HardenedBSD/src 322c331 — lib/libthr libthr.3, lib/libthr/thread thr_pshared.c

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+14-11sys/compat/linux/linux_event.c
+22-3lib/libthr/thread/thr_pshared.c
+8-3share/man/man5/rc.conf.5
+7-1lib/libthr/libthr.3
+2-4share/man/man4/ng_gif_demux.4
+2-3share/man/man4/ng_l2cap.4
+55-2553 files not shown
+159-12859 files

HardenedBSD/src e3a4c66 — lib/libthr libthr.3, lib/libthr/thread thr_pshared.c

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+14-11sys/compat/linux/linux_event.c
+22-3lib/libthr/thread/thr_pshared.c
+8-3share/man/man5/rc.conf.5
+7-1lib/libthr/libthr.3
+2-4share/man/man4/ng_gif_demux.4
+2-3share/man/man4/ng_hci.4
+55-2553 files not shown
+159-12859 files

HardenedBSD/src e8a7efd — sys/dev/nvme nvme_private.h nvme.h

nvme: set the controller Timestamp feature

Controllers that report ONCS.TIMESTAMP keep a millisecond clock that the
host is expected to seed

Reviewed by:    imp, adrian
Differential Revision:  https://reviews.freebsd.org/D59997
DeltaFile
+60-0sys/dev/nvme/nvme_ctrlr.c
+19-0sys/dev/nvme/nvme.h
+3-0sys/dev/nvme/nvme_private.h
+82-03 files

HardenedBSD/src 0a0490e — sys/dev/nvme nvme_private.h nvme_qpair.c

nvme: do not complete a command when its Abort is not performed

An Abort completion with cdw0 bit 0 set means the controller did not
abort the command; the command can still complete later. The driver
treated this as aborted anyway: it completed the command itself and
freed the CID. When the controller completed the command later,
the CID may already belong to a new command, so the new command
finished with the old command's status, or the unknown-cid assertion
fired on INVARIANTS kernels. The watchdog also kept sending a new
Abort for the same command every half second while the first one was
still pending.

Reviewed by:    imp, adrian
Differential Revision:  https://reviews.freebsd.org/D59634
DeltaFile
+14-24sys/dev/nvme/nvme_qpair.c
+6-0sys/dev/nvme/nvme_private.h
+20-242 files

HardenedBSD/src 22f5037 — sys/dev/nvme nvme_private.h nvme_ctrlr.c

nvme: delete the I/O queues in the system shutdown path

A normal shutdown deletes all I/O submission and completion queues
before setting CC.SHN, as the suspend path already does.  The
device_shutdown path went straight to the shutdown notification with
the queues live, which some drives take slowly or record as an
unclean stop. Skipped the deletion for failed, removed, or
never-initialized controllers.

Reviewed by:    imp, adrian
Differential Revision:  https://reviews.freebsd.org/D59633
DeltaFile
+5-0sys/dev/nvme/nvme.c
+1-1sys/dev/nvme/nvme_ctrlr.c
+1-0sys/dev/nvme/nvme_private.h
+7-13 files

HardenedBSD/src a5b1b2d — lib/libpfctl libpfctl.h libpfctl.c

libpfctl: remove the state getters that do not take a handle

Nothing in the tree calls any of the three.  Remove them rather than
fix them: pfctl_get_states_h() does the same with the handle that the
caller has.  pfctl_free_states(), struct pfctl_states and the list
entry in struct pfctl_state were there for pfctl_get_states() alone,
and go with it.

Reviewed by:            kp
Approved by:            kp (mentor)
Fixes:                  2a478dfc7f9c ("libpfctl: retrieve family id only once")
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60248
DeltaFile
+0-66lib/libpfctl/libpfctl.c
+0-11lib/libpfctl/libpfctl.h
+0-772 files

HardenedBSD/src 66ff928 — sys/dev/igc igc_txrx.c if_igc.c

igc: make the hardware RSS hash agree with the stack's configuration

rss_gethashconfig() is available without options RSS since d9c55b2e8cd6.
Use it to program MRQC, as ixl(4), ice(4) and iavf(4) do, instead of a
fixed field set that included UDP 4-tuple, which the configuration
excludes unless net.inet.rss.udp_4tuple is set.  UDP is now hashed on
addresses only by default.

Also report the UDP hash types on receive; they were passed up as
M_HASHTYPE_NONE.

Reviewed by:            kbowling
Fixes:                  517904de5cca ("igc(4): Introduce new driver for the Intel I225 Ethernet controller.")
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60284
DeltaFile
+21-9sys/dev/igc/if_igc.c
+6-0sys/dev/igc/igc_txrx.c
+27-92 files

HardenedBSD/src edc51d1 — stand/efi/loader version.veriexec version, stand/i386/loader version

stand: Bump version to 3.1

Sponsored by:           Netflix
DeltaFile
+1-0stand/uboot/version
+1-0stand/powerpc/ofw/version
+1-0stand/kboot/kboot/version
+1-0stand/i386/loader/version
+1-0stand/efi/loader/version.veriexec
+1-0stand/efi/loader/version
+6-01 files not shown
+7-07 files

HardenedBSD/src 2050abe — sys/rpc rpc_generic.c

rpc_generic.c: Initialize "cp" to shut the compiler up

This patch does not fix any semantics issue.

MFC after:      3 months
Fixes:  884ee8d6c9b4 ("nfscl: Add some glue for client side NFS over RDMA")
DeltaFile
+1-1sys/rpc/rpc_generic.c
+1-11 files

HardenedBSD/src 4e0870f — share/man/man5 rc.conf.5

rc.conf.5: Fix typo

Fixes:          fa7094c5b06f ("Improve NOAUTO configuration")
MFC after:      3 days
Reported by:    Herbert J. Skuhra <herbert at gojira.at>
Event:          EuroBSDcon Devsummit 2026

(cherry picked from commit 45f4abef5eab5b439f8af272b68171ca5803498d)
DeltaFile
+2-2share/man/man5/rc.conf.5
+2-21 files

HardenedBSD/src 405ee2a — share/man/man5 rc.conf.5

rc.conf.5: Improve NOAUTO configuration + tag SPDX

- Show how to start a NOAUTOed interface
- "configured" is not quite right, try to improve that

MFC after:              3 days
Event:                  EuroBSDcon Devsummit 2026
Reviewed by:            adrian
Discussed with:         Antranig Vartanian <antranigv at freebsd.am>
Differential Revision:  https://reviews.freebsd.org/D59571

(cherry picked from commit fa7094c5b06fe31a025906bcee922a46c1b36ed6)
DeltaFile
+8-3share/man/man5/rc.conf.5
+8-31 files

HardenedBSD/src c678389 — sys/arm/broadcom/bcm2835 bcm2835_pwm.c

bcm2835_pwm: Fix dev.pwm.0.ratio2 register

A typo in the sysctl for RPI0 PWM channel 2 was causing it to
write to the wrong register, leaving it misconfigured if used.

PR:                     298301
MFC after:              3 days (problem reported on 14.4)
Reviewed by:            adrian
Reported by:            Attila Kover <attila.kover at guardian.co.uk>
Differential Revision:  https://reviews.freebsd.org/D59644

(cherry picked from commit 32878e64e687a848fceb710ab9b45e396f27db3f)
DeltaFile
+1-1sys/arm/broadcom/bcm2835/bcm2835_pwm.c
+1-11 files

HardenedBSD/src 206bf19 — share/man/man4 ng_bpf.4 ng_async.4

ng manpages: Standardize descriptions

Netgraph document descriptions are all over the place, wordsmith them
into a standard format of "%s netgraph node", trying to describe them
better to enhance accessiblity of apropos results.

Event:                  EuroBSDcon 2026
MFC after:              3 days
Reviewed by:            dteske, glebius
Discussed with:         des, dteske, glebius
Differential Revision:  https://reviews.freebsd.org/D59643

(cherry picked from commit b1e3d6a668c5a8290ecf32c1badb9f0c9364d280)
DeltaFile
+2-4share/man/man4/ng_gif_demux.4
+2-3share/man/man4/ng_l2cap.4
+2-3share/man/man4/ng_hci.4
+2-2share/man/man4/ng_bpf.4
+2-2share/man/man4/ng_async.4
+2-2share/man/man4/ng_UI.4
+12-1646 files not shown
+103-10952 files

HardenedBSD/src c2089b6 — sys/fs/nfsclient nfs_clvfsops.c nfs.h, sys/rpc rpc_generic.c

nfscl: Add support for b_pages to be used by RDMA

This patch updates the NFS client RDMA glue so that I/O
can be done directly to/from b_pages for buffer cache
blocks.
It also adds a flag to disable read reduction, that might
be needed against some non-FreeBSD servers and sets readahead
to 8 for RDMA unless the "readahead" option has been
specified.

This commit should not affect non-RDMA behaviour.

MFC after:      3 months
Fixes:  884ee8d6c9b4 ("nfscl: Add some glue for client side NFS over RDMA")
DeltaFile
+35-23sys/rpc/rpc_generic.c
+22-19sys/fs/nfsclient/nfs_clrpcops.c
+9-6sys/fs/nfsclient/nfs_clvnops.c
+6-6sys/fs/nfsclient/nfs_clbio.c
+3-3sys/fs/nfsclient/nfs.h
+5-0sys/fs/nfsclient/nfs_clvfsops.c
+80-574 files not shown
+86-6110 files

HardenedBSD/src f39219f — lib/libthr libthr.3

libthr.3: document LIBPTHREAD_PSHARED_LOCK_DESTROY_IMMEDIATE_GC

(cherry picked from commit c2f66b6616425e0e8edab3e893bc4cb58869140d)
DeltaFile
+7-1lib/libthr/libthr.3
+7-11 files

HardenedBSD/src e831067 — lib/libthr/thread thr_private.h thr_init.c

libthr: GC pshared locks not more than each 25msecs by default

PR:     268532

(cherry picked from commit 4472a048cf95c9c1593a8b04655a59096b44b0c9)
DeltaFile
+22-3lib/libthr/thread/thr_pshared.c
+3-0lib/libthr/thread/thr_init.c
+1-0lib/libthr/thread/thr_private.h
+26-33 files

HardenedBSD/src 0143078 — sys/compat/linux linux_event.c

linux(4): Fix signal mask restoration in epoll_pwait(2)/epoll_pwait2(2)

PR:             298878

(cherry picked from commit 16a284b1cdfd45ba99c2723e7f88497e76b235ad)
DeltaFile
+14-11sys/compat/linux/linux_event.c
+14-111 files

HardenedBSD/src f12b765 — sys/kern kern_timeout.c

callout: do not retry a try-lock callout sooner than a tick

When softclock_call_cc() fails to acquire the lock of a CALLOUT_TRYLOCK
callout, it reschedules the callout half its precision after
cc_lastscan and halves the precision. Repeated failures shrink the
delay toward zero, and once the precision reaches 1 the callout is due
immediately: the timer fires again at once and softclock retries the
lock in a tight loop for as long as the lock is held.

If the lock owner runs on the callout's CPU and no other CPU is idle,
the softclock thread preempts it on every attempt, starving the thread
it is waiting on. On an 8-CPU arm64 VM, a test module holding the lock
saw 760,000 attempts per second, each with its own timer interrupt, and
progressed at 38% of its normal rate. On a 4-core amd64 system under
loopback TCP load, a netisr thread holding an inpcb lock made no
progress for 12 minutes while the TCP timer callout was retried 830,000
times per second.

Keep the half-precision retry, but never schedule it less than one

    [20 lines not shown]
DeltaFile
+20-3sys/kern/kern_timeout.c
+20-31 files

HardenedBSD/src de0a279 — libexec/nuageinit nuageinit, libexec/nuageinit/tests nuageinit.sh

nuageinit: apply meta-data if user-data is a script

Tested by:      adam.mizerski at ovhcloud.com
Sponsored by:   OVHcloud
Pull Request:   https://github.com/freebsd/freebsd-src/pull/2446
DeltaFile
+14-12libexec/nuageinit/nuageinit
+16-3libexec/nuageinit/tests/nuageinit.sh
+30-152 files

HardenedBSD/src 7e28b4e — bin/dd args.c, bin/ls print.c

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+9-5bin/dd/args.c
+6-4lib/libjail/jail.c
+4-3sbin/devmatch/devmatch.c
+3-3usr.sbin/jail/config.c
+2-2usr.sbin/pkg/pkg.c
+2-2bin/ls/print.c
+26-192 files not shown
+29-218 files

HardenedBSD/src f4eb661 — bin/dd args.c, bin/ls print.c

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+9-5bin/dd/args.c
+6-4lib/libjail/jail.c
+4-3sbin/devmatch/devmatch.c
+3-3usr.sbin/jail/config.c
+2-2usr.sbin/pkg/pkg.c
+2-2bin/ls/print.c
+26-192 files not shown
+29-218 files

HardenedBSD/src 32fcc66 — stand/libsa/zfs zfsimpl.c

stand: Load dynamic system attribute offsets

zfs_sa_load looks up all the system attribute offsets and stores them in
the mountpoint.

Sponsored by:           Netflix
Differential Revision:  https://reviews.freebsd.org/D60264
DeltaFile
+122-0stand/libsa/zfs/zfsimpl.c
+122-01 files

HardenedBSD/src 262fa46 — stand/libsa/zfs zfsimpl.c

stand: Implement zfs_dnode_readlink in terms of zfs_dnode_sa_lookup

Get the link offset using the zfs_dnode_sa_lookup helper now.

Recently, the symbolic links we rely on in the boot loader have stopped
working.

Prior to OpenZFS commit e90badec11d3 ("Inherit the project ID for every
object type", Matt Turner, 2026-08-14), symbolic link information was
written at a fixed offset in the SA data. Since that commit, the
inherited PROJIDs mean that all pools with quota enabled have started
writing symbolic links with a new, non-fixed offset. Old symbolic links
remained unchanged, but new ones were written with a different
offset. At work, we have all these things: rewritten BEs, quotas, and a
dependence on symbolic links in our boot path.

This came in on 2026-08-24 OpenZFS merge (22649d4dba73). This was 12
hours after stab week for August, so we didn't hit this until the
September stab week. Since the new kernel has to write links at the new

    [4 lines not shown]
DeltaFile
+4-31stand/libsa/zfs/zfsimpl.c
+4-311 files

HardenedBSD/src f382ef1 — stand/libsa/zfs zfsimpl.c

stand: update zfs_dnode_stat to use zfs_dnode_sa_lookup

Find the SA values with the zfs_dnode_sa_lookup and read out the
relevant bits for the stat buffer.

Sponsored by:           Netflix
Differential Revision:  https://reviews.freebsd.org/D60267
DeltaFile
+15-37stand/libsa/zfs/zfsimpl.c
+15-371 files

HardenedBSD/src 8bc06ba — stand/libsa/zfs zfsimpl.c

stand: Lookup specific SA value in a dnode

zfs_dnode_sa_lookup will look in the bonus part of the dnode for the
requested SA values, and fall back to the spill as if it's not there.

Sponsored by:           Netflix
Differential Revision:  https://reviews.freebsd.org/D60266
DeltaFile
+37-0stand/libsa/zfs/zfsimpl.c
+37-01 files

HardenedBSD/src 4175fa1 — stand/libsa/zfs zfsimpl.c

stand: Lookup the offsets for this SA bundle

Compute the offset for the data for this bundle and the requested data
type.

Sponsored by:           Netflix
Differential Revision:  https://reviews.freebsd.org/D60265
DeltaFile
+67-0stand/libsa/zfs/zfsimpl.c
+67-01 files

HardenedBSD/src ecd41c0 — stand/efi/boot1 zfs_module.c, stand/libsa/zfs zfs.c zfsimpl.c

stand: zfs_dnode_stat move from spa to mount argument

When reading dynamic system attributes, we'll need the mount argument
since we can no longer hard-code the offsets. Adjust zfs_dnode_stat to
take it.

Sponsored by:           Netflix
Differential Revision:  https://reviews.freebsd.org/D60261
DeltaFile
+4-4stand/libsa/zfs/zfsimpl.c
+1-1stand/libsa/zfs/zfs.c
+1-1stand/efi/boot1/zfs_module.c
+6-63 files

HardenedBSD/src 16cf795 — stand/libsa/zfs zfsimpl.c

stand: zfs_dnode_readlink move from spa to mount argument

For the dynamic system attributes, we'll need the mount argument. Adjust
zfs_dnode_readlink to take that argument.

Sponsored by:           Netflix
Differential Revision:  https://reviews.freebsd.org/D60262
DeltaFile
+5-4stand/libsa/zfs/zfsimpl.c
+5-41 files

HardenedBSD/src acbcb68 — stand/libsa/zfs zfsimpl.c

stand: Remove const from zfs_lookup's zfsmount argument

Dynamic system attribute layout can require modifications to the mount
structure on lookup. Drop the const to allow that.

Sponsored by:           Netflix
Differential Revision:  https://reviews.freebsd.org/D60260
DeltaFile
+1-1stand/libsa/zfs/zfsimpl.c
+1-11 files

HardenedBSD/src 34f2f57 — release Makefile.vm

EC2: Use stream-optimized VMDK format

Once enabled on all of the branches, this will reduce bandwidth
consumption from uploading weekly snapshot builds from ~500 GB to
~100 GB, as well as significantly speeding up the process.

MFC after:      2 months
Sponsored by:   Amazon
DeltaFile
+1-1release/Makefile.vm
+1-11 files