LLVM/project c2333b4 — clang/docs conf.py index.md

[docs] Enforce unambiguous toctree in clang/docs (#224101)

The rationale and methodology are the same as in
03511907c7a9908f7902e18d3789371a63bb91b1 just in `clang` this time.
DeltaFile
+108-32clang/docs/index.md
+1-0clang/docs/conf.py
+109-322 files

LLVM/project 43d9238 — cross-project-tests/intrinsic-header-tests riscv_packed_simd.c, llvm/lib/Target/RISCV RISCVISelLowering.cpp

[RISCV][P-Ext] Prefer pack/ppairo.h over pncvt.h/pncvth.h in shuffle lowering (#227105)

These have equivalent behavior, but pncvt.h/pncvth.h requires the input
to be a register pair. Shuffle lowering doesn't know if the sources came
from the same 64-bit value so using pncvt.h/pncvth.h may overconstrain
register allocation and require copies.

If some hardware has better performance for pncvt.h/pncvth.h we
can consider ways to intelligently pick the two alternatives. For
now just pick pack/ppairo.h.
DeltaFile
+10-10cross-project-tests/intrinsic-header-tests/riscv_packed_simd.c
+5-10llvm/test/CodeGen/RISCV/rvp-simd-32.ll
+4-4llvm/test/CodeGen/RISCV/rvp-zip.ll
+1-1llvm/lib/Target/RISCV/RISCVISelLowering.cpp
+20-254 files

LLVM/project db7c669 — llvm/include/llvm/TargetParser Triple.h, llvm/lib/Target/ARM ARMTargetMachine.cpp

ARM: Move abi name implied float abi to TargetParser (#226774)

ARMTargetMachine overrode the default float abi based on the abi name.
Move this logic to TargetParser so the ABI will be computable without
depending on codegen.

Co-authored-by: Claude Sonnet 5 <noreply at anthropic.com>
DeltaFile
+6-4llvm/lib/TargetParser/Triple.cpp
+1-8llvm/lib/Target/ARM/ARMTargetMachine.cpp
+4-2llvm/include/llvm/TargetParser/Triple.h
+11-143 files

LLVM/project 9076414 — openmp/runtime/src kmp_invoke_microtask.cpp, openmp/runtime/test/misc_bugs many-microtask-args.c too-many-microtask-args.c

[OpenMP] Support up to 32 arguments in the generic microtask dispatcher (#211071)

Extend the generic `__kmp_invoke_microtask` implementation to support up
to 32 microtask arguments.

The generic dispatcher currently handles at most 15 arguments. OpenMP
regions with more captured variables terminate at runtime.

This affects WebAssembly because call_indirect requires the callee type
to exactly match the call-site type. Unlike assembly dispatchers on
platforms such as x86_64, the generic C++ implementation cannot
construct an arbitrary-arity call dynamically and must provide each
supported signature explicitly.
Real-world OpenMP regions can exceed the existing limit; the motivating
cases require between 16 and 21 arguments.

A longer-term alternative would be to change the compiler/runtime
convention for generic-dispatch targets so captured-variable pointers
are passed through a single packed context argument. That would remove

    [3 lines not shown]
DeltaFile
+60-0openmp/runtime/test/misc_bugs/too-many-microtask-args.c
+30-13openmp/runtime/test/misc_bugs/many-microtask-args.c
+17-0openmp/runtime/src/kmp_invoke_microtask.cpp
+107-133 files

LLVM/project 3f91f48 — lldb/source/Plugins/Process/Windows/Common/x64 RegisterContextWindows_x64.cpp, lldb/source/Plugins/Process/Windows/Common/x86 RegisterContextWindows_x86.cpp

[lldb][Windows] Format in-process x86 and x64 GPRs as lowercase hex (#227299)

The in-process Windows plugin printed `x86`/`x64` registers in uppercase
hex, unlike every other register table.

`Test11588` compares against lowercase hex, so it only passed when the
address happened to have no letters.

This patch uses lowercase hex, matching `lldb-server`. Test11588 is
re-enabled.
DeltaFile
+4-4lldb/source/Plugins/Process/Windows/Common/x64/RegisterContextWindows_x64.cpp
+1-1lldb/source/Plugins/Process/Windows/Common/x86/RegisterContextWindows_x86.cpp
+0-1lldb/test/API/commands/expression/issue_11588/Test11588.py
+5-63 files

LLVM/project 7ed1f48 — llvm/test/CodeGen/X86 twoaddr-reschedule-copy-chain.mir

TwoAddressInstructions: Add another reschedule copy order test (#227342)

Another test for the fix from #227289, which hit a different
assert condition.

Co-authored-by: Claude Opus 5 <noreply at anthropic.com>
DeltaFile
+54-0llvm/test/CodeGen/X86/twoaddr-reschedule-copy-chain.mir
+54-01 files

LLVM/project 0240437 — lldb/source/Plugins/Platform/Windows PlatformWindows.cpp

[lldb][Windows] Register the shadow listener in PlatformWindows (#227277)

`PlatformWindows::DebugProcess` and `PlatformWindows::Attach` create the
Process and hijack its events, but never call
`Process::SetShadowListener` with the listener from the launch or attach
info. `PlatformPOSIX`, `PlatformRemoteGDBServer` and `Target::Launch`'s
all do.

On Windows a shadow listener set with `SBLaunchInfo::SetShadowListener`
therefore never gets an event, which is why
`TestEvents.test_shadow_listener` failed on every run (`"Shadow listener
got event too"`) on both the lldb-server and the in-process backend.
    
Call `SetShadowListener` in both, and in Attach only touch `process_sp`
once it is known to be non-null (HijackProcessEvents was called before
the null check).

I was able to reproduce the failure at desk on a machine that's under
load. The issue no longer reproduces after this patch.

    [3 lines not shown]
DeltaFile
+5-2lldb/source/Plugins/Platform/Windows/PlatformWindows.cpp
+5-21 files

LLVM/project 55400d7 — llvm/include/llvm/CodeGen DIE.h

[CodeGen] Remove DIE::setForceChildren and DIE::ForceChildren (NFC) (#227207)

The last caller of DIE::setForceChildren was removed on March 6, 2017
in commit a175512b18478848bdbe203f2d25dc417860e3c5, leaving
DIE::ForceChildren always false.

Assisted-by: Antigravity
DeltaFile
+1-5llvm/include/llvm/CodeGen/DIE.h
+1-51 files

LLVM/project ca811cf — llvm/lib/Target/RISCV RISCVISelLowering.cpp, llvm/test/CodeGen/RISCV/rvv trunc-select-to-max-usat.ll

[RISCV] Remove combineTruncSelectToSMaxUSat. (#227162)

This is covered by InstCombine for the motivating benchmark.
DeltaFile
+0-295llvm/test/CodeGen/RISCV/rvv/trunc-select-to-max-usat.ll
+1-79llvm/lib/Target/RISCV/RISCVISelLowering.cpp
+1-3742 files

LLVM/project d909762 — offload/plugins-nextgen/common/src PluginInterface.cpp

[Offload] Remove unreachable code (#227100)

The function already has an early return after failed allocation.
DeltaFile
+0-7offload/plugins-nextgen/common/src/PluginInterface.cpp
+0-71 files

LLVM/project 9cafc5e — clang/lib/Sema SemaDeclCXX.cpp, clang/test/CXX/basic/basic.start/basic.start.main p2.cpp

[Clang] prevent instantiation of invalid friend function templates (#227038)

Fixes #226673

--- 

This patch addresses the issue in which an invalid friend function
template is instantiated as a valid declaration, leading to a crash upon
a later redeclaration.

---

This fixes a regression introduced by
https://github.com/llvm/llvm-project/pull/216555
DeltaFile
+19-0clang/test/CXX/basic/basic.start/basic.start.main/p2.cpp
+1-4clang/test/SemaTemplate/GH71595.cpp
+1-2clang/lib/Sema/SemaDeclCXX.cpp
+21-63 files

FreeBSD/src 7b8e59c — crypto/openssl/ssl d1_lib.c, crypto/openssl/ssl/statem statem_dtls.c

openssl: Fix CVE-2026-84782

This is a backport of an upstream commit to fix:
  dtls: reset init_off before retransmitting a message

Approved by:    so
Security:       FreeBSD-SA-26:68.openssl
Security:       CVE-2026-84782
DeltaFile
+17-0crypto/openssl/ssl/d1_lib.c
+2-0crypto/openssl/ssl/statem/statem_dtls.c
+19-02 files

FreeBSD/src 666f08d — lib/libc/sys fcntl.2, sys/kern vfs_syscalls.c

vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors

The FD_RESOLVE_BENEATH flag was intended to try to resolve bugzilla PR
262179 without entirely disallowing fd passing between jails.  However,
one can use renameat() to bypass the restriction: upon receiving a
directory fd with FD_RESOLVE_BENEATH set, a jailed process can still
move its CWD or one of its ancestors to the directory, and just cd
out of its jail root.

So disallow renameat() when either the source or destination directory
fds has FD_RESOLVE_BENEATH set, like we do with fchdir() and fchroot()
to prevent similar escapes.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101305
PR:             262179
Reported by:    firk at cantconnect.ru
Reviewed by:    olce, kib
Differential Revision:  https://reviews.freebsd.org/D59875
DeltaFile
+8-1lib/libc/sys/fcntl.2
+9-0sys/kern/vfs_syscalls.c
+17-12 files

FreeBSD/src 5f9f2ac — sys/fs/fdescfs fdesc_vnops.c, tests/sys/fs Makefile

fdescfs: Pass up additional metadata during lookups

When an fdescfs mount has the nodup option set, fdesc_lookup(/dev/fd/n)
returns the vnode referenced by file descriptor n, rather than returning
an fdescfs vnode.  This meant that fd metadata attached to fd n was not
preserved when reopening the file, which is contrary to the expected
semantics for capsicum rights and the UF_RESOLVE_BENEATH fd flag.  For
regular fdescfs mounts, this metadata is copied via dupfdopen().

Fix the problem by passing up this metadata through the nameidata
structure.  Thus, if one opens /dev/fd/n, the returned fd will inherit
UF_RESOLVE_BENEATH and the capability rights of fd n.  Add some
regression tests as well.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101304
Reported by:    Jan Bramkamp
Reviewed by:    kib

    [2 lines not shown]
DeltaFile
+274-0tests/sys/fs/fdescfs/fdescfs_test.c
+35-2sys/fs/fdescfs/fdesc_vnops.c
+9-0tests/sys/fs/fdescfs/Makefile
+1-0tests/sys/fs/Makefile
+319-24 files

FreeBSD/src f89e6b5 — sys/kern kern_descrip.c, sys/sys filedesc.h

file: Add a helper function to check whether filecaps are full

In a couple of places we want to know whether someone has limited rights
on an fd.  There, we want a predicate which determines whether the set
of rights is smaller than CAP_ALL, and whether there are explicit ioctl
or fcntl lists.  Factor this out into a helper function, in preparation
for use elsewhere.

No functional change intended.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59884
DeltaFile
+12-8sys/kern/kern_descrip.c
+1-0sys/sys/filedesc.h
+13-82 files

FreeBSD/src 616f35f — lib/libc/capability cap_rights_init.3, sys/kern subr_capability.c kern_descrip.c

file: Add filecaps_intersect() and cap_rights_intersect()

These routines let one compute the intersection of two sets of filecaps
or capability rights, just as filecaps_merge() and cap_rights_merge()
compute the union.  This will be useful in an upcoming patch.

filecaps_intersect() is complex due to the need to merge sets of ioctls.
For now this is implemented with a dumb nested loop on the basis that
ioctl lists are typically short enough that this is fine.  It may be
better to instead sort the two lists first and step through them
together.

No functional change intended.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59885
DeltaFile
+49-0sys/kern/kern_descrip.c
+23-0sys/kern/subr_capability.c
+14-2lib/libc/capability/cap_rights_init.3
+1-0sys/sys/filedesc.h
+1-0sys/sys/capsicum.h
+88-25 files

FreeBSD/src 04f841a — sys/kern sysv_sem.c

sysvsem: Fix another sequence number wraparound race

semop() may sleep waiting for a semaphore.  Upon waking up, it checks to
see if the set's sequence number has changed, indicating that the set
was removed.  The sequence number is not wide enough to prevent a false
negative due to wraparound, in which case the subsequent access of
`semakptr->u.__sem_base[sopptr->sem_num]` may be out of bounds.  This
race can be leveraged to elevate privileges.

Fix this by introducing a 64-bit sequence number for each semaphore
pool.  This is wide enough to make the race impossible to hit.  Allocate
a separate array for them, as we cannot really change the layout of
struct semid_kernel since some userspace tools (e.g., ipcrm(1)) embed
the layout.

While here, use semvalid() instead of open-coding its implementation,
convert a couple of flags to be bool, and use a better variable name to
store required permissions.


    [8 lines not shown]
DeltaFile
+39-31sys/kern/sysv_sem.c
+39-311 files

LLVM/project f7f5a96 — clang/test/CodeGen/RISCV rvp-intrinsics.c, llvm/test/CodeGen/AMDGPU global_atomics_scan_fadd.ll amdgcn.bitcast.512bit.ll

Merge branch 'main' into users/slinder1/cargo-toctree
DeltaFile
+47,307-47,314llvm/test/CodeGen/AMDGPU/amdgcn.bitcast.1024bit.ll
+9,228-9,364llvm/test/CodeGen/AMDGPU/amdgcn.bitcast.512bit.ll
+4,893-7,581clang/test/CodeGen/RISCV/rvp-intrinsics.c
+6,086-6,026llvm/test/CodeGen/RISCV/rvv/expandload.ll
+10,602-137llvm/test/CodeGen/RISCV/rvv/vector-interleave-fixed.ll
+4,817-5,217llvm/test/CodeGen/AMDGPU/global_atomics_scan_fadd.ll
+82,933-75,6399,397 files not shown
+561,705-327,0029,403 files

FreeBSD/src 6c9ee5f — lib/libsys fcntl.2, sys/kern vfs_syscalls.c

vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors

The FD_RESOLVE_BENEATH flag was intended to try to resolve bugzilla PR
262179 without entirely disallowing fd passing between jails.  However,
one can use renameat() to bypass the restriction: upon receiving a
directory fd with FD_RESOLVE_BENEATH set, a jailed process can still
move its CWD or one of its ancestors to the directory, and just cd
out of its jail root.

So disallow renameat() when either the source or destination directory
fds has FD_RESOLVE_BENEATH set, like we do with fchdir() and fchroot()
to prevent similar escapes.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101305
PR:             262179
Reported by:    firk at cantconnect.ru
Reviewed by:    olce, kib
Differential Revision:  https://reviews.freebsd.org/D59875
DeltaFile
+8-1lib/libsys/fcntl.2
+9-0sys/kern/vfs_syscalls.c
+17-12 files

FreeBSD/src 4536e59 — lib/libc/capability cap_rights_init.3, sys/kern subr_capability.c kern_descrip.c

file: Add filecaps_intersect() and cap_rights_intersect()

These routines let one compute the intersection of two sets of filecaps
or capability rights, just as filecaps_merge() and cap_rights_merge()
compute the union.  This will be useful in an upcoming patch.

filecaps_intersect() is complex due to the need to merge sets of ioctls.
For now this is implemented with a dumb nested loop on the basis that
ioctl lists are typically short enough that this is fine.  It may be
better to instead sort the two lists first and step through them
together.

No functional change intended.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59885
DeltaFile
+49-0sys/kern/kern_descrip.c
+23-0sys/kern/subr_capability.c
+14-2lib/libc/capability/cap_rights_init.3
+1-0sys/sys/filedesc.h
+1-0sys/sys/capsicum.h
+88-25 files

FreeBSD/src 8063b1b — sys/kern sysv_sem.c

sysvsem: Fix another sequence number wraparound race

semop() may sleep waiting for a semaphore.  Upon waking up, it checks to
see if the set's sequence number has changed, indicating that the set
was removed.  The sequence number is not wide enough to prevent a false
negative due to wraparound, in which case the subsequent access of
`semakptr->u.__sem_base[sopptr->sem_num]` may be out of bounds.  This
race can be leveraged to elevate privileges.

Fix this by introducing a 64-bit sequence number for each semaphore
pool.  This is wide enough to make the race impossible to hit.  Allocate
a separate array for them, as we cannot really change the layout of
struct semid_kernel since some userspace tools (e.g., ipcrm(1)) embed
the layout.

While here, use semvalid() instead of open-coding its implementation,
convert a couple of flags to be bool, and use a better variable name to
store required permissions.


    [8 lines not shown]
DeltaFile
+39-31sys/kern/sysv_sem.c
+39-311 files

FreeBSD/src 5c2ba42 — sys/kern kern_descrip.c, sys/sys filedesc.h

file: Add a helper function to check whether filecaps are full

In a couple of places we want to know whether someone has limited rights
on an fd.  There, we want a predicate which determines whether the set
of rights is smaller than CAP_ALL, and whether there are explicit ioctl
or fcntl lists.  Factor this out into a helper function, in preparation
for use elsewhere.

No functional change intended.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59884
DeltaFile
+12-8sys/kern/kern_descrip.c
+1-0sys/sys/filedesc.h
+13-82 files

FreeBSD/src 5db05b5 — sys/kern kern_event.c

kqueue: Fix a potential OOB access in kqueue_fork_copy_knote()

Here, fdp points to the new fdtable, copied from that of the parent
process.  There is a window after the fdtable is copied, and before
kqueue_fork_copy_knote() runs, where a different thread in the parent
could have grown the parent's fdtable and registered a knote with ident
larger than the size of the child's fdtable.  This race can lead to an
out-of-bounds read.

Add a bounds check for this case; skip the knote if it is referencing a
non-existent file.

Approved by:    so
Security:       FreeBSD-SA-26:65.kqueue
Security:       CVE-2026-58100
Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59916
DeltaFile
+2-1sys/kern/kern_event.c
+2-11 files

FreeBSD/src 0ee32bf — sys/kern kern_event.c

kqueue: Fix handling of marker knotes during fork

Commit d8bdcb08d0eb fixed a problem in kqueue_fork_copy_knote() where we
did not skip over marker knotes when copying.  However, that fix was not
sufficient: we bump the influx counter and check for a marker after
dropping the kqueue lock.  So, if multiple threads in a process are
forking concurrently, kqueue_fork_copy_list() may mark a marker as
in-flux and drop the lock; if the marker owner then frees the marker,
the first thread will decrement the in-flux counter of a freed knotes.
This use-after-free can be exploited, at least prior to commit
d8bdcb08d0eb, which makes exploitation more challenging.

Approved by:    so
Security:       FreeBSD-SA-26:65.kqueue
Security:       CVE-2026-58099
Reported by:    Reo Shiseki
Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59522
DeltaFile
+3-3sys/kern/kern_event.c
+3-31 files

FreeBSD/src 46c9357 — sys/fs/fdescfs fdesc_vnops.c, tests/sys/fs Makefile

fdescfs: Pass up additional metadata during lookups

When an fdescfs mount has the nodup option set, fdesc_lookup(/dev/fd/n)
returns the vnode referenced by file descriptor n, rather than returning
an fdescfs vnode.  This meant that fd metadata attached to fd n was not
preserved when reopening the file, which is contrary to the expected
semantics for capsicum rights and the UF_RESOLVE_BENEATH fd flag.  For
regular fdescfs mounts, this metadata is copied via dupfdopen().

Fix the problem by passing up this metadata through the nameidata
structure.  Thus, if one opens /dev/fd/n, the returned fd will inherit
UF_RESOLVE_BENEATH and the capability rights of fd n.  Add some
regression tests as well.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101304
Reported by:    Jan Bramkamp
Reviewed by:    kib

    [2 lines not shown]
DeltaFile
+236-0tests/sys/fs/fdescfs/fdescfs_test.c
+35-2sys/fs/fdescfs/fdesc_vnops.c
+9-0tests/sys/fs/fdescfs/Makefile
+1-0tests/sys/fs/Makefile
+281-24 files

FreeBSD/src ee87d97 — crypto/openssl/ssl d1_lib.c, crypto/openssl/ssl/statem statem_dtls.c

openssl: Fix CVE-2026-84782

This is a commit from upstream to fix:
  dtls: reset init_off before retransmitting a message

Approved by:    so
Security:       FreeBSD-SA-26:68.openssl
Security:       CVE-2026-84782
DeltaFile
+414-2crypto/openssl/test/dtlstest.c
+17-0crypto/openssl/ssl/d1_lib.c
+2-0crypto/openssl/ssl/statem/statem_dtls.c
+433-23 files

LLVM/project c3460c8 — clang/include/clang/Basic Attr.td AttrDocs.td

[Clang][docs] Markup corrections for attribute documentation (#226729)

The conversion of Clang attribute documentation from reST to MyST
markdown did not transform markup correctly in all cases. Additionally,
some PRs that were originally authored for reST were merged after the
conversion resulting in reST formatted markdown getting re-introduced.
This change corrects all such cases the author was able to identify,
applies markup that was previously missing, corrects a few typos along
the way, and even adds a missing attribute documentation reference that
has prevented the `#pragma clang loop` `pipeline` and
`pipeline_initiation_interval` documentation from being published since
2019.
DeltaFile
+204-221clang/include/clang/Basic/AttrDocs.td
+1-1clang/include/clang/Basic/Attr.td
+205-2222 files

FreeBSD/src 9c10f4c — lib/libsys fcntl.2, sys/kern vfs_syscalls.c

vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors

The FD_RESOLVE_BENEATH flag was intended to try to resolve bugzilla PR
262179 without entirely disallowing fd passing between jails.  However,
one can use renameat() to bypass the restriction: upon receiving a
directory fd with FD_RESOLVE_BENEATH set, a jailed process can still
move its CWD or one of its ancestors to the directory, and just cd
out of its jail root.

So disallow renameat() when either the source or destination directory
fds has FD_RESOLVE_BENEATH set, like we do with fchdir() and fchroot()
to prevent similar escapes.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101305
PR:             262179
Reported by:    firk at cantconnect.ru
Reviewed by:    olce, kib
Differential Revision:  https://reviews.freebsd.org/D59875
DeltaFile
+8-1lib/libsys/fcntl.2
+9-0sys/kern/vfs_syscalls.c
+17-12 files

FreeBSD/src 0475627 — sys/fs/fdescfs fdesc_vnops.c, tests/sys/fs/fdescfs fdescfs_test.c

fdescfs: Pass up additional metadata during lookups

When an fdescfs mount has the nodup option set, fdesc_lookup(/dev/fd/n)
returns the vnode referenced by file descriptor n, rather than returning
an fdescfs vnode.  This meant that fd metadata attached to fd n was not
preserved when reopening the file, which is contrary to the expected
semantics for capsicum rights and the UF_RESOLVE_BENEATH fd flag.  For
regular fdescfs mounts, this metadata is copied via dupfdopen().

Fix the problem by passing up this metadata through the nameidata
structure.  Thus, if one opens /dev/fd/n, the returned fd will inherit
UF_RESOLVE_BENEATH and the capability rights of fd n.  Add some
regression tests as well.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101304
Reported by:    Jan Bramkamp
Reviewed by:    kib

    [2 lines not shown]
DeltaFile
+165-0tests/sys/fs/fdescfs/fdescfs_test.c
+36-2sys/fs/fdescfs/fdesc_vnops.c
+201-22 files

FreeBSD/src 52b2056 — crypto/openssl/ssl d1_lib.c, crypto/openssl/ssl/statem statem_dtls.c

openssl: Fix CVE-2026-84782

This is a commit from upstream to fix:
  dtls: reset init_off before retransmitting a message

Approved by:    so
Security:       FreeBSD-SA-26:68.openssl
Security:       CVE-2026-84782
DeltaFile
+414-2crypto/openssl/test/dtlstest.c
+17-0crypto/openssl/ssl/d1_lib.c
+2-0crypto/openssl/ssl/statem/statem_dtls.c
+433-23 files