Fix the checksum choices result, the extent readonly event test and the create mount-path check
## Problem
- **checksum choices**: `pool.dataset.checksum_choices` now returns the checksums `zfs.resource` accepts, which include OFF, but its result model still had the fixed fields master's list had without OFF and forbids extras. Every call failed result validation: integration tests raise, production logs a serialization warning, and older API clients fail outright because the adapter validates against the current model first.
- **extent readonly test**: `test_readonly_on_an_extent_zvol_syncs_the_extent` expected two CHANGED events for one readonly change. The second came from the iSCSI resync writing readonly back onto the zvol, which the resync no longer does, so the test failed.
- **create mount-path check**: create refused a filesystem when `/mnt/<path>` already existed, while the share ACL is applied at the path the filesystem really mounts at. Under an ancestor with a non-default mountpoint the two differ, so an occupied real mount path went unnoticed until the mount failed after the resource was created, and a stray `/mnt/<path>` refused a create that would never mount there.
## Solution
- **checksum choices**: added OFF to the v27 result model. Create and update have always accepted `checksum=OFF`, so the list now matches what they take. Older API versions keep their models, and the adapter drops OFF for those clients as before.
- **extent readonly test**: it now expects the single CHANGED event from the caller's own set.
- **create mount-path check**: it tests the nearest existing ancestor's mountpoint joined with the rest of the path, the same path the ACL step uses. With default mountpoints that is still `/mnt/<path>`.
sysutils/broot: update to 1.60.2
v1.60.2
- fix some combinations being wrongly interpreted for input on some terminals (eg shift-r with kitty keyboard protocol enabled on ghostty/mac was interpreted as just a 'r')
- preview of CRLF (Windows style) text files no longer shows a replacement char at the end of every line - Fix #1216
- :copy_line no longer copies the end of line characters
- PSD images are no longer previewed
- content search no longer reports false matches in .bz2, .xz, .zst and .br files
- nerdfont icons for TOML and YAML files - Thanks @noahkawaguchi
v1.60.1
- the official macOS binary now includes the clipboard feature (:copy_path, :copy_line, :input_paste)
- a verb redefined with the name of an existing one no longer makes typing a prefix of that name ambiguous
- on macOS, the trash listing verbs (:open_trash, etc.) are no longer offered, as they couldn't work there
- paths containing shell special characters (globs, $, parentheses, etc.) are now quoted in commands executed by the shell function - Fix #595
- the terminal title no longer shows paths quoted
- fix double-click not opening the file when the tree is scrolled - Fix #150
- git statuses are no longer missing in subdirectories when broot is launched from a subdirectory of the repository
- the diff preview is shown for a modified file given as launch argument
[2 lines not shown]
shells/oh-my-posh: update to 31.4.0
Bug Fixes
- config: honor segment cache while streaming (1ff660a), closes #7882
- git: bare repo .Upstream holds raw remote list, not the tracking branch (9fa688e), closes #7799
- pwsh: count wrapped rows for ExtraPromptLineCount (2b37f96), closes #7881
- segments: coerce non-string key/value option values instead of panicking (4013b4a)
- strava: show the skiing icon for nordic and alpine skis (a8f56ab)
- template: trust markup in var values and cross-segment text (36a80f6), closes #7858
Features
- agents: add stop hooks for CI quality checks (1a3d860)
[VectorCombine] Pass flags during IR creation (#193271)
Since commit 777d6b5, VectorCombine has been using InstSimplifyFolder to
simplify vector instructions during IR construction. When creating a new
instruction, InstSimplifyFolder may fold the operation and return an
existing operand instead of emitting a new instruction.
In such cases, copying IR flags to the returned value is incorrect and
may unintentionally propagate flags to pre‑existing instructions,
polluting the original IR. To avoid this, flags should be passed at IR
creation rather than being set after construction. Fix #192607.
pci: Reserve bus numbers required by SR-IOV VFs
Some firmware assigns only one bus number to each PCI-PCI bridge. This
prevents later SR-IOV VF enumeration when a VF routing ID falls on a bus
number already allocated to a sibling bridge.
Reserve only the additional bus numbers required by SR-IOV PFs.
Enumerate all directly attached functions before child drivers and
bridges attach, inspect their device_t objects for SR-IOV, and grow the
PCI bus resource through the highest possible VF routing ID.
First VF Offset and VF Stride may change when NumVFs changes. Probe
every valid NumVFs value and preserve the original setting. When the
upstream hierarchy uses ARI, temporarily enable the SR-IOV ARI Hierarchy
control in the lowest-numbered PF while sizing, then restore it. Scope
active-VF detection to each conventional PCI slot; an ARI bus remains
one slot-0 hierarchy. If firmware left VFs enabled on a device, do not
modify it and reserve only its active layout.
[20 lines not shown]
png: update to 1.6.59.
Version 1.6.59 [September 28, 2026]
Fixed CVE-2026-46675 (medium severity):
Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt
or iCCP decompression.
(Reported independently by Ze Sheng and
<JasonHonKL at users.noreply.github.com>.)
Fixed a regression introduced in version 1.6.47 that caused libpng to reject
hIST chunks in their correct position, after PLTE.
(Contributed by Yuki Sekiguchi.)
Prevented a double free of `png_struct` members after an allocation failure.
(Contributed by Anthony Hurtado.)
Applied fixes and updates to the CMake build.
Adopted the REUSE Specification for licensing the CI files.
pcre2: update to 10.49.
Version 10.49 28-September-2026
-------------------------------
1. (GHSA-r9hj-j2rw-4q3m) Security fix to prevent an out-of-bounds write with
arbitrary data. Applications are only affected if using the
pcre2_jit_stack_create() and pcre2_jit_stack_assign() APIs to provide a growable
JIT stack, and then matching against a pattern with unusually high JIT stack
usage, such as a large number of capturing groups.
The implications of an out-of-bounds write could include arbitrary code
execution.
The issue is not a regression and affects releases 10.48 and earlier.