summaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
* Fix OpenSSH Denial of Service vulnerability. [SA-17:06]releng/11.1delphij2017-08-105-1/+26
| | | | | | | | Fix VNET kernel panic with asynchronous I/O. [EN-17:07] Fix pf(4) housekeeping thread causes kernel panic. [EN-17:08] Approved by: so
* - Switch releng/11.1 to -RELEASE.gjb2017-07-203-2/+5
| | | | | | | | - Add the anticipated 11.1-RELEASE date to UPDATING. - Set a static __FreeBSD_version. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation
* Document r307265, vfs.zfs.compressed_arc_enabled.gjb2017-07-161-0/+7
| | | | | | Proxied by: allanjude, emaste Approved by: re (implicit) Sponsored by: The FreeBSD Foundation
* Rename releng/11.1 to RC3 as part of the 11.1-RELEASE cycle.gjb2017-07-132-2/+2
| | | | | | | Use the 'release_1' package set to populate the dvd1.iso packages. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation
* Document r320954, deprecation of digi(4), ie(4), mcd(4), scd(4),gjb2017-07-131-0/+7
| | | | | | | si(4), spic(4), wl(4), sicontrol(8), and wlconfig(8). Approved by: re (implicit) Sponsored by: The FreeBSD Foundation
* MFS11 320921:jhb2017-07-1316-9/+68
| | | | | | Add deprecation notices for various device drivers removed in 12.0. Approved by: re (kib)
* Document pkg(8) version 1.10.1.gjb2017-07-131-41/+2
| | | | | | | | Prune empty sections. Remove a stale comment. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation
* Document SA-17:05.heimdal.gjb2017-07-131-0/+8
| | | | | Approved by: re (implicit) Sponsored by: The FreeBSD Foundation
* MF11 r320947; MFC r320876:hselasky2017-07-131-1/+7
| | | | | | | | | Make sure the mlx4en RX DMA ring gets stamped with software ownership in order to prevent the flow of QP to error in the firmware once UPDATE_QP is called. Approved by: re (marius) Sponsored by: Mellanox Technologies
* MFS 320891grehan2017-07-133-4/+4
| | | | | | | | | | MFC r317542, r317543, r317543 317542 comment fix 317543 set rfb default port 317543 listen on localhost by default for rfb Approved by: re (kib)
* MFS 320866grehan2017-07-1313-2/+321
| | | | | | | | | | | | MFC 313727, 317483 In addition, replace the missing caph routines with small helper functions (bhyverun.c) or an open-coded replacement (uart_emul.c) 313727 Capsicumize bhyve 317483 Allow CAP_MMAP_RW on memfd for PCI passthru Approved by: re (kib)
* MFS r320855grehan2017-07-131-8/+19
| | | | | | ps2 mouse fixes, found by plan9/9front. Approved by: re (kib)
* MF11: r320898; MFC: r320577, r320620marius2017-07-121-2/+14
| | | | | | | | | Retry up to 2 ms to enable bus power as at least with some Intel SDHCI/eMMC controllers the first attempt after a D3 to D0 transition, i. e. when the firmware has put the devices into D3 state before, can fail. Approved by: re (gjb)
* MFS r320907: MFC r320906: MFV r320905: Import upstream fix fordelphij2017-07-121-2/+2
| | | | | | | | | | | | | | | CVE-2017-11103. In _krb5_extract_ticket() the KDC-REP service name must be obtained from encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unecrypted version provides an opportunity for successful server impersonation and other attacks. Submitted by: hrs Obtained from: Heimdal Security: FreeBSD-SA-17:05.heimdal Security: CVE-2017-11103 Approved by: re (kib)
* MFS r320889:kib2017-07-121-0/+1
| | | | | | Restore layout of struct vm_map_entry. Approved by: re (delphij)
* MFC r320843 MFS r320903:kib2017-07-121-1/+1
| | | | | | Fix loop termination in vm_map_find_min(). Approved by: re (delphij)
* MFC r320801 MFS r320887:kib2017-07-111-3/+5
| | | | | | Simplify language. Approved by: re (delphij)
* Document r320874, gdb(1) and kgdb(1) deprecation.gjb2017-07-101-0/+6
| | | | | Approved by: re (implicit) Sponsored by: The FreeBSD Foundation
* MFS11 320824: Add deprecation notices for gdb and kgdb.jhb2017-07-102-1/+16
| | | | | | | | | | Even though gdb and kgdb may not be removed for 12.0 on some architectures, the notice is unconditional as these tools will likely be removed at some point in the future when adequate replacements are available (gdb in ports or lldb in base). Approved by: re (gjb) Relnotes: yes
* MFS11 r320870:gjb2017-07-101-0/+1
| | | | | | | | MFC r320785: Connect ena(4) to the build. Approved by: re (kib) Sponsored by: The FreeBSD Foundation
* MFC r320619 MFS r320863:kib2017-07-101-9/+8
| | | | | | Resolve confusion between different error code spaces. Approved by: re (delphij)
* MFC r320570 MFS r320822:kib2017-07-091-4/+5
| | | | | | Correct signatures of several pthreads stubs. Approved by: re (gjb)
* MFS r320799: MFC r320665:delphij2017-07-081-3/+3
| | | | | | | In open_binary_fd: when using buffer size for strl* and snprintf, always use >= instead of > to avoid truncation. Approved by: re (kib)
* Document r320760, ena(4) addition.gjb2017-07-073-0/+9
| | | | | | | | Add the ena(4) manual page. Add Amazon.com to the sponsors.ent file. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation
* Rename releng/11.1 to RC2 as part of the 11.1-RELEASE cycle.gjb2017-07-071-1/+1
| | | | | Approved by: re (implicit) Sponsored by: The FreeBSD Foundation
* MFS11 r320753:gjb2017-07-071-1/+1
| | | | | | | | | MFC r320748: Allow passing NOPKG= to make(1) to enable the pkg-stage target from getting executed when NOPKG is defined but empty. Approved by: re (kib) Sponsored by: The FreeBSD Foundation
* Add MAP_GUARD and use it for stack grow area protection.kib2017-07-079-250/+311
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Bump __FreeBSD_version. This is an MFS of stable/11 r320666. MFC r320317: Implement address space guards. MFC r320338: Remove stale part of the comment. MFC r320339: Correctly handle small MAP_STACK requests. MFC r320344: For now, allow mprotect(2) over the guards to succeed regardless of the requested protection. MFC r320430: Treat the addr argument for mmap(2) request without MAP_FIXED flag as a hint. MFC r320560 (by alc): Modify vm_map_growstack() to protect itself from the possibility of the gap entry in the vm map being smaller than the sysctl-derived stack guard size. Approved by: re (delphij)
* MF11 r320731,320749,320759: Add Amazon Elastic Network Adapter drivercperciva2017-07-0719-1/+12317
| | | | | | | | | and turn it on in EC2 AMI builds Approved by: re (gjb) Relnotes: FreeBSD now supports "next generation" Enhanced Networking in the Amazon EC2 cloud Sponsored by: Amazon.com Inc. (original work)
* MF11 r320685: Update to ELF Tool Chain snapshot at r3561emaste2017-07-065-192/+620
| | | | | | | | | | | | | | | | | | | | | | | This update is primarily bug fixes in C++ symbol demangling, including: - rvalue reference - builtin type auto and decltype(auto) - revamped support for function return types - formatting fixes - omit void when its the only param - ref-qualifiers and others in function types - type qualifiers in pointer-to-member function types - incorrect handling regarding CV-qualifiers in function types - ref-qualifier found in nested-name - properly handle <name> ::= <substitute><template-args> - make sure that nested function name is not a substitute candidate - correctly handle expression in template args - skip unknown substitution abbreviations Also r320663 libelftc: bump version, tracking import in r320343 Approved by: re (gjb) Sponsored by: The FreeBSD Foundation
* MFS r320744: MFC r320690:markj2017-07-061-1/+1
| | | | | | | Defer ACPI taskqueue creation to SI_SUB_KICK_SCHEDULER. PR: 220277 Approved by: re (gjb)
* Update the pkg(8) configuration for the default installation andgjb2017-07-062-2/+2
| | | | | | | | | | | the dvd1.iso to use the quarterly set, now that the new quarterly branch exists and packages have built. This commit was deferred when branching releng/11.1, since the 2017Q3 branch did not exist yet. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation
* MFS11 r320697:gjb2017-07-061-19/+19
| | | | | | | | | | | | | MFC r320599: Fix Vagrant image upload after recent API changes. - Update ATLAS_UPLOAD_URL to avoid various regular expressions from failing to match due to redirections. - Use ATLAS_UPLOAD_URL throughout the script. - Adjust several regular expression patterns. Approved by: re (kib) Sponsored by: The FreeBSD Foundation
* MFS r320605, r320610: MFC r303052, r309017 (by alc):markj2017-07-059-37/+28
| | | | | | | Omit v_cache_count when computing the number of free pages, since its value is always 0. Approved by: re (gjb, kib)
* MFS r320684: MFC r320451 (by cem):markj2017-07-051-5/+7
| | | | | | Complete support for the IO_APPEND flag in fuse. Approved by: re (gjb)
* Document r320654, rcmd deprecation.gjb2017-07-051-0/+6
| | | | | Approved by: re (implicit) Sponsored by: The FreeBSD Foundation
* Merge r320645 from stable/11 into releng/11.1:allanjude2017-07-048-8/+80
| | | | | | | Add deprecation notices for all rcmd tools Approved by: re (gjb) Relnotes: yes
* MFC r320422:kib2017-07-041-1/+1
| | | | | | Do not ignore an error from vm_mmap_object(). Approved by: re (delphij)
* Merge r320602 from stable/11 into releng/11.1:ken2017-07-031-2/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | ------------------------------------------------------------------------ r320602 | ken | 2017-07-03 09:34:21 -0600 (Mon, 03 Jul 2017) | 45 lines MFC r320421: ------------------------------------------------------------------------ r320421 | ken | 2017-06-27 13:26:02 -0600 (Tue, 27 Jun 2017) | 37 lines Fix a panic in camperiphfree(). If a peripheral driver (e.g. da, sa, cd) is added or removed from the peripheral driver list while an unrelated peripheral driver instance (e.g. da0, sa5, cd2) is going away and is inside camperiphfree(), we could dereference an invalid pointer. When peripheral drivers are added or removed (see periphdriver_register() and periphdriver_unregister()), the peripheral driver array is resized and existing entries are moved. Although we hold the topology lock while we traverse the peripheral driver list, we retain a pointer to the location of the peripheral driver pointer and then drop the topology lock. So we are still vulnerable to the list getting moved around while the lock is dropped. To solve the problem, cache a copy of the peripheral driver pointer. If its storage location in the list changes while we have the lock dropped, it won't have any effect. This doesn't solve the issue that peripheral drivers ("da", "cd", as opposed to individual instances like "da0", "cd0") are not generally part of a reference counting scheme to guard against deregistering them while there are instances active. The caller (generally the person unloading a module) has to be aware of active drivers and not unload something that is in use. sys/cam/cam_periph.c: In camperiphfree(), cache a pointer to the peripheral driver instance to avoid holding a pointer to an invalid memory location in the event that the peripheral driver list changes while we have the topology lock dropped. PR: kern/219701 Submitted by: avg Sponsored by: Spectra Logic ------------------------------------------------------------------------ ------------------------------------------------------------------------ Approved by: re (gjb)
* Merge r320600 from stable/11 into releng/11.1:ken2017-07-031-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | ------------------------------------------------------------------------ r320600 | ken | 2017-07-03 09:10:16 -0600 (Mon, 03 Jul 2017) | 30 lines MFC r320420: ------------------------------------------------------------------------ r320420 | ken | 2017-06-27 11:55:25 -0600 (Tue, 27 Jun 2017) | 25 lines In scsi_zbc_in(), fill in the length in the ZBC IN CDB. Without the allocation length set, the target will either reject the command or complete it without transferring any data. This fixes the REPORT ZONES command for SCSI ZBC protocol devices, as well as ATA ZAC protocol devices that are behind a SCSI to ATA translation layer. (LSI/Broadcom's 12Gb SAS adapters translate ZBC commands to ZAC commands.) Those are Host Aware and Host Managed SMR drives. This will fix REPORT ZONE commands sent to the da(4) driver via the GEOM bio interface and zonectl, and REPORT ZONE commands sent from camcontrol(8). Note that in the case of camcontrol(8), we currently only send SCSI ZBC commands to native SCSI protocol devices, not ATA devices behind a SAT layer. sys/cam/scsi/scsi_da.c: Fill in the length field in scsi_zbc_in(). Sponsored by: Spectra Logic ------------------------------------------------------------------------ ------------------------------------------------------------------------ Approved by: re (gjb)
* MFS11 r320596:gjb2017-07-031-1/+1
| | | | | | | | | | MFC r320488: Correct the branch naming convention in param.h. While here, consistently use upper-case 'X' to represent the version number. Approved by: re (kib, marius) Sponsored by: The FreeBSD Foundation
* Merge from stable/11 r320593:ae2017-07-033-3/+3
| | | | | | | | Fix IPv6 extension header parsing. The length field doesn't include the first 8 octets. Obtained from: Yandex LLC Approved by: re (marius)
* MFS r320586: MFC r320093: Check return value of seteuid() and bail outdelphij2017-07-031-2/+8
| | | | | | if we fail. Approved by: re (kib)
* MFS r320566: MFC r320390:araujo2017-07-031-1/+2
| | | | | | | | | | | With r318394 seems it breaks gpart(8) in some embedded systems such like PCEngines, RPI1-B, Alix and APU2 boards as well as NanoBSD with the following message: vnode_pager_generic_getpages_done: I/O read error 5 Seems the breakage was because it was missed to include acr in glabel update. Approved by: re (delphij)
* MFS r320581: MFC r320494: Fix double free by reverting r300385 anddelphij2017-07-031-3/+1
| | | | | | r300624 which was false positive reported by cppcheck. Approved by: re (kib)
* MFC r320316:kib2017-07-011-4/+4
| | | | | | Do not try to unmark MAP_ENTRY_IN_TRANSITION marked by other thread. Approved by: re (gjb)
* release.ent:gjb2017-06-304-153/+23
| | | | | | | | | | | | | | | | | - Update versions, and switch from 'snapshot' to 'release'. errata/article.xml: - Prune stale entries from 11.0-RELEASE. - Bump copyright date. relnotes/article.xml: - Remove several empty sections. readme/article.xml: - Fix a malformed URL. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation
* - Copy stable/11@r320475 to releng/11.1 as part of the 11.1-RELEASEgjb2017-06-292-2/+2
| | | | | | | | | | cycle. - Prune svn:mergeinfo from the new branch. - Bump __FreeBSD_version. - Rename releng/11.1 to RC1. Approved by: re (implicit) Sponsored by: The FreeBSD Foundation
* MFC r320372:markj2017-06-291-1/+2
| | | | | | Fix a memory leak in ses_get_elm_devnames(). Approved by: re (gjb)
* MFC r320353: linux_getdents, linux_readdir: fix mismatch between malloc and ↵avg2017-06-291-4/+4
| | | | | | free tags Approved by: re (gjb)
* MFC r320263:tuexen2017-06-285-72/+89
| | | | | | | | | | | | Use a longer buffer for messages in ERROR chunks. MFC r320264: Check the length of a COOKIE chunk before accessing fields in it. MFC r320300: Handle sctp_get_next_param() in a consistent way. Approved by: re (marius@)
OpenPOWER on IntegriCloud