FreeBSD/ports 597ff51textproc/wdiff Makefile distinfo

textproc/wdiff: update to 1.2.3
DeltaFile
+3-40textproc/wdiff/pkg-plist
+3-2textproc/wdiff/distinfo
+2-2textproc/wdiff/Makefile
+8-443 files

FreeBSD/src 185f1a1crypto/aes aes_x86core.c, doc/man3 X509_verify_cert.pod

openssl: import 3.5.8

This change adds OpenSSL 3.5.8 from upstream [1].

The 3.5.8 artifact was been verified via PGP key [2] and by SHA256 checksum [3].

This is a security patch release. The highest severity issue is medium.

More information about the release (from a high level) can be found in
the release notes [4].

Updated via [5] with `update_openssl.sh 3.5.8`.

1. https://github.com/openssl/openssl/releases/download/openssl-3.5.8/openssl-3.5.8.tar.gz
2. https://github.com/openssl/openssl/releases/download/openssl-3.5.8/openssl-3.5.8.tar.gz.asc
3. https://github.com/openssl/openssl/releases/download/openssl-3.5.8/openssl-3.5.8.tar.gz.sha256
4. https://github.com/openssl/openssl/blob/openssl-3.5.8/NEWS.md
5. https://codeberg.org/ngie/freebsd-powertools:shell/update_openssl.sh@c2f51140
DeltaFile
+0-867crypto/aes/aes_x86core.c
+851-3test/evp_extra_test.c
+394-125test/evp_extra_test2.c
+476-32test/endecode_test.c
+439-61doc/man3/X509_verify_cert.pod
+337-5test/radix/quic_tests.c
+2,497-1,093256 files not shown
+8,213-2,267262 files

FreeBSD/ports f62c942security/vuxml/vuln 2026.xml

security/vuxml: correct a tpyo

FreeBSD-SA-26:61.openssl not FreeBSD-SA-26:62.openssl.

Fixes:          6caee4041ace ("security/vuxml: reference FreeBSD-SA-26:61.openssl")
Pointy hat to:  philip
DeltaFile
+1-1security/vuxml/vuln/2026.xml
+1-11 files

FreeBSD/ports efb5ff9security/vuxml/vuln 2026.xml

security/vuxml: remove duplicate OpenSSL entry

Reference FreeBSD-SA-26:35.openssl in the existing entry for OpenSSL
CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, CVE-2026-34181,
CVE-2026-34182, CVE-2026-34183, CVE-2026-42764, CVE-2026-42766,
CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-42770,
CVE-2026-45445, CVE-2026-45446 and CVE-2026-45447 instead of duplicating
the entry.

FreeBSD-SA-26:35.openssl affected all supported versions of FreeBSD.
DeltaFile
+8-82security/vuxml/vuln/2026.xml
+8-821 files

FreeBSD/ports d4032casecurity/vuxml/vuln 2026.xml

security/vuxml: add FreeBSD SAs issued on 2026-08-25

FreeBSD-SA-26:56.hwpmc affects all supported releases
FreeBSD-SA-26:57.unix affects 15.0R and 15.1R
FreeBSD-SA-26:58.sound affects all supported releases
FreeBSD-SA-26:59.mac_do affects 15.0R and 15.1R
FreeBSD-SA-26:60.ppp affects all supported releases
FreeBSD-SA-26:62.tty affects all supported releases
FreeBSD-SA-26:63.posixshm affects all supported releases
DeltaFile
+267-0security/vuxml/vuln/2026.xml
+267-01 files

FreeBSD/ports 6caee40security/vuxml/vuln 2026.xml

security/vuxml: reference FreeBSD-SA-26:61.openssl

Add a reference to FreeBSD-SA-26:61.openssl (issued 2026-08-25) to the
vuxml entry for OpenSSL CVE-2026-14457, CVE-2026-18798, CVE-2026-54874,
CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075 and
CVE-2026-63076

FreeBSD-SA-26:61.openssl affects all supported versions of FreeBSD
DeltaFile
+8-0security/vuxml/vuln/2026.xml
+8-01 files

FreeBSD/ports d4af645devel/wasmer Makefile Makefile.crates

devel/wasmer: Update to 7.3.0

Changelog: https://github.com/wasmerio/wasmer/blob/main/CHANGELOG.md#730---21082026

PR:             297771
Reported by:    Krešimir Jozić <kjozic at gmail.com> (maintainer)
DeltaFile
+537-487devel/wasmer/distinfo
+267-242devel/wasmer/Makefile.crates
+1-2devel/wasmer/Makefile
+805-7313 files

FreeBSD/ports aa5f496security/sniffglue Makefile distinfo

sniffglue: Update to 0.16.2

Changelog: https://github.com/kpcyrd/sniffglue/releases/tag/v0.16.2

PR:             295174
Reported by:    Martin Filla <freebsd at sysctl.cz> (maintainer)
Reviewed by:    vvd, nxjoseph
DeltaFile
+223-213security/sniffglue/distinfo
+111-107security/sniffglue/Makefile
+334-3202 files

FreeBSD/ports a021825net-im/gomuks Makefile distinfo, net-im/gomuks/files/packagejsons package.json package-lock.json

net-im/gomuks: Update 26.07 => 26.08

Changelog: https://github.com/gomuks/gomuks/releases/tag/v0.2608.0

PR:             297671
Reported by:    Derek Schrock <dereks at lifeofadishwasher.com> (maintainer)
Reviewed by:    meta
DeltaFile
+373-450net-im/gomuks/files/packagejsons/package-lock.json
+7-7net-im/gomuks/distinfo
+3-3net-im/gomuks/files/packagejsons/package.json
+1-2net-im/gomuks/Makefile
+384-4624 files

FreeBSD/ports 7e27f9dmultimedia/hdrprobe Makefile Makefile.crates

multimedia/hdrprobe: Update to 1.0.1

Changelog:
- https://github.com/matthane/hdrprobe/releases/tag/v1.0.0
- https://github.com/matthane/hdrprobe/releases/tag/v1.0.1

PR:             297691
Reported by:    Michiel van Baak Jansen <michiel at vanbaak.eu> (maintainer)
DeltaFile
+7-11multimedia/hdrprobe/distinfo
+2-4multimedia/hdrprobe/Makefile.crates
+1-1multimedia/hdrprobe/Makefile
+10-163 files

FreeBSD/ports 672433dnet-im/mautrix-whatsapp Makefile distinfo, net-im/mautrix-whatsapp/files config.yaml.sample

net-im/mautrix-whatsapp: Update to 0.2608.0

Changelog: https://github.com/mautrix/whatsapp/blob/v0.2608.0/CHANGELOG.md

- Switched direct chats to use LIDs instead of phone numbers.

Release post: https://mau.fi/blog/2026-08-mautrix-release/

PR:             297594
Reported by:    Julian Weigt <juw at posteo.de> (maintainer)
DeltaFile
+27-11net-im/mautrix-whatsapp/files/config.yaml.sample
+5-5net-im/mautrix-whatsapp/distinfo
+1-2net-im/mautrix-whatsapp/Makefile
+33-183 files

FreeBSD/ports 47495c4mail/py-resend Makefile distinfo

mail/py-resend: Update to 2.40.2

Changelog: https://github.com/resend/resend-python/releases/tag/v2.40.2

Reported by:    Repology
DeltaFile
+3-3mail/py-resend/distinfo
+1-1mail/py-resend/Makefile
+4-42 files

FreeBSD/ports 32ac18bmisc/crush Makefile distinfo

misc/crush: Update to 0.91.1

Changelog: https://github.com/charmbracelet/crush/releases/tag/v0.91.1

Reported by:    GitHub (watch releases)
DeltaFile
+5-5misc/crush/distinfo
+1-1misc/crush/Makefile
+6-62 files

FreeBSD/doc 03688f0website/content/en/releases/14.4R errata.adoc, website/content/en/releases/15.0R errata.adoc

Add errata affecting 14.4R, 15.0R and 15.1R

FreeBSD-EN-26:20.microcode affects all supported releases
FreeBSD-EN-26:21.openssl affects 14.4R
DeltaFile
+2-0website/content/en/releases/14.4R/errata.adoc
+1-0website/content/en/releases/15.1R/errata.adoc
+1-0website/content/en/releases/15.0R/errata.adoc
+4-03 files

FreeBSD/doc 3925b5cwebsite/content/en/releases/14.4R errata.adoc, website/content/en/releases/15.0R errata.adoc

Add security advisories affecting 14.4R, 15.0R and 15.1R

FreeBSD-SA-26:56.hwpmc affects all supported releases
FreeBSD-SA-26:57.unix affects 15.0R and 15.1R
FreeBSD-SA-26:58.sound affects all supported releases
FreeBSD-SA-26:59.mac_do affects 15.0R and 15.1R
FreeBSD-SA-26:60.ppp affects all supported releases
FreeBSD-SA-26:61.openssl affects all supported releases
FreeBSD-SA-26:62.tty affects all supported releases
FreeBSD-SA-26:63.posixshm affects all supported releases
DeltaFile
+8-0website/content/en/releases/15.1R/errata.adoc
+8-0website/content/en/releases/15.0R/errata.adoc
+6-0website/content/en/releases/14.4R/errata.adoc
+22-03 files

FreeBSD/src 132e609sys/dev/igc if_igc.h

igc: Restore the watchdog event counter

The MFC of the fatal memory-error recovery dropped watchdog_events from
the softc.  The driver still increments it, includes it in
IFCOUNTER_OERRORS, and exports it as the watchdog_timeouts sysctl.

Fixes: ee9bbfca423f ("igc: Recover from fatal internal memory errors")
DeltaFile
+1-0sys/dev/igc/if_igc.h
+1-01 files

FreeBSD/src 87b9783sys/net iflib.c ifdi_if.m

iflib: Allow conditional LED device support

A driver class may implement LED control even though the capability is
not available on every device or firmware version it supports.  Add an
optional capability method and consult it before creating the led(4)
device.  Default to supported so existing providers are unchanged.

This will be used by bnxt which blends PF and VF in the same driver.

(cherry picked from commit 2519e19f05e0c3e5925bf81b729b4c28f2ad1af6)
DeltaFile
+10-0sys/net/ifdi_if.m
+1-1sys/net/iflib.c
+11-12 files

FreeBSD/src b730642sys/dev/igc if_igc.h if_igc.c

igc: Report corrected internal ECC errors

I225 and I226 do not interrupt for corrected internal ECC errors.
Instead, the DMA packet buffer and PCIe memories expose sticky status
bits in PBECCSTS and PCIEECCSTS.

Sample these bits with the regular hardware statistics update, preserve
the PBECCSTS ECC enable state while clearing its RW1C indication, and
expose separate counters for the DMA packet buffer, PCIe transmit-data
memory, and PCIe retry buffer.

These counters represent observed indications rather than an exact error
count because multiple corrections between samples collapse into one
sticky status bit.

Hardware validation used an I225-IT (rev 3) and a debug kernel that
wrote only the documented self-clearing injection bits.  Each test
armed the injector, exercised the owning RAM with traffic, and compared
the corresponding counter before and after.

    [15 lines not shown]
DeltaFile
+40-0sys/dev/igc/if_igc.c
+3-0sys/dev/igc/if_igc.h
+43-02 files

FreeBSD/src 7b48d8dsys/dev/igc igc_regs.h if_igc.h

igc: Recover from fatal internal memory errors

I225 and I226 report uncorrectable internal memory errors through
ICR.FER and identify the affected region in PEIND.  Depending on the
region, hardware stops transmit or all PCIe and DMA traffic until the
port is reset and reinitialized.

Enable the fatal error interrupt and capture its read clear status in
the interrupt filter.  Mask the cause while an iflib reset is pending,
report the affected memory regions, and expose per region indication
counters.

PCIe region parity failures require a different recovery order from a
normal reset: assert DEV_RST, wait at least 3 ms, disable PCIe master
requests, clear PCIEERRSTS, and then reinitialize the port.  Follow that
sequence before entering the normal reset path and clear the remaining
LAN status afterward.

The I225/I226 PBECCSTS layout is unrelated to the PCH layout previously

    [21 lines not shown]
DeltaFile
+221-5sys/dev/igc/if_igc.c
+20-5sys/dev/igc/igc_defines.h
+10-0sys/dev/igc/if_igc.h
+7-2sys/dev/igc/igc_regs.h
+258-124 files

FreeBSD/src 7ac83b9sys/dev/ixgbe ixgbe.h if_ix.c

ixgbe: Defer E610 thermal shutdown to iflib

The E610 firmware event handler invoked ixgbe_if_stop() directly from
IFDI_UPDATE_ADMIN_STATUS().  This reset the device without the iflib
queue lifecycle and left the interface marked running after its hardware
was stopped.

Request an iflib reset instead.  Fail the automatic initialization once
so the reset transaction stops the interface and publishes that state.
A later operator-requested initialization remains possible, matching the
previous recovery policy without bypassing iflib.

(cherry picked from commit 3aac283613bd3fd0228a06d6c854ca0bf190ecfb)
DeltaFile
+14-5sys/dev/ixgbe/if_ix.c
+1-0sys/dev/ixgbe/ixgbe.h
+15-52 files

FreeBSD/src f89ea9esys/dev/ixgbe if_ix.c

ixgbe: Defer firmware recovery transitions to iflib

The firmware-mode callout invoked ixgbe_if_stop() directly.  This
performed a full device reset without the iflib context lock or the
iflib queue lifecycle.  It could also poll the E610 firmware command
interface from callout context while identification was active.

Request an iflib reset from the callout instead.  Reject initialization
while firmware recovery remains active.  This leaves the interface
stopped and lets iflib publish that state.  Request initialization when
firmware exits recovery so an administratively-up interface can recover
without operator intervention.

(cherry picked from commit 43aa553ef45a4345bdfabadae40d811730151144)
DeltaFile
+12-4sys/dev/ixgbe/if_ix.c
+12-41 files

FreeBSD/src 16b31a1sys/dev/ixgbe ixgbe_type.h ixgbe.h

ixgbe: Defer ECC recovery to iflib

The link interrupt filter performed a full hardware reset in interrupt
context.  This bypassed iflib stop and initialization, including queue
quiescence and restoration of temporary LED state.

Record the ECC event in the administrative request mask and ask iflib
to perform the reset from its taskqueue.  Keep the ECC cause masked
until reset so the intermediate admin pass cannot re-enable a sticky
condition.  Handle ECC independently of Flow Director and in legacy
interrupt mode.

Remove the redundant EICR write; the filter has already cleared the
reported causes.  Also remove the accompanying complement-mask update
of mac.flags.  It set every flag except DOUBLE_RESET_REQUIRED and had
no place in ECC recovery.

(cherry picked from commit c28f2c551daf07345ac78b74459efe1014c49464)
DeltaFile
+40-14sys/dev/ixgbe/if_ix.c
+1-0sys/dev/ixgbe/ixgbe_type.h
+1-0sys/dev/ixgbe/ixgbe.h
+42-143 files

FreeBSD/src 553667cshare/man/man4 ixl.4, sys/dev/ixl ixl_pf_iflib.c ixl_pf.h

ixl: Add led(4) identification support

Expose each physical port identification LED through /dev/led/ixl*.
Use the existing GPIO LED helpers for most devices and the PHY
provisioning interface for X710 10GBASE-T adapters.

Preserve and restore the original GPIO or PHY indication mode,
including before the interface is stopped.

(cherry picked from commit 8b2e75970c0328e7397290417cc06e9d9c763d2a)
DeltaFile
+77-1sys/dev/ixl/if_ixl.c
+6-1share/man/man4/ixl.4
+5-0sys/dev/ixl/ixl_pf.h
+2-0sys/dev/ixl/ixl_pf_iflib.c
+90-24 files

FreeBSD/src d7bed48share/man/man4 ix.4, sys/dev/ixgbe ixgbe.h if_ix.c

ixgbe: Add led(4) identification support

Expose the physical port identification LED through /dev/led/ix*.
Save and restore the NVM-selected LEDCTL value around each request.
The X550 operations also clear their PHY manual override before the
register is restored.

Use the dedicated firmware port-identification command on E610.  Its
interface selects between firmware blinking and the original mode
rather than directly controlling LEDCTL.

Restore the normal indication before a device stop or reset.

(cherry picked from commit fb7e249ce4fd03fe53e4407efe661f9e94852bb6)
DeltaFile
+54-0sys/dev/ixgbe/if_ix.c
+6-1share/man/man4/ix.4
+2-0sys/dev/ixgbe/ixgbe.h
+62-13 files

FreeBSD/src 9fbf429sys/dev/igc if_igc.c

igc: Remove invalid debug ring pointer iteration

The debug routine reads queue registers by queue index.  It also
advanced unused pointers to rings embedded in queue structures.  Those
pointers had the wrong stride and could proceed beyond the ring object.

Remove the unused pointer arithmetic.

(cherry picked from commit 423927d6c3dc87628fc2a19f25b5b5c07b3b73e2)
DeltaFile
+2-4sys/dev/igc/if_igc.c
+2-41 files

FreeBSD/src b06e426sys/dev/e1000 if_em.c

e1000: Fix the multiqueue debug register dump

The debug routine advanced ring pointers as if rings were contiguous.
They are embedded in queue structures, so rings beyond queue zero had
the wrong stride.  The bogus queue index could cause an invalid MMIO
read and panic the machine.

Index the queue arrays first and then select the embedded ring.

(cherry picked from commit 7dd826171b69a01c234ba6e9117917398ba2705e)
DeltaFile
+6-4sys/dev/e1000/if_em.c
+6-41 files

FreeBSD/src 9d5a148sys/dev/e1000 if_em.c

e1000: Identify SerDes adapters with LED blink

The generic LED on and off operations do not handle internal SerDes
media, leaving the led(4) device ineffective on my I210 fiber port.

Use the hardware blink operation for the on phase on internal SerDes.
The off phase restores the saved OEM LED configuration as before.

(cherry picked from commit 28f96cc3748fc46408cc6ab6172f09bc2182cad7)
DeltaFile
+4-1sys/dev/e1000/if_em.c
+4-11 files

FreeBSD/src 34817fashare/man/man4 igc.4, sys/dev/igc if_igc.h igc_defines.h

igc: Add led(4) identification support

I225 and I226 expose three programmable LED outputs.  Use LED1 for
adapter identification, following the convention in DPDK.  Preserve the
OEM configuration across identification requests.

Restore the OEM configuration before a device reset so an active led(4)
pattern cannot leave the output overridden across stop or detach.

The LED mode values follow the Intel I225 Software User Manual.

(cherry picked from commit 19f75b38199b9d30e85fab83e61ff36b0b9ed015)
DeltaFile
+45-0sys/dev/igc/if_igc.c
+9-1share/man/man4/igc.4
+5-2sys/dev/igc/igc_defines.h
+2-2sys/dev/igc/if_igc.h
+61-54 files

FreeBSD/src 618cd9fshare/man/man4 em.4

igb(4): Document identification LED device nodes

The shared em(4) manual page lists only the em device-node name.
Document the /dev/led/igb* name as well.

(cherry picked from commit fc0e6adb9d26f94616db5357afcbb585e4176c6d)
DeltaFile
+3-3share/man/man4/em.4
+3-31 files

FreeBSD/src 95cf012sys/dev/ixgbe if_ix.c

ixgbe: Defer firmware recovery transitions to iflib

The firmware-mode callout invoked ixgbe_if_stop() directly.  This
performed a full device reset without the iflib context lock or the
iflib queue lifecycle.  It could also poll the E610 firmware command
interface from callout context while identification was active.

Request an iflib reset from the callout instead.  Reject initialization
while firmware recovery remains active.  This leaves the interface
stopped and lets iflib publish that state.  Request initialization when
firmware exits recovery so an administratively-up interface can recover
without operator intervention.

(cherry picked from commit 43aa553ef45a4345bdfabadae40d811730151144)
DeltaFile
+12-4sys/dev/ixgbe/if_ix.c
+12-41 files