contrib/flex: Guard against int overflow in sko_push().
sko_sz is an int; doubling it unchecked could overflow and produce a
huge size_t for realloc(). Bail out if it would overflow.
It's sad that the upstream project hasn't had a new release since 2017,
so we decided to directly patch the contributed source.
Bug: #3426
contrib/flex: Guard against int overflow in sko_push().
sko_sz is an int; doubling it unchecked could overflow and produce a
huge size_t for realloc(). Bail out if it would overflow.
It's sad that the upstream project hasn't had a new release since 2017,
so we decided to directly patch the contributed source.
Bug: #3426
libc: reject a negative wchar_t in the UTF-8 encoder
_UTF8_wcrtomb() and _UTF8_wcrtombin() pick the four byte form with
"wc <= 0x10ffff". wchar_t is signed, so every negative value passes
that test and is encoded from its low bits: wcrtomb() of (wchar_t)-1
returns 4 and writes ff bf bf bf, and printf("%lc", -1) prints those
bytes instead of failing with EILSEQ as it does for 0x110000.
Add "wc >= 0 &&" to both tests, as FreeBSD's utf8.c has.
GitHub-PR: https://github.com/DragonFlyBSD/DragonFlyBSD/pull/57
FreeBSD: https://github.com/freebsd/freebsd-src/commit/8bb93485fb51aac423ec000aa292815cf50bb02c
libc: type a positional %F argument in __find_arguments()
When a format uses positional arguments, __find_arguments() walks it
first to learn the type of every argument, and lists the floating
point conversions as a A e E f g G. F is missing, so a double that
is only referred to through %F never gets a type, its slot in the
argument table stays unset, and the conversion reads whatever is
there:
printf("[%1$F]\n", -INFINITY); [0.000000]
printf("[%1$F]\n", 1.5); [0.000000]
printf("[%F]\n", 1.5); [1.500000]
The same format with %1$f, or with any other conversion of the same
argument, works because those give it a type. abseil's str_format
test compares against the C library and caught it.
Add F next to f in both __find_arguments() and __find_warguments().
GitHub-PR: https://github.com/DragonFlyBSD/DragonFlyBSD/pull/56
gpt(8): Fix "expand" command to update 'hdr_lba_end'
Update the usuable LBA by fixing the 'hdr_lba_end' after expanding.
Otherwise, the extended partition may extend beyond the usuable LBA.
Bugs: #3276, #3423
libc: reject a negative wchar_t in the UTF-8 encoder
_UTF8_wcrtomb() and _UTF8_wcrtombin() pick the four byte form with
"wc <= 0x10ffff". wchar_t is signed, so every negative value passes
that test and is encoded from its low bits: wcrtomb() of (wchar_t)-1
returns 4 and writes ff bf bf bf, and printf("%lc", -1) prints those
bytes instead of failing with EILSEQ as it does for 0x110000.
Add "wc >= 0 &&" to both tests, as FreeBSD's utf8.c has.
GitHub-PR: https://github.com/DragonFlyBSD/DragonFlyBSD/pull/57
FreeBSD: https://github.com/freebsd/freebsd-src/commit/8bb93485fb51aac423ec000aa292815cf50bb02c
libc: type a positional %F argument in __find_arguments()
When a format uses positional arguments, __find_arguments() walks it
first to learn the type of every argument, and lists the floating
point conversions as a A e E f g G. F is missing, so a double that
is only referred to through %F never gets a type, its slot in the
argument table stays unset, and the conversion reads whatever is
there:
printf("[%1$F]\n", -INFINITY); [0.000000]
printf("[%1$F]\n", 1.5); [0.000000]
printf("[%F]\n", 1.5); [1.500000]
The same format with %1$f, or with any other conversion of the same
argument, works because those give it a type. abseil's str_format
test compares against the C library and caught it.
Add F next to f in both __find_arguments() and __find_warguments().
GitHub-PR: https://github.com/DragonFlyBSD/DragonFlyBSD/pull/56
gpt(8): Add '-n' to "expand" to not auto extend the last partition
Add the '-n' option to the "expand" command to not auto extend the last
partition, so only the GPT itself is expanded.
Rewrite the "expand" command description in the man page to read more
clear and fluent.
Bug: #3276
gpt(8): Fix two bugs in "expand" command
* Commit f4b4c056f1 introduced a regression to the "expand" command that
the existing secondary GPT header and table were not relocated to the
new end of the expanded disk, leaving the primary GPT header pointing
at a non-existent secondary GPT. A second run would then creates it.
Fix the regression by always setting the 'map_start' of the existing
secondary GPT header and table to correctly relocate them.
It's actually a hack to directly modify the 'map_start' field instead
of deleting the map entry and then readding it, because there is no
map_delete(). However, this is okay because we don't call map_add()
afterwards.
* Update the usuable LBA by fixing the 'hdr_lba_end' after expanding.
This fixes the warning revealed by the previous commit.
Bugs: #3422, #3423
gpt(8): Add warnings about invalid partition LBA range
* Check the partition LBA range against the disk's usuable LBA range and
warn the invalid LBA ranges. This helps catch errors in GPT header
(e.g., the hdr_lba_end) and table.
* Add a verbose message printing the disk's usuable LBA range.
* Don't hide the CRC errors behind the verbose flag.
Bugs: #3276, #3423
cpdup: Don't pass an uninitialized pointer to getgroups(0, ...).
getmygroups() passed *gidlist to the size-only getgroups() query
before it was initialized. The list argument is ignored when the
size is 0, so pass NULL instead.
Bug: #3425
libevtr: Fix off-by-one in string namespace indexing.
evtr_dump_string() indexed evtr->strings[ns] although the array is
sized EVTR_NS_MAX - 1. The namespace IDs are EVTR_NS_PATH=1,
EVTR_NS_FUNC=2 and EVTR_NS_DSTR=3, so ns == 3 runs one past the array
and aliases the following union member (fmts): the dynamic-string
namespace and the format-string table then share a hashtable, and the
table allocated for that slot by evtr_open_write() leaks.
The read side already uses maps[ns - 1], so make the write side
consistent and only allocate/free the EVTR_NS_MAX - 1 entries.
Also reject ns == 0 in evtr_load_string(); the old check let it
through and maps[ns - 1] would read before the array on corrupt input.
Bug: #3424
cpdup: Don't pass an uninitialized pointer to getgroups(0, ...).
getmygroups() passed *gidlist to the size-only getgroups() query
before it was initialized. The list argument is ignored when the
size is 0, so pass NULL instead.
Bug: #3425
libevtr: Fix off-by-one in string namespace indexing.
evtr_dump_string() indexed evtr->strings[ns] although the array is
sized EVTR_NS_MAX - 1. The namespace IDs are EVTR_NS_PATH=1,
EVTR_NS_FUNC=2 and EVTR_NS_DSTR=3, so ns == 3 runs one past the array
and aliases the following union member (fmts): the dynamic-string
namespace and the format-string table then share a hashtable, and the
table allocated for that slot by evtr_open_write() leaks.
The read side already uses maps[ns - 1], so make the write side
consistent and only allocate/free the EVTR_NS_MAX - 1 entries.
Also reject ns == 0 in evtr_load_string(); the old check let it
through and maps[ns - 1] would read before the array on corrupt input.
Bug: #3424
libc: Remove obsolete CWARNFLAGS hack for gdtoa sources
The CWARNFLAGS was added to replace the warning flags with `-w` to
disable all warnings for the contributed gdtoa sources. It turned out
this hack is no longer needed, so just remove it.
initrd: Clean up rescue link by using more per-program libraries
Move those libraries that are only used by one program to be per-program
libraries, i.e., move them from global ${CRUNCH_LIBS} to be per-program
${CRUNCH_LIB_${P}}. This helps clean up the final link command and
reduce the probability of symbol conflicts and unexpected hiding.
See also the previous commit 4935cf62c0e4f0dc2b7ecd1fcab301589d1f789e.
initrd: Fix cryptsetup and tcplay rescue programs
My previous rescue.libcrypto merge commit
(250a8b4928d6d15bd3909848d72a595025c798b9) introduced a regression and
broke cryptsetup/tcplay. For example,
```
$ sudo /rescue/cryptsetup isLuks /dev/zero
ioctl deps call failed: No such file or directory
Cannot initialize device-mapper. Is dm kernel module loaded?
```
This was caused by that the libdm.a's symbols were hidden by
libdevmapper.a, which appeared before libdm.
To solve this conflict, separately link libdm.a for cryptsetup/tcplay,
and remove -ldm from the final link command, so there is no symbol
hiding problem.
[5 lines not shown]
initrd: Separate 'depend' and 'all' stages and chain with '&&'
Although the current makefile works, separate them to avoid races
between the 'depend' and 'all' stages to be future-proof.
bsd.crunchgen.mk: Fix crunchgen multiple exec issue in parallel mode
crunchgen(1) outputs three files:
OUTPUTS=${OUTMK} ${OUTC} ${PROG}.cache
In parallel mode (-jN), the ${OUTPUTS} target previously caused the
rules to be executed three times (if N>=3).
Fix this issue by introducing a cookie file and route the rules through
it to build the outputs.
Bump __DragonFly_version for merging libthread_xu into libc
There is no ABI/API change with this merge, but it's a general good idea
to bump the version.
Suggested-by: tuxillo
kernel - Fix lost wakeup in fifo_open()
* fifo_open() tests fi_readers, drops the fifo and vnode locks, then
tsleeps. A peer opening in that window bumps the counter and issues
its wakeup before the sleeper is queued, so open(2) blocks forever
with a peer already attached. Both paths are affected.
* Queue with tsleep_interlock() before releasing the locks and sleep
with PINTERLOCKED.
Reviewed-by: @dillon
libc: Merge libthread_xu into libc
* Build the pthread implementation in libthread_xu as part of libc.
Keep libthread_xu and libpthread as empty compatibility shims so
existing DT_NEEDED entries continue to load.
Initialize pthread state lazily from public pthread entry points,
so processes that never use pthread avoid startup work, signal
handlers, extra mappings, and rtld lock activation.
Preserve cold fork and cancellation-point syscall performance with a
direct __fork() path when no pthread work is needed and raw
read/write/readv/writev syscalls before pthread state exists. Repair
fork-child pid and tid state lazily.
Keep existing libc symbol versions, publish the newly linkable
pthread_create and pthread_cancel interfaces in DF606.0, and retain
the historical pthread names as compatibility ABI.
[51 lines not shown]