HardenedBSD/src 6f086b9 — share/man/man4 Makefile, share/man/man9 acl.9

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+18-1share/man/man9/acl.9
+0-13sys/contrib/openzfs/module/os/freebsd/zfs/sysctl_os.c
+1-0share/man/man4/Makefile
+19-143 files

HardenedBSD/src cb568a0 — contrib/expat Changes, contrib/expat/doc reference.html

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+790-0contrib/expat/tests/props_tests.c
+681-73contrib/expat/doc/reference.html
+413-154contrib/expat/lib/xmlparse.c
+56-220contrib/expat/lib/xmltok.c
+131-39contrib/expat/tests/basic_tests.c
+102-26contrib/expat/Changes
+2,173-51248 files not shown
+3,011-89354 files

HardenedBSD/src 8b38529 — share/man/man4 Makefile, share/man/man9 acl.9

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+18-1share/man/man9/acl.9
+0-13sys/contrib/openzfs/module/os/freebsd/zfs/sysctl_os.c
+1-0share/man/man4/Makefile
+19-143 files

HardenedBSD/src 4354c48 — contrib/expat Changes, contrib/expat/doc reference.html

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+790-0contrib/expat/tests/props_tests.c
+681-73contrib/expat/doc/reference.html
+413-154contrib/expat/lib/xmlparse.c
+56-220contrib/expat/lib/xmltok.c
+131-39contrib/expat/tests/basic_tests.c
+102-26contrib/expat/Changes
+2,173-51248 files not shown
+3,011-89354 files

HardenedBSD/src 05c49e2 — share/man/man4 Makefile

man: Link mgb.4 to if_mgb.4

For consistency, create a symbolic link from mgb.4 to also
if_mgb.4

Reviewed by:            #manpages, ziaee, emaste
Differential Revision:  https://reviews.freebsd.org/D60551
MFC after:              3 days
DeltaFile
+1-0share/man/man4/Makefile
+1-01 files

HardenedBSD/src 7a48c3f — share/man/man9 acl.9

acl(9): expound on NFSv4 constants' meanings

This change adds missing documentation for various NFSv4 constants
supported by acl(9).

Bump `.Dd` for the change.

MFC after:      1 week
Reviewed by:    rmacklem
Differential Revision:  https://reviews.freebsd.org/D58736
DeltaFile
+18-1share/man/man9/acl.9
+18-11 files

HardenedBSD/src 62e958d — sys/contrib/openzfs/module/os/freebsd/zfs sysctl_os.c

zfs: drop duplicate `vfs.zfs.metaslab.condense_pct` sysctl

`metaslab.c` already registers this tunable via `ZFS_MODULE_PARAM`, so the
`SYSCTL_UINT` here is a second registration of the same leaf. This
resulted in messages like:

```
sysctl_register_oid: can't re-use a leaf (vfs.zfs.metaslab.condense_pct)
```

Remove the duplicate sysctl registration, as upstream (OpenZFS) did.

MFC after:      1 week
Signed-off-by:  Christos Longros <chris.longros at gmail.com>
Reviewed by:    imp, mm, ngie
Differential Revision:  https://reviews.freebsd.org/D57721
DeltaFile
+0-13sys/contrib/openzfs/module/os/freebsd/zfs/sysctl_os.c
+0-131 files

HardenedBSD/src 406596b — sys/netinet/libalias alias_local.h alias_db.h

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+102-42sys/netinet/libalias/alias_db.c
+7-1sys/netinet/libalias/alias_db.h
+4-1sys/netinet/libalias/alias_local.h
+113-443 files

HardenedBSD/src 5cebf4c — sys/netinet/libalias alias_local.h alias_db.h

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+102-42sys/netinet/libalias/alias_db.c
+7-1sys/netinet/libalias/alias_db.h
+4-1sys/netinet/libalias/alias_local.h
+113-443 files

HardenedBSD/src 179dfe4 — lib/lib80211 lib80211_regdomain.c

lib80211: fix build with eXpat 2.9.0

eXpat 2.9.0 deprecates XML_GetCurrentLineNumber() in favour of
XML_GetCurrentLineNumber64().  The new function behaves the same
as the old one but is not prone to 32 bit integer wrap-around.

(cherry picked from commit 657c089950a0388811c7ba3f6d3e7127c297864e)
DeltaFile
+27-26lib/lib80211/lib80211_regdomain.c
+27-261 files

HardenedBSD/src 94fd9b5 — contrib/expat Changes, contrib/expat/doc reference.html

contrib/expat: import expat 2.9.0

Changes: https://github.com/libexpat/libexpat/blob/R_2_9_0/expat/Changes

Security:       CVE-2026-102633
Security:       CVE-2026-77214

(cherry picked from commit 22c3edb31297a79ec3c7bf8f906be2df11b472d2)
DeltaFile
+790-0contrib/expat/tests/props_tests.c
+681-73contrib/expat/doc/reference.html
+413-154contrib/expat/lib/xmlparse.c
+56-220contrib/expat/lib/xmltok.c
+131-39contrib/expat/tests/basic_tests.c
+102-26contrib/expat/Changes
+2,173-51247 files not shown
+2,984-86753 files

HardenedBSD/src 16bc669 — sys/netinet/libalias alias_local.h alias_db.h

libalias: index fully specified inbound links by remote endpoint

Inbound lookups find the (alias address, alias port, link type) group
with a splay tree and then walk grp->full, a list of every fully
specified link in that group, comparing the remote address and port.
With redirect_addr in front of a busy server, every client connection
to public:443 lands in the same group, so each inbound packet that is
not near the head of the list walks all of it.  TCP links live up to
24 hours unless libalias sees a clean close, so the list can grow to
hundreds of thousands of entries and saturate a core at a few hundred
packets per second.

Keep the fully specified links of a group in an RB tree ordered by
(dst_addr, dst_port).  Links that share an endpoint are ordered newest
first by a per-instance insertion counter, which keeps the "most recent
link wins" behaviour of the list (tested by 3_natin:2_portoverlap).

Lookups with an unknown remote address and a known port still scan the
group.  Each link grows by 16 bytes.

    [8 lines not shown]
DeltaFile
+102-42sys/netinet/libalias/alias_db.c
+7-1sys/netinet/libalias/alias_db.h
+4-1sys/netinet/libalias/alias_local.h
+113-443 files

HardenedBSD/src b7632e1 — sys/dev/bnxt/bnxt_en bnxt_hwrm.c bnxt_sysctl.c, usr.sbin/sysconf sysconf_poudriere.c

Merge remote-tracking branch 'rad/hardened/current/master' into hardened/current/pledge
DeltaFile
+2,257-0sys/dev/bnxt/bnxt_en/bnxt_ktls.c
+1,080-0sys/dev/bnxt/bnxt_en/bnxt_mpc.c
+793-264sys/dev/bnxt/bnxt_en/if_bnxt.c
+677-0usr.sbin/sysconf/sysconf_poudriere.c
+654-19sys/dev/bnxt/bnxt_en/bnxt_sysctl.c
+422-156sys/dev/bnxt/bnxt_en/bnxt_hwrm.c
+5,883-439153 files not shown
+10,401-2,010159 files

HardenedBSD/src a39a861 — sys/dev/acpica acpi_timer.c, sys/fs/cd9660 cd9660_rrip.c

Merge remote-tracking branch 'rad/hardened/15-stable/main' into hardened/15-stable/pledge
DeltaFile
+167-61sys/fs/cd9660/cd9660_rrip.c
+84-134sys/dev/acpica/acpi_timer.c
+174-35usr.sbin/pciconf/pciconf.c
+101-88sys/kern/kern_jail.c
+69-70usr.sbin/bhyve/pci_emul.c
+93-0sys/sys/jail.h
+688-38849 files not shown
+1,054-61255 files

HardenedBSD/src 2baf9b6 — cddl/contrib/opensolaris/tools/ctf/cvt util.c, lib/libthr/thread thr_private.h thr_mutex.c

Merge branch 'freebsd/current/main' into hardened/current/master
DeltaFile
+43-39sys/dev/hyperv/vmbus/hyperv_mmu.c
+48-0sys/dev/amdgpio/amdgpio.c
+0-10cddl/contrib/opensolaris/tools/ctf/cvt/util.c
+1-8lib/libthr/thread/thr_mutex.c
+0-6sys/dev/bnxt/bnxt_en/bnxt_dcb.c
+6-0lib/libthr/thread/thr_private.h
+98-632 files not shown
+100-658 files

HardenedBSD/src c6af277 — sys/compat/linsysfs linsysfs.c, usr.bin/hexdump odsyntax.c

Merge branch 'freebsd/15-stable/main' into hardened/15-stable/main
DeltaFile
+56-2sys/compat/linsysfs/linsysfs.c
+1-1usr.bin/hexdump/odsyntax.c
+57-32 files

HardenedBSD/src 7ed9a5a — sys/compat/linsysfs linsysfs.c

linux: Exposes renderD nodes and chardev in sysfs

To allow normal users to render through the render device, we expose the
renderD node. This enables Wayland applications to use hardware
acceleration when running under the Linux emulator.

Additionally, libdrm and Mesa need to look up
/sys/dev/char/<major>:<minor> and <pcidev>/drm to identify the
corresponding renderer device (e.g., a renderD device). We expose this
path as well so that libdrm can locate the renderer.

Differential Revision: https://reviews.freebsd.org/D59190

(cherry picked from commit 102adf88e6e8f83a9ab9769732d168c501f8eb6c)
DeltaFile
+56-2sys/compat/linsysfs/linsysfs.c
+56-21 files

HardenedBSD/src 8c47cbc — usr.bin/hexdump odsyntax.c

hexdump: Support octal and hex for -N option

GNU hexdump supports octal and hex, we add supports for BSD style
hexdump for better compatibility.

See: https://github.com/llvm/llvm-project/pull/206581/

MFC after:      2 weeks
Sponsored by:   The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D58074

(cherry picked from commit b8f1972d51cf93ba4393d621b126dbd408423b87)
DeltaFile
+1-1usr.bin/hexdump/odsyntax.c
+1-11 files

HardenedBSD/src 5b1f1fd — sys/dev/hyperv/vmbus hyperv_mmu.c

hyperv: Fix single page invalidation path

A single page invalidation sets addr2 == 0. In the original code, it
falsely flush the whole address in non global pmap. However, the
kernel pmap are all PG_G, which means a single page flush will always be
staled and thus become invalid. As a result, we set parameter based on
their op in a new helper function instead of relying on args. This
affects only on AMD platform as Intel has their PTI implementation.

PR:     291577
Tested by:      franco at opnsense.org
MFC after:      2 weeks
Differential Revision: https://reviews.freebsd.org/D60380
DeltaFile
+43-39sys/dev/hyperv/vmbus/hyperv_mmu.c
+43-391 files

HardenedBSD/src 305c304 — lib/libthr/thread thr_init.c thr_private.h

libthr: Support disable spinloop

Like yieldloops, we shoulde be able to set _thr_spinloops to zero.
Originally, it makes us to enformce default spin time even if we try to
disable it. Make MUTEX_ADAPTIVE_SPINS a one time initialization now.

Reviewed by:    kib
MFC after:      2 weeks
Differential Revision: https://reviews.freebsd.org/D60486
DeltaFile
+1-8lib/libthr/thread/thr_mutex.c
+6-0lib/libthr/thread/thr_private.h
+1-1lib/libthr/thread/thr_init.c
+8-93 files

HardenedBSD/src 16d92e9 — sys/dev/amdgpio amdgpio.c

amdgpio: Suspend routine

Mask all interrupts when suspending and warn when there are unserviced
interrupts which might block entry to S0i3.

In the future we won't want to mask wake interrupts.

Once we can actually make use of GPIO interrupts on x86, we'll also want
to unmask relevant pins when resuming.

Reviewed by:    aokblast, avg
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D51589
DeltaFile
+48-0sys/dev/amdgpio/amdgpio.c
+48-01 files

HardenedBSD/src 6c3f2b8 — sys/dev/mgb if_mgb.c

mgb: Correct TX interrupt bit

The TX interrupt handler checked MGB_INTR_STS_RX(qidx) instead of
MGB_INTR_STS_TX(qidx) -- presumably a copy-paste issue.

Because the driver does not use TX interrupts so there was no actual
issue in practice.

Reviewed by:    adrian
Sponsored by:   The FreeBSD Foundation
Fixes: 8890ab7758b8 ("Introduce if_mgb driver for Microchip LAN743x PCIe NIC")
Differential Revision: https://reviews.freebsd.org/D60550
DeltaFile
+1-1sys/dev/mgb/if_mgb.c
+1-11 files

HardenedBSD/src 31cbd8f — sys/dev/bnxt/bnxt_en bnxt_dcb.c

bnxt_en: dcb: stop zeroing ETS and PFC config in bnxt_dcb_init()

bnxt_dcb_init() currently pushes all-zero ETS and PFC settings to
the firmware at every attach. This reserves bandwidth allocation
for RoCE traffic, which prevents L2 traffic from reaching line rate.

These settings should only be updated with valid values when the
RoCE driver is loaded. Therefore, we should stop programming them
during bnxt_dcb_init().

Signed-off-by:  Andy Gospodarek <gospo at broadcom.com>
Reviewed by:    chandrakanth.patil_broadcom.com, gallatin
MFC after:      2 weeks
Sponsored by:   Broadcom Inc.
Differential Revision:  https://reviews.freebsd.org/D60516
DeltaFile
+0-6sys/dev/bnxt/bnxt_en/bnxt_dcb.c
+0-61 files

HardenedBSD/src e959f2a — cddl/contrib/opensolaris/tools/ctf/cvt util.c

ctf*: exit with error upon terminate()

The initial port of the CTF tools had a FreeBSD-specific patch to print
the termination message but exit with a 0 status, with a goal of getting
as much to build as possible and silently ignoring any issues.

We're now past the point where silently ignoring failures makes sense.
Any future issues need to be found and addressed.

PR:             276826
PR:             276930 [exp-run]
Reviewed by:    markj
Sponsored by:   The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D43743
DeltaFile
+0-10cddl/contrib/opensolaris/tools/ctf/cvt/util.c
+0-101 files

HardenedBSD/src 617af6c — libexec/rtld-elf map_object.c, sys/kern kern_jail.c

HBSD: Resolve merge conflicts

Signed-off-by:  Shawn Webb <shawn.webb at hardenedbsd.org>
DeltaFile
+0-5sys/kern/kern_jail.c
+0-5libexec/rtld-elf/map_object.c
+0-102 files

HardenedBSD/src 0c13d2d — sys/dev/acpica acpi_timer.c, sys/fs/cd9660 cd9660_rrip.c

Merge remote-tracking branch 'rad/freebsd/15-stable/main' into hardened/15-stable/main

Conflicts:
        libexec/rtld-elf/map_object.c (unresolved)
        sys/kern/kern_jail.c (unresolved)
DeltaFile
+167-61sys/fs/cd9660/cd9660_rrip.c
+84-134sys/dev/acpica/acpi_timer.c
+174-35usr.sbin/pciconf/pciconf.c
+104-86sys/kern/kern_jail.c
+69-70usr.sbin/bhyve/pci_emul.c
+93-0sys/sys/jail.h
+691-38647 files not shown
+1,004-60653 files

HardenedBSD/src 6d8b5a8 — sys/dev/sound/pcm mixer.c

HBSD: Resolve merge conflict

Leave the microphone muted by default.

Signed-off-by:  Shawn Webb <shawn.webb at hardenedbsd.org>
DeltaFile
+0-4sys/dev/sound/pcm/mixer.c
+0-41 files

HardenedBSD/src 31393cf — sys/dev/bnxt/bnxt_en bnxt_hwrm.c bnxt_sysctl.c, usr.sbin/sysconf sysconf_poudriere.c

Merge remote-tracking branch 'rad/freebsd/current/main' into hardened/current/master

Conflicts:
        sys/dev/sound/pcm/mixer.c (unresolved)
DeltaFile
+2,257-0sys/dev/bnxt/bnxt_en/bnxt_ktls.c
+1,080-0sys/dev/bnxt/bnxt_en/bnxt_mpc.c
+793-264sys/dev/bnxt/bnxt_en/if_bnxt.c
+677-0usr.sbin/sysconf/sysconf_poudriere.c
+654-19sys/dev/bnxt/bnxt_en/bnxt_sysctl.c
+422-156sys/dev/bnxt/bnxt_en/bnxt_hwrm.c
+5,883-439146 files not shown
+10,305-1,945152 files

HardenedBSD/src 02880dd — sys/dev/thunderbolt nhi_var.h nhi_reg.h

thunderbolt: Router suspend routine

Suspend routine for USB4 v1.0 NHIs. This will work on v2.0 NHIs too for
now, but there's ideally a different method we should be using for those
in fine.

Reviewed by:    imp, ngie, emaste
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D49453
DeltaFile
+78-0sys/dev/thunderbolt/router.c
+13-0sys/dev/thunderbolt/nhi.c
+11-0sys/dev/thunderbolt/router_var.h
+4-2sys/dev/thunderbolt/nhi_pci.c
+5-0sys/dev/thunderbolt/nhi_reg.h
+2-0sys/dev/thunderbolt/nhi_var.h
+113-26 files

HardenedBSD/src 39f7dbf — share/mk bsd.dirs.mk

bsd.dirs.mk: Improve "installing DIRS" message

Some of these messages looked at first glance like they were incorrectly
concatenated, e.g. "installing DIRS testsFILESDIR".  Add a colon to
clarify.

Reviewed by:    brooks, imp
Sponsored by:   The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D60525
DeltaFile
+1-1share/mk/bsd.dirs.mk
+1-11 files