HardenedBSD/src 75bc2c1 — sys/cam/scsi scsi_cd.c

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+10-0sys/cam/scsi/scsi_cd.c
+10-01 files

HardenedBSD/src 09b72b1 — sys/cam/scsi scsi_cd.c

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+10-0sys/cam/scsi/scsi_cd.c
+10-01 files

HardenedBSD/src 90745f0 — sys/cam/scsi scsi_cd.c

cam/cd: avoid integer divide fault in cdstart()

If something goes very badly (e.g. forcibly removing a medium while
the OS tries to start it), this could end up in params.blksize being 0
(and params.disksize 1).  Avoid an integer divide fault, panicking the
kernel, by bailing out before.

MFC after:      3 days

(cherry picked from commit 34ae0f7834d1bd6bb765d1c12e57e01e32b3e060)
DeltaFile
+10-0sys/cam/scsi/scsi_cd.c
+10-01 files

HardenedBSD/src 4aa13e3 — sys/dev/aq aq_hw_llh.h aq_ring.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/cross-dso-cfi
DeltaFile
+25-0sys/dev/aq/aq_hw.c
+19-4sys/dev/aq/aq_main.c
+9-0sys/dev/aq/aq_hw_llh.c
+5-0sys/dev/aq/aq_hw_llh_internal.h
+0-4sys/dev/aq/aq_ring.c
+3-0sys/dev/aq/aq_hw_llh.h
+61-81 files not shown
+63-87 files

HardenedBSD/src 17d610b — sys/dev/aq aq_hw_llh.h aq_ring.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+25-0sys/dev/aq/aq_hw.c
+19-4sys/dev/aq/aq_main.c
+9-0sys/dev/aq/aq_hw_llh.c
+5-0sys/dev/aq/aq_hw_llh_internal.h
+0-4sys/dev/aq/aq_ring.c
+3-0sys/dev/aq/aq_hw_llh.h
+61-81 files not shown
+63-87 files

HardenedBSD/src 6639956 — sys/dev/aq aq_hw_llh.h aq_ring.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+25-0sys/dev/aq/aq_hw.c
+19-4sys/dev/aq/aq_main.c
+9-0sys/dev/aq/aq_hw_llh.c
+5-0sys/dev/aq/aq_hw_llh_internal.h
+0-4sys/dev/aq/aq_ring.c
+3-0sys/dev/aq/aq_hw_llh.h
+61-81 files not shown
+63-87 files

HardenedBSD/src 050683b — sys/dev/aq aq_main.c

aq: Report partial initialization failures to iflib

Stop initialization when hardware setup, ring initialization/start, or
datapath start fails. Run the existing best-effort stop/cache/reset
cleanup and report the failure through iflib_init_failed(). Do not keep
configuring later rings or publish the interface as running.

Reviewed by:    nprice
MFC after:      2 weeks
Sponsored by:   BBOX.io
Differential Revision:  https://reviews.freebsd.org/D59853
DeltaFile
+15-4sys/dev/aq/aq_main.c
+15-41 files

HardenedBSD/src 4993c10 — sys/dev/aq aq_hw_llh.h aq_ring.c

aq: Invalidate the descriptor cache after stopping all rings

Atlantic controllers can retain receive descriptors and their data
addresses after their rings are disabled. Reusing or releasing those
mappings without invalidating the device cache has caused observed
IOMMU and SMMU faults in the referenced Linux reports (7a1bb49461b1,
ed4d81c4b3f2 and 7526183cfdbe).

Move global cache invalidation out of the per-ring stop routine. Disable
every ring first, toggle invalidation once, and wait for its completion
indication. Exclude Atlantic A0, as in the upstream workaround. Report
a completion timeout rather than silently discarding it.

Reviewed by:    nprice
MFC after:      2 weeks
Sponsored by:   BBOX.io
Differential Revision:  https://reviews.freebsd.org/D59852
DeltaFile
+25-0sys/dev/aq/aq_hw.c
+9-0sys/dev/aq/aq_hw_llh.c
+5-0sys/dev/aq/aq_hw_llh_internal.h
+0-4sys/dev/aq/aq_ring.c
+4-0sys/dev/aq/aq_main.c
+3-0sys/dev/aq/aq_hw_llh.h
+46-41 files not shown
+48-47 files

HardenedBSD/src 1412d8e — sys/fs/cd9660 cd9660_vfsops.c, sys/fs/ext2fs ext2_vfsops.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/cross-dso-cfi
DeltaFile
+9-13sys/kern/vfs_subr.c
+3-12sys/fs/ext2fs/ext2_vfsops.c
+13-0sys/geom/geom_vfs.c
+3-8sys/fs/udf/udf_vfsops.c
+3-8sys/fs/cd9660/cd9660_vfsops.c
+6-3sys/kern/vfs_cache.c
+37-447 files not shown
+55-6313 files

HardenedBSD/src 63a86c0 — sys/fs/cd9660 cd9660_vfsops.c, sys/fs/ext2fs ext2_vfsops.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+9-13sys/kern/vfs_subr.c
+3-12sys/fs/ext2fs/ext2_vfsops.c
+13-0sys/geom/geom_vfs.c
+3-8sys/fs/udf/udf_vfsops.c
+3-8sys/fs/cd9660/cd9660_vfsops.c
+6-3sys/kern/vfs_cache.c
+37-447 files not shown
+55-6313 files

HardenedBSD/src 1b179fc — sys/fs/cd9660 cd9660_vfsops.c, sys/fs/ext2fs ext2_vfsops.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+9-13sys/kern/vfs_subr.c
+3-12sys/fs/ext2fs/ext2_vfsops.c
+13-0sys/geom/geom_vfs.c
+3-8sys/fs/udf/udf_vfsops.c
+3-8sys/fs/cd9660/cd9660_vfsops.c
+6-3sys/kern/vfs_cache.c
+37-447 files not shown
+55-6313 files

HardenedBSD/src 6429199 — sys/powerpc/pseries phyp_llan.c

llan: byte swap the receive queue entries

The receive queue of a PAPR logical LAN is filled in by the hypervisor, so
its fields are big endian, but llan_intr() read the offset and the length of
each frame natively.  On a little endian kernel the length of a 134 byte
frame reads as 0x86000000, and ether_input() discards the mbuf because m_len
is not even large enough for an ethernet header.  No frame is ever received.

Reproduced on a POWER9 pseries guest with a spapr-vlan interface.  Before:

  llan0: discard frame w/o leading ethernet header (len -2046820352
      pkt len -2046820352)
  llan0 1500 <Link#1> 52:54:00:12:34:56  123  118  0  5838733312  7  0

that is 118 input errors out of 123 packets, dhclient(8) never completes and
ping(8) loses every packet, although transmit works because the transmit
path passes the lengths in hcall registers rather than through memory.
Afterwards the interface gets a DHCP lease and ping reports no loss.


    [3 lines not shown]
DeltaFile
+4-4sys/powerpc/pseries/phyp_llan.c
+4-41 files

HardenedBSD/src 30ad844 — sys/kern vnode_if.src vfs_subr.c

VFS: require locked vnode for fsync()

Stop exempting devfs nodes.

Reviewed by:    markj
Tested by:      pho
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
Differential revision:  https://reviews.freebsd.org/D59932
DeltaFile
+8-12sys/kern/vfs_subr.c
+1-1sys/kern/vnode_if.src
+9-132 files

HardenedBSD/src e40c72c — sys/fs/nullfs null_vfsops.c, sys/kern vfs_subr.c vfs_mount.c

VFS: style

Wrap long lines, related to the nullfs mounts over regular files and
sockets type checks.  Also fix indent.

Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
DeltaFile
+6-3sys/kern/vfs_cache.c
+4-2sys/kern/vfs_mount.c
+2-1sys/fs/nullfs/null_vfsops.c
+1-1sys/kern/vfs_subr.c
+13-74 files

HardenedBSD/src 53edaad — sys/fs/cd9660 cd9660_vfsops.c, sys/fs/ext2fs ext2_vfsops.c

filesystems: use g_vfs_close_unlocked(9)

As result, we lock the devvp vnode around calls to VOP_FSYNC() on
unmount. For instance, the vn_fsync_buf() implementation of fsync()
needs exclusive lock on the vnode to guarantee that all dirty buffers
are indeed synced.

Reviewed by:    markj
Tested by:      pho
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
Differential revision:  https://reviews.freebsd.org/D59932
DeltaFile
+3-12sys/fs/ext2fs/ext2_vfsops.c
+3-8sys/fs/udf/udf_vfsops.c
+3-8sys/fs/cd9660/cd9660_vfsops.c
+2-5sys/ufs/ffs/ffs_vfsops.c
+2-5sys/fs/msdosfs/msdosfs_vfsops.c
+13-385 files

HardenedBSD/src 87962e0 — sys/geom geom_vfs.h geom_vfs.c

g_vfs_close_unlocked(9): wrapper around g_vfs_close(9)

that locks both bo vnode and topology.

Reviewed by:    markj
Tested by:      pho
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
Differential revision:  https://reviews.freebsd.org/D59932
DeltaFile
+13-0sys/geom/geom_vfs.c
+3-1sys/geom/geom_vfs.h
+16-12 files

HardenedBSD/src cbf35e4 — lib/clang/libllvm Makefile, share/man/man5 src.conf.5

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/cross-dso-cfi
DeltaFile
+42-101usr.sbin/makefs/cd9660.c
+6-83lib/clang/libllvm/Makefile
+27-0sys/dev/nvme/nvme.h
+11-2sys/dev/nvme/nvme_ctrlr.c
+1-6share/man/man5/src.conf.5
+2-4usr.sbin/makefs/cd9660/cd9660_eltorito.c
+89-19626 files not shown
+105-25032 files

HardenedBSD/src ae32fa4 — lib/clang/libllvm Makefile, share/man/man5 src.conf.5

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+42-101usr.sbin/makefs/cd9660.c
+6-83lib/clang/libllvm/Makefile
+27-0sys/dev/nvme/nvme.h
+11-2sys/dev/nvme/nvme_ctrlr.c
+1-6share/man/man5/src.conf.5
+2-4usr.sbin/makefs/cd9660/cd9660_eltorito.c
+89-19626 files not shown
+105-25032 files

HardenedBSD/src 5cb0b5f — tests/sys/fs/tarfs tarfs_test.sh, usr.bin/gh-bc/tests dc_tests.sh bc_tests.sh

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+78-19tests/sys/fs/tarfs/tarfs_test.sh
+1-1usr.bin/gh-bc/tests/dc_tests.sh
+1-1usr.bin/gh-bc/tests/bc_tests.sh
+80-213 files

HardenedBSD/src 377c16e — lib/clang/libllvm Makefile, share/man/man5 src.conf.5

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+42-101usr.sbin/makefs/cd9660.c
+6-83lib/clang/libllvm/Makefile
+27-0sys/dev/nvme/nvme.h
+11-2sys/dev/nvme/nvme_ctrlr.c
+1-6share/man/man5/src.conf.5
+2-4usr.sbin/makefs/cd9660/cd9660_eltorito.c
+89-19626 files not shown
+105-25032 files

HardenedBSD/src 580bd64 — tests/sys/fs/tarfs tarfs_test.sh, usr.bin/gh-bc/tests dc_tests.sh bc_tests.sh

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+78-19tests/sys/fs/tarfs/tarfs_test.sh
+1-1usr.bin/gh-bc/tests/dc_tests.sh
+1-1usr.bin/gh-bc/tests/bc_tests.sh
+80-213 files

HardenedBSD/src fc544d3 — usr.sbin/makefs makefs.8, usr.sbin/makefs/cd9660 cd9660_eltorito.c

makefs: Remove unused "mac68k" support

Obtained from:  OpenBSD 4f3c7809d4013a2eb3e75fc5e7bd2d8ae1f41843
DeltaFile
+2-4usr.sbin/makefs/cd9660/cd9660_eltorito.c
+0-1usr.sbin/makefs/makefs.8
+2-52 files

HardenedBSD/src dd16a5f — sys/kern kern_lockf.c

lockf: Do not block in vfs_busy()

A race is possible otherwise: vfs_busy() may return after an unmounted
filesystem has been removed from the global mount list.  That is,
vfs_busy() will block until vfs_mount_destroy() sets MNTK_REFEXPIRE, and
at that point the mountpoint has been removed from the mountlist, so
TAILQ_FOREACH can return an invalid value.

Simply do not block if the mountpoint is being unmounted.

Reviewed by:    kib
Fixes:          eca39864f702 ("Add sysctl KERN_LOCKF")
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59982
DeltaFile
+1-1sys/kern/kern_lockf.c
+1-11 files

HardenedBSD/src c14281f — tests/sys/kern unix_connectat.c

tests/sys/kern: skip unix_connectat fdescfs cases when fdescfs is missing

unix_connectat's fdescfs cases call mount_fdescfs(), which skipped on ENODEV.
nmount(2) never returns ENODEV: vfs_donmount() remaps the ENODEV from a failed
fdescfs module load to EINVAL with errmsg "Invalid fstype", so the skip never
fired and the cases failed on kernels without fdescfs.

Approved by:    ngie, asomers
Sponsored by:   Netflix
Differential Revision:  https://reviews.freebsd.org/D59227
DeltaFile
+1-3tests/sys/kern/unix_connectat.c
+1-31 files

HardenedBSD/src 884b961 — usr.sbin/makefs makefs.h ffs.c

makefs: Make target filesystem inodes 64 bits

Obtained from:  NetBSD 2501d4dfda92, 7022656d8ab2
DeltaFile
+2-2usr.sbin/makefs/ffs.c
+1-1usr.sbin/makefs/makefs.h
+3-32 files

HardenedBSD/src 742e58d — sys/vm vm_page.c

vm_page: Fix the error path in vm_page_alloc_contig_domain()

If we are inserting a run of pages into a VM object and fail at some
point due to a memory allocation failure, we have to free all of the
pages in the run.  We do that by resetting some fields and calling
vm_page_free_toq() on each page; this removes the page from the object
and frees it back to the buddy allocator.

If the page is supposed to be wired, we reset the reference count, but
this was done incorrectly: the VPRC_OBJREF flag must be retained as the
page still belongs to an object.  Resetting it to zero will cause a
panic in vm_page_free_prep(): vm_page_free_object_prep() will subtract
VPRC_OBJREF from the refcount, causing underflow, and
vm_page_free_prep() subsequently calls panic() if the refcount is
non-zero.

Reviewed by:    alc, kib
Fixes:          fee2a2fa3983 ("Change synchonization rules for vm_page reference counting.")
MFC after:      1 week

    [2 lines not shown]
DeltaFile
+1-1sys/vm/vm_page.c
+1-11 files

HardenedBSD/src b9811d1 — usr.sbin/makefs cd9660.c

cd9660: merge level 1 and 2 filename conversion

Merge the nearly identical level 1 and level 2 filename conversion
functions and add output buffer bounds checking.

Always NUL-terminate the converted filename, allowing the redundant
memset() in cd9660_translate_node_common() to be removed.

Signed-off-by: Manuel Einfalt <einfalt1 at proton.me>
Reviewed by: emaste
Pull request: https://github.com/freebsd/freebsd-src/pull/2443
DeltaFile
+42-101usr.sbin/makefs/cd9660.c
+42-1011 files

HardenedBSD/src d2cce99 — tools/build/options WITHOUT_GCC_BOOTSTRAP WITHOUT_GCC

build/options: Remove old, obolsete GCC options

These aren't referenced in the tree anymore, so remove them from
here. This doesn't chanage src.conf.5, so I didn't commit that file.

Sponsored by:           Netflix
DeltaFile
+0-3tools/build/options/WITH_GCC_BOOTSTRAP
+0-3tools/build/options/WITH_GCC
+0-1tools/build/options/WITHOUT_GCC_BOOTSTRAP
+0-1tools/build/options/WITHOUT_GCC
+0-84 files

HardenedBSD/src b99595c — sys/dev/nvme nvme.h nvme_ctrlr.c

nvme: derive CC.CSS from CAP.CSS instead of hardcoding the NVM set

CC.CSS was always writting zero, which is a reserved encoding on a
controller that does not support the NVM command set.
Select 111b on admin-only controllers and 110b when the
I/O command set mechanism is available.

Reviewed by:    ngie, imp, adrian
Differential Revision:  https://reviews.freebsd.org/D59628
DeltaFile
+11-2sys/dev/nvme/nvme_ctrlr.c
+9-0sys/dev/nvme/nvme.h
+20-22 files

HardenedBSD/src 2c41f7d — sbin/nvmecontrol identify.c format.c, sys/dev/nvme nvme_ns.c nvme.h

nvme: honor FLBAS Format Index Upper when selecting the LBA format

Added nvme_ns_data_format_index() in the nvme, nda, and nvmf
host paths as well as nvmecontrol and camdd.

Reviewed by:    imp, adrian
Differential Revision:  https://reviews.freebsd.org/D59627
DeltaFile
+18-0sys/dev/nvme/nvme.h
+2-2sys/dev/nvmf/host/nvmf_ns.c
+2-2sys/dev/nvme/nvme_ns.c
+1-1sbin/nvmecontrol/identify.c
+1-1sbin/nvmecontrol/format.c
+1-1sbin/nvmecontrol/devlist.c
+25-72 files not shown
+27-98 files