elad
68988657cd
Don't allow unprivileged users to access the veriexec device.
2005-06-16 15:31:21 +00:00
elad
faffb35d60
Run veriexec before securelevel and sysctl scripts. Suggested by Nino Dehne.
2005-06-15 18:49:40 +00:00
christos
3ccdf9a0d7
default swapoff to yes, and explain why.
2005-06-15 03:34:45 +00:00
he
c4f693fe6b
Make a simple fix for inculsion of disklabel.h. Since this script
...
doesn't do CPP conditionals, just avoid trying to "include" files
in the newly established nbinclude area, the in-tree version in the
normal place should work fine.
Fixes build problem for (among several others) cats.
2005-06-14 20:47:46 +00:00
tron
abba7e56c8
Enable RAIDframe support in the NetBSD-macppc installation media.
...
Based on patches submitted by Ian Spray in PR port-macppc/30465.
2005-06-09 13:29:57 +00:00
he
82e01bc59d
Now that /var/log/wtmp and /var/log/wtmp should have group=utmp,
...
instruct newsyslog to follow up this when rotating these logs.
2005-06-05 07:33:17 +00:00
bouyer
44d1677f84
Remove support for build.sh -m xen, this has been merged in the i386
...
build. Pointed out by Chuck Silvers.
2005-05-29 10:54:40 +00:00
blymn
c1a5be3d85
Fix naming of the verified exec character device placeholder.
2005-05-28 14:54:06 +00:00
tsutsui
d4c33e9952
Ecoff kernels are no longer needed.
2005-05-23 13:05:04 +00:00
macallan
d2d9cb8374
added wd*
2005-05-23 00:43:13 +00:00
lukem
1bd2839e9a
Consistently use 0664 root:utmp for /var/log/{lastlog,wtmp}{,x}.
...
Rest of PR 18670.
2005-05-22 14:34:20 +00:00
chs
1c2ca83340
add a ramdisk and LIF image for sysinst-based installation.
2005-05-18 14:04:26 +00:00
chs
408467d27a
allow rsh if the user's password is null. from christos.
2005-05-14 15:17:47 +00:00
lukem
e03970d626
correct line for "password"
2005-05-13 02:56:34 +00:00
christos
4aafff6cc5
it makes no sense to check ptyfs for new and gone devices. From Rui Paulo,
...
many thanks.
2005-05-12 14:02:05 +00:00
peter
7147ba1184
PR/30177: Rui Paulo: /var/chroot/pflogd isn't created by default
2005-05-11 10:41:51 +00:00
martin
7a5b2dfb39
Tweak the iso-image support: avoid arbitrary hardcoded sizes - use awk to
...
estimate the real size and round up a bit instead. Doesn't matter much, but
produces a "better" sgi volume header.
While there, simplify a few bits and avoid grep|awk pipes.
2005-05-10 21:58:03 +00:00
martin
5f3107ece4
Add wscons virtual consoles
2005-05-02 13:39:54 +00:00
lukem
b26a3203a3
Add /etc/pam.conf and /etc/pam.d/*
2005-05-02 03:23:43 +00:00
lukem
188cee5c01
Fix previous, caused by premature optimization...
...
Noted by Kirk Russell.
2005-05-02 02:51:04 +00:00
lukem
710a7ff6e8
Use zeropad() and hexprint() instead of printf(1).
2005-05-02 00:47:58 +00:00
lukem
117d01fe78
Add hexprint(); display the given number as hex.
...
Add a comment to document zeropad()'s purpose.
2005-05-02 00:46:46 +00:00
augustss
c246220559
Make /dev/usb readable to all; it is only used to report USB events.
2005-04-30 16:26:06 +00:00
christos
699bb11d46
Add more locale directories in preparation of new gettext.
2005-04-26 19:39:11 +00:00
cjs
2dc0814b72
Make ifaliases_lo0 in rc.conf work just like other interfaces (instead of
...
being ignored). Also, when configuring aliases set as ifaliases_xxN,
print out the interface name and the alias address.
2005-04-26 10:28:29 +00:00
martin
441f539b14
Pickup bootblock.h from $DESTDIR to make this work when crosscompiling.
2005-04-22 09:49:45 +00:00
blymn
8387760ed1
Rototill of the verified exec functionality.
...
* We now use hash tables instead of a list to store the in kernel
fingerprints.
* Fingerprint methods handling has been made more flexible, it is now
even simpler to add new methods.
* the loader no longer passes in magic numbers representing the
fingerprint method so veriexecctl is not longer kernel specific.
* fingerprint methods can be tailored out using options in the kernel
config file.
* more fingerprint methods added - rmd160, sha256/384/512
* veriexecctl can now report the fingerprint methods supported by the
running kernel.
* regularised the naming of some portions of veriexec.
2005-04-20 13:44:45 +00:00
lukem
8232ca0162
Tweaks for the move of postinstall from /etc to /usr/sbin
2005-04-17 23:12:40 +00:00
lukem
5c5750a595
Move /etc/postinstall (and the etc.tgz set) to /usr/sbin/postinstall
...
(and the base.tgz set).
2005-04-17 15:15:48 +00:00
lukem
41595413ba
elaborate on sysctl rename
2005-04-16 04:19:24 +00:00
kleink
7a5e7ac8e9
Adjust for the Argentina directory that came with tzdata2004b;
...
noted by Geoff C. Wing in PR bin/29954.
2005-04-12 15:35:54 +00:00
jwise
bfd29aa656
/var/chroot/spamd is now /var/chroot/pfspamd.
2005-04-12 14:24:32 +00:00
peter
271ad04cd9
Allow an underscore as first character and embedded underscores & dots
...
for login and group names.
Fixes PR misc/29913 from Arto Selonen.
2005-04-11 15:46:42 +00:00
bouyer
4b058b80fb
Add xencons to the default list of devices. Fix port-xen/29887 by Juan RP.
2005-04-06 21:06:28 +00:00
peter
c37e23a1f9
Add _pflogd group.
2005-04-05 19:57:30 +00:00
christos
96cf4771d1
PR/29891: Arto Selonen: su(1) does not seem to honor SU_ROOTAUTH any more
...
Move the rootauth group line before the wheel check, so that rootauth users
are not required to be in wheel [still commented out]
2005-04-05 18:23:36 +00:00
peter
ee8532311f
Add _pflogd to the uid check. Pointed out by Luke Mewburn.
2005-04-05 07:03:33 +00:00
peter
80271013f5
Add the _pflogd user which will be used by pflogd(8), the logging daemon
...
for pf(4).
Approved by core.
2005-04-04 19:06:43 +00:00
lukem
c0372ca1ef
ypserv(8) doesn't need the domainname(1) set -- it will serve any maps
...
present under /var/yp/<somedomain>/<map> -- so don't require it.
Thanks to Chuck Cranor for the suggestion.
2005-04-01 23:25:29 +00:00
peter
7c4b722858
Add pf to the all target. Pointed out by Steve Rumble.
2005-04-01 21:07:01 +00:00
lukem
d45db391ec
Install all obsolete X11 sets (even empty ones).
2005-03-28 03:13:39 +00:00
tnozaki
a3b248100e
add csmapper:CNS11643-1,2 and esdb:ISO-2022-CN,
...
integrate esdb:EUC-TW, locale:zh_TW.eucTW.
2005-03-27 22:30:05 +00:00
tron
f1f5ecd1a9
We must check for "${MACHINE}" and not "${MACHINE_ARCH}" of course to
...
decide about port specific obsolete lists.
2005-03-25 20:15:20 +00:00
tron
728512171e
Checking for the file "xserver" in "${OBSOLETE.dir}" doesn't work because
...
the check will be done before the target which is used to create that file.
So simply add "xserver" to "${OBSOLETE.file}" based on the architecture.
2005-03-24 20:23:55 +00:00
martin
6ebdd24d9a
Make var/db/obsolete/xserver optional.
2005-03-24 09:07:17 +00:00
rtr
c6b047ea8b
+ do not install getconfig
2005-03-24 05:27:18 +00:00
rtr
80843b35d1
+ getconfig scripts and configs
2005-03-22 21:43:24 +00:00
lukem
857d896931
-s can be given 'etc.tgz' directly. (Thanks to hubertf for the reminder)
...
Improve usage.
2005-03-22 04:43:53 +00:00
tron
fb571c8922
Add support for handling obsolete X11 files and directories.
2005-03-21 23:09:39 +00:00
tron
96f232123e
Remove directory which got obsoleted by XFree86 4.5.0.
2005-03-21 14:45:19 +00:00