FreeBSD/src ef78a88 — . misc-agent.c ed25519.sh, openbsd-compat port-linux-selinux.c

Vendor import of OpenSSH 10.6p1

Sponsored by:   The FreeBSD Foundation
DeltaFile
+4,598-1,983ed25519.c
+1,277-1,052ChangeLog
+279-261configure
+256-165ed25519.sh
+191-65misc-agent.c
+243-0openbsd-compat/port-linux-selinux.c
+6,844-3,526127 files not shown
+9,000-4,999133 files

FreeBSD/src 77a7a48 — sys/fs/nfs nfs_var.h, sys/fs/nfsclient nfs_clrpcops.c nfs_clcomsubs.c

nfscl: Fix oddball cases for session slot release

We have identified some cases where silent slot loss can occur
when operations on NFS mounts are aborted. We experience this
when using NFSv4.2, but it likely also occurs with NFSv4.1.

A slot is acquired for compound operations by nfsv4_setsequence()
and freed by newnfs_request(). Any call path that abandons the
compound before reaching newnfs_request() loses the slot permanently.

We identified four call sites where this happens, one of
which where it actually does happen for us in a semi-reproducible
way, which allowed us to develop a candidate patch, attached.

The patch adds one function, nfsv4_freeunsentslot(), to
nfs_clcomsubs.c. It is called from each of the four call
sites: nfsrpc_writerpc(), nfsrpc_writeds(), and two in
nfsrpc_setextattr().


    [11 lines not shown]
DeltaFile
+18-0sys/fs/nfsclient/nfs_clcomsubs.c
+4-0sys/fs/nfsclient/nfs_clrpcops.c
+2-0sys/fs/nfs/nfs_var.h
+24-03 files

FreeBSD/src 192781b — lib/libthr/thread thr_mutex.c

libthr: Consume error in check_and_init_mutex

MFC after:      2 weeks
DeltaFile
+1-1lib/libthr/thread/thr_mutex.c
+1-11 files

FreeBSD/src 657c089 — lib/lib80211 lib80211_regdomain.c

lib80211: fix build with eXpat 2.9.0

eXpat 2.9.0 deprecates XML_GetCurrentLineNumber() in favour of
XML_GetCurrentLineNumber64().  The new function behaves the same
as the old one but is not prone to 32 bit integer wrap-around.
DeltaFile
+27-26lib/lib80211/lib80211_regdomain.c
+27-261 files

FreeBSD/src 22c3edb — contrib/expat Changes, contrib/expat/doc reference.html

contrib/expat: import expat 2.9.0

Changes: https://github.com/libexpat/libexpat/blob/R_2_9_0/expat/Changes

Security:       CVE-2026-102633
Security:       CVE-2026-77214
MFC after:      3 days
DeltaFile
+790-0contrib/expat/tests/props_tests.c
+681-73contrib/expat/doc/reference.html
+413-154contrib/expat/lib/xmlparse.c
+56-220contrib/expat/lib/xmltok.c
+131-39contrib/expat/tests/basic_tests.c
+102-26contrib/expat/Changes
+2,173-51247 files not shown
+2,984-86753 files

FreeBSD/src 9af3990 — contrib/netbsd-tests/lib/librt t_sem.c

sem test: avoid ETIMEDOUT races in the EINTR test cases

timedwait and clockwait_absolute_intr_remaining arm a 50ms SIGALRM and then
wait until an absolute deadline only 100ms in the future.
On a loaded VM the signal can be delivered more than 50ms late, so the wait
times out first.

Approved by:    imp
Sponsored by:   Netflix
Differential Revision:  https://reviews.freebsd.org/D60347
DeltaFile
+10-2contrib/netbsd-tests/lib/librt/t_sem.c
+10-21 files

FreeBSD/src ab7249c — sys/cam cam_iosched.c

cam: Assert we have the periph lock when updating the iosched stats

Sponsored by:           Netflix
Differential Revision:  https://reviews.freebsd.org/D60350
DeltaFile
+2-0sys/cam/cam_iosched.c
+2-01 files

FreeBSD/src bd86f05 — sys/cam/scsi scsi_da.c

da: Update trim stats with the periph lock held

Separate the updating the stats for the completion from the biodone for
each one.

Sponsored by:           Netflix
Reviewed by:            ali_mashtizadeh.com
Differential Revision:  https://reviews.freebsd.org/D60156
DeltaFile
+14-14sys/cam/scsi/scsi_da.c
+14-141 files

FreeBSD/src 7845cf8 — sys/cam/ata ata_da.c

ada: Update trim stats for every bio

Separate the updating the stats for the completion from the biodone for
each one.

Sponsored by:           Netflix
Reviewed by:            ali_mashtizadeh.com
Differential Revision:  https://reviews.freebsd.org/D60157
DeltaFile
+10-13sys/cam/ata/ata_da.c
+10-131 files

FreeBSD/src 4a3a5de — sys/cam cam_iosched.h cam_iosched.c, sys/cam/nvme nvme_da.c

nda: Update trim stats with the periph lock held

Separate the updating the stats for the completion from the biodone for
each one.

Sponsored by:           Netflix
Reviewed by:            ali_mashtizadeh.com
Differential Revision:  https://reviews.freebsd.org/D60155
DeltaFile
+4-18sys/cam/nvme/nvme_da.c
+22-0sys/cam/cam_iosched.c
+2-0sys/cam/cam_iosched.h
+28-183 files

FreeBSD/src 0040d1f — sys/cam cam_iosched.h cam_iosched.c, sys/cam/ata ata_da.c

cam: Rename cam_iosched_bio_complete to cam_iosched_bio_update_stats

The function updates scheduler statistics but does not complete the
bio. Rename it to avoid implying ownership of bio completion.

Sponsored by:           Netflix

Reviewed by:    ali_mashtizadeh.com
Differential Revision:  https://reviews.freebsd.org/D60349
DeltaFile
+3-3sys/cam/nvme/nvme_da.c
+1-1sys/cam/scsi/scsi_da.c
+1-1sys/cam/cam_iosched.h
+1-1sys/cam/cam_iosched.c
+1-1sys/cam/ata/ata_da.c
+7-75 files

FreeBSD/src 3b4437e — sys/netpfil/pf pf_nl.c, tests/sys/netpfil/pf src_track.sh

pf: set the correct type for rule timeouts

PR:             298877
MFC after:      1 week
Sponsored by:   Rubicon Communications, LLC ("Netgate")

(cherry picked from commit 3c58e64369fd8124c83f1c7d63106bddca83fa1e)
DeltaFile
+25-0tests/sys/netpfil/pf/src_track.sh
+1-1sys/netpfil/pf/pf_nl.c
+26-12 files

FreeBSD/src e3f5a83 — sbin/camcontrol fwdownload.c

camcontrol: Add Spectra Logic copyright

The majority of lines of code currently in fwdownload.c come from ken@'s
rework in commit 0e358df062dd ("Revamp camcontrol(8) fwdownload support
and add the opcodes subcommand.").  Add the appropriate copyright.

Approved by:    ken
DeltaFile
+1-0sbin/camcontrol/fwdownload.c
+1-01 files

FreeBSD/src fabb224 — sbin/camcontrol fwdownload.c

camcontrol: Add support for firmware uploading on HPE-branded drives

PR:             299059
(cherry picked from commit b30e67dc130ea8217e92e0b4c462f189e2268eba)
DeltaFile
+2-0sbin/camcontrol/fwdownload.c
+2-01 files

FreeBSD/src 3e01ebd — sys/riscv/riscv identcpu.c

riscv: support the new "riscv,isa-extensions" string-array.

Support the new "riscv,isa-extensions" property on RISC-V hart nodes
in FDT.

The "riscv,isa" property is deprecated, but cannot be removed because
doing so would break compatibility with existing DTBs. The new properties
replace it: "riscv,isa-base" describes the base ISA and
"riscv,isa-extensions" is a string array containing the supported ISA
extensions.

The "riscv,isa-extensions" property can be relatively large; on the
Spacemit K3 SoC it is approximately 300 bytes.

The FreeBSD OFW interface does not provide access to the underlying FDT
property data without copying it, and memory allocation is not possible
this early. So allocate a static buffer for the property instead.

Reuse the existing parse_riscv_isa() implementation to parse both the new

    [5 lines not shown]
DeltaFile
+80-26sys/riscv/riscv/identcpu.c
+80-261 files

FreeBSD/src 572cd66 — sys/dev/hwpmc hwpmc_ibs.c

hwpmc: handle delayed IBS NMIs on Zen 6

On Zen 6, an extra IBS NMI can arrive after later samples. Keep the
credit until the empty NMI arrives, and handle fetch and op samples when
both are ready.

Reviewed by:    mhorne
Fixes:  34b00ed041a4 ("hwpmc: fix IBS fetch and op NMI handling")
Fixes:  e51ef8ae490f ("hwpmc: Initial support for AMD IBS")
Sponsored by:   AMD
Differential Revision:  https://reviews.freebsd.org/D60367
DeltaFile
+15-6sys/dev/hwpmc/hwpmc_ibs.c
+15-61 files

FreeBSD/src 3e8ce38 — sys/sys pmc.h

pmc.h: bump PMC_VERSION_MINOR

Bump for the addition of PMC_OP_GETCAPS and the recently added Intel
CPUs.

Sponsored by:   The FreeBSD Foundation

(cherry picked from commit e39d3a6b32331437da6c13a4aeb67e5bcca67625)
DeltaFile
+1-1sys/sys/pmc.h
+1-11 files

FreeBSD/src 1cc380d — lib/libpmc libpmc.c, share/man/man4 hwpmc.4

libpmc: Query hwpmc for caps

This change allows for fine-grained capabilities per counter index. This
is particularly useful for AMD where subclasses are not exposed to the
general PMC code, but other architectures also have asymmetric behaviors
when it comes to specific counter indices.

A new PMC_OP_GETCAPS op is added to the hwpmc(4) ioctl interface.

Reviewed by:    mhorne
Sponsored by:   Netflix
Pull Request:   https://github.com/freebsd/freebsd-src/pull/2058

(cherry picked from commit 44a983d249d05d932b6cff333f130baf70febc22)
DeltaFile
+45-0sys/dev/hwpmc/hwpmc_mod.c
+9-10lib/libpmc/libpmc.c
+14-1sys/sys/pmc.h
+15-0sys/dev/hwpmc/hwpmc_amd.c
+4-0share/man/man4/hwpmc.4
+87-115 files

FreeBSD/src 04aa36c — sys/sys pmc.h

pmc.h: bump PMC_VERSION_MINOR

Bump for the addition of PMC_OP_GETCAPS and the recently added Intel
CPUs.

Sponsored by:   The FreeBSD Foundation

(cherry picked from commit e39d3a6b32331437da6c13a4aeb67e5bcca67625)
DeltaFile
+1-1sys/sys/pmc.h
+1-11 files

FreeBSD/src 7c5caf7 — lib/libpmc libpmc.c, share/man/man4 hwpmc.4

libpmc: Query hwpmc for caps

This change allows for fine-grained capabilities per counter index. This
is particularly useful for AMD where subclasses are not exposed to the
general PMC code, but other architectures also have asymmetric behaviors
when it comes to specific counter indices.

A new PMC_OP_GETCAPS op is added to the hwpmc(4) ioctl interface.

Reviewed by:    mhorne
Sponsored by:   Netflix
Pull Request:   https://github.com/freebsd/freebsd-src/pull/2058

(cherry picked from commit 44a983d249d05d932b6cff333f130baf70febc22)
DeltaFile
+45-0sys/dev/hwpmc/hwpmc_mod.c
+9-10lib/libpmc/libpmc.c
+14-1sys/sys/pmc.h
+15-0sys/dev/hwpmc/hwpmc_amd.c
+4-0share/man/man4/hwpmc.4
+87-115 files

FreeBSD/src de5689d — usr.sbin/bsnmpd/tools/bsnmptools bsnmpget.c, usr.sbin/bsnmpd/tools/libbsnmptools bsnmptools.c

bsnmp: validate the lower bound of error_index in responses

Check if the response's error_index is within a sane interval.
Otherwise, a rogue peer could crash us.

PR:             298222
Reported by:    Robert Morris
Reviewed by:    markj
Discussed with: secteam (markj)
MFC after:      2 weeks
Analyzed with:  Claude Code Opus 5

(cherry picked from commit 296e3fd54ca8972fa6696974097a2f2705f8dfc4)
DeltaFile
+6-2usr.sbin/bsnmpd/tools/bsnmptools/bsnmpget.c
+2-1usr.sbin/bsnmpd/tools/libbsnmptools/bsnmptools.c
+8-32 files

FreeBSD/src 0154a0d — usr.sbin/bsnmpd/tools/libbsnmptools bsnmptools.c

bsnmpget: initialise the suboption value in getsubopt1()

Otherwise, "bsnmpget -o verbose -I cut" crashes.

Reported by:    clang static analyzer
MFC after:      2 weeks

(cherry picked from commit 5d169b5365b1f5cdf8586efa9421feaa4bfe40af)
DeltaFile
+1-0usr.sbin/bsnmpd/tools/libbsnmptools/bsnmptools.c
+1-01 files

FreeBSD/src 2da1096 — sbin/ipfw dummynet.c

dummynet: do not overflow the points[ED_MAX_SAMPLES_NO] array

Otherwise, the following would segfault

dnctl pipe 1 config bw 1Mbit/s profile 1025points.txt

Found with:     Claude Code Sonnet 5
MFC after:      2 weeks

(cherry picked from commit 04fcf30961266cd77139b40774cb0d6ef6eb2be5)
DeltaFile
+3-0sbin/ipfw/dummynet.c
+3-01 files

FreeBSD/src 274236e — libexec/rtld-elf rtld.c

rtld.c: avoid double-free on dso load failure in do_load_object()

The obj->path is assigned directly from the path argument, and
load_object() frees the path on do_load_object() failure.  Do not free
it in obj_free() on the error path.

Reviewed by:    markj
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
Differential revision:  https://reviews.freebsd.org/D60402
DeltaFile
+1-0libexec/rtld-elf/rtld.c
+1-01 files

FreeBSD/src 4445d03 — stand/userboot/userboot libuserboot.h main.c

stand: userboot: improve userdisk error handling

Currently, userdisk_init() iterates through disks and
checks whether DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls
are available for the device. If either ioctl fails, userdisk_init()
returns ENXIO with ud_info only partially initialized.
devinit() records the failure, but loader_main() ignores
devinit()'s return value, so later code may access an
uninitialized entry.

In certain cases this code can still boot from a disk even if
userdisk_init() returns ENXIO, for example, when the first of
two disks is valid and the second errors out.

To address this issue while not breaking the current behavior, do
the following:

 - Zero-initialize the userdisk_info array and use a zero media size
   to mark disks that do not support the ioctls mentioned above or

    [14 lines not shown]
DeltaFile
+32-13stand/userboot/userboot/userboot_disk.c
+6-3stand/userboot/userboot/main.c
+1-0stand/userboot/userboot/libuserboot.h
+39-163 files

FreeBSD/src b3b90af — usr.sbin/bhyveload bhyveload.c

bhyveload: validate character disk devices

Currently, bhyveload(8) does not validate the supplied disk
image path. For example, it allows passing the /dev/null
device, which later fails in userboot because it does not
support DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls (see
userdisk_init() in stand/userboot/userboot/userboot_disk.c).

Fix that by checking DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls early.
A similar check already exists in bhyve(8). While here, make
cb_diskioctl() report the obtained sector size instead of
hard-coding 512.

Reviewed by:    markj
MFC after:      2 weeks
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59253

(cherry picked from commit 51234535ddd6ec0afe9dd4e3f34a31b92d5cdd78)
DeltaFile
+31-3usr.sbin/bhyveload/bhyveload.c
+31-31 files

FreeBSD/src 0c409a5 — contrib/llvm-project/clang/lib/Sema SemaTemplateInstantiateDecl.cpp

Merge commit c4ce37507537 from llvm-project (by ShengYi Hung):

  [Clang][Sema] Create LocalScope for Variable Template (#228280)

  A variable template should create its own LocalScope, as it should be
  opaque to other instantiations. This can occur when there are multiple
  instantiations in the same lexical scope. The correct behavior is that
  these instantiations should not be chained together.

  Assisted-by: Claude # Test ReleaseNote
  Fixes: #134148

This fixes an assertion while building the devel/glaze port.

PR:             276265
MFC after:      3 days

(cherry picked from commit fe9c7137871ee0b5c48d4c38b87d80f72e73379e)
DeltaFile
+4-0contrib/llvm-project/clang/lib/Sema/SemaTemplateInstantiateDecl.cpp
+4-01 files

FreeBSD/src fb099c1 — contrib/llvm-project/clang/lib/Sema SemaTemplateInstantiateDecl.cpp

Merge commit c4ce37507537 from llvm-project (by ShengYi Hung):

  [Clang][Sema] Create LocalScope for Variable Template (#228280)

  A variable template should create its own LocalScope, as it should be
  opaque to other instantiations. This can occur when there are multiple
  instantiations in the same lexical scope. The correct behavior is that
  these instantiations should not be chained together.

  Assisted-by: Claude # Test ReleaseNote
  Fixes: #134148

This fixes an assertion while building the devel/glaze port.

PR:             276265
MFC after:      3 days

(cherry picked from commit fe9c7137871ee0b5c48d4c38b87d80f72e73379e)
DeltaFile
+4-0contrib/llvm-project/clang/lib/Sema/SemaTemplateInstantiateDecl.cpp
+4-01 files

FreeBSD/src bceab8b — lib/clang llvm.build.mk, lib/clang/include/llvm/Config Targets.def Disassemblers.def

llvm: add LoongArch target support, not enabled by default

Note there is ongoing work to add LoongArch support to the base system,
but having target support in llvm is an essential component.

This must be explicitly enabled using WITH_LLVM_TARGET_LOONGARCH.

Reviewed by:    dim
MFC after:      1 week
Differential Revision: https://reviews.freebsd.org/D59899

(cherry picked from commit 2f49e40a684a4bffd8e368a6878384ec4f735ea8)
DeltaFile
+49-6lib/clang/libllvm/Makefile
+3-4share/man/man5/src.conf.5
+6-0lib/clang/llvm.build.mk
+0-3tools/build/options/WITH_LLVM_TARGET_BPF
+3-0lib/clang/include/llvm/Config/Targets.def
+3-0lib/clang/include/llvm/Config/Disassemblers.def
+64-136 files not shown
+74-1412 files

FreeBSD/src 8b75481 — lib/clang llvm.build.mk, lib/clang/include/llvm/Config Targets.def Disassemblers.def

llvm: add LoongArch target support, not enabled by default

Note there is ongoing work to add LoongArch support to the base system,
but having target support in llvm is an essential component.

This must be explicitly enabled using WITH_LLVM_TARGET_LOONGARCH.

Reviewed by:    dim
MFC after:      1 week
Differential Revision: https://reviews.freebsd.org/D59899

(cherry picked from commit 2f49e40a684a4bffd8e368a6878384ec4f735ea8)
DeltaFile
+49-6lib/clang/libllvm/Makefile
+3-4share/man/man5/src.conf.5
+6-0lib/clang/llvm.build.mk
+0-3tools/build/options/WITH_LLVM_TARGET_BPF
+3-0lib/clang/include/llvm/Config/Targets.def
+3-0lib/clang/include/llvm/Config/Disassemblers.def
+64-136 files not shown
+74-1412 files