HardenedBSD/src b4d07f7 — sys/contrib/openzfs/man/man8 zstream.8, sys/contrib/openzfs/module/os/freebsd/spl acl_common.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/cross-dso-cfi
DeltaFile
+0-2,076sys/contrib/openzfs/module/os/linux/zfs/zio_crypt.c
+0-1,809sys/contrib/openzfs/module/os/freebsd/zfs/zio_crypt.c
+1,679-0sys/contrib/openzfs/module/zfs/zio_crypt.c
+0-1,307sys/contrib/openzfs/module/os/freebsd/spl/acl_common.c
+218-158sys/contrib/openzfs/man/man8/zstream.8
+0-363sys/contrib/openzfs/module/os/freebsd/zfs/zfs_ioctl_compat.c
+1,897-5,713233 files not shown
+7,175-7,292239 files

HardenedBSD/src 5953a91 — sys/contrib/openzfs/man/man8 zstream.8, sys/contrib/openzfs/module/os/freebsd/spl acl_common.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+0-2,076sys/contrib/openzfs/module/os/linux/zfs/zio_crypt.c
+0-1,809sys/contrib/openzfs/module/os/freebsd/zfs/zio_crypt.c
+1,679-0sys/contrib/openzfs/module/zfs/zio_crypt.c
+0-1,307sys/contrib/openzfs/module/os/freebsd/spl/acl_common.c
+218-158sys/contrib/openzfs/man/man8/zstream.8
+0-363sys/contrib/openzfs/module/os/freebsd/zfs/zfs_ioctl_compat.c
+1,897-5,713233 files not shown
+7,175-7,292239 files

HardenedBSD/src 5fa1c93 — sys/dev/sound/usb uaudio.c

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+22-1sys/dev/sound/usb/uaudio.c
+22-11 files

HardenedBSD/src e8a1d69 — sys/contrib/openzfs/man/man8 zstream.8, sys/contrib/openzfs/module/os/freebsd/spl acl_common.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+0-2,076sys/contrib/openzfs/module/os/linux/zfs/zio_crypt.c
+0-1,809sys/contrib/openzfs/module/os/freebsd/zfs/zio_crypt.c
+1,679-0sys/contrib/openzfs/module/zfs/zio_crypt.c
+0-1,307sys/contrib/openzfs/module/os/freebsd/spl/acl_common.c
+218-158sys/contrib/openzfs/man/man8/zstream.8
+0-363sys/contrib/openzfs/module/os/freebsd/zfs/zfs_ioctl_compat.c
+1,897-5,713233 files not shown
+7,175-7,292239 files

HardenedBSD/src 7661c5e — sys/dev/sound/usb uaudio.c

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+22-1sys/dev/sound/usb/uaudio.c
+22-11 files

HardenedBSD/src 806adba — lib/libpfctl libpfctl.c, sys/netpfil/pf pf_nl.h

libpfctl: decode PFR_A_AF into a u8

The kernel sends PFR_A_AF as a u32, although it is documented and
parsed as a u8, and libpfctl decoded it with snl_attr_get_uint32()
straight into the u8 pfra_af.  That overwrote pfra_net, pfra_not and
pfra_fback, and left pfra_af zero on big-endian hosts.

Decode it via a temporary, and accept a u8 as well, so that the
kernel can be corrected later without breaking libpfctl.

Reviewed by:            kp
Approved by:            kp (mentor)
Fixes:                  f27e44e2e3b5 ("pf: convert DIOCRGETADDRS to netlink")
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60110
DeltaFile
+17-1lib/libpfctl/libpfctl.c
+1-1sys/netpfil/pf/pf_nl.h
+18-22 files

HardenedBSD/src 0dac2c5 — sys/contrib/openzfs/cmd/zinject translate.c, sys/contrib/openzfs/cmd/zpool zpool_main.c

Revert "zpool: Add zpool status -vv error ranges"

This reverts commit e903655c50fe2e710a4cdfe6e638454012ef6324.

The commit comes from the OpenZFS merge.

OpenZFS introduced in d2f5cb3a5 two new libraries: libbtree and
librange_tree. We don't have these in our build.

To keep diffs as minimal as possible and avoid future breakages we
should import these for the FreeBSD build with bells and whistles.

After this issue is resolved, e903655c5 can be re-committed.
DeltaFile
+25-292sys/contrib/openzfs/lib/libzfs/libzfs_pool.c
+51-182sys/contrib/openzfs/cmd/zpool/zpool_main.c
+0-173sys/contrib/openzfs/tests/zfs-tests/tests/functional/cli_root/zpool_status/zpool_status_-v.ksh
+4-75sys/contrib/openzfs/cmd/zinject/translate.c
+3-46sys/contrib/openzfs/module/zfs/zfs_znode.c
+1-23sys/contrib/openzfs/module/zfs/zfs_ioctl.c
+84-79111 files not shown
+94-88217 files

HardenedBSD/src 77b7540 — sys/dev/sound/usb uaudio.c

snd_uaudio: Read the UAC2 sample rate back after setting it

Some devices only apply a new sample rate once it has been read back,
and produce no sound at all otherwise.

PR:             294803
Reported by:    tatsuki_makino at hotmail.com
Tested by:      tatsuki_makino at hotmail.com
MFC after:      2 weeks
Sponsored by:   The FreeBSD Foundation
Reviewed by:    emaste
Differential Revision:  https://reviews.freebsd.org/D59616

(cherry picked from commit 694923501f56a5d4519f548ee06db603f9486bc7)
DeltaFile
+22-1sys/dev/sound/usb/uaudio.c
+22-11 files

HardenedBSD/src 6aef93f — cddl/lib/libzfs Makefile

Revert "zfs: add btree.c to libzfs"

This reverts commit b4fdb5c236d00825c8e3ea8ffc7bc25dafb6abcf.
DeltaFile
+0-2cddl/lib/libzfs/Makefile
+0-21 files

HardenedBSD/src b4fdb5c — cddl/lib/libzfs Makefile

zfs: add btree.c to libzfs

Fixes breakage from 34f9f5680 (openzfs/zfs at 1f380a4f3)
DeltaFile
+2-0cddl/lib/libzfs/Makefile
+2-01 files

HardenedBSD/src 081f751 — stand/powerpc/ofw ofwfdt.c

stand/powerpc/ofw: do not truncate device tree properties to 1024 bytes

When the OpenFirmware loader flattens the firmware device tree into the
FDT it hands to the kernel (usefdt=1, i.e. on every real-mode OF system
such as pSeries LPARs and QEMU pseries guests), add_node_to_fdt() clamps
every property value to 1024 bytes.  Any larger property reaches the
kernel truncated.

On QEMU pseries the PCI host bridge's "interrupt-map" is 3584 bytes
(32 slots x 4 pins x 7 cells), so only the entries for slots 0-8 survive
and the entry for slot 9 is cut in the middle.  A PCI device in slot 9
or above therefore gets no INTx routing (irq 0), and with INVARIANTS the
partial trailing entry trips the "ofw_bus_search_intrmap: truncated map"
assertion in ofw_bus_search_intrmap() during PCI attach, panicking the
kernel as soon as such a device is present.  "ibm,drc-indexes",
"ibm,drc-names" and "ibm,drc-power-domains" are cut the same way.

Drop the clamp.  fdt_setprop() already reports a property that does not
fit into the FDT buffer, so no separate limit is needed.

    [4 lines not shown]
DeltaFile
+0-2stand/powerpc/ofw/ofwfdt.c
+0-21 files

HardenedBSD/src 34f9f56 — sys/contrib/openzfs/man/man8 zstream.8, sys/contrib/openzfs/module/os/freebsd/spl acl_common.c

zfs: merge openzfs/zfs at 1f380a4f3

Notable upstream pull request merges:
 #17864 e903655c5 zpool: Add zpool status -vv error ranges
 #18820 -multiple zdb: account pending DDT-log frees in leak detection
 #18884 -multiple zio_crypt: establish platform interface; rework common
                  code to use it
 #19010 -multiple zfs_namecheck: reject '.' and '..' before a snapshot or
                  bookmark
 #19031 994fb1703 Fix metaslab count assertion in metaslab_group_alloc()
                  for small vdevs
 #19093 f5b2fc8e2 zfs_ctldir: make .zfs/snapshot/<name> btime the snapshot
                  creation time
 #19097 2dece2a34 zstream: report invalid record context without assertions
 #19102 78f49e1dd vdev_disk: simplify alignment checks for linear ABDs
 #19108 -multiple Fix permanent errors misfiled into the scrub error log
 #19110 fa4bc4dec spa_errlog: don't let one unresolvable entry hide the
                  whole error log
 #19116 b6dde8a17 zio_crypt: free the key unwrap uios when decryption fails

    [13 lines not shown]
DeltaFile
+0-2,076sys/contrib/openzfs/module/os/linux/zfs/zio_crypt.c
+0-1,809sys/contrib/openzfs/module/os/freebsd/zfs/zio_crypt.c
+1,679-0sys/contrib/openzfs/module/zfs/zio_crypt.c
+0-1,307sys/contrib/openzfs/module/os/freebsd/spl/acl_common.c
+218-158sys/contrib/openzfs/man/man8/zstream.8
+0-363sys/contrib/openzfs/module/os/freebsd/zfs/zfs_ioctl_compat.c
+1,897-5,713234 files not shown
+7,659-7,353240 files

HardenedBSD/src e1c59c9 — sys/dev/cxgbe adapter.h t4_main.c

cxgbe: Report SR-IOV VF status

Retain the PF-accepted MAC and VLAN settings from the per-port t4iov
companion and expose them through the corresponding cxgbe ifnet.

Publish, snapshot, and destroy the cache under the existing adapter
synchronized-operation mechanism so status queries cannot race IOV
configuration or teardown.

Track successful t4iov attachment independently of the active VF count.
Restrict reporting to the port main VI, return an empty status for a
supported but unconfigured PF, and omit status from VF and auxiliary
VIs.

Reviewed by:    jhb
Sponsored by:   BBOX.io
Differential Revision:  https://reviews.freebsd.org/D58741
DeltaFile
+93-22sys/dev/cxgbe/t4_iov.c
+66-0sys/dev/cxgbe/t4_main.c
+10-0sys/dev/cxgbe/adapter.h
+169-223 files

HardenedBSD/src fa78e1d — share/man/man4 pci.4, sys/dev/pci pci_private.h pci_iov.c

pci: Reserve bus numbers required by SR-IOV VFs

Some firmware assigns only one bus number to each PCI-PCI bridge.  This
prevents later SR-IOV VF enumeration when a VF routing ID falls on a bus
number already allocated to a sibling bridge.

Reserve only the additional bus numbers required by SR-IOV PFs.
Enumerate all directly attached functions before child drivers and
bridges attach, inspect their device_t objects for SR-IOV, and grow the
PCI bus resource through the highest possible VF routing ID.

First VF Offset and VF Stride may change when NumVFs changes.  Probe
every valid NumVFs value and preserve the original setting.  When the
upstream hierarchy uses ARI, temporarily enable the SR-IOV ARI Hierarchy
control in the lowest-numbered PF while sizing, then restore it.  Scope
active-VF detection to each conventional PCI slot; an ARI bus remains
one slot-0 hierarchy.  If firmware left VFs enabled on a device, do not
modify it and reserve only its active layout.


    [20 lines not shown]
DeltaFile
+189-0sys/dev/pci/pci.c
+9-9sys/dev/pci/pci_iov.c
+10-1share/man/man4/pci.4
+3-0sys/powerpc/ofw/ofw_pcibus.c
+3-0sys/dev/pci/pci_private.h
+214-105 files

HardenedBSD/src 5926bc3 — lib/libc/gen sysctl.3, sys/kern kern_sysctl.c imgact_elf.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/cross-dso-cfi
DeltaFile
+68-0tests/sys/netpfil/pf/table.sh
+11-4sys/netpfil/pf/pf_table.c
+0-9sys/kern/imgact_elf.c
+3-0lib/libc/gen/sysctl.3
+1-1sys/kern/kern_sysctl.c
+83-145 files

HardenedBSD/src a868a35 — lib/libc/gen sysctl.3, sys/kern kern_sysctl.c imgact_elf.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+68-0tests/sys/netpfil/pf/table.sh
+11-4sys/netpfil/pf/pf_table.c
+0-9sys/kern/imgact_elf.c
+3-0lib/libc/gen/sysctl.3
+1-1sys/kern/kern_sysctl.c
+83-145 files

HardenedBSD/src 1244f60 — sys/amd64/amd64 exec_machdep.c pmap.c, sys/amd64/include cpufunc.h

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+76-0sys/amd64/amd64/machdep.c
+29-0sys/amd64/amd64/initcpu.c
+26-1sys/amd64/amd64/sys_machdep.c
+23-0sys/amd64/include/cpufunc.h
+14-0sys/amd64/amd64/pmap.c
+10-0sys/amd64/amd64/exec_machdep.c
+178-111 files not shown
+212-217 files

HardenedBSD/src c0c3e35 — lib/libc/gen sysctl.3, sys/kern kern_sysctl.c imgact_elf.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+68-0tests/sys/netpfil/pf/table.sh
+11-4sys/netpfil/pf/pf_table.c
+0-9sys/kern/imgact_elf.c
+3-0lib/libc/gen/sysctl.3
+1-1sys/kern/kern_sysctl.c
+83-145 files

HardenedBSD/src ca6dd83 — sys/amd64/amd64 exec_machdep.c pmap.c, sys/amd64/include cpufunc.h

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+76-0sys/amd64/amd64/machdep.c
+29-0sys/amd64/amd64/initcpu.c
+26-1sys/amd64/amd64/sys_machdep.c
+23-0sys/amd64/include/cpufunc.h
+14-0sys/amd64/amd64/pmap.c
+10-0sys/amd64/amd64/exec_machdep.c
+178-111 files not shown
+212-217 files

HardenedBSD/src da0067d — sbin/ipfw nat64clat.c

ipfw: guard against NULL deref with clat/plat prefixes without length

Found with:     Claude Code Sonnet 5
MFC after:      2 weeks

(cherry picked from commit 47b02ace19c53e72ad2290d974025292ff97464a)
DeltaFile
+3-0sbin/ipfw/nat64clat.c
+3-01 files

HardenedBSD/src a76e986 — lib/libc/gen sysctl.3, sys/kern kern_sysctl.c

sysctl: Return ECAPMODE when trying to access sysctls in capability mode

We have always returned EPERM in this case, but it's incorrect, we
should return ECAPMODE for capability mode violations.  Fix the errno
value.

Reviewed by:    emaste
MFC after:      2 weeks
Differential Revision:  https://reviews.freebsd.org/D59887
DeltaFile
+3-0lib/libc/gen/sysctl.3
+1-1sys/kern/kern_sysctl.c
+4-12 files

HardenedBSD/src 5799049 — sys/kern imgact_elf.c

exec: Remove an unneeded capability mode check

The subsequent namei() call is relative to AT_FDCWD, and such lookups
are always disallowed in capability mode.

No functional change intended.

Reviewed by:    emaste
Differential Revision:  https://reviews.freebsd.org/D59888
DeltaFile
+0-9sys/kern/imgact_elf.c
+0-91 files

HardenedBSD/src d95433e — sys/amd64/amd64 sys_machdep.c, sys/x86/include sysarch.h

amd64: add userspace control for disabling splitlocks

(cherry picked from commit 51cea5416a2421f29d22100bc71ab6486b1dc54a)
DeltaFile
+26-1sys/amd64/amd64/sys_machdep.c
+2-0sys/x86/include/sysarch.h
+28-12 files

HardenedBSD/src 6d6a824 — sys/amd64/amd64 vm_machdep.c exec_machdep.c, sys/amd64/include proc.h md_var.h

amd64: support for tracking per-thread 'disable splitlocks' state

(cherry picked from commit e318f24c0f53b52bd280b827509ad752db0497bf)
DeltaFile
+36-0sys/amd64/amd64/machdep.c
+14-0sys/amd64/amd64/pmap.c
+10-0sys/amd64/amd64/exec_machdep.c
+5-0sys/amd64/include/md_var.h
+2-0sys/amd64/include/proc.h
+2-0sys/amd64/amd64/vm_machdep.c
+69-03 files not shown
+72-09 files

HardenedBSD/src c52f99a — sys/amd64/amd64 machdep.c

amd64: use WRMSRNS immediate form to update splitlock control, when available

(cherry picked from commit 20c09e6fece29dbcf4835b4dd90e969f1b9b3e59)
DeltaFile
+34-4sys/amd64/amd64/machdep.c
+34-41 files

HardenedBSD/src 0dce4f2 — sys/amd64/amd64 mp_machdep.c machdep.c, sys/amd64/include md_var.h pcpu.h

amd64: cache MSR_MEMORY_CTL in pcpu

(cherry picked from commit 74d325fee2dbcb5f8541819481ce76f87c151a21)
DeltaFile
+11-0sys/amd64/amd64/initcpu.c
+3-4sys/amd64/amd64/machdep.c
+2-1sys/amd64/include/pcpu.h
+2-0sys/amd64/amd64/mp_machdep.c
+1-0sys/amd64/include/md_var.h
+19-55 files

HardenedBSD/src b4a9afd — sys/amd64/amd64 machdep.c initcpu.c, sys/amd64/include md_var.h

amd64: calculate if hardware supports disabling splitlocks

(cherry picked from commit d8c1abb0e3409314fb89400bc85b5051649e91ab)
DeltaFile
+18-0sys/amd64/amd64/initcpu.c
+11-0sys/amd64/amd64/machdep.c
+3-0sys/amd64/include/md_var.h
+32-03 files

HardenedBSD/src 77a99f3 — sys/amd64/amd64 trap.c

amd64: handle #AC in kernel mode

(cherry picked from commit c6d7235ac15d208435a839bf847dd898d9b1d9fe)
DeltaFile
+8-0sys/amd64/amd64/trap.c
+8-01 files

HardenedBSD/src ca7aa1c — sys/amd64/include proc.h

amd64: add md thread flags word

(cherry picked from commit dc975612213369f597449ced5a3c5edabc2aae6d)
DeltaFile
+1-0sys/amd64/include/proc.h
+1-01 files

HardenedBSD/src 54cb4bf — sys/amd64/include cpufunc.h

amd64: gate WRMSRNS immediate form on compiler support

(cherry picked from commit 53fe018630d06eeef6791cfacaa6dc9acdf4d669)
DeltaFile
+10-0sys/amd64/include/cpufunc.h
+10-01 files