FreeBSD/src e40d608 — sys/kern kern_prot.c

cred: freebsd14_setgroups(): Remove a now-unnecessary local variable

MFC with:       e6fbef451dd4 ("cred: Fix a race in the FreeBSD-14-compatible setgroups(2)")
Sponsored by:   The FreeBSD Foundation
DeltaFile
+2-5sys/kern/kern_prot.c
+2-51 files

FreeBSD/src e6fbef4 — sys/kern kern_prot.c, sys/sys syscallsubr.h

cred: Fix a race in the FreeBSD-14-compatible setgroups(2)

The freebsd14_setgroups() function would try to modify the effective GID
on the current process' credentials without holding the process lock,
allowing races with other threads concurrently modifying the process
credentials.  In the worst case, freebsd14_setgroups() could be
manipulating a 'struct ucred' already freed by another thread (in the
very small window after reading 'p_ucred' without lock but before
modifying the effective GID).  Concurrent uses of freebsd14_setgroups()
or setcred() could also lead to non-atomic credentials modifications.

Fix this by making kern_setgroups() take a new boolean indicating
whether the passed array includes the effective GID in its first slot.
When this boolean is true, it internally keeps the effective GID in
a separate variable, pretends that the groups[] array that was passed
actually starts at 'groups + 1', do the usual steps to set the
supplementary groups and new extra ones to set the effective GID along,
without releasing the process lock in between.


    [5 lines not shown]
DeltaFile
+43-15sys/kern/kern_prot.c
+2-1sys/sys/syscallsubr.h
+45-162 files

FreeBSD/src 2447e77 — contrib/tzcode version theory.html

tzcode: Update to 2026e

MFC after:      1 week
DeltaFile
+38-0contrib/tzcode/NEWS
+3-3contrib/tzcode/localtime.c
+2-2contrib/tzcode/asctime.c
+1-1contrib/tzcode/version
+1-1contrib/tzcode/theory.html
+45-75 files

FreeBSD/src c8754e8 — . version theory.html

Import tzcode 2026e
DeltaFile
+38-0NEWS
+2-2asctime.c
+3-0localtime.c
+1-1version
+1-1theory.html
+45-45 files

FreeBSD/src 304088e — sys/powerpc/aim mmu_radix.c

powerpc/radix: fix double page offset in mmu_radix_sync_icache()

mmu_radix_sync_icache() adds the offset of va within its page to the
physical address it gets from mmu_radix_extract_locked().  That address
already includes the offset - the extract routines return the physical
address of the byte, not of the frame - so the offset is counted twice
and __syncicache() is handed frame + 2 * offset.

The hash MMU counterpart, moea64_sync_icache(), has to add the offset
because PVO_PADDR() yields only the frame.  Here the addition is wrong.

Fixes:  6f0b2a235a13 ("powerpc/pmap: Add pmap_sync_icache() for radix pmap")
Reviewed by:    jhibbits
MFC after:      1 week
Differential Revision:  https://reviews.freebsd.org/D59870

(cherry picked from commit 9d0859637f99160e17b656df153effae3df31f8b)
(cherry picked from commit 107212618921492ffed84d6ea3c9a27c77aaf725)
DeltaFile
+2-4sys/powerpc/aim/mmu_radix.c
+2-41 files

FreeBSD/src 6db5b4f — sys/powerpc/powerpc elf64_machdep.c

sys/powerpc/powerpc/elf64_machdep.c: enable ASLR on ELFv2

Turns out that ever since introducing ELFv2 support, it was missing
ASLR, it was only used for ELFv1 processes.

Reviewed by:    jhibbits (via IRC #powerpc64)
MFC after:      1 week

(cherry picked from commit 30ed27ff2556c591a1791105d1dfe7464d3f5b80)
(cherry picked from commit edb560a7ccd69440e3bcd3e00ad9b347328f1be3)
DeltaFile
+1-1sys/powerpc/powerpc/elf64_machdep.c
+1-11 files

FreeBSD/src 1072126 — sys/powerpc/aim mmu_radix.c

powerpc/radix: fix double page offset in mmu_radix_sync_icache()

mmu_radix_sync_icache() adds the offset of va within its page to the
physical address it gets from mmu_radix_extract_locked().  That address
already includes the offset - the extract routines return the physical
address of the byte, not of the frame - so the offset is counted twice
and __syncicache() is handed frame + 2 * offset.

The hash MMU counterpart, moea64_sync_icache(), has to add the offset
because PVO_PADDR() yields only the frame.  Here the addition is wrong.

Fixes:  6f0b2a235a13 ("powerpc/pmap: Add pmap_sync_icache() for radix pmap")
Reviewed by:    jhibbits
MFC after:      1 week
Differential Revision:  https://reviews.freebsd.org/D59870

(cherry picked from commit 9d0859637f99160e17b656df153effae3df31f8b)
DeltaFile
+2-4sys/powerpc/aim/mmu_radix.c
+2-41 files

FreeBSD/src edb560a — sys/powerpc/powerpc elf64_machdep.c

sys/powerpc/powerpc/elf64_machdep.c: enable ASLR on ELFv2

Turns out that ever since introducing ELFv2 support, it was missing
ASLR, it was only used for ELFv1 processes.

Reviewed by:    jhibbits (via IRC #powerpc64)
MFC after:      1 week

(cherry picked from commit 30ed27ff2556c591a1791105d1dfe7464d3f5b80)
DeltaFile
+1-1sys/powerpc/powerpc/elf64_machdep.c
+1-11 files

FreeBSD/src 6b3d312 — usr.sbin/traceroute6 traceroute6.8 traceroute6.c

traceroute6: MFC: implement firewall evasion mode

Merge implementation of "traceroute -e" to traceroute6 for TCP/UDP/SCTP.

(cherry picked from commit f1cfcfb2e51ae5afa8941342ad10f650db8279c5)
DeltaFile
+16-12usr.sbin/traceroute6/traceroute6.c
+6-2usr.sbin/traceroute6/traceroute6.8
+22-142 files

FreeBSD/src bc57de1 — share/man/man4 me.4

me.4: MFC: note that it is a point-to-point interface

Add explicit note that me(4) works as a point-to-point pseudo device.

(cherry picked from commit f69eab727edbab1385e5ffc8b3f6cb5a233f62c0)
DeltaFile
+2-2share/man/man4/me.4
+2-21 files

FreeBSD/src 42f9573 — usr.sbin/traceroute6 traceroute6.8 traceroute6.c

traceroute6: MFC: implement firewall evasion mode

Merge implementation of "traceroute -e" to traceroute6 for TCP/UDP/SCTP.

(cherry picked from commit f1cfcfb2e51ae5afa8941342ad10f650db8279c5)
DeltaFile
+16-12usr.sbin/traceroute6/traceroute6.c
+6-2usr.sbin/traceroute6/traceroute6.8
+22-142 files

FreeBSD/src f07c4f6 — share/man/man4 me.4

me.4: MFC: note that it is a point-to-point interface

Add explicit note that me(4) works as a point-to-point pseudo device.

(cherry picked from commit f69eab727edbab1385e5ffc8b3f6cb5a233f62c0)
DeltaFile
+2-2share/man/man4/me.4
+2-21 files

FreeBSD/src a179e72 — sys/ufs/ufs ufs_lookup.c ufs_vnops.c

ufs: report a mismatched ".." in ufs_dirrewrite()

When ufs_rename() moves a directory to a new parent and ufs_dirrewrite()
fails to rewrite its ".." entry, it reports "bad dir ... rename: missing
.. entry" whatever the error.  ufs_dirrewrite() never finds a missing
"..", though: it fails with EIDRM when the ".." entry names another inode
than the expected one, and otherwise only when the directory block cannot
be read or written.  The latter happens for every directory rename in
flight when the device goes away under a forcibly unmounted file system,
and the log then fills with reports of directories that are intact on
disk.

Report the EIDRM case with ufs_dirbad() in ufs_dirrewrite() itself, so
that all of its callers get the same diagnostic, and drop the report
from ufs_rename().  Errors from the lower layers are not reported, as
usual for an I/O initiator.

Reviewed by:    kib
MFC after:      2 weeks
Differential Revision:  https://reviews.freebsd.org/D60137
DeltaFile
+1-3sys/ufs/ufs/ufs_vnops.c
+2-0sys/ufs/ufs/ufs_lookup.c
+3-32 files

FreeBSD/src f11af65 — contrib/tzdata zone1970.tab zone.tab

contrib/tzdata: import tzdata 2026e

Changes: https://github.com/eggert/tz/blob/2026e/NEWS

Briefly:
    Manitoba moves to permanent -05 on 2026-10-31.

MFC after:      3 days
DeltaFile
+98-20contrib/tzdata/northamerica
+38-0contrib/tzdata/NEWS
+26-4contrib/tzdata/europe
+4-1contrib/tzdata/zonenow.tab
+1-1contrib/tzdata/zone1970.tab
+1-1contrib/tzdata/zone.tab
+168-273 files not shown
+171-309 files

FreeBSD/src cc5c384 — . zone1970.tab zone.tab

Import tzdata 2026e
DeltaFile
+98-20northamerica
+38-0NEWS
+26-4europe
+4-1zonenow.tab
+1-1zone1970.tab
+1-1zone.tab
+168-273 files not shown
+171-309 files

FreeBSD/src c121ed3 — sys/compat/linuxkpi/common/src linux_pci.c

linuxkpi: Fix double-cleanup in linux_pci_attach_device() error path

(cherry picked from commit ac9c07a3e90888d69d0a524de520d4de8ae60de5)
DeltaFile
+7-12sys/compat/linuxkpi/common/src/linux_pci.c
+7-121 files

FreeBSD/src 6d78add — share/misc bsd-family-tree

bsd-family-tree: add NetBSD 10.2

(cherry picked from commit 7b7ef798bfc56c56e80b88bc277d5c6158dcaee4)
DeltaFile
+23-20share/misc/bsd-family-tree
+23-201 files

FreeBSD/src 75655f9 — share/misc bsd-family-tree

bsd-family-tree: add NetBSD 9.5 and FreeBSD 14.5

(cherry picked from commit ae458518935eee7a6dc59958f1fb9da223b873c3)
DeltaFile
+41-37share/misc/bsd-family-tree
+41-371 files

FreeBSD/src 493231a — share/misc bsd-family-tree

bsd-family-tree: add NetBSD 10.2

(cherry picked from commit 7b7ef798bfc56c56e80b88bc277d5c6158dcaee4)
DeltaFile
+23-20share/misc/bsd-family-tree
+23-201 files

FreeBSD/src 1eacca6 — share/misc bsd-family-tree

bsd-family-tree: add NetBSD 9.5 and FreeBSD 14.5

(cherry picked from commit ae458518935eee7a6dc59958f1fb9da223b873c3)
DeltaFile
+41-37share/misc/bsd-family-tree
+41-371 files

FreeBSD/src ec8b68b — sys/amd64/conf GENERIC

amd64: Revert an unintended change to GENERIC

Fixes:  767cd9bb4200 ("vm_swapout: Fix the build without options RACCT")
DeltaFile
+3-3sys/amd64/conf/GENERIC
+3-31 files

FreeBSD/src 5990a88 — tests/sys/geom/class/label basic.sh, tests/sys/geom/class/zoned conf.sh

tests/geom: fix ATF test listing when geom class module is missing

geom_subr.sh serves both legacy TAP tests and ATF tests. It defaults to the
TAP path, so ATF tests must set ATF_TEST=true before sourcing it.

Sponsored by:   Netflix
DeltaFile
+1-0tests/sys/geom/class/zoned/conf.sh
+1-0tests/sys/geom/class/label/basic.sh
+2-02 files

FreeBSD/src af5a659 — test/recipes/10-test_bn_data bngcd.txt, test/recipes/30-test_evp_data evppkey_ecc.txt evpkdf_ssh.txt

openssl: import 3.5.9

This change adds openssl 3.5.9 from [upstream][1].

The 3.5.9 artifact was been verified via [PGP key][2] and by [SHA256 checksum][3].

3.5.9 is a security patch release, with the highest CVE fixed being ranked High.

More information about the release (from a high level) can be found in
the [release notes][4].

Updated via [`update_openssl.sh`][5] `update_openssl.sh 3.5.9`.

Maintainer note: large test input files under `tests/recipes` were removed as
part of the import in order to pass the pre-receive checker. Please see this
[GitHub Issue][6] for more details.

1: https://github.com/openssl/openssl/releases/download/openssl-3.5.9/openssl-3.5.9.tar.gz
2: https://github.com/openssl/openssl/releases/download/openssl-3.5.9/openssl-3.5.9.tar.gz.asc

    [4 lines not shown]
DeltaFile
+0-23,927test/recipes/30-test_evp_data/evpciph_aes_ccm_cavs.txt
+0-17,330test/recipes/10-test_bn_data/bngcd.txt
+0-11,686test/recipes/30-test_evp_data/evppkey_kas.txt
+0-5,037test/recipes/30-test_evp_data/evpkdf_tls13_kdf.txt
+0-4,943test/recipes/30-test_evp_data/evpkdf_ssh.txt
+0-4,563test/recipes/30-test_evp_data/evppkey_ecc.txt
+0-67,4861,249 files not shown
+10,636-197,9141,255 files

FreeBSD/src afe3e2e — share/man/man4 unionfs.4

unionfs.4: Canonicalize SYNOPSIS + nit SPDX

MFC after:      3 days
DeltaFile
+4-12share/man/man4/unionfs.4
+4-121 files

FreeBSD/src bfe3273 — share/man/man4 ums.4

ums.4: Canonicalize SYNOPSIS + tag SPDX

MFC after:      3 days
DeltaFile
+10-15share/man/man4/ums.4
+10-151 files

FreeBSD/src dc20c58 — share/man/man4 umoscom.4

umoscom.4: Canonicalize SYNOPSIS + tag SPDX

MFC after:      3 days
DeltaFile
+7-13share/man/man4/umoscom.4
+7-131 files

FreeBSD/src c4e25d1 — share/man/man4 umodem.4

umodem.4: Canonicalize SYNOPSIS + tag SPDX

MFC after:      3 days
DeltaFile
+8-13share/man/man4/umodem.4
+8-131 files

FreeBSD/src c3e55f4 — usr.sbin/bhyve rtc_pl031.c

bhyve: rtc_pl031: Fix PeriphID and CellID values

PeriphID and CellID values are determined by macros which take an
index. They currently receive a bus offset which has a stride of 4 bytes.
This causes the ID1-3 registers to report incorrect values.
Scale the offset before passing it to the macro to fix this.

Tested with kvm-unit-tests/arm/pl031.

Signed-off-by: Kajetan Puchalski <kajetan.puchalski at arm.com>

Reviewed by:    jrtc27
Fixes:          014d7082a239 ("bhyve: Implement a PL031 RTC on arm64")
MFC after:      1 week
Pull Request:   https://github.com/freebsd/freebsd-src/pull/2358
Closes:         https://github.com/freebsd/freebsd-src/pull/2358

(cherry picked from commit a554906ea44c26925730a25263e64890d48d2b36)
DeltaFile
+2-2usr.sbin/bhyve/rtc_pl031.c
+2-21 files

FreeBSD/src 767cd9b — sys/amd64/conf GENERIC, sys/vm vm_swapout.c

vm_swapout: Fix the build without options RACCT

Reported by:    Jenkins
Fixes:          da0764f23554 ("vm_swapout: Restore handling of RLIMIT_RSS")
DeltaFile
+6-1sys/vm/vm_swapout.c
+3-3sys/amd64/conf/GENERIC
+9-42 files

FreeBSD/src f3d6bce — usr.sbin/zonectl/tests zonectl_test.sh

tests/zonectl: skip when geom_zoned module is missing

Approved by:    asomers
Sponsored by:   Netflix
Differential Revision:  https://reviews.freebsd.org/D60144
DeltaFile
+8-0usr.sbin/zonectl/tests/zonectl_test.sh
+8-01 files