FreeBSD/ports 26b8135 — graphics/embree3 Makefile, math/fastops Makefile

graphics/embree3: try to fix the build against CMake 4.x

While here, add forgotten type annotation in the similar
commit made to `math/fastops' port earlier.

PR:     299180
Fixes:  fa07c9073bc9
DeltaFile
+1-1math/fastops/Makefile
+1-0graphics/embree3/Makefile
+2-12 files

FreeBSD/src ef78a88 — . misc-agent.c ed25519.sh, openbsd-compat port-linux-selinux.c

Vendor import of OpenSSH 10.6p1

Sponsored by:   The FreeBSD Foundation
DeltaFile
+4,598-1,983ed25519.c
+1,277-1,052ChangeLog
+279-261configure
+256-165ed25519.sh
+191-65misc-agent.c
+243-0openbsd-compat/port-linux-selinux.c
+6,844-3,526127 files not shown
+9,000-4,999133 files

FreeBSD/src 77a7a48 — sys/fs/nfs nfs_var.h, sys/fs/nfsclient nfs_clrpcops.c nfs_clcomsubs.c

nfscl: Fix oddball cases for session slot release

We have identified some cases where silent slot loss can occur
when operations on NFS mounts are aborted. We experience this
when using NFSv4.2, but it likely also occurs with NFSv4.1.

A slot is acquired for compound operations by nfsv4_setsequence()
and freed by newnfs_request(). Any call path that abandons the
compound before reaching newnfs_request() loses the slot permanently.

We identified four call sites where this happens, one of
which where it actually does happen for us in a semi-reproducible
way, which allowed us to develop a candidate patch, attached.

The patch adds one function, nfsv4_freeunsentslot(), to
nfs_clcomsubs.c. It is called from each of the four call
sites: nfsrpc_writerpc(), nfsrpc_writeds(), and two in
nfsrpc_setextattr().


    [11 lines not shown]
DeltaFile
+18-0sys/fs/nfsclient/nfs_clcomsubs.c
+4-0sys/fs/nfsclient/nfs_clrpcops.c
+2-0sys/fs/nfs/nfs_var.h
+24-03 files

LLVM/project 1701550 — llvm/lib/Target/AMDGPU GCNHazardRecognizer.cpp, llvm/test/CodeGen/AMDGPU wmma-coexecution-valu-hazards.mir

[AMDGPU] Fix missed WMMA C-operand co-exec hazard

The gfx1250 WMMA co-execution hazard check treats only A, B and the
SWMMAC index as registers the in-flight MMA still reads. C (src2 of a
non-SWMMAC WMMA) is missing, so a VALU scheduled into the MMA's shadow
can clobber C and the MMA consumes the new value.

This is latent while C is tied to vdst, since the existing D check then
covers it. It miscompiles where the tie does not hold: for
v_wmma_bf16f32_16x16x32_bf16, whose D is narrower than C, and for the
_threeaddr form of any WMMA.
DeltaFile
+171-2llvm/test/CodeGen/AMDGPU/wmma-coexecution-valu-hazards.mir
+3-4llvm/lib/Target/AMDGPU/GCNHazardRecognizer.cpp
+174-62 files

FreeBSD/ports f5130e2 — www/mod_evasive pkg-descr pkg-message, www/mod_evasive/files patch-test.pl patch-mod__evasive24.c

www/mod_evasive: update to version 2.4.0

New mod_evasive port from https://github.com/jvdmr/mod_evasive
that is actively maintained.

PR:     251261
DeltaFile
+23-23www/mod_evasive/Makefile
+42-0www/mod_evasive/files/patch-mod__evasive24.c
+16-0www/mod_evasive/pkg-message
+13-0www/mod_evasive/files/99_regular_config_pf/mod_evasive.conf
+0-11www/mod_evasive/files/patch-test.pl
+4-5www/mod_evasive/pkg-descr
+98-392 files not shown
+105-428 files

FreeBSD/ports 76e33ab — www/mod_evasive Makefile

www/mod_evasive: new maintainer

New maintainer for mod_evasive

PR:     251261
DeltaFile
+1-1www/mod_evasive/Makefile
+1-11 files

LLVM/project 0cbdbd9 — llvm/lib/Transforms/Utils SimplifyLibCalls.cpp, llvm/test/Transforms/InstCombine math-odd-even-parity.ll

[InstCombine] Treat `asin`, `asinh`, `atan` and `cbrt` as odd-functions (#227336)

Add `asin`, `asinh`, `atan` and `cbrt` into the odd-functions list. They
should be treated as odd-functions now.

For #227011
DeltaFile
+87-0llvm/test/Transforms/InstCombine/math-odd-even-parity.ll
+16-0llvm/lib/Transforms/Utils/SimplifyLibCalls.cpp
+103-02 files

FreeBSD/ports 9e79524 — java/dbvis Makefile distinfo

java/dbvis: Update 26.2.2 => 26.2.3

Release Notes:
https://www.dbvis.com/releasenotes/26.2/

Sponsored by:   UNIS Labs
MFH:            2026Q4

(cherry picked from commit a4712c2fce03347199830e6ddd9d399f430836bb)
DeltaFile
+3-3java/dbvis/distinfo
+1-1java/dbvis/Makefile
+4-42 files

FreeBSD/src 192781b — lib/libthr/thread thr_mutex.c

libthr: Consume error in check_and_init_mutex

MFC after:      2 weeks
DeltaFile
+1-1lib/libthr/thread/thr_mutex.c
+1-11 files

FreeBSD/ports a4712c2 — java/dbvis Makefile distinfo

java/dbvis: Update 26.2.2 => 26.2.3

Release Notes:
https://www.dbvis.com/releasenotes/26.2/

Sponsored by:   UNIS Labs
MFH:            2026Q4
DeltaFile
+3-3java/dbvis/distinfo
+1-1java/dbvis/Makefile
+4-42 files

DragonFlyBSD/src 3f39eb0 — etc/defaults make.conf, libexec/ssh-keysign Makefile

make.conf: Delete the mislabeled ENABLE_SUID_SSH knob

This knob actually controlled the SUID bit of libexec/ssh-keysign, which
is needed for host-based authentication, and it actually requires the
SUID permission to work.

So just remove the ENABLE_SUID_SSH knob and always install ssh-keysign
with SUID.  While there, explicitly set BINOWN=root and change BINMODE
to 4555, following both FreeBSD and OpenBSD.

Obtained-from: FreeBSD (commit 0041e47595fad8de5f6c3fd28522e4aa14eef32a)
DeltaFile
+1-6share/man/man5/make.conf.5
+3-3libexec/ssh-keysign/Makefile
+0-3etc/defaults/make.conf
+4-123 files

FreeBSD/src 657c089 — lib/lib80211 lib80211_regdomain.c

lib80211: fix build with eXpat 2.9.0

eXpat 2.9.0 deprecates XML_GetCurrentLineNumber() in favour of
XML_GetCurrentLineNumber64().  The new function behaves the same
as the old one but is not prone to 32 bit integer wrap-around.
DeltaFile
+27-26lib/lib80211/lib80211_regdomain.c
+27-261 files

FreeBSD/src 22c3edb — contrib/expat Changes, contrib/expat/doc reference.html

contrib/expat: import expat 2.9.0

Changes: https://github.com/libexpat/libexpat/blob/R_2_9_0/expat/Changes

Security:       CVE-2026-102633
Security:       CVE-2026-77214
MFC after:      3 days
DeltaFile
+790-0contrib/expat/tests/props_tests.c
+681-73contrib/expat/doc/reference.html
+413-154contrib/expat/lib/xmlparse.c
+56-220contrib/expat/lib/xmltok.c
+131-39contrib/expat/tests/basic_tests.c
+102-26contrib/expat/Changes
+2,173-51247 files not shown
+2,984-86753 files

LLVM/project 0997812 — llvm/lib/CodeGen MachineOutliner.cpp, llvm/test/CodeGen/AArch64 machine-outliner-call-debugloc.mir

[MachineOutliner] Attribute outlined calls to the candidate's last call (#229260)

An outlined call stands in for a whole candidate but can carry only one
debug location, so no choice is correct for every instruction it
replaces. Prioritize the location that keeps unwinding as if the code
were not outlined: a return address is symbolized at the preceding
instruction, so unwinding through a call in the candidate resolves the
caller frame at the outlined call. Using the candidate's first location
could attribute that frame to an unrelated inlined callee, as seen in
ASan reports.

Prefer the last call's location. A candidate ending in a call may be
outlined as a thunk whose tail call returns directly past the outlined
call, making the backtrace match the unoutlined code exactly. With
multiple calls, the location can still be exact for only one of them.

Keep the first location when the candidate has no call, its last call
has no line, or the replacement is a tail branch that nothing returns
to.

Follow-up to llvm/llvm-project#224189.
DeltaFile
+46-4llvm/test/CodeGen/AArch64/machine-outliner-call-debugloc.mir
+22-10llvm/lib/CodeGen/MachineOutliner.cpp
+68-142 files

NetBSD/src DpAfWgR — share/mk bsd.own.mk

   bsd.own.mk: Respect USE_FORT even if defined after bsd.own.mk.

   Using (a chain of logic that boils down to)

   .if ${USE_FORT:Uno} != "no"
   CPPFLAGS+=   -D_FORTIFY_SOURCE=2
   .endif

   expands USE_FORT eagerly, so if USE_FORT was not already defined before
   including <bsd.own.mk>, it's too late after.

   Using (a chain of logic that boils down to)

   CPPFLAGS+=   ${${USE_FORT:Uno} != "no":?-D_FORTIFY_SOURCE=2:}

   expands USE_FORT lazily, so it's only when CPPFLAGS itself is expanded
   -- usually in a recipe, after all variable assignments, prerequisite
   lists, and .directives have been processed -- that USE_FORT is
   expanded.

    [9 lines not shown]
VersionDeltaFile
1.1488+2-4share/mk/bsd.own.mk
+2-41 files

LLVM/project 13d5a13 — llvm/lib/CodeGen/AsmPrinter AsmPrinter.cpp, llvm/test/CodeGen/ARM call-graph-section-assembly.ll

[AsmPrinter] Fix direct callee operand lookup in CallGraphSection (#218534)

In handleCallsiteForCallgraph, direct callee operand was assumed to
always be at index 0 (MI.getOperand(0)). While true for x86_64, on
ARM Thumb/Thumb-2 (e.g. tBL), operand 0 represent predicate condition
code not the callee operand. Use getCalleeOperand to correctly retrieve
the operand.

Assisted-by: Gemini
DeltaFile
+2-1llvm/lib/CodeGen/AsmPrinter/AsmPrinter.cpp
+2-0llvm/test/CodeGen/ARM/call-graph-section-assembly.ll
+4-12 files

NetBSD/src PjIc8Yu — lib/libc shlib_version

   libc: Add a note to shlib_version about nixing __ssp_protected_*.

   PR lib/60858: fortuitous embarrassment: fortify is all kinds of busted
VersionDeltaFile
1.302+2-1lib/libc/shlib_version
+2-11 files

NetBSD/src NUwjChS — include/ssp ssp.h, lib/libc/ssp ssp_redirect.c

   ssp.h: Stop creating references to useless __ssp_protected_* symbols.

   The ssp wrappers are useful _only_ when they are actually used for
   inline function call expansion; if the function is used for anything
   else like a function pointer, only the underlying library symbol
   should be used.

   To pacify linker complaints about spurious references to
   __ssp_protected_getcwd/read/readlink, we added equally spurious
   definitions of those symbols to libc without understanding why; it
   turns out it only happened because the ssp wrappers declared, e.g.:

   extern inline read(...) __RENAME(__ssp_protected_read);
   extern inline read(...) { <ssp check>; return __ssp_real_read(...); }

   The declaration with __RENAME caused the compiler to generate
   references, required by the linker to be resolved, to the symbol
   `__ssp_protected_read' when compiling code that takes the address of
   the function read() to pass around a function pointer.  Instead, the

    [15 lines not shown]
VersionDeltaFile
1.4+42-18lib/libc/ssp/ssp_redirect.c
1.17+1-2include/ssp/ssp.h
+43-202 files

LLVM/project 0cdc8ce — llvm/test/tools/llvm-ar zos-symattrs.test

Fix test
DeltaFile
+1-1llvm/test/tools/llvm-ar/zos-symattrs.test
+1-11 files

Linux/linux 602042b — kernel workqueue.c

Merge tag 'wq-for-7.3-rc6-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/wq

Pull workqueue fixes from Tejun Heo:

 - Fix a NULL dereference in the chained work check when a kworker
   queues work on a draining or destroying workqueue outside work item
   execution.

* tag 'wq-for-7.3-rc6-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/wq:
  workqueue: Fix NULL current_pwq deref in chained work check
DeltaFile
+1-1kernel/workqueue.c
+1-11 files

LLVM/project 6e19e16 — clang/lib/StaticAnalyzer/Checkers/WebKit RawPtrRefSafetyModel.h RawPtrRefLambdaCapturesChecker.cpp, clang/test/Analysis/Checkers/WebKit unborrowed-local-vars.cpp

[WebKit Checkers] Allow a view into a temporary CanBorrow prvalue without a Borrow<T> (#229495)

Common example:

```
for (auto& x : copyToVector(y)) {
}
```

This is safe without any explicit Borrow<T> because it is syntactically
impossible to name the Vector, so we must have exclusive access to it,
with no other pointers/references/views that can invalidate it.

The one edge case to consider is that the iterator itself might hold a
pointer to the Vector, and vend an API that can invalidate the Vector.
(A pre-existing regression test covers this case.)

To decide that, `isSafeExpr` now also receives the sink type (the type
of the variable, parameter, or lambda capture that receives the value)

    [2 lines not shown]
DeltaFile
+50-4clang/lib/StaticAnalyzer/Checkers/WebKit/RawPtrRefSafetyModel.cpp
+23-1clang/test/Analysis/Checkers/WebKit/unborrowed-local-vars.cpp
+9-6clang/lib/StaticAnalyzer/Checkers/WebKit/RawPtrRefCallArgsChecker.cpp
+7-4clang/lib/StaticAnalyzer/Checkers/WebKit/RawPtrRefLocalVarsChecker.cpp
+6-3clang/lib/StaticAnalyzer/Checkers/WebKit/RawPtrRefLambdaCapturesChecker.cpp
+4-2clang/lib/StaticAnalyzer/Checkers/WebKit/RawPtrRefSafetyModel.h
+99-201 files not shown
+99-217 files

Linux/linux 0d32b3e — kernel/cgroup cpuset.c

Merge tag 'cgroup-for-7.3-rc6-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/cgroup

Pull cgroup fixes from Tejun Heo:

 - During CPU offline, the active mask drops the CPU before cpuset
   updates the effective CPUs, so a task placement in that window could
   find no active CPU in the top cpuset and dereference NULL. Restore
   the NULL check.

 - The cpuset v2-mode test read the subsystem's root pointer, which is
   stale during a cgroup filesystem rebind, and the hotplug handler
   evaluated it before taking the cpuset mutex. Record the mode in a
   flag and test it under the mutex.

* tag 'cgroup-for-7.3-rc6-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/cgroup:
  cgroup/cpuset: Call is_in_v2_mode() after acquiring cpuset_mutex in cpuset_handle_hotplug()
  cgroup/cpuset: Handle cpu hotplug race in guarantee_active_cpus()
  cgroup/cpuset: Don't access cpuset_cgrp_subsys.root in is_in_v2_mode()
DeltaFile
+32-8kernel/cgroup/cpuset.c
+32-81 files

NetBSD/pkgsrc CFufFrb — doc CHANGES-2026

   Note the addition of editors/eh, version 1.9.0, to the packages collection.
VersionDeltaFile
1.6747+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc ikqLWfi — editors Makefile, editors/eh PLIST distinfo

   Add and enable editors/eh, version 1.9.0, to the packages collection

        A minimalist version of vi(1).  It is an example of the "Buffer Gap"
        method outlined in the The Craft Of Text Editing used by many Emacs
        style editors.

        Create or read a text file to edit.  Text files consists of lines of
        printable UTF-8 text, tabs, or newline characters.  A physical line
        can be of arbitrary length and is delimited by either a newline or the
        end of file.  Tab stops are every eight columns.  The behaviour of
        non-printable characters may vary depending on the implementation of
        the Curses library, stty(1) settings, or terminal emulator.

   eh was the winner of IOCCC28, catalogued as 2024/howe
VersionDeltaFile
1.1+35-0editors/eh/Makefile
1.1+10-0editors/eh/DESCR
1.1+5-0editors/eh/distinfo
1.271+2-1editors/Makefile
1.1+2-0editors/eh/PLIST
+54-15 files

LLVM/project 03302cd — llvm/lib/Target/RISCV RISCVInstrInfo.cpp, llvm/test/CodeGen/RISCV machine-sink-jumptable-edge-split.ll

[RISCV] Add Xqcisls loads to getJumpTableIndex (#229006)
DeltaFile
+88-0llvm/test/CodeGen/RISCV/machine-sink-jumptable-edge-split.ll
+1-0llvm/lib/Target/RISCV/RISCVInstrInfo.cpp
+89-02 files

LLVM/project b46a38c — clang/lib/CIR/CodeGen CIRGenDecl.cpp CIRGenModule.cpp, clang/test/CIR/CodeGen unions-with-zero-init.cpp member-pointer-null-init.cpp

[CIR] Correct 'null' init for array types with non-zero init (#229543)

The member pointers are supposed to be initialized to -1, so an array of
them or a record of them needs to be initialized properly to -1. This
patch makes sure we look through array types/etc to get the correct
initialization.

Also, quite a few places were using 'getZeroAttr' when they meant 'null
init', so this changes that as well.
DeltaFile
+50-4clang/test/CIR/CodeGen/member-pointer-null-init.cpp
+17-4clang/lib/CIR/CodeGen/CIRGenExprConstant.cpp
+2-7clang/test/CIR/CodeGen/unions-with-zero-init.cpp
+2-2clang/lib/CIR/CodeGen/CIRGenModule.cpp
+3-1clang/lib/CIR/CodeGen/CIRGenTypes.cpp
+1-1clang/lib/CIR/CodeGen/CIRGenDecl.cpp
+75-196 files

LLVM/project 4a5b1cd — llvm/lib/Target/RISCV RISCVFrameLowering.cpp

[RISCV][NFC] Simplify isSupportedStackID (#229117)

The switch case approach meant that we had to add a case every time a
new `TargetStackID` gets added. The original switch was added in
https://reviews.llvm.org/D94465 at which time I guess we had only a few
valid cases.
DeltaFile
+1-12llvm/lib/Target/RISCV/RISCVFrameLowering.cpp
+1-121 files

LLVM/project dfc6aa6 — clang/lib/CIR/CodeGen CIRGenStmt.cpp, clang/test/CIR/CodeGen non-odr-use-const-bool.cpp requires-expr.cpp

[CIR] Skip 'dead' branches when emitting an 'if' statement (#229553)

At one point, we actively decided not to skip these, as it would
possibly be useful for static-analysis. However, we're finding that this
is actually taken advantage of in quite a few places (particularly
    things that call undefined things in the false branch), so we are
going revert our previous decision and do the FE level omission.

This functionality could potentially be restored in the future, but we
probably would want a CIRSimplify patch to do the dead-branch
elimination that runs all the time, but that would require better
constant folding in CIR.
DeltaFile
+47-0clang/test/CIR/CodeGen/if.cpp
+16-30clang/test/CIR/CodeGen/requires-expr.cpp
+36-3clang/test/CIR/CodeGen/non-odr-use-const-bool.cpp
+6-24clang/test/CIR/CodeGenBuiltins/builtin-trivally-copyable.cpp
+12-8clang/lib/CIR/CodeGen/CIRGenStmt.cpp
+0-17clang/test/CIR/CodeGenBuiltins/builtin-types-compatible.c
+117-826 files

Linux/linux 762122d — kernel/sched sched.h, kernel/sched/ext internal.h inlines.h

Merge tag 'sched_ext-for-7.3-rc6-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/tj/sched_ext

Pull sched_ext fixes from Tejun Heo:

 - Taking a CPU offline could hang, or stall until the watchdog ejected
   the BPF scheduler, when tasks on the dying CPU were still held by the
   scheduler or sitting on a user dispatch queue. Re-enqueue them onto
   the local queue when the runqueue goes offline so that the CPU pushes
   them off like the other sched classes.

 - The sequence number guarding against stale dispatches was per
   runqueue, so a task re-enqueued on another CPU could get the same
   number and a dispatch meant for its earlier instance was applied to
   the new one. Use a per-task counter.

 - A task dispatched to another CPU's local queue got its ops.dequeue()
   only when picked to run and flagged as a core-sched pick. Call it at
   insertion like for same-CPU dispatches.


    [5 lines not shown]
DeltaFile
+270-0tools/testing/selftests/sched_ext/dequeue_remote.bpf.c
+204-0tools/testing/selftests/sched_ext/dequeue_remote.c
+37-9kernel/sched/ext/ext.c
+7-1kernel/sched/ext/inlines.h
+3-3kernel/sched/sched.h
+5-0kernel/sched/ext/internal.h
+526-133 files not shown
+528-179 files

FreeBSD/src 9af3990 — contrib/netbsd-tests/lib/librt t_sem.c

sem test: avoid ETIMEDOUT races in the EINTR test cases

timedwait and clockwait_absolute_intr_remaining arm a 50ms SIGALRM and then
wait until an absolute deadline only 100ms in the future.
On a loaded VM the signal can be delivered more than 50ms late, so the wait
times out first.

Approved by:    imp
Sponsored by:   Netflix
Differential Revision:  https://reviews.freebsd.org/D60347
DeltaFile
+10-2contrib/netbsd-tests/lib/librt/t_sem.c
+10-21 files