FreeBSD/src a52c50b — sys/fs/nfsserver nfs_nfsdstate.c

nfs_nfsdstate.c: Add an extra safety belt check for the backchannel

I do not think that xp_p2 can be NULL at this point,
but add an extra safety belt, just in case.

Reviewed by:    rmacklem
MFC after:      1 week
Sponsored by:   VersatusHPC
DeltaFile
+2-1sys/fs/nfsserver/nfs_nfsdstate.c
+2-11 files

FreeBSD/src 49bec8c — sys/rpc clnt_vc.c

clnt_vc.c: Fix handling of broken TCP connections

After more than, I don't know, maybe 10k operations: mount, copy,
remove, verify and unmount cycles, one cp command hung in
close() / ncl_flush and never recovered. The machine and the mount
continued to work normally through a new connection, but the writes
using the old connection stayed frozen.

I did not understand exactly what happened.  I traced what appears to
be the issue in the code. My current understanding is that
clnt_vc_soupcall() saw the EOF and woke the caller waiting for RPC
replies, but one caller remained blocked in sosend().
That thread continued holding a reference to the old client, preventing
it from being completely cleaned up.

The attached patch calls socantsendmore() when EOF is received, which
should wake the blocked sender and let the normal reconnect code replace
the connection.


    [3 lines not shown]
DeltaFile
+7-5sys/rpc/clnt_vc.c
+7-51 files

FreeBSD/src 81a6514 — sys/rpc clnt_vc.c

clnt_vc.c: Fix handling of backchannel xprt

When clnt_vc_destroy() is called, it might not be the
current connection.  Without this patch, if it is not
the current connection, xp_p2 is set NULL and xprt is released
when it should not be released.

This patch adds a check for "current connection" to fix
the problem.  Found during testing to the client RDMA code,
but could happen for TCP as well.

MFC after:      1 week
DeltaFile
+8-2sys/rpc/clnt_vc.c
+8-21 files

FreeBSD/src 479c982 — sys/ufs/ffs ffs_softdep.c

ffs: revalidate mkdir dependencies after vnode lookup

flush_pagedep_deps() drops the soft updates lock while obtaining the
vnode of a newly created directory with get_parent_vp().  The
MKDIR_BODY dependency may complete during this interval, invalidating
the diradd selected before the lock was dropped.

Once the directory's allocdirect is retired, the lookup of its first
block by block number in flush_newblk_dep() can find an older
dependency for a previous use of the same physical block.  The newblk
hash is not unique by block number: when ffs_reallocblks() relocates a
cluster, the completed allocindirs of the old blocks stay on the
indirdep's ir_completehd until the indirect block pointer in the inode
is written, while the old blocks are already free and may be allocated
to a new directory.  flush_newblk_dep() then finds a D_ALLOCINDIR where
it expects a D_ALLOCDIRECT and panics with "flush_newblk_dep: Bad
newblk".

Retain the vnode returned by get_parent_vp(), reacquire the soft

    [33 lines not shown]
DeltaFile
+170-55sys/ufs/ffs/ffs_softdep.c
+170-551 files

FreeBSD/src a127039 — tools/test/stress2/misc mkdir_blkreuse.sh

stress2: add a reproducer for the flush_newblk_dep() "Bad newblk" panic

flush_pagedep_deps() drops the soft updates lock to obtain the vnode of
a new directory.  If its MKDIR_BODY dependency completes in that window,
the lookup of the directory's first block in flush_newblk_dep() can find
a stale allocindir left behind by a previous owner of the same block,
relocated by ffs_reallocblks() and freed, and panic.

The test grows interleaved files past UFS_NDADDR to keep clusters being
relocated, while other workers create subdirectories in a parent with
IN_ENDOFF set, so that ffs_vput_pair() syncs it, and fsync() them to
complete the mkdir dependencies.  The file system layout and the way
the writers put their blocks on disk are arranged so that a new
directory takes over a freed block whose dependency is still retained;
the details are in the script.  With dtrace=1, the test also counts how
often this precondition is met, which works on a fixed kernel too.

PR:             297976
Reviewed by:    kib, pho

    [3 lines not shown]
DeltaFile
+584-0tools/test/stress2/misc/mkdir_blkreuse.sh
+584-01 files

FreeBSD/src 35b5998 — sys/geom/part g_part.c

g_part: access leak causes process to hang

So if one inserts a USB drive with a GPT that doesn't match the media
size, a resize is initiated, so gpart takes g_access(cp, 1, 1, 1) on the
disk and holds it until the resize is accepted or rejected. The orphan
path releases it, but the spoil path does not. So if the drive is
ejected while the resize is in flight, we call spoil directly, without
releasing the access. Since gpt_opened is not cleared for the spoil
path, this causes several different process to hang in the open path
waiting for the leaked access.

Move the release into the wither function when gpt_opened is set, and
remove the release elsewhere. Since all paths to destroy the geom pass
through wither, this ensure that access is always released when we've
taken the access for resize.

PR:                     297777
Reported by:            Rick Richard
MFC After:              1 week

    [2 lines not shown]
DeltaFile
+3-11sys/geom/part/g_part.c
+3-111 files

FreeBSD/src e8a7efd — sys/dev/nvme nvme_private.h nvme.h

nvme: set the controller Timestamp feature

Controllers that report ONCS.TIMESTAMP keep a millisecond clock that the
host is expected to seed

Reviewed by:    imp, adrian
Differential Revision:  https://reviews.freebsd.org/D59997
DeltaFile
+60-0sys/dev/nvme/nvme_ctrlr.c
+19-0sys/dev/nvme/nvme.h
+3-0sys/dev/nvme/nvme_private.h
+82-03 files

FreeBSD/src 0a0490e — sys/dev/nvme nvme_private.h nvme_qpair.c

nvme: do not complete a command when its Abort is not performed

An Abort completion with cdw0 bit 0 set means the controller did not
abort the command; the command can still complete later. The driver
treated this as aborted anyway: it completed the command itself and
freed the CID. When the controller completed the command later,
the CID may already belong to a new command, so the new command
finished with the old command's status, or the unknown-cid assertion
fired on INVARIANTS kernels. The watchdog also kept sending a new
Abort for the same command every half second while the first one was
still pending.

Reviewed by:    imp, adrian
Differential Revision:  https://reviews.freebsd.org/D59634
DeltaFile
+14-24sys/dev/nvme/nvme_qpair.c
+6-0sys/dev/nvme/nvme_private.h
+20-242 files

FreeBSD/src 22f5037 — sys/dev/nvme nvme_private.h nvme_ctrlr.c

nvme: delete the I/O queues in the system shutdown path

A normal shutdown deletes all I/O submission and completion queues
before setting CC.SHN, as the suspend path already does.  The
device_shutdown path went straight to the shutdown notification with
the queues live, which some drives take slowly or record as an
unclean stop. Skipped the deletion for failed, removed, or
never-initialized controllers.

Reviewed by:    imp, adrian
Differential Revision:  https://reviews.freebsd.org/D59633
DeltaFile
+5-0sys/dev/nvme/nvme.c
+1-1sys/dev/nvme/nvme_ctrlr.c
+1-0sys/dev/nvme/nvme_private.h
+7-13 files

FreeBSD/src a5b1b2d — lib/libpfctl libpfctl.h libpfctl.c

libpfctl: remove the state getters that do not take a handle

Nothing in the tree calls any of the three.  Remove them rather than
fix them: pfctl_get_states_h() does the same with the handle that the
caller has.  pfctl_free_states(), struct pfctl_states and the list
entry in struct pfctl_state were there for pfctl_get_states() alone,
and go with it.

Reviewed by:            kp
Approved by:            kp (mentor)
Fixes:                  2a478dfc7f9c ("libpfctl: retrieve family id only once")
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60248
DeltaFile
+0-66lib/libpfctl/libpfctl.c
+0-11lib/libpfctl/libpfctl.h
+0-772 files

FreeBSD/src 66ff928 — sys/dev/igc igc_txrx.c if_igc.c

igc: make the hardware RSS hash agree with the stack's configuration

rss_gethashconfig() is available without options RSS since d9c55b2e8cd6.
Use it to program MRQC, as ixl(4), ice(4) and iavf(4) do, instead of a
fixed field set that included UDP 4-tuple, which the configuration
excludes unless net.inet.rss.udp_4tuple is set.  UDP is now hashed on
addresses only by default.

Also report the UDP hash types on receive; they were passed up as
M_HASHTYPE_NONE.

Reviewed by:            kbowling
Fixes:                  517904de5cca ("igc(4): Introduce new driver for the Intel I225 Ethernet controller.")
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60284
DeltaFile
+21-9sys/dev/igc/if_igc.c
+6-0sys/dev/igc/igc_txrx.c
+27-92 files

FreeBSD/src edc51d1 — stand/efi/loader version.veriexec version, stand/i386/loader version

stand: Bump version to 3.1

Sponsored by:           Netflix
DeltaFile
+1-0stand/uboot/version
+1-0stand/powerpc/ofw/version
+1-0stand/kboot/kboot/version
+1-0stand/i386/loader/version
+1-0stand/efi/loader/version.veriexec
+1-0stand/efi/loader/version
+6-01 files not shown
+7-07 files

FreeBSD/src 2050abe — sys/rpc rpc_generic.c

rpc_generic.c: Initialize "cp" to shut the compiler up

This patch does not fix any semantics issue.

MFC after:      3 months
Fixes:  884ee8d6c9b4 ("nfscl: Add some glue for client side NFS over RDMA")
DeltaFile
+1-1sys/rpc/rpc_generic.c
+1-11 files

FreeBSD/src 4e0870f — share/man/man5 rc.conf.5

rc.conf.5: Fix typo

Fixes:          fa7094c5b06f ("Improve NOAUTO configuration")
MFC after:      3 days
Reported by:    Herbert J. Skuhra <herbert at gojira.at>
Event:          EuroBSDcon Devsummit 2026

(cherry picked from commit 45f4abef5eab5b439f8af272b68171ca5803498d)
DeltaFile
+2-2share/man/man5/rc.conf.5
+2-21 files

FreeBSD/src 405ee2a — share/man/man5 rc.conf.5

rc.conf.5: Improve NOAUTO configuration + tag SPDX

- Show how to start a NOAUTOed interface
- "configured" is not quite right, try to improve that

MFC after:              3 days
Event:                  EuroBSDcon Devsummit 2026
Reviewed by:            adrian
Discussed with:         Antranig Vartanian <antranigv at freebsd.am>
Differential Revision:  https://reviews.freebsd.org/D59571

(cherry picked from commit fa7094c5b06fe31a025906bcee922a46c1b36ed6)
DeltaFile
+8-3share/man/man5/rc.conf.5
+8-31 files

FreeBSD/src 514bd44 — share/man/man5 rc.conf.5

rc.conf.5: Improve NOAUTO configuration + tag SPDX

- Show how to start a NOAUTOed interface
- "configured" is not quite right, try to improve that

MFC after:              3 days
Event:                  EuroBSDcon Devsummit 2026
Reviewed by:            adrian
Discussed with:         Antranig Vartanian <antranigv at freebsd.am>
Differential Revision:  https://reviews.freebsd.org/D59571

(cherry picked from commit fa7094c5b06fe31a025906bcee922a46c1b36ed6)
DeltaFile
+8-3share/man/man5/rc.conf.5
+8-31 files

FreeBSD/src 3b59336 — share/man/man4 ng_bpf.4 ng_async.4

ng manpages: Standardize descriptions

Netgraph document descriptions are all over the place, wordsmith them
into a standard format of "%s netgraph node", trying to describe them
better to enhance accessiblity of apropos results.

Event:                  EuroBSDcon 2026
MFC after:              3 days
Reviewed by:            dteske, glebius
Discussed with:         des, dteske, glebius
Differential Revision:  https://reviews.freebsd.org/D59643

(cherry picked from commit b1e3d6a668c5a8290ecf32c1badb9f0c9364d280)
DeltaFile
+2-4share/man/man4/ng_gif_demux.4
+2-3share/man/man4/ng_l2cap.4
+2-3share/man/man4/ng_hci.4
+2-2share/man/man4/ng_bpf.4
+2-2share/man/man4/ng_async.4
+2-2share/man/man4/ng_UI.4
+12-1646 files not shown
+103-10952 files

FreeBSD/src 2febf35 — sys/arm/broadcom/bcm2835 bcm2835_pwm.c

bcm2835_pwm: Fix dev.pwm.0.ratio2 register

A typo in the sysctl for RPI0 PWM channel 2 was causing it to
write to the wrong register, leaving it misconfigured if used.

PR:                     298301
MFC after:              3 days (problem reported on 14.4)
Reviewed by:            adrian
Reported by:            Attila Kover <attila.kover at guardian.co.uk>
Differential Revision:  https://reviews.freebsd.org/D59644

(cherry picked from commit 32878e64e687a848fceb710ab9b45e396f27db3f)
DeltaFile
+1-1sys/arm/broadcom/bcm2835/bcm2835_pwm.c
+1-11 files

FreeBSD/src c678389 — sys/arm/broadcom/bcm2835 bcm2835_pwm.c

bcm2835_pwm: Fix dev.pwm.0.ratio2 register

A typo in the sysctl for RPI0 PWM channel 2 was causing it to
write to the wrong register, leaving it misconfigured if used.

PR:                     298301
MFC after:              3 days (problem reported on 14.4)
Reviewed by:            adrian
Reported by:            Attila Kover <attila.kover at guardian.co.uk>
Differential Revision:  https://reviews.freebsd.org/D59644

(cherry picked from commit 32878e64e687a848fceb710ab9b45e396f27db3f)
DeltaFile
+1-1sys/arm/broadcom/bcm2835/bcm2835_pwm.c
+1-11 files

FreeBSD/src 206bf19 — share/man/man4 ng_bpf.4 ng_async.4

ng manpages: Standardize descriptions

Netgraph document descriptions are all over the place, wordsmith them
into a standard format of "%s netgraph node", trying to describe them
better to enhance accessiblity of apropos results.

Event:                  EuroBSDcon 2026
MFC after:              3 days
Reviewed by:            dteske, glebius
Discussed with:         des, dteske, glebius
Differential Revision:  https://reviews.freebsd.org/D59643

(cherry picked from commit b1e3d6a668c5a8290ecf32c1badb9f0c9364d280)
DeltaFile
+2-4share/man/man4/ng_gif_demux.4
+2-3share/man/man4/ng_l2cap.4
+2-3share/man/man4/ng_hci.4
+2-2share/man/man4/ng_bpf.4
+2-2share/man/man4/ng_async.4
+2-2share/man/man4/ng_UI.4
+12-1646 files not shown
+103-10952 files

FreeBSD/src c2089b6 — sys/fs/nfsclient nfs_clvfsops.c nfs.h, sys/rpc rpc_generic.c

nfscl: Add support for b_pages to be used by RDMA

This patch updates the NFS client RDMA glue so that I/O
can be done directly to/from b_pages for buffer cache
blocks.
It also adds a flag to disable read reduction, that might
be needed against some non-FreeBSD servers and sets readahead
to 8 for RDMA unless the "readahead" option has been
specified.

This commit should not affect non-RDMA behaviour.

MFC after:      3 months
Fixes:  884ee8d6c9b4 ("nfscl: Add some glue for client side NFS over RDMA")
DeltaFile
+35-23sys/rpc/rpc_generic.c
+22-19sys/fs/nfsclient/nfs_clrpcops.c
+9-6sys/fs/nfsclient/nfs_clvnops.c
+6-6sys/fs/nfsclient/nfs_clbio.c
+3-3sys/fs/nfsclient/nfs.h
+5-0sys/fs/nfsclient/nfs_clvfsops.c
+80-574 files not shown
+86-6110 files

FreeBSD/src f39219f — lib/libthr libthr.3

libthr.3: document LIBPTHREAD_PSHARED_LOCK_DESTROY_IMMEDIATE_GC

(cherry picked from commit c2f66b6616425e0e8edab3e893bc4cb58869140d)
DeltaFile
+7-1lib/libthr/libthr.3
+7-11 files

FreeBSD/src e831067 — lib/libthr/thread thr_private.h thr_init.c

libthr: GC pshared locks not more than each 25msecs by default

PR:     268532

(cherry picked from commit 4472a048cf95c9c1593a8b04655a59096b44b0c9)
DeltaFile
+22-3lib/libthr/thread/thr_pshared.c
+3-0lib/libthr/thread/thr_init.c
+1-0lib/libthr/thread/thr_private.h
+26-33 files

FreeBSD/src 0143078 — sys/compat/linux linux_event.c

linux(4): Fix signal mask restoration in epoll_pwait(2)/epoll_pwait2(2)

PR:             298878

(cherry picked from commit 16a284b1cdfd45ba99c2723e7f88497e76b235ad)
DeltaFile
+14-11sys/compat/linux/linux_event.c
+14-111 files

FreeBSD/src f12b765 — sys/kern kern_timeout.c

callout: do not retry a try-lock callout sooner than a tick

When softclock_call_cc() fails to acquire the lock of a CALLOUT_TRYLOCK
callout, it reschedules the callout half its precision after
cc_lastscan and halves the precision. Repeated failures shrink the
delay toward zero, and once the precision reaches 1 the callout is due
immediately: the timer fires again at once and softclock retries the
lock in a tight loop for as long as the lock is held.

If the lock owner runs on the callout's CPU and no other CPU is idle,
the softclock thread preempts it on every attempt, starving the thread
it is waiting on. On an 8-CPU arm64 VM, a test module holding the lock
saw 760,000 attempts per second, each with its own timer interrupt, and
progressed at 38% of its normal rate. On a 4-core amd64 system under
loopback TCP load, a netisr thread holding an inpcb lock made no
progress for 12 minutes while the TCP timer callout was retried 830,000
times per second.

Keep the half-precision retry, but never schedule it less than one

    [20 lines not shown]
DeltaFile
+20-3sys/kern/kern_timeout.c
+20-31 files

FreeBSD/src de0a279 — libexec/nuageinit nuageinit, libexec/nuageinit/tests nuageinit.sh

nuageinit: apply meta-data if user-data is a script

Tested by:      adam.mizerski at ovhcloud.com
Sponsored by:   OVHcloud
Pull Request:   https://github.com/freebsd/freebsd-src/pull/2446
DeltaFile
+14-12libexec/nuageinit/nuageinit
+16-3libexec/nuageinit/tests/nuageinit.sh
+30-152 files

FreeBSD/src 262fa46 — stand/libsa/zfs zfsimpl.c

stand: Implement zfs_dnode_readlink in terms of zfs_dnode_sa_lookup

Get the link offset using the zfs_dnode_sa_lookup helper now.

Recently, the symbolic links we rely on in the boot loader have stopped
working.

Prior to OpenZFS commit e90badec11d3 ("Inherit the project ID for every
object type", Matt Turner, 2026-08-14), symbolic link information was
written at a fixed offset in the SA data. Since that commit, the
inherited PROJIDs mean that all pools with quota enabled have started
writing symbolic links with a new, non-fixed offset. Old symbolic links
remained unchanged, but new ones were written with a different
offset. At work, we have all these things: rewritten BEs, quotas, and a
dependence on symbolic links in our boot path.

This came in on 2026-08-24 OpenZFS merge (22649d4dba73). This was 12
hours after stab week for August, so we didn't hit this until the
September stab week. Since the new kernel has to write links at the new

    [4 lines not shown]
DeltaFile
+4-31stand/libsa/zfs/zfsimpl.c
+4-311 files

FreeBSD/src 32fcc66 — stand/libsa/zfs zfsimpl.c

stand: Load dynamic system attribute offsets

zfs_sa_load looks up all the system attribute offsets and stores them in
the mountpoint.

Sponsored by:           Netflix
Differential Revision:  https://reviews.freebsd.org/D60264
DeltaFile
+122-0stand/libsa/zfs/zfsimpl.c
+122-01 files

FreeBSD/src 8bc06ba — stand/libsa/zfs zfsimpl.c

stand: Lookup specific SA value in a dnode

zfs_dnode_sa_lookup will look in the bonus part of the dnode for the
requested SA values, and fall back to the spill as if it's not there.

Sponsored by:           Netflix
Differential Revision:  https://reviews.freebsd.org/D60266
DeltaFile
+37-0stand/libsa/zfs/zfsimpl.c
+37-01 files

FreeBSD/src f382ef1 — stand/libsa/zfs zfsimpl.c

stand: update zfs_dnode_stat to use zfs_dnode_sa_lookup

Find the SA values with the zfs_dnode_sa_lookup and read out the
relevant bits for the stat buffer.

Sponsored by:           Netflix
Differential Revision:  https://reviews.freebsd.org/D60267
DeltaFile
+15-37stand/libsa/zfs/zfsimpl.c
+15-371 files