sysutils/modules: Update to 5.7.0
- Use the Tcl interpreter selected by the ports framework
- Add missing runtime bash dependency and SHEBANG_FILES for envml
- Drop the unnecessary Sphinx build dependency
- Fix Portscout release detection
Release notes:
https://github.com/envmodules/modules/releases/tag/v5.7.0
Approved by: thierry (mentor, implicit)
cuse: Rename cuse_server_free() to cuse_server_dtor()
This name is clearer, given that this function is the cdevpriv
destructor callback.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
cuse: Assert the server refcount
Assert that the refcount does not underflow before decrementing it, and
that it really is zero by the time the server is freed.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Reviewed by: kib
Differential Revision: https://reviews.freebsd.org/D60043
cuse: Implement hot-unload
cuse_kern_uninit() can hang on destroy_dev(), because of threads
sleeping in CUSE_IOCTL_GET_COMMAND, so implement d_purge to wake them up
before calling destroy_dev(). Also do not allow threads to go back to
sleep if the is_closing flag has been set.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Reviewed by: kib
Differential Revision: https://reviews.freebsd.org/D60022
cuse: Use make_dev_s() to create client devices
make_dev_s() sets si_drv1 before the node is published in devfs, which
avoids a race where cuse_client_open() could see it as NULL. It also now
reports finer-grained errors on failure, instead of only ENOMEM.
While here, drop the NULL checks on kern_dev in cuse_server_free_dev(),
since a device is only added to the server's list once it has been
created.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Reviewed by: kib
Differential Revision: https://reviews.freebsd.org/D59874
cuse: Improve server cleanup
Move cuse_server_unref()'s device cleanup loop into a new
cuse_server_free_devs_locked(), and call it from cuse_server_free()
instead. The cdevpriv destructor now destroys the server's devices
before dropping its reference, which closes the clients using them, so
that the destructor is always the one that takes the last reference.
By the time cuse_server_unref() frees the server, the device list should
be empty, so assert this.
In cuse_kern_uninit(), delete the infinite loop which waits for all open
/dev/cuse instances to exit, and instead call destroy_dev() directly,
which runs their cdevpriv destructor.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Reviewed by: kib
Differential Revision: https://reviews.freebsd.org/D59872
cuse: Create /dev/cuse with MAKEDEV_CHECKNAME
Since we now use make_dev_credf(), make sure to fail kldload if it
returned NULL.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Reviewed by: kib
Differential Revision: https://reviews.freebsd.org/D59863
cuse: Actually use cuse_modevent()
We can call cuse_kern_init()/cuse_kern_uninit() here, rather than using
SYSINIT/SYSUNINIT.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Reviewed by: kib
Differential Revision: https://reviews.freebsd.org/D59862
cuse: Fix hang on readv(2) and writev(2) with multiple iovecs
uiomove() leaves an iovec it has just emptied as the current one, so
cuse_client_read() and cuse_client_write() picked it up again on the
next iteration, sent the server a zero-length command, and got zero
bytes back. That left the residual count unchanged, so the loop never
terminated and the call never returned.
Step past empty iovecs at the start of every iteration. This also covers
caller-supplied zero-length iovecs, which hung in the same way
PR: 293489
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Reviewed by: kib, markj
Differential Revision: https://reviews.freebsd.org/D59822
udp: Let jail policy rewrite the dstaddr for v6 sendto()s
When performing an unconnected sendto() on a v6 UDP socket in a classic
jail, we were not applying the usual policy of replacing the loopback
addr with the jail's primary IP. Compare with, e.g., udp6_connect() or
the IPv4 udp_send(). Fix that.
Approved by: so
Security: FreeBSD-SA-26:69.udp
Security: CVE-2026-101303
Reported by: Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li,
and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai
Reviewed by: bz, glebius
MFC after: 2 weeks
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59772
(cherry picked from commit fecb9537a83b6746bc731a7cb3bcf6a33df79562)
(cherry picked from commit f3b4b6b756e2ce9e012068c5c91492f757b5c548)
openssl: Fix CVE-2026-84782
This is a commit from upstream to fix:
dtls: reset init_off before retransmitting a message
Approved by: so
Security: FreeBSD-SA-26:68.openssl
Security: CVE-2026-84782
ktls: Fix an off-by-one bug in tls13_find_record_type()
If the entire plaintext is zero-filled, the backwards walk in
tls13_find_record_type() would return the offset of the last byte of the
TLS header. This causes an underflow when decrypting, resulting in a
null pointer dereference.
Fix the bug and add a regression test.
Approved by: so
Security: FreeBSD-SA-26:67.ktls
Security: CVE-2026-101302
Reviewed by: gallatin, jhb
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59767
(cherry picked from commit 7c5e457d3afdc7742ee24f0b5ee6e5e7aa00a6bd)
(cherry picked from commit 6d6a85c0be942d903a076d930c0ee67d150b0cfb)
ktls: Add a tunable to disable TLS receive
TLS receive offload is really only beneficial for in-kernel use cases
(such as NFS over TLS) or when using a hardware offload. In addition,
several recent SAs have involved the TLS receive path, but the only
current mitigation for those is to disable TLS offload entirely.
Approved by: so
Security: FreeBSD-SA-26:67.ktls
Reviewed by: ziaee, gallatin, markj
Relnotes: yes
Sponsored by: Netflix
Sponsored by: Chelsio Communications
Co-authored-by: John Baldwin <jhb at FreeBSD.org>
Differential Revision: https://reviews.freebsd.org/D57974
(cherry picked from commit 08cda4bcd43cfcb2c0b1abd29bc7cd30896727bc)
(cherry picked from commit 4d3f5d2ca43c7b00fe03276e85a51e215655bc6d)
unix: Preserve FD_RESOLVE_BENEATH when passing an fd
The FD_RESOLVE_BENEATH flag is supposed to be sticky. It's set when you
receive an fd from a different jail and preserved by openat(<dfd>) etc..
However, if you send the fd to yourself, the flag is stripped since
SCM_RIGHTS message don't preserve file descriptor flags.
Fix this by preserving those flags and checking for UF_RESOLVE_BENEATH
in restrict_rights().
Approved by: so
Security: FreeBSD-SA-26:66.jail
Security: CVE-2026-101306
Fixes: 350ba9672a7f ("unix: Set O_RESOLVE_BENEATH on fds transferred between jails")
Reviewed by: kib
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D58317
[2 lines not shown]
vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors
The FD_RESOLVE_BENEATH flag was intended to try to resolve bugzilla PR
262179 without entirely disallowing fd passing between jails. However,
one can use renameat() to bypass the restriction: upon receiving a
directory fd with FD_RESOLVE_BENEATH set, a jailed process can still
move its CWD or one of its ancestors to the directory, and just cd
out of its jail root.
So disallow renameat() when either the source or destination directory
fds has FD_RESOLVE_BENEATH set, like we do with fchdir() and fchroot()
to prevent similar escapes.
Approved by: so
Security: FreeBSD-SA-26:66.jail
Security: CVE-2026-101305
PR: 262179
Reported by: firk at cantconnect.ru
Reviewed by: olce, kib
Differential Revision: https://reviews.freebsd.org/D59875
fdescfs: Pass up additional metadata during lookups
When an fdescfs mount has the nodup option set, fdesc_lookup(/dev/fd/n)
returns the vnode referenced by file descriptor n, rather than returning
an fdescfs vnode. This meant that fd metadata attached to fd n was not
preserved when reopening the file, which is contrary to the expected
semantics for capsicum rights and the UF_RESOLVE_BENEATH fd flag. For
regular fdescfs mounts, this metadata is copied via dupfdopen().
Fix the problem by passing up this metadata through the nameidata
structure. Thus, if one opens /dev/fd/n, the returned fd will inherit
UF_RESOLVE_BENEATH and the capability rights of fd n. Add some
regression tests as well.
Approved by: so
Security: FreeBSD-SA-26:66.jail
Security: CVE-2026-101304
Reported by: Jan Bramkamp
Reviewed by: kib
[2 lines not shown]
file: Add filecaps_intersect() and cap_rights_intersect()
These routines let one compute the intersection of two sets of filecaps
or capability rights, just as filecaps_merge() and cap_rights_merge()
compute the union. This will be useful in an upcoming patch.
filecaps_intersect() is complex due to the need to merge sets of ioctls.
For now this is implemented with a dumb nested loop on the basis that
ioctl lists are typically short enough that this is fine. It may be
better to instead sort the two lists first and step through them
together.
No functional change intended.
Approved by: so
Security: FreeBSD-SA-26:66.jail
Reviewed by: kib
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59885
file: Add a helper function to check whether filecaps are full
In a couple of places we want to know whether someone has limited rights
on an fd. There, we want a predicate which determines whether the set
of rights is smaller than CAP_ALL, and whether there are explicit ioctl
or fcntl lists. Factor this out into a helper function, in preparation
for use elsewhere.
No functional change intended.
Approved by: so
Security: FreeBSD-SA-26:66.jail
Reviewed by: kib
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59884
kqueue: Fix a potential OOB access in kqueue_fork_copy_knote()
Here, fdp points to the new fdtable, copied from that of the parent
process. There is a window after the fdtable is copied, and before
kqueue_fork_copy_knote() runs, where a different thread in the parent
could have grown the parent's fdtable and registered a knote with ident
larger than the size of the child's fdtable. This race can lead to an
out-of-bounds read.
Add a bounds check for this case; skip the knote if it is referencing a
non-existent file.
Approved by: so
Security: FreeBSD-SA-26:65.kqueue
Security: CVE-2026-58100
Reviewed by: kib
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59916