sshd(8): Fix sshd_config installation failure in 'make distribution'
The nrelease/Makefile runs etc's 'make distribution' with a temporary
MAKEOBJDIRPREFIX, so sshd/Makefile.etc cannot use the 'sshd_config'
built along with buildworld.
This fixes the failure introduced by my previous commit
d715c6bde30c404dde667d6642819526181ddc8b.
hammer(8): Fix check_period() to handle DST for daily period
Converting rounded local midnights with mktime() can leave only 23 hours
between consecutive dates when daylight saving time starts. Fix it by
using timegm() that ignores DST offsets.
Reported-by: pavalos
Bug: https://bugs.dragonflybsd.org/issues/2526
if_run: simplify the revision comparison
Revisions below 0x0201 are also below 0x0211. Remove the redundant
comparison without changing which revisions take this branch.
Note: FreeBSD's and OpenBSD's if_run.c still have this redundant
condition.
Reported-by: dcb
Bug: https://bugs.dragonflybsd.org/issues/3018
if_ath: use a single-bit mask for sync interrupt counters
Select bit i with 1U << i rather than i << i. The unsigned mask also
avoids signed left-shift overflow when selecting bit31.
Reported-by: dcb
Bug: https://bugs.dragonflybsd.org/issues/3022
libssh: Define SSH_TUN_COMPAT_AF to fix tun(4)-based tunnel feature
ssh supports to use tun(4) to create a layer-3 tunnel. Our tun(4) works
in the same way as FreeBSD's, so define SSH_TUN_COMPAT_AF and fix
if_tun.h inclusion to enable TUNSIFHEAD and AF header conversion.
However, this feature only works with logging as the root user, due to a
permission restriction in tun(4) that needs to be removed.
Also, this feature is disabled by default and requires manually setting
'PermitTunnel yes' in sshd_config.
nlist(3): Sync with FreeBSD
* Handle multiple symbol tables in ELF files.
(see FreeBSD commit 4617a6cb82a673b02257257c1f5f8a3c8d2bb943)
* Remove legacy a.out code.
* Update man page.
In particular, this fixes the forthcoming OpenSSH's using nlist(3) to
detect a required symbol in the PKCS#11 or FIDO/U2F providers (libraries).
sshd(8): Use sed to disable PasswordAuthentication in sshd_config
So we don't need to modifiy a vendor file for future upgrades.
Also remove the unused and duplicate files in libexec/sshd-session.
libssh: Fix crypt() misdetection to avoid custom auth passwd
The configure script failed to detect crypt() availability so xcrypt.c
chose DES_crypt() from OpenSSL/LibreSSL, which is incompatible.
Fix the misdetection by setting -DHAVE_CRYPT in CFLAGS. And this
reverts commit 4a1ac62bb5d7392fd6305e93850de57407b334e6.
make.conf: Delete the mislabeled ENABLE_SUID_SSH knob
This knob actually controlled the SUID bit of libexec/ssh-keysign, which
is needed for host-based authentication, and it actually requires the
SUID permission to work.
So just remove the ENABLE_SUID_SSH knob and always install ssh-keysign
with SUID. While there, explicitly set BINOWN=root and change BINMODE
to 4555, following both FreeBSD and OpenBSD.
Obtained-from: FreeBSD (commit 0041e47595fad8de5f6c3fd28522e4aa14eef32a)
socket: Implement getsockopt(SO_ACCEPTCONN)
SO_ACCEPTCONN is defined in <sys/socket.h>, but sogetopt() did not
handle it, so getsockopt(2) returned ENOPROTOOPT. FreeBSD, OpenBSD
and NetBSD all report it among the SOL_SOCKET options.
TigerVNC and similar servers probe this option to tell whether
their standard input is a connected socket or a listening socket
inherited from inetd "wait" mode. Without it, TigerVNC treats the
listening socket as connected, getpeername() fails with ENOTCONN,
and inetd respawns the server in a loop.
Add SO_ACCEPTCONN to the integer SOL_SOCKET option group, matching
FreeBSD (see commit dcb5fef5dbd4ca8488deff7a9074850d851bdc08).
Reported-by: Adrian Kieß
Bug: https://bugs.dragonflybsd.org/issues/3300
catopen(3): align returned errors with POSIX.1-2024
Return ENOENT instead of EFTYPE for invalid/empty names, non-existent
catalogue files, and bad catalogue headers. Require the complete header
and reject sizes that exceed mmap() limit.
Also save the errno in handling the open() failure.
Derived-from: FreeBSD (commit 1176390d2d2bbb1e207c840d1f7a66a6ac1096ff)
Reported-by: pmjdebruijn
Bug: https://bugs.dragonflybsd.org/issues/3393
catopen(3): Fix race condition
The current code uses a rwlock to protect the cached list, which
in turn holds a list of catentry objects, and increments reference
count while holding only read lock. Fix this by converting the
reference counter to use atomic operations.
Also improve the cleanups of memory allocations.
Obtained-from: FreeBSD (commit 4188ba1a3b65b4a55fc938b71d9091fafb57967d)
Reported-by: pmjdebruijn
Bug: https://bugs.dragonflybsd.org/issues/3393
drm: Balance dma-buf file references on get and fd export
dma_buf_get() drops its lookup reference before returning, but its callers
release the returned buffer with dma_buf_put(). Repeated imports can
therefore consume references owned by the descriptor and PRIME caches.
Retain an independent file reference before dropping the lookup reference.
dma_buf_fd() transfers the caller's reference to the new descriptor.
fsetfd() acquires another reference, so drop the caller's reference after
successful installation. Keep it on allocation failure.
FreeBSD's dma-buf implementation follows the same ownership rules: retain
the fget() reference on lookup and drop the extra reference taken by
finstall() after successful descriptor installation.
The comments were extracted from the patch bundle by servik and dillon:
https://apollo.backplane.com/DFlyMisc/drm98.patch
Reference: https://github.com/freebsd/drm-kmod/blob/f252a30f27d157d9c763cd408850775096a6263f/drivers/dma-buf/dma-buf.c#L498-L544
Bug: https://bugs.dragonflybsd.org/issues/3428
kdmsg: shut down the transport while waiting for reconnect workers
KILLRX and a wakeup on msg_ctl do not interrupt a reader blocked in
fp_read() on a quiet connection. Reconnect can then wait indefinitely
for the reader and writer to exit. HAMMER2's recluster ioctl holds the
root vnode during this wait, blocking other filesystem operations.
Shut down msg_fp before sleeping in the worker-wait loop. This wakes
blocked transport I/O and leaves the existing state cleanup and file
reference handling in place.
Keep the shutdown inside the loop: lksleep() releases msglk, so another
reconnect may replace the connection while this caller is asleep. A
one-time shutdown before the loop can leave this caller waiting on the
replacement workers.
Bug: https://bugs.dragonflybsd.org/issues/3434
drm: notify userspace of connector changes
Emit the DRM CONNECTOR HOTPLUG devctl event for the primary card. The
empty hotplug handler leaves libudev-devd clients unaware of connector
changes.
Use the event contract implemented in FreeBSD drm-kmod
drivers/gpu/drm/drm_sysfs.c.
Bug: https://bugs.dragonflybsd.org/issues/3440
bpf: add XOR and modulo instructions
libpcap can generate XOR and modulo instructions, but the kernel
interpreter and validator do not support them.
Add constant and register operands for both operations. Reject constant
modulo by zero and return zero for a register zero divisor, as for DIV.
Update the manual to match.
Patch-by: guy
Bug: https://bugs.dragonflybsd.org/issues/3387
drm: reject unload while core teardown is incomplete
Unloading drm.ko reaches ttm_exit(), which waits for device_released.
The callback which sets that flag is compiled out and device unregister
is a stub, so kldunload sleeps indefinitely while holding the linker
lock. The module event handler has already cleared the Linux task and
process cleanup callbacks by then.
DRM also retains worker threads and undrained RCU callouts, so removing
the TTM wait alone would not make unloading safe. Return EBUSY from
MOD_UNLOAD before changing callbacks or entering SYSUNINIT. Keep the
module usable until complete teardown is implemented.
Bug: https://bugs.dragonflybsd.org/issues/3443
vm: use normal COW inheritance for user-wired mappings
Forking an mlock()ed MAP_PRIVATE file mapping can panic with
"vm_fault_copy_wired: page missing". The wired-copy path expects the
page in the front object, but it may be in a backing object or have
been removed after the file was truncated.
Use normal COW inheritance for normal mappings with only a user wire.
The parent stays user-wired and the child remains unwired. The normal
fault path resolves backing pages and handles pager errors. Keep eager
copying for hard-wired and virtual-page-table mappings.
Reviewed-by: dillon
Bug: https://bugs.dragonflybsd.org/issues/3433
vm: allow writes to user-wired COW mappings
A later write to a MAP_PRIVATE mapping that was mlock()ed currently gets
KERN_PROTECTION_FAILURE from vm_map_lookup() because the entry is both
MAP_ENTRY_USER_WIRED and MAP_ENTRY_COW. The normal page-fault path does
not retry with VM_PROT_OVERRIDE_WRITE, so the write never completes and the
process receives SIGSEGV.
Fix the bug by removing the obsolete check so the normal copy-on-write
path runs.
vm_map_user_wiring() already created the shadow object before wiring the
entry, so a later COW is a normal copy into the process's own shadow. The
NEEDS_COPY block below still creates the shadow if it was not created at
wiring time.
Reviewed-by: dillon
Bug: https://bugs.dragonflybsd.org/issues/3431
pc64: balance wired PTE replacement and hard-busy wired refaults
pmap_enter drops the previous wired mapping, so account for the new
wired mapping even if the old PTE was wired. Otherwise protection
changes can underflow the pmap and vm_page wire counts.
Use vm_page_wire_quick for an already-wired same-page replacement, which
may be soft-busied. Skip fictitious pages, which have no physical wiring
count.
The old physical wire is released by pmap_removed_pte, and the old pmap
wire count is dropped separately in pmap_enter. Do not add another unwire.
Also reject FW_WIRED in vm_fault_bypass. An ordinary fault on a wired entry
may need to establish a new wire after its PTE was invalidated, so the
soft-busy shortcut cannot assume an old wired reference still exists.
A shared file mapped twice, mlock on one alias, MADV_INVAL on that alias
and a subsequent read otherwise panics in vm_page_wire. The normal
hard-busy fault path handles this case.
[6 lines not shown]
pc64: Support to apply AMD microcode update
* Implement ucode_load_bsp() that runs in hammer_time() immediately
before identify_cpu(), so the microcode update that's preloaded by the
boot loader can be applied before kernel detecting the CPU features.
The companion ucode_apply() function is called from initializecpu() on
each AP to picks up the microcode update.
Note: Only AMD CPUs are supported now.
* Add "cpu_microcode_load" and "cpu_microcode_name" variables to
loader.conf to load the CPU microcode and document them.
Co-authored-by: Aaron LI <aly at aaronly.me>
GitHub-PR: https://github.com/DragonFlyBSD/DragonFlyBSD/pull/55
boot: Support to preload firmware files
Support to preload the firmware files with the "firmware" type for the
firmware(9) subsystem to register, which is supported in the previous
commit.
Add the "./firmware" directory (which resolves to "/firmware" or
"/boot/firmware") to "module_path" variable for searching for the
firmware files.
Introduce the firmware="dir1/file1.bin dir2/file2.bin ..." variable to
the loader.conf for specifying the firmware files to be preloaded.
Co-authored-by: Aaron LI <aly at aaronly.me>
GitHub-PR: https://github.com/DragonFlyBSD/DragonFlyBSD/pull/55
kern: Support loading firmware from preloaded images or filesystem files
Extend the firmware loading mechanisms to support two more methods:
* preloaded images: load a firmware from an in-memory image preloaded by
the boot loader.
* firmware files: load a firmware by directly reading a firmware file
from the filesystem. A new sysctl variable "hw.firmware_path" and a
tunable of the same name is added to specify the search locations,
which defaults to "/usr/local/lib/firmware;/usr/lib/firmware".
The first method may be used to apply a CPU microcode update, and the
second method is mainly used by modern GPU/WiFi drivers to load the
required firmare directly from binary files (e.g., installed by a
firmware package).
Co-authored-by: Aaron LI <aly at aaronly.me>
GitHub-PR: https://github.com/DragonFlyBSD/DragonFlyBSD/pull/55
kern: Fix write-open "." or ".." to return EISDIR instead of EEXIST
Before the fix, opening "." or ".." for write would return EEXIST, which
was incorrect per the POSIX spec:
https://pubs.opengroup.org/onlinepubs/9699919799/functions/fopen.html
where one would expect one of EISDIR, EINVAL, EACCES.
For example:
```
% sh -c 'echo xxx > /tmp/.'
sh: cannot create /tmp/.: File exists
```
Fix the code to return EISDIR. Note that opening a directory other than
"." or ".." for write already returns EISDIR, e.g.,
[6 lines not shown]