FreeBSD/src e89c3ac — sys/dev/acpica/Osd OsdSchedule.c

acpi: Tasks: Document why 'acpi_task_count' is accessed unsynchronized

MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
DeltaFile
+1-0sys/dev/acpica/Osd/OsdSchedule.c
+1-01 files

FreeBSD/src f0825f7 — sys/dev/acpica/Osd OsdSchedule.c

acpi: Tasks: Make OsdSchedule.c whitespace clean

MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
DeltaFile
+1-1sys/dev/acpica/Osd/OsdSchedule.c
+1-11 files

FreeBSD/src 2165acc — sys/dev/acpica/Osd OsdSchedule.c

acpi: Tasks: Remove unnecessary includes

MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
DeltaFile
+0-2sys/dev/acpica/Osd/OsdSchedule.c
+0-21 files

FreeBSD/src 4a0ec46 — sys/net iflib.c

iflib: Do not ring the transmit doorbell when nothing is pending

For a lightly used ring iflib_txd_db_check() may defer zero descriptors,
so its "pending >= limit" test is true even when nothing has been queued
since the last doorbell.  iflib_txq_drain() calls it before, inside and
after its loop, so a sender that drains its own packet wrote the tail
register three times per packet, twice with the value the hardware
already had.

The log of 81be655266fa ("iflib: ensure that tx interrupts enabled and
cleanups") calls skipping the doorbell when db_pending is zero "an
obvious missing optimization"; the comparison against a limit of zero
defeated it.  vmx(4) and mgb(4) have dropped such repeated requests in
the driver since 2019.  Return early when nothing is pending.

Reviewed by:            gallatin
MFC after:              2 weeks
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60290
DeltaFile
+7-0sys/net/iflib.c
+7-01 files

FreeBSD/src 16c787f — sys/arm64/arm64 busdma_bounce.c, sys/arm64/include bus_dma.h

arm64: Elide coherent busdma maps

Avoid allocating per-transfer maps for coherent tags that cannot
bounce. Retain maps for cache synchronization, CCA realms, and KMSAN.
These un-used maps carry with them memory and cache miss overheads.

Reviewed by: andrew
Differential Revision: https://reviews.freebsd.org/D60098
Sponsored by: Netflix
DeltaFile
+65-15sys/arm64/arm64/busdma_bounce.c
+8-4sys/arm64/include/bus_dma.h
+73-192 files

FreeBSD/src 2082f44 — crypto/openssh FREEBSD-upgrade

openssh: Add date bump command to FREEBSD-upgrade instructions

Provide a convenient in-place sed edit command to update the FreeBSD
VersionAddendum dates with today's date.

Sponsored by:   The FreeBSD Foundation

(cherry picked from commit 0ec81f6a531bf7b3b06e869c99295f3d4ab9ed8e)
(cherry picked from commit 2ba5b9da2be10261c383035bef932cd37d52f903)
DeltaFile
+5-0crypto/openssh/FREEBSD-upgrade
+5-01 files

FreeBSD/src b690ed4 — crypto/openssh FREEBSD-upgrade

openssh: Add reference for another local patch

A bug fix was committed locally and submitted upstream.  Document it in
our upgrade instructions, as these sometimes take a long time before
getting merged.

Sponsored by:   The FreeBSD Foundation

(cherry picked from commit 6531070132b0210aaaeb08c0dc93cb272bed348e)
(cherry picked from commit 14d6926293569048d2d04f6e5a13d80f192ad99e)
DeltaFile
+5-0crypto/openssh/FREEBSD-upgrade
+5-01 files

FreeBSD/src 0dfc112 — secure/usr.bin/scp Makefile, secure/usr.bin/sftp Makefile

openssh: Remove residual blank line at start of Makefile

This is part of commit e9ac41698b2f in main by imp@
DeltaFile
+0-1secure/usr.bin/ssh-keyscan/Makefile
+0-1secure/usr.bin/ssh-keygen/Makefile
+0-1secure/usr.bin/ssh-agent/Makefile
+0-1secure/usr.bin/ssh-add/Makefile
+0-1secure/usr.bin/sftp/Makefile
+0-1secure/usr.bin/scp/Makefile
+0-66 files not shown
+0-1212 files

FreeBSD/src dcab585 — secure ssh.mk, secure/lib/libssh Makefile

secure: Rearrange Makefile SRCS to match upstream Makefile.in

SRCS entries are kept in the same order and with the same line breaks as
upstream, to make comparison easier.

No functional change intended.

Reviewed by:    emaste
Approved by:    emaste (mentor)
Differential Revision:  https://reviews.freebsd.org/D49793

(cherry picked from commit 9440aad19dca73fdd224b128ac2dc2e78191ff15)
DeltaFile
+16-7secure/lib/libssh/Makefile
+2-2secure/libexec/sftp-server/Makefile
+1-2secure/usr.bin/sftp/Makefile
+1-1secure/usr.bin/scp/Makefile
+1-1secure/libexec/ssh-pkcs11-helper/Makefile
+2-0secure/ssh.mk
+23-131 files not shown
+24-147 files

FreeBSD/src 412c3a0 — sys/arm64/arm64 gicv5_acpi.c

arm64/gicv5: Use ArmMpidr to find the correct CPU

The GICv5 ACPI code uses CpuInterfaceNumber to as the CPU ID. This a
GICv5 CPU ID and may not be the same as the appropriate FreeBSD value.

It is also possible the target CPU is disabled, e.g. when the hw.ncpu
tunable is uses to limit CPUs. If this is the case we don't want to
enable the CPU in the cpu set as it is offline so cannot handle
interrupts.

Switch to use ArmMpidr to find which pcpu to use when finding which
CPUs the IRS is attached to.

Fixes:  9556306213e1 ("arm64: Add ACPI support to GICv5 driver")
Differential Revision:  https://reviews.freebsd.org/D59993
Sponsored by:   Arm Ltd
DeltaFile
+14-3sys/arm64/arm64/gicv5_acpi.c
+14-31 files

FreeBSD/src 128e91e — libexec/rc/rc.d nuageinit_user_data_script

nuageinit: Allow the userdata script to run before firstboot* rc services

Allowing nuageinit user scripts to run before these makes it possible to
customize official BASIC-CI and BASIC-CLOUDINIT FreeBSD images.

This was requested by KDE for their CI.

Approved by:    cperciva
Pull-Request:   https://ron-dev.freebsd.org/FreeBSD/src/pulls/60

(cherry picked from commit 16e47f317c4ce2be5fed530bf8a9af9f9bf55364)
DeltaFile
+1-0libexec/rc/rc.d/nuageinit_user_data_script
+1-01 files

FreeBSD/src fdd3f6f — share/mk sys.mk bsd.lib.mk

bsd.lib.mk: only ctfmerge if objfiles have a CTF section

PR:             299013
Reported by:    Trond.Endrestol at ximalas.info
Reviewed by:    emaste
Fixes:          222210c6a822 ("libgcc_s: add libgcc_s_asneeded.so wrapper for gcc 16")
MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D60252
DeltaFile
+1-1share/mk/sys.mk
+1-1share/mk/bsd.lib.mk
+2-22 files

FreeBSD/src 68386f6 — sys/dev/igc if_igc.c

igc: Fix the flow control sysctl

dev.igc.N.fc read and wrote a function-static variable shared by every
igc device, so a read returned the last value written to any of them (3
until the first write), not the state of the device.  The softc value
started as 0, which is also the value of "no flow control", while the
hardware was set up for full flow control.  As a result:

- Writing 0 was taken for no change and did nothing, unless another
  value had been written to that device before.
- igc_reset() took a softc value of 0 for "not set", so a device set to
  0 went back to full flow control on the next init.
- With more than one receive queue the driver enabled per-queue drop
  (SRRCTL.DROP_EN), which is meant for a MAC that does not send pause
  frames, although the MAC was told to send them.
- Values out of range were accepted and ignored.

A write only forced the MAC's flow control bits.  The pause bits
advertised to the link partner, the pause thresholds and DROP_EN stayed

    [24 lines not shown]
DeltaFile
+16-16sys/dev/igc/if_igc.c
+16-161 files

FreeBSD/src f2b0910 — crypto/openssh moduli servconf.c, crypto/openssh/regress/unittests/crypto/testdata nistkats-44.json

OpenSSH: Update to 10.4p1

Full release notes are available at
https://www.openssh.com/txt/release-10.4

Selected highlights from the release notes:

Potentially-incompatible changes
--------------------------------

 * sshd(8): configuration dump mode ("sshd -G") now writes directives
   in mixed case (e.g. "PubkeyAuthentication") whereas previously it
   emitted only lower-case names.

 * ssh(1), sshd(8): make the transport protocol stricter by
   disconnecting if the peer sends non-KEX messages during a post-
   authentication key re-exchange. Previously a malicious peer could
   continue sending non-key exchange messages without penalty. These
   would be buffered, causing memory to be wasted up until the

    [73 lines not shown]
DeltaFile
+27,332-0crypto/openssh/libcrux_internal.h
+0-11,752crypto/openssh/libcrux_mlkem768_sha3.h
+1,869-1,349crypto/openssh/ChangeLog
+1,446-525crypto/openssh/servconf.c
+539-585crypto/openssh/moduli
+802-0crypto/openssh/regress/unittests/crypto/testdata/nistkats-44.json
+31,988-14,211158 files not shown
+37,553-15,620164 files

FreeBSD/src 2bdbd0a — crypto/openssh channels.c ssh-pkcs11-helper.c, crypto/openssh/openbsd-compat bsd-misc.c

OpenSSH: Update to 10.2p1

Full release notes are available at
https://www.openssh.com/txt/release-10.2

Selected highlights from the release notes:

Bugfixes
--------

 * ssh(1): fix mishandling of terminal connections when
   ControlPersist was active that rendered the session unusable.
   bz3872

Sponsored by:   The FreeBSD Foundation

(cherry picked from commit e68aa5ab80ab57bdbcbe94dd2922a018d675e7f0)
DeltaFile
+146-37crypto/openssh/ChangeLog
+26-5crypto/openssh/ssh-pkcs11.c
+24-0crypto/openssh/openbsd-compat/bsd-misc.c
+0-16crypto/openssh/ssh-pkcs11-helper.c
+8-4crypto/openssh/regress/test-exec.sh
+5-4crypto/openssh/channels.c
+209-6616 files not shown
+248-8022 files

FreeBSD/src e1e83fd — crypto/openssh packet.c .depend

OpenSSH: Update to 10.3p1

Full release notes are available at
https://www.openssh.com/txt/release-10.3

Selected highlights from the release notes:

 * ssh(1), sshd(8): remove bug compatibility for implementations
   that don't support rekeying. If such an implementation tries to
   interoperate with OpenSSH, it will now eventually fail when the
   transport needs rekeying.

 * ssh(1), sshd(8): support IANA-assigned codepoints for SSH agent
   forwarding, as per draft-ietf-sshm-ssh-agent. Support for the new
   names is advertised via the EXT_INFO message. If a server offers
   support for the new names, then they are used preferentially.

 * ssh(1): add a ~I escape option that shows information about the
   current SSH connection.

    [15 lines not shown]
DeltaFile
+7,257-7,843crypto/openssh/libcrux_mlkem768_sha3.h
+2,871-1,684crypto/openssh/ChangeLog
+585-426crypto/openssh/moduli
+222-213crypto/openssh/channels.c
+172-173crypto/openssh/.depend
+253-51crypto/openssh/packet.c
+11,360-10,390241 files not shown
+15,887-12,691247 files

FreeBSD/src 687a0d4 — crypto/openssh moduli ssh-pkcs11.c

OpenSSH: Update to 10.1p1

Full release notes are available at
https://www.openssh.com/txt/release-10.1

Selected highlights from the release notes:

Potentially-incompatible changes

 * ssh(1): add a warning when the connection negotiates a non-post
   quantum key agreement algorithm.

 * ssh(1), sshd(8): major changes to handling of DSCP marking/IPQoS

 * ssh(1), sshd(8): deprecate support for IPv4 type-of-service (ToS)
   keywords in the IPQoS configuration directive.

 * ssh-add(1): when adding certificates to an agent, set the expiry
   to the certificate expiry time plus a short (5 min) grace period.

    [19 lines not shown]
DeltaFile
+3,255-1,388crypto/openssh/ChangeLog
+1,018-474crypto/openssh/pkcs11.h
+0-1,113crypto/openssh/sshkey-xmss.c
+0-1,106crypto/openssh/xmss_fast.c
+637-243crypto/openssh/ssh-pkcs11.c
+426-433crypto/openssh/moduli
+5,336-4,757308 files not shown
+10,988-10,646314 files

FreeBSD/src 2ba5b9d — crypto/openssh FREEBSD-upgrade

openssh: Add date bump command to FREEBSD-upgrade instructions

Provide a convenient in-place sed edit command to update the FreeBSD
VersionAddendum dates with today's date.

Sponsored by:   The FreeBSD Foundation

(cherry picked from commit 0ec81f6a531bf7b3b06e869c99295f3d4ab9ed8e)
DeltaFile
+5-0crypto/openssh/FREEBSD-upgrade
+5-01 files

FreeBSD/src 14d6926 — crypto/openssh FREEBSD-upgrade

openssh: Add reference for another local patch

A bug fix was committed locally and submitted upstream.  Document it in
our upgrade instructions, as these sometimes take a long time before
getting merged.

Sponsored by:   The FreeBSD Foundation

(cherry picked from commit 6531070132b0210aaaeb08c0dc93cb272bed348e)
DeltaFile
+5-0crypto/openssh/FREEBSD-upgrade
+5-01 files

FreeBSD/src 1f1043d — sys/powerpc/powerpc trap.c exec_machdep.c

powerpc: keep FP, VMX and VSX ownership changes atomic with preemption

trap() and set_mcontext() change the FP/VMX/VSX ownership state in
several steps with preemption enabled.  A context switch in between
leaves the thread computing with another thread's register contents:

- enable_fpu()/enable_vec() set PCB_FPU/PCB_VEC before loading the
  registers, so a switch mid-load saves a half-loaded unit over the PCB.
- set_mcontext() clears the frame's MSR bits and then the PCB flags;
  a switch in between re-enables the unit, and the thread returns to
  user space with it enabled but not owned, so it is neither saved nor
  restored until the next signal.

Both paths run after every sigreturn(2), setcontext(2) and
swapcontext(3).  A POWER9 test that keeps f14-f31 live across a signal,
with other threads using the FPU on the same CPU, saw 283 corrupted
round trips out of 882000; none after this change.

Hold a critical section around both, as amd64 and arm64 do.

    [4 lines not shown]
DeltaFile
+7-1sys/powerpc/powerpc/exec_machdep.c
+6-0sys/powerpc/powerpc/trap.c
+13-12 files

FreeBSD/src 8bf2795 — sys/conf files

bnxt_en: add bnxt_sriov.c to sys/conf/files for built-in kernel builds

The SR-IOV series added bnxt_sriov.c and listed it in sys/modules/bnxt/bnxt_en/Makefile,
but kernels that build bnxt into the image only compile sources named in sys/conf/files.
Add bnxt_sriov.c next to the other bnxt_en entries so built-in bnxt (including LINT)
links the SR-IOV implementation and avoids undefined symbols referenced from if_bnxt.c.

Fixes: f2f831b2c151 ("bnxt_en: Add core SR-IOV infrastructure")

MFC after:      1 month
Reviewed by:    ssaxena
Differential Revision: https://reviews.freebsd.org/D56688

(cherry picked from commit c21c63fb565f1bc7f9564dbf12068c864f8891d8)
DeltaFile
+1-0sys/conf/files
+1-01 files

FreeBSD/src 80af0a3 — sys/netinet tcp_subr.c

tcp: Preserve borrowed ICMPv6 error mbufs

The TCP-over-UDP ICMP callback receives ip6c_m as a borrowed chain owned
by icmp6_notify_error.  It used m_pulldown() to obtain a contiguous UDP
header even though that API frees the complete chain when the requested
range is unavailable.  The callback could then return without
propagating the lost ownership, leaving raw ICMP delivery to read and
free a stale head.

Validate that the complete UDP header was quoted, copy it through the
chain with m_copydata(), and temporarily advance the parser offset
instead of consuming bytes from the caller-owned packet.

A remote sender can reach the old path when TCP UDP tunneling is enabled
by quoting the configured local UDP source port in an ICMPv6 error and
including only four through seven UDP-header bytes.

Signed-off-by: Andrew Griffiths <andrew at calif.io>


    [3 lines not shown]
DeltaFile
+9-13sys/netinet/tcp_subr.c
+9-131 files

FreeBSD/src c109a68 — sys/netinet6 in6.c

netinet6: Fix the OSIOCAIFADDR_IN6 handler

We cannot simply treat a pointer to struct oin6_aliasreq as a pointer to
struct in6_aliasreq: the latter is larger.  In particular, the store to
ifra->ifra_vhid is out of bounds.

Since OSIOCAIFADDR_IN6 does not need to copy data back out, it can
simply use a struct in6_ifaliasreq on the stack.

Reported by:    Andrew <xxx.sys at protonmail.com>
Reviewed by:    pouria
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D60184
DeltaFile
+4-2sys/netinet6/in6.c
+4-21 files

FreeBSD/src b30e67d — sbin/camcontrol fwdownload.c

camcontrol: Add support for firmware uploading on HPE-branded drives

PR:             299059
DeltaFile
+2-0sbin/camcontrol/fwdownload.c
+2-01 files

FreeBSD/src d7e7397 — sys/compat/linuxkpi/common/include/linux crc16.h, sys/sys crc16.h

LinuxKPI: Add crc16.h for amdkfd support

Reviewed by:    wulf
Differential Revision:  https://reviews.freebsd.org/D60275
DeltaFile
+13-0sys/compat/linuxkpi/common/include/linux/crc16.h
+1-1sys/sys/crc16.h
+14-12 files

FreeBSD/src a52c50b — sys/fs/nfsserver nfs_nfsdstate.c

nfs_nfsdstate.c: Add an extra safety belt check for the backchannel

I do not think that xp_p2 can be NULL at this point,
but add an extra safety belt, just in case.

Reviewed by:    rmacklem
MFC after:      1 week
Sponsored by:   VersatusHPC
DeltaFile
+2-1sys/fs/nfsserver/nfs_nfsdstate.c
+2-11 files

FreeBSD/src 49bec8c — sys/rpc clnt_vc.c

clnt_vc.c: Fix handling of broken TCP connections

After more than, I don't know, maybe 10k operations: mount, copy,
remove, verify and unmount cycles, one cp command hung in
close() / ncl_flush and never recovered. The machine and the mount
continued to work normally through a new connection, but the writes
using the old connection stayed frozen.

I did not understand exactly what happened.  I traced what appears to
be the issue in the code. My current understanding is that
clnt_vc_soupcall() saw the EOF and woke the caller waiting for RPC
replies, but one caller remained blocked in sosend().
That thread continued holding a reference to the old client, preventing
it from being completely cleaned up.

The attached patch calls socantsendmore() when EOF is received, which
should wake the blocked sender and let the normal reconnect code replace
the connection.


    [3 lines not shown]
DeltaFile
+7-5sys/rpc/clnt_vc.c
+7-51 files

FreeBSD/src 81a6514 — sys/rpc clnt_vc.c

clnt_vc.c: Fix handling of backchannel xprt

When clnt_vc_destroy() is called, it might not be the
current connection.  Without this patch, if it is not
the current connection, xp_p2 is set NULL and xprt is released
when it should not be released.

This patch adds a check for "current connection" to fix
the problem.  Found during testing to the client RDMA code,
but could happen for TCP as well.

MFC after:      1 week
DeltaFile
+8-2sys/rpc/clnt_vc.c
+8-21 files

FreeBSD/src 479c982 — sys/ufs/ffs ffs_softdep.c

ffs: revalidate mkdir dependencies after vnode lookup

flush_pagedep_deps() drops the soft updates lock while obtaining the
vnode of a newly created directory with get_parent_vp().  The
MKDIR_BODY dependency may complete during this interval, invalidating
the diradd selected before the lock was dropped.

Once the directory's allocdirect is retired, the lookup of its first
block by block number in flush_newblk_dep() can find an older
dependency for a previous use of the same physical block.  The newblk
hash is not unique by block number: when ffs_reallocblks() relocates a
cluster, the completed allocindirs of the old blocks stay on the
indirdep's ir_completehd until the indirect block pointer in the inode
is written, while the old blocks are already free and may be allocated
to a new directory.  flush_newblk_dep() then finds a D_ALLOCINDIR where
it expects a D_ALLOCDIRECT and panics with "flush_newblk_dep: Bad
newblk".

Retain the vnode returned by get_parent_vp(), reacquire the soft

    [33 lines not shown]
DeltaFile
+170-55sys/ufs/ffs/ffs_softdep.c
+170-551 files

FreeBSD/src a127039 — tools/test/stress2/misc mkdir_blkreuse.sh

stress2: add a reproducer for the flush_newblk_dep() "Bad newblk" panic

flush_pagedep_deps() drops the soft updates lock to obtain the vnode of
a new directory.  If its MKDIR_BODY dependency completes in that window,
the lookup of the directory's first block in flush_newblk_dep() can find
a stale allocindir left behind by a previous owner of the same block,
relocated by ffs_reallocblks() and freed, and panic.

The test grows interleaved files past UFS_NDADDR to keep clusters being
relocated, while other workers create subdirectories in a parent with
IN_ENDOFF set, so that ffs_vput_pair() syncs it, and fsync() them to
complete the mkdir dependencies.  The file system layout and the way
the writers put their blocks on disk are arranged so that a new
directory takes over a freed block whose dependency is still retained;
the details are in the script.  With dtrace=1, the test also counts how
often this precondition is met, which works on a fixed kernel too.

PR:             297976
Reviewed by:    kib, pho

    [3 lines not shown]
DeltaFile
+584-0tools/test/stress2/misc/mkdir_blkreuse.sh
+584-01 files