powerpc/radix: fix double page offset in mmu_radix_sync_icache()
mmu_radix_sync_icache() adds the offset of va within its page to the
physical address it gets from mmu_radix_extract_locked(). That address
already includes the offset - the extract routines return the physical
address of the byte, not of the frame - so the offset is counted twice
and __syncicache() is handed frame + 2 * offset.
The hash MMU counterpart, moea64_sync_icache(), has to add the offset
because PVO_PADDR() yields only the frame. Here the addition is wrong.
Fixes: 6f0b2a235a13 ("powerpc/pmap: Add pmap_sync_icache() for radix pmap")
Reviewed by: jhibbits
MFC after: 1 week
Differential Revision: https://reviews.freebsd.org/D59870
(cherry picked from commit 9d0859637f99160e17b656df153effae3df31f8b)
(cherry picked from commit 107212618921492ffed84d6ea3c9a27c77aaf725)
sys/powerpc/powerpc/elf64_machdep.c: enable ASLR on ELFv2
Turns out that ever since introducing ELFv2 support, it was missing
ASLR, it was only used for ELFv1 processes.
Reviewed by: jhibbits (via IRC #powerpc64)
MFC after: 1 week
(cherry picked from commit 30ed27ff2556c591a1791105d1dfe7464d3f5b80)
(cherry picked from commit edb560a7ccd69440e3bcd3e00ad9b347328f1be3)
powerpc/radix: fix double page offset in mmu_radix_sync_icache()
mmu_radix_sync_icache() adds the offset of va within its page to the
physical address it gets from mmu_radix_extract_locked(). That address
already includes the offset - the extract routines return the physical
address of the byte, not of the frame - so the offset is counted twice
and __syncicache() is handed frame + 2 * offset.
The hash MMU counterpart, moea64_sync_icache(), has to add the offset
because PVO_PADDR() yields only the frame. Here the addition is wrong.
Fixes: 6f0b2a235a13 ("powerpc/pmap: Add pmap_sync_icache() for radix pmap")
Reviewed by: jhibbits
MFC after: 1 week
Differential Revision: https://reviews.freebsd.org/D59870
(cherry picked from commit 9d0859637f99160e17b656df153effae3df31f8b)
sys/powerpc/powerpc/elf64_machdep.c: enable ASLR on ELFv2
Turns out that ever since introducing ELFv2 support, it was missing
ASLR, it was only used for ELFv1 processes.
Reviewed by: jhibbits (via IRC #powerpc64)
MFC after: 1 week
(cherry picked from commit 30ed27ff2556c591a1791105d1dfe7464d3f5b80)
TwoAddressInstructions: Use a range loop to move the copy chain (#227296)
Cleanup some messy iterator work.
Co-authored-by: Claude Opus 5 <noreply at anthropic.com>
[CodeGenPrepare] don't promote sdiv/srem by -1 (#218737)
`store-extract` promotion was widening sdiv/srem to the vector type
without checking if thats safe or not... and INT_MIN lane / -1 is UB.
skip sdiv/srem by -1 in `shouldPromote`, rest still promotes fine.
Fixes #218570
[clang][bytecode] Move past-end check into CheckFinalLoad (#227181)
It makes more sense there. Also remove the one of for non-const
pointers, since that one isn't needed anymore
lang/babashka: Update to 1.13.225
Changes since 1.13.224:
1.13.225 (2026-09-28)
* #2170: Read the docstring and :org.babashka/cli metadata of a var
as :exec-fn or :fn in a task :cmd tree
* #2170: A :doc in a task handler's :org.babashka/cli metadata takes
precedence over its docstring
* Run BABASHKA_PRELOADS before resolving bb.edn dependencies
* Add org.jline.terminal.Terminal$Signal and allow reify of
org.jline.terminal.Terminal$SignalHandler
* Add org.jsoup.nodes.Document$OutputSettings
* Bump jline to 4.4.6
* Bump rewrite-clj to 1.3.58
[LAA] Honor no-wrap predicates already in PSE in isNoWrap (#226430)
getPtrStride checks pointer wrapping assuming PSE's predicate holds.
Before #203787, isNoWrap used `PSE.hasNoOverflow` to see NUSW flags
recorded by `setNoOverflow`. Removing that bookkeeping made queries that
cannot add predicates accept only static no-wrap facts, ignoring NUSW
predicates LAA already added for the pointer.
LoopLoadElimination's `isDependenceDistanceOfOne` makes these queries
for each forwarding candidate's load and store. A pointer needing a wrap
predicate (e.g. a non-inbounds GEP where null is valid) is rejected with
"Pointer may wrap", although dependence analysis already added the
predicate and LLE versions the loop on all PSE predicates. Recurrences
such as `A[i] -= B[i-1] * A[i-1]` then reload `A[i-1]` each iteration
instead of reusing the stored value.
When isNoWrap cannot add predicates, check whether PSE's predicate
implies the AddRec's NUSW wrap predicate. Callers allowed to add
predicates are unchanged: they collect it, and adding an implied
[16 lines not shown]
X86: Respect the exception model module flag in X86LFIRewritePass
This is preparation for removing the TargetOptions ExceptionModel field.
Currently this doesn't show an observable behavior change because the
codegen pass pipeline is driven by this field. Add the module flag based
check so in the future, if the pass runs on a module not using sjlj, it
will skip the sjlj specific handling.
Co-Authored-By: Claude Opus 5 <noreply at anthropic.com>
[Hexagon] Fix hwloop trip count for post-increment load induction (#225411)
A pointer-chasing loop whose exit test is a null check was miscompiled
into a hardware loop with a bogus trip count.
A post-increment load defines two registers:
%3, %11 = L2_loadri_pi %1(tied-def 1), 4
%11 is the incremented address (tied to the base), but %3 is the value
loaded from memory, which bears no relation to the base. The helper only
checked that the base register is defined by the PHI, never that the
register feeding the PHI back from the latch is the incremented address.
Here the PHI is fed by %3 -- so the loop was treated as bumping its
induction variable by a constant 4 per iteration, and getLoopTripCount
derived a count from the numeric value of head.
Require that the register feeding the PHI is the post-incremented
address, located through the base operand's tie rather than a fixed
operand index: the tied def is operand 1 for loads (L2_loadri_pi,
V6_vL32b_pi) but operand 0 for stores (S2_storeri_pi, V6_vS32b_pi), and
[4 lines not shown]
TwoAddressInstructions: Use the per-operand early clobber flag for tied copies (#227581)
The live interval update for the copy inserted for a tied operand ended
the new segment at getRegSlot(IsEarlyClobber), using a flag computed
once per instruction for any tied pairs. Use the flag
of the def actually being processed.
With an inline asm mixing "=&r" and "=r" outputs tied to the same input,
the copy for the plain def ended at the early clobber slot, leaving a
hole before its own def. That splits the live range into multiple
connected components and asserts in updatePressureDiffs.
Co-authored-by: Claude Opus 5 <noreply at anthropic.com>
[IR][ADT] Update ValueHandle PrevPtr via move constructor (NFC) (#227484)
In LLVMContextImpl::ValueHandles, the first ValueHandleBase node's
PrevPtr points directly to the head pointer inside the DenseMap
bucket, so relocating a bucket invalidates that PrevPtr.
This patch wraps the head pointer in ValueHandleHead, whose move
constructor updates Head->setPrevPtr(&Head) whenever a bucket is
relocated by grow() or erase(). Specifically, this allows us to:
- Simplify ValueHandleBase::AddToUseList by removing the manual
reallocation check and linear fixup loop after insertion.
- Use the standard one-argument Handles.erase(getValPtr()) in
ValueHandleBase::RemoveFromUseList instead of the private callback
erase, addressing the TODO there.
- Remove friend class ValueHandleBase, the two-argument callback
erase(Key, OnMoved), and the OnMoved callback parameter on
[2 lines not shown]
pf: Prevent pf dropping TCP state with crafted reset packet.
Revision 1.1212 of pf.c weakened the TCP reset check in stateful
connection tracking to let legitimate resets pass in the backwards
window. Such a reset is accepted only if its acknowledgment number
matches perfectly. But as a workaround for broken stacks, pf
replaces an acknowledgment number of 0 in a reset with the tracked
sequence of the peer. Then the perfect match always succeeds, and
an attacker can spoof resets more easily than intended. Use the
acknowledgment number from the wire, before the workaround has
modified it.
discovered by Minghao Zhang; OK sashan@
Obtained from: OpenBSD, bluhm <bluhm at openbsd.org>, 1e0a1f4b82
Sponsored by: Rubicon Communications, LLC ("Netgate")
pf: allows TCP RST packets in the backwards window if ACK matches
TCP reset packets are generated for the sequence numbers that have
been acknowledged. Our pf(4) is quite strict regarding sequence
numbers of reset packets to avoid evil connection drops. It expected
exact match and did not allow a sequence window for resets. As pf
tracks neither gaps in the sequence space nor the acknowledged data,
it does not know where exactly the reset is expected by the TCP
stack.
Problem was that legit reset packets before a gap but not at the
highest sequence numbers were blocked by pf. Solution is to fix
pf_tcp_track_full(). Now it allows sequence number windows if the
packet has ACK+RST flags set and the acknowlege number matches
perfectly. This still prevents reset number guessing by an attacker.
Curiously the TCP stack behaves correctly and accepts only resets
before the gap. pf only allowed resets after the final data. So
any reset was ignored by the system. When the other side processed
[7 lines not shown]
[LoopIdiom] Fix 64-to-32-bit stride truncation in strlen idiom recognition (#227406)
This patch fixes a silent miscompile where loops with massive strides
(e.g., 0x100000001 or 0x2000000000000001) were incorrectly optimized
into strlen calls.
Previously, getZExtValue() was truncated to a 32-bit unsigned integer,
causing some massive strides to appear as a stride of 1. Furthermore,
the OpWidth check relied on multiplication (StepSize * 8), which is
vulnerable to 64-bit integer overflow.
By upgrading StepSize to uint64_t and using division (OpWidth / 8), we
ensure the optimization is safely aborted for massive strides without
risking arithmetic overflow.
[mlir][affine] Fix crash when rolling back vectorization of reduction loops (#226912)
Reductions introduce operations outside of the created loop, that are
users of said loop. When rolling back (e.g. when an op inside the loop
being vectorized is not vectorizable), only the created loop is deleted,
which leads to the error: “operation destroyed but still has uses”.
This PR fixes this by recursively deleting users of the newly created
loop before removing it when rolling back.
py-setuptools-gettext: updated to 0.1.19
0.1.19
Add support for package-based installation
Require setuptools>=69.0 for setuptools.modified
Use bool for install_mo.force to match Command base type
Various dev-dependency bumps (ruff, mypy)
py-wrapt: updated to 2.5.0
2.5.0
New Features
Added with_doc, a decorator for overriding the docstring that help(), pydoc and other introspection tools see for a wrapped callable without mutating the wrapped function itself. It is the companion of with_signature. The docstring can be supplied directly, or as a factory callable that derives it from the wrapped function at decoration time. When stacked above with_signature the factory sees the overridden signature and can embed it in the docstring. Assigning to __doc__ on the resulting wrapper replaces the override, and deleting it restores delegation to the wrapped function. Previously the only option was to assign to __doc__ on a wrapper, which writes through to the wrapped function since __doc__ on every proxy delegates to the wrapped object, and so changed what was reported for the wrapped function everywhere. The override is handled for instance methods, class methods and static methods, and propagates through outer wrapt decorators stacked on top. See the “Docstring Override” section of Bundled Decorators for details.
with_signature now accepts a doc argument for overriding the docstring at the same time as the signature, and the factory callable may return a tuple of (signature_or_prototype, docstring) so that a single factory can derive both from the wrapped function in one pass. When doc is supplied, the docstring from the tuple is ignored. When neither is given, __doc__ continues to delegate to the wrapped function as before, including for assignment and deletion.
A class derived from wrapt.BaseObjectProxy may now define __doc__ as a property, or other descriptor, in its class body, and that is used for instances of the class in place of the default delegation of __doc__ to the wrapped object. This works with both the pure Python implementation and the C extension, and the descriptor is inherited by further derived classes. Previously the pure Python metaclass overwrote such a descriptor with the default delegating property, and the C extension forwarded __doc__ to the wrapped object before consulting the type, so it was never used. Only __doc__ is affected, with __module__ always delegating to the wrapped object. This is the mechanism with_doc relies on.
py-blessed: updated to 1.50.0
1.50
* change: default timeout of automatic terminal queries from 1 to 5 seconds with environment
variable ``BLESSED_QUERY_TIMEOUT_SECONDS`` override,
* bugfix: Do not automatic query `XTGETTCAP`_ for older CONPTY builds (Windows Server 2022), which
displays control codes as visible text
* bugfix: :meth:`~Terminal.mouse_enabled` failed to yield ``MOUSE_*`` keystrokes on older CONPTY
builds (Windows Server 2022), where the console's "QuickEdit mode" blocks transmission,
* bugfix: an `XTGETTCAP`_ received after query time out was returned by :meth:`~Terminal.inkey` as
errant keystrokes. It is no longer yielded by :meth:`~Terminal.inkey`,
* bugfix: :meth:`~Terminal.does_iterm2_graphics` results are now more accurate, by drawing a
transparent pixel,
* improve: performance of :meth:`~Terminal.does_xtgettcap`,
* improve: skip some automatic queries for Apple's Terminal.app that leak VT100 codes as output
* change: default timeout of automatic terminal queries from 1 to 5 seconds with environment
variable ``BLESSED_QUERY_TIMEOUT_SECONDS`` override,