x11/glcapsviewer: allow to build with future CMake versions
Drop cmake_policy(VERSION) as cmake_minimum_required(VERSION)
command implicitly calls it too.
devel/R-cran-arg: New port
Checks function arguments, ideally for use in R packages. Uses a simple
interface and produces clean, informative error messages using 'cli'.
archivers/lzfse: Fix build with CMake 4
Bump cmake_minimum_required() from 2.8.6 to 3.5; compatibility with
versions below 3.5 has been removed in CMake 4. Also move the call
before project().
PR: 298638
www/linkwarden: New port
Linkwarden is a self-hosted, collaborative bookmark manager that collects,
organizes and preserves webpages. Every saved link is archived as a
screenshot, a PDF, a single file HTML copy and a readable article, so the
content stays available even when the original page is gone.
Co-authored-by: Jochen Neumeister <joneum at FreeBSD.org>
pf: take the rules read lock in pf_handle_getrule()
pfctl -sr calls PFNL_CMD_GETRULE once per rule, and
pf_handle_getrule() takes the rules write lock each time, so listing a
ruleset of N rules stops packet processing N times. Only zeroing the
counters (pfctl -z) needs the write lock. Take the read lock
otherwise, as DIOCGETRULENV does.
Reviewed by: kp
Approved by: kp (mentor)
Fixes: 777a4702c591 ("pf: implement addrule via netlink")
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")
Differential Revision: https://reviews.freebsd.org/D60161
pf: leave the epoch to purge unlinked rules
pf_purge_thread() calls pf_purge_unlinked_rules() in the network
epoch, where sleeping is not allowed, and it takes pf_config_lock, an
sx lock. If a rule is being added at the time, the purge thread
can sleep on the lock, which panics with INVARIANTS.
Reviewed by: kp
Approved by: kp (mentor)
Fixes: f92d9b1aad73 ("pflow: import from OpenBSD")
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")
Differential Revision: https://reviews.freebsd.org/D60160
pf: free an unparsed rule with pf_krule_free() in pf_handle_addrule()
When the PFNL_CMD_ADDRULE message fails to parse, pf_handle_addrule()
frees the rule with pf_free_rule(), which asserts the rules and config
locks (neither is held) and releases references that
pf_ioctl_addrule() has not taken yet. With INVARIANTS this panics on
any parse error; without, a rule address parsed as PF_ADDR_TABLE makes
pfr_detach_table() dereference NULL.
Use pf_krule_free(), as the ioctl paths do.
Reviewed by: kp
Approved by: kp (mentor)
Fixes: e249f5daa41f ("pf: fix memory leak on rule add parse failure")
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")
Differential Revision: https://reviews.freebsd.org/D60104
libpfctl: zero the counters before summing per-chunk results
The chunked table address functions (set, add, del, clr_astats) add
each chunk's result to the caller's counter without initialising it.
pfctl reuses nadd for the number of tables created, so a replace that
also creates the table is off by one:
pfctl -t foo -T replace 192.0.2.1
reports "2 addresses added".
Zero the counters first, as pfctl_test_addrs() already does. Remove
the workaround for the add case from pfctl (da64f6e047b5), which is
no longer needed.
Add a regression test.
Reviewed by: kp
Approved by: kp (mentor)
[4 lines not shown]
pf: modify pfik_flags atomically
The purge thread sets PFI_IFLAG_REFS on the interfaces that states
refer to without the rules lock, under which the other flags are
changed. The updates can interleave, so that a "set skip on" is lost,
or outlives its removal, until the next ruleset load.
Use atomic operations to modify the flags. In the purge thread, only
write if the flag is not already set.
Reviewed by: kp
Approved by: kp (mentor)
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")
Differential Revision: https://reviews.freebsd.org/D60107