From nobody Tue Aug 11 08:15:39 2026 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hK4FD468Qz6X90Q for ; Tue, 11 Aug 2026 08:15:44 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hK4FD2yqzz3xvj for ; Tue, 11 Aug 2026 08:15:44 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1786436144; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=PMZW5brRuLxN1GXmkDTtbcwM183H2yJlivEE3/GgkkE=; b=KjK5caXOYLtHiizosAumDvo/HO29sVD+g2vy6y9v/k/Fumn7VGMcvfR6oQZeBXZ431T9Ff 72Aul3+mlBpHOeIBAEzF9hpLx+7YLZwLep/XL+Ov1iuIvLk382TuQx1aTGGKqkgQ8m1yMf 7gZAzxcyUJ6Vdtv80u5wfidzh8i8BICCBI4CnSXPkgvH7SARyM/RzIxIxyVI786ptu8fjH ZSP4YJ+UVCGSCUJfdLp+0oJ1AvIyUXkuZzAb/0qx5MZarh2NPo9YrgHPQriX9rGf7DFuW2 VIMEYA8Jy6M4Y2TXml80N2o0fc7v6xXagmzrV2PMp6KGTS+WeqCLoYxXlapnJg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1786436144; a=rsa-sha256; cv=none; b=TNiGLCDZvjTCVfGvK7XEpOoV9tgKJH4N+n83+M3br0Sr+56Uh/h+gIrsA8BC56AYMLqLQx xVRhgbcUQI+ERH6EYizPDzflWNqGUSXbcwHpAYlX4taR0ox8rgbr2DCum/geUmjL92IF9L 22PjoqJqAGj5/xQtEUlWcbvVuqrVHBYoY/1PtPk5iOI4QRrDocbE2U7nDAgbHVINj3b/sv fSV9+b1JjSJJZgZEZysL6mBviFoetN0wYisEJtoZVYP1akiblDC5AJIQwKxCE2VQUI6Vnq oWXFMYhp0/+uorlu5y0d26GctlJcsP4cOHemd5dvYZI+MpWWCWJ/MnGRO40Rkg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1786436144; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=PMZW5brRuLxN1GXmkDTtbcwM183H2yJlivEE3/GgkkE=; b=Erg9Q84joi2O9Y3FzXJsu38CNuhDpb4OuKJT0Z4BFAH/MpwZIvv3LxdZd4sx5HKafh0oB4 LJXEND+nJIp1XC0THpqICd9DUn7Gxbys/G0qLV+oyAAe+cP+JyJOQWMeW0pi9QiZUL56Hw H8KnmNNMojRS5bp/7ZLJUNrDDoWZZ66KM06bLW+40UGX7Tiwcje6v6LNr79zRqzVuGTcwJ OqjRmWgyEO1uAPtVQC53dst3FIhetjKCQA24n6y2tXqrfq3LFz7KLFeWjjhgg7iYwztnV8 2GFuBgo0H9DHxMMiqqMOcANWtMuv5porcYF3QnqdoV9BFm51mCX+YorCeGVX/g== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hK4FD1Qylzmpq for ; Tue, 11 Aug 2026 08:15:44 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 25e1f by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Tue, 11 Aug 2026 08:15:39 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org Cc: Boris Lytochkin From: Andrey V. Elsukov Subject: git: c64d42caebb7 - stable/14 - ipfw: rework 32-bit KBI detection List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-branches@freebsd.org Sender: owner-dev-commits-src-branches@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: ae X-Git-Repository: src X-Git-Refname: refs/heads/stable/14 X-Git-Reftype: branch X-Git-Commit: c64d42caebb77f927777408f5a284a7313df1fc4 Auto-Submitted: auto-generated Date: Tue, 11 Aug 2026 08:15:39 +0000 Message-Id: <6a7ada2b.25e1f.260afbfb@gitrepo.freebsd.org> The branch stable/14 has been updated by ae: URL: https://cgit.FreeBSD.org/src/commit/?id=c64d42caebb77f927777408f5a284a7313df1fc4 commit c64d42caebb77f927777408f5a284a7313df1fc4 Author: Boris Lytochkin AuthorDate: 2026-08-11 08:03:16 +0000 Commit: Andrey V. Elsukov CommitDate: 2026-08-11 08:03:16 +0000 ipfw: rework 32-bit KBI detection When we run 14.X jail on 15.X host system previous implementation could not correctly detect 32-bit KBI due to jails can overwrite osreldate. Add special handling for this case and use detection using IP_FW_DUMP_SOPTCODES and IP_FW_XGET sockopts version. Reported by: Vova Grebenschikov Fixes: 704ec5e68c44 MFC after: 3 days Differential Revision: https://reviews.freebsd.org/D56616 --- sbin/ipfw/ipfw2.c | 102 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ sbin/ipfw/ipfw2.h | 1 + sbin/ipfw/main.c | 14 ++++---- 3 files changed, 110 insertions(+), 7 deletions(-) diff --git a/sbin/ipfw/ipfw2.c b/sbin/ipfw/ipfw2.c index 56e5b0640135..a8a70dccf125 100644 --- a/sbin/ipfw/ipfw2.c +++ b/sbin/ipfw/ipfw2.c @@ -33,6 +33,7 @@ #include #include #include +#include #include #include #include @@ -5829,6 +5830,107 @@ ipfw_internal_handler(int ac, char *av[]) } } +/* + * Detect 32 bit ipfw KBI by presence of XGET v=1. + * + * 32-bit KBI was introduced in 1500034. Report 32-bit KBI for osreldate equal + * or greater than 1500034. For lower values, jailed status must be checked to + * make sure getosreldate() returned a real value as jail init can be + * instructed to override this value (see jail(8)). In case we're in a jail, + * use ipfw socket to detect 32-bit KBI using ophandler probes. + * + * Return: + * 2 - 32-bit opcode KBI detected despite of getosreldate() retval + * 1 - 32-bit opcode KBI detected + * 0 - 16-bit opcode KBI detected + * -1 - an error occurred + */ + +int +ipfw_detect_u32_kbi(void) +{ + ipfw_obj_lheader *hdr = NULL; + ipfw_sopt_info *info; + socklen_t len; + size_t need; + uint32_t i; + int s, opver, ret = -1; + + if (getosreldate() >= 1500034) + return (1); + + /* Make more checks for lower osreldate values */ + s = 0; + need = sizeof(s); + sysctlbyname("security.jail.jailed", &s, &need, NULL, 0); + + /* We're not in a jail, value from getosreldate() is real */ + if (s == 0) + return (0); + + /* + * We're in a jail, osreldate may be altered. Use ipfw socket to + * decide. + */ + s = socket(AF_INET, SOCK_RAW, IPPROTO_RAW); + if (s < 0) + return (-1); + + /* + * ipfw code @ RELENG_15 can register 61 sockopt handlers. + * Pre-allocate enough to evade realloc() + */ + need = sizeof(ipfw_obj_lheader) + (64 * sizeof(ipfw_sopt_info)); + + opver = 0; + for (i = 4; i >= 0; i--) { + hdr = realloc(hdr, need); + memset(hdr, 0, need); + if (hdr == NULL) + break; + + hdr->opheader.opcode = IP_FW_DUMP_SOPTCODES; + hdr->opheader.version = opver; + hdr->size = need; + + /* Check DUMP_SOPTCODES v=1 existance */ + len = need; + if (getsockopt(s, IPPROTO_IP, IP_FW3, hdr, &len) != 0) { + if (errno == ENOMEM) { + need = hdr->size; + continue; + } + /* Does not exist. 32-bit KBI? */ + if (errno == EINVAL && opver == 0) { + opver = 1; + continue; + } + /* Report an error */ + ret = -1; + break; + } + /* Fetched soptcodes successfully */ + info = (ipfw_sopt_info *)(hdr + 1); + for (i = 0; i < hdr->count; i++) { + if (info[i].opcode != IP_FW_XGET) + continue; + if (info[i].version == 0) { + ret = 0; + break; + } + if (info[i].version == 1) { + ret = 2; + break; + } + } + break; + } + + free(hdr); + close(s); + return (ret); +} + static int ipfw_get_tracked_ifaces(ipfw_obj_lheader **polh) { diff --git a/sbin/ipfw/ipfw2.h b/sbin/ipfw/ipfw2.h index 2137719296f9..58b73a627bd7 100644 --- a/sbin/ipfw/ipfw2.h +++ b/sbin/ipfw/ipfw2.h @@ -454,6 +454,7 @@ int fill_ext6hdr(struct _ipfw_insn *cmd, char *av); void bp_flush(struct buf_pr *b); void fill_table(struct _ipfw_insn *cmd, char *av, uint8_t opcode, struct tidx *tstate); +int ipfw_detect_u32_kbi(void); /* tables.c */ struct _ipfw_obj_ctlv; diff --git a/sbin/ipfw/main.c b/sbin/ipfw/main.c index 3d5cfc96af46..2ad521bdbea4 100644 --- a/sbin/ipfw/main.c +++ b/sbin/ipfw/main.c @@ -18,7 +18,6 @@ * Command line interface for IP firewall facility */ -#include #include #include #include @@ -31,8 +30,6 @@ #include #include -#include - #include "ipfw2.h" static void @@ -673,6 +670,7 @@ ipfw_readfile(int ac, char *av[]) int main(int ac, char *av[]) { + int ret; #if defined(_WIN32) && defined(TCC) { WSADATA wsaData; @@ -697,17 +695,19 @@ main(int ac, char *av[]) * KBI-incompatibility detected, check for availability of ipfw/dnctl15 * binaries and run them instead */ - if (getosreldate() >= 1500000) { + ret = ipfw_detect_u32_kbi(); + if (ret > 0) { const char *releng15_progname; - int ret; if (g_co.prog == cmdline_prog_ipfw) releng15_progname = "/sbin/ipfw15"; else releng15_progname = "/sbin/dnctl15"; - printf("WARNING! KBI incompatibility for ipfw is detected," - " trying to run %s.\n", releng15_progname); + if (ret == 1) + printf("WARNING! KBI incompatibility for ipfw is" + " detected, trying to run %s.\n", + releng15_progname); if ((ret = execv(releng15_progname, av)) < 0) { printf("execv(%s) error: %s\n", releng15_progname,