[TailCallElim] Do not mark a call tail when it is handed the frame (#218797)
markTails refuses to mark a call tail if it is passed an alloca or a
byval
argument, but it missed the intrinsics that return an address in the
current
frame, such as llvm.frameaddress(0), llvm.localaddress and
llvm.stacksave. The
frame is torn down before a tail callee runs, so the callee received a
dangling
pointer. gcc.c-torture/execute/frame-address.c aborts because of this.
llvm.stackrestore is no longer treated as an escape, since it does not
capture
its argument. Otherwise calls after a VLA scope would lose their tail
marking.
LangRef now states that a tail callee may not access the caller's stack
frame.
[3 lines not shown]
[VectorCombine] Fold insertelement chains of scalar parts to a bitcast and shuffle (#226224)
An insertelement chain whose elements are all truncated parts of the
same scalar is lowered element by element, unless InstCombine can turn
an in-order pair of halves into a bitcast (`foldTruncInsEltPair`). The
SLP vectorizer produces such chains for the fields of a struct that SROA
loaded as one integer, e.g. when summing two float fields in a loop:
```llvm
%hi = lshr i64 %x, 32
%h = trunc i64 %hi to i32
%l = trunc i64 %x to i32
%v0 = insertelement <2 x i32> poison, i32 %h, i64 0
%v1 = insertelement <2 x i32> %v0, i32 %l, i64 1
```
which X86 lowers to shrq + vmovd + vpinsrd. If TTI says it is cheaper,
replace the chain by a shuffle of the bitcast scalar:
[27 lines not shown]
py-scrapy: updated to 2.19.0
Scrapy 2.19.0 (2026-09-10)
Highlights:
- New ``RemoteControl`` extension which allows inspecting and controlling a
running crawl over HTTP, used by the :ref:`Scrapy MCP server
<using-mcp-server>`
- Experimental ``aiohttp``-based download handler (now the default when
running without a reactor)
Modified requirements
- Added support for Python 3.15.
- New dependencies:
- aiohttp_ >= 3.13.3
[215 lines not shown]
[CIR][CUDA][HIP] Exclude wrong-side virtual functions from vtables (#228433)
OGCG builds the vtables of a CUDA/HIP compilation for the side being
compiled, that is a slot whose virtual function cannot be emitted on
that side is null.
Port both parts of CodeGenVTables::addVTableComponent to
CIRGenVTables::getVTableComponent. As in OGCG, a null slot that holds a
thunk still advances the thunk index, so later thunks keep their slots.
Assisted-by: Claude Opus 5.5
Signed-off-by: Steffen Holst Larsen <sholstla at amd.com>
openssl: Fix CVE-2026-84782
This is a backport of an upstream commit to fix:
dtls: reset init_off before retransmitting a message
Approved by: so
Security: FreeBSD-SA-26:68.openssl
Security: CVE-2026-84782
unix: Preserve FD_RESOLVE_BENEATH when passing an fd
The FD_RESOLVE_BENEATH flag is supposed to be sticky. It's set when you
receive an fd from a different jail and preserved by openat(<dfd>) etc..
However, if you send the fd to yourself, the flag is stripped since
SCM_RIGHTS message don't preserve file descriptor flags.
Fix this by preserving those flags and checking for UF_RESOLVE_BENEATH
in restrict_rights().
Approved by: so
Security: FreeBSD-SA-26:66.jail
Security: CVE-2026-101306
Fixes: 350ba9672a7f ("unix: Set O_RESOLVE_BENEATH on fds transferred between jails")
Reviewed by: kib
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D58317
[2 lines not shown]
vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors
The FD_RESOLVE_BENEATH flag was intended to try to resolve bugzilla PR
262179 without entirely disallowing fd passing between jails. However,
one can use renameat() to bypass the restriction: upon receiving a
directory fd with FD_RESOLVE_BENEATH set, a jailed process can still
move its CWD or one of its ancestors to the directory, and just cd
out of its jail root.
So disallow renameat() when either the source or destination directory
fds has FD_RESOLVE_BENEATH set, like we do with fchdir() and fchroot()
to prevent similar escapes.
Approved by: so
Security: FreeBSD-SA-26:66.jail
Security: CVE-2026-101305
PR: 262179
Reported by: firk at cantconnect.ru
Reviewed by: olce, kib
Differential Revision: https://reviews.freebsd.org/D59875
net/frr: CARP event handler, skip interfaces that report OSPF as not running (#5762)
The handler assumed that every interface listed by ospfd has
a cost. ospfd lists an interface on which OSPF is not running (e.g. a
CARP bound WireGuard instance that is down on the backup node) without
one, so the handler ended with KeyError: 'cost' and left all following
interfaces in ospfd_carp.conf at their default cost.
Skip such interfaces and continue with the rest.
fdescfs: Pass up additional metadata during lookups
When an fdescfs mount has the nodup option set, fdesc_lookup(/dev/fd/n)
returns the vnode referenced by file descriptor n, rather than returning
an fdescfs vnode. This meant that fd metadata attached to fd n was not
preserved when reopening the file, which is contrary to the expected
semantics for capsicum rights and the UF_RESOLVE_BENEATH fd flag. For
regular fdescfs mounts, this metadata is copied via dupfdopen().
Fix the problem by passing up this metadata through the nameidata
structure. Thus, if one opens /dev/fd/n, the returned fd will inherit
UF_RESOLVE_BENEATH and the capability rights of fd n. Add some
regression tests as well.
Approved by: so
Security: FreeBSD-SA-26:66.jail
Security: CVE-2026-101304
Reported by: Jan Bramkamp
Reviewed by: kib
[2 lines not shown]
file: Add filecaps_intersect() and cap_rights_intersect()
These routines let one compute the intersection of two sets of filecaps
or capability rights, just as filecaps_merge() and cap_rights_merge()
compute the union. This will be useful in an upcoming patch.
filecaps_intersect() is complex due to the need to merge sets of ioctls.
For now this is implemented with a dumb nested loop on the basis that
ioctl lists are typically short enough that this is fine. It may be
better to instead sort the two lists first and step through them
together.
No functional change intended.
Approved by: so
Security: FreeBSD-SA-26:66.jail
Reviewed by: kib
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59885
file: Add a helper function to check whether filecaps are full
In a couple of places we want to know whether someone has limited rights
on an fd. There, we want a predicate which determines whether the set
of rights is smaller than CAP_ALL, and whether there are explicit ioctl
or fcntl lists. Factor this out into a helper function, in preparation
for use elsewhere.
No functional change intended.
Approved by: so
Security: FreeBSD-SA-26:66.jail
Reviewed by: kib
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59884
udp: Let jail policy rewrite the dstaddr for v6 sendto()s
When performing an unconnected sendto() on a v6 UDP socket in a classic
jail, we were not applying the usual policy of replacing the loopback
addr with the jail's primary IP. Compare with, e.g., udp6_connect() or
the IPv4 udp_send(). Fix that.
Approved by: so
Security: FreeBSD-SA-26:69.udp
Security: CVE-2026-101303
Reported by: Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li,
and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai
Reviewed by: bz, glebius
MFC after: 2 weeks
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59772
(cherry picked from commit fecb9537a83b6746bc731a7cb3bcf6a33df79562)
(cherry picked from commit 809221661a8136a19661e4e379a44203e0ea2a03)
ktls: Fix an off-by-one bug in tls13_find_record_type()
If the entire plaintext is zero-filled, the backwards walk in
tls13_find_record_type() would return the offset of the last byte of the
TLS header. This causes an underflow when decrypting, resulting in a
null pointer dereference.
Fix the bug and add a regression test.
Approved by: so
Security: FreeBSD-SA-26:67.ktls
Security: CVE-2026-101302
Reviewed by: gallatin, jhb
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D59767
(cherry picked from commit 7c5e457d3afdc7742ee24f0b5ee6e5e7aa00a6bd)
(cherry picked from commit fc1a02c93ba4c9a98e329a4166618bbaf17d584b)