FreeBSD/ports 1885886misc/crush Makefile distinfo, misc/crush/files extra-patch-disable-command-blocking

misc/crush: Update to 0.95.0

Changelog: https://github.com/charmbracelet/crush/releases/tag/v0.95.0

Reported by:    GitHub (watch releases)
DeltaFile
+5-5misc/crush/distinfo
+2-2misc/crush/files/extra-patch-disable-command-blocking
+1-1misc/crush/Makefile
+8-83 files

FreeBSD/ports 57ae357security/vuxml/vuln 2026.xml

security/vuxml: Document vulnerabilities in net/traefik
DeltaFile
+31-0security/vuxml/vuln/2026.xml
+31-01 files

FreeBSD/ports 2635272security/vuxml/vuln 2026.xml

security/vuxml: Document vulnerabilities in multimedia/mkvtoolnix
DeltaFile
+29-0security/vuxml/vuln/2026.xml
+29-01 files

FreeBSD/ports 310043cgraphics/hyprland-protocols Makefile distinfo

graphics/hyprland-protocols: Update to 0.7.1

Changelog: https://github.com/hyprwm/hyprland-protocols/releases/tag/v0.7.1

Reported by:    GitHub (watch releases)
DeltaFile
+3-3graphics/hyprland-protocols/distinfo
+3-2graphics/hyprland-protocols/Makefile
+6-52 files

FreeBSD/ports e262e7fnet-mgmt/nagios-pf-plugin Makefile, net-mgmt/nagios-pf-plugin/files patch-Makefile patch-check_pf.c

net-mgmt/nagios-pf-plugin: fix build on FreeBSD 15+

PR:             294009
Approved by:    maintainer timeout (never replied)
MFH:            2026Q3

(cherry picked from commit 9eddf7dd87dfa63edde409b82273742b00b1344a)
DeltaFile
+149-0net-mgmt/nagios-pf-plugin/files/extra-patch-check_pf_15.c
+0-64net-mgmt/nagios-pf-plugin/files/patch-check_pf.c
+64-0net-mgmt/nagios-pf-plugin/files/extra-patch-check_pf.c
+14-5net-mgmt/nagios-pf-plugin/Makefile
+14-2net-mgmt/nagios-pf-plugin/files/patch-Makefile
+241-715 files

FreeBSD/ports 9eddf7dnet-mgmt/nagios-pf-plugin Makefile, net-mgmt/nagios-pf-plugin/files patch-Makefile patch-check_pf.c

net-mgmt/nagios-pf-plugin: fix build on FreeBSD 15+

PR:             294009
Approved by:    maintainer timeout (never replied)
MFH:            2026Q3
DeltaFile
+149-0net-mgmt/nagios-pf-plugin/files/extra-patch-check_pf_15.c
+0-64net-mgmt/nagios-pf-plugin/files/patch-check_pf.c
+64-0net-mgmt/nagios-pf-plugin/files/extra-patch-check_pf.c
+14-5net-mgmt/nagios-pf-plugin/Makefile
+14-2net-mgmt/nagios-pf-plugin/files/patch-Makefile
+241-715 files

FreeBSD/ports 45a47e1audio/shairport-sync Makefile distinfo

audio/shairport-sync: Update to 5.5.2
DeltaFile
+3-3audio/shairport-sync/distinfo
+1-1audio/shairport-sync/Makefile
+4-42 files

FreeBSD/src 0380d01lib/libbsdconf bsdconf.h bsdconf.c, usr.sbin/sysconf sysconf_priv.h sysconf.c

libbsdconf: independent version macros

sysconf(8) --version now prints the library version alongside its
own so each can move on its own clock.  Assigning a bitmask to
bool already converts zero/nonzero; drop the redundant != 0 (fuz).

Reviewed by:    fuz, kfv
Differential Revision:  https://reviews.freebsd.org/D59720
DeltaFile
+11-11lib/libbsdconf/bsdconf_put.c
+6-6lib/libbsdconf/bsdconf.c
+6-2usr.sbin/sysconf/sysconf.8
+8-0lib/libbsdconf/bsdconf.h
+3-2usr.sbin/sysconf/sysconf.c
+1-1usr.sbin/sysconf/sysconf_priv.h
+35-226 files

FreeBSD/ports 2fab821audio/noctavox Makefile Makefile.crates, audio/noctavox/files patch-cargo-crates_cpal-0.18.1_src_host_mod.rs patch-cargo-crates_cpal-0.18.1_src_host_alsa_mod.rs

audio/noctavox: Update to 0.3.5

ChangeLog:

1. https://github.com/Jaxx497/NoctaVox/releases/tag/v0.3.5

Reported by:    "github-actions[bot]" <notifications at github.com>
DeltaFile
+103-105audio/noctavox/distinfo
+50-51audio/noctavox/Makefile.crates
+0-50audio/noctavox/files/patch-cargo-crates_cpal-0.18.1_src_host_alsa_mod.rs
+0-10audio/noctavox/files/patch-cargo-crates_cpal-0.18.1_src_host_mod.rs
+2-2audio/noctavox/Makefile
+155-2185 files

FreeBSD/ports ba0bd56multimedia/mkvtoolnix Makefile pkg-plist

multimedia/mkvtoolnix: Update to upstream release 102.0

Details:
Bug- and security fixes, see
https://mkvtoolnix.download/doc/NEWS.md

MFH:            2026Q3
Security:       CVE-2026-90783
DeltaFile
+3-3multimedia/mkvtoolnix/distinfo
+5-0multimedia/mkvtoolnix/pkg-plist
+1-1multimedia/mkvtoolnix/Makefile
+9-43 files

FreeBSD/ports 8fb2c0fnet/traefik distinfo Makefile

net/traefik: Update to upstream release 3.7.13

Details:
* Bug- and security fixes, see
  https://github.com/traefik/traefik/releases/tag/v3.7.13
* Changes may require updating the configuration, see
  https://doc.traefik.io/traefik/v3.7/migrate/v3/#v3713

MFH:            2026Q3
Security:       https://github.com/traefik/traefik/security/advisories/GHSA-qqjf-53cj-pwvv
                https://github.com/traefik/traefik/security/advisories/GHSA-f52w-8j3h-j724
                https://github.com/traefik/traefik/security/advisories/GHSA-v67p-phpq-fc8x
                https://github.com/traefik/traefik/security/advisories/GHSA-w4v4-9rw7-5326
                https://github.com/traefik/traefik/security/advisories/GHSA-8fcf-v89g-xpg6
DeltaFile
+3-3net/traefik/Makefile
+3-1net/traefik/distinfo
+6-42 files

FreeBSD/src 3fe5961lib/libbsdconf bsdconf_stmt.c bsdconf_format.3, usr.sbin/sysconf sysconf.8 sysconf.c

Add sysconf(8) and libbsdconf(3)

Complete the native configuration trinity: sysctl(8) for live kernel
state, sysrc(8) for rc.conf(5), and sysconf(8) for the remaining base
configuration -- loader.conf(5), sysctl.conf(5), and the make.conf(5)
family -- atop libbsdconf(3).

libbsdconf resurrects figpar as a unified reader/writer.  Callbacks own
semantics; statements may span multiple lines via backslash continuation;
non-seekable input is spooled; writes are atomic (mkstemp, fsync, rename)
with mode/owner preservation.  Format descriptors name each target, its
files, and quoting rules without private parsers.  Multi-file targets
follow boot sourcing order; loader chases loader_conf_files as the boot
loader does.

sysconf(8) is the operator-facing tool: name / name=value on a required
target, sysrc-style list edits, make append and list-strike where they
belong, jail/altroot, and a capsicum sandbox for read-only use.


    [21 lines not shown]
DeltaFile
+761-0usr.sbin/sysconf/sysconf.c
+733-0lib/libbsdconf/bsdconf.c
+704-0usr.sbin/sysconf/sysconf.8
+693-0lib/libbsdconf/bsdconf_format.c
+560-0lib/libbsdconf/bsdconf_format.3
+547-0lib/libbsdconf/bsdconf_stmt.c
+3,998-041 files not shown
+10,120-047 files

FreeBSD/ports 3f1a145math/octave-forge-statistics Makefile distinfo

math/octave-forge-statistics: Update to 1.9.3.
DeltaFile
+3-3math/octave-forge-statistics/distinfo
+1-1math/octave-forge-statistics/Makefile
+4-42 files

FreeBSD/src f308d6dshare/man/man4 em.4, sys/dev/e1000 if_igbv.c

igbv: Recover disabled Hyper-V transmit queues

The Windows PF can disable a VF transmit queue while continuing to
report carrier up.  Link polling alone then leaves the VF operationally
up even though it cannot transmit.  The reproduced VLAN failure shows
this state with PF driver 14.1.5.0 and an MDD indication in the host trace.

Check queue zero from the admin path only while the Hyper-V VF is
running with sanitized queues and a completed host handshake.  Report
operational link down and invalidate the statistics baseline when the
queue is disabled.  Request recovery through the normal iflib stop/init
path only when a fresh, accessible STATUS read reports carrier up.
Rate limit requests if the host continues to hold the queue disabled,
and leave recovery pending while carrier is down.

Document the recovery behavior and clarify why the Hyper-V reset retains
the VF-local software reset before its host reset/MAC exchange.

Sponsored by:   BBOX.io
DeltaFile
+35-0sys/dev/e1000/if_igbv.c
+7-1share/man/man4/em.4
+42-12 files

FreeBSD/ports 9b95040devel Makefile

devel/Makefile: add missing py-opengrok-tools

Reported by:    rcm at rcm.sh
Fixes:          789a6e9d868a
DeltaFile
+1-0devel/Makefile
+1-01 files

FreeBSD/doc 0e06804website/archetypes/release hardware.adoc

hardware: Add the amdsmu driver
DeltaFile
+2-0website/archetypes/release/hardware.adoc
+2-01 files

FreeBSD/ports 8986ed8math/R-cran-combinat Makefile distinfo

math/R-cran-combinat: Update 0.0-8 => 0.0-9

While here, populate pkg-descr.

Commit log:
https://github.com/cran/combinat/compare/0.0-8...0.0-9

PR:             298551
Approved by:    no maintainer
Approved by:    osa, vvd (Mentors, implicit)
DeltaFile
+3-3math/R-cran-combinat/distinfo
+5-1math/R-cran-combinat/pkg-descr
+1-2math/R-cran-combinat/Makefile
+9-63 files

FreeBSD/src 2072f71share/man/man4 amdsmu.4

amdsmu.4: Canonicalize SYNOPSIS and HARDWARE

MFC after:              no
Reviewed by:            obiwac
Differential Revision:  https://reviews.freebsd.org/D59738
DeltaFile
+7-16share/man/man4/amdsmu.4
+7-161 files

FreeBSD/src ed5fc80sys/dev/cxgbe/crypto t7_kern_tls.c

cxgbe: Use the correct GHASH offset for a GMAC from a full TLS record

If a TLS request transmits all but a part of the GMAC at the end of a
TLS record, the work request asks the crypto engine to return the
calculated GMAC to the driver so it can be sent in a simple TCP packet
when the rest of the TLS record is transmitted in the future.
However, the offset of the returned GHASH offset was calculated
incorrectly in this case causing the driver to not recognize the
cached GMAC and instead use a more wasteful work request in the future
that encrypted the entire TLS record discarding all but the needed
bytes of the trailer.

Note that this does not effect correctness, just efficiency.

Reviewed by:    np
Fixes:          9e269eafebfc ("cxgbe: Use partial GCM mode for partial TLS records on T7")
Sponsored by:   Chelsio Communications
Differential Revision:  https://reviews.freebsd.org/D59711
DeltaFile
+1-1sys/dev/cxgbe/crypto/t7_kern_tls.c
+1-11 files

FreeBSD/poudriere 8b41a68src/share/poudriere ports.sh jail.sh

jail, ports: Avoid set -e trap in quiet-mode "done" idiom

4cb78962 introduced `[ -n "${quiet}" ] && echo " done"` in the svn/git
checkout and update paths of install_from_vcs() (jail.sh) and ports.sh.
When quiet is unset the test is false, so the statement returns exit 1;
under set -e a bare call to the enclosing function/case arm would abort
the script right after that line runs, as seen with the identical
pattern in image.sh (PR #1378). None of these 8 occurrences are
currently a function's last statement, so they don't trip today, but
the pattern is fragile under refactoring. Use an if/fi block instead,
matching the idiom already used for the preceding header line, so the
statement always returns 0.

This closes #1387
DeltaFile
+12-4src/share/poudriere/ports.sh
+12-4src/share/poudriere/jail.sh
+24-82 files

FreeBSD/src 50b3763sys/net if_vlan.c

vlan: Notify the parent when replacing a VLAN ID

Changing the VID of an existing VLAN interface rehashes the interface and
announces the new VID, but does not unregister the old VID.  Parent
drivers and VLAN event consumers can consequently retain stale filter
membership.

After successfully inserting the new VID, emit vlan_unconfig for the old
VID before the existing vlan_config notification.  Do not unregister
anything if insertion fails and the old VID is restored.

MFC after:      2 weeks
Sponsored by:   BBOX.io
DeltaFile
+2-0sys/net/if_vlan.c
+2-01 files

FreeBSD/poudriere 9cc4067src/share/poudriere jail.sh

jail: Reject a period in the new name on rename

create_jail() rejects a period in JAILNAME since jail(8) names cannot
contain one, but rename_jail() never validated NEWJAILNAME at all, so
'poudriere jail -r' could rename a jail to a name jail(8) itself would
reject. Apply the same check used at creation.

This closes #1388
DeltaFile
+2-0src/share/poudriere/jail.sh
+2-01 files

FreeBSD/src 89ce1aashare/man/man4 em.4, sys/dev/e1000 if_em.h if_em.c

igbv: Support Hyper-V virtual functions

Use the Hyper-V reset/MAC exchange for 82576 and I350 VFs instead of the
native posted mailbox protocol, which the Windows PF does not service.
Read the host assigned address through configuration bytes 0x201 through
0x206 only during reset, and use it to identify the matching synthetic
hn(4) interface.  The operations are local to the VF frontend.

Poll hardware link status rather than retaining a native mailbox link
handshake.  Leave MAC, multicast, promiscuous-mode, and VLAN membership
policy with the host.  Disable guest VLAN registration and native receive
limit requests, and limit the VF to an MTU of 1500 bytes.

Preserve accumulated statistics across host resets without counting a
counter clear as a wrap.  Reject inaccessible register samples and rebase
after a reset indication or a disabled transmit queue, including when the
PF blocks the queue for malicious driver detection.

Document single queue support and host assigned access VLANs.  Guest VLAN

    [9 lines not shown]
DeltaFile
+103-0sys/dev/e1000/if_igbv.c
+77-5sys/dev/e1000/if_em.c
+26-3share/man/man4/em.4
+11-0sys/dev/e1000/if_em.h
+217-84 files

FreeBSD/poudriere d504b2asrc/share/poudriere/include pkg.sh

pkg: Add trailing ellipsis to repository signing status messages

Each of these msg() calls is immediately followed by an unredirected
injail pkg-repo invocation whose own output streams directly to the
console right after the header, the same shape as other "action
followed by unbuffered command output" status lines that already use
a trailing "...". pkg repo has no quiet/verbose toggle in play here
(PKG_REPO_FLAGS only carries --hash/--symlink), so this is a plain
ellipsis fix, not an idiom conversion.

This closes #1381
DeltaFile
+3-3src/share/poudriere/include/pkg.sh
+3-31 files

FreeBSD/ports 0e75541sysutils/edk2 Makefile, sysutils/edk2/files patch-OvmfPkg_Bhyve_BhyveX64.fdf patch-OvmfPkg_Bhyve_BhyveX64.dsc

sysutils/edk2: fix network boot on bhyve

NetworkPkg's DxeNetLib needs EFI_RNG_PROTOCOL, and the Bhyve build's
only producer is VirtioRngDxe, which never binds since bhyve has no
virtio-rng device. RngDxe uses RDRAND instead and needs no device.
TcpDxe depexes gEfiHash2ServiceBindingProtocolGuid, so add
Hash2DxeCrypto too; without TcpDxe there is no HttpServiceBinding.
Also enable HTTP boot.

This recommits 3fcead9dc69a ("sysutils/edk2: fix network boot on bhyve"),
which also contained three unrelated patch files.

PR:             298499
Approved by:    manu
Sponsored by:   Netflix
DeltaFile
+34-0sysutils/edk2/files/patch-OvmfPkg_Bhyve_BhyveX64.dsc
+21-0sysutils/edk2/files/patch-OvmfPkg_Bhyve_BhyveX64.fdf
+1-1sysutils/edk2/Makefile
+56-13 files

FreeBSD/ports d6250b8devel/codebase-memory-mcp/files patch-src_ui_http__server.c, net-mgmt/pmacct/files patch-src_nfv9__template.c

Revert "sysutils/edk2: fix network boot on bhyve"

This reverts commit 3fcead9dc69a1fb01bf4200ce3b079e942b57f39.

Wrongly added non-related files to previous commit.
DeltaFile
+0-39net/pimd/files/patch-src_main.c
+0-34sysutils/edk2/files/patch-OvmfPkg_Bhyve_BhyveX64.dsc
+0-29devel/codebase-memory-mcp/files/patch-src_ui_http__server.c
+0-22net-mgmt/pmacct/files/patch-src_nfv9__template.c
+0-21sysutils/edk2/files/patch-OvmfPkg_Bhyve_BhyveX64.fdf
+1-1sysutils/edk2/Makefile
+1-1466 files

FreeBSD/poudriere e0c11d8src/share/poudriere image.sh

image: Use quiet-aware msg idiom for pkgbase install status

install_world_from_pkgbase() always reported "Installing base
packages" / "Base packages installed" as two separate msg() lines,
regardless of PKG_QUIET. Under the default quiet pkg install
(-q, unless -v was passed), nothing prints between them, so treat it
like the other silent/slow operations with msg_n "...done". When -v
clears PKG_QUIET, pkg's own install output streams between the
header and completion, so keep the header on its own line via msg()
with a trailing "..." and skip the redundant "done", matching the
quiet-vs-verbose idiom already used for jail.sh's install_from_vcs().
DeltaFile
+8-2src/share/poudriere/image.sh
+8-21 files

FreeBSD/ports de9ecabsecurity/debian-keyring Makefile distinfo

security/debian-keyring: Update 2026.06.27 → 2026.08.27

Changelog:
https://salsa.debian.org/debian-keyring/keyring/-/raw/2026.08.27/debian/changelog

PR:             298552
Approved by:    osa, vvd (Mentors, implicit)
DeltaFile
+3-3security/debian-keyring/distinfo
+1-1security/debian-keyring/Makefile
+4-42 files

FreeBSD/src 16c5abbshare/man/man4 Makefile

man: Link mlx5en.4 also to if_mce.4

For consistency, create a symbolic link from mlx5en.4 to also if_mce.4

Reviewed by:            ziaee, #manpages
Event:                  EuroBSDCon 2026
Differential Revision:  https://reviews.freebsd.org/D59610
MFC after:              3 days

(cherry picked from commit e46a7d842a7572cc7ccef88a463a9af1a725fefc)
DeltaFile
+2-1share/man/man4/Makefile
+2-11 files

FreeBSD/ports 0766903Mk bsd.port.mk

Mk: fix checksum when makesum is defined

Fixes regression from 076687302bffe156fb9b379c2eb622f0ac2e711e

Reported by:    eduardo
DeltaFile
+2-1Mk/bsd.port.mk
+2-11 files