it seems to work very well !!!

Very nice work with carp! Congrats :)

Thanks for the help,
Pedro



Re: trouble with IPv6 address with pkg_add(1)

2006-11-28 Thread Bruno Carnazzi

2006/11/28, Marcus Popp <[EMAIL PROTECTED]>:

On 2006-11-28T20:58, Bruno Carnazzi wrote:
...
> >I don't think this problem is caused by IPv6.
> >Have you tried adding a slash, as stated in man 1 pkg_add, to the
> >PKG_PATH?


You are right : adding an ending slash did the trick.

Thank you and sorry for the noise...


>
> I'm updating... :)
>
> But I don't think the backslash is the problem, as in second case,
> everything works fine (without backslash)...
very likely these are different ftp-servers (application) with differnt
configurations => different behavior.

so long,

Marcus.




Re: Jacek Artymiak

2006-11-28 Thread Chris 'Xenon' Hanson

Henning Brauer wrote:

* Siju George <[EMAIL PROTECTED]> [2006-11-28 17:56]:

If anyone is in touch with Jacek Artymiak ( the PF book author ) or
know anything about his health Please let me know.

apparently he's fine, mailed me a few days ago


  Tell him we're all eagerly awaiting an updated printing of his book. ;)

--
 Chris 'Xenon' Hanson | Xenon @ 3D Nature | http://www.3DNature.com/
 "I set the wheels in motion, turn up all the machines, activate the programs,
  and run behind the scenes. I set the clouds in motion, turn up light and 
sound,
  activate the window, and watch the world go 'round." -Prime Mover, Rush.



Re: iwi0 connection frustration

2006-11-28 Thread Vim Visual

ahem... I did this, of course...

2006/11/28, Bruno Carnazzi <[EMAIL PROTECTED]>:

2006/11/28, Vim Visual <[EMAIL PROTECTED]>:
> As I wrote in the previous email, I have pkg_add'ed the damien firmware.
>
> this means that I did
>
> sudo pkg_add 
http://damien.bergamini.free.fr/packages/openbsd/iwi-firmware-3.0.tgz
>
> the files
>
> /etc/firmware/iwi-license
> /etc/firmware/iwi-boot
> /etc/firmware/iwi-bss
> /etc/firmware/iwi-ibss
> /etc/firmware/iwi-monitor
> /etc/firmware/iwi-ucode-bss
> /etc/firmware/iwi-ucode-ibss
> /etc/firmware/iwi-ucode-monitor
>
> are there and dmesg | grep iwi tells me that the adpater has been
> recognized during the boot process; what's more, I get *something*
> like
>
> # ifconfig iwi0
> iwi0: flags=8802 mtu 1500
> address: xx:xx:xx:xx:xx:xx
> nwid ""
> media: IEEE802.11 autoselect
> status: no network

Maybe
# ifconfig iwi0 up
?

>
> but I am missing the "powersave" line. I don't know whether this is
> related to the problem.
>
> It cannot be a hardware problem because the crashbox with the debian
> variant ubuntu recognised the chip and I was able to connect to my
> nwid
>
> I am wondering whether this has something to do with the encryption
> bit rate... I see that the maximum is 104-bit and I don't remember
> which rate I chose (the wlan modem is at home, I am in the office now)
>
> Mmmh... maybe I should try to switch off the wep and see what happens...
>
> 2006/11/28, Der Engel <[EMAIL PROTECTED]>:
> > Did you install the firmware?
> >
> > On 11/28/06, Vim Visual <[EMAIL PROTECTED]> wrote:
> > > Hi,
> > >
> > > I am still testing a "crashbox" (not bad, from zero to a full OpenBSD
> > > system including port trees in less than a week, my first OpenBSD system 
:) )
> > > but I have now an issue with the wlan connection. The card is an Intel
> > > PRO/Wireless
> > > 2200BG
> > >
> > > First of all: I have read the man pages (good boy, good boy! arf, arf!)
> > >
> > > My net:
> > >
> > > nwid: pepitogrillo
> > >
> > > nwkey: eltrenloco
> > >
> > > (hahaha!)
> > >
> > > I have pkg_add'ed the damien firmware.
> > >
> > > But still I cannot connect. My command line is
> > >
> > > sudo ifconfig iwi0 nwkey eltrenloco nwid pepitogrillo
> > >
> > > (I hope that the order of the factors doesn't alter the product! Is
> > > iwi an abelian group? )
> > >
> > > and then
> > >
> > > sudo dhclient iwi0
> > >
> > > After the first DHCPDISCOVER on iwi0 to 255.255.255.255 I get
> > > "send_packet: No buffer space available", this goes on some 12 times
> > > and then No DHCPOFFERS received and No working leases in presistent
> > > database - sleeping
> > >
> > > I cannot show you dmesg because, as a matter of fact, the crashbox
> > > doesn't have connection :) And I don't feel like typping everything!
> > >
> > > Trying it via /etc/hostname.iwi0 doesn't help
> > >
> > > Any hint? (I am sure yes!)
> > >
> > > thanks in advance,
> > >
> > > Pau
> > >
> > > PS: The "send_packet: No buffer space available" disappears after a
> > > sudo ifconfig iwi0 down, sudo ifwonfig iwi0 up




Re: [EMAIL PROTECTED]: ET1310 Documentation]

2006-11-28 Thread Emmanuel Jarri
They've just gained their place in the vendorwatch.org list, scored as
"unfriendly" ;)
http://vendorwatch.org/

On 11/28/06, Jonathan Gray <[EMAIL PROTECTED]> wrote:
>
> This is an example of us trying to talk to a vendor and
> being totally shut down. Not only did they license the PCI express and
> MAC portions, but they don't want to help us to support their products
> at all. No information, no people to talk to, nothing.
>
> - Forwarded message from "Ubowski, Richard M (Richard)" <
> [EMAIL PROTECTED]> -
>
> From: "Ubowski, Richard M (Richard)" <[EMAIL PROTECTED]>
> Date: Tue, 28 Nov 2006 09:41:36 -0500
> To: [EMAIL PROTECTED]
> Cc: "Soriano, Victor John (Vic)" <[EMAIL PROTECTED]>
> Subject: ET1310 Documentation
>
>
>
> Hi Jason,
> I forwarded your request to the Agere ET1310 Product Manager and a
> decision was made to not release the ET1310 documentation at this time.
> Appreciate your interest in developing an OpenBSD driver for the ET1310.
>
>
> The ET1310 GigE PHY is an Agere design and the Agere MAC was licensed
> from a 3rd party.
>
> Rgds,
> Rich Ubowski
> PCS Applications Manager
>
> -- Forwarded Message
> From: Jonathan Gray <[EMAIL PROTECTED]>
> Date: Wed, 29 Nov 2006 00:31:36 +1100
> To: Victor Soriano <[EMAIL PROTECTED]>
> Subject: Re: ET1310 datasheet
>
> On Mon, Nov 13, 2006 at 12:44:51PM -0500, Victor Soriano wrote:
> > Hi John,
> >
> > I'm Vic Soriano, a Sr. Software Engineer for Agere and the
> > author/maintainer of the Linux driver source code for the ET1310
> Gigabit MAC/PHY.
> >
> > I've copied our Applications Engineering Manager for the ET1310, Rich
> > Ubowski, on this email. He is currently looking into obtaining the
> > datasheets you've requested.
> >
> > In addition to documentation, I'm attaching the last release of the
> > ET1310 Linux driver for reference, as this might also help in your
> > porting or development efforts.
>
> Have you had a chance to find the documentation yet?
> I can't seem to manage to get MII access to return non zero values.
>
> It appears that the ET1310 design was initially based around a National
> cassini+ design?
>
> Jonathan
>
> -- End of Forwarded Message
>
> - End forwarded message -



Re: [EMAIL PROTECTED]: ET1310 Documentation]

2006-11-28 Thread Andreas Maus

Hi.

Thanks for the information.
If I see any of their products on a list for my customer
I will _strongly_ vote against their product - independant
of used the OS.

On 11/28/06, Jonathan Gray <[EMAIL PROTECTED]> wrote:

This is an example of us trying to talk to a vendor and
being totally shut down. Not only did they license the PCI express and
MAC portions, but they don't want to help us to support their products
at all. No information, no people to talk to, nothing.


Andreas.

--
Hobbes : Shouldn't we read the instructions?
Calvin : Do I look like a sissy?



Re: ftp-proxy clarification

2006-11-28 Thread Camiel Dobbelaar
On Tue, 28 Nov 2006, Ryan Corder wrote:
> While the PF User Guide is truly an excellent document, it seems to
> assume that you allow all outound traffic, so it only instructs you to
> add a couple of anchors and a redirect rule.  Do I need an additional
> outbound 'pass' rule for FTP high ports, or does ftp-proxy handle all of
> that via the anchors?

ftp-proxy handles all the data connections (passive and active) via the 
anchors.  You don't need to add extra rules.

That _should_ become clear from the manpage...  if not improvements are 
always welcome.  :-)

--
Cam



Processes getting out of hand

2006-11-28 Thread Jesse Gumm

Hello there,

I run an OpenBSD web server (still running 3.9), and I encounter an
unusual intermittent problem.  It runs Apache with php, and for the
most part it runs great with a load average of
around 3-5 processes.

Occasionally, however (every few days, lately), it freaks out and it
seems to try running everything at one time.

I leave "top" running so that I can see what's going on before it
starts to lock (it's not ACTUALLY locked, it's just running
ridiculously slowly), and just before it toasted most recently, this
was the status:

load averages: 168.48, 108.33, 54.01
257 processes: 179 running, 76 idle, 1 zombie, 1 on processor

Additionally the CPU States for each processor is at like 65% system
usage (this clearly sounds to me like the OS is just trying to juggle
the ridiculous number of running processes).  Generally speaking
though, the CPU Stats tends to hover around "20% system" which seems
unusually high to me.

So my question is rather general, I guess.

What should I be looking for that would prevent this from freaking out
like this?  I've tinkered with the login.conf and the apache
configurations, and I'm curious if there are other things I should
consider looking at.

Jesse
--
http://www.dkpsystem.com



Re: Processes getting out of hand

2006-11-28 Thread Jack J. Woehr
On Nov 28, 2006, at 12:04 PM, Jesse Gumm wrote:

>   It runs Apache with php

"With php", eh? Does one assume you have some kewl PHP code running
on your server (still chroot'ed?)? Might look at your code!

-- 
Jack J. Woehr
Director of Development
Absolute Performance, Inc.
[EMAIL PROTECTED]
303-443-7000 ext. 527



Re: Processes getting out of hand

2006-11-28 Thread L. V. Lammert
On Tue, 28 Nov 2006, Jack J. Woehr wrote:

> On Nov 28, 2006, at 12:04 PM, Jesse Gumm wrote:
>
> >   It runs Apache with php
>
> "With php", eh? Does one assume you have some kewl PHP code running
> on your server (still chroot'ed?)? Might look at your code!
>
Before you look at the code, you need to see which 179 processes are
active. I have seen exactly this sort of situation on a customer's machine
when their DNS was not responding and all of the mail processes were
hanging.

Once you see what is running, check the logs (assuming it's Apache) to see
what PAGE is running.

Look at that page should then give you a clue - is it accessing a
database? Sending email?

Lee


  Leland V. Lammert[EMAIL PROTECTED]
Chief Scientist Omnitec Corporation
 Network/Internet Consultants   www.omnitec.net




Re: ftp-proxy clarification

2006-11-28 Thread Mark Freeze

I also have a question regarding ftp proxy.   My situation is that we
have our firewall running, and I can connect and upload files to ftp
sites from any of my workstations. The problem occurs when we are
trying to download files.  When I connect my machine will negotiate
the connection and get a directory listing, but crash when I try to
download files from the site.   I know that it's the firewall because
my machines connect and download when the fw is taken out of the
process. I thought that maybe it was crashing when moving to an upper
port?  And, if that is the case how do I correct it?

What in my rule set would allow me to ftp upload a file, but crash on
the ftp download?

My pf.conf is listed below:

ext_if="fxp0"
dmz_if="rl1"  # RL1 not r11
int_if="rl0"

ext_ip_58="xx.xxx.xxx.58"
ext_ip_59="xx.xxx.xxx.59"
ext_ip_60="xx.xxx.xxx.60"
ext_ip_61="xx.xxx.xxx.61"
ext_ip_62="xx.xxx.xxx.62"
ext_ip_230="xx.xxx.xxx.230"

TCP_OPTIONS = "flags S/SAFRUP keep state"
accu_server_int="10.2.0.10"
jeff_int="10.2.0.11"
uncle_frank_int="10.2.0.12"

#accu_server_ports="{ 22, 80, 443, 110, 143, 993, 995, 25, 465, 4,
5, 6, 7, 8 }"
#jeff_ports="{ 22, 80, 443, 5900 }"
#uncle_frank_ports="{ 22, 80, 443, 5900 }"

#set skip on { lo $int_if }

scrub in

nat-anchor "ftp-proxy/*"
rdr-anchor "ftp-proxy/*"
rdr pass log on $int_if proto tcp from any to any port 21 -> 127.0.0.1 port 8021

nat on $ext_if from !($ext_if) -> ($ext_if:0)

binat pass on $ext_if from $jeff_int to any -> $ext_ip_59
binat pass on $ext_if from $uncle_frank_int to any -> $ext_ip_60
binat pass on $ext_if from $accu_server_int to any -> $ext_ip_230

anchor "ftp-proxy/*"
block in
pass out keep state

pass quick on { lo $int_if $dmz_if }

pass out log proto tcp from proxy to any port 21 keep state

# - Allow Ping
pass in quick on $ext_if proto icmp
pass out quick on $ext_if proto icmp
pass in quick on $dmz_if proto icmp

pass in quick on $int_if proto icmp
pass in on $ext_if proto tcp to ($ext_if) port ssh keep state
pass in log on $ext_if proto tcp to ($ext_if) port > 49151 user proxy keep state

Any help will be greatly appreciated. (Plus, if you see any other
craziness in the rules please let me know!)

Thanks,
Mark.



On 11/28/06, Camiel Dobbelaar <[EMAIL PROTECTED]> wrote:

On Tue, 28 Nov 2006, Ryan Corder wrote:
> While the PF User Guide is truly an excellent document, it seems to
> assume that you allow all outound traffic, so it only instructs you to
> add a couple of anchors and a redirect rule.  Do I need an additional
> outbound 'pass' rule for FTP high ports, or does ftp-proxy handle all of
> that via the anchors?

ftp-proxy handles all the data connections (passive and active) via the
anchors.  You don't need to add extra rules.

That _should_ become clear from the manpage...  if not improvements are
always welcome.  :-)

--
Cam




Re: Baffling problem with OBSD-protected servers and Windows Vista...

2006-11-28 Thread Reverend Deuce

Okay guys, I posted that long message about Firefox/etc on Windows
Vista a couple of days ago.

After I re-read my post and looked at the tcpdump output, and chatting
with a friend of mine who also runs several OBSD firewalls at his
company which exhibited the same EXACT problem when my Vista installs
attempted to connect... I think we've figured it out.

I remember that Vista (and presumably Longhorn Server) have a
completely re-written TCP stack by Microsoft. They've put in all kinds
of new stuff. One of which is Receive Window Auto-Tuning.

I noticed in my tcpdump the following lines:


From Opera/Firefox:


20:40:45.824144 my.workstation.ip.49370 > remote.server.ip.80: S
1215871830:1215871830(0) win 8192  (DF)
20:38:25.198320 remote.server.ip.80 > my.workstation.ip.49357: S
852828096:852828096(0) ack 643900712 win 64240 


From IE 7:


20:39:08.834465 my.workstation.ip.49358 > remote.server.ip.80: S
4155969795:4155969795(0) win 8192  (DF)
20:39:08.835095 remote.server.ip.80 > my.workstation.ip.49358: S
3294485308:3294485308(0) ack 4155969796 win 64240 

Notice the window scale is 2 for IE, and 8 for Firefox/Opera.


From the following MS blog @

http://www.microsoft.com/technet/community/columns/cableguy/cg1105.mspx
:

Note: Some Internet gateway devices and firewalls block packet flows
because they do not correctly interpret the scaling factor used in TCP
connections. Because of this, Internet Explorer in Windows Vista uses
an initial scaling factor of 2. Other applications use a default
initial scaling factor of 8.

After doing the new Vista-equivilent of sudo and elevating my command
shell to Administrator mode, I was able to use the following command
to disable window scaling completely:

C:\windows\system32> netsh interface tcp set global autotuninglevel=disabled

Once I performed this command, Firefox/Opera/Remote Desktop Connection
all function once more as expected.

Now, as I am clearly looking at the window scale issue here, I had
found a thread at
http://archive.openbsd.nu/?ml=openbsd-pf&a=2006-07&t=2147873 where
Daniel Hartmeier comments there are three things that need to be done
to have state created correctly:

 a) there is a default block policy
 b) all 'pass' rules that can match TCP have 'flags S/SA'
 c) all 'pass' rules have 'keep state'

Here is what I am seeing inside PF with the connections in question:

Nov 26 23:09:36.970856 rule 80/(match) pass in on fxp1:
my.workstation.ip.59970 > remote.server.ip.443: [|tcp] (DF)

Then if I pull the 80th rule out:

@80 pass in log quick on fxp1 inet proto tcp from any to
remote.server.ip port = https flags S/SA keep state label "ExchangeIn"

Now, I can easily see that I am matching B and C of Daniel's list,
however A is a bit more in question from my point of view.

The rules I do have are:

@47 block drop in log on fxp1 all label "DefaultBlock"

@48 block return-rst in log on fxp1 proto tcp all label "DefaultBlock"

@49 block return-icmp(port-unr, port-unr) in log on fxp1 proto udp all
label "DefaultBlock"

So, it appears I have condition A matched as well. I do have a line regarding:

@95 pass in quick on fxp0 inet proto tcp from  to any flags
S/SA keep state label "lanOUT"

That should not come into play here at all, as again it is creating
state on a Syn, not a Syn Ack.

However, after testing on this system, I am thinking I am filtering
wrong here. Here is what I have found as the full story of what is
going on:

Connection is open:

Nov 27 12:09:07.978281 rule 80/(match) pass in on fxp1:
my.workstation.ip.62658 > remote.server.ip.443: [|tcp] (DF)

Two state entries are created:

all tcp remote.server.ip:443 <- remote.server.ip:443 <-
my.workstation.ip:62658   ESTABLISHED:ESTABLISHED
  [4265902579 + 65535]  [1356591875 + 65535]
  age 00:01:08, expires in 119:59:09, 12:9 pkts, 2014:5401 bytes, rule 80
  id: 453e890500b00c1e creatorid: 19ad04b2
all tcp my.workstation.ip:62658 <- remote.server.ip:443
ESTABLISHED:ESTABLISHED
  [1356591875 + 65535]  [4265902579 + 65535]
  age 00:01:08, expires in 119:59:09, 9:11 pkts, 5401:1966 bytes, rule 96
  id: 453e890500b00c1f creatorid: 19ad04b2

Rules that match the state entries:

@80 pass in log quick on fxp1 inet proto tcp from any to
remote.server.ip port = https flags S/SA keep state label "ExchangeIn"
 [ Evaluations: 5000  Packets: 204   Bytes: 50906   States: 5 ]
 [ Inserted: uid 0 pid 806 ]
@95 pass in quick on fxp0 inet proto tcp from  to any flags
S/SA keep state label "lanOUT"
 [ Evaluations: 417330Packets: 60770372  Bytes: 36986041704  States: 771  ]
 [ Inserted: uid 0 pid 6307 ]
@96 pass in quick on fxp0 from  to any keep state label "lanOUT"
 [ Evaluations: 429312Packets: 9560597   Bytes: 5957780712  States: 135   ]
 [ Inserted: uid 0 pid 6307 ]

Now, it is looking to me like the issue is a second state entry is
created by that rule 96. When it is modified to be only protocol UDP,
traffic through the FW stops due to the rules:

block in  log   

Boot above cylinder 1024

2006-11-28 Thread Brian Candler
I've recently installed OpenBSD 4.0 on two machines in spare space at the
end of the disk.

It turns out that OpenBSD is unbootable if the root filesystem starts above
cylinder 1024. However, this isn't a problem for FreeBSD; I guess it makes
use of newer BIOS calls.

I can still boot OpenBSD on these machines, by using the cd40.iso CDROM or a
USB pen containing cdrom40.fs, and typing "boot hd0a:/bsd" or "boot
hd1a:/bsd" at the boot> prompt. However this is a bit ugly.

So I was wondering, are the OpenBSD and FreeBSD boot processes similar
enough that I could use the FreeBSD boot loader (first and/or second stage)
to boot OpenBSD? And if so, has anyone got a recipe for this that they would
care to share?

Thanks,

Brian.



Which tools the OpenBSD developers are using?

2006-11-28 Thread Alvaro Mantilla Gimenez

Hi OpenBSD developers,


  Which are your preferred tools for develop? (For C, C++, Java, 
etcno matter the language)


  It is good to know which tools and why...


  Thanks,


  Alvaro



Re: iwi0 connection frustration

2006-11-28 Thread Vim Visual

I said I was writing blindly because the laptop was at home but, of
course, after an ifconfig iwi0 up I get the correct flag there... UP

2006/11/28, Vim Visual <[EMAIL PROTECTED]>:

ahem... I did this, of course...

2006/11/28, Bruno Carnazzi <[EMAIL PROTECTED]>:
> 2006/11/28, Vim Visual <[EMAIL PROTECTED]>:
> > As I wrote in the previous email, I have pkg_add'ed the damien firmware.
> >
> > this means that I did
> >
> > sudo pkg_add 
http://damien.bergamini.free.fr/packages/openbsd/iwi-firmware-3.0.tgz
> >
> > the files
> >
> > /etc/firmware/iwi-license
> > /etc/firmware/iwi-boot
> > /etc/firmware/iwi-bss
> > /etc/firmware/iwi-ibss
> > /etc/firmware/iwi-monitor
> > /etc/firmware/iwi-ucode-bss
> > /etc/firmware/iwi-ucode-ibss
> > /etc/firmware/iwi-ucode-monitor
> >
> > are there and dmesg | grep iwi tells me that the adpater has been
> > recognized during the boot process; what's more, I get *something*
> > like
> >
> > # ifconfig iwi0
> > iwi0: flags=8802 mtu 1500
> > address: xx:xx:xx:xx:xx:xx
> > nwid ""
> > media: IEEE802.11 autoselect
> > status: no network
>
> Maybe
> # ifconfig iwi0 up
> ?
>
> >
> > but I am missing the "powersave" line. I don't know whether this is
> > related to the problem.
> >
> > It cannot be a hardware problem because the crashbox with the debian
> > variant ubuntu recognised the chip and I was able to connect to my
> > nwid
> >
> > I am wondering whether this has something to do with the encryption
> > bit rate... I see that the maximum is 104-bit and I don't remember
> > which rate I chose (the wlan modem is at home, I am in the office now)
> >
> > Mmmh... maybe I should try to switch off the wep and see what happens...
> >
> > 2006/11/28, Der Engel <[EMAIL PROTECTED]>:
> > > Did you install the firmware?
> > >
> > > On 11/28/06, Vim Visual <[EMAIL PROTECTED]> wrote:
> > > > Hi,
> > > >
> > > > I am still testing a "crashbox" (not bad, from zero to a full OpenBSD
> > > > system including port trees in less than a week, my first OpenBSD 
system :) )
> > > > but I have now an issue with the wlan connection. The card is an Intel
> > > > PRO/Wireless
> > > > 2200BG
> > > >
> > > > First of all: I have read the man pages (good boy, good boy! arf, arf!)
> > > >
> > > > My net:
> > > >
> > > > nwid: pepitogrillo
> > > >
> > > > nwkey: eltrenloco
> > > >
> > > > (hahaha!)
> > > >
> > > > I have pkg_add'ed the damien firmware.
> > > >
> > > > But still I cannot connect. My command line is
> > > >
> > > > sudo ifconfig iwi0 nwkey eltrenloco nwid pepitogrillo
> > > >
> > > > (I hope that the order of the factors doesn't alter the product! Is
> > > > iwi an abelian group? )
> > > >
> > > > and then
> > > >
> > > > sudo dhclient iwi0
> > > >
> > > > After the first DHCPDISCOVER on iwi0 to 255.255.255.255 I get
> > > > "send_packet: No buffer space available", this goes on some 12 times
> > > > and then No DHCPOFFERS received and No working leases in presistent
> > > > database - sleeping
> > > >
> > > > I cannot show you dmesg because, as a matter of fact, the crashbox
> > > > doesn't have connection :) And I don't feel like typping everything!
> > > >
> > > > Trying it via /etc/hostname.iwi0 doesn't help
> > > >
> > > > Any hint? (I am sure yes!)
> > > >
> > > > thanks in advance,
> > > >
> > > > Pau
> > > >
> > > > PS: The "send_packet: No buffer space available" disappears after a
> > > > sudo ifconfig iwi0 down, sudo ifwonfig iwi0 up




Re: iwi0 connection frustration

2006-11-28 Thread Vim Visual

Gosh, I don't understand anything. I am sorry that I am overwhelming
your inboxes today but

1- I tried to make the nwid visible (it's possible to make it invisible)

2- I also tried to switch off the wep key

and _nothing_

But the wlan CAN scan the networks! When I type ifconfig -M iwi0 I get
the usual neighbour's access points and mine! It's only that protocol
doesn't get a DHCPOFFER

I am writing this email from a debian laptop connected to my network
and the funny thing is that the wlan chip is the same one...

any hint?

I want to totally move to O'bsd but wlan connection is crucial for me
and it's the only thing that's stopping me to install obsd on the
production laptop, I'm bored of the crashbox, now I want to make the
Move

Cheers,

Pau

2006/11/28, Vim Visual <[EMAIL PROTECTED]>:

I said I was writing blindly because the laptop was at home but, of
course, after an ifconfig iwi0 up I get the correct flag there... UP

2006/11/28, Vim Visual <[EMAIL PROTECTED]>:
> ahem... I did this, of course...
>
> 2006/11/28, Bruno Carnazzi <[EMAIL PROTECTED]>:
> > 2006/11/28, Vim Visual <[EMAIL PROTECTED]>:
> > > As I wrote in the previous email, I have pkg_add'ed the damien firmware.
> > >
> > > this means that I did
> > >
> > > sudo pkg_add 
http://damien.bergamini.free.fr/packages/openbsd/iwi-firmware-3.0.tgz
> > >
> > > the files
> > >
> > > /etc/firmware/iwi-license
> > > /etc/firmware/iwi-boot
> > > /etc/firmware/iwi-bss
> > > /etc/firmware/iwi-ibss
> > > /etc/firmware/iwi-monitor
> > > /etc/firmware/iwi-ucode-bss
> > > /etc/firmware/iwi-ucode-ibss
> > > /etc/firmware/iwi-ucode-monitor
> > >
> > > are there and dmesg | grep iwi tells me that the adpater has been
> > > recognized during the boot process; what's more, I get *something*
> > > like
> > >
> > > # ifconfig iwi0
> > > iwi0: flags=8802 mtu 1500
> > > address: xx:xx:xx:xx:xx:xx
> > > nwid ""
> > > media: IEEE802.11 autoselect
> > > status: no network
> >
> > Maybe
> > # ifconfig iwi0 up
> > ?
> >
> > >
> > > but I am missing the "powersave" line. I don't know whether this is
> > > related to the problem.
> > >
> > > It cannot be a hardware problem because the crashbox with the debian
> > > variant ubuntu recognised the chip and I was able to connect to my
> > > nwid
> > >
> > > I am wondering whether this has something to do with the encryption
> > > bit rate... I see that the maximum is 104-bit and I don't remember
> > > which rate I chose (the wlan modem is at home, I am in the office now)
> > >
> > > Mmmh... maybe I should try to switch off the wep and see what happens...
> > >
> > > 2006/11/28, Der Engel <[EMAIL PROTECTED]>:
> > > > Did you install the firmware?
> > > >
> > > > On 11/28/06, Vim Visual <[EMAIL PROTECTED]> wrote:
> > > > > Hi,
> > > > >
> > > > > I am still testing a "crashbox" (not bad, from zero to a full OpenBSD
> > > > > system including port trees in less than a week, my first OpenBSD 
system :) )
> > > > > but I have now an issue with the wlan connection. The card is an Intel
> > > > > PRO/Wireless
> > > > > 2200BG
> > > > >
> > > > > First of all: I have read the man pages (good boy, good boy! arf, 
arf!)
> > > > >
> > > > > My net:
> > > > >
> > > > > nwid: pepitogrillo
> > > > >
> > > > > nwkey: eltrenloco
> > > > >
> > > > > (hahaha!)
> > > > >
> > > > > I have pkg_add'ed the damien firmware.
> > > > >
> > > > > But still I cannot connect. My command line is
> > > > >
> > > > > sudo ifconfig iwi0 nwkey eltrenloco nwid pepitogrillo
> > > > >
> > > > > (I hope that the order of the factors doesn't alter the product! Is
> > > > > iwi an abelian group? )
> > > > >
> > > > > and then
> > > > >
> > > > > sudo dhclient iwi0
> > > > >
> > > > > After the first DHCPDISCOVER on iwi0 to 255.255.255.255 I get
> > > > > "send_packet: No buffer space available", this goes on some 12 times
> > > > > and then No DHCPOFFERS received and No working leases in presistent
> > > > > database - sleeping
> > > > >
> > > > > I cannot show you dmesg because, as a matter of fact, the crashbox
> > > > > doesn't have connection :) And I don't feel like typping everything!
> > > > >
> > > > > Trying it via /etc/hostname.iwi0 doesn't help
> > > > >
> > > > > Any hint? (I am sure yes!)
> > > > >
> > > > > thanks in advance,
> > > > >
> > > > > Pau
> > > > >
> > > > > PS: The "send_packet: No buffer space available" disappears after a
> > > > > sudo ifconfig iwi0 down, sudo ifwonfig iwi0 up




Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Bob Beck
* Alvaro Mantilla Gimenez <[EMAIL PROTECTED]> [2006-11-28 14:03]:
> Hi OpenBSD developers,
> 
> 
>   Which are your preferred tools for develop? (For C, C++, Java, 
> etcno matter the language)


Visual C++, .NET, and C sharp of course. Theo mandates
taht we  all to use only the 7337est toolz..



Re: Boot above cylinder 1024

2006-11-28 Thread Joachim Schipper
On Tue, Nov 28, 2006 at 08:49:43PM +, Brian Candler wrote:
> I've recently installed OpenBSD 4.0 on two machines in spare space at the
> end of the disk.
> 
> It turns out that OpenBSD is unbootable if the root filesystem starts above
> cylinder 1024. However, this isn't a problem for FreeBSD; I guess it makes
> use of newer BIOS calls.
> 
> I can still boot OpenBSD on these machines, by using the cd40.iso CDROM or a
> USB pen containing cdrom40.fs, and typing "boot hd0a:/bsd" or "boot
> hd1a:/bsd" at the boot> prompt. However this is a bit ugly.

Yes. All this is documented, though.

> So I was wondering, are the OpenBSD and FreeBSD boot processes similar
> enough that I could use the FreeBSD boot loader (first and/or second stage)
> to boot OpenBSD? And if so, has anyone got a recipe for this that they would
> care to share?

I know that GRUB should be able to do this, although I've never tried
that. I presume any bootloader that can be persuaded to load another and
then hand off execution (chain-loading in GRUB terms) could be used.

Joachim



black fdisk/partition sorcery with usb external disks

2006-11-28 Thread frantisek holop
hi there,

i have bought a very nice little 160GB external usb disk.
i have left the fat32 partition in place, except that i made
it 8G shorter and have put ffs in there for openbsd backup
purposes.  hotplugd mounted both partitions fine, i worked
with it for some time.  today i started getting strange
errors from windows when copying to the fat32 partition,
namely "sector not found" and "disk is full" messages.

chkdsk said all is fine.  i was puzzled.  so i opened
partitionmagic which greeted me with the following errors:

"PowerQuest PartitionMagic has detected an error 116 on the partition
starting at sector 295804656 on disk2.

the starting LBA value is 295894656 and the CHS value is 16434495.
the LBA and CHS values must be equal.

PowerQuest PartitionMagic has verified that the LBA value is correct
and can fix the CHS value.

fix this error?"

after hitting [yes], another one:

"PowerQuest PartitionMagic has detected an error 110 on the partition
starting at sector 63 on disk2.

the length of the partition in the partition table is incorrect.
the CHS length is 295789725, the LBA length is 295804593, and the
File System length is 295804593.

PowerQuest PartitionMagic has determined that the length can be changed
to the correct value of 295804782.

fix this error?"

after "fixing" these errors the first partition became "BAD" and the second
unusable.  using the storage manager in windows i deleted the openbsd
partition and everything went back to normal.  almost normal.
i could recreate the partition and i did, but a fat32 this time.
i found out that it doesn't matter, if the disk is mounted under
openbsd the partition table becomes corrupted.



this is were i looked at the disks from openbsd and using partitioninfo
a utility by powerquest.  i was quite surprised:


this is my wd0 in my notebook:

amaaq> fdisk wd0
Disk: wd0   geometry: 9729/255/63 [156296385 Sectors]
Offset: 0   Signature: 0xAA55
 Starting   Ending   LBA Info:
 #: idC   H  S -C   H  S [   start:  size   ]

 0: 070   1  1 - 1977 254 63 [  63:31776507 ] HPFS/QNX/AUX
 1: 0C 1978   0  1 - 8198 254 63 [31776570:99940365 ] Win95 FAT32L
*2: A6 8199   0  1 - 9728 254 63 [   131716935:24579450 ] OpenBSD
 3: 000   0  0 -0   0  0 [   0:   0 ] unused


powerquest:
===
Disk Geometry Information for Disk 1:9729 Cylinders,  255 Heads,  63 
Sectors/Track
System  PartSect  # Boot BCyl Head Sect  FSECyl Head Sect
StartSect NumSects
===
   0  0  80 011  071977  254   63   
63   31,776,507
   0  1  00  197801  0C8198  254   63   
31,776,570   99,940,365
   0  2  00  819901  A69728  254   63  
131,716,935   24,579,450

peace and harmony -- everything the same.


now here is my new toy (indenting the fdisk for readability):

amaaq> fdisk sd0
fdisk: sysctl(machdep.bios.diskinfo): Device not configured
Disk: sd0   geometry: 152627/64/32 [312581808 Sectors]
Offset: 0   Signature: 0xAA55
 Starting   Ending   LBA Info:
 #: id  C   H  S -  C   H  S [   start:  size   ]

*0: 0C  0   1 32 - 144435  55 16 [  63:   295804593 ] Win95 FAT32L
 1: 0C 144435  55 17 - 152627  53 16 [   295804656:16777152 ] Win95 FAT32L
 2: 00  0   0  0 -  0   0  0 [   0:   0 ] unused
 3: 00  0   0  0 -  0   0  0 [   0:   0 ] unused

where is my nice */255/63 geometry i thought at this point...
these partitions are definitely not on CHS boundaries...

funny thing is, even partitioninfo barfed and came up with an entirely
different geometry (but "aligned" the partitions to CHS boundary):

===
Disk Geometry Information for Disk 2:   310,101 Cylinders,  16 Heads,  63 
Sectors/Track
System  PartSect  # Boot BCyl Head Sect  FSECyl Head Sect
StartSect NumSects
===
   0  0  80 011  0C 293,456   15   63   
63  295,804,593
   0  1  00 293457   01  0C 310,100   15   63  
295,804,656   16,777,152

at this point i had to do the "repairing" dance again, deleting the second
partition, chkdsk, recreating the partition in partitionmagic, then i replugged
the disk, and this seemed much better:

===

Re: iwi0 connection frustration

2006-11-28 Thread Fred Crowson

Vim Visual wrote:

Gosh, I don't understand anything. I am sorry that I am overwhelming
your inboxes today but

1- I tried to make the nwid visible (it's possible to make it invisible)

2- I also tried to switch off the wep key

and _nothing_

But the wlan CAN scan the networks! When I type ifconfig -M iwi0 I get
the usual neighbour's access points and mine! It's only that protocol
doesn't get a DHCPOFFER

I am writing this email from a debian laptop connected to my network
and the funny thing is that the wlan chip is the same one...

any hint?

I want to totally move to O'bsd but wlan connection is crucial for me
and it's the only thing that's stopping me to install obsd on the
production laptop, I'm bored of the crashbox, now I want to make the
Move

Cheers,

Pau



Hi Pau,

have you tried putting something like:

dhcp NONE NONE NONE \
nwid pepitogrillo nwkey eltrenloco

in your hostname.iwi0 file and then using:

/bin/sh -x /etc/netstart iwi0

to restart the interface?

I have had an issue with an ipw0 Intel Pro 2100 that would only clear 
its wifi connection on reboot, with the appropriate hostname.if just 
uping and downing the interface was not clearing the nwkey.


HTH

Fred
--
OpenBSD on the Zaurus C3200
http://www.crowsons.net/puters/zaurus.php



Bob GreyScanner life excitements

2006-11-28 Thread Daniel Ouellet
I just wanted to pass some update on this and also to pass my thanks fro 
Bob great work on spamd and greyscanner work.


I discover the greyscanner from the presentation Bob did a few weeks ago 
and install it to test it and give it a good run!


I started to run it with my very long lists of rdbl filter. The results 
were impressive.


I then remove more and more of the rdbl lists.

I now only use Bob lists from the University as a start and that's it.

I then finally added about 50+ domains that really have no valid email 
accounts to them in the greyscanner setup.


Then I also install it on the ISP side of the house for my customers.

I also configure some white lists based on the proper whitelisting and 
also use some limited spf lists as well.


So far the results as drastic no less!

For my own business accounts, I used to get close to one thousand spam a 
day without filters. A few hundred with a good list of rdbl. Under 100 
with spamd, most likely around 50+ per day.


Now in the last 4 days, I have got NONE!

Adding a long lists of fake email address in spamd and a long lists of 
spare domains in greyscanner without any rdbl lists what so ever I get 
no more spam!



I am not sure how long this will last for sure and I am also working on 
installing LDAP support as well for the greyscanner too!


This is the best ever so far!

Many thanks Bob!!!

I sure hope this make it in the default setup in 4.1 as this is just 
incredible!


Almost better then Sex! And sometimes I think it's even better when I 
see the results!


As for my customers!

No one complain at all so far. No lost emails what so ever, no more 
problem with Verizon either and the only calls we get is from users 
asking of the mail servers are working properly as they don't get full 
mail box anymore and are nervous to loose emails, but none have been 
lost yet!


If you are not running greyscanner with a lists of spamtrap emails 
account and a few spare domains you don't need in your setup, you are 
loosing big here.


It is definitely worth the investments!

Best,

Daniel.

PS: I can call myself spam free for a few days now. Will see how long it 
will last however. For now, I welcome the relief and my servers as well!




Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Floor Terra

Hi,

Probably the preferred tool is a computer, a keyboard is a big plus too.
Trust me, I tried programming on a Palm TX with the stylus.
For brainstorming a pen and paper could be helpful.
And if I run into problems Google is my friend.

The more specific tools depend on the language and type of program.

Floor

On Nov 28, 2006, at 9:48 PM, Alvaro Mantilla Gimenez wrote:


Hi OpenBSD developers,


  Which are your preferred tools for develop? (For C, C++, Java,  
etcno matter the language)


  It is good to know which tools and why...


  Thanks,


  Alvaro




Re: Boot above cylinder 1024

2006-11-28 Thread frantisek holop
hmm, on Tue, Nov 28, 2006 at 08:49:43PM +, Brian Candler said that
> I've recently installed OpenBSD 4.0 on two machines in spare space at the
> end of the disk.

i am booting openbsd fine using gag from around the 60th gigabyte...

amaaq> fdisk wd0
Disk: wd0   geometry: 9729/255/63 [156296385 Sectors]
Offset: 0   Signature: 0xAA55
 Starting   Ending   LBA Info:
 #: idC   H  S -C   H  S [   start:  size   ]

 0: 070   1  1 - 1977 254 63 [  63:31776507 ] HPFS/QNX/AUX
 1: 0C 1978   0  1 - 8198 254 63 [31776570:99940365 ] Win95 FAT32L
*2: A6 8199   0  1 - 9728 254 63 [   131716935:24579450 ] OpenBSD
 3: 000   0  0 -0   0  0 [   0:   0 ] unused


disklabel:

# sizeoffset  fstype [fsize bsize  cpg]
  a:  8.1G 62.8G  4.2BSD   2048 16384  328 # Cyl 130671*-147432
  b:  0.6G 70.9Gswap   # Cyl 147433 -148753
  c: 74.5G  0.0G  unused  0 0  # Cyl 0 -155060


-f
-- 
the best way out of a difficulty is through it.



Re: iwi0 connection frustration

2006-11-28 Thread Vim Visual

Fred, would you like to marry me?

Oh, my! I always forget that I am already married! Too bad!

Thanks!

That did it! But it requiered a reboot, which I don't like much, but
the network is there and I can connect!

Does this mean that I have to reboot everytime I change the connection
point? Well it's not perfect but it's the last problem I have solved
(with your help!) now

LET'S MOVE TO OPENBSD

Enough crashboxes! Now let's go for the production thing!

Thanks a LOT to everybody!

gracias!

Pau


Hi Pau,

have you tried putting something like:

 dhcp NONE NONE NONE \
 nwid pepitogrillo nwkey eltrenloco

in your hostname.iwi0 file and then using:

/bin/sh -x /etc/netstart iwi0

to restart the interface?

I have had an issue with an ipw0 Intel Pro 2100 that would only clear
its wifi connection on reboot, with the appropriate hostname.if just
uping and downing the interface was not clearing the nwkey.

HTH

Fred
--
OpenBSD on the Zaurus C3200
http://www.crowsons.net/puters/zaurus.php




Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Jasper Lievisse Adriaanse
On Tue, Nov 28, 2006 at 02:16:35PM -0700, Bob Beck wrote:
> * Alvaro Mantilla Gimenez <[EMAIL PROTECTED]> [2006-11-28 14:03]:
> > Hi OpenBSD developers,
> > 
> > 
> >   Which are your preferred tools for develop? (For C, C++, Java, 
> > etcno matter the language)
> 
> 
>   Visual C++, .NET, and C sharp of course. Theo mandates
> taht we  all to use only the 7337est toolz..
don't forget the actual work is done on mirbsd boxes
we and only use openbsd to commit from.

silly boy, asking the obvious..



Re: ppp.conf for ueagle and pppoa

2006-11-28 Thread Stefan Olsson
- Original Message - 
From: "Damien Bergamini" <[EMAIL PROTECTED]>

Sent: Tuesday, November 28, 2006 7:26 AM

The "route" command is only necessary for plain IPoA.
For PPPoA, ppp will create the route for you.
Just put:

   set device PPPoA:ueagle0:8.35

in your ppp.conf file.


That gives me:
/etc/ppp:4365$ sudo ppp adsl
Working in interactive mode
Warning: iface rm: ioctl(SIOCDIFADDR_IN6,
fe80:8::250:4ff:fe5d:1022/64): Can't assign requested address
Using interface: tun1
Command: adsl: set device PPPoA:ueagle0:8.35
Command: adsl: set authname [EMAIL PROTECTED]
Command: adsl: set authkey 
ppp ON saltkudde> dial
Command: /dev/tty: dial
Warning: deflink: Device (PPPoA:ueagle0:8.35) must begin
with a '/', a '!' or contain at least one ':'


/etc/ppp:4366$ cat ppp.conf
default:
set log Phase Warning
add! default HISADDR
set ifaddr 0.0.0.1/0 0.0.0.2/0 255.255.255.0 0.0.0.0
set login

adsl:
set log local CCP Command DNS IPCP LCP TCP/IP Warning
set device PPPoA:ueagle0:8.35
set authname "[EMAIL PROTECTED]"
set authkey nytt95
# enable lqr
# enable dns
# disable ipv6cp
# set reconnect 10 100
---
/etc/ppp:4367$ dmesg 
[EMAIL PROTECTED]:/usr/src/sys/arch/i386/compile/GENERIC

cpu0: Intel Pentium III ("GenuineIntel" 686-class) 702 MHz
cpu0: 
FPU,V86,DE,PSE,TSC,MSR,PAE,MCE,CX8,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,MMX,FXSR,SSE

real mem  = 133722112 (130588K)
avail mem = 114577408 (111892K)
using 1657 buffers containing 6787072 bytes (6628K) of memory
mainbus0 (root)
bios0 at mainbus0: AT/286+(32) BIOS, date 05/19/00, BIOS32 rev. 0 @ 0xfd890, 
SMBIOS rev. 2.3 @ 0xebd60 (50 entries)

bios0: Dell Computer Corporation Inspiron 7500
apm0 at bios0: Power Management spec V1.2
apm0: battery life expectancy 100%
apm0: AC on, battery charge high, estimated 3:20 hours
apm0: flags 30102 dobusy 0 doidle 1
pcibios0 at bios0: rev 2.1 @ 0xfd890/0x770
pcibios0: PCI IRQ Routing Table rev 1.0 @ 0xfdf50/144 (7 entries)
pcibios0: PCI Interrupt Router at 000:07:0 ("Intel 82371FB ISA" rev 0x00)
pcibios0: PCI bus #3 is the last bus
bios0: ROM list: 0xc/0x1
cpu0 at mainbus0
pci0 at mainbus0 bus 0: configuration mode 1 (no bios)
pchb0 at pci0 dev 0 function 0 "Intel 82443BX AGP" rev 0x03
ppb0 at pci0 dev 1 function 0 "Intel 82443BX AGP" rev 0x03
pci1 at ppb0 bus 1
vga1 at pci1 dev 0 function 0 "ATI Mobility 1" rev 0x64
wsdisplay0 at vga1 mux 1: console (80x25, vt100 emulation)
wsdisplay0: screen 1-5 added (80x25, vt100 emulation)
cbb0 at pci0 dev 4 function 0 "TI PCI1225 CardBus" rev 0x01: irq 11
cbb1 at pci0 dev 4 function 1 "TI PCI1225 CardBus" rev 0x01: irq 11
pcib0 at pci0 dev 7 function 0 "Intel 82371AB PIIX4 ISA" rev 0x02
pciide0 at pci0 dev 7 function 1 "Intel 82371AB IDE" rev 0x01: DMA, channel 
0 wired to compatibility, channel 1 wired to compatibility

wd0 at pciide0 channel 0 drive 0: 
wd0: 16-sector PIO, LBA, 17301MB, 35433216 sectors
wd0(pciide0:0:0): using PIO mode 4, Ultra-DMA mode 2
atapiscsi0 at pciide0 channel 1 drive 0
scsibus0 at atapiscsi0: 2 targets
sd0 at scsibus0 targ 0 lun 0:  SCSI0 
0/direct removable

sd0: drive offline
atapiscsi1 at pciide0 channel 1 drive 1
scsibus1 at atapiscsi1: 2 targets
cd0 at scsibus1 targ 0 lun 0:  SCSI0 
5/cdrom removable

sd0(pciide0:1:0): using PIO mode 0, DMA mode 1
cd0(pciide0:1:1): using PIO mode 4, Ultra-DMA mode 2
uhci0 at pci0 dev 7 function 2 "Intel 82371AB USB" rev 0x01: irq 5
usb0 at uhci0: USB revision 1.0
uhub0 at usb0
uhub0: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub0: 2 ports with 2 removable, self powered
piixpm0 at pci0 dev 7 function 3 "Intel 82371AB Power" rev 0x02: SMI
iic0 at piixpm0
maestro0 at pci0 dev 8 function 0 "ESS Maestro 2E" rev 0x10: irq 5
ac97: codec id 0x83847609 (SigmaTel STAC9721/23)
ac97: codec features 18 bit DAC, 18 bit ADC, SigmaTel 3D
audio0 at maestro0
"AT&T/Lucent LTMODEM" rev 0x01 at pci0 dev 16 function 0 not configured
cardslot0 at cbb0 slot 0 flags 0
cardbus0 at cardslot0: bus 2 device 0 cacheline 0x0, lattimer 0x20
pcmcia0 at cardslot0
cardslot1 at cbb1 slot 1 flags 0
cardbus1 at cardslot1: bus 3 device 0 cacheline 0x0, lattimer 0x20
pcmcia1 at cardslot1
isa0 at pcib0
isadma0 at isa0
pckbc0 at isa0 port 0x60/5
pckbd0 at pckbc0 (kbd slot)
pckbc0: using irq 1 for kbd slot
wskbd0 at pckbd0: console keyboard, using wsdisplay0
pms0 at pckbc0 (aux slot)
pckbc0: using irq 12 for aux slot
wsmouse0 at pms0 mux 0
pcppi0 at isa0 port 0x61
midi0 at pcppi0: 
spkr0 at pcppi0
lpt0 at isa0 port 0x378/4 irq 7
npx0 at isa0 port 0xf0/16: using exception 16
pccom0 at isa0 port 0x3f8/8 irq 4: ns16550a, 16 byte fifo
biomask ef6d netmask ef6d ttymask ffef
pctr: 686-class user-level performance counters enabled
mtrr: Pentium Pro MTRR support
xl0 at cardbus0 dev 0 function 0 "3Com Corporation, 3CCFE575BT, LAN Cardbus 
Card": 3Com 3c575B-TX Ethernet: irq 11, address 00:50:04:5d:10:22

tqphy0 at xl0 phy 0: 78Q2120 10/100 PHY, rev. 3
ueagle0 at uhub0 port 1
ueagle0: Analog Devices Eagle III, rev 1.00/20.0b, addr 2
ueagle0: address: 00:60:4c:51:c

spamd [-c maxcon]

2006-11-28 Thread Daniel Ouellet

Is there a reason why it's not possible to start spamd with example

spamd -c 1000

Not a big deal, but I just couldn't do this.

So far any number other then

spamd -c 800

just doesn't go anywhere.

Daniel



Re: Baffling problem with OBSD-protected servers and Windows Vista...

2006-11-28 Thread Stuart Henderson
On 2006/11/28 14:32, Reverend Deuce wrote:
> Okay guys, I posted that long message about Firefox/etc on Windows
> Vista a couple of days ago.

this would be easier if you just posted pf.conf rather than non-linear
snippets; however..

>  a) there is a default block policy

I didn't notice you posting anything showing a default block for outgoing
packets, check this and if not, add one.

> block in  log from any to any label 
> "DefaultBlock"

> block in  log on { $ext_if }   all label "DefaultBlock"
> block return-rst  in  log on { $ext_if } proto tcp all label "DefaultBlock"
> block return-icmp in  log on { $ext_if } proto udp all label "DefaultBlock"

fwiw, you can simplify these if you like:
'block return in log on { $ext_if } label "DefaultBlock"'

> I have heard it said that it makes no sense to filter on two
> interfaces, best to pass on one and block on the other.

that advice is usually given in relation to filtering bridges.



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Diana Eichert
I use a soldering iron, dremel tool, sheet metal/plastic nibbler and
solder wick.

diana
PS  Then I load my AR-15 to see if I can shoot any holes in my code.



Re: Baffling problem with OBSD-protected servers and Windows Vista...

2006-11-28 Thread Michael Lockhart
Set net.inet.tcp.rfc1323=0 in /etc/sysctl.conf and that should resolve
the issue.  We've been testing in house with OpenBSD for Vista (we have
700+/- systems in the field) and this seems to resolve the issue.

Regards,
Mike Lockhart
 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Mike Lockhart[Systems Engineering & Operations]
StayOnline, Inc
http://www.stayonline.net/
mailto: [EMAIL PROTECTED]
GPG: 8714 6F73 3FC8 E0A4 0663  3AFF 9F5C 888D 0767 1550
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf
Of Stuart Henderson
Sent: Tuesday, November 28, 2006 5:46 PM
To: Reverend Deuce
Cc: misc@openbsd.org
Subject: Re: Baffling problem with OBSD-protected servers and Windows
Vista...

On 2006/11/28 14:32, Reverend Deuce wrote:
> Okay guys, I posted that long message about Firefox/etc on Windows
> Vista a couple of days ago.

this would be easier if you just posted pf.conf rather than non-linear
snippets; however..

>  a) there is a default block policy

I didn't notice you posting anything showing a default block for
outgoing
packets, check this and if not, add one.

> block in  log from any to any
label "DefaultBlock"

> block in  log on { $ext_if }   all label
"DefaultBlock"
> block return-rst  in  log on { $ext_if } proto tcp all label
"DefaultBlock"
> block return-icmp in  log on { $ext_if } proto udp all label
"DefaultBlock"

fwiw, you can simplify these if you like:
'block return in log on { $ext_if } label "DefaultBlock"'

> I have heard it said that it makes no sense to filter on two
> interfaces, best to pass on one and block on the other.

that advice is usually given in relation to filtering bridges.



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Jim Razmus
* Diana Eichert <[EMAIL PROTECTED]> [061128 18:09]:
> I use a soldering iron, dremel tool, sheet metal/plastic nibbler and
> solder wick.
> 
> diana
> PS  Then I load my AR-15 to see if I can shoot any holes in my code.
> 

I use home brewed Sierra Nevada Pale Ale.  But then, I'm not an
official developer.  I expect they use "real" beer.

Jim



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Ioan Nemes
That's the problem, you should use an AK45! Much-much cheaper
than the AR-15 (I've been offred one for $US15.00 in Sudan),
and is widely available.

Ioan
 

>> Diana Eichert <[EMAIL PROTECTED]> 11/29 9:58 am >>>
I use a soldering iron, dremel tool, sheet metal/plastic nibbler and
solder wick.

diana
PS  Then I load my AR-15 to see if I can shoot any holes in my code.



Re: spamd [-c maxcon]

2006-11-28 Thread Jon Simola

On 11/28/06, Daniel Ouellet <[EMAIL PROTECTED]> wrote:

Is there a reason why it's not possible to start spamd with example

spamd -c 1000


in /usr/src/libexec/spamd/spamd.c:
#define MAXCON 800


Not a big deal, but I just couldn't do this.


spamd(8) says the default is 800, which is actually a compiled-in
limit and is quite generous for most situations. The consequences of
raising it are not immediately obvious, but I imagine could be
entertaining.

--
Jon



Re: spamd [-c maxcon]

2006-11-28 Thread Daniel Ouellet

Jon Simola wrote:

On 11/28/06, Daniel Ouellet <[EMAIL PROTECTED]> wrote:

Is there a reason why it's not possible to start spamd with example

spamd -c 1000


in /usr/src/libexec/spamd/spamd.c:
#define MAXCON 800


Not a big deal, but I just couldn't do this.


spamd(8) says the default is 800, which is actually a compiled-in
limit and is quite generous for most situations. The consequences of
raising it are not immediately obvious, but I imagine could be
entertaining.


Yes the man page did say default 800. I read that. Usually the default 
setup are not the maximum in OpenBSD.


I stand corrected.

Thanks

Daniel



Re: Baffling problem with OBSD-protected servers and Windows Vista...

2006-11-28 Thread Stuart Henderson
On 2006/11/28 18:07, Michael Lockhart wrote:
> Set net.inet.tcp.rfc1323=0 in /etc/sysctl.conf and that should resolve
> the issue.

that's not a fix though, it just avoids the conditions which cause the
problem to occur. better to ensure the ruleset is completely sane. if so,
then test cases need to be found to isolate the problem.

if anyone wants an example of wonderful source code commenting,
the pf_norm.c sections relating to rfc1323 are particularly good.



Re: spamd [-c maxcon]

2006-11-28 Thread Bob Beck
> >spamd(8) says the default is 800, which is actually a compiled-in
> >limit and is quite generous for most situations. The consequences of
> >raising it are not immediately obvious, but I imagine could be
> >entertaining.

because if you go much beyond it you need to consider things like
kern.maxfiles, etc. etc. 

Making spamd want to use more file descriptors than the kernel can
give you is usually not advisable. the hard limit of 800 is a
conservative safe upper bound for a stock OpenBSD system running GENERIC.

-Bob



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread John Brooks
Haven't heard of an AK45, but I'm told the Russians are real 
proud of their AK-47.

--
John Brooks
[EMAIL PROTECTED] 

> -Original Message-
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of
> Ioan Nemes
> Sent: Tuesday, November 28, 2006 5:23 PM
> To: misc@openbsd.org; [EMAIL PROTECTED]
> Subject: Re: Which tools the OpenBSD developers are using?
> 
> 
> That's the problem, you should use an AK45! Much-much cheaper
> than the AR-15 (I've been offred one for $US15.00 in Sudan),
> and is widely available.
> 
> Ioan
>  
> 
> >> Diana Eichert <[EMAIL PROTECTED]> 11/29 9:58 am >>>
> I use a soldering iron, dremel tool, sheet metal/plastic nibbler and
> solder wick.
> 
> diana
> PS  Then I load my AR-15 to see if I can shoot any holes in my code.



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Zoong PHAM
On Tuesday, 28 November 2006 at 18:12:48 -0500, Jim Razmus wrote:
> * Diana Eichert <[EMAIL PROTECTED]> [061128 18:09]:
> > I use a soldering iron, dremel tool, sheet metal/plastic nibbler and
> > solder wick.

I am low budget developer so I use chopsticks, sushi and tap water.



Re: spamd [-c maxcon]

2006-11-28 Thread Daniel Ouellet

Bob Beck wrote:

spamd(8) says the default is 800, which is actually a compiled-in
limit and is quite generous for most situations. The consequences of
raising it are not immediately obvious, but I imagine could be
entertaining.


because if you go much beyond it you need to consider things like
kern.maxfiles, etc. etc. 


Making spamd want to use more file descriptors than the kernel can
give you is usually not advisable. the hard limit of 800 is a
conservative safe upper bound for a stock OpenBSD system running GENERIC.

-Bob


Thanks for the update. I understand that. Not a complain what so ever, 
but just a thought that may be the man page should include the default 
of 800 to be also the max allow. Again, not a big deal really. I didn't 
think of checking the code this time as usually OpenBSD never preset 
default to max value. That's what I am used to anyway. When I read the 
man page and saw the default to be 800, I was puzzle by not be able to 
increase it beyond that.


I should have thought of it obviously.

Thanks for correcting me!

Daniel



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Zoong PHAM
On Tuesday, 28 November 2006 at 17:33:38 -0600, John Brooks wrote:
> Haven't heard of an AK45, but I'm told the Russians are real 
> proud of their AK-47.

The AK47 is the original and the most popular (licenced to China and
other countries to manufacture) of the AK series.
There are newer and more advanced AKs after the AK47.

I never seen a AK45. Maybe it's a "open source" version of AK47.
Anyway, AK47s are simple and just works like OpenBSD.

Zoong



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Shane J Pearson

On 29/11/2006, at 11:43 AM, Zoong PHAM wrote:


On Tuesday, 28 November 2006 at 18:12:48 -0500, Jim Razmus wrote:

* Diana Eichert <[EMAIL PROTECTED]> [061128 18:09]:

I use a soldering iron, dremel tool, sheet metal/plastic nibbler and
solder wick.


I am low budget developer so I use chopsticks, sushi and tap water.


I hope you don't eat fugu! That would be blasphemy!


Shane J Pearson
shanejp netspace net au



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread L. V. Lammert
On Wed, 29 Nov 2006, Zoong PHAM wrote:

> I am low budget developer so I use chopsticks, sushi and tap water.
>
Since when is sushi low budget? Must be in Japan?

Lee


  Leland V. Lammert[EMAIL PROTECTED]
Chief Scientist Omnitec Corporation
 Network/Internet Consultants   www.omnitec.net




Re: Jacek Artymiak

2006-11-28 Thread Nick Davey

Here's the website for the book:

http://www.firewallwarrior.net/

If you read the google group he gives updates just fyi.

Nick

Chris 'Xenon' Hanson wrote:

Henning Brauer wrote:

* Siju George <[EMAIL PROTECTED]> [2006-11-28 17:56]:

If anyone is in touch with Jacek Artymiak ( the PF book author ) or
know anything about his health Please let me know.

apparently he's fine, mailed me a few days ago


  Tell him we're all eagerly awaiting an updated printing of his book. ;)




Re: [EMAIL PROTECTED]: ET1310 Documentation]

2006-11-28 Thread J.C. Roberts
On Tuesday 28 November 2006 07:16, Jonathan Gray wrote:
> This is an example of us trying to talk to a vendor and
> being totally shut down. Not only did they license the PCI express
> and MAC portions, but they don't want to help us to support their
> products at all. No information, no people to talk to, nothing.

The PCI Express was licensed from Synopsis:
http://www.synopsys.com/products/success/agere_dwss.pdf

I believe the MAC is *might* be licensed from SiS but I'm just guessing 
on that one.

We all know the lack of help from Richard Ubowski means he is just 
covering his ass due to the IP/NDA issues involved. He probably doesn't 
have the authority to release the docs and by ignoring the requests, he 
hopes the problem will just go away...

Jonathan took the logical/reasonable approach of contacting the people 
involved with the working on the particular product in order to get the 
required docs. -And what he got was the typical run-around.

I'll try the opposite illogical/unreasonable aproach, namely, start at 
the top and work down. I'll try to contact Rick Clemmer, the Agere CEO, 
to see what he has to say about prefering lost sales to open docs...

All the rest of you out there in misc@ land are free to pick an aproach 
and join the fray. Just remember, executives and board members are only 
human beings but they *especially* want to know what keeps us from 
buying their products...

http://www.agere.com/company/team.html
http://www.agere.com/company/board.html

It doesn't hurt to try...

Kind Regards,
JCR

p.s. I sure hope someone records Jonathan's lecture at OpenCon for those 
of us who can't make it to Venice.



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread bofh

On 11/28/06, Shane J Pearson <[EMAIL PROTECTED]> wrote:

I hope you don't eat fugu! That would be blasphemy!


I think Theo actually had fugu once, so it can't be that bad, so maybe
that's how he got his powers?



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread bofh

On 11/28/06, L. V. Lammert <[EMAIL PROTECTED]> wrote:

On Wed, 29 Nov 2006, Zoong PHAM wrote:

> I am low budget developer so I use chopsticks, sushi and tap water.
>
Since when is sushi low budget? Must be in Japan?


Sushi is the "fast" food in Japan, easily and cheaply available all
over the place.  However, speaking of sushi, I was recently up over at
a small town in the ozarks, and had some sushi.  They brought out some
samples of the new sushi they had created.  I took one look, and
remarked that we must still be in the deep south, because the sushi
they brought out was a bacon and ham roll, deep fried.



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Miod Vallat (on the road)
> I never seen a AK45. Maybe it's a "open source" version of AK47.
> Anyway, AK47s are simple and just works like OpenBSD.

USB AK47 are not ready for primetime, though, the driver has issues. Get
a missile launcher instead.



Re: Boot above cylinder 1024

2006-11-28 Thread Nick Holland
Brian Candler wrote:
> I've recently installed OpenBSD 4.0 on two machines in spare space at the
> end of the disk.
> 
> It turns out that OpenBSD is unbootable if the root filesystem starts above
> cylinder 1024. However, this isn't a problem for FreeBSD; I guess it makes
> use of newer BIOS calls.
> 
> I can still boot OpenBSD on these machines, by using the cd40.iso CDROM or a
> USB pen containing cdrom40.fs, and typing "boot hd0a:/bsd" or "boot
> hd1a:/bsd" at the boot> prompt. However this is a bit ugly.
> 
> So I was wondering, are the OpenBSD and FreeBSD boot processes similar
> enough that I could use the FreeBSD boot loader (first and/or second stage)
> to boot OpenBSD? And if so, has anyone got a recipe for this that they would
> care to share?

Wow, gotta love broad, general statements that are just plain wrong.

OpenBSD can DEFINITELY boot from way beyond cylinder 1024, as long as
your BIOS supports it.  I've booted from the last couple G of a 160G IDE
drive since the 3.5 days.

Since the system boots from a floppy and CDROM, it sounds like the BIOS
can do everything it needs to do.

You provide no information about your system or your process or what you
mean by "unbootable", so guessing what is wrong is probably foolish on
my part, but what the heck.

First, read and understand this:
   http://www.openbsd.org/o/faq/faq14.html#Boot386

When you install a fresh system (picking 'y' for "use entire disk for
OpenBSD"), OpenBSD installs a MBR, a PBR and /boot.  In order to boot,
the MBR calls the PBR which loads the /boot file.  IF you are
partitioning around another OS that is already on the system (apparently
the case on your machine), OpenBSD will not install an MBR unless you
deliberately tell fdisk to do so.  It seems to be one of few OSs that
don't just replace your existing MBR with its own.

If whatever MBR was already in place was not ready for big disks (again,
you provide no evidence for a 1024 cyl limit...it could also have been a
32G limit or 128G limit), it wouldn't have been able to pull the PBR
from the "far" partition...and no PBR means no /boot which means no OpenBSD.

This would explain why the CDROM and floppy work rather nicely.  You can
verify my speculation by looking at the boot messages, and compare to
what si in the above link.  If you don't see "Using drive ..." message,
you can't blame OpenBSD.

You can replace the MBR with a third party program, but the PBR and
second stage boot loader (/boot) are OpenBSD specific.  I'm not aware of
anyone writing a third-party OpenBSD-specific PBR or second-stage boot
loader..can't think of any reason why they should, the OpenBSD ones Just
Work Pretty Darned Well.  Grub et al. are just over-sized partition
flagging programs for OpenBSD.

Nick.



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Karsten McMinn

On 11/28/06, Diana Eichert <[EMAIL PROTECTED]> wrote:

I use a soldering iron, dremel tool, sheet metal/plastic nibbler and
solder wick.

diana
PS  Then I load my AR-15 to see if I can shoot any holes in my code.


I highly recommend glue guns, gnomes and jars of fat free mayonaise.
why fat free you ask? because I dont want blobs sticking to my
arteries.



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Darrin Chandler
On Tue, Nov 28, 2006 at 06:50:22PM -0800, Karsten McMinn wrote:
> On 11/28/06, Diana Eichert <[EMAIL PROTECTED]> wrote:
> >I use a soldering iron, dremel tool, sheet metal/plastic nibbler and
> >solder wick.
> >
> >diana
> >PS  Then I load my AR-15 to see if I can shoot any holes in my code.
> 
> I highly recommend glue guns, gnomes and jars of fat free mayonaise.
> why fat free you ask? because I dont want blobs sticking to my
> arteries.

C'mon! Stick to the real topic!

I love tail, personally. When that doesn't do it, then head usually
works.

-- 
Darrin Chandler|  Phoenix BSD Users Group
[EMAIL PROTECTED]   |  http://bsd.phoenix.az.us/
http://www.stilyagin.com/  |



OpenBSD 4.0 - Intel D102GGC2 board and DLink 580TX 10/100

2006-11-28 Thread riwanlky

Dear All,

I have a problem with Intel D102GGC2 board and DLink 580TX card, where
it did not detect the DLink 4 ports 10/100 ethernet on OpenBSD 4.0.
OpenBSD 4.0 only detect two ports ste2 and ste3.

I am wondering if it is the problem with detecting IRQ, It stated IRQ 11. Where
on Windows the Intel motherboard D102GGC2  could detect the DLink 4 ports,
with different IRQ.

Thanks and best regards,
Riwan

Attached is the dmesg:
OpenBSD 4.0 (GENERIC) #1107: Sat Sep 16 19:15:58 MDT 2006
[EMAIL PROTECTED]:/usr/src/sys/arch/i386/compile/GENERIC
RTC BIOS diagnostic error 80
cpu0: Intel(R) Pentium(R) 4 CPU 3.20GHz ("GenuineIntel" 686-class) 3.21 GHz
cpu0: 
FPU,V86,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,SBF,SSE3,MWAIT,DS-CPL,CNXT-ID,CX16

real mem  = 937385984 (915416K)
avail mem = 846831616 (826984K)
using 4256 buffers containing 46972928 bytes (45872K) of memory
RTC BIOS diagnostic error 80
mainbus0 (root)
bios0 at mainbus0: AT/286+(00) BIOS, date 05/02/06, SMBIOS rev. 2.4 @ 
0xe4cd0 (29 entries)

bios0: Intel Corporation D102GGC2
apm0 at bios0: Power Management spec V1.2
apm0: battery life expectancy 0%
apm0: AC off, battery charge unknown, estimated 0:00 hours
apm0: flags 30102 dobusy 0 doidle 1
pcibios at bios0 function 0x1a not configured
bios0: ROM list: 0xc/0xc000
cpu0 at mainbus0
pci0 at mainbus0 bus 0: configuration mode 1 (no bios)
pchb0 at pci0 dev 0 function 0 vendor "ATI", unknown product 0x5a33 rev 0x01
ppb0 at pci0 dev 1 function 0 "ATI RS480 PCIE" rev 0x00
pci1 at ppb0 bus 1
vga1 at pci1 dev 5 function 0 "ATI Radeon XPRESS 200" rev 0x00
wsdisplay0 at vga1 mux 1: console (80x25, vt100 emulation)
wsdisplay0: screen 1-5 added (80x25, vt100 emulation)
pciide0 at pci0 dev 17 function 0 "ATI IXP400 SATA" rev 0x80: DMA
pciide0: using irq 10 for native-PCI interrupt
pciide1 at pci0 dev 18 function 0 "ATI IXP400 SATA" rev 0x80: DMA
pciide1: using irq 11 for native-PCI interrupt
piixpm0 at pci0 dev 20 function 0 "ATI IXP400 SMBus" rev 0x81: SMI
iic0 at piixpm0
adt0 at iic0 addr 0x2e: sch5017 rev 0x8a
pciide2 at pci0 dev 20 function 1 "ATI IXP400 IDE" rev 0x80: DMA, channel 0 
configured to compatibility, channel 1 configured to compatibility

wd0 at pciide2 channel 0 drive 0: 
wd0: 16-sector PIO, LBA48, 76319MB, 156301488 sectors
wd0(pciide2:0:0): using PIO mode 4, DMA mode 2, Ultra-DMA mode 5
pcib0 at pci0 dev 20 function 3 "ATI IXP400 ISA" rev 0x80
ppb1 at pci0 dev 20 function 4 "ATI IXP400 PCI" rev 0x80
pci2 at ppb1 bus 2
rl0 at pci2 dev 2 function 0 "Realtek 8139" rev 0x10: irq 11, address 
00:19:d1:0f:e3:b1

rlphy0 at rl0 phy 0: RTL internal PHY
ppb2 at pci2 dev 3 function 0 "Intel S21152BB PCI-PCI" rev 0x00
pci3 at ppb2 bus 3
ste0 at pci3 dev 4 function 0 "D-Link Systems 550TX" rev 0x15: irq 11ste0: 
global reset never completed

ste0: eeprom failed to come ready
: failed to read station address
ste1 at pci3 dev 5 function 0 "D-Link Systems 550TX" rev 0x15: irq 11ste1: 
global reset never completed

ste1: eeprom failed to come ready
: failed to read station address
ste2 at pci3 dev 6 function 0 "D-Link Systems 550TX" rev 0x15: irq 11, 
address 00:0d:88:68:88:4a
ukphy0 at ste2 phy 1: Generic IEEE 802.3u media interface, rev. 0: OUI 
0x0090c3, model 0x0004
ste3 at pci3 dev 7 function 0 "D-Link Systems 550TX" rev 0x15: irq 11, 
address 00:0d:88:68:88:4b
ukphy1 at ste3 phy 1: Generic IEEE 802.3u media interface, rev. 0: OUI 
0x0090c3, model 0x0004

isa0 at pcib0
isadma0 at isa0
pckbc0 at isa0 port 0x60/5
pckbd0 at pckbc0 (kbd slot)
pckbc0: using irq 1 for kbd slot
wskbd0 at pckbd0: console keyboard, using wsdisplay0
pcppi0 at isa0 port 0x61
midi0 at pcppi0: 
spkr0 at pcppi0
npx0 at isa0 port 0xf0/16: using exception 16
pccom0 at isa0 port 0x3f8/8 irq 4: ns16550a, 16 byte fifo
biomask ffed netmask ffed ttymask ffef
pctr: user-level cycle counter enabled
dkcsum: wd0 matches BIOS drive 0x80
root on wd0a
rootdev=0x0 rrootdev=0x300 rawdev=0x302



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Shane J Pearson

On 29/11/2006, at 2:05 PM, Darrin Chandler wrote:


C'mon! Stick to the real topic!

I love tail, personally. When that doesn't do it, then head usually
works.


Careful doing that in a public forum. If you get caught, your GF/wife  
might use split on you.



Shane J Pearson
shanejp netspace net au



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Chris Kuethe

On 11/28/06, Shane J Pearson <[EMAIL PROTECTED]> wrote:

On 29/11/2006, at 2:05 PM, Darrin Chandler wrote:

> C'mon! Stick to the real topic!
>
> I love tail, personally. When that doesn't do it, then head usually
> works.

Careful doing that in a public forum. If you get caught, your GF/wife
might use split on you.


if you're not careful about your date, you might find you have some
unwanted growfs. you never know what's in swap space.

you also need to worry about cut. maybe even kill. individuals wishing
to use these might need to get some help from man... maybe ed or biff.

i'll leave the rest of /usr/*bin to someone else.

CK

--
GDB has a 'break' feature; why doesn't it have 'fix' too?



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Darrin Chandler
On Wed, Nov 29, 2006 at 02:26:16PM +1100, Shane J Pearson wrote:
> On 29/11/2006, at 2:05 PM, Darrin Chandler wrote:
> 
> >C'mon! Stick to the real topic!
> >
> >I love tail, personally. When that doesn't do it, then head usually
> >works.
> 
> Careful doing that in a public forum. If you get caught, your GF/wife  
> might use split on you.

That happened with the last GF after I suggested tee with her and
another girl. Well, more or less.

-- 
Darrin Chandler|  Phoenix BSD Users Group
[EMAIL PROTECTED]   |  http://bsd.phoenix.az.us/
http://www.stilyagin.com/  |



Re: spamd [-c maxcon]

2006-11-28 Thread jared r r spiegel
On Tue, Nov 28, 2006 at 07:43:48PM -0500, Daniel Ouellet wrote:
>
> Thanks for the update. I understand that. Not a complain what so ever, 
> but just a thought that may be the man page should include the default 
> of 800 to be also the max allow.

  jmc@ took care of that 2w ago

-- 

  jared



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Lyndon Nerenberg

On Nov 28, 2006, at 7:39 PM, Chris Kuethe wrote:


if you're not careful about your date, you might find you have some
unwanted growfs. you never know what's in swap space.


That's why it's important to finger, first.



MYSQL-5.0.24a on amd64 - How is it supposed to work for Apache in chroot ?

2006-11-28 Thread Uwe Dippel
Has there been a change with respect to how it works with chrooted Apache,
compared to 3.8 ?

I referred to the fabulous hints found at http://openbsdsupport.org/mysql.htm
and start mysql successfully with
su -c _mysql root -c '/usr/local/bin/mysqld_safe &' > /dev/null & echo -n
' mysql'
in rc.local

In 3.8 I used
rm -Rf /var/run/mysql
rm -Rf /var/www/var/run/mysql/*
ln -s /var/www/var/run/mysql /var/run/mysql
sleep 1
/usr/bin/sudo -c _mysql -u _mysql /usr/local/bin/mysqld_safe --user=_mysql
--log=/var/log/mysql &
with success.
If I do that here, by the way, I can reproduce a segfault on the fresh
pkg_add: mysql> show databases;
++
| Database   |
++
| information_schema |
| mysql  |
| test   |
++
Segmentation fault (core dumped)
, but that's not the major problem. Only for those proposing a similar
solution.

I short: Can someone please hit me with a clue on what is missing here to
connect to the databases through Apache ?
(I have checked, it is okay on the box; I can mysql -u user -p; so I guess
the missing link is the one into chroot)

Uwe

The php testpage shows mysql:
MySQL Support   enabled
Active Persistent Links 0
Active Links0
Client API version  5.0.24a
MYSQL_MODULE_TYPE   external
MYSQL_SOCKET/var/run/mysql/mysql.sock
MYSQL_INCLUDE   -I/usr/local/include/mysql
MYSQL_LIBS  -L/usr/local/lib -lmysqlclient

OpenBSD 4.0 (GENERIC.MP) #0: Mon Nov 27 18:31:04 SGT 2006
[EMAIL PROTECTED]:/usr/src/sys/arch/amd64/compile/GENERIC.MP
real mem = 2147033088 (2096712K)
avail mem = 1835143168 (1792132K)
using 22937 buffers containing 214913024 bytes (209876K) of memory
mainbus0 (root)
bios0 at mainbus0: SMBIOS rev. 2.3 @ 0xec000 (62 entries)
bios0: HP ProLiant ML350 G4
mainbus0: Intel MP Specification (Version 1.4) (HP   PROLIANT)
cpu0 at mainbus0: apid 0 (boot processor)
cpu0: Intel(R) Xeon(TM) CPU 3.00GHz, 3000.45 MHz
cpu0: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,SBF,SSE3,LONG
cpu0: 1MB 64b/line 8-way L2 cache
cpu0: apic clock running at 200MHz
cpu1 at mainbus0: apid 6 (application processor)
cpu1: Intel(R) Xeon(TM) CPU 3.00GHz, 3000.11 MHz
cpu1: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,SBF,SSE3,LONG
cpu1: 1MB 64b/line 8-way L2 cache
mpbios: bus 0 is type PCI
mpbios: bus 1 is type PCI
mpbios: bus 2 is type PCI
mpbios: bus 5 is type PCI
mpbios: bus 6 is type PCI
mpbios: bus 9 is type PCI
mpbios: bus 13 is type PCI
mpbios: bus 16 is type PCI
mpbios: bus 32 is type ISA
ioapic0 at mainbus0 apid 8 pa 0xfec0, version 20, 24 pins
ioapic1 at mainbus0 apid 9 pa 0xfec1, version 20, 24 pins
ioapic1: misconfigured as apic 0, remapped to apid 9
ioapic2 at mainbus0 apid 10 pa 0xfec8, version 20, 24 pins
ioapic3 at mainbus0 apid 11 pa 0xfec80400, version 20, 24 pins
pci0 at mainbus0 bus 0: configuration mode 1
pchb0 at pci0 dev 0 function 0 "Intel E7520 MCH" rev 0x0c
ppb0 at pci0 dev 2 function 0 "Intel MCH PCIE" rev 0x0c
pci1 at ppb0 bus 5
ppb1 at pci1 dev 0 function 0 "Intel PCIE-PCIE" rev 0x09
pci2 at ppb1 bus 6
ppb2 at pci1 dev 0 function 2 "Intel PCIE-PCIE" rev 0x09
pci3 at ppb2 bus 9
ppb3 at pci0 dev 4 function 0 "Intel MCH PCIE" rev 0x0c
pci4 at ppb3 bus 13
ppb4 at pci0 dev 6 function 0 "Intel MCH PCIE" rev 0x0c
pci5 at ppb4 bus 16
ppb5 at pci0 dev 28 function 0 "Intel 6300ESB PCIX" rev 0x02
pci6 at ppb5 bus 2
mpi0 at pci6 dev 3 function 0 "Symbios Logic 53c1030" rev 0x08: apic 9 int 0 
(irq 5)
scsibus0 at mpi0: 16 targets
sd0 at scsibus0 targ 0 lun 0:  SCSI3 0/direct fixed
sd0: 140014MB, 41991 cyl, 10 head, 682 sec, 512 bytes/sec, 286749488 sec total
sd1 at scsibus0 targ 2 lun 0:  SCSI3 0/direct fixed
sd1: 34732MB, 50824 cyl, 2 head, 699 sec, 512 bytes/sec, 71132000 sec total
mpi0: target 0 Sync at 160MHz width 16bit offset 127 QAS 1 DT 1 IU 1
mpi0: target 2 Sync at 160MHz width 16bit offset 63 QAS 1 DT 1 IU 1
mpi1 at pci6 dev 3 function 1 "Symbios Logic 53c1030" rev 0x08: apic 9 int 1 
(irq 5)
scsibus1 at mpi1: 16 targets
uhci0 at pci0 dev 29 function 0 "Intel 6300ESB USB" rev 0x02: apic 8 int 16 
(irq 3)
usb0 at uhci0: USB revision 1.0
uhub0 at usb0
uhub0: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub0: 2 ports with 2 removable, self powered
uhci1 at pci0 dev 29 function 1 "Intel 6300ESB USB" rev 0x02: apic 8 int 19 
(irq 7)
usb1 at uhci1: USB revision 1.0
uhub1 at usb1
uhub1: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub1: 2 ports with 2 removable, self powered
"Intel 6300ESB WDT" rev 0x02 at pci0 dev 29 function 4 not configured
"Intel 6300ESB APIC" rev 0x02 at pci0 dev 29 function 5 not configured
ehci0 at pci0 dev 29 function 7 "Intel 6300ESB USB" rev 0x02: apic 8 int 23 
(irq 7)
usb2 at ehci0: USB revision 2.0
uhub2 at usb2
uhub2: Intel EHCI root hub, rev 2.00/1.00, addr 1
uhub2: 4 ports with 4 removable, self powered

Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Jacob Yocom-Piatt
 Original message 
>Date: Wed, 29 Nov 2006 01:28:51 +
>From: "Miod Vallat (on the road)" <[EMAIL PROTECTED]>  
>Subject: Re: Which tools the OpenBSD developers are using?  
>To: Zoong PHAM <[EMAIL PROTECTED]>
>Cc: misc@openbsd.org
>
>> I never seen a AK45. Maybe it's a "open source" version of AK47.
>> Anyway, AK47s are simple and just works like OpenBSD.
>
>USB AK47 are not ready for primetime, though, the driver has issues. Get
>a missile launcher instead.
>

if you're not careful with your missle launcher, a french court might have to
take issue with it.

:)



Re: spamd [-c maxcon]

2006-11-28 Thread Daniel Ouellet

jared r r spiegel wrote:

On Tue, Nov 28, 2006 at 07:43:48PM -0500, Daniel Ouellet wrote:
Thanks for the update. I understand that. Not a complain what so ever, 
but just a thought that may be the man page should include the default 
of 800 to be also the max allow.


  jmc@ took care of that 2w ago


Thanks!

Sorry for the noise then.



Re: Jacek Artymiak

2006-11-28 Thread Siju George

On 11/28/06, Henning Brauer <[EMAIL PROTECTED]> wrote:

* Siju George <[EMAIL PROTECTED]> [2006-11-28 17:56]:
> If anyone is in touch with Jacek Artymiak ( the PF book author ) or
> know anything about his health Please let me know.

apparently he's fine, mailed me a few days ago



Nice to Know that :-)
Thanks to all who replied :-)

KindRegards

Siju



Re: Which tools the OpenBSD developers are using?

2006-11-28 Thread Travers Buda
On Wed, 29 Nov 2006 01:28:51 +
"Miod Vallat (on the road)" <[EMAIL PROTECTED]> wrote:

> > I never seen a AK45. Maybe it's a "open source" version of AK47.
> > Anyway, AK47s are simple and just works like OpenBSD.
> 
> USB AK47 are not ready for primetime, though, the driver has issues. Get
> a missile launcher instead.
> 

Hrm, you could crack one of those open, put some relays on it and have
even MORE fun with your bigger SSH-controlled missile launcher (replete
with explosive warheads!)

Travers Buda




Re: ftp-proxy clarification

2006-11-28 Thread Camiel Dobbelaar
On Tue, 28 Nov 2006, Mark Freeze wrote:
> I also have a question regarding ftp proxy.   My situation is that we
> have our firewall running, and I can connect and upload files to ftp
> sites from any of my workstations. The problem occurs when we are
> trying to download files.  When I connect my machine will negotiate
> the connection and get a directory listing, but crash when I try to
> download files from the site.   I know that it's the firewall because
> my machines connect and download when the fw is taken out of the
> process. I thought that maybe it was crashing when moving to an upper
> port?  And, if that is the case how do I correct it?
> 
> What in my rule set would allow me to ftp upload a file, but crash on
> the ftp download?

Please start a new thread the next time.

If you run ftp-proxy with "-d -D6" do you see anything interesting in the 
logging?

If that doesn't help, can you try to catch the control and data 
connections on both sides of the firewall with tcpdump (snaplen 1500) ?

ftp-proxy doesn't touch the data connections itself...  it only commits 
rules into the anchors to let them pass.

It does proxy the control connection, so it may buffer some lines that the 
FTP server is sending to the client and send them together.  That's 
perfectly legal though.

Which client are you using?



Marvell Libertas 88W8310 malo driver

2006-11-28 Thread Sam Fourman Jr.

hello misc@

Below is a full dmesg off of the latest available -current i386

the system has a ASUS P5AD2-E-Premium motherboard that has a Marvell
88W8310 wireless card integrated in it.

I did a fresh install and added the firmware package this is the dmesg
I received
hope this is of some help to the developers.

if it would be helpful contact me off list and i can set one of these
machines up(I have 2 identical) with root ssh with a public ip for
several days and over the weekend.


just a side note the sound card device does not give the invalid PCM
error on netbsd

Sam Fourman Jr.

OpenBSD 4.0-current (GENERIC) #1240: Tue Nov 28 05:03:09 MST 2006
   [EMAIL PROTECTED]:/usr/src/sys/arch/i386/compile/GENERIC
cpu0: Intel(R) Pentium(R) 4 CPU 3.20GHz ("GenuineIntel" 686-class) 3.22 GHz
cpu0: 
FPU,V86,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,SBF,SSE3,MWAIT,DS-CPL,CNXT-ID
real mem  = 2146725888 (2096412K)
avail mem = 1950015488 (1904312K)
using 4256 buffers containing 107458560 bytes (104940K) of memory
mainbus0 (root)
bios0 at mainbus0: AT/286+(00) BIOS, date 03/23/05, BIOS32 rev. 0 @
0xf0010, SMBIOS rev. 2.3 @ 0xf04d0 (79 entries)
bios0: ASUSTeK Computer INC. P5AD2-E-Premium
apm0 at bios0: Power Management spec V1.2
apm0: AC on, battery charge unknown
apm0: flags 30102 dobusy 0 doidle 1
pcibios0 at bios0: rev 2.1 @ 0xf/0x1
pcibios0: PCI IRQ Routing Table rev 1.0 @ 0xf8160/352 (20 entries)
pcibios0: PCI Interrupt Router at 000:31:0 ("Intel 82801FB LPC" rev 0x00)
pcibios0: PCI bus #5 is the last bus
bios0: ROM list: 0xc/0xee00! 0xcf000/0x4800 0xd3800/0x1000 0xd4800/0x1000
acpi at mainbus0 not configured
cpu0 at mainbus0
pci0 at mainbus0 bus 0: configuration mode 1 (no bios)
pchb0 at pci0 dev 0 function 0 "Intel 82925X MCH Host" rev 0x0e
ppb0 at pci0 dev 1 function 0 "Intel 82925X PCIE" rev 0x0e
pci1 at ppb0 bus 5
vga1 at pci1 dev 0 function 0 "NVIDIA GeForce 6800 GT" rev 0xa2
wsdisplay0 at vga1 mux 1: console (80x25, vt100 emulation)
wsdisplay0: screen 1-5 added (80x25, vt100 emulation)
azalia0 at pci0 dev 27 function 0 "Intel 82801FB HD Audio" rev 0x04: irq 10
azalia0: host: High Definition Audio rev. 1.0
azalia0: codec: CMedia CMI9880 (rev. 0.2), HDA version 0.9
azalia0: /usr/src/sys/dev/pci/azalia.c/1159 invalid PCM format: 0x
delete_encodings...
ppb1 at pci0 dev 28 function 0 "Intel 82801FB PCIE" rev 0x04
pci2 at ppb1 bus 4
ppb2 at pci0 dev 28 function 1 "Intel 82801FB PCIE" rev 0x04
pci3 at ppb2 bus 3
mskc0 at pci3 dev 0 function 0 "Marvell Yukon 88E8053" rev 0x15,
Marvell Yukon-2 EC rev. A2 (0x1): irq 5
msk0 at mskc0 port A, address 00:11:d8:55:58:e8
eephy0 at msk0 phy 0: Marvell 88E Gigabit PHY, rev. 2
ppb3 at pci0 dev 28 function 2 "Intel 82801FB PCIE" rev 0x04
pci4 at ppb3 bus 2
mskc1 at pci4 dev 0 function 0 "Marvell Yukon 88E8053" rev 0x15,
Marvell Yukon-2 EC rev. A2 (0x1): irq 5
msk1 at mskc1 port A, address 00:11:d8:55:55:64
eephy1 at msk1 phy 0: Marvell 88E Gigabit PHY, rev. 2
uhci0 at pci0 dev 29 function 0 "Intel 82801FB USB" rev 0x04: irq 11
usb0 at uhci0: USB revision 1.0
uhub0 at usb0
uhub0: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub0: 2 ports with 2 removable, self powered
uhci1 at pci0 dev 29 function 1 "Intel 82801FB USB" rev 0x04: irq 3
usb1 at uhci1: USB revision 1.0
uhub1 at usb1
uhub1: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub1: 2 ports with 2 removable, self powered
uhci2 at pci0 dev 29 function 2 "Intel 82801FB USB" rev 0x04: irq 5
usb2 at uhci2: USB revision 1.0
uhub2 at usb2
uhub2: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub2: 2 ports with 2 removable, self powered
uhci3 at pci0 dev 29 function 3 "Intel 82801FB USB" rev 0x04: irq 10
usb3 at uhci3: USB revision 1.0
uhub3 at usb3
uhub3: Intel UHCI root hub, rev 1.00/1.00, addr 1
uhub3: 2 ports with 2 removable, self powered
ehci0 at pci0 dev 29 function 7 "Intel 82801FB USB" rev 0x04: irq 11
usb4 at ehci0: USB revision 2.0
uhub4 at usb4
uhub4: Intel EHCI root hub, rev 2.00/1.00, addr 1
uhub4: 8 ports with 8 removable, self powered
ppb4 at pci0 dev 30 function 0 "Intel 82801BA AGP" rev 0xd4
pci5 at ppb4 bus 1
"Marvell Libertas 88W8310" rev 0x07 at pci5 dev 0 function 0 not configured
vendor "TI", unknown product 0x8025 (class serial bus subclass
Firewire, rev 0x01) at pci5 dev 3 function 0 not configured
pciide0 at pci5 dev 4 function 0 "ITExpress IT8212F" rev 0x13: DMA,
channel 0 wired to native-PCI, channel 1 wired to native-PCI
pciide0: using irq 11 for native-PCI interrupt
pciide1 at pci5 dev 5 function 0 "CMD Technology SiI3114 SATA" rev 0x02: DMA
pciide1: using irq 10 for native-PCI interrupt
rl0 at pci5 dev 10 function 0 "Accton MPX 5030/5038" rev 0x10: irq 10,
address 00:30:f1:1f:9a:62
rlphy0 at rl0 phy 0: RTL internal PHY
ichpcib0 at pci0 dev 31 function 0 "Intel 82801FB LPC" rev 0x04: PM disabled
pciide2 at pci0 dev 31 function 1 "Intel 82801FB IDE" rev 0x04: DMA,
channel 0 configured to compatibility, channel 1 con

Re: ppp.conf for ueagle and pppoa

2006-11-28 Thread Damien Bergamini
You must recompile user ppp with ATM enabled:

cd /usr/src/usr.sbin/ppp/ppp/
vi Makefile
remove line NOATM= /usr/include/netnatm required
then run make && make install

then ppp -dedicated adsl

this is explained here:
http://damien.bergamini.free.fr/ueagle/ppp.html
(just skip the "synchronizing the modem" section
which is outdated).

Regards,
Damien

| That gives me:
| /etc/ppp:4365$ sudo ppp adsl
| Working in interactive mode
| Warning: iface rm: ioctl(SIOCDIFADDR_IN6,
| fe80:8::250:4ff:fe5d:1022/64): Can't assign requested address
| Using interface: tun1
| Command: adsl: set device PPPoA:ueagle0:8.35
| Command: adsl: set authname [EMAIL PROTECTED]
| Command: adsl: set authkey 
| ppp ON saltkudde> dial
| Command: /dev/tty: dial
| Warning: deflink: Device (PPPoA:ueagle0:8.35) must begin
| with a '/', a '!' or contain at least one ':'
| 
| 
| /etc/ppp:4366$ cat ppp.conf
| default:
| set log Phase Warning
| add! default HISADDR
| set ifaddr 0.0.0.1/0 0.0.0.2/0 255.255.255.0 0.0.0.0
| set login
| 
| adsl:
| set log local CCP Command DNS IPCP LCP TCP/IP Warning
| set device PPPoA:ueagle0:8.35
| set authname "[EMAIL PROTECTED]"
| set authkey nytt95
| # enable lqr
| # enable dns
| # disable ipv6cp
| # set reconnect 10 100