FreeBSD/src e3f5a83 — sbin/camcontrol fwdownload.c

camcontrol: Add Spectra Logic copyright

The majority of lines of code currently in fwdownload.c come from ken@'s
rework in commit 0e358df062dd ("Revamp camcontrol(8) fwdownload support
and add the opcodes subcommand.").  Add the appropriate copyright.

Approved by:    ken
DeltaFile
+1-0sbin/camcontrol/fwdownload.c
+1-01 files

FreeBSD/src fabb224 — sbin/camcontrol fwdownload.c

camcontrol: Add support for firmware uploading on HPE-branded drives

PR:             299059
(cherry picked from commit b30e67dc130ea8217e92e0b4c462f189e2268eba)
DeltaFile
+2-0sbin/camcontrol/fwdownload.c
+2-01 files

FreeBSD/src 3e01ebd — sys/riscv/riscv identcpu.c

riscv: support the new "riscv,isa-extensions" string-array.

Support the new "riscv,isa-extensions" property on RISC-V hart nodes
in FDT.

The "riscv,isa" property is deprecated, but cannot be removed because
doing so would break compatibility with existing DTBs. The new properties
replace it: "riscv,isa-base" describes the base ISA and
"riscv,isa-extensions" is a string array containing the supported ISA
extensions.

The "riscv,isa-extensions" property can be relatively large; on the
Spacemit K3 SoC it is approximately 300 bytes.

The FreeBSD OFW interface does not provide access to the underlying FDT
property data without copying it, and memory allocation is not possible
this early. So allocate a static buffer for the property instead.

Reuse the existing parse_riscv_isa() implementation to parse both the new

    [5 lines not shown]
DeltaFile
+80-26sys/riscv/riscv/identcpu.c
+80-261 files

FreeBSD/src 572cd66 — sys/dev/hwpmc hwpmc_ibs.c

hwpmc: handle delayed IBS NMIs on Zen 6

On Zen 6, an extra IBS NMI can arrive after later samples. Keep the
credit until the empty NMI arrives, and handle fetch and op samples when
both are ready.

Reviewed by:    mhorne
Fixes:  34b00ed041a4 ("hwpmc: fix IBS fetch and op NMI handling")
Fixes:  e51ef8ae490f ("hwpmc: Initial support for AMD IBS")
Sponsored by:   AMD
Differential Revision:  https://reviews.freebsd.org/D60367
DeltaFile
+15-6sys/dev/hwpmc/hwpmc_ibs.c
+15-61 files

FreeBSD/src 3e8ce38 — sys/sys pmc.h

pmc.h: bump PMC_VERSION_MINOR

Bump for the addition of PMC_OP_GETCAPS and the recently added Intel
CPUs.

Sponsored by:   The FreeBSD Foundation

(cherry picked from commit e39d3a6b32331437da6c13a4aeb67e5bcca67625)
DeltaFile
+1-1sys/sys/pmc.h
+1-11 files

FreeBSD/src 1cc380d — lib/libpmc libpmc.c, share/man/man4 hwpmc.4

libpmc: Query hwpmc for caps

This change allows for fine-grained capabilities per counter index. This
is particularly useful for AMD where subclasses are not exposed to the
general PMC code, but other architectures also have asymmetric behaviors
when it comes to specific counter indices.

A new PMC_OP_GETCAPS op is added to the hwpmc(4) ioctl interface.

Reviewed by:    mhorne
Sponsored by:   Netflix
Pull Request:   https://github.com/freebsd/freebsd-src/pull/2058

(cherry picked from commit 44a983d249d05d932b6cff333f130baf70febc22)
DeltaFile
+45-0sys/dev/hwpmc/hwpmc_mod.c
+9-10lib/libpmc/libpmc.c
+14-1sys/sys/pmc.h
+15-0sys/dev/hwpmc/hwpmc_amd.c
+4-0share/man/man4/hwpmc.4
+87-115 files

FreeBSD/src 04aa36c — sys/sys pmc.h

pmc.h: bump PMC_VERSION_MINOR

Bump for the addition of PMC_OP_GETCAPS and the recently added Intel
CPUs.

Sponsored by:   The FreeBSD Foundation

(cherry picked from commit e39d3a6b32331437da6c13a4aeb67e5bcca67625)
DeltaFile
+1-1sys/sys/pmc.h
+1-11 files

FreeBSD/src 7c5caf7 — lib/libpmc libpmc.c, share/man/man4 hwpmc.4

libpmc: Query hwpmc for caps

This change allows for fine-grained capabilities per counter index. This
is particularly useful for AMD where subclasses are not exposed to the
general PMC code, but other architectures also have asymmetric behaviors
when it comes to specific counter indices.

A new PMC_OP_GETCAPS op is added to the hwpmc(4) ioctl interface.

Reviewed by:    mhorne
Sponsored by:   Netflix
Pull Request:   https://github.com/freebsd/freebsd-src/pull/2058

(cherry picked from commit 44a983d249d05d932b6cff333f130baf70febc22)
DeltaFile
+45-0sys/dev/hwpmc/hwpmc_mod.c
+9-10lib/libpmc/libpmc.c
+14-1sys/sys/pmc.h
+15-0sys/dev/hwpmc/hwpmc_amd.c
+4-0share/man/man4/hwpmc.4
+87-115 files

FreeBSD/src de5689d — usr.sbin/bsnmpd/tools/bsnmptools bsnmpget.c, usr.sbin/bsnmpd/tools/libbsnmptools bsnmptools.c

bsnmp: validate the lower bound of error_index in responses

Check if the response's error_index is within a sane interval.
Otherwise, a rogue peer could crash us.

PR:             298222
Reported by:    Robert Morris
Reviewed by:    markj
Discussed with: secteam (markj)
MFC after:      2 weeks
Analyzed with:  Claude Code Opus 5

(cherry picked from commit 296e3fd54ca8972fa6696974097a2f2705f8dfc4)
DeltaFile
+6-2usr.sbin/bsnmpd/tools/bsnmptools/bsnmpget.c
+2-1usr.sbin/bsnmpd/tools/libbsnmptools/bsnmptools.c
+8-32 files

FreeBSD/src 0154a0d — usr.sbin/bsnmpd/tools/libbsnmptools bsnmptools.c

bsnmpget: initialise the suboption value in getsubopt1()

Otherwise, "bsnmpget -o verbose -I cut" crashes.

Reported by:    clang static analyzer
MFC after:      2 weeks

(cherry picked from commit 5d169b5365b1f5cdf8586efa9421feaa4bfe40af)
DeltaFile
+1-0usr.sbin/bsnmpd/tools/libbsnmptools/bsnmptools.c
+1-01 files

FreeBSD/src 2da1096 — sbin/ipfw dummynet.c

dummynet: do not overflow the points[ED_MAX_SAMPLES_NO] array

Otherwise, the following would segfault

dnctl pipe 1 config bw 1Mbit/s profile 1025points.txt

Found with:     Claude Code Sonnet 5
MFC after:      2 weeks

(cherry picked from commit 04fcf30961266cd77139b40774cb0d6ef6eb2be5)
DeltaFile
+3-0sbin/ipfw/dummynet.c
+3-01 files

FreeBSD/src 274236e — libexec/rtld-elf rtld.c

rtld.c: avoid double-free on dso load failure in do_load_object()

The obj->path is assigned directly from the path argument, and
load_object() frees the path on do_load_object() failure.  Do not free
it in obj_free() on the error path.

Reviewed by:    markj
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
Differential revision:  https://reviews.freebsd.org/D60402
DeltaFile
+1-0libexec/rtld-elf/rtld.c
+1-01 files

FreeBSD/src 4445d03 — stand/userboot/userboot libuserboot.h main.c

stand: userboot: improve userdisk error handling

Currently, userdisk_init() iterates through disks and
checks whether DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls
are available for the device. If either ioctl fails, userdisk_init()
returns ENXIO with ud_info only partially initialized.
devinit() records the failure, but loader_main() ignores
devinit()'s return value, so later code may access an
uninitialized entry.

In certain cases this code can still boot from a disk even if
userdisk_init() returns ENXIO, for example, when the first of
two disks is valid and the second errors out.

To address this issue while not breaking the current behavior, do
the following:

 - Zero-initialize the userdisk_info array and use a zero media size
   to mark disks that do not support the ioctls mentioned above or

    [14 lines not shown]
DeltaFile
+32-13stand/userboot/userboot/userboot_disk.c
+6-3stand/userboot/userboot/main.c
+1-0stand/userboot/userboot/libuserboot.h
+39-163 files

FreeBSD/src b3b90af — usr.sbin/bhyveload bhyveload.c

bhyveload: validate character disk devices

Currently, bhyveload(8) does not validate the supplied disk
image path. For example, it allows passing the /dev/null
device, which later fails in userboot because it does not
support DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls (see
userdisk_init() in stand/userboot/userboot/userboot_disk.c).

Fix that by checking DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls early.
A similar check already exists in bhyve(8). While here, make
cb_diskioctl() report the obtained sector size instead of
hard-coding 512.

Reviewed by:    markj
MFC after:      2 weeks
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59253

(cherry picked from commit 51234535ddd6ec0afe9dd4e3f34a31b92d5cdd78)
DeltaFile
+31-3usr.sbin/bhyveload/bhyveload.c
+31-31 files

FreeBSD/src 0c409a5 — contrib/llvm-project/clang/lib/Sema SemaTemplateInstantiateDecl.cpp

Merge commit c4ce37507537 from llvm-project (by ShengYi Hung):

  [Clang][Sema] Create LocalScope for Variable Template (#228280)

  A variable template should create its own LocalScope, as it should be
  opaque to other instantiations. This can occur when there are multiple
  instantiations in the same lexical scope. The correct behavior is that
  these instantiations should not be chained together.

  Assisted-by: Claude # Test ReleaseNote
  Fixes: #134148

This fixes an assertion while building the devel/glaze port.

PR:             276265
MFC after:      3 days

(cherry picked from commit fe9c7137871ee0b5c48d4c38b87d80f72e73379e)
DeltaFile
+4-0contrib/llvm-project/clang/lib/Sema/SemaTemplateInstantiateDecl.cpp
+4-01 files

FreeBSD/src fb099c1 — contrib/llvm-project/clang/lib/Sema SemaTemplateInstantiateDecl.cpp

Merge commit c4ce37507537 from llvm-project (by ShengYi Hung):

  [Clang][Sema] Create LocalScope for Variable Template (#228280)

  A variable template should create its own LocalScope, as it should be
  opaque to other instantiations. This can occur when there are multiple
  instantiations in the same lexical scope. The correct behavior is that
  these instantiations should not be chained together.

  Assisted-by: Claude # Test ReleaseNote
  Fixes: #134148

This fixes an assertion while building the devel/glaze port.

PR:             276265
MFC after:      3 days

(cherry picked from commit fe9c7137871ee0b5c48d4c38b87d80f72e73379e)
DeltaFile
+4-0contrib/llvm-project/clang/lib/Sema/SemaTemplateInstantiateDecl.cpp
+4-01 files

FreeBSD/src bceab8b — lib/clang llvm.build.mk, lib/clang/include/llvm/Config Targets.def Disassemblers.def

llvm: add LoongArch target support, not enabled by default

Note there is ongoing work to add LoongArch support to the base system,
but having target support in llvm is an essential component.

This must be explicitly enabled using WITH_LLVM_TARGET_LOONGARCH.

Reviewed by:    dim
MFC after:      1 week
Differential Revision: https://reviews.freebsd.org/D59899

(cherry picked from commit 2f49e40a684a4bffd8e368a6878384ec4f735ea8)
DeltaFile
+49-6lib/clang/libllvm/Makefile
+3-4share/man/man5/src.conf.5
+6-0lib/clang/llvm.build.mk
+0-3tools/build/options/WITH_LLVM_TARGET_BPF
+3-0lib/clang/include/llvm/Config/Targets.def
+3-0lib/clang/include/llvm/Config/Disassemblers.def
+64-136 files not shown
+74-1412 files

FreeBSD/src 8b75481 — lib/clang llvm.build.mk, lib/clang/include/llvm/Config Targets.def Disassemblers.def

llvm: add LoongArch target support, not enabled by default

Note there is ongoing work to add LoongArch support to the base system,
but having target support in llvm is an essential component.

This must be explicitly enabled using WITH_LLVM_TARGET_LOONGARCH.

Reviewed by:    dim
MFC after:      1 week
Differential Revision: https://reviews.freebsd.org/D59899

(cherry picked from commit 2f49e40a684a4bffd8e368a6878384ec4f735ea8)
DeltaFile
+49-6lib/clang/libllvm/Makefile
+3-4share/man/man5/src.conf.5
+6-0lib/clang/llvm.build.mk
+0-3tools/build/options/WITH_LLVM_TARGET_BPF
+3-0lib/clang/include/llvm/Config/Targets.def
+3-0lib/clang/include/llvm/Config/Disassemblers.def
+64-136 files not shown
+74-1412 files

FreeBSD/src 3108ab6 — contrib/llvm-project/clang/lib/CodeGen CGDebugInfo.cpp

Merge commit 80e8c0a59189 from llvm-project (by ShengYi Hung):

  [DebugInfo] Fill Column 0 if Line is not found (#227559)

  It is possible that user specified line 0 as the start of the line in C
  language (using `# 0`). However, it is rejected by the Lexer as we have
  no line but still carries column information. As a result, we fill
  column to 0 if we cannot find line.

  Assisted-by: Claude # Test
  Fixes: #56186

This fixes a fatal error when building the textproc/peg port.

PR:             264853
MFC after:      3 days

(cherry picked from commit 37c9eba1644b0f9e1b5d130ccff381122f48aebe)
DeltaFile
+5-2contrib/llvm-project/clang/lib/CodeGen/CGDebugInfo.cpp
+5-21 files

FreeBSD/src afc8c5f — contrib/llvm-project/clang/lib/CodeGen CGDebugInfo.cpp

Merge commit 80e8c0a59189 from llvm-project (by ShengYi Hung):

  [DebugInfo] Fill Column 0 if Line is not found (#227559)

  It is possible that user specified line 0 as the start of the line in C
  language (using `# 0`). However, it is rejected by the Lexer as we have
  no line but still carries column information. As a result, we fill
  column to 0 if we cannot find line.

  Assisted-by: Claude # Test
  Fixes: #56186

This fixes a fatal error when building the textproc/peg port.

PR:             264853
MFC after:      3 days

(cherry picked from commit 37c9eba1644b0f9e1b5d130ccff381122f48aebe)
DeltaFile
+5-2contrib/llvm-project/clang/lib/CodeGen/CGDebugInfo.cpp
+5-21 files

FreeBSD/src 0bccbb9 — sys/sys sched.h

sched.h: Fix a typo and remove an extra line

Fixes:          42490d5cd29d ("sched: New scheduler interface definition scheme")
Sponsored by:   The FreeBSD Foundation
DeltaFile
+1-2sys/sys/sched.h
+1-21 files

FreeBSD/src 42490d5 — sys/arm/arm mp_machdep.c, sys/arm64/arm64 mp_machdep.c

sched: New scheduler interface definition scheme

Define the scheduler interface once and for all (in 'sys/sys/sched.h')
and remove all code duplication related to it (function signatures, slot
names, dispatch, scheduler instance declaration), making it easier to
modify the interface or to add new schedulers.

This is implemented by defining the interface as X macros, which are
passed a macro (and additional arguments for it) that is "called" with
a variable number of arguments describing a single function of the
interface.  The convention used for a function's parameters is that each
parameter is represented with two macro arguments, the first one being
the type and the second one being the name.  Helper macros allow to
process arguments described in this convention in order to generate
a list of arguments for function definitions (currently, up to
4 function parameters).  The chosen convention eliminates the need for
any specific declaration of functions depending on their number of
arguments.


    [48 lines not shown]
DeltaFile
+347-168sys/sys/sched.h
+21-75sys/kern/sched_shim.c
+6-56sys/kern/sched_ule.c
+2-52sys/kern/sched_4bsd.c
+1-1sys/arm64/arm64/mp_machdep.c
+1-1sys/arm/arm/mp_machdep.c
+378-3535 files not shown
+383-35811 files

FreeBSD/src 35aeff7 — usr.sbin/bhyveload bhyveload.c

bhyveload: validate character disk devices

Currently, bhyveload(8) does not validate the supplied disk
image path. For example, it allows passing the /dev/null
device, which later fails in userboot because it does not
support DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls (see
userdisk_init() in stand/userboot/userboot/userboot_disk.c).

Fix that by checking DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls early.
A similar check already exists in bhyve(8). While here, make
cb_diskioctl() report the obtained sector size instead of
hard-coding 512.

Reviewed by:    markj
MFC after:      2 weeks
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59253

(cherry picked from commit 51234535ddd6ec0afe9dd4e3f34a31b92d5cdd78)
DeltaFile
+31-3usr.sbin/bhyveload/bhyveload.c
+31-31 files

FreeBSD/src b4e2c9a — lib/libcasper/libcasper zygote.c libcasper.c

libcasper: tolerate kernels without PD_NOWAITPID

Commit 1a296762b3d0 made libcasper pass PD_NOWAITPID to pdfork(2).
Kernels predating the flag (15.1 and earlier, since the flag first
ships in 15.2) reject it with EINVAL, which makes cap_init() and every
service fork fail when a newer world runs on an older kernel, for
example in a poudriere jail.

Add casper_pdfork(), which retries without the flag on EINVAL, and use
it at both pdfork(2) call sites.  The retry is safe because the kernel
validates pdfork flags before creating a child.  On such kernels the
zombie must still be reaped with waitpid(2), as before the flag was
introduced.

The fallback is compiled out once __FreeBSD_version reaches 1700000,
so it disappears from main when stable/16 branches while remaining in
the stable/15 and stable/16 branches that need it.

Reviewed by:    kib

    [3 lines not shown]
DeltaFile
+23-0lib/libcasper/libcasper/libcasper_impl.h
+1-1lib/libcasper/libcasper/zygote.c
+1-1lib/libcasper/libcasper/libcasper.c
+25-23 files

FreeBSD/src ea23918 — libexec/rtld-elf/i386 reloc.c

rtld-elf/i386: remove no longer true __unused args annotations

Fixes:  d45d7aea6197 ("i386 rtld: implement support for TLSDESC relocation")
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
DeltaFile
+1-1libexec/rtld-elf/i386/reloc.c
+1-11 files

FreeBSD/src 7c66df6 — sys/conf files

ufshci: build the ioctl file into the kernel

The passthrough ioctl went into the module build only. A kernel with
device ufshci then failed to link, because ufshci_ctrlr.c calls
ufshci_ioctl_construct() and ufshci_ioctl_destruct() and neither was
compiled in.

Add the file to sys/conf/files.

Fixes:          28fefc441e3b ("ufshci: add a control device node")
Sponsored by:   Samsung Electronics

(cherry picked from commit d435248a2196bc78f626850a7ae700aaeace1c13)
DeltaFile
+1-0sys/conf/files
+1-01 files

FreeBSD/src 26ca0a1 — sys/dev/ufshci ufshci_private.h ufshci_uic_cmd.c

ufshci: add a passthrough ioctl

This ioctl is for a port of ufs-utils:
https://github.com/SanDisk-Open-Source/ufs-utils

The driver only exposed a CAM SIM. Reading a descriptor, an attribute
or a flag needs a query request, and a UniPro attribute needs a DME
command. The driver built both only for its own setup, so userland
could reach neither.

Add two ioctls on the control node. UFSHCI_PASSTHROUGH_CMD sends a
UPIU the caller built, sizes the request from its transaction code,
and copies the response UPIU back. UFSHCI_PASSTHROUGH_UIC carries the
four attribute commands and refuses the rest, which can drop the link
or power the device off. It keeps the raw argument2 so the caller can
read the result code the device reported, not just a failure.

Validate the input and bound it by what the controller can map. The
descriptor has no request length, so the controller reads it from the

    [12 lines not shown]
DeltaFile
+236-0sys/dev/ufshci/ufshci_ioctl.c
+10-4sys/dev/ufshci/ufshci_ioctl.h
+8-2sys/dev/ufshci/ufshci.h
+3-2sys/dev/ufshci/ufshci_uic_cmd.c
+2-0sys/dev/ufshci/ufshci_private.h
+259-85 files

FreeBSD/src 4392fed — sys/dev/ufshci ufshci.h ufshci_private.h, sys/modules/ufshci Makefile

ufshci: add a control device node

The driver only exposed a CAM SIM. Userland had no way to reach the
device for anything that is not a SCSI command, so reading a descriptor
or an attribute was impossible.

Add /dev/ufshci%d as a root only node and the ioctl ABI header for it.
The node answers no ioctl yet. The header pulls in ufshci.h, which
declares bool only under _KERNEL, so include stdbool.h for userland the
way nvme.h already does.

Reviewed by:    imp (mentor)
Sponsored by:   Samsung Electronics
Differential Revision:  https://reviews.freebsd.org/D59558

(cherry picked from commit 28fefc441e3b701acc2888892a518774394255c7)
DeltaFile
+67-0sys/dev/ufshci/ufshci_ioctl.c
+54-0sys/dev/ufshci/ufshci_ioctl.h
+6-0sys/dev/ufshci/ufshci_private.h
+6-0sys/dev/ufshci/ufshci_ctrlr.c
+3-0sys/dev/ufshci/ufshci.h
+1-0sys/modules/ufshci/Makefile
+137-06 files

FreeBSD/src d815ad7 — etc/mtree BSD.include.dist, include Makefile

ufshci: install the ioctl header

The passthrough ioctl has a userland ABI header, but nothing installed
it. A program that wanted to use the ioctl had to copy the headers out
of the source tree by hand.

Install ufshci.h and ufshci_ioctl.h under /usr/include/dev/ufshci, the
way nvme installs nvme.h. The ioctl header pulls in ufshci.h, so both
go. Add the directory to the include mtree so installworld creates it.

Reviewed by:    imp (mentor)
Sponsored by:   Samsung Electronics
Differential Revision:  https://reviews.freebsd.org/D59560

(cherry picked from commit 8895b1348f3d21e2db16a06f31d555be0471e36d)
DeltaFile
+6-0include/Makefile
+2-0etc/mtree/BSD.include.dist
+8-02 files

FreeBSD/src ac1ad37 — sys/dev/ufshci ufshci_req_queue.c

ufshci: tell the controller how long the EHS is

The transfer request descriptor has a field for the total Extra Header
Segment length. The driver left it at zero. A request that carried an
EHS went out as the bare command UPIU, and the device answered a request
it had only seen part of.

Fill the field from the request UPIU header, which already carries the
same length. Every other path sets it to zero, so nothing else changes.
An EHS is the first thing that makes a request vary in size, so assert
that the request and the response still fit in the command descriptor.

Reviewed by:    imp (mentor)
Sponsored by:   Samsung Electronics
Differential Revision:  https://reviews.freebsd.org/D59557

(cherry picked from commit d3e5082ce4dcb154cbf50cba05d8f1dbbd55a5fc)
DeltaFile
+7-2sys/dev/ufshci/ufshci_req_queue.c
+7-21 files