opnsense-src/sys
Mark Johnston a9184e99af kthread: Set *newtdp earlier in kthread_add1()
syzbot reported a single boot-time crash in g_event_procbody(), a page
fault when dereferencing g_event_td.  g_event_td is initialized by the
kproc_kthread_add() call which creates the GEOM event thread:

  kproc_kthread_add(g_event_procbody, NULL, &g_proc, &g_event_td,
      RFHIGHPID, 0, "geom", "g_event");

I believe that the caller of kproc_kthread_add() was preempted after
adding the new thread to the scheduler, and before setting *newtdp,
which is equal to g_event_td.  Thus, since the first action of the GEOM
event thread is to lock itself, it ended up dereferencing a NULL
pointer.

Fix the problem simply by initializing *newtdp earlier.  I see no harm
in that, and it matches kproc_create1().  The scheduler provides
sufficient synchronization to ensure that the store is visible to the
new thread, wherever it happens to run.

Reported by:	syzbot+5397f4d39219b85a9409@syzkaller.appspotmail.com
Reviewed by:	kib
MFC after:	1 week
Differential Revision:	https://reviews.freebsd.org/D42986

(cherry picked from commit ae77041e0714627f9ec8045ca9ee2b6ea563138e)
2023-12-17 21:20:13 -05:00
..
amd64 makesyscalls: don't make syscall.mk by default 2023-12-13 23:07:06 +00:00
arm arm: Disable the VFP during boot 2023-12-17 21:07:49 -05:00
arm64 arm64: lop off another 24MB of KVA for early device mappings 2023-12-14 18:58:08 -06:00
bsm
cam ctl_ha: don't shutdown threads if scheduler is stopped 2023-12-08 18:02:44 -04:00
cddl boot/zfs: Add some fields to dsl_dir_phys_t 2023-10-25 10:27:26 -04:00
compat sysvipc: Fix 32-bit compat on !i386 2023-12-13 23:10:53 +00:00
conf arm: Compile vfp.c conditionally rather than using an ifdef 2023-12-17 21:07:45 -05:00
contrib x86emu: remove localy added __FBSDID 2023-12-13 23:08:51 +00:00
crypto ossl: Fix some bugs in the fallback AES-GCM implementation 2023-12-03 12:48:09 -05:00
ddb
dev bhnd: Correct the softc size in the siba_bhndb_driver definition 2023-12-11 19:30:05 -05:00
dts
fs nfscl: Fix comment for commit 6aded1e6b2e5 2023-12-17 12:32:08 -08:00
gdb
geom shutdown: audit shutdown_post_sync event callbacks 2023-12-08 18:02:44 -04:00
gnu
i386 makesyscalls: don't make syscall.mk by default 2023-12-13 23:07:06 +00:00
isa isa: Postpone removal of the non-PNP driver until 15 2023-10-30 08:55:08 +08:00
kern kthread: Set *newtdp earlier in kthread_add1() 2023-12-17 21:20:13 -05:00
kgssapi
libkern
modules zfs: merge openzfs/zfs@494aaaed8 (zfs-2.2-release) into stable/14 2023-12-01 12:31:24 +01:00
net vnet: (read) lock the vnet list while iterating it 2023-12-14 12:20:25 +01:00
net80211 net80211: remove ieee80211_unref_node() 2023-11-30 00:36:58 +00:00
netgraph ng_ksocket: fix accept(2) 2023-11-30 09:01:40 -08:00
netinet tcp: add PRR 6937bis heuristic and retire prr_conservative sysctl 2023-12-15 09:25:07 +01:00
netinet6 Avoid IPv6 source address selection on accepting TCP connections 2023-10-30 20:12:50 +03:00
netipsec
netlink netlink: fix potential llentry lock leak in newneigh handler 2023-11-01 10:05:49 +01:00
netpfil pf: fix mem leaks upon vnet destroy 2023-12-06 10:08:25 +01:00
netsmb
nfs
nfsclient
nfsserver
nlm
ofed ibcore: Introduce enum ib_raw_packet_caps from Linux 4.11 2023-11-04 15:22:18 -04:00
opencrypto
powerpc powerpc: better handling of shutdown flags 2023-12-08 18:02:44 -04:00
riscv busdma: emit a warning for use of filters 2023-12-06 19:23:14 -04:00
rpc libc/libc/rpc: refactor some global variables 2023-11-29 20:16:16 -07:00
security veriexec: Simplify the initialization of loader tunable 2023-11-13 11:56:57 +08:00
sys kmsan: Add kmsan_check_uio() 2023-12-14 09:44:38 -05:00
teken teken: fix style in teken_wcwidth.h 2023-10-21 17:28:35 +03:00
tests netlink: move NETLINK define to opt_global.h 2023-10-16 09:42:33 +02:00
tools makesyscalls: don't make syscall.mk by default 2023-12-13 23:07:06 +00:00
ufs Increase UFS/FFS maximum link count from 32767 to 65530. 2023-12-16 19:45:51 -08:00
vm uma: Micro-optimize memory trashing 2023-12-08 21:32:43 -05:00
x86 busdma: emit a warning for use of filters 2023-12-06 19:23:14 -04:00
xdr
xen
Makefile
README.md

FreeBSD Kernel Source:

This directory contains the source files and build glue that make up the FreeBSD kernel and its modules, including both original and contributed software.

Kernel configuration files are located in the conf/ subdirectory of each architecture. GENERIC is the configuration used in release builds. NOTES contains documentation of all possible entries. LINT is a compile-only configuration used to maximize build coverage and detect regressions.

Documentation:

Source code documentation is maintained in a set of man pages, under section 9. These pages are located in share/man/man9, from the top-level of the src tree. Consult intro(9) for an overview of existing pages.

Some additional high-level documentation of the kernel is maintained in the Architecture Handbook.

Source Roadmap:

Directory Description
amd64 AMD64 (64-bit x86) architecture support
arm 32-bit ARM architecture support
arm64 64-bit ARM (AArch64) architecture support
cam Common Access Method storage subsystem - cam(4) and ctl(4)
cddl CDDL-licensed optional sources such as DTrace
conf kernel build glue
compat Linux compatibility layer, FreeBSD 32-bit compatibility
contrib 3rd-party imported software such as OpenZFS
crypto crypto drivers
ddb interactive kernel debugger - ddb(4)
fs most filesystems, excluding UFS, NFS, and ZFS
dev device drivers and other arch independent code
gdb kernel remote GDB stub - gdb(4)
geom GEOM framework - geom(4)
i386 i386 (32-bit x86) architecture support
kern main part of the kernel
libkern libc-like and other support functions for kernel use
modules kernel module infrastructure
net core networking code
net80211 wireless networking (IEEE 802.11) - net80211(4)
netgraph graph-based networking subsystem - netgraph(4)
netinet IPv4 protocol implementation - inet(4)
netinet6 IPv6 protocol implementation - inet6(4)
netipsec IPsec protocol implementation - ipsec(4)
netpfil packet filters - ipfw(4), pf(4), and ipfilter(4)
opencrypto OpenCrypto framework - crypto(7)
powerpc PowerPC/POWER (32 and 64-bit) architecture support
riscv 64-bit RISC-V architecture support
security security facilities - audit(4) and mac(4)
sys kernel headers
tests kernel unit tests
ufs Unix File System - ffs(7)
vm virtual memory system
x86 code shared by AMD64 and i386 architectures