x11-themes/ghostbsd-icons: Update to 26.10.0
Install the G logo icons into hicolor at stage time instead of copying
them in pkg-install, so pkg tracks them. Only the size directories and
scalable are copied so ghostbsd's index.theme does not replace hicolor's.
Drop the upstream icon-theme.cache files and depend on
gtk-update-icon-cache, whose pkg trigger regenerates the caches.
Update the network page for the current NetworkMgr net_api
NetworkMgr's net_api now appends the full caps string, the security
type and an enterprise flag to each access point entry. The page read
ssid_info[-1] as the caps string, so it got the enterprise boolean and
crashed on any WPA or WEP password. It now reads ssid_info[7].
Port the networkmgr connection handling. WPA-Enterprise networks open
an EAP authentication dialog and are written with write_eap_config.
Open networks get a quoted SSID in wpa_supplicant.conf, and every write
to that file uses a 077 umask. Secured access points show the -secure
signal icons.
Bring up any WiFi card that is down before the first scan, and add a
Rescan button next to the wired status when a WiFi card is detected.
The rescan runs in a thread and updates the status and access point
list on the GTK main loop.
Connecting to a known SSID no longer blocks the UI, status updates
[8 lines not shown]
Bring the wireless interface up on first setup
On a fresh system wpa_supplicant has no saved network. driver_bsd
downs the interface while it initializes and only raises it again to
scan or associate, which it never does without an enabled network.
rc does not run ifconfig up on WPA interfaces either, so the card
stayed down and wpa_supplicant sat in INTERFACE_DISABLED, refusing
scan requests with FAIL-BUSY.
When setup-nic.py declares the wlan in rc.conf for the first time, it
now marks the interface up after pccard_ether starts it, so
wpa_supplicant sees the interface enabled and starts scanning.
Run the installer in a MATE session instead of marco and feh
The .xinitrc named a wallpaper, so the installer's background was a path
in this repo rather than whatever GhostBSD ships, and it had drifted from
the mountain-sunset.jpg ghostbsd-mate-settings sets as the default.
mate-session now supplies the theme, fonts, cursor and wallpaper.
The session is trimmed to the window manager, since the panel and the
file manager have nothing to offer during an installation. Both keys are
root's own dconf, so the live user's session keeps the full desktop.
show-desktop-icons has to be off: with no caja to draw the desktop,
mate-settings-daemon paints the wallpaper, and only right away when that
key is false.
The empty autostart directory keeps tray applets and update notifiers
out. install-station is still the client X waits on, so quitting it hands
the boot back to rc.
Build and release the tray icon instead of toggling its visibility
Hiding a Gtk.StatusIcon and showing it again re-embeds it in the panel.
That leaves the notification area with a stale embedded window and makes
GTK thaw a GdkWindow it never froze, which prints:
Gdk-CRITICAL: gdk_window_thaw_toplevel_updates: assertion
'window->update_and_descendants_freeze_count > 0' failed
TrayIcon now builds the status icon when it is shown and releases it when
it is hidden, through its own set_visible(). Releasing the icon is what
removes it from the panel, since Gtk.StatusIcon has no destroy() and
run_dispose() leaves the embedded window in place.
tray_icon() is gone and the call sites go through Data.system_tray
directly. left_click() is no longer a classmethod because it has to hide
the icon through the new path rather than through the status icon the
signal hands it. The empty menu built in the constructor is removed,
nm_menu() replaces it on every right click.
hwpmc tests: the sampling log file
Nine ATF cases covering PMC_OP_CONFIGURELOG and the descriptor-less
log operations: which descriptors are accepted, when a log is required
in the first place, and what the log operations do without one.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
Assisted-by: Claude Code (Opus 5)
(cherry picked from commit 8f0789bee7abb2fdb2ff6d625f254533a138e6e8)
hwpmc: add credential-transition exec tests (keep and drop)
The companion to pmc_exec_test.c, which covers only the drop side of a
credential-changing exec. Three cases cover what the drop must not
overreach into: an exec that changes no credentials keeps the PMC, a
set-id exec whose credential change the kernel suppresses for a traced
target keeps it too, and a set-id fexecve(2) drops it. They exercise
the permission logic FreeBSD-SA-26:56.hwpmc reworked, not the defect
it fixed.
All three pass on a debug (INVARIANTS+WITNESS) kernel. The two
keep-cases were each observed to fail on a kernel mutated to detach
unconditionally.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
Assisted-by: Claude Code (Opus 4.8)
(cherry picked from commit bea7b932b9eeaff39393347e0600b982fd859a92)
hwpmc tests: process-attachment lifecycle and ownership cases
Seven ATF cases covering process-attachment teardown orderings: a
target that exits before it is detached, the owner that exits before
its target (hwpmc's other unlink path), releasing a still-running
attached PMC, row exhaustion with out-of-order release, and
PMC_F_DESCENDANTS inheritance including a fork storm.
All pass on a debug (INVARIANTS+WITNESS) and a KASAN kernel.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
Assisted-by: Claude Code (Opus 5)
(cherry picked from commit d00da14532bc4408f3e66535c88276d00905af7c)
hwpmc: add regression tests for a credential-changing exec
This tests what FreeBSD-SA-26:56.hwpmc fixed.
exec_setgid_drops_pmc asserts the kernel takes a process-mode PMC away
when its target execs a set-gid program its owner is not entitled to
trace.
exec_setuid_no_double_unlink lets the target exec a set-uid program;
the teardown must unlink the process descriptor exactly once, and
completing at all is the assertion.
Both need an unprivileged owner and must not drop privileges themselves,
since p_candebug() would then refuse the target to its own owner; they
ask for require.user instead.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
[3 lines not shown]
hwpmc: add tests for handle validation and the privilege boundaries
A pmc_id_t is a packed integer that the driver hands to userland and
accepts back on eleven operations, and nothing tested what happens when
one comes back forged, stale, or belonging to another process. Neither
was there a test that an unprivileged caller is refused the operations
that need a privilege.
The cases use a SOFT-class PMC wherever the counter itself does not
matter, so they run on a machine with no PMU.
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
Assisted-by: Claude Code (Opus 5)
(cherry picked from commit 17fca802ded118102d04a7a0bbc0c076de18c4d8)
hwpmc tests: sort the list of test programs
MFC after: 1 month
MFC to: stable/15
MFC to: stable/14
(cherry picked from commit df537ff1520d82410328ebd6de529929dae620a6)
if_bnxt: add bnxt logger module files to sys/conf/files for built-in kernel builds
The bnxt snapdump and coredump support patches added bnxt_log/{_data}.c. and listed it in
sys/modules/bnxt/bnxt_en/Makefile, but missed to add these files in sys/conf/files.
Fix up the issue by adding bnxt_log/{_data}.c in sys/conf/files.
Fixes: f85e66e655c9 ("if_bnxt/bnxt_re: add support for driver snapdump")
(cherry picked from commit 03676cafa882c471a29436aae76c8751d451dd07)
if_bnxt: add few source files to version control
Commits- f85e66e655c9 ("if_bnxt/bnxt_re: add support for driver snapdump")
and 03839879a2dd ("if_bnxt: Add Firmware crashdump collection support")
missed to add few files under version control, those files are
added now:
sys/dev/bnxt/bnxt_en/bnxt_log.c
sys/dev/bnxt/bnxt_en/bnxt_log.h
sys/dev/bnxt/bnxt_en/bnxt_log_data.c
sys/dev/bnxt/bnxt_en/bnxt_log_data.h
sys/dev/bnxt/bnxt_en/bnxt_coredump.c
sys/dev/bnxt/bnxt_en/bnxt_coredump.h
bnxt_coredump.c entry is added in sys/conf/files as well.
Fixes: f85e66e655c9 ("if_bnxt/bnxt_re: add support for driver snapdump")
Fixes: 03839879a2dd ("if_bnxt: Add Firmware crashdump collection support")
(cherry picked from commit 9931dc5bf3831146c08a381c42ecbfcedb8ac7f1)
if_bnxt: Add support for HWRM passthrough with multiple DMA buffers
Added support for HWRM passthrough commands with multiple DMA buffers.
Also, changed the mgmt_lock to sleepable exclusive lock.
MFC after: 2 weeks
Reviewed by: gallatin, ssaxena
Differential Revision: https://reviews.freebsd.org/D56686
(cherry picked from commit 9d87ca8b9f60bdec0bbc1733920df250a08beb0c)
if_bnxt/bnxt_re: add support for driver snapdump
Add a logging module which helps to log and collect the driver`s
various events and state of device data structures.
APIs help modules like l2, RoCE etc. to register and
add logs into thg buffers. A segment header is added to the
data available in buffers.
The final log messages are arranged in following fashion
|SegHeader0|Data0|SegHeader1|Data1|
Logging module provides two different kinds of buffers:
a) A large contiguous memory chunk is used to form circular buffers.
Module need to provide a number of buffers while registering to
the logging module.Please note that, since memory for the
buffers remains with the module as long as it is registered, memory
footprints of the driver could be higher so the modules should
allocate an appropriate number of buffers. Also, due to limited
[23 lines not shown]
if_bnxt: Add Firmware crashdump collection support
This patch adds support for DDR-based firmware coredump memory handling.
It detects firmware coredump capability, allocates host DDR (DMA) memory
for crash dumps, and programs the firmware with the allocated memory during
attach. The allocated memory is released during driver detach.
Also, This patch adds functions to retrieve crash dump data from host DDR
memory. The implementation handles data copying from page tables and
checks dump availability. Main function bnxt_get_coredump() copies
stored crash dump data from DDR memory to the application buffer.
MFC after: 2 weeks
Reviewed by: gallatin, ssaxena
Differential Revision: https://reviews.freebsd.org/D56684
(cherry picked from commit 03839879a2dd2505eab80b99211b0637ebdc9d32)
bnxt: Fix build / load error for bnxt(4) in kernels without PCI_IOV
This change removes the hard-forcing of PCI_IOV and adds shims to
allow the driver to compile and work when the kernel is missing
PCI_IOV support.
Fixes: 7c450d1127c7
Reviewed by: sumit.saxena_broadcom.com
Differential Revision: https://reviews.freebsd.org/D57300
Sponsored by: Netflix
(cherry picked from commit 3118f1b99f23431235c202d9aadbe3d183bcc259)
if_bnxt: Fix the Unknown command 0x80000000 ioctl command error
With the latest niccli version, user will observe below
Unknown command command error when try to list the devices.
if_bnxt: Unknown command 0x80000000
Here, niccli is issuing command opcode as 0x80000000 but
driver is expecting 0x20000000 command opcode.
So, replaced _IOW(0,0,0) with the _IOC(IOC_IN,0,0,0).
Fixes: d53d7b4 ("bnxt: Fix up ioctl opcodes to support IOC_VOID along with IOC_IN")
MFC after: 2 weeks
Reviewed by: gallatin, ssaxena
Differential Revision: https://reviews.freebsd.org/D56685
(cherry picked from commit 3987058a3a943c461c27dbebf10dad555b1bb2fa)
bnxt: Fix up ioctl opcodes to support IOC_VOID along with IOC_IN
The driver and applications currently use hard-coded numeric ioctl command
opcodes. These opcodes are interpreted as having the IOC_IN direction (data
copied from the user application to the driver), regardless of the actual packet
size. Consequently, when the packet size is zero and the direction is set to
IOC_IN, the kernel fails these ioctls if COMPAT is disabled.
While the driver and applications should ideally set the direction correctly—
for example, using IOC_VOID when the packet size is zero—the driver will now
be updated to define ioctl opcodes using the _IOC macro to support both
IOC_VOID and IOC_IN. This change ensures backward compatibility with older
applications that exclusively use IOC_IN.
Reviewed by: gallatin
Differential Revision: https://reviews.freebsd.org/D54601
MFC after: 3 days
(cherry picked from commit d53d7b466016408229491cfd2f8bdc742ff642e3)
bnxt_en: Address review comments for core SR-IOV support
This patch addresses the code review comments provided for:
https://reviews.freebsd.org/D56197
* P7 VF PCI ID: rename NETXTREME_E_P7_VF to E_P7_VF (P7/Thor2 line drops the
Netxtreme name in product strings; other VF device IDs are unchanged).
* Use the return value of bnxt_vf_parse_schema() in bnxt_iov_vf_add() to
decide when to call bnxt_set_vf_admin_mac(); make parse_schema() return
bool and remove the has_admin_mac field.
* In bnxt_free_vf_resources(), fix indentation after dma_free_coherent() so
the NULL assignment is clearly separate from the call.
* In bnxt_hwrm_func_vf_resource_free(), use first_vf_id/last_vf_id in the
HWRM_FUNC_VF_RESC_FREE loop.
MFC after: 1 month
Reviewed by: ssaxena
Differential Revision: https://reviews.freebsd.org/D56644
(cherry picked from commit 7c450d1127c7f08361f848c0ac57189910da8d3b)
bnxt_en: Re-enable SR-IOV after firmware reset
When the firmware undergoes a hot-reset and the driver re-opens the
device, previously active Virtual Functions lose their resource
configuration. bnxt_reenable_sriov() restores that configuration by
replaying bnxt_cfg_hw_sriov() with the saved resource parameters.
The function is called from bnxt_fw_reset_task() in the
BNXT_FW_RESET_STATE_OPENING state, guarded by #ifdef PCI_IOV.
Because bnxt_cfg_hw_sriov() is a no-op when active_vfs is zero the
call is safe on any PF regardless of whether VFs were ever created.
MFC after: 1 month
Reviewed by: ssaxena
Differential Revision: https://reviews.freebsd.org/D56201
(cherry picked from commit 8743209350cb4b7db6d367df99da0a7ae3bc5d39)
bnxt_en: VF ring reservation, HWRM registration, and PF-only operation guards
VFs require separate HWRM commands for ring reservation and async
completion ring setup, so a common PF/VF dispatcher is introduced and
the async CR path is extended to handle both. The PF must populate the
VF request forwarding bitmap during driver registration so the firmware
correctly forwards VF-originated HWRM commands. VF reservation strategy
and min-guaranteed capability flags are now parsed for correct resource
partitioning, and PF-only operations (DCB, NVM, package version sysctl)
are guarded against VF invocation.
The short command buffer allocation is also reordered before the function
reset to ensure extended HWRM messages are available when needed, a
prerequisite uncovered during VF bring-up.
MFC after: 1 month
Reviewed by: ssaxena
Differential Revision: https://reviews.freebsd.org/D56232
(cherry picked from commit c972c5acbac472a5dc797856f39f478862b6c6ea)
bnxt_en: Add VF load path and PF/VF context differentiation
Teach the driver to distinguish a Physical Function from a Virtual
Function at probe time and configure each appropriately.
* Introduce bnxt_is_vf_device() to identify all known VF device IDs
(NetXtreme-C/E Gen1-3, Thor1/2, Hyper-V variants). Add corresponding
PVID entries to bnxt_vendor_info_array.
* Refactor the iflib shared context: rename bnxt_sctx_init to
bnxt_sctx_template, add a Thor2-specific bnxt_sctx_template_p7, and
build per-call PF/VF instances via bnxt_init_sctx_variants(); the VF
instance carries IFLIB_IS_VF. bnxt_register() selects the correct sctx.
* bnxt_attach_pre(): replace the hard-coded NPAR/VF switch with
bnxt_set_flags_by_devid(); on a VF call bnxt_approve_mac() to request
PF approval for the firmware-assigned MAC address.
* bnxt_hwrm_func_qcaps(): populate fw_fid and MAC for PF and VF contexts
[14 lines not shown]
bnxt_en: Add per-VF trust, spoof-check and promiscuous controls
Expose per-VF policy knobs via the FreeBSD sysctl tree and enforce
them at the data-path level.
Trust (dev.bnxt.<unit>.vfN.trusted):
bnxt_set_vf_trust() sets/clears BNXT_VF_TRUST and sends
HWRM_FUNC_CFG with FLAGS_TRUSTED_VF_ENABLE/DISABLE.
bnxt_create_trusted_vf_sysctls() / bnxt_destroy_trusted_vf_sysctls()
manage the sysctl lifetime with VF creation/teardown.
Spoof-check (dev.bnxt.<unit>.vfN.spoofchk):
bnxt_set_vf_spoofchk() issues HWRM_FUNC_CFG with
SRC_MAC_ADDR_CHECK_ENABLE/DISABLE.
Promiscuous gating:
bnxt_is_trusted_vf() queries firmware via HWRM_FUNC_QCFG.
bnxt_promisc_ok() returns false for untrusted VFs, preventing them
from entering promiscuous mode. bnxt_promisc_set() is updated to
[11 lines not shown]