HardenedBSD/src 186e70b — contrib/llvm-project/clang/lib/Sema SemaTemplateInstantiateDecl.cpp, sys/dev/vt/hw/fb vt_fb.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+30-2usr.sbin/bhyve/bhyve.8
+4-0contrib/llvm-project/clang/lib/Sema/SemaTemplateInstantiateDecl.cpp
+0-3sys/dev/vt/hw/fb/vt_fb.c
+34-53 files

HardenedBSD/src 7576a6a — contrib/tzdata zone1970.tab zonenow.tab, usr.sbin/bhyveload bhyveload.c

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+98-20contrib/tzdata/northamerica
+38-0contrib/tzdata/NEWS
+26-4contrib/tzdata/europe
+5-1usr.sbin/bhyveload/bhyveload.c
+4-1contrib/tzdata/zonenow.tab
+1-1contrib/tzdata/zone1970.tab
+172-274 files not shown
+176-3110 files

HardenedBSD/src 7611334 — contrib/llvm-project/clang/lib/Sema SemaTemplateInstantiateDecl.cpp, sys/dev/vt/hw/fb vt_fb.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+30-2usr.sbin/bhyve/bhyve.8
+4-0contrib/llvm-project/clang/lib/Sema/SemaTemplateInstantiateDecl.cpp
+0-3sys/dev/vt/hw/fb/vt_fb.c
+34-53 files

HardenedBSD/src ea3007d — contrib/tzdata zone1970.tab zonenow.tab, usr.sbin/bhyveload bhyveload.c

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+98-20contrib/tzdata/northamerica
+38-0contrib/tzdata/NEWS
+26-4contrib/tzdata/europe
+5-1usr.sbin/bhyveload/bhyveload.c
+4-1contrib/tzdata/zonenow.tab
+1-1contrib/tzdata/zone1970.tab
+172-274 files not shown
+176-3110 files

HardenedBSD/src fe9c713 — contrib/llvm-project/clang/lib/Sema SemaTemplateInstantiateDecl.cpp

Merge commit c4ce37507537 from llvm-project (by ShengYi Hung):

  [Clang][Sema] Create LocalScope for Variable Template (#228280)

  A variable template should create its own LocalScope, as it should be
  opaque to other instantiations. This can occur when there are multiple
  instantiations in the same lexical scope. The correct behavior is that
  these instantiations should not be chained together.

  Assisted-by: Claude # Test ReleaseNote
  Fixes: #134148

This fixes an assertion while building the devel/glaze port.

PR:             276265
MFC after:      3 days
DeltaFile
+4-0contrib/llvm-project/clang/lib/Sema/SemaTemplateInstantiateDecl.cpp
+4-01 files

HardenedBSD/src 2300c23 — sys/dev/vt/hw/fb vt_fb.c

vt_fb: Do not perform VT switch in vd_init hook

After 40c20fc29cad it is done by vt_core as soon as vt lock is dropped
after vd_init() has been executed to avoid sleeping with non-sleepable
lock held.

Reviewed by:    quentin.thebault_defenso.fr, vexeduxr
Differential Revision:  https://reviews.freebsd.org/D59632
DeltaFile
+0-3sys/dev/vt/hw/fb/vt_fb.c
+0-31 files

HardenedBSD/src 49276e4 — usr.sbin/bhyveload bhyveload.c

bhyveload: do not hang on EOF from console input

Currently, when bhyveload(8) fails to boot the guest,
it drops into the loader prompt waiting for user input.

This behaviour is inconvenient when using bhyveload(8) from
scripts.

Make it exit when it receives EOF from console input.

PR:             286289
Reviewed by:    markj
MFC after:      2 weeks
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59226

(cherry picked from commit 8c20260bc55d7b4be0cbcf0a940505ae15ab41a9)
DeltaFile
+5-1usr.sbin/bhyveload/bhyveload.c
+5-11 files

HardenedBSD/src ff2efe6 — usr.sbin/bhyve bhyve.8

bhyve.8: add details on using TPM with UEFI

Add a note that UEFI VMs using TPM devices should be configured
to use a varfile. Some UEFI boot loaders, such as shim, update
persistent boot variables and then reset the system when a TPM is
present. Without a writable varfile, the VM may be reset repeatedly.

Add a TPM device example to the examples list.

While here, add a missing "\" to the "uefivm" example, and add ".Pp"
before the vCPU pinning examples for consistency with other examples.

PR:             287326
Reviewed by:    michaelo, ziaee
Sponsored by:   The FreeBSD Foundation
MFC after:      3 days
Differential Revision:  https://reviews.freebsd.org/D60181
DeltaFile
+30-2usr.sbin/bhyve/bhyve.8
+30-21 files

HardenedBSD/src 961a842 — contrib/tzdata theory.html backzone

contrib/tzdata: import tzdata 2026e

Changes: https://github.com/eggert/tz/blob/2026e/NEWS

Briefly:
    Manitoba moves to permanent -05 on 2026-10-31.

(cherry picked from commit f11af6535044c8266d52806d72b07e939f94049c)
DeltaFile
+98-20contrib/tzdata/northamerica
+38-0contrib/tzdata/NEWS
+26-4contrib/tzdata/europe
+4-1contrib/tzdata/zonenow.tab
+1-1contrib/tzdata/theory.html
+1-1contrib/tzdata/backzone
+168-273 files not shown
+171-309 files

HardenedBSD/src e509472 — contrib/netbsd-tests/lib/libc/gen t_assert.c, lib/libc/stdlib getenv.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+6-20contrib/netbsd-tests/lib/libc/gen/t_assert.c
+7-0sys/kern/subr_witness.c
+1-1lib/libc/stdlib/getenv.c
+14-213 files

HardenedBSD/src fb3202e — contrib/netbsd-tests/lib/libc/gen t_assert.c, lib/libc/stdlib getenv.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+6-20contrib/netbsd-tests/lib/libc/gen/t_assert.c
+7-0sys/kern/subr_witness.c
+1-1lib/libc/stdlib/getenv.c
+14-213 files

HardenedBSD/src d9e2cac — sys/kern subr_witness.c

jail: note existing process/prison lock order in witness.
DeltaFile
+7-0sys/kern/subr_witness.c
+7-01 files

HardenedBSD/src 9d5a33d — contrib/netbsd-tests/lib/libc/gen t_assert.c

[tests] lib/libc/gen:assert_test: undefine `NDEBUG`

In the event `NDEBUG` was defined, `assert` would become a no-op,
breaking some of the expectations in `assert_test` around `assert(..)`
failing generating a coredump.

This is a better approach than the previous one committed in 6f3445006a
as it continues to test the `assert(..)` function instead of just
skipping it if `NDEBUG` was defined.

Suggested by:   kevans
MFC after:      4 days
MFC with:       6f3445006a
Fixes:          6f3445006a
Differential Revision: https://reviews.freebsd.org/D60253
DeltaFile
+6-20contrib/netbsd-tests/lib/libc/gen/t_assert.c
+6-201 files

HardenedBSD/src dec68ae — lib/libc/stdlib getenv.c

libc/stdlib/getenv.c:  always allocate new environment

in particular, if the old environment is NULL.

Among making it less surprising for userspace to observe NULL environ,
the change also prevents NULL deref in __rebuild_environ() when
terminating the empty as NULL environment with the NULL pointer.

Reported by:     Leo Bicknell <bicknell at ufp.org>
PR:     298747
Reviewed by:    emaste, markj
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
Differential revision:  https://reviews.freebsd.org/D59996
DeltaFile
+1-1lib/libc/stdlib/getenv.c
+1-11 files

HardenedBSD/src e744688 — sys/dev/hwpmc hwpmc_ibs.c hwpmc_mod.c, sys/kern stack_protector.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+0-29sys/dev/hwpmc/hwpmc_mod.c
+1-9sys/dev/hwpmc/hwpmc_ibs.c
+1-2sys/kern/stack_protector.c
+1-0sys/netpfil/pf/pf_nl.c
+3-404 files

HardenedBSD/src 47eeb98 — sys/kern sched_shim.c sched_ule.c, sys/net/route nhgrp_ctl.c fib_algo.c

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+128-22sys/net/route/fib_algo.c
+46-33sys/kern/sched_4bsd.c
+46-25sys/kern/sched_ule.c
+19-0sys/net/route/nhgrp_ctl.c
+3-3sys/kern/sched_shim.c
+2-1sys/sys/sched.h
+244-841 files not shown
+245-847 files

HardenedBSD/src 29fb592 — sys/dev/hwpmc hwpmc_ibs.c hwpmc_mod.c, sys/kern stack_protector.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+0-29sys/dev/hwpmc/hwpmc_mod.c
+1-9sys/dev/hwpmc/hwpmc_ibs.c
+1-2sys/kern/stack_protector.c
+1-0sys/netpfil/pf/pf_nl.c
+3-404 files

HardenedBSD/src 91209c0 — sys/kern sched_shim.c sched_ule.c, sys/net/route nhgrp_ctl.c fib_algo.c

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+128-22sys/net/route/fib_algo.c
+46-33sys/kern/sched_4bsd.c
+46-25sys/kern/sched_ule.c
+19-0sys/net/route/nhgrp_ctl.c
+3-3sys/kern/sched_shim.c
+2-1sys/sys/sched.h
+244-841 files not shown
+245-847 files

HardenedBSD/src 891bda1 — sys/net/route nhop.h nhgrp_ctl.c

route/fib_algo: Fix nexthop index collision across families

fib_algo indexes its idx->nhop array by the nexthop index with
assumption of its uniqueness. Which is true except for IPv4 over
IPv6 nexthops.
Give each index space its own segment within the same array and
offset the index by the segment base. Segments are created on demand
and sized independently, so the rib's own family keeps base 0 and
tables without cross-family nexthops index exactly as before.

Reviewed by:    melifaro
Discussed with: markj
MFC after:      2 weeks
Differential Revision:  https://reviews.freebsd.org/D59552

(cherry picked from commit 63343822430453f4add20bcbfa134c99132361df)
DeltaFile
+128-22sys/net/route/fib_algo.c
+19-0sys/net/route/nhgrp_ctl.c
+1-0sys/net/route/nhop.h
+148-223 files

HardenedBSD/src 782c6ea — sys/netpfil/pf pf_nl.c

pf: do not leak a source hash row lock in the netlink dump

pf_handle_get_srcnodes() returns with the lock of a source hash row
held when it cannot start the message for a source node.  Unlock the
row there, as the other error exit of the loop does.

Reviewed by:            kp
Approved by:            kp (mentor)
Fixes:                  9c125336727b ("pf: convert DIOCGETSRCNODES to netlink")
MFC after:              1 week
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60251
DeltaFile
+1-0sys/netpfil/pf/pf_nl.c
+1-01 files

HardenedBSD/src b406f4a — sys/kern sched_4bsd.c sched_ule.c

sched: factor out hogticks calculation into sched_update_hogticks()

Suggested by:   olce
Reviewed by:    olce
Approved by:    olce (mentor)
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59471

(cherry picked from commit 5a879394ba2eac14f65b466a46dae39326df00db)
DeltaFile
+11-6sys/kern/sched_ule.c
+10-6sys/kern/sched_4bsd.c
+21-122 files

HardenedBSD/src 3d1b845 — sys/kern sched_ule.c

sched_ule: fix typo in comment

Reviewed by:    olce
Approved by:    olce (mentor)
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59409

(cherry picked from commit 5803063625371dfbaf68e55b0d9e15021f103e28)
DeltaFile
+1-1sys/kern/sched_ule.c
+1-11 files

HardenedBSD/src f1f19d0 — sys/kern sched_ule.c sched_4bsd.c, sys/sys sched.h

sched: rename sched_schedcpu() to sched_sysinit()

sched_schedcpu() is called only during SYSINIT to start kthread that
calls schedcpu() every second in 4BSD, but its name implies it's doing
what 4BSD's schedcpu() does. Rename this function to sched_sysinit() to
mark that schedulers can use it for its own SYSINIT routine. Note that
their SYSINIT routine does not necessarily need to be similar to 4BSD's
decay in schedcpu().

The scheduler.9 man page is planned to be rewritten from scratch, so no
change to it for now.

Reviewed by:    olce
Approved by:    olce (mentor)
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59437

(cherry picked from commit 962125aef24b55b4bb8808dcab335abc4b3f0d4e)
DeltaFile
+3-3sys/kern/sched_shim.c
+2-2sys/kern/sched_ule.c
+2-2sys/kern/sched_4bsd.c
+2-1sys/sys/sched.h
+9-84 files

HardenedBSD/src bd7d81d — sys/kern sched_ule.c

sched_ule: fix invalid tdq_slice() and sched_slice_min

sched_slice_min should always to be greater than zero. When modifying
sched_slice through sysctl, if the new value is less than
SCHED_SLICE_MIN_DIVISOR, sched_slice_min is computed to zero. Add
imax(1, ...) to prevent this.

tdq_slice() should not return a value less than sched_slice_min since
that will cause integer underflow of ts2->ts_slice in
sched_ule_fork_thread. SCHED_SLICE_MIN_DIVISOR is currently set to 6 so
when load is 5 and sched_slice is 4, the two if conditions in
tdq_slice() will pass and the function will return zero. Thus use imax()
so tdq_slice returns sched_slice_min at minimum.

Reviewed by:    olce
Approved by:    olce (mentor)
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59408

    [2 lines not shown]
DeltaFile
+2-4sys/kern/sched_ule.c
+2-41 files

HardenedBSD/src 3d89848 — sys/kern sched_ule.c

sched_ule: fix comment on ts_slice

In ULE ts_slice stores the number of ticks of slice passed not
remaining.

Reviewed by:    olce
Approved by:    olce (mentor)
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59407

(cherry picked from commit 872074c50e99ab8858c2defe255d716f8f75f15b)
DeltaFile
+1-1sys/kern/sched_ule.c
+1-11 files

HardenedBSD/src 48cef99 — sys/kern sched_4bsd.c

sched_4bsd: fix comment in maybe_preempt()

The comment says the new thread's priority is not a realtime priority
while the code states pri > PRI_MAX_ITHD which is interrupt priorities
not realtime.

Reviewed by:    olce
Approved by:    olce (mentor)
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59402

(cherry picked from commit 351f6733180cebdc83585f9a00677f4998f6c6f1)
DeltaFile
+1-1sys/kern/sched_4bsd.c
+1-11 files

HardenedBSD/src b74d313 — sys/kern sched_4bsd.c

sched_4bsd: fix vague comment

The comment "was incremented in schedcpu()" doesn't give enough
background for decrementing ts_slptime by 1 (thus ignoring decay_cpu()
for 1 ts_slptime). More accurately, ts_slptime is decremented by 1
because decay_cpu() has already executed once in schedcpu() when
ts_slptime was 1.

Reviewed by:    olce
Approved by:    olce (mentor)
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59406

(cherry picked from commit cd33abbce5a5c3b454f00ca3d0ecd71c2234106c)
DeltaFile
+2-1sys/kern/sched_4bsd.c
+2-11 files

HardenedBSD/src 78deebb — sys/kern sched_4bsd.c

sched_4bsd: remove obsolete comment

'awake' checks if a thread, not a process, is awake.

Reviewed by:    olce
Approved by:    olce (mentor)
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59404

(cherry picked from commit 6c0c77e190b27d768595ef5b38d798430fb03a8b)
DeltaFile
+1-5sys/kern/sched_4bsd.c
+1-51 files

HardenedBSD/src b47f52c — sys/kern sched_4bsd.c

sched_4bsd: move comment to correct location

Reviewed by:    olce
Approved by:    olce (mentor)
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59403

(cherry picked from commit 039498c2735ee0697da24b9c60c9e67680f91f31)
DeltaFile
+6-5sys/kern/sched_4bsd.c
+6-51 files

HardenedBSD/src 99c0a52 — sys/kern sched_ule.c

sched_ule: fix typo goup to group

Reviewed by:    olce
Approved by:    olce (mentor)
MFC after:      2 weeks
Sponsored by:   FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59400

(cherry picked from commit f609ca733fee72894634f751d1fbc3db53d603dc)
DeltaFile
+10-10sys/kern/sched_ule.c
+10-101 files