sys/usb: validate USB endpoint and configuration lengths
Reject undersized endpoint descriptors before accessing wMaxPacketSize;
require wTotalLength to cover the configuration header and match the
allocated size after the full fetch.
Reported by Stuart Thomas
OK: deraadt@
Instead of redrawing the entire pane or scene when moving or redrawing a
pane, add damage rectangles and redraw only the affected spans. From
Michael Grant.
pf(4): pfr_insert_kentry() always needs PF_LOCK()
pfr_insert_kentry() inserts an IP address into a table. The table's
consistency is protected by PF_LOCK(). Unfortunately, PF_LOCK()
protection is missing for the code path executed on behalf
of the overload action in a pf rule. The overload action instructs
the firewall to insert the packet's source address into the table specified
as the overload action parameter. That particular code path in
pf_test() function runs without any lock protection.
The bug was introduced in revision 1.1074 and remained unnoticed
until now, when it was kindly reported by alf (a.schlichting () lemarit ! com>)
OK henning@, OK dlg@, OK jmatthew@
httpd: add header block/drop rules for request filtering
With this incoming requests can also be rejected based on the value of a
request header. Valid options are:
header block name value code [arg]
Close the connection with an error response when a
request header matches. Both name and value are shell-
style patterns and are matched case-insensitively against
the header name and value. code must be a valid HTTP
status code. For codes in the 3xx range, arg is required
and sent as the "Location" header. It must start with
"http://" or "https://". For all other codes, arg is
optional and used as the log message identifying the
rule.
header drop name value
Silently close the connection without sending a response
when a request header matches, using the same pattern
[10 lines not shown]
relayd: apply the header length limit to chunk size and trailer lines
Chunk size and trailer lines were not limited, so a line without line
ending could be buffered without bound. Limit each chunk size line and
the whole trailer to the configured header length and close the
session if they exceed it.
Spotted by Acts1631 (with diff), OK kirill@
relayd: apply the header length limit to unterminated lines
The limit was only checked for complete lines, so a header line
without line ending could be buffered without bound. Reject such
lines with 413 as soon as they exceed the limit.
Spotted by Acts1631 (with diff), OK kirill@
don't access the DE_CFG MSR when running on a hypervisor
Sebastian Albert encountered a KVM hosting provider where trying
to access the MSR resulted in a protection fault.
DE_CFG is not documented in AMD's 'AMD64 Architecture Programmer's Manual'.
ok brynet@ mlarkin@
sys/qwz: fix REO queue lifetime
Track REO completions before publication and wait for peer unmap,
deletion, and cache flushes before reusing queue DMA. Submission errors
and timeouts retain ownership; hardware failures block reuse until cold
cleanup. HAL error conventions and flush semantics follow ath12k;
tracking and the reuse barrier adapt qwz's retained pool.
sys/qwz: fix WCN7850 REO layout
Use WCN7850 REO tags and 64-bit TLV headers so commands and completions
use the correct offsets. Correct the status ring size and clear command
payloads before reuse.
The layout follows Linux ath12k's WCN7850 definitions.
OK: stsp@