HardenedBSD/src 6fe940clibexec/rc rc.conf, libexec/rc/rc.d os-release

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+27-22sys/kern/tty.c
+15-11sys/netinet6/raw_ip6.c
+4-4usr.sbin/rtadvd/rtadvd.c
+4-4libexec/rc/rc.conf
+6-1share/man/man4/ctl.4
+2-2libexec/rc/rc.d/os-release
+58-445 files not shown
+64-4811 files

HardenedBSD/src 7e28c96contrib/lib9p/example Makefile server.c, share/man/man4 ctl.4

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+27-22sys/kern/tty.c
+15-11sys/netinet6/raw_ip6.c
+4-4usr.sbin/rtadvd/rtadvd.c
+6-1share/man/man4/ctl.4
+2-2contrib/lib9p/example/server.c
+1-1contrib/lib9p/example/Makefile
+55-412 files not shown
+57-418 files

HardenedBSD/src 32daa4ccddl/usr.bin/ctfmerge ctfmerge.1, sbin/nvmecontrol nvmecontrol.8

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+51-29cddl/usr.bin/ctfmerge/ctfmerge.1
+13-2share/man/man4/padlock.4
+5-1sbin/nvmecontrol/nvmecontrol.8
+2-2share/man/man4/rtw89.4
+2-2share/man/man4/rtw88.4
+2-2share/man/man4/iwlwifi.4
+75-381 files not shown
+76-397 files

HardenedBSD/src e27e9d6libexec/rc rc.conf, libexec/rc/rc.d os-release

HBSD: Update /etc/os-release and /var/run/os-release

Now that we have completed the migration to Radicle, we need to update
the URLs and other auxiliary data in the os-release files.

Signed-off-by:  Shawn Webb <shawn.webb at hardenedbsd.org>
MFC-to:         15-STABLE
DeltaFile
+4-4libexec/rc/rc.conf
+2-2libexec/rc/rc.d/os-release
+6-62 files

HardenedBSD/src 6a2f1e3sbin/nvmecontrol nvmecontrol.8

nvmecontrol.8: Explain non-operational power modes

`nvmecontrol power -l ...` lists the available power modes.
Non-operational modes are marked with an asterisk. While here,
add <device-id | namespace-id> to the "nvmecontrol power" synopsis.

MFC after:              3 days
Reviewed by:            dab, imp, michaelo, ziaee
Differential Revision:  https://reviews.freebsd.org/D58480

(cherry picked from commit 868158f7fd2a172ef22f1b6b682cc1d38e54cf63)
DeltaFile
+5-1sbin/nvmecontrol/nvmecontrol.8
+5-11 files

HardenedBSD/src 70c87c0cddl/usr.bin/ctfmerge ctfmerge.1

ctfmerge.1: Fix uniqlabel typos

The flag is -D, but it was written as a second -d. Add a period too.

MFC after:      3 days

(cherry picked from commit 4f293e32e4529617dd05bd64fd3c22a57a56a355)
DeltaFile
+2-2cddl/usr.bin/ctfmerge/ctfmerge.1
+2-21 files

HardenedBSD/src 2cdb856share/man/man5 pf.conf.5

pf.conf.5: Fix typo

Fix small typo in pf.conf(5)

MFC after:              3 days
Reviewed by:            ziaee
Differential Revision:  https://reviews.freebsd.org/D57938

(cherry picked from commit bbc2d15857b8c44cf8558bf00663b508d421c94c)
DeltaFile
+1-1share/man/man5/pf.conf.5
+1-11 files

HardenedBSD/src 279fdaashare/man/man4 rtw89.4 rtw88.4

iwlwifi.4, rtw88.4, rtw89.4: Fix xref typos

MFC after:      3 days
Reviewed by:    bz, ziaee
Fixes:  0a2f7683bf0c ("man: iwlwifi/rtw88/rtw89: update man pages for Linux v7.0 based updates")
Differential Revision:  https://reviews.freebsd.org/D57720

(cherry picked from commit d036b3b348d3f7be21f79461d7ad48e97b088ba8)
DeltaFile
+2-2share/man/man4/rtw89.4
+2-2share/man/man4/rtw88.4
+2-2share/man/man4/iwlwifi.4
+6-63 files

HardenedBSD/src 5650618cddl/usr.bin/ctfmerge ctfmerge.1

ctfmerge.1: Import ENVIRONMENT from NetBSD

Import the ENVIRONMENT section from NetBSD, minus the variable that our
ctfmerge does not have. Alphabetize them, polish grammar and alignment,
and add the variables to the man database. While here, remove whitespace
from the end of some lines to quiet linter.

MFC after:      3 days
PR:             291186
Co-authored-by: Alexander Ziaee <ziaee at FreeBSD.org>
Obtained from:  NetBSD (christos <christos at NetBSD.org>, 8a0c0d8)
Differential Revision:  https://reviews.freebsd.org/D54054

(cherry picked from commit 32cf24b725fdf899fb642c47004b69fcfae9b9db)
DeltaFile
+49-27cddl/usr.bin/ctfmerge/ctfmerge.1
+49-271 files

HardenedBSD/src c553a42share/man/man4 padlock.4

padlock.4: Update slightly for 64-bit hardware

- Change the document description to "Via and Zhaoxin CPU crypto driver"
- Add a HARDWARE section mentioning these in the hardware release note

This manual still needs desperate help, but just this little bit could
have saved a lot of confusion. I'd write more if I had information.

PR:             295517
Fixes:          14b8531c4ccb8 (Restore padlock_rng the the amd64 build)
MFC after:      3 days (to 15 only)
Reviewed by:    bcr, asomers
Differential Revision:  https://reviews.freebsd.org/D57920

(cherry picked from commit 380c6f59c4f87dbc45a67983d927700ca7e22be2)
DeltaFile
+13-2share/man/man4/padlock.4
+13-21 files

HardenedBSD/src 200de1busr.sbin/rtadvd rtadvd.c

rtadvd(8): Fix RA flag inconsistency messages

During flag inconsistency report, we handle rai->rai_otherflg
as a bool, but the value is 0x40. Make it a simple number comparison.

PR:             295995
Reviewed by:    markj, Faraz Vahedi <kfv at kfv.io>
MFC after:      3 days
Differential Revision: https://reviews.freebsd.org/D58672
DeltaFile
+4-4usr.sbin/rtadvd/rtadvd.c
+4-41 files

HardenedBSD/src 62ccaeclib/libc/gen exterr_cat_filenames.h, sys/kern tty.c

kern/tty.c: Exterrorize returns

Approved by:    kib
Pull Request:   https://github.com/freebsd/freebsd-src/pull/2349
DeltaFile
+27-22sys/kern/tty.c
+1-0sys/sys/exterr_cat.h
+1-0lib/libc/gen/exterr_cat_filenames.h
+29-223 files

HardenedBSD/src a4e4b1eusr.sbin/bsdinstall/scripts auto

HBSD: Explicitly dissuade from pkgbase use

HardenedBSD isn't ready for pkgbase. I would rather folks not use it,
but if they do, they know it's really not supported.

Signed-off-by:  Shawn Webb <shawn.webb at hardenedbsd.org>
MFC-to:         15-STABLE
DeltaFile
+1-1usr.sbin/bsdinstall/scripts/auto
+1-11 files

HardenedBSD/src e6b0384contrib/lib9p/example Makefile server.c

lib9p: fix compilation errors in example server

Reviewed by:    markj
MFC after:      1 week
Differential Revision:  https://reviews.freebsd.org/D58634
DeltaFile
+2-2contrib/lib9p/example/server.c
+1-1contrib/lib9p/example/Makefile
+3-32 files

HardenedBSD/src 3c8f843share/man/man4 ctl.4

ctl.4: Document the assumption that CTL HA runs only on trusted networks

The CTL High Availablity clustering feature allows a pair of hosts to
implement transparent failover.  The implementation uses a TCP
connection to exchange messages.  There is no authentication mechanism
and the protocol itself embeds kernel pointers in the messages exchanged
between HA hosts.  This property (of CTL_MSG_DATAMOVE messages
specifically), as well as insufficient validation of inbound messages,
mean that anyone able to access a CTL HA port is able to remotely
execute code on that host.

Provide a warning to this effect in the CTL man page.

Reported by:    Ryan of Calif.io
Reviewed by:    ziaee, ken, mav
MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D58622
DeltaFile
+6-1share/man/man4/ctl.4
+6-11 files

HardenedBSD/src 196874csys/netinet6 raw_ip6.c

rawip: Fix handling of checksums in rip6_input()

A v6 raw socket may ask the kernel to validate the checksum of an
inbound packet.  If it does, and the validation fails, we discard the
packet, but this isn't really right: other raw sockets may wish to
receive a copy of the packet anyway.

Rework checksum handling to address this problem, and use a flag to
avoid computing the checksum more than once for a given packet.

Fixes:          de2d47842e880281 ("SMR protection for inpcbs")
Reviewed by:    pouria, glebius
Reported by:    Yunzhi Ke
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D58559
DeltaFile
+15-11sys/netinet6/raw_ip6.c
+15-111 files

HardenedBSD/src 56c0d82sys/fs/pseudofs pseudofs.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+0-1sys/fs/pseudofs/pseudofs.c
+0-11 files

HardenedBSD/src b6c0d2esys/fs/pseudofs pseudofs.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+0-1sys/fs/pseudofs/pseudofs.c
+0-11 files

HardenedBSD/src 2b07783lib/libsys stat.2, sys/amd64/amd64 exec_machdep.c

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+12-5sys/amd64/amd64/exec_machdep.c
+16-1sys/kern/vfs_subr.c
+11-1lib/libsys/stat.2
+4-4sys/kern/imgact_elf.c
+2-1sys/sys/mount.h
+1-1sys/kern/vfs_syscalls.c
+46-136 files

HardenedBSD/src 4ebcdb8sys/fs/pseudofs pseudofs.c

pseudofs: Don't purge the cache on shutdown

This is a waste of time and results in a use-after-free if linsysfs is
loaded and a USB network interface is in use, since USB devices are
disconnected at shutdown, which triggers a call into linsysfs, which
then tries to destroy a pseudofs node which has already been purged.

MFC after:      1 week
Reviewed by:    glebius
Differential Revision:  https://reviews.freebsd.org/D58359
DeltaFile
+0-1sys/fs/pseudofs/pseudofs.c
+0-11 files

HardenedBSD/src 5adc7b1sys/kern vfs_subr.c, sys/sys mount.h

vfs_busy(): add MBF_PCATCH flag to allow interrupting the sleep

(cherry picked from commit fb4d7bd4b7676963f9f37ff47f315f8c3652538b)
DeltaFile
+16-1sys/kern/vfs_subr.c
+2-1sys/sys/mount.h
+18-22 files

HardenedBSD/src abe9c47sys/kern vfs_syscalls.c

statfs(2): allow to interrupt busying

(cherry picked from commit b72f9bfc4513e3e286fb3fc2d07ebdd94ed7ac57)
DeltaFile
+1-1sys/kern/vfs_syscalls.c
+1-11 files

HardenedBSD/src 5bdb00blib/libsys stat.2

stat.2: enhance the description of st_blocks

(cherry picked from commit 4c58eef12d30ec699c86d9ab8939253adbf35e79)
DeltaFile
+11-1lib/libsys/stat.2
+11-11 files

HardenedBSD/src 8b62109sys/kern imgact_elf.c

ptrace: Propagate errors from set_fpregs()

(cherry picked from commit 1932bd20ed53f2e695a576cffd183937ed25de3f)
DeltaFile
+4-4sys/kern/imgact_elf.c
+4-41 files

HardenedBSD/src aea04a8sys/amd64/amd64 exec_machdep.c

amd64: do not allow to set reserved bits in MXCSR for ptrace(PT_SETFPREGS)

(cherry picked from commit cef05c5a62ba63eda222eed083972bfaa1449ac2)
DeltaFile
+12-5sys/amd64/amd64/exec_machdep.c
+12-51 files

HardenedBSD/src 49dce82sys/dev/e1000 if_em.c, sys/dev/igc if_igc.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+12-6sys/dev/igc/if_igc.c
+12-6sys/dev/e1000/if_em.c
+24-122 files

HardenedBSD/src dfe8f1fsys/dev/e1000 if_em.c, sys/dev/igc if_igc.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+12-6sys/dev/igc/if_igc.c
+12-6sys/dev/e1000/if_em.c
+24-122 files

HardenedBSD/src 45d93ffusr.sbin/boot0cfg boot0cfg.8 boot0cfg.c

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+34-6usr.sbin/boot0cfg/boot0cfg.c
+26-6usr.sbin/boot0cfg/boot0cfg.8
+60-122 files

HardenedBSD/src 30ccf2fsys/dev/igc if_igc.c

igc: defer sysctl-driven reinit to the admin task

igc_sysctl_eee() and igc_sysctl_dmac() called igc_if_init() directly.

Request the reset through iflib instead, and skipping while the interface
is down; the new value is picked up by the next init.

Unlike e1000, igc has no ASSERT_CTX_LOCK_HELD and no acquire_swflag
path, so the defect is silent here rather than an assertion failure.

While here also remove unnecessary igc_if_init uses:
iflib_if_init_locked() already runs after IFDI_RESUME and
IFDI_MEDIA_CHANGE, so the trailing *_if_init() only added an unstopped
IFDI_INIT that the following iflib_stop() undoes.

MFC after:      1 week
Differential Revision:  https://reviews.freebsd.org/D58629
DeltaFile
+12-6sys/dev/igc/if_igc.c
+12-61 files

HardenedBSD/src abdde8bsys/dev/e1000 if_em.c

e1000: defer sysctl-driven reinit to the admin task

Request the reset through iflib and let the admin task perform the
stop/init under the context lock, matching what the VF and SR-IOV paths
already do.

The assertion is compiled out without INVARIANTS, where the same write
instead resets the MAC and takes the ICH software flag while the queues
stay live and an ioctl or the admin task may be running.

While here also remove unnecessary em_if_init uses:
iflib_if_init_locked() already runs after IFDI_RESUME and
IFDI_MEDIA_CHANGE, so the trailing *_if_init() only added an unstopped
IFDI_INIT that the following iflib_stop() undoes.

MFC after:      1 week
Differential Revision:  https://reviews.freebsd.org/D58628
DeltaFile
+12-6sys/dev/e1000/if_em.c
+12-61 files