HardenedBSD/src 0026410 — share/misc bsd-family-tree, usr.sbin/bhyve rtc_pl031.c

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+44-37share/misc/bsd-family-tree
+2-2usr.sbin/bhyve/rtc_pl031.c
+1-1usr.sbin/bsdinstall/scripts/auto
+47-403 files

FreeBSD/src 6d78add — share/misc bsd-family-tree

bsd-family-tree: add NetBSD 10.2

(cherry picked from commit 7b7ef798bfc56c56e80b88bc277d5c6158dcaee4)
DeltaFile
+23-20share/misc/bsd-family-tree
+23-201 files

FreeBSD/src 75655f9 — share/misc bsd-family-tree

bsd-family-tree: add NetBSD 9.5 and FreeBSD 14.5

(cherry picked from commit ae458518935eee7a6dc59958f1fb9da223b873c3)
DeltaFile
+41-37share/misc/bsd-family-tree
+41-371 files

HardenedBSD/src 6b1365b — share/misc bsd-family-tree, usr.sbin/bhyve rtc_pl031.c

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+44-37share/misc/bsd-family-tree
+2-2usr.sbin/bhyve/rtc_pl031.c
+46-392 files

HardenedBSD/ports 54f84a2 — chinese/libchewing distinfo, devel/antlr4-cpp-runtime pkg-plist

Merge branch 'freebsd/main' into hardenedbsd/main
DeltaFile
+0-703devel/py-pyrepl/files/patch-2to3
+171-189x11-fonts/py-shaperglot/distinfo
+9-226mail/thunderbird/files/patch-libwebrtc-generated
+84-93x11-fonts/py-shaperglot/Makefile.crates
+177-0devel/antlr4-cpp-runtime/pkg-plist
+57-105chinese/libchewing/distinfo
+498-1,316940 files not shown
+5,064-4,921946 files

FreeBSD/src 493231a — share/misc bsd-family-tree

bsd-family-tree: add NetBSD 10.2

(cherry picked from commit 7b7ef798bfc56c56e80b88bc277d5c6158dcaee4)
DeltaFile
+23-20share/misc/bsd-family-tree
+23-201 files

HardenedBSD/src 493231a — share/misc bsd-family-tree

bsd-family-tree: add NetBSD 10.2

(cherry picked from commit 7b7ef798bfc56c56e80b88bc277d5c6158dcaee4)
DeltaFile
+23-20share/misc/bsd-family-tree
+23-201 files

HardenedBSD/src 1eacca6 — share/misc bsd-family-tree

bsd-family-tree: add NetBSD 9.5 and FreeBSD 14.5

(cherry picked from commit ae458518935eee7a6dc59958f1fb9da223b873c3)
DeltaFile
+41-37share/misc/bsd-family-tree
+41-371 files

FreeBSD/src 1eacca6 — share/misc bsd-family-tree

bsd-family-tree: add NetBSD 9.5 and FreeBSD 14.5

(cherry picked from commit ae458518935eee7a6dc59958f1fb9da223b873c3)
DeltaFile
+41-37share/misc/bsd-family-tree
+41-371 files

LLVM/project 3a2f13f — clang/lib/CodeGen CGExprScalar.cpp, clang/test/CodeGenHLSL/BasicFeatures VectorElementwiseCast.hlsl

[HLSL] Extract matrix elementwise cast operands from SSA (#227065)

Avoid materializing matrix operands in the hlsl.ewcast.src temporary
when performing matrix-to-vector elementwise casts. Extract each element
directly from the canonical matrix SSA value using its column-major
flattened index.

Factor vector result construction into a shared helper so aggregate and
matrix sources use the same conversion and insertion logic.

Update the matrix-to-vector CodeGen checks for both row-major and
column-major layouts.

Assisted by Copilot using GPT 5.6 Sol
DeltaFile
+25-47clang/test/CodeGenHLSL/BasicFeatures/VectorElementwiseCast.hlsl
+48-18clang/lib/CodeGen/CGExprScalar.cpp
+73-652 files

LLVM/project afab119 — llvm/lib/CodeGen/SelectionDAG SelectionDAG.cpp, llvm/test/CodeGen/RISCV/rvv fixed-vectors-vploadff.ll vploadff.ll

[SelectionDAG] Add computeKnownBits support for VP_LOAD_FF's second result (#227389)

The second result of `ISD::VP_LOAD_FF` is the new EVL, which is always
less than or equal to(1) the EVL operand of this intrinsic, and (2) the
largest length of the loaded vector. This patch teaches computeKnownBits
about these ranges so that DAGCombiner can eliminate things like
redundant z/sext + truncate on this new EVL.

In RISC-V, this means that if there are two consecutive fault only first
loads where the second one is using the EVL from the first load, there
won't be any redundant zext + truncate generated for the intermediate
EVL in between.
DeltaFile
+38-0llvm/test/CodeGen/RISCV/rvv/vploadff.ll
+18-0llvm/lib/CodeGen/SelectionDAG/SelectionDAG.cpp
+13-0llvm/test/CodeGen/RISCV/rvv/fixed-vectors-vploadff.ll
+69-03 files

LLVM/project 71879b9 — bolt/runtime common.h

[BOLT] Keep instrumentation diagnostics out of line (#225986)

The instrumentation runtime's diagnostics reserve a 32 KiB scratch
buffer on the stack. When `assert()` or `reportNumber()` get inlined
into callers on instrumented code paths, the buffer inflates every
caller frame — on small thread stacks a single such frame already
overflows the guard region and the profiled binary segfaults even when
no assertion fires.

Move the `assert()` failure path into a `noinline` helper
(`reportAssertFailure`) and mark `reportNumber()` `noinline` as well, so
the scratch buffer is only reserved when a diagnostic is actually
emitted. This matches the fix sketched in the issue report.

Verified: `common.h` syntax-checks clean in the freestanding runtime
build; the only behavioral change is where the buffer lives.

Fixes #225479


    [2 lines not shown]
DeltaFile
+13-4bolt/runtime/common.h
+13-41 files

GhostBSD/ports 2c9e9ca — net-im/libsignal-node Makefile

net-im/libsignal-node: Fix build with npm 12

npm 12 rejects unknown CLI flags with EUNKNOWNCONFIG instead of only
warning about them, so --nodedir and --ignore-optional are now hard
errors.

Point node-gyp at the node headers through npm_config_nodedir in
MAKE_ENV instead. node-gyp reads any npm_config_* variable from the
environment, and this is already how bitwarden-cli, signal-desktop and
vscode do it.

--ignore-optional is a yarn flag left over from when this port used
yarn. npm never honored it, so dropping it does not change what gets
installed.
DeltaFile
+4-3net-im/libsignal-node/Makefile
+4-31 files

GhostBSD/ports 5808570 — security/node-sqlcipher Makefile

security/node-sqlcipher: Fix build with npm 12

npm 12 rejects unknown CLI flags with EUNKNOWNCONFIG instead of only
warning about them, so --nodedir is now a hard error.

Point node-gyp at the node headers through npm_config_nodedir in
MAKE_ENV instead. node-gyp reads any npm_config_* variable from the
environment, and this is already how bitwarden-cli, signal-desktop and
vscode do it.
DeltaFile
+3-2security/node-sqlcipher/Makefile
+3-21 files

LLVM/project 8219f5c — llvm/test/Instrumentation/MemorySanitizer masked-divrem.ll

[msan] add tests for llvm.masked.{udiv,sdiv,urem,srem} (#227462)

In preparation for #225363, which changes behavior.
DeltaFile
+307-0llvm/test/Instrumentation/MemorySanitizer/masked-divrem.ll
+307-01 files

LLVM/project a903200 — llvm/include/llvm/IR Constants.h

Fix typo in comment for ConstantInt get method (#227493)

Originally found this typo from docs generated by Doxygen.
DeltaFile
+1-1llvm/include/llvm/IR/Constants.h
+1-11 files

LLVM/project 9b63886 — clang/include/clang/CIR/Dialect/IR CIROps.td, clang/lib/CIR/CodeGen CIRGenBuiltin.cpp

fixup! [CIR] Support type deduction builder for BinaryFPToFPBuiltinOp
DeltaFile
+2-5clang/lib/CIR/CodeGen/CIRGenBuiltin.cpp
+0-4clang/include/clang/CIR/Dialect/IR/CIROps.td
+2-92 files

LLVM/project 69385fc — orc-rt/cmake OrcRTTesting.cmake, orc-rt/test/regression README.md lit.cfg.py

[orc-rt] Make split-file a required regression test tool. (#227510)

split-file is an LLVM utility, like FileCheck and not, so it's available
wherever they are. Require it in the same way, rather than gating tests
on a split-file lit feature.
DeltaFile
+14-1orc-rt/cmake/OrcRTTesting.cmake
+6-8orc-rt/test/regression/lit.cfg.py
+0-2orc-rt/test/regression/README.md
+0-1orc-rt/test/regression/languages/c/addressing/cross-object/hidden-data-load.test
+0-1orc-rt/test/regression/languages/c/addressing/cross-object/global-data-load.test
+0-1orc-rt/test/regression/languages/c/addressing/cross-object/global-array-element-pointer-in-data.test
+20-146 files

LLVM/project 9af3f9f — llvm/test/TableGen HwModeBitSet.td, llvm/unittests/MC TargetRegistry.cpp

[MC] Add baseline test for MCContext::getSubtargetCopy HwMode loss

No change intended here, just adding test coverage showing that
MCContext::getSubtargetCopy currently slices away the target's
<Target>GenMCSubtargetInfo subclass and causes getHwMode() and
getHwModeSet() to return 0.

This commit was created with the help of AI tools
DeltaFile
+34-0llvm/unittests/MC/TargetRegistry.cpp
+9-0llvm/test/TableGen/HwModeBitSet.td
+43-02 files

LLVM/project 5978944 — llvm/test/tools/llvm-objdump/ELF/RISCV mapping-sym-isa-disassembly.s mapping-sym-isa-mattr-conflict.s, llvm/tools/llvm-objdump llvm-objdump.cpp

[llvm-objdump][RISC-V] Do not leak file-level features into $x<ISA> regions

Previously, RISCVISATargetCache::get initialized per-region features from
Base.SubtargetInfo->getFeatureString(), which already included the
file-level Tag_RISCV_arch and --mattr flags. Because RISCVISAInfo::toFeatures()
only emits "+ext" for extensions present in the "$x<ISA>" mapping symbol
(and never "-ext"), any extension enabled in Tag_RISCV_arch or via a
conflicting --mattr remained enabled even in regions whose "$x<ISA>"
mapping symbol disabled it.

Start from an empty SubtargetFeatures instead and populate it from the
parsed "$x<ISA>" mapping symbol (plus non-conflicting --mattr flags).

This commit was created with the help of AI tools
DeltaFile
+12-15llvm/tools/llvm-objdump/llvm-objdump.cpp
+10-0llvm/test/tools/llvm-objdump/ELF/RISCV/mapping-sym-isa-mattr-conflict.s
+2-2llvm/test/tools/llvm-objdump/ELF/RISCV/mapping-sym-isa-disassembly.s
+24-173 files

LLVM/project f0e6410 — llvm/lib/Target/RISCV RISCVInstrFormats.td, llvm/test/MC/RISCV rvi-pseudos-invalid.s

[RISC-V][MC] Reject x0 as the temporary register for store pseudos

The zero register as the temporary for the store pseudo is illegal since
it is used to synthesize the store address and using zero would mean
that the auipc result is ignored and we store to an invalid location.
DeltaFile
+31-14llvm/test/MC/RISCV/rvi-pseudos-invalid.s
+2-2llvm/lib/Target/RISCV/RISCVInstrFormats.td
+33-162 files

LLVM/project a2e1ea9 — bolt/runtime CMakeLists.txt

[BOLT] Ensure runtime is built with uncompressed debug symbols (#218126)

Currently, if the runtime is built with compressed debug symbols it
causes an out-of-bounds read and segfault when instrumenting a binary.

This is due to JITLink currently not supporting SHF_COMPRESSED symbols
as it would need to decompress the symbols first to update the reloc
symbols

As some distributions are starting to enable compressed debug sections
in their toolchains by default, ensure the runtime is built without them
until JITLink supports updating SHF_COMPRESSED relocs.
DeltaFile
+3-0bolt/runtime/CMakeLists.txt
+3-01 files

FreeBSD/ports 0d401ad — benchmarks/iperf3 Makefile distinfo

benchmarks/iperf3: Update to iperf-3.22.

Notable changes: https://github.com/esnet/iperf/releases/tag/3.22

Security:       CVE-2026-101276
Security:       CVE-2026-101283
Security:       CVE-2026-102253
Security:       CVE-2026-71217

Sponsored by:   Energy Sciences Network (ESnet)
DeltaFile
+3-3benchmarks/iperf3/distinfo
+1-1benchmarks/iperf3/Makefile
+4-42 files

HardenedBSD/ports 0d401ad — benchmarks/iperf3 Makefile distinfo

benchmarks/iperf3: Update to iperf-3.22.

Notable changes: https://github.com/esnet/iperf/releases/tag/3.22

Security:       CVE-2026-101276
Security:       CVE-2026-101283
Security:       CVE-2026-102253
Security:       CVE-2026-71217

Sponsored by:   Energy Sciences Network (ESnet)
DeltaFile
+3-3benchmarks/iperf3/distinfo
+1-1benchmarks/iperf3/Makefile
+4-42 files

LLVM/project 53504f5 — llvm/test/TableGen RegClassByHwModeCompressPat4Modes.td RegClassByHwModeCompressPatError.td, llvm/utils/TableGen CompressInstEmitter.cpp

[TableGen] Support HwMode registers in CompressInstEmitter

Previously, CompressInstEmitter only handled plain Register and
RegisterClass records when matching and validating operands in
CompressPat definitions. Attempting to use a RegisterByHwMode (such as a
mode-dependent stack pointer) or a RegClassByHwMode with mode-dependent
registers failed because CompressInstEmitter could not resolve the
underlying register or register class for a given subtarget configuration.

Introduce HwModePredicates in CodeGenHwModes to resolve HwModeSelect
records using the subtarget features required by a CompressPat (with
predicates implying the absence of all non-default modes resolving to
DefaultMode). This allows using a single instruction definition for
compressed instructions like RISC-V C_ADDI4SPN/C_ADDI16SP across HwModes
instead of duplicating the instruction definitions for each mode.

This commit was created with the help of AI tools
DeltaFile
+194-0llvm/utils/TableGen/Common/CodeGenHwModes.cpp
+99-83llvm/utils/TableGen/CompressInstEmitter.cpp
+154-1llvm/test/TableGen/RegClassByHwModeCompressPat.td
+129-0llvm/test/TableGen/RegClassByHwModeCompressPatError.td
+116-0llvm/test/TableGen/RegClassByHwModeCompressPat4Modes.td
+50-0llvm/utils/TableGen/Common/SubtargetFeatureInfo.cpp
+742-842 files not shown
+785-848 files

FreeBSD/src ec8b68b — sys/amd64/conf GENERIC

amd64: Revert an unintended change to GENERIC

Fixes:  767cd9bb4200 ("vm_swapout: Fix the build without options RACCT")
DeltaFile
+3-3sys/amd64/conf/GENERIC
+3-31 files

HardenedBSD/src ec8b68b — sys/amd64/conf GENERIC

amd64: Revert an unintended change to GENERIC

Fixes:  767cd9bb4200 ("vm_swapout: Fix the build without options RACCT")
DeltaFile
+3-3sys/amd64/conf/GENERIC
+3-31 files

LLVM/project 48b6484 — clang/lib/CIR/Dialect/Transforms CallConvLoweringPass.cpp, clang/lib/CIR/Dialect/Transforms/TargetLowering CIRABIRewriteContext.h CIRABIRewriteContext.cpp

[CIR] Assert that getIndirectCalleeType is given an indirect call

Assisted-by: Claude Code / claude-opus-5-5
DeltaFile
+1-2clang/lib/CIR/Dialect/Transforms/TargetLowering/CIRABIRewriteContext.h
+1-2clang/lib/CIR/Dialect/Transforms/TargetLowering/CIRABIRewriteContext.cpp
+1-1clang/lib/CIR/Dialect/Transforms/CallConvLoweringPass.cpp
+3-53 files

FreeBSD/src 5990a88 — tests/sys/geom/class/label basic.sh, tests/sys/geom/class/zoned conf.sh

tests/geom: fix ATF test listing when geom class module is missing

geom_subr.sh serves both legacy TAP tests and ATF tests. It defaults to the
TAP path, so ATF tests must set ATF_TEST=true before sourcing it.

Sponsored by:   Netflix
DeltaFile
+1-0tests/sys/geom/class/zoned/conf.sh
+1-0tests/sys/geom/class/label/basic.sh
+2-02 files

HardenedBSD/src 5990a88 — tests/sys/geom/class/label basic.sh, tests/sys/geom/class/zoned conf.sh

tests/geom: fix ATF test listing when geom class module is missing

geom_subr.sh serves both legacy TAP tests and ATF tests. It defaults to the
TAP path, so ATF tests must set ATF_TEST=true before sourcing it.

Sponsored by:   Netflix
DeltaFile
+1-0tests/sys/geom/class/zoned/conf.sh
+1-0tests/sys/geom/class/label/basic.sh
+2-02 files