HardenedBSD/src 545d872lib/libbsdconf bsdconf_stmt.c bsdconf_format.3, usr.sbin/sysconf sysconf.8 sysconf.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/cross-dso-cfi
DeltaFile
+762-0usr.sbin/sysconf/sysconf.c
+733-0lib/libbsdconf/bsdconf.c
+708-0usr.sbin/sysconf/sysconf.8
+693-0lib/libbsdconf/bsdconf_format.c
+560-0lib/libbsdconf/bsdconf_format.3
+547-0lib/libbsdconf/bsdconf_stmt.c
+4,003-054 files not shown
+10,425-3060 files

HardenedBSD/src 12d8da8lib/libbsdconf bsdconf_stmt.c bsdconf_format.3, usr.sbin/sysconf sysconf.8 sysconf.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+762-0usr.sbin/sysconf/sysconf.c
+733-0lib/libbsdconf/bsdconf.c
+708-0usr.sbin/sysconf/sysconf.8
+693-0lib/libbsdconf/bsdconf_format.c
+560-0lib/libbsdconf/bsdconf_format.3
+547-0lib/libbsdconf/bsdconf_stmt.c
+4,003-054 files not shown
+10,425-3060 files

HardenedBSD/src ef95cd8share/man/man4 Makefile

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+2-1share/man/man4/Makefile
+2-11 files

HardenedBSD/src 3b301d7lib/libbsdconf bsdconf_stmt.c bsdconf_format.3, usr.sbin/sysconf sysconf.8 sysconf.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+762-0usr.sbin/sysconf/sysconf.c
+733-0lib/libbsdconf/bsdconf.c
+708-0usr.sbin/sysconf/sysconf.8
+693-0lib/libbsdconf/bsdconf_format.c
+560-0lib/libbsdconf/bsdconf_format.3
+547-0lib/libbsdconf/bsdconf_stmt.c
+4,003-050 files not shown
+10,411-2656 files

HardenedBSD/src b5a49a1share/man/man4 Makefile

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+2-1share/man/man4/Makefile
+2-11 files

HardenedBSD/src 0380d01lib/libbsdconf bsdconf.h bsdconf.c, usr.sbin/sysconf sysconf_priv.h sysconf.c

libbsdconf: independent version macros

sysconf(8) --version now prints the library version alongside its
own so each can move on its own clock.  Assigning a bitmask to
bool already converts zero/nonzero; drop the redundant != 0 (fuz).

Reviewed by:    fuz, kfv
Differential Revision:  https://reviews.freebsd.org/D59720
DeltaFile
+11-11lib/libbsdconf/bsdconf_put.c
+6-6lib/libbsdconf/bsdconf.c
+6-2usr.sbin/sysconf/sysconf.8
+8-0lib/libbsdconf/bsdconf.h
+3-2usr.sbin/sysconf/sysconf.c
+1-1usr.sbin/sysconf/sysconf_priv.h
+35-226 files

HardenedBSD/src 3fe5961lib/libbsdconf bsdconf_stmt.c bsdconf_format.3, usr.sbin/sysconf sysconf.8 sysconf.c

Add sysconf(8) and libbsdconf(3)

Complete the native configuration trinity: sysctl(8) for live kernel
state, sysrc(8) for rc.conf(5), and sysconf(8) for the remaining base
configuration -- loader.conf(5), sysctl.conf(5), and the make.conf(5)
family -- atop libbsdconf(3).

libbsdconf resurrects figpar as a unified reader/writer.  Callbacks own
semantics; statements may span multiple lines via backslash continuation;
non-seekable input is spooled; writes are atomic (mkstemp, fsync, rename)
with mode/owner preservation.  Format descriptors name each target, its
files, and quoting rules without private parsers.  Multi-file targets
follow boot sourcing order; loader chases loader_conf_files as the boot
loader does.

sysconf(8) is the operator-facing tool: name / name=value on a required
target, sysrc-style list edits, make append and list-strike where they
belong, jail/altroot, and a capsicum sandbox for read-only use.


    [21 lines not shown]
DeltaFile
+761-0usr.sbin/sysconf/sysconf.c
+733-0lib/libbsdconf/bsdconf.c
+704-0usr.sbin/sysconf/sysconf.8
+693-0lib/libbsdconf/bsdconf_format.c
+560-0lib/libbsdconf/bsdconf_format.3
+547-0lib/libbsdconf/bsdconf_stmt.c
+3,998-041 files not shown
+10,120-047 files

HardenedBSD/src f308d6dshare/man/man4 em.4, sys/dev/e1000 if_igbv.c

igbv: Recover disabled Hyper-V transmit queues

The Windows PF can disable a VF transmit queue while continuing to
report carrier up.  Link polling alone then leaves the VF operationally
up even though it cannot transmit.  The reproduced VLAN failure shows
this state with PF driver 14.1.5.0 and an MDD indication in the host trace.

Check queue zero from the admin path only while the Hyper-V VF is
running with sanitized queues and a completed host handshake.  Report
operational link down and invalidate the statistics baseline when the
queue is disabled.  Request recovery through the normal iflib stop/init
path only when a fresh, accessible STATUS read reports carrier up.
Rate limit requests if the host continues to hold the queue disabled,
and leave recovery pending while carrier is down.

Document the recovery behavior and clarify why the Hyper-V reset retains
the VF-local software reset before its host reset/MAC exchange.

Sponsored by:   BBOX.io
DeltaFile
+35-0sys/dev/e1000/if_igbv.c
+7-1share/man/man4/em.4
+42-12 files

HardenedBSD/src 2072f71share/man/man4 amdsmu.4

amdsmu.4: Canonicalize SYNOPSIS and HARDWARE

MFC after:              no
Reviewed by:            obiwac
Differential Revision:  https://reviews.freebsd.org/D59738
DeltaFile
+7-16share/man/man4/amdsmu.4
+7-161 files

HardenedBSD/src 13a598fshare/mk src.opts.mk bsd.prog.mk

HBSD: Add plumbing for bounds safety

clang/llvm is working on `-fbounds-safety`. This feature isn't available
in the version of llvm currently in base, but should be available in a
future release. Get ready for that release by adding a new src.conf(5)
knob: MK_BOUNDS_SAFETY (disabled by default).

Note that enabling this feature is effectively a no-op. Just like with
Capsicum, this feature requires manual integration.

Given that the bounds safety feature is still experimental, we enable
the feature with `-Xclang -fexperimental-bounds-safety`. Once clang/llvm
determines the feature to be production-ready (and that version of llvm
has been imported into base) we will update share/mk/bsd.sys.mk to take
into account the switch from the experimental flag to the actual
`-fbounds-safety` flag.

Signed-off-by:  Shawn Webb <shawn.webb at hardenedbsd.org>
See-Also:       https://clang.llvm.org/docs/BoundsSafety.html
See-Also:       https://clang.llvm.org/docs/BoundsSafetyImplPlans.html
DeltaFile
+3-4share/mk/bsd.sys.mk
+5-0share/mk/bsd.prog.mk
+5-0share/mk/bsd.lib.mk
+1-0share/mk/src.opts.mk
+14-44 files

HardenedBSD/src ed5fc80sys/dev/cxgbe/crypto t7_kern_tls.c

cxgbe: Use the correct GHASH offset for a GMAC from a full TLS record

If a TLS request transmits all but a part of the GMAC at the end of a
TLS record, the work request asks the crypto engine to return the
calculated GMAC to the driver so it can be sent in a simple TCP packet
when the rest of the TLS record is transmitted in the future.
However, the offset of the returned GHASH offset was calculated
incorrectly in this case causing the driver to not recognize the
cached GMAC and instead use a more wasteful work request in the future
that encrypted the entire TLS record discarding all but the needed
bytes of the trailer.

Note that this does not effect correctness, just efficiency.

Reviewed by:    np
Fixes:          9e269eafebfc ("cxgbe: Use partial GCM mode for partial TLS records on T7")
Sponsored by:   Chelsio Communications
Differential Revision:  https://reviews.freebsd.org/D59711
DeltaFile
+1-1sys/dev/cxgbe/crypto/t7_kern_tls.c
+1-11 files

HardenedBSD/src 50b3763sys/net if_vlan.c

vlan: Notify the parent when replacing a VLAN ID

Changing the VID of an existing VLAN interface rehashes the interface and
announces the new VID, but does not unregister the old VID.  Parent
drivers and VLAN event consumers can consequently retain stale filter
membership.

After successfully inserting the new VID, emit vlan_unconfig for the old
VID before the existing vlan_config notification.  Do not unregister
anything if insertion fails and the old VID is restored.

MFC after:      2 weeks
Sponsored by:   BBOX.io
DeltaFile
+2-0sys/net/if_vlan.c
+2-01 files

HardenedBSD/src 89ce1aashare/man/man4 em.4, sys/dev/e1000 if_em.h if_em.c

igbv: Support Hyper-V virtual functions

Use the Hyper-V reset/MAC exchange for 82576 and I350 VFs instead of the
native posted mailbox protocol, which the Windows PF does not service.
Read the host assigned address through configuration bytes 0x201 through
0x206 only during reset, and use it to identify the matching synthetic
hn(4) interface.  The operations are local to the VF frontend.

Poll hardware link status rather than retaining a native mailbox link
handshake.  Leave MAC, multicast, promiscuous-mode, and VLAN membership
policy with the host.  Disable guest VLAN registration and native receive
limit requests, and limit the VF to an MTU of 1500 bytes.

Preserve accumulated statistics across host resets without counting a
counter clear as a wrap.  Reject inaccessible register samples and rebase
after a reset indication or a disabled transmit queue, including when the
PF blocks the queue for malicious driver detection.

Document single queue support and host assigned access VLANs.  Guest VLAN

    [9 lines not shown]
DeltaFile
+103-0sys/dev/e1000/if_igbv.c
+77-5sys/dev/e1000/if_em.c
+26-3share/man/man4/em.4
+11-0sys/dev/e1000/if_em.h
+217-84 files

HardenedBSD/src 16c5abbshare/man/man4 Makefile

man: Link mlx5en.4 also to if_mce.4

For consistency, create a symbolic link from mlx5en.4 to also if_mce.4

Reviewed by:            ziaee, #manpages
Event:                  EuroBSDCon 2026
Differential Revision:  https://reviews.freebsd.org/D59610
MFC after:              3 days

(cherry picked from commit e46a7d842a7572cc7ccef88a463a9af1a725fefc)
DeltaFile
+2-1share/man/man4/Makefile
+2-11 files

HardenedBSD/src 39b8430sys/dev/acpica acpi.c

acpi: Fix unused variable error

Fixes:          9b4caca81de2 ("acpi: Don't compile CPU_VENDOR_{AMD,HYGON} cases on non-x86_64")
Sponsored by:   The FreeBSD Foundation
DeltaFile
+1-1sys/dev/acpica/acpi.c
+1-11 files

HardenedBSD/src 3820d1esys/dev/amdsmu amdsmu_reg.h

amdsmu: Add clarifying comment for the *sw_drips metrics

Sponsored by:   The FreeBSD Foundation
DeltaFile
+7-0sys/dev/amdsmu/amdsmu_reg.h
+7-01 files

HardenedBSD/src 9b4cacasys/dev/acpica acpi.c

acpi: Don't compile CPU_VENDOR_{AMD,HYGON} cases on non-x86_64

Fixes build on aarch64.

Fixes:          5f68acc931a4 ("acpi: Warn if no amdsmu(4) loaded after suspend-to-idle resume")
Sponsored by:   The FreeBSD Foundation
DeltaFile
+3-1sys/dev/acpica/acpi.c
+3-11 files

HardenedBSD/src 506e52fcontrib/unbound configure, contrib/unbound/util configparser.c configlexer.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/cross-dso-cfi
DeltaFile
+3,518-3,462contrib/unbound/util/configlexer.c
+1,936-2,732contrib/unbound/configure
+2,070-2,037contrib/unbound/util/configparser.c
+779-0sys/dev/hyperv/hvuio/hv_uio.c
+371-99sys/dev/mlx5/mlx5_ib/mlx5_ib_main.c
+312-105usr.bin/truss/setup.c
+8,986-8,435120 files not shown
+12,206-9,603126 files

HardenedBSD/src 3e4b79econtrib/unbound configure, contrib/unbound/util configparser.c configlexer.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+3,518-3,462contrib/unbound/util/configlexer.c
+1,936-2,732contrib/unbound/configure
+2,070-2,037contrib/unbound/util/configparser.c
+779-0sys/dev/hyperv/hvuio/hv_uio.c
+371-99sys/dev/mlx5/mlx5_ib/mlx5_ib_main.c
+312-105usr.bin/truss/setup.c
+8,986-8,435120 files not shown
+12,206-9,603126 files

HardenedBSD/src e4efa63share/man/man4 vmx.4 uath.4

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+33-61share/man/man4/udbp.4
+31-29share/man/man4/virtio_scsi.4
+25-28share/man/man4/ntb_hw_plx.4
+19-27share/man/man4/uath.4
+23-23share/man/man4/tws.4
+22-20share/man/man4/vmx.4
+153-18849 files not shown
+643-79655 files

HardenedBSD/src 9aef747contrib/unbound configure, contrib/unbound/util configparser.c configlexer.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+3,518-3,462contrib/unbound/util/configlexer.c
+1,936-2,732contrib/unbound/configure
+2,070-2,037contrib/unbound/util/configparser.c
+779-0sys/dev/hyperv/hvuio/hv_uio.c
+371-99sys/dev/mlx5/mlx5_ib/mlx5_ib_main.c
+312-105usr.bin/truss/setup.c
+8,986-8,435120 files not shown
+12,206-9,603126 files

HardenedBSD/src 0a72795share/man/man4 vmx.4 uath.4

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+33-61share/man/man4/udbp.4
+31-29share/man/man4/virtio_scsi.4
+25-28share/man/man4/ntb_hw_plx.4
+19-27share/man/man4/uath.4
+23-23share/man/man4/tws.4
+22-20share/man/man4/vmx.4
+153-18849 files not shown
+643-79655 files

HardenedBSD/src 29fcb85share/man/man4 iflib.4, sys/net iflib.c

iflib: add a new global tunable "prefer_mpring"

net.iflib.prefer_mpring can be used to control whether or
not all iflib driver instances default to mp_ring or simple_tx.

This is intended to be temporary, to allow easy testing (now) of
simple_tx, and to allow an easy fallback to the legacy path
(later) once the default is switched to simple_tx
DeltaFile
+15-2share/man/man4/iflib.4
+5-0sys/net/iflib.c
+20-22 files

HardenedBSD/src 5f68accsys/dev/acpica acpi.c

acpi: Warn if no amdsmu(4) loaded after suspend-to-idle resume

If amdsmu(4) is not loaded when entering suspend-to-idle and on an AMD
CPU, emit a warning.

FreeBSD currently only supports S0ix on AMD CPUs through the SMU. When
Intel support is completed, we should check the equivalent for Intel
(intelpmc).

Reviewed by:    olce
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59672
DeltaFile
+33-0sys/dev/acpica/acpi.c
+33-01 files

HardenedBSD/src c6728cfsys/net iflib.c

iflib: implement driver-provided queue selection for simple tx

Until now, simple tx has used its own queue selector, and has
ignored isc_txq_select and isc_txq_select_v2 (not this only
seems to matter for ice(4) with dcb enabled). This change
makes simple-tx use isc_txq_select* when present.

The implementation is defined to be efficient, with a
transmit routine chosen up-front that hard-codes the
queue selection and calls an always-inlined body.  This
avoids a useless test per packet in the hotpath, and
also may avoid speculation into header parsing.

Note that this was designed for readability and efficiency
in the common case (interface up, not ALTQ).  That's why
we do queue selection without duplicating nic-running and
altq checks, leaving them to the common implmentation.

Sponsored by: Netflix

    [2 lines not shown]
DeltaFile
+87-31sys/net/iflib.c
+87-311 files

HardenedBSD/src 3484217sys/kern kern_proc.c

proc: free kstack buffers when debug permission changes

The kern.proc.kstack handler allocates its output and stack buffers
before deliberately checking p_candebug again under the process lock.
If trace-control state changes between authorization checks, the failure
path balances the process and exec state but leaks both buffers.

Submitted by calif.io for the OpenAI Patch The Planet program

Signed-off-by: Andrew Griffiths <andrew at calif.io>

Fixes:          8b5abd9027b8 ("kern_proc.c: disallow execve around sysctl kern.proc.kstacks")
Reviewed by:    markj
MFC after:      1 week
DeltaFile
+2-0sys/kern/kern_proc.c
+2-01 files

HardenedBSD/src 5d0b876sys/security/mac_bsdextended mac_bsdextended.c

mac_bsdextended: reject negative rule indices in sysctl_rule()

The security.mac.bsdextended.rules.<N> node handler takes N as
`index = name[0]` (a signed int) and only checks
`index >= MAC_BSDEXTENDED_MAXRULES`.  A negative index is caught on
the read branch, but the write-only add and delete
branches proceed to `rules[index]` unconditionally.

Reject `index < 0` alongside the existing upper-bound check.

Submitted by calif.io for the OpenAI Patch The Planet program

Signed-off-by: Andrew Griffiths <andrew at calif.io>

Reviewed by:    markj
MFC after:      2 weeks
DeltaFile
+2-2sys/security/mac_bsdextended/mac_bsdextended.c
+2-21 files

HardenedBSD/src 151a851usr.bin/truss truss.h extern.h

truss(1): capsicumize

The new ptrace(2) features allow to change truss(1) to systematically
operate on the process descriptors instead of pids.

Allocate the global kqueue that tracks all noted children
by pdopenpid()-ing them and adding to the kqueue with
EVFILT_PROCDESC/NOTE_PDSIGCHLD. The activated knote triggers the
pdwait() call to return the child tracing info. This replaces the
waitid(P_ALL) call in the non-capsicumized truss(1) eventloop.

Reviewed by:    markj
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
Differential revision:  https://reviews.freebsd.org/D58094
DeltaFile
+312-105usr.bin/truss/setup.c
+92-65usr.bin/truss/syscalls.c
+22-10usr.bin/truss/main.c
+18-9usr.bin/truss/extern.h
+25-2usr.bin/truss/truss.1
+9-0usr.bin/truss/truss.h
+478-1916 files

HardenedBSD/src 1fb9c5fcontrib/unbound config.h.in configure, contrib/unbound/services authzone.c

unbound: Update to 1.26.1

Release notes at
    https://community.nlnetlabs.nl/t/unbound-1-26-1-released

Merge commit '120aa088f4807126af42a652a07c5090e7294fcf'

Security:       CVE-2026-77860
Security:       CVE-2026-77955
Security:       CVE-2026-78227
Security:       CVE-2026-80225
Security:       CVE-2026-81634
Security:       CVE-2026-81642
Security:       CVE-2026-82717
Security:       CVE-2026-82720
Security:       CVE-2026-85501
DeltaFile
+3,518-3,462contrib/unbound/util/configlexer.c
+1,936-2,732contrib/unbound/configure
+2,070-2,037contrib/unbound/util/configparser.c
+189-199lib/libunbound/config.h
+186-196contrib/unbound/config.h.in
+177-67contrib/unbound/services/authzone.c
+8,076-8,69352 files not shown
+8,842-8,93958 files

HardenedBSD/src 644f899contrib/ofed/libibverbs kern-abi.h cmd.c, contrib/ofed/libibverbs/man ibv_create_flow.3

verbs/mlx5: Add GRE and MPLS flow specification filter

[PATCH 30/31] FreeBSD OFED support for DPDK MLX5 PMD

a) Allow verbs applications packet steering of GRE tunneled traffic.
Adding GRE flow specification based on RFC 2890.
GRE consists of flags, protocol and key fields.
IPv4 protocol 47 (IPPROTO_GRE) can be used when GRE packets are
encapsulated in IPv4.

b) verbs: Add MPLS flow specification filter
Add MPLS flow specification based on RFC 3032.
MPLS spec defined with label field which includes the
label value and additional parameters such as: BoS, TC and TTL.
MPLS allows stacking multiple labels in sequence.
In addition, the MPLS header can be encapsulated on top of different
layers, e.g.: ETH, IP (rfc4023), UDP (rfc7510), GRE (rfc4023).

Therefore, when using the flow creation verb, the application should

    [14 lines not shown]
DeltaFile
+42-0contrib/ofed/libibverbs/verbs.h
+19-1contrib/ofed/libibverbs/man/ibv_create_flow.3
+14-0contrib/ofed/libibverbs/cmd.c
+2-0contrib/ofed/libmlx5/mlx5dv.h
+2-0contrib/ofed/libibverbs/kern-abi.h
+79-15 files