git: 58031cbd54b8 - main - ipfw: cleanup !FreeBSD and !_KERNEL code

From: Gleb Smirnoff <glebius_at_FreeBSD.org>
Date: Fri, 18 Sep 2026 22:50:30 UTC
The branch main has been updated by glebius:

URL: https://cgit.FreeBSD.org/src/commit/?id=58031cbd54b8d6c4bb171f7f67d23b7d423ea7d7

commit 58031cbd54b8d6c4bb171f7f67d23b7d423ea7d7
Author:     Gleb Smirnoff <glebius@FreeBSD.org>
AuthorDate: 2026-09-18 22:49:10 +0000
Commit:     Gleb Smirnoff <glebius@FreeBSD.org>
CommitDate: 2026-09-18 22:50:23 +0000

    ipfw: cleanup !FreeBSD and !_KERNEL code
    
    These are leftovers from last import from Luigi Rizzo in 2013, that were
    never compiled checked since and lots of changes have had happened since
    and more changes to come.  Let's not pretend ipfw is buildable on
    something else than FreeBSD nor it can be compiled for userland.
    
    Reviewed by:            lytboris_gmail.com
    Differential Revision:  https://reviews.freebsd.org/D59427
---
 sys/netpfil/ipfw/dn_sched_qfq.c  | 20 --------------------
 sys/netpfil/ipfw/ip_dn_io.c      | 28 ----------------------------
 sys/netpfil/ipfw/ip_dn_private.h | 28 ----------------------------
 sys/netpfil/ipfw/ip_fw2.c        | 39 ---------------------------------------
 sys/netpfil/ipfw/ip_fw_log.c     |  5 -----
 5 files changed, 120 deletions(-)

diff --git a/sys/netpfil/ipfw/dn_sched_qfq.c b/sys/netpfil/ipfw/dn_sched_qfq.c
index 1f8ef86388e1..982742f8094f 100644
--- a/sys/netpfil/ipfw/dn_sched_qfq.c
+++ b/sys/netpfil/ipfw/dn_sched_qfq.c
@@ -66,31 +66,16 @@ static void dump_sched(struct qfq_sched *q, const char *msg);
 typedef	unsigned long	bitmap;
 
 /*
- * bitmaps ops are critical. Some linux versions have __fls
- * and the bitmap ops. Some machines have ffs
  * NOTE: fls() returns 1 for the least significant bit,
  *       __fls() returns 0 for the same case.
  * We use the base-0 version __fls() to match the description in
  * the ToN QFQ paper
  */
-#if defined(_WIN32) || (defined(__MIPSEL__) && defined(LINUX_24))
-int fls(unsigned int n)
-{
-	int i = 0;
-	for (i = 0; n > 0; n >>= 1, i++)
-		;
-	return i;
-}
-#endif
-
-#if !defined(_KERNEL) || defined( __FreeBSD__ ) || defined(_WIN32) || (defined(__MIPSEL__) && defined(LINUX_24))
 static inline unsigned long __fls(unsigned long word)
 {
 	return fls(word) - 1;
 }
-#endif
 
-#if !defined(_KERNEL) || !defined(__linux__)
 #ifdef QFQ_DEBUG
 static int test_bit(int ix, bitmap *p)
 {
@@ -116,11 +101,6 @@ static void __clear_bit(int ix, bitmap *p)
 #define __set_bit(ix, pData)	(*pData) |= (1<<(ix))
 #define __clear_bit(ix, pData)	(*pData) &= ~(1<<(ix))
 #endif /* !QFQ_DEBUG */
-#endif /* !__linux__ */
-
-#ifdef __MIPSEL__
-#define __clear_bit(ix, pData)	(*pData) &= ~(1<<(ix))
-#endif
 
 /*-------------------------------------------*/
 /*
diff --git a/sys/netpfil/ipfw/ip_dn_io.c b/sys/netpfil/ipfw/ip_dn_io.c
index 3a8de2b2bfee..818ec68f535c 100644
--- a/sys/netpfil/ipfw/ip_dn_io.c
+++ b/sys/netpfil/ipfw/ip_dn_io.c
@@ -256,34 +256,6 @@ dn_tag_get(struct mbuf *m)
 static inline void
 mq_append(struct mq *q, struct mbuf *m)
 {
-#ifdef USERSPACE
-	// buffers from netmap need to be copied
-	// XXX note that the routine is not expected to fail
-	ND("append %p to %p", m, q);
-	if (m->m_flags & M_STACK) {
-		struct mbuf *m_new;
-		void *p;
-		int l, ofs;
-
-		ofs = m->m_data - m->__m_extbuf;
-		// XXX allocate
-		MGETHDR(m_new, M_NOWAIT, MT_DATA);
-		ND("*** WARNING, volatile buf %p ext %p %d dofs %d m_new %p",
-			m, m->__m_extbuf, m->__m_extlen, ofs, m_new);
-		p = m_new->__m_extbuf;	/* new pointer */
-		l = m_new->__m_extlen;	/* new len */
-		if (l <= m->__m_extlen) {
-			panic("extlen too large");
-		}
-
-		*m_new = *m;	// copy
-		m_new->m_flags &= ~M_STACK;
-		m_new->__m_extbuf = p; // point to new buffer
-		_pkt_copy(m->__m_extbuf, p, m->__m_extlen);
-		m_new->m_data = p + ofs;
-		m = m_new;
-	}
-#endif /* USERSPACE */
 	if (q->head == NULL)
 		q->head = m;
 	else
diff --git a/sys/netpfil/ipfw/ip_dn_private.h b/sys/netpfil/ipfw/ip_dn_private.h
index 9a43b86791e0..8de0608afed3 100644
--- a/sys/netpfil/ipfw/ip_dn_private.h
+++ b/sys/netpfil/ipfw/ip_dn_private.h
@@ -451,34 +451,6 @@ int ecn_mark(struct mbuf* m);
 static inline void
 mq_append(struct mq *q, struct mbuf *m)
 {
-#ifdef USERSPACE
-	// buffers from netmap need to be copied
-	// XXX note that the routine is not expected to fail
-	ND("append %p to %p", m, q);
-	if (m->m_flags & M_STACK) {
-		struct mbuf *m_new;
-		void *p;
-		int l, ofs;
-
-		ofs = m->m_data - m->__m_extbuf;
-		// XXX allocate
-		MGETHDR(m_new, M_NOWAIT, MT_DATA);
-		ND("*** WARNING, volatile buf %p ext %p %d dofs %d m_new %p",
-			m, m->__m_extbuf, m->__m_extlen, ofs, m_new);
-		p = m_new->__m_extbuf;	/* new pointer */
-		l = m_new->__m_extlen;	/* new len */
-		if (l <= m->__m_extlen) {
-			panic("extlen too large");
-		}
-
-		*m_new = *m;	// copy
-		m_new->m_flags &= ~M_STACK;
-		m_new->__m_extbuf = p; // point to new buffer
-		_pkt_copy(m->__m_extbuf, p, m->__m_extlen);
-		m_new->m_data = p + ofs;
-		m = m_new;
-	}
-#endif /* USERSPACE */
 	if (q->head == NULL)
 		q->head = m;
 	else
diff --git a/sys/netpfil/ipfw/ip_fw2.c b/sys/netpfil/ipfw/ip_fw2.c
index 8c7b36740ab6..c1ae8bd9be1f 100644
--- a/sys/netpfil/ipfw/ip_fw2.c
+++ b/sys/netpfil/ipfw/ip_fw2.c
@@ -430,7 +430,6 @@ iface_match(struct ifnet *ifp, ipfw_insn_if *cmd, struct ip_fw_chain *chain,
 				return(1);
 		}
 	} else {
-#if !defined(USERSPACE) && defined(__FreeBSD__)	/* and OSX too ? */
 		struct ifaddr *ia;
 
 		NET_EPOCH_ASSERT();
@@ -442,7 +441,6 @@ iface_match(struct ifnet *ifp, ipfw_insn_if *cmd, struct ip_fw_chain *chain,
 			    (ia->ifa_addr))->sin_addr.s_addr)
 				return (1);	/* match */
 		}
-#endif /* __FreeBSD__ */
 	}
 	return(0);	/* no match, fail ... */
 }
@@ -471,9 +469,6 @@ iface_match(struct ifnet *ifp, ipfw_insn_if *cmd, struct ip_fw_chain *chain,
 static int
 verify_path(struct in_addr src, struct ifnet *ifp, u_int fib)
 {
-#if defined(USERSPACE) || !defined(__FreeBSD__)
-	return 0;
-#else
 	struct nhop_object *nh;
 
 	nh = fib4_lookup(fib, src, 0, NHR_NONE, 0);
@@ -500,7 +495,6 @@ verify_path(struct in_addr src, struct ifnet *ifp, u_int fib)
 
 	/* found valid route */
 	return 1;
-#endif /* __FreeBSD__ */
 }
 
 /*
@@ -1101,15 +1095,6 @@ static int
 check_uidgid(ipfw_insn_u32 *insn, struct ip_fw_args *args, int *ugid_lookupp,
     struct ucred **uc)
 {
-#if defined(USERSPACE)
-	return 0;	// not supported in userspace
-#else
-#ifndef __FreeBSD__
-	/* XXX */
-	return cred_check(insn, proto, oif,
-	    dst_ip, dst_port, src_ip, src_port,
-	    (struct bsd_ucred *)uc, ugid_lookupp, ((struct mbuf *)inp)->m_skb);
-#else  /* FreeBSD */
 	struct in_addr src_ip, dst_ip;
 	struct inpcbinfo *pi;
 	struct ipfw_flow_id *id;
@@ -1206,8 +1191,6 @@ check_uidgid(ipfw_insn_u32 *insn, struct ip_fw_args *args, int *ugid_lookupp,
 	else if (insn->o.opcode == O_JAIL)
 		match = ((*uc)->cr_prison->pr_id == (int)insn->d[0]);
 	return (match);
-#endif /* __FreeBSD__ */
-#endif /* not supported in userspace */
 }
 
 /*
@@ -1428,11 +1411,7 @@ ipfw_chk(struct ip_fw_args *args)
 	 * these types of constraints, as well as decrease contention
 	 * on pcb related locks.
 	 */
-#ifndef __FreeBSD__
-	struct bsd_ucred ucred_cache;
-#else
 	struct ucred *ucred_cache = NULL;
-#endif
 	uint32_t f_pos = 0;	/* index of current rule in the array */
 	int ucred_lookup = 0;
 	int retval = 0;
@@ -1989,11 +1968,7 @@ do {									\
 					match = check_uidgid(
 						    (ipfw_insn_u32 *)cmd,
 						    args, &ucred_lookup,
-#ifdef __FreeBSD__
 						    &ucred_cache);
-#else
-						    (void *)&ucred_cache);
-#endif
 				break;
 
 			case O_RECV:
@@ -2233,27 +2208,17 @@ do {									\
 					memcpy(key.mac, eh->ether_shost,
 					    sizeof(key.mac));
 					break;
-#ifndef USERSPACE
 				case LOOKUP_UID:
 				case LOOKUP_JAIL:
 					check_uidgid(insntod(cmd, u32),
 					    args, &ucred_lookup,
-#ifdef __FreeBSD__
 					    &ucred_cache);
 					if (lookup_type == LOOKUP_UID)
 						key.u32 = ucred_cache->cr_uid;
 					else if (lookup_type == LOOKUP_JAIL)
 						key.u32 = ucred_cache->cr_prison->pr_id;
-#else /* !__FreeBSD__ */
-					    (void *)&ucred_cache);
-					if (lookup_type == LOOKUP_UID)
-						key.u32 = ucred_cache.uid;
-					else if (lookup_type == LOOKUP_JAIL)
-						key.u32 = ucred_cache.xid;
-#endif /* !__FreeBSD__ */
 					keylen = sizeof(key.u32);
 					break;
-#endif /* !USERSPACE */
 				case LOOKUP_MARK:
 					key.u32 = args->rule.pkt_mark;
 					keylen = sizeof(key.u32);
@@ -2824,7 +2789,6 @@ do {									\
 				break;
 
 			case O_SOCKARG:	{
-#ifndef USERSPACE	/* not supported in userspace */
 				struct inpcb *inp = args->inp;
 				struct inpcbinfo *pi;
 				bool inp_locked = false;
@@ -2875,7 +2839,6 @@ do {									\
 					if (inp_locked)
 						INP_RUNLOCK(inp);
 				}
-#endif /* !USERSPACE */
 				break;
 			}
 
@@ -3561,10 +3524,8 @@ do {									\
 			send_reject(args, reject_code, reject_mtu,
 				    iplen, ip);
 	}
-#ifdef __FreeBSD__
 	if (ucred_cache != NULL)
 		crfree(ucred_cache);
-#endif
 	return (retval);
 
 pullup_failed:
diff --git a/sys/netpfil/ipfw/ip_fw_log.c b/sys/netpfil/ipfw/ip_fw_log.c
index 0f8a4df4e5d6..9b7dd15bd6eb 100644
--- a/sys/netpfil/ipfw/ip_fw_log.c
+++ b/sys/netpfil/ipfw/ip_fw_log.c
@@ -428,15 +428,10 @@ ipfw_log_syslog(struct ip_fw_chain *chain, struct ip_fw *f, u_int hlen,
 	else
 		mark_str[0] = '\0';
 
-#ifdef __FreeBSD__
 	log(LOG_SECURITY | LOG_INFO, "ipfw: %d %s %s%s %s via %s%s\n",
 	    f ? f->rulenum : -1, action, proto, mark_str,
 	    args->flags & IPFW_ARGS_OUT ? "out" : "in", args->ifp->if_xname,
 	    fragment);
-#else
-	log(LOG_SECURITY | LOG_INFO, "ipfw: %d %s %s%s [no if info]%s\n",
-	    f ? f->rulenum : -1, action, proto, mark_str, fragment);
-#endif
 	if (limit_reached)
 		log(LOG_SECURITY | LOG_NOTICE,
 		    "ipfw: limit %d reached on entry %d\n",