<feed xmlns='http://www.w3.org/2005/Atom'>
<title>src/tests, branch stable/13</title>
<subtitle>FreeBSD source tree</subtitle>
<id>https://cgit-dev.freebsd.org/src/atom?h=stable%2F13</id>
<link rel='self' href='https://cgit-dev.freebsd.org/src/atom?h=stable%2F13'/>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/'/>
<updated>2026-04-28T19:35:48Z</updated>
<entry>
<title>pf: improve SCTP validation</title>
<updated>2026-04-28T19:35:48Z</updated>
<author>
<name>Kristof Provost</name>
<email>kp@FreeBSD.org</email>
</author>
<published>2026-04-26T09:34:55Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=ed0e766f125620aa64f3cab1231317557dde5a6a'/>
<id>urn:sha1:ed0e766f125620aa64f3cab1231317557dde5a6a</id>
<content type='text'>
As per RFC5061 "4.2.  New Parameter Types" the add/delete IP address
parameters (0xc001, 0xc002) may not be present in an INIT or INIT-ACK
chunk. They are only allowed to be present in an ASCONF chunk.

This also prevents unbounded recursion while parsing an SCTP packet.

Approved by:	so
Security:	FreeBSD-SA-26:14.pf
Security:	CVE-2026-7164
PR:		294799
Reported by:	Igor Gabriel Sousa e Souza
MFC after:	3 days
Sponsored by:	Orange Business Services
</content>
</entry>
<entry>
<title>pkru: Fix handling of 1GB largepage mappings</title>
<updated>2026-04-21T15:43:53Z</updated>
<author>
<name>Mark Johnston</name>
<email>markj@FreeBSD.org</email>
</author>
<published>2026-03-31T13:37:43Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=b8fc561930689d167d831e79a77f72726302db76'/>
<id>urn:sha1:b8fc561930689d167d831e79a77f72726302db76</id>
<content type='text'>
pmap_pkru_update_range() did not handle the case where a PDPE has PG_PS
set.  More generally, the SET_PKRU and CLEAR_PKRU sysarch
implementations did not check whether the request covers a "boundary" vm
map entry.  Fix this, add the missing PG_PS test, and add some tests.

Approved by:	so
Security:	FreeBSD-SA-26:11.amd64
Security:	CVE-2026-6386
Reported by:	Nicholas Carlini &lt;npc@anthropic.com&gt;
Reviewed by:	kib, alc
Differential Revision:	https://reviews.freebsd.org/D56184
</content>
</entry>
<entry>
<title>tty: Avoid leaving dangling pointers in tty_drop_ctty()</title>
<updated>2026-04-21T15:43:53Z</updated>
<author>
<name>Mark Johnston</name>
<email>markj@FreeBSD.org</email>
</author>
<published>2026-03-23T15:22:48Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=5eae7f23fe0e189f2d5160772cf6cd4d107dd30a'/>
<id>urn:sha1:5eae7f23fe0e189f2d5160772cf6cd4d107dd30a</id>
<content type='text'>
The TIOCNOTTY handler detaches the calling process from its controlling
terminal.  It clears the link from the session to the tty, but not the
pointers from the tty to the session and process group.  This means that
sess_release() doesn't call tty_rel_sess(), and that pgdelete() doesn't
call tty_rel_pgrp(), so the pointers are left dangling.

Fix this by clearing pointers in tty_drop_ctty().  Add a standalone
regression test.

Approved by:	so
Security:	FreeBSD-SA-26:10.tty
Security:	CVE-2026-5398
Reported by:	Nicholas Carlini &lt;npc@anthropic.com&gt;
Reviewed by:	kib, kevans
Fixes:		1b50b999f9b5 ("tty: implement TIOCNOTTY")
Differential Revision:	https://reviews.freebsd.org/D56046
</content>
</entry>
<entry>
<title>pf tests: verify that we handle address range rules correctly</title>
<updated>2026-03-24T06:15:01Z</updated>
<author>
<name>Kristof Provost</name>
<email>kp@FreeBSD.org</email>
</author>
<published>2026-03-12T14:23:32Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=6666b2a0e7c26e9e0d913955765c7eb252c1b10a'/>
<id>urn:sha1:6666b2a0e7c26e9e0d913955765c7eb252c1b10a</id>
<content type='text'>
There's been a problem where rules which differed only in address ranges
were considered duplicates and not added. Test for this.

MFC after:	1 week
Sponsored by:	Rubicon Communications, LLC ("Netgate")

(cherry picked from commit ab74151e8d097b263237942c0b12277098bc9533)
</content>
</entry>
<entry>
<title>unix/tests: Add a regression test for fd transfer across jails</title>
<updated>2026-02-09T18:07:10Z</updated>
<author>
<name>Mark Johnston</name>
<email>markj@FreeBSD.org</email>
</author>
<published>2025-06-24T20:08:22Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=c9977132865ec06d2d3e1f404e946836019ff7a2'/>
<id>urn:sha1:c9977132865ec06d2d3e1f404e946836019ff7a2</id>
<content type='text'>
MFC after:	3 weeks

(cherry picked from commit 5843b8ee02e99527c28f579acfc1f48e10033529)
</content>
</entry>
<entry>
<title>pf: relax sctp v_tag verification</title>
<updated>2025-12-11T09:22:15Z</updated>
<author>
<name>Kristof Provost</name>
<email>kp@FreeBSD.org</email>
</author>
<published>2025-11-25T09:59:02Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=7b4482f3834a93142f10a7dfe47b4456dbdf3660'/>
<id>urn:sha1:7b4482f3834a93142f10a7dfe47b4456dbdf3660</id>
<content type='text'>
pf was too strict when validating SCTP tags. When a server receives a
retransmitted INIT it will reply with a random initiate tag every time.
However, pf saves the first initiate tag and expects every subsequent INIT_ACK
retransmission to have the same tag. This is not the case, leading to endless
INIT/INIT_ACK cycles.

Allow the tag to be updated as long as we've not gone past COOKIE_WAIT.

Add a test case to verify this.

MFC after:	2 weeks
See also:	https://redmine.pfsense.org/issues/16516
Sponsored by:	Rubicon Communications, LLC ("Netgate")

(cherry picked from commit bc3b72ff48953551e0e8bd6e5a2c718ecd973285)
</content>
</entry>
<entry>
<title>tests: Add a regression test for commit 7587f6d4840f8</title>
<updated>2025-11-19T20:47:50Z</updated>
<author>
<name>Mark Johnston</name>
<email>markj@FreeBSD.org</email>
</author>
<published>2025-05-28T15:28:36Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=b55b92729641e05a05cc8526b08bd7ac3dfcb4fc'/>
<id>urn:sha1:b55b92729641e05a05cc8526b08bd7ac3dfcb4fc</id>
<content type='text'>
Reviewed by:	kib
MFC after:	2 weeks
Differential Revision:	https://reviews.freebsd.org/D50533

(cherry picked from commit a5dac34f6e98c47bd7cb1946e39cc45432e167a8)
</content>
</entry>
<entry>
<title>src.conf: Add a MK_ZFS_TESTS knob</title>
<updated>2025-11-19T20:47:50Z</updated>
<author>
<name>Mark Johnston</name>
<email>markj@FreeBSD.org</email>
</author>
<published>2024-09-07T14:36:28Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=90118a35a3ae469ca91a4c52b3623bf4d0c5212e'/>
<id>urn:sha1:90118a35a3ae469ca91a4c52b3623bf4d0c5212e</id>
<content type='text'>
The in-tree ZFS test suite is somewhat outdated and I see a number of
failures there.  I tend to think that we want to integrate the OpenZFS
test suite somehow, replacing the legacy one, though it's also possible
to run that as a separate test suite.

In any case, if one wants to run the OpenZFS test suite separately, it's
useful to be able to disable installation of the legacy ZFS test suite,
so let's provide a src.conf option to do that.

Reviewed by:	asomers
MFC after:	2 weeks
Differential Revision:	https://reviews.freebsd.org/D46476

(cherry picked from commit 24affded3d4ec5fafb6b22f773ec1e20d73b9b03)
</content>
</entry>
<entry>
<title>pf: improve DIOCRCLRTABLES validation</title>
<updated>2025-11-03T08:34:27Z</updated>
<author>
<name>Kristof Provost</name>
<email>kp@FreeBSD.org</email>
</author>
<published>2025-10-29T08:28:59Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=8f92db3cf5405e38f565591d878c7b1b409dc055'/>
<id>urn:sha1:8f92db3cf5405e38f565591d878c7b1b409dc055</id>
<content type='text'>
Unterminated strings in the anchor or name could cause crashes.
Validate them, and add a test case.

Reported by:	Ilja Van Sprundel &lt;ivansprundel@ioactive.com&gt;
MFC after:	3 days
Sponsored by:	Rubicon Communications, LLC ("Netgate")

(cherry picked from commit 1da3c0ca5b1decaa9cf55859cd134bdcd1218116)
</content>
</entry>
<entry>
<title>pf: improve add state validation</title>
<updated>2025-11-03T08:34:26Z</updated>
<author>
<name>Kristof Provost</name>
<email>kp@FreeBSD.org</email>
</author>
<published>2025-10-29T10:40:52Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=ba198fe8a03bbe1e11efcd651d7ef7c83837efbe'/>
<id>urn:sha1:ba198fe8a03bbe1e11efcd651d7ef7c83837efbe</id>
<content type='text'>
Both for the DIOCADDSTATE ioctl and for states imported through pfsync packets.
Add a test case to exercise this code path.

Reported by:	Ilja Van Sprundel &lt;ivansprundel@ioactive.com&gt;
MFC after:	3 days
Sponsored by:	Rubicon Communications, LLC ("Netgate")

(cherry picked from commit faacc0d968816cf8714c974b6d8df6191cfb0e0d)
</content>
</entry>
</feed>
