Re: how to set an alias on a carp interface?

2011-02-19 Thread Stuart Henderson
On 2011-02-19, Claudio Jeker  wrote:
> On Sat, Feb 19, 2011 at 02:01:36AM -0500, Daniel Ouellet wrote:
>> On 2/19/11 12:51 AM, Ted Unangst wrote:
>> >On Fri, Feb 18, 2011 at 3:58 PM, Daniel Ouellet  wrote:
>> >>On 2/18/11 3:45 PM, Daniel Ouellet wrote:
>> >>>
>> >>>On 2/18/11 3:23 PM, Ted Unangst wrote:
>> >>Unless you refer at me writing /32 instead of the long way
>> >
>> >Ah, yes, I thought you somehow meant just writing, for instance.
>> Sorry to have added to the confusion there, My bad!
>> Would be cool to be able to do it however like in the pf.conf and
>> bgpd.conf, etc. (;>
> It is possible to that in ifconfig as well. I use it all the time.
> It works in hostname.if if you skip the inet IIRC.

For main addresses, yes it does (either with or without the "inet"),
but not for aliases.

Re: [OT] significance of application level bandwidth throttling

2011-02-19 Thread Ted Unangst
On Sat, Feb 19, 2011 at 9:08 AM, Ana Zgombic  wrote:
> background: i'm looking at playing with thttpd and i want to remove
> the bandwidth throttling code since it looks insignificant to me.

you know you don't have to use every feature a program comes with, right?

Re: Suspend on an IBM Thinkpad X40

2011-02-19 Thread Joe Snikeris
On Wed, Dec 15, 2010 at 10:23 PM, Joe Snikeris  wrote:
> On Tue, Nov 30, 2010 at 7:52 PM, Joe Snikeris  wrote:
>> I was experiencing frequent freezes after resuming from suspend on my
>> Thinkpad X40.  It would happen intermittently when suspending from X.
>> Upon resuming, I would be at the first virtual terminal and could type
>> things, but pressing enter would do nothing.  Attempting to switch to
>> another virtual terminal would lock up the machine, requiring a
>> reboot.
>> This Thinkpad has an option in the bios called Redisafe which prepares
>> the hibernate file before suspending, and is supposed to be safer.
>> Disabling this option fixed this issue.
> For the sake of someone searching for a similar issue, it turns out
> that Redisafe wasn't the issue here.  I'm still experiencing this
> behavior and I haven't figured out what it is due to.  I've tried
> disabling ACPI, but that didn't resolve it either.

I'm no longer experiencing this issue in -current.

btree in ldapd user stories

2011-02-19 Thread Ana Zgombic
Hi misc,

was wondering if anybody has experience with the in-tree ldapd. more
specifically some numbers on how btree performs in terms of size
growth, speed in searches and the like.


Ana Zgombic

Re: Libretto 70CT Debugging

2011-02-19 Thread Sebastian Reitenbach

with all this libretto thread, I backed out my old Libretto 60, but I
can only confirm that it also has the same problem:

booting hd0a:/bsd: 8254588+118 [61+372400+358030]=0x99e480
entry point at 0x200120

[ using 730908 bytes of bsd ELF symbol table ]
Copyright (c) 1982, 1986, 1989, 1991, 1993
The Regents of the University of California.  All rights reserved.
Copyright (c) 1995-2011 OpenBSD. All rights reserved. 

OpenBSD 4.9 (GENERIC) #660: Wed Feb 16 13:39:36 MST 2011
cpu0: Intel Pentium (P54C) ("GenuineIntel" 586-class) 100 MHz
real mem  = 33255424 (31MB)
avail mem = 22691840 (21MB)
mainbus0 at root
bios0 at mainbus0: AT/286+ BIOS, date 06/09/97
apm0 at bios0: Power Management spec V1.2
apm0: battery life expectancy 100%
apm0: AC on, battery charge high, charging
pcibios at bios0 function 0x1a not configured
bios0: ROM list: 0xe4000/0xc000
cpu0 at mainbus0: (uniprocessor)
cpu0: F00F bug workaround installed
isa0 at mainbus0
isadma0 at isa0
com0 at isa0 port 0x3f8/8 irq 4: ns16550a, 16 byte fifo
com0: console
com1 at isa0 port 0x2f8/8 irq 3: ns16550a, 16 byte fifo
pckbc0 at isa0 port 0x60/5
pckbd0 at pckbc0 (kbd slot)
pckbc0: using irq 1 for kbd slot
wskbd0 at pckbd0: console keyboard
pms0 at pckbc0 (aux slot)
pckbc0: using irq 12 for aux slot
wsmouse0 at pms0 mux 0
vga0 at isa0 port 0x3b0/48 iomem 0xa/131072
wsdisplay0 at vga0 mux 1: console (80x25, vt100 emulation), using wskbd0
wsdisplay0: screen 1-5 added (80x25, vt100 emulation)
wdc0 at isa0 port 0x1f0/8 irq 14
wd0 at wdc0 channel 0 drive 0: 
wd0: 16-sector PIO, LBA, 5729MB, 11733120 sectors
wd0(wdc0:0:0): using BIOS timings
sb0 at isa0 port 0x220/24 irq 5 drq 1: dsp v3.01
midi0 at sb0: 
audio0 at sb0
opl at sb0 not configured
wss0 at isa0 port 0x530/8 irq 10 drq 0: CS4231 or AD1845 (vers 4)
audio1 at wss0
pcppi0 at isa0 port 0x61
spkr0 at pcppi0
lpt0 at isa0 port 0x378/4 irq 7
npx0 at isa0 port 0xf0/16: reported by CPUID; using exception 16
pcic0 at isa0 port 0x3e0/2 iomem 0xd/65536
pcic0 controller 0:  has sockets A and B
pcmcia0 at pcic0 controller 0 socket 0
pcmcia1 at pcic0 controller 0 socket 1
pcic0: irq 9, polling enabled
biomask e945 netmask e945 ttymask fbdf
vscsi0 at root
scsibus0 at vscsi0: 256 targets
softraid0 at root
kernel: integer divide fault trap, code=0
Stopped at  cpu_switchto+0x76:  popl%ebx
ddb> ps
 9  0  0  0  20x100200crypto
 8  0  0  0  20x100200pfpurge
 7  0  0  0  20x100200pcic0,0,1
 6  0  0  0  20x100200pcic0,0,0
 5  0  0  0  20x100200apm0
 4  0  0  0  20x100200syswq
 3  0  0  0  20x100200idle0
 2  0  0  0  20x100200kmthread
*1  0  0  0  7   0swapper
 0 -1  0  0  3 0x80200  wdccmdswapper
ddb> trace
cpu_switchto(d09bda74,d0daa800,d0ba0f08,d03e4890,d0daa800) at

Fred wrote:
> Hi Misc,
> I'm stumped (again) my Toshiba Libretto 70CT has not been
> able to boot a kernel since 4.3, this is know issue [1],
> I have just compiled a kernel with option DEBUG and option
> WDCDEBUG to see if I can track down the issue.
> I disabled softraid at the UKC> prompt (due to a hint from [2])
> The kernel integer divide fault trap occurred again, but there was some 
> additional debug info which I have not seen before:
> root device softraid not configured
> dkcsum: bootdev=0xa000
> dkcsum: BIOS drive 0x80 bsd_dev=0xa200 checksum=0xc31f9477
> kernel: integer divide fault trap, code=0
> Stopped at  cpu_switchto+0x76:  popl%ebx
> Not sure if this sheds any further light on the problem?
> Is there any other debugging information I can get?
> The dmesg, trace and ps are at the end of this email.
> Any clues appreciated, and as a side note the bsd.rd  kernels boot
> fine (with the exception of the 4.8 bsd.rd that had the "memory" 
> clobber to lidt inline asm issue [3]).
> Thanks
> Fred
> [1] http://cvs.openbsd.org/cgi-bin/query-pr-wrapper?full=yes&numbers=6052
> [2] http://marc.info/?t=12786677461&r=1&w=2
> [3] http://marc.info/?l=openbsd-cvs&m=128224641425290
> dmesg, trace, ps and second trace and ps following: 
> Script started on Mon Feb 14 23:19:43 2011
> x41:fred ~> cu -l /dev/cuaU0 -s9600
> Connected
>>> OpenBSD/i386 BOOT 3.01
> boot> bsd.lib -c
> booting hd0a:bsd.lib: 
> /-\|/8299772-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\|/-\

Re: [OT] significance of application level bandwidth throttling

2011-02-19 Thread Ana Zgombic
Hi Joachim

On Sat, Feb 19, 2011 at 11:25 PM, Joachim Schipper

--- >8 ---
> I don't think bandwidth throttling is all that useful (request
> throttling is another matter), but what are you really trying to do? I'm

checked on request throttling and i now get the context of this. my
subject was a mistake.

i'm looking at a minimal-featured httpd server as base for some things
i need to do. thttpd looks like an excellent base.

> sure that tinyhttpd runs on stuff that doesn't run pf, so it makes sense
> to keep that code around.

yes. i think the code should be kept somewhere. checked nginx and it
has this feature too. i think i can strip it away and proxy with

thank you for the response.

> B  B  B  B  B  B  B  B Joachim


Re: usb external disk freezes system [SOLVED ON -CURRENT]

2011-02-19 Thread Kenneth R Westerback
On Sat, Feb 19, 2011 at 09:24:16AM +0800, shweg...@gmail.com wrote:
> On Wed, 16 Feb 2011, Kenneth R Westerback wrote:
> >On Wed, Feb 16, 2011 at 06:05:59PM +0800, shweg...@gmail.com wrote:
> >>I have an external usb drive which freezes the system, especially if
> >>I do some cp of scp of big files, but not necessarily, it happens
> >>also with small files, here is the error I get:
> >>
> >>attempting to restore vector in use vecproc 0 veccpu 6boff0
> >>attempting to restore vector in use vecproc 0 veccpu 6boff0
> >>(yes, written to times)
> >>umass0: Invalid CSW: sig 0x40f00ee0 shuld be 0x53425355
> >
> >Please try a -current snapshot. Many, many USB fixes since Aug. and
> >it would be good to know if the problem still exists as 4.9 is
> >about to lock.
> >
> > Ken
> The problem seems to be gone, thank you very much!

Excellent! Thanks for testing.


Re: [OT] significance of application level bandwidth throttling

2011-02-19 Thread Joachim Schipper
On Sat, Feb 19, 2011 at 10:08:50PM +0800, Ana Zgombic wrote:
> Hi Misc,
> i'm trying to collect firsthand experience on implementing application
> level bandwidth throttling.
> background: i'm looking at playing with thttpd and i want to remove
> the bandwidth throttling code since it looks insignificant to me.
> insignificant because at this day and age, there's pf and most routers
> can do some sort of QoS or rate limiting or similar things.
> am i on the right track here? am i asking the right questions?
> thank you for your patience.

I don't think bandwidth throttling is all that useful (request
throttling is another matter), but what are you really trying to do? I'm
sure that tinyhttpd runs on stuff that doesn't run pf, so it makes sense
to keep that code around.


PotD: textproc/p5-XML-Twig - perl module for parsing huge XML documents

Re: hibernate function

2011-02-19 Thread Kevin Chadwick
On Fri, 18 Feb 2011 20:53:42 +0100
Benny Lofgren wrote:

> > I don't really see how hibernate could be done safely without all
> > systems having a TPM. Maybe a storage file in /var that only root can
> > access, but that's still a compromise.  
> I'm sure it's just my too-narrow mind, but I fail to see any particular
> security implications that are not also implied by having actual
> physical access to the machine. Could you elaborate?

If you switch the main power off before leaving your machine then that
isn't true. Also I'm fairly sure it's easier to get access to data on a
disk, especially if deleted than all data in memory.

Re: security of hibernate (was: hibernate function)

2011-02-19 Thread Kevin Chadwick
On Fri, 18 Feb 2011 16:54:57 -0500
Ted Unangst wrote:

> On Fri, Feb 18, 2011 at 3:35 PM, Joachim Schipper
>  wrote:
> > Actually, if one could specify an encryption password for the memory
> > written to disk, a stolen hibernating system would be less dangerous
> > than a running/ACPI-sleeping system because it's suddenly impossible to
> > get interesting data from the system memory. Interesting data like the
> > keys in ssh-agent or a softraid decryption key.
> Not really much difference between encrypting memory that's written to
> disk and memory that's just left in memory.

Unless the power is removed in between. Unfortunately motherboards
don't do that without intervention, but they should. I've seen one abit
board with a convenient switch but that doesn't help on remote systems.
In fact they seem to be getting more and more stupid, especially in Bios
access. I also have one system that won't let you hibernate two OS's at
once and another system that wants you to reset the bios to detect a new
hard disk etc.. 

Maybe the want for green systems will change keeping power to the ram
but I doubt it, they'd need to distinguish between hibernate and
standby at the lowest level or remove standby.

A password or wipeable password file seem like good ideas to me or the
user can just decide whether to allow hibernate at all.

[OT] significance of application level bandwidth throttling

2011-02-19 Thread Ana Zgombic
Hi Misc,

i'm trying to collect firsthand experience on implementing application
level bandwidth throttling.

background: i'm looking at playing with thttpd and i want to remove
the bandwidth throttling code since it looks insignificant to me.

insignificant because at this day and age, there's pf and most routers
can do some sort of QoS or rate limiting or similar things.

am i on the right track here? am i asking the right questions?

thank you for your patience.


Re: security of hibernate (was: hibernate function)

2011-02-19 Thread Joachim Schipper
On Fri, Feb 18, 2011 at 04:54:57PM -0500, Ted Unangst wrote:
> On Fri, Feb 18, 2011 at 3:35 PM, Joachim Schipper
>  wrote:
> > Actually, if one could specify an encryption password for the memory
> > written to disk, a stolen hibernating system would be less dangerous
> > than a running/ACPI-sleeping system because it's suddenly impossible to
> > get interesting data from the system memory. Interesting data like the
> > keys in ssh-agent or a softraid decryption key.
> Not really much difference between encrypting memory that's written to
> disk and memory that's just left in memory.

Yes, but when hibernating you can be pretty sure that e.g. disk cache
and video memory are actually empty. You do have a good point, but there
are just more potential problems with ACPI sleep.

Or am I babbling nonsense? I'll admit to not knowing much about ACPI...


TFMotD: ec (4) - 3Com EtherLink II (3c503) Ethernet device


Re: rsu0 problem

2011-02-19 Thread Gianluca D'Auri Muscelli
On Fri, 18 Feb 2011 20:42:31 +0100
Hans Zimmerman  wrote:

> On 02/18/2011 05:30 PM, Gianluca D'Auri Muscelli wrote:
> > On Fri, 18 Feb 2011 13:03:27 +0100
> > Hans Zimmerman  wrote:
> >
> >> On Fri, 18 Feb 2011 02:58:52 +0100, "Gianluca D'Auri Muscelli"
> >>   wrote:
> >>> now when i sudo sh /etc/netstart rsu0
> >>> rsu0.no link  sleeping
> >>> and in console i look ' rsu0: could not send site survey command'
> >>> my hostname.rsu0 is:
> >>> dhcp NONE NONE NONE nwkey my_wep_password_clear_text chan 6
> >>> or
> >>> dhcp NONE NONE NONE nwid my_wii_name nwkey my_pass_cl_text chan 6
> >>> ;(
> >>>
> >>> Do u know how i can resolve this problem??
> >>> tks vvm
> >>
> >> I think I have the same problem, see pr 6534
> >> http://cvs.openbsd.org/cgi-bin/query-pr-wrapper?full=yes&numbers=6534
> >>
> >> I have not found a solution yet.
> >>
> >> Hans
> >>
> >>
> >
> > I'v found a solution only to get my network with WAP encryption,
> > this card with WEP doesn't function, I try many many time!
> >
> >
> Gianluca,
> do you mean WPA? Which version of WPA? WPA or WPA2, TKIP or AES?
> Hans


Gianluca D'Auri Muscelli

Fingerprint: 3A277FACD60A3D33388BC371F4548B69078A9A04

 ,(   ).
 | \,--_ / |
 /_  _  `  /
/-.,-.`\  _    _ _
\O|O  | |/ ___ \   |  _ \ / |  __ \
  (___)`--'_/   / /  / /___  ___   | |_) | (___ | |  | |
   `.__/`  /   / /  / / __ \/ _ \/ __ \|  _ < \___ \| |  | |
 `.__,   ,/   / /__/ / /_/ /  __/ / / /| |_) |) | |__| |
  \_/ .___/\___/_/ /_/ |/|_/|_/
 ___/ /__

