sysutils/cni-epair: New port: CNI plugin giving containers a LAN address via epair and bridge
A CNI plugin that gives FreeBSD containers an address on a real LAN segment.
FreeBSD has no macvlan. This plugin does the native equivalent: it creates an
epair per container, attaches one end to a host bridge, moves the other into
the container's jail, and applies the address supplied by IPAM.
IPv4 and IPv6 are both supported, together or alone: a network configuration
carrying a range for each gives the container an address and a default route
in both families.
It implements the ADD, DEL, CHECK and VERSION commands, and delegates address
allocation to the IPAM plugin named in the network configuration.
WWW: https://github.com/daemonless/cni-epair
PR: 298571
sysutils/fjord: New port: Web UI for managing container compose stacks
fjord is a web management interface and daemon for running OCI container
applications natively on FreeBSD, as Compose stacks. Delivered as a single
self-contained binary with an embedded web UI, it manages stack lifecycles,
storage, networks and application catalogs using standard compose.yaml and
.env files directly on the filesystem with zero database lock-in.
Features:
- Dual-engine runtime: orchestrate stacks via Podman (with ocijail) or
native FreeBSD jails via AppJail (appjail-director).
- Filesystem source of truth: stacks are plain directories containing
standard compose.yaml and .env files.
- Workload adoption: convert existing standalone containers or jails into
managed Compose stacks in place.
- Automated host diagnostics: pre-flight checks verify engine binaries,
API sockets, and PF firewall anchors with copyable fixes.
- Integrated application catalog for one-click stack deployments.
[3 lines not shown]
deskutils/copyq: Update to 17.0.0
Enable audio and QCA encryption support, disabled since 14.0.0 while
the required ports were sorted out. Both are now optional and on by
default, pulling in audio/miniaudio, security/qca and
security/qtkeychain.
ChangeLog: https://github.com/hluk/CopyQ/releases/tag/v17.0.0
www/deno: enable Temporal, fix deno compile
- Re-enable Temporal support in V8. Use the cargo-vendored
temporal_capi crate instead of building it with GN, which would need
the Chromium Rust toolchain; a static library built from it in
pre-build is linked into mksnapshot.
- Fix executables produced by `deno compile`, which failed with
"Exec format error": libsui relocated the program header table past
the first page, which the FreeBSD kernel rejects. For executables,
store the payload in a non-allocated section and read it back from
the file instead.
- Implement os.cpus() with sysctl(3) instead of returning dummy
values, and process.title with setproctitle(3).
- Use system sqlite3, libffi, libdeflate and liblzma instead of
bundled copies.
- Drop unused openssl crates from CARGO_CRATES; they were only needed
by keyring's vendored feature, which is already disabled.
- Remove obsolete patches for the release channel and tsgo.
security/keepassxc276: Fix build with CMake 4
Set CMAKE_POLICY_VERSION_MINIMUM to 3.5 as upstream 2.7.6 still declares
cmake_minimum_required() below 3.5, which CMake 4 rejects.
PR: 298433
Reported by: arrowd
stand: Implement zfs_dnode_readlink in terms of zfs_dnode_sa_lookup
Get the link offset using the zfs_dnode_sa_lookup helper now.
Recently, the symbolic links we rely on in the boot loader have stopped
working.
Prior to OpenZFS commit e90badec11d3 ("Inherit the project ID for every
object type", Matt Turner, 2026-08-14), symbolic link information was
written at a fixed offset in the SA data. Since that commit, the
inherited PROJIDs mean that all pools with quota enabled have started
writing symbolic links with a new, non-fixed offset. Old symbolic links
remained unchanged, but new ones were written with a different
offset. At work, we have all these things: rewritten BEs, quotas, and a
dependence on symbolic links in our boot path.
This came in on 2026-08-24 OpenZFS merge (22649d4dba73). This was 12
hours after stab week for August, so we didn't hit this until the
September stab week. Since the new kernel has to write links at the new
[4 lines not shown]
stand: Load dynamic system attribute offsets
zfs_sa_load looks up all the system attribute offsets and stores them in
the mountpoint.
Sponsored by: Netflix
Differential Revision: https://reviews.freebsd.org/D60264
stand: Lookup specific SA value in a dnode
zfs_dnode_sa_lookup will look in the bonus part of the dnode for the
requested SA values, and fall back to the spill as if it's not there.
Sponsored by: Netflix
Differential Revision: https://reviews.freebsd.org/D60266
stand: update zfs_dnode_stat to use zfs_dnode_sa_lookup
Find the SA values with the zfs_dnode_sa_lookup and read out the
relevant bits for the stat buffer.
Sponsored by: Netflix
Differential Revision: https://reviews.freebsd.org/D60267
stand: Lookup the offsets for this SA bundle
Compute the offset for the data for this bundle and the requested data
type.
Sponsored by: Netflix
Differential Revision: https://reviews.freebsd.org/D60265