iflib: Do not ring the transmit doorbell when nothing is pending
For a lightly used ring iflib_txd_db_check() may defer zero descriptors,
so its "pending >= limit" test is true even when nothing has been queued
since the last doorbell. iflib_txq_drain() calls it before, inside and
after its loop, so a sender that drains its own packet wrote the tail
register three times per packet, twice with the value the hardware
already had.
The log of 81be655266fa ("iflib: ensure that tx interrupts enabled and
cleanups") calls skipping the doorbell when db_pending is zero "an
obvious missing optimization"; the comparison against a limit of zero
defeated it. vmx(4) and mgb(4) have dropped such repeated requests in
the driver since 2019. Return early when nothing is pending.
Reviewed by: gallatin
MFC after: 2 weeks
Sponsored by: Rubicon Communications, LLC ("Netgate")
Differential Revision: https://reviews.freebsd.org/D60290
arm64: Elide coherent busdma maps
Avoid allocating per-transfer maps for coherent tags that cannot
bounce. Retain maps for cache synchronization, CCA realms, and KMSAN.
These un-used maps carry with them memory and cache miss overheads.
Reviewed by: andrew
Differential Revision: https://reviews.freebsd.org/D60098
Sponsored by: Netflix
openssh: Add date bump command to FREEBSD-upgrade instructions
Provide a convenient in-place sed edit command to update the FreeBSD
VersionAddendum dates with today's date.
Sponsored by: The FreeBSD Foundation
(cherry picked from commit 0ec81f6a531bf7b3b06e869c99295f3d4ab9ed8e)
(cherry picked from commit 2ba5b9da2be10261c383035bef932cd37d52f903)
openssh: Add reference for another local patch
A bug fix was committed locally and submitted upstream. Document it in
our upgrade instructions, as these sometimes take a long time before
getting merged.
Sponsored by: The FreeBSD Foundation
(cherry picked from commit 6531070132b0210aaaeb08c0dc93cb272bed348e)
(cherry picked from commit 14d6926293569048d2d04f6e5a13d80f192ad99e)
secure: Rearrange Makefile SRCS to match upstream Makefile.in
SRCS entries are kept in the same order and with the same line breaks as
upstream, to make comparison easier.
No functional change intended.
Reviewed by: emaste
Approved by: emaste (mentor)
Differential Revision: https://reviews.freebsd.org/D49793
(cherry picked from commit 9440aad19dca73fdd224b128ac2dc2e78191ff15)
arm64/gicv5: Use ArmMpidr to find the correct CPU
The GICv5 ACPI code uses CpuInterfaceNumber to as the CPU ID. This a
GICv5 CPU ID and may not be the same as the appropriate FreeBSD value.
It is also possible the target CPU is disabled, e.g. when the hw.ncpu
tunable is uses to limit CPUs. If this is the case we don't want to
enable the CPU in the cpu set as it is offline so cannot handle
interrupts.
Switch to use ArmMpidr to find which pcpu to use when finding which
CPUs the IRS is attached to.
Fixes: 9556306213e1 ("arm64: Add ACPI support to GICv5 driver")
Differential Revision: https://reviews.freebsd.org/D59993
Sponsored by: Arm Ltd
nuageinit: Allow the userdata script to run before firstboot* rc services
Allowing nuageinit user scripts to run before these makes it possible to
customize official BASIC-CI and BASIC-CLOUDINIT FreeBSD images.
This was requested by KDE for their CI.
Approved by: cperciva
Pull-Request: https://ron-dev.freebsd.org/FreeBSD/src/pulls/60
(cherry picked from commit 16e47f317c4ce2be5fed530bf8a9af9f9bf55364)
bsd.lib.mk: only ctfmerge if objfiles have a CTF section
PR: 299013
Reported by: Trond.Endrestol at ximalas.info
Reviewed by: emaste
Fixes: 222210c6a822 ("libgcc_s: add libgcc_s_asneeded.so wrapper for gcc 16")
MFC after: 3 days
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D60252
igc: Fix the flow control sysctl
dev.igc.N.fc read and wrote a function-static variable shared by every
igc device, so a read returned the last value written to any of them (3
until the first write), not the state of the device. The softc value
started as 0, which is also the value of "no flow control", while the
hardware was set up for full flow control. As a result:
- Writing 0 was taken for no change and did nothing, unless another
value had been written to that device before.
- igc_reset() took a softc value of 0 for "not set", so a device set to
0 went back to full flow control on the next init.
- With more than one receive queue the driver enabled per-queue drop
(SRRCTL.DROP_EN), which is meant for a MAC that does not send pause
frames, although the MAC was told to send them.
- Values out of range were accepted and ignored.
A write only forced the MAC's flow control bits. The pause bits
advertised to the link partner, the pause thresholds and DROP_EN stayed
[24 lines not shown]
devel/py-dbus: devel/py-dbus: unbreak with python 3.13+, fix plist
Backport upstream commit to fix build with Python 3.13+
Fix plist, this unbreak packaging with free-treaded versions of Python
Limit minimal allowed Python version to 3.12
Revieved by: arrowd (desktop)
OpenSSH: Update to 10.4p1
Full release notes are available at
https://www.openssh.com/txt/release-10.4
Selected highlights from the release notes:
Potentially-incompatible changes
--------------------------------
* sshd(8): configuration dump mode ("sshd -G") now writes directives
in mixed case (e.g. "PubkeyAuthentication") whereas previously it
emitted only lower-case names.
* ssh(1), sshd(8): make the transport protocol stricter by
disconnecting if the peer sends non-KEX messages during a post-
authentication key re-exchange. Previously a malicious peer could
continue sending non-key exchange messages without penalty. These
would be buffered, causing memory to be wasted up until the
[73 lines not shown]
OpenSSH: Update to 10.2p1
Full release notes are available at
https://www.openssh.com/txt/release-10.2
Selected highlights from the release notes:
Bugfixes
--------
* ssh(1): fix mishandling of terminal connections when
ControlPersist was active that rendered the session unusable.
bz3872
Sponsored by: The FreeBSD Foundation
(cherry picked from commit e68aa5ab80ab57bdbcbe94dd2922a018d675e7f0)
OpenSSH: Update to 10.3p1
Full release notes are available at
https://www.openssh.com/txt/release-10.3
Selected highlights from the release notes:
* ssh(1), sshd(8): remove bug compatibility for implementations
that don't support rekeying. If such an implementation tries to
interoperate with OpenSSH, it will now eventually fail when the
transport needs rekeying.
* ssh(1), sshd(8): support IANA-assigned codepoints for SSH agent
forwarding, as per draft-ietf-sshm-ssh-agent. Support for the new
names is advertised via the EXT_INFO message. If a server offers
support for the new names, then they are used preferentially.
* ssh(1): add a ~I escape option that shows information about the
current SSH connection.
[15 lines not shown]
OpenSSH: Update to 10.1p1
Full release notes are available at
https://www.openssh.com/txt/release-10.1
Selected highlights from the release notes:
Potentially-incompatible changes
* ssh(1): add a warning when the connection negotiates a non-post
quantum key agreement algorithm.
* ssh(1), sshd(8): major changes to handling of DSCP marking/IPQoS
* ssh(1), sshd(8): deprecate support for IPv4 type-of-service (ToS)
keywords in the IPQoS configuration directive.
* ssh-add(1): when adding certificates to an agent, set the expiry
to the certificate expiry time plus a short (5 min) grace period.
[19 lines not shown]
openssh: Add date bump command to FREEBSD-upgrade instructions
Provide a convenient in-place sed edit command to update the FreeBSD
VersionAddendum dates with today's date.
Sponsored by: The FreeBSD Foundation
(cherry picked from commit 0ec81f6a531bf7b3b06e869c99295f3d4ab9ed8e)
openssh: Add reference for another local patch
A bug fix was committed locally and submitted upstream. Document it in
our upgrade instructions, as these sometimes take a long time before
getting merged.
Sponsored by: The FreeBSD Foundation
(cherry picked from commit 6531070132b0210aaaeb08c0dc93cb272bed348e)
powerpc: keep FP, VMX and VSX ownership changes atomic with preemption
trap() and set_mcontext() change the FP/VMX/VSX ownership state in
several steps with preemption enabled. A context switch in between
leaves the thread computing with another thread's register contents:
- enable_fpu()/enable_vec() set PCB_FPU/PCB_VEC before loading the
registers, so a switch mid-load saves a half-loaded unit over the PCB.
- set_mcontext() clears the frame's MSR bits and then the PCB flags;
a switch in between re-enables the unit, and the thread returns to
user space with it enabled but not owned, so it is neither saved nor
restored until the next signal.
Both paths run after every sigreturn(2), setcontext(2) and
swapcontext(3). A POWER9 test that keeps f14-f31 live across a signal,
with other threads using the FPU on the same CPU, saw 283 corrupted
round trips out of 882000; none after this change.
Hold a critical section around both, as amd64 and arm64 do.
[4 lines not shown]
bnxt_en: add bnxt_sriov.c to sys/conf/files for built-in kernel builds
The SR-IOV series added bnxt_sriov.c and listed it in sys/modules/bnxt/bnxt_en/Makefile,
but kernels that build bnxt into the image only compile sources named in sys/conf/files.
Add bnxt_sriov.c next to the other bnxt_en entries so built-in bnxt (including LINT)
links the SR-IOV implementation and avoids undefined symbols referenced from if_bnxt.c.
Fixes: f2f831b2c151 ("bnxt_en: Add core SR-IOV infrastructure")
MFC after: 1 month
Reviewed by: ssaxena
Differential Revision: https://reviews.freebsd.org/D56688
(cherry picked from commit c21c63fb565f1bc7f9564dbf12068c864f8891d8)
tcp: Preserve borrowed ICMPv6 error mbufs
The TCP-over-UDP ICMP callback receives ip6c_m as a borrowed chain owned
by icmp6_notify_error. It used m_pulldown() to obtain a contiguous UDP
header even though that API frees the complete chain when the requested
range is unavailable. The callback could then return without
propagating the lost ownership, leaving raw ICMP delivery to read and
free a stale head.
Validate that the complete UDP header was quoted, copy it through the
chain with m_copydata(), and temporarily advance the parser offset
instead of consuming bytes from the caller-owned packet.
A remote sender can reach the old path when TCP UDP tunneling is enabled
by quoting the configured local UDP source port in an ICMPv6 error and
including only four through seven UDP-header bytes.
Signed-off-by: Andrew Griffiths <andrew at calif.io>
[3 lines not shown]
netinet6: Fix the OSIOCAIFADDR_IN6 handler
We cannot simply treat a pointer to struct oin6_aliasreq as a pointer to
struct in6_aliasreq: the latter is larger. In particular, the store to
ifra->ifra_vhid is out of bounds.
Since OSIOCAIFADDR_IN6 does not need to copy data back out, it can
simply use a struct in6_ifaliasreq on the stack.
Reported by: Andrew <xxx.sys at protonmail.com>
Reviewed by: pouria
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D60184