FreeBSD/src 41c078c — lib/libpam/modules/pam_ssh pam_ssh.c

pam_ssh: Fix build - chase OpenSSH function signature change

Reported by: dch
Fixes: 644b4646c7ac ("OpenSSH: Update to 10.1p1")
Sponsored by: The FreeBSD Foundation

(cherry picked from commit b76b05c04cc9ed2cd053c7b367c92628447ede6f)
DeltaFile
+1-1lib/libpam/modules/pam_ssh/pam_ssh.c
+1-11 files

FreeBSD/src 1e595e9 — sys/fs/devfs devfs_vnops.c

devfs_open: do not access dsw after dev_relthread()

Noted and reviewed by:  markj
Fixes:  850d4562928e ("cdevsw: add D_NONPASSABLE flag")
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
Differential revision:  https://reviews.freebsd.org/D60393
DeltaFile
+3-2sys/fs/devfs/devfs_vnops.c
+3-21 files

FreeBSD/src a5ae2a9 — sys/kern kern_jaildesc.c

jaildesc: Lock prison pointer when filling kinfo

Submitted by:   Yuri Tkachenko <yura.tkachenko at gmail.com>
MFC after:      3 days
Differential Revision:  https://reviews.freebsd.org/D60392
DeltaFile
+2-0sys/kern/kern_jaildesc.c
+2-01 files

FreeBSD/src 9197016 — . Changes, doc reference.html

Vendor import of expat 2.9.0
DeltaFile
+790-0tests/props_tests.c
+681-73doc/reference.html
+413-154lib/xmlparse.c
+56-220lib/xmltok.c
+131-39tests/basic_tests.c
+102-26Changes
+2,173-51244 files not shown
+2,978-86150 files

FreeBSD/src bb5f10e — sys/compat/linux linux_dummy.c linux_misc.h

linux: implement sched_getattr()

This change adds the necessary glue to translate Linux scheduler policy
and priority from FreeBSD so this information is available to Linux
applications.

This unbreaks using the Linux version of Chromium on FreeBSD.

This change was originally submitted via [freebsd/freebsd-src#2370][github-pr].

MFC after:      2 weeks
PR:     297468
Co-Authored-By: Enji Cooper <ngie at FreeBSD.org>
Signed-off-by:  Joao Bonifacio <joaoboni017 at gmail.com>

[github-pr]: https://github.com/freebsd/freebsd-src/pull/2370

Differential Revision:  https://reviews.freebsd.org/D60214
DeltaFile
+89-0sys/compat/linux/linux_misc.c
+17-2sys/compat/linux/linux_misc.h
+0-1sys/compat/linux/linux_dummy.c
+106-33 files

FreeBSD/src 4bb6015 — sys/netinet in.c, sys/netinet6 in6.c

netinet: Deprecate OSIOCAIFADDR and OSIOCAIFADDR_IN6

Requested by:   glebius
Reviewed by:    pouria, glebius
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D60247
DeltaFile
+3-0sys/netinet/in.c
+2-0sys/netinet6/in6.c
+5-02 files

FreeBSD/src 499901d — sys/ufs/ffs ffs_suspend.c

ufssuspend(4): mark non-passable

This fixes long-standing issue where ufssuspend file descriptor could
leak over fork or be passed over unix domain socket, and then closing it
in the opener would not unsuspend the file system.

It should not affect the well-behaving growfs(8) utility, but makes the
userspace API safer on principle.

Reviewed by:    markj
Tested by:      pho (previous version)
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
Differential revision:  https://reviews.freebsd.org/D60285
DeltaFile
+1-0sys/ufs/ffs/ffs_suspend.c
+1-01 files

FreeBSD/src 850d456 — sys/fs/devfs devfs_vnops.c, sys/sys conf.h

cdevsw: add D_NONPASSABLE flag

to make the opened device files non-passable.

Reviewed by:    markj
Tested by:      pho (previous version)
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
Differential revision:  https://reviews.freebsd.org/D60285
DeltaFile
+25-2sys/fs/devfs/devfs_vnops.c
+2-0sys/sys/conf.h
+27-22 files

FreeBSD/src 481447a — sys/dev/e1000 if_em.c

e1000: Fix the flow control sysctl

dev.em.N.fc and dev.igb.N.fc read and wrote a function-static variable
shared by every em(4) and igb(4) device, so a read returned the last
value written to any of them (3 until the first write), not the state of
the device.  The softc value started as 0, which is also the value of
"no flow control", while the hardware was set up for full flow control.
As a result:

- Writing 0 was taken for no change and did nothing, unless another
  value had been written to that device before.
- em_reset() took a softc value of 0 for "not set", so a device set to 0
  went back to full flow control on the next init.
- On igb(4) with more than one receive queue the driver enabled
  per-queue drop (SRRCTL.DROP_EN), which is meant for a MAC that does
  not send pause frames, although the MAC was told to send them.
- Values out of range were accepted and ignored.

A write only forced the MAC's flow control bits.  The pause bits

    [18 lines not shown]
DeltaFile
+20-17sys/dev/e1000/if_em.c
+20-171 files

FreeBSD/src b45d14d — share/mk sys.mk

sys.mk: CTFMERGE: don't assume objfiles always have CTF sections

There are many instances, e.g. in the kernel, where
object files don't have CTF sections, but still need
to be merged into one that does have a CTF section.

This fixes cases like the following:

--------------------------------------------------------------
>>> stage 3.1: building everything
--------------------------------------------------------------

linking kernel.full
ctfmerge -t -L VERSION -g -o kernel.full ...
ERROR: ctfmerge: Input file force-dynamic-hack.pico was partially built from C sources, but no CTF data was present
Removing kernel.full

    kernel.full ---
    [kernel.full] Error code 1

    [8 lines not shown]
DeltaFile
+1-1share/mk/sys.mk
+1-11 files

FreeBSD/src 152dd1a — . ObsoleteFiles.inc

ObsoleteFiles.inc: add more obsolete files
DeltaFile
+13-0ObsoleteFiles.inc
+13-01 files

FreeBSD/src 01f9356 — secure/libexec/ssh-keysign Makefile, secure/libexec/ssh-pkcs11-helper Makefile

secure: Adapt Makefile to ssh-sk-client everywhere

Upstream commit 7b47b40b1 ("adapt Makefile to ssh-sk-client everywhere")
adapted the Makefiles to ssh-sk-client.  Do the same here.

Reviewed by:    emaste
Approved by:    emaste (mentor)
Differential Revision:  https://reviews.freebsd.org/D49795

(cherry picked from commit 65d8491719bbc88ed45637d2381931c2d29cfe87)
DeltaFile
+1-2secure/usr.bin/ssh-keygen/Makefile
+2-1secure/usr.sbin/sshd/Makefile
+1-1secure/usr.bin/ssh-agent/Makefile
+1-1secure/usr.bin/ssh-add/Makefile
+1-1secure/libexec/ssh-pkcs11-helper/Makefile
+1-1secure/libexec/ssh-keysign/Makefile
+7-74 files not shown
+10-1010 files

FreeBSD/src 98cd53b — stand/images freebsd-logo-rev.png

stand/images: remove translucent pixels around orb

Remove semi-transparent pixels around the orb. These become more
pronounced when the orb is used as the spash screen image.

While here also strip metadata.

MFC after:      3 days
Reviewed by:    tsoome
Differential Revision:  https://reviews.freebsd.org/D60163

(cherry picked from commit f7663278c2ba527dc681b1a806d4cc78ea49452b)
DeltaFile
+0-0stand/images/freebsd-logo-rev.png
+0-01 files

FreeBSD/src 2192d42 — stand/images freebsd-logo-rev.png

stand/images: remove translucent pixels around orb

Remove semi-transparent pixels around the orb. These become more
pronounced when the orb is used as the spash screen image.

While here also strip metadata.

MFC after:      3 days
Reviewed by:    tsoome
Differential Revision:  https://reviews.freebsd.org/D60163

(cherry picked from commit f7663278c2ba527dc681b1a806d4cc78ea49452b)
DeltaFile
+0-0stand/images/freebsd-logo-rev.png
+0-01 files

FreeBSD/src ac24108 — sys/net iflib.c

iflib: Make the deferral test in iflib_txd_db_check() an early return

Invert the test so the doorbell write is no longer nested inside the
conditional, and wrap its comments to 80 columns.  Fix a typo in one of
them.

No functional change intended.

Reviewed by:            kbowling
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60371
DeltaFile
+19-18sys/net/iflib.c
+19-181 files

FreeBSD/src e89c3ac — sys/dev/acpica/Osd OsdSchedule.c

acpi: Tasks: Document why 'acpi_task_count' is accessed unsynchronized

MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
DeltaFile
+1-0sys/dev/acpica/Osd/OsdSchedule.c
+1-01 files

FreeBSD/src f0825f7 — sys/dev/acpica/Osd OsdSchedule.c

acpi: Tasks: Make OsdSchedule.c whitespace clean

MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
DeltaFile
+1-1sys/dev/acpica/Osd/OsdSchedule.c
+1-11 files

FreeBSD/src 2165acc — sys/dev/acpica/Osd OsdSchedule.c

acpi: Tasks: Remove unnecessary includes

MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
DeltaFile
+0-2sys/dev/acpica/Osd/OsdSchedule.c
+0-21 files

FreeBSD/src 4a0ec46 — sys/net iflib.c

iflib: Do not ring the transmit doorbell when nothing is pending

For a lightly used ring iflib_txd_db_check() may defer zero descriptors,
so its "pending >= limit" test is true even when nothing has been queued
since the last doorbell.  iflib_txq_drain() calls it before, inside and
after its loop, so a sender that drains its own packet wrote the tail
register three times per packet, twice with the value the hardware
already had.

The log of 81be655266fa ("iflib: ensure that tx interrupts enabled and
cleanups") calls skipping the doorbell when db_pending is zero "an
obvious missing optimization"; the comparison against a limit of zero
defeated it.  vmx(4) and mgb(4) have dropped such repeated requests in
the driver since 2019.  Return early when nothing is pending.

Reviewed by:            gallatin
MFC after:              2 weeks
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60290
DeltaFile
+7-0sys/net/iflib.c
+7-01 files

FreeBSD/src 16c787f — sys/arm64/arm64 busdma_bounce.c, sys/arm64/include bus_dma.h

arm64: Elide coherent busdma maps

Avoid allocating per-transfer maps for coherent tags that cannot
bounce. Retain maps for cache synchronization, CCA realms, and KMSAN.
These un-used maps carry with them memory and cache miss overheads.

Reviewed by: andrew
Differential Revision: https://reviews.freebsd.org/D60098
Sponsored by: Netflix
DeltaFile
+65-15sys/arm64/arm64/busdma_bounce.c
+8-4sys/arm64/include/bus_dma.h
+73-192 files

FreeBSD/src 2082f44 — crypto/openssh FREEBSD-upgrade

openssh: Add date bump command to FREEBSD-upgrade instructions

Provide a convenient in-place sed edit command to update the FreeBSD
VersionAddendum dates with today's date.

Sponsored by:   The FreeBSD Foundation

(cherry picked from commit 0ec81f6a531bf7b3b06e869c99295f3d4ab9ed8e)
(cherry picked from commit 2ba5b9da2be10261c383035bef932cd37d52f903)
DeltaFile
+5-0crypto/openssh/FREEBSD-upgrade
+5-01 files

FreeBSD/src b690ed4 — crypto/openssh FREEBSD-upgrade

openssh: Add reference for another local patch

A bug fix was committed locally and submitted upstream.  Document it in
our upgrade instructions, as these sometimes take a long time before
getting merged.

Sponsored by:   The FreeBSD Foundation

(cherry picked from commit 6531070132b0210aaaeb08c0dc93cb272bed348e)
(cherry picked from commit 14d6926293569048d2d04f6e5a13d80f192ad99e)
DeltaFile
+5-0crypto/openssh/FREEBSD-upgrade
+5-01 files

FreeBSD/src 0dfc112 — secure/usr.bin/scp Makefile, secure/usr.bin/sftp Makefile

openssh: Remove residual blank line at start of Makefile

This is part of commit e9ac41698b2f in main by imp@
DeltaFile
+0-1secure/usr.bin/ssh-keyscan/Makefile
+0-1secure/usr.bin/ssh-keygen/Makefile
+0-1secure/usr.bin/ssh-agent/Makefile
+0-1secure/usr.bin/ssh-add/Makefile
+0-1secure/usr.bin/sftp/Makefile
+0-1secure/usr.bin/scp/Makefile
+0-66 files not shown
+0-1212 files

FreeBSD/src dcab585 — secure ssh.mk, secure/lib/libssh Makefile

secure: Rearrange Makefile SRCS to match upstream Makefile.in

SRCS entries are kept in the same order and with the same line breaks as
upstream, to make comparison easier.

No functional change intended.

Reviewed by:    emaste
Approved by:    emaste (mentor)
Differential Revision:  https://reviews.freebsd.org/D49793

(cherry picked from commit 9440aad19dca73fdd224b128ac2dc2e78191ff15)
DeltaFile
+16-7secure/lib/libssh/Makefile
+2-2secure/libexec/sftp-server/Makefile
+1-2secure/usr.bin/sftp/Makefile
+1-1secure/usr.bin/scp/Makefile
+1-1secure/libexec/ssh-pkcs11-helper/Makefile
+2-0secure/ssh.mk
+23-131 files not shown
+24-147 files

FreeBSD/src 412c3a0 — sys/arm64/arm64 gicv5_acpi.c

arm64/gicv5: Use ArmMpidr to find the correct CPU

The GICv5 ACPI code uses CpuInterfaceNumber to as the CPU ID. This a
GICv5 CPU ID and may not be the same as the appropriate FreeBSD value.

It is also possible the target CPU is disabled, e.g. when the hw.ncpu
tunable is uses to limit CPUs. If this is the case we don't want to
enable the CPU in the cpu set as it is offline so cannot handle
interrupts.

Switch to use ArmMpidr to find which pcpu to use when finding which
CPUs the IRS is attached to.

Fixes:  9556306213e1 ("arm64: Add ACPI support to GICv5 driver")
Differential Revision:  https://reviews.freebsd.org/D59993
Sponsored by:   Arm Ltd
DeltaFile
+14-3sys/arm64/arm64/gicv5_acpi.c
+14-31 files

FreeBSD/src 128e91e — libexec/rc/rc.d nuageinit_user_data_script

nuageinit: Allow the userdata script to run before firstboot* rc services

Allowing nuageinit user scripts to run before these makes it possible to
customize official BASIC-CI and BASIC-CLOUDINIT FreeBSD images.

This was requested by KDE for their CI.

Approved by:    cperciva
Pull-Request:   https://ron-dev.freebsd.org/FreeBSD/src/pulls/60

(cherry picked from commit 16e47f317c4ce2be5fed530bf8a9af9f9bf55364)
DeltaFile
+1-0libexec/rc/rc.d/nuageinit_user_data_script
+1-01 files

FreeBSD/src fdd3f6f — share/mk sys.mk bsd.lib.mk

bsd.lib.mk: only ctfmerge if objfiles have a CTF section

PR:             299013
Reported by:    Trond.Endrestol at ximalas.info
Reviewed by:    emaste
Fixes:          222210c6a822 ("libgcc_s: add libgcc_s_asneeded.so wrapper for gcc 16")
MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D60252
DeltaFile
+1-1share/mk/sys.mk
+1-1share/mk/bsd.lib.mk
+2-22 files

FreeBSD/src 68386f6 — sys/dev/igc if_igc.c

igc: Fix the flow control sysctl

dev.igc.N.fc read and wrote a function-static variable shared by every
igc device, so a read returned the last value written to any of them (3
until the first write), not the state of the device.  The softc value
started as 0, which is also the value of "no flow control", while the
hardware was set up for full flow control.  As a result:

- Writing 0 was taken for no change and did nothing, unless another
  value had been written to that device before.
- igc_reset() took a softc value of 0 for "not set", so a device set to
  0 went back to full flow control on the next init.
- With more than one receive queue the driver enabled per-queue drop
  (SRRCTL.DROP_EN), which is meant for a MAC that does not send pause
  frames, although the MAC was told to send them.
- Values out of range were accepted and ignored.

A write only forced the MAC's flow control bits.  The pause bits
advertised to the link partner, the pause thresholds and DROP_EN stayed

    [24 lines not shown]
DeltaFile
+16-16sys/dev/igc/if_igc.c
+16-161 files

FreeBSD/src f2b0910 — crypto/openssh moduli servconf.c, crypto/openssh/regress/unittests/crypto/testdata nistkats-44.json

OpenSSH: Update to 10.4p1

Full release notes are available at
https://www.openssh.com/txt/release-10.4

Selected highlights from the release notes:

Potentially-incompatible changes
--------------------------------

 * sshd(8): configuration dump mode ("sshd -G") now writes directives
   in mixed case (e.g. "PubkeyAuthentication") whereas previously it
   emitted only lower-case names.

 * ssh(1), sshd(8): make the transport protocol stricter by
   disconnecting if the peer sends non-KEX messages during a post-
   authentication key re-exchange. Previously a malicious peer could
   continue sending non-key exchange messages without penalty. These
   would be buffered, causing memory to be wasted up until the

    [73 lines not shown]
DeltaFile
+27,332-0crypto/openssh/libcrux_internal.h
+0-11,752crypto/openssh/libcrux_mlkem768_sha3.h
+1,869-1,349crypto/openssh/ChangeLog
+1,446-525crypto/openssh/servconf.c
+539-585crypto/openssh/moduli
+802-0crypto/openssh/regress/unittests/crypto/testdata/nistkats-44.json
+31,988-14,211158 files not shown
+37,553-15,620164 files

FreeBSD/src 2bdbd0a — crypto/openssh channels.c ssh-pkcs11-helper.c, crypto/openssh/openbsd-compat bsd-misc.c

OpenSSH: Update to 10.2p1

Full release notes are available at
https://www.openssh.com/txt/release-10.2

Selected highlights from the release notes:

Bugfixes
--------

 * ssh(1): fix mishandling of terminal connections when
   ControlPersist was active that rendered the session unusable.
   bz3872

Sponsored by:   The FreeBSD Foundation

(cherry picked from commit e68aa5ab80ab57bdbcbe94dd2922a018d675e7f0)
DeltaFile
+146-37crypto/openssh/ChangeLog
+26-5crypto/openssh/ssh-pkcs11.c
+24-0crypto/openssh/openbsd-compat/bsd-misc.c
+0-16crypto/openssh/ssh-pkcs11-helper.c
+8-4crypto/openssh/regress/test-exec.sh
+5-4crypto/openssh/channels.c
+209-6616 files not shown
+248-8022 files