FreeBSD/src e2279d5 — usr.sbin/tcpdrop tcpdrop.c

tcpdrop: improve handling of -C and -S

Handle empty strings for -Cand -S correctly.

Reported by:            maxim
Reviewed by:            maxim
MFC after:              1 week
MFC to:                 stable/14
MFC to:                 stable/15
Sponsored by:           Netflix, Inc.
Differential Revision:  https://reviews.freebsd.org/D60210
DeltaFile
+11-9usr.sbin/tcpdrop/tcpdrop.c
+11-91 files

OPNSense/core ea58b68 — src/etc/inc interfaces.inc, src/opnsense/scripts/interfaces ppp-ipv6.php

interfaces: be more conservative with -no_dad #10951

In e0e1401f8739e we're enabling it always which also affects
assigned tunnels such as WireGuard which tend to avoid wanting
DAD so make room for leaving the flag unchanged and change it
everywhere else explicitly per type.
DeltaFile
+9-6src/etc/inc/interfaces.inc
+1-1src/opnsense/scripts/interfaces/ppp-ipv6.php
+10-72 files

LLVM/project 1e1f35b — compiler-rt/lib/fuzzer FuzzerDriver.cpp FuzzerFlags.def

[libFuzzer] Fix typos and punctuation in flag descriptions (#122619)

Co-authored-by: Stan Ulbrych <stan at python.org>
DeltaFile
+36-36compiler-rt/lib/fuzzer/FuzzerFlags.def
+1-1compiler-rt/lib/fuzzer/FuzzerDriver.cpp
+37-372 files

LLVM/project b7cf639 — llvm/include/llvm/IR IntrinsicsAMDGPU.td, llvm/lib/Target/AMDGPU VOP3Instructions.td AMDGPULowerIntrinsics.cpp

[AMDGPU] Validate scale_sel in v_cvt_scale_*

These instructions can be block16 or block32 depending on the target
and scale_sel bits. Block16 is not supported in strict mode.

Re-enable the rest of the instructions in the strict mode but validate
the scale selector.
DeltaFile
+268-0llvm/test/CodeGen/AMDGPU/llvm.amdgcn.cvt.scale.pk-scale-range.ll
+135-16llvm/test/MC/AMDGPU/gfx1250-strict_err.s
+61-0llvm/lib/Target/AMDGPU/AMDGPULowerIntrinsics.cpp
+47-0llvm/lib/Target/AMDGPU/AsmParser/AMDGPUAsmParser.cpp
+7-9llvm/lib/Target/AMDGPU/VOP3Instructions.td
+6-8llvm/include/llvm/IR/IntrinsicsAMDGPU.td
+524-333 files not shown
+533-489 files

LLVM/project f3eb046 — clang/include/clang/Basic BuiltinsAMDGPU.td, clang/test/SemaOpenCL builtins-amdgcn-error-gfx1250-strict.cl

[AMDGPU] v_cvt_scale_pk8_* are block32 in strict mode (#227426)

Re-enable these instructions in strict mode.

Fixes: LCOMPILER-2841
DeltaFile
+15-14llvm/lib/Target/AMDGPU/VOP3Instructions.td
+0-27llvm/test/MC/AMDGPU/gfx1250-strict_err.s
+10-9llvm/include/llvm/IR/IntrinsicsAMDGPU.td
+9-9clang/include/clang/Basic/BuiltinsAMDGPU.td
+0-9clang/test/SemaOpenCL/builtins-amdgcn-error-gfx1250-strict.cl
+34-685 files

LLVM/project d47315b — compiler-rt/lib/sanitizer_common/symbolizer sanitizer_wrappers.cpp, compiler-rt/test/ubsan/TestCases/Misc/Posix hsa-load-order.cpp shared-libsan-dso.cpp

[compiler-rt] Fix -shared-libsan usage with internal symbolizer (#227717)

Summary:
https://github.com/llvm/llvm-project/pull/226551 exposed a preexisting
issue when using `-shared-libsan` nad the internal symbolizer builds.
The symbolizer will try to look up the symbol via `RTLD_NEXT`, which
goes in load order. If the sanitizer library is loaded *after* `libc.so`
then this `dlsym` call will miss it.

The solution is to have a fallback that checks using `RTLD_DEFAULT`.
This
should allow us to find the symbol in these exceptional cases. I don't
expect much fallout as this covers a case that currently returns `NULL`.
Loading it in means it could grab a reference ahead of the runtime that
was intended to be intercepted, but for this use-case I don't think this
will apply.
DeltaFile
+23-0compiler-rt/test/ubsan/TestCases/Misc/Posix/shared-libsan-dso.cpp
+8-1compiler-rt/lib/sanitizer_common/symbolizer/sanitizer_wrappers.cpp
+0-4compiler-rt/test/ubsan/TestCases/Misc/Posix/hsa-load-order.cpp
+31-53 files

FreeBSD/ports a95f20e — www/nextcloud-contacts Makefile distinfo

www/nextcloud-contacts: Update to 8.9.1
DeltaFile
+3-3www/nextcloud-contacts/distinfo
+1-1www/nextcloud-contacts/Makefile
+4-42 files

LLVM/project 87db728 — clang/docs ReleaseNotes.md, clang/lib/AST ExprConstant.cpp

[clang] Fix crash constant-evaluating the construction of huge arrays (#226899)

Fixes #173728

The constant evaluator runs on ordinary code all the time (range checks
for `-W` warnings, `isEvaluatable` in codegen), and it
default-constructs an array by building one `APValue` per element. The
element count got truncated to `unsigned` first and nothing checked its
size, so a local like `struct T {} s[0xFFFFFFFF][0]` ran it out of
memory; with the issue's reproducer, where the count wraps to 2^64 - 4,
an assertions build hits the "bounds check failed" assertion in
`adjustIndex` first. Copying such an array, e.g. into a lambda capture,
had the same problem. This goes back to at least Clang 3.4. The bytecode
interpreter has its own version: it emits code for every element, so a
constructor with a member like `T a[0xFFFFFFFF]` runs it out of memory
too.

Array default construction and `ArrayInitLoopExpr` now go through the
existing `CheckArraySize` guard, the same one `new` already uses, so

    [6 lines not shown]
DeltaFile
+61-0clang/test/AST/ByteCode/dynalloc-limits.cpp
+15-2clang/lib/AST/ByteCode/Compiler.cpp
+7-0clang/lib/AST/ByteCode/InterpHelpers.h
+4-0clang/lib/AST/ExprConstant.cpp
+4-0clang/docs/ReleaseNotes.md
+91-25 files

FreeBSD/ports e560407 — www/nextcloud-calendar Makefile distinfo

www/nextcloud-calendar: Update to 6.6.2
DeltaFile
+3-3www/nextcloud-calendar/distinfo
+1-1www/nextcloud-calendar/Makefile
+4-42 files

FreeBSD/ports 078f7ec — www/nextcloud-appointments Makefile distinfo

www/nextcloud-appointments: Update to 2.8.0
DeltaFile
+3-3www/nextcloud-appointments/distinfo
+2-2www/nextcloud-appointments/Makefile
+5-52 files

NetBSD/pkgsrc qPKNCiN — doc CHANGES-2026

   doc: Updated net/powerdns-recursor to 5.4.7
VersionDeltaFile
1.6578+2-1doc/CHANGES-2026
+2-11 files

LLVM/project d6a906b — lldb/source/Core Module.cpp

[LLDB] Acquire the module mutex at the start of SetLoadAddress (#227149)

Fixes a potential dead-lock from parallel module loading. 

I received a quick-stack of LLDB hung loading a core with parallel
module loading enabled, where two threads were trying to mutate a given
module and an object file, but having acquired the module mutex first in
one case, and the object file's section mutex first in the second case,
which each trying to subsequently acquire the other lock.

In the update case, [SetLoadAddress acquires the section list mutex and
then tries to acquire the module
mutex](https://github.com/llvm/llvm-project/blob/60f717946cb5ca911b6be22169b9bd646225c59f/lldb/source/Symbol/ObjectFile.cpp#L614)

```
SectionList *ObjectFile::GetSectionList(bool update_module_section_list) {
  std::lock_guard<std::recursive_mutex> guard(m_sections_mutex);
  if (m_sections_up)
    return m_sections_up.get();

    [26 lines not shown]
DeltaFile
+4-0lldb/source/Core/Module.cpp
+4-01 files

NetBSD/pkgsrc 94KNQEi — net/powerdns-recursor cargo-depends.mk Makefile

   powerdns-recursor: Update to 5.4.7

   Released: 1st of October 2026
   Bug Fixes
   Rec: Fix Lua to YAML conversion of custom RPZ policies
   References: pull request 18029

   Rec: retrieve DNSSEC data with RPZ processing disabled
   References: pull request 18035

   Rec: Catch exception thrown by parsing system resolver result
   References: pull request 18068

   Fix(rec): Wipe caches when wiping all NTA’s
   References: pull request 18070

   Rec and auth: fix axfr failure to invalidate fd on close in all cases.
   References: pull request 18084


    [2 lines not shown]
VersionDeltaFile
1.55+3-3net/powerdns-recursor/distinfo
1.71+2-3net/powerdns-recursor/Makefile
1.8+0-0net/powerdns-recursor/cargo-depends.mk
+5-63 files

FreeBSD/ports a421d32 — net-im/nextcloud-talk Makefile distinfo

net-im/nextcloud-talk: Update to 25.0.3
DeltaFile
+3-3net-im/nextcloud-talk/distinfo
+1-1net-im/nextcloud-talk/Makefile
+4-42 files

NetBSD/pkgsrc mZlaHMe — textproc/expat builtin.mk Makefile

   Pullup ticket #7251 - requested by taca
   textproc/expat: security fix

   Revisions pulled up:
   - textproc/expat/Makefile                                       1.69
   - textproc/expat/builtin.mk                                     1.29
   - textproc/expat/distinfo                                       1.63

   ---
      Module Name:      pkgsrc
      Committed By:     adam
      Date:             Wed Sep 23 05:31:06 UTC 2026

      Modified Files:
        pkgsrc/textproc/expat: Makefile builtin.mk distinfo

      Log Message:
      expat: updated to 2.8.5


    [56 lines not shown]
VersionDeltaFile
1.62.2.1+4-4textproc/expat/distinfo
1.28.2.1+2-2textproc/expat/builtin.mk
1.68.2.1+2-2textproc/expat/Makefile
+8-83 files

NetBSD/pkgsrc NgzwOfm — net/net-snmp Makefile Makefile.common, net/net-snmp/patches patch-configure

   Pullup ticket #7250 - requested by taca
   net/net-snmp: security fix
   net/py-netsnmp: security fix

   Revisions pulled up:
   - net/net-snmp/Makefile                                         1.149
   - net/net-snmp/Makefile.common                                  1.10
   - net/net-snmp/distinfo                                         1.108
   - net/net-snmp/patches/patch-configure                          1.7
   - net/py-netsnmp/Makefile                                       1.15
   - net/py-netsnmp/PLIST                                          1.2

   ---
      Module Name:      pkgsrc
      Committed By:     adam
      Date:             Tue Sep 22 07:42:22 UTC 2026

      Modified Files:
        pkgsrc/net/net-snmp: Makefile Makefile.common distinfo

    [69 lines not shown]
VersionDeltaFile
1.6.6.1+51-5net/net-snmp/patches/patch-configure
1.107.6.1+5-5net/net-snmp/distinfo
1.14.22.1+4-5net/py-netsnmp/Makefile
1.1.98.1+5-4net/py-netsnmp/PLIST
1.9.6.1+3-3net/net-snmp/Makefile.common
1.148.2.1+2-2net/net-snmp/Makefile
+70-246 files

LLVM/project 88156f8 — clang/lib/CodeGen CGStmtOpenMP.cpp, clang/test/OpenMP teams_generic_loop_reduction_distribute_codegen.cpp

[clang][OpenMP] Don't use fused dist schedule for teams loop emitted as distribute (#228129)

Fix teams loop reductions lowered as 'distribute' lose their loop.

Claude assisted with this patch.
DeltaFile
+63-0clang/test/OpenMP/teams_generic_loop_reduction_distribute_codegen.cpp
+9-0clang/lib/CodeGen/CGStmtOpenMP.cpp
+72-02 files

LLVM/project 6321d0c — clang/test/CodeGenOpenCL builtins-amdgcn-make-buffer-rsrc.cl, llvm/lib/Target/AMDGPU AMDGPUInstCombineIntrinsic.cpp

[AMDGPU] Canonicalize num_records to its actual width in InstCombine

llvm.amdgcn.make.buffer.rsrc is overloaded on the type of its
num_records argument, but the hardware field it ends up in has a fixed
width (32 bits, or 45 bits on gfx1250 and up). Rewrite the intrinsic to
use that width, zero-extending or truncating num_records as needed, so
that IR-level optimizations can see that the extra bits of, for example,
the i64 that Clang emits are not demanded.

Targets that aren't concrete enough for the buffer resource layout to be
known are left alone.

AI disclosure: This was my idea but Claude wrote the code (and I've
tried to tighten up the comments)
DeltaFile
+36-44clang/test/CodeGenOpenCL/builtins-amdgcn-make-buffer-rsrc.cl
+22-12llvm/test/Transforms/InstCombine/AMDGPU/make-buffer-rsrc-num-records.ll
+21-1llvm/lib/Target/AMDGPU/AMDGPUInstCombineIntrinsic.cpp
+1-1llvm/test/Transforms/InstCombine/AMDGPU/amdgcn-intrinsics.ll
+80-584 files

LLVM/project 9247019 — llvm/test/Transforms/InstCombine/AMDGPU make-buffer-rsrc-num-records.ll

[AMDGPU] Pre-commit tests for num_records canonicalizations (#217067)

Add tests for having InstCombine canonicalize the num_records argument
of llvm.amdgcn.make.buffer.rsrc to the width it will ultimately have,
which lets later passes see that, for example, the high bits of the i64
that Clang emits aren't used.

AI disclosure: Claude generated these and I've looked at them
DeltaFile
+153-0llvm/test/Transforms/InstCombine/AMDGPU/make-buffer-rsrc-num-records.ll
+153-01 files

NetBSD/pkgsrc iUTWLbZ — doc CHANGES-2026

   Updated devel/py-ruff, devel/py-cbor2
VersionDeltaFile
1.6577+3-1doc/CHANGES-2026
+3-11 files

NetBSD/pkgsrc vtimVCf — devel/py-cbor2 Makefile distinfo

   py-cbor2: updated to 6.1.5

   6.1.5

   - Fixed :class:`CBORSimpleValue` hashing inconsistently with the integer it compares equal to
   - Fixed canonical encoding with value sharing enabled emitting shared references to container
     keys that were never written to the stream, because the throwaway encoding used to sort the keys
     registered them as shared values; the output then failed to decode, or decoded with the wrong
     keys substituted in
   - Fixed shared references (tag 29) to a map or an unhandled tag resolving to the raw
     :class:`dict` or :class:`CBORTag` instead of the value returned by ``object_hook`` or
     ``tag_hook``, a regression from 5.x
   - Fixed the encoder not giving a nested stringref namespace (tag 256) its own index space
   - Fixed the decoder returning its internal break marker as a value when a break stop code
     appeared where a data item was expected
   - Fixed a ``PanicException`` when trying to decode an epoch-form date (tag 100) with a payload near
     ``i32::MAX`` which then overflowed the addition instead of raising a clean decode error
   - Fixed the decoder accepting a string-form datetime (tag 0) without a UTC offset and returning
     a naive :class:`~datetime.datetime` instead of rejecting it

    [2 lines not shown]
VersionDeltaFile
1.20+4-4devel/py-cbor2/distinfo
1.22+2-2devel/py-cbor2/Makefile
+6-62 files

FreeNAS/freenas 183ebd0 — src/middlewared/middlewared/plugins/ntp peers.py

ruff it
DeltaFile
+45-41src/middlewared/middlewared/plugins/ntp/peers.py
+45-411 files

FreeBSD/ports 3086e36 — www/apache24 Makefile distinfo

www/apache24: Security update to 2.4.69

Security:       ed670f20-bdc3-11f1-a6ea-8447094a420f
MFH:            2026Q3
(cherry picked from commit 6a77d475b77a7f057cf1294478728a27cb6a6aea)
DeltaFile
+3-3www/apache24/distinfo
+1-1www/apache24/Makefile
+4-42 files

NetBSD/pkgsrc b9dMjRd — devel/py-ruff Makefile cargo-depends.mk

   py-ruff: updated to 0.16.10

   0.16.10

   Preview features

   Add a migration guide for categories
   [pyupgrade] Add rule for context manager iterator annotations (UP052)

   Performance

   Reduce memory used by diagnostics

   Server

   Avoid running uv format in untrusted workspaces

   Documentation


    [7 lines not shown]
VersionDeltaFile
1.123+22-22devel/py-ruff/distinfo
1.117+6-6devel/py-ruff/cargo-depends.mk
1.126+3-3devel/py-ruff/Makefile
+31-313 files

FreeNAS/freenas d52bb7b — src/middlewared/middlewared/alert/source ntp.py, src/middlewared/middlewared/plugins/ntp enums.py peers.py

Read NTP peers from the chronyd socket

Stop running chronyc and ask chronyd directly over its unix socket. Replies are checked the same way libchrony checks them. Drop the NTPPeer wrapper so the alert reads the peer entries as they are. Add a unit test for the request and reply handling.
DeltaFile
+138-93src/middlewared/middlewared/plugins/ntp/peers.py
+107-0src/middlewared/middlewared/pytest/unit/plugins/test_ntp_peers.py
+31-43src/middlewared/middlewared/plugins/ntp/enums.py
+6-8src/middlewared/middlewared/alert/source/ntp.py
+282-1444 files

FreeBSD/ports 6a77d47 — www/apache24 Makefile distinfo

www/apache24: Security update to 2.4.69

Security:       ed670f20-bdc3-11f1-a6ea-8447094a420f
MFH:            2026Q3
DeltaFile
+3-3www/apache24/distinfo
+1-2www/apache24/Makefile
+4-52 files

FreeBSD/ports 9e8e24c — security/vuxml/vuln 2026.xml

security/vuxml: Document Apache httpd vulnerabilities
DeltaFile
+66-0security/vuxml/vuln/2026.xml
+66-01 files

LLVM/project 152d32e — clang/lib/CodeGen/TargetBuiltins RISCV.cpp, clang/test/CodeGen/RISCV rvp-intrinsics.c

[Clang][RISCV][P-ext] Add packed Q-format widening accumulate intrinsics (#228009)

Add support for the Packed "Q-format" Multiply with Widening Accumulate
intrinsics:

- `__riscv_pmqwacc_i32x2`
- `__riscv_pmqrwacc_i32x2`

RV32 selects the direct instructions, while RV64 lowers to the
spec-listed `zip16p` and packed Q-format accumulate sequences.
DeltaFile
+32-0llvm/test/CodeGen/RISCV/rvp-simd-64.ll
+28-0clang/test/CodeGen/RISCV/rvp-intrinsics.c
+24-0llvm/lib/Target/RISCV/RISCVISelLowering.cpp
+17-5llvm/lib/Target/RISCV/RISCVInstrInfoP.td
+16-0cross-project-tests/intrinsic-header-tests/riscv_packed_simd.c
+9-0clang/lib/CodeGen/TargetBuiltins/RISCV.cpp
+126-53 files not shown
+144-59 files

NetBSD/src qRNQ0Z7 — usr.sbin/fssconfig fssconfig.8

   fssconfig(8): Clarify some details.

   - Note up front that fssdev can be mounted with mount(8).

   - Emphasize that fssconfig -c takes a mount point, not an arbitrary
     directory.

   - Break the prose paragraph of options for snapstore into a bulleted
     list.

   - Clarify that you needn't use fssconfig(8) at all with dump(8).

   - Move dump -X/-x option up front to make it more obvious.
VersionDeltaFile
1.19+37-17usr.sbin/fssconfig/fssconfig.8
+37-171 files

FreeBSD/src 74152f8 — lib/clang llvm.build.mk, lib/clang/include/llvm/Config Targets.h

llvm: remove Mips target support

The Mips architecture has been removed from all supported branches now.

MFC after:      1 week

(cherry picked from commit b5d1e0c5a4929e2be3bc58aad8e5b707860ec0fd)
DeltaFile
+6-83lib/clang/libllvm/Makefile
+1-6share/man/man5/src.conf.5
+0-4tools/build/options/WITH_LLVM_TARGET_MIPS
+0-4tools/build/options/WITHOUT_LLVM_TARGET_MIPS
+0-4lib/clang/include/llvm/Config/Targets.h
+0-3lib/clang/llvm.build.mk
+7-1045 files not shown
+8-11711 files