HardenedBSD/src 741cd29sys/fs/nfs nfs_commonkrpc.c, sys/fs/nfsclient nfs_clrpcops.c

nfscl: Yet more fixes for the NFS over RDMA client glue

This should be it for a while, but there will be another cycle
of "glue" updates.  I just found out that I'll need to create
an alternate code path that uses a contigmalloc() blob instead
of scatter/gather of pages, since some NICs cannot do the
scatter/gather of pages well.

This commit should not affect non-RDMA behaviour.

MFC after:      3 months
Fixes:  884ee8d6c9b4 ("nfscl: Add some glue for client side NFS over RDMA")
DeltaFile
+20-2sys/rpc/clntrdma.h
+21-0sys/rpc/rpc_generic.c
+4-2sys/fs/nfsclient/nfs_clrpcops.c
+1-1sys/rpc/clnt_rc.c
+2-0sys/fs/nfs/nfs_commonkrpc.c
+48-55 files

HardenedBSD/src 75a1939share/man/man4 aq.4, sys/dev/aq aq_fw.h aq_fw2x.c

aq(4): arm PHY thermal shutdown from the admin poll

move thermal shutdown arming to the admin poll

this gives a more reasonable delay prior to the first attempt, and also
allows us to retry and make the option runtime-tuneable via a new
disable_thermal_arm sysctl

Approved by:    adrian (mentor)
Reviewed by:    adrian
Differential Revision:  https://reviews.freebsd.org/D59593

Signed-off-by: Nick Price <nprice at FreeBSD.org>
DeltaFile
+34-1sys/dev/aq/aq2_fw.c
+30-0sys/dev/aq/aq_irq.c
+14-10sys/dev/aq/aq_main.c
+16-6sys/dev/aq/aq_fw2x.c
+20-1share/man/man4/aq.4
+2-2sys/dev/aq/aq_fw.h
+116-201 files not shown
+118-207 files

HardenedBSD/src b3f7a43etc/mtree BSD.tests.dist, share/man/man4 fdescfs.4

fdescfs: descend through /dev/fd/N when mounted linrdlnk

Linux resolves a path below /proc/self/fd/N in the directory the
descriptor names, and linprocfs makes /proc/<pid>/fd a symlink to
/dev/fd.  Under linrdlnk the fdescfs node carries only VV_READLINK,
which namei will not walk through, so such a path fails with ENOTDIR.

Return the underlying vnode from fdesc_lookup for a non-final component,
or a trailing slash, reusing the machinery the nodup option already
uses.  The last component is untouched, so open("/dev/fd/N") keeps its
dup(2) semantic; a descriptor with no vnode behind it, such as a pipe,
yields ENOTDIR.

Add ATF coverage for traversal, descriptor reuse, and preservation of
last-component and mount-option semantics.

Approved by:    adrian (mentor)
Reviewed by:    kib, adrian
Differential Revision:  https://reviews.freebsd.org/D59393

    [2 lines not shown]
DeltaFile
+373-0tests/sys/fs/fdescfs/fdescfs_test.c
+15-1sys/fs/fdescfs/fdesc_vnops.c
+9-0tests/sys/fs/fdescfs/Makefile
+6-1share/man/man4/fdescfs.4
+2-0etc/mtree/BSD.tests.dist
+1-0tests/sys/fs/Makefile
+406-26 files

HardenedBSD/src cb2964fsys/amd64/conf MINIMAL GENERIC, sys/powerpc/conf QORIQ64 MPC85XX

amd64, powerpc: Enable tpm(4) in supported kernels

tpm(4) was removed from amd64 GENERIC because it broke suspend and
resume.  The preceding lifecycle, state-save, interrupt, locality, and
teardown fixes address those failures for both TPM 1.2 and TPM 2.0.

Restore the driver to amd64 GENERIC and MINIMAL, where TPM entropy
harvesting remained enabled.  Enable the driver and entropy harvesting
in the MPC85XX and QORIQ64 configurations, which already provide FDT,
spibus, and the platform SPI controller required by FDT-attached TPMs.
Leave the generic AIM and POWER configurations unchanged because they
have no TPM attachment bus.

The TPM 1.2 path completed repeated S3 cycles and command tests on
ThinkPad T430 and T440p systems.  The TPM 2.0 path completed repeated
device and full-system suspend/resume cycles on a ThinkPad P51.  The
PowerPC configuration matrix was checked to retain tpm(4) only where its
FDT SPI attachment path is present.


    [8 lines not shown]
DeltaFile
+2-3sys/amd64/conf/MINIMAL
+2-3sys/amd64/conf/GENERIC
+2-0sys/powerpc/conf/QORIQ64
+2-0sys/powerpc/conf/MPC85XX
+8-64 files

HardenedBSD/src 9ed5901sys/dev/puc pucdata.c

puc: add the WCH CH382 2S dual serial card

Two 16850 UARTs in the first I/O BAR at offset 0xc0, 8 bytes apart.

Approved by:    adrian (mentor)
Reviewed by:    imp, adrian
Differential Revision:  https://reviews.freebsd.org/D59512

Signed-off-by: Nick Price <nprice at FreeBSD.org>
DeltaFile
+20-0sys/dev/puc/pucdata.c
+20-01 files

HardenedBSD/src 8228171sys/dev/puc puc_pci.c puc_cfg.h

puc: be more careful about using MSI

puc has preferred MSI for every card since MSI support was added, with
only a global tunable to opt out.  uart(4) makes the same decision for
the serial devices it attaches directly, and has since grown two
defences: it skips MSI unless the device advertises exactly one vector,
because attaching a single instance to a device offering many has caused
problems (PR 235016), and it lets individual devices be flagged when
they claim MSI support that does not work.

Adopt both.

Approved by:    adrian (mentor)
Reviewed by:    adrian
Differential Revision:  https://reviews.freebsd.org/D59623

Signed-off-by: Nick Price <nprice at FreeBSD.org>
DeltaFile
+3-1sys/dev/puc/puc_pci.c
+4-0sys/dev/puc/puc_cfg.h
+7-12 files

HardenedBSD/src 9c650fbsys/dev/ncthwm ncthwm.c, sys/dev/superio superio.c

superio, ncthwm: add support for the Nuvoton NCT6798D

The ASUS PRIME X570-P carries a Nuvoton NCT6798D, Super I/O device ID 0xd42b. Add an exact-match entry to both. Exact rather than masked: the neighboring 0xd42a entries are deliberately exact with an extid because that ID is claimed by both NCT6796D-E and NCT5585D, and widening the family would make them collide.

The NCT6798D has seven tachometers, so raise NCTHWM_FAN_MAX to seven and describe the two extra ones; existing entries keep fan_count = 5 and are unaffected. Fan names follow the NCT6779 convention and do not map to any board's physical headers.

Tested on: ASUS PRIME X570-P, Ryzen 9 5950X, FreeBSD 16.0-CURRENT.

Approved by:    adrian
Reviewed by:    stephane.rochoy_stormshield.eu, adrian
Differential Revision:  https://reviews.freebsd.org/D58291

Signed-off-by: Nick Price <nprice at FreeBSD.org>
DeltaFile
+16-1sys/dev/ncthwm/ncthwm.c
+5-0sys/dev/superio/superio.c
+21-12 files

HardenedBSD/src 877294ausr.sbin/bsdinstall/partedit partedit_x86.c

bsdinstall: allow ZFS root on GPT under UEFI (amd64)

GPT+ZFS+UEFI boots fine, but the manual guided
wizard prevented it.

MFC after: 3 days

Reviewed by:    imp, adrian
Differential Revision:  https://reviews.freebsd.org/D59603
DeltaFile
+1-2usr.sbin/bsdinstall/partedit/partedit_x86.c
+1-21 files

HardenedBSD/src 243bdaflib/googletest/tests Makefile.inc

lib/googletest: also use -O0 for internal tests with GCC

This fixes the build with gcc 16's aggressive inlining.

Reviewed by:    ngie
MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59538
DeltaFile
+3-3lib/googletest/tests/Makefile.inc
+3-31 files

HardenedBSD/src 06488d2sys/compat/linux linux_misc.c

linux: LINUX_PR_SET_THP_DISABLE all non-zero values are disable

Linux treats any nonzero value as "disable", so accept them all.

Fixes: a8a6eac57091
Sponsored by:           Netflix
DeltaFile
+2-3sys/compat/linux/linux_misc.c
+2-31 files

HardenedBSD/src 577ea37stand/efi/include efilib.h, stand/efi/libefi efinet.c

loader.efi: Expose efi_devpath_get_mac to get mac

This is a convenient way to test if a device path is a nic or not, so
expose it to the world.

Sponsored by:           Netflix
DeltaFile
+3-6stand/efi/libefi/efinet.c
+1-0stand/efi/include/efilib.h
+4-62 files

HardenedBSD/src 772c658stand/common md.c

loader: Use %u to print unsigned value

Fixes: 7055aa7a070f
Sponsored by:           Netflix
DeltaFile
+1-1stand/common/md.c
+1-11 files

HardenedBSD/src 6413a87stand loader.mk defs.mk, stand/efi/libefi efipart.c Makefile

loader: Move some support things around, maybe lame?

Sponsored by:           Netflix
DeltaFile
+7-0stand/efi/loader/memdisk.c
+1-5stand/loader.mk
+6-0stand/efi/libefi/efinet.c
+6-0stand/defs.mk
+3-0stand/efi/libefi/Makefile
+2-0stand/efi/libefi/efipart.c
+25-56 files

HardenedBSD/src 197df29stand/efi/loader main.c

loader.efi: Only try to download md if we're netbooting

The only possible time we could download the initmd that the dhcp server
told us about is if we're netbooting. So only attempt to do that if the
load device for loader.efi is a network. IF you are booting off disk and
then need to snag an initmd off the network, that's a different path,
and wouldn't need to necessarily do a dhcp exchange, except to get the
IP address.

Sponsored by:           Netflix
DeltaFile
+16-1stand/efi/loader/main.c
+16-11 files

HardenedBSD/src bbee544stand/efi/libefi efihttp.c

loader.efi: Fix memory leak in efihttp_dev_close

Save enough context to free the host we allocated in open on close.

Fixes: 6788e42d53c6
Noticed by: claude + Sonet 5
Sponsored by: Netflix
DeltaFile
+6-4stand/efi/libefi/efihttp.c
+6-41 files

HardenedBSD/src f9517d2usr.sbin/mpsutil mps_show.c

mpsutil: Better naming form the discovery_status function

It's really discovery_status_str(). Rename it and use open_memstream()
to write the string so we don't have to play as many str* games.

Fixes: afb60897a15c
Noticed by: claude + Sonet 5 (size error, bad fix ignored)
Sponsored by: Netflix
DeltaFile
+22-17usr.sbin/mpsutil/mps_show.c
+22-171 files

HardenedBSD/src baa78c8sbin/nvmecontrol power.c

nvmecontrol: Minor correctness issues

Turn an assert into a bounds check to not overflow if the nvme drive
reports too many power states (we validate the user input, but not the
drive's identify data).

Use a uint32_t instead of int for entry so right shift we do is defined.

No functional changes.

Fixes:                  35793364d722
Noticed by:             claude + Sonet 5
Sponsored by:           Netflix
DeltaFile
+4-3sbin/nvmecontrol/power.c
+4-31 files

HardenedBSD/src 79e2a46sbin/nvmecontrol power.c

nvmecontrol: Fix APST transition encoding

Use uin64_t casts to encode data sent to avoid overflows.

Fixes: 35793364d722
Sponsored by: Netflix
DeltaFile
+6-4sbin/nvmecontrol/power.c
+6-41 files

HardenedBSD/src b485d70sbin/dhclient dhclient.c

dhclient(8): Fix dhcpack comment

Restore a comment accidentally removed above dhcpack.

Fixes:  37fd3fcaaf0e ("dhclient(8): Add support for IPv6-Only option (RFC 8925)")
DeltaFile
+2-1sbin/dhclient/dhclient.c
+2-11 files

HardenedBSD/src 37fd3fcsbin/dhclient Makefile dhcpd.h

dhclient(8): Add support for IPv6-Only option (RFC 8925)

Accept and validate the ipv6only option. When dhclient receives this
option and IPv6 connectivity is available, stop the DHCP configuration
process and wait for the duration specified by the option before
restarting DHCP discovery.

If the address was previously leased, disassociate it and send a
DHCPRELEASE packet.

Use netlink to check for IPv6 connectivity.

Also, unregister ignored options from default PRL.

Reviewed by:    ziaee, kfv
Tested by:      Marek Zarychta <zarychtam at plan-b.pwste.edu.pl>
Relnotes:       yes
Differential Revision: https://reviews.freebsd.org/D56637
DeltaFile
+160-22sbin/dhclient/dhclient.c
+118-0sbin/dhclient/inet6.c
+67-1sbin/dhclient/options.c
+31-0sbin/dhclient/clparse.c
+11-0sbin/dhclient/dhcpd.h
+9-1sbin/dhclient/Makefile
+396-243 files not shown
+409-279 files

HardenedBSD/src 3ca70c5sys/powerpc/booke pmap.c

powerpc/pmap: Add a minimum TID width

QEMU doesn't appear to emulate the MMUCFG register for Book-E CPUs, so
give a sane small default of 7, for an 8 bit PID register.
DeltaFile
+2-0sys/powerpc/booke/pmap.c
+2-01 files

HardenedBSD/src 300c54asys/powerpc/booke pmap.c

powerpc/booke pmap: Adjust TID bits to correct size

MMUCFG::PIDSIZE is the TID field size less 1, so adjust to get the
full width.
DeltaFile
+1-1sys/powerpc/booke/pmap.c
+1-11 files

HardenedBSD/src 35973ecbin/sh sh.1

sh.1: Renew description of case

Update case synopsis, split description into paragraphs, improve markup,
light wordsmithing, and import exit status line from NetBSD.

While here, remove the '-' from the beginning of this document.

PR:     298329
Event:  EuroBSDcon 2026
Fixes:  c9afaa63894e ("Add case statement fallthrough")
Fixes:  f7a9b7fe3a8d ("Allow a left parenthesis before patterns in case blocks")
Fixes:  e00e16ad7f86 ("Allow empty case/esac statements")
MFC after:      3 days
Reviewed by:    bcr, jilles, Artem Bunichev <temcbun at gmail.com>
Differential Revision:  https://reviews.freebsd.org/D59518
DeltaFile
+37-17bin/sh/sh.1
+37-171 files

HardenedBSD/src d5c09e3usr.sbin/wpa/wpa_supplicant wpa_supplicant.8

wpa_supplicant.8: Renew SEE ALSO + tag SPDX

- remove old wifi drivers, these are very old and we have many more
- add quick start guide to connecting to wifi

Event:                  EuroBSDCon 2026
MFC after:              3 days
Reviewed by:            bz, emaste
Differential Revision:  https://reviews.freebsd.org/D59615
DeltaFile
+5-9usr.sbin/wpa/wpa_supplicant/wpa_supplicant.8
+5-91 files

HardenedBSD/src e46a7d8share/man/man4 Makefile

man: Link mlx5en.4 also to if_mce.4

For consistency, create a symbolic link from mlx5en.4 to also if_mce.4

Reviewed by:            ziaee, #manpages
Event:                  EuroBSDCon 2026
Differential Revision:  https://reviews.freebsd.org/D59610
MFC after:              3 days
DeltaFile
+2-1share/man/man4/Makefile
+2-11 files

HardenedBSD/src 465942esys/netinet raw_ip.c

raw ip: clear sin_port on bind(2)

Application may set sin_port to some value.  Although this value is not
used by SOCK_RAW, it breaks a check that the address is available.  A
perfect fix would be not use sockaddrs for ifaddrs, but that would be a
bigger change.

PR:                     298366
Reviewed by:            pouria, bnovkov, adrian
Differential Revision:  https://reviews.freebsd.org/D59570
Fixes:                  948ad32ae1e0811f45e1d38f26636fefed5051f0
DeltaFile
+1-1sys/netinet/raw_ip.c
+1-11 files

HardenedBSD/src a1e236esys/dev/acpica acpi_spmc.c

acpi_spmc: Check AMD constraint packages

Also match behaviour with Intel constraint parsing by skipping malformed
constraints instead of failing hard.

Reviewed by:    olce
Sponsored by:   The FreeBSD Foundation
Event:          EuroBSDCon Devsummit 2026
Differential Revision:  https://reviews.freebsd.org/D59568
DeltaFile
+38-6sys/dev/acpica/acpi_spmc.c
+38-61 files

HardenedBSD/src 508efe3sys/dev/acpica acpi_spmc.c

acpi_spmc: Check Intel constraint packages

Some firmware inexplicably decides to do non-standard and annoying stuff
here, e.g. the Fujitsu Futro S940 with an Intel Pentium J5005 sometimes
returns the following when calling the DEVICE_CONSTRAINTS function on
the Intel DSM:

    Return (Package (0x01)
    {
        Zero
    })

(Package elements here are supposed to be constraint packages, not just a
single value.)

First reported in the following forum post:

https://forum.netgate.com/topic/201090/2.9.0-beta-leads-to-kernel-panic-on-boot


    [5 lines not shown]
DeltaFile
+46-6sys/dev/acpica/acpi_spmc.c
+46-61 files

HardenedBSD/src 66830bdlibexec/rtld-elf/amd64 rtld_machdep.h rtld_start.S, libexec/rtld-elf/i386 rtld_start.S reloc.c

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+95-3libexec/rtld-elf/i386/reloc.c
+92-2libexec/rtld-elf/amd64/reloc.c
+53-36sys/dev/e1000/if_em.c
+65-0libexec/rtld-elf/amd64/rtld_start.S
+36-0libexec/rtld-elf/i386/rtld_start.S
+34-1libexec/rtld-elf/amd64/rtld_machdep.h
+375-4210 files not shown
+442-5216 files

HardenedBSD/src 08c0ac8libexec/rtld-elf/amd64 rtld_machdep.h rtld_start.S, libexec/rtld-elf/i386 rtld_start.S reloc.c

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+95-3libexec/rtld-elf/i386/reloc.c
+92-2libexec/rtld-elf/amd64/reloc.c
+53-36sys/dev/e1000/if_em.c
+65-0libexec/rtld-elf/amd64/rtld_start.S
+36-0libexec/rtld-elf/i386/rtld_start.S
+34-1libexec/rtld-elf/amd64/rtld_machdep.h
+375-4210 files not shown
+442-5216 files