pf(4): pfr_insert_kentry() always needs PF_LOCK()
pfr_insert_kentry() inserts an IP address into a table. The table's
consistency is protected by PF_LOCK(). Unfortunately, PF_LOCK()
protection is missing for the code path executed on behalf
of the overload action in a pf rule. The overload action instructs
the firewall to insert the packet's source address into the table specified
as the overload action parameter. That particular code path in
pf_test() function runs without any lock protection.
The bug was introduced in revision 1.1074 and remained unnoticed
until now, when it was kindly reported by alf (a.schlichting () lemarit ! com>)
OK henning@, OK dlg@, OK jmatthew@
httpd: add header block/drop rules for request filtering
With this incoming requests can also be rejected based on the value of a
request header. Valid options are:
header block name value code [arg]
Close the connection with an error response when a
request header matches. Both name and value are shell-
style patterns and are matched case-insensitively against
the header name and value. code must be a valid HTTP
status code. For codes in the 3xx range, arg is required
and sent as the "Location" header. It must start with
"http://" or "https://". For all other codes, arg is
optional and used as the log message identifying the
rule.
header drop name value
Silently close the connection without sending a response
when a request header matches, using the same pattern
[10 lines not shown]
relayd: apply the header length limit to chunk size and trailer lines
Chunk size and trailer lines were not limited, so a line without line
ending could be buffered without bound. Limit each chunk size line and
the whole trailer to the configured header length and close the
session if they exceed it.
Spotted by Acts1631 (with diff), OK kirill@
relayd: apply the header length limit to unterminated lines
The limit was only checked for complete lines, so a header line
without line ending could be buffered without bound. Reject such
lines with 413 as soon as they exceed the limit.
Spotted by Acts1631 (with diff), OK kirill@
don't access the DE_CFG MSR when running on a hypervisor
Sebastian Albert encountered a KVM hosting provider where trying
to access the MSR resulted in a protection fault.
DE_CFG is not documented in AMD's 'AMD64 Architecture Programmer's Manual'.
ok brynet@ mlarkin@
sys/qwz: fix REO queue lifetime
Track REO completions before publication and wait for peer unmap,
deletion, and cache flushes before reusing queue DMA. Submission errors
and timeouts retain ownership; hardware failures block reuse until cold
cleanup. HAL error conventions and flush semantics follow ath12k;
tracking and the reuse barrier adapt qwz's retained pool.
sys/qwz: fix WCN7850 REO layout
Use WCN7850 REO tags and 64-bit TLV headers so commands and completions
use the correct offsets. Correct the status ring size and clear command
payloads before reuse.
The layout follows Linux ath12k's WCN7850 definitions.
OK: stsp@
Update to 2026egtz from https://github.com/JodaOrg/global-tz
o Manitoba moves to permanent -05 on 2026-10-31.
o In 1925 Ireland fell back on 09-20 not 10-04.
rpki-client: do not fatal after RB_INSERT() into the NCA trees
rpki-client is generally a bit too quick to error out and a repeated source
of problems has been errx after RB_INSERT() (one fixed just yesterday).
The first of these is probably not reachable but do that for good measure.
The other one was shown to be reachable in somewhat contrived setups by
eur1ka, which means rpki-client would refuse to start.
ok claudio
Track the nofetch variable by TAL.
This matches better with the MAX_REPO_PER_TAL limit which is already tracked
by TAL and with that a TAL hitting the limit will not affect the other TALs.
Reported by eur1ka
OK tb@
Reattempt the upgrade to gnupg-2.5.24
Upstream published a fix for regression that broke mail/notmuch
configure. Updating now means smaller steps if we need an update for
a security issue in the next 8.0 OpenBSD release. ok sthen@ naddy@
sys/qwz: preserve decoded radiotap frequency
Management RX parameters already contain a hostorder chanel
frequency. Avoid decoding it again before writing the little endian
radiotap field.
OK: stsp@
sys/qwz: report radiotap channels and rates
Based on sys/dev/ic/qwx.c,v 1.93 and sys/dev/ic/qwxvar.h,v 1.31
Populate radiotap channel and rate fields with WCN7850 RX rate decoding.
Use QWZ presence masks and omit unavailable timestamps, noise and
signal strength for data frames.
Correct 54 Mb/s encoding from 104 to 108 in 500 kb/s.
OK: stsp@
sys/qwz: drain REO RX exceptions
Based on sys/dev/ic/qwx.c,v 1.33
Drain REO RX exceptions using descriptor layouts and qwz cookie.
Reclaim packet buffers, return link descriptors and replenish RX,
checking bank bounds and release ring space.
OK: stsp@
sys/qwz: handle WBM RX errors
Based on sys/dev/ic/qwx.c,v 1.35 and sys/dev/ic/qwxvar.h,v 1.18 ,
sys/dev/ic/qwx.c,v 1.89 , sys/dev/ic/qwx.c,v 1.121 and sys/dev/ic/qwxvar.h,v 1.36
Process WBM RX releases using WCN7850 descriptor and cookie formats.
Deliver valid null queue frames through existing RX processing, clear
mbuf pointers after delivery, and then replenish descriptors
OK: stsp@
sys/qwz: report hardware RX aggregation
Based on sys/dev/ic/qwx.c,v 1.85 and sys/dev/ic/qwx.c,v 1.90
Report hardware deaggregation and reordering after successful RX
reconstruction; allow repaeted sequence numbers for later A-MSDU
subframes and clear the AMSDU QoS bit.
OK: stsp@