t_ipsec_policy: Skip if net.inet.ipsec.enabled doesn't exist too.
Presumably this means the kernel was built without IPsec support.
PR kern/60669: netipsec key_sp2msg buffer overrun
x11/picom: update to 13
pkgsrc: now that 9 was deprecated this can be imported.
IIRC it should build with 10 default gcc.
v13
(see also: v13-rc1)
v13-rc1 (2025-Dec-09)
New features
Separate the "geometry" animation trigger into "size" and "position" to allow finer-grained control. "geometry" is kept as an alias for setting both "size" and "position".
Add a "urgent" target that can be used in rules to match urgent (according to ICCCM) windows. (#1445)
New "shadow-color" per-window option can now be used in rules to give each window a different shadow color. (#257)
Added new animation trigger color, which can now be used to transition window shadow-color changes. (#257)
Add support for using custom shaders when rendering the desktop background. (#1440)
New variables "window-blur-opacity-before", and "window-blur-opacity" are now available in animation scripts. (#919)
New per-window option blur-opacity can now be used in rules. (#919)
Macro definitions can now be specified when setting shader in window rules. (#1066)
[187 lines not shown]
misc/rozi: update to 0.0.28
Added
You can unlock a checkout with Ctrl+U in the Worktrees picker or rozi worktrees unlock <PATH>. For a stale-locked checkout, confirm its removal with Ctrl+K in the picker or the sidebar remove action. (#84)
The Agents view can list each Claude Code conversation under its own repository and branch, alongside the hook state for the conversation it follows. (#85)
Sessions has a tab for each host in use. The active tab scopes session listing and session creation, including Ctrl+N, Ctrl+T, and Ctrl+X. (#87)
You can opt in to keeping a host awake while agent runtimes are Working with [session] keep_awake_while_agents_work = true or Settings → Sessions → Keep awake while agents work. It is disabled by default. (#90)
Changed
The remote install dialog presents host, destination, and version as labeled rows. The destination shows the managed install path with the home directory shortened to ~. During installation, the host shows an installing… status in the Remote hosts picker and sidebar. (#83)
Worktrees picker rows show the branch with the path and state in one description. The picker can grow to 160 columns, within the viewport. (#89)
Fixed
Interactive clients and CLI commands can prompt for SSH authentication by default, including host-key approval. Commands without a UI broker or terminal, background monitoring, and explicit batch_mode = true remain noninteractive. (#82)
In Remote hosts, Enter connects to a disconnected or unreachable host, and Ctrl+R is unavailable. For a reached or connected host, Enter opens its sessions and Ctrl+R reconnects. (#86)
The command palette lists Worktrees only when the focused pane has an attached session on a repository and is not on a nested SSH host. A key bound to open-worktrees still runs and explains why Worktrees is unavailable. (#88)
[6 lines not shown]
audio/ncspot: update to 1.5.0
Added
Vim-like command completion by pressing Tab
Support Vim-style numeric count prefixes for keybindings (e.g. 10j moves
down 10 rows); the pending count is shown in the status bar
Add a proxy configuration option that routes all of ncspot's network
traffic (access point, Spotify APIs, OAuth and cover art downloads) through
a single proxy. Supports HTTP CONNECT proxies and SOCKS5 proxies with
remote DNS resolution (socks5h://), both with optional credentials.
Without this option, the http_proxy environment variable is still
honoured as before.
Replace already existing queue notifications instead of stacking new ones.
What's Changed
chore(deps): bump log from 0.4.33 to 0.4.34 in the cargo group by @dependabot[bot] in #1865
chore(toolchain): update by @hrkfdn in #1864
[9 lines not shown]
t_sigio: Add diagnostics to fillpipebuf.
For some reason, on some of the releng testbeds, in
socket_local_write_shutdown (and only socket_local_write_shutdown),
it's putting only 7168 (= 8192 - 1024) bytes into a local socket's
buffer before write fails with EAGAIN, but then _after_ fillpipebuf
has returned, write succeeds:
filled 4 with 7168 bytes
[thread] waiting for barrier
[thread] giving other thread a head start
checking that write fails with 35 (Resource temporarily unavailable)...
*** Check failed: /tmp/build/2026.10.02.08.45.07-i386/src/tests/lib/libc/sys/t_sigio.c:368: Expected true value in (nwrit = write(writefd, &c, 1)) == -1
*** Check failed: /tmp/build/2026.10.02.08.45.07-i386/src/tests/lib/libc/sys/t_sigio.c:369: nwrit != -1: nwrit=1
[thread] shutdown(SHUT_RD)
[thread] shutdown
But on my machine, and presumably on other testbeds where the test
passes, it fills the whole 8192 bytes before EAGAIN, and the next
[24 lines not shown]
t_fdrestart: Skip signal handler; let atf take SIGALRM as failure.
Safer than calling atf_tc_fail in the SIGALRM handler, and the xfail
is finer-grained this way (any check failure will be reported as test
failure; only SIGALRM will be reported as expected).
PR kern/57659: closing pipe writefd fails to wake concurrent write on
same writefd