OPNSense/plugins 92215cd — dns/rfc2136 Makefile, dns/rfc2136/src/etc/inc/plugins.inc.d rfc2136.inc

dns/rfc2136: subscribe to "updateip" event

interface_configure() was still calling newwanip:rfc2136 but this meant
it had knowledge about this specifc plugin.  By adding this consumer we
can hide the actual plugins using it and perhaps add updateip to all
relevant code paths as well.  newwanip is only called for dynamic addressing.
DeltaFile
+1-1dns/rfc2136/Makefile
+1-0dns/rfc2136/src/etc/inc/plugins.inc.d/rfc2136.inc
+2-12 files

LLVM/project 95d9c12 — llvm/include/llvm/ADT DenseMap.h

[ADT] Share relocateBucket across DenseMap.h (NFC) (#227970)

This patch moves relocateBucket from SmallDenseMapStorage into namespace
densemap::detail and uses it in DenseMapBase::moveFrom and
DenseMapBase::eraseFromFilledBucket as well.

Assisted-by: Antigravity
DeltaFile
+12-22llvm/include/llvm/ADT/DenseMap.h
+12-221 files

FreeNAS/freenas f8e7aa0 — src/middlewared/middlewared/common/license_reconcile __init__.py, src/middlewared/middlewared/plugins/service __init__.py

Tie webshare lifecycle to TrueNAS Connect state

## Problem
Webshare's Caddy only picks up its TLS certificates when it starts, but middleware never stopped, started or restarted webshare on any TrueNAS Connect transition. Setting up TNC and webshare, then unsetting TNC left webshare running, and setting TNC up again left it serving zero or stale certificates until someone restarted it by hand. At boot systemd could also start webshare before middleware was ready, so it came up with no certificates at all.

## Solution
Webshare now only runs when the WEBSHARE entitlement is granted and TNC is configured, regardless of product type.

- **Start gate**: `before_start` refuses START and RESTART with a `CallError` explaining why, so a restart or failover restart can't bypass it either.
- **Following TNC**: webshare subscribes to the existing `tn_connect.config` event. When TNC stops being configured (disable or 401 auto-unset) webshare is stopped; when it becomes configured again and webshare is enabled, it is started; a certificate renewal restarts a running webshare. A restart is used rather than a reload because a reload does not make every webshare listener re-read its certificates.
- **Boot**: on `system.ready` (non-HA) a running webshare is restarted so it loads the right certificates.
- **Licence changes**: the license reconcile framework could only render, reload or restart, so it had no way to stop a service that lost its entitlement or start one that regained it. Delegates can now resolve their action at runtime and return START or STOP. Those go through a new private `service.converge_verb`, which only starts a service that is stopped, enabled and allowed on this node, and only stops one that is running. Webshare registers a delegate on top of this instead of its own licence hook, and its TNC/boot handling uses the same guard.

The persisted enable flag is never touched, so the user's intent survives TNC or the licence going away and webshare comes back by itself once both are in place again.
DeltaFile
+52-1src/middlewared/middlewared/plugins/webshare/utils.py
+37-0src/middlewared/middlewared/pytest/unit/plugins/service/test_converge_verb.py
+26-3src/middlewared/middlewared/plugins/truenas/license_reconcile.py
+22-0src/middlewared/middlewared/plugins/webshare/__init__.py
+21-0src/middlewared/middlewared/plugins/service/__init__.py
+15-3src/middlewared/middlewared/common/license_reconcile/__init__.py
+173-75 files not shown
+209-711 files

LLVM/project 8995a35 — llvm/lib/CodeGen MachineBasicBlock.cpp, llvm/test/CodeGen/AMDGPU phi-elimination-split-critical-edge-nonoverlapping-subrange.mir

[LLVM] Skip non-overlapping subranges (#227852)

Add guard to skip subranges that not live in the interval.

fix to: https://github.com/llvm/llvm-project/pull/227252

Passed local libc tests:
```
Total Discovered Tests: 814
  Passed: 814 (100.00%)
```

assisted by: cursor
DeltaFile
+43-0llvm/test/CodeGen/AMDGPU/phi-elimination-split-critical-edge-nonoverlapping-subrange.mir
+4-2llvm/lib/CodeGen/MachineBasicBlock.cpp
+47-22 files

LLVM/project 150f9dc — lldb/include/lldb/Target StackFrame.h, lldb/source/Target ThreadPlan.cpp StackFrame.cpp

[lldb] Reject thread until targets outside of an inline frame's function (#227800)

`thread until -f N <line>` rejects a line outside of the function of
frame N.

Before this patch, for an inline frame, it checked the concrete
function, not the inlined function, so it accepted lines of other
inlined functions. The until plan then ignored a hit of such a target,
because it is not in the scope of frame N.

This commit changes GetStepUntilAddresses to only accepts an address if
its innermost inlined function is the one of frame N, as it does for a
regular frame.

As a before/after example, consider this backtrace:

```
  frame #0: 0x00000001000003c0 deep`sink(x=81) at deep.c:4:6 [opt]
  frame #1: 0x0000000100000418 deep`level3(a=48) at deep.c:11:3 [opt] [inlined]

    [10 lines not shown]
DeltaFile
+57-0lldb/test/API/functionalities/inline-frame-pc/TestInlineFrameUntil.py
+30-0lldb/test/API/functionalities/inline-frame-pc/main.c
+15-0lldb/source/Target/StackFrame.cpp
+6-0lldb/include/lldb/Target/StackFrame.h
+1-4lldb/source/Target/ThreadPlan.cpp
+3-0lldb/test/API/functionalities/inline-frame-pc/Makefile
+112-41 files not shown
+113-57 files

LLVM/project 52b2261 — llvm/lib/CodeGen WasmEHPrepare.cpp, llvm/lib/Target/WebAssembly WebAssemblyCFGStackify.cpp WebAssemblyTargetMachine.cpp

Fall back to the TargetOptions exception model

Staging change to keep tests working until the full removal
DeltaFile
+21-9llvm/lib/Target/WebAssembly/WebAssemblyLowerEmscriptenEHSjLj.cpp
+28-0llvm/test/CodeGen/WebAssembly/exception-model.ll
+16-6llvm/lib/CodeGen/WasmEHPrepare.cpp
+9-6llvm/lib/Target/WebAssembly/WebAssemblyTargetMachine.cpp
+9-6llvm/lib/Target/WebAssembly/WebAssemblyCodeGenPassBuilder.cpp
+7-3llvm/lib/Target/WebAssembly/WebAssemblyCFGStackify.cpp
+90-306 files not shown
+126-4012 files

LLVM/project 7b927d7 — llvm/lib/Target/WebAssembly WebAssemblyTargetMachine.cpp WebAssemblyCodeGenPassBuilder.cpp, llvm/test/CodeGen/WebAssembly wasm-eh-prepare-exception-model.ll exception-model.ll

WebAssembly: Take the exception model from the module flag

The WebAssembly EH passes chose whether and how to run from
MCAsmInfo::getExceptionHandlingType() and TargetOptions::ExceptionModel,
A module that asked for Wasm EH through the module flag alone would have
its invokes rewritten by LowerInvoke before WasmEHPrepare ran.

Schedule the passes unconditionally and read the module flag inside the
passes instead. Passes for other models can noop on the models they are
not intended for.

Co-authored-by: Claude Opus 5 <noreply at anthropic.com>
DeltaFile
+133-0llvm/test/Transforms/LowerInvoke/respect-exception-model-flag.ll
+93-0llvm/test/CodeGen/WebAssembly/exception-model.ll
+60-0llvm/test/CodeGen/WebAssembly/wasm-eh-prepare-exception-model.ll
+8-20llvm/lib/Target/WebAssembly/WebAssemblyCodeGenPassBuilder.cpp
+10-18llvm/lib/Target/WebAssembly/WebAssemblyLowerEmscriptenEHSjLj.cpp
+7-14llvm/lib/Target/WebAssembly/WebAssemblyTargetMachine.cpp
+311-528 files not shown
+345-7914 files

FreeBSD/doc da78dc7 — website/content/en/cgi man.cgi

man.cgi: correct name for X.Org project
DeltaFile
+1-1website/content/en/cgi/man.cgi
+1-11 files

FreeBSD/doc bbd2b26 — website/content/en/cgi man.cgi

man.cgi: remove duplicated alias v7man

There is already an alias "v7" for Unix Seventh Edition.
DeltaFile
+0-1website/content/en/cgi/man.cgi
+0-11 files

FreeBSD/ports d5105bf — sysutils/fluent-bit pkg-plist Makefile

sysutils/fluent-bit: Update to 5.1.3

Release notes:  https://github.com/fluent/fluent-bit/releases/tag/v5.1.3
DeltaFile
+3-3sysutils/fluent-bit/distinfo
+1-1sysutils/fluent-bit/Makefile
+1-0sysutils/fluent-bit/pkg-plist
+5-43 files

NetBSD/pkgsrc HQIcxb3 — devel/libuv distinfo, devel/libuv/patches patch-src_unix_process.c

   libuv: Backport https://github.com/libuv/libuv/pull/5284.

   Fixes infinite loop in posix_spawn() handling which was breaking the build
   of at least devel/cmake.
VersionDeltaFile
1.1+127-0devel/libuv/patches/patch-src_unix_process.c
1.90+2-1devel/libuv/distinfo
+129-12 files

FreeBSD/doc 1a8250b — website/content/en/cgi man.cgi

man.cgi: group releases by OS vendor

In the release select box, group the list of releases by OS vendor.
DeltaFile
+28-1website/content/en/cgi/man.cgi
+28-11 files

LLVM/project a95ee8a — llvm/lib/Target/AMDGPU AMDGPUSwLowerLDS.cpp, llvm/test/CodeGen/AMDGPU amdgpu-sw-lower-lds-flat-to-lds-cast-roundtrip.ll amdgpu-sw-lower-lds-flat-to-lds-cast.ll

[AMDGPU][SwLowerLDS] Rebase flat to LDS addrspacecasts to buffer offsets
DeltaFile
+117-0llvm/test/CodeGen/AMDGPU/amdgpu-sw-lower-lds-flat-to-lds-cast.ll
+87-0llvm/test/CodeGen/AMDGPU/amdgpu-sw-lower-lds-flat-to-lds-cast-roundtrip.ll
+33-5llvm/lib/Target/AMDGPU/AMDGPUSwLowerLDS.cpp
+237-53 files

LLVM/project 778dd2c — llvm/lib/Target/AArch64 AArch64SchedPredNeoverse.td AArch64SchedNeoverseV1.td, llvm/test/tools/llvm-mca/AArch64/Neoverse V1-basic-instructions.s

[AArch64][NeoverseV1] Load/Store Register Half with scaling (#222282)

On Neoverse V1, LDRH/STRH with scaling has a specific execution compared
to other LDR/STR.

Opcode            | Latency   | Pipelines
-------------------------------------------
Common LDR        | 4         | L
LDRH with scaling | 5         | I, L
Common STR        | 1         | L01, D
STRH with scaling | 2         | I, L01, D

Verified on Neoverse V1 with micro benchmarks and compared all
addressing mode variantes. Neoverse V2 is unaffected (confirmed by SOG
documentation and microbenchmarks).
DeltaFile
+9-9llvm/test/tools/llvm-mca/AArch64/Neoverse/V1-basic-instructions.s
+16-0llvm/lib/Target/AArch64/AArch64SchedNeoverseV1.td
+10-0llvm/lib/Target/AArch64/AArch64SchedPredNeoverse.td
+35-93 files

LLVM/project d24b9bf — clang/include/clang/CIR/Dialect/IR CIROps.td, clang/lib/CIR/Lowering/DirectToLLVM LowerToLLVM.cpp

[CIR] Extract CIR_ClassCastOp base class for BaseClassAddrOp and DerivedClassAddrOp

Both ops have identical structure (arguments, results, assembly format)
and differ only in mnemonic and description. Extract a shared TableGen
base class to eliminate the duplication. Also improve the assembly format
to print nonnull before the operand and place the type after the offset.
DeltaFile
+22-33clang/include/clang/CIR/Dialect/IR/CIROps.td
+12-12clang/test/CIR/Analysis/alias-analysis-underlying-object.cir
+8-8clang/test/CIR/CodeGen/vtt.cpp
+6-6clang/test/CIR/CodeGen/destructor-vtable-reinit.cpp
+5-5clang/test/CIR/CodeGen/derived-to-base.cpp
+5-5clang/lib/CIR/Lowering/DirectToLLVM/LowerToLLVM.cpp
+58-6921 files not shown
+103-11427 files

FreeBSD/doc 5d0e66b — website/themes/beastie/layouts/_partials site-footer.html

website/footer: Move CoC to legal to bring balance

Reviewed by:            carlavilla, wosch
Differential Revision:  https://reviews.freebsd.org/D60178
DeltaFile
+3-3website/themes/beastie/layouts/_partials/site-footer.html
+3-31 files

LLVM/project 2d6f747 — llvm/lib/Target/AMDGPU SIInstrInfo.cpp

generate stack offsets from the subreg instead of using lanebitmasks.
DeltaFile
+4-6llvm/lib/Target/AMDGPU/SIInstrInfo.cpp
+4-61 files

FreeBSD/src ab9fcc5 — sys/arm/include ifunc.h, sys/arm64/include ifunc.h

ifuncs: Have DEFINE_*IFUNC() macros expand the passed name

While here, make each <machine/ifunc.h> header include <sys/types.h> so
that it can be included standalone.

Reviewed by:    kib
MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D60167
DeltaFile
+12-7sys/riscv/include/ifunc.h
+11-7sys/x86/include/ifunc.h
+11-7sys/arm/include/ifunc.h
+10-6sys/arm64/include/ifunc.h
+8-6sys/powerpc/include/ifunc.h
+52-335 files

OPNSense/core a37badb — src/opnsense/mvc/app/models/OPNsense/Base/FieldTypes PortField.php, src/opnsense/mvc/tests/app/models/OPNsense/Base/FieldTypes PortFieldTest.php

MVC: PortField - keep the first well-known service in the option list (#10947)
DeltaFile
+15-0src/opnsense/mvc/tests/app/models/OPNsense/Base/FieldTypes/PortFieldTest.php
+4-3src/opnsense/mvc/app/models/OPNsense/Base/FieldTypes/PortField.php
+19-32 files

LLVM/project dc3fae3 —

[MLIR] Emit final-policy remarks in deterministic order (#224616)

`RemarkEmittingPolicyFinal` stores remarks in a `DenseSet` whose hash covers the location pointer and the process hash seed, so `finalize()` emitted them in bucket order. That order depends on the build configuration and on memory layout, which is why `mlir/test/Pass/remark-final.mlir` used `CHECK-DAG`.

The engine already assigns every remark a `RemarkId` from a monotonic counter when it is created, and the set already keeps the newer of two remarks with the same identity. `finalize()` now sorts the drained remarks by that ID before emitting. Remarks come out in creation order, a replaced identity takes the position of its last report, and linked remarks still follow their parent.

Behaviour change: order only. The identity, `DenseMapInfo<Remark>` and the header are unchanged. Only remarks handed to the policy outside the engine have no ID; the unit tests that do so assert unordered or single results.

Creation order is deterministic for a single-threaded pipeline. When passes report from several threads the IDs come from a shared counter and depend on scheduling; #227360 adds the lock and a source-position sort for that case, on top of this change.

Whether the identity itself is right is a separate question for a follow-up: the docs say a later `passed` replaces an earlier `failed` at the same location, but `kind` has been part of the key since #180953, so both are shown today. This PR leaves the docs as they are on that point.

Assisted-by: Claude Code (Claude Fable 5.1).
DeltaFile
+0-00 files

LLVM/project a75b42d — llvm/test/CodeGen/AMDGPU amdgcn.bitcast.768bit.ll amdgcn.bitcast.960bit.ll

Merge branch 'main' into users/xlauko/cgutils-03-ehpersonality-struct
DeltaFile
+43,527-43,588llvm/test/CodeGen/AMDGPU/amdgcn.bitcast.1024bit.ll
+8,456-8,694llvm/test/CodeGen/AMDGPU/amdgcn.bitcast.512bit.ll
+5,501-5,654llvm/test/CodeGen/AMDGPU/amdgcn.bitcast.896bit.ll
+5,473-5,576llvm/test/CodeGen/AMDGPU/amdgcn.bitcast.832bit.ll
+5,285-5,462llvm/test/CodeGen/AMDGPU/amdgcn.bitcast.960bit.ll
+4,549-4,668llvm/test/CodeGen/AMDGPU/amdgcn.bitcast.768bit.ll
+72,791-73,6423,131 files not shown
+199,275-164,0443,137 files

FreeBSD/ports 258e335 — java/apache-commons-lang Makefile

java/apache-commons-lang: mention unpatched CVE

Security:       CVE-2025-48924 "Uncontrolled Recursion"
DeltaFile
+2-2java/apache-commons-lang/Makefile
+2-21 files

FreeBSD/ports 6faa37f — security/vuxml/vuln 2026.xml

security/vuxml: apache-commons-lang -- Uncontrolled Recursion vulnerability
DeltaFile
+30-0security/vuxml/vuln/2026.xml
+30-01 files

FreeBSD/src 1fadced — usr.bin/sdiff sdiff.c sdiff.1

sdiff.1: Document exit status and --help

MFC after:      3 days
Approved by:    bnovkov (mentor)
Sponsored by:   fme AG
Differential Revision:  https://reviews.freebsd.org/D59927

(cherry picked from commit 14c7492637ec0644b5bb88da114e8cc76b9bf629)
DeltaFile
+22-1usr.bin/sdiff/sdiff.1
+1-0usr.bin/sdiff/sdiff.c
+23-12 files

FreeBSD/src 2670aa4 — usr.bin/sdiff sdiff.c sdiff.1

sdiff.1: Document exit status and --help

MFC after:      3 days
Approved by:    bnovkov (mentor)
Sponsored by:   fme AG
Differential Revision:  https://reviews.freebsd.org/D59927

(cherry picked from commit 14c7492637ec0644b5bb88da114e8cc76b9bf629)
DeltaFile
+22-1usr.bin/sdiff/sdiff.1
+1-0usr.bin/sdiff/sdiff.c
+23-12 files

FreeBSD/ports 4acd1b0 — misc/mc pkg-plist distinfo, misc/mc/files patch-src_filemanager_filemanager.c patch-misc_mc.ext.ini.in

misc/mc: update Midnight Commander to the latest version 4.8.33

- Tentatively switch default renderer from S-Lang to ncurses which
  is part of the base system and does not pull EoLed `devel/pcre'
- GC no longer needed USES+=shebangfix, adjust Python dependency
- Add support for entering and viewing FreeBSD packages, based on
  the idea and patch by Walter von Entferndt
- Register installation conflict with `misc/mc6' port while at it

PR:     292865, 293259, 294086
DeltaFile
+15-0misc/mc/files/patch-misc_mc.ext.ini.in
+0-11misc/mc/files/patch-src_filemanager_filemanager.c
+5-6misc/mc/Makefile
+3-3misc/mc/distinfo
+2-0misc/mc/pkg-plist
+25-205 files

FreeNAS/freenas 84d33f2 — src/middlewared/middlewared/plugins/service/services webshare.py, src/middlewared/middlewared/plugins/truenas_connect __init__.py utils.py

Tie webshare lifecycle to TrueNAS Connect state

## Problem
Webshare's Caddy only picks up its TLS certificates when it starts, but middleware never stopped, started or restarted webshare on any TrueNAS Connect transition. Setting up TNC and webshare, then unsetting TNC left webshare running, and setting TNC up again left it serving zero or stale certificates until someone restarted it by hand. At boot systemd could also start webshare before middleware was ready, so it came up with no certificates at all.

## Solution
Webshare now only runs when the WEBSHARE entitlement is granted and TNC is configured, regardless of product type.

- **Start gate**: `before_start` refuses START and RESTART with a `CallError` explaining why, so a restart or failover restart can't bypass it either.
- **Following TNC**: webshare subscribes to the existing `tn_connect.config` event. When TNC stops being configured (disable or 401 auto-unset) webshare is stopped; when it becomes configured again and webshare is enabled, it is started; a certificate renewal restarts a running webshare. A restart is used rather than a reload because a reload does not make every webshare listener re-read its certificates.
- **Licence and boot**: the same check runs on licence updates and on `system.ready` (non-HA), where a running webshare is restarted so it loads the right certificates.

The persisted enable flag is never touched, so the user's intent survives TNC being unset and webshare comes back by itself once TNC is set up again.
DeltaFile
+67-1src/middlewared/middlewared/plugins/webshare/utils.py
+14-0tests/api2/test_webshare_service.py
+9-0src/middlewared/middlewared/plugins/truenas_connect/utils.py
+7-0src/middlewared/middlewared/plugins/service/services/webshare.py
+6-0src/middlewared/middlewared/plugins/webshare/__init__.py
+5-0src/middlewared/middlewared/plugins/truenas_connect/__init__.py
+108-11 files not shown
+109-17 files

FreeNAS/freenas b9eeeb7 — src/middlewared/middlewared/plugins/zfs resource.py rules_common.py, src/middlewared/middlewared/pytest/unit/plugins/zfs test_create_post_write.py

Fix the thick grow test, drop dead pool.dataset shims and tidy stale zfs.resource comments and rules

## Problem
test_grow_thick_volume_keeps_it_thick read the refreservation off the entry returned by the second grow. Since thick re-reserve only adds refreservation=auto when the reservation equals the volsize, that grow sends volsize alone and ZFS grows its own auto reservation, so the returned entry carries no refreservation and the test failed with a KeyError. The private pool.dataset.path_in_locked_datasets and pool.dataset.kill_processes shims had no callers left, every user having moved to zfs.resource.path_is_locked and zfs.resource.kill_processes. A few comments were also stale: the create rule and the zfs.resource.create docstring compared the default thick refreservation to `zfs create -V`, which sets the larger auto value while zr reserves exactly the volsize, the create TODO had lost why auto isn't used yet, and the build_set_of_zfs_props docstring had the None and empty list cases backwards. A unit test named for announcing created ancestors and the leaf only checked that an internal path announces nothing, and the create and set force_size rules each carried their own copy of the refusal instead of a shared reject helper like every other rule both sides apply, with the create one also missing from __all__.

## Solution
- **Test:** read the reservation from the zvol itself, as the first grow already does.
- **Shims:** remove the two unused shims.
- **force_size rule:** both sides call a shared reject_force_size_on_filesystem, and the create rule is listed in __all__.
- **Unit test:** rename it to test_create_announces_nothing_for_an_internal_path and inline its single case.
- **Comments:** drop the `zfs create -V` comparison, restore the reason auto can't be used on create (zfs_create() doesn't resolve it, so create fails with "out of space") and that a grow switches these volumes to auto, and describe build_set_of_zfs_props as it behaves, including that its cache ignores req_props once filled.
DeltaFile
+8-6src/middlewared/middlewared/plugins/zfs/property_management.py
+3-8src/middlewared/middlewared/pytest/unit/plugins/zfs/test_create_post_write.py
+6-3src/middlewared/middlewared/plugins/zfs/create_rules.py
+5-0src/middlewared/middlewared/plugins/zfs/rules_common.py
+2-2tests/api2/test_zfs_resource_set.py
+2-2src/middlewared/middlewared/plugins/zfs/resource.py
+26-213 files not shown
+28-309 files

FreeBSD/ports 5c59100 — textproc/py-zensical Makefile Makefile.crates

textproc/py-zensical: Update to 0.0.67

Approved by:    kai (maintainer via email)
DeltaFile
+159-3textproc/py-zensical/distinfo
+79-1textproc/py-zensical/Makefile.crates
+1-1textproc/py-zensical/Makefile
+239-53 files

LLVM/project d7e4505 — llvm/include/llvm/Analysis ScalarEvolution.h, llvm/lib/Analysis ScalarEvolution.cpp

[SCEV] Extend cache-lookup for AR (NFC) (#218927)

It allows us to improve some code, but it cannot be used in getAR
without making functional changes.
DeltaFile
+38-0llvm/test/Analysis/ScalarEvolution/addrec-computed-during-addrec-calculation.ll
+8-10llvm/lib/Analysis/ScalarEvolution.cpp
+5-3llvm/include/llvm/Analysis/ScalarEvolution.h
+51-133 files