OPNSense/src 7e3d386 — sys/dev/aq aq_ring.c aq_hw.c

sys: Import snapshot of Aquantia ACQ107 vendor driver

Obtained from https://github.com/Aquantia/aqtion-freebsd commit
c61d27b1d94af72c642deefa0595884481ea7377.

This is not using a vendor branch.  The formerly-upstream repo is
abandoned and I do not believe it will receive updates.  This initial
import serves as a snapshot of the vendor code, but from here we will
iterate on it in the tree as our own code.

Bug fixes, code cleanup, and build infrastructure will follow.

NetBSD and OpenBSD have derivatives of this driver (with additional
hardware support).  We can look to changes in those drivers, and the
Linux driver, to add support here.

Reviewed by:    adrian
Sponsored by:   The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D53813

    [2 lines not shown]
DeltaFile
+3,335-0sys/dev/aq/aq_hw_llh_internal.h
+1,986-0sys/dev/aq/aq_hw_llh.c
+1,329-0sys/dev/aq/aq_main.c
+1,176-0sys/dev/aq/aq_hw_llh.h
+907-0sys/dev/aq/aq_hw.c
+581-0sys/dev/aq/aq_ring.c
+9,314-012 files not shown
+12,109-018 files

OPNSense/src d41d432 — sys/conf files options

conf: remove trailing whitespace

This prevents unwanted change when saving files on IDEs (e.g. VSCode,
Zed)

Signed-off-by: Minsoo Choo <minsoo at minsoo.io>
Sponsored by:   The FreeBSD Foundation
Pull request:   https://github.com/freebsd/freebsd-src/pull/2152

(cherry picked from commit a338f5a0e7b1b5c22595aacbac44582ed5e0fe86)
DeltaFile
+5-5sys/conf/files.powerpc
+2-2sys/conf/options
+1-1sys/conf/files
+8-83 files

OPNSense/src 975fafe — sys/dev/bnxt/bnxt_en bnxt.h bnxt_mgmt.c

if_bnxt: Add support for HWRM passthrough with multiple DMA buffers

Added support for HWRM passthrough commands with multiple DMA buffers.

Also, changed the mgmt_lock to sleepable exclusive lock.

MFC after:      2 weeks
Reviewed by:    gallatin, ssaxena
Differential Revision: https://reviews.freebsd.org/D56686

(cherry picked from commit 9d87ca8b9f60bdec0bbc1733920df250a08beb0c)
DeltaFile
+57-39sys/dev/bnxt/bnxt_en/bnxt_mgmt.c
+3-0sys/dev/bnxt/bnxt_en/bnxt.h
+60-392 files

OPNSense/src b20cae1 — sys/conf files

bnxt_en: add bnxt_sriov.c to sys/conf/files for built-in kernel builds

The SR-IOV series added bnxt_sriov.c and listed it in sys/modules/bnxt/bnxt_en/Makefile,
but kernels that build bnxt into the image only compile sources named in sys/conf/files.
Add bnxt_sriov.c next to the other bnxt_en entries so built-in bnxt (including LINT)
links the SR-IOV implementation and avoids undefined symbols referenced from if_bnxt.c.

Fixes: f2f831b2c151 ("bnxt_en: Add core SR-IOV infrastructure")

MFC after:      1 month
Reviewed by:    ssaxena
Differential Revision: https://reviews.freebsd.org/D56688

(cherry picked from commit c21c63fb565f1bc7f9564dbf12068c864f8891d8)
DeltaFile
+1-0sys/conf/files
+1-01 files

OPNSense/src 6159a23 — sys/dev/bnxt/bnxt_en bnxt_log_data.h bnxt_coredump.h

if_bnxt: add few source files to version control

Commits- f85e66e655c9 ("if_bnxt/bnxt_re: add support for driver snapdump")
and 03839879a2dd ("if_bnxt: Add Firmware crashdump collection support")
missed to add few files under version control, those files are
added now:

sys/dev/bnxt/bnxt_en/bnxt_log.c
sys/dev/bnxt/bnxt_en/bnxt_log.h
sys/dev/bnxt/bnxt_en/bnxt_log_data.c
sys/dev/bnxt/bnxt_en/bnxt_log_data.h
sys/dev/bnxt/bnxt_en/bnxt_coredump.c
sys/dev/bnxt/bnxt_en/bnxt_coredump.h

bnxt_coredump.c entry is added in sys/conf/files as well.

Fixes: f85e66e655c9 ("if_bnxt/bnxt_re: add support for driver snapdump")
Fixes: 03839879a2dd ("if_bnxt: Add Firmware crashdump collection support")
(cherry picked from commit 9931dc5bf3831146c08a381c42ecbfcedb8ac7f1)
DeltaFile
+318-0sys/dev/bnxt/bnxt_en/bnxt_log.c
+186-0sys/dev/bnxt/bnxt_en/bnxt_coredump.c
+123-0sys/dev/bnxt/bnxt_en/bnxt_log.h
+78-0sys/dev/bnxt/bnxt_en/bnxt_log_data.c
+50-0sys/dev/bnxt/bnxt_en/bnxt_coredump.h
+35-0sys/dev/bnxt/bnxt_en/bnxt_log_data.h
+790-01 files not shown
+791-07 files

OPNSense/src be4b009 — sys/conf files

if_bnxt: add bnxt logger module files to sys/conf/files for built-in kernel builds

The bnxt snapdump and coredump support patches added bnxt_log/{_data}.c. and listed it in
sys/modules/bnxt/bnxt_en/Makefile, but missed to add these files in sys/conf/files.

Fix up the issue by adding bnxt_log/{_data}.c in sys/conf/files.

Fixes: f85e66e655c9 ("if_bnxt/bnxt_re: add support for driver snapdump")
(cherry picked from commit 03676cafa882c471a29436aae76c8751d451dd07)
DeltaFile
+2-0sys/conf/files
+2-01 files

HardenedBSD/src fe0be67 — contrib/expat Changes, contrib/expat/doc reference.html

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+790-0contrib/expat/tests/props_tests.c
+681-73contrib/expat/doc/reference.html
+413-154contrib/expat/lib/xmlparse.c
+56-220contrib/expat/lib/xmltok.c
+131-39contrib/expat/tests/basic_tests.c
+102-26contrib/expat/Changes
+2,173-51255 files not shown
+3,066-90261 files

HardenedBSD/src 76c6eb0 — lib/libsys stat.2, share/man/man4 Makefile

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+23-2lib/libsys/stat.2
+2-0sys/kern/vfs_vnops.c
+2-0sys/kern/vfs_syscalls.c
+1-0sys/sys/stat.h
+1-0share/man/man4/Makefile
+29-25 files

HardenedBSD/src 380114c — contrib/expat Changes, contrib/expat/doc reference.html

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+790-0contrib/expat/tests/props_tests.c
+681-73contrib/expat/doc/reference.html
+413-154contrib/expat/lib/xmlparse.c
+56-220contrib/expat/lib/xmltok.c
+131-39contrib/expat/tests/basic_tests.c
+102-26contrib/expat/Changes
+2,173-51255 files not shown
+3,066-90261 files

OPNSense/src f269083 — sys/dev/bnxt/bnxt_en bnxt_mgmt.h

if_bnxt: Fix the Unknown command 0x80000000 ioctl command error

With the latest niccli version, user will observe below
Unknown command command error when try to list the devices.

if_bnxt: Unknown command 0x80000000

Here, niccli is issuing command opcode as 0x80000000 but
driver is expecting 0x20000000 command opcode.

So, replaced _IOW(0,0,0) with the _IOC(IOC_IN,0,0,0).

Fixes: d53d7b4 ("bnxt: Fix up ioctl opcodes to support IOC_VOID along with IOC_IN")

MFC after:      2 weeks
Reviewed by:    gallatin, ssaxena
Differential Revision: https://reviews.freebsd.org/D56685

(cherry picked from commit 3987058a3a943c461c27dbebf10dad555b1bb2fa)
DeltaFile
+5-5sys/dev/bnxt/bnxt_en/bnxt_mgmt.h
+5-51 files

OPNSense/src e01b50d — sys/dev/bnxt/bnxt_en bnxt.h bnxt_mgmt.h, sys/modules/bnxt/bnxt_en Makefile

if_bnxt: Add Firmware crashdump collection support

This patch adds support for DDR-based firmware coredump memory handling.
It detects firmware coredump capability, allocates host DDR (DMA) memory
for crash dumps, and programs the firmware with the allocated memory during
attach. The allocated memory is released during driver detach.

Also, This patch adds functions to retrieve crash dump data from host DDR
memory. The implementation handles data copying from page tables and
checks dump availability. Main function bnxt_get_coredump() copies
stored crash dump data from DDR memory to the application buffer.

MFC after:      2 weeks
Reviewed by:    gallatin, ssaxena
Differential Revision: https://reviews.freebsd.org/D56684

(cherry picked from commit 03839879a2dd2505eab80b99211b0637ebdc9d32)
DeltaFile
+151-0sys/dev/bnxt/bnxt_en/bnxt_mgmt.c
+120-0sys/dev/bnxt/bnxt_en/bnxt_hwrm.c
+43-5sys/dev/bnxt/bnxt_en/if_bnxt.c
+28-1sys/dev/bnxt/bnxt_en/bnxt_mgmt.h
+19-1sys/dev/bnxt/bnxt_en/bnxt.h
+1-0sys/modules/bnxt/bnxt_en/Makefile
+362-76 files

HardenedBSD/src 29c9ef7 — lib/libsys stat.2, share/man/man4 Makefile

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+23-2lib/libsys/stat.2
+2-0sys/kern/vfs_vnops.c
+2-0sys/kern/vfs_syscalls.c
+1-0sys/sys/stat.h
+1-0share/man/man4/Makefile
+29-25 files

OPNSense/src e805dc0 — sys/dev/bnxt/bnxt_en hsi_struct_def.h, sys/dev/bnxt/bnxt_re qplib_fp.h qplib_fp.c

if_bnxt/bnxt_re: Update hsi headers

Update hsi headers

MFC after:      2 weeks
Reviewed by:    gallatin, ssaxena
Differential Revision: https://reviews.freebsd.org/D56683

(cherry picked from commit 308784bebe796cbdaccf7ef259caf7d87f874d02)
DeltaFile
+9,182-488sys/dev/bnxt/bnxt_en/hsi_struct_def.h
+0-2sys/dev/bnxt/bnxt_re/qplib_fp.c
+0-1sys/dev/bnxt/bnxt_re/qplib_fp.h
+9,182-4913 files

OPNSense/src 4793fbe — sys/dev/bnxt/bnxt_en bnxt_mgmt.h bnxt_ulp.c, sys/dev/bnxt/bnxt_re main.c

if_bnxt/bnxt_re: add support for driver snapdump

Add a logging module which helps to log and collect the driver`s
various events and state of device data structures.
APIs help modules like l2, RoCE etc. to register and
add logs into thg buffers. A segment header is added to the
data available in buffers.

The final log messages are arranged in following fashion

|SegHeader0|Data0|SegHeader1|Data1|
Logging module provides two different kinds of buffers:
a) A large contiguous memory chunk is used to form circular buffers.

Module need to provide a number of buffers while registering to
the logging module.Please note that, since memory for the
buffers remains with the module as long as it is registered, memory
footprints of the driver could be higher so the modules should
allocate an appropriate number of buffers. Also, due to limited

    [23 lines not shown]
DeltaFile
+335-43sys/dev/bnxt/bnxt_en/bnxt_mgmt.c
+79-3sys/dev/bnxt/bnxt_en/if_bnxt.c
+65-0sys/dev/bnxt/bnxt_re/main.c
+42-2sys/dev/bnxt/bnxt_en/bnxt.h
+35-0sys/dev/bnxt/bnxt_en/bnxt_ulp.c
+31-0sys/dev/bnxt/bnxt_en/bnxt_mgmt.h
+587-482 files not shown
+593-488 files

OPNSense/src fb81e1c — sys/dev/bnxt/bnxt_en bnxt_mgmt.c bnxt_mgmt.h

bnxt: Fix up ioctl opcodes to support IOC_VOID along with IOC_IN

The driver and applications currently use hard-coded numeric ioctl command
opcodes. These opcodes are interpreted as having the IOC_IN direction (data
copied from the user application to the driver), regardless of the actual packet
size. Consequently, when the packet size is zero and the direction is set to
IOC_IN, the kernel fails these ioctls if COMPAT is disabled.

While the driver and applications should ideally set the direction correctly—
for example, using IOC_VOID when the packet size is zero—the driver will now
be updated to define ioctl opcodes using the _IOC macro to support both
IOC_VOID and IOC_IN. This change ensures backward compatibility with older
applications that exclusively use IOC_IN.

Reviewed by: gallatin
Differential Revision: https://reviews.freebsd.org/D54601
MFC after: 3 days

(cherry picked from commit d53d7b466016408229491cfd2f8bdc742ff642e3)
DeltaFile
+8-3sys/dev/bnxt/bnxt_en/bnxt_mgmt.h
+6-3sys/dev/bnxt/bnxt_en/bnxt_mgmt.c
+14-62 files

OPNSense/src 47fd2ba — sys/dev/bnxt/bnxt_en if_bnxt.c bnxt_sriov.h

bnxt: Fix build / load error for bnxt(4) in kernels without PCI_IOV

This change removes the hard-forcing of  PCI_IOV and adds shims to
allow the driver to compile and work when the kernel is missing
PCI_IOV support.

Fixes: 7c450d1127c7
Reviewed by: sumit.saxena_broadcom.com
Differential Revision: https://reviews.freebsd.org/D57300
Sponsored by: Netflix

(cherry picked from commit 3118f1b99f23431235c202d9aadbe3d183bcc259)
DeltaFile
+39-0sys/dev/bnxt/bnxt_en/bnxt_sriov.c
+0-4sys/dev/bnxt/bnxt_en/bnxt_sriov.h
+0-2sys/dev/bnxt/bnxt_en/if_bnxt.c
+39-63 files

HardenedBSD/ports 600b06e — devel/redasm/files patch-LibREDasm_depends_capstone_CMakeLists.txt, sysutils/onefetch Makefile.crates distinfo

Merge branch 'freebsd/main' into hardenedbsd/main
DeltaFile
+167-175sysutils/onefetch/distinfo
+82-86sysutils/onefetch/Makefile.crates
+54-42www/pomerium/files/modules.txt
+43-43www/pomerium/distinfo
+24-24www/mod_evasive/Makefile
+48-0devel/redasm/files/patch-LibREDasm_depends_capstone_CMakeLists.txt
+418-37030 files not shown
+610-47836 files

OPNSense/src aace457 — sys/dev/bnxt/bnxt_en bnxt_sriov.h bnxt.h

bnxt_en: Address review comments for core SR-IOV support

This patch addresses the code review comments provided for:
https://reviews.freebsd.org/D56197

* P7 VF PCI ID: rename NETXTREME_E_P7_VF to E_P7_VF (P7/Thor2 line drops the
  Netxtreme name in product strings; other VF device IDs are unchanged).
* Use the return value of bnxt_vf_parse_schema() in bnxt_iov_vf_add() to
  decide when to call bnxt_set_vf_admin_mac(); make parse_schema() return
  bool and remove the has_admin_mac field.
* In bnxt_free_vf_resources(), fix indentation after dma_free_coherent() so
  the NULL assignment is clearly separate from the call.
* In bnxt_hwrm_func_vf_resource_free(), use first_vf_id/last_vf_id in the
  HWRM_FUNC_VF_RESC_FREE loop.

MFC after:      1 month
Reviewed by:    ssaxena
Differential Revision: https://reviews.freebsd.org/D56644

(cherry picked from commit 7c450d1127c7f08361f848c0ac57189910da8d3b)
DeltaFile
+16-15sys/dev/bnxt/bnxt_en/bnxt_sriov.c
+2-2sys/dev/bnxt/bnxt_en/if_bnxt.c
+1-1sys/dev/bnxt/bnxt_en/bnxt.h
+0-1sys/dev/bnxt/bnxt_en/bnxt_sriov.h
+19-194 files

OPNSense/src 2cf32cb — sys/dev/bnxt/bnxt_en bnxt_hwrm.h bnxt.h

bnxt_en: VF ring reservation, HWRM registration, and PF-only operation guards

VFs require separate HWRM commands for ring reservation and async
completion ring setup, so a common PF/VF dispatcher is introduced and
the async CR path is extended to handle both.  The PF must populate the
VF request forwarding bitmap during driver registration so the firmware
correctly forwards VF-originated HWRM commands.  VF reservation strategy
and min-guaranteed capability flags are now parsed for correct resource
partitioning, and PF-only operations (DCB, NVM, package version sysctl)
are guarded against VF invocation.

The short command buffer allocation is also reordered before the function
reset to ensure extended HWRM messages are available when needed, a
prerequisite uncovered during VF bring-up.

MFC after:      1 month
Reviewed by:    ssaxena
Differential Revision: https://reviews.freebsd.org/D56232

(cherry picked from commit c972c5acbac472a5dc797856f39f478862b6c6ea)
DeltaFile
+93-12sys/dev/bnxt/bnxt_en/bnxt_hwrm.c
+18-5sys/dev/bnxt/bnxt_en/if_bnxt.c
+5-4sys/dev/bnxt/bnxt_en/bnxt_sysctl.c
+3-0sys/dev/bnxt/bnxt_en/bnxt_dcb.c
+1-0sys/dev/bnxt/bnxt_en/bnxt_hwrm.h
+1-0sys/dev/bnxt/bnxt_en/bnxt.h
+121-216 files

FreeBSD/ports 2320512 — devel/glab pkg-plist Makefile

devel/glab: update to 1.121.0

Changes:        https://gitlab.com/gitlab-org/cli/-/releases
DeltaFile
+5-5devel/glab/distinfo
+2-2devel/glab/Makefile
+2-0devel/glab/pkg-plist
+9-73 files

OPNSense/src 2a64e77 — sys/dev/bnxt/bnxt_en if_bnxt.c bnxt_sriov.c

bnxt_en: Re-enable SR-IOV after firmware reset

When the firmware undergoes a hot-reset and the driver re-opens the
device, previously active Virtual Functions lose their resource
configuration.  bnxt_reenable_sriov() restores that configuration by
replaying bnxt_cfg_hw_sriov() with the saved resource parameters.

The function is called from bnxt_fw_reset_task() in the
BNXT_FW_RESET_STATE_OPENING state, guarded by #ifdef PCI_IOV.
Because bnxt_cfg_hw_sriov() is a no-op when active_vfs is zero the
call is safe on any PF regardless of whether VFs were ever created.

MFC after:      1 month
Reviewed by:    ssaxena
Differential Revision: https://reviews.freebsd.org/D56201

(cherry picked from commit 8743209350cb4b7db6d367df99da0a7ae3bc5d39)
DeltaFile
+10-0sys/dev/bnxt/bnxt_en/bnxt_sriov.c
+3-0sys/dev/bnxt/bnxt_en/if_bnxt.c
+13-02 files

OPNSense/src ca8e649 — sys/dev/bnxt/bnxt_en if_bnxt.c bnxt_sriov.c

bnxt_en: Add per-VF trust, spoof-check and promiscuous controls

Expose per-VF policy knobs via the FreeBSD sysctl tree and enforce
them at the data-path level.

Trust (dev.bnxt.<unit>.vfN.trusted):
  bnxt_set_vf_trust() sets/clears BNXT_VF_TRUST and sends
  HWRM_FUNC_CFG with FLAGS_TRUSTED_VF_ENABLE/DISABLE.
  bnxt_create_trusted_vf_sysctls() / bnxt_destroy_trusted_vf_sysctls()
  manage the sysctl lifetime with VF creation/teardown.

Spoof-check (dev.bnxt.<unit>.vfN.spoofchk):
  bnxt_set_vf_spoofchk() issues HWRM_FUNC_CFG with
  SRC_MAC_ADDR_CHECK_ENABLE/DISABLE.

Promiscuous gating:
  bnxt_is_trusted_vf() queries firmware via HWRM_FUNC_QCFG.
  bnxt_promisc_ok() returns false for untrusted VFs, preventing them
  from entering promiscuous mode.  bnxt_promisc_set() is updated to

    [11 lines not shown]
DeltaFile
+266-1sys/dev/bnxt/bnxt_en/bnxt_sriov.c
+4-2sys/dev/bnxt/bnxt_en/if_bnxt.c
+270-32 files

OPNSense/src a5dbde2 — sys/dev/bnxt/bnxt_en if_bnxt.c bnxt_sriov.c

bnxt_en: Add VF forwarded HWRM request handling

Enable the Physical Function to proxy HWRM commands issued by Virtual
Functions through the firmware forwarded-request mechanism.

When a VF issues a command that requires PF arbitration, the firmware
delivers a CMPL_BASE_TYPE_HWRM_FWD_REQ completion to the PF async ring.

* bnxt_process_async_msg() recognises CMPL_BASE_TYPE_HWRM_FWD_REQ,
  identifies the originating VF by its firmware function ID, sets the
  corresponding bit in pf.vf_event_bmap, and raises
  BNXT_HWRM_EXEC_FWD_REQ_SP_EVENT to schedule deferred processing.

* bnxt_sp_task() dispatches to bnxt_hwrm_exec_fwd_req(), which iterates
  over all pending VF bits and calls bnxt_vf_req_validate_snd() for each.

* bnxt_vf_req_validate_snd() inspects the encapsulated request type:
  HWRM_FUNC_VF_CFG (MAC change) is handled by bnxt_vf_configure_mac()
  which enforces trust/existing-MAC rules; HWRM_CFA_L2_FILTER_ALLOC is

    [10 lines not shown]
DeltaFile
+178-0sys/dev/bnxt/bnxt_en/bnxt_sriov.c
+22-0sys/dev/bnxt/bnxt_en/if_bnxt.c
+200-02 files

LLVM/project 3b3c65b — orc-rt/include/orc-rt/bedrock Session.h InProcessControllerAccess.h, orc-rt/lib/bedrock InProcessControllerAccess.cpp

[orc-rt] Mark ControllerAccess constructor as noexcept. (#229663)

ControllerAccess construction should not throw. Add the noexcept
specifier to the ControllerAccess constructor, in-tree subclass
constructors (InProcessControllerAccess and SocketSimpleRemoteCA) and to
the operations they depend upon.
DeltaFile
+4-4orc-rt/lib/bedrock/InProcessControllerAccess.cpp
+3-3orc-rt/include/orc-rt/bedrock/InProcessControllerAccess.h
+1-1orc-rt/lib/bedrock/sys/posix/sps/SimpleRemoteCAOverSocket.cpp
+1-1orc-rt/include/orc-rt/bedrock/Session.h
+9-94 files

OPNSense/src 9805693 — sys/dev/bnxt/bnxt_en bnxt.h bnxt_sriov.c

bnxt_en: Add VF load path and PF/VF context differentiation

Teach the driver to distinguish a Physical Function from a Virtual
Function at probe time and configure each appropriately.

* Introduce bnxt_is_vf_device() to identify all known VF device IDs
  (NetXtreme-C/E Gen1-3, Thor1/2, Hyper-V variants).  Add corresponding
  PVID entries to bnxt_vendor_info_array.

* Refactor the iflib shared context: rename bnxt_sctx_init to
  bnxt_sctx_template, add a Thor2-specific bnxt_sctx_template_p7, and
  build per-call PF/VF instances via bnxt_init_sctx_variants(); the VF
  instance carries IFLIB_IS_VF.  bnxt_register() selects the correct sctx.

* bnxt_attach_pre(): replace the hard-coded NPAR/VF switch with
  bnxt_set_flags_by_devid(); on a VF call bnxt_approve_mac() to request
  PF approval for the firmware-assigned MAC address.

* bnxt_hwrm_func_qcaps(): populate fw_fid and MAC for PF and VF contexts

    [14 lines not shown]
DeltaFile
+153-42sys/dev/bnxt/bnxt_en/if_bnxt.c
+77-29sys/dev/bnxt/bnxt_en/bnxt_hwrm.c
+62-0sys/dev/bnxt/bnxt_en/bnxt_sriov.c
+1-0sys/dev/bnxt/bnxt_en/bnxt.h
+293-714 files

OPNSense/src a60f97b — sys/dev/bnxt/bnxt_en bnxt_txrx.c

bnxt: set hardware checksum only if required

The test condition in the bnxt driver for TCP/UDP transmit hardware checksum
offload is invalid: only the TCP / UDP csum bits should be tested

Only the relevant ipi_csum_flags bits are now tested

Reviewed by: tuexen
Sponsored by: Stormshield
Differential Revision: https://reviews.freebsd.org/D53941

(cherry picked from commit 2e94e1631ef517f5495e25d7fa22c95f7dca0dc6)
DeltaFile
+16-6sys/dev/bnxt/bnxt_en/bnxt_txrx.c
+16-61 files

OPNSense/src 2816a65 — sys/dev/bnxt/bnxt_en if_bnxt.c bnxt.h, sys/modules/bnxt/bnxt_en Makefile

bnxt_en: Add core SR-IOV infrastructure

Introduce the foundational building blocks for SR-IOV Virtual Function
support on Broadcom NetXtreme-C/E adapters.

* Add bnxt_sriov.h: defines the extended bnxt_vf_info structure (per-VF
  firmware FID, MAC addresses, VLAN, flags, DMA command buffers, resource
  counts), the bnxt_resc_map helper, flag macros (BNXT_VF_TRUST,
  BNXT_VF_SPOOFCHK, etc.), and prototypes for all SR-IOV functions.

* Add bnxt_sriov.c: implements the SR-IOV attachment sequence
  (bnxt_sriov_attach), the iflib IOV callbacks (bnxt_iov_init,
  bnxt_iov_uninit, bnxt_iov_vf_add), VF resource allocation and
  firmware configuration helpers (bnxt_alloc_vf_resources,
  bnxt_cfg_hw_sriov, bnxt_hwrm_func_vf_resc_cfg, bnxt_hwrm_func_buf_rgtr,
  bnxt_hwrm_func_vf_resource_free), and the per-VF parameter helper.

* Extend bnxt.h: include bnxt_sriov.h; extend bnxt_pf_info with VF-
  tracking fields (vf array, firmware FID/MAC, resource-reservation

    [17 lines not shown]
DeltaFile
+469-0sys/dev/bnxt/bnxt_en/bnxt_sriov.c
+116-0sys/dev/bnxt/bnxt_en/bnxt_sriov.h
+29-26sys/dev/bnxt/bnxt_en/bnxt.h
+17-2sys/dev/bnxt/bnxt_en/if_bnxt.c
+1-0sys/modules/bnxt/bnxt_en/Makefile
+632-285 files

OPNSense/src fe43793 — sys/netinet6 nd6.c

nd6: Fix regeneration of temp addresses in detached state

When an on-link prefix becomes detached, the kernel keeps
generating new RFC 8981 temporary addresses for that prefix.
Fix it by ignoring the detached addresses in regen_tmpaddr().
While here, change its return type to bool.

PR:             298533
Discussed with: markj
MFC after:      3 days
Differential Revision:  https://reviews.freebsd.org/D60051

(cherry picked from commit 61f98a98250da7bd2c80c6d93d0032961d7f2fad)
DeltaFile
+18-12sys/netinet6/nd6.c
+18-121 files

OPNSense/src 087e254 — sys/netinet raw_ip.c

raw ip: clear sin_port on bind(2)

Application may set sin_port to some value.  Although this value is not
used by SOCK_RAW, it breaks a check that the address is available.  A
perfect fix would be not use sockaddrs for ifaddrs, but that would be a
bigger change.

PR:                     298366
Reviewed by:            pouria, bnovkov, adrian
Differential Revision:  https://reviews.freebsd.org/D59570
Fixes:                  948ad32ae1e0811f45e1d38f26636fefed5051f0

(cherry picked from commit 465942e8cc8160b21e1a3d5e45fa3ddbb852f6db)
DeltaFile
+1-1sys/netinet/raw_ip.c
+1-11 files

OPNSense/src 4bdad53 — sys/compat/linuxkpi/common/include/linux xarray.h

Fix statement with no effect in linuxkpi's xarray.h

When compiling the kernel with gcc 14, errors similar to the following
are emitted:

  sys/dev/cxgbe/iw_cxgbe/ev.c: In function 'c4iw_ev_handler':
  sys/compat/linuxkpi/common/include/linux/xarray.h:132:23: error: statement with no effect [-Werror=unused-value]
    132 |                 flags == 0; \
  sys/dev/cxgbe/iw_cxgbe/ev.c:274:17: note: in expansion of macro 'xa_unlock_irqrestore'
    274 |                 xa_unlock_irqrestore(&dev->cqs, flag);
        |                 ^~~~~~~~~~~~~~~~~~~~
  sys/compat/linuxkpi/common/include/linux/xarray.h:132:23: error: statement with no effect [-Werror=unused-value]
    132 |                 flags == 0; \
  sys/dev/cxgbe/iw_cxgbe/ev.c:283:17: note: in expansion of macro 'xa_unlock_irqrestore'
    283 |                 xa_unlock_irqrestore(&dev->cqs, flag);
        |                 ^~~~~~~~~~~~~~~~~~~~

It looks like the intent of the "flags == 0" statement was to make the
'flags' macro argument not unused, but it still results in a warning.

    [7 lines not shown]
DeltaFile
+1-1sys/compat/linuxkpi/common/include/linux/xarray.h
+1-11 files