LLVM/project 956a164 — llvm/test/CodeGen/AMDGPU/GlobalISel llvm.amdgcn.struct.buffer.atomic.cmpswap.ll llvm.amdgcn.raw.ptr.buffer.load.ll

AMDGPU: Mark SCC clobbers dead in GlobalISel waterfall loops

Co-authored-by: Claude Opus 5 <noreply at anthropic.com>
DeltaFile
+120-120llvm/test/CodeGen/AMDGPU/GlobalISel/llvm.amdgcn.s.buffer.load.ll
+64-64llvm/test/CodeGen/AMDGPU/GlobalISel/regbankselect-amdgcn.s.buffer.load.ll
+36-36llvm/test/CodeGen/AMDGPU/GlobalISel/llvm.amdgcn.raw.buffer.load.ll
+34-34llvm/test/CodeGen/AMDGPU/GlobalISel/llvm.amdgcn.raw.buffer.store.ll
+24-24llvm/test/CodeGen/AMDGPU/GlobalISel/llvm.amdgcn.struct.buffer.atomic.cmpswap.ll
+24-24llvm/test/CodeGen/AMDGPU/GlobalISel/llvm.amdgcn.raw.ptr.buffer.load.ll
+302-30269 files not shown
+788-78475 files

LLVM/project 1ddb374 — llvm/test/CodeGen/AMDGPU/GlobalISel global-atomic-fadd.f32-rtn.ll divergence-structurizer.ll

AMDGPU/GlobalISel: Mark SCC clobbers on control flow pseudos dead

Co-Authored-By: Claude Opus 5 <noreply at anthropic.com>
DeltaFile
+36-22llvm/test/CodeGen/AMDGPU/GlobalISel/legalize-brcond.mir
+22-22llvm/test/CodeGen/AMDGPU/GlobalISel/llvm.amdgcn.wqm.demote.ll
+16-16llvm/test/CodeGen/AMDGPU/GlobalISel/global-atomic-fadd.f32-no-rtn.ll
+13-13llvm/test/CodeGen/AMDGPU/GlobalISel/divergence-divergent-i1-used-outside-loop.ll
+12-12llvm/test/CodeGen/AMDGPU/GlobalISel/global-atomic-fadd.f32-rtn.ll
+12-12llvm/test/CodeGen/AMDGPU/GlobalISel/divergence-structurizer.ll
+111-976 files not shown
+152-13112 files

LLVM/project 0f5654d — llvm/lib/Target/RISCV/GISel RISCVLegalizerInfo.cpp, llvm/test/CodeGen/RISCV/GlobalISel half-convert.ll

[RISCV][GlobalIsel] Use Zfhmin for G_FPEXT from f16 to f32 (#227225)

fcvt.s.h is available with Zfhmin. Use the __extendhfsf2 libcall without
it.
DeltaFile
+82-0llvm/test/CodeGen/RISCV/GlobalISel/half-convert.ll
+2-1llvm/lib/Target/RISCV/GISel/RISCVLegalizerInfo.cpp
+84-12 files

LLVM/project ec0b2cd — llvm/lib/Target/AMDGPU SIInstrInfo.cpp, llvm/test/CodeGen/AMDGPU move-load-addr-to-valu-flat.mir move-load-addr-to-valu.mir

AMDGPU: Mark SCC clobber dead when moving scalar branches to VALU

Co-Authored-By: Claude Opus 5 <noreply at anthropic.com>
DeltaFile
+10-10llvm/test/CodeGen/AMDGPU/move-load-addr-to-valu.mir
+8-8llvm/test/CodeGen/AMDGPU/move-load-addr-to-valu-flat.mir
+2-1llvm/lib/Target/AMDGPU/SIInstrInfo.cpp
+20-193 files

LLVM/project 1b14a3e — lld/test/ELF loongarch-relax-pcrel-stress.s loongarch-relax-call-stress.s

Address weining's comments
DeltaFile
+17-6lld/test/ELF/loongarch-relax-pcrel-stress.s
+17-6lld/test/ELF/loongarch-relax-call-stress.s
+34-122 files

FreeBSD/ports e2adb01 — sysutils/modules pkg-plist distinfo

sysutils/modules: Update to 5.7.0

- Use the Tcl interpreter selected by the ports framework
- Add missing runtime bash dependency and SHEBANG_FILES for envml
- Drop the unnecessary Sphinx build dependency
- Fix Portscout release detection

Release notes:
https://github.com/envmodules/modules/releases/tag/v5.7.0

Approved by:    thierry (mentor, implicit)
DeltaFile
+10-7sysutils/modules/Makefile
+3-3sysutils/modules/distinfo
+3-1sysutils/modules/pkg-plist
+16-113 files

LLVM/project a82586d — llvm/lib/Transforms/Scalar GVN.cpp

[fixup] Clean GVNPassImpl from histerical cruft
DeltaFile
+7-9llvm/lib/Transforms/Scalar/GVN.cpp
+7-91 files

LLVM/project 31db0f0 — llvm/lib/Target/AMDGPU SIInstrInfo.cpp, llvm/test/CodeGen/AMDGPU/GlobalISel legalize-trap-gfx11.mir

AMDGPU: Mark scc clobbers in the simulated trap expansion dead

Co-Authored-By: Claude Opus 5 <noreply at anthropic.com>
DeltaFile
+4-4llvm/test/CodeGen/AMDGPU/GlobalISel/legalize-trap-gfx11.mir
+4-2llvm/lib/Target/AMDGPU/SIInstrInfo.cpp
+8-62 files

FreeBSD/src b55b6e1 — sys/fs/cuse cuse.c

cuse: Rename cuse_server_free() to cuse_server_dtor()

This name is clearer, given that this function is the cdevpriv
destructor callback.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
DeltaFile
+2-2sys/fs/cuse/cuse.c
+2-21 files

FreeBSD/src f96c4f4 — sys/fs/cuse cuse.c

cuse: Assert the server refcount

Assert that the refcount does not underflow before decrementing it, and
that it really is zero by the time the server is freed.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D60043
DeltaFile
+2-0sys/fs/cuse/cuse.c
+2-01 files

FreeBSD/src d38ef1a — sys/fs/cuse cuse.c

cuse: Implement hot-unload

cuse_kern_uninit() can hang on destroy_dev(), because of threads
sleeping in CUSE_IOCTL_GET_COMMAND, so implement d_purge to wake them up
before calling destroy_dev(). Also do not allow threads to go back to
sleep if the is_closing flag has been set.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D60022
DeltaFile
+59-33sys/fs/cuse/cuse.c
+59-331 files

FreeBSD/src fad756f — sys/fs/cuse cuse.c

cuse: Use make_dev_s() to create client devices

make_dev_s() sets si_drv1 before the node is published in devfs, which
avoids a race where cuse_client_open() could see it as NULL. It also now
reports finer-grained errors on failure, instead of only ENOMEM.

While here, drop the NULL checks on kern_dev in cuse_server_free_dev(),
since a device is only added to the server's list once it has been
created.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D59874
DeltaFile
+13-13sys/fs/cuse/cuse.c
+13-131 files

FreeBSD/src 34b00da — sys/fs/cuse cuse_defs.h cuse.c

cuse: Retire unnecessary CUSE_VERSION

No functional change intended.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
DeltaFile
+0-4sys/fs/cuse/cuse.c
+0-2sys/fs/cuse/cuse_defs.h
+0-62 files

FreeBSD/src e923a30 — sys/fs/cuse cuse.c

cuse: Remove unnecessary semicolon in cuse_convert_error()

No functional change intended.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
DeltaFile
+0-1sys/fs/cuse/cuse.c
+0-11 files

FreeBSD/src 40431ec — sys/fs/cuse cuse.c

cuse: Improve server cleanup

Move cuse_server_unref()'s device cleanup loop into a new
cuse_server_free_devs_locked(), and call it from cuse_server_free()
instead. The cdevpriv destructor now destroys the server's devices
before dropping its reference, which closes the clients using them, so
that the destructor is always the one that takes the last reference.

By the time cuse_server_unref() frees the server, the device list should
be empty, so assert this.

In cuse_kern_uninit(), delete the infinite loop which waits for all open
/dev/cuse instances to exit, and instead call destroy_dev() directly,
which runs their cdevpriv destructor.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D59872
DeltaFile
+22-30sys/fs/cuse/cuse.c
+22-301 files

FreeBSD/src 3b3e647 — sys/fs/cuse cuse.c

cuse: Create /dev/cuse with MAKEDEV_CHECKNAME

Since we now use make_dev_credf(), make sure to fail kldload if it
returned NULL.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D59863
DeltaFile
+12-6sys/fs/cuse/cuse.c
+12-61 files

FreeBSD/src 2fd8d2e — sys/fs/cuse cuse.c

cuse: Actually use cuse_modevent()

We can call cuse_kern_init()/cuse_kern_uninit() here, rather than using
SYSINIT/SYSUNINIT.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D59862
DeltaFile
+33-30sys/fs/cuse/cuse.c
+33-301 files

FreeBSD/src 872c36c — sys/fs/cuse cuse.c

cuse: Fix hang on readv(2) and writev(2) with multiple iovecs

uiomove() leaves an iovec it has just emptied as the current one, so
cuse_client_read() and cuse_client_write() picked it up again on the
next iteration, sent the server a zero-length command, and got zero
bytes back. That left the residual count unchanged, so the loop never
terminated and the call never returned.

Step past empty iovecs at the start of every iteration. This also covers
caller-supplied zero-length iovecs, which hung in the same way

PR:             293489
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib, markj
Differential Revision:  https://reviews.freebsd.org/D59822
DeltaFile
+24-4sys/fs/cuse/cuse.c
+24-41 files

OPNSense/src 2c3bf8d — . UPDATING, sys/conf newvers.sh

Add UPDATING entries and bump version

Approved by:    so
DeltaFile
+24-0UPDATING
+1-1sys/conf/newvers.sh
+25-12 files

FreeBSD/ports 5cd0e13 — devel/py-python-gitlab Makefile distinfo

devel/py-python-gitlab: Update from 8.5.0 to 8.6.0

PR:             298976
Changelog:      https://github.com/python-gitlab/python-gitlab/releases/tag/v8.6.0
DeltaFile
+3-3devel/py-python-gitlab/distinfo
+1-1devel/py-python-gitlab/Makefile
+4-42 files

OPNSense/src 63a0f2d — sys/netinet6 udp6_usrreq.c

udp: Let jail policy rewrite the dstaddr for v6 sendto()s

When performing an unconnected sendto() on a v6 UDP socket in a classic
jail, we were not applying the usual policy of replacing the loopback
addr with the jail's primary IP.  Compare with, e.g., udp6_connect() or
the IPv4 udp_send().  Fix that.

Approved by:    so
Security:       FreeBSD-SA-26:69.udp
Security:       CVE-2026-101303
Reported by:    Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li,
                and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai
Reviewed by:    bz, glebius
MFC after:      2 weeks
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59772

(cherry picked from commit fecb9537a83b6746bc731a7cb3bcf6a33df79562)
(cherry picked from commit f3b4b6b756e2ce9e012068c5c91492f757b5c548)
DeltaFile
+4-0sys/netinet6/udp6_usrreq.c
+4-01 files

OPNSense/src 659aca9 — crypto/openssl/ssl d1_lib.c, crypto/openssl/ssl/statem statem_dtls.c

openssl: Fix CVE-2026-84782

This is a commit from upstream to fix:
  dtls: reset init_off before retransmitting a message

Approved by:    so
Security:       FreeBSD-SA-26:68.openssl
Security:       CVE-2026-84782
DeltaFile
+414-2crypto/openssl/test/dtlstest.c
+17-0crypto/openssl/ssl/d1_lib.c
+2-0crypto/openssl/ssl/statem/statem_dtls.c
+433-23 files

OPNSense/src 8076867 — sys/kern uipc_ktls.c, tests/sys/kern ktls_test.c

ktls: Fix an off-by-one bug in tls13_find_record_type()

If the entire plaintext is zero-filled, the backwards walk in
tls13_find_record_type() would return the offset of the last byte of the
TLS header.  This causes an underflow when decrypting, resulting in a
null pointer dereference.

Fix the bug and add a regression test.

Approved by:    so
Security:       FreeBSD-SA-26:67.ktls
Security:       CVE-2026-101302
Reviewed by:    gallatin, jhb
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59767

(cherry picked from commit 7c5e457d3afdc7742ee24f0b5ee6e5e7aa00a6bd)
(cherry picked from commit 6d6a85c0be942d903a076d930c0ee67d150b0cfb)
DeltaFile
+66-5tests/sys/kern/ktls_test.c
+2-2sys/kern/uipc_ktls.c
+68-72 files

OPNSense/src cddf1ef — share/man/man4 ktls.4, sys/kern uipc_ktls.c

ktls: Add a tunable to disable TLS receive

TLS receive offload is really only beneficial for in-kernel use cases
(such as NFS over TLS) or when using a hardware offload.  In addition,
several recent SAs have involved the TLS receive path, but the only
current mitigation for those is to disable TLS offload entirely.

Approved by:    so
Security:       FreeBSD-SA-26:67.ktls
Reviewed by:    ziaee, gallatin, markj
Relnotes:       yes
Sponsored by:   Netflix
Sponsored by:   Chelsio Communications
Co-authored-by: John Baldwin <jhb at FreeBSD.org>
Differential Revision:  https://reviews.freebsd.org/D57974

(cherry picked from commit 08cda4bcd43cfcb2c0b1abd29bc7cd30896727bc)
(cherry picked from commit 4d3f5d2ca43c7b00fe03276e85a51e215655bc6d)
DeltaFile
+58-32tests/sys/kern/ktls_test.c
+6-1sys/kern/uipc_ktls.c
+3-1share/man/man4/ktls.4
+67-343 files

OPNSense/src 7b0a472 — sys/kern uipc_usrreq.c, tests/sys/kern unix_passfd_test.c

unix: Preserve FD_RESOLVE_BENEATH when passing an fd

The FD_RESOLVE_BENEATH flag is supposed to be sticky.  It's set when you
receive an fd from a different jail and preserved by openat(<dfd>) etc..
However, if you send the fd to yourself, the flag is stripped since
SCM_RIGHTS message don't preserve file descriptor flags.

Fix this by preserving those flags and checking for UF_RESOLVE_BENEATH
in restrict_rights().

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101306
Fixes:          350ba9672a7f ("unix: Set O_RESOLVE_BENEATH on fds transferred between jails")
Reviewed by:    kib
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D58317


    [2 lines not shown]
DeltaFile
+31-0tests/sys/kern/unix_passfd_test.c
+19-8sys/kern/uipc_usrreq.c
+50-82 files

OPNSense/src 93d226e — lib/libsys fcntl.2, sys/kern vfs_syscalls.c

vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors

The FD_RESOLVE_BENEATH flag was intended to try to resolve bugzilla PR
262179 without entirely disallowing fd passing between jails.  However,
one can use renameat() to bypass the restriction: upon receiving a
directory fd with FD_RESOLVE_BENEATH set, a jailed process can still
move its CWD or one of its ancestors to the directory, and just cd
out of its jail root.

So disallow renameat() when either the source or destination directory
fds has FD_RESOLVE_BENEATH set, like we do with fchdir() and fchroot()
to prevent similar escapes.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101305
PR:             262179
Reported by:    firk at cantconnect.ru
Reviewed by:    olce, kib
Differential Revision:  https://reviews.freebsd.org/D59875
DeltaFile
+8-1lib/libsys/fcntl.2
+9-0sys/kern/vfs_syscalls.c
+17-12 files

OPNSense/src f601bcf — sys/fs/fdescfs fdesc_vnops.c, tests/sys/fs Makefile

fdescfs: Pass up additional metadata during lookups

When an fdescfs mount has the nodup option set, fdesc_lookup(/dev/fd/n)
returns the vnode referenced by file descriptor n, rather than returning
an fdescfs vnode.  This meant that fd metadata attached to fd n was not
preserved when reopening the file, which is contrary to the expected
semantics for capsicum rights and the UF_RESOLVE_BENEATH fd flag.  For
regular fdescfs mounts, this metadata is copied via dupfdopen().

Fix the problem by passing up this metadata through the nameidata
structure.  Thus, if one opens /dev/fd/n, the returned fd will inherit
UF_RESOLVE_BENEATH and the capability rights of fd n.  Add some
regression tests as well.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101304
Reported by:    Jan Bramkamp
Reviewed by:    kib

    [2 lines not shown]
DeltaFile
+236-0tests/sys/fs/fdescfs/fdescfs_test.c
+35-2sys/fs/fdescfs/fdesc_vnops.c
+9-0tests/sys/fs/fdescfs/Makefile
+1-0tests/sys/fs/Makefile
+281-24 files

OPNSense/src 81be2f8 — lib/libc/capability cap_rights_init.3, sys/kern subr_capability.c kern_descrip.c

file: Add filecaps_intersect() and cap_rights_intersect()

These routines let one compute the intersection of two sets of filecaps
or capability rights, just as filecaps_merge() and cap_rights_merge()
compute the union.  This will be useful in an upcoming patch.

filecaps_intersect() is complex due to the need to merge sets of ioctls.
For now this is implemented with a dumb nested loop on the basis that
ioctl lists are typically short enough that this is fine.  It may be
better to instead sort the two lists first and step through them
together.

No functional change intended.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59885
DeltaFile
+49-0sys/kern/kern_descrip.c
+23-0sys/kern/subr_capability.c
+14-2lib/libc/capability/cap_rights_init.3
+1-0sys/sys/filedesc.h
+1-0sys/sys/capsicum.h
+88-25 files

OPNSense/src 4f7b973 — sys/kern kern_descrip.c, sys/sys filedesc.h

file: Add a helper function to check whether filecaps are full

In a couple of places we want to know whether someone has limited rights
on an fd.  There, we want a predicate which determines whether the set
of rights is smaller than CAP_ALL, and whether there are explicit ioctl
or fcntl lists.  Factor this out into a helper function, in preparation
for use elsewhere.

No functional change intended.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59884
DeltaFile
+12-8sys/kern/kern_descrip.c
+1-0sys/sys/filedesc.h
+13-82 files

OPNSense/src 4c3ac1b — sys/kern kern_event.c

kqueue: Fix a potential OOB access in kqueue_fork_copy_knote()

Here, fdp points to the new fdtable, copied from that of the parent
process.  There is a window after the fdtable is copied, and before
kqueue_fork_copy_knote() runs, where a different thread in the parent
could have grown the parent's fdtable and registered a knote with ident
larger than the size of the child's fdtable.  This race can lead to an
out-of-bounds read.

Add a bounds check for this case; skip the knote if it is referencing a
non-existent file.

Approved by:    so
Security:       FreeBSD-SA-26:65.kqueue
Security:       CVE-2026-58100
Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59916
DeltaFile
+2-1sys/kern/kern_event.c
+2-11 files