iavf: Honor PF-negotiated RSS sizes
Use the key and lookup table lengths returned by GET_VF_RESOURCES when
configuring RSS through virtchnl, as DPDK does. The Windows E835 PF
advertises a 40-byte key and rejects our fixed 52-byte CONFIG_RSS_KEY
request, leaving receive traffic on queue zero.
Validate the negotiated lengths before constructing AdminQ messages and
publish the lookup table size to iflib. Preserve register-mode RSS
selection and its fixed hardware sizes. Use aligned, zero initialized
key storage so an RSS kernel's 40-byte key does not leave an uninitialized
tail when the PF requests 52 bytes.
Validation: normal and RSS enabled iavf module builds passed. On an E835
VF under Hyper-V Server 2025, repeated IPv4 and IPv6 receive tests used all
three configured guest RX queues in both transparent hn and non-transparent
lagg modes. The RSS key rejection disappeared, IPv4 transmit tests passed,
and no TX watchdog fired. Each traffic case used three runs of 16 streams.
[3 lines not shown]
thunderbolt: Account for CRC in router config write message size
Fixes: 9c6e9bfb3474 ("thunderbolt: Support writing to router config space")
Sponsored by: The FreeBSD Foundation
hn: Forward capability changes to transparent VFs
The transparent VF capability handler ignored the requested change and
only copied the VF's enabled capabilities. Forward SIOCSIFCAP to the VF
and return its result. Preserve VF capabilities which hn does not expose.
Limit advertised capabilities to those supported by the transparent
packet path and VLAN relay. Do not inherit VF services such as send tags
or the extended capability ioctl when hn has no corresponding methods.
At handoff, adopt the VF's enabled offloads without reconfiguring it.
Mark the datapath as switching while the VF applies a capability change,
since its ioctl may reinitialize the device. If the association is still
ready and unchanged afterwards, synchronize hn with the actual VF state
even on error and restrict checksum assistance to the forwarded offloads.
Republish link state suppressed during the transition when the VF is
still ready. Refresh VLAN child capabilities after adoption and when
restoring the synthetic path.
[9 lines not shown]
hn: Relay VLAN membership to transparent VFs
VLANs configured on the synthetic interface do not otherwise reach the
accelerating VF's VLAN callbacks. Those callbacks can be needed for
hardware filter membership or for interpreting stripped VLAN tags, even
though no vlan interface is attached directly to the VF.
Subscribe to VLAN events only in transparent mode and schedule the
existing VF task. Snapshot the synthetic interface's VLAN topology under
network epoch, then leave epoch before invoking the VF callbacks, which
may sleep. Do not acquire hn_lock or configure the VF from a VLAN event
handler; the worker applies membership outside the VLAN configuration
lock.
Keep an applied-VID bitmap under hn_lock and relay only changes. Replay
VLANs configured before VF arrival, reconcile changes while acceleration
is active, and preserve membership across temporary datapath switches.
This relays guest intent; it does not configure host access VLAN policy
or overcome PF restrictions on tagged traffic.
[7 lines not shown]
ice: Use sleepable locks in shared code
The Intel shared code can wait for firmware resources while holding its
OS abstraction locks. FreeBSD mapped these locks to mutexes, which
cannot be held across a voluntary sleep. Concurrent PF rebuilds
therefore trigger WITNESS when RSS profile updates contend for the
firmware change lock.
Map the shared-code lock abstraction to exclusive sx locks. This also
covers tunnel and flow-profile operations which can reach the same
firmware wait while serialized.
Validated with WITNESS on a dual port Intel E835. Sixteen CORE resets
rebuilt both PFs without lock warnings, reset failures, or watchdogs.
Ten interface down/up cycles and twenty promiscuous-filter cycles also
completed cleanly.
Reviewed by: erj
MFC after: 2 weeks
[2 lines not shown]
libbsdconf: independent version macros
sysconf(8) --version now prints the library version alongside its
own so each can move on its own clock. Assigning a bitmask to
bool already converts zero/nonzero; drop the redundant != 0 (fuz).
Reviewed by: fuz, kfv
Differential Revision: https://reviews.freebsd.org/D59720
Add sysconf(8) and libbsdconf(3)
Complete the native configuration trinity: sysctl(8) for live kernel
state, sysrc(8) for rc.conf(5), and sysconf(8) for the remaining base
configuration -- loader.conf(5), sysctl.conf(5), and the make.conf(5)
family -- atop libbsdconf(3).
libbsdconf resurrects figpar as a unified reader/writer. Callbacks own
semantics; statements may span multiple lines via backslash continuation;
non-seekable input is spooled; writes are atomic (mkstemp, fsync, rename)
with mode/owner preservation. Format descriptors name each target, its
files, and quoting rules without private parsers. Multi-file targets
follow boot sourcing order; loader chases loader_conf_files as the boot
loader does.
sysconf(8) is the operator-facing tool: name / name=value on a required
target, sysrc-style list edits, make append and list-strike where they
belong, jail/altroot, and a capsicum sandbox for read-only use.
[21 lines not shown]
igbv: Recover disabled Hyper-V transmit queues
The Windows PF can disable a VF transmit queue while continuing to
report carrier up. Link polling alone then leaves the VF operationally
up even though it cannot transmit. The reproduced VLAN failure shows
this state with PF driver 14.1.5.0 and an MDD indication in the host trace.
Check queue zero from the admin path only while the Hyper-V VF is
running with sanitized queues and a completed host handshake. Report
operational link down and invalidate the statistics baseline when the
queue is disabled. Request recovery through the normal iflib stop/init
path only when a fresh, accessible STATUS read reports carrier up.
Rate limit requests if the host continues to hold the queue disabled,
and leave recovery pending while carrier is down.
Document the recovery behavior and clarify why the Hyper-V reset retains
the VF-local software reset before its host reset/MAC exchange.
Sponsored by: BBOX.io
cxgbe: Use the correct GHASH offset for a GMAC from a full TLS record
If a TLS request transmits all but a part of the GMAC at the end of a
TLS record, the work request asks the crypto engine to return the
calculated GMAC to the driver so it can be sent in a simple TCP packet
when the rest of the TLS record is transmitted in the future.
However, the offset of the returned GHASH offset was calculated
incorrectly in this case causing the driver to not recognize the
cached GMAC and instead use a more wasteful work request in the future
that encrypted the entire TLS record discarding all but the needed
bytes of the trailer.
Note that this does not effect correctness, just efficiency.
Reviewed by: np
Fixes: 9e269eafebfc ("cxgbe: Use partial GCM mode for partial TLS records on T7")
Sponsored by: Chelsio Communications
Differential Revision: https://reviews.freebsd.org/D59711
jail, ports: Avoid set -e trap in quiet-mode "done" idiom
4cb78962 introduced `[ -n "${quiet}" ] && echo " done"` in the svn/git
checkout and update paths of install_from_vcs() (jail.sh) and ports.sh.
When quiet is unset the test is false, so the statement returns exit 1;
under set -e a bare call to the enclosing function/case arm would abort
the script right after that line runs, as seen with the identical
pattern in image.sh (PR #1378). None of these 8 occurrences are
currently a function's last statement, so they don't trip today, but
the pattern is fragile under refactoring. Use an if/fi block instead,
matching the idiom already used for the preceding header line, so the
statement always returns 0.
This closes #1387
vlan: Notify the parent when replacing a VLAN ID
Changing the VID of an existing VLAN interface rehashes the interface and
announces the new VID, but does not unregister the old VID. Parent
drivers and VLAN event consumers can consequently retain stale filter
membership.
After successfully inserting the new VID, emit vlan_unconfig for the old
VID before the existing vlan_config notification. Do not unregister
anything if insertion fails and the old VID is restored.
MFC after: 2 weeks
Sponsored by: BBOX.io
jail: Reject a period in the new name on rename
create_jail() rejects a period in JAILNAME since jail(8) names cannot
contain one, but rename_jail() never validated NEWJAILNAME at all, so
'poudriere jail -r' could rename a jail to a name jail(8) itself would
reject. Apply the same check used at creation.
This closes #1388