FreeBSD/ports 49ee85bdevel/gitaly distinfo, net/gitlab-agent distinfo

www/gitlab: security and patch update to 19.4.1

Changes:        https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/?nav=19.4.1
Security:       3f11e437-b7cd-11f1-a883-2cf05da270f3
DeltaFile
+13-13devel/gitaly/distinfo
+6-6www/gitlab/distinfo
+5-5www/gitlab-workhorse/distinfo
+5-5www/gitlab-pages/distinfo
+5-5net/gitlab-agent/distinfo
+1-1www/gitlab/Makefile.common
+35-356 files

FreeBSD/src 8d94a93contrib/atf/atf-sh integration_test.sh

integration_test: backport fix from freebsd/atf

See the related merge commit for more details.

MFC after:      28 days
Obtained from:  [freebsd/atf at 2690b04c][upstream]
Fixes:          95223108 ("contrib/atf: upgrade to 0.26")

Merge commit '8fd09407c8e64fd26d095c9b00990c545577db5a'

[upstream]: https://github.com/freebsd/atf/commit/2690b04cbc608af165a58426b7275c063b779f03
DeltaFile
+1-1contrib/atf/atf-sh/integration_test.sh
+1-11 files

FreeBSD/src 8fd0940atf-sh integration_test.sh

atf-sh/integration_test: fix hang when invoked via kyua

The code in `create_test_program` called cat on top of the calling
function, resulting in code that would hang waiting for an EOF to be
sent. This was wrong. Pass the heredoc output directly to
`create_test_program` so the content is output to the test program once.

Closes: #201
Signed-off-by: Enji Cooper <ngie at FreeBSD.org>
DeltaFile
+1-1atf-sh/integration_test.sh
+1-11 files

FreeBSD/ports 42b6b5bsecurity/vuxml/vuln 2026.xml

security/vuxml: document gitlab vulnerabilities
DeltaFile
+49-0security/vuxml/vuln/2026.xml
+49-01 files

FreeBSD/ports 10714b9textproc/py-jinjanator-plugins Makefile, textproc/py-jinjanator-plugins/files patch-pyproject.toml

textproc/py-jinjanator-plugins: Chase py-hatchling update

(cherry picked from commit dc6e55b7119993abcfe678bcc1e72c9f2f174a2d)
DeltaFile
+2-1textproc/py-jinjanator-plugins/Makefile
+1-1textproc/py-jinjanator-plugins/files/patch-pyproject.toml
+3-22 files

FreeBSD/ports dc6e55btextproc/py-jinjanator-plugins Makefile, textproc/py-jinjanator-plugins/files patch-pyproject.toml

textproc/py-jinjanator-plugins: Chase py-hatchling update
DeltaFile
+1-1textproc/py-jinjanator-plugins/files/patch-pyproject.toml
+1-1textproc/py-jinjanator-plugins/Makefile
+2-22 files

FreeBSD/ports ed66a84editors/cudatext Makefile pkg-plist

editors/cudatext: Update to 1.237.0.2

ChangeLog at:   https://github.com/Alexey-T/CudaText/blob/master/app/readme/history.txt
DeltaFile
+5-5editors/cudatext/distinfo
+9-0editors/cudatext/pkg-plist
+2-2editors/cudatext/Makefile
+16-73 files

FreeBSD/src bcc27cfsys/netinet raw_ip.c

raw ip: clear sin_port on bind(2)

Application may set sin_port to some value.  Although this value is not
used by SOCK_RAW, it breaks a check that the address is available.  A
perfect fix would be not use sockaddrs for ifaddrs, but that would be a
bigger change.

PR:                     298366
Reviewed by:            pouria, bnovkov, adrian
Differential Revision:  https://reviews.freebsd.org/D59570
Fixes:                  948ad32ae1e0811f45e1d38f26636fefed5051f0

(cherry picked from commit 465942e8cc8160b21e1a3d5e45fa3ddbb852f6db)
DeltaFile
+1-1sys/netinet/raw_ip.c
+1-11 files

FreeBSD/src 7b4bc01sys/netinet tcp_subr.c tcp_usrreq.c

tcp: fix TCPS_CLOSED state underleak in syncache_socket()

The syncache entry holds one TCPS_SYN_RECEIVED count that normally is
transferred to the the newborn tp.  Upon failure syncache_socket() shall
not use TCPSTATES_INC/TCPSTATES_DEC (see 5050df3f4aa4 why).  But when
syncache_socket() fails in_pcbconnect(), it calls tcp_discardcb() to free
resources that were just allocated by tcp_newtcpcb() and this
tcp_discardcb() would do TCPSTATES_DEC(tp->t_state).  The t_state is
TCPS_CLOSED at this point.

Make tcp_discardcb() symmetrical to tcp_newtcpcb() - not responsible for
the TCPSTATES.  Make the caller responsible for state count book keeping.

Reviewed by:            tuexen
Fixes:                  3703e1a73e0e0367c04f47f793e46495e46e647b
Differential Revision:  https://reviews.freebsd.org/D59325

(cherry picked from commit b712bb84a7a7dc229324a95170b8a77e0d9c5bec)
DeltaFile
+0-1sys/netinet/tcp_subr.c
+1-0sys/netinet/tcp_usrreq.c
+1-12 files

FreeBSD/src 7b0bd7elib/libsys recv.2

recv(2): update description of MSG_WAITALL

Remove a note about "data of a different type".  This was a bug that was
fixed in FreeBSD 15.  Instead put an exact quote from SUS that lists
allowed cases of a short read with MSG_WAITALL.  See discussion in D57511.

(cherry picked from commit e5bcf988398924568015202bf853b3a9abd3845e)
DeltaFile
+5-3lib/libsys/recv.2
+5-31 files

FreeBSD/src 8359e00sys/netgraph ng_ipfw.c

ng_ipfw: provide a tree for faster hook lookup

This should assist setups that connect a lot of nodes to ipfw: and then
distribute traffic with ipfw(4) tablearg feature.

Reviewed by:            pouria
Differential Revision:  https://reviews.freebsd.org/D58547

(cherry picked from commit d3a0bf0a79efb0a28d85d48c88d14bc5d89ab00a)
DeltaFile
+36-11sys/netgraph/ng_ipfw.c
+36-111 files

FreeBSD/ports 2a50636lang/babashka Makefile distinfo

lang/babashka: Update to 1.13.224

Changes since 1.13.223:

1.13.224 (2026-09-23)

  * Bundle clojure.data.json
  * #2162: Fix clojure.datafy/datafy on a namespace
  * Bump babashka.ffi to 0.1.2
  * Bump jline to 4.4.5
  * Dep resolution improvements
    - Ignore an empty <version/> element in maven-metadata-local.xml
      when listing an artifact's versions
    - Resolve a locally installed -SNAPSHOT version when a repository
      cannot be reached
    - Record metadata update checks in resolver-status.properties
    - Read versions from a snapshots-only repository for LATEST and
      for version ranges
    - Verify the checksum of maven-metadata.xml under the repository

    [13 lines not shown]
DeltaFile
+5-5lang/babashka/distinfo
+1-1lang/babashka/Makefile
+6-62 files

FreeBSD/ports e0d2f85security/seal Makefile distinfo

security/seal: Update to 4.4.5
DeltaFile
+3-3security/seal/distinfo
+1-1security/seal/Makefile
+4-42 files

FreeBSD/ports 84040bfdevel/jenkins Makefile distinfo

devel/jenkins: Update to 2.583

Sponsored by:   The FreeBSD Foundation
DeltaFile
+3-3devel/jenkins/distinfo
+1-1devel/jenkins/Makefile
+4-42 files

FreeBSD/ports 85418betextproc/nerdlog Makefile distinfo

textproc/nerdlog: Update to 1.11.0
DeltaFile
+5-5textproc/nerdlog/distinfo
+1-2textproc/nerdlog/Makefile
+6-72 files

FreeBSD/ports fbee0f9devel/php-swoole Makefile distinfo, devel/php-swoole/files patch-config.m4 patch-src_core_misc.cc

devel/php-swoole: update to 6.2.3.
DeltaFile
+11-0devel/php-swoole/files/patch-src_core_misc.cc
+3-3devel/php-swoole/files/patch-config.m4
+3-3devel/php-swoole/distinfo
+3-2devel/php-swoole/Makefile
+20-84 files

FreeBSD/ports 457ca74www/phalcon Makefile distinfo

www/phalcon: update to 5.22.0.
DeltaFile
+3-3www/phalcon/distinfo
+1-1www/phalcon/Makefile
+4-42 files

FreeBSD/src 508b182sys/dev/ichiic ig4_pci.c

ichiic: Add PCI id for Arrow Lake.

Add PCI id for Arrow Lake to attach iic driver

Reviewed by: wulf, mav
Differential Revision: https://reviews.freebsd.org/D51107

(cherry picked from commit 87994467966806ffbd1f500b510858909c736b88)
DeltaFile
+12-0sys/dev/ichiic/ig4_pci.c
+12-01 files

FreeBSD/src 5a19be1sys/dev/ichiic ig4_pci.c

ig4: Add Lunar Lake-M I2C controllers 4 and 5

Commit 851dffef532a added the Lunar Lake-M I2C controllers 0 through 3
(0xa878-0xa87b), which sit on PCI device 0x15.  The platform exposes two
further controllers at 0xa850 and 0xa851 on PCI device 0x19, reported by
Intel as I2C #4 and #5.  This mirrors the layout already handled for
Arrow Lake-U, where both the 0x777x and 0x775x ranges are listed.

On an HP OmniBook X Flip 16-as0xxx (Core Ultra 9 288V) the firmware
enables only four of the six controllers, and both HID devices sit on
the two that were missing: an ELAN2514 touchscreen on controller 4 and
a SYNA3503 touchpad on controller 5.  Neither attaches without this
change, so the machine has no working pointing device.

Like the other four, these use the Tiger Lake revision of the I2C IP;
Linux treats 0xa850/0xa851 identically to 0xa878-0xa87b in
intel-lpss-pci.c.

Tested on:      HP OmniBook X Flip 16-as0xxx (Intel Core Ultra 9 288V)

    [6 lines not shown]
DeltaFile
+4-0sys/dev/ichiic/ig4_pci.c
+4-01 files

FreeBSD/src 1fdced9sys/dev/ichiic ig4_pci.c

ig4: Add support for Lunar Lake-M I2C

this patch adds PCI IDs to the ig4(4) driver:
- Lunar Lake-M (0xa878, 0xa879, 0xa87a, 0xa87b)
These controllers use the Tiger Lake hardware revision of the I2C IP.
Adding these IDs enables support for peripherals connected to the I2C Bus.
Tested on: Intel Lunar Lake (LENOVO_MT_21QX_BU_Think_FM_ThinkPad T14s Gen 6)

Signed-off-by: Defenso-EBO <etienne.bonnand at defenso.fr>

MFC after: 2 weeks

Sponsored by: Defenso

Reviewed by: imp
Pull Request: https://github.com/freebsd/freebsd-src/pull/1995

(cherry picked from commit 851dffef532ad9611fcaf02318744c8de9f397b0)
DeltaFile
+8-0sys/dev/ichiic/ig4_pci.c
+8-01 files

FreeBSD/src 3f27c54sys/dev/ichiic ig4_pci.c

ig4: Add Lunar Lake-M I2C controllers 4 and 5

Commit 851dffef532a added the Lunar Lake-M I2C controllers 0 through 3
(0xa878-0xa87b), which sit on PCI device 0x15.  The platform exposes two
further controllers at 0xa850 and 0xa851 on PCI device 0x19, reported by
Intel as I2C #4 and #5.  This mirrors the layout already handled for
Arrow Lake-U, where both the 0x777x and 0x775x ranges are listed.

On an HP OmniBook X Flip 16-as0xxx (Core Ultra 9 288V) the firmware
enables only four of the six controllers, and both HID devices sit on
the two that were missing: an ELAN2514 touchscreen on controller 4 and
a SYNA3503 touchpad on controller 5.  Neither attaches without this
change, so the machine has no working pointing device.

Like the other four, these use the Tiger Lake revision of the I2C IP;
Linux treats 0xa850/0xa851 identically to 0xa878-0xa87b in
intel-lpss-pci.c.

Tested on:      HP OmniBook X Flip 16-as0xxx (Intel Core Ultra 9 288V)

    [6 lines not shown]
DeltaFile
+4-0sys/dev/ichiic/ig4_pci.c
+4-01 files

FreeBSD/src c4d21f6sys/dev/ichiic ig4_pci.c

ig4: Add support for Lunar Lake-M I2C

this patch adds PCI IDs to the ig4(4) driver:
- Lunar Lake-M (0xa878, 0xa879, 0xa87a, 0xa87b)
These controllers use the Tiger Lake hardware revision of the I2C IP.
Adding these IDs enables support for peripherals connected to the I2C Bus.
Tested on: Intel Lunar Lake (LENOVO_MT_21QX_BU_Think_FM_ThinkPad T14s Gen 6)

Signed-off-by: Defenso-EBO <etienne.bonnand at defenso.fr>

MFC after: 2 weeks

Sponsored by: Defenso

Reviewed by: imp
Pull Request: https://github.com/freebsd/freebsd-src/pull/1995

(cherry picked from commit 851dffef532ad9611fcaf02318744c8de9f397b0)
DeltaFile
+8-0sys/dev/ichiic/ig4_pci.c
+8-01 files

FreeBSD/src 784f570usr.bin/split split.1

split.1: grammar

PR:             294757
Reported by:    Ulrich Eduard
MFC after:      1 week

(cherry picked from commit c0c7d1e1af4e42deb9c5a95c735602100c3cc1f2)
DeltaFile
+1-1usr.bin/split/split.1
+1-11 files

FreeBSD/src c5cc084sbin/ipfw ipfw.8

ipfw.8: clarify a difference between reset and reset6 actions

PR:             298348
MFC after:      2 weeks

(cherry picked from commit 009940e3d4d398f0cba8b689d284bd8585e2ad5a)
DeltaFile
+3-3sbin/ipfw/ipfw.8
+3-31 files

FreeBSD/src 1511b29sbin/ipfw ipfw.8

ipfw.8: more grammar fixes

(cherry picked from commit b31db8d8de6785804f6b552bc9d7d1960a47eea5)
DeltaFile
+3-3sbin/ipfw/ipfw.8
+3-31 files

FreeBSD/src f38dfbfsbin/ipfw ipfw.8

ipfw.8: whitespace police

(cherry picked from commit b891252f209bf22938c9492496d166da96fcba1f)
DeltaFile
+1-1sbin/ipfw/ipfw.8
+1-11 files

FreeBSD/src fd3ded8sbin/ipfw ipfw.8

ipfw.8: grammar

(cherry picked from commit 055a726ca6324eead24df4177effd9c69755f386)
DeltaFile
+8-8sbin/ipfw/ipfw.8
+8-81 files

FreeBSD/ports cc0257fdeskutils/taskwarrior Makefile, deskutils/taskwarrior/files patch-src_CMakeLists.txt extra-patch-src_libshared_src_Datetime.cpp

deskutils/taskwarrior: Fix i386 build and WITH_DEBUG builds

- Cast to time_t in Datetime::operator+/- (libshared): time_t is 32-bit
  on i386, so the braced return narrowed int64_t and clang rejected it
  with -Wc++11-narrowing.  Only needed on 32-bit architectures, so apply
  the patch through EXTRA_PATCHES when ARCH is i386 instead of always.
- Stop upstream from compiling -DTASK_TEST_RCDIR="${CMAKE_SOURCE_DIR}/doc/rc"
  into the binary for Debug builds: WITH_DEBUG made the binary write
  "include <WRKSRC>/doc/rc/default.theme" into every generated .taskrc,
  breaking it once the work directory is removed.  Also drop the
  ineffective -DCMAKE_BUILD_TYPE=release (Uses/cmake.mk appends its own
  CMAKE_BUILD_TYPE afterwards, which always wins).
DeltaFile
+23-0deskutils/taskwarrior/files/extra-patch-src_libshared_src_Datetime.cpp
+19-0deskutils/taskwarrior/files/patch-src_CMakeLists.txt
+10-3deskutils/taskwarrior/Makefile
+52-33 files

FreeBSD/src 10a3562sys/kern kern_jail.c

jail: set default root directory for a jail to its parent's root.

All default jail parameter values are an empty or otherwise standard
value, or are copied the jail's parent.  A notable exception is the
root directory, which is instead copied from the creating process's
jail.  Fix that to be in line with everything else.

This change affects only the default when no path is specified; if
a path of "/" is explicitly given, that will still be the creating
process's root directory.
DeltaFile
+1-1sys/kern/kern_jail.c
+1-11 files

FreeBSD/ports e4db654x11/cde-devel distinfo Makefile, x11/cde-devel/files patch-programs_dtterm_Makefile.am patch-programs_dtksh_Makefile.am

x11/cde-devel: Update to the latest cdesktopenv-code commit

Update to the latest cdedesktop-code commit proxied through my GH account
DeltaFile
+12-4x11/cde-devel/Makefile
+11-0x11/cde-devel/files/patch-programs_dtksh_Makefile.am
+0-7x11/cde-devel/files/patch-programs_dtterm_Makefile.am
+3-3x11/cde-devel/distinfo
+26-144 files