FreeBSD/src 6d7f016 — sys/netpfil/pf pf_nl.c

pf: take the rules read lock in pf_handle_getrule()

pfctl -sr calls PFNL_CMD_GETRULE once per rule, and
pf_handle_getrule() takes the rules write lock each time, so listing a
ruleset of N rules stops packet processing N times. Only zeroing the
counters (pfctl -z) needs the write lock. Take the read lock
otherwise, as DIOCGETRULENV does.

Reviewed by:            kp
Approved by:            kp (mentor)
Fixes:                  777a4702c591 ("pf: implement addrule via netlink")
MFC after:              1 week
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60161
DeltaFile
+20-6sys/netpfil/pf/pf_nl.c
+20-61 files

FreeBSD/src 82ab4ad — sys/netpfil/pf pf.c

pf: leave the epoch to purge unlinked rules

pf_purge_thread() calls pf_purge_unlinked_rules() in the network
epoch, where sleeping is not allowed, and it takes pf_config_lock, an
sx lock. If a rule is being added at the time, the purge thread
can sleep on the lock, which panics with INVARIANTS.

Reviewed by:            kp
Approved by:            kp (mentor)
Fixes:                  f92d9b1aad73 ("pflow: import from OpenBSD")
MFC after:              1 week
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60160
DeltaFile
+6-0sys/netpfil/pf/pf.c
+6-01 files

FreeBSD/src be7e57f — sys/netpfil/pf pf_nl.c

pf: free an unparsed rule with pf_krule_free() in pf_handle_addrule()

When the PFNL_CMD_ADDRULE message fails to parse, pf_handle_addrule()
frees the rule with pf_free_rule(), which asserts the rules and config
locks (neither is held) and releases references that
pf_ioctl_addrule() has not taken yet. With INVARIANTS this panics on
any parse error; without, a rule address parsed as PF_ADDR_TABLE makes
pfr_detach_table() dereference NULL.

Use pf_krule_free(), as the ioctl paths do.

Reviewed by:            kp
Approved by:            kp (mentor)
Fixes:                  e249f5daa41f ("pf: fix memory leak on rule add parse failure")
MFC after:              1 week
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60104
DeltaFile
+1-1sys/netpfil/pf/pf_nl.c
+1-11 files

FreeBSD/src 55a69b9 — lib/libpfctl libpfctl.c, sbin/pfctl pfctl_radix.c

libpfctl: zero the counters before summing per-chunk results

The chunked table address functions (set, add, del, clr_astats) add
each chunk's result to the caller's counter without initialising it.
pfctl reuses nadd for the number of tables created, so a replace that
also creates the table is off by one:

pfctl -t foo -T replace 192.0.2.1

reports "2 addresses added".

Zero the counters first, as pfctl_test_addrs() already does. Remove
the workaround for the add case from pfctl (da64f6e047b5), which is
no longer needed.

Add a regression test.

Reviewed by:            kp
Approved by:            kp (mentor)

    [4 lines not shown]
DeltaFile
+38-0tests/sys/netpfil/pf/table.sh
+16-0lib/libpfctl/libpfctl.c
+0-3sbin/pfctl/pfctl_radix.c
+54-33 files

FreeBSD/src c1241c6 — sys/netpfil/pf pf_if.c pf.c

pf: modify pfik_flags atomically

The purge thread sets PFI_IFLAG_REFS on the interfaces that states
refer to without the rules lock, under which the other flags are
changed. The updates can interleave, so that a "set skip on" is lost,
or outlives its removal, until the next ruleset load.

Use atomic operations to modify the flags. In the purge thread, only
write if the flag is not already set.

Reviewed by:            kp
Approved by:            kp (mentor)
MFC after:              1 week
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60107
DeltaFile
+10-2sys/netpfil/pf/pf.c
+5-5sys/netpfil/pf/pf_if.c
+15-72 files

FreeBSD/src 3171a60 — sbin/pfctl pfctl_parser.c, sbin/pfctl/tests pfctl_test_list.inc

pfctl: print "pass" on nat/rdr/binat rules again

c2d03a920ec7 rewrote the action printing in print_rule() from OpenBSD,
which has no natpass, and dropped the "pass" keyword.  A ruleset
loaded from "pfctl -sn" output therefore lost its nat-pass semantics.

Add a parser test covering nat, rdr, rdr log and binat with pass.

Reviewed by:            kp
Approved by:            kp (mentor)
Fixes:                  c2d03a920ec7 ("pfctl: fix anchortypes bounds test")
MFC after:              1 week
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60183
DeltaFile
+4-1sbin/pfctl/pfctl_parser.c
+5-0sbin/pfctl/tests/files/pf1080.ok
+5-0sbin/pfctl/tests/files/pf1080.in
+1-0sbin/pfctl/tests/pfctl_test_list.inc
+15-14 files

FreeBSD/src a30ea64 — sys/fs/nullfs null_vfsops.c, sys/kern vfs_subr.c vfs_mount.c

VFS: style

(cherry picked from commit e40c72c823c6502906d4024933f0c119b5ca17cf)
DeltaFile
+6-3sys/kern/vfs_cache.c
+4-2sys/kern/vfs_mount.c
+2-1sys/fs/nullfs/null_vfsops.c
+1-1sys/kern/vfs_subr.c
+13-74 files

FreeBSD/src c363f72 — sys/fs/cd9660 cd9660_vfsops.c, sys/fs/ext2fs ext2_vfsops.c

filesystems: use g_vfs_close_unlocked(9)

(cherry picked from commit 53edaad235c86e4426e97d63be48f0160bcc5267)
DeltaFile
+3-12sys/fs/ext2fs/ext2_vfsops.c
+3-8sys/fs/udf/udf_vfsops.c
+3-8sys/fs/cd9660/cd9660_vfsops.c
+2-5sys/ufs/ffs/ffs_vfsops.c
+2-5sys/fs/msdosfs/msdosfs_vfsops.c
+13-385 files

FreeBSD/src 592ed51 — sys/kern vnode_if.src vfs_subr.c

VFS: require locked vnode for fsync()

(cherry picked from commit 30ad8440b46838b050360ed87e6165a067f1cf8a)
DeltaFile
+8-12sys/kern/vfs_subr.c
+1-1sys/kern/vnode_if.src
+9-132 files

FreeBSD/src 4302877 — sys/geom geom_vfs.h geom_vfs.c

g_vfs_close_unlocked(9): wrapper around g_vfs_close(9)

(cherry picked from commit 87962e08fa18797103c96c17fd8c88ada056e0c0)
DeltaFile
+13-0sys/geom/geom_vfs.c
+3-1sys/geom/geom_vfs.h
+16-12 files

FreeBSD/src 1e8708d — lib/libsys stat.2

stat.2: document SFBSD_MNTROOT

Reviewed by:    sobomax, markj, olce
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
Differential revision:  https://reviews.freebsd.org/D59910
DeltaFile
+4-0lib/libsys/stat.2
+4-01 files

FreeBSD/src 0d5d887 — sys/kern vfs_vnops.c vfs_syscalls.c, sys/sys stat.h

stat(2): report mount points using st_bsdflags SFBSD_MNTPOINT flag

Reviewed by:    jah, sobomax, markj, olce
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
Differential revision:  https://reviews.freebsd.org/D59910
DeltaFile
+2-0sys/kern/vfs_vnops.c
+2-0sys/kern/vfs_syscalls.c
+1-0sys/sys/stat.h
+5-03 files

FreeBSD/src 9cf774a — sys/dev/cxgbe offload.h t4_main.c, sys/dev/cxgbe/crypto t7_kern_tls.c t6_kern_tls.c

cxgbe: Add a sysctl/tunable to control KTLS offload of AES-CBC cipher suites

Disable these by default as they are less efficient and rarely used.

Sponsored by:   Chelsio Communications
DeltaFile
+10-1sys/dev/cxgbe/t4_main.c
+4-3sys/dev/cxgbe/crypto/t7_kern_tls.c
+4-3sys/dev/cxgbe/crypto/t6_kern_tls.c
+1-0sys/dev/cxgbe/offload.h
+19-74 files

FreeBSD/src 0fc4ef1 — sys/riscv/starfive jh7110_gpio.c

jh7110_gpio: fdt_pinctrl interface

This provides GPIO programming/configuration at attach time based on the
device tree 'pinmux' descriptions.

Reference:
device-tree/Bindings/pinctrl/starfive,jh7110-sys-pinctrl.yaml

Reviewed by:    Brian Scott <bscott at bunyatech.com.au>
Tested by:      Brian Scott <bscott at bunyatech.com.au>
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59992
DeltaFile
+169-3sys/riscv/starfive/jh7110_gpio.c
+169-31 files

FreeBSD/src 6f9d0f0 — sys/riscv/starfive jh7110_gpio.c

jh7110_gpio: handle preset high/low

Take action in the presence of the GPIO_PIN_PRESET_LOW/HIGH flags. This
part of the GPIO interface seems to be unused, but is trivially
implemented in our driver.

Reviewed by:    Brian Scott <bscott at bunyatech.com.au>
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59991
DeltaFile
+25-6sys/riscv/starfive/jh7110_gpio.c
+25-61 files

FreeBSD/src 6d587ff — sys/dev/cxgbe/crypto t7_kern_tls.c

cxgbe: Don't cache nsegs for KTLS requests

KTLS mbufs are initially parsed when they are first enqueued to
estimate the number of transmit descriptors needed so that the mbuf is
queued until enough descriptors are available.  As part of this
estimate, the number of DSGL segments required by each KTLS mbuf is
calculated.  Originally, the count for the first TLS record in a chain
was cached in the header mbuf to avoid having to recalculate it when
writing out the actual work request for the first TLS record, but this
requires duplicating fairly complex logic both when parsing and
transmitting requests.

Sponsored by:   Chelsio Communications
DeltaFile
+5-22sys/dev/cxgbe/crypto/t7_kern_tls.c
+5-221 files

FreeBSD/src 1dd03aa — sys/dev/cxgbe/crypto t7_kern_tls.c

cxgbe: Don't query mbuf_nsegs for header-only requests

Sponsored by:   Chelsio Communications
DeltaFile
+3-2sys/dev/cxgbe/crypto/t7_kern_tls.c
+3-21 files

FreeBSD/src 613e7ce — sys/dev/cxgbe/crypto t7_kern_tls.c

cxgbe: Greatly simplify ktls_wr_len for T7

Don't try to fine-tune the WR size when estimating the work request
length when parsing the packet.  Use a much simpler worst-case
estimate that only depends on a few fields in the mbuf metadata.

Sponsored by:   Chelsio Communications
DeltaFile
+44-90sys/dev/cxgbe/crypto/t7_kern_tls.c
+44-901 files

FreeBSD/src 1bc81d3 — sys/dev/cxgbe t4_main.c adapter.h, sys/dev/cxgbe/crypto t7_kern_tls.c

cxgbe tls: Send final data as immediate when trailing waste is trimmed

When a request needs to drop data from the crypto output (via a split
mode request), send the last 16 bytes of input as immediate data
instead of via DSGL.  Requests with small payloads (16 bytes or fewer)
are now sent as immediate data only without any DSGL at all.

Sponsored by:   Chelsio Communications
DeltaFile
+175-26sys/dev/cxgbe/crypto/t7_kern_tls.c
+8-0sys/dev/cxgbe/t4_sge.c
+2-0sys/dev/cxgbe/t4_main.c
+2-0sys/dev/cxgbe/adapter.h
+187-264 files

FreeBSD/src 17126d5 — sys/dev/cxgbe/crypto t7_kern_tls.c

cxgbe: Various assertions for lengths in KTLS work requests

The construction of KTLS work requests is quite fragile, and these
assertions ensure that the constructed work requests match the length
fields encoded in some of the WR structures.

Sponsored by:   Chelsio Communications
DeltaFile
+16-0sys/dev/cxgbe/crypto/t7_kern_tls.c
+16-01 files

FreeBSD/src 0761869 — test/recipes/10-test_bn_data bngcd.txt, test/recipes/30-test_evp_data evppkey_ecc.txt evpkdf_ssh.txt

vendor/openssl-3.0: remove test/recipes

This directory contains a large number of files which are not currently
used by OpenSSL in the base system. Remove the files to reduce space
needed when doing version updates.
DeltaFile
+0-23,927test/recipes/30-test_evp_data/evpciph_aes_ccm_cavs.txt
+0-17,179test/recipes/10-test_bn_data/bngcd.txt
+0-11,667test/recipes/30-test_evp_data/evppkey_kas.txt
+0-4,947test/recipes/30-test_evp_data/evpkdf_tls13_kdf.txt
+0-4,867test/recipes/30-test_evp_data/evpkdf_ssh.txt
+0-4,501test/recipes/30-test_evp_data/evppkey_ecc.txt
+0-67,088815 files not shown
+0-135,190821 files

FreeBSD/src be0569f — secure/lib/libcrypto/man/man3 SSL_CTX_set_security_level.3 ENGINE_add.3, secure/lib/libcrypto/man/man5 fips_config.5 config.5

crypto/openssl: update generated files to match 3.5.9 release content

A new manpage has been added and some source files have been refactored
slightly, but by and large this is just a standard "version bump" update
(3.5.8 -> 3.5.9).

MFC after:      1 day
MFC with:       b3a31d78
DeltaFile
+107-0secure/lib/libcrypto/man/man3/X509V3_EXT_nconf_nid.3
+46-49secure/lib/libcrypto/man/man3/ENGINE_add.3
+83-11secure/lib/libcrypto/man/man3/SSL_CTX_set_security_level.3
+31-34secure/lib/libcrypto/man/man7/EVP_PKEY-EC.7
+31-34secure/lib/libcrypto/man/man5/config.5
+30-33secure/lib/libcrypto/man/man5/fips_config.5
+328-161904 files not shown
+4,295-6,061910 files

FreeBSD/src b32597a — tests/sys/pmc Makefile pmc_log_test.c

hwpmc tests: the sampling log file

Nine ATF cases covering PMC_OP_CONFIGURELOG and the descriptor-less
log operations: which descriptors are accepted, when a log is required
in the first place, and what the log operations do without one.

MFC after:      1 month
MFC to:         stable/15
MFC to:         stable/14
Assisted-by:    Claude Code (Opus 5)

(cherry picked from commit 8f0789bee7abb2fdb2ff6d625f254533a138e6e8)
DeltaFile
+453-0tests/sys/pmc/pmc_log_test.c
+1-0tests/sys/pmc/Makefile
+454-02 files

FreeBSD/src 4a82521 — tests/sys/pmc Makefile pmc_credexec_test.c

hwpmc: add credential-transition exec tests (keep and drop)

The companion to pmc_exec_test.c, which covers only the drop side of a
credential-changing exec.  Three cases cover what the drop must not
overreach into: an exec that changes no credentials keeps the PMC, a
set-id exec whose credential change the kernel suppresses for a traced
target keeps it too, and a set-id fexecve(2) drops it.  They exercise
the permission logic FreeBSD-SA-26:56.hwpmc reworked, not the defect
it fixed.

All three pass on a debug (INVARIANTS+WITNESS) kernel.  The two
keep-cases were each observed to fail on a kernel mutated to detach
unconditionally.

MFC after:      1 month
MFC to:         stable/15
MFC to:         stable/14
Assisted-by:    Claude Code (Opus 4.8)

(cherry picked from commit bea7b932b9eeaff39393347e0600b982fd859a92)
DeltaFile
+348-0tests/sys/pmc/pmc_credexec_test.c
+1-0tests/sys/pmc/Makefile
+349-02 files

FreeBSD/src 81ddb2e — tests/sys/pmc Makefile pmc_lifecycle_test.c

hwpmc tests: process-attachment lifecycle and ownership cases

Seven ATF cases covering process-attachment teardown orderings: a
target that exits before it is detached, the owner that exits before
its target (hwpmc's other unlink path), releasing a still-running
attached PMC, row exhaustion with out-of-order release, and
PMC_F_DESCENDANTS inheritance including a fork storm.

All pass on a debug (INVARIANTS+WITNESS) and a KASAN kernel.

MFC after:      1 month
MFC to:         stable/15
MFC to:         stable/14
Assisted-by:    Claude Code (Opus 5)

(cherry picked from commit d00da14532bc4408f3e66535c88276d00905af7c)
DeltaFile
+436-0tests/sys/pmc/pmc_lifecycle_test.c
+1-0tests/sys/pmc/Makefile
+437-02 files

FreeBSD/src 198c334 — tests/sys/pmc Makefile pmc_api_test.c

hwpmc: add tests for handle validation and the privilege boundaries

A pmc_id_t is a packed integer that the driver hands to userland and
accepts back on eleven operations, and nothing tested what happens when
one comes back forged, stale, or belonging to another process.  Neither
was there a test that an unprivileged caller is refused the operations
that need a privilege.

The cases use a SOFT-class PMC wherever the counter itself does not
matter, so they run on a machine with no PMU.

MFC after:      1 month
MFC to:         stable/15
MFC to:         stable/14
Assisted-by:    Claude Code (Opus 5)

(cherry picked from commit 17fca802ded118102d04a7a0bbc0c076de18c4d8)
DeltaFile
+507-0tests/sys/pmc/pmc_api_test.c
+1-0tests/sys/pmc/Makefile
+508-02 files

FreeBSD/src 517d051 — tests/sys/pmc Makefile

hwpmc tests: sort the list of test programs

MFC after:      1 month
MFC to:         stable/15
MFC to:         stable/14

(cherry picked from commit df537ff1520d82410328ebd6de529929dae620a6)
DeltaFile
+1-1tests/sys/pmc/Makefile
+1-11 files

FreeBSD/src d5a5e41 — tests/sys/pmc Makefile pmc_exec_test.c

hwpmc: add regression tests for a credential-changing exec

This tests what FreeBSD-SA-26:56.hwpmc fixed.

exec_setgid_drops_pmc asserts the kernel takes a process-mode PMC away
when its target execs a set-gid program its owner is not entitled to
trace.

exec_setuid_no_double_unlink lets the target exec a set-uid program;
the teardown must unlink the process descriptor exactly once, and
completing at all is the assertion.

Both need an unprivileged owner and must not drop privileges themselves,
since p_candebug() would then refuse the target to its own owner; they
ask for require.user instead.

MFC after:      1 month
MFC to:         stable/15
MFC to:         stable/14

    [3 lines not shown]
DeltaFile
+264-0tests/sys/pmc/pmc_exec_test.c
+1-0tests/sys/pmc/Makefile
+265-02 files

FreeBSD/src f9bc005 — crypto/openssl/test/recipes/10-test_bn_data bngcd.txt, crypto/openssl/test/recipes/30-test_evp_data evppkey_ecc.txt evpkdf_ssh.txt

crypto/openssl: update to 3.5.9

This is a security fix release addressing CVE High issues. Users are
strongly encouraged to update to this version.

See the release notes for the release for more details on what is being
fixed.

MFC after:      1 day
Merge commit 'af5a659dc1cd2b0a6994f2cee1956d0bf50bb1a2'
DeltaFile
+0-23,927crypto/openssl/test/recipes/30-test_evp_data/evpciph_aes_ccm_cavs.txt
+0-17,330crypto/openssl/test/recipes/10-test_bn_data/bngcd.txt
+0-11,686crypto/openssl/test/recipes/30-test_evp_data/evppkey_kas.txt
+0-5,037crypto/openssl/test/recipes/30-test_evp_data/evpkdf_tls13_kdf.txt
+0-4,943crypto/openssl/test/recipes/30-test_evp_data/evpkdf_ssh.txt
+0-4,563crypto/openssl/test/recipes/30-test_evp_data/evppkey_ecc.txt
+0-67,4861,248 files not shown
+10,203-197,9121,254 files

FreeBSD/src 63b3fde — tests/sys/pmc Makefile pmc_log_test.c

hwpmc tests: the sampling log file

Nine ATF cases covering PMC_OP_CONFIGURELOG and the descriptor-less
log operations: which descriptors are accepted, when a log is required
in the first place, and what the log operations do without one.

MFC after:      1 month
MFC to:         stable/15
MFC to:         stable/14
Assisted-by:    Claude Code (Opus 5)

(cherry picked from commit 8f0789bee7abb2fdb2ff6d625f254533a138e6e8)
DeltaFile
+453-0tests/sys/pmc/pmc_log_test.c
+1-0tests/sys/pmc/Makefile
+454-02 files