FreeBSD/src e049759 — lib/libsys pdfork.2

pdfork.2: downgrade sections inside description to subsections

(cherry picked from commit 233b6efe5f2f2af799a854745e79cce35893c166)
DeltaFile
+2-2lib/libsys/pdfork.2
+2-21 files

FreeBSD/src a362cdb — sys/amd64/amd64 mp_machdep.c

amd64/mp_machdep.c: remove double 'for' in comment

(cherry picked from commit cc467e45136d2f562f654ff6f4f9b91ee9767b0f)
DeltaFile
+1-1sys/amd64/amd64/mp_machdep.c
+1-11 files

FreeBSD/src 2ccc244 — crypto/openssl/test/recipes/10-test_bn_data bngcd.txt, crypto/openssl/test/recipes/30-test_evp_data evpkdf_ssh.txt evpkdf_tls13_kdf.txt

crypto/openssl: upgrade to 3.0.22

All of the security content from 3.0.22 has been merged to this branch
already; this follows through with the remainder of the changes to
finish off the version update -- in part to make future updates easier.

This is a direct commit to :stable/14.

See commit 3180d4d82f5 a description of the content update done between
the two versions, as well as the update methodology used when importing
OpenSSL 3.0.22.
DeltaFile
+0-79,394crypto/openssl/test/recipes/30-test_evp_data/evprand.txt
+0-23,927crypto/openssl/test/recipes/30-test_evp_data/evpciph_aes_ccm_cavs.txt
+0-17,179crypto/openssl/test/recipes/10-test_bn_data/bngcd.txt
+0-11,667crypto/openssl/test/recipes/30-test_evp_data/evppkey_kas.txt
+0-4,947crypto/openssl/test/recipes/30-test_evp_data/evpkdf_tls13_kdf.txt
+0-4,867crypto/openssl/test/recipes/30-test_evp_data/evpkdf_ssh.txt
+0-141,9811,727 files not shown
+3,697-216,3581,733 files

FreeBSD/src 43b0384 — usr.bin/stat Makefile stat.c, usr.bin/stat/tests Makefile mountpoint_test.sh

mountpoint(1): new utility, implemented as a stat(1) hardlink

Add mountpoint(1), a simple utility to tell whether the file pointed
to by the argument is a mount point.  It prints whether it is, unless
-q is given, and exits 0 if it is, 1 if it is not, and 2 on error.

The answer comes from the kernel with a single stat(2): the root vnode
of a mounted file system is reported with SFBSD_MNTPOINT in
st_bsdflags.  Unlike comparing realpath(3) of the argument with that
of statfs(2)'s f_mntonname, this works for arbitrarily deep
hierarchies, and after chroot(2) or inside a jail.  A chroot or jail
root is reported as a mount point only if it is one.

The argument does not have to be a directory: file systems such as
nullfs(5) can be mounted over regular files and sockets, and stat(2)
reports those mount points as well.

Since all that is needed is one stat(2) call, make mountpoint a
hardlink to stat(1), the same way readlink(1) is, and document it in

    [11 lines not shown]
DeltaFile
+401-0usr.bin/stat/tests/mountpoint_test.sh
+58-3usr.bin/stat/stat.1
+48-0usr.bin/stat/stat.c
+3-2usr.bin/stat/Makefile
+1-0usr.bin/stat/tests/Makefile
+511-55 files

FreeBSD/src 5f275e5 — sys/dev/cxgbe t4_vf.c

cxgbev(4): verify the vendor id before claiming a device

PR:             299002
Reviewed by:    jhb
MFC after:      1 week
Sponsored by:   Chelsio Communications
Differential Revision:  https://reviews.freebsd.org/D60203
DeltaFile
+20-4sys/dev/cxgbe/t4_vf.c
+20-41 files

FreeBSD/src a2fbd98 — sys/amd64/amd64 fpu.c pmap.c, sys/amd64/vmm vmm.c

ifuncs: Include <machine/ifunc.h> instead of <x86/ifunc.h>

All architectures have been providing an 'ifunc.h' header with
DEFINE_IFUNC() et alter working both in kernel and userland since commit
cf41d1113377 ("riscv: implement kernel ifunc resolution"), and separate
<i386/ifunc.h> and <amd64/ifunc.h> headers were introduced in commit
2b1db07bec92 ("x86: add machine/ifunc.h"), so stop including
<x86/ifunc.h> directly and use the common <machine/ifunc.h> idiom.

While here, re-order includes in the blocks featuring <x86/ifunc.h>,
which requires fixing <x86/apicvar.h> so that it can be included before
<machine/intr_machdep.h>.

Reviewed by:    kib
MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D60194
DeltaFile
+6-6sys/amd64/vmm/vmm.c
+5-5sys/amd64/amd64/machdep.c
+4-4sys/amd64/amd64/pmap.c
+2-2sys/x86/x86/cpu_machdep.c
+2-2sys/i386/i386/npx.c
+2-2sys/amd64/amd64/fpu.c
+21-218 files not shown
+31-2814 files

FreeBSD/src 18ce3f5 — sys/dev/random rdseed.c ivy.c

random: Remove unused include of ifuncs

No functional change (intended).

Reviewed by:    markj, emaste
Fixes:          3a12982962ce ("random: add RDSEED as a provably unique entropy source")
MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D60193
DeltaFile
+0-1sys/dev/random/rdseed.c
+0-1sys/dev/random/ivy.c
+0-22 files

FreeBSD/src 0b98828 — tests/sys/fs/fusefs misc.cc

fusefs: fix gcc build error with shadowed variable in tests

Reported by:    gcc -Werror=shadow
Reviewed by:    asomers, markj
Fixes:  ee1c3d38a26a ("fusefs: fix vnode locking violations during execve")
Differential Revision:  https://reviews.freebsd.org/D58130

(cherry picked from commit c503d23a6ccb8090edabc1c90981f9b8f202e093)
DeltaFile
+2-2tests/sys/fs/fusefs/misc.cc
+2-21 files

FreeBSD/src e2279d5 — usr.sbin/tcpdrop tcpdrop.c

tcpdrop: improve handling of -C and -S

Handle empty strings for -Cand -S correctly.

Reported by:            maxim
Reviewed by:            maxim
MFC after:              1 week
MFC to:                 stable/14
MFC to:                 stable/15
Sponsored by:           Netflix, Inc.
Differential Revision:  https://reviews.freebsd.org/D60210
DeltaFile
+11-9usr.sbin/tcpdrop/tcpdrop.c
+11-91 files

FreeBSD/src 74152f8 — lib/clang llvm.build.mk, lib/clang/include/llvm/Config Targets.h

llvm: remove Mips target support

The Mips architecture has been removed from all supported branches now.

MFC after:      1 week

(cherry picked from commit b5d1e0c5a4929e2be3bc58aad8e5b707860ec0fd)
DeltaFile
+6-83lib/clang/libllvm/Makefile
+1-6share/man/man5/src.conf.5
+0-4tools/build/options/WITH_LLVM_TARGET_MIPS
+0-4tools/build/options/WITHOUT_LLVM_TARGET_MIPS
+0-4lib/clang/include/llvm/Config/Targets.h
+0-3lib/clang/llvm.build.mk
+7-1045 files not shown
+8-11711 files

FreeBSD/src c93b512 — lib/clang llvm.build.mk, lib/clang/include/llvm/Config Targets.h

llvm: remove Mips target support

The Mips architecture has been removed from all supported branches now.

MFC after:      1 week

(cherry picked from commit b5d1e0c5a4929e2be3bc58aad8e5b707860ec0fd)
DeltaFile
+6-83lib/clang/libllvm/Makefile
+1-6share/man/man5/src.conf.5
+0-4tools/build/options/WITH_LLVM_TARGET_MIPS
+0-4tools/build/options/WITHOUT_LLVM_TARGET_MIPS
+0-4lib/clang/include/llvm/Config/Targets.h
+0-3lib/clang/llvm.build.mk
+7-1045 files not shown
+8-11711 files

FreeBSD/src 9deffad — sys/dev/cxgbe/firmware t7fw_cfg_uwire.txt t7fw_cfg_fpga.txt

cxgbe(4): Use alternate credit compute mechanism in T7 LB modes

MFC after:      2 weeks
Sponsored by:   Chelsio Communications
DeltaFile
+2-2sys/dev/cxgbe/firmware/t7fw_cfg_uwire.txt
+2-2sys/dev/cxgbe/firmware/t7fw_cfg_fpga.txt
+2-2sys/dev/cxgbe/firmware/t7fw_cfg.txt
+6-63 files

FreeBSD/src a68d11d — tools/test/stress2/misc gnop7.sh gnop6.sh

stress2: Fix script bugs in gnop6.sh, gnop7.sh and fdatasync*.sh

gnop6.sh recorded the checkfs result with "checkfs ... || s=1 && s=0",
which the shell parses as "(checkfs || s=1) && s=0", so the test passed
even when the file system check failed.

gnop7.sh only sets s when unmount or fsck_ffs fails and ends with
"exit $s".  On a clean run s is unset, and the script exits with the
status of the preceding "[ $notloaded ] && gnop unload", which is 1
whenever geom_nop was already loaded, for instance by an earlier test.

fdatasync.sh and fdatasync2.sh ran "df -i $RUNDIR" before creating the
directory.  With a RUNDIR that does not exist yet, df failed, the test
printed "[: -lt: unexpected operator" and the free inode check was
skipped.

Reviewed by:    pho
Differential Revision:  https://reviews.freebsd.org/D60136
Sponsored by:   Sippy Software, Inc.
MFC after:      2 weeks
DeltaFile
+1-2tools/test/stress2/misc/fdatasync2.sh
+1-2tools/test/stress2/misc/fdatasync.sh
+1-1tools/test/stress2/misc/gnop6.sh
+1-0tools/test/stress2/misc/gnop7.sh
+4-54 files

FreeBSD/src 9279dd3 — usr.sbin/tcpdrop tcpdrop.8

tcpdrop.8: Xr mod_cc(4)

MFC after:      1 week
DeltaFile
+1-0usr.sbin/tcpdrop/tcpdrop.8
+1-01 files

FreeBSD/src cdb4538 — usr.sbin/tcpdrop tcpdrop.8

tcpdrop.8: spell newreno

MFC after:      1 week
DeltaFile
+5-5usr.sbin/tcpdrop/tcpdrop.8
+5-51 files

FreeBSD/src 2748019 — tests/sys/vfs abi_root_symlink.sh

tests/sys/vfs: Fix the Linux kld check

linux and linux64 are file names, not module names.  The corresponding
module names are linuxelf and linux64elf, respectively, so these tests
were always being skipped.

Fixes:          b98d169d1f91 ("tests/sys/vfs: add ABI-root absolute symlink tests")
Sponsored by:   The FreeBSD Foundation
DeltaFile
+1-1tests/sys/vfs/abi_root_symlink.sh
+1-11 files

FreeBSD/src f117b6b — sys/kern kern_lockf.c

lockf: Do not block in vfs_busy()

A race is possible otherwise: vfs_busy() may return after an unmounted
filesystem has been removed from the global mount list.  That is,
vfs_busy() will block until vfs_mount_destroy() sets MNTK_REFEXPIRE, and
at that point the mountpoint has been removed from the mountlist, so
TAILQ_FOREACH can return an invalid value.

Simply do not block if the mountpoint is being unmounted.

Reviewed by:    kib
Fixes:          eca39864f702 ("Add sysctl KERN_LOCKF")
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59982

(cherry picked from commit dd16a5f53b0b2e967d20d2900f18fc320997679b)
DeltaFile
+1-1sys/kern/kern_lockf.c
+1-11 files

FreeBSD/src a5d112b — sys/kern kern_lockf.c

lockf: Do not block in vfs_busy()

A race is possible otherwise: vfs_busy() may return after an unmounted
filesystem has been removed from the global mount list.  That is,
vfs_busy() will block until vfs_mount_destroy() sets MNTK_REFEXPIRE, and
at that point the mountpoint has been removed from the mountlist, so
TAILQ_FOREACH can return an invalid value.

Simply do not block if the mountpoint is being unmounted.

Reviewed by:    kib
Fixes:          eca39864f702 ("Add sysctl KERN_LOCKF")
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59982

(cherry picked from commit dd16a5f53b0b2e967d20d2900f18fc320997679b)
DeltaFile
+1-1sys/kern/kern_lockf.c
+1-11 files

FreeBSD/src c3b8e0b — sys/vm vm_page.c

vm_page: Fix the error path in vm_page_alloc_contig_domain()

If we are inserting a run of pages into a VM object and fail at some
point due to a memory allocation failure, we have to free all of the
pages in the run.  We do that by resetting some fields and calling
vm_page_free_toq() on each page; this removes the page from the object
and frees it back to the buddy allocator.

If the page is supposed to be wired, we reset the reference count, but
this was done incorrectly: the VPRC_OBJREF flag must be retained as the
page still belongs to an object.  Resetting it to zero will cause a
panic in vm_page_free_prep(): vm_page_free_object_prep() will subtract
VPRC_OBJREF from the refcount, causing underflow, and
vm_page_free_prep() subsequently calls panic() if the refcount is
non-zero.

Reviewed by:    alc, kib
Fixes:          fee2a2fa3983 ("Change synchonization rules for vm_page reference counting.")
MFC after:      1 week

    [4 lines not shown]
DeltaFile
+1-1sys/vm/vm_page.c
+1-11 files

FreeBSD/src 3be409a — sys/security/mac_bsdextended mac_bsdextended.c

mac_bsdextended: reject negative rule indices in sysctl_rule()

The security.mac.bsdextended.rules.<N> node handler takes N as
`index = name[0]` (a signed int) and only checks
`index >= MAC_BSDEXTENDED_MAXRULES`.  A negative index is caught on
the read branch, but the write-only add and delete
branches proceed to `rules[index]` unconditionally.

Reject `index < 0` alongside the existing upper-bound check.

Submitted by calif.io for the OpenAI Patch The Planet program

Signed-off-by: Andrew Griffiths <andrew at calif.io>

Reviewed by:    markj
MFC after:      2 weeks

(cherry picked from commit 5d0b87669a91244e330a35fc973e6c60f92f6d1f)
DeltaFile
+2-2sys/security/mac_bsdextended/mac_bsdextended.c
+2-21 files

FreeBSD/src d1b4981 — usr.sbin/ppp tty.c radius.c

ppp: Fix address leaks

Avoid printing timer addresses, so as to not divulge information about
the address space layout.

In ip.c, print the actual SPI instead of a pointer to the SPI in the
header buffer.

When debug logging is enabled, don't leak pointers when logging function
arguments or return values.

Reported by:    Reo Shiseki
MFC after:      2 weeks
Sponsored by:   The FreeBSD Foundation

(cherry picked from commit c91777f23a3b13649cdf303515ee45a04c788af3)
DeltaFile
+11-8usr.sbin/ppp/timer.c
+4-4usr.sbin/ppp/ip.c
+2-2usr.sbin/ppp/radius.c
+2-2usr.sbin/ppp/id.c
+1-2usr.sbin/ppp/tty.c
+20-185 files

FreeBSD/src ce4ece1 — sys/vm vm_page.c

vm_page: Fix the error path in vm_page_alloc_contig_domain()

If we are inserting a run of pages into a VM object and fail at some
point due to a memory allocation failure, we have to free all of the
pages in the run.  We do that by resetting some fields and calling
vm_page_free_toq() on each page; this removes the page from the object
and frees it back to the buddy allocator.

If the page is supposed to be wired, we reset the reference count, but
this was done incorrectly: the VPRC_OBJREF flag must be retained as the
page still belongs to an object.  Resetting it to zero will cause a
panic in vm_page_free_prep(): vm_page_free_object_prep() will subtract
VPRC_OBJREF from the refcount, causing underflow, and
vm_page_free_prep() subsequently calls panic() if the refcount is
non-zero.

Reviewed by:    alc, kib
Fixes:          fee2a2fa3983 ("Change synchonization rules for vm_page reference counting.")
MFC after:      1 week

    [4 lines not shown]
DeltaFile
+1-1sys/vm/vm_page.c
+1-11 files

FreeBSD/src 6ff5cdc — usr.sbin/ppp tty.c radius.c

ppp: Fix address leaks

Avoid printing timer addresses, so as to not divulge information about
the address space layout.

In ip.c, print the actual SPI instead of a pointer to the SPI in the
header buffer.

When debug logging is enabled, don't leak pointers when logging function
arguments or return values.

Reported by:    Reo Shiseki
MFC after:      2 weeks
Sponsored by:   The FreeBSD Foundation

(cherry picked from commit c91777f23a3b13649cdf303515ee45a04c788af3)
DeltaFile
+11-8usr.sbin/ppp/timer.c
+4-4usr.sbin/ppp/ip.c
+2-2usr.sbin/ppp/radius.c
+2-2usr.sbin/ppp/id.c
+1-2usr.sbin/ppp/tty.c
+20-185 files

FreeBSD/src adfcef9 — sys/kern uipc_shm.c

posixshm: Fix a double unlock in shm_partial_page_invalidate()

For some reason, shm_partial_page_invalidate() unlocks the object upon
an error, but its callers don't expect this.  Don't do any special error
handling.  Keep the subroutine anyway since the name is a bit clearer
than vm_page_grab_zero_partial().

While here, normalize the object pointer used for locking in
shm_deallocate().

Reviewed by:    kib
Fixes:          454bc887f250 ("uipc_shm: Implements fspacectl(2) support")
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59877

(cherry picked from commit ba974faaf30b74472acc4f0dc5853a22d43951f2)
DeltaFile
+2-7sys/kern/uipc_shm.c
+2-71 files

FreeBSD/src 62dfa6c — sys/security/mac_bsdextended mac_bsdextended.c

mac_bsdextended: reject negative rule indices in sysctl_rule()

The security.mac.bsdextended.rules.<N> node handler takes N as
`index = name[0]` (a signed int) and only checks
`index >= MAC_BSDEXTENDED_MAXRULES`.  A negative index is caught on
the read branch, but the write-only add and delete
branches proceed to `rules[index]` unconditionally.

Reject `index < 0` alongside the existing upper-bound check.

Submitted by calif.io for the OpenAI Patch The Planet program

Signed-off-by: Andrew Griffiths <andrew at calif.io>

Reviewed by:    markj
MFC after:      2 weeks

(cherry picked from commit 5d0b87669a91244e330a35fc973e6c60f92f6d1f)
DeltaFile
+2-2sys/security/mac_bsdextended/mac_bsdextended.c
+2-21 files

FreeBSD/src 37c9eba — contrib/llvm-project/clang/lib/CodeGen CGDebugInfo.cpp

Merge commit 80e8c0a59189 from llvm-project (by ShengYi Hung):

  [DebugInfo] Fill Column 0 if Line is not found (#227559)

  It is possible that user specified line 0 as the start of the line in C
  language (using `# 0`). However, it is rejected by the Lexer as we have
  no line but still carries column information. As a result, we fill
  column to 0 if we cannot find line.

  Assisted-by: Claude # Test
  Fixes: #56186

This fixes a fatal error when building the textproc/peg port.

PR:             264853
MFC after:      3 days
DeltaFile
+5-2contrib/llvm-project/clang/lib/CodeGen/CGDebugInfo.cpp
+5-21 files

FreeBSD/src b69c008 — sys/netinet6 nd6.c

nd6: Fix regeneration of temp addresses in detached state

When an on-link prefix becomes detached, the kernel keeps
generating new RFC 8981 temporary addresses for that prefix.
Fix it by ignoring the detached addresses in regen_tmpaddr().
While here, change its return type to bool.

PR:             298533
Discussed with: markj
MFC after:      3 days
Differential Revision:  https://reviews.freebsd.org/D60051

(cherry picked from commit 61f98a98250da7bd2c80c6d93d0032961d7f2fad)
DeltaFile
+18-12sys/netinet6/nd6.c
+18-121 files

FreeBSD/src f05af59 — lib/libpfctl libpfctl.c, sys/netpfil/pf pf_nl.h pf_nl.c

pf: return per-address feedback from netlink table test

The PFNL_CMD_TABLE_TEST_ADDRS reply carries only the match count, so
the per-address feedback from pfr_tst_addrs() is lost:
"pfctl -v -T test" lists nothing and "pfctl -vv -T test" reports
every address as "nomatch".

Return each address, as updated by pfr_tst_addrs(), in a nested
PF_TAS_ADDR attribute, and decode them into the caller's array in
libpfctl.  PF_TA_ADDR is not reused: it shares its value with
PF_TAS_ASTATS, which older libpfctl would decode into an
uninitialised target.  That target was also read when no reply was
parsed, so the match count could be garbage; initialise it.

Add a regression test.

Reviewed by:            kp
Approved by:            kp (mentor)
Fixes:                  281282e9357b ("pf: convert DIOCRTSTADDRS to netlink")

    [3 lines not shown]
DeltaFile
+55-0tests/sys/netpfil/pf/table.sh
+10-2lib/libpfctl/libpfctl.c
+4-0sys/netpfil/pf/pf_nl.c
+1-0sys/netpfil/pf/pf_nl.h
+70-24 files

FreeBSD/src 5c13a82 — sys/netpfil/pf pf_ioctl.c

pf: remove a source limiter from the id tree if its name is taken

When pf_sourcelim_add() finds the name of the new limiter taken, it
undoes the insertion into the id tree with RB_REMOVE() on the name tree,
which the limiter is not in, and then frees the limiter.  The freed
limiter stays in the inactive id tree, and RB_REMOVE() of an element
with no links clears the root of the name tree, which loses every other
inactive limiter from it.  pf_statelim_add() gets this right.

parse.y refuses duplicate names, so pfctl does not get here, but any
netlink client can.

Reviewed by:            kp
Approved by:            kp (mentor)
Fixes:                  461648121230 ("pf: introduce source and state limiters")
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60189
DeltaFile
+1-1sys/netpfil/pf/pf_ioctl.c
+1-11 files

FreeBSD/src 2fa4ef4 — sys/netpfil/pf pf_ioctl.c

pf: free the packet rate counter of a rule

pf_ioctl_addrule() allocates a counter_rate for every rule, whether it
has a max-pkt-rate or not, and pf_krule_free() never frees it.

Free it with the rest of the rule.

Reviewed by:            kp
Approved by:            kp (mentor)
Fixes:                  ff11f1c8c76c ("pf: add a generic packet rate matching filter")
MFC after:              1 week
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60190
DeltaFile
+1-0sys/netpfil/pf/pf_ioctl.c
+1-01 files