LLVM/project 9dd6a72 — llvm/lib/Target/AMDGPU SIShrinkInstructions.cpp, llvm/test/CodeGen/AMDGPU s_or_b32_transformation.ll shrink-disjoint-or-scc.mir

Address review feedback:
1. Use allImplicitDefsAreDead() helper to check whether SCC is dead
2. Simplify .ll test case
3. Add a new .mir test case
DeltaFile
+35-0llvm/test/CodeGen/AMDGPU/shrink-disjoint-or-scc.mir
+6-8llvm/test/CodeGen/AMDGPU/s_or_b32_transformation.ll
+1-2llvm/lib/Target/AMDGPU/SIShrinkInstructions.cpp
+42-103 files

LLVM/project 10415c9 — llvm/test/CodeGen/AMDGPU s_or_b32_transformation.ll

Precommit test case for s_or incorrectly transformed to s_addk when SCC is live
DeltaFile
+28-0llvm/test/CodeGen/AMDGPU/s_or_b32_transformation.ll
+28-01 files

LLVM/project bb55485 — llvm/lib/Target/AMDGPU SIShrinkInstructions.cpp, llvm/test/CodeGen/AMDGPU s_or_b32_transformation.ll

[AMDGPU] Preserve live SCC when shrinking disjoint S_OR_B32
DeltaFile
+6-0llvm/lib/Target/AMDGPU/SIShrinkInstructions.cpp
+2-1llvm/test/CodeGen/AMDGPU/s_or_b32_transformation.ll
+8-12 files

FreeBSD/ports 9c22323 — cad/kicad-devel Makefile, cad/kicad-devel/files patch-3d-viewer_3d__rendering_opengl_create__scene.cpp

cad/kicad-devel: Fix build
DeltaFile
+12-2cad/kicad-devel/files/patch-3d-viewer_3d__rendering_opengl_create__scene.cpp
+1-2cad/kicad-devel/Makefile
+13-42 files

LLVM/project 723be84 — llvm/lib/Target/AMDGPU AMDGPUSwLowerLDS.cpp, llvm/test/CodeGen/AMDGPU amdgpu-sw-lower-lds-flat-arg-kernel-id.ll

[AMDGPU][SwLowerLDS] Lower non-kernels with LDS instructions and assign kernel IDs to their callers
DeltaFile
+122-84llvm/lib/Target/AMDGPU/AMDGPUSwLowerLDS.cpp
+152-0llvm/test/CodeGen/AMDGPU/amdgpu-sw-lower-lds-flat-arg-kernel-id.ll
+274-842 files

OPNSense/src 20f4d07 — . UPDATING, sys/conf newvers.sh

Add UPDATING entries and bump version

Approved by:    so
DeltaFile
+20-0UPDATING
+1-1sys/conf/newvers.sh
+21-12 files

OPNSense/src 7aff526 — crypto/openssl/ssl d1_lib.c, crypto/openssl/ssl/statem statem_dtls.c

openssl: Fix CVE-2026-84782

This is a backport of an upstream commit to fix:
  dtls: reset init_off before retransmitting a message

Approved by:    so
Security:       FreeBSD-SA-26:68.openssl
Security:       CVE-2026-84782
DeltaFile
+17-0crypto/openssl/ssl/d1_lib.c
+2-0crypto/openssl/ssl/statem/statem_dtls.c
+19-02 files

OPNSense/src 58f4d2f — sys/kern uipc_usrreq.c, tests/sys/kern unix_passfd_test.c

unix: Preserve FD_RESOLVE_BENEATH when passing an fd

The FD_RESOLVE_BENEATH flag is supposed to be sticky.  It's set when you
receive an fd from a different jail and preserved by openat(<dfd>) etc..
However, if you send the fd to yourself, the flag is stripped since
SCM_RIGHTS message don't preserve file descriptor flags.

Fix this by preserving those flags and checking for UF_RESOLVE_BENEATH
in restrict_rights().

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101306
Fixes:          350ba9672a7f ("unix: Set O_RESOLVE_BENEATH on fds transferred between jails")
Reviewed by:    kib
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D58317


    [2 lines not shown]
DeltaFile
+31-0tests/sys/kern/unix_passfd_test.c
+19-8sys/kern/uipc_usrreq.c
+50-82 files

OPNSense/src 22b532d — sys/kern vfs_syscalls.c

vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors

The FD_RESOLVE_BENEATH flag was intended to try to resolve bugzilla PR
262179 without entirely disallowing fd passing between jails.  However,
one can use renameat() to bypass the restriction: upon receiving a
directory fd with FD_RESOLVE_BENEATH set, a jailed process can still
move its CWD or one of its ancestors to the directory, and just cd
out of its jail root.

So disallow renameat() when either the source or destination directory
fds has FD_RESOLVE_BENEATH set, like we do with fchdir() and fchroot()
to prevent similar escapes.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101305
PR:             262179
Reported by:    firk at cantconnect.ru
Reviewed by:    olce, kib
Differential Revision:  https://reviews.freebsd.org/D59875
DeltaFile
+9-0sys/kern/vfs_syscalls.c
+9-01 files

OPNSense/plugins c37f8c9 — net/frr/src/opnsense/scripts/frr/lib/events ospfd.py

net/frr: CARP event handler, skip interfaces that report OSPF as not running (#5762)

The handler assumed that every interface listed by ospfd has
a cost.  ospfd lists an interface on which OSPF is not running (e.g. a
CARP bound WireGuard instance that is down on the backup node) without
one, so the handler ended with KeyError: 'cost' and left all following
interfaces in ospfd_carp.conf at their default cost.

Skip such interfaces and continue with the rest.
DeltaFile
+4-0net/frr/src/opnsense/scripts/frr/lib/events/ospfd.py
+4-01 files

OPNSense/src 90afaba — sys/fs/fdescfs fdesc_vnops.c, tests/sys/fs Makefile

fdescfs: Pass up additional metadata during lookups

When an fdescfs mount has the nodup option set, fdesc_lookup(/dev/fd/n)
returns the vnode referenced by file descriptor n, rather than returning
an fdescfs vnode.  This meant that fd metadata attached to fd n was not
preserved when reopening the file, which is contrary to the expected
semantics for capsicum rights and the UF_RESOLVE_BENEATH fd flag.  For
regular fdescfs mounts, this metadata is copied via dupfdopen().

Fix the problem by passing up this metadata through the nameidata
structure.  Thus, if one opens /dev/fd/n, the returned fd will inherit
UF_RESOLVE_BENEATH and the capability rights of fd n.  Add some
regression tests as well.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101304
Reported by:    Jan Bramkamp
Reviewed by:    kib

    [2 lines not shown]
DeltaFile
+274-0tests/sys/fs/fdescfs/fdescfs_test.c
+35-2sys/fs/fdescfs/fdesc_vnops.c
+9-0tests/sys/fs/fdescfs/Makefile
+1-0tests/sys/fs/Makefile
+319-24 files

OPNSense/src dd56fac — lib/libc/capability cap_rights_init.3, sys/kern subr_capability.c kern_descrip.c

file: Add filecaps_intersect() and cap_rights_intersect()

These routines let one compute the intersection of two sets of filecaps
or capability rights, just as filecaps_merge() and cap_rights_merge()
compute the union.  This will be useful in an upcoming patch.

filecaps_intersect() is complex due to the need to merge sets of ioctls.
For now this is implemented with a dumb nested loop on the basis that
ioctl lists are typically short enough that this is fine.  It may be
better to instead sort the two lists first and step through them
together.

No functional change intended.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59885
DeltaFile
+49-0sys/kern/kern_descrip.c
+23-0sys/kern/subr_capability.c
+14-2lib/libc/capability/cap_rights_init.3
+1-0sys/sys/filedesc.h
+1-0sys/sys/capsicum.h
+88-25 files

OPNSense/src be94f30 — sys/kern kern_descrip.c, sys/sys filedesc.h

file: Add a helper function to check whether filecaps are full

In a couple of places we want to know whether someone has limited rights
on an fd.  There, we want a predicate which determines whether the set
of rights is smaller than CAP_ALL, and whether there are explicit ioctl
or fcntl lists.  Factor this out into a helper function, in preparation
for use elsewhere.

No functional change intended.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59884
DeltaFile
+12-8sys/kern/kern_descrip.c
+1-0sys/sys/filedesc.h
+13-82 files

OPNSense/src 31b1c1f — sys/netinet6 udp6_usrreq.c

udp: Let jail policy rewrite the dstaddr for v6 sendto()s

When performing an unconnected sendto() on a v6 UDP socket in a classic
jail, we were not applying the usual policy of replacing the loopback
addr with the jail's primary IP.  Compare with, e.g., udp6_connect() or
the IPv4 udp_send().  Fix that.

Approved by:    so
Security:       FreeBSD-SA-26:69.udp
Security:       CVE-2026-101303
Reported by:    Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li,
                and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai
Reviewed by:    bz, glebius
MFC after:      2 weeks
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59772

(cherry picked from commit fecb9537a83b6746bc731a7cb3bcf6a33df79562)
(cherry picked from commit 809221661a8136a19661e4e379a44203e0ea2a03)
DeltaFile
+4-0sys/netinet6/udp6_usrreq.c
+4-01 files

OPNSense/src e3a2a91 — sys/kern uipc_ktls.c, tests/sys/kern ktls_test.c

ktls: Fix an off-by-one bug in tls13_find_record_type()

If the entire plaintext is zero-filled, the backwards walk in
tls13_find_record_type() would return the offset of the last byte of the
TLS header.  This causes an underflow when decrypting, resulting in a
null pointer dereference.

Fix the bug and add a regression test.

Approved by:    so
Security:       FreeBSD-SA-26:67.ktls
Security:       CVE-2026-101302
Reviewed by:    gallatin, jhb
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59767

(cherry picked from commit 7c5e457d3afdc7742ee24f0b5ee6e5e7aa00a6bd)
(cherry picked from commit fc1a02c93ba4c9a98e329a4166618bbaf17d584b)
DeltaFile
+66-5tests/sys/kern/ktls_test.c
+2-2sys/kern/uipc_ktls.c
+68-72 files

OPNSense/src 4d4c278 — share/man/man4 ktls.4, sys/kern uipc_ktls.c

ktls: Add a tunable to disable TLS receive

TLS receive offload is really only beneficial for in-kernel use cases
(such as NFS over TLS) or when using a hardware offload.  In addition,
several recent SAs have involved the TLS receive path, but the only
current mitigation for those is to disable TLS offload entirely.

Approved by:    so
Security:       FreeBSD-SA-26:67.ktls
Reviewed by:    ziaee, gallatin, markj
Relnotes:       yes
Sponsored by:   Netflix
Sponsored by:   Chelsio Communications
Co-authored-by: John Baldwin <jhb at FreeBSD.org>
Differential Revision:  https://reviews.freebsd.org/D57974

(cherry picked from commit 08cda4bcd43cfcb2c0b1abd29bc7cd30896727bc)
(cherry picked from commit f80f8c38fada66163324e509d9eb6b2c844d7c58)
DeltaFile
+58-32tests/sys/kern/ktls_test.c
+6-1sys/kern/uipc_ktls.c
+3-1share/man/man4/ktls.4
+67-343 files

OPNSense/src 54f3b65 — sys/kern sysv_sem.c

sysvsem: Fix another sequence number wraparound race

semop() may sleep waiting for a semaphore.  Upon waking up, it checks to
see if the set's sequence number has changed, indicating that the set
was removed.  The sequence number is not wide enough to prevent a false
negative due to wraparound, in which case the subsequent access of
`semakptr->u.__sem_base[sopptr->sem_num]` may be out of bounds.  This
race can be leveraged to elevate privileges.

Fix this by introducing a 64-bit sequence number for each semaphore
pool.  This is wide enough to make the race impossible to hit.  Allocate
a separate array for them, as we cannot really change the layout of
struct semid_kernel since some userspace tools (e.g., ipcrm(1)) embed
the layout.

While here, use semvalid() instead of open-coding its implementation,
convert a couple of flags to be bool, and use a better variable name to
store required permissions.


    [8 lines not shown]
DeltaFile
+39-31sys/kern/sysv_sem.c
+39-311 files

OPNSense/src 465f8dc — contrib/tzdata asia southamerica

contrib/tzdata: import tzdata 2026d

Approved by:    so
Security:       FreeBSD-EN-26:24.tzdata
Changes: https://github.com/eggert/tz/blob/2026d/NEWS

(cherry picked from commit fe81d42176f04718d7534242dfd4b9f250ac50fc)
(cherry picked from commit 7fa0ed470f721ef98273ef228caca7ed517d984d)
DeltaFile
+80-46contrib/tzdata/northamerica
+114-1contrib/tzdata/NEWS
+32-31contrib/tzdata/theory.html
+49-5contrib/tzdata/backward
+16-13contrib/tzdata/southamerica
+18-6contrib/tzdata/asia
+309-1028 files not shown
+332-12314 files

LLVM/project dbeca9a — llvm/lib/Transforms/Vectorize VectorCombine.cpp

address unused-vars in the no-assert build for PR #213007 (#228986)
DeltaFile
+3-5llvm/lib/Transforms/Vectorize/VectorCombine.cpp
+3-51 files

FreeBSD/ports 2f82719 — x11/ashell Makefile Makefile.crates, x11/ashell/files patch-pipewire-sys-0.9.2 patch-pipewire-sys-0.10.1

x11/ashell: Update to 0.11.0

Changelog: https://github.com/MalpenZibo/ashell/blob/0.11.0/CHANGELOG.md

Reported by:    GitHub (watch releases)
DeltaFile
+37-41x11/ashell/distinfo
+0-59x11/ashell/files/patch-pipewire-sys-0.9.2
+59-0x11/ashell/files/patch-pipewire-sys-0.10.1
+17-19x11/ashell/Makefile.crates
+1-2x11/ashell/Makefile
+114-1215 files

NetBSD/src jMC4UzE — usr.sbin/cpuctl/arch i386.c

   cpuctl(8): update Transmeta identification for Efficeon (TM8000 series).

   It uses family 15 and it has a new way to decode processor revision, so update
   family > 6 default to "Efficeon" and call transmeta_cpu_info() for it.

   Decode processor revision from leaf leaf 0x80860002 EAX
   when leaf 0x80860001 EBX contains 0x02000000.

   Untested on the actual hardware (I don't have one).
   Verified by the CPUID dump available online.
VersionDeltaFile
1.152+31-11usr.sbin/cpuctl/arch/i386.c
+31-111 files

NetBSD/pkgsrc ysAC2zi — doc CHANGES-2026

   doc: Updated x11/copyq to 17.0.0
VersionDeltaFile
1.6690+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc qAxHetT — x11/copyq Makefile distinfo

   copyq: update to 17.0.0

   * Added
   - Adds support for GNOME 50 (#3677).

   * Changed
   - Tab data and state files are moved to XDG-compliant directories,
     %LOCALAPPDATA% on Windows and ~/Library/Application Support on macOS
     (#3692, #3693). State path can be changed using COPYQ_STATE_PATH
     environment variable.
     Important: This is backwards incompatible. The data and state files are
     moved when the new app version starts. Older versions of the app will not see
     these files and basically lose all items.
   - FakeVim is updated from upstream repository.

   * Fixed
   - Fixes audio engine always using a small amount of CPU and indicating (on KDE)
     that it plays audio (#3684). The engine is initialized only when needed and

    [14 lines not shown]
VersionDeltaFile
1.11+4-4x11/copyq/distinfo
1.25+2-3x11/copyq/Makefile
+6-72 files

LLVM/project 2571ecb — llvm/lib/CodeGen/GlobalISel IRTranslator.cpp

braces
DeltaFile
+2-1llvm/lib/CodeGen/GlobalISel/IRTranslator.cpp
+2-11 files

FreeNAS/freenas 3cbc4cb — src/middlewared/middlewared/common/license_reconcile __init__.py, src/middlewared/middlewared/etc_files README.md

Only reconcile license delegates whose entitlements changed

This commit adds changes to make license reconcile delegates act only when an entitlement they depend on actually changes. Previously every license upload ran every delegate, so re-uploading the same license or adding an unrelated feature would still restart ctdb and s3 and reload smb, discovery and zfs tier.

The upload now snapshots resolved entitlements before the new license is installed and hands that to the reconcile job, which diffs it against live entitlements and skips any delegate whose declared features did not change. ctdb is started when HA is gained and stopped (with its config re-rendered) when HA is lost instead of being restarted, and sync_to_peer snapshots the peer's entitlements before pushing the license so its final hook call on the peer only touches what changed.
DeltaFile
+40-0src/middlewared/middlewared/pytest/unit/plugins/truenas/test_license_reconcile.py
+29-5src/middlewared/middlewared/plugins/truenas/license_reconcile.py
+21-5src/middlewared/middlewared/common/license_reconcile/__init__.py
+21-4src/middlewared/middlewared/plugins/failover.py
+5-3src/middlewared/middlewared/etc_files/README.md
+6-2src/middlewared/middlewared/plugins/truenas/license.py
+122-199 files not shown
+141-2015 files

FreeNAS/freenas 1ef9af5 — src/middlewared/middlewared/alert/source license_status.py

Skip serial and model license checks for non-enterprise licenses

This commit fixes an issue where TrueNAS Connect community and commercial licenses raised critical serial mismatch and unsupported hardware alerts, because the serial, chassis model and expansion shelf checks ran for every license type. Those checks only make sense for serial-bound enterprise licenses, so they are now gated on the license type while support expiry alerts keep firing for everyone.
DeltaFile
+55-51src/middlewared/middlewared/alert/source/license_status.py
+55-511 files

FreeNAS/freenas e97329a — src/middlewared/middlewared/pytest/unit/plugins test_iscsi_target.py, src/middlewared/middlewared/pytest/unit/utils test_license_legacy_utils.py test_entitlements.py

Remove hw_l and ce_l entitlement columns

This commit adds changes to drop the HW+L and CE+L columns from the entitlement engine. Fibre channel was the only feature granted through them, so it is now gated purely on the license carrying the FIBRECHANNEL key (hw_k/ce_k), and a license lacking a feature's key resolves to no column and is denied.
DeltaFile
+43-53src/middlewared/middlewared/pytest/unit/utils/test_entitlements.py
+26-26src/middlewared/middlewared/utils/entitlements/matrix.py
+10-14src/middlewared/middlewared/utils/entitlements/engine.py
+1-3src/middlewared/middlewared/pytest/unit/utils/test_license_legacy_utils.py
+1-3src/middlewared/middlewared/pytest/unit/plugins/test_iscsi_target.py
+81-995 files

LLVM/project 09910aa — compiler-rt/lib/tsan/rtl tsan_interceptors_posix.cpp, compiler-rt/test/tsan/Linux fd_fcntl_dupfd_cloexec_norace.cpp

[tsan] fcntl interceptor with F_DUPFD and F_DUPFD_CLOEXEC support (#221064)

behaves like dup

fixes https://github.com/rust-lang/rust/issues/130037 and bunch of
others
DeltaFile
+49-12compiler-rt/lib/tsan/rtl/tsan_interceptors_posix.cpp
+46-0compiler-rt/test/tsan/Linux/fd_fcntl_dupfd_cloexec_norace.cpp
+95-122 files

FreeBSD/ports 9983eda — devel Makefile, devel/py-pathlib-abc pkg-descr distinfo

devel/py-pathlib-abc: New port: Backport of pathlib ABCs

PR:             299045
Approved by:    Baptiste Daroussin <bapt at FreeBSD.org> (on behalf of portmgr@)
DeltaFile
+22-0devel/py-pathlib-abc/Makefile
+3-0devel/py-pathlib-abc/pkg-descr
+3-0devel/py-pathlib-abc/distinfo
+1-0devel/Makefile
+29-04 files

FreeBSD/ports 1d64837 — graphics Makefile, graphics/py-pyvista-validation pkg-descr distinfo

graphics/py-pyvista-validation: New port: Validate and standardize array-like input

PR:             298893
Approved by:    Baptiste Daroussin <bapt at FreeBSD.org> (on behalf of portmgr@)
DeltaFile
+27-0graphics/py-pyvista-validation/Makefile
+22-0graphics/py-pyvista-validation/files/patch-pyproject.toml
+3-0graphics/py-pyvista-validation/distinfo
+2-0graphics/py-pyvista-validation/pkg-descr
+1-0graphics/Makefile
+55-05 files