Re: pflogd write /var/run/mypflogdinstance.pid?

2020-12-13 Thread Harald Dunkel
On 12/13/20 8:32 PM, Theo de Raadt wrote: If a pflogd dies because of a bug, the pid listed in the file may be reused, and then your kill `cat pidfile` will kill the incorrect process. I understand your concern, but as written before, I am not asking to drop pkill support. How about adding a

Re: pflogd write /var/run/mypflogdinstance.pid?

2020-12-13 Thread trondd
>> On 2020-12-13, Harald Dunkel wrote: > On 12/13/20 7:10 PM, Theo de Raadt wrote: >> >> And I'm suggesting the arguments should look like this: >> >> pflogd: [priv] -s 160 -i pflog0 -f /var/log/pflog (pflogd) >> pflogd: [running] -s 160 -i pflog0 -f /var/log/pflog (pflogd) >> >> That mi

Re: How to whitelist a good IP coming in with a senderscore of 0?

2020-12-13 Thread gilles
December 13, 2020 6:26 PM, "Chris Bennett" wrote: > I have run into a problem with an organization getting a senderscore of > 0. > This is not at all a spam source, but a political organization which is > the kiss of death these days. > > What's the right method to deal with this? I certainly d

Re: pflogd write /var/run/mypflogdinstance.pid?

2020-12-13 Thread Aleksander De
On Sun, Dec 13, 2020 at 08:24:13PM -, Stuart Henderson wrote: > On 2020-12-13, Harald Dunkel wrote: > > On 12/13/20 7:10 PM, Theo de Raadt wrote: > >> > >> And I'm suggesting the arguments should look like this: > >> > >> pflogd: [priv] -s 160 -i pflog0 -f /var/log/pflog (pflogd) > >>

Re: How to whitelist a good IP coming in with a senderscore of 0?

2020-12-13 Thread Chris Bennett
On Sun, Dec 13, 2020 at 08:45:53PM +, gil...@poolp.org wrote: > You should probably look into the bypass keyword, it lets you create a > filter rule that will bypass a phase (ie: in phase connect, if ip addr > is X, then bypass the phase). > > Gilles > Thanks! Chris

Re: Switching from trunk(4) to aggr(4)

2020-12-13 Thread Daniel Jakots
On Sun, 13 Dec 2020 20:34:35 - (UTC), Stuart Henderson wrote: > On 2020-12-12, Daniel Jakots wrote: > > I've been using a LACP trunk on my apu (with the three em(4)). On > > top of which I have some vlans. I've been doing that for years and > > it's working fine. > > I used load-balancing

Re: Switching from trunk(4) to aggr(4)

2020-12-13 Thread Stuart Henderson
On 2020-12-12, Daniel Jakots wrote: > I've been using a LACP trunk on my apu (with the three em(4)). On > top of which I have some vlans. I've been doing that for years and it's > working fine. I used load-balancing trunk on APU before but stopped when I came to the conclusion that APU running Op

Re: pflogd write /var/run/mypflogdinstance.pid?

2020-12-13 Thread Stuart Henderson
On 2020-12-13, Harald Dunkel wrote: > On 12/13/20 7:10 PM, Theo de Raadt wrote: >> >> And I'm suggesting the arguments should look like this: >> >> pflogd: [priv] -s 160 -i pflog0 -f /var/log/pflog (pflogd) >> pflogd: [running] -s 160 -i pflog0 -f /var/log/pflog (pflogd) >> >> That mi

Re: How to whitelist a good IP coming in with a senderscore of 0?

2020-12-13 Thread Stuart Henderson
On 2020-12-13, Chris Bennett wrote: > I have run into a problem with an organization getting a senderscore of > 0. > This is not at all a spam source, but a political organization which is > the kiss of death these days. > > What's the right method to deal with this? I certainly don't want to > st

Re: pflogd write /var/run/mypflogdinstance.pid?

2020-12-13 Thread Consus
On Sun, Dec 13, 2020 at 10:42:20PM +0300, Consus wrote: On Sun, Dec 13, 2020 at 08:27:24PM +0100, Harald Dunkel wrote: At least OpenBSD is not alone with this problem. On Debian there is a tool "/bin/pidof", trying to guess the pid of a daemon to kill by looking at the process list as well. So

Re: pflogd write /var/run/mypflogdinstance.pid?

2020-12-13 Thread Consus
On Sun, Dec 13, 2020 at 08:27:24PM +0100, Harald Dunkel wrote: At least OpenBSD is not alone with this problem. On Debian there is a tool "/bin/pidof", trying to guess the pid of a daemon to kill by looking at the process list as well. Some dude from Google came up with a good solution (for Lin

Re: pflogd write /var/run/mypflogdinstance.pid?

2020-12-13 Thread Theo de Raadt
Harald Dunkel wrote: > On 12/13/20 7:10 PM, Theo de Raadt wrote: > > > > And I'm suggesting the arguments should look like this: > > > > pflogd: [priv] -s 160 -i pflog0 -f /var/log/pflog (pflogd) > > pflogd: [running] -s 160 -i pflog0 -f /var/log/pflog (pflogd) > > > > That might allow

Re: pflogd write /var/run/mypflogdinstance.pid?

2020-12-13 Thread Harald Dunkel
On 12/13/20 7:10 PM, Theo de Raadt wrote: And I'm suggesting the arguments should look like this: pflogd: [priv] -s 160 -i pflog0 -f /var/log/pflog (pflogd) pflogd: [running] -s 160 -i pflog0 -f /var/log/pflog (pflogd) That might allow more accurate pkill targetting. Wouldn't you

Re: pflogd write /var/run/mypflogdinstance.pid?

2020-12-13 Thread Theo de Raadt
Harald Dunkel wrote: > On 12/7/20 7:19 PM, Theo de Raadt wrote: > > Yep. > > > > It is possible we need a better strategy --- like placing *all* original > > argv in the [priv] title. > > > > If you change the pflogd command line in the process list, what is > supposed to happen to the existing

How to whitelist a good IP coming in with a senderscore of 0?

2020-12-13 Thread Chris Bennett
I have run into a problem with an organization getting a senderscore of 0. This is not at all a spam source, but a political organization which is the kiss of death these days. What's the right method to deal with this? I certainly don't want to stop senderscore filtering, but I do want to receive

Issues with Teclast F7 Plus

2020-12-13 Thread Joel Carnat
Hello, I just got a Teclast F7 Plus laptop and installed OpenBSD 6.8-current on it. Most things works except apm and touchpad. Using zzz or ZZZ, it seems suspend/hibernation start but are never achieved. The backlight keyboard and power led are still on. On Linux, keyboard goes black and pow

Re: Switching from trunk(4) to aggr(4)

2020-12-13 Thread Daniel Jakots
On Sun, 13 Dec 2020 11:00:32 +0100, livio wrote: > # cat /etc/hostname.aggr0 > trunkport em1 trunkport em2 trunkport em3 lacpmode active lacptimeout > slow description "i_data" > up I just tried adding "lacpmode active lacptimeout slow" in case ifconfig(8) was lying and they were not the default

Re: pflogd write /var/run/mypflogdinstance.pid?

2020-12-13 Thread Harald Dunkel
On 12/7/20 7:19 PM, Theo de Raadt wrote: Yep. It is possible we need a better strategy --- like placing *all* original argv in the [priv] title. If you change the pflogd command line in the process list, what is supposed to happen to the existing code using pkill or pgrep, expecting the *old*

Re: Switching from trunk(4) to aggr(4)

2020-12-13 Thread livio
Hey, My setup at home is almost identical. APU with aggr interface and a couple of VLANs: https://github.com/liv-io/ansible-playbooks-example/blob/master/bsd/host_vars/fw01.example.com.yml # cat /etc/hostname.em{1,2,3} up # cat /etc/hostname.aggr0 trunkport em1 trunkport em2 trunkport em3 lacpm

Re: OpenBSD as a NAS

2020-12-13 Thread jeanfrancois
Hello, For your use case make sure from reading softraid it will fit your needs in the first place, perform some tests to make sure softraid meets what you need. Otherwise have a look at hardware raids which OpenBSD supports. As far as NAS for local, yes OpenBSD's perfect for the job, I've