FreeBSD/src fa78e1d — share/man/man4 pci.4, sys/dev/pci pci_private.h pci_iov.c

pci: Reserve bus numbers required by SR-IOV VFs

Some firmware assigns only one bus number to each PCI-PCI bridge.  This
prevents later SR-IOV VF enumeration when a VF routing ID falls on a bus
number already allocated to a sibling bridge.

Reserve only the additional bus numbers required by SR-IOV PFs.
Enumerate all directly attached functions before child drivers and
bridges attach, inspect their device_t objects for SR-IOV, and grow the
PCI bus resource through the highest possible VF routing ID.

First VF Offset and VF Stride may change when NumVFs changes.  Probe
every valid NumVFs value and preserve the original setting.  When the
upstream hierarchy uses ARI, temporarily enable the SR-IOV ARI Hierarchy
control in the lowest-numbered PF while sizing, then restore it.  Scope
active-VF detection to each conventional PCI slot; an ARI bus remains
one slot-0 hierarchy.  If firmware left VFs enabled on a device, do not
modify it and reserve only its active layout.


    [20 lines not shown]
DeltaFile
+189-0sys/dev/pci/pci.c
+9-9sys/dev/pci/pci_iov.c
+10-1share/man/man4/pci.4
+3-0sys/powerpc/ofw/ofw_pcibus.c
+3-0sys/dev/pci/pci_private.h
+214-105 files

FreeBSD/src da0067d — sbin/ipfw nat64clat.c

ipfw: guard against NULL deref with clat/plat prefixes without length

Found with:     Claude Code Sonnet 5
MFC after:      2 weeks

(cherry picked from commit 47b02ace19c53e72ad2290d974025292ff97464a)
DeltaFile
+3-0sbin/ipfw/nat64clat.c
+3-01 files

FreeBSD/src 5799049 — sys/kern imgact_elf.c

exec: Remove an unneeded capability mode check

The subsequent namei() call is relative to AT_FDCWD, and such lookups
are always disallowed in capability mode.

No functional change intended.

Reviewed by:    emaste
Differential Revision:  https://reviews.freebsd.org/D59888
DeltaFile
+0-9sys/kern/imgact_elf.c
+0-91 files

FreeBSD/src a76e986 — lib/libc/gen sysctl.3, sys/kern kern_sysctl.c

sysctl: Return ECAPMODE when trying to access sysctls in capability mode

We have always returned EPERM in this case, but it's incorrect, we
should return ECAPMODE for capability mode violations.  Fix the errno
value.

Reviewed by:    emaste
MFC after:      2 weeks
Differential Revision:  https://reviews.freebsd.org/D59887
DeltaFile
+3-0lib/libc/gen/sysctl.3
+1-1sys/kern/kern_sysctl.c
+4-12 files

FreeBSD/src c52f99a — sys/amd64/amd64 machdep.c

amd64: use WRMSRNS immediate form to update splitlock control, when available

(cherry picked from commit 20c09e6fece29dbcf4835b4dd90e969f1b9b3e59)
DeltaFile
+34-4sys/amd64/amd64/machdep.c
+34-41 files

FreeBSD/src 0dce4f2 — sys/amd64/amd64 mp_machdep.c machdep.c, sys/amd64/include md_var.h pcpu.h

amd64: cache MSR_MEMORY_CTL in pcpu

(cherry picked from commit 74d325fee2dbcb5f8541819481ce76f87c151a21)
DeltaFile
+11-0sys/amd64/amd64/initcpu.c
+3-4sys/amd64/amd64/machdep.c
+2-1sys/amd64/include/pcpu.h
+2-0sys/amd64/amd64/mp_machdep.c
+1-0sys/amd64/include/md_var.h
+19-55 files

FreeBSD/src d95433e — sys/amd64/amd64 sys_machdep.c, sys/x86/include sysarch.h

amd64: add userspace control for disabling splitlocks

(cherry picked from commit 51cea5416a2421f29d22100bc71ab6486b1dc54a)
DeltaFile
+26-1sys/amd64/amd64/sys_machdep.c
+2-0sys/x86/include/sysarch.h
+28-12 files

FreeBSD/src 6d6a824 — sys/amd64/amd64 vm_machdep.c exec_machdep.c, sys/amd64/include proc.h md_var.h

amd64: support for tracking per-thread 'disable splitlocks' state

(cherry picked from commit e318f24c0f53b52bd280b827509ad752db0497bf)
DeltaFile
+36-0sys/amd64/amd64/machdep.c
+14-0sys/amd64/amd64/pmap.c
+10-0sys/amd64/amd64/exec_machdep.c
+5-0sys/amd64/include/md_var.h
+2-0sys/amd64/include/proc.h
+2-0sys/amd64/amd64/vm_machdep.c
+69-03 files not shown
+72-09 files

FreeBSD/src ca7aa1c — sys/amd64/include proc.h

amd64: add md thread flags word

(cherry picked from commit dc975612213369f597449ced5a3c5edabc2aae6d)
DeltaFile
+1-0sys/amd64/include/proc.h
+1-01 files

FreeBSD/src b4a9afd — sys/amd64/amd64 machdep.c initcpu.c, sys/amd64/include md_var.h

amd64: calculate if hardware supports disabling splitlocks

(cherry picked from commit d8c1abb0e3409314fb89400bc85b5051649e91ab)
DeltaFile
+18-0sys/amd64/amd64/initcpu.c
+11-0sys/amd64/amd64/machdep.c
+3-0sys/amd64/include/md_var.h
+32-03 files

FreeBSD/src 77a99f3 — sys/amd64/amd64 trap.c

amd64: handle #AC in kernel mode

(cherry picked from commit c6d7235ac15d208435a839bf847dd898d9b1d9fe)
DeltaFile
+8-0sys/amd64/amd64/trap.c
+8-01 files

FreeBSD/src 54cb4bf — sys/amd64/include cpufunc.h

amd64: gate WRMSRNS immediate form on compiler support

(cherry picked from commit 53fe018630d06eeef6791cfacaa6dc9acdf4d669)
DeltaFile
+10-0sys/amd64/include/cpufunc.h
+10-01 files

FreeBSD/src 61412c0 — sys/amd64/include cpufunc.h

amd64 cpufunc.h: add WRMSRNS helpers

(cherry picked from commit 4a8acccc2e59b6ac5f4068471d94b40347ebeff0)
DeltaFile
+13-0sys/amd64/include/cpufunc.h
+13-01 files

FreeBSD/src ee05a36 — sys/netpfil/pf pf_table.c, tests/sys/netpfil/pf table.sh

pf: do not loop on an address that is cleared twice in pfr_clr_astats()

pfr_clr_astats() looks up each address it is given and inserts the entry
it finds at the head of a work queue. If the same address is given more
than once, the entry is inserted twice and the second insertion makes it
its own successor. pfr_clstats_kentries() then walks the queue forever,
with the rules lock held for writing, so packet processing and every
other pf operation in that vnet stop as well. To reproduce:

pfctl -e
pfctl -t foo -T add 192.0.2.1
pfctl -t foo -T zero 192.0.2.1 192.0.2.1

Do as pfr_del_addrs() does: clear pfrke_mark on the entries named, then
queue an entry only the first time it is seen. An address given more
than once is cleared, and counted, once. Validate all addresses before
any entry is touched.

Add a regression test.

    [6 lines not shown]
DeltaFile
+34-0tests/sys/netpfil/pf/table.sh
+9-2sys/netpfil/pf/pf_table.c
+43-22 files

FreeBSD/src f084f28 — sys/netpfil/pf pf_table.c, tests/sys/netpfil/pf table.sh

pf: fix NULL dereference in pfr_set_addrs() with feedback

Since DIOCRSETADDRS was converted to netlink, pf_handle_table_set_addrs()
calls pfr_set_addrs() with a NULL size2, as the netlink interface has no
buffer to return the deleted addresses in. pfr_set_addrs() only checked
size2 for NULL at the end of the function; with PFR_FLAG_FEEDBACK set it
dereferenced it unconditionally first. pfctl sets PFR_FLAG_FEEDBACK
when run with -v, so "pfctl -v -t foo -T replace ..." panicked the
kernel with a NULL pointer dereference. To reproduce:

pfctl -e
pfctl -t foo -T add 192.0.2.1
pfctl -v -t foo -T replace 192.0.2.2

Check size2 for NULL before dereferencing it, as is already done at the
end of the function. The per-address feedback for added and changed
addresses is still copied back as before; only the list of deleted
addresses, which the netlink caller has no room for, is skipped.


    [9 lines not shown]
DeltaFile
+34-0tests/sys/netpfil/pf/table.sh
+2-2sys/netpfil/pf/pf_table.c
+36-22 files

FreeBSD/src 334e874 — share/man/man4 wsp.4

wsp.4: Canonicalize SYNOPSIS + tag SPDX

MFC after:              3 days
Reviewed by:            wulf
Differential Revision:  https://reviews.freebsd.org/D59257
DeltaFile
+8-12share/man/man4/wsp.4
+8-121 files

FreeBSD/src 3a542d8 — share/man/man4 uep.4

uep.4: Canonicalize SYNOPSIS, KERNEL CONFIGURATION

MFC after:              3 days
Reviewed by:            glebius, wulf
Differential Revision:  https://reviews.freebsd.org/D59869
DeltaFile
+19-18share/man/man4/uep.4
+19-181 files

FreeBSD/src 9d30640 — sys/dev/hwpmc hwpmc_amd.h hwpmc_mod.c, sys/sys pmc.h

hwpmc_amd: add PerfMonV2 global-control path

Add support for AMD PerfMonV2 (Family 19h+) core counters, which need
both the per-counter EVSEL enable bit and the global GLOBAL_CTL bit set
to count. Detects PerfMonV2 at init and switches to v2-specific
start/stop/interrupt handlers; older CPUs and L3/DF counters keep using
the classic path unchanged.

Adds a read-only sysctl, kern.hwpmc.amd_perfmon_v2, to report which path
is active.

Signed-off-by:  Andre Silva <andasilv at amd.com>
Reviewed by:    Ali Mashtizadeh <ali at mashtizadeh.com>
Sponsored by:   AMD
Differential Revision:  https://reviews.freebsd.org/D58256
DeltaFile
+489-18sys/dev/hwpmc/hwpmc_amd.c
+69-0sys/dev/hwpmc/hwpmc_mod.c
+11-0sys/dev/hwpmc/hwpmc_amd.h
+5-0sys/sys/pmc.h
+574-184 files

FreeBSD/src c901f93 — usr.sbin/bhyve pci_emul.c

bhyve: fix boot device ordering

EDK2's QemuBootOrderLib inspects the bootorder file provided
via fw_cfg and requires it to be NUL-terminated. Otherwise,
it rejects the supplied bootorder and falls back to its
default boot order.

Currently, bhyve registers bootorder with qemu_fwcfg_add_file()
using bootorder_len returned by open_memstream(), which excludes
the trailing NUL byte.

Fix that by passing bootorder_len + 1 to qemu_fwcfg_add_file() so
the fw_cfg payload is properly NUL-terminated.

PR:             279720
Reviewed by:    markj
Found with:     codex (gpt-5.6-sol)
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation

    [3 lines not shown]
DeltaFile
+1-1usr.sbin/bhyve/pci_emul.c
+1-11 files

FreeBSD/src 34b00ed — sys/dev/hwpmc hwpmc_ibs.c

hwpmc: fix IBS fetch and op NMI handling

Service each IBS unit with a valid bit set when fetch and op share an
NMI. Otherwise, op samples can be lost. Treat the extra NMI that follows
as expected (skip it).

Reviewed by:    mhorne
Fixes:  e51ef8ae490f ("hwpmc: Initial support for AMD IBS")
Differential Revision:  https://reviews.freebsd.org/D60004
DeltaFile
+20-3sys/dev/hwpmc/hwpmc_ibs.c
+20-31 files

FreeBSD/src f3c0dcd — sys/dev/ipmi ipmi_isa.c

ipmi: Add some additional diagnostic output on errors

Add some additional diagnostic output for IPMI code,
particularly on error paths. This has been found to be helpful at
$WORK and seems generally useful, so contributing the changes back to
upstream.

Sponsored by: Dell Technologies
Reviewed by: vangyzen@
Differential Revision: https://reviews.freebsd.org/D60091
DeltaFile
+16-1sys/dev/ipmi/ipmi_isa.c
+16-11 files

FreeBSD/src 2f49e40 — lib/clang llvm.build.mk, lib/clang/include/llvm/Config Disassemblers.def AsmPrinters.def

llvm: add LoongArch target support, not enabled by default

Note there is ongoing work to add LoongArch support to the base system,
but having target support in llvm is an essential component.

This must be explicitly enabled using WITH_LLVM_TARGET_LOONGARCH.

Reviewed by:    dim
MFC after:      1 week
Differential Revision: https://reviews.freebsd.org/D59899
DeltaFile
+49-6lib/clang/libllvm/Makefile
+3-4share/man/man5/src.conf.5
+6-0lib/clang/llvm.build.mk
+3-0lib/clang/include/llvm/Config/Disassemblers.def
+3-0lib/clang/include/llvm/Config/AsmPrinters.def
+3-0lib/clang/include/llvm/Config/AsmParsers.def
+67-106 files not shown
+74-1412 files

FreeBSD/src 1a6e0c3 — usr.sbin/bhyve pci_emul.c

bhyve: fix boot device ordering

EDK2's QemuBootOrderLib inspects the bootorder file provided
via fw_cfg and requires it to be NUL-terminated. Otherwise,
it rejects the supplied bootorder and falls back to its
default boot order.

Currently, bhyve registers bootorder with qemu_fwcfg_add_file()
using bootorder_len returned by open_memstream(), which excludes
the trailing NUL byte.

Fix that by passing bootorder_len + 1 to qemu_fwcfg_add_file() so
the fw_cfg payload is properly NUL-terminated.

PR:             279720
Reviewed by:    markj
Found with:     codex (gpt-5.6-sol)
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation

    [3 lines not shown]
DeltaFile
+1-1usr.sbin/bhyve/pci_emul.c
+1-11 files

FreeBSD/src 592ede6 — lib/libkvm kvm_powerpc64.h kvm_minidump_powerpc64.c, lib/libkvm/tests kvm_open2_test.c

libkvm: support powerpc64 radix minidumps

PowerPC64 radix minidumps use a 64KB root directory followed by three
levels of 4KB page tables.  Add an MMU backend which walks those tables,
handles large-page leaves, and decodes their always-big-endian entries
on both powerpc64 and powerpc64le.

Reject old radix minidumps whose pmap section is empty with a specific
diagnostic.  Add a synthetic powerpc64le dump test which reads a page
through both its kernel and direct-map addresses.

PR:             298532
Reviewed by:    jhb
Approved by:    jhb (mentor)
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59743
DeltaFile
+270-0lib/libkvm/kvm_minidump_powerpc64_radix.c
+118-0lib/libkvm/tests/kvm_open2_test.c
+2-1lib/libkvm/Makefile
+2-0lib/libkvm/kvm_powerpc64.h
+2-0lib/libkvm/kvm_minidump_powerpc64.c
+394-15 files

FreeBSD/src a38a698 — sys/powerpc/aim mmu_radix.c

powerpc/radix: include page tables in minidumps

The radix pmap did not implement the minidump pmap callbacks, so radix
minidumps were emitted with an empty pmap section.  Such dumps do not
contain enough information for libkvm to translate kernel virtual
addresses.

Snapshot the 64KB radix root table in the pmap section, add lower-level
page-table pages to the sparse dump, and include pages backing non-DMAP
kernel mappings.  Keep the bulk direct map out of the dump while
retaining the relocated kernel image.

PR:             298532
Reviewed by:    jhb
Approved by:    jhb (mentor)
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59743
DeltaFile
+157-0sys/powerpc/aim/mmu_radix.c
+157-01 files

FreeBSD/src 4cb357c — sys/arm/arm minidump_machdep.c

arm: pad minidump page table

libkvm locates the sparse page array after the page-rounded PTE table
size, but the ARM minidump writer emitted only the unrounded size.  When
the table size was not page-aligned, libkvm therefore read every dumped
physical page at the wrong offset.

The mismatch was introduced when libkvm began rounding ptesize.  It has
affected ARM minidumps since ffdeef323449 ("libkvm: Improve physical
address lookup scaling."). It is exposed when the dumped KVA span is not
a multiple of 4 MiB.

Zero-pad the final PTE page and include the padding in the dump size.

Reviewed by:    jhb
Approved by:    jhb (mentor)
Fixes:          ffdeef323449 ("libkvm: Improve physical address lookup scaling.")
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59716
DeltaFile
+4-2sys/arm/arm/minidump_machdep.c
+4-21 files

FreeBSD/src 61f98a9 — sys/netinet6 nd6.c

nd6: Fix regeneration of temp addresses in detached state

When an on-link prefix becomes detached, the kernel keeps
generating new RFC 8981 temporary addresses for that prefix.
Fix it by ignoring the detached addresses in regen_tmpaddr().
While here, change its return type to bool.

PR:             298533
Discussed with: markj
MFC after:      3 days
Differential Revision:  https://reviews.freebsd.org/D60051
DeltaFile
+18-12sys/netinet6/nd6.c
+18-121 files

FreeBSD/src 8d31b78 — . .cirrus.yml, .cirrus-ci pkg-install.sh

ci: Remove Cirrus CI files

Cirrus CI shutted down its service on June 1, 2026 and its CI dashboard
website (https://cirrus-ci.com) is now inaccessible. Since these files
are no longer used, remove them from the repository.

Reviewed by:    brooks, emaste, lwhsu
Approved by:    olce (mentor)
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59858
DeltaFile
+0-237.cirrus.yml
+0-22.cirrus-ci/pkg-install.sh
+0-2592 files

FreeBSD/src 8970a9f — sys/powerpc/aim mmu_radix.c

powerpc/radix: synchronize temporary kernel mappings

The radix kremove implementation cleared a kernel PTE without
invalidating its TLB entry.  Reusing crashdumpmap could therefore keep
accessing an old physical page, causing minidumps to contain repeated
stale page contents.

Invalidate the removed kernel mapping and synchronize newly installed
kernel PTEs before they are accessed.

Reviewed by:    jhibbits
Approved by:    olce (mentor)
Fixes:          65bbba25d214 ("powerpc64: Implement Radix MMU for POWER9 CPUs")
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59728
DeltaFile
+3-0sys/powerpc/aim/mmu_radix.c
+3-01 files

FreeBSD/src 7b8f3db — lib/libkvm kvm_minidump_powerpc64_hpt.c kvm_minidump_powerpc64.c

libkvm: support little-endian powerpc64 minidumps

Reviewed by:    jhibbits
Approved by:    olce (mentor)
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59719
DeltaFile
+12-12lib/libkvm/kvm_minidump_powerpc64.c
+2-2lib/libkvm/kvm_minidump_powerpc64_hpt.c
+14-142 files