FreeBSD/ports b163bb5 — net/samba424 Makefile, net/samba424/files patch-source3_modules_vfs__freebsd.c

net/samba424: fix sys_proc_fd_path() buffer type in vfs_freebsd.c

At all 5 call sites, vfs_freebsd.c declared a plain "char buf[PATH_MAX]"
and passed its address to sys_proc_fd_path(fd, &buf). Samba 4.24
changed that function's signature to
"char *sys_proc_fd_path(int fd, struct sys_proc_fd_path_buf *buf)",
so "&buf" here has type "char (*)[PATH_MAX]", not the expected
"struct sys_proc_fd_path_buf *" - a type mismatch left over from an
incomplete migration of this patch to the new API (the sibling
patch-source3_modules_vfs__zfsacl.c was already updated correctly).

Change all 5 declarations to "struct sys_proc_fd_path_buf buf;" to
match the current signature.

PR:     298884
Co-Authored-By: Claude Sonnet 5 <noreply at anthropic.com>
Approved by:    samba (kiwi)
DeltaFile
+5-5net/samba424/files/patch-source3_modules_vfs__freebsd.c
+1-1net/samba424/Makefile
+6-62 files

FreeBSD/doc ca416e3 — website/content/en/cgi ports.cgi

ports.cgi: fix HTML errors
DeltaFile
+2-2website/content/en/cgi/ports.cgi
+2-21 files

FreeBSD/ports a7c965b — sysutils/lxqt-qtplugin Makefile

sysutils/lxqt-qtplugin: Schedule for removal

Depends on deprecated libdbusmenu-qt.

PR:             298946, 298957
Approved by:    acm
DeltaFile
+4-0sysutils/lxqt-qtplugin/Makefile
+4-01 files

FreeBSD/ports d820a7f — textproc/groff Makefile distinfo

textproc/groff: Security update 1.24.1 => 1.24.2 (CWE-78)

This release resolves the following issues in the GNU Savannah ticket
tracker.

bug #68689: [PATCH] [mm] `mmroff` vulnerable to command injection (CWE-78)
bug #68688: [PATCH] [grohtml] `pre-grohtml` vulnerable to command injection (CWE-78)
bug #68687: [PATCH] [pdfmom] vulnerable to command injection (CWE-78)
bug #68152: [gxditview] SEGVs when invoked with no arguments

WWW:            https://lists.gnu.org/archive/html/info-groff/2026-09/msg00000.html
MFH:            2026Q3
(cherry picked from commit ec5b9d646d4ab9334f3a41b4fb2fbae215420448)
DeltaFile
+3-3textproc/groff/distinfo
+2-3textproc/groff/Makefile
+5-62 files

FreeBSD/ports ec5b9d6 — textproc/groff Makefile distinfo

textproc/groff: Security update 1.24.1 => 1.24.2 (CWE-78)

This release resolves the following issues in the GNU Savannah ticket
tracker.

bug #68689: [PATCH] [mm] `mmroff` vulnerable to command injection (CWE-78)
bug #68688: [PATCH] [grohtml] `pre-grohtml` vulnerable to command injection (CWE-78)
bug #68687: [PATCH] [pdfmom] vulnerable to command injection (CWE-78)
bug #68152: [gxditview] SEGVs when invoked with no arguments

WWW:            https://lists.gnu.org/archive/html/info-groff/2026-09/msg00000.html
MFH:            2026Q3
DeltaFile
+3-3textproc/groff/distinfo
+2-3textproc/groff/Makefile
+5-62 files

FreeBSD/doc 4599cb8 — website/content/en/cgi cgi-style-responsive.pl

cgi: sync style and links from the main static website
DeltaFile
+29-28website/content/en/cgi/cgi-style-responsive.pl
+29-281 files

FreeBSD/ports 28117ea — net/rustconn Makefile Makefile.crates

net/rustconn: Update to 0.22.9

ChangeLog:

1. https://github.com/totoshko88/RustConn/releases/tag/v0.22.8
2. https://github.com/totoshko88/RustConn/releases/tag/v0.22.9

Reported by:    "github-actions[bot]" <notifications at github.com>
DeltaFile
+7-7net/rustconn/distinfo
+2-2net/rustconn/Makefile.crates
+1-1net/rustconn/Makefile
+10-103 files

FreeBSD/ports da28c3f — archivers/libszip Makefile, audio/artyfx-lv2 Makefile

*/*: CMake 4 compatibility

PR:     295319
DeltaFile
+3-1devel/libcsptr/Makefile
+2-0devel/termcolor/Makefile
+2-0devel/gcem/Makefile
+2-0audio/artyfx-lv2/Makefile
+2-0archivers/libszip/Makefile
+1-0net/zyre/Makefile
+12-18 files not shown
+20-114 files

FreeBSD/ports 06fa617 — audio/fabla2-lv2 distinfo Makefile

audio/fabla2-lv2: update g20180331 → g20240803
DeltaFile
+6-4audio/fabla2-lv2/Makefile
+3-3audio/fabla2-lv2/distinfo
+9-72 files

FreeBSD/ports b1f10ca — devel Makefile, devel/libftdi distinfo pkg-descr

devel/libftdi: remove
DeltaFile
+0-49devel/libftdi/Makefile
+0-17devel/libftdi/pkg-plist
+0-10devel/libftdi/files/patch-src_ftdi.c
+0-5devel/libftdi/pkg-descr
+0-2devel/libftdi/distinfo
+0-1devel/Makefile
+0-841 files not shown
+1-847 files

FreeBSD/ports b6e0d36 — audio/ggwave Makefile distinfo

audio/ggwave: update 0.4.1 → 0.4.3
DeltaFile
+3-3audio/ggwave/distinfo
+3-1audio/ggwave/Makefile
+6-42 files

FreeBSD/ports e1f5d6d — misc/molequeue distinfo Makefile

misc/molequeue: update 0.9.0-17 → 0.9.0.24
DeltaFile
+4-3misc/molequeue/Makefile
+3-3misc/molequeue/distinfo
+7-62 files

FreeBSD/ports 09c60a3 — devel/rapidcheck pkg-plist distinfo

devel/rapidcheck: update g20220314 → g20260806
DeltaFile
+3-3devel/rapidcheck/distinfo
+3-3devel/rapidcheck/Makefile
+1-0devel/rapidcheck/pkg-plist
+7-63 files

FreeBSD/src 081f751 — stand/powerpc/ofw ofwfdt.c

stand/powerpc/ofw: do not truncate device tree properties to 1024 bytes

When the OpenFirmware loader flattens the firmware device tree into the
FDT it hands to the kernel (usefdt=1, i.e. on every real-mode OF system
such as pSeries LPARs and QEMU pseries guests), add_node_to_fdt() clamps
every property value to 1024 bytes.  Any larger property reaches the
kernel truncated.

On QEMU pseries the PCI host bridge's "interrupt-map" is 3584 bytes
(32 slots x 4 pins x 7 cells), so only the entries for slots 0-8 survive
and the entry for slot 9 is cut in the middle.  A PCI device in slot 9
or above therefore gets no INTx routing (irq 0), and with INVARIANTS the
partial trailing entry trips the "ofw_bus_search_intrmap: truncated map"
assertion in ofw_bus_search_intrmap() during PCI attach, panicking the
kernel as soon as such a device is present.  "ibm,drc-indexes",
"ibm,drc-names" and "ibm,drc-power-domains" are cut the same way.

Drop the clamp.  fdt_setprop() already reports a property that does not
fit into the FDT buffer, so no separate limit is needed.

    [4 lines not shown]
DeltaFile
+0-2stand/powerpc/ofw/ofwfdt.c
+0-21 files

FreeBSD/ports 276120a — x11-servers/Xfstt Makefile

x11-servers/Xfstt: Reset maintainer

PR:             294565
Approved by:    gspurki at gmail.com (maintainer)
DeltaFile
+1-1x11-servers/Xfstt/Makefile
+1-11 files

FreeBSD/ports e026d11 — net/samba424 Makefile, net/samba424/files patch-python_samba_join.py

net/samba424: fix swapped paths/targetdir args in join.py provision_fill call

patch-python_samba_provision_____init____.py extends provision_fill()'s
signature to provision_fill(..., paths, targetdir, schema=None, ...),
but the DCJoinContext call site in patch-python_samba_join.py passed
the two positional arguments in the opposite order (targetdir, paths).
This silently bound paths to a plain targetdir string and targetdir to
the ProvisionPaths object, which would raise AttributeError as soon as
provision_fill() accesses paths.netlogon/paths.sysvol.

Present identically since net/samba422 (join.py was not touched at all
in net/samba419) and carried forward unnoticed through samba423 and
samba424. Only reachable via the AD DC subdomain-join code path
(DCJoinContext), not via a fresh/root-domain provision.

PR:     298883
Co-Authored-By: Claude Sonnet 5 <noreply at anthropic.com>
Aproved by:     samba (kiwi)
DeltaFile
+1-1net/samba424/files/patch-python_samba_join.py
+1-1net/samba424/Makefile
+2-22 files

FreeBSD/ports ccd0bb1 — math/openlibm pkg-plist Makefile, math/openlibm/files patch-CMakeLists.txt

math/openlibm: Update to 0.8.8

Also improve port artifacts versioning

Changes: https://github.com/JuliaMath/openlibm/releases/tag/v0.8.8

Approved by:    thierry (mentor, implicit)
DeltaFile
+19-9math/openlibm/files/patch-CMakeLists.txt
+3-3math/openlibm/distinfo
+4-1math/openlibm/Makefile
+1-1math/openlibm/pkg-plist
+27-144 files

FreeBSD/ports 30c1b81 — . UPDATING, www/mod_wsgi pkg-descr distinfo

www/mod_wsgi: Update to 6.1.0

mod_wsgi has been upgraded to major version 6 with several potentially
breaking changes. Read the release notes very carefully:
https://modwsgi.readthedocs.io/en/latest/release-notes.html

PR:             298961
Approved by:    douglas at douglasthrift.net (maintainer)
DeltaFile
+5-4www/mod_wsgi/Makefile
+8-0UPDATING
+3-3www/mod_wsgi/distinfo
+3-2www/mod_wsgi/pkg-descr
+19-94 files

FreeBSD/ports 59c6916 — net/samba424 Makefile, net/samba424/files patch-buildtools_scripts_abi__gen.sh patch-dynconfig_wscript

net/samba424: fix dropped %%GDB_CMD%% and %%SAMBA4_CONFIG%% placeholders

patch-buildtools_scripts_abi__gen.sh hardcoded the abi_gen.sh gdb
invocation to "true" instead of the %%GDB_CMD%% placeholder that the
port's post-patch target substitutes via _GDB_CMD. This made the
Makefile's REINPLACE_CMD for %%GDB_CMD%% a dead no-op and silently
disabled real gdb-based ABI/symbol-version checking under the
DEVELOPER option, even though the devel/gdb dependency is still pulled
in for that option.

patch-dynconfig_wscript hardcoded the CONFIGFILE path to smb4.conf
instead of the %%SAMBA4_CONFIG%% placeholder, making the corresponding
REINPLACE_CMD for %%SAMBA4_CONFIG%% a dead no-op too. Harmless in
practice since _SAMBA_CONFIG already equals smb4.conf, but it silently
removes the ability to reconfigure the config file name through the
mechanism the Makefile provides for it.

Restore both placeholders so the existing substitution logic in the
Makefile actually takes effect again.

    [4 lines not shown]
DeltaFile
+2-2net/samba424/files/patch-dynconfig_wscript
+1-1net/samba424/files/patch-buildtools_scripts_abi__gen.sh
+1-1net/samba424/Makefile
+4-43 files

FreeBSD/src 34f9f56 — sys/contrib/openzfs/man/man8 zstream.8, sys/contrib/openzfs/module/os/freebsd/spl acl_common.c

zfs: merge openzfs/zfs at 1f380a4f3

Notable upstream pull request merges:
 #17864 e903655c5 zpool: Add zpool status -vv error ranges
 #18820 -multiple zdb: account pending DDT-log frees in leak detection
 #18884 -multiple zio_crypt: establish platform interface; rework common
                  code to use it
 #19010 -multiple zfs_namecheck: reject '.' and '..' before a snapshot or
                  bookmark
 #19031 994fb1703 Fix metaslab count assertion in metaslab_group_alloc()
                  for small vdevs
 #19093 f5b2fc8e2 zfs_ctldir: make .zfs/snapshot/<name> btime the snapshot
                  creation time
 #19097 2dece2a34 zstream: report invalid record context without assertions
 #19102 78f49e1dd vdev_disk: simplify alignment checks for linear ABDs
 #19108 -multiple Fix permanent errors misfiled into the scrub error log
 #19110 fa4bc4dec spa_errlog: don't let one unresolvable entry hide the
                  whole error log
 #19116 b6dde8a17 zio_crypt: free the key unwrap uios when decryption fails

    [13 lines not shown]
DeltaFile
+0-2,076sys/contrib/openzfs/module/os/linux/zfs/zio_crypt.c
+0-1,809sys/contrib/openzfs/module/os/freebsd/zfs/zio_crypt.c
+1,679-0sys/contrib/openzfs/module/zfs/zio_crypt.c
+0-1,307sys/contrib/openzfs/module/os/freebsd/spl/acl_common.c
+218-158sys/contrib/openzfs/man/man8/zstream.8
+0-363sys/contrib/openzfs/module/os/freebsd/zfs/zfs_ioctl_compat.c
+1,897-5,713234 files not shown
+7,659-7,353240 files

FreeBSD/src e1c59c9 — sys/dev/cxgbe adapter.h t4_main.c

cxgbe: Report SR-IOV VF status

Retain the PF-accepted MAC and VLAN settings from the per-port t4iov
companion and expose them through the corresponding cxgbe ifnet.

Publish, snapshot, and destroy the cache under the existing adapter
synchronized-operation mechanism so status queries cannot race IOV
configuration or teardown.

Track successful t4iov attachment independently of the active VF count.
Restrict reporting to the port main VI, return an empty status for a
supported but unconfigured PF, and omit status from VF and auxiliary
VIs.

Reviewed by:    jhb
Sponsored by:   BBOX.io
Differential Revision:  https://reviews.freebsd.org/D58741
DeltaFile
+93-22sys/dev/cxgbe/t4_iov.c
+66-0sys/dev/cxgbe/t4_main.c
+10-0sys/dev/cxgbe/adapter.h
+169-223 files

FreeBSD/ports 22a13e4 — sysutils/nerdctl pkg-descr distinfo

sysutils/nerdctl: Update to 2.4.0

- Install the upstream NOTICE file
- Add an EXAMPLES option
- Stop installing Linux-only rootless helper scripts

Release notes:
https://github.com/containerd/nerdctl/releases/tag/v2.4.0

Approved by:    thierry (mentor, implicit)
DeltaFile
+10-7sysutils/nerdctl/Makefile
+5-5sysutils/nerdctl/distinfo
+0-1sysutils/nerdctl/pkg-descr
+15-133 files

FreeBSD/ports 23fd6c1 — databases/pgrouting pkg-plist Makefile

databases/pgrouting: Update to 4.0.2
DeltaFile
+3-3databases/pgrouting/distinfo
+1-1databases/pgrouting/Makefile
+1-0databases/pgrouting/pkg-plist
+5-43 files

FreeBSD/ports df36222 — graphics/py-geopandas distinfo Makefile

graphics/py-geopandas: Update to 1.2.0
DeltaFile
+4-3graphics/py-geopandas/Makefile
+3-3graphics/py-geopandas/distinfo
+7-62 files

FreeBSD/ports c8641e5 — graphics/py-pygeoapi Makefile distinfo

graphics/py-pygeoapi: Update to 0.24.0
DeltaFile
+3-3graphics/py-pygeoapi/distinfo
+1-2graphics/py-pygeoapi/Makefile
+4-52 files

FreeBSD/ports fad6990 — net/openmpi pkg-plist Makefile, net/pmix distinfo Makefile

net/openmpi: Update to 5.0.11

- Update net/pmix to 5.0.11
- Update net/prrte to 3.0.14
- Move SLURM support to PRRTE
- Refine libevent dependencies and configure arguments

Reviewed by:    thierry (implicit)
Approved by:    thierry (implicit)
DeltaFile
+17-8net/prrte/Makefile
+5-8net/openmpi/Makefile
+6-4net/pmix/Makefile
+3-3net/prrte/distinfo
+3-3net/pmix/distinfo
+3-3net/openmpi/pkg-plist
+37-293 files not shown
+42-349 files

FreeBSD/src fa78e1d — share/man/man4 pci.4, sys/dev/pci pci_private.h pci_iov.c

pci: Reserve bus numbers required by SR-IOV VFs

Some firmware assigns only one bus number to each PCI-PCI bridge.  This
prevents later SR-IOV VF enumeration when a VF routing ID falls on a bus
number already allocated to a sibling bridge.

Reserve only the additional bus numbers required by SR-IOV PFs.
Enumerate all directly attached functions before child drivers and
bridges attach, inspect their device_t objects for SR-IOV, and grow the
PCI bus resource through the highest possible VF routing ID.

First VF Offset and VF Stride may change when NumVFs changes.  Probe
every valid NumVFs value and preserve the original setting.  When the
upstream hierarchy uses ARI, temporarily enable the SR-IOV ARI Hierarchy
control in the lowest-numbered PF while sizing, then restore it.  Scope
active-VF detection to each conventional PCI slot; an ARI bus remains
one slot-0 hierarchy.  If firmware left VFs enabled on a device, do not
modify it and reserve only its active layout.


    [20 lines not shown]
DeltaFile
+189-0sys/dev/pci/pci.c
+9-9sys/dev/pci/pci_iov.c
+10-1share/man/man4/pci.4
+3-0sys/powerpc/ofw/ofw_pcibus.c
+3-0sys/dev/pci/pci_private.h
+214-105 files

FreeBSD/ports 5b2f214 — sysutils/duplicity distinfo Makefile

sysutils/duplicity: Update to 3.2.1

ChangeLog: https://gitlab.com/duplicity/duplicity/-/releases/rel.3.2.1
DeltaFile
+4-7sysutils/duplicity/Makefile
+3-3sysutils/duplicity/distinfo
+7-102 files

FreeBSD/ports 5ccc078 — graphics/yacreader Makefile distinfo

graphics/yacreader: Update to 10.3.2

ChangeLog: https://github.com/YACReader/yacreader/releases/tag/10.3.2
DeltaFile
+3-3graphics/yacreader/distinfo
+1-1graphics/yacreader/Makefile
+4-42 files

FreeBSD/ports c50d01f — graphics/py-pygeoapi Makefile, graphics/py-pygeoapi/files patch-setup.py

graphics/py-pygeoapi: Fix stage-qa

- Bump PORTREVISION for package change

====> Running Q/A tests (stage-qa)
Error: Python package installs top-level 'tests/' directory in site-packages
Error:   Location: lib/python3.12/site-packages/tests
Error: This causes file conflicts with other packages. Exclude it via pyproject.toml:
Error:   [tool.setuptools.packages.find]
Error:   exclude = ["tests", "tests.*"]
Error: See: https://setuptools.pypa.io/en/latest/userguide/package_discovery.html
*** Error code 1
DeltaFile
+11-0graphics/py-pygeoapi/files/patch-setup.py
+1-1graphics/py-pygeoapi/Makefile
+12-12 files