FreeBSD/ports e123382 — x11/quickshell Makefile distinfo, x11/quickshell/files patch-src_wayland_hyprland_ipc_connection.cpp

x11/quickshell: Update to 0.3.2

Changelog: https://git.outfoxxed.me/quickshell/quickshell/src/tag/v0.3.2/changelog/v0.3.2.md

Reported by:    GitHub (watch releases)
DeltaFile
+3-3x11/quickshell/distinfo
+2-3x11/quickshell/Makefile
+2-2x11/quickshell/files/patch-src_wayland_hyprland_ipc_connection.cpp
+7-83 files

LLVM/project cbdad67 — llvm/lib/Target/AMDGPU SIInstrInfo.h GCNCreateVOPD.cpp, llvm/test/CodeGen/AMDGPU llvm.amdgcn.fdot2.f32.bf16.ll llvm.amdgcn.fdot2.ll

[AMDGPU] Form VOPD dot2 pairs with a literal in src1 (#230183)

This PR restores VOPD pair formation after the legality checks
relaxation introduced by #229906. Before the legality check relaxation,
MachineCSE was commuting immediate operands from src1 to src0, and then
failing to commute them back, which inadvertently results in the
immediate operands in src0, and the VOPD pairing would succeed. After
the legality relaxation, MachineCSE is now able to successfully commute
the immediates back from src0 to src1, which breaks VOPD pairing since
the pass expected the immediates to be in src0 position. This change
adds a check in GCNVOPDUtils.cpp which checks if a commute is necessary
to allow the VOPD pairing, and then records that finding so that
GCNCreateVOPD applies the commute before creating the VOPD pair.

Co-authored by: Claude Code

---------

Co-authored-by: Claude <noreply at anthropic.com>
DeltaFile
+149-0llvm/test/CodeGen/AMDGPU/vopd-dot2-commute-imm-src1.mir
+58-19llvm/lib/Target/AMDGPU/GCNVOPDUtils.cpp
+12-35llvm/test/CodeGen/AMDGPU/llvm.amdgcn.fdot2.ll
+3-6llvm/test/CodeGen/AMDGPU/llvm.amdgcn.fdot2.f32.bf16.ll
+9-0llvm/lib/Target/AMDGPU/GCNCreateVOPD.cpp
+2-2llvm/lib/Target/AMDGPU/SIInstrInfo.h
+233-621 files not shown
+236-627 files

LLVM/project 024cc93 — llvm/test/CodeGen/AMDGPU amdgcn.bitcast.896bit.ll amdgcn.bitcast.960bit.ll

[AMDGPU] Allow commuting immediates out of src0 when legal (#229906)

Fixes issue introduced by #181918 on gfx10+ where an immediate can get
commuted from src0 to src1 but then fail to get commuted back to src0
due to the legality checks in `isLegalToSwap`.

This PR relaxes the checks in `isLegalToSwap`, since gfx10+ allows the
immediate to be in locations other than src0. Relaxing these checks
causes MachineCSE to also successfully commute immediate operands out of
src0, which is the reason behind all the lit tests that required
modification. The PR also adds 2 new tests.

Co-authored by: Claude Code

Fixes: LCOMPILER-2920

---------

Co-authored-by: Claude <noreply at anthropic.com>
DeltaFile
+2,824-2,824llvm/test/CodeGen/AMDGPU/amdgcn.bitcast.1024bit.ll
+1,412-1,412llvm/test/CodeGen/AMDGPU/amdgcn.bitcast.512bit.ll
+706-706llvm/test/CodeGen/AMDGPU/amdgcn.bitcast.256bit.ll
+496-496llvm/test/CodeGen/AMDGPU/amdgcn.bitcast.320bit.ll
+480-480llvm/test/CodeGen/AMDGPU/amdgcn.bitcast.960bit.ll
+448-448llvm/test/CodeGen/AMDGPU/amdgcn.bitcast.896bit.ll
+6,366-6,366207 files not shown
+13,892-13,589213 files

LLVM/project 0cbb7c7 — orc-rt/include/orc-rt/support/sps SPSSymbolLookupSet.h, orc-rt/lib/bedrock/sps NativeDylibManagerSPSCI.cpp

[orc-rt] Add SPSSymbolLookupResult typedef, clean up users. (#230877)

Existing serializers of SymbolLookupResult were spelling out the SPS
type in full (SPSSequence<SPSOptional<SPSExecutorAddr>>). Define an
SPSSymbolLookupResult typedef and use in instead so that serialization
points can pick up any future changes automatically.

This is the result-side counterpart to 8ff4f386cfeb, which added a
typedef for SymbolLookupSet.
DeltaFile
+2-3orc-rt/test/unit/support/sps/SPSSymbolLookupSetTest.cpp
+2-3orc-rt/lib/bedrock/sps/NativeDylibManagerSPSCI.cpp
+2-0orc-rt/include/orc-rt/support/sps/SPSSymbolLookupSet.h
+6-63 files

FreeBSD/ports d0dcfed — x11 Makefile, x11/bhotkeys-screenshot pkg-descr distinfo

x11/bhotkeys-screenshot: New port

Screenshot hotkeys for bhotkeys.

Reviewed by:    fuz, jrm
Differential Revision:  https://reviews.freebsd.org/D60587
DeltaFile
+23-0x11/bhotkeys-screenshot/Makefile
+9-0x11/bhotkeys-screenshot/pkg-plist
+3-0x11/bhotkeys-screenshot/pkg-descr
+3-0x11/bhotkeys-screenshot/distinfo
+1-0x11/Makefile
+39-05 files

FreeBSD/ports 399e849 — mail/mutt Makefile distinfo

mail/mutt: Update 2.4.2 => 2.4.3

Changelog:
https://gitlab.com/muttmua/mutt/-/blob/mutt-2-4-3-rel/ChangeLog

Release Notes:
https://marc.info/?l=mutt-users&m=179154210212456&w=2

PR:             299267
Security:       CVE-2026-107570
Sponsored by:   UNIS Labs (vvd, commit patch)
MFH:            2026Q4

(cherry picked from commit 9df2e29aa86546b84fab62487e75b930633bc68d)
DeltaFile
+3-3mail/mutt/distinfo
+2-2mail/mutt/Makefile
+5-52 files

FreeBSD/ports 39cc573 — graphics/urho3d Makefile

graphics/urho3d: Deprecate

The build system needs updating to support recent versions of CMake, but
upstream project has been archived a few years ago.

PR:             299256
Reported by:    arrowd
DeltaFile
+2-0graphics/urho3d/Makefile
+2-01 files

LLVM/project 611eee0 — llvm/lib/Transforms/Vectorize SLPVectorizer.cpp, llvm/lib/Transforms/Vectorize/SLPVectorizer SLPUtils.cpp SLPMemoryUtils.h

[SLP]Vectorize consecutive loads with undef lanes as a wide load

Model the lane with the absorbing constant (0 for mul/and, -1 for or) of
a copyable node as op(V, undef), so the operand column of the other
lanes gets an undef lane. Cover such undef lanes in a column of
consecutive loads with a single frozen vector load, if the whole range
is dereferenceable.

Fixes #46897

Assisted-by: Cursor

Reviewers: RKSimon

Pull Request: https://github.com/llvm/llvm-project/pull/228872
DeltaFile
+124-16llvm/lib/Transforms/Vectorize/SLPVectorizer.cpp
+50-86llvm/test/Transforms/SLPVectorizer/X86/absorbing-copyable-lane.ll
+40-63llvm/test/Transforms/SLPVectorizer/X86/wide-load-absorbed-lane.ll
+54-0llvm/lib/Transforms/Vectorize/SLPVectorizer/SLPMemoryUtils.cpp
+16-0llvm/lib/Transforms/Vectorize/SLPVectorizer/SLPMemoryUtils.h
+15-0llvm/lib/Transforms/Vectorize/SLPVectorizer/SLPUtils.cpp
+299-1652 files not shown
+310-1708 files

FreeBSD/ports 9df2e29 — mail/mutt Makefile distinfo

mail/mutt: Update 2.4.2 => 2.4.3

Changelog:
https://gitlab.com/muttmua/mutt/-/blob/mutt-2-4-3-rel/ChangeLog

PR:             299267
Security:       CVE-2026-107570
Sponsored by:   UNIS Labs (vvd, commit patch)
MFH:            2026Q4
DeltaFile
+3-3mail/mutt/distinfo
+2-2mail/mutt/Makefile
+5-52 files

LLVM/project 9048ff1 — llvm/lib/CodeGen/SelectionDAG TargetLowering.cpp

fix(SelectionDAG): validate identity fold demands

KnownBits returned for the LHS may only be valid for the demand
already reduced by the RHS. Check the full result demand before
folding AND/OR to the LHS.

Share the masked-bit check between both operations. Drop Disjoint
when the query rewrites an OR operand.
DeltaFile
+59-33llvm/lib/CodeGen/SelectionDAG/TargetLowering.cpp
+59-331 files

LLVM/project 8ff4f38 — orc-rt/include/orc-rt/support/sps SPSSymbolLookupSet.h, orc-rt/lib/bedrock/sps NativeDylibManagerSPSCI.cpp

[orc-rt] Add SPSSymbolLookupSet typedef, clean up users. (#230876)

Existing deserializers of SymbolLookupSet were spelling out the SPS type
in full (SPSSequence<SPSTuple<SPSString, bool>>). Define an
SPSSymbolLookupSet typedef and use in instead so that deserialization
points can pick up any future changes automatically.
DeltaFile
+3-3orc-rt/lib/bedrock/sps/NativeDylibManagerSPSCI.cpp
+2-3orc-rt/test/unit/support/sps/SPSSymbolLookupSetTest.cpp
+1-2orc-rt/test/unit/bedrock/sps/NativeDylibManagerSPSCITest.cpp
+2-0orc-rt/include/orc-rt/support/sps/SPSSymbolLookupSet.h
+8-84 files

NetBSD/pkgsrc kekxGz2 — mail/mutt Makefile distinfo

   Pullup ticket #7271 - requested by tron
   mail/mutt: Security fix

   Revisions pulled up:
   - mail/mutt/Makefile                                            1.302
   - mail/mutt/distinfo                                            1.130

   ---
      Module Name:      pkgsrc
      Committed By:     tron
      Date:             Fri Oct  9 17:37:08 UTC 2026

      Modified Files:
        pkgsrc/mail/mutt: Makefile distinfo

      Log Message:
      mail/mutt: Update to version 2.4.3

      This release fixes two bugs.  One of them is for CVE-2026-107570, fixing an

    [12 lines not shown]
VersionDeltaFile
1.129.2.1+4-4mail/mutt/distinfo
1.301.2.1+2-2mail/mutt/Makefile
+6-62 files

FreeBSD/src 7fdc748 — sys/amd64/conf MINIMAL GENERIC, sys/powerpc/conf QORIQ64 MPC85XX

amd64, powerpc: Enable tpm(4) in supported kernels

tpm(4) was removed from amd64 GENERIC because it broke suspend and
resume.  The preceding lifecycle, state-save, interrupt, locality, and
teardown fixes address those failures for both TPM 1.2 and TPM 2.0.

Restore the driver to amd64 GENERIC and MINIMAL, where TPM entropy
harvesting remained enabled.  Enable the driver and entropy harvesting
in the MPC85XX and QORIQ64 configurations, which already provide FDT,
spibus, and the platform SPI controller required by FDT-attached TPMs.
Leave the generic AIM and POWER configurations unchanged because they
have no TPM attachment bus.

The TPM 1.2 path completed repeated S3 cycles and command tests on
ThinkPad T430 and T440p systems.  The TPM 2.0 path completed repeated
device and full-system suspend/resume cycles on a ThinkPad P51.  The
PowerPC configuration matrix was checked to retain tpm(4) only where its
FDT SPI attachment path is present.


    [9 lines not shown]
DeltaFile
+1-1sys/amd64/conf/MINIMAL
+1-1sys/amd64/conf/GENERIC
+2-0sys/powerpc/conf/QORIQ64
+2-0sys/powerpc/conf/MPC85XX
+6-24 files

FreeBSD/src 5329e07 — usr.sbin/bhyve tpm_intf_crb.c

bhyve: tpm: allow the last dword of the CRB command buffer

The bounds check rejected any access ending exactly at the end of the
register block, so a four byte write at offset 0xffc was refused,
returning EINVAL and killing the VM.

PR:             291063
Fixes:          75909086a45d ("bhyve: allow read/write to full CRB buffer")
Sponsored by:   Defenso

Signed-off-by: Quentin Thébault <quentin.thebault at defenso.fr>
Reviewed-by: aokblast, kevans, markj
Pull-Request: https://github.com/freebsd/freebsd-src/pull/2362
(cherry picked from commit 4505445ccdb9555efc23262a971a18ca03486969)
DeltaFile
+1-1usr.sbin/bhyve/tpm_intf_crb.c
+1-11 files

FreeBSD/src 99229e5 — usr.sbin/bhyve tpm_intf_crb.c

bhyve: allow read/write to full CRB buffer

For some reason, we've incorrectly calculated the size of the CRB data buffer
register. There's no need to divide the CRB data buffer size by 4. We should
allow access to the whole buffer instead.

Reviewed by:            markj
Sponsored by:           Beckhoff Automation GmbH & Co. KG
Pull Request:           https://github.com/freebsd/freebsd-src/pull/2169

(cherry picked from commit 75909086a45da3c5aeaff8152728111cf798c6bc)
DeltaFile
+1-1usr.sbin/bhyve/tpm_intf_crb.c
+1-11 files

FreeBSD/src bf62832 — sys/dev/tpm tpm_crb.c

tpm: crb: check the error bit only after taking locality

tpmcrb_transmit() read CRB_CTRL_STS before requesting locality 0.
An AMD Pluton fTPM (like FrameWork Desktop) using the plain CRB start method
reads the control area as all-ones until locality is assigned, so bit 0 looks
like a stuck tpmSts and every command failed with EIO.

With RANDOM_ENABLE_TPM the harvester retries every 10 seconds, so this printed
"Device has Error bit set" forever.

Reviewed by:    kbowling
Approved by:    kbowling
Sponsored by:   Netflix
Differential Revision:  https://reviews.freebsd.org/D59661

(cherry picked from commit 7c375af72ef3f631e89431ae32a855d806e6ec98)
DeltaFile
+13-5sys/dev/tpm/tpm_crb.c
+13-51 files

FreeBSD/src a81e324 — sys/dev/tpm tpm_crb.c

tpm: crb: make the Pluton startmethod more resilient

The original implementation assumed that the start/reply doorbells
lived within the device _CRS space, but that isn't always the case.  On
my AMD Ryzen 7640U-based frame.work laptop, device memory runs from
0xc0500000-0xc0500fff while the doorbells are up around 0xc0508000.

Stop sanity checking the addresses and just map them in to work reliably
whether they're within the device range or not.

pluton_wait_reply is cribbed from tpm_wait_for_u32, but rewritten
slightly to read in just one place and to read one last time before
giving up at the end of the timeout, just in case.

Reviewed by:    kbowling
Differential Revision:  https://reviews.freebsd.org/D59327

(cherry picked from commit 6af3031c951614f2a42dfd67ce2c3a48ee8314ae)
DeltaFile
+88-29sys/dev/tpm/tpm_crb.c
+88-291 files

FreeBSD/src 6327629 — sys/dev/tpm tpm.c

tpm: Do not use timed tsleep() while polling during cold boot

Commit 4e0f283fb97a made tpm_tis12_init() wait for TPM_STS_CMD_READY
after aborting any command.  The wait is implemented by the driver's
existing tpm_waitfor_poll() loop, which sleeps with a one-tick tsleep()
between status reads.  Until now, that loop only ran from the resume and
command paths after boot.  From tpm_attach() it can panic with "timed
sleep before timers are working" when the TPM is attached from ACPI
during cold boot and the chip does not report ready on the first status
read.

Before 4e0f283fb97a, tpm_tis12_init() wrote TPM_STS_CMD_READY and
returned without waiting, so the polling loops only ran after boot.
tpm_request_locality() had the same latent hazard but its fast path
returns before sleeping whenever locality is already active.

Nothing calls wakeup() on the channels used by these polling loops, so
the sleeps are pure delays.  Use pause_sig(), which falls back to
DELAY() while the kernel is cold and returns EWOULDBLOCK, a value these

    [11 lines not shown]
DeltaFile
+3-3sys/dev/tpm/tpm.c
+3-31 files

LLVM/project 8847f81 — clang/docs LanguageExtensions.md, clang/include/clang/Basic DiagnosticSemaKinds.td

Address review feedback on FP8 conversion builtins

Reuse err_builtin_invalid_arg_type for all source operand errors
instead of builtin-specific diagnostics.

Accept integer constants that fit the format width, such as 0x38,
and std::byte, so common byte values need no explicit cast.

Drop the unused OpenCL fp64 path from checkFloatingPointTypeSupport.

Document floating-point environment and fast-math behavior; trim
implementation detail from the user docs.

Change-Id: I8676a49540bdbbb8a90827c83764803eeea850a5
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply at anthropic.com>
DeltaFile
+44-22clang/lib/Sema/SemaChecking.cpp
+30-9clang/test/Sema/builtins-elementwise-convert-from-arbitrary-fp.c
+10-17clang/lib/Sema/SemaType.cpp
+24-1clang/test/SemaCXX/builtins-elementwise-convert-from-arbitrary-fp.cpp
+8-7clang/docs/LanguageExtensions.md
+1-11clang/include/clang/Basic/DiagnosticSemaKinds.td
+117-674 files not shown
+131-7110 files

LLVM/project 476eb9d — clang/docs LanguageExtensions.md, clang/lib/Sema SemaType.cpp SemaChecking.cpp

[clang] Add elementwise conversions from encoded FP8 values

Add nine builtins converting Float8E5M2, Float8E4M3FN, and Float8E5M3FNU
encodings to _Float16, __bf16, or float through
llvm.convert.from.arbitrary.fp.

Accept exactly 8-bit integer scalars and generic fixed-length vectors,
preserving vector kinds and element counts without integer promotions.
Also support scalar AArch64 __mfp8 containers. Apply destination type
availability checks, including deferred offload diagnostics, and reject
constant-expression use.

Document the interface and add semantic, template, language-mode,
target-specific, and IR-generation regression coverage.
DeltaFile
+172-0clang/test/CodeGen/builtins-elementwise-convert-from-arbitrary-fp.c
+135-0clang/test/Sema/builtins-elementwise-convert-from-arbitrary-fp.c
+105-0clang/lib/Sema/SemaChecking.cpp
+97-0clang/docs/LanguageExtensions.md
+50-18clang/lib/Sema/SemaType.cpp
+44-0clang/test/Sema/builtins-elementwise-convert-from-arbitrary-fp-target.c
+603-1810 files not shown
+804-1816 files

FreeBSD/ports 68b9620 — ftp/curl-impersonate Makefile distinfo, ftp/curl-impersonate/files patch-patches_curl.patch patch-patches_boringssl.patch

ftp/curl-impersonate: update 2.2.2 → 2.2.3

(cherry picked from commit 85b28d8b53211d8c763c03264c8586ea01fcfc53)
DeltaFile
+17-8ftp/curl-impersonate/files/patch-CMakeLists.txt
+7-5ftp/curl-impersonate/distinfo
+7-3ftp/curl-impersonate/Makefile
+2-2ftp/curl-impersonate/files/patch-patches_curl.patch
+2-2ftp/curl-impersonate/files/patch-patches_boringssl.patch
+35-205 files

FreeBSD/ports 6d44cc3 — ftp/curl-impersonate Makefile pkg-plist

ftp/curl-impersonate: move headers to include/curl-impersonate; remove MAKE_JOBS_UNSAFE

(cherry picked from commit 45b6c5e4cdb610c02f1525408a6bb0f0568366e3)
DeltaFile
+12-12ftp/curl-impersonate/pkg-plist
+3-2ftp/curl-impersonate/Makefile
+15-142 files

LLVM/project 9703767 — llvm/lib/Target/AMDGPU SIInstrInfo.h GCNCreateVOPD.cpp, llvm/test/CodeGen/AMDGPU llvm.amdgcn.fdot2.f32.bf16.ll llvm.amdgcn.fdot2.ll

[AMDGPU] Form VOPD dot2 pairs with a literal in src1

A V_DOT2 with a register in src0 and a literal in src1 is matched as if
commuted, and commuted when the VOPD pair is built. This recovers the
pairs lost once MachineCSE stopped leaving those literals in src0.

Co-Authored-By: Claude <noreply at anthropic.com>
DeltaFile
+149-0llvm/test/CodeGen/AMDGPU/vopd-dot2-commute-imm-src1.mir
+54-19llvm/lib/Target/AMDGPU/GCNVOPDUtils.cpp
+12-35llvm/test/CodeGen/AMDGPU/llvm.amdgcn.fdot2.ll
+3-6llvm/test/CodeGen/AMDGPU/llvm.amdgcn.fdot2.f32.bf16.ll
+9-0llvm/lib/Target/AMDGPU/GCNCreateVOPD.cpp
+2-2llvm/lib/Target/AMDGPU/SIInstrInfo.h
+229-621 files not shown
+232-627 files

LLVM/project c048ebc — llvm/lib/Target/AMDGPU GCNVOPDUtils.cpp, llvm/test/CodeGen/AMDGPU vopd-dot2-commute-imm-src1.mir

[AMDGPU] Address review comments

Co-Authored-By: Claude <noreply at anthropic.com>
DeltaFile
+9-5llvm/lib/Target/AMDGPU/GCNVOPDUtils.cpp
+1-1llvm/test/CodeGen/AMDGPU/vopd-dot2-commute-imm-src1.mir
+10-62 files

LLVM/project 72e3ec8 — llvm/test/CodeGen/AMDGPU clmul.ll

[AMDGPU] Update clmul.ll for literal commute

Co-Authored-By: Claude <noreply at anthropic.com>
DeltaFile
+4-4llvm/test/CodeGen/AMDGPU/clmul.ll
+4-41 files

FreeBSD/src 74f8911 — sys/dev/tpm tpm_tis_core.c

tpm_tis: Quiesce interrupts before registering a handler

The current interrupt path uses the IRQ resource value directly as the
LPC SIRQ selector in TPM_INT_VECTOR and already restricts it to 1 through
15. This is a driver limitation: a parent interrupt number need not equal
an LPC SIRQ channel, and SPI TPMs can use a separate parallel interrupt.

On the reported system with ACPI IRQ 45, the existing range check runs
after handler registration and returns before disabling firmware interrupt
delivery. This can leave a polling device with a handler on an asserted
source.

Disable and verify interrupt delivery before registering a handler or
starting common TPM services. Preserve the existing range policy, using
polling without registering a handler for routes rejected by that check,
and release their IRQ resources. Keep a failed setup's potentially stale
output cookie out of the device state; the interrupt framework may
already have removed that handler.


    [20 lines not shown]
DeltaFile
+90-23sys/dev/tpm/tpm_tis_core.c
+90-231 files

FreeBSD/src 606ce72 — sys/dev/tpm tpm20.h tpm20.c

tpm20: Move user copies outside the lifecycle lock

The TPM 2.0 character-device methods held the global device lock
while uiomove() accessed user memory.  User page faults could therefore
delay suspend or detach even though the read response was already
buffered.

Add a per-open sleepable lock to serialize operations on each response
buffer.  Stage commands under that lock before acquiring the device
lock, and copy them into the response buffer only after the lifecycle
checks succeed.  This preserves an unread response when suspend or
detach rejects a write.  Release the device lock before copying buffered
responses out.  Also advance the response offset by the bytes actually
copied when uiomove() returns after a partial transfer.

Validated on an Intel TPM 2.0 TIS device.  PCR reads and GetRandom
passed under 16-process mixed command load.  A response was consumed
correctly in 5-byte, 7-byte, and remainder reads.  Module unload/reload
recreated the device and entropy source without lock diagnostics.

    [7 lines not shown]
DeltaFile
+29-8sys/dev/tpm/tpm20.c
+1-0sys/dev/tpm/tpm20.h
+30-82 files

FreeBSD/src ef68bf6 — sys/dev/tpm tpm20.h

tpm20: Correct 32-bit register helpers

OR4() reads only the low byte before writing the complete 32-bit
register.  Preserve all register bits by using a matching 32-bit read.

Make BIT() produce an unsigned value so masks containing bit 31 do not
rely on a signed left shift into the sign bit.  OpenBSD carries the
same change.

Reviewed by:    kevans
Sponsored by:   BBOX.io
Differential Revision:  https://reviews.freebsd.org/D59244

(cherry picked from commit f613a43c366600e8c388c3200f74c6dd27f8a7a2)
DeltaFile
+2-2sys/dev/tpm/tpm20.h
+2-21 files

FreeBSD/src 3904c7a — sys/dev/tpm tpm_crb.c tpm_tis_core.c

tpm20: Release transport state after command failures

Once a transport acquires locality, several TIS and CRB error paths
return without relinquishing it.  They can also leave a partial FIFO
transaction or an active CRB command for the next operation to inherit.

Route post-locality exits through common cleanup.  Reset the TIS command
state on every attempt.  For CRB, cancel an active failed command when
necessary, request the idle state, and relinquish locality even when the
state transition itself fails.

Successful command handling is unchanged apart from sharing the same
cleanup path.

Reviewed by:    kevans
Sponsored by:   BBOX.io
Differential Revision:  https://reviews.freebsd.org/D59243

(cherry picked from commit 2fe8510b0a06ad577789ece7be8c9319c8ce3d06)
DeltaFile
+41-24sys/dev/tpm/tpm_tis_core.c
+37-20sys/dev/tpm/tpm_crb.c
+78-442 files

FreeBSD/src bd54c7b — sys/dev/tpm tpm_tis_core.c

tpm_tis: release TPM resources after reading response

Per TIS 1.3 section 5.6.12, write commandReady to TPM_STS after reading the
response so the TPM can free its ReadFIFO and other internal resources.
The subsequent tpmtis_go_ready() provides the second write the spec describes
and waits for the state transition.

PR:             295103
Reported by:    Benoit Sansoni <benoit.sansoni at gmail.com>
Reviewed by:    kevans
Approved by:    kevans
Differential Revision:  https://reviews.freebsd.org/D57841

(cherry picked from commit e4c50d86796d07cf90e6a683234e1c0e9ca5e03c)
DeltaFile
+10-0sys/dev/tpm/tpm_tis_core.c
+10-01 files