]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/log
FreeBSD/FreeBSD.git
4 years agoThis commit makes significant changes to pam_login_access(8) to bring it
cy [Tue, 18 Feb 2020 11:27:08 +0000 (11:27 +0000)]
This commit makes significant changes to pam_login_access(8) to bring it
up to par with the Linux pam_access(8).

Like the Linux pam_access(8) our pam_login_access(8) is a service module
for pam(3) that allows a administrator to limit access from specified
remote hosts or terminals. Unlike the Linux pam_access, pam_login_access
is missing some features which are added by this commit:

Access file can now be specified. The default remains /etc/access.conf.
The syntax is consistent with Linux pam_access.

By default usernames are matched. If the username fails to match a match
against a group name is attempted. The new nodefgroup module option will
only match a username and no attempt to match a group name is made.
Group names must be specified in brackets, "()" when nodefgroup is
specified. Otherwise the old backward compatible behavior is used.
This is consistent with Linux pam_access.

A new field separator module option allows the replacement of the default
colon (:) with any other character. This facilitates potential future
specification of X displays. This is also consistent with Linux pam_access.

A new list separator module option to replace the default space/comma/tab
with another character. This too is consistent with Linux pam_access.

Linux pam_access options not implemented in this commit are the debug
and audit options. These will be implemented at a later date.

Reviewed by: bjk, bcr (for manpages)
Approved by: des (blanket, implicit)
MFC after: 1 month
Differential Revision: https://reviews.freebsd.org/D23198

4 years agostrchr() returns a pointer not an int.
cy [Tue, 18 Feb 2020 11:27:05 +0000 (11:27 +0000)]
strchr() returns a pointer not an int.

Reported by: bjk
Approved by: des (blanket, implicit)
MFC after: 3 days

4 years agoAdd missing SYNOPSIS section.
cy [Tue, 18 Feb 2020 11:27:02 +0000 (11:27 +0000)]
Add missing SYNOPSIS section.

Reported by: ports/textproc/igor
MFC after: 3 days

4 years agoThere is no pam(8) man page, it is pam(3).
cy [Tue, 18 Feb 2020 11:26:59 +0000 (11:26 +0000)]
There is no pam(8) man page, it is pam(3).

Approved by: des (implicit, blanket)
MFC after: 3 days

4 years agoWhen pam_login_access(5) fails to match a username it attempts to
cy [Tue, 18 Feb 2020 11:26:56 +0000 (11:26 +0000)]
When pam_login_access(5) fails to match a username it attempts to
match the primary group a user belongs to. This commit extends the
match to secondary groups a user belongs to as well, just as the Linux
pam_access(5) does.

Approved by: des (implicit, blanket)

4 years agoThe words ALL, LOCAL, and EXCEPT have special meaning and are documented
cy [Tue, 18 Feb 2020 11:26:52 +0000 (11:26 +0000)]
The words ALL, LOCAL, and EXCEPT have special meaning and are documented
as in the login.access(5) man page. However strcasecmp() is used to compare
for these special strings. Because of this User accounts and groups with
the corresponding lowercase names are misintrepreted to have special
whereas they should not.

This commit fixes this, conforming to the man page and to how the Linux
pam_access(8) handles these special words.

Approved by: des (implicit, blanket)

4 years agoAs with ipf(8), give ippool(8) the ability to load IP pools from multiple
cy [Tue, 18 Feb 2020 11:26:49 +0000 (11:26 +0000)]
As with ipf(8), give ippool(8) the ability to load IP pools from multiple
files. This allows for loading, during the same invocation of ippool, of
multiple sources of input using multiple tools to concurrently maintain the
files such as fail2ban, macro preprocessors, and manually.

MFC after: 1 week

4 years agoUpdate ncurses to 20200118
bapt [Tue, 18 Feb 2020 08:11:52 +0000 (08:11 +0000)]
Update ncurses to 20200118

Among the changes from before:
- Add support for extended colors on widechar version
- Enable ncurses extended functions
- Enable version 2 of the extended mouse support
- Enable SCREEN extensions

Modification that differs from upstream:
- _nc_delink_entries used to be exposed and was turn static,
  turn it back as dynamic to not break abi
- Adapt our old termcap.c to modern ncurses

MFC after: 3 weeks

4 years agoUse 0x5c for the scan code 0x7d.
hrs [Tue, 18 Feb 2020 01:50:44 +0000 (01:50 +0000)]
Use 0x5c for the scan code 0x7d.

Japanese keyboards traditionally use 0x5c for
both Japanese yen sign key and backslash key.
While a Japanese yen sign is depicted on the keytop,
most of Japanese expect that the scan code 0x7d gives
a backslash (0x5c), not a Japanese yen sign (0xa5).

This is because JIS X 0201 encoding (aka ISO/IEC 646-JA,
an extended version of ASCII which is very popular
in Japan) has Japanese yen sign at 0x5c and
no backslash.  On the other hand, ISO/IEC 8859-1
has Japanese yen sign at 0xa5.  This difference has
caused a confusion after Unicode became popular since
ISO/IEC 10646 adopted 8859-1 for the plane 0.

MFC after: 1 week

4 years agoamd64: keep PTE bitmasks in sync with target pmap during pv reclaim
chs [Tue, 18 Feb 2020 00:02:20 +0000 (00:02 +0000)]
amd64: keep PTE bitmasks in sync with target pmap during pv reclaim

in reclaim_pv_chunk_domain(), when we switch to a new target pmap from which
we are trying to reclaim a pv chunk, always update the current PTE bitmasks
to match.

Reviewed by: kib, markj
Approved by: imp (mentor)
Sponsored by: Netflix

4 years agoReally skip the tests in capsicum tests
lwhsu [Mon, 17 Feb 2020 20:25:33 +0000 (20:25 +0000)]
Really skip the tests in capsicum tests

Sponsored by: The FreeBSD Foundation

4 years agoMerge r358042 from the clang1000-import branch:
dim [Mon, 17 Feb 2020 20:24:21 +0000 (20:24 +0000)]
Merge r358042 from the clang1000-import branch:

Add casts and L suffixes to libc quad support, to work around various
-Werror warnings from clang 10.0.0, such as:

lib/libc/quad/fixdfdi.c:57:12: error: implicit conversion from 'long long' to 'double' changes value from 9223372036854775807 to 9223372036854775808 [-Werror,-Wimplicit-int-float-conversion]
                if (x >= QUAD_MAX)
                      ~~ ^~~~~~~~
/usr/obj/usr/src/powerpc.powerpc/tmp/usr/include/sys/limits.h:89:19: note: expanded from macro 'QUAD_MAX'
#define QUAD_MAX        (__QUAD_MAX)    /* max value for a quad_t */
                         ^~~~~~~~~~
/usr/obj/usr/src/powerpc.powerpc/tmp/usr/include/machine/_limits.h:91:20: note: expanded from macro '__QUAD_MAX'
#define __QUAD_MAX      __LLONG_MAX     /* max value for a quad_t */
                        ^~~~~~~~~~~
/usr/obj/usr/src/powerpc.powerpc/tmp/usr/include/machine/_limits.h:75:21: note: expanded from macro '__LLONG_MAX'
#define __LLONG_MAX     0x7fffffffffffffffLL    /* max value for a long long */
                        ^~~~~~~~~~~~~~~~~~~~

and many instances of:

lib/libc/quad/fixunsdfdi.c:73:17: error: shift count >= width of type [-Werror,-Wshift-count-overflow]
        toppart = (x - ONE_HALF) / ONE;
                       ^~~~~~~~
lib/libc/quad/fixunsdfdi.c:45:19: note: expanded from macro 'ONE_HALF'
#define ONE_HALF        (ONE_FOURTH * 2.0)
                         ^~~~~~~~~~
lib/libc/quad/fixunsdfdi.c:44:23: note: expanded from macro 'ONE_FOURTH'
#define ONE_FOURTH      (1 << (LONG_BITS - 2))
                           ^  ~~~~~~~~~~~~~~~
lib/libc/quad/fixunsdfdi.c:73:29: error: shift count >= width of type [-Werror,-Wshift-count-overflow]
        toppart = (x - ONE_HALF) / ONE;
                                   ^~~
lib/libc/quad/fixunsdfdi.c:46:15: note: expanded from macro 'ONE'
#define ONE             (ONE_FOURTH * 4.0)
                         ^~~~~~~~~~
lib/libc/quad/fixunsdfdi.c:44:23: note: expanded from macro 'ONE_FOURTH'
#define ONE_FOURTH      (1 << (LONG_BITS - 2))
                           ^  ~~~~~~~~~~~~~~~

MFC after: 3 days

4 years agoMerge r358034 from the clang1000-import branch:
dim [Mon, 17 Feb 2020 20:23:26 +0000 (20:23 +0000)]
Merge r358034 from the clang1000-import branch:

Disable new clang 10.0.0 warnings about misleading indentation in
sys/contrib/ncsw/Peripherals/FM/fman_ncsw.c.

This is horribly formatted contributed code, and fixing it is not worth
the effort.

MFC after: 3 days

4 years agoMerge r358030 from the clang1000-import branch:
dim [Mon, 17 Feb 2020 20:22:10 +0000 (20:22 +0000)]
Merge r358030 from the clang1000-import branch:

Work around new clang 10.0.0 -Werror warning:

sys/arm/allwinner/aw_cir.c:208:41: error: converting the result of '<<' to a boolean; did you mean '((1 & 255) << 23) != 0'? [-Werror,-Wint-in-bool-context]
        active_delay = (AW_IR_ACTIVE_T + 1) * (AW_IR_ACTIVE_T_C ? 128 : 1);
                                               ^
sys/arm/allwinner/aw_cir.c:130:39: note: expanded from macro 'AW_IR_ACTIVE_T_C'
#define AW_IR_ACTIVE_T_C                ((1 & 0xff) << 23)
                                                    ^

Add the != 0 part to indicate that we indeed want to compare against
zero.

MFC after: 3 days

4 years agoFix syntax error from r357647. Adjust a variable name to make the use more
scottl [Mon, 17 Feb 2020 20:12:34 +0000 (20:12 +0000)]
Fix syntax error from r357647.  Adjust a variable name to make the use more
clear.

Reported by: dim

4 years agoFix the non-default stream schedulers such that do not interleave
tuexen [Mon, 17 Feb 2020 18:05:03 +0000 (18:05 +0000)]
Fix the non-default stream schedulers such that do not interleave
user messages when it is now allowed.

Thanks to Christian Wright for reporting the issue for the userland
stack and providing a fix for the priority scheduler.

MFC after: 1 week

4 years agoUse EARLY_DRIVER_MODULE in the acpi bus.
andrew [Mon, 17 Feb 2020 15:32:21 +0000 (15:32 +0000)]
Use EARLY_DRIVER_MODULE in the acpi bus.

We need this to use EARLY_DRIVER_MODULE in child drivers on arm64. This
should be a no-op on x86 as it has DRIVER_MODULE in the nexus driver making
all later drivers attach in the last pass.

Reviewed by: imp
MFC after: 1 month
Sponsored by: Innovate UK
Differential Revision: https://reviews.freebsd.org/D23717

4 years agoRemove swblk_t.
markj [Mon, 17 Feb 2020 15:11:07 +0000 (15:11 +0000)]
Remove swblk_t.

It was used only to store the bounds of each swap device.  However,
since swblk_t is a signed 32-bit int and daddr_t is a signed 64-bit
int, swp_pager_isondev() may return an invalid result if swap devices
are repeatedly added and removed and sw_end for a device ends up
becoming a negative number.

Note that the removed comment about maximum swap size still applies.

Reviewed by: jeff, kib
Tested by: pho
MFC after: 2 weeks
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D23666

4 years agoFix a swap block allocation race.
markj [Mon, 17 Feb 2020 15:10:41 +0000 (15:10 +0000)]
Fix a swap block allocation race.

putpages' allocation of swap blocks is done under the global sw_dev
lock.  Previously it would drop that lock before inserting the allocated
blocks into the object's trie, creating a window in which swap blocks
are allocated but are not visible to swapoff.  This can cause
swp_pager_strategy() to fail and panic the system.

Fix the problem bluntly, by allocating swap blocks under the object
lock.

Reviewed by: jeff, kib
Tested by: pho
MFC after: 2 weeks
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D23665

4 years agoFix object locking races in swapoff(2).
markj [Mon, 17 Feb 2020 15:09:40 +0000 (15:09 +0000)]
Fix object locking races in swapoff(2).

swap_pager_swapoff_object()'s goal is to allocate pages for all valid
swap blocks belonging to the object, for which there is no resident
page.  If the page corresponding to a block is already resident and
valid, the block can simply be discarded.

The existing implementation tries to minimize the number of I/Os used.
For each cluster of swap blocks, it finds maximal runs of valid swap
blocks not resident in memory, and valid resident pages.  During this
processing, the object lock may be dropped in several places: when
calling getpages, or when blocking on a busy page in
vm_page_grab_pages().  While the lock is dropped, another thread may
free swap blocks, causing getpages to page in stale data.

Fix the problem following a suggestion from Jeff: use getpages'
readahead capability to perform clustering rather than doing it
ourselves.  The simplies the code a bit without reintroducing the old
behaviour of performing one I/O per page.

Reviewed by: jeff
Reported by: dhw, gallatin
Tested by: pho
MFC after: 2 weeks
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D23664

4 years agoDon't use uninitialised stack memory if the sysctl variable
tuexen [Mon, 17 Feb 2020 14:54:21 +0000 (14:54 +0000)]
Don't use uninitialised stack memory if the sysctl variable
net.inet.tcp.hostcache.enable is set to 0.
The bug resulted in using possibly a too small MSS value or wrong
initial retransmission timer settings. Possibly the value used
for ssthresh was also wrong.

Submitted by: Richard Scheffenegger
Reviewed by: Cheng Cui, rgrimes@, tuexen@
MFC after: 1 week
Differential Revision: https://reviews.freebsd.org/D23687

4 years agopciconf: List names of all known extended PCIe capabilities.
kib [Mon, 17 Feb 2020 13:31:30 +0000 (13:31 +0000)]
pciconf: List names of all known extended PCIe capabilities.

Some ids are redundand because the list_ecaps() function decodes them
by explicit switch case.  But listing them all makes it easier to not
miss ecaps, while not changing the functionality.

Initial submission by: Dmitry Luhtionov <dmitryluhtionov@gmail.com>
Sponsored by: The FreeBSD Foundation
MFC after: 3 days

4 years agoFix typo.
kib [Mon, 17 Feb 2020 13:26:36 +0000 (13:26 +0000)]
Fix typo.

Sponsored by: The FreeBSD Foundation
MFC after: 3 days

4 years agoPartially revert VNET change and expand VNET structure.
bz [Mon, 17 Feb 2020 11:08:50 +0000 (11:08 +0000)]
Partially revert VNET change and expand VNET structure.

Revert parts of r353274 replacing vnet_state with a shutdown flag.

Not having the state flag for the current SI_SUB_* makes it harder to debug
kernel or module panics related to VNET bringup or teardown.
Not having the state also does not allow us to check for other dependency
levels between components, e.g. for moving interfaces.

Expand the VNET structure with the new boolean flag indicating that we are
doing a shutdown of a given vnet and update the vnet magic cookie for the
change.

Update libkvm to compile with a bool in the kernel struct.

Bump __FreeBSD_version for (external) module builds to more easily detect
the change.

Reviewed by: hselasky
MFC after: 1 week
Differential Revision: https://reviews.freebsd.org/D23097

4 years agoFix kernel panic while trying to read multicast stream.
hselasky [Mon, 17 Feb 2020 09:46:32 +0000 (09:46 +0000)]
Fix kernel panic while trying to read multicast stream.

When VIMAGE is enabled make sure the "m_pkthdr.rcvif" pointer is set
for all mbufs being input by the IGMP/MLD6 code. Else there will be a
NULL-pointer dereference in the netisr code when trying to set the
VNET based on the incoming mbuf. Add an assert to catch this when
queueing mbufs on a netisr to make debugging of similar cases easier.

Found by: Vladislav V. Prodan
PR: 244002
Reviewed by: bz@
MFC after: 1 week
Sponsored by: Mellanox Technologies

4 years agoAdd a simple accessor that returns the bytes of memory consumed by a zone.
jeff [Mon, 17 Feb 2020 01:59:55 +0000 (01:59 +0000)]
Add a simple accessor that returns the bytes of memory consumed by a zone.

4 years agoRefactor _vm_page_busy_sleep to reduce the delta between the various
jeff [Mon, 17 Feb 2020 01:08:00 +0000 (01:08 +0000)]
Refactor _vm_page_busy_sleep to reduce the delta between the various
sleep routines and introduce a variant that supports lockless sleep.

Reviewed by: kib
Differential Revision: https://reviews.freebsd.org/D23612

4 years agoUMA has become more particular about zone types. Use the right allocator
jeff [Mon, 17 Feb 2020 01:06:18 +0000 (01:06 +0000)]
UMA has become more particular about zone types.  Use the right allocator
calls in uma_zwait().

4 years agoAdd rudamentary support for UFS to probe whether a block device supports the
scottl [Sun, 16 Feb 2020 23:10:59 +0000 (23:10 +0000)]
Add rudamentary support for UFS to probe whether a block device supports the
BIO_SPEEDUP command.  Add complimentary support to the CAM periphs that
support it.  This is a redo of r357710.

4 years agorefcount: update comments about fencing when releasing counts after r357989
mjg [Sun, 16 Feb 2020 18:20:09 +0000 (18:20 +0000)]
refcount: update comments about fencing when releasing counts after r357989

Requested by: kib
Reviewed by: kib
Differential Revision: https://reviews.freebsd.org/D23719

4 years agoTemporarily skip flakey test case sys.netinet.fibs_test.udp_dontroute6 in CI
lwhsu [Sun, 16 Feb 2020 17:55:32 +0000 (17:55 +0000)]
Temporarily skip flakey test case sys.netinet.fibs_test.udp_dontroute6 in CI

PR: 244172
Sponsored by: The FreeBSD Foundation

4 years agoTemporarily skip flakey test case sys.netinet6.frag6.frag6_07.frag6_07 in CI
lwhsu [Sun, 16 Feb 2020 17:36:16 +0000 (17:36 +0000)]
Temporarily skip flakey test case sys.netinet6.frag6.frag6_07.frag6_07 in CI

PR: 244170
Sponsored by: The FreeBSD Foundation

4 years agoMark more nodes as CTLFLAG_MPSAFE or CTLFLAG_NEEDGIANT (5 of many)
kaktus [Sun, 16 Feb 2020 17:11:54 +0000 (17:11 +0000)]
Mark more nodes as CTLFLAG_MPSAFE or CTLFLAG_NEEDGIANT (5 of many)

r357614 added CTLFLAG_NEEDGIANT to make it easier to find nodes that are
still not MPSAFE (or already are but aren’t properly marked). Use it in
preparation for a general review of all nodes.
This is non-functional change that adds annotations to SYSCTL_NODE and
SYSCTL_PROC nodes using one of the soon-to-be-required flags.

Reviewed by: imp, kib
Approved by: kib (mentor)
Differential Revision: https://reviews.freebsd.org/D23633

4 years agoTemporarily skip sys.net.if_lagg_test.lacp_linkstate_destroy_stress on i386 CI
lwhsu [Sun, 16 Feb 2020 16:49:29 +0000 (16:49 +0000)]
Temporarily skip sys.net.if_lagg_test.lacp_linkstate_destroy_stress on i386 CI

It panics kernel

PR: 244168
Sponsored by: The FreeBSD Foundation

4 years agoFix build of some modules for some kernel configs.
kib [Sun, 16 Feb 2020 15:43:28 +0000 (15:43 +0000)]
Fix build of some modules for some kernel configs.

Namely, vmm.ko cannot be compiled without 'option SMP', the code uses
IPIs and LAPIC.
Recently systrace was forced over any configs, check for KDTRACE_HOOK
before compiling the dtrace/ modules.

Reviewed by: markj
Discussed with: mjg
Tested by: se (previous version)
Sponsored by: The FreeBSD Foundation (kib)
Differential revision: https://reviews.freebsd.org/D23699

4 years agoTemporarily skip flakey test in sys.capsicum.capsicum-test.main:
lwhsu [Sun, 16 Feb 2020 14:33:55 +0000 (14:33 +0000)]
Temporarily skip flakey test in sys.capsicum.capsicum-test.main:

PipePdfork.WildcardWait

PR: 244165
Sponsored by: The FreeBSD Foundation

4 years agobridge: Basic test case
kp [Sun, 16 Feb 2020 13:16:40 +0000 (13:16 +0000)]
bridge: Basic test case

Very basic bridge test: Set up two jails and test that they can pass IPv4
traffic over the bridge.

Reviewed by: melifaro, philip
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D23697

4 years agoTemporarily skip failing sys.net.if_lagg_test.witness on i386 CI
lwhsu [Sun, 16 Feb 2020 11:16:05 +0000 (11:16 +0000)]
Temporarily skip failing sys.net.if_lagg_test.witness on i386 CI

PR: 244163
Sponsored by: The FreeBSD Foundation

4 years agoRemove trailing whitespace
lwhsu [Sun, 16 Feb 2020 10:59:32 +0000 (10:59 +0000)]
Remove trailing whitespace

Sponsored by: The FreeBSD Foundation

4 years agoRemove trailing whitespace
lwhsu [Sun, 16 Feb 2020 10:57:42 +0000 (10:57 +0000)]
Remove trailing whitespace

Sponsored by: The FreeBSD Foundation

4 years agovfs: fix vlrureclaim ->v_object access
mjg [Sun, 16 Feb 2020 03:33:34 +0000 (03:33 +0000)]
vfs: fix vlrureclaim ->v_object access

The routine was checking for ->v_type == VBAD. Since vgone drops the interlock
early sets this type at the end of the process of dooming a vnode, this opens
a time window where it can clear the pointer while the inerlock-holders is
accessing it.

Another note is that the code was:
   (vp->v_object != NULL &&
   vp->v_object->resident_page_count > trigger)

With the compiler being fully allowed to emit another read to get the pointer,
and in fact it did on the kernel used by pho.

Use atomic_load_ptr and remember the result.

Note that this depends on type-safety of vm_object.

Reported by: pho

4 years agovfs: check early for VCHR in vput_final to short-circuit in the common case
mjg [Sun, 16 Feb 2020 03:16:28 +0000 (03:16 +0000)]
vfs: check early for VCHR in vput_final to short-circuit in the common case

Otherwise the compiler inlines v_decr_devcount which keps getting jumped over
in the common case of not dealing with a device.

4 years agorefcount: add missing release fence to refcount_release_if_gt
mjg [Sun, 16 Feb 2020 03:14:55 +0000 (03:14 +0000)]
refcount: add missing release fence to refcount_release_if_gt

The CPU succeeding in releasing the not last reference can still have pending
stores to the object protected by the affected counter. This opens a time
window where another CPU can release the last reference and free the object,
resulting in use-after-free. On top of that this prevents the compiler from
generating more accesses to the object regardless of how atomic_fcmpset_rel_int
is implemented (of course as long as it provides the release semantic).

Reviewed by: markj

4 years agoSlightly restructure uma_zalloc* to generate better code from clang and
jeff [Sun, 16 Feb 2020 01:07:19 +0000 (01:07 +0000)]
Slightly restructure uma_zalloc* to generate better code from clang and
reduce duplication among zalloc functions.

Reviewed by: markj
Discussed with: mjg
Differential Revision: https://reviews.freebsd.org/D23672

4 years agoAdd zfree to zero allocation before free
mmacy [Sun, 16 Feb 2020 00:12:53 +0000 (00:12 +0000)]
Add zfree to zero allocation before free

Key and cookie management typically wants to
avoid information leaks by explicitly zeroing
before free. This routine simplifies that by
permitting consumers to do so without carrying
the size around.

Reviewed by: jeff@, jhb@
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC (Netgate)
Differential Revision: https://reviews.freebsd.org/D22790

4 years agoAdd chacha20poly1305 support to crypto build
mmacy [Sun, 16 Feb 2020 00:03:09 +0000 (00:03 +0000)]
Add chacha20poly1305 support to crypto build

This is a dependency for in-kernel wireguard.

Reviewed by: cem@
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC (Netgate)
Differential Revision: https://reviews.freebsd.org/D23689

4 years agoAdd pthread_peekjoin_np(3).
kib [Sat, 15 Feb 2020 23:25:39 +0000 (23:25 +0000)]
Add pthread_peekjoin_np(3).

The function allows to peek at the thread exit status and even see
return value, without joining (and thus finally destroying) the target
thread.

Reviewed by: markj
Sponsored by: The FreeBSD Foundation (kib)
MFC after: 2 weeks
Differential revision: https://reviews.freebsd.org/D23676

4 years agosem_remove(): fix the loop that compacts sem array on semaphores removal.
kib [Sat, 15 Feb 2020 23:19:23 +0000 (23:19 +0000)]
sem_remove(): fix the loop that compacts sem array on semaphores removal.

As written now, it copies random kernel memory from beyond the bounds
of the array.

Reported and tested by: pho
Reviewed by: markj
Sponsored by: The FreeBSD Foundation (kib)
MFC after: 1 week
Differential revision: https://reviews.freebsd.org/D23694

4 years agosem_remove(): add some asserts.
kib [Sat, 15 Feb 2020 23:18:02 +0000 (23:18 +0000)]
sem_remove(): add some asserts.

Assert that sema[idx] allocation from sem[] is sane.
Also assert that sem_mtx is owned, it protects the SEM_ALLOC flag.

Reviewed by: markj
Tested by: pho
Sponsored by: The FreeBSD Foundation (kib)
MFC after: 1 week
Differential revision: https://reviews.freebsd.org/D23694

4 years agoUse designated initializers for seminfo.
kib [Sat, 15 Feb 2020 23:15:42 +0000 (23:15 +0000)]
Use designated initializers for seminfo.

Reviewed by: markj
Tested by: pho
Sponsored by: The FreeBSD Foundation (kib)
MFC after: 1 week
Differential revision: https://reviews.freebsd.org/D23694

4 years agoufs: use faster lockgmr entry points in ffs_lock
mjg [Sat, 15 Feb 2020 21:48:48 +0000 (21:48 +0000)]
ufs: use faster lockgmr entry points in ffs_lock

4 years agocommitters-ports.dot: add myself as a ports committer
kevans [Sat, 15 Feb 2020 21:21:13 +0000 (21:21 +0000)]
committers-ports.dot: add myself as a ports committer

4 years agofetch(3): don't leak sockshost on failure
kevans [Sat, 15 Feb 2020 19:47:49 +0000 (19:47 +0000)]
fetch(3): don't leak sockshost on failure

fetch_socks5_getenv will allocate memory for the host (or set it to NULL) in
all cases through the function; the caller is responsible for freeing it if
we end up allocating.

While I'm here, I've eliminated a label that just jumps to the next line...

4 years agofetch(3): fix regression in IPv6:port spec from r357977
kevans [Sat, 15 Feb 2020 19:39:50 +0000 (19:39 +0000)]
fetch(3): fix regression in IPv6:port spec from r357977

In case the port was specified, we never actually populated *host. Do so
now.

Pointy hat: kevans

4 years agofetch(3): move bits of fetch_socks5_getenv around
kevans [Sat, 15 Feb 2020 19:31:40 +0000 (19:31 +0000)]
fetch(3): move bits of fetch_socks5_getenv around

This commit separates out port parsing and validation from grabbing the host
from the env var. The only related bit really is that we need to be more
specific with the delimiter in the IPv6 case.

4 years agoMerge r357970 from the clang1000-import branch:
dim [Sat, 15 Feb 2020 19:15:24 +0000 (19:15 +0000)]
Merge r357970 from the clang1000-import branch:

Fix the following -Werror warning from clang 10.0.0 in hptmv(4):

sys/dev/hptmv/ioctl.c:240:4: error: misleading indentation; statement is not part of the previous 'if' [-Werror,-Wmisleading-indentation]
                        _vbus_p=pArray->pVBus;
                        ^
sys/dev/hptmv/ioctl.c:237:10: note: previous statement is here
                if(!mIsArray(pArray))
                ^

This is because the return statement after the if statement was not
indented.  (Note that this file has been idented assuming 4-space tabs.)

MFC after: 3 days

4 years agorandom(6): Re-add undocumented support for floating point denominators
cem [Sat, 15 Feb 2020 19:13:37 +0000 (19:13 +0000)]
random(6): Re-add undocumented support for floating point denominators

And document it in the manual page.

PR: 244139
Submitted by: Keith White <kwhite AT site.uottawa.ca> (earlier version)

4 years agoMark more nodes as CTLFLAG_MPSAFE or CTLFLAG_NEEDGIANT (4 of many)
kaktus [Sat, 15 Feb 2020 18:57:49 +0000 (18:57 +0000)]
Mark more nodes as CTLFLAG_MPSAFE or CTLFLAG_NEEDGIANT (4 of many)

r357614 added CTLFLAG_NEEDGIANT to make it easier to find nodes that are
still not MPSAFE (or already are but aren’t properly marked). Use it in
preparation for a general review of all nodes.
This is non-functional change that adds annotations to SYSCTL_NODE and
SYSCTL_PROC nodes using one of the soon-to-be-required flags.

Reviewed by: kib
Approved by: kib (mentor)
Differential Revision: https://reviews.freebsd.org/D23625
X-Generally looks fine: jhb

4 years agoMark more nodes as CTLFLAG_MPSAFE or CTLFLAG_NEEDGIANT (2 of many)
kaktus [Sat, 15 Feb 2020 18:54:59 +0000 (18:54 +0000)]
Mark more nodes as CTLFLAG_MPSAFE or CTLFLAG_NEEDGIANT (2 of many)

r357614 added CTLFLAG_NEEDGIANT to make it easier to find nodes that are
still not MPSAFE (or already are but aren’t properly marked). Use it in
preparation for a general review of all nodes.
This is non-functional change that adds annotations to SYSCTL_NODE and
SYSCTL_PROC nodes using one of the soon-to-be-required flags.

Reviewed by: hselasky, kib, zeising
Approved by: kib (mentor)
Differential Revision: https://reviews.freebsd.org/D23631

4 years agoMark more nodes as CTLFLAG_MPSAFE or CTLFLAG_NEEDGIANT (2 of many)
kaktus [Sat, 15 Feb 2020 18:52:12 +0000 (18:52 +0000)]
Mark more nodes as CTLFLAG_MPSAFE or CTLFLAG_NEEDGIANT (2 of many)

r357614 added CTLFLAG_NEEDGIANT to make it easier to find nodes that are
still not MPSAFE (or already are but aren’t properly marked). Use it in
preparation for a general review of all nodes.
This is non-functional change that adds annotations to SYSCTL_NODE and
SYSCTL_PROC nodes using one of the soon-to-be-required flags.

Reviewed by: hselasky, kib
Approved by: kib (mentor)
Differential Revision: https://reviews.freebsd.org/D23632

4 years agoMark more nodes as CTLFLAG_MPSAFE or CTLFLAG_NEEDGIANT (1 of many)
kaktus [Sat, 15 Feb 2020 18:48:38 +0000 (18:48 +0000)]
Mark more nodes as CTLFLAG_MPSAFE or CTLFLAG_NEEDGIANT (1 of many)

r357614 added CTLFLAG_NEEDGIANT to make it easier to find nodes that are
still not MPSAFE (or already are but aren’t properly marked). Use it in
preparation for a general review of all nodes.
This is non-functional change that adds annotations to SYSCTL_NODE and
SYSCTL_PROC nodes using one of the soon-to-be-required flags.

Reviewed by: kib, trasz
Approved by: kib (mentor)
Differential Revision: https://reviews.freebsd.org/D23640

4 years agoThe KASSERT is too strict: revert r357897
imp [Sat, 15 Feb 2020 18:14:23 +0000 (18:14 +0000)]
The KASSERT is too strict: revert r357897

It's valid for a periph to be removed with outstanding transactions on the
device. In CAM, multiple periphs attach to a single device. There's no interlock
to prevent one of these going away while other periphs have outstanding CCBs and
it's not an error either. Remove this overly agressive KASSERT to prevent
false-positive panics when devices depart.

4 years agofetch(3): Add SOCKS5 support
kevans [Sat, 15 Feb 2020 18:03:16 +0000 (18:03 +0000)]
fetch(3): Add SOCKS5 support

This change adds SOCKS5 support to the library fetch(3) and updates the man
page.

Details: Within the fetch_connect() function, fetch(3) checks if the
SOCKS5_PROXY environment variable is set. If so, it connects to this host
rather than the end-host. It then initializes the SOCKS5 connection in
accordance with RFC 1928 and returns the resulting conn_t (file descriptor)
for usage by the regular FTP/HTTP handlers.

Design Decision: This change defaults all DNS resolutions through the proxy
by sending all IPs as hostnames. Going forward, another feature might be to
create another environmental variable to toggle resolutions through the
proxy or not..

One may set the SOCKS5_PROXY environment variable in any of the formats:

SOCKS5_PROXY=proxy.example.com
SOCKS5_PROXY=proxy.example.com:1080
SOCKS5_PROXY=192.0.2.0
SOCKS5_PROXY=198.51.100.0:1080
SOCKS5_PROXY=[2001:db8::1]
SOCKS5_PROXY=[2001:db8::2]:1080

Then perform a request with fetch(1).

(note by kevans)
I've since been informed that Void Linux/xbps has a fork of libfetch that
also implements SOCKS5. I may compare/contrast the two in the mid-to-near
future.

Submitted by: Farhan Khan <farhan farhan codes>
Differential Revision: https://reviews.freebsd.org/D18908

4 years agoMake ping6(1) return code consistent with the man page.
melifaro [Sat, 15 Feb 2020 15:39:53 +0000 (15:39 +0000)]
Make ping6(1) return code consistent with the man page.
 When every sendto() call originated by ping6(1) fails, current code always
 returns 2 ("transmission was successful but no responses were received")
 which is incorrect. Return EX_OSERR instead as in many cases it indicates
 some kernel-level problems.

MFC after: 3 weeks

4 years agovfs: make write suspension mandatory
mjg [Sat, 15 Feb 2020 13:00:39 +0000 (13:00 +0000)]
vfs: make write suspension mandatory

At the time opt-in was introduced adding yourself as a writer was esrializing
across the mount point. Nowadays it is fully per-cpu, the only impact being
a small single-threaded hit on top of what's there right now.

Vast majority of the overhead stems from the call to VOP_GETWRITEMOUNT which
has is done regardless.

Should someone want to microoptimize this single-threaded they can coalesce
looking the mount up with adding a write to it.

4 years agoMFV: r357927
jkim [Sat, 15 Feb 2020 03:47:25 +0000 (03:47 +0000)]
MFV: r357927

Merge ACPICA 20200214.

4 years agocapsicum: use new helpers
mjg [Sat, 15 Feb 2020 01:30:27 +0000 (01:30 +0000)]
capsicum: use new helpers

4 years agokqueue: use new capsicum helpers
mjg [Sat, 15 Feb 2020 01:30:13 +0000 (01:30 +0000)]
kqueue: use new capsicum helpers

4 years agocloudabi: use new capsicum helpers
mjg [Sat, 15 Feb 2020 01:29:58 +0000 (01:29 +0000)]
cloudabi: use new capsicum helpers

4 years agosctp: use new capsicum helpers
mjg [Sat, 15 Feb 2020 01:29:40 +0000 (01:29 +0000)]
sctp: use new capsicum helpers

4 years agovm: use new capsicum helpers
mjg [Sat, 15 Feb 2020 01:29:07 +0000 (01:29 +0000)]
vm: use new capsicum helpers

4 years agofd: use new capsicum helpers
mjg [Sat, 15 Feb 2020 01:28:55 +0000 (01:28 +0000)]
fd: use new capsicum helpers

4 years agovfs: use new capsicum helpers
mjg [Sat, 15 Feb 2020 01:28:42 +0000 (01:28 +0000)]
vfs: use new capsicum helpers

4 years agocapsicum: add cap_rights_init_zero, cap_rights_init_one, cap_rights_set_one
mjg [Sat, 15 Feb 2020 01:28:06 +0000 (01:28 +0000)]
capsicum: add cap_rights_init_zero, cap_rights_init_one, cap_rights_set_one

... which allow the compiler to generate relevant code in place without
resorting to calling to a routine at runtime.

4 years agoConsolidate read code for timecounters and fix possible overflow in
kib [Fri, 14 Feb 2020 23:27:45 +0000 (23:27 +0000)]
Consolidate read code for timecounters and fix possible overflow in
bintime()/binuptime().

The algorithm to read the consistent snapshot of current timehand is
repeated in each accessor, including the details proper rollup
detection and synchronization with the writer.  In fact there are only
two different kind of readers: one for bintime()/binuptime() which has
to do the in-place calculation, and another kind which fetches some
member from struct timehand.

Extract the logic into type-checked macros, GETTHBINTIME() for bintime
calculation, and GETTHMEMBER() for safe read of a structure' member.
This way, the synchronization is only written in bintime_off() and
getthmember().

In bintime_off(), use overflow-safe calculation of th_scale *
delta(timecounter).  In tc_windup, pre-calculate the min delta value
which overflows and require slow algorithm, into the new timehands
th_large_delta member.

This part with overflow fix was written by Bruce Evans.

Reported by: Mark Millard <marklmi@yahoo.com> (the overflow issue)
Tested by: pho
Discussed with: emaste
Sponsored by: The FreeBSD Foundation (kib)
MFC after: 3 weeks

4 years agovfs: remove no longer needed atomic_load_ptr casts
mjg [Fri, 14 Feb 2020 23:18:32 +0000 (23:18 +0000)]
vfs: remove no longer needed atomic_load_ptr casts

4 years agofd: remove no longer needed atomic_load_ptr casts
mjg [Fri, 14 Feb 2020 23:18:22 +0000 (23:18 +0000)]
fd: remove no longer needed atomic_load_ptr casts

4 years agokcov: remove no longer needed atomic_load_ptr casts
mjg [Fri, 14 Feb 2020 23:18:03 +0000 (23:18 +0000)]
kcov: remove no longer needed atomic_load_ptr casts

4 years agoi386: remove no longer needed atomic_load_ptr casts
mjg [Fri, 14 Feb 2020 23:17:37 +0000 (23:17 +0000)]
i386: remove no longer needed atomic_load_ptr casts

4 years agoarm64: remove no longer needed atomic_load_ptr casts
mjg [Fri, 14 Feb 2020 23:17:18 +0000 (23:17 +0000)]
arm64: remove no longer needed atomic_load_ptr casts

4 years agoamd64: remove no longer needed atomic_load_ptr casts
mjg [Fri, 14 Feb 2020 23:17:03 +0000 (23:17 +0000)]
amd64: remove no longer needed atomic_load_ptr casts

4 years agovm: remove no longer needed atomic_load_ptr casts
mjg [Fri, 14 Feb 2020 23:16:29 +0000 (23:16 +0000)]
vm: remove no longer needed atomic_load_ptr casts

4 years agoMake atomic_load_ptr type-aware
mjg [Fri, 14 Feb 2020 23:15:41 +0000 (23:15 +0000)]
Make atomic_load_ptr type-aware

Returned value has type based on the argument, meaning consumers no longer
have to cast in the commmon case.

This commit keeps the kernel compilable without patching the rest.

4 years agoUpdate version in openssh FREEBSD-vendor metadata
emaste [Fri, 14 Feb 2020 22:32:33 +0000 (22:32 +0000)]
Update version in openssh FREEBSD-vendor metadata

It appears that FREEBSD-vendor is an idea that never really took off
and we should probably just remove it, but until then we might as well
record the correct version.

4 years agomips: fix kernel build after r357804
kevans [Fri, 14 Feb 2020 20:25:04 +0000 (20:25 +0000)]
mips: fix kernel build after r357804

Drop the padding down the size of a single uintptr_t to account for
pc_zpcpu_offset

4 years agoUpdate OpenSSH upgrade instructions to use https, not ftp
emaste [Fri, 14 Feb 2020 19:33:50 +0000 (19:33 +0000)]
Update OpenSSH upgrade instructions to use https, not ftp

ftp://ftp.openbsd.org/ does not work.

4 years agoRemove /usr/include/ssp from BSD.include.dist after r356356
dim [Fri, 14 Feb 2020 19:31:24 +0000 (19:31 +0000)]
Remove /usr/include/ssp from BSD.include.dist after r356356

This avoids having to delete it every time with "make delete-old".

PR: 242950
MFC after: 2 weeks
X-MFC-With: r356356

4 years agoUpgrade to OpenSSH 7.9p1.
emaste [Fri, 14 Feb 2020 19:06:59 +0000 (19:06 +0000)]
Upgrade to OpenSSH 7.9p1.

MFC after: 2 months
Sponsored by: The FreeBSD Foundation

4 years agosshd: add upgrade process note about TCP wrappers
emaste [Fri, 14 Feb 2020 18:59:50 +0000 (18:59 +0000)]
sshd: add upgrade process note about TCP wrappers

We need to add user-facing deprecation notices for TCP wrappers; start
with a note in the upgrade process docmentation.

Sponsored by: The FreeBSD Foundation

4 years agodtc: re-apply r353961, r354115
kevans [Fri, 14 Feb 2020 18:50:03 +0000 (18:50 +0000)]
dtc: re-apply r353961, r354115

I missed in final review of r357923's diff that these ones hadn't yet been
sent upstream and inadvertently reverted them. =-( Re-apply now.

4 years agoPull in latest fixes from dtc, up to 0060471
kevans [Fri, 14 Feb 2020 18:46:34 +0000 (18:46 +0000)]
Pull in latest fixes from dtc, up to 0060471

This includes a small battery of /memreserve/ fixes to make sure dtc is
properly writing these regions into the output file and reading them back
out.

As of this update, dtc will now also assume common defaults for -I/-O if
only one is specified; namely, dts for one implies dtb for the other and
vice versa (Requested by: jhibbits, preserves GPL dtc behavior too).

MFC after: 1 week

4 years agoopenssh: add a note about libwrap in config.h
emaste [Fri, 14 Feb 2020 17:05:35 +0000 (17:05 +0000)]
openssh: add a note about libwrap in config.h

LIBWRAP is defined by the Makefile based on MK_TCP_WRAPPERS and should
not be defined in config.h.

PR: 210141
Sponsored by: The FreeBSD Foundation

4 years agosysctl(9): properly use xor in ENFORCE_FLAGS macro
kaktus [Fri, 14 Feb 2020 16:56:59 +0000 (16:56 +0000)]
sysctl(9): properly use xor in ENFORCE_FLAGS macro

Assert on not specifying any of the (soon to be) required flags as well
 as specifying both of them.

Pointed out by: cem, hselasky
Reviewed by: hselasky, kib
Approved by: kib (mentor)
Differential Revision: https://reviews.freebsd.org/D23678

4 years agoAdd support for Hygon NTB PCI device in ntb_hw_amd driver.
mav [Fri, 14 Feb 2020 15:04:56 +0000 (15:04 +0000)]
Add support for Hygon NTB PCI device in ntb_hw_amd driver.

Submitted by: Pu Wen <puwen@hygon.cn>
MFC after: 1 week
Differential Revision: https://reviews.freebsd.org/D23565

4 years agoAdd Hygon PCI ID and description for AHCI SATA controller.
mav [Fri, 14 Feb 2020 14:55:40 +0000 (14:55 +0000)]
Add Hygon PCI ID and description for AHCI SATA controller.

Submitted by: Pu Wen <puwen@hygon.cn>
MFC after: 1 week
Differential Revision: https://reviews.freebsd.org/D23556

4 years agocommitters-ports: add koobs@ information, somewhat belatedly
kevans [Fri, 14 Feb 2020 14:03:44 +0000 (14:03 +0000)]
committers-ports: add koobs@ information, somewhat belatedly

4 years agoamd64: only check for error != 0 in the inlined part of l1d flush check
mjg [Fri, 14 Feb 2020 13:14:19 +0000 (13:14 +0000)]
amd64: only check for error != 0 in the inlined part of l1d flush check

this replaces the following near the syscall exit:
cmp    $0x39,%rax
ja     0xffffffff8108f82c
movabs $0x200001800060005,%rcx
bt     %rax,%rcx
jae    0xffffffff8108f82c

with:
test   %edi,%edi
jne    0xffffffff8091a49c

4 years agoMerge audit and systrace checks
mjg [Fri, 14 Feb 2020 13:09:41 +0000 (13:09 +0000)]
Merge audit and systrace checks

This further shortens the syscall routine by not having to re-check after
the system call.

4 years agoAnnotate branches in the syscall path
mjg [Fri, 14 Feb 2020 13:08:46 +0000 (13:08 +0000)]
Annotate branches in the syscall path

This in particular significantly shortens amd64_syscall, which otherwise
keeps jumping forward over 2KB of code in total.

Note some of these branches should be either eliminated altogether or
coalesced.

4 years agor357895: fix typo in the relocation name for i386 IRELATIVE.
kib [Fri, 14 Feb 2020 12:59:27 +0000 (12:59 +0000)]
r357895: fix typo in the relocation name for i386 IRELATIVE.

Reported by: antoine
Sponsored by: The FreeBSD Foundation
MFC after: 6 days