PR misc/60836 - Be more careful with /etc/ifconfig.* cloner configs
Only config cloner interfaces when an /etc/ifconfig.${cloner}N file
exists, if N is completely numeric.
sys/param.h: Welcome to 11.99.9!
This version arises out of an abundance of caution in the slim chance
that anything is affected by the change in the signature of
sbappendcontrol to return void instead of a boolean indicating
success or failure; the caller is now (and, really, was already)
responsible for checking buffer sizes.
PR kern/60832: AF_LOCAL stream: sendmsg() with SCM_RIGHTS silently
drops data and descriptors but reports success
fifo: Followups to fix previous fifo_vnops.c change.
1. Fix open so with O_RDONLY and not O_NONBLOCK, it will block as
POSIX specifies until there are writers -- not until there are
writers _or_ a read is possible without blocking (which is always
immediately true because read will immediately report EOF).
This was a regression in the previous change which I failed to
catch because I committed the change a few days ago to hg and
forgot that I hadn't yet run all the applicable tests when I
exported it to CVS today -- I had only done the background
research and thought about the semantics.
2. Clear xfail on various tests that were fixed by the change.
PR kern/59056: poll POLLHUP bugs
PR kern/60789: read on fifo without writer may block
tzdata2netbsd - more updates for hg repo use
I am getting closer to having a version that "just works" using hg.
No changes that affect the use of the script with cvs as the repo.
sbappendcontrol never fails; nix the return value indicating success.
Cleanup which in principle changes the module ABI (I doubt there are
any modules out there that actually use sbappendcontrol, though rump
does use it across libraries) after:
PR kren/60832: AF_LOCAL stream: sendmsg() with SCM_RIGHTS silently
drops data and descriptors but reports success
XXX kernel revbump due to API/ABI change -- not for pullup
sendmsg(2): Don't fail with ENOBUFS on fd passing.
We don't fail with ENOBUFS if we're not fd-passing -- we just block
or fail earlier on with EAGAIN; no reason to invent a new failure
mode just for the fd-passing case.
Whether we should have _any_ path that checks the receiving socket's
receive buffer limit is another question, but it's silly for it to:
1. apply _only_ when passing fds,
2. trip only when the kernel internally expands the buffer, and/or
3. fail with ENOBUFS instead of blocking or failing with EAGAIN.
This change essentially matches FreeBSD's subversion r337328:
commit 5b0480f2cca0a4a04f21055ed769be93f11348de
Author: Mark Johnston <markj at FreeBSD.org>
Date: Sat Aug 4 20:26:54 2018 +0000
Don't check rcv sockbuf limits when sending on a unix stream socket.
[25 lines not shown]
sendmsg(2): Treat ENOBUFS on fd passing as a bug.
PR kern/60832: AF_LOCAL stream: sendmsg() with SCM_RIGHTS silently
drops data and descriptors but reports success
fifo: Fix EOF reporting in various cases.
According to POSIX:
> When attempting to read from an empty pipe or FIFO:
>
> If no process has the pipe open for writing, read() shall
> return 0 to indicate end-of-file.
So:
1. When there are no writers, after open(O_RDONLY|O_NONBLOCK),
blocking reads should immediately report EOF instead of blocking,
and should continue to immediately report EOF on repeated reads.
Previously, they would simply block, because the wrong socket was
initialized with SS_CANTRCVMORE -- though curiously, nonblocking
reads would consistently report EOF.
[42 lines not shown]
sendmsg(2): Report ENOBUFS instead of success on failure to pass fds.
PR kern/60832: AF_LOCAL stream: sendmsg() with SCM_RIGHTS silently
drops data and descriptors but reports success
cmsg: Test edge case of fd-passing near buffer size.
This test allows sendmsg to fail with ENOBUFS without blocking, and
verifies that the fds are received if it succeeds.
When passing file descriptors, sendmsg can fail with ENOBUFS it did
not or would not block because _after_ the blocking criterion is
tested in the AF-generic uipc_socket.c logic (essentially, whether
the data length + control length would exceed the send buffer size),
the control buffer is expanded on some architectures by converting
each int file descriptor to a struct file pointer in the kernel, and
then the buffer size is checked again in AF_LOCAL-specific logic when
unp_send calls sbappendcontrol.
Frankly I think this is a bad design, and sendmsg should just not
fail for this reason if it has passed the blocking criterion: either
(a) the AF_LOCAL-specific logic should count the user's control
buffer size with ints rather than the the kernel's control buffer
[16 lines not shown]
mips: Avoid shifting into sign bit by using unsigned type instead.
Maybe this loop should do arithmetic in the other direction? But at
least left shifts on unsigned t-bit types are reduced mod 2^t and not
undefined, so this is a simpler change to avoid UB.
PR port-evbmips/60812: UBSan: Undefined Behavior in [sys-src] member
access within misaligned address [..] for type '[..]' which requires
128 byte alignment
policy based routing in NPF addition
route-to interface should be specified using "interface" paramter.
indroduces IPv4 and IPv6 gateway using "via" and "via6" parameters.
introduces "dup-to" to duplicated packet and route duplicated traffic via
npf's configured route while allowing the normal packet continue its
journey.
simple use case
route: "interface" wm1, "via" 192.168.64.100 "via6" fe80::1 "dup-to"
Import tzdata2026e from https://github.com/JodaOrg/global-tz/releases/download/2026egtz/tzdata2026egtz.tar.gz
Summary of changes in tzdata2026e (2026-09-29 17:14:38 -0700):
* Manitoba’s 2026-03-08 spring forward was its last foreseeable clock
change, as it moved to permanent -05 thereafter.
* As the change affects both America/Winnipeg and its backward
compatibility link, the obsolescent setting TZ="Canada/Central"
will now use the abbreviation EST for affected timestamps,
akin to TZ="Canada/Pacific" behavior introduced in 2026b.
* In 1925 Ireland fell back on 09-20 not 10-04 (thanks to Stan Ulbrych).
fssconfig(8): Clarify some details.
- Note up front that fssdev can be mounted with mount(8).
- Emphasize that fssconfig -c takes a mount point, not an arbitrary
directory.
- Break the prose paragraph of options for snapstore into a bulleted
list.
- Clarify that you needn't use fssconfig(8) at all with dump(8).
- Move dump -X/-x option up front to make it more obvious.
Pull up following revision(s) (requested by joe in ticket #1344):
usr.sbin/npf/npfctl/npf_build.c: revision 1.64,1.67
improve table load error in npf
an EEXIST should clearly state already defined and a load failure should
also clearly be stated. do not class all error returns under EEXIST
since npf_table_insert can return other errors aside EEXIST.
provide more context into npf reload failures with const tables.
PR lib/60740
Pull up following revision(s) (requested by joe in ticket #494):
usr.sbin/npf/npfctl/npf_build.c: revision 1.64,1.67
improve table load error in npf
an EEXIST should clearly state already defined and a load failure should
also clearly be stated. do not class all error returns under EEXIST
since npf_table_insert can return other errors aside EEXIST.
provide more context into npf reload failures with const tables.
PR lib/60740
Pull up following revision(s) (requested by tsutsui in ticket #493):
sys/kern/vfs_bio.c: revision 1.309
vfs_bio: retry fresh buffer allocation if recycling fails
getnewbuf() uses buf_lotsfree() to choose whether to
allocate a fresh buffer before trying BQ_AGE and BQ_LRU.
If fresh allocation is skipped and no buffer can actually be
recycled, it sleeps on needbuffer_cv even when the buffer cache
is still below its high water mark.
In that situation, a thread which could release a buffer may
itself need another buffer, resulting in a deadlock.
To avoid this, if recycling finds no usable buffer and bufmem is
still below bufmem_hiwater, make one more PR_NOWAIT fresh allocation
attempt before sleeping. See PR kern/60584 for details.
Pull up following revision(s) (requested by tsutsui in ticket #492):
sys/arch/atari/atari/atari_init.c: revision 1.121
sys/arch/atari/atari/atari_init.c: revision 1.122
atari: Fix fatal 68030 MMU TC initialization bug
ATARITT kernels from NetBSD 11.0 and -current fail to boot on my
Atari TT030.
The inline asm that loads TC specifies only `"a" (&tc)` as an input,
so the compiler may eliminate the initialization of tc as a dead store.
Then the generated code loads an uninitialized value from the stack
into TC.
Add an `"m" (tc)` input operand to the inline asm so that the compiler
knows that the asm reads tc from memory.
[26 lines not shown]
Add various Intel models (Lakefield, Granite Rapids, Arrow Lake, Panther Lake,
WildCat, Clearwater Forest, Sierra Forest, Lunar Lake).
Fix Yonah name (missing comma between Pentium and Core Duo).
Add few more AMD K8 models (Lima, Sherman, Windsor FX, Tyler, Richmond).
Fix overly aggressive rejection of valid servers.
Patch taken from https://bugs.ntp.org/3877 . This patch is likely to be
included in the next release.
Fixes PR bin/60831
Rewrite Thumb-2 NEON into ARM form before dispatching the trap.
Now neon_handler() recognize it and turns the FPU on.
Fixes execution of Thumb-2 userland on ARMv7 NEON kernel, which
previously was SIGILLed on the first SIMD code after switching the
FPU off.