ipfw: guard against NULL deref with clat/plat prefixes without length
Found with: Claude Code Sonnet 5
MFC after: 2 weeks
(cherry picked from commit 47b02ace19c53e72ad2290d974025292ff97464a)
exec: Remove an unneeded capability mode check
The subsequent namei() call is relative to AT_FDCWD, and such lookups
are always disallowed in capability mode.
No functional change intended.
Reviewed by: emaste
Differential Revision: https://reviews.freebsd.org/D59888
sysctl: Return ECAPMODE when trying to access sysctls in capability mode
We have always returned EPERM in this case, but it's incorrect, we
should return ECAPMODE for capability mode violations. Fix the errno
value.
Reviewed by: emaste
MFC after: 2 weeks
Differential Revision: https://reviews.freebsd.org/D59887
pf: do not loop on an address that is cleared twice in pfr_clr_astats()
pfr_clr_astats() looks up each address it is given and inserts the entry
it finds at the head of a work queue. If the same address is given more
than once, the entry is inserted twice and the second insertion makes it
its own successor. pfr_clstats_kentries() then walks the queue forever,
with the rules lock held for writing, so packet processing and every
other pf operation in that vnet stop as well. To reproduce:
pfctl -e
pfctl -t foo -T add 192.0.2.1
pfctl -t foo -T zero 192.0.2.1 192.0.2.1
Do as pfr_del_addrs() does: clear pfrke_mark on the entries named, then
queue an entry only the first time it is seen. An address given more
than once is cleared, and counted, once. Validate all addresses before
any entry is touched.
Add a regression test.
[6 lines not shown]
pf: fix NULL dereference in pfr_set_addrs() with feedback
Since DIOCRSETADDRS was converted to netlink, pf_handle_table_set_addrs()
calls pfr_set_addrs() with a NULL size2, as the netlink interface has no
buffer to return the deleted addresses in. pfr_set_addrs() only checked
size2 for NULL at the end of the function; with PFR_FLAG_FEEDBACK set it
dereferenced it unconditionally first. pfctl sets PFR_FLAG_FEEDBACK
when run with -v, so "pfctl -v -t foo -T replace ..." panicked the
kernel with a NULL pointer dereference. To reproduce:
pfctl -e
pfctl -t foo -T add 192.0.2.1
pfctl -v -t foo -T replace 192.0.2.2
Check size2 for NULL before dereferencing it, as is already done at the
end of the function. The per-address feedback for added and changed
addresses is still copied back as before; only the list of deleted
addresses, which the netlink caller has no room for, is skipped.
[9 lines not shown]
graphics/drm-latest-kmod: Update to drm_v6.12.85_3 to fix build
After src commit 33595d4ae01c added pci_map_rom() and pci_unmap_rom() to
linuxkpi, graphics/drm-latest-kmod failed to build because drm-kmod
defined the same macros itself.
Upstream drm-kmod made its definitions conditional, and ports commit
7e420adaf6ef pulled that fix in for drm-515-kmod, drm-61-kmod,
drm-66-kmod, and drm-612-kmod. drm-latest-kmod was missed, so move it
to the same tag as drm-612-kmod.
Bump PORTREVISION of the nvidia-drm-latest-kmod ports, which build
against the drm-kmod sources, and update their distinfo for the new
tarball.
Reference: https://github.com/freebsd/drm-kmod/pull/503
Reviewed by: dumbbell
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D60084
games/jinput: Fix build if maven39 installed
[ERROR] Plugin org.apache.maven.plugins:maven-resources-plugin:3.4.0 or one of its dependencies could not be resolved:
[ERROR] Cannot access central (https://repo.maven.apache.org/maven2) in offline mode and the artifact org.apache.maven.plugins:maven-resources-plugin:jar:3.4.0 has not been downloaded from it before.
[ERROR] -> [Help 1]
[ERROR]
[ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch.
[ERROR] Re-run Maven using the -X switch to enable full debug logging.
[ERROR]
[ERROR] For more information about the errors and possible solutions, please read the following articles:
[ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/PluginResolutionException
Approved by: blanket (fix build)
Sponsored by: UNIS Labs
MFH: 2026Q3
(cherry picked from commit 5a8f4f19bebcaf728753b7f8f5e3f5837b56bda1)
games/jinput: Fix build if maven39 installed
[ERROR] Plugin org.apache.maven.plugins:maven-resources-plugin:3.4.0 or one of its dependencies could not be resolved:
[ERROR] Cannot access central (https://repo.maven.apache.org/maven2) in offline mode and the artifact org.apache.maven.plugins:maven-resources-plugin:jar:3.4.0 has not been downloaded from it before.
[ERROR] -> [Help 1]
[ERROR]
[ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch.
[ERROR] Re-run Maven using the -X switch to enable full debug logging.
[ERROR]
[ERROR] For more information about the errors and possible solutions, please read the following articles:
[ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/PluginResolutionException
Approved by: blanket (fix build)
Sponsored by: UNIS Labs
MFH: 2026Q3
games/jutils: Fix build if maven39 installed
[ERROR] Plugin org.apache.maven.plugins:maven-surefire-plugin:3.5.4 or one of its dependencies could not be resolved:
[ERROR] Cannot access central (https://repo.maven.apache.org/maven2) in offline mode and the artifact org.apache.maven.plugins:maven-surefire-plugin:jar:3.5.4 has not been downloaded from it before.
[ERROR] -> [Help 1]
[ERROR]
[ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch.
[ERROR] Re-run Maven using the -X switch to enable full debug logging.
[ERROR]
[ERROR] For more information about the errors and possible solutions, please read the following articles:
[ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/PluginResolutionException
Approved by: blanket (fix build)
Sponsored by: UNIS Labs
MFH: 2026Q3
(cherry picked from commit d5cc2f5d3fe60a240e642b2514c120b4395d4a16)
games/jutils: Fix build if maven39 installed
[ERROR] Plugin org.apache.maven.plugins:maven-surefire-plugin:3.5.4 or one of its dependencies could not be resolved:
[ERROR] Cannot access central (https://repo.maven.apache.org/maven2) in offline mode and the artifact org.apache.maven.plugins:maven-surefire-plugin:jar:3.5.4 has not been downloaded from it before.
[ERROR] -> [Help 1]
[ERROR]
[ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch.
[ERROR] Re-run Maven using the -X switch to enable full debug logging.
[ERROR]
[ERROR] For more information about the errors and possible solutions, please read the following articles:
[ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/PluginResolutionException
Approved by: blanket (fix build)
Sponsored by: UNIS Labs
MFH: 2026Q3
website: Revive donations page
Restore donations links on the project website to the projects donations
page. These links were replaced in the foundation sponsored website
refresh with links to the foundations donations page.
The very first link on this page is to the Foundations donations, but
importantly, it explains where this money actually goes, which has many
common misconceptions, such as the cluster. There are also other links
on the page, such as hardware donations, which we actually need right
now for the aging cluster.
Event: EuroBSDcon 2026
Reviewed by: adrian, bapt, gahr, kevans, obiwac, philip,
Reviewed by: vishwin, wosch,
Reviewed by: Antranig Vartanian <antranigv at freebsd.am>,
Reviewed by: Lukas Engelhardt <lukas.engelhardt at gmx.de>
Differential Revision: https://reviews.freebsd.org/D59505
net/frr9: Install daemons in lib/frr, fix SNMP build and rc.d restart
Daemons move from ${PREFIX}/sbin to ${PREFIX}/lib/frr, matching the Linux
packages and net/frr10. Only vtysh and frr-reload stay in bin/ and sbin/.
This avoids filename collision with net/openbgpd*, net/pimd, net/quagga, etc.
Fix the SNMP build.
Backport frr10's rc.d fixes: a bare "service frr restart" restarted watchfrr
only, leaving the daemons it supervises untouched.