FreeBSD/ports 0e85fd3 — security/vuxml/vuln 2026.xml

security/vuxml: Document net/keycloak vulnerabilities

PR:             299044
Approved by:    osa, vvd (Mentors, implicit)
DeltaFile
+37-0security/vuxml/vuln/2026.xml
+37-01 files

FreeBSD/ports df816ab — net/keycloak Makefile distinfo

net/keycloak: Update 26.7.4 => 26.8.0

Release Notes:
https://www.keycloak.org/2026/10/keycloak-2680-released

Upgrading Notes:
https://www.keycloak.org/docs/latest/upgrading/index.html#migrating-to-26-8-0

PR:             299044
Approved by:    osa, vvd (Mentors, implicit)
Security:       CVE-2026-12388
Security:       CVE-2026-14781
Security:       CVE-2026-19608
Security:       CVE-2026-54515
Security:       CVE-2026-59889
Security:       CVE-2026-59903
MFH:            2026Q4

(cherry picked from commit 88d0de231ca6496d46b1c18d0a39cf70c0268e04)
DeltaFile
+334-323net/keycloak/pkg-plist
+3-3net/keycloak/distinfo
+1-1net/keycloak/Makefile
+338-3273 files

LLVM/project 82cb0c2 — clang/include/clang/Basic Attr.td, clang/lib/Sema SemaAPINotes.cpp

[APINotes][Unversioned] Capture presence of versioned slices separately, and track different slice groups (#224860)

## Group versioned slices by lookup

Under `-fswift-version-independent-apinotes`, Clang attaches every
APINotes slice unapplied, wrapped in `SwiftVersionedAdditionAttr` or
`SwiftVersionedRemovalAttr`, and leaves the version selection to the
client. To redo that selection the client has to know which slices
compete with each other across different APINote lookups, and nothing in
the attributes said so.

The slices a client must choose between are the ones a single *lookup*
produced, not the ones a single APINotes reader supplied. Sema runs
selection once per lookup and applies every winner, and there can be
more than one lookup for the same declaration against the same reader. A
global function with a `Where:` parameter selector gets two: the broad
lookup, and the exact one.

For example, consider module `Bar`:

    [102 lines not shown]
DeltaFile
+67-35clang/lib/Sema/SemaAPINotes.cpp
+52-0clang/test/APINotes/slice-groups-order.c
+49-2clang/include/clang/Basic/Attr.td
+41-0clang/test/APINotes/slice-groups.c
+39-0clang/test/APINotes/slice-groups-exact.c
+30-6clang/test/APINotes/versioned-version-independent.m
+278-4310 files not shown
+386-5916 files

FreeBSD/ports 88d0de2 — net/keycloak Makefile distinfo

net/keycloak: Update 26.7.4 => 26.8.0

Release Notes:
https://www.keycloak.org/2026/10/keycloak-2680-released

Upgrading Notes:
https://www.keycloak.org/docs/latest/upgrading/index.html#migrating-to-26-8-0

PR:             299044
Approved by:    osa, vvd (Mentors, implicit)
Security:       CVE-2026-12388
Security:       CVE-2026-14781
Security:       CVE-2026-19608
Security:       CVE-2026-54515
Security:       CVE-2026-59889
Security:       CVE-2026-59903
MFH:            2026Q4
DeltaFile
+334-323net/keycloak/pkg-plist
+3-3net/keycloak/distinfo
+1-1net/keycloak/Makefile
+338-3273 files

LLVM/project b31aad9 — llvm/test/CodeGen/AArch64 arm64_32-mops.ll streaming-compatible-memory-ops.ll, llvm/test/CodeGen/RISCV memmove.ll memcpy.ll

[SelectionDAG] zext/trunc size of memory libcalls to target pointer size (#226672)

Fixes #226666 

For `memcpy`, `memmove`, and `memset`, the value for the number of bytes
for the operation ("Size") used the type of the intrinsic. When the type
of Size was narrower than that of the "length" parameter of the libcall,
the value would be widened with ANY_EXTEND. On RISC-V, this can
materialize as a sign extension, which leads to writing `2^33` times as
many bytes.

Changes
- Zero-extends or truncates the Size to the target pointer width (Note
that GISel already does this correctly).
- Added new RISC-V/AArch64 tests, and updated existing ones.

Note that this also fixed an AArch64 crash. With `-mattr=+mops`, SD
crashed with any non-constant i32 length argument to one of these
libcalls with "unimplemented reg-to-reg copy"
DeltaFile
+194-0llvm/test/CodeGen/AArch64/aarch64-mops.ll
+156-0llvm/test/CodeGen/AArch64/streaming-compatible-memory-ops.ll
+125-0llvm/test/CodeGen/RISCV/memset.ll
+96-2llvm/test/CodeGen/RISCV/memcpy.ll
+74-0llvm/test/CodeGen/RISCV/memmove.ll
+55-0llvm/test/CodeGen/AArch64/arm64_32-mops.ll
+700-22 files not shown
+720-48 files

LLVM/project 69212dd — llvm/lib/Target/AArch64 AArch64TargetTransformInfo.cpp, llvm/test/Analysis/CostModel/AArch64 masked_compress_load.ll masked_expand_load.ll

[AArch64] Adjust costs for masked CompressStore and ExpandLoad (#226950)

Currently, costs for the `llvm.expand.compressstore` and
`llvm.masked.expandload` are costs simply at 2 x the type legalization
cost. However, this does not properly represent the instructions that
are generated for these intrinsics.

The costs have been adjusted to better represent the cost of using these
intrinsics with SVE Instructions.
DeltaFile
+108-108llvm/test/Analysis/CostModel/AArch64/masked_expand_load.ll
+85-85llvm/test/Analysis/CostModel/AArch64/masked_compress_load.ll
+7-3llvm/lib/Target/AArch64/AArch64TargetTransformInfo.cpp
+200-1963 files

NetBSD/src G3Pp3Uk — external/mit/lua/dist/doc lua.1

   Remove empty newline (caused HTML rendering issues)
VersionDeltaFile
1.10+1-2external/mit/lua/dist/doc/lua.1
+1-21 files

FreeBSD/doc 1cbc3cb — documentation/content/en/books/handbook/containers _index.adoc

containers: Fix duplicate tag error
DeltaFile
+1-1documentation/content/en/books/handbook/containers/_index.adoc
+1-11 files

FreeBSD/ports 621c54d — www/py-yt-dlp-ejs distinfo distinfo.aarch64

www/py-yt-dlp-ejs: fix build on arm64

distinfo os made arch-specific.
DeltaFile
+11-4www/py-yt-dlp-ejs/Makefile
+0-5www/py-yt-dlp-ejs/distinfo
+5-0www/py-yt-dlp-ejs/distinfo.aarch64
+5-0www/py-yt-dlp-ejs/distinfo.amd64
+21-94 files

FreeBSD/ports 0544f37 — finance/py-openbb-platform-api distinfo Makefile

finance/py-openbb-platform-api: update 1.3.6 → 2.0.1
DeltaFile
+4-3finance/py-openbb-platform-api/Makefile
+3-3finance/py-openbb-platform-api/distinfo
+7-62 files

FreeBSD/ports e0c74e3 — misc/py-mistral-common Makefile distinfo

misc/py-mistral-common: update 1.11.7 → 1.12.0
DeltaFile
+3-3misc/py-mistral-common/distinfo
+3-2misc/py-mistral-common/Makefile
+6-52 files

FreeBSD/ports a608dfd — www/py-lomond distinfo Makefile

www/py-lomond: update 0.3.3 → 0.3.4
DeltaFile
+12-2www/py-lomond/Makefile
+3-3www/py-lomond/distinfo
+15-52 files

FreeBSD/ports f797671 — finance/py-openbb-mcp-server distinfo Makefile

finance/py-openbb-mcp-server: update 1.4.1 → 2.0.1
DeltaFile
+7-4finance/py-openbb-mcp-server/Makefile
+3-3finance/py-openbb-mcp-server/distinfo
+10-72 files

FreeBSD/ports 1991382 — graphics/py-plotly distinfo Makefile

graphics/py-plotly: update 5.24.1 → 7.1.0

PR:             295406
Approved by:    jjachuf at gmail.com (maintainer's timeout; 4 months 12 days)
DeltaFile
+8-4graphics/py-plotly/Makefile
+3-3graphics/py-plotly/distinfo
+11-72 files

FreeBSD/ports 5062f13 — math/py-fdasrsf distinfo Makefile, math/py-fdasrsf/files patch-pyproject.toml

math/py-fdasrsf: update 2.6.10 → 2.7.2
DeltaFile
+18-6math/py-fdasrsf/Makefile
+14-0math/py-fdasrsf/files/patch-pyproject.toml
+3-3math/py-fdasrsf/distinfo
+35-93 files

FreeBSD/ports dd931fd — misc/py-fastmcp distinfo Makefile, misc/py-fastmcp-slim Makefile distinfo

misc/py-fastmcp{,-slim}: update 4.0.3 → 4.0.10
DeltaFile
+4-7misc/py-fastmcp/Makefile
+3-3misc/py-fastmcp/distinfo
+3-3misc/py-fastmcp-slim/distinfo
+1-1misc/py-fastmcp-slim/Makefile
+11-144 files

LLVM/project 2985550 — clang/test/Interpreter pretty-print.cpp

[clang-repl] Don't check printf output order in pretty-print.cpp (#228349)

The test added in #228334 checked the output of a JIT'd printf() with
CHECK-NEXT between lines that clang-repl prints itself. The C runtime
buffers the JIT'd code's stdout separately, so the order is not
guaranteed: on llvm-clang-x86_64-sie-win, "foo()" came after all of
clang-repl's output.

Remove that case. The case before it already checks that a void call
without a semicolon is executed (through the value of a variable it
sets), and so does the unit test ValueOfVoidCallExecutesTheCall.

Assisted-by: Claude Opus 5.5

Follows up on #228334, which introduced failures on Windows:

```
The Buildbot has detected a new failure on builder llvm-clang-x86_64-sie-win while building clang.


    [67 lines not shown]
DeltaFile
+0-3clang/test/Interpreter/pretty-print.cpp
+0-31 files

LLVM/project bcaabf1 — llvm/test/CodeGen/SPIRV/extensions/SPV_INTEL_inline_assembly inline_asm.ll, llvm/test/CodeGen/SPIRV/extensions/SPV_INTEL_int4 negative.ll

[NFC][SPIR-V] Fix more CHECK lines that never fire in tests (#227962)

Follow-up to #227332

FileCheck ignores these lines, so the behavior they describe was
untested

- Typo `-NO:`, `-:`, `ACHECK:` and `OpCabilitity` (discard.ll,
inline_asm.ll, intel-usm-addrspaces.ll, merge-exit-break.ll,
SPV_KHR_bit_instructions.ll)
- Invalid directive `CHECK-4` (fp-simple-hierarchy.ll)
- Prefix no RUN line enables (cl_intel_sub_groups.ll,
cl_intel_subgroup_local_block_io.ll, negative.ll)
DeltaFile
+4-4llvm/test/CodeGen/SPIRV/hlsl-intrinsics/discard.ll
+3-3llvm/test/CodeGen/SPIRV/extensions/SPV_INTEL_subgroups/cl_intel_subgroup_local_block_io.ll
+3-3llvm/test/CodeGen/SPIRV/extensions/SPV_INTEL_subgroups/cl_intel_sub_groups.ll
+3-3llvm/test/CodeGen/SPIRV/extensions/SPV_INTEL_inline_assembly/inline_asm.ll
+2-2llvm/test/CodeGen/SPIRV/extensions/SPV_INTEL_usm_storage_classes/intel-usm-addrspaces.ll
+2-2llvm/test/CodeGen/SPIRV/extensions/SPV_INTEL_int4/negative.ll
+17-173 files not shown
+20-209 files

FreeBSD/ports a739b55 — cad/freecad-devel Makefile.git_rev distinfo

cad/freecad-devel: Update to 2026.10.01
DeltaFile
+33-19cad/freecad-devel/pkg-plist
+9-9cad/freecad-devel/distinfo
+6-6cad/freecad-devel/Makefile.git_rev
+48-343 files

NetBSD/src tCCeYm7 — sys/arch/mips/mips locore.S

   Don't optimise the MIPSnnR2 case for something that happens once on
   each CPU per boot.  Makes this little block of code easier to read.
VersionDeltaFile
1.234+2-6sys/arch/mips/mips/locore.S
+2-61 files

FreeBSD/ports 651d8f6 — www/vaultwarden-web_vault Makefile distinfo

www/vaultwarden-web_vault: Update to 2026.7.0

PR:             298907
Reported by:    foudfou
DeltaFile
+3-3www/vaultwarden-web_vault/distinfo
+1-1www/vaultwarden-web_vault/Makefile
+4-42 files

FreeBSD/ports 3d3fa33 — security/vaultwarden Makefile Makefile.crates

security/vaultwarden: Update to 1.37.3

PR:             298901
Reported by:    foudfou
DeltaFile
+279-259security/vaultwarden/distinfo
+138-128security/vaultwarden/Makefile.crates
+2-2security/vaultwarden/Makefile
+419-3893 files

FreeBSD/ports 2a6f1dd — deskutils/nextcloudclient Makefile distinfo

deskutils/nextcloudclient: Update to 34.0.4
DeltaFile
+3-3deskutils/nextcloudclient/distinfo
+1-1deskutils/nextcloudclient/Makefile
+4-42 files

LLVM/project f8e3228 — llvm/lib/Target/X86 X86PreTileConfig.cpp, llvm/test/CodeGen/X86/AMX amx-fastconfig.mir amx-fastconfig-spill.mir

X86: Mark the tile register defs of PLDTILECFGV dead (#227602)

ldtilecfg invalidates all tile registers, which the pseudo models by
listing them in Defs. Nothing reads them from the configuration
instruction itself, so mark them dead where the pseudo is built instead
of leaving it to be re-inferred.

Co-authored-by: Claude Opus 5 <noreply at anthropic.com>
DeltaFile
+11-11llvm/test/CodeGen/X86/AMX/amx-fastconfig-phi.mir
+5-5llvm/test/CodeGen/X86/AMX/amx-fastconfig-phi4.mir
+4-4llvm/test/CodeGen/X86/AMX/amx-fastconfig-spill.mir
+4-4llvm/test/CodeGen/X86/AMX/amx-fastconfig-phi2.mir
+3-3llvm/test/CodeGen/X86/AMX/amx-fastconfig.mir
+2-1llvm/lib/Target/X86/X86PreTileConfig.cpp
+29-282 files not shown
+31-298 files

LLVM/project 6247c91 — llvm/include/llvm/CodeGen SjLjEHPrepare.h, llvm/include/llvm/Target TargetMachine.h

Triple: Move getSjLjDataSize off TargetMachine

This eliminates the TargetMachine dependence of SjLjEHPrepare.
The pass had the questionable behavior of just proceeding with the
default size without a TargetMachine. VE is the only user and changes
the integer bitwidth used, and this doesn't seem worthwhile of a
virtual function. Move to the triple in keeping with migrating
ABI parameters out of codegen.

Co-authored-by: Claude (Claude-Opus-4.8) <noreply at anthropic.com>
DeltaFile
+5-11llvm/lib/CodeGen/SjLjEHPrepare.cpp
+6-0llvm/lib/TargetParser/Triple.cpp
+0-5llvm/include/llvm/CodeGen/SjLjEHPrepare.h
+0-4llvm/include/llvm/Target/TargetMachine.h
+4-0llvm/include/llvm/TargetParser/Triple.h
+0-2llvm/lib/Target/VE/VETargetMachine.h
+15-224 files not shown
+19-2610 files

LLVM/project 02ff559 — llvm/lib/Target/PowerPC PPCInstrVSX.td PPCInstrInfo.td

[PowerPC] Correct the SDTypeProfile for VECSHL and FP_EXTEND_HALF. (#228341)

These used SDTCisPtrTy, but the operand is always created with i32 type.
DeltaFile
+1-1llvm/lib/Target/PowerPC/PPCInstrVSX.td
+1-1llvm/lib/Target/PowerPC/PPCInstrInfo.td
+2-22 files

LLVM/project db412aa — llvm/lib/Target/Mips MipsSEISelLowering.cpp

[Mips] Convert index to pointer type in lowerMSACopyIntr. (#228332)

The MipsISD::VEXTRACT_[SZ]EXT_ELT nodes expect a pointer sized index.

Found while trying to implement SDTCisPtrTy checking in verifySDNode.
DeltaFile
+3-1llvm/lib/Target/Mips/MipsSEISelLowering.cpp
+3-11 files

FreeBSD/ports d86b02d — . UPDATING, www/nginx-devel Makefile.options.desc Makefile

www/nginx-devel: Follow the OpenSSL port rename

security/openssl35 is now security/openssl.

Sponsored by:   Netzkommune GmbH
DeltaFile
+7-7www/nginx-devel/Makefile
+12-0UPDATING
+1-1www/nginx-devel/Makefile.options.desc
+20-83 files

LLVM/project 9bb435a — llvm/bindings/ocaml/llvm llvm_ocaml.c, llvm/bindings/ocaml/target target_ocaml.c

[llvm-c][ocaml] Move DataLayout bindings from Target to Core/IR (#227714)

DataLayout is part of IR (or "Core" in C API terminology), so bindings
for it should be defined there as well. They were part of Target for
historical reasons.

This is to avoid any layering issues with referencing DataLayout from IR
APIs.
DeltaFile
+6-126llvm/include/llvm-c/Target.h
+129-0llvm/include/llvm-c/Core.h
+0-117llvm/bindings/ocaml/target/target_ocaml.c
+114-0llvm/bindings/ocaml/llvm/llvm_ocaml.c
+0-97llvm/lib/Target/Target.cpp
+94-0llvm/lib/IR/Core.cpp
+343-34015 files not shown
+481-46521 files

NetBSD/pkgsrc cCcH3hf — doc CHANGES-2026

   doc: Updated finance/rex to 0.3.0
VersionDeltaFile
1.6589+2-1doc/CHANGES-2026
+2-11 files