FreeBSD/src 7ba7285 — sbin/dhclient dhclient.c

dhclient: export the Captive Portal URI to the script

Differential Revision=  https://reviews.freebsd.org/D60259
DeltaFile
+14-3sbin/dhclient/dhclient.c
+14-31 files

FreeBSD/src 0f1ca95 — sbin/dhclient dhclient-script.8 dhclient-script

dhclient-script: store the Captive Portal URI

Write the URI received in DHCP option 114 to
/var/run/captive-portal.IFACE atomically, with the legacy option 160 as
a fallback, and remove the file on EXPIRE and FAIL.

Reviewed by:    bcr (manpage)
Differential Revision:  https://reviews.freebsd.org/D60259
DeltaFile
+32-0sbin/dhclient/dhclient-script
+10-1sbin/dhclient/dhclient-script.8
+42-12 files

FreeBSD/src afee6fb — sbin/dhclient clparse.c

dhclient: request the Captive Portal options

Add DHCP options 114 (captive-portal) and 160 (captive-portal-legacy)
to the default Parameter Request List so that servers advertise the
Captive Portal API URI.

Approved by:            emaste
Reviewed by:            emaste
Differential Revision:  https://reviews.freebsd.org/D60257
DeltaFile
+5-0sbin/dhclient/clparse.c
+5-01 files

FreeBSD/src a1789e3 — sbin/dhclient dhcp.h dhclient.c

dhclient: recognize the Captive Portal DHCP options

Rename option 114 from "url" to "captive-portal" (RFC 8910) and retain
"url" as a deprecated alias.  Rename option 160 from the generic
"option-160" to "captive-portal-legacy" (RFC 7710).

Reviewed by:    emaste, dch
Apprived by:    emaste, dch
Differential Revision:  https://reviews.freebsd.org/D60256
DeltaFile
+16-5sbin/dhclient/dhcp-options.5
+8-4sbin/dhclient/tables.c
+2-1sbin/dhclient/dhcp.h
+2-1sbin/dhclient/dhclient.c
+28-114 files

FreeBSD/src 67f85bf — sys/dev/gve gve_utils.c

gve: fix double free on ring allocation failure

When gve_alloc_rings fails (such as when failing to acquire MSI-X
vectors or during partial ring allocation), ring cleanup can be
executed multiple times across nested error paths (e.g. within
gve_alloc_rings abort and gve_attach abort).

Because gve_free_counters invoked counter_u64_free without nullifying
the pointer in the stats array, repeated invocation caused a double-free
panic when freeing the same counter references.

Check for non-NULL before freeing and nullify each counter pointer
upon release in gve_free_counters.

Signed-off-by: Jasper Tran O'Leary <jtranoleary at google.com>

Reviewed by:    adrian, markj
MFC after:      2 weeks
Differential Revision:  https://reviews.freebsd.org/D60386
DeltaFile
+6-2sys/dev/gve/gve_utils.c
+6-21 files

FreeBSD/src d45b063 — sys/dev/gve gve_tx.c gve_rx.c

gve: fix kernel panic on attach failure

When device initialization fails during attach (for instance, if device
resource configuration or firmware negotiation fails), the driver aborts
and unrolls partial state via its detach routine. However, the teardown
path assumes transmit and receive queues have already been created. If
attach aborts before queue allocation, tearing down the uninitialized
queues triggers a NULL pointer dereference and panics the kernel during
boot.

Guard queue teardown against uninitialized queue state so that early
attach failures unwind safely, allowing the driver to report the failure
gracefully without crashing the operating system.

Signed-off-by: Jasper Tran O'Leary <jtranoleary at google.com>

Reviewed by:    adrian, markj
MFC after:      2 weeks
Differential Revision:  https://reviews.freebsd.org/D60385
DeltaFile
+10-6sys/dev/gve/gve_main.c
+3-0sys/dev/gve/gve_tx.c
+3-0sys/dev/gve/gve_rx.c
+16-63 files

FreeBSD/src 5c20c75 — sys/net if_epair.c

epair: Make vnet_epair_uninit() run earlier

I can't see a reason for vnet_epair_init() and vnet_epair_uninit() to be
inconsistent in the sys(un)init run order.  Move vnet_epair_uninit() to
SI_SUB_PSEUDO, which is more appropriate for software ifnet drivers.

Reviewed by:    glebius
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D60388
DeltaFile
+1-1sys/net/if_epair.c
+1-11 files

FreeBSD/src a23901a — sys/compat/linux linux_if.c

linux: Initialize per-VNET state earlier

Make sure that linux_ifnet_departure() can't run after
linux_ifnet_vnet_uninit() has destroyed the per-VNET unit number
allocator.  Otherwise, when ifc_detach_cloner() destroys instances of an
interface type, it might be running too late.  Most cloner-based drivers
tear themselves down during SI_SUB_PSEUDO or SI_SUB_PROTO_IF.

Reviewed by:    pouria, glebius
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D60389
DeltaFile
+2-2sys/compat/linux/linux_if.c
+2-21 files

FreeBSD/src bd369bc — . .mailmap, share/misc committers-src.dot

committers-src: Add lytboris mentored by ae@

Reviewed by:    ae
Approved by:    ae (mentor)
DeltaFile
+2-0share/misc/committers-src.dot
+1-0usr.bin/calendar/calendars/calendar.freebsd
+1-0.mailmap
+4-03 files

FreeBSD/src b6d10a9 — sys/sys sched.h

sched.h: Include <sys/pcpu.h> unconditionally

Even if SCHED_STATS is not defined, this header is necessary to provide
a definition of 'curthread' used in sched_pin() and sched_unpin().

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
DeltaFile
+0-2sys/sys/sched.h
+0-21 files

FreeBSD/src 25faf86 — share/man/man4 pcm.4, sys/dev/sound/pcm channel.c

pcm.4: Remove DIAGNOSTICS section

These diagnostics do not exist anymore.

MFC after:      1 week
DeltaFile
+1-9share/man/man4/pcm.4
+1-1sys/dev/sound/pcm/channel.c
+2-102 files

FreeBSD/src c977992 — sys/fs/cuse cuse.c

cuse: Rename cuse_server_free() to cuse_server_dtor()

This name is clearer, given that this function is the cdevpriv
destructor callback.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation

(cherry picked from commit b55b6e1d727bdc810b157047cb12e2e550333551)
DeltaFile
+2-2sys/fs/cuse/cuse.c
+2-21 files

FreeBSD/src 2cb963e — sys/fs/cuse cuse.c

cuse: Implement hot-unload

cuse_kern_uninit() can hang on destroy_dev(), because of threads
sleeping in CUSE_IOCTL_GET_COMMAND, so implement d_purge to wake them up
before calling destroy_dev(). Also do not allow threads to go back to
sleep if the is_closing flag has been set.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D60022

(cherry picked from commit d38ef1aca969f9a79572958c06bc4a4e03f053c2)
DeltaFile
+59-33sys/fs/cuse/cuse.c
+59-331 files

FreeBSD/src 58ca5e4 — sys/fs/cuse cuse.c

cuse: Assert the server refcount

Assert that the refcount does not underflow before decrementing it, and
that it really is zero by the time the server is freed.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D60043

(cherry picked from commit f96c4f45f791124192363c9aa2898b1d0e4cc6d0)
DeltaFile
+2-0sys/fs/cuse/cuse.c
+2-01 files

FreeBSD/src 4772247 — sys/fs/cuse cuse.c

cuse: Actually use cuse_modevent()

We can call cuse_kern_init()/cuse_kern_uninit() here, rather than using
SYSINIT/SYSUNINIT.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D59862

(cherry picked from commit 2fd8d2eb7bb91148169471291dbcfa499579b1bc)
DeltaFile
+33-30sys/fs/cuse/cuse.c
+33-301 files

FreeBSD/src b1aea70 — sys/fs/cuse cuse.c

cuse: Fix hang on readv(2) and writev(2) with multiple iovecs

uiomove() leaves an iovec it has just emptied as the current one, so
cuse_client_read() and cuse_client_write() picked it up again on the
next iteration, sent the server a zero-length command, and got zero
bytes back. That left the residual count unchanged, so the loop never
terminated and the call never returned.

Step past empty iovecs at the start of every iteration. This also covers
caller-supplied zero-length iovecs, which hung in the same way

PR:             293489
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib, markj
Differential Revision:  https://reviews.freebsd.org/D59822

(cherry picked from commit 872c36cb6f2de17278c559a300c2163d8b39b3c6)
DeltaFile
+24-4sys/fs/cuse/cuse.c
+24-41 files

FreeBSD/src 8b462fa — sys/fs/cuse cuse.c

cuse: Remove unnecessary semicolon in cuse_convert_error()

No functional change intended.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation

(cherry picked from commit e923a30ecf2a34cdf46afcfbffdbc30e822148d1)
DeltaFile
+0-1sys/fs/cuse/cuse.c
+0-11 files

FreeBSD/src 1c6b481 — sys/fs/cuse cuse.c

cuse: Use make_dev_s() to create client devices

make_dev_s() sets si_drv1 before the node is published in devfs, which
avoids a race where cuse_client_open() could see it as NULL. It also now
reports finer-grained errors on failure, instead of only ENOMEM.

While here, drop the NULL checks on kern_dev in cuse_server_free_dev(),
since a device is only added to the server's list once it has been
created.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D59874

(cherry picked from commit fad756fd200bf988861eb80146392661a887ab71)
DeltaFile
+13-13sys/fs/cuse/cuse.c
+13-131 files

FreeBSD/src f9669d9 — sys/fs/cuse cuse_defs.h cuse.c

cuse: Retire unnecessary CUSE_VERSION

No functional change intended.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation

(cherry picked from commit 34b00da59b8f8c3fa877135beaefd3ad31841f41)
DeltaFile
+0-4sys/fs/cuse/cuse.c
+0-2sys/fs/cuse/cuse_defs.h
+0-62 files

FreeBSD/src ba847a0 — sys/fs/cuse cuse.c

cuse: Improve server cleanup

Move cuse_server_unref()'s device cleanup loop into a new
cuse_server_free_devs_locked(), and call it from cuse_server_free()
instead. The cdevpriv destructor now destroys the server's devices
before dropping its reference, which closes the clients using them, so
that the destructor is always the one that takes the last reference.

By the time cuse_server_unref() frees the server, the device list should
be empty, so assert this.

In cuse_kern_uninit(), delete the infinite loop which waits for all open
/dev/cuse instances to exit, and instead call destroy_dev() directly,
which runs their cdevpriv destructor.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D59872

    [2 lines not shown]
DeltaFile
+22-30sys/fs/cuse/cuse.c
+22-301 files

FreeBSD/src 598eb67 — sys/fs/cuse cuse.c

cuse: Create /dev/cuse with MAKEDEV_CHECKNAME

Since we now use make_dev_credf(), make sure to fail kldload if it
returned NULL.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D59863

(cherry picked from commit 3b3e6473b13093c6900194b42e8a11f56c2ea7d8)
DeltaFile
+12-6sys/fs/cuse/cuse.c
+12-61 files

FreeBSD/src 556d10a — share/man/man4 Makefile

man: Link ena.4 to if_ena.4

For consistency, create a symbolic link from ena.4 to also if_ena.4

Reviewed by:            #manpages, ziaee
Differential Revision:  https://reviews.freebsd.org/D60191
MFC after:              3 days

(cherry picked from commit 566fdcba48817b0f8fea1f9b2963505b925675fb)
DeltaFile
+1-0share/man/man4/Makefile
+1-01 files

FreeBSD/src 139fa2c — sys/net/route route_ctl.c

routing: fix rtentry use-after-free in multipath route append

add_route_flags() drops the RIB lock and passes the existing entry,
rt_orig, to add_route_flags_mpath(). If a concurrent delete removes
the prefix in that window, the retry re-inserts rt_orig, which is
then freed while still linked, crashing later in rn_match().

Pass the new rt instead, return ENOENT when the prefix is gone and
RTM_F_CREATE is not set, and fix the rnd_orig NULL check.

Approved by:    pouria
Fixes:          c24a8f19c5d5 ("routing: fix rib_add_route_px()")
Differential Revision:  https://reviews.freebsd.org/D60353
DeltaFile
+12-2sys/net/route/route_ctl.c
+12-21 files

FreeBSD/src a6a8640 — tests/sys/netinet6 ndp.sh

tests/netinet6: fix ndp_del_gu_success flakiness

The test pinged an unanswered address and then deleted the resulting
INCOMPLETE neighbor entry.
The kernel frees that entry after about 3s, so on a loaded VM,
ndp -d could run too late and fail with ENOENT.

Configure 2001:db8::2 on epair0b so the ping gets a reply and the
entry becomes REACHABLE.

Approved by:    pouria
Sponsored by:   Netflix
Differential Revision:  https://reviews.freebsd.org/D60348
DeltaFile
+8-4tests/sys/netinet6/ndp.sh
+8-41 files

FreeBSD/src ad3fdab — sys/kern vfs_vnops.c vfs_syscalls.c, sys/sys stat.h

stat(2): report mount points using st_bsdflags SFBSD_MNTPOINT flag

(cherry picked from commit 0d5d8872931c2659692b5e59db2190b715ff314c)
DeltaFile
+2-0sys/kern/vfs_vnops.c
+2-0sys/kern/vfs_syscalls.c
+1-0sys/sys/stat.h
+5-03 files

FreeBSD/src 9a0ea12 — lib/libsys stat.2

stat.2: document SFBSD_MNTROOT

(cherry picked from commit 1e8708d9b598415a993fecb7b5c5cc8a9e64cba5)
DeltaFile
+4-0lib/libsys/stat.2
+4-01 files

FreeBSD/src 2961d9d — lib/libsys stat.2

stat(2): Document st_bsdflags and SFBSD_NAMEDATTR

(cherry picked from commit 72e391060bb6c83ed65ac7ca3936bd6e07ab1ebc)
DeltaFile
+19-2lib/libsys/stat.2
+19-21 files

FreeBSD/src ef78a88 — . misc-agent.c ed25519.sh, openbsd-compat port-linux-selinux.c

Vendor import of OpenSSH 10.6p1

Sponsored by:   The FreeBSD Foundation
DeltaFile
+4,598-1,983ed25519.c
+1,277-1,052ChangeLog
+279-261configure
+256-165ed25519.sh
+191-65misc-agent.c
+243-0openbsd-compat/port-linux-selinux.c
+6,844-3,526127 files not shown
+9,000-4,999133 files

FreeBSD/src 77a7a48 — sys/fs/nfs nfs_var.h, sys/fs/nfsclient nfs_clrpcops.c nfs_clcomsubs.c

nfscl: Fix oddball cases for session slot release

We have identified some cases where silent slot loss can occur
when operations on NFS mounts are aborted. We experience this
when using NFSv4.2, but it likely also occurs with NFSv4.1.

A slot is acquired for compound operations by nfsv4_setsequence()
and freed by newnfs_request(). Any call path that abandons the
compound before reaching newnfs_request() loses the slot permanently.

We identified four call sites where this happens, one of
which where it actually does happen for us in a semi-reproducible
way, which allowed us to develop a candidate patch, attached.

The patch adds one function, nfsv4_freeunsentslot(), to
nfs_clcomsubs.c. It is called from each of the four call
sites: nfsrpc_writerpc(), nfsrpc_writeds(), and two in
nfsrpc_setextattr().


    [11 lines not shown]
DeltaFile
+18-0sys/fs/nfsclient/nfs_clcomsubs.c
+4-0sys/fs/nfsclient/nfs_clrpcops.c
+2-0sys/fs/nfs/nfs_var.h
+24-03 files

FreeBSD/src 192781b — lib/libthr/thread thr_mutex.c

libthr: Consume error in check_and_init_mutex

MFC after:      2 weeks
DeltaFile
+1-1lib/libthr/thread/thr_mutex.c
+1-11 files