openssl: make libcrypto export the same symbols as upstream
Make the libcrypto Version.map export the same symbol names as upstream
3.5.8 (and 3.5.9, no new symbols were added).
Remove 52 names that upstream does not export:
- the internal threading and record layer functions (ossl_crypto_*,
ssl3_cbc_*, tls1_cbc_*), which only libssl used;
- the internal WPACKET_quic_* functions;
- OPENSSL_cpuid_setup;
- ASN.1 item functions that are not in util/libcrypto.num.
Add 7 public names that were missing (ASYNC_get_mem_functions,
ASYNC_set_mem_functions, CMS_EnvelopedData_it, EVP_CipherPipeline*) to
OPENSSL_3_5_0, where the other symbols from upstream 3.1 to 3.5 are.
EC_GFp_nistp224_method, EC_GFp_nistp256_method and
EC_GFp_nistp521_method stay unexported (see 6f6446b33064).
[9 lines not shown]
acpi_timer: Trim some more leftovers from the ACPI-safe timer
The "safe" variant of the hook to read the timer is no longer used and
can be removed. Instead, initialize the get_timecount member of
acpi_timer_timecounter to the normal hook statically. While here,
initialize a few more fields in acpi_timer_timecounter statically.
I've kept the name as just "ACPI" instead of "ACPI-fast" now.
During device probe there is no longer any reason to alloc the
register resource since it is not used, so remove all that. While
here, defer registration of the timecounter until attach (kind of odd
to do such a thing during probe leaving a window where the timer
register was unallocated but in theory could still be read via the
timecounter).
Reviewed by: cperciva
Fixes: 00d061855deb ("Garbage-collect ACPI-safe timer and friends")
Differential Revision: https://reviews.freebsd.org/D59933
(cherry picked from commit d23d186ff212023c4e1ff61a0f488dc4dcb1b75c)
acpi_timer: Remove unneeded acpi_timer_freq global variable
This was just an alias of acpi_timer_timecounter.tc_frequency. While
here, register the machdep.acpi_timer_freq sysctl node dynamically
only if the driver attaches rather than making the handler fail with
EOPNOTSUPP if the driver had not attached.
Differential Revision: https://reviews.freebsd.org/D59935
(cherry picked from commit 381840e88072a90df7ffb5731c08935412edbc19)
pcib: Only apply ARI translation to a bridge's own secondary bus
ARI changes RID interpretation only for the device on a downstream
port's secondary bus. pcib_xlate_ari() applied that translation to
every config access through an ARI-enabled bridge, including cycles
forwarded to a subordinate bus.
A non-zero slot on a subordinate bus then panics an INVARIANTS kernel
and is misrouted otherwise. Translate only when the access targets
this bridge's secondary bus.
Reviewed by: kib, jhb
Fixes: 55d3ea1731d1 ("Add support for PCIe ARI")
Sponsored by: AMD
Differential Revision: https://reviews.freebsd.org/D60033
(cherry picked from commit 10409ee40baf593b810cd0140f3c2f0d737c1a65)
dtrace: Remove bogus Makefile.inc
This was added in the initial import of dtrace and overrides the
normal load/unload targets with a custom target that loads a hardcoded
set of modules. Over time, the set of modules has not been updated
and is now incomplete. It's also not really useful compared to the
default implementation of these targets used for loading or unloading
an individual module being actively developed.
This functionality is also available via dtraceall.ko which is how
users commonly load the full suite of dtrace modules.
Reviewed by: imp, markj
Differential Revision: https://reviews.freebsd.org/D59821
(cherry picked from commit df7b90556859e1e5dbaf8d3dae2177ca607c0558)
acpi/apm: Don't claim silent success for APMIO_BIOS ioctls
Report failure as if the request had failed. This causes apm(8) to
correctly report the resume timer as "unknown" rather than random
garbage.
Reviewed by: imp
Differential Revision: https://reviews.freebsd.org/D59939
(cherry picked from commit 1d7f0c742863ad65e9d27df8f5ae4afddd6cc5e2)
acpi_timer: Add a softc to avoid use of global variables
Add a softc and use it to mostly replace the use of global variables
in this driver. Simplify the suspend and resume event handlers by
saving the old timecounter in the softc and passing the softc pointer
to the handlers.
Differential Revision: https://reviews.freebsd.org/D59936
(cherry picked from commit 34cf45a93c54ee9a222d2893b97832283a850715)
cxgbe: Use the correct GHASH offset for a GMAC from a full TLS record
If a TLS request transmits all but a part of the GMAC at the end of a
TLS record, the work request asks the crypto engine to return the
calculated GMAC to the driver so it can be sent in a simple TCP packet
when the rest of the TLS record is transmitted in the future.
However, the offset of the returned GHASH offset was calculated
incorrectly in this case causing the driver to not recognize the
cached GMAC and instead use a more wasteful work request in the future
that encrypted the entire TLS record discarding all but the needed
bytes of the trailer.
Note that this does not effect correctness, just efficiency.
Reviewed by: np
Fixes: 9e269eafebfc ("cxgbe: Use partial GCM mode for partial TLS records on T7")
Sponsored by: Chelsio Communications
Differential Revision: https://reviews.freebsd.org/D59711
(cherry picked from commit ed5fc8066f98e639f624de9997b33727ed883c32)
bhyve: Refactor initial PCI BAR setup
Fully initialize BARs with an address of 0 in pci_emul_alloc_bar()
instead of deferring some of that initialization to
pci_emul_assign_bar(). Now, the latter is only used to allocate an
initial address range for PCI BARs.
Note that this means that the pci_passthru model now overrides the
initial lobits after they are set removing the need for a workaround
in pci_emul_assign_bar().
Reviewed by: bnovkov
Differential Revision: https://reviews.freebsd.org/D58893
(cherry picked from commit b00bb87a614212a2bbb156288bfdd51b27bcb329)
cxgbe KTLS tx: Distribute FW6_PLD replies across rx queues
If the connection flowid is available then the replies are requested on
the rx queue that is receiving wire traffic for the connection. This
reduces contention for the txq lock.
Reviewed by: jhb
MFC after: 3 days
Sponsored by: Chelsio Communications
Differential Revision: https://reviews.freebsd.org/D53385
(cherry picked from commit a6ae6090bb3dc14eda750aa53650fccf4c0bf818)
bhyve: Don't set the prefetch flag for large 64-bit memory BARs
The only device model that can create a large 64-bit memory BAR is the
passthru device model, and that device model reuses the lobits of the
existing BAR explicitly.
Fixes: e87a6f3ef284 ("bhyve: use physical lobits for BARs of passthru devices")
(cherry picked from commit 3807c8be4645d7f02c5253aa88b193000e6aef09)
kld: Reject kernel modules with PT_LOAD segments where filesz > memsz
All sorts of places in the ELF loading code assume that filesz <=
memsz, so check that explicitly up front.
Reported by: Jane Smith <thebugfixers at pm.me> (via D57785)
Reviewed by: jrtc27, kib
Differential Revision: https://reviews.freebsd.org/D58542
(cherry picked from commit 486dfbb67e093a461a5ebd97f66be9b345f9de77)
rtld: Reject ELF files with PT_LOAD or PT_TLS segments where filesz > memsz
All sorts of places in the ELF loading code assume that filesz <=
memsz, so check that explicitly up front. The kernel already performs
this check for the PT_LOAD segments in the main binary and rtld in
imgact_elf.c.
Reviewed by: jrtc27, kib
Differential Revision: https://reviews.freebsd.org/D58541
(cherry picked from commit 535eb24d8451bad8de745937018800df1895a9aa)
rangelock: Enable rl_q_owner tracking under INVARIANT_SUPPORT
This fixes the build for kernels with INVARIANT_SUPPORT but without
INVARIANTS.
Fixes: 2e376cca379b ("rangelock: Reimplement _rangelock_cookie_assert()")
(cherry picked from commit bcd1e7a8caac9129cc08995f8ff81a0eef0529bc)
stand: Improve error handling when loading ELF files
Previously all the 'goto out' statements after the image was loaded into
memory returned success rather than an error. This is despite comments
indicating some of these conditions were in fact errors, and some of
these error conditions (such as missing PT_DYNAMIC) are treated as errors
in the kernel linker.
In addition, when failing to looking up the symbols for the linker
set, those cases returned failure leaking memory (though it's clear
from the original code from commit ca49b3342d1e that only the second
failure was intended to be an actual error).
To avoid more confusion, move the assignment of `ret` to just before
the `out` label so that `goto out` always returns an error. This is a
more consistent pattern with other code in the tree that tends to use
labels for the error case.
Restructure some other code to avoid a few bogus errors.
[8 lines not shown]
bhyve: Tidy lobits handling in pci_passthru
- The lobits field in the "physical" BAR settings is never used, so
don't bother setting it.
- Expand the comment explaining why the existing lobits are preserved
(namely, to preserve the prefetch flag on memory BARs).
Reviewed by: bnovkov
Differential Revision: https://reviews.freebsd.org/D58894
(cherry picked from commit 0ffad4ce5655cbe412b79185d2b7924d0d72983e)
stand: Remove a pointless goto
Commit 505222d35fea removed a batch of code that this goto used to skip
around.
Reviewed by: olce, kib, markj
Fixes: 505222d35fea ("Implement the long-awaited module->file cache database. A userland tool (kldxref(8)) keeps a cache of what modules and versions are inside what .ko files. I have tested this on both Alpha and i386.")
Differential Revision: https://reviews.freebsd.org/D58539
(cherry picked from commit 8aec309852b5285cfa03424f7776a0bf432dff7a)
ctld: Normalize physical port names
Don't require ioctl port names to be fully expanded as this
contradicts the syntax documented in the ctl.conf(5). However, don't
require users to exactly guess when pp or vp can be omitted. Instead,
normalize all physical port names by parsing any port name with a pp
or vp value and reformatting them to a standardized format. This
format is also used when generating names for kernel-enumerated ports.
Reported by: Seth Hoffert <seth.hoffert at gmail.com>
Fixes: caef3c50ac06 ("ctld: Refactor ioctl port handling")
Sponsored by: Chelsio Communications
(cherry picked from commit 4907d1c5c7f97ca985611441df5871705b90030c)
ctld: Simplify handling of non-iSCSI and non-NVMe kernel ports
Just add these directly to the kports object rather than treating them
as iSCSI ports.
Sponsored by: Chelsio Communications
Differential Revision: https://reviews.freebsd.org/D57283
(cherry picked from commit 03ac6fe4f6d2bce06a672024152eb894a423dfcb)
pciconf: Minor cleanups in the config register methods
This is mostly to provide cleaner code for future changes to copy
from.
- Use NULL instead of casting 0 to pointer types.
- Inline readone() in the sole caller now that it is just a single line.
- Use a helper variable for the count of items on each line of output
in readit().
- Fix the double space in the middle of byte output to only trigger
for width 1. For other widths it would output spurious spaces at
the end of the line which doesn't really hurt, but is buggy
nonetheless.
- Avoid using implicit booleans by explicitly comparing integer
expressions against zero.
[6 lines not shown]
getfhat: Add missing 'const' to path argument
This matches the documented prototype and avoids spurious
-Wincompatible-pointer-types-discards-qualifiers warnings when passing
a constant pathname.
Sponsored by: AFRL, DARPA
(cherry picked from commit 09da0899551a63ce3eb841e4ce4385b6e48dd4ec)