openbsd-misc mailing list

FromSubjectsort iconDate
frantisek holop
Re: external usb disk freezing machine

none of them.
it seems that it was acpi after all,
and acpi.c,v 1.78 solves this issue.

-f
--
friends are people you can be quiet with.

Feb 14, 7:08 pm 2007
Marco Peereboom Feb 14, 7:17 pm 2007
Mitja
Tunnel, VPN, NAT

I've managed to solve a problem that was bodering me for some time now.
I decided to put this solution to the list just in case someday somebody
will be in similar situation.

How to solve the problem described on this picture:

193.x.x.x/27 193.y.y.y/27
| 192.168.1.0/24 | 192.168.2.0/24
| | | |
| | | |
Host A ------------ tunnel ------------ Host D -----Internet...

Feb 14, 6:19 pm 2007
Jamie Penman-Smithson
Re: Problems with routing

I read afterboot(8) but I didn't see anything related to the issue
that I'm experiencing.

Time to go back to Linux I suppose..

--
-Jamie L. Penman-Smithson <jpenman.smithson@gmail.com>

Feb 14, 6:18 pm 2007
Martin Schröder
Re: Problems with routing

----------------------
If you wish to route packets between interfaces, add one or both of the
following directives (depending on whether IPv4 or IPv6 routing is re-
quired) to /etc/sysctl.conf:

net.inet.ip.forwarding=1
net.inet6.ip6.forwarding=1

Packets are not forwarded by default, due to RFC requirements.

We won't miss you.

Best
Martin

Feb 14, 6:34 pm 2007
Jamie Penman-Smithson
Re: Problems with routing

I already did this, to no effect.

--
-Jamie L. Penman-Smithson <jpenman.smithson@gmail.com>

Feb 14, 7:49 pm 2007
Falk Brockerhoff - s...
Nagios plugin for checking OpenBGPd-Peers

Hello,

has anybody wrote a nagios plugin to check the presence of some
specified bgp-peers set up with openbgpd? In the past I used check_bgp
in combination with cisco routers, which checks the peer-state via snmp.

Regards,

Falk

Feb 14, 5:13 pm 2007
Chris C.
PF + rsync trouble

Hi

I'm having issues with rsyncing ftp.rfc-editor.org through a PF firewall,
other connections (also other rsync connections) work well.

rsync -avz --delete ftp.rfc-editor.org::rfcs-text-only my-rfc-mirror
receiving file list ... done
./
rfc-index.xml
...
rfc1591.txt
rfc1592.txt
nothing is going to happen... will timeout in a few minutes

my setup is LAN --> OBSDGW2 -> PPPOE -> Internet

fxp1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
lladdr 00:...

Feb 14, 4:59 pm 2007
Chris C.
Re: PF + rsync trouble

Have to reply to my own post...
The rsync process completes on the gateway itself, but not on any device
behind it.

Feb 14, 6:15 pm 2007
Darren Spruell
Re: PF + rsync trouble

Enable debugging in PF and see if you get any error conditions in your
kernel logs.

# pfctl -x loud

(set back to normal with 'pfctl -x urgent')

--
Darren Spruell
phatbuckett@gmail.com

Feb 14, 7:17 pm 2007
Jack J. Woehr
Re: Free Linux Driver Development!

Actually, someone should (has already?) start one of those projects/
campaigns like
"browse anywhere" (http://www.anybrowser.org/campaign/) and create a
website and a cute downloadable
URL snippet-cum-icon and get people to put it all over the cyberverse.

"Open Hardware Specs, no blobs, no NDA's".

--
Jack J. Woehr
Director of Development
Absolute Performance, Inc.
jwoehr@absolute-performance.com
303-443-7000 ext. 527

Feb 14, 4:53 pm 2007
Soner Tari
Re: SIP on OpenBSD

Head of the ftp://ftp.sangoma.com/OpenBSD/current_wanpipe/README reads:

Future release: Wanpipe version
----------------------------------------------------------
o Support Asterisk interface.

Nov 23, 2006: wanpipe version - 1.6.5-8 (wanpipe-1.6.5-8.tgz)
----------------------------------------------------------
[...]
o Support OpenBSD-4.0 kernel

Therefore, I am hoping to have Asterisk+Sangoma cards running on OpenBSD
sooner than most people are expecting. (Meaning that we won't need
zapte...

Feb 14, 4:14 pm 2007
Stuart Henderson
Re: SIP on OpenBSD

"The Sangoma cards work with their own drivers with zaptel loaded on top"
http://www.voip-info.org/wiki/view/Sangoma

btw, asterisk-bsd is probably a better venue for this.

Feb 14, 4:34 pm 2007
RedShift
dmesg for supermicro x7dvl-e

Hello

I've got a new toy today, here's the dmesg:

What does this server contain?
* Intel Xeon 5130
* SuperMicro X7DVL-E
(http://www.supermicro.com/products/motherboard/Xeon1333/5000V/X7DVL-E.cfm)
No other specialities.

The keyboard is connected via USB, works. Disks are attached to the SATA
controller, detected. Fully functional it appears.

Made using cd40.iso from amd64.

OpenBSD 4.0 (RAMDISK_CD) #883: Sat Sep 16 20:46:50 MDT 2006
deraadt@amd64.openbsd.org:/usr/src/sys/arch/amd...

Feb 14, 3:41 pm 2007
Darren Spruell
Re: OT? Is this bad news?

In general, the developers have already given that advice. Boycott
uncooperative vendors' products, give your money to those that provide
documentation.

No, the OpenBSD community will not put a dent in the picture when
compared with the market share of the rest of the customer base.
However, even tiny hits to the bottom line become large issues to
address when shareholders realize that the company's bottom line isn't
where it _could be_. Small though it be, such action can make a
difference, esp...

Feb 14, 3:05 pm 2007
Tim Kuhlman
PF drops tcp packets from a machine with Gentoo linux kernel...

I have pf running on an OpenBSD 4.0 (patches 1-5, 7) router and I have one
user with two Gentoo Linux machines with kernel 2.6.18 who is having
troubles. Everyone else is having no problem at all. This user is having any
tcp connection he makes dropped by the firewall. The state shows up when I
run "pfctl -ss" but a sniff on both ends of the router shows that it is
dropping the packets. If I set the debug level to loud I get the following
output.

Gentoo and OpenBSD talking to each other

Fe...

Feb 14, 2:47 pm 2007
Stuart Henderson
Re: PF drops tcp packets from a machine with Gentoo linux ke...

Ruleset more likely. If you post it, people can make suggestions.
Might be useful to capture a SYN with tcpdump and post any state entries
relating to it, too (the relevant parts of pfctl -ss -v).

Feb 14, 4:29 pm 2007
Otto Moerbeek
Re: PF drops tcp packets from a machine with Gentoo linux ke...

On Wed, 14 Feb 2007, Tim Kuhlman wrote:

Not always, but very often. The main rule is to make sure that the
packet creating the state is not a packet of an already established
connection, but a packet creating the connection. Creating the state
from the beginning allows pf to get the info about the window scaling
and other tcp options used.

Using flags S/SA keep state is the easiest way to achieve that. Note
that on current, this is the default.

-Otto

Feb 14, 3:54 pm 2007
Darren Spruell
Re: PF drops tcp packets from a machine with Gentoo linux ke...

This kind of thing has happened to me in the past; likely you're doing
something wrong with your state building in the first place so that
you're getting state built one direction one interface and checked on
a different one, or similar.

If you simplify your ruleset as a temporary test, you'll probably find
things magically work. If so you'll know it's not the Linux boxen or
firewall itself but your policy. Gradually add components back into

Yeah, when I went through it scrub rules had nothin...

Feb 14, 3:11 pm 2007
Stuart Henderson
Re: PF drops tcp packets from a machine with Gentoo linux ke...

New linux kernels (and Windows) set the window size such that wscale>0
by default (if you want to test this from an OpenBSD box, increase
net.inet.tcp.recvspace).

As tcpdump will show you, the wscale value is *only* in SYN packets.
This is multiplied by the window size in the TCP headers of subsequent
packets to find the actual window size (see RFC1323 paragraph 1.1 on
'window size limit' and paragraph 2).

If the state was created from a packet other than the SYN, it won't have
wscale infor...

Feb 14, 4:27 pm 2007
Tim Kuhlman
Re: PF drops tcp packets from a machine with Gentoo linux ke...

You think it is an issue with my state table rules even though running an "pfctl -ss" shows that the state is established?

I keep state on my outgoing connection and don't do any on the incoming connection except for some ssh connections which I rate limit. These ssh connections haven't been the issue anyway.

The basic outgoing rule is relatively simple it is
pass out on { $int_if $vpn_if $ext_if $dsl_if $DMZ_production_if $DMZ_proto_if } proto {tcp udp icmp} modulate state

After that I do som...

Feb 14, 4:08 pm 2007
Ryan Corder
ftp though ftp-proxy timeouts

Since upgrading a couple firewalls this weekend from 3.8 to 4.0, I've
noticed a large increase in passive-mode FTP transfer timeouts. Before
the upgrade, I had no issues...but now there are a number of client's
FTP servers that I have to transfer files to and from that transfers
simply fail on. I can log in just fine, but the data connections hang
at random. Sometimes they work, but often they don't.

I've increased the debugging on ftp-proxy and it isn't telling me
anything relevant.

my ftppr...

Feb 14, 2:02 pm 2007
Jose Fragoso
Re: slow io operations on xSeries 336

>> thats very... vague...

I did run the same command again. Only this time I used

tar xzf ports.tar.gz

Look at the times:

# date;tar xzf ports.tar.gz;date
Wed Feb 14 10:59:34 BRT 2007
Wed Feb 14 11:11:04 BRT 2007

The total number of interrupts ranged from 270 to 850, most of it
being mpi0 (170 out of 271 and 747 out of 850). It always showed
100 for clock. If you feel it is important, I can send you the
print screen of the moment these values were shown (off the list
if you ...

Feb 14, 1:38 pm 2007
David Gwynne
Re: slow io operations on xSeries 336

can i see a dmesg as well? if you're running the machine as an amd64,
can you try it again as an i386?

dlg

Feb 14, 5:37 pm 2007
Steven
Concerns: Linux Driver Development FAQ

Hi Greg,

I've read your FAQ
http://www.kroah.com/log/linux/free_drivers_faq.html

which was linked to from Slashdot
http://linux.slashdot.org/article.pl?sid=07/02/13/0220233&from=rss,

and I have some concerns about the program. Now, I realize that
you're trying to get hardware developers on-board so that they'll
give Linux developers the information the developers need to write
drivers for the hardware. However, you state that you'd sign an NDA
to do so.

While it is possible that, af...

Feb 14, 12:17 pm 2007
Mark Zimmerman
Kernel panic in 4.1-beta

Greetings:

I will not have time for a proper bug report until this evening when I
get home, but I thought I would throw this out there for now.

This issue is reproducible, and it occurred in the previous snapshot
as well. Briefly, here is how it happens:

I have net.inet.ip.forwarding=1, and two interfaces: re0 is on my
internal LAN which is routed to the internet through another box
running 4.0-stable. vr0 is connected to an ibook, also running
4.0-stable, through a switch. The box that panics...

Feb 14, 11:28 am 2007
Ingo Schwarze
driver maintenance problems

Hi Greg,

if i understand correctly, you are advocating the program
described on http://www.kroah.com/log/linux/free_drivers.html
in order to enable one open source operating system to
support as much hardware as possible, which is certainly
a useful goal. In fact, i am using Linux myself for one
of my servers (the others are running OpenBSD) and for
the majority of the workstations i maintain.

Yet i am concerned about questions of maintainability of
driver code. As far as i understand, the ma...

Feb 14, 10:45 am 2007
Frans Haarman
pf route-to & rdr

when routing packets to another interface, is it then possible to do redirection
for those packets on the other interface ?

I am trying to:
- route subnets to a tunnel
- redirect the subnets to private ip

10.100.1.1 ----> bge0 --- route-to ---> tun0 --- rdr 10.100.1.1 -> 192.168.1.1

I am seeing mostly

2007-02-14 15:29:43.043821 rule 1/0(match): pass out on tun0:
172.16.11.24 > 10.100.1.1: ICMP echo request, id 512, seq 20225,
length 40

So no rdr. Its probably supposed to work...

Feb 14, 10:31 am 2007
Manuel Ravasio
Annoying problem with dnsmasq

Hello all.
I'm trying to set up a firewall/web-proxy/dns-proxy/dhcp-server box at
home, using a quite old i386-based pc (AMD k6-2 300, 256mb RAM, 2x10G
IDE disks) and OpenBSD 4.0.

OS installation, disk management, additional software installation and
configuration... everything went fine.
Problems started in configuring dnsmasq: I managed to make dns
forwarding work ( I really don't need anything more than standard
behaviour), then I created a DHCP range entry:

expand-hosts
domain=manuel.test
...

Feb 14, 10:30 am 2007
The Rogue Fugu
Re: Annoying problem with dnsmasq

On my OpenWRT router, dnsmasq needs to be told that it is
authoritative on dhcp requests with the ``dhcp-authoritative'' keyword
in dnsmasq.conf

--
----
ID: AF133028
fp:9D6B DC0F CCDA 53FA 3F04 A551 BC23 374D AF13 3028

Feb 14, 2:18 pm 2007
Darren Spruell
Re: Annoying problem with dnsmasq

Not sure about anything else you might be missing, but DHCP uses UDP, not TCP.

See if PF is currently blocking traffic to your service(s) also.

DS

Feb 14, 1:53 pm 2007
Giancarlo Razzolini
Re: Annoying problem with dnsmasq

Don't know why you would prefer dnsmasq when the default installation of
OpenBSD already have both ISC dhcpd and bind daemons. I use then, rather
then having to install a package and configure it. Also, if you want a
caching nameserver only, simply putting named_flags= on
/etc/rc.conf.local and opening requests to your internal net only, on
both TCP and UDP port 53, will give a fully functional recursive dns.
And the configuration of /etc/dhcpd.conf is the same as ISC dhcpd. There
is even an exampl...

Feb 14, 2:34 pm 2007
Pete Vickers
Performance problems with bge under OpenBSD4.0/i386

Hi,

I'm trying to track down the cause of poor network performance under
OpenBSD4.0/i386 on HP Proliants (DL380-G4 and DL360-G4p), which seems
to be concerning ethernet 802.3x flow control on the bge NICs.

Test topology is:

HP DL380-G4
int bge0 (BCM5704C auto at 1000baseT full-duplex)
|
|
int Gig 13/6 (auto at 1000baseT full-duplex)
Cisco 6513 chassis + WS-X6548-GE-TX + WS-X6748-GE-TX
int Gig 12/47 (auto at 1000baseT full-duplex)
|
|
int bge0 (BCM5704C auto at 1000...

Feb 14, 8:33 am 2007
Mark Kettenis
Re: Performance problems with bge under OpenBSD4.0/i386

This suggests flow control has *not* been negotiated. With msk(4), I
get:

borodin$ ifconfig msk0
msk0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
lladdr 00:16:cb:a2:87:67
groups: egress
media: Ethernet autoselect (1000baseT full-duplex,rxpause,txpause)
status: active
inet6 fe80::216:cbff:fea2:8767%msk0 prefixlen 64 scopeid 0x1
inet 192.168.0.17 netmask 0xffffff00 broadcast 192.168.0.255

Feb 14, 5:42 pm 2007
Ronnie Garcia
Re: Performance problems with bge under OpenBSD4.0/i386

Did you tweek kernel parameters, like net.inet.ip.ifq.maxlen ?
What is the CPU usage during the transfer ?
Did you try with autonegotiation off, and with speed fixed at 1000base-T
FD on each port ?

--
Ronnie Garcia <r.garcia at ovea dot com>

Feb 14, 9:13 am 2007
Markus Ritzer
I386: Real Mode vs. Protected Mode

Hello!

I would like to know when the CPU is switched into protected mode on i386?

Before or after executing init386() ?
Or does the bootloader / or the BIOS do this?

Markus

Feb 14, 8:19 am 2007
Hannah Schroeter
Re: I386: Real Mode vs. Protected Mode

Hello!

/usr/src/sys/arch/i386/stand/boot/srt0.S, around line 60:
popl %edx
cli
pushl %cs
popl %ds
addr32 data32 lgdt (Gdtr - LINKADDR)
movl %cr0, %eax
orl $CR0_PE, %eax
data32 movl %eax, %cr0
data32 ljmp $8, $1f
1:

Kind regards,

Hannah.
--
Hannah Schrvter Entwicklung hannah@schlund.de
Bei Schlund + Partner AG Brauerstra_e 48 D-76135 Karlsruhe
"Our software isn't released - ...

Feb 14, 10:08 am 2007
Jose Fragoso
slow io operations on xSeries 336

Hi,

I just installed OpenBSD 4.0 on an IBM xSeries 336. I have noticed that, for
some reason,
I/O operations are not carried out as fast as one would expect for a machine
with SCSI
disks. For instance, the creation of a 50GB partion took a really long time.
The command
4tar xzvf ports.tar.gz4 took more than 14 minutes to finish. Something must be
wrong,
but I have no idea nor the knowledge to discover. I took a suggestion from a
old message
in the list and tried to run the .MP kernel, but it di...

Feb 14, 7:59 am 2007
David Gwynne
Re: slow io operations on xSeries 336

thats very... vague...

where are you creating this 50G partitiong? in the installer, or in
the installed operating system? what command did you use?

how long did it actually take? "a really long time" could be 5

that does seem excessive. can you watch the interrupt rates in the

the driver is doing a lot of probing to find what sensors are

Feb 14, 8:51 am 2007
atstake atstake
mediawiki on chroot

I'm getting this error & I understand that I need to symlink some file
inside the chroot (/var/www) area but I'm not sure which file to be
exact. I search previous misc@ archive but they seem a bit confusing.

Warning: dl() [function.dl]: Unable to load dynamic library
'/var/www/lib/php/modules/mysql.so' - File not found in
/mysite/mediawiki/install-utils.inc on line 17
Could not load MySQL driver! Please compile php --with-mysql or
install the mysql.so module.

Here are the necessary packages...

Feb 14, 6:55 am 2007
Stuart Henderson
Re: mediawiki on chroot

You probably didn't do the 'phpxs' after installing php5-mysql

Feb 14, 7:44 am 2007
atstake atstake
named doesn't bind to IP

My named doesn't bind to my private IP and only binds to localhost.

starting BIND 9.3.2-P1
command channel listening on 127.0.0.1#953
command channel listening on ::1#953

I already have the listen-on option in /var/named/etc/named.conf file
pointed to my private IP.

options {
listen-on { 192.168.25.5; };
allow-recursion { clients; };
};

If I do a "named -c /var/named/etc/named.conf" it gives error -

none:0: open: /var/named/etc/named.conf: file not found
loading configuration: file not...

Feb 14, 6:50 am 2007
Giancarlo Razzolini
Re: named doesn't bind to IP

AFAIK, bind on openbsd listen on all interfaces. Even the dynamically
created ones. The only issue i found is, that it doesn't listen on
0.0.0.0 or ::, it listens on each address of each interface. When an
interface is created, like a ppp or a tun interface, it take a time to
listen on that interface. I don't know how long is this time, but it
never was a big deal to me. I think you don't need to set the listen on
option, unless you really need it. And also, you must edit the file
/var/named/etc/name...

Feb 14, 7:48 am 2007
Paul de Weerd
Re: named doesn't bind to IP

On Wed, Feb 14, 2007 at 09:50:07PM +1100, atstake atstake wrote:
| My named doesn't bind to my private IP and only binds to localhost.
|
| starting BIND 9.3.2-P1
| command channel listening on 127.0.0.1#953
| command channel listening on ::1#953
|
| I already have the listen-on option in /var/named/etc/named.conf file
| pointed to my private IP.
|
| options {
| listen-on { 192.168.25.5; };
| allow-recursion { clients; };
| };
|
| If I do a "named -c /var/named/etc/named.conf" it gives error -...

Feb 14, 7:01 am 2007
Artur Grabowski
Re: OT? Is this bad news?

Sue Linux for anti-competitive behavior?

//art

Feb 14, 5:58 am 2007
Han Boetes
Re: OT? Is this bad news?

Nah. You can't sue `linux,' complain to Greg Kroah Hartmann. Most
GPL fans don't want this deal at all. Explain Greg this is
unethical. Just like when you email a manifacturer of hardware
requesting documentation.

# Han

Feb 14, 7:51 am 2007
Matthew R. Dempsky
Re: OT? Is this bad news?

Real GPL fans appear to be an increasingly diminishing subset of Linux
users today though. They're being supplanted by users who want snazzy
3D desktops and simply embrace ``Free Software'' because it's free of
cost.

Feb 14, 11:11 am 2007
Han Boetes
Re: OT? Is this bad news?

I'm afraid you are right. And I can even understand their
reasoning, since they are not really educated on the matter. And
that must be remedied.

In 1915 the Irish resistance against the English occupation was so
strong the English offered a peace-treaty. They offered to divide
Ireland into two sections, one in their control -- Northern
Ireland -- and controled by Ireland itself.

Half of the Irish resistance wanted to fight on for a decent
treaty and the other half wanted to accept the deal.
...

Feb 14, 11:54 am 2007
Stephan A. Rickauer
Free Linux Driver Development!

On the subject of http://www.kroah.com/log/linux/free_drivers.html

Now these companies have a great excuse to keep specs locked up tight
under NDA, while pretending to be "open."

The OpenBSD project has been made clear more than once how this will
hurt Free Software in the long run. Signing NDA's ensures that Linux
gets a working driver, sure, but the internals are indistinguishable
from magic. It is a source code version of a blob.

It now became clear you also don't give a damn about freedom.
...

Feb 14, 3:39 am 2007
Greg KH
Re: Free Linux Driver Development!

I'm guessing that you did not read the followup FAQ about the program
at:
http://www.kroah.com/log/linux/free_drivers_faq.html

Please see the final question and answer on that page.

thanks,

greg k-h

Feb 14, 3:50 am 2007
previous daytodaynext day
NoneFebruary 14, 2007None