FreeBSD/src 2127135 — sys/kern kern_jail.c, sys/sys syscallsubr.h

jail_{get,set}: user_ implementations

This will enable compat implementations in the future.

Reviewed by:    jamie, jhb
Effort:         CHERI upstreaming
Sponsored by:   Innovate UK
Differential Revision:  https://reviews.freebsd.org/D60026
DeltaFile
+24-8sys/kern/kern_jail.c
+5-0sys/sys/syscallsubr.h
+29-82 files

FreeBSD/src afe41f1 — sys/kern subr_uio.c, sys/sys uio.h syscallsubr.h

sys/uio: add updateiov()

This function take a struct uio previously created by copyinuio and and
updates the lengths of the user-space iovec to match those in the uio.

To reduce the risks of pointer leakage and cross-ABI pointer confusion,
lengths are updated individually.

Reviewed by:    jamie, jhb
Effort:         CHERI upstreaming
Sponsored by:   DARPA, AFRL, Innovate UK
Differential Revision:  https://reviews.freebsd.org/D60025
DeltaFile
+18-0sys/kern/subr_uio.c
+7-0sys/sys/syscallsubr.h
+1-0sys/sys/uio.h
+26-03 files

FreeBSD/ports 3c258ab — net-im/deltachat-desktop Makefile distinfo, net-im/deltachat-desktop/files patch-packages_target-electron_src_deltachat_controller.ts

net-im/deltachat-desktop: Update to 2.62.0
DeltaFile
+72-90net-im/deltachat-desktop/files/packagejsons/pnpm-lock.yaml
+56-49net-im/deltachat-desktop/pkg-plist
+13-4net-im/deltachat-desktop/files/patch-packages_target-electron_src_deltachat_controller.ts
+5-5net-im/deltachat-desktop/distinfo
+3-6net-im/deltachat-desktop/files/packagejsons/packages/target-electron/package.json
+3-3net-im/deltachat-desktop/Makefile
+152-1573 files not shown
+158-1619 files

FreeBSD/ports fa3f569 — net/deltachat-rpc-server Makefile Makefile.crates

net/deltachat-rpc-server: Update to 2.62.0
DeltaFile
+53-51net/deltachat-rpc-server/distinfo
+25-24net/deltachat-rpc-server/Makefile.crates
+2-2net/deltachat-rpc-server/Makefile
+80-773 files

FreeBSD/ports a866a85 — graphics/R-cran-s2 distinfo Makefile

graphics/R-cran-s2: Update to 1.1.13

ChangeLog: https://cran.r-project.org/web/packages/s2/news/news.html
DeltaFile
+7-9graphics/R-cran-s2/Makefile
+3-3graphics/R-cran-s2/distinfo
+10-122 files

FreeBSD/ports e08c033 — textproc/hs-pandoc pkg-descr Makefile

textproc/hs-pandoc: Update 3.11 => 3.12

Approved by:            haskell@ (alven@)
DeltaFile
+175-61textproc/hs-pandoc/distinfo
+74-32textproc/hs-pandoc/Makefile.cabal
+3-5textproc/hs-pandoc/Makefile
+1-1textproc/hs-pandoc/pkg-descr
+253-994 files

FreeBSD/ports 9b82eb5 — net-im/parla Makefile distinfo

net-im/parla: Update to 0.9.8
DeltaFile
+3-3net-im/parla/distinfo
+1-1net-im/parla/Makefile
+4-42 files

FreeBSD/doc 8d1d1be — website/content/en/releases/15.1R/ec2-ami-ids latest.adoc

15.1: Update "latest" AMIs

We now have 15.1-RELEASE-p4 AMIs.

Approved by:    re (implicit)
Sponsored by:   Amazon
DeltaFile
+512-512website/content/en/releases/15.1R/ec2-ami-ids/latest.adoc
+512-5121 files

FreeBSD/doc 610ed77 — website/content/en/releases/15.0R/ec2-ami-ids latest.adoc

15.0: Update "latest" AMIs

We now have 15.0-RELEASE-p14 AMIs.

Approved by:    re (implicit)
Sponsored by:   Amazon
DeltaFile
+512-512website/content/en/releases/15.0R/ec2-ami-ids/latest.adoc
+512-5121 files

FreeBSD/ports 82bf977 — security/cvechecker pkg-descr pkg-plist, security/cvechecker/files pkg-message.in patch-scripts_cverules

security/cvechecker: Remove expired port

2026-09-28 security/cvechecker: The project has been declared EOL by its author.
DeltaFile
+0-52security/cvechecker/Makefile
+0-48security/cvechecker/files/patch-scripts_pullcves
+0-37security/cvechecker/files/patch-scripts_cverules
+0-21security/cvechecker/pkg-plist
+0-14security/cvechecker/files/pkg-message.in
+0-9security/cvechecker/pkg-descr
+0-1813 files not shown
+1-1859 files

FreeBSD/ports c387e46 — graphics/nvidia-drm-66-kmod distinfo, graphics/nvidia-drm-latest-kmod distinfo

x11/nvidia-driver, x11/nvidia-kmod, x11/linux-nvidia-libs, graphics/nvidia-drm*-kmod, x11nvidia-settings, x11/nvidia-xconfig: Update to 595.104.02

Update to latest Production Branch of drivers 595.104.02:
https://www.nvidia.com/en-us/drivers/details/279809/

Linux counterparts for x11/linux-nvidia-libs:
https://www.nvidia.com/en-us/drivers/details/279807/

PR:              298790
Differential Revision:  https://reviews.freebsd.org/D59925
DeltaFile
+3-3x11/nvidia-xconfig/distinfo
+3-3x11/nvidia-settings/distinfo
+3-3x11/nvidia-driver/distinfo
+3-3x11/linux-nvidia-libs/distinfo
+3-3graphics/nvidia-drm-latest-kmod/distinfo
+3-3graphics/nvidia-drm-66-kmod/distinfo
+18-1812 files not shown
+36-3618 files

FreeBSD/ports da85b05 — editors/openoffice-4 Makefile

editors/openoffice-4: undeprecate, no longer depends on expired textproc/libtextcat
DeltaFile
+0-3editors/openoffice-4/Makefile
+0-31 files

FreeBSD/ports cd28f28 — net/rclone-browser Makefile

net/rclone-browser: Mark deprecated

PR:             298903
Approved by:    driesm (maintainer)

(cherry picked from commit 3f5dc4e97b0fd767e671b70ab3bac46d174c0277)
DeltaFile
+4-0net/rclone-browser/Makefile
+4-01 files

FreeBSD/ports 3f5dc4e — net/rclone-browser Makefile

net/rclone-browser: Mark deprecated

PR:             298903
Approved by:    driesm (maintainer)
DeltaFile
+4-0net/rclone-browser/Makefile
+4-01 files

FreeBSD/ports 0707d11 — textproc/py-python-slugify Makefile distinfo

textproc/py-python-slugify: update to 9.1.2

Changes:        https://github.com/un33k/python-slugify/blob/v9.1.2/CHANGELOG.md
Reported-by:    repology, portscout
DeltaFile
+3-3textproc/py-python-slugify/distinfo
+1-1textproc/py-python-slugify/Makefile
+4-42 files

FreeBSD/ports 97a84ef — astro/pykep Makefile, audio/guitarix-lv2 Makefile

*/*: update boost consumers after boost-1.92
DeltaFile
+1-1audio/wavetral/Makefile
+1-1audio/supercollider/Makefile
+1-1audio/patchage/Makefile
+1-1audio/ncmpcpp/Makefile
+1-1audio/guitarix-lv2/Makefile
+1-1astro/pykep/Makefile
+6-6256 files not shown
+262-175262 files

FreeBSD/ports 5ec5b66 — devel/boost-libs Makefile pkg-plist, devel/boost-libs/files patch-libs_process_CMakeLists.txt patch-libs_graph_test_Jamfile.v2

devel/boost*: update to 1.92.0 release (+)

Include corresponding update for boost_build to 5.5.2
Introduce new library, Cobalt, which forces C++20 standart (option OFF by default)

Release notes:  https://www.boost.org/releases/1.92.0/
DeltaFile
+139-7devel/boost-libs/pkg-plist
+18-0devel/boost-libs/files/patch-libs_mpi_src_python_py__request.cpp
+0-16devel/boost-libs/files/patch-libs_graph_test_Jamfile.v2
+16-0devel/boost-libs/files/patch-libs_mpi_src_python_request__with__value.hpp
+14-1devel/boost-libs/Makefile
+14-0devel/boost-libs/files/patch-libs_process_CMakeLists.txt
+201-2412 files not shown
+253-5518 files

FreeBSD/ports 7363e53 — net/rayfish pkg-descr Makefile, net/rayfish/files rayfish.in

net/rayfish: New port

Rayfish is a peer-to-peer mesh VPN for your computers, phones, servers,
and friends' machines. It creates encrypted private networks without an
account, control server, or infrastructure to host.

Peers connect directly when possible and use encrypted relays when they
cannot. Each device has a stable address derived from its cryptographic
identity, plus a name such as alice.gaming.ray through Magic DNS.
DeltaFile
+1,657-0net/rayfish/distinfo
+827-0net/rayfish/Makefile.crates
+33-0net/rayfish/files/rayfish.in
+25-0net/rayfish/pkg-message
+23-0net/rayfish/Makefile
+4-0net/rayfish/pkg-descr
+2,569-02 files not shown
+2,571-18 files

FreeBSD/ports 9798af9 — x11-fonts/iosevka Makefile distinfo

x11-fonts/iosevka: Update to 34.9.0
DeltaFile
+49-49x11-fonts/iosevka/distinfo
+1-1x11-fonts/iosevka/Makefile
+50-502 files

FreeBSD/ports 7eb2fda — devel/etcd37 Makefile distinfo

devel/etcd37: Update to 3.7.2

Sponsored by:   fme AG
DeltaFile
+21-21devel/etcd37/distinfo
+1-1devel/etcd37/Makefile
+22-222 files

FreeBSD/ports 0766e9d — sysutils/bricoler Makefile distinfo

sysutils/bricoler: Refresh distfiles
DeltaFile
+3-3sysutils/bricoler/distinfo
+1-4sysutils/bricoler/Makefile
+4-72 files

FreeBSD/ports 08a1cdd — math/pffft pkg-plist distinfo, math/pffft/files patch-pffft__double.c patch-src_pffft__double.c

math/pffft: update 2022.12.19 → 1.1.0
DeltaFile
+0-57math/pffft/files/patch-CMakeLists.txt
+9-11math/pffft/Makefile
+13-0math/pffft/files/patch-src_pffft__double.c
+0-11math/pffft/files/patch-pffft__double.c
+3-3math/pffft/distinfo
+4-0math/pffft/pkg-plist
+29-821 files not shown
+30-837 files

FreeBSD/src 7b8e59c — crypto/openssl/ssl d1_lib.c, crypto/openssl/ssl/statem statem_dtls.c

openssl: Fix CVE-2026-84782

This is a backport of an upstream commit to fix:
  dtls: reset init_off before retransmitting a message

Approved by:    so
Security:       FreeBSD-SA-26:68.openssl
Security:       CVE-2026-84782
DeltaFile
+17-0crypto/openssl/ssl/d1_lib.c
+2-0crypto/openssl/ssl/statem/statem_dtls.c
+19-02 files

FreeBSD/src 666f08d — lib/libc/sys fcntl.2, sys/kern vfs_syscalls.c

vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors

The FD_RESOLVE_BENEATH flag was intended to try to resolve bugzilla PR
262179 without entirely disallowing fd passing between jails.  However,
one can use renameat() to bypass the restriction: upon receiving a
directory fd with FD_RESOLVE_BENEATH set, a jailed process can still
move its CWD or one of its ancestors to the directory, and just cd
out of its jail root.

So disallow renameat() when either the source or destination directory
fds has FD_RESOLVE_BENEATH set, like we do with fchdir() and fchroot()
to prevent similar escapes.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101305
PR:             262179
Reported by:    firk at cantconnect.ru
Reviewed by:    olce, kib
Differential Revision:  https://reviews.freebsd.org/D59875
DeltaFile
+8-1lib/libc/sys/fcntl.2
+9-0sys/kern/vfs_syscalls.c
+17-12 files

FreeBSD/src 5f9f2ac — sys/fs/fdescfs fdesc_vnops.c, tests/sys/fs Makefile

fdescfs: Pass up additional metadata during lookups

When an fdescfs mount has the nodup option set, fdesc_lookup(/dev/fd/n)
returns the vnode referenced by file descriptor n, rather than returning
an fdescfs vnode.  This meant that fd metadata attached to fd n was not
preserved when reopening the file, which is contrary to the expected
semantics for capsicum rights and the UF_RESOLVE_BENEATH fd flag.  For
regular fdescfs mounts, this metadata is copied via dupfdopen().

Fix the problem by passing up this metadata through the nameidata
structure.  Thus, if one opens /dev/fd/n, the returned fd will inherit
UF_RESOLVE_BENEATH and the capability rights of fd n.  Add some
regression tests as well.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101304
Reported by:    Jan Bramkamp
Reviewed by:    kib

    [2 lines not shown]
DeltaFile
+274-0tests/sys/fs/fdescfs/fdescfs_test.c
+35-2sys/fs/fdescfs/fdesc_vnops.c
+9-0tests/sys/fs/fdescfs/Makefile
+1-0tests/sys/fs/Makefile
+319-24 files

FreeBSD/src f89e6b5 — sys/kern kern_descrip.c, sys/sys filedesc.h

file: Add a helper function to check whether filecaps are full

In a couple of places we want to know whether someone has limited rights
on an fd.  There, we want a predicate which determines whether the set
of rights is smaller than CAP_ALL, and whether there are explicit ioctl
or fcntl lists.  Factor this out into a helper function, in preparation
for use elsewhere.

No functional change intended.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59884
DeltaFile
+12-8sys/kern/kern_descrip.c
+1-0sys/sys/filedesc.h
+13-82 files

FreeBSD/src 616f35f — lib/libc/capability cap_rights_init.3, sys/kern subr_capability.c kern_descrip.c

file: Add filecaps_intersect() and cap_rights_intersect()

These routines let one compute the intersection of two sets of filecaps
or capability rights, just as filecaps_merge() and cap_rights_merge()
compute the union.  This will be useful in an upcoming patch.

filecaps_intersect() is complex due to the need to merge sets of ioctls.
For now this is implemented with a dumb nested loop on the basis that
ioctl lists are typically short enough that this is fine.  It may be
better to instead sort the two lists first and step through them
together.

No functional change intended.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59885
DeltaFile
+49-0sys/kern/kern_descrip.c
+23-0sys/kern/subr_capability.c
+14-2lib/libc/capability/cap_rights_init.3
+1-0sys/sys/filedesc.h
+1-0sys/sys/capsicum.h
+88-25 files

FreeBSD/src 04f841a — sys/kern sysv_sem.c

sysvsem: Fix another sequence number wraparound race

semop() may sleep waiting for a semaphore.  Upon waking up, it checks to
see if the set's sequence number has changed, indicating that the set
was removed.  The sequence number is not wide enough to prevent a false
negative due to wraparound, in which case the subsequent access of
`semakptr->u.__sem_base[sopptr->sem_num]` may be out of bounds.  This
race can be leveraged to elevate privileges.

Fix this by introducing a 64-bit sequence number for each semaphore
pool.  This is wide enough to make the race impossible to hit.  Allocate
a separate array for them, as we cannot really change the layout of
struct semid_kernel since some userspace tools (e.g., ipcrm(1)) embed
the layout.

While here, use semvalid() instead of open-coding its implementation,
convert a couple of flags to be bool, and use a better variable name to
store required permissions.


    [8 lines not shown]
DeltaFile
+39-31sys/kern/sysv_sem.c
+39-311 files

FreeBSD/src 6c9ee5f — lib/libsys fcntl.2, sys/kern vfs_syscalls.c

vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors

The FD_RESOLVE_BENEATH flag was intended to try to resolve bugzilla PR
262179 without entirely disallowing fd passing between jails.  However,
one can use renameat() to bypass the restriction: upon receiving a
directory fd with FD_RESOLVE_BENEATH set, a jailed process can still
move its CWD or one of its ancestors to the directory, and just cd
out of its jail root.

So disallow renameat() when either the source or destination directory
fds has FD_RESOLVE_BENEATH set, like we do with fchdir() and fchroot()
to prevent similar escapes.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Security:       CVE-2026-101305
PR:             262179
Reported by:    firk at cantconnect.ru
Reviewed by:    olce, kib
Differential Revision:  https://reviews.freebsd.org/D59875
DeltaFile
+8-1lib/libsys/fcntl.2
+9-0sys/kern/vfs_syscalls.c
+17-12 files

FreeBSD/src 4536e59 — lib/libc/capability cap_rights_init.3, sys/kern subr_capability.c kern_descrip.c

file: Add filecaps_intersect() and cap_rights_intersect()

These routines let one compute the intersection of two sets of filecaps
or capability rights, just as filecaps_merge() and cap_rights_merge()
compute the union.  This will be useful in an upcoming patch.

filecaps_intersect() is complex due to the need to merge sets of ioctls.
For now this is implemented with a dumb nested loop on the basis that
ioctl lists are typically short enough that this is fine.  It may be
better to instead sort the two lists first and step through them
together.

No functional change intended.

Approved by:    so
Security:       FreeBSD-SA-26:66.jail
Reviewed by:    kib
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59885
DeltaFile
+49-0sys/kern/kern_descrip.c
+23-0sys/kern/subr_capability.c
+14-2lib/libc/capability/cap_rights_init.3
+1-0sys/sys/filedesc.h
+1-0sys/sys/capsicum.h
+88-25 files