routing: fix rtentry use-after-free in multipath route append
add_route_flags() drops the RIB lock and passes the existing entry,
rt_orig, to add_route_flags_mpath(). If a concurrent delete removes
the prefix in that window, the retry re-inserts rt_orig, which is
then freed while still linked, crashing later in rn_match().
Pass the new rt instead, return ENOENT when the prefix is gone and
RTM_F_CREATE is not set, and fix the rnd_orig NULL check.
Approved by: pouria
Fixes: c24a8f19c5d5 ("routing: fix rib_add_route_px()")
Differential Revision: https://reviews.freebsd.org/D60353
tests/netinet6: fix ndp_del_gu_success flakiness
The test pinged an unanswered address and then deleted the resulting
INCOMPLETE neighbor entry.
The kernel frees that entry after about 3s, so on a loaded VM,
ndp -d could run too late and fail with ENOENT.
Configure 2001:db8::2 on epair0b so the ping gets a reply and the
entry becomes REACHABLE.
Approved by: pouria
Sponsored by: Netflix
Differential Revision: https://reviews.freebsd.org/D60348
nfscl: Fix oddball cases for session slot release
We have identified some cases where silent slot loss can occur
when operations on NFS mounts are aborted. We experience this
when using NFSv4.2, but it likely also occurs with NFSv4.1.
A slot is acquired for compound operations by nfsv4_setsequence()
and freed by newnfs_request(). Any call path that abandons the
compound before reaching newnfs_request() loses the slot permanently.
We identified four call sites where this happens, one of
which where it actually does happen for us in a semi-reproducible
way, which allowed us to develop a candidate patch, attached.
The patch adds one function, nfsv4_freeunsentslot(), to
nfs_clcomsubs.c. It is called from each of the four call
sites: nfsrpc_writerpc(), nfsrpc_writeds(), and two in
nfsrpc_setextattr().
[11 lines not shown]
lib80211: fix build with eXpat 2.9.0
eXpat 2.9.0 deprecates XML_GetCurrentLineNumber() in favour of
XML_GetCurrentLineNumber64(). The new function behaves the same
as the old one but is not prone to 32 bit integer wrap-around.
sem test: avoid ETIMEDOUT races in the EINTR test cases
timedwait and clockwait_absolute_intr_remaining arm a 50ms SIGALRM and then
wait until an absolute deadline only 100ms in the future.
On a loaded VM the signal can be delivered more than 50ms late, so the wait
times out first.
Approved by: imp
Sponsored by: Netflix
Differential Revision: https://reviews.freebsd.org/D60347
da: Update trim stats with the periph lock held
Separate the updating the stats for the completion from the biodone for
each one.
Sponsored by: Netflix
Reviewed by: ali_mashtizadeh.com
Differential Revision: https://reviews.freebsd.org/D60156
ada: Update trim stats for every bio
Separate the updating the stats for the completion from the biodone for
each one.
Sponsored by: Netflix
Reviewed by: ali_mashtizadeh.com
Differential Revision: https://reviews.freebsd.org/D60157
nda: Update trim stats with the periph lock held
Separate the updating the stats for the completion from the biodone for
each one.
Sponsored by: Netflix
Reviewed by: ali_mashtizadeh.com
Differential Revision: https://reviews.freebsd.org/D60155
cam: Rename cam_iosched_bio_complete to cam_iosched_bio_update_stats
The function updates scheduler statistics but does not complete the
bio. Rename it to avoid implying ownership of bio completion.
Sponsored by: Netflix
Reviewed by: ali_mashtizadeh.com
Differential Revision: https://reviews.freebsd.org/D60349
pf: set the correct type for rule timeouts
PR: 298877
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")
(cherry picked from commit 3c58e64369fd8124c83f1c7d63106bddca83fa1e)
camcontrol: Add Spectra Logic copyright
The majority of lines of code currently in fwdownload.c come from ken@'s
rework in commit 0e358df062dd ("Revamp camcontrol(8) fwdownload support
and add the opcodes subcommand."). Add the appropriate copyright.
Approved by: ken
riscv: support the new "riscv,isa-extensions" string-array.
Support the new "riscv,isa-extensions" property on RISC-V hart nodes
in FDT.
The "riscv,isa" property is deprecated, but cannot be removed because
doing so would break compatibility with existing DTBs. The new properties
replace it: "riscv,isa-base" describes the base ISA and
"riscv,isa-extensions" is a string array containing the supported ISA
extensions.
The "riscv,isa-extensions" property can be relatively large; on the
Spacemit K3 SoC it is approximately 300 bytes.
The FreeBSD OFW interface does not provide access to the underlying FDT
property data without copying it, and memory allocation is not possible
this early. So allocate a static buffer for the property instead.
Reuse the existing parse_riscv_isa() implementation to parse both the new
[5 lines not shown]
hwpmc: handle delayed IBS NMIs on Zen 6
On Zen 6, an extra IBS NMI can arrive after later samples. Keep the
credit until the empty NMI arrives, and handle fetch and op samples when
both are ready.
Reviewed by: mhorne
Fixes: 34b00ed041a4 ("hwpmc: fix IBS fetch and op NMI handling")
Fixes: e51ef8ae490f ("hwpmc: Initial support for AMD IBS")
Sponsored by: AMD
Differential Revision: https://reviews.freebsd.org/D60367
pmc.h: bump PMC_VERSION_MINOR
Bump for the addition of PMC_OP_GETCAPS and the recently added Intel
CPUs.
Sponsored by: The FreeBSD Foundation
(cherry picked from commit e39d3a6b32331437da6c13a4aeb67e5bcca67625)
libpmc: Query hwpmc for caps
This change allows for fine-grained capabilities per counter index. This
is particularly useful for AMD where subclasses are not exposed to the
general PMC code, but other architectures also have asymmetric behaviors
when it comes to specific counter indices.
A new PMC_OP_GETCAPS op is added to the hwpmc(4) ioctl interface.
Reviewed by: mhorne
Sponsored by: Netflix
Pull Request: https://github.com/freebsd/freebsd-src/pull/2058
(cherry picked from commit 44a983d249d05d932b6cff333f130baf70febc22)
pmc.h: bump PMC_VERSION_MINOR
Bump for the addition of PMC_OP_GETCAPS and the recently added Intel
CPUs.
Sponsored by: The FreeBSD Foundation
(cherry picked from commit e39d3a6b32331437da6c13a4aeb67e5bcca67625)
libpmc: Query hwpmc for caps
This change allows for fine-grained capabilities per counter index. This
is particularly useful for AMD where subclasses are not exposed to the
general PMC code, but other architectures also have asymmetric behaviors
when it comes to specific counter indices.
A new PMC_OP_GETCAPS op is added to the hwpmc(4) ioctl interface.
Reviewed by: mhorne
Sponsored by: Netflix
Pull Request: https://github.com/freebsd/freebsd-src/pull/2058
(cherry picked from commit 44a983d249d05d932b6cff333f130baf70febc22)
bsnmp: validate the lower bound of error_index in responses
Check if the response's error_index is within a sane interval.
Otherwise, a rogue peer could crash us.
PR: 298222
Reported by: Robert Morris
Reviewed by: markj
Discussed with: secteam (markj)
MFC after: 2 weeks
Analyzed with: Claude Code Opus 5
(cherry picked from commit 296e3fd54ca8972fa6696974097a2f2705f8dfc4)
dummynet: do not overflow the points[ED_MAX_SAMPLES_NO] array
Otherwise, the following would segfault
dnctl pipe 1 config bw 1Mbit/s profile 1025points.txt
Found with: Claude Code Sonnet 5
MFC after: 2 weeks
(cherry picked from commit 04fcf30961266cd77139b40774cb0d6ef6eb2be5)
rtld.c: avoid double-free on dso load failure in do_load_object()
The obj->path is assigned directly from the path argument, and
load_object() frees the path on do_load_object() failure. Do not free
it in obj_free() on the error path.
Reviewed by: markj
Sponsored by: The FreeBSD Foundation
MFC after: 1 week
Differential revision: https://reviews.freebsd.org/D60402