hwpmc: fix IBS fetch and op NMI handling
Service each IBS unit with a valid bit set when fetch and op share an
NMI. Otherwise, op samples can be lost. Treat the extra NMI that follows
as expected (skip it).
Reviewed by: mhorne
Fixes: e51ef8ae490f ("hwpmc: Initial support for AMD IBS")
Differential Revision: https://reviews.freebsd.org/D60004
ipmi: Add some additional diagnostic output on errors
Add some additional diagnostic output for IPMI code,
particularly on error paths. This has been found to be helpful at
$WORK and seems generally useful, so contributing the changes back to
upstream.
Sponsored by: Dell Technologies
Reviewed by: vangyzen@
Differential Revision: https://reviews.freebsd.org/D60091
llvm: add LoongArch target support, not enabled by default
Note there is ongoing work to add LoongArch support to the base system,
but having target support in llvm is an essential component.
This must be explicitly enabled using WITH_LLVM_TARGET_LOONGARCH.
Reviewed by: dim
MFC after: 1 week
Differential Revision: https://reviews.freebsd.org/D59899
bhyve: fix boot device ordering
EDK2's QemuBootOrderLib inspects the bootorder file provided
via fw_cfg and requires it to be NUL-terminated. Otherwise,
it rejects the supplied bootorder and falls back to its
default boot order.
Currently, bhyve registers bootorder with qemu_fwcfg_add_file()
using bootorder_len returned by open_memstream(), which excludes
the trailing NUL byte.
Fix that by passing bootorder_len + 1 to qemu_fwcfg_add_file() so
the fw_cfg payload is properly NUL-terminated.
PR: 279720
Reviewed by: markj
Found with: codex (gpt-5.6-sol)
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
[3 lines not shown]
libkvm: support powerpc64 radix minidumps
PowerPC64 radix minidumps use a 64KB root directory followed by three
levels of 4KB page tables. Add an MMU backend which walks those tables,
handles large-page leaves, and decodes their always-big-endian entries
on both powerpc64 and powerpc64le.
Reject old radix minidumps whose pmap section is empty with a specific
diagnostic. Add a synthetic powerpc64le dump test which reads a page
through both its kernel and direct-map addresses.
PR: 298532
Reviewed by: jhb
Approved by: jhb (mentor)
MFC after: 2 weeks
Sponsored by: FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59743
powerpc/radix: include page tables in minidumps
The radix pmap did not implement the minidump pmap callbacks, so radix
minidumps were emitted with an empty pmap section. Such dumps do not
contain enough information for libkvm to translate kernel virtual
addresses.
Snapshot the 64KB radix root table in the pmap section, add lower-level
page-table pages to the sparse dump, and include pages backing non-DMAP
kernel mappings. Keep the bulk direct map out of the dump while
retaining the relocated kernel image.
PR: 298532
Reviewed by: jhb
Approved by: jhb (mentor)
MFC after: 2 weeks
Sponsored by: FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59743
arm: pad minidump page table
libkvm locates the sparse page array after the page-rounded PTE table
size, but the ARM minidump writer emitted only the unrounded size. When
the table size was not page-aligned, libkvm therefore read every dumped
physical page at the wrong offset.
The mismatch was introduced when libkvm began rounding ptesize. It has
affected ARM minidumps since ffdeef323449 ("libkvm: Improve physical
address lookup scaling."). It is exposed when the dumped KVA span is not
a multiple of 4 MiB.
Zero-pad the final PTE page and include the padding in the dump size.
Reviewed by: jhb
Approved by: jhb (mentor)
Fixes: ffdeef323449 ("libkvm: Improve physical address lookup scaling.")
MFC after: 2 weeks
Sponsored by: FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59716
nd6: Fix regeneration of temp addresses in detached state
When an on-link prefix becomes detached, the kernel keeps
generating new RFC 8981 temporary addresses for that prefix.
Fix it by ignoring the detached addresses in regen_tmpaddr().
While here, change its return type to bool.
PR: 298533
Discussed with: markj
MFC after: 3 days
Differential Revision: https://reviews.freebsd.org/D60051
ci: Remove Cirrus CI files
Cirrus CI shutted down its service on June 1, 2026 and its CI dashboard
website (https://cirrus-ci.com) is now inaccessible. Since these files
are no longer used, remove them from the repository.
Reviewed by: brooks, emaste, lwhsu
Approved by: olce (mentor)
MFC after: 2 weeks
Sponsored by: FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59858
powerpc/radix: synchronize temporary kernel mappings
The radix kremove implementation cleared a kernel PTE without
invalidating its TLB entry. Reusing crashdumpmap could therefore keep
accessing an old physical page, causing minidumps to contain repeated
stale page contents.
Invalidate the removed kernel mapping and synchronize newly installed
kernel PTEs before they are accessed.
Reviewed by: jhibbits
Approved by: olce (mentor)
Fixes: 65bbba25d214 ("powerpc64: Implement Radix MMU for POWER9 CPUs")
MFC after: 2 weeks
Sponsored by: FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59728
libkvm: route powerpc64 minidumps to minidump backend
The regular powerpc64 core probes only checked the kernel ELF and thus
also matched minidumps. In particular, the powerpc64le probe could
claim a minidump before the minidump backend and then reject it as an
invalid ELF core.
Exclude minidumps from both regular powerpc64 probes and add a
regression test that verifies a powerpc64le minidump reaches the
minidump parser.
Reviewed by: jhibbits
Approved by: olce (mentor)
Fixes: f4eb39ba6bc9 ("[PowerPC64LE] libkvm powerpc64le support.")
MFC after: 2 weeks
Sponsored by: FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59719
ixl: fix big-endian hardware interface handling
Correct the byte order at the driver interfaces that do not operate in
host order. Encode little-endian Admin Queue VSI and MAC/VLAN fields,
and decode firmware-provided queue handles, statistics indices, and
event parameters before using them.
Decode transmit descriptor writeback before examining it, and construct
VLAN descriptor fields in host order for the final descriptor
conversion. Store paged HMC descriptors in little-endian form and retain
the selected field bits when reading HMC contexts.
Keep MMIO values in host order for bus-space accessors and remove the
obsolete le16_to_cpu no-op macro. In particular, retain the atomic
bus_space_read_8() used for 64-bit registers.
On big-endian systems, the unconverted perfect-match filter flag is
presented to firmware as 0x0100 instead of 0x0001. Firmware rejects that
command with EINVAL, leaving receive traffic functional only in
[7 lines not shown]
udp: Let jail policy rewrite the dstaddr for v6 sendto()s
When performing an unconnected sendto() on a v6 UDP socket in a classic
jail, we were not applying the usual policy of replacing the loopback
addr with the jail's primary IP. Compare with, e.g., udp6_connect() or
the IPv4 udp_send(). Fix that.
Reported by: Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li,
and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai
Reviewed by: bz, glebius
MFC after: 2 weeks
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59772
(cherry picked from commit fecb9537a83b6746bc731a7cb3bcf6a33df79562)
udp: Let jail policy rewrite the dstaddr for v6 sendto()s
When performing an unconnected sendto() on a v6 UDP socket in a classic
jail, we were not applying the usual policy of replacing the loopback
addr with the jail's primary IP. Compare with, e.g., udp6_connect() or
the IPv4 udp_send(). Fix that.
Reported by: Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li,
and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai
Reviewed by: bz, glebius
MFC after: 2 weeks
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59772
(cherry picked from commit fecb9537a83b6746bc731a7cb3bcf6a33df79562)
ktls: Add a tunable to disable TLS receive
TLS receive offload is really only beneficial for in-kernel use cases
(such as NFS over TLS) or when using a hardware offload. In addition,
several recent SAs have involved the TLS receive path, but the only
current mitigation for those is to disable TLS offload entirely.
Reviewed by: ziaee, gallatin, markj
Relnotes: yes
Sponsored by: Netflix
Sponsored by: Chelsio Communications
Co-authored-by: John Baldwin <jhb at FreeBSD.org>
Differential Revision: https://reviews.freebsd.org/D57974
(cherry picked from commit 08cda4bcd43cfcb2c0b1abd29bc7cd30896727bc)
ktls: Fix an off-by-one bug in tls13_find_record_type()
If the entire plaintext is zero-filled, the backwards walk in
tls13_find_record_type() would return the offset of the last byte of the
TLS header. This causes an underflow when decrypting, resulting in a
null pointer dereference.
Fix the bug and add a regression test.
Reviewed by: gallatin, jhb
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59767
(cherry picked from commit 7c5e457d3afdc7742ee24f0b5ee6e5e7aa00a6bd)
ktls: Fix an off-by-one bug in tls13_find_record_type()
If the entire plaintext is zero-filled, the backwards walk in
tls13_find_record_type() would return the offset of the last byte of the
TLS header. This causes an underflow when decrypting, resulting in a
null pointer dereference.
Fix the bug and add a regression test.
Reviewed by: gallatin, jhb
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59767
(cherry picked from commit 7c5e457d3afdc7742ee24f0b5ee6e5e7aa00a6bd)
ktls: Add a tunable to disable TLS receive
TLS receive offload is really only beneficial for in-kernel use cases
(such as NFS over TLS) or when using a hardware offload. In addition,
several recent SAs have involved the TLS receive path, but the only
current mitigation for those is to disable TLS offload entirely.
Reviewed by: ziaee, gallatin, markj
Relnotes: yes
Sponsored by: Netflix
Sponsored by: Chelsio Communications
Co-authored-by: John Baldwin <jhb at FreeBSD.org>
Differential Revision: https://reviews.freebsd.org/D57974
(cherry picked from commit 08cda4bcd43cfcb2c0b1abd29bc7cd30896727bc)
proc: free kstack buffers when debug permission changes
The kern.proc.kstack handler allocates its output and stack buffers
before deliberately checking p_candebug again under the process lock.
If trace-control state changes between authorization checks, the failure
path balances the process and exec state but leaks both buffers.
Submitted by calif.io for the OpenAI Patch The Planet program
Signed-off-by: Andrew Griffiths <andrew at calif.io>
Fixes: 8b5abd9027b8 ("kern_proc.c: disallow execve around sysctl kern.proc.kstacks")
Reviewed by: markj
MFC after: 1 week
(cherry picked from commit 3484217cc47c1f77d2be2ed0e012b870d1cd3dca)
dtrace/arm64: de-pessimize dtrace_copy
When DTrace catches a data abort exception it resumes execution on the
next instruction. If a probe executes copyinto from unmapped memory,
then dtrace_copy keeps faulting on successive bytes until the loop
counter is exhausted. Detect the situation by witnessing the absence
of zero-extension from an aborted unprivileged load.
Reviewed by: markj
MFC after: 2 weeks
Differential Revision: https://reviews.freebsd.org/D59341
(cherry picked from commit 464b29857ff18801aca49d1001643c5cdd1324e8)
proc: free kstack buffers when debug permission changes
The kern.proc.kstack handler allocates its output and stack buffers
before deliberately checking p_candebug again under the process lock.
If trace-control state changes between authorization checks, the failure
path balances the process and exec state but leaks both buffers.
Submitted by calif.io for the OpenAI Patch The Planet program
Signed-off-by: Andrew Griffiths <andrew at calif.io>
Fixes: 8b5abd9027b8 ("kern_proc.c: disallow execve around sysctl kern.proc.kstacks")
Reviewed by: markj
MFC after: 1 week
(cherry picked from commit 3484217cc47c1f77d2be2ed0e012b870d1cd3dca)
ice(4): Fix link bringup on driver load
Patch adding Total Port Shutdown support incorrectly
handled a case when this feature was not enabled in the NVM.
When TPS bit is not set driver should apply link configuration
according to user settings and update the status. Those steps
were mistakenly omitted, while the state flag was still set
to prevent link renegotation and status update on first
attempt to bring interface up with ifconfig.
Signed-off-by: Krzysztof Galazka <krzysztof.galazka at intel.com>
Reported by: kbowling
Reviewed by: kbowling
Fixes: 0011cd9f8863 ("ice(4): Support Total Port Shutdown on E830 devices")
MFC after: 2 weeks
Sponsored by: Intel Corporation
Differential Revision: https://reviews.freebsd.org/D59578