FreeBSD/src 304088e — sys/powerpc/aim mmu_radix.c

powerpc/radix: fix double page offset in mmu_radix_sync_icache()

mmu_radix_sync_icache() adds the offset of va within its page to the
physical address it gets from mmu_radix_extract_locked().  That address
already includes the offset - the extract routines return the physical
address of the byte, not of the frame - so the offset is counted twice
and __syncicache() is handed frame + 2 * offset.

The hash MMU counterpart, moea64_sync_icache(), has to add the offset
because PVO_PADDR() yields only the frame.  Here the addition is wrong.

Fixes:  6f0b2a235a13 ("powerpc/pmap: Add pmap_sync_icache() for radix pmap")
Reviewed by:    jhibbits
MFC after:      1 week
Differential Revision:  https://reviews.freebsd.org/D59870

(cherry picked from commit 9d0859637f99160e17b656df153effae3df31f8b)
(cherry picked from commit 107212618921492ffed84d6ea3c9a27c77aaf725)
DeltaFile
+2-4sys/powerpc/aim/mmu_radix.c
+2-41 files

FreeBSD/src 6db5b4f — sys/powerpc/powerpc elf64_machdep.c

sys/powerpc/powerpc/elf64_machdep.c: enable ASLR on ELFv2

Turns out that ever since introducing ELFv2 support, it was missing
ASLR, it was only used for ELFv1 processes.

Reviewed by:    jhibbits (via IRC #powerpc64)
MFC after:      1 week

(cherry picked from commit 30ed27ff2556c591a1791105d1dfe7464d3f5b80)
(cherry picked from commit edb560a7ccd69440e3bcd3e00ad9b347328f1be3)
DeltaFile
+1-1sys/powerpc/powerpc/elf64_machdep.c
+1-11 files

FreeBSD/src 1072126 — sys/powerpc/aim mmu_radix.c

powerpc/radix: fix double page offset in mmu_radix_sync_icache()

mmu_radix_sync_icache() adds the offset of va within its page to the
physical address it gets from mmu_radix_extract_locked().  That address
already includes the offset - the extract routines return the physical
address of the byte, not of the frame - so the offset is counted twice
and __syncicache() is handed frame + 2 * offset.

The hash MMU counterpart, moea64_sync_icache(), has to add the offset
because PVO_PADDR() yields only the frame.  Here the addition is wrong.

Fixes:  6f0b2a235a13 ("powerpc/pmap: Add pmap_sync_icache() for radix pmap")
Reviewed by:    jhibbits
MFC after:      1 week
Differential Revision:  https://reviews.freebsd.org/D59870

(cherry picked from commit 9d0859637f99160e17b656df153effae3df31f8b)
DeltaFile
+2-4sys/powerpc/aim/mmu_radix.c
+2-41 files

FreeBSD/src edb560a — sys/powerpc/powerpc elf64_machdep.c

sys/powerpc/powerpc/elf64_machdep.c: enable ASLR on ELFv2

Turns out that ever since introducing ELFv2 support, it was missing
ASLR, it was only used for ELFv1 processes.

Reviewed by:    jhibbits (via IRC #powerpc64)
MFC after:      1 week

(cherry picked from commit 30ed27ff2556c591a1791105d1dfe7464d3f5b80)
DeltaFile
+1-1sys/powerpc/powerpc/elf64_machdep.c
+1-11 files

LLVM/project 87e5a59 — llvm/lib/CodeGen TwoAddressInstructionPass.cpp

TwoAddressInstructions: Use a range loop to move the copy chain (#227296)

Cleanup some messy iterator work.

Co-authored-by: Claude Opus 5 <noreply at anthropic.com>
DeltaFile
+7-6llvm/lib/CodeGen/TwoAddressInstructionPass.cpp
+7-61 files

LLVM/project 73a0b12 — llvm/lib/CodeGen CodeGenPrepare.cpp, llvm/test/Transforms/CodeGenPrepare/X86 store-extract-division-ub.ll

[CodeGenPrepare] don't promote sdiv/srem by -1 (#218737)

`store-extract` promotion was widening sdiv/srem to the vector type
without checking if thats safe or not... and INT_MIN lane / -1 is UB.
skip sdiv/srem by -1 in `shouldPromote`, rest still promotes fine.

Fixes #218570
DeltaFile
+114-0llvm/test/Transforms/CodeGenPrepare/X86/store-extract-division-ub.ll
+2-5llvm/lib/CodeGen/CodeGenPrepare.cpp
+116-52 files

LLVM/project d80ae72 — clang/test/CIR/CodeGen builtin-memcpy.c, clang/test/CIR/CodeGenCUDA uniform-work-group-size.cu

[CIR][NFC][AMDGPU] Use new triple in CIR tests (#226972)
DeltaFile
+9-9clang/test/CIR/CodeGenCUDA/uniform-work-group-size.cu
+6-6clang/test/CIR/CodeGenHIP/builtins-amdgcn-wave64.hip
+6-6clang/test/CIR/CodeGenHIP/builtins-amdgcn-wave32.hip
+3-3clang/test/CIR/CodeGenHIP/builtin-bool-result.hip
+3-3clang/test/CIR/CodeGen/builtin-memcpy.c
+2-2clang/test/CIR/CodeGenHIP/cleanup-alloca-addrspace.hip
+29-292 files not shown
+32-328 files

LLVM/project ed32737 — clang/lib/AST/ByteCode Interp.cpp EvalEmitter.cpp

[clang][bytecode] Move past-end check into CheckFinalLoad (#227181)

It makes more sense there. Also remove the one of for non-const
pointers, since that one isn't needed anymore
DeltaFile
+0-9clang/lib/AST/ByteCode/EvalEmitter.cpp
+3-0clang/lib/AST/ByteCode/Interp.cpp
+3-92 files

FreeBSD/ports 4b6ac23 — lang/babashka Makefile distinfo

lang/babashka: Update to 1.13.225

Changes since 1.13.224:

1.13.225 (2026-09-28)

  * #2170: Read the docstring and :org.babashka/cli metadata of a var
    as :exec-fn or :fn in a task :cmd tree
  * #2170: A :doc in a task handler's :org.babashka/cli metadata takes
    precedence over its docstring
  * Run BABASHKA_PRELOADS before resolving bb.edn dependencies
  * Add org.jline.terminal.Terminal$Signal and allow reify of
    org.jline.terminal.Terminal$SignalHandler
  * Add org.jsoup.nodes.Document$OutputSettings
  * Bump jline to 4.4.6
  * Bump rewrite-clj to 1.3.58
DeltaFile
+5-5lang/babashka/distinfo
+1-1lang/babashka/Makefile
+6-62 files

LLVM/project 4076fac — llvm/docs GettingInvolved.md

docs: Remove Johannes' office hours (#227350)
DeltaFile
+0-6llvm/docs/GettingInvolved.md
+0-61 files

LLVM/project 8a4f055 — llvm/lib/Analysis LoopAccessAnalysis.cpp, llvm/test/Analysis/LoopAccessAnalysis retry-runtime-checks-after-dependence-analysis.ll

[LAA] Honor no-wrap predicates already in PSE in isNoWrap (#226430)

getPtrStride checks pointer wrapping assuming PSE's predicate holds.
Before #203787, isNoWrap used `PSE.hasNoOverflow` to see NUSW flags
recorded by `setNoOverflow`. Removing that bookkeeping made queries that
cannot add predicates accept only static no-wrap facts, ignoring NUSW
predicates LAA already added for the pointer.

LoopLoadElimination's `isDependenceDistanceOfOne` makes these queries
for each forwarding candidate's load and store. A pointer needing a wrap
predicate (e.g. a non-inbounds GEP where null is valid) is rejected with
"Pointer may wrap", although dependence analysis already added the
predicate and LLE versions the loop on all PSE predicates. Recurrences
such as `A[i] -= B[i-1] * A[i-1]` then reload `A[i-1]` each iteration
instead of reusing the stored value.

When isNoWrap cannot add predicates, check whether PSE's predicate
implies the AddRec's NUSW wrap predicate. Callers allowed to add
predicates are unchanged: they collect it, and adding an implied

    [16 lines not shown]
DeltaFile
+166-0llvm/test/Transforms/LoopLoadElim/wrap-predicate-from-dependence-analysis.ll
+25-25llvm/test/Analysis/LoopAccessAnalysis/retry-runtime-checks-after-dependence-analysis.ll
+8-5llvm/lib/Analysis/LoopAccessAnalysis.cpp
+199-303 files

LLVM/project 951a8cb — llvm/lib/Target/X86 X86LFIRewritePass.cpp, llvm/test/CodeGen/X86 lfi-align-sjlj.ll

Drop the redundant SJLJ landing pad alignment
DeltaFile
+3-23llvm/lib/Target/X86/X86LFIRewritePass.cpp
+2-2llvm/test/CodeGen/X86/lfi-align-sjlj.ll
+5-252 files

LLVM/project 3c86a03 — llvm/lib/Target/X86 X86LFIRewritePass.cpp, llvm/test/CodeGen/X86 lfi-align-sjlj.ll

X86: Respect the exception model module flag in X86LFIRewritePass

This is preparation for removing the TargetOptions ExceptionModel field.
Currently this doesn't show an observable behavior change because the
codegen pass pipeline is driven by this field. Add the module flag based
check so in the future, if the pass runs on a module not using sjlj, it
will skip the sjlj specific handling.

Co-Authored-By: Claude Opus 5 <noreply at anthropic.com>
DeltaFile
+66-0llvm/test/CodeGen/X86/lfi-align-sjlj.ll
+23-14llvm/lib/Target/X86/X86LFIRewritePass.cpp
+89-142 files

LLVM/project a5a1b58 — llvm/lib/Target/Hexagon HexagonInstrInfo.h HexagonInstrInfo.cpp, llvm/test/CodeGen/Hexagon hwloop-postinc-iv-ptrchase.ll hwloop-postinc-iv-tied-operands-hvx.ll

[Hexagon] Fix hwloop trip count for post-increment load induction (#225411)

A pointer-chasing loop whose exit test is a null check was miscompiled
into a hardware loop with a bogus trip count.

A post-increment load defines two registers:
%3, %11 = L2_loadri_pi %1(tied-def 1), 4
%11 is the incremented address (tied to the base), but %3 is the value
loaded from memory, which bears no relation to the base. The helper only
checked that the base register is defined by the PHI, never that the
register feeding the PHI back from the latch is the incremented address.
Here the PHI is fed by %3 -- so the loop was treated as bumping its
induction variable by a constant 4 per iteration, and getLoopTripCount
derived a count from the numeric value of head.

Require that the register feeding the PHI is the post-incremented
address, located through the base operand's tie rather than a fixed
operand index: the tied def is operand 1 for loads (L2_loadri_pi,
V6_vL32b_pi) but operand 0 for stores (S2_storeri_pi, V6_vS32b_pi), and

    [4 lines not shown]
DeltaFile
+63-0llvm/test/CodeGen/Hexagon/hwloop-postinc-iv-tied-operands.ll
+55-0llvm/test/CodeGen/Hexagon/hwloop-postinc-iv-tied-operands-hvx.ll
+47-0llvm/lib/Target/Hexagon/HexagonHardwareLoops.cpp
+41-0llvm/test/CodeGen/Hexagon/hwloop-postinc-iv-ptrchase.ll
+7-0llvm/lib/Target/Hexagon/HexagonInstrInfo.cpp
+1-0llvm/lib/Target/Hexagon/HexagonInstrInfo.h
+214-06 files

LLVM/project 7c9ae52 — llvm/lib/CodeGen TwoAddressInstructionPass.cpp, llvm/test/CodeGen/X86 twoaddr-mixed-early-clobber-tied-defs.ll twoaddr-mixed-early-clobber-tied-defs.mir

TwoAddressInstructions: Use the per-operand early clobber flag for tied copies (#227581)

The live interval update for the copy inserted for a tied operand ended
the new segment at getRegSlot(IsEarlyClobber), using a flag computed
once per instruction for any tied pairs. Use the flag
of the def actually being processed.

With an inline asm mixing "=&r" and "=r" outputs tied to the same input,
the copy for the plain def ended at the early clobber slot, leaving a
hole before its own def. That splits the live range into multiple
connected components and asserts in updatePressureDiffs.

Co-authored-by: Claude Opus 5 <noreply at anthropic.com>
DeltaFile
+28-0llvm/test/CodeGen/X86/twoaddr-mixed-early-clobber-tied-defs.mir
+24-0llvm/test/CodeGen/X86/twoaddr-mixed-early-clobber-tied-defs.ll
+1-1llvm/lib/CodeGen/TwoAddressInstructionPass.cpp
+53-13 files

LLVM/project 7778bb2 — llvm/include/llvm/ADT DenseMap.h, llvm/include/llvm/IR ValueHandle.h

[IR][ADT] Update ValueHandle PrevPtr via move constructor (NFC) (#227484)

In LLVMContextImpl::ValueHandles, the first ValueHandleBase node's
PrevPtr points directly to the head pointer inside the DenseMap
bucket, so relocating a bucket invalidates that PrevPtr.

This patch wraps the head pointer in ValueHandleHead, whose move
constructor updates Head->setPrevPtr(&Head) whenever a bucket is
relocated by grow() or erase().  Specifically, this allows us to:

- Simplify ValueHandleBase::AddToUseList by removing the manual
  reallocation check and linear fixup loop after insertion.

- Use the standard one-argument Handles.erase(getValPtr()) in
  ValueHandleBase::RemoveFromUseList instead of the private callback
  erase, addressing the TODO there.

- Remove friend class ValueHandleBase, the two-argument callback
  erase(Key, OnMoved), and the OnMoved callback parameter on

    [2 lines not shown]
DeltaFile
+15-43llvm/lib/IR/Value.cpp
+2-30llvm/include/llvm/ADT/DenseMap.h
+14-1llvm/lib/IR/LLVMContextImpl.h
+1-0llvm/include/llvm/IR/ValueHandle.h
+32-744 files

OPNSense/src 1962d2c — sys/netpfil/pf pf.c

pf: Prevent pf dropping TCP state with crafted reset packet.

Revision 1.1212 of pf.c weakened the TCP reset check in stateful
connection tracking to let legitimate resets pass in the backwards
window.  Such a reset is accepted only if its acknowledgment number
matches perfectly.  But as a workaround for broken stacks, pf
replaces an acknowledgment number of 0 in a reset with the tracked
sequence of the peer.  Then the perfect match always succeeds, and
an attacker can spoof resets more easily than intended.  Use the
acknowledgment number from the wire, before the workaround has
modified it.

discovered by Minghao Zhang; OK sashan@

Obtained from:  OpenBSD, bluhm <bluhm at openbsd.org>, 1e0a1f4b82
Sponsored by:   Rubicon Communications, LLC ("Netgate")
DeltaFile
+3-2sys/netpfil/pf/pf.c
+3-21 files

OPNSense/src b337ac3 — sys/netpfil/pf pf.c

pf: allows TCP RST packets in the backwards window if ACK matches

TCP reset packets are generated for the sequence numbers that have
been acknowledged.  Our pf(4) is quite strict regarding sequence
numbers of reset packets to avoid evil connection drops.  It expected
exact match and did not allow a sequence window for resets.  As pf
tracks neither gaps in the sequence space nor the acknowledged data,
it does not know where exactly the reset is expected by the TCP
stack.

Problem was that legit reset packets before a gap but not at the
highest sequence numbers were blocked by pf.  Solution is to fix
pf_tcp_track_full().  Now it allows sequence number windows if the
packet has ACK+RST flags set and the acknowlege number matches
perfectly.  This still prevents reset number guessing by an attacker.

Curiously the TCP stack behaves correctly and accepts only resets
before the gap.  pf only allowed resets after the final data.  So
any reset was ignored by the system.  When the other side processed

    [7 lines not shown]
DeltaFile
+5-1sys/netpfil/pf/pf.c
+5-11 files

LLVM/project cf28b9f — llvm/lib/Transforms/Scalar LoopIdiomRecognize.cpp, llvm/test/Transforms/LoopIdiom strlen.ll

[LoopIdiom] Fix 64-to-32-bit stride truncation in strlen idiom recognition (#227406)

This patch fixes a silent miscompile where loops with massive strides
(e.g., 0x100000001 or 0x2000000000000001) were incorrectly optimized
into strlen calls.

Previously, getZExtValue() was truncated to a 32-bit unsigned integer,
causing some massive strides to appear as a stride of 1. Furthermore,
the OpWidth check relied on multiplication (StepSize * 8), which is
vulnerable to 64-bit integer overflow.

By upgrading StepSize to uint64_t and using division (OpWidth / 8), we
ensure the optimization is safely aborted for massive strides without
risking arithmetic overflow.
DeltaFile
+56-12llvm/test/Transforms/LoopIdiom/strlen.ll
+3-3llvm/lib/Transforms/Scalar/LoopIdiomRecognize.cpp
+59-152 files

FreeBSD/doc 543234d — website/content/en/cgi man.cgi

man.cgi: improve grouping of release permalinks
DeltaFile
+67-7website/content/en/cgi/man.cgi
+67-71 files

LLVM/project e3bae38 — mlir/lib/Dialect/Affine/Transforms SuperVectorize.cpp, mlir/test/Dialect/Affine/SuperVectorize vectorize_reduction.mlir

[mlir][affine] Fix crash when rolling back vectorization of reduction loops (#226912)

Reductions introduce operations outside of the created loop, that are
users of said loop. When rolling back (e.g. when an op inside the loop
being vectorized is not vectorizable), only the created loop is deleted,
which leads to the error: “operation destroyed but still has uses”.

This PR fixes this by recursively deleting users of the newly created
loop before removing it when rolling back.
DeltaFile
+16-3mlir/lib/Dialect/Affine/Transforms/SuperVectorize.cpp
+19-0mlir/test/Dialect/Affine/SuperVectorize/vectorize_reduction.mlir
+35-32 files

NetBSD/pkgsrc Lr24mio — doc CHANGES-2026

   Updated security/py-gnupg, devel/py-setuptools-gettext
VersionDeltaFile
1.6516+5-1doc/CHANGES-2026
+5-11 files

NetBSD/pkgsrc bH5crbg — devel/py-setuptools-gettext Makefile PLIST

   py-setuptools-gettext: updated to 0.1.19

   0.1.19

   Add support for package-based installation
   Require setuptools>=69.0 for setuptools.modified
   Use bool for install_mo.force to match Command base type
   Various dev-dependency bumps (ruff, mypy)
VersionDeltaFile
1.4+4-4devel/py-setuptools-gettext/distinfo
1.3+4-1devel/py-setuptools-gettext/PLIST
1.4+2-2devel/py-setuptools-gettext/Makefile
+10-73 files

NetBSD/pkgsrc 6XgEFQH — security/py-gnupg Makefile distinfo

   py-gnupg: updated to 0.5.7

   0.5.7
   This is an enhancement and bug-fix release, and all users are encouraged to upgrade.
VersionDeltaFile
1.16+4-4security/py-gnupg/distinfo
1.46+2-5security/py-gnupg/Makefile
+6-92 files

NetBSD/pkgsrc MKyw2U8 — devel/py-wrapt Makefile PLIST

   py-wrapt: updated to 2.5.0

   2.5.0

   New Features

   Added with_doc, a decorator for overriding the docstring that help(), pydoc and other introspection tools see for a wrapped callable without mutating the wrapped function itself. It is the companion of with_signature. The docstring can be supplied directly, or as a factory callable that derives it from the wrapped function at decoration time. When stacked above with_signature the factory sees the overridden signature and can embed it in the docstring. Assigning to __doc__ on the resulting wrapper replaces the override, and deleting it restores delegation to the wrapped function. Previously the only option was to assign to __doc__ on a wrapper, which writes through to the wrapped function since __doc__ on every proxy delegates to the wrapped object, and so changed what was reported for the wrapped function everywhere. The override is handled for instance methods, class methods and static methods, and propagates through outer wrapt decorators stacked on top. See the “Docstring Override” section of Bundled Decorators for details.
   with_signature now accepts a doc argument for overriding the docstring at the same time as the signature, and the factory callable may return a tuple of (signature_or_prototype, docstring) so that a single factory can derive both from the wrapped function in one pass. When doc is supplied, the docstring from the tuple is ignored. When neither is given, __doc__ continues to delegate to the wrapped function as before, including for assignment and deletion.
   A class derived from wrapt.BaseObjectProxy may now define __doc__ as a property, or other descriptor, in its class body, and that is used for instances of the class in place of the default delegation of __doc__ to the wrapped object. This works with both the pure Python implementation and the C extension, and the descriptor is inherited by further derived classes. Previously the pure Python metaclass overwrote such a descriptor with the default delegating property, and the C extension forwarded __doc__ to the wrapped object before consulting the type, so it was never used. Only __doc__ is affected, with __module__ always delegating to the wrapped object. This is the mechanism with_doc relies on.
VersionDeltaFile
1.31+4-4devel/py-wrapt/distinfo
1.11+4-1devel/py-wrapt/PLIST
1.37+2-2devel/py-wrapt/Makefile
+10-73 files

NetBSD/pkgsrc-wip 70ad714 — suse15_gdb Makefile distinfo

suse15_gdb: reduce warnings

when looking up the correct debug set to warn about - still doesn't
work because the set information is not available
DeltaFile
+9-0suse15_gdb/distinfo
+3-0suse15_gdb/Makefile
+12-02 files

NetBSD/pkgsrc xnBL5HT — devel/py-blessed Makefile distinfo

   py-blessed: updated to 1.50.0

   1.50
   * change: default timeout of automatic terminal queries from 1 to 5 seconds with environment
     variable ``BLESSED_QUERY_TIMEOUT_SECONDS`` override,
   * bugfix: Do not automatic query `XTGETTCAP`_ for older CONPTY builds (Windows Server 2022), which
     displays control codes as visible text
   * bugfix: :meth:`~Terminal.mouse_enabled` failed to yield ``MOUSE_*`` keystrokes on older CONPTY
     builds (Windows Server 2022), where the console's "QuickEdit mode" blocks transmission,
   * bugfix: an `XTGETTCAP`_ received after query time out was returned by :meth:`~Terminal.inkey` as
     errant keystrokes.  It is no longer yielded by :meth:`~Terminal.inkey`,
   * bugfix: :meth:`~Terminal.does_iterm2_graphics` results are now more accurate, by drawing a
     transparent pixel,
   * improve: performance of :meth:`~Terminal.does_xtgettcap`,
   * improve: skip some automatic queries for Apple's Terminal.app that leak VT100 codes as output
   * change: default timeout of automatic terminal queries from 1 to 5 seconds with environment
     variable ``BLESSED_QUERY_TIMEOUT_SECONDS`` override,
VersionDeltaFile
1.17+4-4devel/py-blessed/distinfo
1.22+2-2devel/py-blessed/Makefile
+6-62 files

NetBSD/pkgsrc SOKvpok — doc CHANGES-2026

   Updated emulators/qemu, sysutils/qemu-guest-agent
VersionDeltaFile
1.6515+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc n4g6PRc — emulators/qemu Makefile distinfo, sysutils/qemu-guest-agent Makefile

   qemu[-guest-agent]: updated to 11.1.2

   11.1.2
   Bug fixes
VersionDeltaFile
1.257+4-4emulators/qemu/distinfo
1.3+4-4emulators/qemu/Makefile.common
1.18+1-2sysutils/qemu-guest-agent/Makefile
1.417+1-2emulators/qemu/Makefile
+10-124 files

NetBSD/pkgsrc-wip efd30e2 — suse15_gdb distinfo Makefile

suse15_gdb: gdb now starts
DeltaFile
+0-42suse15_gdb/TODO
+16-15suse15_gdb/Makefile
+3-0suse15_gdb/distinfo
+19-573 files