FreeBSD/src b6d10a9 — sys/sys sched.h

sched.h: Include <sys/pcpu.h> unconditionally

Even if SCHED_STATS is not defined, this header is necessary to provide
a definition of 'curthread' used in sched_pin() and sched_unpin().

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
DeltaFile
+0-2sys/sys/sched.h
+0-21 files

FreeBSD/src 25faf86 — share/man/man4 pcm.4, sys/dev/sound/pcm channel.c

pcm.4: Remove DIAGNOSTICS section

These diagnostics do not exist anymore.

MFC after:      1 week
DeltaFile
+1-9share/man/man4/pcm.4
+1-1sys/dev/sound/pcm/channel.c
+2-102 files

FreeBSD/src c977992 — sys/fs/cuse cuse.c

cuse: Rename cuse_server_free() to cuse_server_dtor()

This name is clearer, given that this function is the cdevpriv
destructor callback.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation

(cherry picked from commit b55b6e1d727bdc810b157047cb12e2e550333551)
DeltaFile
+2-2sys/fs/cuse/cuse.c
+2-21 files

FreeBSD/src 2cb963e — sys/fs/cuse cuse.c

cuse: Implement hot-unload

cuse_kern_uninit() can hang on destroy_dev(), because of threads
sleeping in CUSE_IOCTL_GET_COMMAND, so implement d_purge to wake them up
before calling destroy_dev(). Also do not allow threads to go back to
sleep if the is_closing flag has been set.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D60022

(cherry picked from commit d38ef1aca969f9a79572958c06bc4a4e03f053c2)
DeltaFile
+59-33sys/fs/cuse/cuse.c
+59-331 files

FreeBSD/src 58ca5e4 — sys/fs/cuse cuse.c

cuse: Assert the server refcount

Assert that the refcount does not underflow before decrementing it, and
that it really is zero by the time the server is freed.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D60043

(cherry picked from commit f96c4f45f791124192363c9aa2898b1d0e4cc6d0)
DeltaFile
+2-0sys/fs/cuse/cuse.c
+2-01 files

FreeBSD/src 4772247 — sys/fs/cuse cuse.c

cuse: Actually use cuse_modevent()

We can call cuse_kern_init()/cuse_kern_uninit() here, rather than using
SYSINIT/SYSUNINIT.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D59862

(cherry picked from commit 2fd8d2eb7bb91148169471291dbcfa499579b1bc)
DeltaFile
+33-30sys/fs/cuse/cuse.c
+33-301 files

FreeBSD/src b1aea70 — sys/fs/cuse cuse.c

cuse: Fix hang on readv(2) and writev(2) with multiple iovecs

uiomove() leaves an iovec it has just emptied as the current one, so
cuse_client_read() and cuse_client_write() picked it up again on the
next iteration, sent the server a zero-length command, and got zero
bytes back. That left the residual count unchanged, so the loop never
terminated and the call never returned.

Step past empty iovecs at the start of every iteration. This also covers
caller-supplied zero-length iovecs, which hung in the same way

PR:             293489
MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib, markj
Differential Revision:  https://reviews.freebsd.org/D59822

(cherry picked from commit 872c36cb6f2de17278c559a300c2163d8b39b3c6)
DeltaFile
+24-4sys/fs/cuse/cuse.c
+24-41 files

FreeBSD/src 8b462fa — sys/fs/cuse cuse.c

cuse: Remove unnecessary semicolon in cuse_convert_error()

No functional change intended.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation

(cherry picked from commit e923a30ecf2a34cdf46afcfbffdbc30e822148d1)
DeltaFile
+0-1sys/fs/cuse/cuse.c
+0-11 files

FreeBSD/src 1c6b481 — sys/fs/cuse cuse.c

cuse: Use make_dev_s() to create client devices

make_dev_s() sets si_drv1 before the node is published in devfs, which
avoids a race where cuse_client_open() could see it as NULL. It also now
reports finer-grained errors on failure, instead of only ENOMEM.

While here, drop the NULL checks on kern_dev in cuse_server_free_dev(),
since a device is only added to the server's list once it has been
created.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D59874

(cherry picked from commit fad756fd200bf988861eb80146392661a887ab71)
DeltaFile
+13-13sys/fs/cuse/cuse.c
+13-131 files

FreeBSD/src f9669d9 — sys/fs/cuse cuse_defs.h cuse.c

cuse: Retire unnecessary CUSE_VERSION

No functional change intended.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation

(cherry picked from commit 34b00da59b8f8c3fa877135beaefd3ad31841f41)
DeltaFile
+0-4sys/fs/cuse/cuse.c
+0-2sys/fs/cuse/cuse_defs.h
+0-62 files

FreeBSD/src ba847a0 — sys/fs/cuse cuse.c

cuse: Improve server cleanup

Move cuse_server_unref()'s device cleanup loop into a new
cuse_server_free_devs_locked(), and call it from cuse_server_free()
instead. The cdevpriv destructor now destroys the server's devices
before dropping its reference, which closes the clients using them, so
that the destructor is always the one that takes the last reference.

By the time cuse_server_unref() frees the server, the device list should
be empty, so assert this.

In cuse_kern_uninit(), delete the infinite loop which waits for all open
/dev/cuse instances to exit, and instead call destroy_dev() directly,
which runs their cdevpriv destructor.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D59872

    [2 lines not shown]
DeltaFile
+22-30sys/fs/cuse/cuse.c
+22-301 files

FreeBSD/src 598eb67 — sys/fs/cuse cuse.c

cuse: Create /dev/cuse with MAKEDEV_CHECKNAME

Since we now use make_dev_credf(), make sure to fail kldload if it
returned NULL.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
Reviewed by:    kib
Differential Revision:  https://reviews.freebsd.org/D59863

(cherry picked from commit 3b3e6473b13093c6900194b42e8a11f56c2ea7d8)
DeltaFile
+12-6sys/fs/cuse/cuse.c
+12-61 files

FreeBSD/src 556d10a — share/man/man4 Makefile

man: Link ena.4 to if_ena.4

For consistency, create a symbolic link from ena.4 to also if_ena.4

Reviewed by:            #manpages, ziaee
Differential Revision:  https://reviews.freebsd.org/D60191
MFC after:              3 days

(cherry picked from commit 566fdcba48817b0f8fea1f9b2963505b925675fb)
DeltaFile
+1-0share/man/man4/Makefile
+1-01 files

FreeBSD/src 139fa2c — sys/net/route route_ctl.c

routing: fix rtentry use-after-free in multipath route append

add_route_flags() drops the RIB lock and passes the existing entry,
rt_orig, to add_route_flags_mpath(). If a concurrent delete removes
the prefix in that window, the retry re-inserts rt_orig, which is
then freed while still linked, crashing later in rn_match().

Pass the new rt instead, return ENOENT when the prefix is gone and
RTM_F_CREATE is not set, and fix the rnd_orig NULL check.

Approved by:    pouria
Fixes:          c24a8f19c5d5 ("routing: fix rib_add_route_px()")
Differential Revision:  https://reviews.freebsd.org/D60353
DeltaFile
+12-2sys/net/route/route_ctl.c
+12-21 files

FreeBSD/src a6a8640 — tests/sys/netinet6 ndp.sh

tests/netinet6: fix ndp_del_gu_success flakiness

The test pinged an unanswered address and then deleted the resulting
INCOMPLETE neighbor entry.
The kernel frees that entry after about 3s, so on a loaded VM,
ndp -d could run too late and fail with ENOENT.

Configure 2001:db8::2 on epair0b so the ping gets a reply and the
entry becomes REACHABLE.

Approved by:    pouria
Sponsored by:   Netflix
Differential Revision:  https://reviews.freebsd.org/D60348
DeltaFile
+8-4tests/sys/netinet6/ndp.sh
+8-41 files

FreeBSD/src ad3fdab — sys/kern vfs_vnops.c vfs_syscalls.c, sys/sys stat.h

stat(2): report mount points using st_bsdflags SFBSD_MNTPOINT flag

(cherry picked from commit 0d5d8872931c2659692b5e59db2190b715ff314c)
DeltaFile
+2-0sys/kern/vfs_vnops.c
+2-0sys/kern/vfs_syscalls.c
+1-0sys/sys/stat.h
+5-03 files

FreeBSD/src 9a0ea12 — lib/libsys stat.2

stat.2: document SFBSD_MNTROOT

(cherry picked from commit 1e8708d9b598415a993fecb7b5c5cc8a9e64cba5)
DeltaFile
+4-0lib/libsys/stat.2
+4-01 files

FreeBSD/src 2961d9d — lib/libsys stat.2

stat(2): Document st_bsdflags and SFBSD_NAMEDATTR

(cherry picked from commit 72e391060bb6c83ed65ac7ca3936bd6e07ab1ebc)
DeltaFile
+19-2lib/libsys/stat.2
+19-21 files

FreeBSD/src ef78a88 — . misc-agent.c ed25519.sh, openbsd-compat port-linux-selinux.c

Vendor import of OpenSSH 10.6p1

Sponsored by:   The FreeBSD Foundation
DeltaFile
+4,598-1,983ed25519.c
+1,277-1,052ChangeLog
+279-261configure
+256-165ed25519.sh
+191-65misc-agent.c
+243-0openbsd-compat/port-linux-selinux.c
+6,844-3,526127 files not shown
+9,000-4,999133 files

FreeBSD/src 77a7a48 — sys/fs/nfs nfs_var.h, sys/fs/nfsclient nfs_clrpcops.c nfs_clcomsubs.c

nfscl: Fix oddball cases for session slot release

We have identified some cases where silent slot loss can occur
when operations on NFS mounts are aborted. We experience this
when using NFSv4.2, but it likely also occurs with NFSv4.1.

A slot is acquired for compound operations by nfsv4_setsequence()
and freed by newnfs_request(). Any call path that abandons the
compound before reaching newnfs_request() loses the slot permanently.

We identified four call sites where this happens, one of
which where it actually does happen for us in a semi-reproducible
way, which allowed us to develop a candidate patch, attached.

The patch adds one function, nfsv4_freeunsentslot(), to
nfs_clcomsubs.c. It is called from each of the four call
sites: nfsrpc_writerpc(), nfsrpc_writeds(), and two in
nfsrpc_setextattr().


    [11 lines not shown]
DeltaFile
+18-0sys/fs/nfsclient/nfs_clcomsubs.c
+4-0sys/fs/nfsclient/nfs_clrpcops.c
+2-0sys/fs/nfs/nfs_var.h
+24-03 files

FreeBSD/src 192781b — lib/libthr/thread thr_mutex.c

libthr: Consume error in check_and_init_mutex

MFC after:      2 weeks
DeltaFile
+1-1lib/libthr/thread/thr_mutex.c
+1-11 files

FreeBSD/src 657c089 — lib/lib80211 lib80211_regdomain.c

lib80211: fix build with eXpat 2.9.0

eXpat 2.9.0 deprecates XML_GetCurrentLineNumber() in favour of
XML_GetCurrentLineNumber64().  The new function behaves the same
as the old one but is not prone to 32 bit integer wrap-around.
DeltaFile
+27-26lib/lib80211/lib80211_regdomain.c
+27-261 files

FreeBSD/src 22c3edb — contrib/expat Changes, contrib/expat/doc reference.html

contrib/expat: import expat 2.9.0

Changes: https://github.com/libexpat/libexpat/blob/R_2_9_0/expat/Changes

Security:       CVE-2026-102633
Security:       CVE-2026-77214
MFC after:      3 days
DeltaFile
+790-0contrib/expat/tests/props_tests.c
+681-73contrib/expat/doc/reference.html
+413-154contrib/expat/lib/xmlparse.c
+56-220contrib/expat/lib/xmltok.c
+131-39contrib/expat/tests/basic_tests.c
+102-26contrib/expat/Changes
+2,173-51247 files not shown
+2,984-86753 files

FreeBSD/src 9af3990 — contrib/netbsd-tests/lib/librt t_sem.c

sem test: avoid ETIMEDOUT races in the EINTR test cases

timedwait and clockwait_absolute_intr_remaining arm a 50ms SIGALRM and then
wait until an absolute deadline only 100ms in the future.
On a loaded VM the signal can be delivered more than 50ms late, so the wait
times out first.

Approved by:    imp
Sponsored by:   Netflix
Differential Revision:  https://reviews.freebsd.org/D60347
DeltaFile
+10-2contrib/netbsd-tests/lib/librt/t_sem.c
+10-21 files

FreeBSD/src ab7249c — sys/cam cam_iosched.c

cam: Assert we have the periph lock when updating the iosched stats

Sponsored by:           Netflix
Differential Revision:  https://reviews.freebsd.org/D60350
DeltaFile
+2-0sys/cam/cam_iosched.c
+2-01 files

FreeBSD/src bd86f05 — sys/cam/scsi scsi_da.c

da: Update trim stats with the periph lock held

Separate the updating the stats for the completion from the biodone for
each one.

Sponsored by:           Netflix
Reviewed by:            ali_mashtizadeh.com
Differential Revision:  https://reviews.freebsd.org/D60156
DeltaFile
+14-14sys/cam/scsi/scsi_da.c
+14-141 files

FreeBSD/src 7845cf8 — sys/cam/ata ata_da.c

ada: Update trim stats for every bio

Separate the updating the stats for the completion from the biodone for
each one.

Sponsored by:           Netflix
Reviewed by:            ali_mashtizadeh.com
Differential Revision:  https://reviews.freebsd.org/D60157
DeltaFile
+10-13sys/cam/ata/ata_da.c
+10-131 files

FreeBSD/src 4a3a5de — sys/cam cam_iosched.h cam_iosched.c, sys/cam/nvme nvme_da.c

nda: Update trim stats with the periph lock held

Separate the updating the stats for the completion from the biodone for
each one.

Sponsored by:           Netflix
Reviewed by:            ali_mashtizadeh.com
Differential Revision:  https://reviews.freebsd.org/D60155
DeltaFile
+4-18sys/cam/nvme/nvme_da.c
+22-0sys/cam/cam_iosched.c
+2-0sys/cam/cam_iosched.h
+28-183 files

FreeBSD/src 0040d1f — sys/cam cam_iosched.h cam_iosched.c, sys/cam/ata ata_da.c

cam: Rename cam_iosched_bio_complete to cam_iosched_bio_update_stats

The function updates scheduler statistics but does not complete the
bio. Rename it to avoid implying ownership of bio completion.

Sponsored by:           Netflix

Reviewed by:    ali_mashtizadeh.com
Differential Revision:  https://reviews.freebsd.org/D60349
DeltaFile
+3-3sys/cam/nvme/nvme_da.c
+1-1sys/cam/scsi/scsi_da.c
+1-1sys/cam/cam_iosched.h
+1-1sys/cam/cam_iosched.c
+1-1sys/cam/ata/ata_da.c
+7-75 files

FreeBSD/src 3b4437e — sys/netpfil/pf pf_nl.c, tests/sys/netpfil/pf src_track.sh

pf: set the correct type for rule timeouts

PR:             298877
MFC after:      1 week
Sponsored by:   Rubicon Communications, LLC ("Netgate")

(cherry picked from commit 3c58e64369fd8124c83f1c7d63106bddca83fa1e)
DeltaFile
+25-0tests/sys/netpfil/pf/src_track.sh
+1-1sys/netpfil/pf/pf_nl.c
+26-12 files