From: Stuart Henderson Subject: Re: [UPDATE] net/i2pd: update to 2.61.0 To: David Uhden Collado Cc: ports@openbsd.org, openbsd@systemfailure.net, lucas@sexy.is Date: Wed, 22 Jul 2026 18:23:56 +0100 On 2026/07/22 16:16, David Uhden Collado wrote: > Stuart Henderson wrote: > > On 2026/07/22 15:25, David Uhden Collado wrote: > > > Stuart Henderson wrote: > > > > we are pretty conservative in what is automatically run by pkg_add, > > > > to my eye this is too much. > > > > > > > > I wouldn't object to installing a script and asking the user to run it, > > > > though I think by default it should just print the operations needed so > > > > the user can review (maybe with a flag to run them automatically after > > > > checking). > > > > > > > > there should not be an @bin marker for scripts. > > > > > > > > the revised pledge still feels like shoehorning it into a program > > > > which has not been designed to actually work with it. big clue > > > > is having file access and network access in the same process. > > > > (sure, there's worse in ports, and it's not a total blocker, but > > > > it does make me wonder how well tested it's been, because clearly > > > > there hasn't been too much careful thought about how to use this > > > > prior to it being committed uptream..) > > > > > > > Hello Stuart, > > > > > > Earlier, you mentioned that users would not normally make these changes > > > themselves, so the migration should be automated and made as robust as > > > possible. That is what I have tried to implement. > > > > I think you refer to this that I wrote earlier? > > > > +----- > > | > @newgroup _i2pd:838 > > | > -@newuser _i2pd:838:838::i2pd account:${LOCALSTATEDIR}/lib/i2pd:/sbin/nologin > > | > +@newuser _i2pd:838:838::i2pd account:${LOCALSTATEDIR}/i2pd:/sbin/nologin > > | > > | This will not get changed for users with existing installs > > | so there will need to be some documentation about how to do that. > > +----- > > > > What I mean is: pkg_add will not automatically change this if the user > > has previously installed an old version. (We generally consider this > > too risky if the user changed something in a way that pkg_add / the > > package doesn't expect). > > > > We normally don't make changes like this in ports because of the extra > > hassle for upgrading users. However if it is unavoidable then there must > > be information for users to follow. I didn't say anything about > > automating it (and actually making the changes automatically without > > user review first seems risky in the same way it would be for pkg_add > > to update /etc/passwd lines directly). > > > Hello Stuart, > > Thanks for the clarification. I misunderstood your earlier comment and > assumed that the migration should be performed without first asking the > user. > > I have now added an @ask-update entry so that pkg_add explains the directory > migration and asks the user for confirmation before running the migration > script. The script itself remains non-interactive. > > The migration only runs during an update from an older i2pd package. It > copies existing .dat files without overwriting destination files, leaves the > original files under /var/lib/i2pd untouched, and changes the _i2pd home > directory only if it is still set to the old default. > > I have attached the revised patch. > > Best regards, > David. > ? patches > Index: Makefile > =================================================================== > RCS file: /cvs/ports/net/i2pd/Makefile,v > diff -u -p -u -r1.33 Makefile > --- Makefile 21 Feb 2026 14:20:20 -0000 1.33 > +++ Makefile 22 Jul 2026 16:09:34 -0000 > @@ -2,7 +2,7 @@ COMMENT = client for the I2P anonymous n > > GH_ACCOUNT = PurpleI2P > GH_PROJECT = i2pd > -GH_TAGNAME = 2.59.0 > +GH_TAGNAME = 2.61.0 > > CATEGORIES = net > HOMEPAGE = https://i2pd.website > @@ -12,9 +12,10 @@ MAINTAINER = SystemFailure # BSD > PERMIT_PACKAGE = Yes > > +# uses pledge() and unveil() > WANTLIB += ${COMPILER_LIBCXX} > WANTLIB += boost_filesystem-mt boost_program_options-mt > -WANTLIB += boost_atomic-mt c crypto m miniupnpc ssl z > +WANTLIB += boost_atomic-mt boost_container-mt c crypto m miniupnpc ssl z > > COMPILER = base-clang ports-gcc > MODULES = devel/cmake > @@ -29,6 +30,8 @@ CONFIGURE_ARGS = -DWITH_UPNP=ON > WRKSRC = ${WRKDIST}/build > > post-install: > + ${INSTALL_DATA_DIR} ${PREFIX}/libexec > + ${INSTALL_SCRIPT} ${FILESDIR}/i2pd-migrate ${PREFIX}/libexec/i2pd-migrate > ${INSTALL_DATA_DIR} ${PREFIX}/include/i2pd > ${INSTALL_DATA} ${WRKDIST}/libi2pd{,_client}/*.h \ > ${PREFIX}/include/i2pd > Index: distinfo > =================================================================== > RCS file: /cvs/ports/net/i2pd/distinfo,v > diff -u -p -u -r1.26 distinfo > --- distinfo 21 Feb 2026 14:20:20 -0000 1.26 > +++ distinfo 22 Jul 2026 16:09:34 -0000 > @@ -1,2 +1,2 @@ > -SHA256 (i2pd-2.59.0.tar.gz) = Dr6wXk82qzgJRJVhoJXcdnrYIaxqYclWI6tJvk/9OYs= > -SIZE (i2pd-2.59.0.tar.gz) = 743516 > +SHA256 (i2pd-2.61.0.tar.gz) = QJzTwCV0kShmEatqr2kJQMckj7iYN3wT+ttlqDbioKs= > +SIZE (i2pd-2.61.0.tar.gz) = 779272 > Index: files/i2pd-migrate > =================================================================== > RCS file: files/i2pd-migrate > diff -N files/i2pd-migrate > --- /dev/null 1 Jan 1970 00:00:00 -0000 > +++ files/i2pd-migrate 22 Jul 2026 16:09:34 -0000 > @@ -0,0 +1,94 @@ > +#!/bin/ksh > + > +# Copy the old package data directory before changing the _i2pd home. > +# This script is run by pkg_add, not while the package is being built. > + > +old=/var/lib/i2pd > +new=/var/i2pd > + > +failed() > +{ > + printf '%s\n' "$2" >>"$1" > + printf 'i2pd migration: unable to copy %s\n' "$2" >&2 > +} > + > +copy_dat() > +{ > + status_file=$1 > + src=$2 > + rel=${src#"$old"/} > + dst=$new/$rel > + dir=${dst%/*} > + > + if [ -e "$dst" ] || [ -L "$dst" ]; then > + if [ -f "$dst" ] && [ ! -L "$dst" ]; then > + printf 'i2pd migration: leaving existing file unchanged: %s\n' \ > + "$dst" >&2 > + return 0 > + fi > + failed "$status_file" "$src (destination is not a regular file)" > + return 1 > + fi > + > + if ! mkdir -p "$dir" || ! chown _i2pd:_i2pd "$dir" || \ > + ! chmod 0750 "$dir"; then > + failed "$status_file" "$src (cannot prepare $dir)" > + return 1 > + fi > + if ! cp -p "$src" "$dst" || ! chown _i2pd:_i2pd "$dst"; then > + failed "$status_file" "$src -> $dst" > + return 1 > + fi > + printf 'i2pd migration: copied %s -> %s\n' "$src" "$dst" > +} > + > +if [ "$1" = --copy ]; then > + copy_dat "$2" "$3" > + exit $? > +fi > + > +if [ ! -d "$old" ]; then > + exit 0 > +fi > + > +if [ -L "$old" ]; then > + printf 'i2pd migration: refusing to follow symbolic-link directory: %s\n' \ > + "$old" >&2 > + exit 1 > +fi > + > +status=$(mktemp -d /tmp/i2pd-migrate.XXXXXXXX) || exit 1 > +trap 'rm -rf "$status"' EXIT > + > +if ! mkdir -p "$new" || ! chown _i2pd:_i2pd "$new" || \ > + ! chmod 0750 "$new"; then > + printf 'i2pd migration: unable to prepare %s\n' "$new" >&2 > + exit 1 > +fi > + > +if [ -d "$old" ]; then > + if ! find "$old" -type f -name '*.dat' -exec "$0" \ > + --copy "$status/status" {} \;; then > + printf 'i2pd migration: error while searching %s\n' "$old" >&2 > + exit 1 > + fi > + if [ -s "$status/status" ]; then > + printf 'i2pd migration: one or more files were not copied; keeping _i2pd home unchanged\n' >&2 > + exit 1 > + fi > +fi > + > +entry=$(getent passwd _i2pd) || { > + printf 'i2pd migration: cannot inspect _i2pd account; keeping home unchanged\n' >&2 > + exit 1 > +} > +home=$(printf '%s\n' "$entry" | cut -d: -f6) > +if [ "$home" = /var/lib/i2pd ]; then > + if ! usermod -d /var/i2pd _i2pd; then > + printf 'i2pd migration: unable to change _i2pd home directory\n' >&2 > + exit 1 > + fi > + printf 'i2pd migration: changed _i2pd home to /var/i2pd\n' > +fi > + > +exit 0 > Index: pkg/PLIST > =================================================================== > RCS file: /cvs/ports/net/i2pd/pkg/PLIST,v > diff -u -p -u -r1.18 PLIST > --- pkg/PLIST 21 Feb 2026 14:20:20 -0000 1.18 > +++ pkg/PLIST 22 Jul 2026 16:09:34 -0000 > @@ -1,7 +1,9 @@ > @newgroup _i2pd:838 > -@newuser _i2pd:838:838::i2pd account:${LOCALSTATEDIR}/lib/i2pd:/sbin/nologin > +@newuser _i2pd:838:838::i2pd account:${LOCALSTATEDIR}/i2pd:/sbin/nologin > @rcscript ${RCDIR}/i2pd > @bin bin/i2pd > +@ask-update i2pd-<2.61.0 The i2pd data directory has moved from /var/lib/i2pd to /var/i2pd. Existing .dat files will be copied without overwriting files. > +@bin libexec/i2pd-migrate > include/i2pd/ > include/i2pd/AddressBook.h > include/i2pd/BOB.h > @@ -29,6 +31,7 @@ include/i2pd/I2NPProtocol.h > include/i2pd/I2PEndian.h > include/i2pd/I2PService.h > include/i2pd/I2PTunnel.h > +include/i2pd/IdentMetrics.h > include/i2pd/Identity.h > include/i2pd/KadDHT.h > include/i2pd/LeaseSet.h > @@ -54,6 +57,7 @@ include/i2pd/Socks5.h > include/i2pd/Streaming.h > include/i2pd/Tag.h > include/i2pd/Timestamp.h > +include/i2pd/Torrents.h > include/i2pd/TransitTunnel.h > include/i2pd/TransportSession.h > include/i2pd/Transports.h > @@ -69,14 +73,17 @@ include/i2pd/util.h > include/i2pd/version.h > @static-lib lib/libi2pd.a > @static-lib lib/libi2pdclient.a > +@mode 0750 > @owner _i2pd > @group _i2pd > @sample ${SYSCONFDIR}/i2pd/ > -@sample ${LOCALSTATEDIR}/lib/i2pd/ > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/ > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/family/ > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/ > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/router/ > +@mode > +@sample ${LOCALSTATEDIR}/i2pd/ > +@exec-update %D/libexec/i2pd-migrate > +@sample ${LOCALSTATEDIR}/i2pd/certificates/ > +@sample ${LOCALSTATEDIR}/i2pd/certificates/family/ > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/ > +@sample ${LOCALSTATEDIR}/i2pd/certificates/router/ > @owner > @group > @static-lib lib/libi2pdlang.a > @@ -87,139 +94,150 @@ share/examples/i2pd/certificates/family/ > share/examples/i2pd/certificates/family/gostcoin.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/family/gostcoin.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/family/gostcoin.crt > @owner > @group > share/examples/i2pd/certificates/family/i2p-dev.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/family/i2p-dev.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/family/i2p-dev.crt > @owner > @group > share/examples/i2pd/certificates/family/i2pd-dev.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/family/i2pd-dev.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/family/i2pd-dev.crt > @owner > @group > share/examples/i2pd/certificates/family/mca2-i2p.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/family/mca2-i2p.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/family/mca2-i2p.crt > @owner > @group > share/examples/i2pd/certificates/family/stormycloud.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/family/stormycloud.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/family/stormycloud.crt > @owner > @group > share/examples/i2pd/certificates/family/volatile.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/family/volatile.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/family/volatile.crt > @owner > @group > share/examples/i2pd/certificates/reseed/ > +share/examples/i2pd/certificates/reseed/acetone_at_mail.i2p.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/ > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/acetone_at_mail.i2p.crt > @owner > @group > -share/examples/i2pd/certificates/reseed/acetone_at_mail.i2p.crt > +share/examples/i2pd/certificates/reseed/admin_at_likogan.dev.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/acetone_at_mail.i2p.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/admin_at_likogan.dev.crt > @owner > @group > share/examples/i2pd/certificates/reseed/admin_at_stormycloud.org.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/admin_at_stormycloud.org.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/admin_at_stormycloud.org.crt > @owner > @group > share/examples/i2pd/certificates/reseed/creativecowpat_at_mail.i2p.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/creativecowpat_at_mail.i2p.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/creativecowpat_at_mail.i2p.crt > @owner > @group > share/examples/i2pd/certificates/reseed/diyarciftci_at_protonmail.com.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/diyarciftci_at_protonmail.com.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/diyarciftci_at_protonmail.com.crt > @owner > @group > share/examples/i2pd/certificates/reseed/echelon3_at_mail.i2p.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/echelon3_at_mail.i2p.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/echelon3_at_mail.i2p.crt > @owner > @group > share/examples/i2pd/certificates/reseed/hankhill19580_at_gmail.com.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/hankhill19580_at_gmail.com.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/hankhill19580_at_gmail.com.crt > @owner > @group > share/examples/i2pd/certificates/reseed/i2p-reseed_at_mk16.de.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/i2p-reseed_at_mk16.de.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/i2p-reseed_at_mk16.de.crt > @owner > @group > share/examples/i2pd/certificates/reseed/igor_at_novg.net.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/igor_at_novg.net.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/igor_at_novg.net.crt > @owner > @group > share/examples/i2pd/certificates/reseed/lazygravy_at_mail.i2p.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/lazygravy_at_mail.i2p.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/lazygravy_at_mail.i2p.crt > @owner > @group > share/examples/i2pd/certificates/reseed/orignal_at_mail.i2p.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/orignal_at_mail.i2p.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/orignal_at_mail.i2p.crt > @owner > @group > share/examples/i2pd/certificates/reseed/r4sas-reseed_at_mail.i2p.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/r4sas-reseed_at_mail.i2p.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/r4sas-reseed_at_mail.i2p.crt > @owner > @group > share/examples/i2pd/certificates/reseed/rambler_at_mail.i2p.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/rambler_at_mail.i2p.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/rambler_at_mail.i2p.crt > @owner > @group > share/examples/i2pd/certificates/reseed/reseed_at_diva.exchange.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/reseed_at_diva.exchange.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/reseed_at_diva.exchange.crt > @owner > @group > share/examples/i2pd/certificates/reseed/sahil_at_mail.i2p.crt > @owner _i2pd > @group _i2pd > -@sample ${LOCALSTATEDIR}/lib/i2pd/certificates/reseed/sahil_at_mail.i2p.crt > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/sahil_at_mail.i2p.crt > @owner > @group > -share/examples/i2pd/i2pd.conf > +share/examples/i2pd/certificates/reseed/vserod1488_at_proton.me.crt > @owner _i2pd > @group _i2pd > +@sample ${LOCALSTATEDIR}/i2pd/certificates/reseed/vserod1488_at_proton.me.crt > +@owner > +@group > +share/examples/i2pd/i2pd.conf > +@mode 0640 > +@owner root > +@group _i2pd > @sample ${SYSCONFDIR}/i2pd/i2pd.conf > +@mode > @owner > @group > share/examples/i2pd/tunnels.conf > -@owner _i2pd > +@mode 0640 > +@owner root > @group _i2pd > @sample ${SYSCONFDIR}/i2pd/tunnels.conf > +@mode > @owner > @group > share/examples/login.conf.d/i2pd > Index: pkg/README > =================================================================== > RCS file: /cvs/ports/net/i2pd/pkg/README,v > diff -u -p -u -r1.4 README > --- pkg/README 16 Apr 2024 15:22:32 -0000 1.4 > +++ pkg/README 22 Jul 2026 16:09:34 -0000 > @@ -5,7 +5,7 @@ > Resource Limits: File Descriptors > ================================= > > -${PKGSTEM} needs to open a lot of file descriptors. > +i2pd needs to open a lot of file descriptors. > > For a regular node, you should raise the system-wide maxfiles limit to > 8192: > @@ -24,3 +24,67 @@ and also edit /etc/login.conf.d/i2pd: > :openfiles-cur=8192:\ > :openfiles-max=8192:\ > :tc=daemon: > + > + > +The HTTP interface > +================== > + > +On OpenBSD, i2pd's HTTP interface is disabled by default, because it > +allows any user on the system to perform actions on the daemon, such > +as shutting it down, or access private data, such as the router > +identity and the tunnels' B32 addresses. > + > +If you want to use this interface anyway, you can reenable it in > +${SYSCONFDIR}/i2pd/i2pd.conf under the [http] section. > + > + > +Data directory migration > +========================= > + > +When this package is installed or upgraded, any .dat files found under > +/var/lib/i2pd are copied to the same relative paths under /var/i2pd. > +Existing destination files are never overwritten. The old files and > +/var/lib/i2pd are not deleted. The _i2pd home directory is changed to > +/var/i2pd only when it still has the old package default, > +/var/lib/i2pd. Administrators should verify the migration before > +manually removing /var/lib/i2pd. > + > + > +Graceful shutdown > +================= > + > +It is good practice to shutdown the i2pd daemon gracefully, to avoid > +immediately severing all connections, which would disconnect all > +your peers and affect the overall operation of the I2P network. > + > +You can initiate a graceful shutdown without the HTTP interface by > +sending a signal to the i2pd daemon like this: > + > + kill -INT $(cat /var/i2pd/i2pd.pid) > + > +When it shuts down gracefully, the i2pd daemon waits for all transit > +tunnels to expire, which usually takes 10 minutes. > + > + > +Logging > +======= > + > +By default, this package sends its log messages to > +syslogd(8), which writes them to the /var/log/daemon file. > + > +The default log level of i2pd ("warn") can be very verbose. You > +may want to reduce this log verbosity by changing the "loglevel" > +parameter in ${SYSCONFDIR}/i2pd/i2pd.conf. > + > +If you want log messages to be written to another file, e.g. > +${LOCALSTATEDIR}/i2pd/i2pd.log, you can change the "log" and "logfile" > +parameters in ${SYSCONFDIR}/i2pd/i2pd.conf. To have this log file > +rotated automatically, you can add an entry to /etc/newsyslog.conf using the i2pd pid > +file so that newsyslog(8) can send SIGHUP to the daemon after rotation. > + > +For example: > + > + ${LOCALSTATEDIR}/i2pd/i2pd.log _i2pd:_i2pd 644 6 * $D13 Z ${LOCALSTATEDIR}/i2pd/i2pd.pid > + > +Sending SIGHUP is enough for log rotation, and also makes i2pd reload > +its tunnel configuration and rotate transient keys. > Index: pkg/i2pd.rc > =================================================================== > RCS file: /cvs/ports/net/i2pd/pkg/i2pd.rc,v > diff -u -p -u -r1.4 i2pd.rc > --- pkg/i2pd.rc 11 Mar 2022 19:46:04 -0000 1.4 > +++ pkg/i2pd.rc 22 Jul 2026 16:09:34 -0000 > @@ -2,7 +2,12 @@ > > daemon="${TRUEPREFIX}/bin/i2pd --daemon" > daemon_user="_i2pd" > -daemon_flags="--service --datadir=${LOCALSTATEDIR}/lib/i2pd --conf=${SYSCONFDIR}/i2pd/i2pd.conf --tunconf=${SYSCONFDIR}/i2pd/tunnels.conf --tunnelsdir=${SYSCONFDIR}/i2pd/tunnels.d" > +daemon_flags="--service \ > + --datadir=${LOCALSTATEDIR}/i2pd \ > + --conf=${SYSCONFDIR}/i2pd/i2pd.conf \ > + --tunconf=${SYSCONFDIR}/i2pd/tunnels.conf \ > + --tunnelsdir=${SYSCONFDIR}/i2pd/tunnels.d \ > + --certsdir=${LOCALSTATEDIR}/i2pd/certificates" > > . /etc/rc.d/rc.subr > > Index: patches/patch-daemon_Daemon_cpp > =================================================================== > RCS file: patches/patch-daemon_Daemon_cpp > diff -N patches/patch-daemon_Daemon_cpp > --- /dev/null 1 Jan 1970 00:00:00 -0000 > +++ patches/patch-daemon_Daemon_cpp 22 Jul 2026 16:09:35 -0000 > @@ -0,0 +1,13 @@ > +Use only the pledge promises required by i2pd. It forks when daemonizing > +and locks its pidfile, but does not use the other promises from upstream's > +default set. > + > +Index: daemon/Daemon.cpp > +--- daemon/Daemon.cpp.orig > ++++ daemon/Daemon.cpp > +@@ -115,4 +115,3 @@ > + LogPrint(eLogDebug, "Use default pledge values"); > +- // TODO: remove that not need > +- pledge("stdio rpath wpath cpath inet dns unix recvfd sendfd proc error mcast chown flock",nullptr); > ++ pledge("stdio rpath wpath cpath inet dns unix proc flock", nullptr); > + } else { When I say "user review" I mean "actual review of the changes that it intends to make", not "is it ok if I do some stuff as root from a shell script that I'm not going to show you first"