Displaying 1 50 of 260,868 commits (0.021s)

HardenedBSD — share/examples/bhyve vmrun.sh

HBSD: Resolve merge conflict

Signed-off-by:        Shawn Webb <shawn.webb at hardenedbsd.org>
Sponsored-by:        SoldierX
Delta File
+1 -5 share/examples/bhyve/vmrun.sh
+1 -5 1 file

HardenedBSD — share/examples/bhyve vmrun.sh

vmrun.sh: add -A option for AHCI emulation of disk devices

AHCI emulation is useful for testing scenarios closer to the real
hardware.  For example, it allows to exercise the CAM subsystem.
There could be other uses as well.

MFC after:        2 weeks
Delta File
+8 -3 share/examples/bhyve/vmrun.sh
+8 -3 1 file

HardenedBSD — usr.bin/vmstat vmstat.c

vmstat: use 64-bit counters from struct vmtotal.

Consistently print counters using unsigned intmax type.

Submitted by:        Pawel Biernacki <pawel.biernacki at gmail.com>
Sponsored by:        Mysterious Code Ltd.
Differential revision:        https://reviews.freebsd.org/D13199
Delta File
+6 -6 usr.bin/vmstat/vmstat.c
+6 -6 1 file

HardenedBSD — usr.bin/vmstat vmstat.c

Use C standard spelling uint64_t for u_int64_t.

Submitted by:        Pawel Biernacki <pawel.biernacki at gmail.com>
Sponsored by:        Mysterious Code Ltd.
X-Differential revision:        https://reviews.freebsd.org/D13199
Delta File
+3 -3 usr.bin/vmstat/vmstat.c
+3 -3 1 file

HardenedBSD — sys/arm/arm machdep.c, sys/arm64/arm64 machdep.c

Ensure we check the program state set in the trap frame on arm and arm64.
This value may be set by userspace so we need to check it before using it.
If this is not done correctly on exception return the kernel may continue
in kernel mode with all registers set to a userspace controlled value. Fix
this by moving the check into set_mcontext, and also add the missing
sanitisation from the arm64 set_regs.

Discussed with:        security-officer@
MFC after:        3 days
Sponsored by:        DARPA, AFRL

HardenedBSD — contrib/binutils/bfd peXXigen.c

bfd: avoid crash on corrupt binaries

From binutils commits 5a4b0ccc20ba30caef53b01bee2c0aaa5b855339 and
7e1e19887abd24aeb15066b141cdff5541e0ec8e, made available under GPLv2
by Nick Clifton.

PR:                198824
MFC after:        1 week
Security:        CVE-2014-8501
Security:        CVE-2014-8502
Delta File
+20 -0 contrib/binutils/bfd/peXXigen.c
+20 -0 1 file

HardenedBSD — contrib/less command.c, usr.bin/less Makefile

HBSD: Fix cfi-icall in /usr/bin/less

The gr_getc callback was being improperly handled, triggering the
cfi-icall scheme to fire.

Signed-off-by:        Shawn Webb <shawn.webb at hardenedbsd.org>
Sponsored-by:        SoldierX

HardenedBSD — . ObsoleteFiles.inc

HBSD: Do not remove librt_p.a

Signed-off-by:        Shawn Webb <shawn.webb at hardenedbsd.org>
Sponsored-by:        SoldierX
Delta File
+0 -1 ObsoleteFiles.inc
+0 -1 1 file

HardenedBSD — sys/dev/efidev efirtc.c

Zero struct efi_tm before setting the needed values. We don't use the dst
or timezone fields so ensure these are set.

Reported by:        emaste
Sponsored by:        DARPA, AFRL
Delta File
+1 -0 sys/dev/efidev/efirtc.c
+1 -0 1 file

HardenedBSD — sys/dev/ahci ahci_pci.c

MFC r325571: Add some PCI IDs found on AMD Epyc system.
Delta File
+5 -0 sys/dev/ahci/ahci_pci.c
+5 -0 1 file

HardenedBSD — sys/cam/ata ata_da.c, sys/cam/scsi scsi_da.c

MFC r325888:

Add some 4k quirks for Samsung pm863a SSDs

Submitted by:        Nikita Kozlov <nikita.kozlov at blade-group.com>
Sponsored by:        blade
Differential Revision:        https://reviews.freebsd.org/D13093
Delta File
+8 -0 sys/cam/ata/ata_da.c
+8 -0 sys/cam/scsi/scsi_da.c
+16 -0 2 files

HardenedBSD — sys/kern kern_sx.c

sx: unbreak debug after r326107

An assertion was modified to use the found value, but it was not updated to
handle a race where blocked threads appear after the entrance to the func.

Move the assertion down to the area protected with sleepq lock where the
lock is read anyway. This does not affect coverage of the assertion and
is consistent with what rw locks are doing.

Reported by:        Shawn Webb
Delta File
+1 -1 sys/kern/kern_sx.c
+1 -1 1 file

HardenedBSD — sys/kern kern_rwlock.c

rwlock: unbreak WITNESS builds after r326110

Reported by:        Shawn Webb
Delta File
+1 -1 sys/kern/kern_rwlock.c
+1 -1 1 file

HardenedBSD — usr.bin/less Makefile

HBSD: Disable cfi-icall for less, again

The newly-imported less violates the cfi-icall scheme.

Signed-off-by:        Shawn Webb <shawn.webb at hardenedbsd.org>
Sponsored-by:        SoldierX
Delta File
+2 -0 usr.bin/less/Makefile
+2 -0 1 file

HardenedBSD — sys/kern kern_rwlock.c

rwlock: don't check for curthread's read lock count in the fast path
Delta File
+17 -9 sys/kern/kern_rwlock.c
+17 -9 1 file

HardenedBSD — sys/conf files, sys/dev/bhnd bhnd_types.h

bhnd(4): Add a basic ChipCommon GPIO driver sufficient to support bwn(4)

The driver is functional on both BHND Wi-Fi adapters and MIPS SoCs, but
does not currently include support for features not required by bwn(4),
including GPIO interrupt handling.

Approved by:        adrian (mentor, implicit)
Sponsored by:        The FreeBSD Foundation
Differential Revision:        https://reviews.freebsd.org/D12708

HardenedBSD — usr.bin/systat vmstat.c

Order declarations alphabetically.
Match signess of the format and the value.

Noted by:        bde
Sponsored by:        The FreeBSD Foundation
Delta File
+2 -2 usr.bin/systat/vmstat.c
+2 -2 1 file

HardenedBSD — sys/kern kern_sx.c kern_mutex.c, sys/sys mutex.h rwlock.h

locks: pass the found lock value to unlock slow path

This avoids an explicit read later.

While here whack the cheaply obtainable 'tid' argument.

HardenedBSD — sys/kern kern_rwlock.c kern_sx.c, sys/sys rwlock.h sx.h

locks: remove the file + line argument from internal primitives when not used

The pair is of use only in debug or LOCKPROF kernels, but was passed (zeroed)
for many locks even in production kernels.

While here whack the tid argument from wlock hard and xlock hard.

There is no kbi change of any sort - "external" primitives still accept the

HardenedBSD — lib/libnetgraph netgraph.3 Makefile

MFC r325552: s/NgSendMsgReply/NgSendReplyMsg/ in man to match the code.

Submitted by:        Dmitry Luhtionov <dmitryluhtionov at gmail.com>

HardenedBSD — sys/kern kern_proc.c

HBSD: Resolve merge conflict

Signed-off-by:        Shawn Webb <shawn.webb at hardenedbsd.org>
Sponsored-by:        SoldierX
Delta File
+1 -2 sys/kern/kern_proc.c
+1 -2 1 file

HardenedBSD — usr.sbin/bsdinstall/scripts services

HBSD: Resolve merge conflict

Signed-off-by:        Shawn Webb <shawn.webb at hardenedbsd.org>
Sponsored-by:        SoldierX

HardenedBSD — sys/vm vm_map.c

When vm_map_find(find_space = VMFS_OPTIMAL_SPACE) fails to find space, a
second scan of the address space with find_space = VMFS_ANY_SPACE is
performed.  Previously, vm_map_find() released and reacquired the map lock
between the first and second scans.  However, there is no compelling
reason to do so.  This revision modifies vm_map_find() to retain the map

Reviewed by:        jhb, kib, markj
MFC after:        1 week
X-Differential Revision:        https://reviews.freebsd.org/D13155
Delta File
+2 -2 sys/vm/vm_map.c
+2 -2 1 file

HardenedBSD — cddl/usr.sbin/dtrace/tests/tools exclude.sh

Annotate pragma/err.invalidlibdep.ksh as EXFAIL.

The test creates a D library with a "depends_on library" pragma
referencing a non-existent library, and expects compilation to fail.
However, as far as I can tell, libdtrace is supposed simply abort
compilation of the library in this case, and continue. This behaviour
is desirable when adding libraries which depend on optional KLDs, for

MFC after:        1 week

HardenedBSD — usr.sbin/bsdinstall/scripts services

bsdinstall: Add ntpdate option

When you install a computer for the first time, the date in the CMOS sometimes
not accurate and you need to ntpdate as ntpd will fail a the time difference
is too big.
Add an option in bsdinstall to enable ntpdate that will do that for us.

Reviewed by:        allanjude
Differential Revision:        https://reviews.freebsd.org/D13149

HardenedBSD — usr.sbin/bsdinstall/scripts wlanconfig

Fix indentation in bsdinstall-created wpa_supplicant.conf

r309934 cleaned up some cases in bsdinstall to use heredocs but broke
the indentation of the generated output, because <<- heredocs strip
leading tabs.

PR:                221982
Reviewed by:        allanjude, dteske
MFC after:        2 weeks
Sponsored by:        The FreeBSD Foundation
Differential Revision:        https://reviews.freebsd.org/D13190
Delta File
+38 -38 usr.sbin/bsdinstall/scripts/wlanconfig
+38 -38 1 file

HardenedBSD — sys/netinet tcp_subr.c

Use the right variable for the IP header parameter to tcp:::send.

This addresses a regression from r311225.

MFC after:        1 week
Delta File
+8 -4 sys/netinet/tcp_subr.c
+8 -4 1 file

HardenedBSD — sys/riscv/riscv pmap.c

o Invalidate the correct page in pmap_protect().
  With this bug fix we don't need to invalidate all the entries.
o Remove a call to pmap_invalidate_all(). This was never called
  as the anyvalid variable is never set.

Obtained from:        arm64/pmap.c (r322797, r322800)
Sponsored by:        DARPA, AFRL
Delta File
+1 -8 sys/riscv/riscv/pmap.c
+1 -8 1 file

HardenedBSD — share/man/man4 ctl.4, sys/cam/ctl ctl.c ctl_private.h

MFC r325517, r325554

ctl: Make max_luns and max_ports tunable variables instead of hardcoded

Reviewed by:        trasz (earlier version), bapt (earlier version), bcr (manpages)
Sponsored by:        Gandi.net
Differential Revision:        https://reviews.freebsd.org/D12836

ctl(4): Insert a new line after a sentence-ending full stop.

Reported by:        bjk
Sponsored by:        Gandi.net
X-MFC-With:  r325517

HardenedBSD — stand/common dev_net.c

net_parse_rootpath() has no parameters

Add void for parameter list.
Delta File
+1 -1 stand/common/dev_net.c
+1 -1 1 file

HardenedBSD — stand/efi/libefi efipart.c

loader.efi: efipart does not recognize partitionless disks

Rework the block device handle check to allow more robust device
classification. This is mostly usability issue - it can be quite confusing
for user when no disks are listed with lsdev.

Add more comments about what and why is done.

Reviewed by:        imp
Differential Revision:        https://reviews.freebsd.org/D13026
Delta File
+100 -11 stand/efi/libefi/efipart.c
+100 -11 1 file

HardenedBSD — share/man/man4 arcmsr.4, sys/dev/arcmsr arcmsr.c arcmsr.h

MFC r325532: Update arcmsr(4) to

 - Fix clear doorbell queue buffer for ADAPTER_TYPE_B
 - Fix release memory resource when detach device
 - Add support for ARC-1216, 1226 SAS 12Gb controllers
 - Declare some functions as static
 - Change checking dword read/write for IOP rqbuffer.

Many thanks to Areca for continuing to support FreeBSD.

Submitted by: 黃清隆 <ching2048 areca com tw>

HardenedBSD — usr.bin/patch patch.c

patch(1): don't assume a match if we run out of context to check

Patches with very little context (-U0 and -U1) could get misapplied if
the file to be patched changes and a hunk is no longer applicable. Matching
with fuzz would be attempted and default to a match when we unexpectedly ran
out of context.

This also affected patches with higher levels of context but had limited
actual context due to the hunk being located near the beginning/end of file.

PR:                74127, 223545 (exp-run)
Reviewed by:        emaste, pfg
Approved by:        emaste (mentor)
Differential Revision:        https://reviews.freebsd.org/D12631
Delta File
+3 -0 usr.bin/patch/patch.c
+3 -0 1 file

HardenedBSD — sys/cddl/dev/profile profile.c

PowerPC has 12 artificial frames for the profiler

It may need to be different between AIM and Book-E, this was tested only on
Book-E (64- and 32-bit)

MFC after:        3 weeks
Delta File
+1 -1 sys/cddl/dev/profile/profile.c
+1 -1 1 file

HardenedBSD — usr.sbin/freebsd-update freebsd-update.sh

freebsd-update: do not duplicate patchlist entries

PR:                221079
Submitted by:        Masachika ISHIZUKA
Submitted by:        ota at j.email.ne.jp
Reviewed by:        cperciva
MFC after:        1 week

HardenedBSD — sys/dev/bhnd bhnd.h bhnd_bus_if.m, sys/dev/bhnd/bhndb bhndb_subr.c bhndb.c

bhnd(4): Add support for querying DMA address translation parameters

BHND Wi-Fi chipsets and SoCs share a common DMA engine, operating within
backplane address space. To support host DMA on Wi-Fi chipsets, the bridge
core maps host address space onto the backplane; any host addresses must
be translated to their corresponding backplane address.

- Defines a new bhnd_get_dma_translation(9) API to support querying DMA
  address translation parameters from the bhnd(4) bus.
- Extends bhndb(4) to provide DMA translation descriptors from a DMA
  address translation table defined in the host bridge-specific
- Defines bhndb(4) DMA address translation tables for all supported host
  bridge cores.
- Extends mips/broadcom's bhnd_nexus driver to return an identity (no-op)
  DMA translation descriptor; no translation is required when addressing
  the SoC backplane.

Approved by:        adrian (mentor)
Sponsored by:        The FreeBSD Foundation
Differential Revision:        https://reviews.freebsd.org/D12582

HardenedBSD — sys/dev/bhnd bhnd_bus_if.m bhnd.h, sys/dev/bhnd/bcma bcma_subr.c bcma.c

bhnd(4): implement MIPS and PCI(e) interrupt support

On BHND MIPS SoCs, this replaces the use of hard-coded MIPS IRQ#s in the
common bhnd(4) core drivers; we now register an INTRNG child PIC that
handles routing of backplane interrupt vectors via the MIPS core.

On BHND PCI devices, backplane interrupt vectors are now routed to the
PCI/PCIe host bridge core when bus_setup_intr() is called, where they are
dispatched by the PCI core via a host interrupt (e.g. INTx/MSI).

The bhndb(4) bridge driver tracks registered interrupt handlers for the
bridged bhnd(4) devices and manages backplane interrupt routing, while
delegating actual bus interrupt setup/teardown to the parent bus on behalf
of the bridged cores.

Approved by:        adrian (mentor, implicit)
Sponsored by:        The FreeBSD Foundation
Differential Revision:        https://reviews.freebsd.org/D12518

HardenedBSD — sys/contrib/cloudabi cloudabi_vdso_armv6_on_64bit.S cloudabi_vdso_armv6.S

Import the latest CloudABI definitions, v0.18.

In addition to some small style fixes to the ARMv6 vDSO, this release
includes a new vDSO that can be used for the execution of ARMv6/ARMv7
code on 64-bit platforms.

Just like for i686 on x86-64, this new vDSO is responsible for padding
arguments and return values to 64-bit values, so that the kernel can
easily forward system calls to the native system calls.

Obtained from:        https://github.com/NuxiNL/cloudabi

HardenedBSD — etc/periodic/daily 200.backup-passwd

filter all passwords (not only changed) from periodic passwd backup

The periodic 200.backup-passwd script outputs any differences it finds
in master.passwd, relative to the previous backup.  It intends to elide
the encrypted password field, but previously did so only for changed
lines (i.e., those beginning with - or + in the diff).

Apply the sed expression also to unchanged lines to also elide their

PR:                223461
Reported by:        Andre Albsmeier
MFC after:        2 weeks
Sponsored by:        The FreeBSD Foundation

HardenedBSD — usr.bin/systat vmstat.c Makefile

systat: use and correctly display 64bit counters.

Following struct vmtotal changes, make systat use and correctly
display 64-bit counters.  Switch to humanize_number(3) to overcome
homegrown arithmetics limits in pretty printing large numbers.  Use
1024 as a divisor for memory fields to make it consistent with other
tools and users expectations.

Submitted by:        Pawel Biernacki <pawel.biernacki at gmail.com>
Sponsored by:        Mysterious Code Ltd.
PR:        2137
Differential revision:        https://reviews.freebsd.org/D13105
Delta File
+40 -20 usr.bin/systat/vmstat.c
+1 -1 usr.bin/systat/Makefile
+41 -21 2 files

HardenedBSD — stand Makefile.inc

Unbreak riscv build in universe.

riscv doesn't have -msoft-float. For the moment, just don't add
anything. There's no /boot/loader or other bootstrap contained in the
tree for riscv*. However, with real hardware coming next year, there
are plans for one, so keep building at least a minimal libsa and
ficl to prevent bitrot.

Sponsored by: Netflix
Delta File
+3 -1 stand/Makefile.inc
+3 -1 1 file

HardenedBSD — . Makefile

Use TARGET_ARCH=riscv64 when TARGET=riscv

The supported targets are riscv64 and riscv64sf. Use the former when
building with a bare TARGET=riscv and it is the more common one.

Sponsored by: Netflix
Delta File
+1 -1 Makefile
+1 -1 1 file

HardenedBSD — sys/cddl/contrib/opensolaris/uts/common/fs/zfs zfs_vnops.c

zfs_write: fix problem with writes appearing to succeed when over quota

The problem happens when the writes have offsets and sizes aligned with
a filesystem's recordsize (maximum block size).  In this scenario
dmu_tx_assign() would fail because of being over the quota, but the uio
would already be modified in the code path where we copy data from the
uio into a borrowed ARC buffer.  That makes an appearance of a partial
write, so zfs_write() would return success and the uio would be modified
consistently with writing a single block.

That bug can result in a data loss because the writes over the quota
would appear to succeed while the actual data is being discarded.

This commit fixes the bug by ensuring that the uio is not changed until
after all error checks are done.  To achieve that the code now uses
uiocopy() + uioskip() as in the original illumos design.  We can do that
now that uiocopy() has been updated in r326067 to use

Reported by:        mav
Analyzed by:        mav
Reviewed by:        mav
Pointyhat to:        avg (myself)
MFC after:        1 week
X-MFC after:        r326067
X-Erratum:        wanted

HardenedBSD — stand/i386/gptzfsboot Makefile, stand/i386/libi386 Makefile

Fix gptzfsboot for cases with GELI.

HAVE_GPT isn't currently a thing, but HAVE_GELI is. Replace the former
with the latter and remove util.o from the build list (it's picked up
from libsa/libsa32, and that's OK).

Sponsored by: Netflix

HardenedBSD — release/tools ec2.conf gce.conf

Remove /etc/resolv.conf from virtual machine images, which is
copied from the build host.  It is renamed to /etc/resolv.conf.bak
on boot, so never used anyway.

Noticed by:        peter
MFC after:        3 days
Sponsored by:        The FreeBSD Foundation

HardenedBSD — sys/cddl/compat/opensolaris/kern opensolaris_uio.c

make illumos uiocopy use vn_io_fault_uiomove

uiocopy() is currently unused, its purpose is copy data from a uio
without modifying the uio.  It was in use before the vn_io_fault support
was added to ZFS, at which point our code diverged from the illumos code
a little bit.  Because ZFS is the only (potential) user of the function
we are free to modify it to better suit ZFS needs.

The intention behind this change is to remove the differences introduced
earlier in zfs_write().

While here, re-implement uioskip() using uiomove() with
uio_segflg == UIO_NOCOPY.
The story of uioskip is the same as with uiocopy.

Reviewed by:        mav
MFC after:        1 week

HardenedBSD — sys/arm64/conf GENERIC, sys/conf files

Add a driver for the EFI RTC. This uses the EFI Runtime Services to query
the system time.

As we seem to only read this time on boot, and this is the only source of
time on many arm64 machines we need to enable this by default there. As
this is not always the case with U-Boot firmware, or when we have been
booted from a non-UEFI environment we only enable the device driver when
the Runtime Services are present and reading the time doesn't result in an

PR:                212185
Reviewed by:        imp, kib
Tested by:        emaste
Relnotes:        yes
Sponsored by:        DARPA, AFRL
Differential Revision:        https://reviews.freebsd.org/D12650

HardenedBSD — sys/cam cam.c

Fix uninitialized variable from 326034

Reported by:        Coverity
CID:                1382887
MFC after:        20 days
X-MFC-With:        326034
Sponsored by:        Spectra Logic Corp
Delta File
+2 -1 sys/cam/cam.c
+2 -1 1 file

HardenedBSD — lib/libproc proc_sym.c, lib/libproc/tests proc_test.c target_prog.c

Refine symtab sorting in libproc.

Add some rules to more closely match what illumos does when an address
resolves to multiple symbols:
- prefer non-local symbols
- prefer symbols with fewer leading underscores and no leading '$'

Add some regression tests to verify these rules.

HardenedBSD — cddl/usr.sbin/dtrace/tests/tools exclude.sh

Annotate usdt/tst.eliminate.ksh as EXFAIL.

It appears to depend on some behaviour specific to the Sun link editor.

MFC after:        1 week