HardenedBSD/src 6a5325f — secure/lib/libcrypto/man/man3 SSL_CTX_set_security_level.3 ENGINE_add.3, secure/lib/libcrypto/man/man5 fips_config.5 config.5

crypto/openssl: update generated files to match 3.5.9 release content

A new manpage has been added and some source files have been refactored
slightly, but by and large this is just a standard "version bump" update
(3.5.8 -> 3.5.9).

MFC after:      1 day
MFC with:       b3a31d78

(cherry picked from commit be0569f12f48fe414467cf9cba8627e439ca1cd4)
Signed-off-by: Shawn Webb <shawn.webb at hardenedbsd.org>
DeltaFile
+107-0secure/lib/libcrypto/man/man3/X509V3_EXT_nconf_nid.3
+46-49secure/lib/libcrypto/man/man3/ENGINE_add.3
+83-11secure/lib/libcrypto/man/man3/SSL_CTX_set_security_level.3
+31-34secure/lib/libcrypto/man/man7/EVP_PKEY-EC.7
+31-34secure/lib/libcrypto/man/man5/config.5
+30-33secure/lib/libcrypto/man/man5/fips_config.5
+328-161904 files not shown
+4,295-6,061910 files

HardenedBSD/src 01acc52 — crypto/openssl/test/recipes/10-test_bn_data bngcd.txt, crypto/openssl/test/recipes/30-test_evp_data evppkey_ecc.txt evpkdf_ssh.txt

crypto/openssl: update to 3.5.9

This is a security fix release addressing CVE High issues. Users are
strongly encouraged to update to this version.

See the release notes for the release for more details on what is being
fixed.

MFC after:      1 day
Merge commit 'af5a659dc1cd2b0a6994f2cee1956d0bf50bb1a2'

(cherry picked from commit f9bc005b8ef3b507a5ecbc2d7fe4411ef70eff38)
Signed-off-by: Shawn Webb <shawn.webb at hardenedbsd.org>
DeltaFile
+0-23,927crypto/openssl/test/recipes/30-test_evp_data/evpciph_aes_ccm_cavs.txt
+0-17,330crypto/openssl/test/recipes/10-test_bn_data/bngcd.txt
+0-11,686crypto/openssl/test/recipes/30-test_evp_data/evppkey_kas.txt
+0-5,037crypto/openssl/test/recipes/30-test_evp_data/evpkdf_tls13_kdf.txt
+0-4,943crypto/openssl/test/recipes/30-test_evp_data/evpkdf_ssh.txt
+0-4,563crypto/openssl/test/recipes/30-test_evp_data/evppkey_ecc.txt
+0-67,4861,248 files not shown
+10,203-197,9121,254 files

HardenedBSD/src 1153a5b — crypto/openssl/test/recipes/10-test_bn_data bngcd.txt, crypto/openssl/test/recipes/30-test_evp_data evppkey_ecc.txt evpkdf_ssh.txt

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/cross-dso-cfi
DeltaFile
+0-23,927crypto/openssl/test/recipes/30-test_evp_data/evpciph_aes_ccm_cavs.txt
+0-17,330crypto/openssl/test/recipes/10-test_bn_data/bngcd.txt
+0-11,686crypto/openssl/test/recipes/30-test_evp_data/evppkey_kas.txt
+0-5,037crypto/openssl/test/recipes/30-test_evp_data/evpkdf_tls13_kdf.txt
+0-4,943crypto/openssl/test/recipes/30-test_evp_data/evpkdf_ssh.txt
+0-4,563crypto/openssl/test/recipes/30-test_evp_data/evppkey_ecc.txt
+0-67,4862,216 files not shown
+14,899-207,1712,222 files

HardenedBSD/src f64281c — crypto/openssl/test/recipes/10-test_bn_data bngcd.txt, crypto/openssl/test/recipes/30-test_evp_data evppkey_ecc.txt evpkdf_ssh.txt

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+0-23,927crypto/openssl/test/recipes/30-test_evp_data/evpciph_aes_ccm_cavs.txt
+0-17,330crypto/openssl/test/recipes/10-test_bn_data/bngcd.txt
+0-11,686crypto/openssl/test/recipes/30-test_evp_data/evppkey_kas.txt
+0-5,037crypto/openssl/test/recipes/30-test_evp_data/evpkdf_tls13_kdf.txt
+0-4,943crypto/openssl/test/recipes/30-test_evp_data/evpkdf_ssh.txt
+0-4,563crypto/openssl/test/recipes/30-test_evp_data/evppkey_ecc.txt
+0-67,4862,216 files not shown
+14,899-207,1712,222 files

HardenedBSD/src 2e93b0a — sys/fs/cuse cuse.c, tests/sys/pmc pmc_exec_test.c pmc_credexec_test.c

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+507-0tests/sys/pmc/pmc_api_test.c
+453-0tests/sys/pmc/pmc_log_test.c
+436-0tests/sys/pmc/pmc_lifecycle_test.c
+348-0tests/sys/pmc/pmc_credexec_test.c
+156-112sys/fs/cuse/cuse.c
+264-0tests/sys/pmc/pmc_exec_test.c
+2,164-1128 files not shown
+2,220-13914 files

HardenedBSD/src 9a188d8 — crypto/openssl/test/recipes/10-test_bn_data bngcd.txt, crypto/openssl/test/recipes/30-test_evp_data evppkey_ecc.txt evpkdf_ssh.txt

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+0-23,927crypto/openssl/test/recipes/30-test_evp_data/evpciph_aes_ccm_cavs.txt
+0-17,330crypto/openssl/test/recipes/10-test_bn_data/bngcd.txt
+0-11,686crypto/openssl/test/recipes/30-test_evp_data/evppkey_kas.txt
+0-5,037crypto/openssl/test/recipes/30-test_evp_data/evpkdf_tls13_kdf.txt
+0-4,943crypto/openssl/test/recipes/30-test_evp_data/evpkdf_ssh.txt
+0-4,563crypto/openssl/test/recipes/30-test_evp_data/evppkey_ecc.txt
+0-67,4862,216 files not shown
+14,899-207,1712,222 files

HardenedBSD/src 8af92dc — tests/sys/pmc Makefile pmc_exec_test.c

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+507-0tests/sys/pmc/pmc_api_test.c
+453-0tests/sys/pmc/pmc_log_test.c
+436-0tests/sys/pmc/pmc_lifecycle_test.c
+348-0tests/sys/pmc/pmc_credexec_test.c
+264-0tests/sys/pmc/pmc_exec_test.c
+6-1tests/sys/pmc/Makefile
+2,014-11 files not shown
+2,015-27 files

HardenedBSD/src be0569f — secure/lib/libcrypto/man/man3 SSL_CTX_set_security_level.3 ENGINE_add.3, secure/lib/libcrypto/man/man5 fips_config.5 config.5

crypto/openssl: update generated files to match 3.5.9 release content

A new manpage has been added and some source files have been refactored
slightly, but by and large this is just a standard "version bump" update
(3.5.8 -> 3.5.9).

MFC after:      1 day
MFC with:       b3a31d78
DeltaFile
+107-0secure/lib/libcrypto/man/man3/X509V3_EXT_nconf_nid.3
+46-49secure/lib/libcrypto/man/man3/ENGINE_add.3
+83-11secure/lib/libcrypto/man/man3/SSL_CTX_set_security_level.3
+31-34secure/lib/libcrypto/man/man7/EVP_PKEY-EC.7
+31-34secure/lib/libcrypto/man/man5/config.5
+30-33secure/lib/libcrypto/man/man5/fips_config.5
+328-161904 files not shown
+4,295-6,061910 files

HardenedBSD/src f9bc005 — crypto/openssl/test/recipes/10-test_bn_data bngcd.txt, crypto/openssl/test/recipes/30-test_evp_data evppkey_ecc.txt evpkdf_ssh.txt

crypto/openssl: update to 3.5.9

This is a security fix release addressing CVE High issues. Users are
strongly encouraged to update to this version.

See the release notes for the release for more details on what is being
fixed.

MFC after:      1 day
Merge commit 'af5a659dc1cd2b0a6994f2cee1956d0bf50bb1a2'
DeltaFile
+0-23,927crypto/openssl/test/recipes/30-test_evp_data/evpciph_aes_ccm_cavs.txt
+0-17,330crypto/openssl/test/recipes/10-test_bn_data/bngcd.txt
+0-11,686crypto/openssl/test/recipes/30-test_evp_data/evppkey_kas.txt
+0-5,037crypto/openssl/test/recipes/30-test_evp_data/evpkdf_tls13_kdf.txt
+0-4,943crypto/openssl/test/recipes/30-test_evp_data/evpkdf_ssh.txt
+0-4,563crypto/openssl/test/recipes/30-test_evp_data/evppkey_ecc.txt
+0-67,4861,248 files not shown
+10,203-197,9121,254 files

HardenedBSD/src 913328f — tests/sys/pmc Makefile pmc_credexec_test.c

hwpmc: add credential-transition exec tests (keep and drop)

The companion to pmc_exec_test.c, which covers only the drop side of a
credential-changing exec.  Three cases cover what the drop must not
overreach into: an exec that changes no credentials keeps the PMC, a
set-id exec whose credential change the kernel suppresses for a traced
target keeps it too, and a set-id fexecve(2) drops it.  They exercise
the permission logic FreeBSD-SA-26:56.hwpmc reworked, not the defect
it fixed.

All three pass on a debug (INVARIANTS+WITNESS) kernel.  The two
keep-cases were each observed to fail on a kernel mutated to detach
unconditionally.

MFC after:      1 month
MFC to:         stable/15
MFC to:         stable/14
Assisted-by:    Claude Code (Opus 4.8)

(cherry picked from commit bea7b932b9eeaff39393347e0600b982fd859a92)
DeltaFile
+348-0tests/sys/pmc/pmc_credexec_test.c
+1-0tests/sys/pmc/Makefile
+349-02 files

HardenedBSD/src 63b3fde — tests/sys/pmc Makefile pmc_log_test.c

hwpmc tests: the sampling log file

Nine ATF cases covering PMC_OP_CONFIGURELOG and the descriptor-less
log operations: which descriptors are accepted, when a log is required
in the first place, and what the log operations do without one.

MFC after:      1 month
MFC to:         stable/15
MFC to:         stable/14
Assisted-by:    Claude Code (Opus 5)

(cherry picked from commit 8f0789bee7abb2fdb2ff6d625f254533a138e6e8)
DeltaFile
+453-0tests/sys/pmc/pmc_log_test.c
+1-0tests/sys/pmc/Makefile
+454-02 files

HardenedBSD/src 7fc0037 — tests/sys/pmc Makefile pmc_lifecycle_test.c

hwpmc tests: process-attachment lifecycle and ownership cases

Seven ATF cases covering process-attachment teardown orderings: a
target that exits before it is detached, the owner that exits before
its target (hwpmc's other unlink path), releasing a still-running
attached PMC, row exhaustion with out-of-order release, and
PMC_F_DESCENDANTS inheritance including a fork storm.

All pass on a debug (INVARIANTS+WITNESS) and a KASAN kernel.

MFC after:      1 month
MFC to:         stable/15
MFC to:         stable/14
Assisted-by:    Claude Code (Opus 5)

(cherry picked from commit d00da14532bc4408f3e66535c88276d00905af7c)
DeltaFile
+436-0tests/sys/pmc/pmc_lifecycle_test.c
+1-0tests/sys/pmc/Makefile
+437-02 files

HardenedBSD/src 24b4ea0 — tests/sys/pmc Makefile pmc_api_test.c

hwpmc: add tests for handle validation and the privilege boundaries

A pmc_id_t is a packed integer that the driver hands to userland and
accepts back on eleven operations, and nothing tested what happens when
one comes back forged, stale, or belonging to another process.  Neither
was there a test that an unprivileged caller is refused the operations
that need a privilege.

The cases use a SOFT-class PMC wherever the counter itself does not
matter, so they run on a machine with no PMU.

MFC after:      1 month
MFC to:         stable/15
MFC to:         stable/14
Assisted-by:    Claude Code (Opus 5)

(cherry picked from commit 17fca802ded118102d04a7a0bbc0c076de18c4d8)
DeltaFile
+507-0tests/sys/pmc/pmc_api_test.c
+1-0tests/sys/pmc/Makefile
+508-02 files

HardenedBSD/src 8ba25f0 — tests/sys/pmc Makefile pmc_exec_test.c

hwpmc: add regression tests for a credential-changing exec

This tests what FreeBSD-SA-26:56.hwpmc fixed.

exec_setgid_drops_pmc asserts the kernel takes a process-mode PMC away
when its target execs a set-gid program its owner is not entitled to
trace.

exec_setuid_no_double_unlink lets the target exec a set-uid program;
the teardown must unlink the process descriptor exactly once, and
completing at all is the assertion.

Both need an unprivileged owner and must not drop privileges themselves,
since p_candebug() would then refuse the target to its own owner; they
ask for require.user instead.

MFC after:      1 month
MFC to:         stable/15
MFC to:         stable/14

    [3 lines not shown]
DeltaFile
+264-0tests/sys/pmc/pmc_exec_test.c
+1-0tests/sys/pmc/Makefile
+265-02 files

HardenedBSD/src 299197d — tests/sys/pmc Makefile

hwpmc tests: sort the list of test programs

MFC after:      1 month
MFC to:         stable/15
MFC to:         stable/14

(cherry picked from commit df537ff1520d82410328ebd6de529929dae620a6)
DeltaFile
+1-1tests/sys/pmc/Makefile
+1-11 files

HardenedBSD/src 5708698 — lib/libfetch ftp.c

libfetch: Plug connection leaks in FTP code

When setting up an FTP transfer, we need to dereference the cached
connection before returning after a failure.

MFC after:      1 week
Reviewed by:    markj
Differential Revision:  https://reviews.freebsd.org/D60017
DeltaFile
+7-3lib/libfetch/ftp.c
+7-31 files

HardenedBSD/src b212f56 — lib/libfetch http.c

libfetch: Plug leak in 304 Not Modified case

When we get a 304 Not Modified response, we need to go through the error
path to properly free any resources we've allocated instead of just
returning NULL directly.

MFC after:      1 week
Reviewed by:    markj
Differential Revision:  https://reviews.freebsd.org/D60016
DeltaFile
+1-1lib/libfetch/http.c
+1-11 files

HardenedBSD/src cd2fca4 — lib/libfetch http.c

libfetch: Correctly free redirect target

When processing a redirect, if we get multiple Location headers, we free
the previous one using free(new) instead of fetchFreeURL(new), which
leaks new->doc.

While here, rename new to loc since new is a reserved word in C++.

MFC after:      1 week
Reviewed by:    markj
Differential Revision:  https://reviews.freebsd.org/D60015
DeltaFile
+16-16lib/libfetch/http.c
+16-161 files

HardenedBSD/src b319c3d — lib/libfetch fetch.c

libfetch: Reject control characters in credentials

If a URL contains credentials, check that neither the user name nor the
password contain control characters which might confuse the server,
especially in the FTP case.

MFC after:      1 week
Reviewed by:    markj
Differential Revision:  https://reviews.freebsd.org/D60008
DeltaFile
+7-1lib/libfetch/fetch.c
+7-11 files

HardenedBSD/src 64ce9da — lib/libfetch common.c

libfetch: Limit response line length

When reading an FTP or HTTP response, error out if we read 64 kB before
hitting a newline.  Otherwise a runaway or malicious server could have
us spinning for quite a while allocating more and more memory before we
gave up or crashed.

MFC after:      1 week
Reviewed by:    markj
Differential Revision:  https://reviews.freebsd.org/D60007
DeltaFile
+15-2lib/libfetch/common.c
+15-21 files

HardenedBSD/src ca37470 — contrib/llvm-project/clang/lib/AST ExprConstant.cpp, contrib/llvm-project/clang/lib/AST/ByteCode Interp.h Opcodes.td

Merge commit c52392a6f464 from llvm-project (by ShengYi Hung):

  [Clang][ExprConst] Drop PRValue for nothrow new (#226753)

  A user defined operator new can accept prvalue for nothrow. However, it
  should not be a ConstExpr. Early returns by
  isUsableAsGlobalAllocationFunctionInConstantEvaluation instead of doing
  LValue evaluation.
  Also, move CheckPlacement new logic into new OpCode. This decouples
  checking from Interp.cpp to Compiler.cpp.

This fixes "Assertion failed: (E->isGLValue() ||
E->getType()->isFunctionType() || E->getType()->isVoidType() ||
isa<ObjCSelectorExpr>(E->IgnoreParens())), function EvaluateLValue" when
building the databases/mariadb123-server port.

MFC after:      1 week
DeltaFile
+31-34contrib/llvm-project/clang/lib/AST/ByteCode/Interp.cpp
+24-18contrib/llvm-project/clang/lib/AST/ExprConstant.cpp
+11-9contrib/llvm-project/clang/lib/AST/ByteCode/Compiler.cpp
+4-0contrib/llvm-project/clang/lib/AST/ByteCode/Opcodes.td
+1-0contrib/llvm-project/clang/lib/AST/ByteCode/Interp.h
+71-615 files

HardenedBSD/src 878856b — sys/dev/acpica acpivar.h acpi.c, sys/x86/acpica acpi_apm.c

acpi: Remove support for /dev/apmctl and apmd(8) compatibility

This simplifies the logic around ACKing suspend requests as there is
no longer the potential for multiple listeners, only devd and the
acknowledgement via acpiconf -k.

Reviewed by:    imp
Differential Revision:  https://reviews.freebsd.org/D59942
DeltaFile
+2-171sys/x86/acpica/acpi_apm.c
+12-46sys/dev/acpica/acpi.c
+0-20sys/dev/acpica/acpivar.h
+14-2373 files

HardenedBSD/src 40ce54c — libexec/rc/rc.d Makefile apm, share/man/man5 rc.conf.5

apm(8): Remove support for APM BIOS

Drop support for queries and commands that are not supported by ACPI's
/dev/apm interface.  This includes dropping support for
enabling/disabling APM BIOS used by /etc/rc.d/apm.

Reviewed by:    ziaee, imp
Differential Revision:  https://reviews.freebsd.org/D59941
DeltaFile
+10-254usr.sbin/apm/apm.c
+12-72usr.sbin/apm/apm.8
+0-50libexec/rc/rc.d/apm
+0-9share/man/man5/rc.conf.5
+0-6libexec/rc/rc.d/Makefile
+1-3tools/build/mk/OptionalObsoleteFiles.inc
+23-3941 files not shown
+26-3947 files

HardenedBSD/src 8cf4fe3 — sys/x86/acpica acpi_apm.c

acpi/apm: Store the ACPI softc in si_drv1

This avoids looking it up via a slower path in apmopen.

Reviewed by:    imp
Differential Revision:  https://reviews.freebsd.org/D59940
DeltaFile
+13-6sys/x86/acpica/acpi_apm.c
+13-61 files

HardenedBSD/src 1d7f0c7 — sys/x86/acpica acpi_apm.c

acpi/apm: Don't claim silent success for APMIO_BIOS ioctls

Report failure as if the request had failed.  This causes apm(8) to
correctly report the resume timer as "unknown" rather than random
garbage.

Reviewed by:    imp
Differential Revision:  https://reviews.freebsd.org/D59939
DeltaFile
+1-2sys/x86/acpica/acpi_apm.c
+1-21 files

HardenedBSD/src e10eb35 — . ObsoleteFiles.inc, share/man/man4 Makefile apm.4

apm.4: Trim down to describing the compat interface exposed by acpi(4)

Reviewed by:    ziaee, imp
Differential Revision:  https://reviews.freebsd.org/D59938
DeltaFile
+0-159share/man/man4/man4.i386/apm.4
+53-0share/man/man4/apm.4
+1-2share/man/man4/man4.i386/Makefile
+3-0ObsoleteFiles.inc
+2-0share/man/man4/Makefile
+59-1615 files

HardenedBSD/src 247503f — usr.sbin/apmd apmd.h apmdparse.y, usr.sbin/apmd/contrib pccardq.c

apmd: Retire the APM daemon

The original purpose of this daemon was to route power management
requests to userspace, e.g. when the suspend button was pressed, the
APM driver posted an event read by apmd(8) that would invoke zzz(8) to
suspend.  However, on ACPI systems this is handled by devd(8) events
instead and running apmd(8) in addition just adds extra complexity.
This probably should have been axed when the APM BIOS support was
retired in commit 8c576a279ed5.

Reviewed by:    imp
Differential Revision:  https://reviews.freebsd.org/D59937
DeltaFile
+0-702usr.sbin/apmd/apmd.c
+0-319usr.sbin/apmd/apmd.8
+0-285usr.sbin/apmd/contrib/pccardq.c
+0-211usr.sbin/apmd/README
+0-206usr.sbin/apmd/apmdparse.y
+0-133usr.sbin/apmd/apmd.h
+0-1,85618 files not shown
+19-2,14624 files

HardenedBSD/src 8d70bf3 — sys/dev/acpica acpi_timer.c

acpi_timer: I/O resource cleanups

- Use bus_read_4 and remove explicit bus_space tag and handle

- Pass rid by value to bus_alloc_resource_any

Differential Revision:  https://reviews.freebsd.org/D59934
DeltaFile
+5-11sys/dev/acpica/acpi_timer.c
+5-111 files

HardenedBSD/src d23d186 — sys/dev/acpica acpi_timer.c

acpi_timer: Trim some more leftovers from the ACPI-safe timer

The "safe" variant of the hook to read the timer is no longer used and
can be removed.  Instead, initialize the get_timecount member of
acpi_timer_timecounter to the normal hook statically.  While here,
initialize a few more fields in acpi_timer_timecounter statically.
I've kept the name as just "ACPI" instead of "ACPI-fast" now.

During device probe there is no longer any reason to alloc the
register resource since it is not used, so remove all that.  While
here, defer registration of the timecounter until attach (kind of odd
to do such a thing during probe leaving a window where the timer
register was unallocated but in theory could still be read via the
timecounter).

Reviewed by:    cperciva
Fixes:          00d061855deb ("Garbage-collect ACPI-safe timer and friends")
Differential Revision:  https://reviews.freebsd.org/D59933
DeltaFile
+15-67sys/dev/acpica/acpi_timer.c
+15-671 files

HardenedBSD/src 34cf45a — sys/dev/acpica acpi_timer.c

acpi_timer: Add a softc to avoid use of global variables

Add a softc and use it to mostly replace the use of global variables
in this driver.  Simplify the suspend and resume event handlers by
saving the old timecounter in the softc and passing the softc pointer
to the handlers.

Differential Revision:  https://reviews.freebsd.org/D59936
DeltaFile
+63-51sys/dev/acpica/acpi_timer.c
+63-511 files