FreeBSD/ports 344a598www/gitea Makefile distinfo

www/gitea: Security update 1.27.2 => 1.27.3

Release Notes:
https://blog.gitea.com/release-of-1.27.3/

PR:             298072
Approved by:    ports at foss-daily.org (maintainer timeout, 2 weeks)
Approved by:    osa, vvd (Mentors, implicit)
Security:       CVE-2026-66877
Security:       CVE-2026-71184
Security:       CVE-2026-68957
Security:       CVE-2026-60010
Security:       CVE-2026-70406
Security:       CVE-2026-63792
Security:       CVE-2026-66874
Security:       CVE-2026-68964
Security:       CVE-2026-67577
Security:       CVE-2026-66849
Security:       CVE-2026-73135

    [18 lines not shown]
DeltaFile
+3-3www/gitea/distinfo
+1-2www/gitea/Makefile
+4-52 files

FreeBSD/ports 8d487eawww/gitea Makefile distinfo

www/gitea: Security update 1.27.2 => 1.27.3

Release Notes:
https://blog.gitea.com/release-of-1.27.3/

PR:             298072
Approved by:    ports at foss-daily.org (maintainer timeout, 2 weeks)
Approved by:    osa, vvd (Mentors, implicit)
Security:       CVE-2026-66877
Security:       CVE-2026-71184
Security:       CVE-2026-68957
Security:       CVE-2026-60010
Security:       CVE-2026-70406
Security:       CVE-2026-63792
Security:       CVE-2026-66874
Security:       CVE-2026-68964
Security:       CVE-2026-67577
Security:       CVE-2026-66849
Security:       CVE-2026-73135

    [16 lines not shown]
DeltaFile
+3-3www/gitea/distinfo
+1-2www/gitea/Makefile
+4-52 files

FreeBSD/ports f8ffacanet-im/telegram-desktop Makefile distinfo

net-im/telegram-desktop: update to 7.2.8 release (+)

Drop unneeded dependecy on protobuf [1]

PR:             298401 [1]
Release notes:  https://github.com/telegramdesktop/tdesktop/releases/tag/v7.2.8
DeltaFile
+3-3net-im/telegram-desktop/distinfo
+1-2net-im/telegram-desktop/Makefile
+4-52 files

FreeBSD/ports 291949enet-im/tg_owt Makefile

net-im/tg_owt: drop unneeded dependency on protobuf

PR:     298401
DeltaFile
+1-1net-im/tg_owt/Makefile
+1-11 files

FreeBSD/ports d069603devel/sem Makefile.crates Makefile

devel/sem: Update to 0.25.0
DeltaFile
+5-3devel/sem/distinfo
+1-2devel/sem/Makefile
+1-0devel/sem/Makefile.crates
+7-53 files

FreeBSD/ports 23b3990sysutils/ngbuddy Makefile distinfo

sysutils/ngbuddy: Update 1.0 => 1.1

This update also corrects rc.d service order
reported by feld@ in PR 298188.

While here, update maintainer address.

Commit log:
https://github.com/bellhyve/ngbuddy/compare/v1.0...v1.1

PR:             298371
Approved by:    osa, vvd (Mentors, implicit)
MFH:            2026Q3

(cherry picked from commit 9daead358475786175c3d923c4d8812179895800)
DeltaFile
+3-3sysutils/ngbuddy/distinfo
+2-2sysutils/ngbuddy/Makefile
+5-52 files

FreeBSD/ports 9daead3sysutils/ngbuddy Makefile distinfo

sysutils/ngbuddy: Update 1.0 => 1.1

This update also corrects rc.d service order
reported by feld@ in PR 298188.

While here, update maintainer address.

Commit log:
https://github.com/bellhyve/ngbuddy/compare/v1.0...v1.1

PR:             298371
Approved by:    osa, vvd (Mentors, implicit)
MFH:            2026Q3
DeltaFile
+3-3sysutils/ngbuddy/distinfo
+2-2sysutils/ngbuddy/Makefile
+5-52 files

FreeBSD/ports 4cc3bf3www/mod_auth_openidc Makefile distinfo

www/mod_auth_openidc: Update to 2.4.20.3
DeltaFile
+3-3www/mod_auth_openidc/distinfo
+1-1www/mod_auth_openidc/Makefile
+4-42 files

FreeBSD/ports 33f2affwww/lexbor Makefile distinfo

www/lexbor: Update 3.0.0 => 3.0.1
DeltaFile
+3-3www/lexbor/distinfo
+1-1www/lexbor/Makefile
+4-42 files

FreeBSD/ports afb021anet/krakend-ce Makefile distinfo

net/krakend-ce: Update 2.13.10 => 2.13.11
DeltaFile
+5-5net/krakend-ce/distinfo
+1-2net/krakend-ce/Makefile
+6-72 files

FreeBSD/ports 1a43a61devel/rustup-init Makefile Makefile.crates, devel/rustup-init/files patch-Cargo.toml patch-Cargo.lock

devel/rustup-init: Update 1.28.1 => 1.29.1

While here:
- Add linked libraries from `ldd` output to LIB_DEPENDS.
- Unbundle OpenSSL.
- Add TESTING_UNSAFE.

Changelog:
https://github.com/rust-lang/rustup/blob/1.29.1/CHANGELOG.md

PR:             298213
Approved by:    osa, vvd (Mentors, implicit)
Co-authored-by: Ian Wagner <ianthetechie at gmail.com>
DeltaFile
+537-597devel/rustup-init/distinfo
+267-297devel/rustup-init/Makefile.crates
+26-0devel/rustup-init/files/patch-Cargo.lock
+20-4devel/rustup-init/Makefile
+11-0devel/rustup-init/files/patch-Cargo.toml
+861-8985 files

FreeBSD/src 9a46a14sys/dev/acpica acpi_cpu.c

acpi_cpu: only report unmapped processor objects enabled in the MADT

Firmware expose a DSDT sized for the largest SKU of the platform,
so a verbose boot prints an "ignored" line for every vacant
processor slot. A vacant slot has no enabled MADT entry; a CPU that
failed to come online does.

Reviewed by:    olce, adrian
Differential Revision:  https://reviews.freebsd.org/D59551
DeltaFile
+62-3sys/dev/acpica/acpi_cpu.c
+62-31 files

FreeBSD/src dd9e49ashare/man/man4 Makefile intel_pmc.4, sys/conf files.x86

intel/intelpmc: Add Intel PMC Core driver

Add driver for Intel Power Management Controller (PMC) found on Sunrise Point PCH chipsets.
This device exposes S0ix sleep state residency counters and power management status.

Sysctls provided:
  dev.intelpmc.0.slp_s0_residency_us - Time in deepest sleep (us)
  dev.intelpmc.0.ltr_ignore          - LTR ignore mask
  dev.intelpmc.0.pm_cfg              - PM configuration register
  dev.intelpmc.0.pm_sts              - PM status register
  dev.intelpmc.0.access_denied       - Firmware lock status

Supported devices for now:
  - Sunrise Point-LP (0x9D21)
  - Sunrise Point-H (0xA121)

Note: Later PCH generations (Cannon Lake, Tiger Lake, ect.) have different PMC register layouts according to the datasheet and would need per-generation tables.
I avoided adding untested hardware in case they have a quirk.


    [2 lines not shown]
DeltaFile
+219-0sys/dev/intel/intel_pmc.c
+83-0share/man/man4/intel_pmc.4
+6-0sys/modules/intel_pmc/Makefile
+2-0sys/modules/Makefile
+1-0sys/conf/files.x86
+1-0share/man/man4/Makefile
+312-06 files

FreeBSD/ports 7431ef2editors/libreoffice Makefile, editors/libreoffice/files patch-external_skia_Library__skia.mk patch-vcl_source_app_salplug.cxx

editors/libreoffice: fix some crashes and VCL selection (+)

* Fix crash with SAL_USE_VCLPLUGIN=gen and enabled Skia [1]
* Allow Qt VCL plugin when LO started outside the known DE (e.g., pure X) [2]

PR:     298257 [1], 298227, [2]
DeltaFile
+15-3editors/libreoffice/files/patch-vcl_source_app_salplug.cxx
+11-2editors/libreoffice/files/patch-external_skia_Library__skia.mk
+1-1editors/libreoffice/Makefile
+27-63 files

FreeBSD/ports 4376c51devel Makefile, devel/py-mockito pkg-descr distinfo

devel/py-mockito: new port
DeltaFile
+23-0devel/py-mockito/Makefile
+3-0devel/py-mockito/distinfo
+1-0devel/Makefile
+1-0devel/py-mockito/pkg-descr
+28-04 files

FreeBSD/ports 72c206cdevel/py-tzdata Makefile distinfo

devel/py-tzdata: Update to 2026.4

Approved by:    kai (maintainer via email)
DeltaFile
+3-3devel/py-tzdata/distinfo
+1-1devel/py-tzdata/Makefile
+4-42 files

FreeBSD/ports 61cd62atextproc/py-zensical Makefile distinfo

textproc/py-zensical: Update to 0.0.62

Approved by:    kai (maintainer via email)
DeltaFile
+3-3textproc/py-zensical/distinfo
+1-1textproc/py-zensical/Makefile
+4-42 files

FreeBSD/ports 0a61592security/vuxml/vuln 2026.xml

security/vuxml: Document multiple strongSwan vulnerabilities

PR:             298372
Sponsored by:   Rubicon Communications, LLC ("Netgate")
DeltaFile
+78-0security/vuxml/vuln/2026.xml
+78-01 files

FreeBSD/src 416611fsys/cam/nvme nvme_da.c, sys/dev/nvme nvme_ns.c

nvme: reject namespaces formatted with metadata

The active LBA format's MS field was never examined. I/O to a
metadata-formatted namespace carries neither interleaved metadata
nor MPTR, so every command is malformed, yet the namespace attaches
as a disk with the wrong sector size.

Reviewed by:    imp, adrian
Differential Revision:  https://reviews.freebsd.org/D59625
DeltaFile
+9-0sys/dev/nvme/nvme_ns.c
+9-0sys/cam/nvme/nvme_da.c
+18-02 files

FreeBSD/ports 57d4f61science/py-tensorflow distinfo Makefile, science/py-tensorflow/files bazelrc

science/py-tensorflow: Fix build

It was broken since with the last update of jsoncpp
its headers were pushed into include/jsoncpp.

Reported by:    fallout
DeltaFile
+9-5science/py-tensorflow/Makefile
+10-1science/py-tensorflow/files/freebsd/cc_toolchain_config.bzl
+2-0science/py-tensorflow/files/bazelrc
+0-1science/py-tensorflow/distinfo
+21-74 files

FreeBSD/ports 28b521dsecurity/strongswan Makefile pkg-plist, security/strongswan/files patch-conf_Makefile.in patch-src_libcharon_plugins_smp_smp.c

security/strongswan: Update 6.0.7 => 6.1.0

Changelog:
https://github.com/strongswan/strongswan/releases/tag/6.1.0

PR:             298372
MFH:            2026Q3
Security:       CVE-2026-78123
Security:       CVE-2026-78124
Security:       CVE-2026-78126
Security:       CVE-2026-78127
Security:       CVE-2026-78129
Security:       CVE-2026-78130
Security:       CVE-2026-78131
Security:       CVE-2026-78132
Security:       CVE-2026-78133
Security:       CVE-2026-78134
Security:       CVE-2026-78135
Sponsored by:   Rubicon Communications, LLC ("Netgate")

    [2 lines not shown]
DeltaFile
+0-23security/strongswan/files/patch-src_libcharon_plugins_smp_smp.c
+3-3security/strongswan/distinfo
+0-5security/strongswan/pkg-plist
+2-2security/strongswan/files/patch-conf_Makefile.in
+2-2security/strongswan/Makefile
+7-355 files

FreeBSD/ports 5a7f758security/strongswan pkg-plist Makefile, security/strongswan/files patch-conf_Makefile.in patch-src_libcharon_plugins_smp_smp.c

security/strongswan: Update 6.0.7 => 6.1.0

Changelog:
https://github.com/strongswan/strongswan/releases/tag/6.1.0

PR:             298372
MFH:            2026Q3
Security:       CVE-2026-78123
Security:       CVE-2026-78124
Security:       CVE-2026-78126
Security:       CVE-2026-78127
Security:       CVE-2026-78129
Security:       CVE-2026-78130
Security:       CVE-2026-78131
Security:       CVE-2026-78132
Security:       CVE-2026-78133
Security:       CVE-2026-78134
Security:       CVE-2026-78135
Sponsored by:   Rubicon Communications, LLC ("Netgate")
DeltaFile
+0-23security/strongswan/files/patch-src_libcharon_plugins_smp_smp.c
+3-3security/strongswan/distinfo
+0-5security/strongswan/pkg-plist
+2-3security/strongswan/Makefile
+2-2security/strongswan/files/patch-conf_Makefile.in
+7-365 files

FreeBSD/ports 2a88a73x11-fm/thunar Makefile distinfo

x11-fm/thunar: Update to 4.20.10
DeltaFile
+3-3x11-fm/thunar/distinfo
+1-1x11-fm/thunar/Makefile
+4-42 files

FreeBSD/src a22eb75sys/dev/tpm tpm_tis_core.c

tpm_tis: Quiesce interrupts before registering a handler

The current interrupt path uses the IRQ resource value directly as the
LPC SIRQ selector in TPM_INT_VECTOR and already restricts it to 1 through
15. This is a driver limitation: a parent interrupt number need not equal
an LPC SIRQ channel, and SPI TPMs can use a separate parallel interrupt.

On the reported system with ACPI IRQ 45, the existing range check runs
after handler registration and returns before disabling firmware interrupt
delivery. This can leave a polling device with a handler on an asserted
source.

Disable and verify interrupt delivery before registering a handler or
starting common TPM services. Preserve the existing range policy, using
polling without registering a handler for routes rejected by that check,
and release their IRQ resources. Keep a failed setup's potentially stale
output cookie out of the device state; the interrupt framework may
already have removed that handler.


    [19 lines not shown]
DeltaFile
+90-23sys/dev/tpm/tpm_tis_core.c
+90-231 files

FreeBSD/ports 44f8819graphics/shotwell distinfo pkg-plist, graphics/shotwell/files patch-meson.build

graphics/shotwell: update to 33.0

Release Notes:
  https://gitlab.gnome.org/GNOME/shotwell/-/blob/33.0/NEWS?ref_type=tags
DeltaFile
+12-12graphics/shotwell/Makefile
+20-0graphics/shotwell/files/patch-meson.build
+5-8graphics/shotwell/pkg-plist
+3-3graphics/shotwell/distinfo
+40-234 files

FreeBSD/src a6b40d7sys/compat/linuxkpi/common/include/linux scatterlist.h, sys/compat/linuxkpi/common/src linux_pci.c

LinuxKPI: Add dma_length field to struct scatterlist

On Linux `dma_length` field of `struct scatterlist` is present on the
arches where DMA mapping code is able to coalesce adjacent segments
of physical address space. It contains total length of coalesced
segments while `length` field contains non-coalesced length of each
segment. On other arches `dma_length` is aliased to `length` field with
`sg_dma_len` macro. As FreeBSD does not merge scatterlist segments it
do not have `dma_length` field. It is appered that at least i915kms
driver depends on existence of `dma_length` field.

Add the field and disable it by default. To enable add to Makefile

.if ${MACHINE_CPUARCH} == "i386" || ${MACHINE_CPUARCH} == "amd64" || \\
    ${MACHINE_CPUARCH} == "aarch64" || ${MACHINE_CPUARCH} == "powerpc"
CFLAGS+=        -DCONFIG_NEED_SG_DMA_LENGTH
.endif

Reported by:    Ryan Fahy

    [4 lines not shown]
DeltaFile
+17-9sys/compat/linuxkpi/common/include/linux/scatterlist.h
+1-0sys/compat/linuxkpi/common/src/linux_pci.c
+18-92 files

FreeBSD/ports c77b145science/ttk Makefile distinfo, science/ttk/files envs.sh patch-core_vtk_ttkWRLExporter_ttkWRLExporter.cpp

science/ttk: update 1.3.0 → 1.4.0
DeltaFile
+241-2science/ttk/pkg-plist
+0-57science/ttk/files/patch-core_vtk_ttkWRLExporter_ttkWRLExporter.cpp
+15-0science/ttk/pkg-message
+3-3science/ttk/distinfo
+3-2science/ttk/Makefile
+2-0science/ttk/files/envs.sh
+264-646 files

FreeBSD/ports fde655cwww/hedgedoc distinfo pkg-descr, www/hedgedoc/files pkg-message.in hedgedoc.in

www/hedgedoc: Add new port

The best platform to write and share markdown.

HedgeDoc (formerly known as CodiMD) is an open-source, web-based,
self-hosted, collaborative markdown editor.

You can use it to easily collaborate on notes, graphs and even
presentations in real-time. All you need to do is to share your
note-link to your co-workers and they're ready to go.

...

This brings back www/hedgedoc which was removed a while back because of
the node.js version on tree.
DeltaFile
+53,785-0www/hedgedoc/pkg-plist
+115-0www/hedgedoc/Makefile
+54-0www/hedgedoc/files/hedgedoc.in
+40-0www/hedgedoc/files/pkg-message.in
+8-0www/hedgedoc/pkg-descr
+5-0www/hedgedoc/distinfo
+54,007-02 files not shown
+54,008-18 files

FreeBSD/ports 87e2831net-im/signal-desktop get_deps.sh Makefile, net-im/signal-desktop/files patch-ts_components_Preferences.dom.tsx pnpm-lock.yaml

net-im/signal-desktop: Update to 8.27.0
DeltaFile
+1,078-659net-im/signal-desktop/files/pnpm-lock.yaml
+5-5net-im/signal-desktop/distinfo
+2-2net-im/signal-desktop/files/patch-ts_components_Preferences.dom.tsx
+1-2net-im/signal-desktop/Makefile
+1-1net-im/signal-desktop/get_deps.sh
+1,087-6695 files

FreeBSD/ports 817a69fsecurity/vuxml/vuln 2026.xml

security/vuxml: document irc/znc vulnerabilities
DeltaFile
+36-0security/vuxml/vuln/2026.xml
+36-01 files