From owner-svn-src-projects@freebsd.org Sat Oct 31 02:47:40 2020 Return-Path: Delivered-To: svn-src-projects@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 74129465D11 for ; Sat, 31 Oct 2020 02:47:40 +0000 (UTC) (envelope-from rmacklem@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "Let's Encrypt Authority X3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4CNNrX2XhKz3c4V; Sat, 31 Oct 2020 02:47:40 +0000 (UTC) (envelope-from rmacklem@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 3B941208F7; Sat, 31 Oct 2020 02:47:40 +0000 (UTC) (envelope-from rmacklem@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id 09V2leYj028666; Sat, 31 Oct 2020 02:47:40 GMT (envelope-from rmacklem@FreeBSD.org) Received: (from rmacklem@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id 09V2ldjW028663; Sat, 31 Oct 2020 02:47:39 GMT (envelope-from rmacklem@FreeBSD.org) Message-Id: <202010310247.09V2ldjW028663@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: rmacklem set sender to rmacklem@FreeBSD.org using -f From: Rick Macklem Date: Sat, 31 Oct 2020 02:47:39 +0000 (UTC) To: src-committers@freebsd.org, svn-src-projects@freebsd.org Subject: svn commit: r367191 - projects/nfs-over-tls/rc.d X-SVN-Group: projects X-SVN-Commit-Author: rmacklem X-SVN-Commit-Paths: projects/nfs-over-tls/rc.d X-SVN-Commit-Revision: 367191 X-SVN-Commit-Repository: base MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-projects@freebsd.org X-Mailman-Version: 2.1.33 Precedence: list List-Id: "SVN commit messages for the src " projects" tree" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 31 Oct 2020 02:47:40 -0000 Author: rmacklem Date: Sat Oct 31 02:47:39 2020 New Revision: 367191 URL: https://svnweb.freebsd.org/changeset/base/367191 Log: Add a new rc.d script that enables the kernel tls and make the other scripts depend on it. Added: projects/nfs-over-tls/rc.d/ktls Modified: projects/nfs-over-tls/rc.d/tlsclntd projects/nfs-over-tls/rc.d/tlsservd Added: projects/nfs-over-tls/rc.d/ktls ============================================================================== --- /dev/null 00:00:00 1970 (empty, because file is newly added) +++ projects/nfs-over-tls/rc.d/ktls Sat Oct 31 02:47:39 2020 (r367191) @@ -0,0 +1,39 @@ +#!/bin/sh +# +# $FreeBSD$ +# + +# PROVIDE: ktls +# REQUIRE: NETWORKING +# KEYWORD: shutdown + +. /etc/rc.subr + +name="ktls" +desc="Enable Kernel TLS" +rcvar="ktls_enable" +start_cmd="${name}_start" +stop_cmd=":" + +ktls_start() +{ + + sysctl -q kern.ipc.tls.enable=1 > /dev/null + err=$? + if [ "${err}" -ne 0 ]; then + warn "kernel must be built with options KERN_TLS for ktls" + return "${err}" + fi + sysctl kern.ipc.mb_use_ext_pgs=1 > /dev/null + + # + # Load ktls_ocf and optionally aesni + # + load_kld ktls_ocf + if checkyesno ktls_aesni_enable; then + load_kld aesni + fi +} + +load_rc_config $name +run_rc_command "$1" Modified: projects/nfs-over-tls/rc.d/tlsclntd ============================================================================== --- projects/nfs-over-tls/rc.d/tlsclntd Sat Oct 31 01:12:35 2020 (r367190) +++ projects/nfs-over-tls/rc.d/tlsclntd Sat Oct 31 02:47:39 2020 (r367191) @@ -4,7 +4,7 @@ # # PROVIDE: tlsclntd -# REQUIRE: NETWORKING +# REQUIRE: NETWORKING root mountcritlocal ktls # KEYWORD: nojail shutdown . /etc/rc.subr Modified: projects/nfs-over-tls/rc.d/tlsservd ============================================================================== --- projects/nfs-over-tls/rc.d/tlsservd Sat Oct 31 01:12:35 2020 (r367190) +++ projects/nfs-over-tls/rc.d/tlsservd Sat Oct 31 02:47:39 2020 (r367191) @@ -4,7 +4,7 @@ # # PROVIDE: tlsservd -# REQUIRE: NETWORKING +# REQUIRE: NETWORKING root mountcritlocal ktls # KEYWORD: nojail shutdown . /etc/rc.subr