FreeBSD/src ba974fasys/kern uipc_shm.c

posixshm: Fix a double unlock in shm_partial_page_invalidate()

For some reason, shm_partial_page_invalidate() unlocks the object upon
an error, but its callers don't expect this.  Don't do any special error
handling.  Keep the subroutine anyway since the name is a bit clearer
than vm_page_grab_zero_partial().

While here, normalize the object pointer used for locking in
shm_deallocate().

Reviewed by:    kib
Fixes:          454bc887f250 ("uipc_shm: Implements fspacectl(2) support")
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59877
DeltaFile
+2-7sys/kern/uipc_shm.c
+2-71 files

FreeBSD/src 7c5e457sys/kern uipc_ktls.c, tests/sys/kern ktls_test.c

ktls: Fix an off-by-one bug in tls13_find_record_type()

If the entire plaintext is zero-filled, the backwards walk in
tls13_find_record_type() would return the offset of the last byte of the
TLS header.  This causes an underflow when decrypting, resulting in a
null pointer dereference.

Fix the bug and add a regression test.

Reviewed by:    gallatin, jhb
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59767
DeltaFile
+66-5tests/sys/kern/ktls_test.c
+2-2sys/kern/uipc_ktls.c
+68-72 files

FreeBSD/src 14c7492usr.bin/sdiff sdiff.c sdiff.1

sdiff.1: Document exit status and --help

MFC after:      3 days
Approved by:    bnovkov (mentor)
Sponsored by:   fme AG
Differential Revision:  https://reviews.freebsd.org/D59927
DeltaFile
+22-1usr.bin/sdiff/sdiff.1
+1-0usr.bin/sdiff/sdiff.c
+23-12 files

FreeBSD/src 30ed27fsys/powerpc/powerpc elf64_machdep.c

sys/powerpc/powerpc/elf64_machdep.c: enable ASLR on ELFv2

Turns out that ever since introducing ELFv2 support, it was missing
ASLR, it was only used for ELFv1 processes.

Reviewed by:    jhibbits (via IRC #powerpc64)
MFC after:      1 week
DeltaFile
+1-1sys/powerpc/powerpc/elf64_machdep.c
+1-11 files

FreeBSD/src 044cae0tests/sys/netpfil/ipfw Makefile unmapped.sh

ipfw tests: cover layer-2 filtering of unmapped mbufs

Test that ipfw's layer-2 hook copes with unmapped mbufs, on the pass
and on the deny path.

Reviewed by:    glebius
Assisted-by:    Claude Code (Fable 5, Opus 5)
Differential Revision:  https://reviews.freebsd.org/D59390
DeltaFile
+189-0tests/sys/netpfil/ipfw/unmapped.sh
+2-1tests/sys/netpfil/ipfw/Makefile
+191-12 files

FreeBSD/src 3897678sys/kern vfs_init.c

vfs_register: prevent kernel crash

vfs_register hashes the filesystem name and uses it for sysctl oids.
A filesystem name which hashes to 0 crashes in sysctl_register_oid().

Map 0 to 1 to prevent the kernel crash.

This can be tested with "udf2" as the filesystem name.

MFC after:      1 month
MFC to:         stable/15 stable/14
Reviewed by:    kib
Differential Revision: https://reviews.freebsd.org/D59839
DeltaFile
+2-0sys/kern/vfs_init.c
+2-01 files

FreeBSD/src 7399be2. UPDATING, sbin/nvmecontrol nvmecontrol.8

misc: Avoid use of Unicode closing single quote

The Unicode closing single quotation mark is classified as a homoglyph
and can trip automated code quality checks in downstream CI pipelines or
cause code review UIs to refuse to display a file.  If used as an
apostrophe, use the ASCII single quote instead.  If used as a closing
single quote, replace with double quotes or no quotes at all.

Sponsored by:   Klara, Inc.
Sponsored by:   NetApp, Inc.
Reviewed by:    ziaee, obiwac, olce
Differential Revision:  https://reviews.freebsd.org/D59911
DeltaFile
+7-7sys/net/sff8472.h
+3-3sys/x86/x86/mp_x86.c
+2-2sys/dev/oce/oce_hw.h
+2-2sbin/nvmecontrol/nvmecontrol.8
+1-1usr.sbin/moused/moused/moused.conf.5
+1-1UPDATING
+16-1610 files not shown
+26-2616 files

FreeBSD/src 72bb9ebbin/pwd pwd.c

pwd(1): De-obfuscate, style(9)

In getcwd_logical(), test for a '.' or '..' component in one of the most
straightforward and intelligible ways possible.

In particular, this removes a superfluous re-test of the the component's
first character being '.' when the first one did not pass and, more
importantly, prevents the second test from relying on a side-effect in
the first.

While here, for better clarity, replace the loop that searches for '/'
with a simple call to strchrnul().

Add high-level comments about what is going on.

While here, test explicitly that pointed 'char' values are not 0 ('\0')
(style(9)).

While here, separate the successive steps of getcwd_logical() with blank

    [9 lines not shown]
DeltaFile
+14-7bin/pwd/pwd.c
+14-71 files

FreeBSD/src 9d08596sys/powerpc/aim mmu_radix.c

powerpc/radix: fix double page offset in mmu_radix_sync_icache()

mmu_radix_sync_icache() adds the offset of va within its page to the
physical address it gets from mmu_radix_extract_locked().  That address
already includes the offset - the extract routines return the physical
address of the byte, not of the frame - so the offset is counted twice
and __syncicache() is handed frame + 2 * offset.

The hash MMU counterpart, moea64_sync_icache(), has to add the offset
because PVO_PADDR() yields only the frame.  Here the addition is wrong.

Fixes:  6f0b2a235a13 ("powerpc/pmap: Add pmap_sync_icache() for radix pmap")
Reviewed by:    jhibbits
MFC after:      1 week
Differential Revision:  https://reviews.freebsd.org/D59870
DeltaFile
+1-3sys/powerpc/aim/mmu_radix.c
+1-31 files

FreeBSD/src 26e90d2sys/compat/linuxkpi/common/include/linux xarray.h

Fix statement with no effect in linuxkpi's xarray.h

When compiling the kernel with gcc 14, errors similar to the following
are emitted:

  sys/dev/cxgbe/iw_cxgbe/ev.c: In function 'c4iw_ev_handler':
  sys/compat/linuxkpi/common/include/linux/xarray.h:132:23: error: statement with no effect [-Werror=unused-value]
    132 |                 flags == 0; \
  sys/dev/cxgbe/iw_cxgbe/ev.c:274:17: note: in expansion of macro 'xa_unlock_irqrestore'
    274 |                 xa_unlock_irqrestore(&dev->cqs, flag);
        |                 ^~~~~~~~~~~~~~~~~~~~
  sys/compat/linuxkpi/common/include/linux/xarray.h:132:23: error: statement with no effect [-Werror=unused-value]
    132 |                 flags == 0; \
  sys/dev/cxgbe/iw_cxgbe/ev.c:283:17: note: in expansion of macro 'xa_unlock_irqrestore'
    283 |                 xa_unlock_irqrestore(&dev->cqs, flag);
        |                 ^~~~~~~~~~~~~~~~~~~~

It looks like the intent of the "flags == 0" statement was to make the
'flags' macro argument not unused, but it still results in a warning.

    [7 lines not shown]
DeltaFile
+1-1sys/compat/linuxkpi/common/include/linux/xarray.h
+1-11 files

FreeBSD/src 82d6bd1sys/compat/linuxkpi/common/include/linux xarray.h

Fix statement with no effect in linuxkpi's xarray.h

When compiling the kernel with gcc 14, errors similar to the following
are emitted:

  sys/dev/cxgbe/iw_cxgbe/ev.c: In function 'c4iw_ev_handler':
  sys/compat/linuxkpi/common/include/linux/xarray.h:132:23: error: statement with no effect [-Werror=unused-value]
    132 |                 flags == 0; \
  sys/dev/cxgbe/iw_cxgbe/ev.c:274:17: note: in expansion of macro 'xa_unlock_irqrestore'
    274 |                 xa_unlock_irqrestore(&dev->cqs, flag);
        |                 ^~~~~~~~~~~~~~~~~~~~
  sys/compat/linuxkpi/common/include/linux/xarray.h:132:23: error: statement with no effect [-Werror=unused-value]
    132 |                 flags == 0; \
  sys/dev/cxgbe/iw_cxgbe/ev.c:283:17: note: in expansion of macro 'xa_unlock_irqrestore'
    283 |                 xa_unlock_irqrestore(&dev->cqs, flag);
        |                 ^~~~~~~~~~~~~~~~~~~~

It looks like the intent of the "flags == 0" statement was to make the
'flags' macro argument not unused, but it still results in a warning.

    [7 lines not shown]
DeltaFile
+1-1sys/compat/linuxkpi/common/include/linux/xarray.h
+1-11 files

FreeBSD/src c7b6798contrib/expat Makefile.in, contrib/expat/lib internal.h xmltok.c

contrib/expat: import expat 2.8.5

Changes: https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/Changes

Security:       CVE-2026-93990
MFC after:      3 days
DeltaFile
+349-5contrib/expat/tests/basic_tests.c
+100-123contrib/expat/lib/xmlparse.c
+139-64contrib/expat/lib/xmltok.c
+67-100contrib/expat/lib/internal.h
+105-56contrib/expat/Makefile.in
+157-0contrib/expat/tests/hash_tests.c
+917-34854 files not shown
+1,614-85960 files

FreeBSD/src 5d169b5usr.sbin/bsnmpd/tools/libbsnmptools bsnmptools.c

bsnmpget: initialise the suboption value in getsubopt1()

Otherwise, "bsnmpget -o verbose -I cut" crashes.

Reported by:    clang static analyzer
MFC after:      2 weeks
DeltaFile
+1-0usr.sbin/bsnmpd/tools/libbsnmptools/bsnmptools.c
+1-01 files

FreeBSD/src 74cab6elib/libbsdconf bsdconf.h bsdconf.3, usr.sbin/sysconf sysconf_scan.c

libbsdconf: parse from a bounded in-memory buffer

Copy the descriptor into a buffer of at most 64 MiB (raise it with
BSDCONF_MAX_BYTES) and tokenize with bsdconf_scan(), the walker
bsdconf_put() already uses.  Input above the cap fails with EFBIG.
Bump libbsdconf to 1.2.0 and sysconf(8) to 2.0.

Suggested by:   fuz
Reviewed by:    fuz
Differential Revision:  https://reviews.freebsd.org/D59751
DeltaFile
+39-420lib/libbsdconf/bsdconf.c
+133-0lib/libbsdconf/bsdconf_stmt.c
+44-18lib/libbsdconf/bsdconf.3
+23-0usr.sbin/sysconf/tests/sysconf_test.sh
+0-16usr.sbin/sysconf/sysconf_scan.c
+9-3lib/libbsdconf/bsdconf.h
+248-4576 files not shown
+267-46312 files

FreeBSD/src 7b7ef79share/misc bsd-family-tree

bsd-family-tree: add NetBSD 10.2
DeltaFile
+23-20share/misc/bsd-family-tree
+23-201 files

FreeBSD/src 296e3fdusr.sbin/bsnmpd/tools/bsnmptools bsnmpget.c, usr.sbin/bsnmpd/tools/libbsnmptools bsnmptools.c

bsnmp: validate the lower bound of error_index in responses

Check if the response's error_index is within a sane interval.
Otherwise, a rogue peer could crash us.

PR:             298222
Reported by:    Robert Morris
Reviewed by:    markj
Discussed with: secteam (markj)
MFC after:      2 weeks
Analyzed with:  Claude Code Opus 5
DeltaFile
+6-2usr.sbin/bsnmpd/tools/bsnmptools/bsnmpget.c
+2-1usr.sbin/bsnmpd/tools/libbsnmptools/bsnmptools.c
+8-32 files

FreeBSD/src b94772dsys/dev/clk/spacemit k1_clk.c k1_apmu.c

clk: Fix a few typos in the spacemit CCU driver

Fixes:  dcb10e3add17
Reported by:    Bruno Banelli <bruno.banelli at sartura.hr> (p_idx typo)
DeltaFile
+3-3sys/dev/clk/spacemit/k1_apmu.c
+2-2sys/dev/clk/spacemit/k1_clk.c
+5-52 files

FreeBSD/src 3d03013sys/net/route fib_algo.c

route/fib_algo: Respect immediate_sync in fd_ref_nhop

Now fd_ref_nhop() returns zero for cross family routes,
Do not schedule nhop references and try to rebuild it immediately
for connected and static routes.

PR:     298733
Fixes:  633438224304 ("route/fib_algo: Fix nexthop index ...")
DeltaFile
+4-2sys/net/route/fib_algo.c
+4-21 files

FreeBSD/src 50eae68sys/net/route fib_algo.c

route/fib_algo: Remove redundant zeroing of fd_af

fd is allocated with M_ZERO and fd_num_af never decreases.
Therefore, no need for zeroing nhaf_count and nhaf_base here.

Fixes:  633438224304 ("route/fib_algo: Fix nexthop index ...")
DeltaFile
+0-2sys/net/route/fib_algo.c
+0-21 files

FreeBSD/src ab636e4usr.sbin/jail config.c

jail(8): Preserve const qualifier on strchr(3) results

Reviewed by:    fuz, dteske
Approved by:    fuz (mentor), dteske (mentor)
MFC after:      1 week
Differential Revision:  https://reviews.freebsd.org/D59876
DeltaFile
+3-3usr.sbin/jail/config.c
+3-31 files

FreeBSD/src 26b3ff1sys/compat/linux linux.c

Ignore LINUX_POLLREMOVE

This matches upstream behaviour since Linux's demangle_poll()
silently discards POLLREMOVE from the requested events.

Reviewed by:    emaste
Sponsored by:   Sippy Software, Inc.
Differential Revision:  https://reviews.freebsd.org/D59914
MFC after:      1 week
PR:             297467
DeltaFile
+4-2sys/compat/linux/linux.c
+4-21 files

FreeBSD/src 0cb85c5share/man/man4 aq.4

aq.4: Remove experimental note

I added the text when this driver was merely an import of
https://github.com/Aquantia/aqtion-freebsd with patches from ports applied.
nprice@ resolved issues and added support for newer cards and the note is
no longer applicable.

Reviewed by:    adrian
Sponsored by:   The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59909
DeltaFile
+0-4share/man/man4/aq.4
+0-41 files

FreeBSD/src 32137c4sys/arm/allwinner a10_codec.c, sys/arm/broadcom/bcm2835 bcm2835_audio.c

sound: Retire the version constants

They exist only to fill in MODULE_DEPEND() and MODULE_VERSION(), and
every consumer passed the same value for all three, so the version
range never did anything. Use 1, like the rest of the tree does.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib, emaste
Differential Revision:  https://reviews.freebsd.org/D59873
DeltaFile
+0-6sys/dev/sound/pcm/sound.h
+1-1sys/dev/firewire/fwisound.c
+1-1sys/arm/freescale/vybrid/vf_sai.c
+1-1sys/arm/freescale/imx/imx6_ssi.c
+1-1sys/arm/broadcom/bcm2835/bcm2835_audio.c
+1-1sys/arm/allwinner/a10_codec.c
+5-1133 files not shown
+38-4439 files

FreeBSD/src 57d542clib/libc/tests/stdlib test-search.h bsearch_test.c

libc: Preserve const qualifier on bsearch(3) results in tests

Reviewed by:    dteske, fuz
Approved by:    dteske (mentor), fuz (mentor)
MFC after:      1 week
Differential Revision:  https://reviews.freebsd.org/D59611

(cherry picked from commit 3caa8d2c58b2787e4c4c64d9ac1831dadd7b0b47)
DeltaFile
+1-1lib/libc/tests/stdlib/test-search.h
+1-1lib/libc/tests/stdlib/bsearch_test.c
+1-1lib/libc/tests/stdlib/bsearch_s_test.c
+1-1lib/libc/tests/stdlib/bsearch_b_test.c
+4-44 files

FreeBSD/src b169b80lib/libc/aarch64/string strpbrk.c, lib/libc/amd64/string strpbrk.c

libc: Parenthesise qualifier-preserving function definitions

Required to prevent function-like macros with the same name from
being expanded in the definitions once they become active in a
later C mode.  Without the parentheses, the macro would rewrite
the declarator, and the file would consequently fail to compile.
This style is already used for similar cases such as mempcpy().

Reviewed by:    fuz
Approved by:    fuz (mentor)
MFC after:      1 week
Differential Revision:  https://reviews.freebsd.org/D59600

(cherry picked from commit c389738f21c09931cd88a84a357be514b5c60030)
DeltaFile
+3-3lib/libc/stdlib/bsearch.c
+1-1lib/libc/string/memrchr.c
+1-1lib/libc/string/memmem.c
+1-1lib/libc/string/memchr.c
+1-1lib/libc/amd64/string/strpbrk.c
+1-1lib/libc/aarch64/string/strpbrk.c
+8-812 files not shown
+20-2018 files

FreeBSD/src 91973f5lib/libc/stdlib bsearch.c bsearch.3, lib/libc/tests/stdlib test-search.h bsearch_b_test.c

libc: Implement bsearch_s(), document bsearch_b(), and add unit tests

- Implement bsearch_s() as per §K.3.6.3.2 in C23, first specified
  in C11.  It behaves identically to bsearch(), except the callback
  is called with a third argument, context, which is passed through
  from the caller, and it also performs runtime constraint checking
  on its arguments.
- Document bsearch_b(), bsearch_s(), and add history section
- Add rudimentary unit tests for bsearch(), bsearch_b(), and bsearch_s()

Reviewed by:    dteske, fuz
Approved by:    dteske (mentor), fuz (mentor)
MFC after:      1 month
Differential Revision:  https://reviews.freebsd.org/D58876

(cherry picked from commit d59c7ea2701fe7b73b32eef49a7c712ef38de5a0)
DeltaFile
+134-0lib/libc/tests/stdlib/bsearch_s_test.c
+103-5lib/libc/stdlib/bsearch.3
+92-0lib/libc/tests/stdlib/bsearch_test.c
+58-0lib/libc/tests/stdlib/bsearch_b_test.c
+51-0lib/libc/tests/stdlib/test-search.h
+38-0lib/libc/stdlib/bsearch.c
+476-55 files not shown
+503-611 files

FreeBSD/src 8b66c7b. MAINTAINERS, .github CODEOWNERS

MAINTAINERS: Add myself to routing subsystem

Add myself as the maintainer for routing subsystem
in the GitHub CODEOWNERS and MAINTAINERS files.
DeltaFile
+1-0MAINTAINERS
+1-0.github/CODEOWNERS
+2-02 files

FreeBSD/src f120213lib/libc/stdlib bsearch.3, lib/libc/string memchr.3 strchr.3

libc: Use C23 pseudo-types in qualifier-preserving man page synopses

Reviewed by:    fuz
Approved by:    fuz (mentor)
MFC after:      1 month
Pull Request:   https://github.com/freebsd/freebsd-src/pull/2288

(cherry picked from commit f9dfe9b8deee0054949eda22f5c0aae8ba3d432d)
DeltaFile
+10-10lib/libc/string/wmemchr.3
+8-8lib/libc/string/strstr.3
+8-8lib/libc/string/string.3
+6-6lib/libc/string/strchr.3
+4-4lib/libc/string/memchr.3
+2-2lib/libc/stdlib/bsearch.3
+38-383 files not shown
+44-449 files

FreeBSD/src 4bdbd68include wchar.h string.h, lib/libc/string string.3 strstr.3

libc: Implement qualifier-preserving standard library functions

Several standard library functions are specified to return an unqualified
pointer while accepting a pointer to a potentially const-qualified object.
N3020 addresses this behaviour, discarding qualifiers due to incompatible
pointer types, by introducing qualifier-preserving macros for the affected
set of standard library functions.

Add `__qualsel()` helper to `<sys/cdefs.h>`, implemented using the generic
selection, and define qualifier-preserving macros for that set of functions
in `<string.h>`, `<wchar.h>`, and `<stdlib.h>`.

Macros are gated on `_STDC_VERSION__ >= 202311L && !__cplusplus`, therefore
there is no behavioural change for earlier C modes or C++ translation units.
The kernel is likewise unaffected, as it does not include userland headers.

As function-like macros, they are transparent except at a call site where
the address-of operator is applied, the macro is suppressed via `#undef`,
or the identifier appears in parenthesised form; all of which cause the

    [8 lines not shown]
DeltaFile
+46-10lib/libc/string/wmemchr.3
+28-0include/string.h
+17-4lib/libc/string/strstr.3
+21-0sys/sys/cdefs.h
+11-5lib/libc/string/string.3
+14-0include/wchar.h
+137-197 files not shown
+187-3313 files

FreeBSD/src 627c766sys/dev/ntb/test ntb_tool.c

ntb_tool: Bound memory window option strings

parse_mw_buf() copies option names from privileged sysctl input into
eight-byte stack buffers.  Unbounded %s conversions permit option tokens
longer than seven bytes to write past those buffers before the parser
validates them.

Limit each conversion to seven characters, leaving space for the
terminating NUL.

Signed-off-by: Yudi Yang <yudi.yang at rice.edu>

Fixes:          96f556f5044a ("NTB Tool: Test driver for NTB hardware drivers.")
Reviewed by:    markj
MFC after:      1 week

(cherry picked from commit 602d1b994a22949fff7e4a87cb6e54d6fbad13b6)
DeltaFile
+1-1sys/dev/ntb/test/ntb_tool.c
+1-11 files