HardenedBSD/src b7632e1 — sys/dev/bnxt/bnxt_en bnxt_hwrm.c bnxt_sysctl.c, usr.sbin/sysconf sysconf_poudriere.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+2,257-0sys/dev/bnxt/bnxt_en/bnxt_ktls.c
+1,080-0sys/dev/bnxt/bnxt_en/bnxt_mpc.c
+793-264sys/dev/bnxt/bnxt_en/if_bnxt.c
+677-0usr.sbin/sysconf/sysconf_poudriere.c
+654-19sys/dev/bnxt/bnxt_en/bnxt_sysctl.c
+422-156sys/dev/bnxt/bnxt_en/bnxt_hwrm.c
+5,883-439153 files not shown
+10,401-2,010159 files

HardenedBSD/src a39a861 — sys/dev/acpica acpi_timer.c, sys/fs/cd9660 cd9660_rrip.c

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+167-61sys/fs/cd9660/cd9660_rrip.c
+84-134sys/dev/acpica/acpi_timer.c
+174-35usr.sbin/pciconf/pciconf.c
+101-88sys/kern/kern_jail.c
+69-70usr.sbin/bhyve/pci_emul.c
+93-0sys/sys/jail.h
+688-38849 files not shown
+1,054-61255 files

HardenedBSD/src 2baf9b6 — cddl/contrib/opensolaris/tools/ctf/cvt util.c, lib/libthr/thread thr_private.h thr_mutex.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+43-39sys/dev/hyperv/vmbus/hyperv_mmu.c
+48-0sys/dev/amdgpio/amdgpio.c
+0-10cddl/contrib/opensolaris/tools/ctf/cvt/util.c
+1-8lib/libthr/thread/thr_mutex.c
+0-6sys/dev/bnxt/bnxt_en/bnxt_dcb.c
+6-0lib/libthr/thread/thr_private.h
+98-632 files not shown
+100-658 files

HardenedBSD/src c6af277 — sys/compat/linsysfs linsysfs.c, usr.bin/hexdump odsyntax.c

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+56-2sys/compat/linsysfs/linsysfs.c
+1-1usr.bin/hexdump/odsyntax.c
+57-32 files

HardenedBSD/src 7ed9a5a — sys/compat/linsysfs linsysfs.c

linux: Exposes renderD nodes and chardev in sysfs

To allow normal users to render through the render device, we expose the
renderD node. This enables Wayland applications to use hardware
acceleration when running under the Linux emulator.

Additionally, libdrm and Mesa need to look up
/sys/dev/char/<major>:<minor> and <pcidev>/drm to identify the
corresponding renderer device (e.g., a renderD device). We expose this
path as well so that libdrm can locate the renderer.

Differential Revision: https://reviews.freebsd.org/D59190

(cherry picked from commit 102adf88e6e8f83a9ab9769732d168c501f8eb6c)
DeltaFile
+56-2sys/compat/linsysfs/linsysfs.c
+56-21 files

HardenedBSD/src 8c47cbc — usr.bin/hexdump odsyntax.c

hexdump: Support octal and hex for -N option

GNU hexdump supports octal and hex, we add supports for BSD style
hexdump for better compatibility.

See: https://github.com/llvm/llvm-project/pull/206581/

MFC after:      2 weeks
Sponsored by:   The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D58074

(cherry picked from commit b8f1972d51cf93ba4393d621b126dbd408423b87)
DeltaFile
+1-1usr.bin/hexdump/odsyntax.c
+1-11 files

HardenedBSD/src 5b1f1fd — sys/dev/hyperv/vmbus hyperv_mmu.c

hyperv: Fix single page invalidation path

A single page invalidation sets addr2 == 0. In the original code, it
falsely flush the whole address in non global pmap. However, the
kernel pmap are all PG_G, which means a single page flush will always be
staled and thus become invalid. As a result, we set parameter based on
their op in a new helper function instead of relying on args. This
affects only on AMD platform as Intel has their PTI implementation.

PR:     291577
Tested by:      franco at opnsense.org
MFC after:      2 weeks
Differential Revision: https://reviews.freebsd.org/D60380
DeltaFile
+43-39sys/dev/hyperv/vmbus/hyperv_mmu.c
+43-391 files

HardenedBSD/src 305c304 — lib/libthr/thread thr_init.c thr_private.h

libthr: Support disable spinloop

Like yieldloops, we shoulde be able to set _thr_spinloops to zero.
Originally, it makes us to enformce default spin time even if we try to
disable it. Make MUTEX_ADAPTIVE_SPINS a one time initialization now.

Reviewed by:    kib
MFC after:      2 weeks
Differential Revision: https://reviews.freebsd.org/D60486
DeltaFile
+1-8lib/libthr/thread/thr_mutex.c
+6-0lib/libthr/thread/thr_private.h
+1-1lib/libthr/thread/thr_init.c
+8-93 files

HardenedBSD/src 16d92e9 — sys/dev/amdgpio amdgpio.c

amdgpio: Suspend routine

Mask all interrupts when suspending and warn when there are unserviced
interrupts which might block entry to S0i3.

In the future we won't want to mask wake interrupts.

Once we can actually make use of GPIO interrupts on x86, we'll also want
to unmask relevant pins when resuming.

Reviewed by:    aokblast, avg
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D51589
DeltaFile
+48-0sys/dev/amdgpio/amdgpio.c
+48-01 files

HardenedBSD/src 6c3f2b8 — sys/dev/mgb if_mgb.c

mgb: Correct TX interrupt bit

The TX interrupt handler checked MGB_INTR_STS_RX(qidx) instead of
MGB_INTR_STS_TX(qidx) -- presumably a copy-paste issue.

Because the driver does not use TX interrupts so there was no actual
issue in practice.

Reviewed by:    adrian
Sponsored by:   The FreeBSD Foundation
Fixes: 8890ab7758b8 ("Introduce if_mgb driver for Microchip LAN743x PCIe NIC")
Differential Revision: https://reviews.freebsd.org/D60550
DeltaFile
+1-1sys/dev/mgb/if_mgb.c
+1-11 files

HardenedBSD/src 31cbd8f — sys/dev/bnxt/bnxt_en bnxt_dcb.c

bnxt_en: dcb: stop zeroing ETS and PFC config in bnxt_dcb_init()

bnxt_dcb_init() currently pushes all-zero ETS and PFC settings to
the firmware at every attach. This reserves bandwidth allocation
for RoCE traffic, which prevents L2 traffic from reaching line rate.

These settings should only be updated with valid values when the
RoCE driver is loaded. Therefore, we should stop programming them
during bnxt_dcb_init().

Signed-off-by:  Andy Gospodarek <gospo at broadcom.com>
Reviewed by:    chandrakanth.patil_broadcom.com, gallatin
MFC after:      2 weeks
Sponsored by:   Broadcom Inc.
Differential Revision:  https://reviews.freebsd.org/D60516
DeltaFile
+0-6sys/dev/bnxt/bnxt_en/bnxt_dcb.c
+0-61 files

HardenedBSD/src e959f2a — cddl/contrib/opensolaris/tools/ctf/cvt util.c

ctf*: exit with error upon terminate()

The initial port of the CTF tools had a FreeBSD-specific patch to print
the termination message but exit with a 0 status, with a goal of getting
as much to build as possible and silently ignoring any issues.

We're now past the point where silently ignoring failures makes sense.
Any future issues need to be found and addressed.

PR:             276826
PR:             276930 [exp-run]
Reviewed by:    markj
Sponsored by:   The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D43743
DeltaFile
+0-10cddl/contrib/opensolaris/tools/ctf/cvt/util.c
+0-101 files

HardenedBSD/src 617af6c — libexec/rtld-elf map_object.c, sys/kern kern_jail.c

HBSD: Resolve merge conflicts

Signed-off-by:  Shawn Webb <shawn.webb at hardenedbsd.org>
DeltaFile
+0-5sys/kern/kern_jail.c
+0-5libexec/rtld-elf/map_object.c
+0-102 files

HardenedBSD/src 0c13d2d — sys/dev/acpica acpi_timer.c, sys/fs/cd9660 cd9660_rrip.c

Merge remote-tracking branch 'rad/freebsd/15-stable/main' into hardened/15-stable/main

Conflicts:
        libexec/rtld-elf/map_object.c (unresolved)
        sys/kern/kern_jail.c (unresolved)
DeltaFile
+167-61sys/fs/cd9660/cd9660_rrip.c
+84-134sys/dev/acpica/acpi_timer.c
+174-35usr.sbin/pciconf/pciconf.c
+104-86sys/kern/kern_jail.c
+69-70usr.sbin/bhyve/pci_emul.c
+93-0sys/sys/jail.h
+691-38647 files not shown
+1,004-60653 files

HardenedBSD/src 6d8b5a8 — sys/dev/sound/pcm mixer.c

HBSD: Resolve merge conflict

Leave the microphone muted by default.

Signed-off-by:  Shawn Webb <shawn.webb at hardenedbsd.org>
DeltaFile
+0-4sys/dev/sound/pcm/mixer.c
+0-41 files

HardenedBSD/src 31393cf — sys/dev/bnxt/bnxt_en bnxt_hwrm.c bnxt_sysctl.c, usr.sbin/sysconf sysconf_poudriere.c

Merge remote-tracking branch 'rad/freebsd/current/main' into hardened/current/master

Conflicts:
        sys/dev/sound/pcm/mixer.c (unresolved)
DeltaFile
+2,257-0sys/dev/bnxt/bnxt_en/bnxt_ktls.c
+1,080-0sys/dev/bnxt/bnxt_en/bnxt_mpc.c
+793-264sys/dev/bnxt/bnxt_en/if_bnxt.c
+677-0usr.sbin/sysconf/sysconf_poudriere.c
+654-19sys/dev/bnxt/bnxt_en/bnxt_sysctl.c
+422-156sys/dev/bnxt/bnxt_en/bnxt_hwrm.c
+5,883-439146 files not shown
+10,305-1,945152 files

HardenedBSD/src 02880dd — sys/dev/thunderbolt nhi_var.h nhi_reg.h

thunderbolt: Router suspend routine

Suspend routine for USB4 v1.0 NHIs. This will work on v2.0 NHIs too for
now, but there's ideally a different method we should be using for those
in fine.

Reviewed by:    imp, ngie, emaste
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D49453
DeltaFile
+78-0sys/dev/thunderbolt/router.c
+13-0sys/dev/thunderbolt/nhi.c
+11-0sys/dev/thunderbolt/router_var.h
+4-2sys/dev/thunderbolt/nhi_pci.c
+5-0sys/dev/thunderbolt/nhi_reg.h
+2-0sys/dev/thunderbolt/nhi_var.h
+113-26 files

HardenedBSD/src 39f7dbf — share/mk bsd.dirs.mk

bsd.dirs.mk: Improve "installing DIRS" message

Some of these messages looked at first glance like they were incorrectly
concatenated, e.g. "installing DIRS testsFILESDIR".  Add a colon to
clarify.

Reviewed by:    brooks, imp
Sponsored by:   The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D60525
DeltaFile
+1-1share/mk/bsd.dirs.mk
+1-11 files

HardenedBSD/src 570d050 — . ObsoleteFiles.inc, usr.bin/ncal/tests Makefile legacy_test.sh

ncal: convert legacy TAP tests to ATF

MFC after:      2 weeks
Sponsored by:   ConnectWise
Pull Request:   https://github.com/freebsd/freebsd-src/pull/2465
Reviewed by:    imp
DeltaFile
+148-0usr.bin/ncal/tests/ncal_test.sh
+0-79usr.bin/ncal/tests/regress.sh
+0-5usr.bin/ncal/tests/legacy_test.sh
+4-0ObsoleteFiles.inc
+1-2usr.bin/ncal/tests/Makefile
+153-865 files

HardenedBSD/src d3c788f — . Makefile.inc1

Makefile.inc1: Don't unnecessarily ignore rm errors

For rm -f it's not an error if the files do not exist.  If there's any
other error it's presumably a real issue, so avoid ignoring all errors.

Reviewed by:    brooks, adrian
Sponsored by:   The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D56714
DeltaFile
+4-4Makefile.inc1
+4-41 files

HardenedBSD/src 24d5194 — . Makefile.inc1

build: Emit a warning for build targets run as root

Build targets should generally be run as an unprivileged user.  Even
though building as root is discouraged many users do so, so just start
with a warning.

Reviewed by:    brooks
Differential Revision: https://reviews.freebsd.org/D50352
DeltaFile
+4-0Makefile.inc1
+4-01 files

HardenedBSD/src 406a74f — usr.sbin/bhyve/aarch64 bhyverun_machdep.c

bhyve: Use the new spelling of MPIDR_Aff*

Fixes:  6bf6fe1d70e7 ("arm64: Fix the MPIDR_EL1 field names")
 Sponsored by:  Arm Ltd
DeltaFile
+3-3usr.sbin/bhyve/aarch64/bhyverun_machdep.c
+3-31 files

HardenedBSD/src 87f0db8 — . Makefile.inc1

Makefile.inc1: Update comment wrt world build targets

The utility targets described by this comment are in fact related to
building (buildworld), not installing (which is included in
`make world`).

Reviewed by:    brooks
Sponsored by:   The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D56715
DeltaFile
+2-2Makefile.inc1
+2-21 files

HardenedBSD/src ac90931 — sys/amd64/amd64 support.S

x86: Fix retpoline capitalization

Fixes: 74d971fe1561 ("x86: Add external retpoline thunk")
DeltaFile
+1-1sys/amd64/amd64/support.S
+1-11 files

HardenedBSD/src 74d971f — sys/amd64/amd64 support.S, sys/i386/i386 support.S

x86: Add external retpoline thunk

This allows use of -mindirect-branch=thunk-extern, and is only a few
bytes of dead code if not used.

Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D60524
DeltaFile
+10-0sys/i386/i386/support.S
+10-0sys/amd64/amd64/support.S
+20-02 files

HardenedBSD/src 81b5b22 — usr.sbin/makefs/tests makefs_zfs_tests.sh, usr.sbin/makefs/zfs fs.c

makefs/zfs: count "." in the link count and size of dataset roots

The root directory of a dataset is populated from an fsnode that is the
"." entry of the staging directory, and its children are the siblings of
that node, so the loop that computes the link count and the size of the
directory (which expects "." among the children, as the nodes of the
other directories have) never counts it.  The link count of the root of
every dataset is one less than it should be (1 for an empty dataset
instead of 2, 19 instead of 20 for a root with 18 subdirectories), and
so is its size.

fts(3) trusts the link count of the directories of ZFS when called with
FTS_NOSTAT and FTS_PHYSICAL: it stops looking for subdirectories once it
has seen as many as the link count says, and does not descend into the
ones it did not look at.  As a result find(1), and rm(1) when it does
not need to stat the entries, silently skip directories of a pool made
by makefs.  On a root filesystem made by makefs, find / does not list
/etc at all.


    [11 lines not shown]
DeltaFile
+54-0usr.sbin/makefs/tests/makefs_zfs_tests.sh
+4-3usr.sbin/makefs/zfs/fs.c
+58-32 files

HardenedBSD/src aa40869 — sys/arm64/vmm/io vgic_v3.c

arm64/vmm: vgic_v3: Fix missing free of vgic_cpu->private_irqs

vgic_cpu->private_irqs is allocated but never freed, as a result leaking
memory whenever the vmm module is unloaded. Add the missing free.

Signed-off-by: Kajetan Puchalski <kajetan.puchalski at arm.com>
Reviewed by:    andrew
Sponsored by:   Arm Ltd
Pull Request:   https://github.com/freebsd/freebsd-src/pull/2439
DeltaFile
+1-0sys/arm64/vmm/io/vgic_v3.c
+1-01 files

HardenedBSD/src 7081201 — sys/arm64/vmm/io vgic_v3.c

arm64/vmm: vgic_v3: Set EOI for level-triggered interrupts

ICH_LR_EL2 bit 41 (EOI) determines whether a maintenance interrupt will
be asserted if the interrupt identified by the LR's vINTID is
deactivated. For level-triggered interrupts, that maintenance interrupt
is necessary for the host to resample the current level once the
interrupt is deactivated.

Set the EOI bit when flushing level-triggered interrupts into LRs.

Signed-off-by: Kajetan Puchalski <kajetan.puchalski at arm.com>
Reviewed by:    andrew
Sponsored by:   Arm Ltd
Pull Request:   https://github.com/freebsd/freebsd-src/pull/2437
DeltaFile
+4-5sys/arm64/vmm/io/vgic_v3.c
+4-51 files

HardenedBSD/src 6bf6fe1 — sys/arm64/include armreg.h, sys/arm64/vmm vmm_reset.c

arm64: Fix the MPIDR_EL1 field names

Use the field names from the Arm Documentation for the MPIDR_EL1
register. These will later be generated from a BSD Licensed JSON file
so to reduce the diff for that rename now.

Reviewed by:    kajetan.puchalski_arm.com
Sponsored by:   Arm Ltd
Differential Revision:  https://reviews.freebsd.org/D59176
DeltaFile
+12-12sys/arm64/include/armreg.h
+4-4sys/arm64/vmm/vmm_reset.c
+3-3sys/arm64/vmm/io/vgic_v3.c
+19-193 files

HardenedBSD/src e8997a4 — sys/arm64/arm64 pmap.c

arm64: Use sysinsn.h to generate tlbi instructions

Some toolchains may not understand the .arch_extension.

Reviewed by:    jhb
Sponsored by:   Arm Ltd
Differential Revision:  https://reviews.freebsd.org/D59148
DeltaFile
+5-12sys/arm64/arm64/pmap.c
+5-121 files