HardenedBSD/src 053da20sys/dev/ufshci ufshci_dev.c ufshci_private.h, sys/net bpf.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+24-33sys/dev/ufshci/ufshci_dev.c
+0-3sys/dev/ufshci/ufshci_private.h
+1-1sys/netpfil/ipfilter/netinet/fil.c
+1-1sys/net/bpf.c
+26-384 files

HardenedBSD/ports d93c616devel/hs-ghcup distinfo Makefile, games/veloren-weekly distinfo Makefile.crates

Merge branch 'freebsd/main' into hardenedbsd/main
DeltaFile
+413-0devel/hs-ghcup/distinfo
+170-0devel/hs-ghcup/Makefile
+81-87games/veloren-weekly/distinfo
+14-95games/veloren-weekly/files/patch-gilrs
+39-42games/veloren-weekly/Makefile.crates
+39-41net-mgmt/nagios4/Makefile
+756-26562 files not shown
+1,247-59268 files

HardenedBSD/ports 049f44dgames/veloren-weekly distinfo Makefile.crates, games/veloren-weekly/files patch-gilrs

games/veloren-weekly: update to s20260203

Changes:        https://gitlab.com/veloren/veloren/-/compare/2cc1712251...fd6760d062
DeltaFile
+81-87games/veloren-weekly/distinfo
+14-95games/veloren-weekly/files/patch-gilrs
+39-42games/veloren-weekly/Makefile.crates
+2-2games/veloren-weekly/Makefile
+136-2264 files

HardenedBSD/ports 80b68aadevel/sdl12-compat distinfo Makefile

devel/sdl12-compat: update to 1.2.74

Changes:        https://github.com/libsdl-org/sdl12-compat/releases/tag/release-1.2.74
Reported by:    GitHub (watch releases)
DeltaFile
+3-3devel/sdl12-compat/distinfo
+1-1devel/sdl12-compat/Makefile
+4-42 files

HardenedBSD/ports 2daf2c8graphics/mesa-devel Makefile distinfo, graphics/mesa-devel/files patch-clock_monotonic

graphics/mesa-devel: update to 26.0.b.736

Changes:        https://gitlab.freedesktop.org/mesa/mesa/-/compare/481df222095...124d550a943
DeltaFile
+21-0graphics/mesa-devel/files/patch-clock_monotonic
+3-4graphics/mesa-devel/Makefile
+3-3graphics/mesa-devel/distinfo
+27-73 files

HardenedBSD/ports 36866deemulators/rpcs3 Makefile distinfo

emulators/rpcs3: update to 0.0.39.18761

Changes:        https://github.com/RPCS3/rpcs3/compare/3e49c32c9c...ebf9374ccd
DeltaFile
+5-5emulators/rpcs3/Makefile
+5-3emulators/rpcs3/distinfo
+10-82 files

HardenedBSD/ports ac8b1c3lang/python314 pkg-plist distinfo

lang/python314: SECURITY update to v3.14.3

ChangeLog:      https://docs.python.org/release/3.14.3/whatsnew/changelog.html
MFH:            2026Q1 (immediately)

Security fixes:

* gh-144125: BytesGenerator will now refuse to serialize (write) headers
  that are unsafely folded or delimited; see verify_generated_headers.
  (Contributed by Bas Bloemsaat and Petr Viktorin in gh-121650).

* gh-143935: Fixed a bug in the folding of comments when flattening an
  email message using a modern email policy. Comments consisting of a
  very long sequence of non-foldable characters could trigger a forced
  line wrap that omitted the required leading space on the continuation
  line, causing the remainder of the comment to be interpreted as a new
  header field. This enabled header injection with carefully crafted
  inputs.


    [11 lines not shown]
DeltaFile
+21-0lang/python314/pkg-plist
+3-3lang/python314/distinfo
+1-1lang/python314/Makefile.version
+25-43 files

HardenedBSD/ports a950cdasecurity/vuxml/vuln 2026.xml

security/vuxml: add python <3.14.3 <3.13.12 security issues

Security:       CVE-2026-0865
Security:       CVE-2026-1299
Security:       bfe9adc8-0224-11f1-8790-c5fb948922ad
DeltaFile
+36-0security/vuxml/vuln/2026.xml
+36-01 files

HardenedBSD/src 0f515c0sys/dev/ufshci ufshci_dev.c ufshci_private.h

ufshci: Remove UIC error during initialization

This patch removes the UIC error caused by QEMU not supporting certain
UIC command. Additionally, it removes the unused unipro_version.

Reviewed by:            imp (mentor)
Sponsored by:           Samsung Electronics
Differential Revision:  https://reviews.freebsd.org/D54513
DeltaFile
+24-33sys/dev/ufshci/ufshci_dev.c
+0-3sys/dev/ufshci/ufshci_private.h
+24-362 files

HardenedBSD/ports c8105b8editors/zed distinfo Makefile.crates, editors/zed/files patch-crates_project_src_agent__registry__store.rs patch-Cargo.lock

editors/zed: Update to 0.221.5

Changelog:
- https://github.com/zed-industries/zed/releases/tag/v0.220.2
- https://github.com/zed-industries/zed/releases/tag/v0.220.3
- https://github.com/zed-industries/zed/releases/tag/v0.220.5
- https://github.com/zed-industries/zed/releases/tag/v0.220.6
- https://github.com/zed-industries/zed/releases/tag/v0.220.7
- https://github.com/zed-industries/zed/releases/tag/v0.221.4
- https://github.com/zed-industries/zed/releases/tag/v0.221.5

Reported by:    GitHub (watch releases)
DeltaFile
+33-31editors/zed/distinfo
+15-14editors/zed/Makefile.crates
+23-0editors/zed/files/patch-crates_project_src_agent__registry__store.rs
+8-8editors/zed/files/patch-Cargo.lock
+12-3editors/zed/files/patch-crates_project_src_agent__server__store.rs
+11-0editors/zed/files/patch-crates_util_src_util.rs
+102-5613 files not shown
+143-9819 files

HardenedBSD/ports 9e9d4c0security/openvpn Makefile distinfo, security/openvpn/files patch-tests__t_cltsrv.sh

security/openvpn: update to v2.6.19 (bugfixes)

ChangeLog:      https://github.com/OpenVPN/openvpn/blob/v2.6.19/Changes.rst#overview-of-changes-in-2619
MFH:            2026Q1 (after a few days)
DeltaFile
+8-8security/openvpn/files/patch-tests__t_cltsrv.sh
+10-2security/openvpn/Makefile
+3-3security/openvpn/distinfo
+21-133 files

HardenedBSD/src 5937e1csys/net bpf.c

bpf: don't clear pointer from descriptor to the tap on descriptor close

During packet processing the descriptor is looked up using epoch(9) and it
can be accessed after bpf_detachd().  In scenario of descriptor close the
tap point is alive (it actually produces packets) and thus the pointer can
be legitimately dereferenced.  This fixes a race on a bpf(4) device close
that would otherwise result in panic.

Differential Revision:  https://reviews.freebsd.org/D55064
DeltaFile
+1-1sys/net/bpf.c
+1-11 files

HardenedBSD/ports 4aa7c51net/tcpkali Makefile

net/tcpkali: forbid port

A possible backdoor issue was discovered.
Forbid this port until this can be investigated in detail.

Reported by:    danilo
MFH:            2026Q1
DeltaFile
+2-0net/tcpkali/Makefile
+2-01 files

HardenedBSD/ports bbadea8devel Makefile, devel/hs-ghcup distinfo Makefile

devel/hs-ghcup: New Port: Main installer Haskell

GHCup is the primary installer and version manager for the Haskell
toolchain. It provides a unified interface to install and switch
between different versions of GHC, Cabal, Stack, and the
Haskell Language Server.

WWW: https://www.haskell.org/ghcup/

PR:             292940
Approved by:    eduardo (mentor)
DeltaFile
+413-0devel/hs-ghcup/distinfo
+170-0devel/hs-ghcup/Makefile
+12-0devel/hs-ghcup/pkg-descr
+1-0devel/Makefile
+596-04 files

HardenedBSD/ports f50adc7x11/py-python-xapp pkg-plist Makefile

x11/py-python-xapp: update to 3.0.2

PR: 292809
DeltaFile
+43-0x11/py-python-xapp/pkg-plist
+5-1x11/py-python-xapp/Makefile
+3-3x11/py-python-xapp/distinfo
+51-43 files

HardenedBSD/ports 5802e9edevel/libdispatch Makefile, devel/libdispatch/files patch-src_event_workqueue__internal.h

devel/libdispatch: do not define HAVE_DISPATCH_WORKQ_MONITORING on FreeBSD

It causes random crashes in telegram-desktop

Reported by:    freebsd_ru community members
DeltaFile
+0-11devel/libdispatch/files/patch-src_event_workqueue__internal.h
+1-0devel/libdispatch/Makefile
+1-112 files

HardenedBSD/ports 2a8608cnet-mgmt/nagios4 Makefile pkg-plist, net-mgmt/nagios4/files patch-html_main.php patch-html_index.php.in

net-mgmt/nagios4: Update 4.5.1 => 4.5.11, take maintainership

Changelog:
https://www.nagios.org/projects/nagios-core/4x/

Improve port:
- Replace PORTVERSION with DISTVERSION.
- Parametrize nagios with ${PORTNAME}.
- Replace CFLAGS, CPPFLAGS and LIBS with USES+=localbase.
- Update CONFLICTS.
- Use ${ETCDIR} instead of ${PREFIX}/etc/nagios.
- Fix warnings from portclippy.
- Fix install with non-default NAGIOSUSER/NAGIOSGROUP.
- Split long line in post-patch.
- Improve indents.
- Regenerate patches with changed line numbers.

PR:             292357
Tested by:      Fabian Wenk <fabian at wenks.ch>

    [2 lines not shown]
DeltaFile
+39-41net-mgmt/nagios4/Makefile
+14-38net-mgmt/nagios4/pkg-plist
+14-15net-mgmt/nagios4/files/patch-html_main.php
+4-10net-mgmt/nagios4/files/patch-html_index.php.in
+5-5net-mgmt/nagios4/files/patch-configure
+3-3net-mgmt/nagios4/distinfo
+79-1121 files not shown
+82-1157 files

HardenedBSD/ports 71e370dnet-mgmt/victoria-logs Makefile, net-mgmt/victoria-logs/files victoria-logs.in victoria_logs.in

net-mgmt/victoria-logs: rename rc script with underscore

PR: 292378
DeltaFile
+0-66net-mgmt/victoria-logs/files/victoria-logs.in
+66-0net-mgmt/victoria-logs/files/victoria_logs.in
+2-1net-mgmt/victoria-logs/Makefile
+68-673 files

HardenedBSD/src e408173sys/netpfil/ipfilter/netinet fil.c

ipfilter: Fix possible overrun

The destination buffer is FR_GROUPLEN (16 bytes) in length. When
gname is created, the userspace utilities correctly use FR_GROUPLEN
as the buffer length. The kernel should also limit its copy operation to
FR_GROUPLEN bytes to avoid any user written code from exploiting this
vulnerability.

Reported by:    Ilja Van Sprundel <ivansprundel at ioactive.com>
MFC after:      1 week
DeltaFile
+1-1sys/netpfil/ipfilter/netinet/fil.c
+1-11 files

HardenedBSD/ports 803ed72net-mgmt/victoria-logs Makefile distinfo

net-mgmt/victoria-logs: upgrade to 1.44.0

- Update to the latest version
- Change download to GH because of goproxy issue
- fix logs directory ownership (PR 292405)

PR: 292405
ChangeLog: https://docs.victoriametrics.com/victorialogs/changelog/
DeltaFile
+9-3net-mgmt/victoria-logs/Makefile
+5-5net-mgmt/victoria-logs/distinfo
+5-0net-mgmt/victoria-logs/pkg-plist
+19-83 files

HardenedBSD/ports 3e08e77devel/bazel/files patch-tools_cpp_bsd__cc__toolchain__config.bzl patch-tools_cpp_bsd_cc_toolchain_config.bzl

devel/bazel: fix build around c23 extensions

This reverts commit 984f80b6e226c37980c68d6a7a12d3be08dee2dc.
PR:     278246
---
 ...g.bzl => patch-tools_cpp_bsd_cc_toolchain_config.bzl} | 9 ++++-----
 1 file changed, 4 insertions(+), 5 deletions(-)
 rename devel/bazel/files/{patch-tools_cpp_bsd__cc__toolchain__config.bzl => patch-tools_cpp_bsd_cc_toolchain_config.bzl} (62%)

PR:     286235
Approved-by:    maintainer timeout (10 months)
DeltaFile
+0-12devel/bazel/files/patch-tools_cpp_bsd__cc__toolchain__config.bzl
+11-0devel/bazel/files/patch-tools_cpp_bsd_cc_toolchain_config.bzl
+11-122 files

HardenedBSD/ports 54e5f43shells/xonsh distinfo Makefile, shells/xonsh/files patch-xonsh_platform.py

shells/xonsh: Update to 0.22.3

ChangeLog: https://github.com/xonsh/xonsh/releases/tag/0.22.3
DeltaFile
+3-3shells/xonsh/distinfo
+3-3shells/xonsh/files/patch-xonsh_platform.py
+1-1shells/xonsh/Makefile
+7-73 files

HardenedBSD/ports 4862ae1shells/xonsh distinfo Makefile

shells/xonsh: Update to 0.22.2

ChangeLog: https://github.com/xonsh/xonsh/releases/tag/0.22.2
DeltaFile
+3-3shells/xonsh/distinfo
+1-1shells/xonsh/Makefile
+4-42 files

HardenedBSD/ports 5a88e86devel/R-cran-globals distinfo Makefile

devel/R-cran-globals: Update to 0.19.0

ChangeLog: https://cran.r-project.org/web/packages/globals/news/news.html
DeltaFile
+3-3devel/R-cran-globals/distinfo
+1-1devel/R-cran-globals/Makefile
+4-42 files

HardenedBSD/ports da1117emath/R-cran-reformulas distinfo Makefile

math/R-cran-reformulas: Update to 0.4.4

ChangeLog: https://cran.r-project.org/web/packages/reformulas/news/news.html
DeltaFile
+3-3math/R-cran-reformulas/distinfo
+1-1math/R-cran-reformulas/Makefile
+4-42 files

HardenedBSD/src 3266176lib/libpmc/pmu-events/arch/x86/graniterapids uncore-cache.json uncore-interconnect.json

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+3,745-0lib/libpmc/pmu-events/arch/x86/graniterapids/uncore-cache.json
+1,979-0lib/libpmc/pmu-events/arch/x86/graniterapids/uncore-interconnect.json
+1,925-0lib/libpmc/pmu-events/arch/x86/graniterapids/uncore-io.json
+1,230-0lib/libpmc/pmu-events/arch/x86/graniterapids/cache.json
+1,145-0lib/libpmc/pmu-events/arch/x86/graniterapids/pipeline.json
+890-0lib/libpmc/pmu-events/arch/x86/graniterapids/uncore-memory.json
+10,914-015 files not shown
+12,562-1821 files

HardenedBSD/ports 67ed3c3multimedia/ab-av1 distinfo Makefile.crates, multimedia/hyprpwcenter Makefile

Merge branch 'freebsd/main' into hardenedbsd/main
DeltaFile
+87-85multimedia/ab-av1/distinfo
+126-0x11-toolkits/wlroots020/pkg-plist
+43-42multimedia/ab-av1/Makefile.crates
+80-0x11-toolkits/wlroots020/Makefile
+28-0x11-toolkits/wlroots020/pkg-descr
+28-0multimedia/hyprpwcenter/Makefile
+392-12758 files not shown
+607-25264 files

HardenedBSD/ports 4507b54www/p5-Firefox-Marionette distinfo Makefile

www/p5-Firefox-Marionette: Update 1.68 => 1.70

Changelog:
https://metacpan.org/release/DDICK/Firefox-Marionette-1.70/source/Changes

PR:     292908
DeltaFile
+3-3www/p5-Firefox-Marionette/distinfo
+2-1www/p5-Firefox-Marionette/Makefile
+2-0www/p5-Firefox-Marionette/pkg-plist
+7-43 files

HardenedBSD/src fe8105dstand/libsa/zfs zfsimpl.c

stand: Minor style tweaks

re-wrap the function calls in a couple of ifs in get_zfs_root so they
are more readable. They really didn't need to be wrapped like this in
the first place.

Sponsored by:           Netflix
DeltaFile
+6-10stand/libsa/zfs/zfsimpl.c
+6-101 files

HardenedBSD/src c2ba906sbin/ifconfig ifgre.c

ifconfig: fix gre(4) status

Set `ifr->ifr_name` to display gre options
for the interface.

Reviewed by: glebius, zlei
Approved by: glebius (mentor)
MFC after: 1 day
Differential Revision: https://reviews.freebsd.org/D55099
DeltaFile
+2-2sbin/ifconfig/ifgre.c
+2-21 files