FreeBSD/src f11af65 — contrib/tzdata zone1970.tab zone.tab

contrib/tzdata: import tzdata 2026e

Changes: https://github.com/eggert/tz/blob/2026e/NEWS

Briefly:
    Manitoba moves to permanent -05 on 2026-10-31.

MFC after:      3 days
DeltaFile
+98-20contrib/tzdata/northamerica
+38-0contrib/tzdata/NEWS
+26-4contrib/tzdata/europe
+4-1contrib/tzdata/zonenow.tab
+1-1contrib/tzdata/zone1970.tab
+1-1contrib/tzdata/zone.tab
+168-273 files not shown
+171-309 files

FreeBSD/src cc5c384 — . zone1970.tab zone.tab

Import tzdata 2026e
DeltaFile
+98-20northamerica
+38-0NEWS
+26-4europe
+4-1zonenow.tab
+1-1zone1970.tab
+1-1zone.tab
+168-273 files not shown
+171-309 files

FreeBSD/src c121ed3 — sys/compat/linuxkpi/common/src linux_pci.c

linuxkpi: Fix double-cleanup in linux_pci_attach_device() error path

(cherry picked from commit ac9c07a3e90888d69d0a524de520d4de8ae60de5)
DeltaFile
+7-12sys/compat/linuxkpi/common/src/linux_pci.c
+7-121 files

FreeBSD/src 6d78add — share/misc bsd-family-tree

bsd-family-tree: add NetBSD 10.2

(cherry picked from commit 7b7ef798bfc56c56e80b88bc277d5c6158dcaee4)
DeltaFile
+23-20share/misc/bsd-family-tree
+23-201 files

FreeBSD/src 75655f9 — share/misc bsd-family-tree

bsd-family-tree: add NetBSD 9.5 and FreeBSD 14.5

(cherry picked from commit ae458518935eee7a6dc59958f1fb9da223b873c3)
DeltaFile
+41-37share/misc/bsd-family-tree
+41-371 files

FreeBSD/src 493231a — share/misc bsd-family-tree

bsd-family-tree: add NetBSD 10.2

(cherry picked from commit 7b7ef798bfc56c56e80b88bc277d5c6158dcaee4)
DeltaFile
+23-20share/misc/bsd-family-tree
+23-201 files

FreeBSD/src 1eacca6 — share/misc bsd-family-tree

bsd-family-tree: add NetBSD 9.5 and FreeBSD 14.5

(cherry picked from commit ae458518935eee7a6dc59958f1fb9da223b873c3)
DeltaFile
+41-37share/misc/bsd-family-tree
+41-371 files

FreeBSD/src ec8b68b — sys/amd64/conf GENERIC

amd64: Revert an unintended change to GENERIC

Fixes:  767cd9bb4200 ("vm_swapout: Fix the build without options RACCT")
DeltaFile
+3-3sys/amd64/conf/GENERIC
+3-31 files

FreeBSD/src 5990a88 — tests/sys/geom/class/label basic.sh, tests/sys/geom/class/zoned conf.sh

tests/geom: fix ATF test listing when geom class module is missing

geom_subr.sh serves both legacy TAP tests and ATF tests. It defaults to the
TAP path, so ATF tests must set ATF_TEST=true before sourcing it.

Sponsored by:   Netflix
DeltaFile
+1-0tests/sys/geom/class/zoned/conf.sh
+1-0tests/sys/geom/class/label/basic.sh
+2-02 files

FreeBSD/src af5a659 — test/recipes/10-test_bn_data bngcd.txt, test/recipes/30-test_evp_data evppkey_ecc.txt evpkdf_ssh.txt

openssl: import 3.5.9

This change adds openssl 3.5.9 from [upstream][1].

The 3.5.9 artifact was been verified via [PGP key][2] and by [SHA256 checksum][3].

3.5.9 is a security patch release, with the highest CVE fixed being ranked High.

More information about the release (from a high level) can be found in
the [release notes][4].

Updated via [`update_openssl.sh`][5] `update_openssl.sh 3.5.9`.

Maintainer note: large test input files under `tests/recipes` were removed as
part of the import in order to pass the pre-receive checker. Please see this
[GitHub Issue][6] for more details.

1: https://github.com/openssl/openssl/releases/download/openssl-3.5.9/openssl-3.5.9.tar.gz
2: https://github.com/openssl/openssl/releases/download/openssl-3.5.9/openssl-3.5.9.tar.gz.asc

    [4 lines not shown]
DeltaFile
+0-23,927test/recipes/30-test_evp_data/evpciph_aes_ccm_cavs.txt
+0-17,330test/recipes/10-test_bn_data/bngcd.txt
+0-11,686test/recipes/30-test_evp_data/evppkey_kas.txt
+0-5,037test/recipes/30-test_evp_data/evpkdf_tls13_kdf.txt
+0-4,943test/recipes/30-test_evp_data/evpkdf_ssh.txt
+0-4,563test/recipes/30-test_evp_data/evppkey_ecc.txt
+0-67,4861,249 files not shown
+10,636-197,9141,255 files

FreeBSD/src afe3e2e — share/man/man4 unionfs.4

unionfs.4: Canonicalize SYNOPSIS + nit SPDX

MFC after:      3 days
DeltaFile
+4-12share/man/man4/unionfs.4
+4-121 files

FreeBSD/src bfe3273 — share/man/man4 ums.4

ums.4: Canonicalize SYNOPSIS + tag SPDX

MFC after:      3 days
DeltaFile
+10-15share/man/man4/ums.4
+10-151 files

FreeBSD/src dc20c58 — share/man/man4 umoscom.4

umoscom.4: Canonicalize SYNOPSIS + tag SPDX

MFC after:      3 days
DeltaFile
+7-13share/man/man4/umoscom.4
+7-131 files

FreeBSD/src c4e25d1 — share/man/man4 umodem.4

umodem.4: Canonicalize SYNOPSIS + tag SPDX

MFC after:      3 days
DeltaFile
+8-13share/man/man4/umodem.4
+8-131 files

FreeBSD/src c3e55f4 — usr.sbin/bhyve rtc_pl031.c

bhyve: rtc_pl031: Fix PeriphID and CellID values

PeriphID and CellID values are determined by macros which take an
index. They currently receive a bus offset which has a stride of 4 bytes.
This causes the ID1-3 registers to report incorrect values.
Scale the offset before passing it to the macro to fix this.

Tested with kvm-unit-tests/arm/pl031.

Signed-off-by: Kajetan Puchalski <kajetan.puchalski at arm.com>

Reviewed by:    jrtc27
Fixes:          014d7082a239 ("bhyve: Implement a PL031 RTC on arm64")
MFC after:      1 week
Pull Request:   https://github.com/freebsd/freebsd-src/pull/2358
Closes:         https://github.com/freebsd/freebsd-src/pull/2358

(cherry picked from commit a554906ea44c26925730a25263e64890d48d2b36)
DeltaFile
+2-2usr.sbin/bhyve/rtc_pl031.c
+2-21 files

FreeBSD/src 767cd9b — sys/amd64/conf GENERIC, sys/vm vm_swapout.c

vm_swapout: Fix the build without options RACCT

Reported by:    Jenkins
Fixes:          da0764f23554 ("vm_swapout: Restore handling of RLIMIT_RSS")
DeltaFile
+6-1sys/vm/vm_swapout.c
+3-3sys/amd64/conf/GENERIC
+9-42 files

FreeBSD/src f3d6bce — usr.sbin/zonectl/tests zonectl_test.sh

tests/zonectl: skip when geom_zoned module is missing

Approved by:    asomers
Sponsored by:   Netflix
Differential Revision:  https://reviews.freebsd.org/D60144
DeltaFile
+8-0usr.sbin/zonectl/tests/zonectl_test.sh
+8-01 files

FreeBSD/src 669cd0d — sys/dev/rge if_rge.c

rge: Preserve replacement mbufs after defragmentation

m_defrag() has pointer-return ownership semantics: success frees the
original chain and returns a replacement, while failure returns NULL and
leaves the original owned by the caller.  rge_encap() compared that
pointer as an integer status and could return failure after success,
causing rge_tx_task() to free its stale old head.

Pass the mbuf by reference, retain the replacement returned by
m_defrag(), and publish it to the caller before retrying DMA mapping.  A
later mapping failure is then cleaned up through the current chain, and
a successful transmission uses that same chain for BPF and TX ownership.

An unprivileged process can reach the EFBIG branch in mapped-sendfile
mode.

Signed-off-by: Andrew Griffiths <andrew at calif.io>

Reviewed by:    adrian, markj

    [2 lines not shown]
DeltaFile
+16-10sys/dev/rge/if_rge.c
+16-101 files

FreeBSD/src 233b6ef — lib/libsys pdfork.2

pdfork.2: downgrade sections inside description to subsections

Sponsored by:   The FreeBSD Foundation
MFC after:      3 days
DeltaFile
+2-2lib/libsys/pdfork.2
+2-21 files

FreeBSD/src cc467e4 — sys/amd64/amd64 mp_machdep.c

amd64/mp_machdep.c: remove double 'for' in comment

Sponsored by:   The FreeBSD Foundation
MFC after:      3 days
DeltaFile
+1-1sys/amd64/amd64/mp_machdep.c
+1-11 files

FreeBSD/src 18e9f60 — tests/sys/fs/fdescfs fdescfs_test.c

tests/fdescfs: skip when module is missing

Approved by:    nprice
Sponsored by:   Netflix
Differential Revision:  https://reviews.freebsd.org/D60145
DeltaFile
+1-0tests/sys/fs/fdescfs/fdescfs_test.c
+1-01 files

FreeBSD/src da0764f — sys/conf files, sys/vm vm_pageout.h vm_pageout.c

vm_swapout: Restore handling of RLIMIT_RSS

In commit 13a1129d700c, I removed the mechanism by which the pagedaemon
signals the swapout thread when page reclamation is unable to keep up
with demand.  This is because the swapout thread's main action in this
case is to swap out sleeping processes, but we removed this support.

However, it had the secondary effect of causing the swapout thread to
enforce RLIMIT_RSS when racct is not enabled.  Without it, if
racct_enabled is false, nothing ever kicks the swapout thread.

Restore the old behaviour of trying to enforce RLIMIT_RSS when the page
daemon is unable to keep up with demand.  I'm not at all convinced this
is a good way to implement the limit, but the change wasn't intentional,
so let's restore it for now.

Fixes:          13a1129d700c ("vm: Remove kernel stack swapping support, part 1")
Reviewed by:    olce, kib
MFC after:      2 weeks
Differential Revision:  https://reviews.freebsd.org/D56142
DeltaFile
+15-3sys/vm/vm_swapout.c
+7-1sys/vm/vm_pageout.c
+1-1sys/conf/files
+2-0sys/vm/vm_pageout.h
+25-54 files

FreeBSD/src eaba514 — lib/libpfctl libpfctl.c, sys/netpfil/pf pf_nl.h pf_nl.c

pf: carry pfra_fback in the netlink pfr_addr encoding

The netlink encoding of struct pfr_addr omits pfra_fback, so no
per-address feedback reaches userspace.  In particular,
pfr_get_astats() marks entries of tables without counters with
PFR_FB_NOCOUNT, which pfctl uses to skip their counters, so
"pfctl -v -T show" prints zero counters for such tables.

Add PFR_A_FBACK, emit it from the kernel and decode it in libpfctl.

Add a regression test.

Reviewed by:    kp
Approved by:    kp (mentor)
Fixes:          08f54dfca197 ("pf: convert DIOCRGETASTATS to netlink")
Sponsored by:   Rubicon Communications, LLC ("Netgate")
DeltaFile
+33-0tests/sys/netpfil/pf/table.sh
+1-0sys/netpfil/pf/pf_nl.h
+1-0sys/netpfil/pf/pf_nl.c
+1-0lib/libpfctl/libpfctl.c
+36-04 files

FreeBSD/src 48b29e9 — stand/common dev_net.h dev_net.c, stand/efi/loader memdisk.c

loader.efi: Retain standalone network configuration

DHCP initmd discovery used net_configure() to open and configure SNP,
then immediately closed the socket and released the protocol.
Selecting net0 as currdev subsequently required another exclusive
SNP attach, which may hang on some EDK II firmware.

Keep the configured socket available for ordinary network consumers
so NFS boot can reuse it. Add an explicit deconfiguration operation
and invoke it only when an initmd URL requires handing SNP back
to the firmware network stack.

Signed-off-by: Krzysztof Galazka <krzysztof.galazka at intel.com>

Reviewed by:    imp
Assisted by:    Github Copilot (GPT-5.6 Sol)
Sponsored by:   Intel Corporation
Differential Revision:  https://reviews.freebsd.org/D59999
DeltaFile
+27-6stand/common/dev_net.c
+2-0stand/efi/loader/memdisk.c
+1-0stand/common/dev_net.h
+30-63 files

FreeBSD/src c464012 — stand/common dev_net.c, stand/efi/loader main.c

loader.efi: Apply command-line DHCP overrides earlier

Ability to override DHCP options with command-line arguments
was affected by intoduction of initmd support. Initmd discovery
configures the network before loader arguments
were parsed, so a dhcp.root-path override was unavailable
during the first network configuration. Move parsing
arguments earlier and apply dhcp.root-path even if DHCP response
does not contain option 17. This allows providing a dynamic NFS
root e.g. by chain loading loader.efi from iPXE.

Signed-off-by: Krzysztof Galazka <krzysztof.galazka at intel.com>

Reviewed by:    imp
Assisted by:    Github Copilot (GPT-5.6 Sol)
Sponsored by:   Intel Corporation
Differential Revision:  https://reviews.freebsd.org/D59998
DeltaFile
+6-1stand/efi/loader/main.c
+1-3stand/libsa/bootp.c
+3-0stand/common/dev_net.c
+10-43 files

FreeBSD/src 3893050 — sys/riscv/include bus.h

riscv: Fix the bus_space_read_stream_8 macro

Reviewed by:    markj
MFC after:      1 week
Differential Revision:  https://reviews.freebsd.org/D60111
DeltaFile
+1-1sys/riscv/include/bus.h
+1-11 files

FreeBSD/src 3c58e64 — sys/netpfil/pf pf_nl.c, tests/sys/netpfil/pf src_track.sh

pf: set the correct type for rule timeouts

PR:             298877
MFC after:      1 week
Sponsored by:   Rubicon Communications, LLC ("Netgate")
DeltaFile
+24-0tests/sys/netpfil/pf/src_track.sh
+1-1sys/netpfil/pf/pf_nl.c
+25-12 files

FreeBSD/src 629c7cf — share/misc bsd-family-tree

bsd-family-tree: add macOS 27
DeltaFile
+3-2share/misc/bsd-family-tree
+3-21 files

FreeBSD/src 123342f — sys/netinet igmp.c

igmp: Deindent some code

No functional change intended.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
DeltaFile
+32-33sys/netinet/igmp.c
+32-331 files

FreeBSD/src dc47a69 — sys/netinet igmp.c

igmp: Refresh the ip header pointer after m_pullup()

There is a chance that the m_pullup() call immediately above invalidated
the "ip" pointer, so refresh it as we do with the IGMP header.
Otherwise the test in igmp_input_v3_query() for whether the packet is an
IGMPv3 general query might use a pointer to a freed mbuf.

MFC after:      1 week
Sponsored by:   The FreeBSD Foundation
DeltaFile
+1-0sys/netinet/igmp.c
+1-01 files