FreeBSD/ports 8cadfe4 — security/vuxml/vuln 2026.xml

security/vuxml: Document rabbitmq-c vulnerabilities fixed prior to 0.18.0

Sponsored by:   SkunkWerks, GmbH
DeltaFile
+107-0security/vuxml/vuln/2026.xml
+107-01 files

FreeBSD/ports ef2304d — net/rabbitmq-c pkg-plist Makefile

net/rabbitmq-c: Update to 0.18.0

Fixes five upstream security advisories since 0.15.0, but library
SOVERSION is unchanged.

Changelog:
https://github.com/alanxz/rabbitmq-c/blob/v0.18.0/ChangeLog.md
Security:
https://vuxml.freebsd.org/freebsd/03308f12-c15d-11f1-ab87-107c611e671e.html
Security:
https://vuxml.freebsd.org/freebsd/03306014-c15d-11f1-acb8-107c611e671e.html
Security:
https://vuxml.freebsd.org/freebsd/03302734-c15d-11f1-8561-107c611e671e.html
Security:       CVE-2026-44235 CVE-2026-44236 CVE-2026-59986
CVE-2026-61547
Reported by:    portscout
Sponsored by:   SkunkWerks, GmbH
MFH:            2026Q4
DeltaFile
+3-3net/rabbitmq-c/distinfo
+1-1net/rabbitmq-c/pkg-plist
+1-1net/rabbitmq-c/Makefile
+5-53 files

FreeBSD/ports 73f7ad6 — lang/crystal Makefile distinfo

lang/crystal: Update to 1.21.1

ChangeLog:      https://github.com/crystal-lang/crystal/blob/master/doc/changelogs/v1.21.md
Sponsored by:   SkunkWerks, GmbH
DeltaFile
+3-3lang/crystal/distinfo
+1-1lang/crystal/Makefile
+4-42 files

FreeBSD/ports 992294e — security/monocypher Makefile distinfo, security/monocypher/files patch-monocypher.pc

security/monocypher: Update to 4.0.3

2026-06-15 Monocypher 4.0.3 is out. Fixed a timing leak vulnerability
with public key signatures, fixed compiler warnings, minor documentation
fixes.

Reported by:    portscout
Sponsored by:   SkunkWerks, GmbH

MFH:            2026Q4
DeltaFile
+0-8security/monocypher/files/patch-monocypher.pc
+3-3security/monocypher/distinfo
+1-1security/monocypher/Makefile
+4-123 files

FreeBSD/ports 0481907 — www/h2o distinfo Makefile, www/h2o/files patch-CMakeLists.txt

www/h2o: Update to 20260102 snapshot

Sponsored by:   SkunkWerks, GmbH
DeltaFile
+12-12www/h2o/files/patch-CMakeLists.txt
+5-4www/h2o/Makefile
+3-3www/h2o/distinfo
+20-193 files

FreeBSD/ports 5b8c531 — filesystems/versitygw Makefile distinfo

filesystems/versitygw: Update to 1.8.0

- https://github.com/versity/versitygw/releases/tag/v1.8.0

Sponsored by: SkunkWerks, Gmbh
DeltaFile
+5-5filesystems/versitygw/distinfo
+1-2filesystems/versitygw/Makefile
+6-72 files

FreeBSD/ports 8455c3b — net/lavinmq distinfo Makefile

net/lavinmq: Update to 2.10.1

- https://github.com/cloudamqp/lavinmq/blob/v2.10.1/CHANGELOG.md
- requires lang/crystal > 1.21 for building
- pet with portfmt & portclippy

Sponsored by:   SkunkWerks, GmbH
DeltaFile
+13-18net/lavinmq/Makefile
+5-5net/lavinmq/distinfo
+18-232 files

FreeBSD/ports 2748eb8 — . MOVED, sysutils Makefile

sysutils/lava: Remove, only works with unsupported CouchDB 1.x

Sponsored by:   SkunkWerks, GmbH
DeltaFile
+0-32sysutils/lava/Makefile
+0-4sysutils/lava/pkg-descr
+0-3sysutils/lava/distinfo
+0-1sysutils/Makefile
+1-0MOVED
+1-405 files

FreeBSD/src 35aeff7 — usr.sbin/bhyveload bhyveload.c

bhyveload: validate character disk devices

Currently, bhyveload(8) does not validate the supplied disk
image path. For example, it allows passing the /dev/null
device, which later fails in userboot because it does not
support DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls (see
userdisk_init() in stand/userboot/userboot/userboot_disk.c).

Fix that by checking DIOCGSECTORSIZE and DIOCGMEDIASIZE ioctls early.
A similar check already exists in bhyve(8). While here, make
cb_diskioctl() report the obtained sector size instead of
hard-coding 512.

Reviewed by:    markj
MFC after:      2 weeks
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D59253

(cherry picked from commit 51234535ddd6ec0afe9dd4e3f34a31b92d5cdd78)
DeltaFile
+31-3usr.sbin/bhyveload/bhyveload.c
+31-31 files

FreeBSD/ports 92c0a25 — mail/stalwart Makefile Makefile.crates

mail/stalwart: update to 0.16.25 release (+)

Release notes:  https://github.com/stalwartlabs/stalwart/releases/tag/v0.16.24 \
                https://github.com/stalwartlabs/stalwart/releases/tag/v0.16.25

PR:             299052
Approved by:    maintainer
DeltaFile
+103-107mail/stalwart/distinfo
+50-52mail/stalwart/Makefile.crates
+1-1mail/stalwart/Makefile
+154-1603 files

FreeBSD/ports e443e90 — mail/stalwart-cli Makefile Makefile.crates

mail/stalwart-cli: update to 1.0.13 release (+)

Release notes:  https://github.com/stalwartlabs/cli/releases/tag/v1.0.13

PR:             299053
Approved by:    maintainer
DeltaFile
+253-243mail/stalwart-cli/distinfo
+125-120mail/stalwart-cli/Makefile.crates
+1-2mail/stalwart-cli/Makefile
+379-3653 files

FreeBSD/src b4e2c9a — lib/libcasper/libcasper zygote.c libcasper.c

libcasper: tolerate kernels without PD_NOWAITPID

Commit 1a296762b3d0 made libcasper pass PD_NOWAITPID to pdfork(2).
Kernels predating the flag (15.1 and earlier, since the flag first
ships in 15.2) reject it with EINVAL, which makes cap_init() and every
service fork fail when a newer world runs on an older kernel, for
example in a poudriere jail.

Add casper_pdfork(), which retries without the flag on EINVAL, and use
it at both pdfork(2) call sites.  The retry is safe because the kernel
validates pdfork flags before creating a child.  On such kernels the
zombie must still be reaped with waitpid(2), as before the flag was
introduced.

The fallback is compiled out once __FreeBSD_version reaches 1700000,
so it disappears from main when stable/16 branches while remaining in
the stable/15 and stable/16 branches that need it.

Reviewed by:    kib

    [3 lines not shown]
DeltaFile
+23-0lib/libcasper/libcasper/libcasper_impl.h
+1-1lib/libcasper/libcasper/zygote.c
+1-1lib/libcasper/libcasper/libcasper.c
+25-23 files

FreeBSD/ports 8c88042 — devel/glab pkg-plist Makefile

devel/glab: update to 1.120.0

Changes:        https://gitlab.com/gitlab-org/cli/-/releases
DeltaFile
+5-5devel/glab/distinfo
+2-2devel/glab/Makefile
+2-0devel/glab/pkg-plist
+9-73 files

FreeBSD/ports 0cfc3e9 — databases/pgvector Makefile distinfo

databases/pgvector: Upgrade from 0.8.2 to 0.8.7

  Changelog for each version:

  0.8.7 (2026-10-01)

    Fixed buffer overflow with IVFFlat index build
    Fixed error with avg aggregate when no matching rows

  0.8.6 (2026-07-29)

    Fixed buffer overflow with IVFFlat index build on 32-bit systems
    Fixed array to sparsevec cast not limiting non-zero elements
    Fixed memory usage for IVFFlat index scans with nested loop joins

  0.8.5 (2026-07-08)

    Reduced memory usage for small tables for IVFFlat index builds


    [14 lines not shown]
DeltaFile
+6-1databases/pgvector/pkg-plist
+3-3databases/pgvector/distinfo
+1-1databases/pgvector/Makefile
+10-53 files

FreeBSD/ports 86e1b05 — www/grist-core Makefile distinfo

www/grist-core: update to 1.7.20

Changes:        https://github.com/gristlabs/grist-core/releases
DeltaFile
+5-5www/grist-core/distinfo
+4-3www/grist-core/Makefile
+9-82 files

FreeBSD/src ea23918 — libexec/rtld-elf/i386 reloc.c

rtld-elf/i386: remove no longer true __unused args annotations

Fixes:  d45d7aea6197 ("i386 rtld: implement support for TLSDESC relocation")
Sponsored by:   The FreeBSD Foundation
MFC after:      1 week
DeltaFile
+1-1libexec/rtld-elf/i386/reloc.c
+1-11 files

FreeBSD/ports 143f1d3 — misc/p5-Business-ISBN-Data Makefile distinfo

Changelog: https://metacpan.org/dist/Business-ISBN-Data/changes
DeltaFile
+3-3misc/p5-Business-ISBN-Data/distinfo
+1-1misc/p5-Business-ISBN-Data/Makefile
+4-42 files

FreeBSD/ports 2ff243f — security/libressl-devel Makefile distinfo

security/libressl-devel: Update to 4.4.0-rc1
DeltaFile
+3-3security/libressl-devel/distinfo
+2-2security/libressl-devel/Makefile
+5-52 files

FreeBSD/ports c31d287 — security/vuxml/vuln 2026.xml

security/vuxml: Document Vaultwarden vulnerabilities
DeltaFile
+33-0security/vuxml/vuln/2026.xml
+33-01 files

FreeBSD/src 7c66df6 — sys/conf files

ufshci: build the ioctl file into the kernel

The passthrough ioctl went into the module build only. A kernel with
device ufshci then failed to link, because ufshci_ctrlr.c calls
ufshci_ioctl_construct() and ufshci_ioctl_destruct() and neither was
compiled in.

Add the file to sys/conf/files.

Fixes:          28fefc441e3b ("ufshci: add a control device node")
Sponsored by:   Samsung Electronics

(cherry picked from commit d435248a2196bc78f626850a7ae700aaeace1c13)
DeltaFile
+1-0sys/conf/files
+1-01 files

FreeBSD/src 26ca0a1 — sys/dev/ufshci ufshci_private.h ufshci_uic_cmd.c

ufshci: add a passthrough ioctl

This ioctl is for a port of ufs-utils:
https://github.com/SanDisk-Open-Source/ufs-utils

The driver only exposed a CAM SIM. Reading a descriptor, an attribute
or a flag needs a query request, and a UniPro attribute needs a DME
command. The driver built both only for its own setup, so userland
could reach neither.

Add two ioctls on the control node. UFSHCI_PASSTHROUGH_CMD sends a
UPIU the caller built, sizes the request from its transaction code,
and copies the response UPIU back. UFSHCI_PASSTHROUGH_UIC carries the
four attribute commands and refuses the rest, which can drop the link
or power the device off. It keeps the raw argument2 so the caller can
read the result code the device reported, not just a failure.

Validate the input and bound it by what the controller can map. The
descriptor has no request length, so the controller reads it from the

    [12 lines not shown]
DeltaFile
+236-0sys/dev/ufshci/ufshci_ioctl.c
+10-4sys/dev/ufshci/ufshci_ioctl.h
+8-2sys/dev/ufshci/ufshci.h
+3-2sys/dev/ufshci/ufshci_uic_cmd.c
+2-0sys/dev/ufshci/ufshci_private.h
+259-85 files

FreeBSD/src 4392fed — sys/dev/ufshci ufshci.h ufshci_private.h, sys/modules/ufshci Makefile

ufshci: add a control device node

The driver only exposed a CAM SIM. Userland had no way to reach the
device for anything that is not a SCSI command, so reading a descriptor
or an attribute was impossible.

Add /dev/ufshci%d as a root only node and the ioctl ABI header for it.
The node answers no ioctl yet. The header pulls in ufshci.h, which
declares bool only under _KERNEL, so include stdbool.h for userland the
way nvme.h already does.

Reviewed by:    imp (mentor)
Sponsored by:   Samsung Electronics
Differential Revision:  https://reviews.freebsd.org/D59558

(cherry picked from commit 28fefc441e3b701acc2888892a518774394255c7)
DeltaFile
+67-0sys/dev/ufshci/ufshci_ioctl.c
+54-0sys/dev/ufshci/ufshci_ioctl.h
+6-0sys/dev/ufshci/ufshci_private.h
+6-0sys/dev/ufshci/ufshci_ctrlr.c
+3-0sys/dev/ufshci/ufshci.h
+1-0sys/modules/ufshci/Makefile
+137-06 files

FreeBSD/src d815ad7 — etc/mtree BSD.include.dist, include Makefile

ufshci: install the ioctl header

The passthrough ioctl has a userland ABI header, but nothing installed
it. A program that wanted to use the ioctl had to copy the headers out
of the source tree by hand.

Install ufshci.h and ufshci_ioctl.h under /usr/include/dev/ufshci, the
way nvme installs nvme.h. The ioctl header pulls in ufshci.h, so both
go. Add the directory to the include mtree so installworld creates it.

Reviewed by:    imp (mentor)
Sponsored by:   Samsung Electronics
Differential Revision:  https://reviews.freebsd.org/D59560

(cherry picked from commit 8895b1348f3d21e2db16a06f31d555be0471e36d)
DeltaFile
+6-0include/Makefile
+2-0etc/mtree/BSD.include.dist
+8-02 files

FreeBSD/src ac1ad37 — sys/dev/ufshci ufshci_req_queue.c

ufshci: tell the controller how long the EHS is

The transfer request descriptor has a field for the total Extra Header
Segment length. The driver left it at zero. A request that carried an
EHS went out as the bare command UPIU, and the device answered a request
it had only seen part of.

Fill the field from the request UPIU header, which already carries the
same length. Every other path sets it to zero, so nothing else changes.
An EHS is the first thing that makes a request vary in size, so assert
that the request and the response still fit in the command descriptor.

Reviewed by:    imp (mentor)
Sponsored by:   Samsung Electronics
Differential Revision:  https://reviews.freebsd.org/D59557

(cherry picked from commit d3e5082ce4dcb154cbf50cba05d8f1dbbd55a5fc)
DeltaFile
+7-2sys/dev/ufshci/ufshci_req_queue.c
+7-21 files

FreeBSD/src 6f16282 — sys/dev/ufshci ufshci_ctrlr.c

ufshci: skip the reinit when the new link works

UFSHCI_QUIRK_REINIT_AFTER_MAX_GEAR_SWITCH always rebuilt the
link after the gear switch. It threw away a working HS link and
ended up in PWM. The reinit is only needed for a dead link.
There the local side reports HS and the peer never answers. A
local readback cannot tell the two apart. Peer traffic can.

Probe the peer with DME_PEER_GET after the switch. Skip the
reinit when the probe succeeds. Log it when the probe fails.

Reviewed by:            imp (mentor)
Sponsored by:           Samsung Electronics
Differential Revision:  https://reviews.freebsd.org/D59299

(cherry picked from commit 9930150214d1ca4ad21561d2e0afce9ebf2cdf6c)
DeltaFile
+19-4sys/dev/ufshci/ufshci_ctrlr.c
+19-41 files

FreeBSD/src 1aaad60 — sys/dev/ufshci ufshci_private.h ufshci.h

ufshci: set HS series per platform and adapt type per gear

The driver always asked for Rate-B. It never set the adaptation
type. The Snapdragon X Elite firmware tunes the PHY for Rate-A.
A Rate-B link dies at every gear there. HS-G4 and above need
initial adaptation. This is a UniPro rule. It applies to
every host.

Add an hs_series field to the device tables. Use Rate-A on the
Snapdragon X Elite. Keep Rate-B on the PCI hosts. A table entry
without an HS series fails to attach. Set PA_TxHsAdaptType to
initial adaptation at HS-G4 and above. Leave it alone below
that. Hosts before UniPro 1.8 do not have it. The Galaxy Book
4 Edge now links at HS-G5 Rate-A.

fio results (128k sequential, 4k random, posixaio):

QD  | SEQ_R(MiB/s) | SEQ_W(MiB/s) | RND_R(kIOPS) | RND_W(kIOPS)
----+--------------+--------------+--------------+-------------

    [12 lines not shown]
DeltaFile
+7-4sys/dev/ufshci/ufshci_dev.c
+7-3sys/dev/ufshci/ufshci_pci.c
+7-2sys/dev/ufshci/ufshci_acpi.c
+7-0sys/dev/ufshci/ufshci_ctrlr.c
+4-0sys/dev/ufshci/ufshci.h
+1-0sys/dev/ufshci/ufshci_private.h
+33-96 files

FreeBSD/src 8dcd02b — sys/dev/ufshci ufshci_acpi.c ufshci_dev.c

ufshci: fix the Snapdragon X Elite reference clock

The driver's ACPI table set bRefClkFreq to 19.2 MHz. The
Snapdragon X Elite feeds the device 38.4 MHz from its CXO. The
firmware has no property for it. The device ran its PLL from
the wrong base. Every HS mode failed. PWM still worked. The
attribute is persistent. The wrong value survived reboots.

Set 38.4 MHz in the table. Read the attribute first. Write it
only when the value differs or the read fails. Log a changed
value and a failed read. Verified on the Galaxy Book 4 Edge.

Reviewed by:            imp (mentor)
Sponsored by:           Samsung Electronics
Differential Revision:  https://reviews.freebsd.org/D59297

(cherry picked from commit 973783515e7db6e19550c57c8f9d94d907e3bd0e)
DeltaFile
+17-0sys/dev/ufshci/ufshci_dev.c
+5-1sys/dev/ufshci/ufshci_acpi.c
+22-12 files

FreeBSD/src 36e915b — sys/dev/ufshci ufshci_sim.c ufshci_ctrlr.c

ufshci: handle a recovery reset before the SIM attach

When the first start attempt fails early, the recovery reset
runs the start sequence again without a SIM. That pass still
looked up the WLUN, so it dereferenced a NULL SIM and panicked.

Attach the SIM whenever it does not exist yet. Also make the
WLUN lookup return NULL when there is no SIM.

Reviewed by:            imp (mentor)
Sponsored by:           Samsung Electronics
Differential Revision:  https://reviews.freebsd.org/D58947

(cherry picked from commit e59d4ec66fcab3da813f593f52bb8f1577cbb403)
DeltaFile
+4-3sys/dev/ufshci/ufshci_ctrlr.c
+4-0sys/dev/ufshci/ufshci_sim.c
+8-32 files

FreeBSD/src 3e6ff53 — sys/dev/ufshci ufshci_req_queue.c

ufshci: reject new requests on a failed controller

A failed controller accepted new requests, but nothing ever
completed them, so the caller waited forever. The admin retry
path could also resubmit a request to a dead queue.

Reject new submits and admin retries on a failed controller.
The submit check runs under the queue lock, so it cannot race
with the queue walk in the fail path.

Reviewed by:            imp (mentor)
Sponsored by:           Samsung Electronics
Differential Revision:  https://reviews.freebsd.org/D58948

(cherry picked from commit 3ecee9314d88e2bb277b365d9413e219fd9a1283)
DeltaFile
+5-2sys/dev/ufshci/ufshci_req_queue.c
+5-21 files

FreeBSD/src c8095bb — sys/dev/ufshci ufshci_req_queue.c

ufshci: build valid fake responses for manual completion

The manual completion wrote the fake response to the wrong
descriptor for task management slots. It also left the task tag
at zero, which tripped the task tag check under INVARIANTS.

Write the fake response where the completion path reads it.
Copy the task tag from the request.

Reviewed by:            imp (mentor)
Sponsored by:           Samsung Electronics
Differential Revision:  https://reviews.freebsd.org/D58946

(cherry picked from commit 746278a6ddc80a98001f875cd975283d7c99b960)
DeltaFile
+20-6sys/dev/ufshci/ufshci_req_queue.c
+20-61 files