HardenedBSD/src dfda65f — share/man/man4 ipmi.4, stand/efi/loader main.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+25-24sys/dev/iwx/if_iwx.c
+33-1share/man/man4/ipmi.4
+18-0sys/dev/ipmi/ipmi.c
+8-2stand/efi/loader/main.c
+3-2sys/dev/iwx/if_iwxreg.h
+87-295 files

HardenedBSD/src d53572f — sys/kern kern_jaildesc.c

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+2-0sys/kern/kern_jaildesc.c
+2-01 files

HardenedBSD/src 4176b70 — share/man/man4 ipmi.4, stand/efi/loader main.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+25-24sys/dev/iwx/if_iwx.c
+33-1share/man/man4/ipmi.4
+18-0sys/dev/ipmi/ipmi.c
+8-2stand/efi/loader/main.c
+3-2sys/dev/iwx/if_iwxreg.h
+87-295 files

HardenedBSD/src c7d9d4d — sys/kern kern_jaildesc.c

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+2-0sys/kern/kern_jaildesc.c
+2-01 files

HardenedBSD/src 6f5803e — sys/dev/iwx if_iwxreg.h if_iwx.c

iwx: update if_iwx.c to OpenBSD v1.184 and if_iwxreg.h to OpenBSD v1.53

This updates iwx to the given OpenBSD versions upstream.

This is a squashed commit of the given differential revisions
and openbsd upstream commits.

Reviewed by:    adrian
Differential Revision:  https://reviews.freebsd.org/D59757
Differential Revision:  https://reviews.freebsd.org/D59758
Differential Revision:  https://reviews.freebsd.org/D59759
Differential Revision:  https://reviews.freebsd.org/D59760
Differential Revision:  https://reviews.freebsd.org/D59761
Differential Revision:  https://reviews.freebsd.org/D59762
Differential Revision:  https://reviews.freebsd.org/D59763
Differential Revision:  https://reviews.freebsd.org/D59764
Differential Revision:  https://reviews.freebsd.org/D59765
Differential Revision:  https://reviews.freebsd.org/D59766


    [10 lines not shown]
DeltaFile
+25-24sys/dev/iwx/if_iwx.c
+3-2sys/dev/iwx/if_iwxreg.h
+28-262 files

HardenedBSD/src bf97446 — share/man/man4 ipmi.4, sys/dev/ipmi ipmi.c

ipmi(4): improve debugging for ioctl(IPMICTL_SEND_COMMAND)

Add a knob to debug ioctl(IPMICTL_SEND_COMMAND). Log the IPMI NetFn and
Cmd fields, followed by a hexdump of the request data. Upon completion,
log the hexdump of the response data.

Reviewed by:    adrian, imp, ngie
Sponsored by:   Vdura
Differential Revision:  https://reviews.freebsd.org/D59514
DeltaFile
+33-1share/man/man4/ipmi.4
+18-0sys/dev/ipmi/ipmi.c
+51-12 files

HardenedBSD/src 8436cbd — sys/kern kern_jaildesc.c

jaildesc: Lock prison pointer when filling kinfo

Submitted by:   Yuri Tkachenko <yura.tkachenko at gmail.com>
MFC after:      3 days
Differential Revision:  https://reviews.freebsd.org/D60392

(cherry picked from commit a5ae2a9bfb1ca7f49e79ee63ed39216c42326d02)
DeltaFile
+2-0sys/kern/kern_jaildesc.c
+2-01 files

HardenedBSD/src 7888736 — stand/efi/loader main.c

loader.efi: devinit() just after parsing args instead

c4640126f1160 ("loader.efi: Apply command-line DHCP overrides earlier")
was really good, but moving it just one statement earlier is even
better.  polarian on Libera describes a GELI setup on a system that
doesn't advertise a serial console via ConOut.  They don't have serial
input at the point that they would get prompted for the GELI passphrase,
but if we parse args just before devinit() then he can override the
console with `efibootmgr -e`.  This gives UEFI one advantage over BIOS
loader, as /boot.config isn't available to provide that kind of override
if your impediment is GELI.

We also considered reading loader.env earlier, but we have a chicken/egg
problem in that we must have probed for the ESP to be able to open() it.
We would instead need a devinit_early() and devinit_late() scheme that
allows GELI probing to be deferred until the later pass, after reading
loader.env to pick up the console override.  That's an idea I'd still
like to discuss because it's more robust than hoping that firmware won't
wipe out our efibootmgr(8) entries.

    [4 lines not shown]
DeltaFile
+8-2stand/efi/loader/main.c
+8-21 files

HardenedBSD/src b5d51c9 — contrib/kyua/doc kyua-report-html.1 kyua-report.1

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+574-0contrib/kyua/doc/kyuafile.5
+498-0contrib/kyua/doc/kyua-test.1
+417-0contrib/kyua/doc/kyua-debug.1
+405-0contrib/kyua/doc/kyua.1
+307-0contrib/kyua/doc/kyua-report.1
+253-0contrib/kyua/doc/kyua-report-html.1
+2,454-010 files not shown
+3,681-1416 files

HardenedBSD/src ca5adbd — . Makefile.inc1, lib/libgcc_s_asneeded Makefile

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+11-0lib/libgcc_s_asneeded/Makefile
+4-3Makefile.inc1
+3-3tests/sys/pmc/pmc_lifecycle_test.c
+2-2tests/sys/pmc/pmc_detach_test.c
+1-1tests/sys/pmc/pmc_log_test.c
+1-1tests/sys/pmc/pmc_exec_test.c
+22-105 files not shown
+27-1311 files

HardenedBSD/src e6bd6c3 — contrib/kyua/doc kyua-report-html.1 kyua-report.1

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+574-0contrib/kyua/doc/kyuafile.5
+498-0contrib/kyua/doc/kyua-test.1
+417-0contrib/kyua/doc/kyua-debug.1
+405-0contrib/kyua/doc/kyua.1
+307-0contrib/kyua/doc/kyua-report.1
+253-0contrib/kyua/doc/kyua-report-html.1
+2,454-010 files not shown
+3,681-1416 files

HardenedBSD/src ab92eca — . Makefile.inc1, lib/libgcc_s_asneeded Makefile

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+11-0lib/libgcc_s_asneeded/Makefile
+4-3Makefile.inc1
+3-3tests/sys/pmc/pmc_lifecycle_test.c
+2-2tests/sys/pmc/pmc_detach_test.c
+1-1tests/sys/pmc/pmc_log_test.c
+1-1tests/sys/pmc/pmc_exec_test.c
+22-105 files not shown
+27-1311 files

HardenedBSD/src a689dd9 — . Makefile.inc1, lib Makefile

libgcc_s: add libgcc_s_asneeded.so wrapper for gcc 16

GCC 16[0][1] now requires a wrapper lib to handle
`--push-state --as-needed -lgcc_s --pop-state` logic[1]
for `gcc` invocations. `g++` will still unconditionally
use `-lgcc_s`.

This fixes buildworld with gcc16.

[0] https://gcc.gnu.org/git/?p=gcc.git;a=commit;h=8a99fdb70493df1294b53406913e5ea1fc971c13
[1] https://gcc.gnu.org/bugzilla/show_bug.cgi?id=123396

Reviewed by:    jhb
MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59511

Squashed commits including fixups:
(cherry picked from commit fdd3f6f78888b02a1bfa69a0572317413dc14a45)

    [2 lines not shown]
DeltaFile
+11-0lib/libgcc_s_asneeded/Makefile
+4-3Makefile.inc1
+1-1share/mk/bsd.lib.mk
+1-0lib/Makefile
+1-0lib/libgcc_s_asneeded/libgcc_s_asneeded.ldscript
+18-45 files

HardenedBSD/src 9b2f363 — tests/sys/pmc pmc_log_test.c pmc_exec_test.c

tests/pmc: annotate busy loop counters with __unused

This fixes the build with gcc 16 after the changes
to -Wunused*[0].

[0] https://gcc.gnu.org/gcc-16/porting_to.html#changes-to-wunused

Reviewed by:    netchild
MFC after:      3 days
Sponsored by:   The FreeBSD Foundation

(cherry picked from commit 0be29268ae4e593581e1f711f0f8822a52215aef)
DeltaFile
+3-3tests/sys/pmc/pmc_lifecycle_test.c
+2-2tests/sys/pmc/pmc_detach_test.c
+1-1tests/sys/pmc/pmc_log_test.c
+1-1tests/sys/pmc/pmc_exec_test.c
+1-1tests/sys/pmc/pmc_credexec_test.c
+8-85 files

HardenedBSD/src 70f18af — sys/conf kern.pre.mk

OFED: add -Wunused-but-set-variable to OFED_C

This keeps it in sync with sys/modules/ibcore/Makefile and
fixes the build on GCC 16 after the changes to -Wunused*[0].

[0] https://gcc.gnu.org/gcc-16/porting_to.html#changes-to-wunused

Reviewed by:    jhb
MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59539

(cherry picked from commit 188c455f3d7a137aeb9695dd0ba08a68d26c45f3)
DeltaFile
+1-1sys/conf/kern.pre.mk
+1-11 files

HardenedBSD/src 6c305c3 — sbin/dhclient dhclient-script.8

dhclient-script(8): s/URI/URL

Reported by:    glebius@
DeltaFile
+2-2sbin/dhclient/dhclient-script.8
+2-21 files

HardenedBSD/src ef947bb — sys/compat/linuxkpi/common/src linux_firmware.c

LinuxKPI: firmware: remove `enoentok` logic in `*firmware_request(..)`

Prior to this change, in the event that a firmware module could not be
loaded, the linux_firmware driver would return a partially initialized
structure with uninitialized/zeroed out values for certain fields. Linux
does not do this, however, so some drivers that use
`request_firmware_nowait` expecting Linux behavior, like `if_bcrmfmac`,
would crash trying to dereference a NULL pointer.

This doesn't address the load/unload situation completely as the driver
remains loaded after the "firmware crashes", but it makes a completely
unusable situation (a kernel panic) into a slightly more usable situation
(driver does not unload).

As a sidenote: the raw free(9) call was replaced with a call to
`linuxkpi_release_firmware` because the latter call [better] ensures
that all resources allocated earlier on in the function are cleaned up.

MFC after:      1 weeks

    [2 lines not shown]
DeltaFile
+7-12sys/compat/linuxkpi/common/src/linux_firmware.c
+7-121 files

HardenedBSD/src 26eb328 — contrib/kyua/doc kyua-report-html.1 kyua-report.1

contrib/kyua: commit generated files

MFC after:      1 month
Fixes: eb8f69902 ("contrib/kyua: update to 0.15.0")
DeltaFile
+574-0contrib/kyua/doc/kyuafile.5
+498-0contrib/kyua/doc/kyua-test.1
+417-0contrib/kyua/doc/kyua-debug.1
+405-0contrib/kyua/doc/kyua.1
+307-0contrib/kyua/doc/kyua-report.1
+253-0contrib/kyua/doc/kyua-report-html.1
+2,454-08 files not shown
+3,672-014 files

HardenedBSD/src 01593eb — contrib/kyua NEWS.md NEWS, contrib/kyua/engine googletest_test.cpp googletest_result_test.cpp

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+0-951contrib/kyua/m4/ax_cxx_compile_stdcxx.m4
+709-0contrib/kyua/NEWS
+0-622contrib/kyua/NEWS.md
+528-0contrib/kyua/engine/googletest_result.cpp
+427-0contrib/kyua/engine/googletest_result_test.cpp
+361-0contrib/kyua/engine/googletest_test.cpp
+2,025-1,573179 files not shown
+4,214-7,588185 files

HardenedBSD/src 9f284f3 — contrib/llvm-project/clang/lib/AST ExprConstant.cpp, contrib/llvm-project/clang/lib/AST/ByteCode Compiler.cpp Interp.cpp

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+269-0sys/riscv/starfive/jh7110_temp.c
+194-9sys/riscv/starfive/jh7110_gpio.c
+31-34contrib/llvm-project/clang/lib/AST/ByteCode/Interp.cpp
+24-18contrib/llvm-project/clang/lib/AST/ExprConstant.cpp
+11-9contrib/llvm-project/clang/lib/AST/ByteCode/Compiler.cpp
+16-0sys/dev/clk/starfive/jh7110_clk_sys.c
+545-705 files not shown
+561-7111 files

HardenedBSD/src 2a6c2bc — contrib/kyua NEWS.md NEWS, contrib/kyua/engine googletest_test.cpp googletest_result_test.cpp

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+0-951contrib/kyua/m4/ax_cxx_compile_stdcxx.m4
+709-0contrib/kyua/NEWS
+0-622contrib/kyua/NEWS.md
+528-0contrib/kyua/engine/googletest_result.cpp
+427-0contrib/kyua/engine/googletest_result_test.cpp
+361-0contrib/kyua/engine/googletest_test.cpp
+2,025-1,573179 files not shown
+4,214-7,588185 files

HardenedBSD/src 1b3a364 — contrib/llvm-project/clang/lib/AST ExprConstant.cpp, contrib/llvm-project/clang/lib/AST/ByteCode Compiler.cpp Interp.cpp

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+269-0sys/riscv/starfive/jh7110_temp.c
+194-9sys/riscv/starfive/jh7110_gpio.c
+31-34contrib/llvm-project/clang/lib/AST/ByteCode/Interp.cpp
+24-18contrib/llvm-project/clang/lib/AST/ExprConstant.cpp
+11-9contrib/llvm-project/clang/lib/AST/ByteCode/Compiler.cpp
+16-0sys/dev/clk/starfive/jh7110_clk_sys.c
+545-705 files not shown
+561-7111 files

HardenedBSD/src b836604 — usr.bin/kyua Makefile

contrib/kyua: commit Makefile changes for version update

This was accidentally missed in the version update.

MFC after:      1 month
Fixes: eb8f69902 ("contrib/kyua: update to 0.15.0")
DeltaFile
+4-21usr.bin/kyua/Makefile
+4-211 files

HardenedBSD/src eb8f699 — contrib/kyua NEWS.md NEWS, contrib/kyua/engine googletest_test.cpp googletest_result_test.cpp

contrib/kyua: update to 0.15.0

This new release contains multiple feature updates and bugfixes. Please
see the release notes mentioned in the merge commit for more details.

MFC after:      1 month
Merge commit '144afd05f8a2300361ec30c1c2020e4022ddd943'

Conflicts:
        contrib/kyua/cli/cmd_debug.cpp
        contrib/kyua/doc/kyua-debug.1.in
        contrib/kyua/doc/kyuafile.5.in
        contrib/kyua/engine/config.cpp
        contrib/kyua/engine/execenv/execenv.cpp
        contrib/kyua/engine/execenv/execenv.hpp
        contrib/kyua/engine/execenv/execenv_host.hpp
        contrib/kyua/engine/requirements.cpp
        contrib/kyua/engine/requirements.hpp
        contrib/kyua/engine/scheduler.cpp

    [8 lines not shown]
DeltaFile
+0-951contrib/kyua/m4/ax_cxx_compile_stdcxx.m4
+709-0contrib/kyua/NEWS
+0-622contrib/kyua/NEWS.md
+528-0contrib/kyua/engine/googletest_result.cpp
+427-0contrib/kyua/engine/googletest_result_test.cpp
+361-0contrib/kyua/engine/googletest_test.cpp
+2,025-1,573143 files not shown
+3,641-7,505149 files

HardenedBSD/src b9180c0 — contrib/llvm-project/clang/lib/AST ExprConstant.cpp, contrib/llvm-project/clang/lib/AST/ByteCode Interp.h Opcodes.td

Merge commit c52392a6f464 from llvm-project (by ShengYi Hung):

  [Clang][ExprConst] Drop PRValue for nothrow new (#226753)

  A user defined operator new can accept prvalue for nothrow. However, it
  should not be a ConstExpr. Early returns by
  isUsableAsGlobalAllocationFunctionInConstantEvaluation instead of doing
  LValue evaluation.
  Also, move CheckPlacement new logic into new OpCode. This decouples
  checking from Interp.cpp to Compiler.cpp.

This fixes "Assertion failed: (E->isGLValue() ||
E->getType()->isFunctionType() || E->getType()->isVoidType() ||
isa<ObjCSelectorExpr>(E->IgnoreParens())), function EvaluateLValue" when
building the databases/mariadb123-server port.

MFC after:      1 week

(cherry picked from commit ca3747034ef484b024a202d213a2e08b16066791)
DeltaFile
+31-34contrib/llvm-project/clang/lib/AST/ByteCode/Interp.cpp
+24-18contrib/llvm-project/clang/lib/AST/ExprConstant.cpp
+11-9contrib/llvm-project/clang/lib/AST/ByteCode/Compiler.cpp
+4-0contrib/llvm-project/clang/lib/AST/ByteCode/Opcodes.td
+1-0contrib/llvm-project/clang/lib/AST/ByteCode/Interp.h
+71-615 files

HardenedBSD/src 144afd0 — . Makefile.in configure, admin ltmain.sh config.guess

kyua: import kyua-0.15.0

This change adds kyua kyua-0.15.0 from [upstream][1].

The kyua-0.15.0 artifact was been verified by [SHA256 checksum][3].

More information about the release (from a high level) can be found in
the [release notes][4].

Updated via [`update_kyua.sh`][4] `update_kyua.sh 0.15.0 kyua-0.15.0`.

1: https://github.com/freebsd/kyua/releases/download/kyua-0.15.0/kyua-0.15.0.tar.gz
2: https://github.com/freebsd/kyua/releases/download/kyua-0.15.0/kyua-0.15.0.tar.gz.sha256
3: https://github.com/freebsd/kyua/blob/kyua-0.15.0/NEWS.md
4: https://codeberg.org/ngie/freebsd-powertools:shell/update_kyua.sh@10a04edb
DeltaFile
+940-1,503admin/config.sub
+600-943admin/config.guess
+159-601m4/libtool.m4
+219-431configure
+80-245admin/ltmain.sh
+35-91Makefile.in
+2,033-3,81410 files not shown
+2,147-3,94116 files

HardenedBSD/src de2c0f1 — lib/libthr/thread thr_umtx.h

libthr: Fix some bugs in trylock

1. When contester > 2, a release causes kernel set CONTENTION bit but
   with no owner. In this case, the userspace should be able to try the
   lock instead of fall immediately. We copy this from trylock2.
2. A PI mutex should consult to kernel instead of decided by userspace
   itself.

Reviewed by:    kib
MFC after:      2 weeks
Differential Revision: https://reviews.freebsd.org/D60427
DeltaFile
+7-1lib/libthr/thread/thr_umtx.h
+7-11 files

HardenedBSD/src 78ae174 — sys/dev/mlx5/mlx5_ib mlx5_ib_devx.c, sys/ofed/include/uapi/rdma mlx5_user_ioctl_cmds.h

mlx5: support DevX UMEM page size bitmap

rdma-core's mlx5dv_devx_umem_reg_ex() passes the page sizes the caller
can use in MLX5_IB_ATTR_DEVX_UMEM_REG_PGSZ_BITMAP.  Add the attribute and
choose the UMEM page size, page offset and MTT count the way Linux commit
7610ab57de56 ("RDMA/mlx5: Allow larger pages in DevX umem") does.

Linux looks at the DMA list only.  The UMEM is mapped at an IOVA equal to
the DMA address of its first byte, ib_umem_find_best_pgsz() picks the
largest page size of the bitmap that this mapping allows, and
devx_umem_find_best_pgsize() halves it while the first DMA address is not
aligned to it or the length is not a multiple of it, stopping at
PAGE_SIZE, even if that is below every size in the bitmap.

The FreeBSD OFED layer has none of the ib_umem helpers this relies on,
so local copies of the current Linux ones are added.
ib_umem_find_best_pgoff() and ib_umem_dma_offset() come from Linux
commit b045db62f6f6 ("RDMA/mlx5: Use ib_umem_find_best_pgoff() for
SRQ"), ib_umem_num_dma_blocks() from Linux commit a665aca89a41

    [18 lines not shown]
DeltaFile
+143-9sys/dev/mlx5/mlx5_ib/mlx5_ib_devx.c
+1-0sys/ofed/include/uapi/rdma/mlx5_user_ioctl_cmds.h
+144-92 files

HardenedBSD/src 99edcc3 — lib/libthr/thread thr_private.h thr_mutex.c

libthr: Reorder pthread mutex to prevent false sharing

On a 64 byte cache line CPU (amd64), m_owner is contended by all of
the shared processes. However, after finding one winner, mtx is
enqueued, which trigger a cache refresh from other processors. Reorder
mtx so that m_lock and m_qu will not be in the same cache line.

Notice that this doesn't affet arch that expose 128 bytes cache line
line aarch64 or powerpc.

Reviewed by:    kib, markj
MFC after:      2 weeks
Differential Revision: https://reviews.freebsd.org/D60434
DeltaFile
+9-0lib/libthr/thread/thr_mutex.c
+5-1lib/libthr/thread/thr_private.h
+14-12 files

HardenedBSD/src bea382f — sys/kern vfs_vnops.c

kern/coredump_vnode.c: avoid dumping to the mount point we suspended

PR:     299095
Reported by:    Rick Richard <rick at sloservers.com>
Reviewed by:    markj
Tested by:      Rick Richard <rick at sloservers.com> (previous version)
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
Differential revision:  https://reviews.freebsd.org/D60283
DeltaFile
+45-1sys/kern/vfs_vnops.c
+45-11 files