HardenedBSD/src 612eb89share/examples/jails jail.xxx.conf jng, sys/dev/ice if_ice_iflib.c ice_lib.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+14-14share/examples/jails/jng
+10-10share/examples/jails/jail.xxx.conf
+10-5sys/dev/ice/ice_lib.c
+12-2sys/sys/sched.h
+9-0sys/dev/ice/if_ice_iflib.c
+3-1sys/dev/usb/wlan/if_rsu.c
+58-324 files not shown
+63-3410 files

HardenedBSD/src c900b0cshare/examples/jails jail.xxx.conf jng, sys/dev/ice if_ice_iflib.c ice_lib.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+14-14share/examples/jails/jng
+10-10share/examples/jails/jail.xxx.conf
+10-5sys/dev/ice/ice_lib.c
+12-2sys/sys/sched.h
+9-0sys/dev/ice/if_ice_iflib.c
+3-1sys/dev/usb/wlan/if_rsu.c
+58-324 files not shown
+63-3410 files

HardenedBSD/src c4bca1fshare/examples/jails jail.xxx.conf jng

New version of jng (9.2)

Use jail.conf(5) $name in the jail.conf examples so the jail name
need only be set on the stanza. Keep host.hostname as xxx.yyy;
a jail name is not a DNS label. Leave the rc.conf excerpt as xxx.

Suggested by:   jlduran
MFC after:      1 week
Reviewed by:    kfv, jlduran
Differential Revision:  https://reviews.freebsd.org/D59032
DeltaFile
+14-14share/examples/jails/jng
+10-10share/examples/jails/jail.xxx.conf
+24-242 files

HardenedBSD/src 0011cd9sys/dev/ice ice_lib.h ice_strings.c

ice(4): Support Total Port Shutdown on E830 devices

When 'Permit Total Port Shutdown' feature in BIOS is enabled then Port
Disable bit is set in the Link Default Override Mask TLV PFA module
in the NVM. In this mode, the driver acts as if the link_active_on_if_down
flag is always disabled and disallow any change to that flag.
This feature applies for E830 and E835 NIC series.

Signed-off-by: Pawel Sobczyk <pawel.sobczyk at intel.com>

Tested by:      Mateusz Moga <mateusz.moga at intel.com>
MFC after:      2 weeks
Sponsored by:   Intel Corporation
Differential Revision:  https://reviews.freebsd.org/D58149
DeltaFile
+10-5sys/dev/ice/ice_lib.c
+9-0sys/dev/ice/if_ice_iflib.c
+2-0sys/dev/ice/ice_strings.c
+1-0sys/dev/ice/ice_lib.h
+22-54 files

HardenedBSD/src 81a67bfsys/dev/usb/wlan if_rsu.c

rsu: add a runtime TX buffer bound check for a kernel buffer overflow

The rsu driver currently relies on a `KASSERT` to prove that the mbuf payload
plus TX descriptor fits in the per-transfer USB TX buffer. On production
kernels without `INVARIANTS`, an oversized raw 802.11 frame can reach
`m_copydata()` and overwrite past that buffer, causing local kernel memory
corruption.

This suggested patch replaces the assertion-only guard with a runtime size
check before the copy. Oversized frames return `EMSGSIZE`, leaving the existing
caller cleanup paths responsible for freeing `m0`, `ni`, and the unused
transfer buffer.

Reachable via root / bpf access

Reviewed by:    bz, adrian
MFC after:      1 week
Differential Revision:  https://reviews.freebsd.org/D58898
DeltaFile
+3-1sys/dev/usb/wlan/if_rsu.c
+3-11 files

HardenedBSD/src 7e9e72bsys/dev/usb/wlan if_mtwvar.h

mtw: fix zero-length queue array that can corrupt struct mtw_softc

The mtw softc declares sc_epq with MTW_BULK_RX even though MTW_BULK_RX is enum
value 0, while initialization and queue handling index up to MTW_EP_QUEUES;
attaching a matching USB WLAN device can drive writes past the absent array and
corrupt adjacent softc fields.

This suggested patch sizes sc_epq with MTW_EP_QUEUES so the softc contains the
endpoint queues the driver initializes and uses.

Fixes:          c14b01624261 ("mt7601U: Importing if_mtw from OpenBSD")
Reviewed by:    bz
MFC after:      1 week
Differential Revision:  https://reviews.freebsd.org/D58897
DeltaFile
+1-1sys/dev/usb/wlan/if_mtwvar.h
+1-11 files

HardenedBSD/src f236685sys/sys sched.h

kern/sched: Hide scheduler selection from C++

The scheduler selection interface uses names that are reserved words in
C++, causing problems for downstream projects that use C++ in the
kernel.  Work around this by hiding the interface from C++ compilers
until we can come up with a better solution.

Fixes:          ce38acee8d0b ("Add kern/sched_shim.c")
MFC after:      1 week
Sponsored by:   Klara, Inc.
Sponsored by:   NetApp, Inc.
Reviewed by:    siderop1_netapp.com, imp, kib
Differential Revision:  https://reviews.freebsd.org/D58991
DeltaFile
+12-2sys/sys/sched.h
+12-21 files

HardenedBSD/src 2ff0ca5lib/libc/gen Makefile.inc

uexterror(3): install the right manpage

Reported by:    Herbert J. Skuhra
DeltaFile
+1-1lib/libc/gen/Makefile.inc
+1-11 files

HardenedBSD/src ee230b3include uexterror.h, lib/libc/gen uexterr_init.c uexterr_set.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+165-2lib/libc/gen/uexterr_format.c
+135-0lib/libc/gen/uexterror.3
+100-0tests/sys/kern/exterr_test.c
+65-0include/uexterror.h
+50-0lib/libc/gen/uexterr_set.c
+26-0lib/libc/gen/uexterr_init.c
+541-210 files not shown
+580-3116 files

HardenedBSD/src 10fbfa9include uexterror.h, lib/libc/gen uexterr_init.c uexterr_set.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+165-2lib/libc/gen/uexterr_format.c
+135-0lib/libc/gen/uexterror.3
+100-0tests/sys/kern/exterr_test.c
+65-0include/uexterror.h
+50-0lib/libc/gen/uexterr_set.c
+26-0lib/libc/gen/uexterr_init.c
+541-210 files not shown
+580-3116 files

HardenedBSD/src 94f86eftests/sys/kern exterr_test.c

uexterror_gettext: add tests for invalid formats

Verify that unsupported, unterminated, and overly long formats output
expected messages.

Reviewed by:    kib
Effort:         CHERI upstreaming
Sponsored by:   Innovate UK
Differential Revision:  https://reviews.freebsd.org/D58413
DeltaFile
+66-0tests/sys/kern/exterr_test.c
+66-01 files

HardenedBSD/src ddf6065tests/sys/kern exterr_test.c

exterr(9): add a few tests of new message formats

This is enough to show that the idea works (and to exercise
uexterr_set()), but isn't complete by any means.

Reviewed by:    kib
Effort:         CHERI upstreaming
Sponsored by:   Innovate UK
Differential Revision:  https://reviews.freebsd.org/D58060
DeltaFile
+34-0tests/sys/kern/exterr_test.c
+34-01 files

HardenedBSD/src 95e3309include uexterror.h, lib/libc/gen uexterr_gettext.c uexterr_init.c

runtime: add the ability to set exterrors in userspace

The UEXTERROR(3) macro is a partial analog to EXTERROR(9) that sets
the current user exterror state and errno.  The main difference is
that it returns no value and sets errno directly since that's the
typical pattern in libraries.

While here move the storage and constructor for single-threaded
program's uexterr to its own file.

Reviewed by:    kib
Effort:         CHERI upstreaming
Sponsored by:   Innovate UK
Differential Revision:  https://reviews.freebsd.org/D58059
DeltaFile
+135-0lib/libc/gen/uexterror.3
+65-0include/uexterror.h
+50-0lib/libc/gen/uexterr_set.c
+26-0lib/libc/gen/uexterr_init.c
+0-18lib/libc/gen/uexterr_gettext.c
+13-0lib/libthr/thread/thr_syscalls.c
+289-186 files not shown
+304-1912 files

HardenedBSD/src 2f024a7lib/libc/gen uexterr_format.c, share/man/man9 exterror.9

exterr: relax format restrictions

Rather than passing the format string to printf and forcing the
arguments to be (u)intmax_t, partially parse format strings and cast
p1 and p2 to the correct type before running the individual format
though printf.  This restructure has a couple motivatations:
 - We can skip formats that make no sense (floating point, %n, etc.).
 - It is possible to special case the printing of pointers in the
   CHERI case.

The first case is motivated by a suggestion from the audiance at
one of Kirk's BSDCan talks on exterr to allow userspace to set exterr
status.  Allowing arbitrary format strings including %n creates a
write-what-where gadget so we need to not do that.

The second case is motivated by our experinces with CHERI and debugging
mmap issues using a different textual error reporting framework.  With
CHERI, pointers are more than integer addresses and it's useful to
include more details.  Doing so will follow in a future commit.

    [8 lines not shown]
DeltaFile
+165-2lib/libc/gen/uexterr_format.c
+10-7share/man/man9/exterror.9
+175-92 files

HardenedBSD/src d58ca84tools/test/stress2/misc socketpair3.sh

Fix zombie leak in test using pdfork()
DeltaFile
+1-1tools/test/stress2/misc/socketpair3.sh
+1-11 files

HardenedBSD/src 8eb77a5tools/test/stress2/misc all.exclude

stress2: Enable two hwpmc tests that now run as expected
DeltaFile
+0-2tools/test/stress2/misc/all.exclude
+0-21 files

HardenedBSD/src 0f7139bshare/examples/jails jail.xxx.conf jng, sys/dev/e1000 if_em.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+47-7sys/dev/e1000/if_em.c
+12-6share/examples/jails/jng
+9-1usr.sbin/jail/jail.8
+1-6sys/fs/tarfs/tarfs_vfsops.c
+2-2usr.bin/login/motd.template
+2-1share/examples/jails/jail.xxx.conf
+73-232 files not shown
+77-248 files

HardenedBSD/src 691ab8ashare/examples/jails rcjail.xxx.conf jail.xxx.conf, sys/dev/e1000 if_em.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+47-7sys/dev/e1000/if_em.c
+12-6share/examples/jails/jng
+9-1usr.sbin/jail/jail.8
+1-6sys/fs/tarfs/tarfs_vfsops.c
+2-1share/examples/jails/rcjail.xxx.conf
+2-1share/examples/jails/jail.xxx.conf
+73-221 files not shown
+75-227 files

HardenedBSD/src 3abca40lib/msun/src catrig.c, sys/dev/fxp rcvbundl.h

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+1-1sys/netpfil/ipfw/dn_sched_fq_pie.c
+1-1sys/fs/nullfs/null_vnops.c
+1-1sys/dev/ppbus/ppb_msq.h
+1-1sys/dev/ichwd/i6300esbwd.c
+1-1sys/dev/fxp/rcvbundl.h
+1-1lib/msun/src/catrig.c
+6-61 files not shown
+7-77 files

HardenedBSD/src aeec956sys/fs/nullfs null_vnops.c

nullfs(4): Fix a typo in a source code comment

- s/modifing/modifying/

(cherry picked from commit 27c70deb3d260b48bee8f3c4c975fd2de64264fb)
DeltaFile
+1-1sys/fs/nullfs/null_vnops.c
+1-11 files

HardenedBSD/src 4fb09e9sys/dev/ichwd i6300esbwd.c

ichwd(4): Fix a typo in a source code comment

- s/modifing/modifying/

(cherry picked from commit 8362aecdeb2548813942a7e604543c71f5a10271)
DeltaFile
+1-1sys/dev/ichwd/i6300esbwd.c
+1-11 files

HardenedBSD/src 4054710sys/dev/fxp rcvbundl.h

fxp(4): Fix a typo in a source code comment

- s/modifing/modifying/

(cherry picked from commit c47b430c6ea3aa8d133af0af426d018bae3b7018)
DeltaFile
+1-1sys/dev/fxp/rcvbundl.h
+1-11 files

HardenedBSD/src 9e62481sys/netpfil/ipfw dn_sched_fq_pie.c

ipfw(4): Fix a typo in a source code comment

- s/varaiables/variables/

(cherry picked from commit 251e6ef40203a6f911d7f4daacf3075de7f870c0)
DeltaFile
+1-1sys/netpfil/ipfw/dn_sched_fq_pie.c
+1-11 files

HardenedBSD/src bbf2339lib/msun/src catrig.c

msun: Fix a typo in a source code comment

- s/uneccessarily/unnecessarily/

Obtained from:  NetBSD

(cherry picked from commit cd4aae2fa9d35015248c445752e23800e75e8517)
DeltaFile
+1-1lib/msun/src/catrig.c
+1-11 files

HardenedBSD/src 352cf5bsys/vm swap_pager.c

swap_pager: Fix a typo in a source code comment

- s/errornous/erroneous/

(cherry picked from commit 88293bdd1eefb4bf518e1764d370b4a2321afdd1)
DeltaFile
+1-1sys/vm/swap_pager.c
+1-11 files

HardenedBSD/src c3b7f92sys/dev/ppbus ppb_msq.h

ppbus(4): Fix a typo in a source code comment

- s/predifined/predefined/

(cherry picked from commit 709bd45a1b3a5ca21e05995c0c01f0ee8e7e8c38)
DeltaFile
+1-1sys/dev/ppbus/ppb_msq.h
+1-11 files

HardenedBSD/src aec0f1bsys/dev/e1000 if_em.c

e1000: Report 82571 packet buffer ECC errors

The 82571 PBA_ECC register contains a 12-bit count of packet buffer ECC
detections.  The shared code enables single-bit correction, but neither
FreeBSD nor the DPDK base driver consumes the counter.

Sample it with the ordinary statistics timer, accumulate the value under
dev.em.N.memory_errors.detected_packet_buffer, and clear the hardware
counter while preserving correction and reserved register state.  Do not
enable its shared interrupt: the register does not distinguish corrected
from uncorrectable events and does not provide a safe fatal recovery
policy.

Validated on a dual port 82571EB.  Both functions reported zero after a
clean boot, and a controlled link down/up cycle left the counter at zero
while the management link recovered at 1 Gb/s without issue.

MFC after:      2 weeks
Sponsored by:   BBOX.io
DeltaFile
+47-7sys/dev/e1000/if_em.c
+47-71 files

HardenedBSD/src 8d83b10share/examples/jails rc.conf.jails rcjail.xxx.conf

New version of jng (9.1)

Update examples and comments to return eifaces in exec.prestop
with ifconfig -vnet (before jng shutdown in poststop).

Reported by:    jlduran
PR:             268397
MFC after:      1 week
Reviewed by:    kfv, jlduran
Differential Revision:  https://reviews.freebsd.org/D58939
DeltaFile
+12-6share/examples/jails/jng
+2-1share/examples/jails/rcjail.xxx.conf
+2-1share/examples/jails/jail.xxx.conf
+2-0share/examples/jails/rc.conf.jails
+18-84 files

HardenedBSD/src ba99013sys/fs/tarfs tarfs_vfsops.c, usr.sbin/jail jail.8

tarfs: allow mounting inside jails

Reviewed by:    des
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D58833
DeltaFile
+9-1usr.sbin/jail/jail.8
+1-1sys/fs/tarfs/tarfs_vfsops.c
+10-22 files

HardenedBSD/src 4d52491sys/fs/tarfs tarfs_vfsops.c

tarfs: remove PRIV_VFS_MOUNT_PERM check

The backing file is already opened successfully, so there is
no need to override the permissions.

Reviewed by:    des
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D58832
DeltaFile
+0-5sys/fs/tarfs/tarfs_vfsops.c
+0-51 files