nd6: Do not allocate an ifaddr for the interface ID in in6_ifadd()
Without a suitable link-local address, in6_ifadd() obtains the
interface identifier from in6_get_ifid(). It wrote the result into a
freshly allocated struct in6_ifaddr, M_NOWAIT since the function runs
in the network epoch, so SLAAC could fail under memory pressure over a
16 byte scratch buffer.
Write the identifier into the on-stack address the rest of the function
uses instead. Zero it first, in6_get_ifid() only fills in the low 64
bits, as the M_ZERO allocation did. Track which path provided the
identifier with a flag instead of a pointer into the ifaddr, so each
path releases its own reference.
Reviewed by: glebius
Fixes: 9e792f7ef729 ("sys/netinet6: Fix SLAAC for interfaces with no /64 LL address")
Fixes: f9fc93690aef ("sys/netinet6: fix memory corruption in in6_ifadd")
MFC after: 2 weeks
Sponsored by: Rubicon Communications, LLC ("Netgate")
Differential Revision: https://reviews.freebsd.org/D60488
openssl: make libcrypto export the same symbols as upstream
Make the libcrypto Version.map export the same symbol names as upstream
3.5.8 (and 3.5.9, no new symbols were added).
Remove 52 names that upstream does not export:
- the internal threading and record layer functions (ossl_crypto_*,
ssl3_cbc_*, tls1_cbc_*), which only libssl used;
- the internal WPACKET_quic_* functions;
- OPENSSL_cpuid_setup;
- ASN.1 item functions that are not in util/libcrypto.num.
Add 7 public names that were missing (ASYNC_get_mem_functions,
ASYNC_set_mem_functions, CMS_EnvelopedData_it, EVP_CipherPipeline*) to
OPENSSL_3_5_0, where the other symbols from upstream 3.1 to 3.5 are.
EC_GFp_nistp224_method, EC_GFp_nistp256_method and
EC_GFp_nistp521_method stay unexported (see 6f6446b33064).
[9 lines not shown]
lang/go126: Update to 1.26.9
Changes:
go1.26.9 (released 2026-10-08) includes security fixes to the go
command, and the crypto/tls, html/template, net/http, net/textproto,
and os packages, as well as bug fixes to the compiler, the linker, the
runtime, vet, and the crypto/mlkem, net/http, and os packages.
MFH: 2026Q4
(cherry picked from commit 9583bcae74f36ce7837a95ba2e9b048d22aa3658)
lang/go127: Update to 1.27.2
Changes:
go1.27.2 (released 2026-10-08) includes security fixes to the go
command, and the crypto/tls, html/template, net/http, net/textproto,
and os packages, as well as bug fixes to the compiler, the linker,
the runtime, the cover tool, the go fix command, vet, and the
compress/flate, crypto/mlkem, encoding/json, encoding/json/v2,
net/http, and os packages.
MFH: 2026Q4
(cherry picked from commit 7f174351b4e219a480af36f815025ae950fdade0)
lang/go126: Update to 1.26.9
Changes:
go1.26.9 (released 2026-10-08) includes security fixes to the go
command, and the crypto/tls, html/template, net/http, net/textproto,
and os packages, as well as bug fixes to the compiler, the linker, the
runtime, vet, and the crypto/mlkem, net/http, and os packages.
MFH: 2026Q4
lang/go127: Update to 1.27.2
Changes:
go1.27.2 (released 2026-10-08) includes security fixes to the go
command, and the crypto/tls, html/template, net/http, net/textproto,
and os packages, as well as bug fixes to the compiler, the linker,
the runtime, the cover tool, the go fix command, vet, and the
compress/flate, crypto/mlkem, encoding/json, encoding/json/v2,
net/http, and os packages.
MFH: 2026Q4
acpi_timer: Trim some more leftovers from the ACPI-safe timer
The "safe" variant of the hook to read the timer is no longer used and
can be removed. Instead, initialize the get_timecount member of
acpi_timer_timecounter to the normal hook statically. While here,
initialize a few more fields in acpi_timer_timecounter statically.
I've kept the name as just "ACPI" instead of "ACPI-fast" now.
During device probe there is no longer any reason to alloc the
register resource since it is not used, so remove all that. While
here, defer registration of the timecounter until attach (kind of odd
to do such a thing during probe leaving a window where the timer
register was unallocated but in theory could still be read via the
timecounter).
Reviewed by: cperciva
Fixes: 00d061855deb ("Garbage-collect ACPI-safe timer and friends")
Differential Revision: https://reviews.freebsd.org/D59933
(cherry picked from commit d23d186ff212023c4e1ff61a0f488dc4dcb1b75c)
acpi_timer: Remove unneeded acpi_timer_freq global variable
This was just an alias of acpi_timer_timecounter.tc_frequency. While
here, register the machdep.acpi_timer_freq sysctl node dynamically
only if the driver attaches rather than making the handler fail with
EOPNOTSUPP if the driver had not attached.
Differential Revision: https://reviews.freebsd.org/D59935
(cherry picked from commit 381840e88072a90df7ffb5731c08935412edbc19)
pcib: Only apply ARI translation to a bridge's own secondary bus
ARI changes RID interpretation only for the device on a downstream
port's secondary bus. pcib_xlate_ari() applied that translation to
every config access through an ARI-enabled bridge, including cycles
forwarded to a subordinate bus.
A non-zero slot on a subordinate bus then panics an INVARIANTS kernel
and is misrouted otherwise. Translate only when the access targets
this bridge's secondary bus.
Reviewed by: kib, jhb
Fixes: 55d3ea1731d1 ("Add support for PCIe ARI")
Sponsored by: AMD
Differential Revision: https://reviews.freebsd.org/D60033
(cherry picked from commit 10409ee40baf593b810cd0140f3c2f0d737c1a65)
dtrace: Remove bogus Makefile.inc
This was added in the initial import of dtrace and overrides the
normal load/unload targets with a custom target that loads a hardcoded
set of modules. Over time, the set of modules has not been updated
and is now incomplete. It's also not really useful compared to the
default implementation of these targets used for loading or unloading
an individual module being actively developed.
This functionality is also available via dtraceall.ko which is how
users commonly load the full suite of dtrace modules.
Reviewed by: imp, markj
Differential Revision: https://reviews.freebsd.org/D59821
(cherry picked from commit df7b90556859e1e5dbaf8d3dae2177ca607c0558)
acpi/apm: Don't claim silent success for APMIO_BIOS ioctls
Report failure as if the request had failed. This causes apm(8) to
correctly report the resume timer as "unknown" rather than random
garbage.
Reviewed by: imp
Differential Revision: https://reviews.freebsd.org/D59939
(cherry picked from commit 1d7f0c742863ad65e9d27df8f5ae4afddd6cc5e2)
acpi_timer: Add a softc to avoid use of global variables
Add a softc and use it to mostly replace the use of global variables
in this driver. Simplify the suspend and resume event handlers by
saving the old timecounter in the softc and passing the softc pointer
to the handlers.
Differential Revision: https://reviews.freebsd.org/D59936
(cherry picked from commit 34cf45a93c54ee9a222d2893b97832283a850715)
cxgbe: Use the correct GHASH offset for a GMAC from a full TLS record
If a TLS request transmits all but a part of the GMAC at the end of a
TLS record, the work request asks the crypto engine to return the
calculated GMAC to the driver so it can be sent in a simple TCP packet
when the rest of the TLS record is transmitted in the future.
However, the offset of the returned GHASH offset was calculated
incorrectly in this case causing the driver to not recognize the
cached GMAC and instead use a more wasteful work request in the future
that encrypted the entire TLS record discarding all but the needed
bytes of the trailer.
Note that this does not effect correctness, just efficiency.
Reviewed by: np
Fixes: 9e269eafebfc ("cxgbe: Use partial GCM mode for partial TLS records on T7")
Sponsored by: Chelsio Communications
Differential Revision: https://reviews.freebsd.org/D59711
(cherry picked from commit ed5fc8066f98e639f624de9997b33727ed883c32)
bhyve: Refactor initial PCI BAR setup
Fully initialize BARs with an address of 0 in pci_emul_alloc_bar()
instead of deferring some of that initialization to
pci_emul_assign_bar(). Now, the latter is only used to allocate an
initial address range for PCI BARs.
Note that this means that the pci_passthru model now overrides the
initial lobits after they are set removing the need for a workaround
in pci_emul_assign_bar().
Reviewed by: bnovkov
Differential Revision: https://reviews.freebsd.org/D58893
(cherry picked from commit b00bb87a614212a2bbb156288bfdd51b27bcb329)
cxgbe KTLS tx: Distribute FW6_PLD replies across rx queues
If the connection flowid is available then the replies are requested on
the rx queue that is receiving wire traffic for the connection. This
reduces contention for the txq lock.
Reviewed by: jhb
MFC after: 3 days
Sponsored by: Chelsio Communications
Differential Revision: https://reviews.freebsd.org/D53385
(cherry picked from commit a6ae6090bb3dc14eda750aa53650fccf4c0bf818)
bhyve: Don't set the prefetch flag for large 64-bit memory BARs
The only device model that can create a large 64-bit memory BAR is the
passthru device model, and that device model reuses the lobits of the
existing BAR explicitly.
Fixes: e87a6f3ef284 ("bhyve: use physical lobits for BARs of passthru devices")
(cherry picked from commit 3807c8be4645d7f02c5253aa88b193000e6aef09)