FreeBSD/src ac24108 — sys/net iflib.c

iflib: Make the deferral test in iflib_txd_db_check() an early return

Invert the test so the doorbell write is no longer nested inside the
conditional, and wrap its comments to 80 columns.  Fix a typo in one of
them.

No functional change intended.

Reviewed by:            kbowling
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60371
DeltaFile
+19-18sys/net/iflib.c
+19-181 files

FreeBSD/ports dfae86c — net/bird3 Makefile distinfo

net/bird3: update to 3.3.3

Sponsored by:   Netflix
DeltaFile
+3-3net/bird3/distinfo
+1-2net/bird3/Makefile
+4-52 files

FreeBSD/ports 257554f — net/bird2 Makefile distinfo

net/bird2: update to 2.19.3

Sponsored by:   Netflix
DeltaFile
+3-3net/bird2/distinfo
+1-2net/bird2/Makefile
+4-52 files

FreeBSD/ports 46cf3d9 — www/firefox Makefile distinfo

www/freifox: update to 157.0.1

Release Notes (soon):
  https://www.firefox.com/en-US/firefox/157.0.1/releasenotes/

(cherry picked from commit f6726c254f0cff9e84a7cd4fb1e8b55f9fef0e0c)
DeltaFile
+3-3www/firefox/distinfo
+1-1www/firefox/Makefile
+4-42 files

FreeBSD/ports f6726c2 — www/firefox Makefile distinfo

www/freifox: update to 157.0.1

Release Notes (soon):
  https://www.firefox.com/en-US/firefox/157.0.1/releasenotes/
DeltaFile
+3-3www/firefox/distinfo
+1-1www/firefox/Makefile
+4-42 files

FreeBSD/ports 46a8951 — www/nextcloud-appointments Makefile distinfo

www/nextcloud-appointments: Update to 2.8.3
DeltaFile
+3-3www/nextcloud-appointments/distinfo
+1-1www/nextcloud-appointments/Makefile
+4-42 files

FreeBSD/ports 877ca3b — security/libressl-devel Makefile distinfo

security/libressl-devel: Security update to 4.3.3

Security:       85bcb950-c0b4-11f1-a6ea-8447094a420f
MFH:            2026Q4
(cherry picked from commit 2c653476eb45808cebe3bc18962e87103c7d264b)
DeltaFile
+3-3security/libressl-devel/distinfo
+1-1security/libressl-devel/Makefile
+4-42 files

FreeBSD/ports 452d88c — security/libressl Makefile distinfo

security/libressl: Security update to 4.3.3

Security:       85bcb950-c0b4-11f1-a6ea-8447094a420f
MFH:            2026Q4
(cherry picked from commit cf9771303f64cef5766f6ab7e2b38cccc3ae5b6e)
DeltaFile
+3-3security/libressl/distinfo
+1-1security/libressl/Makefile
+4-42 files

FreeBSD/ports 2c65347 — security/libressl-devel Makefile distinfo

security/libressl-devel: Security update to 4.3.3

Security:       85bcb950-c0b4-11f1-a6ea-8447094a420f
MFH:            2026Q4
DeltaFile
+3-3security/libressl-devel/distinfo
+1-1security/libressl-devel/Makefile
+4-42 files

FreeBSD/ports cf97713 — security/libressl Makefile distinfo

security/libressl: Security update to 4.3.3

Security:       85bcb950-c0b4-11f1-a6ea-8447094a420f
MFH:            2026Q4
DeltaFile
+3-3security/libressl/distinfo
+1-1security/libressl/Makefile
+4-42 files

FreeBSD/ports e488bd1 — security/vuxml/vuln 2026.xml

security/vuxml: Document LibreSSL vulnerbilities
DeltaFile
+35-0security/vuxml/vuln/2026.xml
+35-01 files

FreeBSD/ports 7d9e072 — print/microtex/files patch-src_platform_cairo_graphic__cairo.cpp

print/microtex: fontconfig-2.18.3 compatibility

PR:             299119
DeltaFile
+12-0print/microtex/files/patch-src_platform_cairo_graphic__cairo.cpp
+12-01 files

FreeBSD/ports 2cf063b — x11/xlockmore Makefile distinfo

x11/xlockmore: update to 5.89
DeltaFile
+3-3x11/xlockmore/distinfo
+2-2x11/xlockmore/Makefile
+5-52 files

FreeBSD/src e89c3ac — sys/dev/acpica/Osd OsdSchedule.c

acpi: Tasks: Document why 'acpi_task_count' is accessed unsynchronized

MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
DeltaFile
+1-0sys/dev/acpica/Osd/OsdSchedule.c
+1-01 files

FreeBSD/src f0825f7 — sys/dev/acpica/Osd OsdSchedule.c

acpi: Tasks: Make OsdSchedule.c whitespace clean

MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
DeltaFile
+1-1sys/dev/acpica/Osd/OsdSchedule.c
+1-11 files

FreeBSD/src 2165acc — sys/dev/acpica/Osd OsdSchedule.c

acpi: Tasks: Remove unnecessary includes

MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
DeltaFile
+0-2sys/dev/acpica/Osd/OsdSchedule.c
+0-21 files

FreeBSD/ports c3216c6 — net/kea-devel Makefile distinfo

net/kea-devel: Update to 3.3.2
DeltaFile
+41-40net/kea-devel/pkg-plist
+3-3net/kea-devel/distinfo
+1-2net/kea-devel/Makefile
+45-453 files

FreeBSD/src 4a0ec46 — sys/net iflib.c

iflib: Do not ring the transmit doorbell when nothing is pending

For a lightly used ring iflib_txd_db_check() may defer zero descriptors,
so its "pending >= limit" test is true even when nothing has been queued
since the last doorbell.  iflib_txq_drain() calls it before, inside and
after its loop, so a sender that drains its own packet wrote the tail
register three times per packet, twice with the value the hardware
already had.

The log of 81be655266fa ("iflib: ensure that tx interrupts enabled and
cleanups") calls skipping the doorbell when db_pending is zero "an
obvious missing optimization"; the comparison against a limit of zero
defeated it.  vmx(4) and mgb(4) have dropped such repeated requests in
the driver since 2019.  Return early when nothing is pending.

Reviewed by:            gallatin
MFC after:              2 weeks
Sponsored by:           Rubicon Communications, LLC ("Netgate")
Differential Revision:  https://reviews.freebsd.org/D60290
DeltaFile
+7-0sys/net/iflib.c
+7-01 files

FreeBSD/src 16c787f — sys/arm64/arm64 busdma_bounce.c, sys/arm64/include bus_dma.h

arm64: Elide coherent busdma maps

Avoid allocating per-transfer maps for coherent tags that cannot
bounce. Retain maps for cache synchronization, CCA realms, and KMSAN.
These un-used maps carry with them memory and cache miss overheads.

Reviewed by: andrew
Differential Revision: https://reviews.freebsd.org/D60098
Sponsored by: Netflix
DeltaFile
+65-15sys/arm64/arm64/busdma_bounce.c
+8-4sys/arm64/include/bus_dma.h
+73-192 files

FreeBSD/src 2082f44 — crypto/openssh FREEBSD-upgrade

openssh: Add date bump command to FREEBSD-upgrade instructions

Provide a convenient in-place sed edit command to update the FreeBSD
VersionAddendum dates with today's date.

Sponsored by:   The FreeBSD Foundation

(cherry picked from commit 0ec81f6a531bf7b3b06e869c99295f3d4ab9ed8e)
(cherry picked from commit 2ba5b9da2be10261c383035bef932cd37d52f903)
DeltaFile
+5-0crypto/openssh/FREEBSD-upgrade
+5-01 files

FreeBSD/src b690ed4 — crypto/openssh FREEBSD-upgrade

openssh: Add reference for another local patch

A bug fix was committed locally and submitted upstream.  Document it in
our upgrade instructions, as these sometimes take a long time before
getting merged.

Sponsored by:   The FreeBSD Foundation

(cherry picked from commit 6531070132b0210aaaeb08c0dc93cb272bed348e)
(cherry picked from commit 14d6926293569048d2d04f6e5a13d80f192ad99e)
DeltaFile
+5-0crypto/openssh/FREEBSD-upgrade
+5-01 files

FreeBSD/src 0dfc112 — secure/usr.bin/scp Makefile, secure/usr.bin/sftp Makefile

openssh: Remove residual blank line at start of Makefile

This is part of commit e9ac41698b2f in main by imp@
DeltaFile
+0-1secure/usr.bin/ssh-keyscan/Makefile
+0-1secure/usr.bin/ssh-keygen/Makefile
+0-1secure/usr.bin/ssh-agent/Makefile
+0-1secure/usr.bin/ssh-add/Makefile
+0-1secure/usr.bin/sftp/Makefile
+0-1secure/usr.bin/scp/Makefile
+0-66 files not shown
+0-1212 files

FreeBSD/src dcab585 — secure ssh.mk, secure/lib/libssh Makefile

secure: Rearrange Makefile SRCS to match upstream Makefile.in

SRCS entries are kept in the same order and with the same line breaks as
upstream, to make comparison easier.

No functional change intended.

Reviewed by:    emaste
Approved by:    emaste (mentor)
Differential Revision:  https://reviews.freebsd.org/D49793

(cherry picked from commit 9440aad19dca73fdd224b128ac2dc2e78191ff15)
DeltaFile
+16-7secure/lib/libssh/Makefile
+2-2secure/libexec/sftp-server/Makefile
+1-2secure/usr.bin/sftp/Makefile
+1-1secure/usr.bin/scp/Makefile
+1-1secure/libexec/ssh-pkcs11-helper/Makefile
+2-0secure/ssh.mk
+23-131 files not shown
+24-147 files

FreeBSD/src 412c3a0 — sys/arm64/arm64 gicv5_acpi.c

arm64/gicv5: Use ArmMpidr to find the correct CPU

The GICv5 ACPI code uses CpuInterfaceNumber to as the CPU ID. This a
GICv5 CPU ID and may not be the same as the appropriate FreeBSD value.

It is also possible the target CPU is disabled, e.g. when the hw.ncpu
tunable is uses to limit CPUs. If this is the case we don't want to
enable the CPU in the cpu set as it is offline so cannot handle
interrupts.

Switch to use ArmMpidr to find which pcpu to use when finding which
CPUs the IRS is attached to.

Fixes:  9556306213e1 ("arm64: Add ACPI support to GICv5 driver")
Differential Revision:  https://reviews.freebsd.org/D59993
Sponsored by:   Arm Ltd
DeltaFile
+14-3sys/arm64/arm64/gicv5_acpi.c
+14-31 files

FreeBSD/ports 0b76328 — net-im/nchat Makefile distinfo, net-im/nchat/files patch-CMakeLists.txt patch-lib_tgchat_src_tgchat.cpp

net-im/nchat: update from 5.17.26 to 5.19.18

ChangeLog:      https://github.com/d99kris/nchat/compare/v5.17.26...v5.19.18

Sponsored by:   tipi.work
DeltaFile
+14-0net-im/nchat/files/patch-lib_tgchat_src_tgchat.cpp
+5-5net-im/nchat/files/patch-CMakeLists.txt
+3-3net-im/nchat/distinfo
+2-1net-im/nchat/Makefile
+24-94 files

FreeBSD/src 128e91e — libexec/rc/rc.d nuageinit_user_data_script

nuageinit: Allow the userdata script to run before firstboot* rc services

Allowing nuageinit user scripts to run before these makes it possible to
customize official BASIC-CI and BASIC-CLOUDINIT FreeBSD images.

This was requested by KDE for their CI.

Approved by:    cperciva
Pull-Request:   https://ron-dev.freebsd.org/FreeBSD/src/pulls/60

(cherry picked from commit 16e47f317c4ce2be5fed530bf8a9af9f9bf55364)
DeltaFile
+1-0libexec/rc/rc.d/nuageinit_user_data_script
+1-01 files

FreeBSD/src fdd3f6f — share/mk sys.mk bsd.lib.mk

bsd.lib.mk: only ctfmerge if objfiles have a CTF section

PR:             299013
Reported by:    Trond.Endrestol at ximalas.info
Reviewed by:    emaste
Fixes:          222210c6a822 ("libgcc_s: add libgcc_s_asneeded.so wrapper for gcc 16")
MFC after:      3 days
Sponsored by:   The FreeBSD Foundation
Differential Revision:  https://reviews.freebsd.org/D60252
DeltaFile
+1-1share/mk/sys.mk
+1-1share/mk/bsd.lib.mk
+2-22 files

FreeBSD/src 68386f6 — sys/dev/igc if_igc.c

igc: Fix the flow control sysctl

dev.igc.N.fc read and wrote a function-static variable shared by every
igc device, so a read returned the last value written to any of them (3
until the first write), not the state of the device.  The softc value
started as 0, which is also the value of "no flow control", while the
hardware was set up for full flow control.  As a result:

- Writing 0 was taken for no change and did nothing, unless another
  value had been written to that device before.
- igc_reset() took a softc value of 0 for "not set", so a device set to
  0 went back to full flow control on the next init.
- With more than one receive queue the driver enabled per-queue drop
  (SRRCTL.DROP_EN), which is meant for a MAC that does not send pause
  frames, although the MAC was told to send them.
- Values out of range were accepted and ignored.

A write only forced the MAC's flow control bits.  The pause bits
advertised to the link partner, the pause thresholds and DROP_EN stayed

    [24 lines not shown]
DeltaFile
+16-16sys/dev/igc/if_igc.c
+16-161 files

FreeBSD/ports f505f12 — devel/py-dbus pkg-plist distinfo

devel/py-dbus: devel/py-dbus: unbreak with python 3.13+, fix plist

Backport upstream commit to fix build with Python 3.13+
Fix plist, this unbreak packaging with free-treaded versions of Python
Limit minimal allowed Python version to 3.12

Revieved by:    arrowd (desktop)
DeltaFile
+5-1devel/py-dbus/Makefile
+2-2devel/py-dbus/pkg-plist
+3-1devel/py-dbus/distinfo
+10-43 files

FreeBSD/src f2b0910 — crypto/openssh moduli servconf.c, crypto/openssh/regress/unittests/crypto/testdata nistkats-44.json

OpenSSH: Update to 10.4p1

Full release notes are available at
https://www.openssh.com/txt/release-10.4

Selected highlights from the release notes:

Potentially-incompatible changes
--------------------------------

 * sshd(8): configuration dump mode ("sshd -G") now writes directives
   in mixed case (e.g. "PubkeyAuthentication") whereas previously it
   emitted only lower-case names.

 * ssh(1), sshd(8): make the transport protocol stricter by
   disconnecting if the peer sends non-KEX messages during a post-
   authentication key re-exchange. Previously a malicious peer could
   continue sending non-key exchange messages without penalty. These
   would be buffered, causing memory to be wasted up until the

    [73 lines not shown]
DeltaFile
+27,332-0crypto/openssh/libcrux_internal.h
+0-11,752crypto/openssh/libcrux_mlkem768_sha3.h
+1,869-1,349crypto/openssh/ChangeLog
+1,446-525crypto/openssh/servconf.c
+539-585crypto/openssh/moduli
+802-0crypto/openssh/regress/unittests/crypto/testdata/nistkats-44.json
+31,988-14,211158 files not shown
+37,553-15,620164 files