FreeBSD/ports 38715a5net-mgmt/monitoring-plugins Makefile distinfo, net-mgmt/monitoring-plugins/files patch-plugins_check__smtp.c patch-configure

net-mgmt/monitoring-plugins: update to 3.0.3

Changes:        https://github.com/monitoring-plugins/monitoring-plugins/releases
(cherry picked from commit d36ee38f32af49f7f9b3a7f5b90a5be10a00a585)
DeltaFile
+5-14net-mgmt/monitoring-plugins/files/patch-configure
+0-11net-mgmt/monitoring-plugins/files/patch-plugins_check__smtp.c
+3-3net-mgmt/monitoring-plugins/distinfo
+1-2net-mgmt/monitoring-plugins/Makefile
+9-304 files

FreeBSD/ports 28767c4net-mgmt/monitoring-plugins/files patch-plugins_check__smtp.c

net-mgmt/monitoring-plugins: fix timeout for check_smtp if -D parameter is used

PR:             296896
(cherry picked from commit 4c478ac9d42ac90d5ae5cc6e9fcc2e327560ff61)
DeltaFile
+11-0net-mgmt/monitoring-plugins/files/patch-plugins_check__smtp.c
+11-01 files

FreeBSD/ports ecc3e22net-mgmt/monitoring-plugins Makefile, net-mgmt/monitoring-plugins/files patch-configure

net-mgmt/monitoring-plugins: fix check_swap command

PR:             296895
(cherry picked from commit a96099194365c20cf573409835a546b4e6114f9a)
DeltaFile
+14-5net-mgmt/monitoring-plugins/files/patch-configure
+1-0net-mgmt/monitoring-plugins/Makefile
+15-52 files

OPNSense/src 4a1cb71lib/libpfctl libpfctl.c

pf: Add missing PF_TS_CNT Netlink attribute

There is no parser entry for PF_TS_CNT, therefore PF_TS_REFCNT
is written starting at pfrts_cnt, causing the refcount
to be wrongly shown in the "Addresses:" section of print_tstats().

Issue: https://github.com/opnsense/src/issues/300
DeltaFile
+2-1lib/libpfctl/libpfctl.c
+2-11 files

FreeBSD/ports d36ee38net-mgmt/monitoring-plugins Makefile distinfo, net-mgmt/monitoring-plugins/files patch-plugins_check__smtp.c patch-configure

net-mgmt/monitoring-plugins: update to 3.0.3

Changes:        https://github.com/monitoring-plugins/monitoring-plugins/releases
DeltaFile
+5-14net-mgmt/monitoring-plugins/files/patch-configure
+0-11net-mgmt/monitoring-plugins/files/patch-plugins_check__smtp.c
+3-3net-mgmt/monitoring-plugins/distinfo
+1-2net-mgmt/monitoring-plugins/Makefile
+9-304 files

FreeBSD/ports d037389security/trivy Makefile distinfo

security/trivy: update to 0.73.0

Changes:        https://github.com/aquasecurity/trivy/releases
DeltaFile
+5-5security/trivy/distinfo
+1-2security/trivy/Makefile
+6-72 files

FreeBSD/ports 267e634devel/glab pkg-plist Makefile

devel/glab: update to 1.112.0

Changes:        https://gitlab.com/gitlab-org/cli/-/releases
DeltaFile
+5-5devel/glab/distinfo
+2-2devel/glab/Makefile
+3-0devel/glab/pkg-plist
+10-73 files

OPNSense/src f23370bsys/dev/igc if_igc.c

igc: additionally disable PCIe ASPM for I226

Always disable PCIe ASPM for i226 type cards to improve stability
and wire sysctl calls to iflib_request_reset instead of igc_if_init
as this will stall the drivers RX path.
DeltaFile
+33-3sys/dev/igc/if_igc.c
+33-31 files

NetBSD/pkgsrc kG457nMdoc CHANGES-2026

   Updated www/py-drf-nested-routers, www/py-django-localflavor
VersionDeltaFile
1.5151+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc sRiLCrVwww/py-django-localflavor Makefile distinfo

   py-django-localflavor: updated to 5.1

   5.1   (2026-08-01)

   New flavors:

   - Added local flavor for Qatar
   - Added local flavor for Taiwan
   - Added local flavor for United Arab Emirates

   New fields for existing flavors:

   - US: Added ``USIndividualTaxpayerIdentificationNumberField``,
     ``USAdoptionTaxpayerIdentificationNumberField``, and
     ``USTaxpayerIdentificationNumberField`` form and model fields for validating
     ITINs, ATINs, and any valid U.S. taxpayer identification number (SSN, ITIN,
     or ATIN).

   Modifications to existing flavors:

    [7 lines not shown]
VersionDeltaFile
1.5+40-1www/py-django-localflavor/PLIST
1.4+4-4www/py-django-localflavor/distinfo
1.9+3-3www/py-django-localflavor/Makefile
+47-83 files

NetBSD/pkgsrc rWUQ4Rrwww/py-drf-nested-routers Makefile distinfo

   py-drf-nested-routers: updated to 0.95.3

   0.95.3

   Removed support to EOLed Python 3.9. Still works for now, but no CI will validate it anymore.
   Update flake8 to 7.1.1
   Test against DRF 3.16 and Django 5.2
   Test and advertise DRF 3.16 and Django 5.2 compatibility
   Fix Error when request.data is a list. Fixes #349.
   Update mypy to 1.13.0
   Fix release pyc leakages
   Add Python 3.14 & Update release flow
VersionDeltaFile
1.13+4-4www/py-drf-nested-routers/distinfo
1.15+2-2www/py-drf-nested-routers/Makefile
+6-62 files

HardenedBSD/src 17260cdcontrib/wpa/src/ap ieee802_11.c, contrib/wpa/src/common proximity_ranging.c qca-vendor.h

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+6,124-33contrib/wpa/src/common/qca-vendor.h
+5,003-0contrib/wpa/wpa_supplicant/nan_supplicant.c
+3,381-671contrib/wpa/src/drivers/driver_nl80211.c
+3,106-664contrib/wpa/src/ap/ieee802_11.c
+3,677-0contrib/wpa/src/nan/nan.c
+2,707-0contrib/wpa/src/common/proximity_ranging.c
+23,998-1,368331 files not shown
+89,794-24,631337 files

HardenedBSD/src 1204701contrib/wpa/src/ap ieee802_11.c, contrib/wpa/src/common proximity_ranging.c qca-vendor.h

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+6,124-33contrib/wpa/src/common/qca-vendor.h
+5,003-0contrib/wpa/wpa_supplicant/nan_supplicant.c
+3,381-671contrib/wpa/src/drivers/driver_nl80211.c
+3,106-664contrib/wpa/src/ap/ieee802_11.c
+3,677-0contrib/wpa/src/nan/nan.c
+2,707-0contrib/wpa/src/common/proximity_ranging.c
+23,998-1,368331 files not shown
+89,794-24,631337 files

HardenedBSD/src fb6f97frelease Makefile.gce

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+2-2release/Makefile.gce
+2-21 files

HardenedBSD/ports 1c34d7adevel/py-pytest Makefile, devel/py-pytest/files patch-pyproject.toml

Merge branch 'freebsd/main' into hardenedbsd/main
DeltaFile
+649-0sysutils/leaves/distinfo
+323-0sysutils/leaves/Makefile.crates
+32-0devel/py-pytest/files/patch-pyproject.toml
+27-0sysutils/leaves/Makefile
+9-16devel/py-pytest/Makefile
+8-6x11-fonts/font-schumacher-misc/Makefile
+1,048-2231 files not shown
+1,112-5837 files

NetBSD/pkgsrc frgGX6mdoc CHANGES-2026

   Updated www/py-django[5], www/py-django-stubs-ext, www/py-django-polymorphic, www/py-djangorestframework
VersionDeltaFile
1.5150+6-1doc/CHANGES-2026
+6-11 files

NetBSD/pkgsrc Z7QeHfmwww/py-djangorestframework Makefile distinfo

   py-djangorestframework: updated to 3.18.0

   3.18.0

   Breaking changes

   Drop support for Django 4.2, Django 5.0 and Django 5.1
   Change errors for list serializers (many=True) to dict format

   Features

   Add support for Django 6.1
   Add unaccent to SearchFilter
   Add @throttle_scope function based view decorator
   Add nulls_distinct support to UniqueTogetherValidator

   Bug fixes

   Replace cc_delim_re usage with split_header_value for Django 6.1+ compatibility

    [9 lines not shown]
VersionDeltaFile
1.34+4-4www/py-djangorestframework/distinfo
1.47+3-3www/py-djangorestframework/Makefile
+7-72 files

NetBSD/pkgsrc ceUPRPewww/py-django-polymorphic Makefile distinfo

   py-django-polymorphic: updated to 4.11.7

   4.11.7
   support django 6.1
   fix: add kwargs to save method to keep compatability with other tools
VersionDeltaFile
1.18+4-4www/py-django-polymorphic/distinfo
1.20+2-2www/py-django-polymorphic/Makefile
+6-62 files

OPNSense/src 4742e7esys/dev/igc igc_base.h igc_base.c

igc: Disable PCIe L1.2 on I225

I225 devices can incorrectly enter L1 substates while CLKREQ# is
asserted, both while idle and in D3.  Disable ASPM and PCI-PM L1.2 on
I225 to prevent the resulting packet loss.

Keep the I226 workaround ASPM-only because it addresses a separate
traffic exit latency observation.

PR:             265714

(cherry picked from commit 4a28d390f5fbae2483e88805559881b04ccf9a80)
DeltaFile
+22-20sys/dev/igc/if_igc.c
+29-0sys/dev/igc/igc_base.c
+1-0sys/dev/igc/igc_base.h
+52-203 files

OPNSense/src 1ca55acsys/dev/igc igc_base.c

igc: Apply ASPM L1.2 workaround to all I226 devices

Classify I226_LMVP and I226_BLANK_NVM as I226 silicon so they
receive the I226-specific ASPM L1.2 workaround.

PR:             279245
Pull-Request:   https://github.com/freebsd/freebsd-src/pull/2318

(cherry picked from commit cecb0f45cb83349c60514da38fddce83ad042468)
DeltaFile
+5-0sys/dev/igc/igc_base.c
+5-01 files

OPNSense/src ece5e3esys/dev/igc igc_base.h igc_base.c

igc: Disable ASPM L1.2 on I226 to prevent RX stalls

I226 parts advertise support for the PCIe L1.2 link substate, but a
hardware erratum makes the exit latency from that low-power state
longer than the packet buffer can absorb under load. This stalls the
inbound packet stream. Disabling ASPM system-wide (BIOS or OS ASPM
policy) does not fix it. The L1.2 enable bit must be cleared directly
in the device's own PCIe L1 PM extended capability.

Add igc_is_device_id_i226() to identify affected parts and
igc_disable_broken_aspm_l1_2() to clear the ASPM L1.2 enable bit
on attach and after resume, since PCIe config space can be
reset across a suspend/resume cycle.

Adapted from the Linux igc driver:

  0325143b59c6 igc: disable L1.2 PCI-E link substate to avoid
               performance issue
  1468c1f97cf3 igc: fix disabling L1.2 PCI-E link substate on I226

    [9 lines not shown]
DeltaFile
+44-0sys/dev/igc/if_igc.c
+21-0sys/dev/igc/igc_base.c
+1-0sys/dev/igc/igc_base.h
+66-03 files

NetBSD/pkgsrc 7lY8Volwww/py-django-stubs-ext Makefile distinfo

   py-django-stubs-ext: updated to 6.0.9

   6.0.9

   6.0.8 was supposed to be the last 6.0.x release, but we found several regressions that we wanted to fix.
   Now we are working on 6.1.0 release :)

   Detect every generic stub class in the generic consistency test
   Don't crash on a many-to-many through model that can't be resolved
VersionDeltaFile
1.10+4-4www/py-django-stubs-ext/distinfo
1.11+2-2www/py-django-stubs-ext/Makefile
+6-62 files

NetBSD/pkgsrc kI0M2yIwww/py-django5 Makefile distinfo

   py-django5: updated to 5.2.17

   Django 5.2.17 fixes one security issue with severity “high”, two security
   issues with severity “moderate”, and one security issue with severity “low” in
   5.2.16.
VersionDeltaFile
1.5+4-4www/py-django5/distinfo
1.5+2-2www/py-django5/Makefile
+6-62 files

NetBSD/pkgsrc N5MZ11Qwww/py-django Makefile distinfo

   py-django: updated to 6.1

   The Django team is happy to announce the release of Django 6.1.

   The release notes offer a harmonious mélange of new features and usability improvements. A few highlights are:

   - Model field fetch modes for configuring on-demand fetching behavior
   - Database-level delete options for ForeignKey.on_delete
   - Dictionary-based email settings
VersionDeltaFile
1.55+23-1www/py-django/PLIST
1.130+4-4www/py-django/distinfo
1.158+3-3www/py-django/Makefile
+30-83 files

OPNSense/src 6b79b4fcontrib/kyua/cli cmd_debug.cpp, contrib/kyua/doc kyua-debug.1.in

kyua-debug: Add -P option

Add -P as shorthand for --pause-before-cleanup.

MFC after:      1 week
Reviewed by:    ngie
Differential Revision:  https://reviews.freebsd.org/D56613

(cherry picked from commit 7c51da13ae55dc98e9cc1b794e1fe6fc001d7f42)
DeltaFile
+2-2contrib/kyua/doc/kyua-debug.1.in
+1-0contrib/kyua/cli/cmd_debug.cpp
+3-22 files

OPNSense/src 33a943elib/libifconfig libifconfig_internal.c libifconfig.c, sys/net rtsock.c

sys/socket.h: Fix AF_MAX

AF_MAX was always intended to be one more than the greatest allocated
value.  Jeff broke this in 2013.  Unfortunately, a bunch of people then
decided to adapt to the mistake instead of correcting it.

Fixes:          863c7e45628d (" - Reserve a special AF for SDP.  The one we were incorrectly using before    was taken by another AF.")
MFC after:      3 days
Sponsored by:   Klara, Inc.
Sponsored by:   NetApp, Inc.
Reviewed by:    kevans, glebius
Differential Revision:  https://reviews.freebsd.org/D58597

(cherry picked from commit ddd850aa7720f77b6605599655df898b16ed74cc)
DeltaFile
+3-3sys/netlink/route/rt.c
+2-2sys/net/rtsock.c
+2-2sys/net/route/route_helpers.c
+2-2lib/libifconfig/libifconfig.c
+3-1sys/sys/socket.h
+1-1lib/libifconfig/libifconfig_internal.c
+13-113 files not shown
+16-149 files

OPNSense/src 2b7b052sys/dev/ena ena.h

ena: Update driver version to v2.8.4

Bug Fixes:
* Fix false 'missing TX completions' warnings due to timestamp race
* Put taskqueues into correct NUMA domain if !RSS

Minor Changes:
* Batch RX statistics updates
* Swap RX/TX completions cleanup order

Submitted by: Arthur Kiyanovski <akiyano at amazon.com>
MFC after: 2 weeks
Sponsored by: Amazon, Inc.
Reviewed by: cperciva
Differential Revision: https://reviews.freebsd.org/D58242

(cherry picked from commit 605e699cd6ca4feae6c73c5c5ea8337054897116)
DeltaFile
+1-1sys/dev/ena/ena.h
+1-11 files

OPNSense/src 28ca5dfsys/dev/ena ena.h ena_datapath.c

ena: Fix false 'missing TX completions' warnings due to timestamp race

Sporadic 'Found a Tx that wasn't completed on time' warnings appear
under sustained TX load, always reporting '1 msecs since last cleanup'
despite the 5-second timeout threshold.

The per-packet TX timestamp uses struct bintime (128 bits: two 64-bit
fields sec and frac) which is read and written non-atomically. A race
exists between the missing TX completion check
(check_missing_comp_in_tx_queue reading the timestamp) and the TX
submit path or cleanup path writing it on another CPU. Since the two
fields are not updated atomically, the check can observe a partially
written timestamp - one field from the old value and one from the new.
This can produce a timestamp with {sec=0, frac=valid}, causing the
check to compute a time offset equal to system uptime and falsely
exceeding the 5-second timeout.

Confirmed by instrumentation showing all occurrences had sec=0 with
valid frac/mbuf, cleanup_running=0, and ticks==last_cleanup_ticks.

    [24 lines not shown]
DeltaFile
+7-6sys/dev/ena/ena.c
+2-2sys/dev/ena/ena_datapath.c
+1-1sys/dev/ena/ena.h
+10-93 files

OPNSense/src 98e492dsys/dev/ena ena_datapath.c

ena: Batch RX statistics updates

Move per-packet counter_enter/counter_exit pairs out of the RX
processing loop and batch them into a single update after the
loop completes.

Previously, each received packet triggered two separate
counter_enter/counter_exit blocks -- one for bytes and one for
packet count. This commit accumulates totals in local variables
and updates all four counters (ring and hw stats for both packets
and bytes) in a single counter_enter/counter_exit block after the
loop.

Also move the stats update to after the refill and LRO flush
so that the error path (goto update_stats) and the normal path
converge at the same label, avoiding code duplication.

Submitted by: David Arinzon <darinzon at amazon.com>
MFC after: 2 weeks

    [5 lines not shown]
DeltaFile
+12-11sys/dev/ena/ena_datapath.c
+12-111 files

OPNSense/src 0fadfcbsys/dev/ena ena_datapath.c

ena: Swap cleanup order

As RX processing is heavier than TX completions processing, swap the
order and process TX completions first, in order to avoid starving the
completions and causing potential missing TX completions.

Submitted by: Ofir Tabachnik <ofirt at amazon.com>
MFC after: 2 weeks
Sponsored by: Amazon, Inc.
Reviewed by: cperciva
Differential Revision: https://reviews.freebsd.org/D58239

(cherry picked from commit f08def9ed97f45700eb0611a3fd9240210c9303e)
DeltaFile
+1-1sys/dev/ena/ena_datapath.c
+1-11 files