Implement get_exe_location with getexecpath(3), functionally
aequivalent with other OS' implementations, instead of previous
hard-coded + SUBST_CMD workaround.
ok tb@ (maintainer)
Use getexecpath(3) instead of getprogname(3) from previous workaround.
This should now be functionally in line with the behaviour on other OS.
ok rsadowski@ (maintainer)
In sysctl KERN_PROC_ARGS "cnt" is an int, read directly from a userspace
process. The while loop has a "cnt > 0" check, but on 32-bit platforms a value
can overflow and result in the querying process having data written past the
supplied buffer. Limit the number of elements in the array to ARG_MAX.
ok deraadt@
the installer picks a partition from several options to stage the
prefetched sets for upgrade/install. Among the decisions it looks for
at least 512M free. However, today an amd64 snap is 792M.
Bump the size we look for to 1024M free space. Software has grown, we
gotta grow with it.
OK deraadt@
No need to document or explicitly implement -h, shorten the
manual page and usage() accordingly; no functional change.
Also delete an incorrect sentence that talked about "multiple -v",
clarify where "rtrctl stats" output goes, and polish .Nm use
in the SYNOPSIS.
OK job@
Redesign vmm(4) to use files to manage vm ownership.
Now when VMM_IOC_CREATE creates a new virtual machine, it provides
the calling process a file descriptor to a file associated with the
vm. Access to the vm via various ioctl(2) calls, like VMM_IOC_RUN
and VMM_IOC_READREGS, now go through a file descriptor for that
file. A process can fork/exec and keep the file descriptor open to
allow inheritable access. (For now, we do not permit passing via
sockets to disparate processes.)
This solves a lot of lifecycle headaches, ties the lifetime of the
vm to the userland processes using it, and removes the hacky use
of pids and magic ids for controlling what a process with access
to /dev/vmm can do to a vm.
In vmd(8), the vmm process now takes sole responsibility for tracking
vm's it has created and the kernel is no longer expected to provide
this list back to vmd via the (now removed) VMM_IOC_INFO command.
[10 lines not shown]
the check for efifb || ACPI >= 5 to decide if GPT booting is preferred
is outdated and exposes consequences in new (-current) vmd which has
ACPI >= 5 but no EFI / GPT support. The right thing to do is check for
efi0 driver attachment. The tight floppy media lacks the efi0 driver,
and will only do MBR for other reasons.
issue discovered by phessler, ok mlarkin kettenis
Filter out some shell special characters in the installer. Some
downstream tools were too trusting of the contents of /etc/installurl.
This could be combined with a MITM on installer images that do not use
TLS. The impact is limited because due to a bug images without timezone
data (e.g. floppies) did not use this data.
ok afresh1@ kn@
net/curl: update to 8.22.0
Includes fixes for
CVE-2026-18924: HTTP/2 server push UAF
CVE-2026-19931: Negotiate ambient user conn reuse
CVE-2026-80230: OpenSSL pinning bypass
CVE-2026-80255: secure cookie attribute bypass with tab