HardenedBSD/src 065e0f3usr.sbin/freebsd-update freebsd-update.sh

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+8-8usr.sbin/freebsd-update/freebsd-update.sh
+8-81 files

HardenedBSD/ports 4e46ef7databases/qof Makefile, deskutils/gnotime Makefile

Merge branch 'freebsd/main' into hardenedbsd/main
DeltaFile
+15-18databases/qof/Makefile
+16-10security/gvm-libs/pkg-plist
+0-20security/openvas/files/patch-nasl_nasl_http2.c
+5-7security/gsa/distinfo
+4-7deskutils/gnotime/Makefile
+5-5security/py-greenbone-feed-sync/pkg-plist
+45-6722 files not shown
+96-10828 files

HardenedBSD/ports 0601f0bsecurity/gsa distinfo, security/gsad distinfo

security/gvm: Update to 26.8.0

security/gsa: Update to 26.4.1 (Only amd64 and aarch64)
security/gsad: Update to 24.9.0
security/openvas: Update to 23.31.4
security/gvmd: Update to 26.8.0
security/gvm-libs: 22.31.1
security/py-greenbone-feed-sync: Update to 25.1.6
security/py-gvm-tools: Update to 25.4.2
security/py-python-gvm: Update to 26.7.1
DeltaFile
+16-10security/gvm-libs/pkg-plist
+0-20security/openvas/files/patch-nasl_nasl_http2.c
+5-7security/gsa/distinfo
+5-5security/py-greenbone-feed-sync/pkg-plist
+3-3security/py-gvm-tools/distinfo
+3-3security/gsad/distinfo
+32-4816 files not shown
+59-7622 files

HardenedBSD/ports 33306b9deskutils/gnotime Makefile

deskutils/gnotime: Undeprecate

qof dependency now has an active upstream, so undeprecate,

Bump PORTREVSION for qof update.

MFH:            2025Q4
DeltaFile
+4-7deskutils/gnotime/Makefile
+4-71 files

HardenedBSD/ports ca25e42databases/qof Makefile distinfo, databases/qof/files patch-qof_Makefile.am

databases/qof: Switch to new upstream

The previous upstream has been unfetchable for quite a while.

There are a number of forks, of which  https://github.com/GnoTime/qof
seems to be the most active.  It is also the same GH account as
is used by deskutils/gnotime, which is our only in-tree consumer.

Take MAINTAINERship and undeprecate.

MFH:            2025Q4
DeltaFile
+15-18databases/qof/Makefile
+10-0databases/qof/files/patch-qof_Makefile.am
+3-2databases/qof/distinfo
+28-203 files

HardenedBSD/src d653ecausr.sbin/freebsd-update freebsd-update.sh

freebsd-update: Add some diagnositic information for a failure case

Users report freebsd-update failing with "The update metadata index is
correctly signed, but failed an integrity check."  Add a hint at which
of the cases is failing to help track down the issue.

PR:             264205
Reviewed by:    dch
Sponsored by:   The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D52222

(cherry picked from commit af4ba95daf75cf1b1624dd57038cfaa3ed2753e7)
DeltaFile
+8-8usr.sbin/freebsd-update/freebsd-update.sh
+8-81 files

HardenedBSD/ports b7ccdbctextproc/md4c distinfo Makefile

textproc/md4c: Update 0.5.2 => 0.5.2.20240225 (last commit)

This update allow onlyoffice-documentserver to use the ports version,
rather than the existing source build.

Changelog:
  Fixes:
    - Fix quadratic time behavior caused by one-by-one walking over
      block lines instead of calling md_lookup_line().
    - Fix quadratic time and output size behavior caused by malicious
      misuse of link reference definitions.
    - The strike-through extension (with flag MD_FLAG_STRIKETHROUGH)
      now follows same logic as other emphasis spans in respect to
      punctuation character and word boundaries.
    - Fix handling tab when removing trailing whitespace, especially in
      connection with ATX headers.
https://github.com/mity/md4c/blob/481fbfb/CHANGELOG.md

Commit log:

    [5 lines not shown]
DeltaFile
+3-3textproc/md4c/distinfo
+2-2textproc/md4c/Makefile
+5-52 files

HardenedBSD/src 7831e55bin/sh jobs.c, bin/sh/tests/execution bg14.0 Makefile

Merge remote-tracking branch 'origin/hardened/current/master' into hardened/current/cross-dso-cfi
DeltaFile
+45-7sys/dev/dpaa2/dpaa2_ni.c
+7-3sys/net/iflib.c
+9-0bin/sh/tests/execution/bg14.0
+5-1bin/sh/jobs.c
+2-1release/scripts/pkg-stage.sh
+1-0bin/sh/tests/execution/Makefile
+69-126 files

HardenedBSD/src c4c356ebin/sh jobs.c, bin/sh/tests/execution bg14.0 Makefile

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+45-7sys/dev/dpaa2/dpaa2_ni.c
+7-3sys/net/iflib.c
+9-0bin/sh/tests/execution/bg14.0
+5-1bin/sh/jobs.c
+2-1release/scripts/pkg-stage.sh
+1-0bin/sh/tests/execution/Makefile
+69-126 files

HardenedBSD/src 9ea6ee3release/scripts pkg-stage.sh

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+2-1release/scripts/pkg-stage.sh
+2-11 files

HardenedBSD/ports 024512caudio/baresip Makefile, multimedia/subtitlecomposer/files patch-CMakeLists.txt

Merge branch 'freebsd/main' into hardenedbsd/main
DeltaFile
+251-221sysutils/dua-cli/distinfo
+124-110sysutils/dua-cli/Makefile.crates
+56-0x11-themes/kf6-breeze-icons/pkg-plist
+17-3security/aide/Makefile
+19-0multimedia/subtitlecomposer/files/patch-CMakeLists.txt
+11-7audio/baresip/Makefile
+478-341109 files not shown
+782-656115 files

HardenedBSD/ports a2c5de3games/openbor distinfo Makefile, games/openbor/files patch-source_utils.c

games/openbor: update to 7757

Changes:        https://github.com/DCurrent/openbor/compare/7eedd899...52921e77
DeltaFile
+4-4games/openbor/files/patch-source_utils.c
+3-3games/openbor/distinfo
+2-2games/openbor/Makefile
+9-93 files

HardenedBSD/src 896dc30sys/net iflib.c

iflib: fix iflib_simple_transmit() when interface is down

Use the same check as iflib_if_transmit() to detect when the
interface is down and return the proper error code, and also
free the mbuf.

This fixes an mbuf leak when a member of a lagg is brought
down (and probably many other scenarios).

Sponsored by: Netflix
DeltaFile
+7-3sys/net/iflib.c
+7-31 files

HardenedBSD/ports 7c6f448devel/sdbus-cpp distinfo Makefile

devel/sdbus-cpp: update to 2.2.0

Changes:        https://github.com/Kistler-Group/sdbus-cpp/releases/tag/v2.2.0
Reported by:    GitHub (watch releases)
DeltaFile
+3-3devel/sdbus-cpp/distinfo
+1-1devel/sdbus-cpp/Makefile
+4-42 files

HardenedBSD/ports 8276d20graphics/mesa-devel distinfo Makefile

graphics/mesa-devel: update to 25.3.b.1394

Changes:        https://gitlab.freedesktop.org/mesa/mesa/-/compare/ad25196d356...80db8171deb
DeltaFile
+3-3graphics/mesa-devel/distinfo
+2-2graphics/mesa-devel/Makefile
+5-52 files

HardenedBSD/ports e8049a2games/veloren-weekly distinfo Makefile

games/veloren-weekly: update to s20251118

Changes:        https://gitlab.com/veloren/veloren/-/compare/07b4403015...d449aa2168
DeltaFile
+3-3games/veloren-weekly/distinfo
+2-2games/veloren-weekly/Makefile
+5-52 files

HardenedBSD/ports ff74ee6graphics/openexr-website-docs distinfo

graphics/openexr-website-docs: fix 3.4.4 distinfo
DeltaFile
+3-3graphics/openexr-website-docs/distinfo
+3-31 files

HardenedBSD/ports d947a5bgraphics/openexr distinfo Makefile, graphics/openexr-website-docs Makefile

graphics/openexr*: update to 3.4.4

ChangeLog:      https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v3.4.4
DeltaFile
+3-3graphics/openexr/distinfo
+2-2graphics/openexr/Makefile
+1-1graphics/openexr-website-docs/Makefile
+6-63 files

HardenedBSD/ports 216f935security/aide Makefile

security/aide: Depend on a crypto library

When not specified the aide build automatically detects the installed
crypto library. It bails if no library is found. We have a choice of
libgcrypt or nettle. Default to libgcrypt but allow the user to
select nettle.
DeltaFile
+12-0security/aide/Makefile
+12-01 files

HardenedBSD/src a731cb9sys/dev/dpaa2 dpaa2_ni.c

dpaa2: Setup interface caps on attach

39d4094173f9 ("epair: add support for checksum offloading") revealed
that HW checksum offloading is not enabled when the dpaa2_ni driver
is attached despite being declared and enabled on the dpni interface.

I modified dpaa2_ni_setup_if_caps to take into account both IPv4 and
IPv6 checksum offloading capabilities and added a call to re-configure
interface capabilities on attach to fix it.

Reviewed by:    bz
Fixes:          39d4094173f9 ("epair: add support for checksum offloading")
MFC after:      1 week
Differential Revision: https://reviews.freebsd.org/D53436
DeltaFile
+45-7sys/dev/dpaa2/dpaa2_ni.c
+45-71 files

HardenedBSD/ports a20c364audio/baresip Makefile distinfo

audio/baresip: Update 4.2.0 => 4.3.0

Changelog:
https://github.com/baresip/baresip/releases/tag/v4.3.0

Improve port:
- Add AMR-NB and AMR-WB audio codecs.

PR:     291103
DeltaFile
+11-7audio/baresip/Makefile
+5-5audio/baresip/distinfo
+3-2audio/baresip/pkg-plist
+19-143 files

HardenedBSD/ports 6caffadaudio/re distinfo pkg-plist

audio/re: Update 4.2.0 => 4.3.0

Changelog:
https://github.com/baresip/re/releases/tag/v4.3.0

PR:     291102
DeltaFile
+3-3audio/re/distinfo
+2-2audio/re/pkg-plist
+1-1audio/re/Makefile
+6-63 files

HardenedBSD/ports e90fe1earchivers/php-lz4 distinfo Makefile

archivers/php-lz4: Update 0.5.0 => 0.6.0

Changelog:
 - This update adds support for frame format
https://github.com/kjdev/php-ext-lz4/releases/tag/0.6.0

Commit log:
https://github.com/kjdev/php-ext-lz4/compare/0.5.0...0.6.0

PR:     291101
DeltaFile
+3-3archivers/php-lz4/distinfo
+1-2archivers/php-lz4/Makefile
+4-52 files

HardenedBSD/ports fdafde9www/gatus distinfo Makefile

www/gatus: update to 5.32.0

ChangeLog: https://github.com/TwiN/gatus/releases/tag/v5.32.0
DeltaFile
+5-5www/gatus/distinfo
+1-1www/gatus/Makefile
+6-62 files

HardenedBSD/ports 5c903a1textproc/py-openpyxl distinfo Makefile

textproc/py-openpyxl: Upgrade port to 3.1.5

* Update COMMENT directly from WWW

Approved by:    antoine (maintainer)
Differential Revision:  https://reviews.freebsd.org/D53690
Release Notes:  https://foss.heptapod.net/openpyxl/openpyxl/-/blob/13627b03ca25a1a98becf40e533b955615b13429/doc/changes.rst?plain=1#L1
DeltaFile
+3-3textproc/py-openpyxl/distinfo
+2-3textproc/py-openpyxl/Makefile
+5-62 files

HardenedBSD/ports 00e6dbetextproc/py-et_xmlfile distinfo Makefile

textproc/py-et_xmlfile: Upgrade port to 2.0.0

Approved by:    antoine (maintainer)
Differential Revision:  https://reviews.freebsd.org/D53689
DeltaFile
+3-3textproc/py-et_xmlfile/distinfo
+1-2textproc/py-et_xmlfile/Makefile
+4-52 files

HardenedBSD/ports 4132c1fsysutils/dua-cli distinfo Makefile.crates

sysutils/dua-cli: Update to 2.32.2

PR:             290635
Approved by:    maintainer
DeltaFile
+251-221sysutils/dua-cli/distinfo
+124-110sysutils/dua-cli/Makefile.crates
+1-2sysutils/dua-cli/Makefile
+376-3333 files

HardenedBSD/ports 7708368security/aide distinfo Makefile, security/aide/files patch-include_util.h

security/aide: Update to 0.19.2
DeltaFile
+0-10security/aide/files/patch-include_util.h
+3-3security/aide/distinfo
+2-3security/aide/Makefile
+5-163 files

HardenedBSD/ports 67df9desecurity/aide Makefile

security/aide: Add license and license file
DeltaFile
+4-1security/aide/Makefile
+4-11 files

HardenedBSD/src f44ac8cbin/sh jobs.c, bin/sh/tests/execution bg14.0 Makefile

sh: Fix job pointer invalidation with trapsasync

Calling dotrap() can do almost anything, including reallocating the
jobtab array. Convert the job pointer to an index before calling
dotrap() and then restore a proper job pointer afterwards.

PR:             290330
Reported by:    bdrewery
Reviewed by:    bdrewery
Differential Revision:  https://reviews.freebsd.org/D53793
DeltaFile
+9-0bin/sh/tests/execution/bg14.0
+5-1bin/sh/jobs.c
+1-0bin/sh/tests/execution/Makefile
+15-13 files