jh7110_gpio: fdt_pinctrl interface
This provides GPIO programming/configuration at attach time based on the
device tree 'pinmux' descriptions.
Reference:
device-tree/Bindings/pinctrl/starfive,jh7110-sys-pinctrl.yaml
Reviewed by: Brian Scott <bscott at bunyatech.com.au>
Tested by: Brian Scott <bscott at bunyatech.com.au>
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59992
jh7110_gpio: handle preset high/low
Take action in the presence of the GPIO_PIN_PRESET_LOW/HIGH flags. This
part of the GPIO interface seems to be unused, but is trivially
implemented in our driver.
Reviewed by: Brian Scott <bscott at bunyatech.com.au>
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59991
cxgbe: Don't cache nsegs for KTLS requests
KTLS mbufs are initially parsed when they are first enqueued to
estimate the number of transmit descriptors needed so that the mbuf is
queued until enough descriptors are available. As part of this
estimate, the number of DSGL segments required by each KTLS mbuf is
calculated. Originally, the count for the first TLS record in a chain
was cached in the header mbuf to avoid having to recalculate it when
writing out the actual work request for the first TLS record, but this
requires duplicating fairly complex logic both when parsing and
transmitting requests.
Sponsored by: Chelsio Communications
cxgbe: Greatly simplify ktls_wr_len for T7
Don't try to fine-tune the WR size when estimating the work request
length when parsing the packet. Use a much simpler worst-case
estimate that only depends on a few fields in the mbuf metadata.
Sponsored by: Chelsio Communications
cxgbe tls: Send final data as immediate when trailing waste is trimmed
When a request needs to drop data from the crypto output (via a split
mode request), send the last 16 bytes of input as immediate data
instead of via DSGL. Requests with small payloads (16 bytes or fewer)
are now sent as immediate data only without any DSGL at all.
Sponsored by: Chelsio Communications
cxgbe: Various assertions for lengths in KTLS work requests
The construction of KTLS work requests is quite fragile, and these
assertions ensure that the constructed work requests match the length
fields encoded in some of the WR structures.
Sponsored by: Chelsio Communications
vendor/openssl-3.0: remove test/recipes
This directory contains a large number of files which are not currently
used by OpenSSL in the base system. Remove the files to reduce space
needed when doing version updates.
crypto/openssl: update generated files to match 3.5.9 release content
A new manpage has been added and some source files have been refactored
slightly, but by and large this is just a standard "version bump" update
(3.5.8 -> 3.5.9).
MFC after: 1 day
MFC with: b3a31d78
hwpmc tests: the sampling log file
Nine ATF cases covering PMC_OP_CONFIGURELOG and the descriptor-less
log operations: which descriptors are accepted, when a log is required
in the first place, and what the log operations do without one.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
Assisted-by: Claude Code (Opus 5)
(cherry picked from commit 8f0789bee7abb2fdb2ff6d625f254533a138e6e8)
hwpmc: add credential-transition exec tests (keep and drop)
The companion to pmc_exec_test.c, which covers only the drop side of a
credential-changing exec. Three cases cover what the drop must not
overreach into: an exec that changes no credentials keeps the PMC, a
set-id exec whose credential change the kernel suppresses for a traced
target keeps it too, and a set-id fexecve(2) drops it. They exercise
the permission logic FreeBSD-SA-26:56.hwpmc reworked, not the defect
it fixed.
All three pass on a debug (INVARIANTS+WITNESS) kernel. The two
keep-cases were each observed to fail on a kernel mutated to detach
unconditionally.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
Assisted-by: Claude Code (Opus 4.8)
(cherry picked from commit bea7b932b9eeaff39393347e0600b982fd859a92)
hwpmc tests: process-attachment lifecycle and ownership cases
Seven ATF cases covering process-attachment teardown orderings: a
target that exits before it is detached, the owner that exits before
its target (hwpmc's other unlink path), releasing a still-running
attached PMC, row exhaustion with out-of-order release, and
PMC_F_DESCENDANTS inheritance including a fork storm.
All pass on a debug (INVARIANTS+WITNESS) and a KASAN kernel.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
Assisted-by: Claude Code (Opus 5)
(cherry picked from commit d00da14532bc4408f3e66535c88276d00905af7c)
hwpmc: add tests for handle validation and the privilege boundaries
A pmc_id_t is a packed integer that the driver hands to userland and
accepts back on eleven operations, and nothing tested what happens when
one comes back forged, stale, or belonging to another process. Neither
was there a test that an unprivileged caller is refused the operations
that need a privilege.
The cases use a SOFT-class PMC wherever the counter itself does not
matter, so they run on a machine with no PMU.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
Assisted-by: Claude Code (Opus 5)
(cherry picked from commit 17fca802ded118102d04a7a0bbc0c076de18c4d8)
hwpmc tests: sort the list of test programs
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
(cherry picked from commit df537ff1520d82410328ebd6de529929dae620a6)
hwpmc: add regression tests for a credential-changing exec
This tests what FreeBSD-SA-26:56.hwpmc fixed.
exec_setgid_drops_pmc asserts the kernel takes a process-mode PMC away
when its target execs a set-gid program its owner is not entitled to
trace.
exec_setuid_no_double_unlink lets the target exec a set-uid program;
the teardown must unlink the process descriptor exactly once, and
completing at all is the assertion.
Both need an unprivileged owner and must not drop privileges themselves,
since p_candebug() would then refuse the target to its own owner; they
ask for require.user instead.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
[3 lines not shown]
crypto/openssl: update to 3.5.9
This is a security fix release addressing CVE High issues. Users are
strongly encouraged to update to this version.
See the release notes for the release for more details on what is being
fixed.
MFC after: 1 day
Merge commit 'af5a659dc1cd2b0a6994f2cee1956d0bf50bb1a2'
hwpmc tests: the sampling log file
Nine ATF cases covering PMC_OP_CONFIGURELOG and the descriptor-less
log operations: which descriptors are accepted, when a log is required
in the first place, and what the log operations do without one.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
Assisted-by: Claude Code (Opus 5)
(cherry picked from commit 8f0789bee7abb2fdb2ff6d625f254533a138e6e8)
hwpmc: add credential-transition exec tests (keep and drop)
The companion to pmc_exec_test.c, which covers only the drop side of a
credential-changing exec. Three cases cover what the drop must not
overreach into: an exec that changes no credentials keeps the PMC, a
set-id exec whose credential change the kernel suppresses for a traced
target keeps it too, and a set-id fexecve(2) drops it. They exercise
the permission logic FreeBSD-SA-26:56.hwpmc reworked, not the defect
it fixed.
All three pass on a debug (INVARIANTS+WITNESS) kernel. The two
keep-cases were each observed to fail on a kernel mutated to detach
unconditionally.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
Assisted-by: Claude Code (Opus 4.8)
(cherry picked from commit bea7b932b9eeaff39393347e0600b982fd859a92)
hwpmc tests: process-attachment lifecycle and ownership cases
Seven ATF cases covering process-attachment teardown orderings: a
target that exits before it is detached, the owner that exits before
its target (hwpmc's other unlink path), releasing a still-running
attached PMC, row exhaustion with out-of-order release, and
PMC_F_DESCENDANTS inheritance including a fork storm.
All pass on a debug (INVARIANTS+WITNESS) and a KASAN kernel.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
Assisted-by: Claude Code (Opus 5)
(cherry picked from commit d00da14532bc4408f3e66535c88276d00905af7c)
hwpmc: add regression tests for a credential-changing exec
This tests what FreeBSD-SA-26:56.hwpmc fixed.
exec_setgid_drops_pmc asserts the kernel takes a process-mode PMC away
when its target execs a set-gid program its owner is not entitled to
trace.
exec_setuid_no_double_unlink lets the target exec a set-uid program;
the teardown must unlink the process descriptor exactly once, and
completing at all is the assertion.
Both need an unprivileged owner and must not drop privileges themselves,
since p_candebug() would then refuse the target to its own owner; they
ask for require.user instead.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
[3 lines not shown]
hwpmc: add tests for handle validation and the privilege boundaries
A pmc_id_t is a packed integer that the driver hands to userland and
accepts back on eleven operations, and nothing tested what happens when
one comes back forged, stale, or belonging to another process. Neither
was there a test that an unprivileged caller is refused the operations
that need a privilege.
The cases use a SOFT-class PMC wherever the counter itself does not
matter, so they run on a machine with no PMU.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
Assisted-by: Claude Code (Opus 5)
(cherry picked from commit 17fca802ded118102d04a7a0bbc0c076de18c4d8)
hwpmc tests: sort the list of test programs
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
(cherry picked from commit df537ff1520d82410328ebd6de529929dae620a6)
libfetch: Plug connection leaks in FTP code
When setting up an FTP transfer, we need to dereference the cached
connection before returning after a failure.
MFC after: 1 week
Reviewed by: markj
Differential Revision: https://reviews.freebsd.org/D60017
libfetch: Plug leak in 304 Not Modified case
When we get a 304 Not Modified response, we need to go through the error
path to properly free any resources we've allocated instead of just
returning NULL directly.
MFC after: 1 week
Reviewed by: markj
Differential Revision: https://reviews.freebsd.org/D60016
libfetch: Correctly free redirect target
When processing a redirect, if we get multiple Location headers, we free
the previous one using free(new) instead of fetchFreeURL(new), which
leaks new->doc.
While here, rename new to loc since new is a reserved word in C++.
MFC after: 1 week
Reviewed by: markj
Differential Revision: https://reviews.freebsd.org/D60015
libfetch: Reject control characters in credentials
If a URL contains credentials, check that neither the user name nor the
password contain control characters which might confuse the server,
especially in the FTP case.
MFC after: 1 week
Reviewed by: markj
Differential Revision: https://reviews.freebsd.org/D60008
libfetch: Limit response line length
When reading an FTP or HTTP response, error out if we read 64 kB before
hitting a newline. Otherwise a runaway or malicious server could have
us spinning for quite a while allocating more and more memory before we
gave up or crashed.
MFC after: 1 week
Reviewed by: markj
Differential Revision: https://reviews.freebsd.org/D60007
Merge commit c52392a6f464 from llvm-project (by ShengYi Hung):
[Clang][ExprConst] Drop PRValue for nothrow new (#226753)
A user defined operator new can accept prvalue for nothrow. However, it
should not be a ConstExpr. Early returns by
isUsableAsGlobalAllocationFunctionInConstantEvaluation instead of doing
LValue evaluation.
Also, move CheckPlacement new logic into new OpCode. This decouples
checking from Interp.cpp to Compiler.cpp.
This fixes "Assertion failed: (E->isGLValue() ||
E->getType()->isFunctionType() || E->getType()->isVoidType() ||
isa<ObjCSelectorExpr>(E->IgnoreParens())), function EvaluateLValue" when
building the databases/mariadb123-server port.
MFC after: 1 week
acpi: Remove support for /dev/apmctl and apmd(8) compatibility
This simplifies the logic around ACKing suspend requests as there is
no longer the potential for multiple listeners, only devd and the
acknowledgement via acpiconf -k.
Reviewed by: imp
Differential Revision: https://reviews.freebsd.org/D59942
apm(8): Remove support for APM BIOS
Drop support for queries and commands that are not supported by ACPI's
/dev/apm interface. This includes dropping support for
enabling/disabling APM BIOS used by /etc/rc.d/apm.
Reviewed by: ziaee, imp
Differential Revision: https://reviews.freebsd.org/D59941