dhclient-script: store the Captive Portal URI
Write the URI received in DHCP option 114 to
/var/run/captive-portal.IFACE atomically, with the legacy option 160 as
a fallback, and remove the file on EXPIRE and FAIL.
Reviewed by: bcr (manpage)
Differential Revision: https://reviews.freebsd.org/D60259
dhclient: request the Captive Portal options
Add DHCP options 114 (captive-portal) and 160 (captive-portal-legacy)
to the default Parameter Request List so that servers advertise the
Captive Portal API URI.
Approved by: emaste
Reviewed by: emaste
Differential Revision: https://reviews.freebsd.org/D60257
dhclient: recognize the Captive Portal DHCP options
Rename option 114 from "url" to "captive-portal" (RFC 8910) and retain
"url" as a deprecated alias. Rename option 160 from the generic
"option-160" to "captive-portal-legacy" (RFC 7710).
Reviewed by: emaste, dch
Apprived by: emaste, dch
Differential Revision: https://reviews.freebsd.org/D60256
gve: fix double free on ring allocation failure
When gve_alloc_rings fails (such as when failing to acquire MSI-X
vectors or during partial ring allocation), ring cleanup can be
executed multiple times across nested error paths (e.g. within
gve_alloc_rings abort and gve_attach abort).
Because gve_free_counters invoked counter_u64_free without nullifying
the pointer in the stats array, repeated invocation caused a double-free
panic when freeing the same counter references.
Check for non-NULL before freeing and nullify each counter pointer
upon release in gve_free_counters.
Signed-off-by: Jasper Tran O'Leary <jtranoleary at google.com>
Reviewed by: adrian, markj
MFC after: 2 weeks
Differential Revision: https://reviews.freebsd.org/D60386
gve: fix kernel panic on attach failure
When device initialization fails during attach (for instance, if device
resource configuration or firmware negotiation fails), the driver aborts
and unrolls partial state via its detach routine. However, the teardown
path assumes transmit and receive queues have already been created. If
attach aborts before queue allocation, tearing down the uninitialized
queues triggers a NULL pointer dereference and panics the kernel during
boot.
Guard queue teardown against uninitialized queue state so that early
attach failures unwind safely, allowing the driver to report the failure
gracefully without crashing the operating system.
Signed-off-by: Jasper Tran O'Leary <jtranoleary at google.com>
Reviewed by: adrian, markj
MFC after: 2 weeks
Differential Revision: https://reviews.freebsd.org/D60385
epair: Make vnet_epair_uninit() run earlier
I can't see a reason for vnet_epair_init() and vnet_epair_uninit() to be
inconsistent in the sys(un)init run order. Move vnet_epair_uninit() to
SI_SUB_PSEUDO, which is more appropriate for software ifnet drivers.
Reviewed by: glebius
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D60388
linux: Initialize per-VNET state earlier
Make sure that linux_ifnet_departure() can't run after
linux_ifnet_vnet_uninit() has destroyed the per-VNET unit number
allocator. Otherwise, when ifc_detach_cloner() destroys instances of an
interface type, it might be running too late. Most cloner-based drivers
tear themselves down during SI_SUB_PSEUDO or SI_SUB_PROTO_IF.
Reviewed by: pouria, glebius
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D60389
sched.h: Include <sys/pcpu.h> unconditionally
Even if SCHED_STATS is not defined, this header is necessary to provide
a definition of 'curthread' used in sched_pin() and sched_unpin().
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
cuse: Rename cuse_server_free() to cuse_server_dtor()
This name is clearer, given that this function is the cdevpriv
destructor callback.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
(cherry picked from commit b55b6e1d727bdc810b157047cb12e2e550333551)
cuse: Implement hot-unload
cuse_kern_uninit() can hang on destroy_dev(), because of threads
sleeping in CUSE_IOCTL_GET_COMMAND, so implement d_purge to wake them up
before calling destroy_dev(). Also do not allow threads to go back to
sleep if the is_closing flag has been set.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Reviewed by: kib
Differential Revision: https://reviews.freebsd.org/D60022
(cherry picked from commit d38ef1aca969f9a79572958c06bc4a4e03f053c2)
cuse: Assert the server refcount
Assert that the refcount does not underflow before decrementing it, and
that it really is zero by the time the server is freed.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Reviewed by: kib
Differential Revision: https://reviews.freebsd.org/D60043
(cherry picked from commit f96c4f45f791124192363c9aa2898b1d0e4cc6d0)
cuse: Actually use cuse_modevent()
We can call cuse_kern_init()/cuse_kern_uninit() here, rather than using
SYSINIT/SYSUNINIT.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Reviewed by: kib
Differential Revision: https://reviews.freebsd.org/D59862
(cherry picked from commit 2fd8d2eb7bb91148169471291dbcfa499579b1bc)
cuse: Fix hang on readv(2) and writev(2) with multiple iovecs
uiomove() leaves an iovec it has just emptied as the current one, so
cuse_client_read() and cuse_client_write() picked it up again on the
next iteration, sent the server a zero-length command, and got zero
bytes back. That left the residual count unchanged, so the loop never
terminated and the call never returned.
Step past empty iovecs at the start of every iteration. This also covers
caller-supplied zero-length iovecs, which hung in the same way
PR: 293489
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Reviewed by: kib, markj
Differential Revision: https://reviews.freebsd.org/D59822
(cherry picked from commit 872c36cb6f2de17278c559a300c2163d8b39b3c6)
cuse: Remove unnecessary semicolon in cuse_convert_error()
No functional change intended.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
(cherry picked from commit e923a30ecf2a34cdf46afcfbffdbc30e822148d1)
cuse: Use make_dev_s() to create client devices
make_dev_s() sets si_drv1 before the node is published in devfs, which
avoids a race where cuse_client_open() could see it as NULL. It also now
reports finer-grained errors on failure, instead of only ENOMEM.
While here, drop the NULL checks on kern_dev in cuse_server_free_dev(),
since a device is only added to the server's list once it has been
created.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Reviewed by: kib
Differential Revision: https://reviews.freebsd.org/D59874
(cherry picked from commit fad756fd200bf988861eb80146392661a887ab71)
cuse: Improve server cleanup
Move cuse_server_unref()'s device cleanup loop into a new
cuse_server_free_devs_locked(), and call it from cuse_server_free()
instead. The cdevpriv destructor now destroys the server's devices
before dropping its reference, which closes the clients using them, so
that the destructor is always the one that takes the last reference.
By the time cuse_server_unref() frees the server, the device list should
be empty, so assert this.
In cuse_kern_uninit(), delete the infinite loop which waits for all open
/dev/cuse instances to exit, and instead call destroy_dev() directly,
which runs their cdevpriv destructor.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Reviewed by: kib
Differential Revision: https://reviews.freebsd.org/D59872
[2 lines not shown]
cuse: Create /dev/cuse with MAKEDEV_CHECKNAME
Since we now use make_dev_credf(), make sure to fail kldload if it
returned NULL.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Reviewed by: kib
Differential Revision: https://reviews.freebsd.org/D59863
(cherry picked from commit 3b3e6473b13093c6900194b42e8a11f56c2ea7d8)
routing: fix rtentry use-after-free in multipath route append
add_route_flags() drops the RIB lock and passes the existing entry,
rt_orig, to add_route_flags_mpath(). If a concurrent delete removes
the prefix in that window, the retry re-inserts rt_orig, which is
then freed while still linked, crashing later in rn_match().
Pass the new rt instead, return ENOENT when the prefix is gone and
RTM_F_CREATE is not set, and fix the rnd_orig NULL check.
Approved by: pouria
Fixes: c24a8f19c5d5 ("routing: fix rib_add_route_px()")
Differential Revision: https://reviews.freebsd.org/D60353
tests/netinet6: fix ndp_del_gu_success flakiness
The test pinged an unanswered address and then deleted the resulting
INCOMPLETE neighbor entry.
The kernel frees that entry after about 3s, so on a loaded VM,
ndp -d could run too late and fail with ENOENT.
Configure 2001:db8::2 on epair0b so the ping gets a reply and the
entry becomes REACHABLE.
Approved by: pouria
Sponsored by: Netflix
Differential Revision: https://reviews.freebsd.org/D60348
nfscl: Fix oddball cases for session slot release
We have identified some cases where silent slot loss can occur
when operations on NFS mounts are aborted. We experience this
when using NFSv4.2, but it likely also occurs with NFSv4.1.
A slot is acquired for compound operations by nfsv4_setsequence()
and freed by newnfs_request(). Any call path that abandons the
compound before reaching newnfs_request() loses the slot permanently.
We identified four call sites where this happens, one of
which where it actually does happen for us in a semi-reproducible
way, which allowed us to develop a candidate patch, attached.
The patch adds one function, nfsv4_freeunsentslot(), to
nfs_clcomsubs.c. It is called from each of the four call
sites: nfsrpc_writerpc(), nfsrpc_writeds(), and two in
nfsrpc_setextattr().
[11 lines not shown]