[MLGO] Do not cap evictions when logging default advisor decisions (#230502)
Otherwise trace collection hits the Regs[CandidatePos].second assertion
on large functions (ones with many evictions)
NAS-144374 / 27.0.0 / Restrict HA node authentication to the heartbeat listener (by yocalebo) (#19975)
A connection was treated as coming from the other HA controller whenever
its source address was a heartbeat address and its source port was below
1024. Both of those are chosen by the client, so an adjacent attacker or
a local container could present them and be granted a full admin
session. The connection now must also have arrived on this node's own
heartbeat listener on port 6000, and the source address must differ from
the local address. Only the real peer controller can meet those
conditions. Nginx never proxies to that listener, so ordinary API and UI
traffic cannot match.
Original PR: https://github.com/truenas/middleware/pull/19973
---------
Co-authored-by: caleb <yocalebo at gmail.com>
(cherry picked from commit 5d8aa52195a74762f1ef9e1ac3aed02a291d5f06)
NAS-144374 / 27.0.0 / Restrict HA node authentication to the heartbeat listener (by yocalebo) (#19975)
A connection was treated as coming from the other HA controller whenever
its source address was a heartbeat address and its source port was below
1024. Both of those are chosen by the client, so an adjacent attacker or
a local container could present them and be granted a full admin
session. The connection now must also have arrived on this node's own
heartbeat listener on port 6000, and the source address must differ from
the local address. Only the real peer controller can meet those
conditions. Nginx never proxies to that listener, so ordinary API and UI
traffic cannot match.
Original PR: https://github.com/truenas/middleware/pull/19973
---------
Co-authored-by: caleb <yocalebo at gmail.com>
NAS-144374 / 28.0.0-BETA.1 / Restrict HA node authentication to the heartbeat listener (#19973)
A connection was treated as coming from the other HA controller whenever
its source address was a heartbeat address and its source port was below
1024. Both of those are chosen by the client, so an adjacent attacker or
a local container could present them and be granted a full admin
session. The connection now must also have arrived on this node's own
heartbeat listener on port 6000, and the source address must differ from
the local address. Only the real peer controller can meet those
conditions. Nginx never proxies to that listener, so ordinary API and UI
traffic cannot match.
[mlgo] Allow passing pre-emitc-ed models (#227941)
Support pre-lowering models and then passing them via the exact same mechanism - i.e. `LLVM_MLGO_MODELS`. The extension for the pre-generated ones needs to be `.inc`. High level, this just skips trying to run the mlir toolchain over those. Mixing `.inc` and `.mlir` is supported. The mlir toolchain isn't required unless `.mlir` are passed in the list.
As a result we can test the AOT case in regular builds. We just always append to the `LLVM_MLGO_MODELS`list the test models, with an "ugly" command line flag (a `_test` prefix). Each pass just lists the mlir test model and its corresponding .inc as part of the call to `MLGOLower`.
The bulk of the change is changing tests accordingly, and the addition of the same models we use in the mlir case, but EmitC-ed.
A subsequent change will remove listing the mlir models in llvm-zorg, since they now get auto-appended to the list when the mlir tools are specified. In the interim (after this change lands but before we change zorg) the ml-rel bot won't get red because we register the models under a dfferent name on zorg.
Issue #199007
[mlir][x86] Fix result tracing through loops (#230229)
Fixes the search for the write of a contraction result in the AMX
lowering when the result is passed through loop args.
The value was followed to the wrong loop result, which either found the
wrong write or crashed when the loop has few results.
Assisted-by: Claude
build: Emit a warning for build targets run as root
Build targets should generally be run as an unprivileged user. Even
though building as root is discouraged many users do so, so just start
with a warning.
Reviewed by: brooks
Differential Revision: https://reviews.freebsd.org/D50352
[mlir][ArithToLLVM] Fix index lowering for addui_extended (#223265)
Lowering `arith.addui_extended` with `index` operands fails because the
LLVM
result struct uses the unconverted sum type, even though the operands
have
already been converted.
Convert the sum type before constructing the LLVM result struct. Extend
the
existing index-bitwidth tests to cover `arith.addui_extended` at 32-,
64-, and
128-bit widths, reusing their RUN lines. Rename
`constant-index-bitwidth.mlir`
to `index-bitwidth.mlir` to reflect the broader coverage.
This preserves the operation's existing `index` support and uses the
converted
index width for the overflow intrinsic. Related discussion of `index`
[12 lines not shown]
[lldb][NativePDB] Only list a compile unit's own global variables (#230126)
`SymbolFileNativePDB::ParseVariablesForCompileUnit` adds every global
data symbol of the globals stream to whichever compile unit it's asked
about. The globals stream covers the whole PDB, so every compile unit
reports all globals of the program, including the CRT's, and target
variable list hundreds of them.
This patch only keeps the variables whose owning compile unit is the one
being parsed.
Requires:
- https://github.com/llvm/llvm-project/pull/230132
Fixes `TestTargetVar` with PDB debug info.
rdar://189620344
Makefile.inc1: Update comment wrt world build targets
The utility targets described by this comment are in fact related to
building (buildworld), not installing (which is included in
`make world`).
Reviewed by: brooks
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D56715
[lldb][NativePDB] Look up global variables by qualified name (#230134)
`SymbolFileNativePDB::FindGlobalVariables` looks the name up in an index
keyed by basename, so a qualified name such as `A::g_points` never
matches (`target variable A::g_points` fails with `"can't find global
variable"`).
This patch splits the name with
`CPlusPlusLanguage::ExtractContextAndIdentifier`, looks up the basename,
and when the name was qualified only keeps variables whose qualified
name contains it, as `SymbolFileDWARF::FindGlobalVariables` does.
Fixes `TestStaticVariables` with PDB debug info.
rdar://189618458
[lldb][NativePDB] Use the public symbol as the mangled name of globals (#230132)
`CreateGlobalVariable` passes `"::" + name` as the mangled name of every
global, and `Variable::GetName` prefers the mangled name, so every
global shows a leading `:: ((int) ::C::abc = 123, (&::ref = ...)`,
SBValue::GetName() returning "::i")`.
This patch uses the `S_PUB32` at the variable's address as the mangled
name when there is one, and no mangled name otherwise, which matches
what lldb shows for MSVC ABI globals with DWARF. NativePDB shell tests
are updated, and `TestFunctionRefs` now accepts both forms (the DWARF
output depends on the C++ ABI), which also removes its Windows XFAIL.
rdar://189620487
[BOLT][AArch64] Shrink large binary call relaxation test (#230526)
The test intermittently times out on the bolt-aarch64-ubuntu-nfc
builder, so I am making the input binary a tad smaller.
[offload][nfc] Pull OpenMP's InteropTbl out of PluginManager
PluginManager is shared with OpenACC, so the OpenMP interop table moves
to OmpPluginManager in libomptarget. The OpenMP PM is defined there, and
interop cleanup is registered from initRuntime.
[AMDGPU] Form VOPD dot2 pairs with a literal in src1
A V_DOT2 with a register in src0 and a literal in src1 is matched as if
commuted, and commuted when the VOPD pair is built. This recovers the
pairs lost once MachineCSE stopped leaving those literals in src0.
Co-Authored-By: Claude <noreply at anthropic.com>
x86: Add external retpoline thunk
This allows use of -mindirect-branch=thunk-extern, and is only a few
bytes of dead code if not used.
Reviewed by: kib
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D60524
makefs/zfs: count "." in the link count and size of dataset roots
The root directory of a dataset is populated from an fsnode that is the
"." entry of the staging directory, and its children are the siblings of
that node, so the loop that computes the link count and the size of the
directory (which expects "." among the children, as the nodes of the
other directories have) never counts it. The link count of the root of
every dataset is one less than it should be (1 for an empty dataset
instead of 2, 19 instead of 20 for a root with 18 subdirectories), and
so is its size.
fts(3) trusts the link count of the directories of ZFS when called with
FTS_NOSTAT and FTS_PHYSICAL: it stops looking for subdirectories once it
has seen as many as the link count says, and does not descend into the
ones it did not look at. As a result find(1), and rm(1) when it does
not need to stat the entries, silently skip directories of a pool made
by makefs. On a root filesystem made by makefs, find / does not list
/etc at all.
[11 lines not shown]