Only reconcile license delegates whose entitlements changed
This commit adds changes to make license reconcile delegates act only when an entitlement they depend on actually changes. Previously every license upload ran every delegate, so re-uploading the same license or adding an unrelated feature would still restart ctdb and s3 and reload smb, discovery and zfs tier.
The upload now snapshots resolved entitlements before the new license is installed and hands that to the reconcile job, which diffs it against live entitlements and skips any delegate whose declared features did not change. ctdb is started when HA is gained and stopped (with its config re-rendered) when HA is lost instead of being restarted, and sync_to_peer snapshots the peer's entitlements before pushing the license so its final hook call on the peer only touches what changed.
Skip serial and model license checks for non-enterprise licenses
This commit fixes an issue where TrueNAS Connect community and commercial licenses raised critical serial mismatch and unsupported hardware alerts, because the serial, chassis model and expansion shelf checks ran for every license type. Those checks only make sense for serial-bound enterprise licenses, so they are now gated on the license type while support expiry alerts keep firing for everyone.
Remove hw_l and ce_l entitlement columns
This commit adds changes to drop the HW+L and CE+L columns from the entitlement engine. Fibre channel was the only feature granted through them, so it is now gated purely on the license carrying the FIBRECHANNEL key (hw_k/ce_k), and a license lacking a feature's key resolves to no column and is denied.
graphics/py-pyvista-validation: New port: Validate and standardize array-like input
PR: 298893
Approved by: Baptiste Daroussin <bapt at FreeBSD.org> (on behalf of portmgr@)
filesystems/py-universal-pathlib: New port: Pathlib API extended to use fsspec backends
PR: 299046
Approved by: Baptiste Daroussin <bapt at FreeBSD.org> (on behalf of portmgr@)
graphics/py-polyxios: New port: Fast 3D file format I/O and processing library
PR: 298876
Approved by: Baptiste Daroussin <bapt at FreeBSD.org> (on behalf of portmgr@)
www/py-pytauri: New port: Tauri binding for Python through PyO3
PR: 299040
Approved by: Baptiste Daroussin <bapt at FreeBSD.org> (on behalf of portmgr@)
www/py-pytauri-wheel: New port: Precompiled wheels for PyTauri
PR: 299039
Approved by: Baptiste Daroussin <bapt at FreeBSD.org> (on behalf of portmgr@)
Further restrict the characters allowed in a command-line supplied user
name, disallowing '$' and '\'.
Reported by SecBuddyF KeenLab Tencent (CodeBuddy Security).
NAS-144136 / 28.0.0-BETA.1 / Report crash-looping app containers as crashed (#19896)
A container that exits with an error under the catalog's default
`unless-stopped` restart policy is reported by Docker as `restarting`,
not `exited`. The container state mapping only looked at the exit code
for `exited`, so a crash-looping container fell through to `exited`. A
multi-container app with a healthy sibling then showed as Running, and a
single-container app showed as Stopped, which hid its workloads and
blocked logs, upgrade and rollback.
Treat a `restarting` container as crashed when its last exit code is
non-zero. Docker only restarts a container after an exit it didn't
cause, since stopping or killing it through Docker cancels the restart
policy, so any non-zero code there is a real failure, including 137 from
an OOM kill. A restart after a clean exit is still reported as exited.
Added a unit test for the Docker status to container state mapping,
which had no coverage.
(cherry picked from commit 0f08fe7a5f6ed7892174cbb20b25935a47f52fd4)
devel/py-joblib: unbreak with missing RUN_DEPENDS
...specified in pyproject.toml
/usr/local/lib/python3.14t/site-packages/joblib/__init__.py:114: in <module>
from ._cloudpickle_wrapper import wrap_non_picklable_objects
/usr/local/lib/python3.14t/site-packages/joblib/_cloudpickle_wrapper.py:14: in <module>
from .externals.loky import wrap_non_picklable_objects
/usr/local/lib/python3.14t/site-packages/joblib/externals/loky/__init__.py:22: in <module>
from .cloudpickle_wrapper import wrap_non_picklable_objects
/usr/local/lib/python3.14t/site-packages/joblib/externals/loky/cloudpickle_wrapper.py:3: in <module>
from cloudpickle import dumps, loads
E ModuleNotFoundError: No module named 'cloudpickle'
With hat: python
(cherry picked from commit b0be372a90503ef37fbe2c3470844b72a6a780e6)