FreeBSD src
Go to file
John Baldwin 2ff447ee3b cxgbe: Enable TOE TLS RX when an RX key is provided via setsockopt().
Rather than requiring a socket to be created as a TLS socket from the
get go, switch a TOE socket from "plain" TOE to TLS mode when a
receive key is added to the socket.

The firmware is only able to switch a "plain" TOE connection to TLS
mode if the head of the pending socket data is the start of a TLS
record, so the connection is migrated to TLS mode as a multi-step
process.

When TOE TLS RX is enabled, the associated connection's receive side
is frozen via a flag in the TCB.  The state of the socket buffer is
then examined to determine if the pending data in the socket buffer
ends on a TLS record boundary.  If so, the connection is migrated to
TLS mode and unfrozen.  Otherwise, the connection is unfrozen
temporarily until more data arrives.  Once more data arrives, the
receive queue is frozen again and rechecked.  This continues until the
connection is paused at a record boundary.  Any records received
before TLS mode is enabled are decrypted as software records.

Note that this removes the 'rx_tls_ports' sysctl.  TOE TLS offload for
receive is now enabled automatically on existing TOE connections when
using a KTLS-aware SSL library just as it was previously enabled
automatically for TLS transmit.  This also enables TLS offload for TOE
connections which enable TLS after passing initial data in the clear
(e.g. STARTTLS with SMTP).

Sponsored by:	Chelsio Communications
Differential Revision:	https://reviews.freebsd.org/D37351
2022-11-15 12:08:51 -08:00
.cirrus-ci Cirrus-CI: add some timing info on pkg install failure 2021-08-04 15:02:00 -04:00
.github .github: Attempt to fix and increase robustness of macOS action 2022-06-30 21:03:26 +01:00
bin ls(1): add a -v flag to sort naturally 2022-10-31 00:00:42 +01:00
cddl pkgbase: Put zfs utilities and lib in their own package 2022-10-26 19:46:30 +02:00
contrib gnu diff3: apply patch to committed src, rather than at build time 2022-11-13 21:33:40 -05:00
crypto ssh: remove VersionAddendum from list of client side config changes 2022-11-14 15:33:51 -05:00
etc sendmail: remove leftovers from mta_start_script and rc.sendmail 2022-11-15 09:10:53 +01:00
gnu gnu diff3: apply patch to committed src, rather than at build time 2022-11-13 21:33:40 -05:00
include Import device-tree files from Linux 6.0 2022-11-15 19:51:46 +01:00
kerberos5 kerberos5: retire now-unused MIPS support 2022-11-02 13:16:18 -04:00
lib rpcb_clnt.c: Do not force use of UDP 2022-11-13 12:16:06 -08:00
libexec othermta: remove leftover from 20 years ago 2022-11-14 09:08:37 +01:00
release release(7): Enable zpoolupgrade rc script in ZFS based VM images 2022-11-07 11:47:33 +08:00
rescue rescue: Link libzutil after libzfs. 2022-10-03 16:10:42 -07:00
sbin nvmecontrol: Fix condition when print number of Firmware Slots and Firmware Slot1 Readonly. 2022-11-15 07:48:20 +01:00
secure caroot: Update VCS instructions 2022-11-07 19:24:09 +08:00
share sendmail: remove leftovers from mta_start_script and rc.sendmail 2022-11-15 09:10:53 +01:00
stand Sort list of supported features for more easy handling 2022-11-10 09:47:23 +01:00
sys cxgbe: Enable TOE TLS RX when an RX key is provided via setsockopt(). 2022-11-15 12:08:51 -08:00
targets Put OPIE to rest. 2022-10-02 03:37:29 +02:00
tests ktls: Add tests for receiving corrupted or invalid records. 2022-11-15 12:03:19 -08:00
tools stress2: Added a new SU+J + snapshot test scenario 2022-11-14 12:03:57 +01:00
usr.bin tcp: account sent/received IP ECN markings independently 2022-11-10 11:35:35 +01:00
usr.sbin bhyve: add basl support for pointers 2022-11-15 08:27:11 +01:00
.arcconfig arcanist: use FreeBSD/git project repository instead of FreeBSD/svn 2022-08-23 14:16:41 +00:00
.arclint arc lint: ignore /tests/ in chmod 2017-12-19 03:38:06 +00:00
.cirrus.yml Cirrus-CI: move QEMU pkg installation to test script 2022-09-07 13:32:12 -04:00
.clang-format clang-format: Add bitset loop macros 2021-09-21 12:08:01 -04:00
.gitattributes Add a basic clang-format configuration file 2019-06-07 15:23:52 +00:00
.gitignore gitignore: Ignore compile_commands.events.json 2022-05-30 10:43:25 -04:00
COPYRIGHT Welcome 2022, update copyrights. 2022-01-01 09:49:49 -07:00
LOCKS LOCKS: update current locks 2018-06-09 03:08:04 +00:00
MAINTAINERS Remove myself from bhyve maintenance; ENOTIME. 2021-11-19 07:09:30 +10:00
Makefile Makefile: replace mergemaster references with etcupdate 2022-10-06 20:19:16 +02:00
Makefile.inc1 build: Use rm -fv for BATCH_DELETE_OLD_FILES 2022-10-25 11:18:55 -04:00
Makefile.libcompat Install working pkgconfig .pc files for compat libraries 2022-08-11 23:18:34 +01:00
Makefile.sys.inc AUTO_OBJ: For all top-level targets enforce using an OBJDIR. 2017-12-05 21:29:47 +00:00
ObsoleteFiles.inc othermta: remove leftover from 20 years ago 2022-11-14 09:08:37 +01:00
README.md README.md: link to the list of supported platforms 2022-11-01 12:20:55 -03:00
RELNOTES RELNOTE: Document the removal of mta_start_script and othermta 2022-11-14 09:12:33 +01:00
UPDATING UPDATING: correct spearate typo 2022-10-26 14:25:12 -04:00

FreeBSD Source:

This is the top level of the FreeBSD source directory.

FreeBSD is an operating system used to power modern servers, desktops, and embedded platforms. A large community has continually developed it for more than thirty years. Its advanced networking, security, and storage features have made FreeBSD the platform of choice for many of the busiest web sites and most pervasive embedded networking and storage devices.

For copyright information, please see the file COPYRIGHT in this directory. Additional copyright information also exists for some sources in this tree - please see the specific source directories for more information.

The Makefile in this directory supports a number of targets for building components (or all) of the FreeBSD source tree. See build(7), config(8), FreeBSD handbook on building userland, and Handbook for kernels for more information, including setting make(1) variables.

For information on the CPU architectures and platforms supported by FreeBSD, see the FreeBSD website's Platforms page.

Source Roadmap:

Directory Description
bin System/user commands.
cddl Various commands and libraries under the Common Development and Distribution License.
contrib Packages contributed by 3rd parties.
crypto Cryptography stuff (see crypto/README).
etc Template files for /etc.
gnu Commands and libraries under the GNU General Public License (GPL) or Lesser General Public License (LGPL). Please see gnu/COPYING and gnu/COPYING.LIB for more information.
include System include files.
kerberos5 Kerberos5 (Heimdal) package.
lib System libraries.
libexec System daemons.
release Release building Makefile & associated tools.
rescue Build system for statically linked /rescue utilities.
sbin System commands.
secure Cryptographic libraries and commands.
share Shared resources.
stand Boot loader sources.
sys Kernel sources (see sys/README.md).
targets Support for experimental DIRDEPS_BUILD
tests Regression tests which can be run by Kyua. See tests/README for additional information.
tools Utilities for regression testing and miscellaneous tasks.
usr.bin User commands.
usr.sbin System administration commands.

For information on synchronizing your source tree with one or more of the FreeBSD Project's development branches, please see FreeBSD Handbook.