bsnmp: validate the lower bound of error_index in responses
Check if the response's error_index is within a sane interval.
Otherwise, a rogue peer could crash us.
PR: 298222
Reported by: Robert Morris
Reviewed by: markj
Discussed with: secteam (markj)
MFC after: 2 weeks
Analyzed with: Claude Code Opus 5
(cherry picked from commit 296e3fd54ca8972fa6696974097a2f2705f8dfc4)
dummynet: do not overflow the points[ED_MAX_SAMPLES_NO] array
Otherwise, the following would segfault
dnctl pipe 1 config bw 1Mbit/s profile 1025points.txt
Found with: Claude Code Sonnet 5
MFC after: 2 weeks
(cherry picked from commit 04fcf30961266cd77139b40774cb0d6ef6eb2be5)
rtld.c: avoid double-free on dso load failure in do_load_object()
The obj->path is assigned directly from the path argument, and
load_object() frees the path on do_load_object() failure. Do not free
it in obj_free() on the error path.
Reviewed by: markj
Sponsored by: The FreeBSD Foundation
MFC after: 1 week
Differential revision: https://reviews.freebsd.org/D60402
stand: userboot: improve userdisk error handling
Currently, userdisk_init() iterates through disks and
checks whether DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls
are available for the device. If either ioctl fails, userdisk_init()
returns ENXIO with ud_info only partially initialized.
devinit() records the failure, but loader_main() ignores
devinit()'s return value, so later code may access an
uninitialized entry.
In certain cases this code can still boot from a disk even if
userdisk_init() returns ENXIO, for example, when the first of
two disks is valid and the second errors out.
To address this issue while not breaking the current behavior, do
the following:
- Zero-initialize the userdisk_info array and use a zero media size
to mark disks that do not support the ioctls mentioned above or
[14 lines not shown]
Merge commit c4ce37507537 from llvm-project (by ShengYi Hung):
[Clang][Sema] Create LocalScope for Variable Template (#228280)
A variable template should create its own LocalScope, as it should be
opaque to other instantiations. This can occur when there are multiple
instantiations in the same lexical scope. The correct behavior is that
these instantiations should not be chained together.
Assisted-by: Claude # Test ReleaseNote
Fixes: #134148
This fixes an assertion while building the devel/glaze port.
PR: 276265
MFC after: 3 days
(cherry picked from commit fe9c7137871ee0b5c48d4c38b87d80f72e73379e)
llvm: add LoongArch target support, not enabled by default
Note there is ongoing work to add LoongArch support to the base system,
but having target support in llvm is an essential component.
This must be explicitly enabled using WITH_LLVM_TARGET_LOONGARCH.
Reviewed by: dim
MFC after: 1 week
Differential Revision: https://reviews.freebsd.org/D59899
(cherry picked from commit 2f49e40a684a4bffd8e368a6878384ec4f735ea8)
Merge commit 80e8c0a59189 from llvm-project (by ShengYi Hung):
[DebugInfo] Fill Column 0 if Line is not found (#227559)
It is possible that user specified line 0 as the start of the line in C
language (using `# 0`). However, it is rejected by the Lexer as we have
no line but still carries column information. As a result, we fill
column to 0 if we cannot find line.
Assisted-by: Claude # Test
Fixes: #56186
This fixes a fatal error when building the textproc/peg port.
PR: 264853
MFC after: 3 days
(cherry picked from commit 37c9eba1644b0f9e1b5d130ccff381122f48aebe)
sched.h: Fix a typo and remove an extra line
Fixes: 42490d5cd29d ("sched: New scheduler interface definition scheme")
Sponsored by: The FreeBSD Foundation
sched: New scheduler interface definition scheme
Define the scheduler interface once and for all (in 'sys/sys/sched.h')
and remove all code duplication related to it (function signatures, slot
names, dispatch, scheduler instance declaration), making it easier to
modify the interface or to add new schedulers.
This is implemented by defining the interface as X macros, which are
passed a macro (and additional arguments for it) that is "called" with
a variable number of arguments describing a single function of the
interface. The convention used for a function's parameters is that each
parameter is represented with two macro arguments, the first one being
the type and the second one being the name. Helper macros allow to
process arguments described in this convention in order to generate
a list of arguments for function definitions (currently, up to
4 function parameters). The chosen convention eliminates the need for
any specific declaration of functions depending on their number of
arguments.
[48 lines not shown]
bhyveload: validate character disk devices
Currently, bhyveload(8) does not validate the supplied disk
image path. For example, it allows passing the /dev/null
device, which later fails in userboot because it does not
support DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls (see
userdisk_init() in stand/userboot/userboot/userboot_disk.c).
Fix that by checking DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls early.
A similar check already exists in bhyve(8). While here, make
cb_diskioctl() report the obtained sector size instead of
hard-coding 512.
Reviewed by: markj
MFC after: 2 weeks
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59253
(cherry picked from commit 51234535ddd6ec0afe9dd4e3f34a31b92d5cdd78)
libcasper: tolerate kernels without PD_NOWAITPID
Commit 1a296762b3d0 made libcasper pass PD_NOWAITPID to pdfork(2).
Kernels predating the flag (15.1 and earlier, since the flag first
ships in 15.2) reject it with EINVAL, which makes cap_init() and every
service fork fail when a newer world runs on an older kernel, for
example in a poudriere jail.
Add casper_pdfork(), which retries without the flag on EINVAL, and use
it at both pdfork(2) call sites. The retry is safe because the kernel
validates pdfork flags before creating a child. On such kernels the
zombie must still be reaped with waitpid(2), as before the flag was
introduced.
The fallback is compiled out once __FreeBSD_version reaches 1700000,
so it disappears from main when stable/16 branches while remaining in
the stable/15 and stable/16 branches that need it.
Reviewed by: kib
[3 lines not shown]
ufshci: build the ioctl file into the kernel
The passthrough ioctl went into the module build only. A kernel with
device ufshci then failed to link, because ufshci_ctrlr.c calls
ufshci_ioctl_construct() and ufshci_ioctl_destruct() and neither was
compiled in.
Add the file to sys/conf/files.
Fixes: 28fefc441e3b ("ufshci: add a control device node")
Sponsored by: Samsung Electronics
(cherry picked from commit d435248a2196bc78f626850a7ae700aaeace1c13)
ufshci: add a control device node
The driver only exposed a CAM SIM. Userland had no way to reach the
device for anything that is not a SCSI command, so reading a descriptor
or an attribute was impossible.
Add /dev/ufshci%d as a root only node and the ioctl ABI header for it.
The node answers no ioctl yet. The header pulls in ufshci.h, which
declares bool only under _KERNEL, so include stdbool.h for userland the
way nvme.h already does.
Reviewed by: imp (mentor)
Sponsored by: Samsung Electronics
Differential Revision: https://reviews.freebsd.org/D59558
(cherry picked from commit 28fefc441e3b701acc2888892a518774394255c7)
ufshci: install the ioctl header
The passthrough ioctl has a userland ABI header, but nothing installed
it. A program that wanted to use the ioctl had to copy the headers out
of the source tree by hand.
Install ufshci.h and ufshci_ioctl.h under /usr/include/dev/ufshci, the
way nvme installs nvme.h. The ioctl header pulls in ufshci.h, so both
go. Add the directory to the include mtree so installworld creates it.
Reviewed by: imp (mentor)
Sponsored by: Samsung Electronics
Differential Revision: https://reviews.freebsd.org/D59560
(cherry picked from commit 8895b1348f3d21e2db16a06f31d555be0471e36d)
ufshci: add a passthrough ioctl
This ioctl is for a port of ufs-utils:
https://github.com/SanDisk-Open-Source/ufs-utils
The driver only exposed a CAM SIM. Reading a descriptor, an attribute
or a flag needs a query request, and a UniPro attribute needs a DME
command. The driver built both only for its own setup, so userland
could reach neither.
Add two ioctls on the control node. UFSHCI_PASSTHROUGH_CMD sends a
UPIU the caller built, sizes the request from its transaction code,
and copies the response UPIU back. UFSHCI_PASSTHROUGH_UIC carries the
four attribute commands and refuses the rest, which can drop the link
or power the device off. It keeps the raw argument2 so the caller can
read the result code the device reported, not just a failure.
Validate the input and bound it by what the controller can map. The
descriptor has no request length, so the controller reads it from the
[12 lines not shown]
ufshci: tell the controller how long the EHS is
The transfer request descriptor has a field for the total Extra Header
Segment length. The driver left it at zero. A request that carried an
EHS went out as the bare command UPIU, and the device answered a request
it had only seen part of.
Fill the field from the request UPIU header, which already carries the
same length. Every other path sets it to zero, so nothing else changes.
An EHS is the first thing that makes a request vary in size, so assert
that the request and the response still fit in the command descriptor.
Reviewed by: imp (mentor)
Sponsored by: Samsung Electronics
Differential Revision: https://reviews.freebsd.org/D59557
(cherry picked from commit d3e5082ce4dcb154cbf50cba05d8f1dbbd55a5fc)
ufshci: skip the reinit when the new link works
UFSHCI_QUIRK_REINIT_AFTER_MAX_GEAR_SWITCH always rebuilt the
link after the gear switch. It threw away a working HS link and
ended up in PWM. The reinit is only needed for a dead link.
There the local side reports HS and the peer never answers. A
local readback cannot tell the two apart. Peer traffic can.
Probe the peer with DME_PEER_GET after the switch. Skip the
reinit when the probe succeeds. Log it when the probe fails.
Reviewed by: imp (mentor)
Sponsored by: Samsung Electronics
Differential Revision: https://reviews.freebsd.org/D59299
(cherry picked from commit 9930150214d1ca4ad21561d2e0afce9ebf2cdf6c)
ufshci: set HS series per platform and adapt type per gear
The driver always asked for Rate-B. It never set the adaptation
type. The Snapdragon X Elite firmware tunes the PHY for Rate-A.
A Rate-B link dies at every gear there. HS-G4 and above need
initial adaptation. This is a UniPro rule. It applies to
every host.
Add an hs_series field to the device tables. Use Rate-A on the
Snapdragon X Elite. Keep Rate-B on the PCI hosts. A table entry
without an HS series fails to attach. Set PA_TxHsAdaptType to
initial adaptation at HS-G4 and above. Leave it alone below
that. Hosts before UniPro 1.8 do not have it. The Galaxy Book
4 Edge now links at HS-G5 Rate-A.
fio results (128k sequential, 4k random, posixaio):
QD | SEQ_R(MiB/s) | SEQ_W(MiB/s) | RND_R(kIOPS) | RND_W(kIOPS)
----+--------------+--------------+--------------+-------------
[12 lines not shown]
ufshci: fix the Snapdragon X Elite reference clock
The driver's ACPI table set bRefClkFreq to 19.2 MHz. The
Snapdragon X Elite feeds the device 38.4 MHz from its CXO. The
firmware has no property for it. The device ran its PLL from
the wrong base. Every HS mode failed. PWM still worked. The
attribute is persistent. The wrong value survived reboots.
Set 38.4 MHz in the table. Read the attribute first. Write it
only when the value differs or the read fails. Log a changed
value and a failed read. Verified on the Galaxy Book 4 Edge.
Reviewed by: imp (mentor)
Sponsored by: Samsung Electronics
Differential Revision: https://reviews.freebsd.org/D59297
(cherry picked from commit 973783515e7db6e19550c57c8f9d94d907e3bd0e)
ufshci: reject new requests on a failed controller
A failed controller accepted new requests, but nothing ever
completed them, so the caller waited forever. The admin retry
path could also resubmit a request to a dead queue.
Reject new submits and admin retries on a failed controller.
The submit check runs under the queue lock, so it cannot race
with the queue walk in the fail path.
Reviewed by: imp (mentor)
Sponsored by: Samsung Electronics
Differential Revision: https://reviews.freebsd.org/D58948
(cherry picked from commit 3ecee9314d88e2bb277b365d9413e219fd9a1283)