linux: implement sched_getattr()
This change adds the necessary glue to translate Linux scheduler policy
and priority from FreeBSD so this information is available to Linux
applications.
This unbreaks using the Linux version of Chromium on FreeBSD.
This change was originally submitted via [freebsd/freebsd-src#2370][github-pr].
MFC after: 2 weeks
PR: 297468
Co-Authored-By: Enji Cooper <ngie at FreeBSD.org>
Signed-off-by: Joao Bonifacio <joaoboni017 at gmail.com>
[github-pr]: https://github.com/freebsd/freebsd-src/pull/2370
Differential Revision: https://reviews.freebsd.org/D60214
ufssuspend(4): mark non-passable
This fixes long-standing issue where ufssuspend file descriptor could
leak over fork or be passed over unix domain socket, and then closing it
in the opener would not unsuspend the file system.
It should not affect the well-behaving growfs(8) utility, but makes the
userspace API safer on principle.
Reviewed by: markj
Tested by: pho (previous version)
Sponsored by: The FreeBSD Foundation
MFC after: 1 week
Differential revision: https://reviews.freebsd.org/D60285
cdevsw: add D_NONPASSABLE flag
to make the opened device files non-passable.
Reviewed by: markj
Tested by: pho (previous version)
Sponsored by: The FreeBSD Foundation
MFC after: 1 week
Differential revision: https://reviews.freebsd.org/D60285
security/snort: Use libpcap from ports
Summary:
Add explicit lib version to force port to use libpcap from ports and
avoid it rebuilding every time base packages are upgraded
Sponsored by: Rubicon Communications, LLC ("Netgate")
Reviewed By: dvl
Differential Revision: https://reviews.freebsd.org/D60381
security/snort3: Use libpcap from ports
Summary:
Add explicit lib version to force port to use libpcap from ports and
avoid it rebuilding every time base packages are upgraded
Sponsored by: Rubicon Communications, LLC ("Netgate")
Reviewed By: bofh
Differential Revision: https://reviews.freebsd.org/D60383
net/libdaq: Use libpcap from ports
Add explicit lib version to force port to use libpcap from ports and
avoid it rebuilding every time base packages are upgraded
Sponsored by: Rubicon Communications, LLC ("Netgate")
Reviewed By: bofh
Differential Revision: https://reviews.freebsd.org/D60383
security/vuxml: Fix entry for expat2 CVE-2026-93990
expat2 package is using expat as package name
PR: 299162
Reported by: Tomáš Čiernik <tomas at ciernik.sk>
www/evcc: update to 0.316.2
Switch back to vite for building till vite-plus got full native
FreeBSD support (vite-plus tries to download linux binaries).
Switched back to node24, node26 core-dumps while executing npm.
e1000: Fix the flow control sysctl
dev.em.N.fc and dev.igb.N.fc read and wrote a function-static variable
shared by every em(4) and igb(4) device, so a read returned the last
value written to any of them (3 until the first write), not the state of
the device. The softc value started as 0, which is also the value of
"no flow control", while the hardware was set up for full flow control.
As a result:
- Writing 0 was taken for no change and did nothing, unless another
value had been written to that device before.
- em_reset() took a softc value of 0 for "not set", so a device set to 0
went back to full flow control on the next init.
- On igb(4) with more than one receive queue the driver enabled
per-queue drop (SRRCTL.DROP_EN), which is meant for a MAC that does
not send pause frames, although the MAC was told to send them.
- Values out of range were accepted and ignored.
A write only forced the MAC's flow control bits. The pause bits
[18 lines not shown]
sys.mk: CTFMERGE: don't assume objfiles always have CTF sections
There are many instances, e.g. in the kernel, where
object files don't have CTF sections, but still need
to be merged into one that does have a CTF section.
This fixes cases like the following:
--------------------------------------------------------------
>>> stage 3.1: building everything
--------------------------------------------------------------
linking kernel.full
ctfmerge -t -L VERSION -g -o kernel.full ...
ERROR: ctfmerge: Input file force-dynamic-hack.pico was partially built from C sources, but no CTF data was present
Removing kernel.full
kernel.full ---
[kernel.full] Error code 1
[8 lines not shown]