OPNSense/core ee367f5src/opnsense/mvc/app/models/OPNsense/Core/ACL ACL.xml

interfaces: fix API ACL patters for GIF/GRE; closes #10871
DeltaFile
+2-2src/opnsense/mvc/app/models/OPNsense/Core/ACL/ACL.xml
+2-21 files

OPNSense/plugins 250286bsecurity/q-feeds-connector/src/opnsense/scripts/qfeeds/lib __init__.py db.py, security/q-feeds-connector/src/opnsense/scripts/qfeeds/sql setup.sql

security/q-feeds-connector - fix performance issue with large deletes and add simple get_meta call
DeltaFile
+19-0security/q-feeds-connector/src/opnsense/scripts/qfeeds/lib/db.py
+5-1security/q-feeds-connector/src/opnsense/scripts/qfeeds/lib/__init__.py
+0-1security/q-feeds-connector/src/opnsense/scripts/qfeeds/sql/setup.sql
+24-23 files

OPNSense/core 0293224src/opnsense/mvc/app/library/OPNsense/Auth TOTP.php

Auth/TOTP - stricten compare operator in authTOTP()
DeltaFile
+1-1src/opnsense/mvc/app/library/OPNsense/Auth/TOTP.php
+1-11 files

OPNSense/src 5f261eesys/dev/qat/include/common adf_accel_devices.h, sys/dev/qat/qat_api/common/crypto/sym lac_sym_alg_chain.c lac_sym_dp.c

qat: driver updates to enhance qat infrastructure

- Updated QAT infrastructure FW version/AE mask/num_banks fields
  to facilitate integration of future QAT products.
- Exposed service as sym;asym instead of cy for gen4
- Enhanced cpaGetInstances() for accurate instance retrieval
- Added 57-bit virtual address support to lac_lock_free_stack
- Minor bug fixes and improvements

Signed-off-by: Hareshx Sankar Raj <hareshx.sankar.raj at intel.com>

Reviewed by:    markj
MFC after:      1 month
Differential Revision:  https://reviews.freebsd.org/D57746

(cherry picked from commit 682f135f5de39cfc24cfd529ea8a161e94c76c8e)
DeltaFile
+34-26sys/dev/qat/qat_api/common/utils/lac_lock_free_stack.h
+32-24sys/dev/qat/qat_api/common/crypto/sym/lac_sym_dp.c
+25-25sys/dev/qat/qat_hw/qat_4xxx/adf_4xxx_hw_data.c
+24-17sys/dev/qat/qat_api/common/crypto/sym/lac_sym_alg_chain.c
+17-18sys/dev/qat/qat_common/adf_freebsd_admin.c
+19-15sys/dev/qat/include/common/adf_accel_devices.h
+151-12541 files not shown
+390-31647 files

OPNSense/src da9693fsys/net if_vxlan.c

if_vxlan(4): Fix panic by validating unused drvspec values

Add validation for unused parameter values in the gap between
VXLAN_PARAM_WITH_LOCAL_ADDR4 and VXLAN_PARAM_WITH_LOCAL_ADDR6 to prevent
panics.

PR:             297151
Reported by:    Robert Morris <rtm at lcs.mit.edu>
Reviewed by:    markj
MFC after:      3 days
Differential Revision: https://reviews.freebsd.org/D58552

(cherry picked from commit c4d7745cd90fc99af3cbccfda7e11798ea7d187b)
DeltaFile
+2-1sys/net/if_vxlan.c
+2-11 files

OPNSense/src a6b97d3sys/dev/ice ice_drv_info.h

ice(4): Add two more 4-part IDs for E835 adapters

Two additional subdevice IDs were introduced
to distinguish between adapters with and without
manageability over USB support.

Signed-off-by: Krzysztof Galazka <krzysztof.galazka at intel.com>

Reviewed by:    erj
Tested by:      Mateusz Moga <mateusz.moga at intel.com>
Sponsored by:   Intel Corporation
Differential Revision:  https://reviews.freebsd.org/D57337

(cherry picked from commit f370d9e4d5844daa06d77e57236e03bd7c5f4ba1)
DeltaFile
+6-0sys/dev/ice/ice_drv_info.h
+6-01 files

OPNSense/src 716a3c0sys/dev/ice ice_drv_info.h

ice(4): Add support for E835 CNSA 2.0 adapters

Added support for E835 adapters with post-quantum cryptographic (PQC)
algorithms in firmware/software signage and in SPDM attestation.

Signed-off-by: Pawel Sobczyk <pawel.sobczyk at intel.com>

Reviewed by:    Miłosz Linkiewicz <milosz.linkiewicz at intel.com>
Differential Revision:  https://reviews.freebsd.org/D57868

(cherry picked from commit 8194c32827e9c3867d4b295edca9842b71608526)
DeltaFile
+30-0sys/dev/ice/ice_drv_info.h
+30-01 files

OPNSense/src 3b63e75sys/dev/ice if_ice_iflib.c

ice: Report initialization failures to iflib

The primary and mirror-VSI ifdi_init callbacks can return early when
reset state or hardware queue and filter setup prevents initialization.
Iflib then marks the interface running and enables interrupts although
the driver did not finish bringing it up.

Report each non-detach failure through iflib_init_failed().  Keep the
existing ice reset and subinterface-reinitialization machinery
responsible for scheduling recovery.

(cherry picked from commit dcdc00a41d3e4be0e75eb625cd3a23d5a927ed15)
DeltaFile
+13-9sys/dev/ice/if_ice_iflib.c
+13-91 files

OPNSense/src a5f6cebshare/man/man4 ice.4, sys/dev/ice ice_iflib.h if_ice_iflib.c

ice: Add led(4) identification support

Expose the firmware-controlled physical port identification LED
through /dev/led/ice*.  Use the AdminQ port-identification command to
select blinking mode and restore the netlist-selected original mode
before the interface is stopped.

Sponsored by:   BBOX.io

(cherry picked from commit a781965b91ea390f9576ae42c35c842db74aab86)
DeltaFile
+44-0sys/dev/ice/if_ice_iflib.c
+8-1share/man/man4/ice.4
+1-0sys/dev/ice/ice_iflib.h
+53-13 files

OPNSense/src b8a3d9csys/dev/e1000 if_em.h e1000_defines.h

e1000: Report corrected LAN management FIFO ECC errors

I350 and I354 report a corrected ECC error in the LAN transmit
management FIFO through LANPERRSTS bit 16.  Unlike the parity status in
the same register, this condition neither interrupts nor stops traffic.

Poll the latch with the other corrected error status, increment a
dedicated counter, and clear only its RW1C bit.  Expose it as
dev.igb.N.memory_errors.corrected_lan_mng_fifo.

Fatal error handling returns before the periodic statistics sweep and
may reset the device.  Drain all I350 and I354 corrected-error status in
the admin task before recovery so the reset does not discard pending
indications.

This follows section 6.21.16 of the Intel Atom Processor C2000 Product
Family Integrated GbE Controller Programmer's Reference Manual,
document 537426 revision 1.5.


    [3 lines not shown]
DeltaFile
+13-1sys/dev/e1000/if_em.c
+1-0sys/dev/e1000/if_em.h
+1-0sys/dev/e1000/e1000_defines.h
+15-13 files

OPNSense/src fb68099sys/dev/e1000 e1000_defines.h if_em.c

e1000: Handle I354 internal memory errors

The Atom C2000 integrated GbE programming reference documents the I354
internal memory error architecture.  It shares the I350 PEIND and
ICR.FER routing, DMA and packet-buffer status, LAN parity status, and
required reset recovery.

Extend the existing I350 recovery and corrected error accounting paths
to I354.  Keep the PCIe corrected error mask family-specific.  C2000
PCIEECCSTS ends at the transmit write-data indication in bit 4 and does
not implement the I350 retry buffer indication in bit 5.  Do not expose
the corresponding retry counter on I354.

The PRM overview says a PCIe region failure requires a system reboot,
while the individual PCIEERRSTS fields prescribe CTRL.RST followed by
port reinitialization.  Use the register specific recovery, matching the
existing I350 path; failed reinitialization still leaves the port down.

This follows sections 5.6 and 6.21 of the Intel Atom Processor C2000

    [6 lines not shown]
DeltaFile
+40-35sys/dev/e1000/if_em.c
+10-8sys/dev/e1000/e1000_defines.h
+50-432 files

OPNSense/core e83acb5src/etc/inc interfaces.inc

interfaces: make sure to set default IPv6 on lo0 as well #10866
DeltaFile
+2-1src/etc/inc/interfaces.inc
+2-11 files

OPNSense/core 8319762src/etc/inc interfaces.inc

interfaces: add interfaces_vlan_match() to avoid future mistakes
DeltaFile
+10-4src/etc/inc/interfaces.inc
+10-41 files

OPNSense/core 90fba3dsrc/etc/inc interfaces.inc

interfaces: minor flow tweak on intefaces_ppps_hardware()
DeltaFile
+8-10src/etc/inc/interfaces.inc
+8-101 files

OPNSense/core bc76a75src/etc/inc filter.lib.inc, src/opnsense/scripts/firmware bogons.sh

Revert "firewall: fix loopback address in private defintions; closes #10694"

This reverts commit 9bac2b8a75f3f218e252a1ca2092c2566291790f.

Since we want to get rid of treating loopback as private and push it to
bogons and this was already broken do not try to repair it.
DeltaFile
+1-1src/opnsense/scripts/firmware/bogons.sh
+1-1src/etc/inc/filter.lib.inc
+2-22 files

OPNSense/core 0b8c7c0src/etc/inc util.inc filter.lib.inc, src/etc/inc/plugins.inc.d pf.inc

firewall: remove handling looback addresses as "private"

Loopbacks are not "private" in the traditional sense and will be handled
by bogons in the near future to more closely align with the upstream bogon
source.
DeltaFile
+2-2src/etc/inc/filter.lib.inc
+1-1src/etc/inc/util.inc
+1-1src/etc/inc/plugins.inc.d/pf.inc
+4-43 files

OPNSense/core 050f3c8src/opnsense/www/js opnsense_bootgrid.js

bootgrid: ensure a minimum amount of rows to render

This is a continuation of https://github.com/opnsense/core/pull/10408

(cherry picked from commit 87cb2d055dd0cb7e07ab30e8656c020a82803a91)
DeltaFile
+28-3src/opnsense/www/js/opnsense_bootgrid.js
+28-31 files

OPNSense/tools 62995c0. Makefile, composite source.sh

composite/source: add small helper
DeltaFile
+32-0composite/source.sh
+1-1Makefile
+33-12 files

OPNSense/tools cbbb1e1. Makefile README.md, build common.sh pkgbase.sh

build/pkgbase: finish set build and TIMESTAMP support

As mentioned in the README this is mostly for educational purposes.
We want a stable reproducible set we can generate incremental sets
for, but still run it from scratch to avoid build artifacts from
ending up in the sets.
DeltaFile
+16-23build/pkgbase.sh
+12-0README.md
+4-1build/common.sh
+3-1Makefile
+1-0config/26.7/build.conf
+36-255 files

OPNSense/tools 9f8f7a1build pkgbase.sh

build/pkgbase: add a bit of context

We likely won't use it for the forseeable future, but that doesn't
mean other's cannot play with it.
DeltaFile
+17-1build/pkgbase.sh
+17-11 files

OPNSense/src fae555asys/net if_media.h

net: Add ifmedia support for 10GBase-BX BiDi

10GBase-BX uses paired wavelengths to carry both directions over a
single strand of single-mode fiber.  The optics must be paired so that
the transmit and receive wavelengths cross over.

(cherry picked from commit 4220b52453c9701922955dcc1c1e1554d6a9f3ae)
DeltaFile
+3-0sys/net/if_media.h
+3-01 files

OPNSense/src 69461c0sys/net iflib.c

iflib: Remove an unused field from struct iflib_rxq

Reported by:    Alexander Sideropoulos <Alexander.Sideropoulos at netapp.com>
MFC after:      1 week

(cherry picked from commit fc09c7fee23b3cf3ddc95105ef6ef41d7956232f)
DeltaFile
+0-1sys/net/iflib.c
+0-11 files

OPNSense/src 3fbc6dasys/net iflib.c

iflib: Permit SR-IOV configuration on a down interface

Drivers which remap PF queues need a stop/mutate/restart transaction
only when the interface has live queues. Permit their IOV
initialization callback while the interface is administratively down
and leave it down afterward.

This restores the standard boot-time iovctl.conf workflow and
lets other opt-in drivers configure VFs before netif brings the PF up.

(cherry picked from commit 2cf580c694f6f392531a63f01c3fb89c0244f89a)
DeltaFile
+31-0sys/net/iflib.c
+31-01 files

OPNSense/src d9f8185sys/net iflib.h iflib.c

iflib: Add restart transactions for IOV reconfiguration

Some devices remap the PF queues when entering or leaving SR-IOV. Add
opt-in PCI IOV helpers that hold the iflib context lock across the
complete stop, driver callback, and restart transaction.

Existing drivers continue to use the non-restarting helpers.

Sponsored by:   BBOX.io

(cherry picked from commit f8fa2d77bc305bec519f9f02afe211e903c57573)
DeltaFile
+22-0sys/net/iflib.c
+2-0sys/net/iflib.h
+24-02 files

OPNSense/src 9ea9fbfsys/net iflib.c

iflib: Initialize the VFLR task unconditionally

The VFLR task was initialized only from drivers MSI-X interrupt
assignment paths.  ixl's legacy interrupt handler can nevertheless defer
VFLR work, leaving an uninitialized task.  Even with MSI-X, the admin
interrupt was established before the task was initialized.

Initialize it alongside the other private tasks.  The existing detach
check and private-taskqueue drains then cover its lifecycle for every
interrupt mode and registration failure.

Sponsored by:   BBOX.io

(cherry picked from commit b4208a67edc2eb7898a9ff2a6f3990c6852910e4)
DeltaFile
+1-1sys/net/iflib.c
+1-11 files

OPNSense/src 52a2571share/man/man4 iflib.4, sys/net iflib.c

iflib: Add an admin task detach fail point

Add an exact-device fail point immediately after the admin task checks
IFC_IN_DETACH. This makes the detach race reproducible without affecting
another interface.

Use a bounded delay to keep the task active while detach enters the
taskqueue drain.  Mark the point nonsleepable as a safety backstop, and
document a one-shot test for verifying that deregistration drains an
already-running task before ether_ifdetach().

Reviewed by:    gallatin, kgalazka
Sponsored by:   BBOX.io
Differential Revision:  https://reviews.freebsd.org/D58720

(cherry picked from commit ac56d36007a5a1a01fe69df370f272060e852e0b)
DeltaFile
+19-0share/man/man4/iflib.4
+11-0sys/net/iflib.c
+30-02 files

OPNSense/src 9ab0500sys/net iflib.c

iflib: Drain configuration tasks before interface detach

iflib_device_deregister() sets IFC_IN_DETACH before removing the
interface, but a task which already passed its detach check can still
report a link change.  This can re-arm if_linktask after
ether_ifdetach() has drained it and leave work pending across queue
teardown.

Drain the entire private taskqueue before ether_ifdetach().  Drivers
may register their own link-related configuration tasks there, so
draining only the framework admin task leaves the same race for those
drivers.

Differential Revision:  https://reviews.freebsd.org/D58452

Co-authored-by: Andrew Gallatin <gallatin at FreeBSD.org>
Co-authored-by: Kevin Bowling <kbowling at FreeBSD.org>
(cherry picked from commit ba353c8950d575f9d15b82c92658e660935fba25)
DeltaFile
+7-0sys/net/iflib.c
+7-01 files

OPNSense/src 10cf6e5share/man/man4 iflib.4, sys/net iflib.c

iflib: Add registration failure injection points

Add six device-scoped fail(9) points at the registration milestones
needed to exercise each unwind path. An exact, runtime-only device
selector prevents unrelated iflib devices from consuming an armed point.

Mark the points non-sleepable because registration holds the ifnet and
context locks. Document one-shot operation and bus-address reprobe so a
failed attach can be recovered without another kernel build.

Reviewed by:    gallatin
Sponsored by:   BBOX.io
Differential Revision:  https://reviews.freebsd.org/D58722

(cherry picked from commit 90e7dbe5e2ca47baff4e4c6d9e892a0554eec4db)
DeltaFile
+46-0sys/net/iflib.c
+40-0share/man/man4/iflib.4
+86-02 files

OPNSense/src 03842ccsys/net iflib.c ifdi_if.m

iflib: Allow conditional LED device support

A driver class may implement LED control even though the capability is
not available on every device or firmware version it supports.  Add an
optional capability method and consult it before creating the led(4)
device.  Default to supported so existing providers are unchanged.

This will be used by bnxt which blends PF and VF in the same driver.

(cherry picked from commit 2519e19f05e0c3e5925bf81b729b4c28f2ad1af6)
DeltaFile
+10-0sys/net/ifdi_if.m
+1-1sys/net/iflib.c
+11-12 files

OPNSense/src 5f7f556sys/net iflib.c

iflib: Create led(4) devices

When a driver implements ifdi_led_func, have the framework create its
led(4) device after attach completes and the ifnet and context locks are
released.

PR:             246885
Reported by:    jlduran
Reviewed by:    markj
Differential Revision:  https://reviews.freebsd.org/D32389

(cherry picked from commit 6591a7f6919295f2ec2b463d1ae9554a8bbf6104)
DeltaFile
+7-0sys/net/iflib.c
+7-01 files