FreeBSD/ports f788767mail/exim Makefile distinfo

mail/exim: 4.100 -> 4.100.1

Security: GCVE-25-2026-09-50-1, GCVE-25-2026-09-51-1,
          GCVE-25-2026-09-55-1, GCVE-25-2026-09-56-1
Requested-by:   The Doctor <doctor at doctor.nl2k.ab.ca>
DeltaFile
+3-3mail/exim/distinfo
+1-1mail/exim/Makefile
+4-42 files

FreeBSD/ports 9c6668bx11/x-on-resize Makefile

x11/x-on-resize: Update to 0.3
DeltaFile
+1-2x11/x-on-resize/Makefile
+1-21 files

FreeBSD/ports 493c246x11-fonts/sudo-font Makefile distinfo

x11-fonts/sudo-font: Update to 3.6
DeltaFile
+0-40x11-fonts/sudo-font/pkg-plist
+3-3x11-fonts/sudo-font/distinfo
+1-1x11-fonts/sudo-font/Makefile
+4-443 files

FreeBSD/ports 4c3c030textproc/py-hjson distinfo Makefile

textproc/py-hjson: Update to 3.1.0
DeltaFile
+6-3textproc/py-hjson/Makefile
+3-3textproc/py-hjson/distinfo
+9-62 files

FreeBSD/ports e2251a2net/pimd distinfo Makefile, net/pimd/files patch-configure.ac patch-src_main.c

net/pimd: update to 3.1.0

troglobit/pimd, the upstream this port tracked, has not seen a commit since
August 2022 and its last release, 2.3.2, is from 2016. The port was pinned
to an unreleased master snapshot (2.3.2b, commit 17ae62f) because there was
nothing newer to move to.

This new fork continues the tree and releases from it. 3.1.0 brings
Anycast-RP (RFC 4610), accept-nbr-from and register-accept-from, and rescans
interfaces at runtime so a link that comes up after the daemon started becomes
a vif without a restart.
DeltaFile
+0-56net/pimd/files/patch-src_main.c
+6-13net/pimd/Makefile
+0-9net/pimd/files/patch-configure.ac
+3-5net/pimd/distinfo
+9-834 files

FreeBSD/ports aa4f53dtextproc/libxmlbird Makefile distinfo

textproc/libxmlbird: Update to 1.2.15
DeltaFile
+3-3textproc/libxmlbird/distinfo
+1-1textproc/libxmlbird/Makefile
+4-42 files

FreeBSD/ports 2a0bf0aemulators/edumips64 Makefile

emulators/edumips64: Return to pool
DeltaFile
+1-1emulators/edumips64/Makefile
+1-11 files

FreeBSD/ports f717c57www/browsh Makefile distinfo

www/browsh: Update to 1.8.3
DeltaFile
+77-9www/browsh/distinfo
+51-24www/browsh/Makefile
+128-332 files

FreeBSD/src 17af098usr.sbin/virtual_oss/virtual_oss main.c

Revert "virtual_oss(8): Fix cuse.ko check"

parse_options() was moved above cuse_init(), which makes every single
regular virtual_oss invocation which uses cuse_dev_create() fail.

This reverts commit f014795ec3bd5efb88dfc249599e9665dc10a59e.
DeltaFile
+5-11usr.sbin/virtual_oss/virtual_oss/main.c
+5-111 files

FreeBSD/src 73ce582sys/netpfil/pf pf_nl.c

pf: table_addr_parser parses to struct nl_parsed_table_addrs

Not to struct pfioc_table.

MFC after:      1 week
Sponsored by:   Rubicon Communications, LLC ("Netgate")
DeltaFile
+5-5sys/netpfil/pf/pf_nl.c
+5-51 files

FreeBSD/ports 81366c2deskutils/joplin-desktop Makefile, deskutils/podman-desktop Makefile

*/*: Bump port revision after electron42 update (7e2f1f94fca1)
DeltaFile
+1-1net-im/teams/Makefile
+1-1net-im/deltachat-desktop/Makefile
+1-1graphics/drawio/Makefile
+1-1deskutils/podman-desktop/Makefile
+1-1deskutils/joplin-desktop/Makefile
+1-0editors/vscode/Makefile
+6-56 files

FreeBSD/ports 7e2f1f9devel/electron42 Makefile.version distinfo, devel/electron42/files patch-gpu_command__buffer_service_shared__context__state.cc patch-electron_spec_chromium-spec.ts

devel/electron42: Update to 42.11.5

Changelog: https://github.com/electron/electron/releases/tag/v42.11.5

Reported by:    GitHub (watch releases)
DeltaFile
+7-7devel/electron42/distinfo
+5-5devel/electron42/files/patch-third__party_blink_renderer_platform_runtime__enabled__features.json5
+4-4devel/electron42/files/patch-gpu_command__buffer_service_shared__context__state.cc
+4-4devel/electron42/files/patch-electron_spec_chromium-spec.ts
+1-1devel/electron42/Makefile.version
+21-215 files

FreeBSD/ports 737bafatextproc/apache-poi Makefile

textproc/apache-poi: Remove NO_EXTRACT

It has no effect anymore, so clean it up.
DeltaFile
+0-1textproc/apache-poi/Makefile
+0-11 files

FreeBSD/ports cf1ff70www/angie distinfo, www/angie-module-jwt Makefile

www/angie-module-jwt: Update to 3.4.6

This bugfix release fixes the module's test suite:

test_conf forwarded an unquoted $@, so the expected message was split
on spaces and only its first word was ever grepped. Two expectations
were pointing at the wrong configuration file, unnoticed.

PR:             298635
Changes:        https://github.com/max-lt/nginx-jwt-module/releases/tag/v3.4.6
Sponsored by:   Netzkommune GmbH
DeltaFile
+2-2www/angie/distinfo
+2-2www/angie-module-jwt/Makefile
+4-42 files

FreeBSD/ports e62eab7www/angie distinfo, www/angie-module-auth-jwt Makefile

www/angie-module-auth-jwt: Update to 0.15.0

This new release adds the nxe-phase submodule and bumps the version of
nxe-jwx from 0.2.0 to 0.4.0.

PR:             298634
Changes:        https://github.com/kjdev/nginx-auth-jwt/releases
Sponsored by:   Netzkommune GmbH
DeltaFile
+6-4www/angie/distinfo
+4-3www/angie-module-auth-jwt/Makefile
+10-72 files

FreeBSD/ports 2c7dcffwww/angie distinfo, www/angie-module-njs Makefile

www/angie-module-njs: Security update to 1.0.1

This maintenance update of njs fixes three security issues:

- Access control bypass in js_access when an asynchronous request body
  continuation threw an exception or produced an unhandled rejection
  (CVE-2026-18329). Previously, nginx could continue processing the
  request as though the js_access check had succeeded. Affects
  0.9.9-1.0.0. Thanks to Ta Duc Thien.

- Worker process crash when reading Response.statusText after an
  upstream server returned a status line with an empty reason phrase
  (CVE-2026-78222). Affects 0.5.1-1.0.0.

- Heap buffer overflow while parsing namespace prefix lists passed to
  xml.exclusiveC14n() (CVE-2026-78689). Affects 0.7.10-1.0.0. Thanks to
  Vladimir, Vulnerability Research Tech Lead @ Cyera, evilgensec.

PR:             298637

    [3 lines not shown]
DeltaFile
+2-2www/angie/distinfo
+2-2www/angie-module-njs/Makefile
+4-42 files

FreeBSD/ports 1fa3fa2www/angie Makefile distinfo, www/angie-module-set-misc Makefile

www/angie: Security update to 1.12.2

This maintenance release fixes CVE-2026-90439:

When using an OpenSSL version without native HTTP/3 support (3.5.0
or earlier), if the default server for the address that accepted a
regular HTTPS request also used HTTP/3 (the listen directive with the
quic parameter, possibly on a different port), while a server block
without HTTP/3 was selected by domain name (SNI), limited worker process
memory corruption or a worker process crash could occur
(CVE-2026-90439); the fix was ported from nginx 1.31.6.

PR:             298632
Changes:        https://en.angie.software/angie/docs/oss_changes/#angie-1-12-2
Security:       6cf2ff4b-b38c-11f1-a655-3497f65b111b
Sponsored by:   Netzkommune GmbH
DeltaFile
+3-3www/angie/distinfo
+1-1www/angie/Makefile
+1-1www/angie-module-zstd/Makefile
+1-1www/angie-module-vod/Makefile
+1-1www/angie-module-upload/Makefile
+1-1www/angie-module-set-misc/Makefile
+8-818 files not shown
+26-2624 files

FreeBSD/ports c13e642www/angie distinfo, www/angie-module-vod Makefile

www/angie-module-vod: Update to 1.9.3

Bug fixes in this update:
1.9.2:
 - Fix code scanning alerts
1.9.3:
 - Fix reference_count size in sidx64 atom
 - Fix media set string array parsing

PR:             298633
Changes:        https://github.com/dio-az/nginx-vod-module/releases
Sponsored by:   Netzkommune GmbH
DeltaFile
+2-2www/angie/distinfo
+2-2www/angie-module-vod/Makefile
+4-42 files

FreeBSD/ports 3d84f52devel/remotery Makefile distinfo, devel/remotery/files patch-sample_sample.c

devel/remotery: Update to 1.2.1
DeltaFile
+18-1devel/remotery/pkg-plist
+2-4devel/remotery/Makefile
+3-3devel/remotery/files/patch-sample_sample.c
+3-3devel/remotery/distinfo
+26-114 files

FreeBSD/ports 7329c42textproc/rubygem-jekyll-archives Makefile

textproc/rubygem-jekyll-archives: Return to pool
DeltaFile
+1-1textproc/rubygem-jekyll-archives/Makefile
+1-11 files

FreeBSD/doc 1725167website/content/en/releases/13.5R readme.adoc, website/content/en/releases/14.3R readme.adoc

fix typo in release docs (releasePrev number)

Approved by: re (implicit)
DeltaFile
+1-1website/content/en/releases/15.2R/readme.adoc
+1-1website/content/en/releases/14.5R/readme.adoc
+1-1website/content/en/releases/14.3R/readme.adoc
+1-1website/content/en/releases/13.5R/readme.adoc
+4-44 files

FreeBSD/ports 2c581f7textproc/rubygem-jekyll-archives Makefile distinfo

textproc/rubygem-jekyll-archives: Update to 2.3.0

While here, return to pool.
DeltaFile
+3-3textproc/rubygem-jekyll-archives/distinfo
+1-1textproc/rubygem-jekyll-archives/Makefile
+4-42 files

FreeBSD/src 47cf9dcsys/dev/sound/pcm mixer.c

sound: Lock around mixer_set*() in mixer_init() for consistency

Sponsored by:   The FreeBSD Foundation
MFC after:      1 month
Differential Revision:  https://reviews.freebsd.org/D59110
DeltaFile
+5-0sys/dev/sound/pcm/mixer.c
+5-01 files

FreeBSD/src 044ef29sys/dev/sound/pcm mixer.c

sound: Remove unncessary locking in sysctl_hw_snd_hwvol_mixer()

The locking around strlcpy() was because of m->hwvol_mixer, but this is
just an int, so we don't need to lock in this case. Instead lock only
when m->hwvol_mixer is written.

While here, add parentheses around the returns.

Sponsored by:   The FreeBSD Foundation
MFC after:      1 month
Differential Revision:  https://reviews.freebsd.org/D59109
DeltaFile
+6-12sys/dev/sound/pcm/mixer.c
+6-121 files

FreeBSD/src db62d78sys/dev/sound/pcm mixer.c

sound: Improve some mixer return values and their handling

Sponsored by:   The FreeBSD Foundation
MFC after:      1 month
Differential Revision:  https://reviews.freebsd.org/D59078
DeltaFile
+10-10sys/dev/sound/pcm/mixer.c
+10-101 files

FreeBSD/src 6c73547sys/dev/sound/pcm mixer.c

sound: Reuse mixer_delete() in mixer_uninit()

Sponsored by:   The FreeBSD Foundation
MFC after:      1 month
Differential Revision:  https://reviews.freebsd.org/D59077
DeltaFile
+1-7sys/dev/sound/pcm/mixer.c
+1-71 files

FreeBSD/ports 15f27bdtextproc/py-restructuredtext-lint distinfo Makefile

textproc/py-restructuredtext-lint: Update to 2.0.2
DeltaFile
+6-4textproc/py-restructuredtext-lint/Makefile
+3-3textproc/py-restructuredtext-lint/distinfo
+9-72 files

FreeBSD/src 03b59d2sys/dev/sound/pcm mixer.c

sound: Do not set a recording source in mixer_uninit()

We currently set the recording source to SOUND_MIXER_MIC during mixer
deletion. Apart from the fact that this control might not be present on
all devices, it is unnecessary to do that, plus we already set all the
volumes to 0 in the mixer_set() call above.

Sponsored by:   The FreeBSD Foundation
MFC after:      1 month
Differential Revision:  https://reviews.freebsd.org/D59076
DeltaFile
+0-2sys/dev/sound/pcm/mixer.c
+0-21 files

FreeBSD/src 9548bfasys/dev/sound/pcm mixer.h mixer.c, sys/dev/sound/usb uaudio.c

sound: Retire mixer_hwvol locked variants

Prior to 9a00e0b8ca56 ("snd_uaudio: Do not use snd_mixer->lock as
mixer_lock"), there was a need for mixer_hwvol_mute_locked() and
mixer_hwvol_step_locked(), because the unlocked variants would acquire
the lock, but uaudio_hid_rx_callback() would also hold the lock, so this
was a measure to avoid recursion on snd_mixer->lock. Now that
snd_uaudio(4) has a private mixer lock, the locked variants are not only
unnecessary, but wrong, because we now lock the private lock and not the
snd_mixer one, which is what mixer_hwvol_mute_locked() and
mixer_hwvol_step_locked() expect. Retire the locked variants and call
the regular functions instead.

The unlocked variants take the mixer lock, which is now the PCM lock,
and reach uaudio_mixer_ctl_set(), which takes mixer_lock. Calling them
straight from uaudio_hid_rx_callback() would therefore take mixer_lock
and the PCM lock in the opposite order to the mixer ioctl path, so
record what the HID report asked for and perform the volume change at
the end of the callback, with mixer_lock dropped. The USB stack allows a

    [5 lines not shown]
DeltaFile
+28-3sys/dev/sound/usb/uaudio.c
+5-19sys/dev/sound/pcm/mixer.c
+0-2sys/dev/sound/pcm/mixer.h
+33-243 files

FreeBSD/src 1a31ab1sys/dev/sound/pcm mixer.h channel.c

sound: Use snddev_info->lock in place of snd_mixer->lock

snd_mixer and snddev_info have a 1:1 relationship. Now that snd_mixer is
embedded into snddev_info, it makes even more sense for both to share
the PCM lock. The only exceptions to this are MIXER_TYPE_SECONDARY
mixers, which still retain a private lock (snd_mixer->priv_lock),
because they are attached to the device driver, and not snddev_info.
Only snd_emu10kx(4) uses a secondary mixer.

A side-effect of this is that the MIXER_SET_LOCK()/MIXER_SET_UNLOCK()
mess goes away. These macros were used in the mixer_set*() functions to
drop the mixer lock if the driver is Giant-locked and the function can
sleep inside MIXER_SET*() methods, and to avoid an LOR before locking
PCM to guard channel list traversal.

Since mixers now use the PCM lock, drop the channel lock in
chn_syncstate() before calling mix_get(), to avoid an LOR. These lines
were actually already commented out for years.


    [3 lines not shown]
DeltaFile
+46-123sys/dev/sound/pcm/mixer.c
+4-4sys/dev/sound/pcm/channel.c
+2-1sys/dev/sound/pcm/mixer.h
+52-1283 files