Page MenuHomeFreeBSD

netchild (Alexander Leidinger)
User

Projects

User Details

User Since
Jul 25 2015, 10:06 AM (573 w, 2 d)

Recent Activity

Yesterday

netchild committed rG3c3f886e4bc7: hwpmc: add regression tests for detaching a live process-mode PMC (authored by netchild).
hwpmc: add regression tests for detaching a live process-mode PMC
Mon, Jul 20, 10:26 AM
netchild committed rG86fa065f1862: hwpmc: drain a process-mode PMC's runcount when a live target detaches (authored by netchild).
hwpmc: drain a process-mode PMC's runcount when a live target detaches
Mon, Jul 20, 10:26 AM
netchild closed D58343: hwpmc: add regression tests for detaching a live process-mode PMC.
Mon, Jul 20, 10:26 AM · pmc
netchild closed D58342: hwpmc: drain a process-mode PMC's runcount when a live target detaches.
Mon, Jul 20, 10:26 AM · pmc
netchild committed rG2cfd82f747c0: hwpmc: add regression tests for counting-PMC counter wraparound (authored by netchild).
hwpmc: add regression tests for counting-PMC counter wraparound
Mon, Jul 20, 10:25 AM
netchild closed D58341: hwpmc: add regression tests for counting-PMC counter wraparound.
Mon, Jul 20, 10:25 AM · pmc
netchild committed rGe42703f5c4b2: hwpmc: handle counter wraparound for process-mode counting PMCs (authored by netchild).
hwpmc: handle counter wraparound for process-mode counting PMCs
Mon, Jul 20, 10:25 AM
netchild closed D58340: hwpmc: handle counter wraparound for process-mode counting PMCs.
Mon, Jul 20, 10:25 AM · pmc
netchild updated the diff for D58322: exterror tests: harden the checks.

full context

Mon, Jul 20, 9:55 AM
netchild updated the diff for D58321: exterror: advertise error strings via kern.features.exterr_strings.

full context

Mon, Jul 20, 9:54 AM

Sun, Jul 19

netchild committed rGd6915bffb7b6: nullfs: close a race when syncing inotify flags from the lower vnode (authored by netchild).
nullfs: close a race when syncing inotify flags from the lower vnode
Sun, Jul 19, 3:14 PM
netchild closed D58344: nullfs: close a race when syncing inotify flags from the lower vnode.
Sun, Jul 19, 3:14 PM
netchild added a comment to D58266: iflib: restore TX watchdog functionality.

Results from the affected hardware (em0, 82541PI), ~44 h
on a v3 kernel. Summary: 16 watchdog fires, all true positives, 0 false
positives.

Sun, Jul 19, 3:05 PM
netchild updated the summary of D58266: iflib: restore TX watchdog functionality.
Sun, Jul 19, 2:52 PM
netchild updated the diff for D58266: iflib: restore TX watchdog functionality.

New tested version, on hardware which triggers the watchdog.

Sun, Jul 19, 2:37 PM
netchild requested review of D58344: nullfs: close a race when syncing inotify flags from the lower vnode.
Sun, Jul 19, 12:30 PM
netchild requested review of D58343: hwpmc: add regression tests for detaching a live process-mode PMC.
Sun, Jul 19, 12:26 PM · pmc
netchild requested review of D58342: hwpmc: drain a process-mode PMC's runcount when a live target detaches.
Sun, Jul 19, 12:22 PM · pmc
netchild added a reviewer for D58340: hwpmc: handle counter wraparound for process-mode counting PMCs: pmc.
Sun, Jul 19, 12:15 PM · pmc
netchild requested review of D58341: hwpmc: add regression tests for counting-PMC counter wraparound.
Sun, Jul 19, 12:15 PM · pmc
netchild requested review of D58340: hwpmc: handle counter wraparound for process-mode counting PMCs.
Sun, Jul 19, 12:10 PM · pmc
netchild updated the diff for D58322: exterror tests: harden the checks.
Sun, Jul 19, 11:24 AM
netchild updated the diff for D58321: exterror: advertise error strings via kern.features.exterr_strings.
Sun, Jul 19, 11:16 AM

Sat, Jul 18

netchild added a comment to D58321: exterror: advertise error strings via kern.features.exterr_strings.

So you disagree with kern.features.exterror.
Do you also disagree with kern.features.exterr_strings which covers the optional behavior of verbose exterror and is useful in unit tests to differentiate between "fails because something is wrong -> error" and "fails because it does not exist -> intendet -> ok".

Sat, Jul 18, 5:40 PM
netchild requested review of D58322: exterror tests: harden the checks.
Sat, Jul 18, 1:23 PM
netchild added a comment to D58321: exterror: advertise error strings via kern.features.exterr_strings.

The kern.features.exterror part is for the benefit of userland programs which want to use it (e.g. difference between FreeBSD 14.x and 15.x).
The kern.features.exterr_strings part is for the benefit of unit tests to be able to skip if the verbose strings are not enabled.

Sat, Jul 18, 1:21 PM
netchild requested review of D58321: exterror: advertise error strings via kern.features.exterr_strings.
Sat, Jul 18, 1:19 PM

Thu, Jul 16

netchild added a comment to D58266: iflib: restore TX watchdog functionality.

This fires too often, maybe some false positives. I will rework.

Thu, Jul 16, 12:31 PM
netchild requested review of D58282: iflib: remove the unused TX queue state machine.
Thu, Jul 16, 11:11 AM
netchild updated the diff for D58266: iflib: restore TX watchdog functionality.

Switch to the mxge way. Mxge seems to harvest the completions
eagerly per interrupt, while iflib seems to reclaim lazy. The
software counter of iflib would get into the watchdog firing
situation on a lightly loaded interface... if I get it correctly.

Thu, Jul 16, 11:10 AM

Wed, Jul 15

netchild published D58266: iflib: restore TX watchdog functionality for review.
Wed, Jul 15, 7:43 PM

Sat, Jul 11

netchild committed R11:631b5de7d8ec: audio/lame: Update to 4.0. (authored by netchild).
audio/lame: Update to 4.0.
Sat, Jul 11, 6:00 PM

Thu, Jul 9

netchild committed R11:ceed65743a03: audio/lame: fix build (missing pkgconfig) (authored by netchild).
audio/lame: fix build (missing pkgconfig)
Thu, Jul 9, 4:34 PM
netchild committed R11:350a144f9572: audio/lame: Update to 3.101. (authored by netchild).
audio/lame: Update to 3.101.
Thu, Jul 9, 12:48 PM

Sun, Jul 5

netchild committed R11:0c8576e93850: ports-mgmt/sccache-overlay: increase prio to fix cargo at configure time (authored by netchild).
ports-mgmt/sccache-overlay: increase prio to fix cargo at configure time
Sun, Jul 5, 10:01 AM

Sat, Jun 27

netchild committed rGd05d60e958bc: rc.d: fix lockd and statd flags processing after scvj (authored by netchild).
rc.d: fix lockd and statd flags processing after scvj
Sat, Jun 27, 1:52 PM

Wed, Jun 24

netchild added a comment to D57628: build: raise our FORTIFY_SOURCE default to 2.

When excluding from fortify the ones for which I mailed the error message to you, I have build
Queued: 1338 Inspected: 0 Ignored: 0 Built: 1338 Failed: 0 Skipped: 0 Fetched: 0 Remaining: 0

Wed, Jun 24, 1:00 PM

Jun 20 2026

netchild added a comment to D57628: build: raise our FORTIFY_SOURCE default to 2.

All supported releases should have it, but it is also harmless to define any of this when it isn't -- I'd probably avoid complicating it too much.

Sounds sensible.

If you don't object to the ports patch as the maintainer, I'll just go ahead and request an exp-run with both patches applied (with the assignment you noted fixed). I had hoped to land this this week, but I also don't want antoine throwing tomatoes at me if we fundamentally break the ports tree. =-)

I don't object for sure. But I suggest to use this instead:

diff --git Mk/Features/fortify.mk Mk/Features/fortify.mk
index 2e43ca98242..86d149ff68e 100644
--- Mk/Features/fortify.mk
+++ Mk/Features/fortify.mk
@@ -14,5 +14,7 @@ FORTIFY_SOURCE?=2
 FORTIFY_CFLAGS?=       -D_FORTIFY_SOURCE=${FORTIFY_SOURCE}
 CFLAGS+=       ${FORTIFY_CFLAGS}
 CXXFLAGS+=     ${FORTIFY_CFLAGS}
+.  else
+FORTIFY_SOURCE=0
 .  endif
 .endif

That works- it does need an .export FORTIFY_SOURCE line to work, though, otherwise the build will pick up the default in bsd.sys.mk if we aren't adding to C*FLAGS (since the port build would be running in a submake)

Jun 20 2026, 3:59 PM

Jun 19 2026

netchild added a comment to D57628: build: raise our FORTIFY_SOURCE default to 2.

All supported releases should have it, but it is also harmless to define any of this when it isn't -- I'd probably avoid complicating it too much.

Jun 19 2026, 9:08 PM
netchild added a comment to D57628: build: raise our FORTIFY_SOURCE default to 2.

Without doing any build-test, should the UNSAFE part be "=0" instead of "?=0"? We want a hard override in the UNSAFE case, don't we?

Jun 19 2026, 8:02 AM
netchild added a comment to D57628: build: raise our FORTIFY_SOURCE default to 2.

@kevans would it help if I build a known failing port with your ports-patch applied?

Jun 19 2026, 7:50 AM
netchild added a comment to D57628: build: raise our FORTIFY_SOURCE default to 2.

This is what I have, this is historically grown and may or may not be an issue today:

Jun 19 2026, 7:35 AM

Jun 5 2026

netchild committed R11:fda9bb4e1965: net/serviio: update to 2.5 (authored by netchild).
net/serviio: update to 2.5
Jun 5 2026, 1:55 PM

Jun 3 2026

netchild committed R11:281839ef4bfa: mail/roundcube-tls_icon: update to 2.0.0 (authored by netchild).
mail/roundcube-tls_icon: update to 2.0.0
Jun 3 2026, 6:04 PM
netchild committed R11:87fb3c9997cd: mail/roundcube-gravatar: update to 1.7 (authored by netchild).
mail/roundcube-gravatar: update to 1.7
Jun 3 2026, 6:04 PM

May 6 2026

netchild committed R11:c31e0541d463: misc/openhab: Update to 4.3.11. (authored by netchild).
misc/openhab: Update to 4.3.11.
May 6 2026, 8:30 AM

May 4 2026

netchild committed R11:90a70c602a0f: www/piwigo: Update to 16.4.0. (authored by netchild).
www/piwigo: Update to 16.4.0.
May 4 2026, 7:37 PM

Apr 27 2026

netchild accepted D56652: kerneldoc: also ingest .md (markdown files).

I assume we do not have .md files in the kernel subsystem directories (yet). As such I assume this should not affect the output on the next run. Based opn that, I so no reason why not to add more supported file types.
If there are .md files, I suggest to check how it affects the output.

Apr 27 2026, 10:03 AM · docs

Apr 19 2026

netchild committed rG315f665fe1ac: Doxygen subsystem config: exclude the content of the .git directory (authored by netchild).
Doxygen subsystem config: exclude the content of the .git directory
Apr 19 2026, 12:48 PM

Apr 17 2026

netchild accepted D56456: rc.conf: Fix typo in comment.
Apr 17 2026, 6:56 AM

Mar 31 2026

netchild closed D51150: Jail sysctls: deprecated a generic sysctl in favour of allow-flags.
Mar 31 2026, 5:24 PM
netchild committed rG6087050ef52c: Jail sysctls: deprecate generic sysctls in favour of allow-flags (authored by netchild).
Jail sysctls: deprecate generic sysctls in favour of allow-flags
Mar 31 2026, 5:24 PM
netchild reclaimed D51150: Jail sysctls: deprecated a generic sysctl in favour of allow-flags.

Very strange. First "patch" told me it is already applied (it was a pristine src tree). Now I do a git diff and it is showing up. Pffft.

Mar 31 2026, 5:19 PM
netchild abandoned D51150: Jail sysctls: deprecated a generic sysctl in favour of allow-flags.

I was wrong. It is committed. It just needs to be closed here. I do not see a way to close. Maybe I'm blind... the only thing I found was abandoning this revision.

Mar 31 2026, 4:39 PM
netchild added a comment to D51150: Jail sysctls: deprecated a generic sysctl in favour of allow-flags.

Yes, it waits for me to remember that this is not committed...

Mar 31 2026, 4:32 PM

Feb 25 2026

netchild committed R11:cb70d4b29f1e: www/piwigo: Update to 16.3.0. (authored by netchild).
www/piwigo: Update to 16.3.0.
Feb 25 2026, 11:44 AM
netchild committed R11:7b23bc26b082: misc/openhab*: Update to 4.3.10 (authored by netchild).
misc/openhab*: Update to 4.3.10
Feb 25 2026, 11:26 AM

Feb 6 2026

netchild committed R9:b407b3ed50bc: pgpkeys: Update my key. (authored by netchild).
pgpkeys: Update my key.
Feb 6 2026, 2:09 PM

Jan 15 2026

netchild committed R11:0b91a98b9923: Mk/Features: allow ZEROREGS opt-out (authored by 2khramtsov_gmail.com).
Mk/Features: allow ZEROREGS opt-out
Jan 15 2026, 11:00 AM

Dec 31 2025

netchild committed R11:c1ffefeac9fb: www/piwigo: Update to 16.2.0. (authored by netchild).
www/piwigo: Update to 16.2.0.
Dec 31 2025, 1:44 PM

Dec 11 2025

netchild committed R11:fb16179057f4: misc/openhab: Update to 4.3.9. (authored by netchild).
misc/openhab: Update to 4.3.9.
Dec 11 2025, 7:50 AM

Dec 8 2025

netchild committed R11:58e084d4d52f: www/piwigo: Update to 16.1.0. (authored by netchild).
www/piwigo: Update to 16.1.0.
Dec 8 2025, 2:29 PM

Nov 25 2025

netchild committed R11:b419989fb145: www/piwigo: Update tp 16.0.0. (authored by netchild).
www/piwigo: Update tp 16.0.0.
Nov 25 2025, 12:11 PM

Nov 14 2025

netchild accepted D53754: rc.subr: Try to make svjc option handling a bit easier to read.

Visual inspection: looks functionally equivalent, all options match their intend.
Test run: OK with 31 service jails (at least net_basic works ok).

Nov 14 2025, 5:55 PM

Oct 21 2025

netchild committed R11:b14ef2e3a017: www/piwigo: Update to 15.7.0. (authored by netchild).
www/piwigo: Update to 15.7.0.
Oct 21 2025, 7:40 PM

Oct 18 2025

netchild accepted D53169: rc: dmesg: Allow file and umask to be configurable.

The umask part looks fine.
About the dmesg_file part: from a technical point of view it is ok.,From a feature point of view, if it is not necessary, don't change it (I can't remember to have seen someone to have asked in the last 20 years about having it in another location).

Oct 18 2025, 2:00 PM

Oct 16 2025

netchild committed R11:1a1006c2b64c: misc/openhab: Update to 4.3.8. (authored by netchild).
misc/openhab: Update to 4.3.8.
Oct 16 2025, 7:24 AM

Oct 6 2025

netchild added a comment to D52934: tcp: improve SEG.ACK validation in SYN-RECEIVED.

I can confirm that this fixes the crash I've seen. Instead of crashing after a few minutes, it now is still humming happily with 16 minutes of uptime.

Oct 6 2025, 8:45 PM

Sep 11 2025

netchild committed R11:a3c7e5d6699a: textproc/modlogan: convert unexec to preunexec (authored by netchild).
textproc/modlogan: convert unexec to preunexec
Sep 11 2025, 8:47 AM
netchild committed R11:29d6c8c1fad0: misc/openhab2*: mark deprecated and set expiration date (authored by netchild).
misc/openhab2*: mark deprecated and set expiration date
Sep 11 2025, 8:47 AM

Aug 29 2025

netchild committed R11:a3fbcaec5398: www/apache24: make the start script service jails ready (authored by netchild).
www/apache24: make the start script service jails ready
Aug 29 2025, 8:09 AM

Aug 27 2025

netchild committed R11:e3d3c40c5c90: openhab*: Update to 4.3.7. (authored by netchild).
openhab*: Update to 4.3.7.
Aug 27 2025, 8:34 AM

Aug 26 2025

netchild committed rG75b18baf096a: UPDATING: fix typo in pattern (authored by netchild).
UPDATING: fix typo in pattern
Aug 26 2025, 10:08 AM
netchild committed rGbcefbb46d2ae: UPDATING: fix typo in the Secure RPC entry. (authored by netchild).
UPDATING: fix typo in the Secure RPC entry.
Aug 26 2025, 9:24 AM
netchild committed rG3463f02706db: UPDATING: add an entry for [gs]etgroups (authored by netchild).
UPDATING: add an entry for [gs]etgroups
Aug 26 2025, 9:23 AM

Jul 26 2025

netchild committed R11:e98b1b21d6e5: misc/openhab*: Update to 4.3.6. (authored by netchild).
misc/openhab*: Update to 4.3.6.
Jul 26 2025, 12:25 PM
netchild committed R11:377a19e1588b: www/piwigo: Update to 15.6.0. (authored by netchild).
www/piwigo: Update to 15.6.0.
Jul 26 2025, 12:25 PM

Jul 3 2025

netchild requested review of D51150: Jail sysctls: deprecated a generic sysctl in favour of allow-flags.
Jul 3 2025, 3:44 PM

May 28 2025

netchild committed R11:bd23362b4d0d: misc/openhab: fix syntax error in files/pkg-message.in (authored by netchild).
misc/openhab: fix syntax error in files/pkg-message.in
May 28 2025, 11:39 AM

May 24 2025

netchild committed R11:7a489e95c51f: Mk/Features: Add features for fortify, zeroregs and stack autoinit. (authored by netchild).
Mk/Features: Add features for fortify, zeroregs and stack autoinit.
May 24 2025, 6:22 PM

May 17 2025

netchild accepted D49976: svcj: correctly handle kernels without INET or INET6.

Just from reading I do not see an obvious issue now. Revision accepted (fixing the minor nit doesn't need another review IMO).

May 17 2025, 5:05 PM

May 10 2025

netchild committed R11:ce5a2bf9966e: misc/openhab: Update to 4.3.5. (authored by netchild).
misc/openhab: Update to 4.3.5.
May 10 2025, 10:09 AM

Apr 23 2025

netchild added a comment to D49976: svcj: correctly handle kernels without INET or INET6.
In D49976#1139747, @des wrote:

Wouldn't it be better to check at point of use rather than at point of initialization?

Apr 23 2025, 11:43 AM
netchild requested changes to D49976: svcj: correctly handle kernels without INET or INET6.
Apr 23 2025, 10:31 AM

Apr 21 2025

netchild added a comment to D49843: jail: add allow.routing jail permission.
In D49843#1138774, @zec wrote:
In D49843#1138771, @zec wrote:

...

No, the host is gone as well, since the attacker has control over network connectivity.

You go to the keyboard of the host, delete the jail, and the attacker is gone.

Sounds pretty much as a very deep redefinition of the jail contract to me.

Apr 21 2025, 8:30 PM
netchild added a comment to D49843: jail: add allow.routing jail permission.
In D49843#1138771, @zec wrote:
In D49843#1138763, @ivy wrote:
In D49843#1138751, @zec wrote:

Consider an exploit in BIRD which would allow routing tables to be manipulated

consider an exploit in BIRD which would allow an attacker to run code as root.

running BIRD in a jail -> only the jail is compromised.

No, the host is gone as well, since the attacker has control over network connectivity.

Apr 21 2025, 3:59 PM
netchild added a comment to D49843: jail: add allow.routing jail permission.
In D49843#1138751, @zec wrote:

Repeating that someone might have his mind set on running BIRD in a swiss-cheese-jail is far from providing arguments on what real security benefit would this provide compared to running it in a plain system (or in a chrooted tree).

Consider an exploit in BIRD which would allow routing tables to be manipulated so that only the attacker would retain connectivity to the compromised host, while to the others the whole system would appear to be dead. What exactly does running BIRD in a service jail bring us, compared to running it in the base system?

Apr 21 2025, 2:22 PM

Apr 17 2025

netchild added a comment to D49843: jail: add allow.routing jail permission.
In D49843#1137302, @lexi_le-fay.org wrote:

i have been mulling over how we can add more restrictions to svcj. i don't think "just use nullfs" is the answer here because that makes everything more complicated, but i don't yet have another proposal. i don't think this is impossible to fix in principle though.

Apr 17 2025, 8:06 PM
netchild added a comment to D49843: jail: add allow.routing jail permission.

The svcj documentation in rc.conf.5 doesn't say anything about why one might want to run a service in a service jail, and what benefits that confers. I think that's a bug, especially given that the feature uses the term "jail" and not "container", and the former has specific connotations relating to security, at least in FreeBSD. And frankly I'm not sure what added security is obtained from having a privileged daemon run in a jail with path=/.

Apr 17 2025, 7:07 PM

Apr 15 2025

netchild added a comment to D49845: rc.subr: add 'settime' to svcj options.

The kernel side (PRIV) of this patch is missing (compared to to the github pull request).
The svcj part is OK.

Apr 15 2025, 7:02 PM

Apr 14 2025

netchild committed rG6fbd1bed6e7b: rc.subr: add ${svc}_svcj_ipaddrs option (authored by ivy).
rc.subr: add ${svc}_svcj_ipaddrs option
Apr 14 2025, 1:25 PM

Apr 2 2025

netchild committed R11:d4664d6d7631: misc/openhab: Update to 4.3.4. (authored by netchild).
misc/openhab: Update to 4.3.4.
Apr 2 2025, 10:52 AM

Mar 12 2025

netchild committed R11:c5a94e997e8d: www/piwigo: Update to 15.5.0. (authored by netchild).
www/piwigo: Update to 15.5.0.
Mar 12 2025, 3:03 PM

Feb 22 2025

netchild committed R11:da1daad73d9f: misc/openhab: Update to 4.3.3. (authored by netchild).
misc/openhab: Update to 4.3.3.
Feb 22 2025, 2:13 PM
netchild committed R11:e66b9ac1325d: www/piwigo: Update to 15.4.0. (authored by netchild).
www/piwigo: Update to 15.4.0.
Feb 22 2025, 2:13 PM
netchild added a comment to D49100: inpcb: Fix reuseport lbgroup array resizing.

In my case I got
panic: invalid local group size 16 and count 16

Feb 22 2025, 11:02 AM

Feb 14 2025

netchild committed R11:353e24e2753c: biology/linux-foldingathome: Update to 8.4.9. (authored by netchild).
biology/linux-foldingathome: Update to 8.4.9.
Feb 14 2025, 8:25 AM

Jan 31 2025

netchild closed D48724: Limit the use of stack clash protection and zeroregs based upon compiler features.
Jan 31 2025, 12:17 PM
netchild committed rG1c2ae9233b0e: Limit some cc options based upon features (authored by netchild).
Limit some cc options based upon features
Jan 31 2025, 12:17 PM

Jan 30 2025

netchild requested review of D48724: Limit the use of stack clash protection and zeroregs based upon compiler features.
Jan 30 2025, 9:26 AM