This URL: https://git.freebsd.catflap.wales/src/stable-15/raw-log-html/ _____________________________________________________________________________________________________________ Commit: 8ab5624f401c4830e0bbbe9f5287fc1a14d4864c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8ab5624f401c4830e0bbbe9f5287fc1a14d4864c Author: Olivier Cochard (Wed 5 Aug 2026 21:46:10 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 03:24:50 BST) tests/sys/kern: Skip capsicum procdesc tests when capability mode is unavailable (cherry picked from commit 3c5c55beee5ef80d8a9526480682cee86cbac584) M tests/sys/kern/Makefile M tests/sys/kern/pdwait.c M tests/sys/kern/procdesc.c _____________________________________________________________________________________________________________ Commit: c41e308ef27bda0b8149931923c6721aa321aad9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c41e308ef27bda0b8149931923c6721aa321aad9 Author: Konstantin Belousov (Sun 23 Aug 2026 21:53:00 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:46 BST) tty: gracefully handle proctree_lock locking (cherry picked from commit 420428718da769ea72d3f18ed8eba7c3d998b1c8) M sys/kern/tty.c M sys/kern/tty_pts.c M sys/sys/tty.h _____________________________________________________________________________________________________________ Commit: 2469f84bec79b090b261a6b075c76304541e2070 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2469f84bec79b090b261a6b075c76304541e2070 Author: Gleb Popov (Mon 3 Aug 2026 20:23:11 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:46 BST) kern/tty.c: Exterrorize returns (cherry picked from commit 62ccaec3dba6272590d97cc0aa0df28fd3d08d1c) M lib/libc/gen/exterr_cat_filenames.h M sys/kern/tty.c M sys/sys/exterr_cat.h _____________________________________________________________________________________________________________ Commit: 5362192f9df36eafa45d889a237778f1045707e6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5362192f9df36eafa45d889a237778f1045707e6 Author: Konstantin Belousov (Mon 24 Aug 2026 15:18:35 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:46 BST) tty: make tty_wait_background() aware of proctree_lock ownership (cherry picked from commit 824f934bf9d5fcb34dd6c97d650a26823158abf1) M sys/kern/tty.c M sys/kern/tty_ttydisc.c M sys/sys/tty.h _____________________________________________________________________________________________________________ Commit: a58557090670d61358b97eab285dcbde2402ad97 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a58557090670d61358b97eab285dcbde2402ad97 Author: Konstantin Belousov (Tue 25 Aug 2026 09:19:32 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:45 BST) tty: add tty_wait_proctree(9) (cherry picked from commit 9bd3fe5712217ef8ae4cebba8be82c45be0c72e6) M sys/kern/tty.c _____________________________________________________________________________________________________________ Commit: 124ccedff25e9a19c4203fb72ba5e0bd646595a8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=124ccedff25e9a19c4203fb72ba5e0bd646595a8 Author: Konstantin Belousov (Tue 25 Aug 2026 09:23:47 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:45 BST) condvar.9: document cv_wait_sig_unblock(9) (cherry picked from commit a15c71254afa25ce008334d63fb6feecd68605f8) M share/man/man9/condvar.9 _____________________________________________________________________________________________________________ Commit: 3867241ba06304309f014e7480a2481774660820 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3867241ba06304309f014e7480a2481774660820 Author: Konstantin Belousov (Tue 25 Aug 2026 09:18:35 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:44 BST) condvars(9): add cv_wait_sig_unlock() (cherry picked from commit 0cc6c442964d6294b796537522d9e462656bf16f) M sys/kern/kern_condvar.c M sys/sys/condvar.h _____________________________________________________________________________________________________________ Commit: 5b10e1c349f99ea56eafbceb95828a058f2102ea URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5b10e1c349f99ea56eafbceb95828a058f2102ea Author: Konstantin Belousov (Mon 31 Aug 2026 00:46:27 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:44 BST) tests/sys/kern/procdesc.c: mark grandchild var in pdopenpid_capmode() as volatile (cherry picked from commit b3734c1386dd2b0ade1a7f20d9ebf5f62c01819e) M tests/sys/kern/procdesc.c _____________________________________________________________________________________________________________ Commit: 2fbb853ec71e71bfa6e6194781ffc66f1fde9968 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2fbb853ec71e71bfa6e6194781ffc66f1fde9968 Author: Konstantin Belousov (Fri 28 Aug 2026 09:37:19 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:44 BST) sys/tests/kern/pdopenpid: pdopenpid(2) is allowed in cap mode (cherry picked from commit ddf62c83fc0aca39a1bfd8346ad6e925bfb2290e) M tests/sys/kern/procdesc.c _____________________________________________________________________________________________________________ Commit: 201fd5bc466185321d7fdfc4d49cc7f784095863 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=201fd5bc466185321d7fdfc4d49cc7f784095863 Author: Konstantin Belousov (Wed 8 Jul 2026 00:51:15 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:43 BST) pdfork.2: document cap mode, namely pdopenpid(2) and pdptrace(2) errors (cherry picked from commit 1ac08a43cf657564ebc2e036434e89552a6d3829) M lib/libsys/pdfork.2 M lib/libsys/ptrace.2 _____________________________________________________________________________________________________________ Commit: 665a5f0f45846c27e6fd253b4adbe5b6193cecb8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=665a5f0f45846c27e6fd253b4adbe5b6193cecb8 Author: Konstantin Belousov (Mon 13 Jul 2026 15:00:47 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:43 BST) Regen M sys/compat/freebsd32/freebsd32_sysent.c M sys/kern/init_sysent.c _____________________________________________________________________________________________________________ Commit: fe56ee28349cbc8e35c898864077aa844a155e61 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fe56ee28349cbc8e35c898864077aa844a155e61 Author: Konstantin Belousov (Tue 1 Sep 2026 23:14:58 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:43 BST) ptrace(2): allow ptrace(PT_TRACE_ME) in cap mode (cherry picked from commit c8f8d00c2422bf7eca71b7b41e9d586ca25c4b8a) M sys/kern/sys_process.c _____________________________________________________________________________________________________________ Commit: c09ee2f0cca6b7ce34d98dc8cc31cafa34fb9322 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c09ee2f0cca6b7ce34d98dc8cc31cafa34fb9322 Author: Konstantin Belousov (Fri 28 Aug 2026 18:54:02 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:42 BST) pdopenpid(2): in cap mode, translate all errors from pdopenpid1() to ECAPMODE (cherry picked from commit 326ab530dcabe70ab48728cad0465f35b30dbf60) M sys/kern/sys_procdesc.c _____________________________________________________________________________________________________________ Commit: 74145b2f9f980ea1c8f455f6b97d5a88e0564dc9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=74145b2f9f980ea1c8f455f6b97d5a88e0564dc9 Author: Konstantin Belousov (Wed 8 Jul 2026 00:46:56 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:42 BST) pdopenpid(2): allow in capability mode with restrictions (cherry picked from commit 73c92a978ccef5e1683914510ea35e6e338646d1) M sys/kern/sys_procdesc.c M sys/kern/syscalls.master _____________________________________________________________________________________________________________ Commit: 1cab7e212476174fc749627cc5114ebaf3f92590 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1cab7e212476174fc749627cc5114ebaf3f92590 Author: Konstantin Belousov (Wed 8 Jul 2026 00:46:56 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:41 BST) pdptrace(2): allow debugging in capability mode (cherry picked from commit 7006cb7bd22d07d2ce30b0fb7ebfe58771b2a32f) M sys/compat/freebsd32/freebsd32_misc.c M sys/kern/sys_process.c M sys/kern/syscalls.master _____________________________________________________________________________________________________________ Commit: 5e9d42f6aa710d71d1c054fa34e984d37447a850 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5e9d42f6aa710d71d1c054fa34e984d37447a850 Author: Konstantin Belousov (Tue 14 Jul 2026 17:59:17 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:41 BST) kern: add p_canopen() (cherry picked from commit 68d4b311270ecca80bbb887a5e502e2caacebc98) M sys/kern/kern_prot.c M sys/kern/sys_process.c M sys/sys/proc.h M sys/sys/ptrace.h _____________________________________________________________________________________________________________ Commit: 547bce66c47788f76720c3e7fd873a7f6424e3a5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=547bce66c47788f76720c3e7fd873a7f6424e3a5 Author: Konstantin Belousov (Sun 23 Aug 2026 00:04:32 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:41 BST) ptrace.2: document PT_GET_ABI_NAME (cherry picked from commit 3dfd63b58463e8982af2e45fc6dc1d5b03a88535) M lib/libsys/ptrace.2 _____________________________________________________________________________________________________________ Commit: 39321b7a14620485f1fd9ff7b769398cfda2dfdb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=39321b7a14620485f1fd9ff7b769398cfda2dfdb Author: Konstantin Belousov (Sat 22 Aug 2026 23:53:14 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:40 BST) ptrace(2): add PT_GET_ABI_NAME request (cherry picked from commit 6b9ef5dfc903c29e1d23bb6369b762251f2608f7) M sys/compat/freebsd32/freebsd32_misc.c M sys/kern/sys_process.c M sys/sys/ptrace.h _____________________________________________________________________________________________________________ Commit: bba959f73e52e284432b2a9569ce2f6f386d502d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bba959f73e52e284432b2a9569ce2f6f386d502d Author: Konstantin Belousov (Fri 28 Aug 2026 09:35:54 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:40 BST) tests/sys/kern/pdwait: adjust test for the addition of CAP_PTRACE (cherry picked from commit 5f5910ba3826435391d3e5b9ba9155376ec0b39d) M tests/sys/kern/pdwait.c _____________________________________________________________________________________________________________ Commit: 48e709bbbda209d46183a42e74b4dd1bda5ec12f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=48e709bbbda209d46183a42e74b4dd1bda5ec12f Author: Konstantin Belousov (Sun 19 Jul 2026 23:56:32 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:40 BST) pdfork.2, rights.4: document pdptrace(2), CAP_PTRACE, and pdfork(PD_PTRACE_CAP) (cherry picked from commit 45633600acade39cccc3b8daace7b3aeeb1f5b07) M lib/libsys/pdfork.2 M lib/libsys/ptrace.2 M share/man/man4/rights.4 _____________________________________________________________________________________________________________ Commit: c3d0110e12f053277ad9e22ac38b321bc0a261fe URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c3d0110e12f053277ad9e22ac38b321bc0a261fe Author: Konstantin Belousov (Fri 21 Aug 2026 10:39:34 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:39 BST) Regen M lib/libsys/_libsys.h M lib/libsys/syscalls.map M sys/compat/freebsd32/freebsd32_proto.h M sys/compat/freebsd32/freebsd32_syscall.h M sys/compat/freebsd32/freebsd32_syscalls.c M sys/compat/freebsd32/freebsd32_sysent.c M sys/compat/freebsd32/freebsd32_systrace_args.c M sys/kern/init_sysent.c M sys/kern/syscalls.c M sys/kern/systrace_args.c M sys/sys/syscall.h M sys/sys/syscall.mk M sys/sys/sysproto.h _____________________________________________________________________________________________________________ Commit: fbf7d1651e9abe2f34c545d9f7f891c41ad236b0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fbf7d1651e9abe2f34c545d9f7f891c41ad236b0 Author: Konstantin Belousov (Fri 21 Aug 2026 10:42:54 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:39 BST) lib/libsys: export pdptrace(2) (cherry picked from commit 6d17a04fc61c63182809dd41515e6a2c4aa0de63) M lib/libsys/Symbol.sys.map M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: 74883c24a04ac0cdf7facd8b80ec536d50ee8c4c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=74883c24a04ac0cdf7facd8b80ec536d50ee8c4c Author: Konstantin Belousov (Sun 19 Jul 2026 22:33:54 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:38 BST) Add pdptrace(2) (cherry picked from commit f8c0616052e2befaf7271fa82b212ff34a7913af) M sys/compat/freebsd32/freebsd32_misc.c M sys/kern/sys_process.c M sys/kern/syscalls.master M sys/sys/ptrace.h _____________________________________________________________________________________________________________ Commit: f83c2423ce0f24ff68cf12da01419c4ab09ad4ca URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f83c2423ce0f24ff68cf12da01419c4ab09ad4ca Author: Konstantin Belousov (Sun 19 Jul 2026 22:33:54 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:38 BST) ptrace: split sys_ptrace()/freebsd32_ptrace() (cherry picked from commit 9cea869940f197d558f640b6851d44a213be9e8a) M sys/compat/freebsd32/freebsd32_misc.c M sys/kern/sys_process.c M sys/sys/ptrace.h _____________________________________________________________________________________________________________ Commit: 06259de78fa0e3a5799f42a0c6e92f52857a257b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=06259de78fa0e3a5799f42a0c6e92f52857a257b Author: Konstantin Belousov (Fri 21 Aug 2026 10:50:49 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:38 BST) sys/bsm/audit_kevents.h: add AUE_PDPTRACE (cherry picked from commit b2f300ee8fc03a05376e1c28a625d701f6d3e0ce) M sys/bsm/audit_kevents.h _____________________________________________________________________________________________________________ Commit: 73e3e21d32855569fe1315f739746e9e321c7c4a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=73e3e21d32855569fe1315f739746e9e321c7c4a Author: Konstantin Belousov (Wed 8 Jul 2026 00:46:56 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:38 BST) pdfork(2): add PD_PTRACE_CAP flag (cherry picked from commit e8c313204887e7ba47b5c349acbe37d64a3162a1) M sys/kern/kern_fork.c M sys/kern/sys_procdesc.c M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: 34bc2da3ac66f3a1890c9a70713a1c6c8ee3f879 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=34bc2da3ac66f3a1890c9a70713a1c6c8ee3f879 Author: Konstantin Belousov (Wed 8 Jul 2026 00:46:28 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:37 BST) capsicum: add CAP_PTRACE (cherry picked from commit 5f82dd8e91610ceafe7ddbc702d97ffe7573f53f) M sys/kern/subr_capability.c M sys/sys/caprights.h M sys/sys/capsicum.h _____________________________________________________________________________________________________________ Commit: 2eff633de3b36b1188676e46edafd0a266520fc3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2eff633de3b36b1188676e46edafd0a266520fc3 Author: Konstantin Belousov (Wed 8 Jul 2026 18:18:51 BST) Committer: Konstantin Belousov (Sat 5 Sep 2026 01:33:37 BST) kern/kern_descrip.c: export filecaps_fill() (cherry picked from commit 8c911d9a9890128ef8f20ead1748ffcbd9f24577) M sys/kern/kern_descrip.c M sys/sys/filedesc.h _____________________________________________________________________________________________________________ Commit: 23621baf099d7ace6cb6445cab9ca6a811f25e80 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=23621baf099d7ace6cb6445cab9ca6a811f25e80 Author: Kevin Bowling (Sat 22 Aug 2026 04:14:37 BST) Committer: Kevin Bowling (Sat 5 Sep 2026 01:29:55 BST) pci: Expose a VF's owning PF to bus subclasses ofw_pcibus now uses pci_iov_get_pf() to inherit PF locality for VFs, but the accessor was inadvertently left in an uncommited ACPI change. This breaks powerpc builds. Expose the accessor from the PCI core and provide a stub when PCI_IOV is omitted. Record VF ownership before pci_add_child() so child added callbacks can safely query it, and remove the later redundant assignment. Sponsored by: BBOX.io (cherry picked from commit 3481a9cdc4dc26ef583bb0f46a04d5d059cde466) M sys/dev/pci/pci.c M sys/dev/pci/pci_iov.c M sys/dev/pci/pci_private.h _____________________________________________________________________________________________________________ Commit: 0b94a7648ff989095ee29e1ca8031b05b27f2d15 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0b94a7648ff989095ee29e1ca8031b05b27f2d15 Author: Kevin Bowling (Sat 22 Aug 2026 02:24:28 BST) Committer: Kevin Bowling (Sat 5 Sep 2026 01:29:29 BST) e1000: Limit the TSO sentinel to lem(4) controllers The TSO workaround splits the final DMA segment to create a four byte sentinel descriptor. Intel documents the premature descriptor writeback erratum and this workaround in the 82540EP and 82545GM specification updates (erratum 3) and the 82546GB specification update (erratum 1). Limit the workaround and its preceding TSO state to the legacy PCI and PCI-X controllers so PCIe controllers retain their natural descriptor layout using one fewer descriptor per TSO packet, no split of the final segment, and one less four byte DMA. Sponsored by: BBOX.io (cherry picked from commit 2a7af8ebcf90af83f01f9523b25bfc6e58c7b809) M sys/dev/e1000/em_txrx.c _____________________________________________________________________________________________________________ Commit: 6878cf03baab0a647bf68186333c7a6037026e30 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6878cf03baab0a647bf68186333c7a6037026e30 Author: Kevin Bowling (Fri 21 Aug 2026 04:08:13 BST) Committer: Kevin Bowling (Sat 5 Sep 2026 01:29:17 BST) ofw_pcibus: Honor device proximity for DMA tags BUS_GET_DOMAIN can report a PCI function's firmware locality, including an SR-IOV VF's inherited PF locality, but ordinary OFW PCI functions still use the shared bus DMA tag. Consequently, busdma metadata and coherent memory can be allocated from the bus's domain instead of the function's domain. Create and cache a child tag for each function that requests a DMA tag and apply its reported domain without modifying the shared parent tag. Apply the same domain to the private IOMMU tag already created by the pSeries PCI bus. Destroy cached tags when PCI children are removed so VF create and destroy cycles do not leak them. Reviewed by: PowerPC (jhibbits) Sponsored by: BBOX.io Differential Revision: https://reviews.freebsd.org/D59065 (cherry picked from commit df6bbc9b17dcb75e220b9ab44f5a6483b47c562e) M sys/powerpc/ofw/ofw_pcibus.c M sys/powerpc/pseries/plpar_pcibus.c _____________________________________________________________________________________________________________ Commit: 985a4791a80c433ebd211e5e0aadbf109df11e1f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=985a4791a80c433ebd211e5e0aadbf109df11e1f Author: Kevin Bowling (Fri 21 Aug 2026 03:45:33 BST) Committer: Kevin Bowling (Sat 5 Sep 2026 01:29:04 BST) ofw_pcibus: Inherit PF locality for SR-IOV VFs PCI VFs are allocated dynamically and have no corresponding OFW node. The zero-filled OFW PCI devinfo currently leaves obd_node as 0, which is not the invalid-node sentinel and can send NUMA lookup through an unrelated firmware node. Initialize dynamically allocated devinfo with an invalid OFW node. For VF locality queries, use the owning PF's node when it exists. Fall back to the PCI bus when neither the VF nor PF has a firmware node. This preserves existing CPU-locality behavior for ordinary PCI devices while making VF domain and interrupt placement follow their PF. Reviewed by: PowerPC (jhibbits) Sponsored by: BBOX.io Differential Revision: https://reviews.freebsd.org/D59064 (cherry picked from commit f003e86335c9c16c6769ef8f0c091d425dba7ef9) M sys/powerpc/ofw/ofw_pcibus.c _____________________________________________________________________________________________________________ Commit: 6f16db3a09536c3bd18ca4c967bd8f048920f001 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6f16db3a09536c3bd18ca4c967bd8f048920f001 Author: Abdelkader Boudih (Mon 17 Aug 2026 04:12:00 BST) Committer: Enji Cooper (Sat 5 Sep 2026 00:07:01 BST) asmc: prefer MMIO backend over PIO when both are present T2, T1, and some pre-T1 Macs advertise a legacy PIO range in the SMC ACPI _CRS alongside a live MMIO window, but the silicon behind the PIO range is bogus. Try MMIO first, validate via LDKN >= 2, fall back to PIO if that fails or no MMIO resource is present. Drop "(T2)" from the backend message since MMIO isn't T2-exclusive. MFC: 1 week Reviewed by: ngie Differential Revision: https://reviews.freebsd.org/D58839 (cherry picked from commit 37826269b41b46c72264191d35b09baf24e055b9) M sys/dev/asmc/asmc.c M sys/dev/asmc/asmcmmio.c _____________________________________________________________________________________________________________ Commit: 9c9a06e0c0953caa58da9486298bd6aaa99b405e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9c9a06e0c0953caa58da9486298bd6aaa99b405e Author: Abdelkader Boudih (Wed 1 Jul 2026 01:15:51 BST) Committer: Enji Cooper (Sat 5 Sep 2026 00:07:01 BST) asmc: deduplicate sensor converters and cause sysctls Replace per-type spXX_to_milli() functions with a table-driven asmc_sensor_convert() that looks up the divisor by SMC type string. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D57854 (cherry picked from commit 126f82a3eb613976f477aa8326a208459f60465d) M sys/dev/asmc/asmc.c _____________________________________________________________________________________________________________ Commit: 4fb3fae62393f02b21e499b2c0cbb28b5a7089ac URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4fb3fae62393f02b21e499b2c0cbb28b5a7089ac Author: Abdelkader Boudih (Wed 1 Jul 2026 01:15:24 BST) Committer: Enji Cooper (Sat 5 Sep 2026 00:07:01 BST) asmc: add system state and board identity sysctls Add dev.asmc.0.system subtree with read-only sysctls for SMC diagnostic and identity keys: shutdown_cause (MSSD), sleep_cause (MSSP), thermal_status (MSAL), time_of_day (CLKT), power_state (MSPS), board_id (RPlt), and chip_gen (RGEN). Each sysctl is registered only if the key exists on the hardware. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D57853 (cherry picked from commit 6a1bd5212f290933d1429a6d4787394ee53e3181) M sys/dev/asmc/asmc.c M sys/dev/asmc/asmcvar.h _____________________________________________________________________________________________________________ Commit: b6fb80014c4660d51712bcc375d0154bf76912f7 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b6fb80014c4660d51712bcc375d0154bf76912f7 Author: Abdelkader Boudih (Wed 1 Jul 2026 01:13:42 BST) Committer: Enji Cooper (Sat 5 Sep 2026 00:07:01 BST) asmc: try PIO before MMIO to avoid false T2 detection Add hw.asmc.system-state and hw.asmc.board-id read-only sysctls to expose the T2 system state register and Mac board identifier via SMC. Try PIO access before MMIO during probe to prevent false T2 detection on Macs that happen to have something mapped at the T2 BAR address. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D57844 (cherry picked from commit bb1e071be47fa03accadace587784c85654de91e) M sys/dev/asmc/asmc.c M sys/dev/asmc/asmcmmio.c M sys/dev/asmc/asmcvar.h _____________________________________________________________________________________________________________ Commit: c4595b2f9590f082310ab8c9b03b641bd56bf44b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c4595b2f9590f082310ab8c9b03b641bd56bf44b Author: Abdelkader Boudih (Thu 25 Jun 2026 03:06:34 BST) Committer: Enji Cooper (Sat 5 Sep 2026 00:07:01 BST) asmc: Refactor sensor detection and sysctl registration Replace repeated per-sensor-type blocks for voltage, current, power, and ambient light sensors with table-driven loops. Reviewed by: ngie, adrian Differential Revision: https://reviews.freebsd.org/D57595 (cherry picked from commit 104b311a03e45ebb8fd7a93e4ac26644bbae9bae) M sys/dev/asmc/asmc.c _____________________________________________________________________________________________________________ Commit: f79bf36c37d5ab29a1feafcddb9e8277f45fe4e4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f79bf36c37d5ab29a1feafcddb9e8277f45fe4e4 Author: Abdelkader Boudih (Sun 14 Jun 2026 21:55:12 BST) Committer: Enji Cooper (Sat 5 Sep 2026 00:07:01 BST) asmc: fix asmc_key_dump() page fault on T2 MMIO backend asmc_key_dump() used I/O port macros (ASMC_DATAPORT_WRITE/READ, asmc_command()) unconditionally. On T2 Macs, sc_ioport is NULL (MMIO backend is used instead), causing a page fault when ASMC_DEBUG triggers asmc_dumpall() during attach. Add an MMIO guard at the top of asmc_key_dump(): delegate to asmc_key_dump_by_index() + asmc_key_read() for MMIO devices, consistent with the rest of the T2 code paths. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D56748 (cherry picked from commit e37e49bfaa2763f0ce522a3e54de9b494e346465) M sys/dev/asmc/asmc.c _____________________________________________________________________________________________________________ Commit: da7f30bc7487a13945779cb691b4653e8cde8a9c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=da7f30bc7487a13945779cb691b4653e8cde8a9c Author: Abdelkader Boudih (Wed 3 Jun 2026 06:57:49 BST) Committer: Enji Cooper (Sat 5 Sep 2026 00:07:00 BST) asmc: add MMIO backend for T2 Macs T2 Macs (2018+) expose the SMC via memory-mapped registers instead of I/O ports. Add asmcmmio.c/asmcmmio.h implementing the MMIO transport: key read/write, getinfo, getbyindex, and a poll-based wait with exponential backoff. The driver probes for MMIO at attach time by checking the LDKN firmware version key; if MMIO is available it is used, otherwise the standard I/O port backend is used. T2 fan speeds use IEEE 754 floats instead of fpe2 fixed-point. Per-fan manual mode uses F%dMd keys instead of the FS! bitmask. Battery charge limit is exposed via dev.asmc.N.battery_charge_limit. Tested on: MacBookPro16,2 (A2251, iBridge2,10) MacBookPro15,4 (A2159, iBridge2,8) MacBookAir8,2 (A1932, iBridge2,5) Mac mini 8,1 (A1993, iBridge2,7) iMac20,2 (A2115, iBridge2,16) iMacPro1,1 (A1862, iBridge1,1) MFC after: 2 weeks Reviewed by: ngie, adrian Differential Revision: https://reviews.freebsd.org/D57086 (cherry picked from commit a48b900300ebdbd5c47e664b4cc06e705da91bd8) M sys/conf/files.amd64 M sys/dev/asmc/asmc.c A sys/dev/asmc/asmcmmio.c A sys/dev/asmc/asmcmmio.h M sys/dev/asmc/asmcvar.h M sys/modules/asmc/Makefile _____________________________________________________________________________________________________________ Commit: 0fb34d22351e2816082047bf0b586af50db3caba URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0fb34d22351e2816082047bf0b586af50db3caba Author: Abdelkader Boudih (Mon 4 May 2026 15:26:44 BST) Committer: Enji Cooper (Sat 5 Sep 2026 00:07:00 BST) asmc: rename wol sysctl to auto_poweron Older SMC firmware exposed AUPO as a Wake-on-LAN control. On updated firmware, the key controls automatic power-on when AC power is restored after a power loss; WoL is handled by the GBE controller instead. Rename the sysctl to reflect the current semantics. No compatibility alias is provided as the sysctl has not appeared in any release. Reviewed by: ziaee, adrian Differential Revision: https://reviews.freebsd.org/D56747 (cherry picked from commit 36b399f55e3fa16063188b6f8ad8eaaf8c2215ab) M share/man/man4/asmc.4 M sys/dev/asmc/asmc.c M sys/dev/asmc/asmcvar.h _____________________________________________________________________________________________________________ Commit: 0e7752e16c313b70e747f31fa64376311a2bb1d7 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0e7752e16c313b70e747f31fa64376311a2bb1d7 Author: Abdelkader Boudih (Thu 30 Apr 2026 01:38:38 BST) Committer: Enji Cooper (Sat 5 Sep 2026 00:07:00 BST) asmc: replace hardcoded model table with universal probing Probe SMC keys at attach time to detect hardware capabilities, supporting all Intel Apple machines without per-model entries. Sensors are discovered by scanning sorted SMC key ranges for known prefixes and types. Capabilities such as SMS, fan safe speed, and ambient light are detected by key presence. A global key description table provides human-readable names for well-known temperature sensors. Tested on: - MacBook Pro (Early 2007, Mid 2014, Mid 2015) - MacBook Air (Early 2015, Mid 2017) - iMac (Mid 2011, Late 2013) - Mac mini (Mid 2011) Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D56405 (cherry picked from commit e7f4269dbfad02119934c35d523cb33ff8c93493) M sys/dev/asmc/asmc.c M sys/dev/asmc/asmcvar.h _____________________________________________________________________________________________________________ Commit: 7d2303e4b8275725b12f9816d6a7d81608e6c5b1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7d2303e4b8275725b12f9816d6a7d81608e6c5b1 Author: Abdelkader Boudih (Fri 17 Apr 2026 03:31:21 BST) Committer: Enji Cooper (Sat 5 Sep 2026 00:07:00 BST) asmc: add automatic voltage/current/power/ambient sensor detection Apple SMCs contain numerous undocumented voltage, current, power, and ambient light sensors. This change adds automatic detection and registration of these sensors as sysctls. New sysctl trees: dev.asmc.0.voltage.* - Voltage sensors (millivolts) dev.asmc.0.current.* - Current sensors (milliamps) dev.asmc.0.power.* - Power sensors (milliwatts) dev.asmc.0.ambient.* - Ambient light sensors Implementation: - Scans all SMC keys at attach time via asmc_key_dump_by_index() - Identifies sensors by key prefix patterns: - Voltage: VC*, VD*, VG*, VP*, VI* - Current: I{C,D,G,M,N,O,H,P,B,A,L}* - Power: P{C,D,N,S,T,H,F,Z,z}* - Light: ALV*, ALS* - Dynamically creates sysctls for detected sensors - Supports 8 fixed-point SMC data types: - sp78, sp87, sp4b, sp5a, sp69, sp96, sp2d, ui16 - Auto-converts all values to milli-units (mV, mA, mW) On Mac Mini 5,1, detects: - 7 voltage sensors - 18 current sensors - 27 power sensors - 2 ambient light sensors Enables power consumption monitoring, voltage rail debugging, and ambient light detection without hardcoding model-specific sensor lists. Tested on: - Mac Mini 5,1 (2011) running FreeBSD 15.0-RELEASE - 54 sensors auto-detected and exposed via sysctl - All sensor types verified with multimeter readings - Fixed-point conversions validated against known values - Memory management tested (malloc/free on detach) Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D55807 (cherry picked from commit aae9068404947dd9ffd8522359d0f9dffaa70414) M sys/dev/asmc/asmc.c M sys/dev/asmc/asmcvar.h _____________________________________________________________________________________________________________ Commit: 8424a1497459318eae816266499f8dab5688bc6c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8424a1497459318eae816266499f8dab5688bc6c Author: Marcus Gartner (Sat 11 Apr 2026 03:03:18 BST) Committer: Enji Cooper (Sat 5 Sep 2026 00:07:00 BST) asmc: add support for MacBookPro13,1 This commit adds support for the MacBookPro13,1 (late 2016, 13-inch). The SMC keys were collected from https://logi.wiki/index.php/SMC_Sensor_Codes. Two temperature keys are omitted because they fail to be read: TI0P (IO Proximity) and Ta0P (Ambient Air). Note that the with this model the `dev.asmc.0.fan.0.minspeed` setting only applies when the fans have been activated by the system. In my testing, the fans did not spin up until CPU temperatures hit about 80C. At lower temperatures, the fans will happily ignore the minimum speed and remain at 0 rpm. Reviewed by: imp Pull Request: https://github.com/freebsd/freebsd-src/pull/2137 (cherry picked from commit b5b9c65a689457e608cc31831ed690d303d63ffa) M sys/dev/asmc/asmc.c M sys/dev/asmc/asmcvar.h _____________________________________________________________________________________________________________ Commit: f497d93a32d84db8dfa4aa979a80621df428ae87 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f497d93a32d84db8dfa4aa979a80621df428ae87 Author: Abdelkader Boudih (Wed 15 Apr 2026 05:20:52 BST) Committer: Enji Cooper (Sat 5 Sep 2026 00:07:00 BST) asmc: add raw SMC key read/write interface This patch adds a debugging interface to read and write arbitrary Apple SMC keys by name through sysctl, enabling hardware exploration and control of undocumented features. The interface provides four sysctls under dev.asmc.0.raw.*: - key - Set the 4-character SMC key name (e.g., "AUPO") - value - Read/write key value as a hex string - len - Auto-detected key value length (can be overridden) - type - Read-only 4-character type string (e.g., "ui8", "flt") Implementation includes a new asmc_key_getinfo() function using SMC command 0x13 to query key metadata. The interface automatically detects key lengths and types, uses hex string encoding for arbitrary binary values, and is safe for concurrent access via CTLFLAG_NEEDGIANT. This interface was essential for discovering that the AUPO key enables Wake-on-LAN from S5 state, and for mapping all 297 SMC keys on Mac Mini 5,1. Reviewed by: ngie, adrian, markj Differential Revision: https://reviews.freebsd.org/D54441 (cherry picked from commit 3e27114a7f961aac49d75a663a55332375d0bef3) M share/man/man4/asmc.4 M sys/dev/asmc/asmc.c M sys/dev/asmc/asmcvar.h _____________________________________________________________________________________________________________ Commit: 7b3d39ef34c24a25b782a6898ca4501f78de9134 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7b3d39ef34c24a25b782a6898ca4501f78de9134 Author: Vladimir Kondratyev (Sun 29 Mar 2026 20:00:59 BST) Committer: Enji Cooper (Sat 5 Sep 2026 00:06:45 BST) asmc(4): Add support for backlight(9) interface MFC after: 1 month (cherry picked from commit 5d7862fb998f48ba71dac7e34106aaad350db348) M share/man/man4/asmc.4 M sys/dev/asmc/asmc.c M sys/dev/asmc/asmcvar.h M sys/modules/asmc/Makefile _____________________________________________________________________________________________________________ Commit: 96dfa566fc168fa386710451e5d1f036ac387cf6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=96dfa566fc168fa386710451e5d1f036ac387cf6 Author: ShengYi Hung (Mon 24 Aug 2026 18:51:41 BST) Committer: Kyle Evans (Fri 4 Sep 2026 18:56:15 BST) xhci: Only reset the data toggle value when the USB stack asks for it The previous patch assumes that we don't want to reset toggle bit in STOPPED_STEP. However, a device can explicitly call usbd_clear_data_toggle if necessary. As a result, instead of not dropping the bit unconditionally, we added a field in xhci to specify that we want to drop it, so that usbd_clear_data_toggle can handle it correctly. Reported by: oh Reviewed by: kevans Tested by: oh Fixes: 28d85db46b48 ("xhci: Do not drop and add bits in xhci") (cherry picked from commit 0f59df83869d3734a33d96b01381823e6a3ef3ff) M sys/dev/usb/controller/xhci.c M sys/dev/usb/controller/xhci.h _____________________________________________________________________________________________________________ Commit: 6b1371fca772dd4583e2ba257b3237bad8c57cab URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6b1371fca772dd4583e2ba257b3237bad8c57cab Author: Etienne Bonnand (Thu 18 Jun 2026 17:37:31 BST) Committer: Kyle Evans (Fri 4 Sep 2026 16:33:04 BST) stand: set st_dev/st_ino in the loader's ZFS stat for veriexec The loader's ZFS implementation never set st_dev or st_ino in zfs_dnode_stat(). With an uninitialized struct stat, veriexec's device comparison in lib/libsecureboot/veopen.c read stack garbage and skipped the matching manifest entry, failing with a spurious "no entry" on ZFS root under UEFI Secure Boot. Rather than zeroing the device (which would break veriexec's ability to tell apart the same path on different datasets), populate st_dev and st_ino with the same intrinsic identifiers the kernel uses: - st_dev = the dataset's ds_fsid_guid (as the kernel does via dmu_objset_fsid_guid()/dsl_dataset_fsid_guid()), already read in zfs_mount_dataset() and now propagated through struct zfsmount. - st_ino = the object number resolved in zfs_lookup(), propagated through struct file (the loader's equivalent of the kernel's z_id). dev_t and ino_t are 64-bit on FreeBSD, so both are assigned directly with no hashing. A memset() at the top of zfs_dnode_stat() zeroes the remaining fields so they no longer hold stack garbage. Tested on 16.0-CURRENT (amd64), ZFS-on-GELI root: rebuilt and re-signed the EFI loader; the system boots under UEFI Secure Boot with mac_veriexec active. (boot1 segment was modified by kevans) PR: 295935 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=295935 ) Sponsored by: Defenso Reviewed-by: kevans Pull-Request: https://github.com/freebsd/freebsd-src/pull/2271 (cherry picked from commit b567434a592e1a35b20c5a39c4ccc2ea9e00601d) M stand/efi/boot1/zfs_module.c M stand/libsa/zfs/zfs.c M stand/libsa/zfs/zfsimpl.c _____________________________________________________________________________________________________________ Commit: 8db4de3a74fd4fee04c6c1c317d5281e1f2b0774 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8db4de3a74fd4fee04c6c1c317d5281e1f2b0774 Author: Kyle Evans (Tue 11 Aug 2026 02:26:47 BST) Committer: Kyle Evans (Fri 4 Sep 2026 16:33:00 BST) usb: xhci: allow up to 1s for SET_ADDRESS Some devices take a little longer, and the spec doesn't really seem to mandate a maximum. The common path in usbd_req_set_address() has already been bumped to 1s and I have a headset (Logitech H390) that does need a little bit longer, so let's match it in xhci. Reviewed by: aokblast (cherry picked from commit 135df778543123a7dea08553c78da1b51a6b3098) M sys/dev/usb/controller/xhci.c _____________________________________________________________________________________________________________ Commit: 48c56b559248295da78ce2a8ec5549afd8cd4d20 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=48c56b559248295da78ce2a8ec5549afd8cd4d20 Author: Kyle Evans (Sat 8 Aug 2026 05:06:33 BST) Committer: Kyle Evans (Fri 4 Sep 2026 16:32:45 BST) kern: fix oversight in security.bsd.unprivileged_kenv_read It was intended that one could close the hole back in loader, but the sysctl was actually not marked TUNABLE. The hardening menu option thus did nothing, because we wouldn't read the value from kenv. Reported by: markj Fixes: 6e81fbf5833d ("bsdinstall: add a hardening knob [...]") Fixes: 4fd518fcb2bb ("kern: add a security knob to disable [...]") (cherry picked from commit 8befc9e8b194d874d00239568584552279bebddd) M sys/kern/kern_environment.c _____________________________________________________________________________________________________________ Commit: 8d227fc5ddf95a6f7f270779ae45f5943db6ad56 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8d227fc5ddf95a6f7f270779ae45f5943db6ad56 Author: Kyle Evans (Fri 7 Aug 2026 02:54:04 BST) Committer: Kyle Evans (Fri 4 Sep 2026 16:32:39 BST) prometheus_sysctl_exporter: don't abort on bad labels We can probaby consider these kernel bugs, in which case asserting is not the most helpful thing we can do. Let's emit the necessary details to stderr and exit non-zero to aid debugging these without completely blocking the ability to export all of the well-formed metrics. Reviewed by: rew (cherry picked from commit 4f42ec2f38ee4a4eba8f3298e7968f0523f87aa0) M usr.sbin/prometheus_sysctl_exporter/prometheus_sysctl_exporter.8 M usr.sbin/prometheus_sysctl_exporter/prometheus_sysctl_exporter.c _____________________________________________________________________________________________________________ Commit: 240bea933ddd3ad296695fc520405bcc4d92be75 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=240bea933ddd3ad296695fc520405bcc4d92be75 Author: Kyle Evans (Fri 7 Aug 2026 00:41:43 BST) Committer: Kyle Evans (Fri 4 Sep 2026 16:32:21 BST) bsdinstall: add a hardening knob for unprivileged kenv access It makes sense. Reviewed by: zleei (cherry picked from commit 6e81fbf5833d43529fd8a253b592af9666b04e8e) M usr.sbin/bsdinstall/scripts/hardening _____________________________________________________________________________________________________________ Commit: 7d87c1ba6c4ad73d02ffbfe7dd67c1bcf7c392f1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7d87c1ba6c4ad73d02ffbfe7dd67c1bcf7c392f1 Author: Enji Cooper (Thu 16 Jul 2026 22:48:37 BST) Committer: Enji Cooper (Fri 4 Sep 2026 07:01:27 BST) libproc: link against libctf if MK_CTF != no instead of MK_CDDL != no Logic prior to this change would incorrectly try linking when MK_CDDL != no, instead of MK_CTF != no, which could result in the library and the tests being broken if/when MK_CTF == no and MK_CDDL != no (an uncommon, but possible combination with today's build knobs). This change updates the conditional to correctly track the value of MK_CTF, which in turn is properly toggled to no if/when MK_CDDL == no as it's a dependent build knob. This [niche] build bug has been present in FreeBSD since 2014. MFC after: 1 week (cherry picked from commit f2e6a8b9e50c7552037cb635f17b955ead84a813) M lib/libproc/Makefile M share/mk/src.libnames.mk _____________________________________________________________________________________________________________ Commit: 46c155b1a3108f9f6afbfc053c072b190088497a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=46c155b1a3108f9f6afbfc053c072b190088497a Author: Enji Cooper (Thu 16 Jul 2026 17:24:54 BST) Committer: Enji Cooper (Fri 4 Sep 2026 06:58:27 BST) rc.d/dumpon: minor hardening/tightening up - Scope local variables properly to each function. - Quote variables that should be treated as single words. - Replace `${cmd}; if [ $? -eq 0 ]` with `if ${cmd}` for simplicity. MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D57899 (cherry picked from commit fc186c24b1e72fa3eba91c166f7a554a5cea5828) M libexec/rc/rc.d/dumpon _____________________________________________________________________________________________________________ Commit: 49a0bf45cb1b3ceb1170ebccb935e37faba257c0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=49a0bf45cb1b3ceb1170ebccb935e37faba257c0 Author: Enji Cooper (Tue 21 Jul 2026 17:08:44 BST) Committer: Enji Cooper (Fri 4 Sep 2026 06:56:19 BST) linux_firmware: reformat error print-out This makes it easier to grep for the error message to better understand the call stack when loading firmware modules fails. Fix a cosmetic-only style(9) bug while here in the same function related to another logging message. MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D58380 (cherry picked from commit a594783bac906ecc4f6528d7d576215f85a21bda) M sys/compat/linuxkpi/common/src/linux_firmware.c _____________________________________________________________________________________________________________ Commit: 8c0ae18f7e0e6fd888077e6b6c7e52ef4a87a33e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8c0ae18f7e0e6fd888077e6b6c7e52ef4a87a33e Author: Enji Cooper (Sat 25 Jul 2026 17:51:53 BST) Committer: Enji Cooper (Fri 4 Sep 2026 06:55:57 BST) [test] libatexit: leverage __{BEGIN,END}_DECLS This change converts the longhand form of `extern "C" {` and its corresponding `}` into `__BEGIN_DECLS` and `__END_DECLS`, respectively. The new form is much easier to grep for and is a best practice to use in the FreeBSD tree. This is meant to be a non-functional change. MFC after: 1 week (cherry picked from commit bc81728c00b200297ac556974b5373c804077a17) M lib/libc/tests/stdlib/libatexit/libatexit.cc _____________________________________________________________________________________________________________ Commit: 59ee4abcdbba8ae333211baf964c46f1a62c51f6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=59ee4abcdbba8ae333211baf964c46f1a62c51f6 Author: Enji Cooper (Sun 9 Aug 2026 06:31:20 BST) Committer: Enji Cooper (Fri 4 Sep 2026 06:54:14 BST) cpuset(9): correct markup - Remove `\(em` from .Nm section as it's not valid mandoc markup. - Remove the section from the .Nm directive (it's handled under the .Dt directive). MFC after: 1 week Reported by: make manlint (cherry picked from commit 5007a5d682d3737fe9b49c4cd69e04d025d209ec) M share/man/man9/cpuset.9 _____________________________________________________________________________________________________________ Commit: afdf887bbf170278d2696e6f3f24e0501596509b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=afdf887bbf170278d2696e6f3f24e0501596509b Author: Enji Cooper (Sun 9 Aug 2026 06:28:35 BST) Committer: Enji Cooper (Fri 4 Sep 2026 06:53:22 BST) DB_COMMAND(9): correct mdoc markup for .Nm entries Add missing commas after .Nm entries. MFC after: 1 week Reported by: make manlint (cherry picked from commit b96a063f61001e60ac282eb3500e703c7c3faf9c) M share/man/man9/DB_COMMAND.9 _____________________________________________________________________________________________________________ Commit: a151a01fdece08445486d9cb277eb3ba6dd2db37 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a151a01fdece08445486d9cb277eb3ba6dd2db37 Author: Enji Cooper (Wed 19 Aug 2026 08:57:27 BST) Committer: Enji Cooper (Fri 4 Sep 2026 06:49:00 BST) contrib/netbsd-tests: lib/libc/c063: sync with NetBSD This change syncs the lib/libc/c063 NetBSD tests with FreeBSD. This does two things: - Addresses bogus tautologically true assertions flagged by clang and gcc with ATF 0.22+ [1]. - Brings in some new test coverage. Obtained from: NetBSD (date tag: `20260818UTC`) MFC after: 2 weeks 1. https://github.com/freebsd/atf/pull/72 (cherry picked from commit 8109a5c0fba0d015354a69b40e6682d5e8c0f638) M contrib/netbsd-tests/lib/libc/c063/t_faccessat.c M contrib/netbsd-tests/lib/libc/c063/t_fchmodat.c M contrib/netbsd-tests/lib/libc/c063/t_mkfifoat.c M contrib/netbsd-tests/lib/libc/c063/t_utimensat.c _____________________________________________________________________________________________________________ Commit: 0d7fc3ad6fa662e81b2b0e86affa97df2c0f5bfc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0d7fc3ad6fa662e81b2b0e86affa97df2c0f5bfc Author: Enji Cooper (Sun 9 Aug 2026 06:04:15 BST) Committer: Enji Cooper (Fri 4 Sep 2026 06:47:34 BST) alq(9): add missing .Nm entry for ALQ(9) MFC after: 1 week Reported by: make manlint (cherry picked from commit 4fa245edc7ad426ebde7a316191b579e62fe795f) M share/man/man9/alq.9 _____________________________________________________________________________________________________________ Commit: 2ed7da9400376427d27129ea5083c0e295f39aa8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2ed7da9400376427d27129ea5083c0e295f39aa8 Author: Enji Cooper (Mon 10 Aug 2026 00:20:46 BST) Committer: Enji Cooper (Fri 4 Sep 2026 06:45:03 BST) acl(9): fix typo (ACL_ACL -> ACL) MFC after: 1 week (cherry picked from commit 9fd963b0a149357b6fbc16ef0b999e6b487e513a) M share/man/man9/acl.9 _____________________________________________________________________________________________________________ Commit: 20b68f03d8f133b2c150520bd16aa462dc4f0223 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=20b68f03d8f133b2c150520bd16aa462dc4f0223 Author: Enji Cooper (Sun 9 Aug 2026 06:02:13 BST) Committer: Enji Cooper (Fri 4 Sep 2026 06:44:34 BST) atomic(9): add missing .Nm entries MFC after: 1 week Reported by: make manlint (cherry picked from commit 8eced03c369a6f8aad0013604f790bafd4526848) M share/man/man9/atomic.9 _____________________________________________________________________________________________________________ Commit: e5a9ad7cbf24230bbde0882f3ed618719e2fc106 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e5a9ad7cbf24230bbde0882f3ed618719e2fc106 Author: Pouria Mousavizadeh Tehrani (Sat 22 Aug 2026 21:37:58 BST) Committer: Pouria Mousavizadeh Tehrani (Fri 4 Sep 2026 00:00:54 BST) route/fib_algo: Free leaked radix_masks in radix_lockless radix_lockless algorithm creates its own radix tree and allocates its own radix_masks by directly calling rnh_addaddr(). However, during destruction, it only frees the radix_tree without freeing its allocated radix_masks. Fix the leak by calling rn_delete() during radix_destroy(). PR: 297339 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297339 ) Reviewed by: melifaro MFC after: 2 weeks Differential Revision: https://reviews.freebsd.org/D59112 (cherry picked from commit 790817f5a7a640c9ceb5c2ad99135f1a69aeb77d) M sys/netinet/in_fib_algo.c M sys/netinet6/in6_fib_algo.c _____________________________________________________________________________________________________________ Commit: 10ebbeb4d78cebdf6398e224a94edf8373de5c88 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=10ebbeb4d78cebdf6398e224a94edf8373de5c88 Author: Mitchell Horne (Mon 13 Jul 2026 20:49:32 BST) Committer: Mitchell Horne (Thu 3 Sep 2026 17:32:44 BST) subr_physmem_test: add tests for two edge-cases Help validate my assertion that "physmem will never report empty ranges". Part of this is covered by the existing tests, which check the merging of adjacent/overlapping regions. The other part is to ensure that addition of zero-sized ranges is ignored. The physmem implementation also includes logic to ignore the first physical page of memory (physical addresses 0 to PAGE_SIZE-1). Add a second test case for this. Reviewed by: markj MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D45914 (cherry picked from commit 1b5ec2e466ee100161017ae2618f91829310f1d6) M tests/sys/kern/subr_physmem_test.c _____________________________________________________________________________________________________________ Commit: 261d589694875521d241b73d23c376e786d735e3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=261d589694875521d241b73d23c376e786d735e3 Author: Mitchell Horne (Mon 13 Jul 2026 20:15:49 BST) Committer: Mitchell Horne (Thu 3 Sep 2026 17:32:36 BST) g_eli: disambiguate CPU-bound worker creation This makes an effort to clarify and correct the intent of the code, which is to either: 1. Create one software crypto worker thread for each CPU, to be pinned later 2. Create the number of threads requested by the kern.geom.eli.threads tunable This is as described in geli(8). If a CPU were somehow* absent, it should be skipped, but not in the second case when creating a set number of threads. To achieve this cleanly and correctly: - split worker creation logic into a helper function - keep the loops separate - debug message for absent CPUs is dropped - add a short explanatory comment - style, rename local var to 'nthreads' *Practically, it is impossible today to get a bootable system with a sparsely populated CPU map. Thus these concerns are hypothetical and this change should have no functional effect. Finally, while here, guard the sc->sc_workers list insertion with the appropriate mutex. The code is safe from races today, but this gives a better guarantee. Reviewed by: kib MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58214 (cherry picked from commit 185039d27252ae4ce7d6e3d68ba74907091cd565) M sys/geom/eli/g_eli.c _____________________________________________________________________________________________________________ Commit: 64dd924bf7712eb72d32ca75dc409ef6e0eb3fdd URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=64dd924bf7712eb72d32ca75dc409ef6e0eb3fdd Author: Mitchell Horne (Mon 13 Jul 2026 20:15:38 BST) Committer: Mitchell Horne (Thu 3 Sep 2026 17:32:36 BST) sched/lapic: remove sched_do_timer_accounting() The check is always true, especially after the removal of hlt_cpus_mask from sched_4bsd. Reviewed by: olce, kib MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58159 (cherry picked from commit 01f165c68103df22cebe26d410c1d4a0e5fae377) M sys/kern/sched_4bsd.c M sys/kern/sched_shim.c M sys/kern/sched_ule.c M sys/sys/sched.h M sys/x86/x86/local_apic.c _____________________________________________________________________________________________________________ Commit: ce2e423045c228d75aa4ff2f26215e63d5371316 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ce2e423045c228d75aa4ff2f26215e63d5371316 Author: Mitchell Horne (Mon 13 Jul 2026 20:15:19 BST) Committer: Mitchell Horne (Thu 3 Sep 2026 17:32:36 BST) smp: remove unused hlt_cpus_mask It is a relic, apparently once populated by a machdep.hlt_cpus sysctl. The sysctl was removed, and ULE has never honored this mask. It is now safe to remove. Remove the mask, and its few remaining references in: sched_4bsd(4), hwpmc(4), and hwt(4). Reviewed by: olce, kib MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58158 (cherry picked from commit df0aca0d73064a1a199dbae3857012951f96cf2d) M sys/dev/hwt/hwt_ioctl.c M sys/dev/hwt/hwt_vm.c M sys/kern/kern_pmc.c M sys/kern/sched_4bsd.c M sys/kern/subr_smp.c M sys/sys/smp.h _____________________________________________________________________________________________________________ Commit: 5ed83588dac8fb30e893f6dcd1a092116bf07366 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5ed83588dac8fb30e893f6dcd1a092116bf07366 Author: Mitchell Horne (Mon 13 Jul 2026 20:15:00 BST) Committer: Mitchell Horne (Thu 3 Sep 2026 17:32:36 BST) g_eli: better handling of absent/disabled CPUs Checking hlt_cpus_mask is a no-op, and the mask will be removed in the next commit. However, we can use the more recent CPU_ABSENT() macro to check the status. Reviewed by: olce MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58157 (cherry picked from commit 63d4f044225d1bb86767759b18c0ae63b25a9c03) M sys/geom/eli/g_eli.c _____________________________________________________________________________________________________________ Commit: 3ef9ef5147d23d6bed18663f1836ad2f768fa1a8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3ef9ef5147d23d6bed18663f1836ad2f768fa1a8 Author: Mitchell Horne (Fri 21 Aug 2026 17:57:12 BST) Committer: Mitchell Horne (Thu 3 Sep 2026 17:29:20 BST) libkern.h: remove HAVE_INLINE_* macros The final consumer of this was OpenZFS, fixed in ffaea0831973 (thanks mav@). That change has been present in all active OpenZFS release branches for at least 6 months. These can finally be retired. Reviewed by: mav MFC after: 3 days Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55201 (cherry picked from commit 76f14217f6051df414e435c3388d3f4bb388cc22) M sys/sys/libkern.h _____________________________________________________________________________________________________________ Commit: 24db9837bee5ba35f7c84edded150d5a5a1bfa73 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=24db9837bee5ba35f7c84edded150d5a5a1bfa73 Author: Mitchell Horne (Sun 10 Aug 2025 18:16:11 BST) Committer: Mitchell Horne (Thu 3 Sep 2026 17:29:13 BST) jh7110_gpio: remove unneeded cleanup Any failure within bus_alloc_resources() will call bus_release_resources(); thus the call is redundant here. MFC after: 3 days Sponsored by: The FreeBSD Foundation (cherry picked from commit 2af2ec524957754ff356daea5fa7ee4990c1c3ea) M sys/riscv/starfive/jh7110_gpio.c _____________________________________________________________________________________________________________ Commit: a722716674ba883bfa4d5eac4b29363706023d33 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a722716674ba883bfa4d5eac4b29363706023d33 Author: Brian Scott (Fri 21 Aug 2026 17:27:00 BST) Committer: Mitchell Horne (Thu 3 Sep 2026 17:29:08 BST) jh7110_gpio: driver enhancements Fix reporting of state and capabilities by the gpioctl command. Support selection of pull-up and pull-down resistors. Support second gpio device (AON - always on power domain) to allow attaching gpioled device to visionfive2 status LED or querying boot selection switches. Reviewed by: mhorne MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D58693 (cherry picked from commit 3d20f8a022435e8ed37e2c0ce8f66d4c1203ec1c) M sys/riscv/starfive/jh7110_gpio.c _____________________________________________________________________________________________________________ Commit: 66fb43c26b3ba9a86335f462ddb6e06b27323823 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=66fb43c26b3ba9a86335f462ddb6e06b27323823 Author: Mitchell Horne (Sun 10 Aug 2025 18:13:23 BST) Committer: Mitchell Horne (Thu 3 Sep 2026 17:29:00 BST) jh7110_gpio: style - Fix whitespace - Replace JH7110_GPIO_READ with RD4 (and WR4) - Trim headers - Explicit conditional checks - Use correct method typedefs MFC after: 3 days Sponsored by: The FreeBSD Foundation (cherry picked from commit 72216145d3e4e2460d48d279a339072e0be2cc74) M sys/riscv/starfive/jh7110_gpio.c _____________________________________________________________________________________________________________ Commit: 55e62f1eadae3206145ec1dae88bf9c00491b404 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=55e62f1eadae3206145ec1dae88bf9c00491b404 Author: Mitchell Horne (Mon 29 Jun 2026 16:24:19 BST) Committer: Mitchell Horne (Thu 3 Sep 2026 17:28:01 BST) release/riscv: tweak GENERICSD partition placement Increase EFI partition size to begin rootfs at 64mb. I believe this was my original intention. I have a microSD card with 8mb block size which emits an advisory in verbose dmesg about the misaligned partition. MFC after: 1 week Sponsored by: The FreeBSD Foundation (cherry picked from commit 49749f21284d817b5431255106c8c2da3afa9965) M release/riscv/GENERICSD.conf _____________________________________________________________________________________________________________ Commit: 4315454760788542e9f5b0f6a255d2a9a62acf9c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4315454760788542e9f5b0f6a255d2a9a62acf9c Author: Mitchell Horne (Thu 5 Feb 2026 18:52:36 GMT) Committer: Mitchell Horne (Thu 3 Sep 2026 17:27:46 BST) cdefs(9): document __nonstring Reviewed by: emaste Discussed with: imp Fixes: 802c6d5d61d1 ("cdefs.h: Introduce __nonstring attribute") MFC after: 3 days Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58804 (cherry picked from commit 2ea905c875b6c89117023e240c3158f2da79bc52) M share/man/man9/cdefs.9 _____________________________________________________________________________________________________________ Commit: 84b241f1cc122a8735abffa74ea5f74b56b61648 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=84b241f1cc122a8735abffa74ea5f74b56b61648 Author: Andre Silva (Tue 11 Aug 2026 17:17:57 BST) Committer: Mitchell Horne (Thu 3 Sep 2026 17:27:28 BST) hwpmc: fix false callchain assertion on the PMC_UR ring pmc_capture_user_callchain() asserts that TDP_CALLCHAIN is set on the current thread, but PMC_UR samples never set that flag -- only PMC_HR and PMC_SR do. That makes the assertion always fail for PMC_UR, panicking INVARIANTS kernels as soon as pmcstat -U is used. Skip the assertion for PMC_UR. No functional change on kernels built without INVARIANTS. Signed-off-by: Andre Silva Reviewed by: mhorne MFC after: 1 week Sponsored by: AMD Differential Revision: https://reviews.freebsd.org/D58572 (cherry picked from commit af3929c5152b47278c0b6ea66efbb782b9637495) M sys/dev/hwpmc/hwpmc_mod.c _____________________________________________________________________________________________________________ Commit: 92cf9e36ecf937618a5b977b53027a4d28efe0f2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=92cf9e36ecf937618a5b977b53027a4d28efe0f2 Author: Andre Silva (Tue 11 Aug 2026 17:16:20 BST) Committer: Mitchell Horne (Thu 3 Sep 2026 17:27:28 BST) hwpmc: fix false runcount assertion in user callchain capture pmc_capture_user_callchain() checks a PMC's runcount before walking the user stack, but reads it without holding the spinlock that protects it. hardclock() can run on the same CPU during the capture and drop the runcount to zero in between, tripping the assertion and panicking INVARIANTS kernels under load. Move the check inside the existing spinlock, right where the code already confirms the sample is still valid. No functional change on kernels built without INVARIANTS. Signed-off-by: Andre Silva Reviewed by: mhorne MFC after: 1 week Sponsored by: AMD Differential Revision: https://reviews.freebsd.org/D58571 (cherry picked from commit 66118c3f1011d7852bce8b659899179a83781897) M sys/dev/hwpmc/hwpmc_mod.c _____________________________________________________________________________________________________________ Commit: 83b88ea4761ec55f924d1c964a56c5a91ca7457f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=83b88ea4761ec55f924d1c964a56c5a91ca7457f Author: Artem Bunichev (Mon 20 Jul 2026 18:29:51 BST) Committer: Mitchell Horne (Thu 3 Sep 2026 17:23:14 BST) vfs_unmountall.9: Fix an outdated .Xr to boot(9) boot.9 was moved to kern_reboot.9, but this reference was not changed appropriately. PR: 286013 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=286013 ) Reviewed by: mhorne, kib, emaste Fixes: 800e74955d4e ("boot(9): update to match reality") MFC after: 3 days Differential Revision: https://reviews.freebsd.org/D58350 (cherry picked from commit 5b7d6a128bef464e7fd331d172e4cf25a5d122c3) M share/man/man9/vfs_unmountall.9 _____________________________________________________________________________________________________________ Commit: 678f107b5c7898570d33d9667217e8901fdc79c6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=678f107b5c7898570d33d9667217e8901fdc79c6 Author: Kristof Provost (Wed 26 Aug 2026 15:52:07 BST) Committer: Kristof Provost (Thu 3 Sep 2026 15:03:04 BST) pfctl: fix printing of wildcard anchors PR: 297839 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297839 ) MFC after: 1 week Obtained from: OpenBSD, henning , 5b6657d4d8 Sponsored by: Rubicon Communications, LLC ("Netgate") (cherry picked from commit 5de5140f06959f2724c626c7fab3e1c9187beefb) M sbin/pfctl/pfctl.c M tests/sys/netpfil/pf/anchor.sh _____________________________________________________________________________________________________________ Commit: 2581bc3af3815e92b0eef44bee224fff92931de8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2581bc3af3815e92b0eef44bee224fff92931de8 Author: Glen Barber (Thu 3 Sep 2026 08:51:28 BST) Committer: Dag-Erling Smørgrav (Thu 3 Sep 2026 12:56:38 BST) hastd: Fix crash on empty message A HAST message can be empty, in which case ebuf_add_tail() does nothing and ebuf_data() returns NULL because the size of the ebuf is zero, but hast_proto_recv_hdr() asserts that the return value is not NULL, resulting in an immediate crash if hastctl or hastd receive an empty message. This is trivially reproducable by running `hastctl status` or `hastctl role init` (as the rc script does prior to stopping hastd). To avoid this, don't try to grow the ebuf or receive additional data if the header size is zero. PR: 298085 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=298085 ) MFC after: 3 days Reviewed by: kevans, gjb Differential Revision: https://reviews.freebsd.org/D59306 (cherry picked from commit 8646d65b45339642d4aab1de35a2bc79fc45f09e) M sbin/hastd/hast_proto.c _____________________________________________________________________________________________________________ Commit: b6eb725e4b100ae3f4d120b5ec1a3ba1dc8bca53 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b6eb725e4b100ae3f4d120b5ec1a3ba1dc8bca53 Author: Dag-Erling Smørgrav (Tue 1 Sep 2026 13:49:24 BST) Committer: Dag-Erling Smørgrav (Thu 3 Sep 2026 12:56:38 BST) various: Fix nlist invocations Fix nlist(3) consumers that either expected our toolchain to prepend an underscore to symbol names or expected nlist(3) to ignore the mismatch, as it did until we overhauled it back in May. While here, also fix cases where the last element in the list had an empty string instead of NULL as sentinel. MFC after: 3 days Fixes: 4617a6cb82a6 ("nlist: Handle multiple symbol tables") Reviewed by: kib, jhb Differential Revision: https://reviews.freebsd.org/D59254 (cherry picked from commit cdfc673811aca2c6690f37bde9ef4896ea2e1d6b) M lib/libkvm/kvm_amd64.c M lib/libkvm/kvm_cptime.c M lib/libkvm/kvm_getloadavg.c M lib/libkvm/kvm_getswapinfo.c M lib/libkvm/kvm_i386.c M lib/libkvm/kvm_pcpu.c M lib/libkvm/kvm_proc.c M lib/libkvm/kvm_vnet.c M lib/libmemstat/memstat_malloc.c M lib/libmemstat/memstat_uma.c M sbin/ddb/ddb_capture.c M usr.bin/ktrdump/ktrdump.c M usr.bin/netstat/Makefile M usr.bin/netstat/nlist_symbols M usr.bin/vmstat/vmstat.c M usr.sbin/iostat/iostat.c M usr.sbin/pstat/pstat.c _____________________________________________________________________________________________________________ Commit: 17fb42865e0e0739f0e77dfa64b38298ae687f1c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=17fb42865e0e0739f0e77dfa64b38298ae687f1c Author: Kevin Bowling (Mon 17 Aug 2026 18:09:23 BST) Committer: Kevin Bowling (Thu 3 Sep 2026 01:53:46 BST) bhyve: Keep passthrough PCI power state virtual The passthrough Command register is emulated, but PMCSR writes were sent directly to the physical function. A guest D3hot-to-D0 transition can perform an internal reset and clear physical Command while its emulated copy remains enabled. Cache the Power Management capability and keep the physical D-state host-owned. Emulate the guest D-state and advertise No_Soft_Reset so the guest is not promised a function reset by a virtual power cycle. Restore the assignment-time virtual state after a managed FLR. Reviewed by: markj Sponsored by: BBOX.io (cherry picked from commit 3b90096cf9bcaec70b717e9ff0a9e23d14b600b6) M usr.sbin/bhyve/pci_passthru.c _____________________________________________________________________________________________________________ Commit: f44cde39f97d0e9e828ed709bd89e6bc6e1ddbb9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f44cde39f97d0e9e828ed709bd89e6bc6e1ddbb9 Author: Kevin Bowling (Sun 16 Aug 2026 00:47:33 BST) Committer: Kevin Bowling (Thu 3 Sep 2026 01:53:24 BST) bhyve: Manage passthrough devices across guest FLR bhyve emulates the guest PCI Command register so BAR sizing does not disable physical decoding. However, PCIe Device Control was passed through. A guest VFIO reset therefore performed a physical FLR, which cleared physical Command, while the guest restored only its emulated copy. The device remained assigned with bus mastering disabled and could not fetch DMA descriptors. Intercept guest FLR writes and issue a PPT-managed reset. Stop all vCPUs, verify ownership, quiesce the function, perform only an FLR, and restore the host-owned PCI configuration, decode, and bus-master state. Keep the IOMMU domain in place. bhyve removes guest BAR mappings before this ioctl; a later guest MEMEN write recreates them. Never escalate a guest FLR to a power reset. Reset the guest-owned Command, MSI, MSI-X, MSI-X table, INTx, and MRRS state. PCIe 6.2 section 6.6.2 explicitly preserves MPS across FLR. Virtualize MPS, MRRS, and Completion Timeout. Keep physical MPS and completion-timeout policy host-owned, and apply physical MRRS with MPS as its floor. Keep Phantom Functions Enable host-owned because it changes requester identities visible to the IOMMU. Serialize guest configuration transactions per function and gate trapped and direct BAR access across the reset. Handle byte, word, dword, and overlapping Device Control accesses. A guest FLR can sleep for at least 100 ms. Reserve the target function while dropping the global PPT lock so a guest cannot delay PPT lifecycle operations for other VMs. Operations on the target wait for its reset while other functions and VMs can proceed. Check pcie_flr_supported() before destructive preparation so PPT applies the generic PCI quirk policy. This includes VFs such as the 82599 which implement FLR without advertising it. Validated with two E610 VFs in a Linux 7.0 guest using VFIO no-IOMMU and DPDK testpmd with two queues per VF. Byte, word, dword, and overlapping FLR writes, 32 alternating resets, DPDK traffic, and ixgbevf reattachment all completed while the sibling VF and host PCIe remained healthy. This fixes Linux VFIO no-IOMMU with DPDK PMDs. Reviewed by: markj Sponsored by: BBOX.io (cherry picked from commit c8343ba84af75c3710a1c587ff9bd2165fcd37a9) M lib/libvmmapi/internal.h M lib/libvmmapi/ppt.c M lib/libvmmapi/vmmapi.h M sys/amd64/include/vmm.h M sys/amd64/include/vmm_dev.h M sys/amd64/vmm/io/ppt.c M sys/amd64/vmm/io/ppt.h M sys/amd64/vmm/vmm.c M sys/amd64/vmm/vmm_dev_machdep.c M usr.sbin/bhyve/pci_emul.c M usr.sbin/bhyve/pci_emul.h M usr.sbin/bhyve/pci_passthru.c _____________________________________________________________________________________________________________ Commit: 61b2ea4b897c03e15511afc277c498dde6874a55 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=61b2ea4b897c03e15511afc277c498dde6874a55 Author: Kevin Bowling (Sun 16 Aug 2026 08:11:57 BST) Committer: Kevin Bowling (Thu 3 Sep 2026 01:53:13 BST) e1000: Report 82571 packet buffer ECC errors The 82571 PBA_ECC register contains a 12-bit count of packet buffer ECC detections. The shared code enables single-bit correction, but neither FreeBSD nor the DPDK base driver consumes the counter. Sample it with the ordinary statistics timer, accumulate the value under dev.em.N.memory_errors.detected_packet_buffer, and clear the hardware counter while preserving correction and reserved register state. Do not enable its shared interrupt: the register does not distinguish corrected from uncorrectable events and does not provide a safe fatal recovery policy. Validated on a dual port 82571EB. Both functions reported zero after a clean boot, and a controlled link down/up cycle left the counter at zero while the management link recovered at 1 Gb/s without issue. Sponsored by: BBOX.io (cherry picked from commit aec0f1b85b54d14819747ed3364f366d21e76d88) M sys/dev/e1000/if_em.c _____________________________________________________________________________________________________________ Commit: abf6f5aaed283a1cc23e5c4f6296c716c6863bce URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=abf6f5aaed283a1cc23e5c4f6296c716c6863bce Author: Mark Johnston (Tue 1 Sep 2026 17:07:09 BST) Committer: Mark Johnston (Wed 2 Sep 2026 18:40:37 BST) devstat: Fix a kernel stack disclosure The 16-byte "device_name" field was not zero-filled, so could contain uninitialized stack data. Zero the whole struct, as that's the prevailing pattern for this kind of conversion code, and it's more robust in the face of future revisions to struct devstat. Reviewed by: olce, kib Reported by: Reo Shiseki Fixes: a11d132f6c62 ("devstat: Provide 32-bit compatibility") MFC after: 3 days Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D59309 (cherry picked from commit 7cb1a76f88158fb690418336b736e66c238cd4f7) M sys/kern/subr_devstat.c _____________________________________________________________________________________________________________ Commit: d489039602a4b1730cfa018c0e982d20e1f496bb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d489039602a4b1730cfa018c0e982d20e1f496bb Author: Mark Johnston (Mon 17 Aug 2026 19:15:17 BST) Committer: Mark Johnston (Wed 2 Sep 2026 18:40:28 BST) malloc: Use ckdint.h helpers instead of WOULD_OVERFLOW This serves to demonstrate some usage of the ckdint.h helpers. The new version also generates better machine code on amd64 and arm64. Reviewed by: kib, emaste MFC after: 2 weeks Sponsored by: The FreeBSD Foundation (cherry picked from commit 2d67765f10e7da43ba2d4a7fc074c15d5354684b) M sys/kern/kern_malloc.c _____________________________________________________________________________________________________________ Commit: bc63853a10ff9a81db695b60ab14b39cf840daf0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bc63853a10ff9a81db695b60ab14b39cf840daf0 Author: Abhijeet Sharma (Wed 19 Aug 2026 13:19:27 BST) Committer: Mark Johnston (Wed 2 Sep 2026 18:40:28 BST) tools/build: stage stdckdint.h's dependencies for non-FreeBSD hosts 37bd69d43c7 gave stdckdint.h two new includes, and . Neither reaches a non-FreeBSD host: _visible.h is staged only under ${.MAKE.OS} == "FreeBSD" and ckdint.h is not staged at all, so the libc bootstrap fails on reallocarray.o when cross-building from macOS. Both headers are self-contained; stage them alongside stdckdint.h. Fixes: 37bd69d43c7 ("sys: Add sys/ckdint.h") Reviewed by: rpaulo, markj Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58943 (cherry picked from commit 805c5004fa86e26486175cd3a0bb253dcb8ec7e0) M tools/build/Makefile _____________________________________________________________________________________________________________ Commit: b955d36a9b36b04b9d434a12aac3dcd31a7574ad URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b955d36a9b36b04b9d434a12aac3dcd31a7574ad Author: Mark Johnston (Mon 17 Aug 2026 18:06:04 BST) Committer: Mark Johnston (Wed 2 Sep 2026 18:40:28 BST) sys: Add sys/ckdint.h We have a C23 stdckdint.h header for userspace, which provides checked addition, subtraction and multiplication. We lack similar helpers in the kernel, where they are regularly needed. Let's just adopt the C23 macros. For bonus points, I added a wrapper to ensure that ignored an return value is raised as an error by the compiler. Reviewed by: kib, emaste MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58773 (cherry picked from commit 37bd69d43c70346b9191f7ce07ee9ed783ce528f) M include/stdckdint.h A sys/sys/ckdint.h _____________________________________________________________________________________________________________ Commit: fcd26df9e24ffc9dfad42105b95026f23ec23e3f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fcd26df9e24ffc9dfad42105b95026f23ec23e3f Author: Mark Johnston (Tue 7 Oct 2025 14:53:54 BST) Committer: Mark Johnston (Wed 2 Sep 2026 18:40:28 BST) tools/build: Bring in stdckdint.h if needed This is needed when bootstrapping libc, reallocarray.c and recallocarray.c include stdckdint.h now. Reviewed by: emaste Fixes: 7233893e9496 ("lib{c,openbsd}: use ckd_mul() for overflow checking in re(c)allocarray") Differential Revision: https://reviews.freebsd.org/D52932 (cherry picked from commit 687cb66411c7bc220ccb90cedc2f7486567d55b6) M tools/build/Makefile _____________________________________________________________________________________________________________ Commit: 6391876d20ba14de3ee0704e6f77d6d14ef8d672 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6391876d20ba14de3ee0704e6f77d6d14ef8d672 Author: Andrew Griffiths (Thu 20 Aug 2026 15:30:03 BST) Committer: Mark Johnston (Wed 2 Sep 2026 18:40:28 BST) rsu: add a runtime TX buffer bound check for a kernel buffer overflow The rsu driver currently relies on a `KASSERT` to prove that the mbuf payload plus TX descriptor fits in the per-transfer USB TX buffer. On production kernels without `INVARIANTS`, an oversized raw 802.11 frame can reach `m_copydata()` and overwrite past that buffer, causing local kernel memory corruption. This suggested patch replaces the assertion-only guard with a runtime size check before the copy. Oversized frames return `EMSGSIZE`, leaving the existing caller cleanup paths responsible for freeing `m0`, `ni`, and the unused transfer buffer. Reachable via root / bpf access Reviewed by: bz, adrian MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D58898 (cherry picked from commit 81a67bfebc60055bbf19ce6e39537fb5f53eeee5) M sys/dev/usb/wlan/if_rsu.c _____________________________________________________________________________________________________________ Commit: 6484d5547fb00aa65d5abdf203c21d4486ad771a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6484d5547fb00aa65d5abdf203c21d4486ad771a Author: Andrew Griffiths (Thu 20 Aug 2026 15:29:53 BST) Committer: Mark Johnston (Wed 2 Sep 2026 18:40:28 BST) mtw: fix zero-length queue array that can corrupt struct mtw_softc The mtw softc declares sc_epq with MTW_BULK_RX even though MTW_BULK_RX is enum value 0, while initialization and queue handling index up to MTW_EP_QUEUES; attaching a matching USB WLAN device can drive writes past the absent array and corrupt adjacent softc fields. This suggested patch sizes sc_epq with MTW_EP_QUEUES so the softc contains the endpoint queues the driver initializes and uses. Fixes: c14b01624261 ("mt7601U: Importing if_mtw from OpenBSD") Reviewed by: bz MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D58897 (cherry picked from commit 7e9e72bee359437b9f78c6a4056ef0a90337f341) M sys/dev/usb/wlan/if_mtwvar.h _____________________________________________________________________________________________________________ Commit: 8b4365741e839683f49f812f2b116549cded7412 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8b4365741e839683f49f812f2b116549cded7412 Author: Mark Johnston (Fri 31 Jul 2026 13:56:45 BST) Committer: Mark Johnston (Wed 2 Sep 2026 18:40:28 BST) amd64: Mark the trapframe as initialized in ipi_bitmap_handler() Fixes: fdc1f3450634 ("x86: change signatures of ipi_{bitmap,swi}_handler() to take pointer") MFC after: 1 week Sponsored by: The FreeBSD Foundation (cherry picked from commit b566e0a7232b4989e79df95c2f02bdedef3ac4e7) M sys/x86/x86/mp_x86.c _____________________________________________________________________________________________________________ Commit: 8af9d5e04a21be6160a8d55f7d04526646ef56e2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8af9d5e04a21be6160a8d55f7d04526646ef56e2 Author: Nimish Jain (Tue 18 Aug 2026 15:41:38 BST) Committer: Mark Johnston (Wed 2 Sep 2026 18:40:28 BST) virtio_p9fs: Disallow detach if a session is in progress PR: 295453 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=295453 ) Reviewed by: markj MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D57500 (cherry picked from commit b39457bb1566912062b2df551b7b8d429b8ba0da) M sys/dev/virtio/p9fs/virtio_p9fs.c _____________________________________________________________________________________________________________ Commit: e2315ce0b6df8a0347e32e2c8b6f02a457b564da URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e2315ce0b6df8a0347e32e2c8b6f02a457b564da Author: Cy Schubert (Wed 11 Feb 2026 19:30:38 GMT) Committer: Cy Schubert (Wed 2 Sep 2026 15:13:13 BST) ipfilter: Avoid negative array indicies Array indices must always be posive. We avoid this by making each index unsigned. This mitigates out-of-bounds reads and writes. Reported by: Ilja Van Sprundel Reviewed by: glebius Differential revision: https://reviews.freebsd.org/D55260 (cherry picked from commit 3fdbd8a07a2dcb8fe3cec19fc59ef064453e4755) M sys/netpfil/ipfilter/netinet/fil.c M sys/netpfil/ipfilter/netinet/ip_fil.h M sys/netpfil/ipfilter/netinet/ip_state.c _____________________________________________________________________________________________________________ Commit: eab989e6a1aa563c255d61cec67cbd9d16a4d85d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=eab989e6a1aa563c255d61cec67cbd9d16a4d85d Author: John Baldwin (Thu 25 Jun 2026 16:37:55 BST) Committer: Ed Maste (Wed 2 Sep 2026 14:52:31 BST) makefs: Fix build on systems without st_birthtime such as Linux Reviewed by: emaste Fixes: 0a301f33306c ("makefs cd9660: Populate creation time stamps in RockRidge extensions") Pull Request: https://github.com/freebsd/freebsd-src/pull/2297 (cherry picked from commit 4e57c2aa307d34ca6e44f01c6fd671734ed5e486) M usr.sbin/makefs/cd9660/iso9660_rrip.c _____________________________________________________________________________________________________________ Commit: fd5a8d6911072c2fa9f42fa3495dd03da75878a1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fd5a8d6911072c2fa9f42fa3495dd03da75878a1 Author: John Baldwin (Tue 23 Jun 2026 16:51:43 BST) Committer: Ed Maste (Wed 2 Sep 2026 14:52:31 BST) makefs cd9660: Populate creation time stamps in RockRidge extensions Differential Revision: https://reviews.freebsd.org/D57527 (cherry picked from commit 0a301f33306c07e629a2423827238aaef85f5d68) M usr.sbin/makefs/cd9660/iso9660_rrip.c _____________________________________________________________________________________________________________ Commit: de60db7469f057748435281d147143f3c8b35474 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=de60db7469f057748435281d147143f3c8b35474 Author: Xuqing Yang (Tue 18 Aug 2026 21:17:44 BST) Committer: Christos Margiolis (Wed 2 Sep 2026 10:38:58 BST) bcm2835_audio: Comment out vchi_service_release() bcm2835_audio_release() calls vchi_service_close() and then unconditionally calls vchi_service_release() with the same service handle. In the VCHI shim implementation, a successful vchi_service_close() calls service_free(service). The subsequent vchi_service_release() therefore dereferences a freed SHIM_SERVICE_T object when it reads service->handle, resulting in a use-after-free panic. vchi_service_release(), however, releases a reference which might block vchi_service_close() from completing successfuly, so comment it out instead of removing it altogether, until further testing is done. PR: 297187 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297187 ) MFC after: 2 weeks Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D58921 (cherry picked from commit 95c04b25323d59da43203a08e56db141ac37181b) M sys/arm/broadcom/bcm2835/bcm2835_audio.c _____________________________________________________________________________________________________________ Commit: 61c2141f50e689f835d0f2c15a98930c66ec917c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=61c2141f50e689f835d0f2c15a98930c66ec917c Author: Ed Maste (Tue 18 Nov 2025 13:21:03 GMT) Committer: Ed Maste (Tue 1 Sep 2026 15:01:56 BST) diff3: Use a format string to quiet a compiler warning And bump WARNS to 2 (cherry picked from commit fd52a9becc62f721ad6a61c7301559afaedee010) M contrib/diff/src/diff3.c M gnu/usr.bin/diff3/Makefile _____________________________________________________________________________________________________________ Commit: 30211e66b98991aca28b61ec6b28ed108702d14f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=30211e66b98991aca28b61ec6b28ed108702d14f Author: Steve Kargl (Wed 29 Jul 2026 12:45:42 BST) Committer: Robert Clausecker (Tue 1 Sep 2026 10:37:28 BST) msun: add asinpi, acospi, and atanpi This commit implements the inverse half-cycle trigonometric functions: asinpi(x) = asin(x) / pi Eq. (1) acospi(x) = acos(x) / pi atanpi(x) = atan(x) / pi Implemention details are contained in src/s_asinpi.c and src/a_atanpi.c, where the details for acospi(x) appear in the former. ************* CAVEAT EMPTOR: The ld128 code has been only compiled. It has not been tested for correctness due to lack of hardware. ************* Code compiled on AMD Ryzen 7 7700X system run FreeBSD 16.0-CURRENT main-n284956-de9fe28ab847. Exhaustive testing of acospif(x), asinpif(x), and atanpif(x) on the indicated intervals yields % ./tlibm acospi -fPE -x 0x1p-120 -X 1 Interval tested for acospif: [7.52316e-37,1] ulp <= 0.5: 99.627% 1002878299 | 99.627% 1002878299 0.5 < ulp <= 0.6: 0.277% 2789599 | 99.904% 1005667898 0.6 < ulp <= 0.7: 0.096% 965062 | 100.000% 1006632960 Max ulp: 0.63661975 at 5.96046412e-08 0x1.fffffep-25 % ./tlibm asinpi -fPED -x 0x1p-120f -X 1.f Interval tested for asinpif: [7.52316e-37,1] ulp <= 0.5: 99.851% 1005129353 | 99.851% 1005129353 0.5 < ulp <= 0.6: 0.149% 1501097 | 100.000% 1006630450 0.6 < ulp <= 0.7: 0.000% 2510 | 100.000% 1006632960 Max ulp: 0.68957579 at 5.04878759e-01 0x1.027f78p-1 % ./tlibm atanpi -fPE -x 0x1p-120 -X max > zatanpif.txt & Interval tested for atanpif: [7.52316e-37,3.40282e+38] ulp <= 0.5: 99.865% 2077574602 | 99.865% 2077574602 0.5 < ulp <= 0.6: 0.131% 2735011 | 99.997% 2080309613 0.6 < ulp <= 0.7: 0.003% 65170 | 100.000% 2080374783 Max ulp: 0.68433094 at 5.01186252e-01 0x1.009b7cp-1 Testing the double and long double version cannot be done in an exhaustive manner. For 300 M values, uniformily distributed in the indicated interals, one finds the max ULP: Interval tested for acospi: [9.31323e-10,0.25] xm = 2.4423788416892520e-01, /* 0x3fcf432f, 0xde79920f */ libm = 4.2146222480005391e-01, /* 0x3fdaf93c, 0xb201001c */ mpfr = 4.2146222480005396e-01, /* 0x3fdaf93c, 0xb201001d */ ULP = 0.50499351466286857 Interval tested for acospi: [0.25,0.5] xm = 4.9689430915631438e-01, /* 0x3fdfcd1d, 0xc9d945c6 */ libm = 3.3447366122373884e-01, /* 0x3fd56804, 0x371513ef */ mpfr = 3.3447366122373889e-01, /* 0x3fd56804, 0x371513f0 */ ULP = 0.57195275455053829 Interval tested for acospi: [0.5,0.75] xm = 5.0238623667462079e-01, /* 0x3fe0138c, 0x4d0f4be0 */ libm = 3.3245556599062825e-01, /* 0x3fd546f3, 0xb5d36303 */ mpfr = 3.3245556599062820e-01, /* 0x3fd546f3, 0xb5d36302 */ ULP = 0.63427929243758807 Interval tested for acospi: [0.75,1] xm = 7.5853651919512177e-01, /* 0x3fe845ee, 0x60d8789f */ libm = 2.2591472240382732e-01, /* 0x3fcceac6, 0x0c3465ce */ mpfr = 2.2591472240382729e-01, /* 0x3fcceac6, 0x0c3465cd */ ULP = 0.56915750216472161 Interval tested for asinpi: [9.31323e-10,0.25] xm = 1.9502362835488171e-01, /* 0x3fc8f688, 0xc4dda0fb */ libm = 6.2478354989018887e-02, /* 0x3faffd29, 0xb6c57c61 */ mpfr = 6.2478354989018881e-02, /* 0x3faffd29, 0xb6c57c60 */ ULP = 0.52347765415885006 Interval tested for asinpi: [0.25,0.5] xm = 4.9937103583123676e-01, /* 0x3fdff5b1, 0xeeddbf62 */ libm = 1.6643553767987129e-01, /* 0x3fc54dc2, 0x7b9d15a4 */ mpfr = 1.6643553767987126e-01, /* 0x3fc54dc2, 0x7b9d15a3 */ ULP = 0.66214688371031072 Interval tested for asinpi: [0.5,0.75] xm = 5.0228515250761718e-01, /* 0x3fe012b8, 0x4fe92bbb */ libm = 1.6750722213679006e-01, /* 0x3fc570e0, 0x6c75edd5 */ mpfr = 1.6750722213679009e-01, /* 0x3fc570e0, 0x6c75edd6 */ ULP = 0.78223048105528226 Interval tested for asinpi: [0.75,1] xm = 7.5425933001419776e-01, /* 0x3fe822e4, 0x7663a4aa */ libm = 2.7200385380185182e-01, /* 0x3fd16882, 0xda1dc13b */ mpfr = 2.7200385380185188e-01, /* 0x3fd16882, 0xda1dc13c */ ULP = 0.53747973176773822 Interval tested for atanpi: [9.31323e-10,0.25] xm = 1.9666113418757322e-01, /* 0x3fc92c31, 0x29dd6d2f */ libm = 6.1810387818117797e-02, /* 0x3fafa59c, 0x7476baa5 */ mpfr = 6.1810387818117804e-02, /* 0x3fafa59c, 0x7476baa6 */ ULP = 0.54674297446584263 Interval tested for atanpi: [0.25,0.5] xm = 4.1312119637707068e-01, /* 0x3fda7093, 0xe2ee5494 */ libm = 1.2470309560460152e-01, /* 0x3fbfec8a, 0xc554ebec */ mpfr = 1.2470309560460154e-01, /* 0x3fbfec8a, 0xc554ebed */ ULP = 0.73116638175113347 Interval tested for atanpi: [0.5,0.75] xm = 5.0018949583396499e-01, /* 0x3fe0018d, 0x66cd1b82 */ libm = 1.4763186871058706e-01, /* 0x3fc2e599, 0xdffacb8f */ mpfr = 1.4763186871058709e-01, /* 0x3fc2e599, 0xdffacb90 */ ULP = 0.69192753950764663 Interval tested for atanpi: [0.75,1] xm = 7.5007880583359599e-01, /* 0x3fe800a5, 0x448f4c03 */ libm = 2.0484881828445453e-01, /* 0x3fca387c, 0x6f93f71f */ mpfr = 2.0484881828445450e-01, /* 0x3fca387c, 0x6f93f71e */ ULP = 0.65765471872064396 Interval tested for atanpi: [1,2] xm = 1.0103228000344093e+00, /* 0x3ff02a48, 0x3d88d0a2 */ libm = 2.5163447403817019e-01, /* 0x3fd01ac7, 0x7b229108 */ mpfr = 2.5163447403817013e-01, /* 0x3fd01ac7, 0x7b229107 */ ULP = 0.67409519689166042 Interval tested for atanpi: [2,4] xm = 2.0231383267437946e+00, /* 0x40002f63, 0x25a530a9 */ libm = 3.5387589538123299e-01, /* 0x3fd6a5e7, 0x156053c6 */ mpfr = 3.5387589538123293e-01, /* 0x3fd6a5e7, 0x156053c5 */ ULP = 0.69695587476021503 Interval tested for atanpi: [4,1.79769e+308] xm = 4.0000000000000000e+00, /* 0x40100000, 0x00000000 */ libm = 4.2202086962263069e-01, /* 0x3fdb0263, 0xd2508e31 */ mpfr = 4.2202086962263069e-01, /* 0x3fdb0263, 0xd2508e31 */ ULP = 0.27709400511686716 PR: 295884 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=295884 ) MFC after: 1 month Reviewed by: fuz (cherry picked from commit ae417b3194e76ce26065dc20281493ee83619879) M lib/msun/Makefile M lib/msun/Symbol.map A lib/msun/ld128/s_asinpil.c A lib/msun/ld128/s_atanpil.c A lib/msun/ld80/s_asinpil.c A lib/msun/ld80/s_atanpil.c A lib/msun/man/acospi.3 A lib/msun/man/asinpi.3 A lib/msun/man/atanpi.3 M lib/msun/src/math.h M lib/msun/src/math_private.h A lib/msun/src/s_asinpi.c A lib/msun/src/s_asinpif.c A lib/msun/src/s_atanpi.c A lib/msun/src/s_atanpif.c _____________________________________________________________________________________________________________ Commit: fb1a13fbc12e5edf6ea76954d3961b366a9a2a3f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fb1a13fbc12e5edf6ea76954d3961b366a9a2a3f Author: Faraz Vahedi (Sat 27 Jun 2026 14:34:21 BST) Committer: Robert Clausecker (Tue 1 Sep 2026 10:36:42 BST) libc: Add strfromd, strfromf, and strfroml per C23 strfromd(), strfromf(), and strfroml() are implemented directly in terms of gdtoa. If a non-conforming format string is passed, the string "EDOOFUS" is returned and errno set to EDOOFUS as an extension. Reviewed by: fuz MFC after: 1 month Pull-Request: https://github.com/freebsd/freebsd-src/pull/2301 Signed-off-by: Faraz Vahedi (cherry picked from commit f68d7bfc1479042184e09431bd55771c50c47f68) M include/stdlib.h M lib/libc/stdlib/Makefile.inc M lib/libc/stdlib/Symbol.map A lib/libc/stdlib/strfrom.c A lib/libc/stdlib/strfrom.h A lib/libc/stdlib/strfromd.3 A lib/libc/stdlib/strfromd.c A lib/libc/stdlib/strfromf.c A lib/libc/stdlib/strfroml.c M lib/libc/tests/stdlib/Makefile A lib/libc/tests/stdlib/strfrom_test.c _____________________________________________________________________________________________________________ Commit: aa85e7aa36bb9651130ea6f25e830235db4e5f5c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=aa85e7aa36bb9651130ea6f25e830235db4e5f5c Author: Sobczyk, Pawel (Tue 18 Aug 2026 09:10:54 BST) Committer: Krzysztof Galazka (Tue 1 Sep 2026 10:03:21 BST) ix(4): Sanitize negative error codes Due to development history FreeBSD driver error codes are reported the same way as in Linux (as negatives) which is inconsistent with FreeBSD standard. It may cause unexpected behavior when driver errors are interpreted by a kernel as syscall handler return values. This patch converts error codes from negative to positive values for NVM access functions. Signed-off-by: Pawel Sobczyk Reviewed by: kbowling, erj, milosz.linkiewicz_intel.com Tested by: Mateusz Moga Sponsored by: Intel Corporation Differential Revision: https://reviews.freebsd.org/D57642 (cherry picked from commit 33e2eac3e3e738daa95a06f42d6c661b87ad9aac) M sys/dev/ixgbe/if_ix.c _____________________________________________________________________________________________________________ Commit: 63e9ab9f31df52ddf11146b9cb04ac041dcfec61 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=63e9ab9f31df52ddf11146b9cb04ac041dcfec61 Author: Krzysztof Galazka (Mon 17 Aug 2026 10:17:46 BST) Committer: Krzysztof Galazka (Tue 1 Sep 2026 10:02:57 BST) ix(4): Remove workaround for 2.5/5G speeds on E610 The problem observed on X550 adapters with 2.5 and 5 Gbps speeds negotiation on some switches is not affecting E610 adapters. Remove workaround, which omitted those speeds in the list of initially advertised speeds and advertise all speeds supported by adapter. Signed-off-by: Krzysztof Galazka Reviewed by: kbowling Tested by: Mateusz Moga Sponsored by: Intel Corporation Differential Revision: https://reviews.freebsd.org/D57339 (cherry picked from commit 62d5d119ee7d935ac05966f1c7c4333c33c4f3a9) M sys/dev/ixgbe/ixgbe_e610.c _____________________________________________________________________________________________________________ Commit: 793abbf91f7fe16c435c415c41b52c4e918e4204 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=793abbf91f7fe16c435c415c41b52c4e918e4204 Author: Siva Mahadevan (Thu 20 Aug 2026 05:18:43 BST) Committer: Siva Mahadevan (Tue 1 Sep 2026 10:02:12 BST) tarfs: allow mounting inside jails Reviewed by: des MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58833 (cherry picked from commit ba99013a4464c2f3e8cc0a89c23d03810dc2d37e) M sys/fs/tarfs/tarfs_vfsops.c M usr.sbin/jail/jail.8 _____________________________________________________________________________________________________________ Commit: 57bc966e65aeba3273fe0c860e23af439af524ba URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=57bc966e65aeba3273fe0c860e23af439af524ba Author: Siva Mahadevan (Thu 20 Aug 2026 05:17:45 BST) Committer: Siva Mahadevan (Tue 1 Sep 2026 10:02:12 BST) tarfs: remove PRIV_VFS_MOUNT_PERM check The backing file is already opened successfully, so there is no need to override the permissions. Reviewed by: des MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58832 (cherry picked from commit 4d524915233092d71b309b49d9743012cb05c11e) M sys/fs/tarfs/tarfs_vfsops.c _____________________________________________________________________________________________________________ Commit: f659997ccee7f74a310412e4e95086fbc35a4145 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f659997ccee7f74a310412e4e95086fbc35a4145 Author: Siva Mahadevan (Wed 12 Aug 2026 19:45:52 BST) Committer: Siva Mahadevan (Tue 1 Sep 2026 10:02:12 BST) rc_subr_test: ignore stderr in no_cycles test nuageinit_user_data_script references 'firstboot_freebsd_update' and 'firstboot_pkg_upgrade', which are from Ports. In a default base system test without sysutils/firstboot-freebsd-update and sysutils/firstboot-pkg-upgrade, rcorder will warn on "unknown provisions" to stderr, but is otherwise harmless. Reviewed by: arrowd Fixes: 16e47f317c4ce2be5fed530bf8a9af9f9bf55364 MFC after: 3 days Sponsored by: The FreeBSD Foundation (cherry picked from commit 3c33729ce2f421e2a583f19f85a181968aa310de) M libexec/rc/tests/rc_subr_test.sh _____________________________________________________________________________________________________________ Commit: fd35c63a351ec80d31a2c6b46283e9eded9e64f8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fd35c63a351ec80d31a2c6b46283e9eded9e64f8 Author: Krzysztof Galazka (Mon 17 Aug 2026 16:46:39 BST) Committer: Krzysztof Galazka (Tue 1 Sep 2026 09:53:14 BST) ice(4): Add two more 4-part IDs for E835 adapters Two additional subdevice IDs were introduced to distinguish between adapters with and without manageability over USB support. Signed-off-by: Krzysztof Galazka Reviewed by: erj Tested by: Mateusz Moga Sponsored by: Intel Corporation Differential Revision: https://reviews.freebsd.org/D57337 (cherry picked from commit f370d9e4d5844daa06d77e57236e03bd7c5f4ba1) M sys/dev/ice/ice_drv_info.h _____________________________________________________________________________________________________________ Commit: ecc16dd11ba2d8f8468396327cba512867693b09 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ecc16dd11ba2d8f8468396327cba512867693b09 Author: Enji Cooper (Sat 29 Aug 2026 03:26:19 BST) Committer: Enji Cooper (Tue 1 Sep 2026 09:16:05 BST) crypto/openssl: add manpages missed in related commit MFC with: 78e936b2d Fixes: 0d4d0f3a9 ("crypto/openssl: update generated content ...") Reported by: Jenkins CI (cherry picked from commit 19c1fe2d0c8f0001558c20f134be624241418191) A secure/lib/libcrypto/man/man3/NAME_CONSTRAINTS_check.3 A secure/lib/libcrypto/man/man3/OPENSSL_armcap.3 _____________________________________________________________________________________________________________ Commit: a281913660fe7b162a230d2455536013a0e041b1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a281913660fe7b162a230d2455536013a0e041b1 Author: Enji Cooper (Sat 29 Aug 2026 02:41:30 BST) Committer: Enji Cooper (Tue 1 Sep 2026 09:16:05 BST) crypto/openssl: update generated content to match 3.5.8 release This contains 2 new manpages as well as some minor manpage content changes. MFC with: 78e936b2d (cherry picked from commit 0d4d0f3a9f229f9e822b43234b0ff72e7223f19f) M crypto/openssl/exporters/libcrypto.pc M crypto/openssl/exporters/libssl.pc M crypto/openssl/exporters/openssl.pc M crypto/openssl/include/openssl/opensslv.h M crypto/openssl/include/openssl/ssl.h M secure/lib/libcrypto/man/man3/ADMISSIONS.3 M secure/lib/libcrypto/man/man3/ASN1_EXTERN_FUNCS.3 M secure/lib/libcrypto/man/man3/ASN1_INTEGER_get_int64.3 M secure/lib/libcrypto/man/man3/ASN1_INTEGER_new.3 M secure/lib/libcrypto/man/man3/ASN1_ITEM_lookup.3 M secure/lib/libcrypto/man/man3/ASN1_OBJECT_new.3 M secure/lib/libcrypto/man/man3/ASN1_STRING_TABLE_add.3 M secure/lib/libcrypto/man/man3/ASN1_STRING_length.3 M secure/lib/libcrypto/man/man3/ASN1_STRING_new.3 M secure/lib/libcrypto/man/man3/ASN1_STRING_print_ex.3 M secure/lib/libcrypto/man/man3/ASN1_TIME_set.3 M secure/lib/libcrypto/man/man3/ASN1_TYPE_get.3 M secure/lib/libcrypto/man/man3/ASN1_aux_cb.3 M secure/lib/libcrypto/man/man3/ASN1_generate_nconf.3 M secure/lib/libcrypto/man/man3/ASN1_item_d2i_bio.3 M secure/lib/libcrypto/man/man3/ASN1_item_new.3 M secure/lib/libcrypto/man/man3/ASN1_item_sign.3 M secure/lib/libcrypto/man/man3/ASYNC_WAIT_CTX_new.3 M secure/lib/libcrypto/man/man3/ASYNC_start_job.3 M secure/lib/libcrypto/man/man3/BF_encrypt.3 M secure/lib/libcrypto/man/man3/BIO_ADDR.3 M secure/lib/libcrypto/man/man3/BIO_ADDRINFO.3 M secure/lib/libcrypto/man/man3/BIO_connect.3 M secure/lib/libcrypto/man/man3/BIO_ctrl.3 M secure/lib/libcrypto/man/man3/BIO_f_base64.3 M secure/lib/libcrypto/man/man3/BIO_f_buffer.3 M secure/lib/libcrypto/man/man3/BIO_f_cipher.3 M secure/lib/libcrypto/man/man3/BIO_f_md.3 M secure/lib/libcrypto/man/man3/BIO_f_null.3 M secure/lib/libcrypto/man/man3/BIO_f_prefix.3 M secure/lib/libcrypto/man/man3/BIO_f_readbuffer.3 M secure/lib/libcrypto/man/man3/BIO_f_ssl.3 M secure/lib/libcrypto/man/man3/BIO_find_type.3 M secure/lib/libcrypto/man/man3/BIO_get_data.3 M secure/lib/libcrypto/man/man3/BIO_get_ex_new_index.3 M secure/lib/libcrypto/man/man3/BIO_get_rpoll_descriptor.3 M secure/lib/libcrypto/man/man3/BIO_meth_new.3 M secure/lib/libcrypto/man/man3/BIO_new.3 M secure/lib/libcrypto/man/man3/BIO_new_CMS.3 M secure/lib/libcrypto/man/man3/BIO_parse_hostserv.3 M secure/lib/libcrypto/man/man3/BIO_printf.3 M secure/lib/libcrypto/man/man3/BIO_push.3 M secure/lib/libcrypto/man/man3/BIO_read.3 M secure/lib/libcrypto/man/man3/BIO_s_accept.3 M secure/lib/libcrypto/man/man3/BIO_s_bio.3 M secure/lib/libcrypto/man/man3/BIO_s_connect.3 M secure/lib/libcrypto/man/man3/BIO_s_core.3 M secure/lib/libcrypto/man/man3/BIO_s_datagram.3 M secure/lib/libcrypto/man/man3/BIO_s_dgram_pair.3 M secure/lib/libcrypto/man/man3/BIO_s_fd.3 M secure/lib/libcrypto/man/man3/BIO_s_file.3 M secure/lib/libcrypto/man/man3/BIO_s_mem.3 M secure/lib/libcrypto/man/man3/BIO_s_null.3 M secure/lib/libcrypto/man/man3/BIO_s_socket.3 M secure/lib/libcrypto/man/man3/BIO_sendmmsg.3 M secure/lib/libcrypto/man/man3/BIO_set_callback.3 M secure/lib/libcrypto/man/man3/BIO_set_flags.3 M secure/lib/libcrypto/man/man3/BIO_should_retry.3 M secure/lib/libcrypto/man/man3/BIO_socket_wait.3 M secure/lib/libcrypto/man/man3/BN_BLINDING_new.3 M secure/lib/libcrypto/man/man3/BN_CTX_new.3 M secure/lib/libcrypto/man/man3/BN_CTX_start.3 M secure/lib/libcrypto/man/man3/BN_add.3 M secure/lib/libcrypto/man/man3/BN_add_word.3 M secure/lib/libcrypto/man/man3/BN_bn2bin.3 M secure/lib/libcrypto/man/man3/BN_cmp.3 M secure/lib/libcrypto/man/man3/BN_copy.3 M secure/lib/libcrypto/man/man3/BN_generate_prime.3 M secure/lib/libcrypto/man/man3/BN_mod_exp_mont.3 M secure/lib/libcrypto/man/man3/BN_mod_inverse.3 M secure/lib/libcrypto/man/man3/BN_mod_mul_montgomery.3 M secure/lib/libcrypto/man/man3/BN_mod_mul_reciprocal.3 M secure/lib/libcrypto/man/man3/BN_new.3 M secure/lib/libcrypto/man/man3/BN_num_bytes.3 M secure/lib/libcrypto/man/man3/BN_rand.3 M secure/lib/libcrypto/man/man3/BN_security_bits.3 M secure/lib/libcrypto/man/man3/BN_set_bit.3 M secure/lib/libcrypto/man/man3/BN_swap.3 M secure/lib/libcrypto/man/man3/BN_zero.3 M secure/lib/libcrypto/man/man3/BUF_MEM_new.3 M secure/lib/libcrypto/man/man3/CMAC_CTX.3 M secure/lib/libcrypto/man/man3/CMS_EncryptedData_decrypt.3 M secure/lib/libcrypto/man/man3/CMS_EncryptedData_encrypt.3 M secure/lib/libcrypto/man/man3/CMS_EncryptedData_set1_key.3 M secure/lib/libcrypto/man/man3/CMS_EnvelopedData_create.3 M secure/lib/libcrypto/man/man3/CMS_add0_cert.3 M secure/lib/libcrypto/man/man3/CMS_add1_recipient_cert.3 M secure/lib/libcrypto/man/man3/CMS_add1_signer.3 M secure/lib/libcrypto/man/man3/CMS_compress.3 M secure/lib/libcrypto/man/man3/CMS_data_create.3 M secure/lib/libcrypto/man/man3/CMS_decrypt.3 M secure/lib/libcrypto/man/man3/CMS_digest_create.3 M secure/lib/libcrypto/man/man3/CMS_encrypt.3 M secure/lib/libcrypto/man/man3/CMS_final.3 M secure/lib/libcrypto/man/man3/CMS_get0_RecipientInfos.3 M secure/lib/libcrypto/man/man3/CMS_get0_SignerInfos.3 M secure/lib/libcrypto/man/man3/CMS_get0_type.3 M secure/lib/libcrypto/man/man3/CMS_get1_ReceiptRequest.3 M secure/lib/libcrypto/man/man3/CMS_sign.3 M secure/lib/libcrypto/man/man3/CMS_sign_receipt.3 M secure/lib/libcrypto/man/man3/CMS_signed_get_attr.3 M secure/lib/libcrypto/man/man3/CMS_uncompress.3 M secure/lib/libcrypto/man/man3/CMS_verify.3 M secure/lib/libcrypto/man/man3/CMS_verify_receipt.3 M secure/lib/libcrypto/man/man3/COMP_CTX_new.3 M secure/lib/libcrypto/man/man3/CONF_modules_free.3 M secure/lib/libcrypto/man/man3/CONF_modules_load_file.3 M secure/lib/libcrypto/man/man3/CRYPTO_THREAD_run_once.3 M secure/lib/libcrypto/man/man3/CRYPTO_get_ex_new_index.3 M secure/lib/libcrypto/man/man3/CRYPTO_memcmp.3 M secure/lib/libcrypto/man/man3/CTLOG_STORE_get0_log_by_id.3 M secure/lib/libcrypto/man/man3/CTLOG_STORE_new.3 M secure/lib/libcrypto/man/man3/CTLOG_new.3 M secure/lib/libcrypto/man/man3/CT_POLICY_EVAL_CTX_new.3 M secure/lib/libcrypto/man/man3/DEFINE_STACK_OF.3 M secure/lib/libcrypto/man/man3/DES_random_key.3 M secure/lib/libcrypto/man/man3/DH_generate_key.3 M secure/lib/libcrypto/man/man3/DH_generate_parameters.3 M secure/lib/libcrypto/man/man3/DH_get0_pqg.3 M secure/lib/libcrypto/man/man3/DH_get_1024_160.3 M secure/lib/libcrypto/man/man3/DH_meth_new.3 M secure/lib/libcrypto/man/man3/DH_new.3 M secure/lib/libcrypto/man/man3/DH_new_by_nid.3 M secure/lib/libcrypto/man/man3/DH_set_method.3 M secure/lib/libcrypto/man/man3/DH_size.3 M secure/lib/libcrypto/man/man3/DSA_SIG_new.3 M secure/lib/libcrypto/man/man3/DSA_do_sign.3 M secure/lib/libcrypto/man/man3/DSA_dup_DH.3 M secure/lib/libcrypto/man/man3/DSA_generate_key.3 M secure/lib/libcrypto/man/man3/DSA_generate_parameters.3 M secure/lib/libcrypto/man/man3/DSA_get0_pqg.3 M secure/lib/libcrypto/man/man3/DSA_meth_new.3 M secure/lib/libcrypto/man/man3/DSA_new.3 M secure/lib/libcrypto/man/man3/DSA_set_method.3 M secure/lib/libcrypto/man/man3/DSA_sign.3 M secure/lib/libcrypto/man/man3/DSA_size.3 M secure/lib/libcrypto/man/man3/DTLS_get_data_mtu.3 M secure/lib/libcrypto/man/man3/DTLS_set_timer_cb.3 M secure/lib/libcrypto/man/man3/DTLSv1_get_timeout.3 M secure/lib/libcrypto/man/man3/DTLSv1_handle_timeout.3 M secure/lib/libcrypto/man/man3/DTLSv1_listen.3 M secure/lib/libcrypto/man/man3/ECDSA_SIG_new.3 M secure/lib/libcrypto/man/man3/ECDSA_sign.3 M secure/lib/libcrypto/man/man3/ECPKParameters_print.3 M secure/lib/libcrypto/man/man3/EC_GFp_simple_method.3 M secure/lib/libcrypto/man/man3/EC_GROUP_copy.3 M secure/lib/libcrypto/man/man3/EC_GROUP_new.3 M secure/lib/libcrypto/man/man3/EC_KEY_get_enc_flags.3 M secure/lib/libcrypto/man/man3/EC_KEY_new.3 M secure/lib/libcrypto/man/man3/EC_POINT_add.3 M secure/lib/libcrypto/man/man3/EC_POINT_new.3 M secure/lib/libcrypto/man/man3/ENGINE_add.3 M secure/lib/libcrypto/man/man3/ERR_GET_LIB.3 M secure/lib/libcrypto/man/man3/ERR_clear_error.3 M secure/lib/libcrypto/man/man3/ERR_error_string.3 M secure/lib/libcrypto/man/man3/ERR_get_error.3 M secure/lib/libcrypto/man/man3/ERR_load_crypto_strings.3 M secure/lib/libcrypto/man/man3/ERR_load_strings.3 M secure/lib/libcrypto/man/man3/ERR_new.3 M secure/lib/libcrypto/man/man3/ERR_print_errors.3 M secure/lib/libcrypto/man/man3/ERR_put_error.3 M secure/lib/libcrypto/man/man3/ERR_remove_state.3 M secure/lib/libcrypto/man/man3/ERR_set_mark.3 M secure/lib/libcrypto/man/man3/EVP_ASYM_CIPHER_free.3 M secure/lib/libcrypto/man/man3/EVP_BytesToKey.3 M secure/lib/libcrypto/man/man3/EVP_CIPHER_CTX_get_app_data.3 M secure/lib/libcrypto/man/man3/EVP_CIPHER_CTX_get_cipher_data.3 M secure/lib/libcrypto/man/man3/EVP_CIPHER_CTX_get_original_iv.3 M secure/lib/libcrypto/man/man3/EVP_CIPHER_meth_new.3 M secure/lib/libcrypto/man/man3/EVP_DigestInit.3 M secure/lib/libcrypto/man/man3/EVP_DigestSignInit.3 M secure/lib/libcrypto/man/man3/EVP_DigestVerifyInit.3 M secure/lib/libcrypto/man/man3/EVP_EncodeInit.3 M secure/lib/libcrypto/man/man3/EVP_EncryptInit.3 M secure/lib/libcrypto/man/man3/EVP_KDF.3 M secure/lib/libcrypto/man/man3/EVP_KEM_free.3 M secure/lib/libcrypto/man/man3/EVP_KEYEXCH_free.3 M secure/lib/libcrypto/man/man3/EVP_KEYMGMT.3 M secure/lib/libcrypto/man/man3/EVP_MAC.3 M secure/lib/libcrypto/man/man3/EVP_MD_meth_new.3 M secure/lib/libcrypto/man/man3/EVP_OpenInit.3 M secure/lib/libcrypto/man/man3/EVP_PBE_CipherInit.3 M secure/lib/libcrypto/man/man3/EVP_PKEY2PKCS8.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_ASN1_METHOD.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_CTX_ctrl.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_CTX_get0_libctx.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_CTX_get0_pkey.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_CTX_get_algor.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_CTX_new.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_CTX_set1_pbe_pass.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_CTX_set_hkdf_md.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_CTX_set_params.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_CTX_set_scrypt_N.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_CTX_set_tls1_prf_md.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_asn1_get_count.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_check.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_copy_parameters.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_decapsulate.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_decrypt.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_derive.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_digestsign_supports_digest.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_encapsulate.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_encrypt.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_fromdata.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_get_attr.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_get_default_digest_nid.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_get_field_type.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_get_group_name.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_get_size.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_gettable_params.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_is_a.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_keygen.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_meth_get_count.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_meth_new.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_new.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_print_private.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_set1_RSA.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_set1_encoded_public_key.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_set_type.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_settable_params.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_sign.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_todata.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_verify.3 M secure/lib/libcrypto/man/man3/EVP_PKEY_verify_recover.3 M secure/lib/libcrypto/man/man3/EVP_RAND.3 M secure/lib/libcrypto/man/man3/EVP_SIGNATURE.3 M secure/lib/libcrypto/man/man3/EVP_SKEY.3 M secure/lib/libcrypto/man/man3/EVP_SKEYMGMT.3 M secure/lib/libcrypto/man/man3/EVP_SealInit.3 M secure/lib/libcrypto/man/man3/EVP_SignInit.3 M secure/lib/libcrypto/man/man3/EVP_VerifyInit.3 M secure/lib/libcrypto/man/man3/EVP_aes_128_gcm.3 M secure/lib/libcrypto/man/man3/EVP_aria_128_gcm.3 M secure/lib/libcrypto/man/man3/EVP_bf_cbc.3 M secure/lib/libcrypto/man/man3/EVP_blake2b512.3 M secure/lib/libcrypto/man/man3/EVP_camellia_128_ecb.3 M secure/lib/libcrypto/man/man3/EVP_cast5_cbc.3 M secure/lib/libcrypto/man/man3/EVP_chacha20.3 M secure/lib/libcrypto/man/man3/EVP_des_cbc.3 M secure/lib/libcrypto/man/man3/EVP_desx_cbc.3 M secure/lib/libcrypto/man/man3/EVP_idea_cbc.3 M secure/lib/libcrypto/man/man3/EVP_md2.3 M secure/lib/libcrypto/man/man3/EVP_md4.3 M secure/lib/libcrypto/man/man3/EVP_md5.3 M secure/lib/libcrypto/man/man3/EVP_mdc2.3 M secure/lib/libcrypto/man/man3/EVP_rc2_cbc.3 M secure/lib/libcrypto/man/man3/EVP_rc4.3 M secure/lib/libcrypto/man/man3/EVP_rc5_32_12_16_cbc.3 M secure/lib/libcrypto/man/man3/EVP_ripemd160.3 M secure/lib/libcrypto/man/man3/EVP_seed_cbc.3 M secure/lib/libcrypto/man/man3/EVP_set_default_properties.3 M secure/lib/libcrypto/man/man3/EVP_sha1.3 M secure/lib/libcrypto/man/man3/EVP_sha224.3 M secure/lib/libcrypto/man/man3/EVP_sha3_224.3 M secure/lib/libcrypto/man/man3/EVP_sm3.3 M secure/lib/libcrypto/man/man3/EVP_sm4_cbc.3 M secure/lib/libcrypto/man/man3/EVP_whirlpool.3 M secure/lib/libcrypto/man/man3/GENERAL_NAME.3 M secure/lib/libcrypto/man/man3/HMAC.3 M secure/lib/libcrypto/man/man3/MD5.3 M secure/lib/libcrypto/man/man3/MDC2_Init.3 M secure/lib/libcrypto/man/man3/Makefile M secure/lib/libcrypto/man/man3/NCONF_new_ex.3 M secure/lib/libcrypto/man/man3/OBJ_nid2obj.3 M secure/lib/libcrypto/man/man3/OCSP_REQUEST_new.3 M secure/lib/libcrypto/man/man3/OCSP_cert_to_id.3 M secure/lib/libcrypto/man/man3/OCSP_request_add1_nonce.3 M secure/lib/libcrypto/man/man3/OCSP_resp_find_status.3 M secure/lib/libcrypto/man/man3/OCSP_response_status.3 M secure/lib/libcrypto/man/man3/OCSP_sendreq_new.3 M secure/lib/libcrypto/man/man3/OPENSSL_Applink.3 M secure/lib/libcrypto/man/man3/OPENSSL_FILE.3 M secure/lib/libcrypto/man/man3/OPENSSL_LH_COMPFUNC.3 M secure/lib/libcrypto/man/man3/OPENSSL_LH_stats.3 M secure/lib/libcrypto/man/man3/OPENSSL_config.3 M secure/lib/libcrypto/man/man3/OPENSSL_fork_prepare.3 M secure/lib/libcrypto/man/man3/OPENSSL_gmtime.3 M secure/lib/libcrypto/man/man3/OPENSSL_hexchar2int.3 M secure/lib/libcrypto/man/man3/OPENSSL_ia32cap.3 M secure/lib/libcrypto/man/man3/OPENSSL_init_crypto.3 M secure/lib/libcrypto/man/man3/OPENSSL_init_ssl.3 M secure/lib/libcrypto/man/man3/OPENSSL_instrument_bus.3 M secure/lib/libcrypto/man/man3/OPENSSL_load_builtin_modules.3 M secure/lib/libcrypto/man/man3/OPENSSL_load_u16_le.3 M secure/lib/libcrypto/man/man3/OPENSSL_malloc.3 M secure/lib/libcrypto/man/man3/OPENSSL_ppccap.3 M secure/lib/libcrypto/man/man3/OPENSSL_riscvcap.3 M secure/lib/libcrypto/man/man3/OPENSSL_s390xcap.3 M secure/lib/libcrypto/man/man3/OPENSSL_secure_malloc.3 M secure/lib/libcrypto/man/man3/OPENSSL_strcasecmp.3 M secure/lib/libcrypto/man/man3/OSSL_ALGORITHM.3 M secure/lib/libcrypto/man/man3/OSSL_CALLBACK.3 M secure/lib/libcrypto/man/man3/OSSL_CMP_ATAV_set0.3 M secure/lib/libcrypto/man/man3/OSSL_CMP_CTX_new.3 M secure/lib/libcrypto/man/man3/OSSL_CMP_HDR_get0_transactionID.3 M secure/lib/libcrypto/man/man3/OSSL_CMP_ITAV_new_caCerts.3 M secure/lib/libcrypto/man/man3/OSSL_CMP_ITAV_set0.3 M secure/lib/libcrypto/man/man3/OSSL_CMP_MSG_get0_header.3 M secure/lib/libcrypto/man/man3/OSSL_CMP_MSG_http_perform.3 M secure/lib/libcrypto/man/man3/OSSL_CMP_SRV_CTX_new.3 M secure/lib/libcrypto/man/man3/OSSL_CMP_STATUSINFO_new.3 M secure/lib/libcrypto/man/man3/OSSL_CMP_exec_certreq.3 M secure/lib/libcrypto/man/man3/OSSL_CMP_log_open.3 M secure/lib/libcrypto/man/man3/OSSL_CMP_validate_msg.3 M secure/lib/libcrypto/man/man3/OSSL_CORE_MAKE_FUNC.3 M secure/lib/libcrypto/man/man3/OSSL_CRMF_MSG_get0_tmpl.3 M secure/lib/libcrypto/man/man3/OSSL_CRMF_MSG_set0_validity.3 M secure/lib/libcrypto/man/man3/OSSL_CRMF_MSG_set1_regCtrl_regToken.3 M secure/lib/libcrypto/man/man3/OSSL_CRMF_MSG_set1_regInfo_certReq.3 M secure/lib/libcrypto/man/man3/OSSL_CRMF_pbmp_new.3 M secure/lib/libcrypto/man/man3/OSSL_DECODER.3 M secure/lib/libcrypto/man/man3/OSSL_DECODER_CTX.3 M secure/lib/libcrypto/man/man3/OSSL_DECODER_CTX_new_for_pkey.3 M secure/lib/libcrypto/man/man3/OSSL_DECODER_from_bio.3 M secure/lib/libcrypto/man/man3/OSSL_DISPATCH.3 M secure/lib/libcrypto/man/man3/OSSL_ENCODER.3 M secure/lib/libcrypto/man/man3/OSSL_ENCODER_CTX.3 M secure/lib/libcrypto/man/man3/OSSL_ENCODER_CTX_new_for_pkey.3 M secure/lib/libcrypto/man/man3/OSSL_ENCODER_to_bio.3 M secure/lib/libcrypto/man/man3/OSSL_ERR_STATE_save.3 M secure/lib/libcrypto/man/man3/OSSL_ESS_check_signing_certs.3 M secure/lib/libcrypto/man/man3/OSSL_GENERAL_NAMES_print.3 M secure/lib/libcrypto/man/man3/OSSL_HPKE_CTX_new.3 M secure/lib/libcrypto/man/man3/OSSL_HTTP_REQ_CTX.3 M secure/lib/libcrypto/man/man3/OSSL_HTTP_parse_url.3 M secure/lib/libcrypto/man/man3/OSSL_HTTP_transfer.3 M secure/lib/libcrypto/man/man3/OSSL_IETF_ATTR_SYNTAX.3 M secure/lib/libcrypto/man/man3/OSSL_IETF_ATTR_SYNTAX_print.3 M secure/lib/libcrypto/man/man3/OSSL_INDICATOR_set_callback.3 M secure/lib/libcrypto/man/man3/OSSL_ITEM.3 M secure/lib/libcrypto/man/man3/OSSL_LIB_CTX.3 M secure/lib/libcrypto/man/man3/OSSL_LIB_CTX_set_conf_diagnostics.3 M secure/lib/libcrypto/man/man3/OSSL_PARAM.3 M secure/lib/libcrypto/man/man3/OSSL_PARAM_BLD.3 M secure/lib/libcrypto/man/man3/OSSL_PARAM_allocate_from_text.3 M secure/lib/libcrypto/man/man3/OSSL_PARAM_dup.3 M secure/lib/libcrypto/man/man3/OSSL_PARAM_int.3 M secure/lib/libcrypto/man/man3/OSSL_PARAM_print_to_bio.3 M secure/lib/libcrypto/man/man3/OSSL_PROVIDER.3 M secure/lib/libcrypto/man/man3/OSSL_QUIC_client_method.3 M secure/lib/libcrypto/man/man3/OSSL_SELF_TEST_new.3 M secure/lib/libcrypto/man/man3/OSSL_SELF_TEST_set_callback.3 M secure/lib/libcrypto/man/man3/OSSL_STORE_INFO.3 M secure/lib/libcrypto/man/man3/OSSL_STORE_LOADER.3 M secure/lib/libcrypto/man/man3/OSSL_STORE_SEARCH.3 M secure/lib/libcrypto/man/man3/OSSL_STORE_attach.3 M secure/lib/libcrypto/man/man3/OSSL_STORE_expect.3 M secure/lib/libcrypto/man/man3/OSSL_STORE_open.3 M secure/lib/libcrypto/man/man3/OSSL_sleep.3 M secure/lib/libcrypto/man/man3/OSSL_trace_enabled.3 M secure/lib/libcrypto/man/man3/OSSL_trace_get_category_num.3 M secure/lib/libcrypto/man/man3/OSSL_trace_set_channel.3 M secure/lib/libcrypto/man/man3/OpenSSL_add_all_algorithms.3 M secure/lib/libcrypto/man/man3/OpenSSL_version.3 M secure/lib/libcrypto/man/man3/PBMAC1_get1_pbkdf2_param.3 M secure/lib/libcrypto/man/man3/PEM_X509_INFO_read_bio_ex.3 M secure/lib/libcrypto/man/man3/PEM_bytes_read_bio.3 M secure/lib/libcrypto/man/man3/PEM_read.3 M secure/lib/libcrypto/man/man3/PEM_read_CMS.3 M secure/lib/libcrypto/man/man3/PEM_read_bio_PrivateKey.3 M secure/lib/libcrypto/man/man3/PEM_read_bio_ex.3 M secure/lib/libcrypto/man/man3/PEM_write_bio_CMS_stream.3 M secure/lib/libcrypto/man/man3/PEM_write_bio_PKCS7_stream.3 M secure/lib/libcrypto/man/man3/PKCS12_PBE_keyivgen.3 M secure/lib/libcrypto/man/man3/PKCS12_SAFEBAG_create_cert.3 M secure/lib/libcrypto/man/man3/PKCS12_SAFEBAG_get0_attrs.3 M secure/lib/libcrypto/man/man3/PKCS12_SAFEBAG_get1_cert.3 M secure/lib/libcrypto/man/man3/PKCS12_SAFEBAG_set0_attrs.3 M secure/lib/libcrypto/man/man3/PKCS12_add1_attr_by_NID.3 M secure/lib/libcrypto/man/man3/PKCS12_add_CSPName_asc.3 M secure/lib/libcrypto/man/man3/PKCS12_add_cert.3 M secure/lib/libcrypto/man/man3/PKCS12_add_friendlyname_asc.3 M secure/lib/libcrypto/man/man3/PKCS12_add_localkeyid.3 M secure/lib/libcrypto/man/man3/PKCS12_add_safe.3 M secure/lib/libcrypto/man/man3/PKCS12_create.3 M secure/lib/libcrypto/man/man3/PKCS12_decrypt_skey.3 M secure/lib/libcrypto/man/man3/PKCS12_gen_mac.3 M secure/lib/libcrypto/man/man3/PKCS12_get_friendlyname.3 M secure/lib/libcrypto/man/man3/PKCS12_init.3 M secure/lib/libcrypto/man/man3/PKCS12_item_decrypt_d2i.3 M secure/lib/libcrypto/man/man3/PKCS12_key_gen_utf8_ex.3 M secure/lib/libcrypto/man/man3/PKCS12_newpass.3 M secure/lib/libcrypto/man/man3/PKCS12_pack_p7encdata.3 M secure/lib/libcrypto/man/man3/PKCS12_parse.3 M secure/lib/libcrypto/man/man3/PKCS5_PBE_keyivgen.3 M secure/lib/libcrypto/man/man3/PKCS5_PBKDF2_HMAC.3 M secure/lib/libcrypto/man/man3/PKCS7_decrypt.3 M secure/lib/libcrypto/man/man3/PKCS7_encrypt.3 M secure/lib/libcrypto/man/man3/PKCS7_get_octet_string.3 M secure/lib/libcrypto/man/man3/PKCS7_sign.3 M secure/lib/libcrypto/man/man3/PKCS7_sign_add_signer.3 M secure/lib/libcrypto/man/man3/PKCS7_type_is_other.3 M secure/lib/libcrypto/man/man3/PKCS7_verify.3 M secure/lib/libcrypto/man/man3/PKCS8_encrypt.3 M secure/lib/libcrypto/man/man3/PKCS8_pkey_add1_attr.3 M secure/lib/libcrypto/man/man3/RAND_add.3 M secure/lib/libcrypto/man/man3/RAND_bytes.3 M secure/lib/libcrypto/man/man3/RAND_cleanup.3 M secure/lib/libcrypto/man/man3/RAND_egd.3 M secure/lib/libcrypto/man/man3/RAND_get0_primary.3 M secure/lib/libcrypto/man/man3/RAND_load_file.3 M secure/lib/libcrypto/man/man3/RAND_set_DRBG_type.3 M secure/lib/libcrypto/man/man3/RAND_set_rand_method.3 M secure/lib/libcrypto/man/man3/RC4_set_key.3 M secure/lib/libcrypto/man/man3/RIPEMD160_Init.3 M secure/lib/libcrypto/man/man3/RSA_blinding_on.3 M secure/lib/libcrypto/man/man3/RSA_check_key.3 M secure/lib/libcrypto/man/man3/RSA_generate_key.3 M secure/lib/libcrypto/man/man3/RSA_get0_key.3 M secure/lib/libcrypto/man/man3/RSA_meth_new.3 M secure/lib/libcrypto/man/man3/RSA_new.3 M secure/lib/libcrypto/man/man3/RSA_padding_add_PKCS1_type_1.3 M secure/lib/libcrypto/man/man3/RSA_print.3 M secure/lib/libcrypto/man/man3/RSA_private_encrypt.3 M secure/lib/libcrypto/man/man3/RSA_public_encrypt.3 M secure/lib/libcrypto/man/man3/RSA_set_method.3 M secure/lib/libcrypto/man/man3/RSA_sign.3 M secure/lib/libcrypto/man/man3/RSA_sign_ASN1_OCTET_STRING.3 M secure/lib/libcrypto/man/man3/RSA_size.3 M secure/lib/libcrypto/man/man3/SCT_new.3 M secure/lib/libcrypto/man/man3/SCT_print.3 M secure/lib/libcrypto/man/man3/SCT_validate.3 M secure/lib/libcrypto/man/man3/SHA256_Init.3 M secure/lib/libcrypto/man/man3/SMIME_read_ASN1.3 M secure/lib/libcrypto/man/man3/SMIME_read_CMS.3 M secure/lib/libcrypto/man/man3/SMIME_read_PKCS7.3 M secure/lib/libcrypto/man/man3/SMIME_write_ASN1.3 M secure/lib/libcrypto/man/man3/SMIME_write_CMS.3 M secure/lib/libcrypto/man/man3/SMIME_write_PKCS7.3 M secure/lib/libcrypto/man/man3/SRP_Calc_B.3 M secure/lib/libcrypto/man/man3/SRP_VBASE_new.3 M secure/lib/libcrypto/man/man3/SRP_create_verifier.3 M secure/lib/libcrypto/man/man3/SRP_user_pwd_new.3 M secure/lib/libcrypto/man/man3/SSL_CIPHER_get_name.3 M secure/lib/libcrypto/man/man3/SSL_COMP_add_compression_method.3 M secure/lib/libcrypto/man/man3/SSL_CONF_CTX_new.3 M secure/lib/libcrypto/man/man3/SSL_CONF_CTX_set1_prefix.3 M secure/lib/libcrypto/man/man3/SSL_CONF_CTX_set_flags.3 M secure/lib/libcrypto/man/man3/SSL_CONF_CTX_set_ssl_ctx.3 M secure/lib/libcrypto/man/man3/SSL_CONF_cmd.3 M secure/lib/libcrypto/man/man3/SSL_CONF_cmd_argv.3 M secure/lib/libcrypto/man/man3/SSL_CTX_add1_chain_cert.3 M secure/lib/libcrypto/man/man3/SSL_CTX_add_extra_chain_cert.3 M secure/lib/libcrypto/man/man3/SSL_CTX_add_session.3 M secure/lib/libcrypto/man/man3/SSL_CTX_config.3 M secure/lib/libcrypto/man/man3/SSL_CTX_ctrl.3 M secure/lib/libcrypto/man/man3/SSL_CTX_dane_enable.3 M secure/lib/libcrypto/man/man3/SSL_CTX_flush_sessions.3 M secure/lib/libcrypto/man/man3/SSL_CTX_free.3 M secure/lib/libcrypto/man/man3/SSL_CTX_get0_param.3 M secure/lib/libcrypto/man/man3/SSL_CTX_get_verify_mode.3 M secure/lib/libcrypto/man/man3/SSL_CTX_has_client_custom_ext.3 M secure/lib/libcrypto/man/man3/SSL_CTX_load_verify_locations.3 M secure/lib/libcrypto/man/man3/SSL_CTX_new.3 M secure/lib/libcrypto/man/man3/SSL_CTX_sess_number.3 M secure/lib/libcrypto/man/man3/SSL_CTX_sess_set_cache_size.3 M secure/lib/libcrypto/man/man3/SSL_CTX_sess_set_get_cb.3 M secure/lib/libcrypto/man/man3/SSL_CTX_sessions.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set0_CA_list.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set1_cert_comp_preference.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set1_curves.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set1_sigalgs.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set1_verify_cert_store.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_alpn_select_cb.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_cert_cb.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_cert_store.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_cert_verify_callback.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_cipher_list.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_client_cert_cb.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_client_hello_cb.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_ct_validation_callback.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_ctlog_list_file.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_default_passwd_cb.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_domain_flags.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_generate_session_id.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_info_callback.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_keylog_callback.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_max_cert_list.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_min_proto_version.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_mode.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_msg_callback.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_new_pending_conn_cb.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_num_tickets.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_options.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_psk_client_callback.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_quiet_shutdown.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_read_ahead.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_record_padding_callback.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_security_level.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_session_cache_mode.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_session_id_context.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_session_ticket_cb.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_split_send_fragment.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_srp_password.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_ssl_version.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_stateless_cookie_generate_cb.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_timeout.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_tlsext_servername_callback.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_tlsext_status_cb.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_tlsext_ticket_key_cb.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_tlsext_use_srtp.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_tmp_dh_callback.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_tmp_ecdh.3 M secure/lib/libcrypto/man/man3/SSL_CTX_set_verify.3 M secure/lib/libcrypto/man/man3/SSL_CTX_use_certificate.3 M secure/lib/libcrypto/man/man3/SSL_CTX_use_psk_identity_hint.3 M secure/lib/libcrypto/man/man3/SSL_CTX_use_serverinfo.3 M secure/lib/libcrypto/man/man3/SSL_SESSION_free.3 M secure/lib/libcrypto/man/man3/SSL_SESSION_get0_cipher.3 M secure/lib/libcrypto/man/man3/SSL_SESSION_get0_hostname.3 M secure/lib/libcrypto/man/man3/SSL_SESSION_get0_id_context.3 M secure/lib/libcrypto/man/man3/SSL_SESSION_get0_peer.3 M secure/lib/libcrypto/man/man3/SSL_SESSION_get_compress_id.3 M secure/lib/libcrypto/man/man3/SSL_SESSION_get_protocol_version.3 M secure/lib/libcrypto/man/man3/SSL_SESSION_get_time.3 M secure/lib/libcrypto/man/man3/SSL_SESSION_has_ticket.3 M secure/lib/libcrypto/man/man3/SSL_SESSION_is_resumable.3 M secure/lib/libcrypto/man/man3/SSL_SESSION_print.3 M secure/lib/libcrypto/man/man3/SSL_SESSION_set1_id.3 M secure/lib/libcrypto/man/man3/SSL_accept.3 M secure/lib/libcrypto/man/man3/SSL_accept_stream.3 M secure/lib/libcrypto/man/man3/SSL_alert_type_string.3 M secure/lib/libcrypto/man/man3/SSL_alloc_buffers.3 M secure/lib/libcrypto/man/man3/SSL_check_chain.3 M secure/lib/libcrypto/man/man3/SSL_clear.3 M secure/lib/libcrypto/man/man3/SSL_connect.3 M secure/lib/libcrypto/man/man3/SSL_do_handshake.3 M secure/lib/libcrypto/man/man3/SSL_export_keying_material.3 M secure/lib/libcrypto/man/man3/SSL_extension_supported.3 M secure/lib/libcrypto/man/man3/SSL_free.3 M secure/lib/libcrypto/man/man3/SSL_get0_connection.3 M secure/lib/libcrypto/man/man3/SSL_get0_group_name.3 M secure/lib/libcrypto/man/man3/SSL_get0_peer_rpk.3 M secure/lib/libcrypto/man/man3/SSL_get0_peer_scts.3 M secure/lib/libcrypto/man/man3/SSL_get1_builtin_sigalgs.3 M secure/lib/libcrypto/man/man3/SSL_get_SSL_CTX.3 M secure/lib/libcrypto/man/man3/SSL_get_all_async_fds.3 M secure/lib/libcrypto/man/man3/SSL_get_certificate.3 M secure/lib/libcrypto/man/man3/SSL_get_ciphers.3 M secure/lib/libcrypto/man/man3/SSL_get_client_random.3 M secure/lib/libcrypto/man/man3/SSL_get_conn_close_info.3 M secure/lib/libcrypto/man/man3/SSL_get_current_cipher.3 M secure/lib/libcrypto/man/man3/SSL_get_default_timeout.3 M secure/lib/libcrypto/man/man3/SSL_get_error.3 M secure/lib/libcrypto/man/man3/SSL_get_event_timeout.3 M secure/lib/libcrypto/man/man3/SSL_get_extms_support.3 M secure/lib/libcrypto/man/man3/SSL_get_fd.3 M secure/lib/libcrypto/man/man3/SSL_get_handshake_rtt.3 M secure/lib/libcrypto/man/man3/SSL_get_peer_cert_chain.3 M secure/lib/libcrypto/man/man3/SSL_get_peer_certificate.3 M secure/lib/libcrypto/man/man3/SSL_get_peer_signature_nid.3 M secure/lib/libcrypto/man/man3/SSL_get_peer_tmp_key.3 M secure/lib/libcrypto/man/man3/SSL_get_psk_identity.3 M secure/lib/libcrypto/man/man3/SSL_get_rbio.3 M secure/lib/libcrypto/man/man3/SSL_get_rpoll_descriptor.3 M secure/lib/libcrypto/man/man3/SSL_get_session.3 M secure/lib/libcrypto/man/man3/SSL_get_shared_sigalgs.3 M secure/lib/libcrypto/man/man3/SSL_get_stream_id.3 M secure/lib/libcrypto/man/man3/SSL_get_stream_read_state.3 M secure/lib/libcrypto/man/man3/SSL_get_value_uint.3 M secure/lib/libcrypto/man/man3/SSL_get_verify_result.3 M secure/lib/libcrypto/man/man3/SSL_get_version.3 M secure/lib/libcrypto/man/man3/SSL_group_to_name.3 M secure/lib/libcrypto/man/man3/SSL_handle_events.3 M secure/lib/libcrypto/man/man3/SSL_in_init.3 M secure/lib/libcrypto/man/man3/SSL_inject_net_dgram.3 M secure/lib/libcrypto/man/man3/SSL_key_update.3 M secure/lib/libcrypto/man/man3/SSL_library_init.3 M secure/lib/libcrypto/man/man3/SSL_load_client_CA_file.3 M secure/lib/libcrypto/man/man3/SSL_new.3 M secure/lib/libcrypto/man/man3/SSL_new_domain.3 M secure/lib/libcrypto/man/man3/SSL_new_listener.3 M secure/lib/libcrypto/man/man3/SSL_new_stream.3 M secure/lib/libcrypto/man/man3/SSL_pending.3 M secure/lib/libcrypto/man/man3/SSL_poll.3 M secure/lib/libcrypto/man/man3/SSL_read.3 M secure/lib/libcrypto/man/man3/SSL_read_early_data.3 M secure/lib/libcrypto/man/man3/SSL_rstate_string.3 M secure/lib/libcrypto/man/man3/SSL_session_reused.3 M secure/lib/libcrypto/man/man3/SSL_set1_host.3 M secure/lib/libcrypto/man/man3/SSL_set1_initial_peer_addr.3 M secure/lib/libcrypto/man/man3/SSL_set1_server_cert_type.3 M secure/lib/libcrypto/man/man3/SSL_set_async_callback.3 M secure/lib/libcrypto/man/man3/SSL_set_bio.3 M secure/lib/libcrypto/man/man3/SSL_set_blocking_mode.3 M secure/lib/libcrypto/man/man3/SSL_set_connect_state.3 M secure/lib/libcrypto/man/man3/SSL_set_default_stream_mode.3 M secure/lib/libcrypto/man/man3/SSL_set_fd.3 M secure/lib/libcrypto/man/man3/SSL_set_incoming_stream_policy.3 M secure/lib/libcrypto/man/man3/SSL_set_quic_tls_cbs.3 M secure/lib/libcrypto/man/man3/SSL_set_retry_verify.3 M secure/lib/libcrypto/man/man3/SSL_set_session.3 M secure/lib/libcrypto/man/man3/SSL_set_session_secret_cb.3 M secure/lib/libcrypto/man/man3/SSL_set_shutdown.3 M secure/lib/libcrypto/man/man3/SSL_set_verify_result.3 M secure/lib/libcrypto/man/man3/SSL_shutdown.3 M secure/lib/libcrypto/man/man3/SSL_state_string.3 M secure/lib/libcrypto/man/man3/SSL_stream_conclude.3 M secure/lib/libcrypto/man/man3/SSL_stream_reset.3 M secure/lib/libcrypto/man/man3/SSL_want.3 M secure/lib/libcrypto/man/man3/SSL_write.3 M secure/lib/libcrypto/man/man3/TS_RESP_CTX_new.3 M secure/lib/libcrypto/man/man3/TS_VERIFY_CTX.3 M secure/lib/libcrypto/man/man3/UI_STRING.3 M secure/lib/libcrypto/man/man3/UI_UTIL_read_pw.3 M secure/lib/libcrypto/man/man3/UI_create_method.3 M secure/lib/libcrypto/man/man3/UI_new.3 M secure/lib/libcrypto/man/man3/X509V3_EXT_print.3 M secure/lib/libcrypto/man/man3/X509V3_get_d2i.3 M secure/lib/libcrypto/man/man3/X509V3_set_ctx.3 M secure/lib/libcrypto/man/man3/X509_ACERT_add1_attr.3 M secure/lib/libcrypto/man/man3/X509_ACERT_add_attr_nconf.3 M secure/lib/libcrypto/man/man3/X509_ACERT_get0_holder_baseCertId.3 M secure/lib/libcrypto/man/man3/X509_ACERT_get_attr.3 M secure/lib/libcrypto/man/man3/X509_ACERT_print_ex.3 M secure/lib/libcrypto/man/man3/X509_ALGOR_dup.3 M secure/lib/libcrypto/man/man3/X509_ATTRIBUTE.3 M secure/lib/libcrypto/man/man3/X509_CRL_get0_by_serial.3 M secure/lib/libcrypto/man/man3/X509_EXTENSION_set_object.3 M secure/lib/libcrypto/man/man3/X509_LOOKUP.3 M secure/lib/libcrypto/man/man3/X509_LOOKUP_hash_dir.3 M secure/lib/libcrypto/man/man3/X509_LOOKUP_meth_new.3 M secure/lib/libcrypto/man/man3/X509_NAME_ENTRY_get_object.3 M secure/lib/libcrypto/man/man3/X509_NAME_add_entry_by_txt.3 M secure/lib/libcrypto/man/man3/X509_NAME_get0_der.3 M secure/lib/libcrypto/man/man3/X509_NAME_get_index_by_NID.3 M secure/lib/libcrypto/man/man3/X509_NAME_print_ex.3 M secure/lib/libcrypto/man/man3/X509_PUBKEY_new.3 M secure/lib/libcrypto/man/man3/X509_REQ_get_attr.3 M secure/lib/libcrypto/man/man3/X509_REQ_get_extensions.3 M secure/lib/libcrypto/man/man3/X509_SIG_get0.3 M secure/lib/libcrypto/man/man3/X509_STORE_CTX_get_by_subject.3 M secure/lib/libcrypto/man/man3/X509_STORE_CTX_get_error.3 M secure/lib/libcrypto/man/man3/X509_STORE_CTX_new.3 M secure/lib/libcrypto/man/man3/X509_STORE_CTX_set_verify_cb.3 M secure/lib/libcrypto/man/man3/X509_STORE_add_cert.3 M secure/lib/libcrypto/man/man3/X509_STORE_get0_param.3 M secure/lib/libcrypto/man/man3/X509_STORE_new.3 M secure/lib/libcrypto/man/man3/X509_STORE_set_verify_cb_func.3 M secure/lib/libcrypto/man/man3/X509_VERIFY_PARAM_set_flags.3 M secure/lib/libcrypto/man/man3/X509_add_cert.3 M secure/lib/libcrypto/man/man3/X509_check_ca.3 M secure/lib/libcrypto/man/man3/X509_check_host.3 M secure/lib/libcrypto/man/man3/X509_check_issued.3 M secure/lib/libcrypto/man/man3/X509_check_private_key.3 M secure/lib/libcrypto/man/man3/X509_check_purpose.3 M secure/lib/libcrypto/man/man3/X509_cmp.3 M secure/lib/libcrypto/man/man3/X509_cmp_time.3 M secure/lib/libcrypto/man/man3/X509_digest.3 M secure/lib/libcrypto/man/man3/X509_dup.3 M secure/lib/libcrypto/man/man3/X509_get0_distinguishing_id.3 M secure/lib/libcrypto/man/man3/X509_get0_notBefore.3 M secure/lib/libcrypto/man/man3/X509_get0_signature.3 M secure/lib/libcrypto/man/man3/X509_get0_uids.3 M secure/lib/libcrypto/man/man3/X509_get_default_cert_file.3 M secure/lib/libcrypto/man/man3/X509_get_extension_flags.3 M secure/lib/libcrypto/man/man3/X509_get_pubkey.3 M secure/lib/libcrypto/man/man3/X509_get_serialNumber.3 M secure/lib/libcrypto/man/man3/X509_get_subject_name.3 M secure/lib/libcrypto/man/man3/X509_get_version.3 M secure/lib/libcrypto/man/man3/X509_load_http.3 M secure/lib/libcrypto/man/man3/X509_new.3 M secure/lib/libcrypto/man/man3/X509_sign.3 M secure/lib/libcrypto/man/man3/X509_verify.3 M secure/lib/libcrypto/man/man3/X509_verify_cert.3 M secure/lib/libcrypto/man/man3/X509v3_get_ext_by_NID.3 M secure/lib/libcrypto/man/man3/b2i_PVK_bio_ex.3 M secure/lib/libcrypto/man/man3/d2i_PKCS8PrivateKey_bio.3 M secure/lib/libcrypto/man/man3/d2i_PrivateKey.3 M secure/lib/libcrypto/man/man3/d2i_RSAPrivateKey.3 M secure/lib/libcrypto/man/man3/d2i_SSL_SESSION.3 M secure/lib/libcrypto/man/man3/d2i_X509.3 M secure/lib/libcrypto/man/man3/i2d_CMS_bio_stream.3 M secure/lib/libcrypto/man/man3/i2d_PKCS7_bio_stream.3 M secure/lib/libcrypto/man/man3/i2d_re_X509_tbs.3 M secure/lib/libcrypto/man/man3/o2i_SCT_LIST.3 M secure/lib/libcrypto/man/man3/s2i_ASN1_IA5STRING.3 M secure/lib/libcrypto/man/man5/config.5 M secure/lib/libcrypto/man/man5/fips_config.5 M secure/lib/libcrypto/man/man5/x509v3_config.5 M secure/lib/libcrypto/man/man7/EVP_ASYM_CIPHER-RSA.7 M secure/lib/libcrypto/man/man7/EVP_ASYM_CIPHER-SM2.7 M secure/lib/libcrypto/man/man7/EVP_CIPHER-AES.7 M secure/lib/libcrypto/man/man7/EVP_CIPHER-ARIA.7 M secure/lib/libcrypto/man/man7/EVP_CIPHER-BLOWFISH.7 M secure/lib/libcrypto/man/man7/EVP_CIPHER-CAMELLIA.7 M secure/lib/libcrypto/man/man7/EVP_CIPHER-CAST.7 M secure/lib/libcrypto/man/man7/EVP_CIPHER-CHACHA.7 M secure/lib/libcrypto/man/man7/EVP_CIPHER-DES.7 M secure/lib/libcrypto/man/man7/EVP_CIPHER-IDEA.7 M secure/lib/libcrypto/man/man7/EVP_CIPHER-NULL.7 M secure/lib/libcrypto/man/man7/EVP_CIPHER-RC2.7 M secure/lib/libcrypto/man/man7/EVP_CIPHER-RC4.7 M secure/lib/libcrypto/man/man7/EVP_CIPHER-RC5.7 M secure/lib/libcrypto/man/man7/EVP_CIPHER-SEED.7 M secure/lib/libcrypto/man/man7/EVP_CIPHER-SM4.7 M secure/lib/libcrypto/man/man7/EVP_KDF-ARGON2.7 M secure/lib/libcrypto/man/man7/EVP_KDF-HKDF.7 M secure/lib/libcrypto/man/man7/EVP_KDF-HMAC-DRBG.7 M secure/lib/libcrypto/man/man7/EVP_KDF-KB.7 M secure/lib/libcrypto/man/man7/EVP_KDF-KRB5KDF.7 M secure/lib/libcrypto/man/man7/EVP_KDF-PBKDF1.7 M secure/lib/libcrypto/man/man7/EVP_KDF-PBKDF2.7 M secure/lib/libcrypto/man/man7/EVP_KDF-PKCS12KDF.7 M secure/lib/libcrypto/man/man7/EVP_KDF-PVKKDF.7 M secure/lib/libcrypto/man/man7/EVP_KDF-SCRYPT.7 M secure/lib/libcrypto/man/man7/EVP_KDF-SS.7 M secure/lib/libcrypto/man/man7/EVP_KDF-SSHKDF.7 M secure/lib/libcrypto/man/man7/EVP_KDF-TLS13_KDF.7 M secure/lib/libcrypto/man/man7/EVP_KDF-TLS1_PRF.7 M secure/lib/libcrypto/man/man7/EVP_KDF-X942-ASN1.7 M secure/lib/libcrypto/man/man7/EVP_KDF-X942-CONCAT.7 M secure/lib/libcrypto/man/man7/EVP_KDF-X963.7 M secure/lib/libcrypto/man/man7/EVP_KEM-EC.7 M secure/lib/libcrypto/man/man7/EVP_KEM-ML-KEM.7 M secure/lib/libcrypto/man/man7/EVP_KEM-RSA.7 M secure/lib/libcrypto/man/man7/EVP_KEM-X25519.7 M secure/lib/libcrypto/man/man7/EVP_KEYEXCH-DH.7 M secure/lib/libcrypto/man/man7/EVP_KEYEXCH-ECDH.7 M secure/lib/libcrypto/man/man7/EVP_KEYEXCH-X25519.7 M secure/lib/libcrypto/man/man7/EVP_MAC-BLAKE2.7 M secure/lib/libcrypto/man/man7/EVP_MAC-CMAC.7 M secure/lib/libcrypto/man/man7/EVP_MAC-GMAC.7 M secure/lib/libcrypto/man/man7/EVP_MAC-HMAC.7 M secure/lib/libcrypto/man/man7/EVP_MAC-KMAC.7 M secure/lib/libcrypto/man/man7/EVP_MAC-Poly1305.7 M secure/lib/libcrypto/man/man7/EVP_MAC-Siphash.7 M secure/lib/libcrypto/man/man7/EVP_MD-BLAKE2.7 M secure/lib/libcrypto/man/man7/EVP_MD-KECCAK.7 M secure/lib/libcrypto/man/man7/EVP_MD-MD2.7 M secure/lib/libcrypto/man/man7/EVP_MD-MD4.7 M secure/lib/libcrypto/man/man7/EVP_MD-MD5-SHA1.7 M secure/lib/libcrypto/man/man7/EVP_MD-MD5.7 M secure/lib/libcrypto/man/man7/EVP_MD-MDC2.7 M secure/lib/libcrypto/man/man7/EVP_MD-NULL.7 M secure/lib/libcrypto/man/man7/EVP_MD-RIPEMD160.7 M secure/lib/libcrypto/man/man7/EVP_MD-SHA1.7 M secure/lib/libcrypto/man/man7/EVP_MD-SHA2.7 M secure/lib/libcrypto/man/man7/EVP_MD-SHA3.7 M secure/lib/libcrypto/man/man7/EVP_MD-SHAKE.7 M secure/lib/libcrypto/man/man7/EVP_MD-SM3.7 M secure/lib/libcrypto/man/man7/EVP_MD-WHIRLPOOL.7 M secure/lib/libcrypto/man/man7/EVP_MD-common.7 M secure/lib/libcrypto/man/man7/EVP_PKEY-DH.7 M secure/lib/libcrypto/man/man7/EVP_PKEY-DSA.7 M secure/lib/libcrypto/man/man7/EVP_PKEY-EC.7 M secure/lib/libcrypto/man/man7/EVP_PKEY-FFC.7 M secure/lib/libcrypto/man/man7/EVP_PKEY-HMAC.7 M secure/lib/libcrypto/man/man7/EVP_PKEY-ML-DSA.7 M secure/lib/libcrypto/man/man7/EVP_PKEY-ML-KEM.7 M secure/lib/libcrypto/man/man7/EVP_PKEY-RSA.7 M secure/lib/libcrypto/man/man7/EVP_PKEY-SLH-DSA.7 M secure/lib/libcrypto/man/man7/EVP_PKEY-SM2.7 M secure/lib/libcrypto/man/man7/EVP_PKEY-X25519.7 M secure/lib/libcrypto/man/man7/EVP_RAND-CRNG-TEST.7 M secure/lib/libcrypto/man/man7/EVP_RAND-CTR-DRBG.7 M secure/lib/libcrypto/man/man7/EVP_RAND-HASH-DRBG.7 M secure/lib/libcrypto/man/man7/EVP_RAND-HMAC-DRBG.7 M secure/lib/libcrypto/man/man7/EVP_RAND-JITTER.7 M secure/lib/libcrypto/man/man7/EVP_RAND-SEED-SRC.7 M secure/lib/libcrypto/man/man7/EVP_RAND-TEST-RAND.7 M secure/lib/libcrypto/man/man7/EVP_RAND.7 M secure/lib/libcrypto/man/man7/EVP_SIGNATURE-DSA.7 M secure/lib/libcrypto/man/man7/EVP_SIGNATURE-ECDSA.7 M secure/lib/libcrypto/man/man7/EVP_SIGNATURE-ED25519.7 M secure/lib/libcrypto/man/man7/EVP_SIGNATURE-HMAC.7 M secure/lib/libcrypto/man/man7/EVP_SIGNATURE-ML-DSA.7 M secure/lib/libcrypto/man/man7/EVP_SIGNATURE-RSA.7 M secure/lib/libcrypto/man/man7/EVP_SIGNATURE-SLH-DSA.7 M secure/lib/libcrypto/man/man7/OSSL_PROVIDER-FIPS.7 M secure/lib/libcrypto/man/man7/OSSL_PROVIDER-base.7 M secure/lib/libcrypto/man/man7/OSSL_PROVIDER-default.7 M secure/lib/libcrypto/man/man7/OSSL_PROVIDER-legacy.7 M secure/lib/libcrypto/man/man7/OSSL_PROVIDER-null.7 M secure/lib/libcrypto/man/man7/OSSL_STORE-winstore.7 M secure/lib/libcrypto/man/man7/RAND.7 M secure/lib/libcrypto/man/man7/RSA-PSS.7 M secure/lib/libcrypto/man/man7/X25519.7 M secure/lib/libcrypto/man/man7/bio.7 M secure/lib/libcrypto/man/man7/ct.7 M secure/lib/libcrypto/man/man7/des_modes.7 M secure/lib/libcrypto/man/man7/evp.7 M secure/lib/libcrypto/man/man7/fips_module.7 M secure/lib/libcrypto/man/man7/life_cycle-cipher.7 M secure/lib/libcrypto/man/man7/life_cycle-digest.7 M secure/lib/libcrypto/man/man7/life_cycle-kdf.7 M secure/lib/libcrypto/man/man7/life_cycle-mac.7 M secure/lib/libcrypto/man/man7/life_cycle-pkey.7 M secure/lib/libcrypto/man/man7/life_cycle-rand.7 M secure/lib/libcrypto/man/man7/openssl-core.h.7 M secure/lib/libcrypto/man/man7/openssl-core_dispatch.h.7 M secure/lib/libcrypto/man/man7/openssl-core_names.h.7 M secure/lib/libcrypto/man/man7/openssl-env.7 M secure/lib/libcrypto/man/man7/openssl-glossary.7 M secure/lib/libcrypto/man/man7/openssl-qlog.7 M secure/lib/libcrypto/man/man7/openssl-quic-concurrency.7 M secure/lib/libcrypto/man/man7/openssl-quic.7 M secure/lib/libcrypto/man/man7/openssl-threads.7 M secure/lib/libcrypto/man/man7/openssl_user_macros.7 M secure/lib/libcrypto/man/man7/ossl-guide-introduction.7 M secure/lib/libcrypto/man/man7/ossl-guide-libcrypto-introduction.7 M secure/lib/libcrypto/man/man7/ossl-guide-libraries-introduction.7 M secure/lib/libcrypto/man/man7/ossl-guide-libssl-introduction.7 M secure/lib/libcrypto/man/man7/ossl-guide-migration.7 M secure/lib/libcrypto/man/man7/ossl-guide-quic-client-block.7 M secure/lib/libcrypto/man/man7/ossl-guide-quic-client-non-block.7 M secure/lib/libcrypto/man/man7/ossl-guide-quic-introduction.7 M secure/lib/libcrypto/man/man7/ossl-guide-quic-multi-stream.7 M secure/lib/libcrypto/man/man7/ossl-guide-quic-server-block.7 M secure/lib/libcrypto/man/man7/ossl-guide-quic-server-non-block.7 M secure/lib/libcrypto/man/man7/ossl-guide-tls-client-block.7 M secure/lib/libcrypto/man/man7/ossl-guide-tls-client-non-block.7 M secure/lib/libcrypto/man/man7/ossl-guide-tls-introduction.7 M secure/lib/libcrypto/man/man7/ossl-guide-tls-server-block.7 M secure/lib/libcrypto/man/man7/ossl_store-file.7 M secure/lib/libcrypto/man/man7/ossl_store.7 M secure/lib/libcrypto/man/man7/passphrase-encoding.7 M secure/lib/libcrypto/man/man7/property.7 M secure/lib/libcrypto/man/man7/provider-asym_cipher.7 M secure/lib/libcrypto/man/man7/provider-base.7 M secure/lib/libcrypto/man/man7/provider-cipher.7 M secure/lib/libcrypto/man/man7/provider-decoder.7 M secure/lib/libcrypto/man/man7/provider-digest.7 M secure/lib/libcrypto/man/man7/provider-encoder.7 M secure/lib/libcrypto/man/man7/provider-kdf.7 M secure/lib/libcrypto/man/man7/provider-kem.7 M secure/lib/libcrypto/man/man7/provider-keyexch.7 M secure/lib/libcrypto/man/man7/provider-keymgmt.7 M secure/lib/libcrypto/man/man7/provider-mac.7 M secure/lib/libcrypto/man/man7/provider-object.7 M secure/lib/libcrypto/man/man7/provider-rand.7 M secure/lib/libcrypto/man/man7/provider-signature.7 M secure/lib/libcrypto/man/man7/provider-skeymgmt.7 M secure/lib/libcrypto/man/man7/provider-storemgmt.7 M secure/lib/libcrypto/man/man7/provider.7 M secure/lib/libcrypto/man/man7/proxy-certificates.7 M secure/lib/libcrypto/man/man7/x509.7 M secure/usr.bin/openssl/man/CA.pl.1 M secure/usr.bin/openssl/man/openssl-asn1parse.1 M secure/usr.bin/openssl/man/openssl-ca.1 M secure/usr.bin/openssl/man/openssl-ciphers.1 M secure/usr.bin/openssl/man/openssl-cmds.1 M secure/usr.bin/openssl/man/openssl-cmp.1 M secure/usr.bin/openssl/man/openssl-cms.1 M secure/usr.bin/openssl/man/openssl-crl.1 M secure/usr.bin/openssl/man/openssl-crl2pkcs7.1 M secure/usr.bin/openssl/man/openssl-dgst.1 M secure/usr.bin/openssl/man/openssl-dhparam.1 M secure/usr.bin/openssl/man/openssl-dsa.1 M secure/usr.bin/openssl/man/openssl-dsaparam.1 M secure/usr.bin/openssl/man/openssl-ec.1 M secure/usr.bin/openssl/man/openssl-ecparam.1 M secure/usr.bin/openssl/man/openssl-enc.1 M secure/usr.bin/openssl/man/openssl-engine.1 M secure/usr.bin/openssl/man/openssl-errstr.1 M secure/usr.bin/openssl/man/openssl-fipsinstall.1 M secure/usr.bin/openssl/man/openssl-format-options.1 M secure/usr.bin/openssl/man/openssl-gendsa.1 M secure/usr.bin/openssl/man/openssl-genpkey.1 M secure/usr.bin/openssl/man/openssl-genrsa.1 M secure/usr.bin/openssl/man/openssl-info.1 M secure/usr.bin/openssl/man/openssl-kdf.1 M secure/usr.bin/openssl/man/openssl-list.1 M secure/usr.bin/openssl/man/openssl-mac.1 M secure/usr.bin/openssl/man/openssl-namedisplay-options.1 M secure/usr.bin/openssl/man/openssl-nseq.1 M secure/usr.bin/openssl/man/openssl-ocsp.1 M secure/usr.bin/openssl/man/openssl-passphrase-options.1 M secure/usr.bin/openssl/man/openssl-passwd.1 M secure/usr.bin/openssl/man/openssl-pkcs12.1 M secure/usr.bin/openssl/man/openssl-pkcs7.1 M secure/usr.bin/openssl/man/openssl-pkcs8.1 M secure/usr.bin/openssl/man/openssl-pkey.1 M secure/usr.bin/openssl/man/openssl-pkeyparam.1 M secure/usr.bin/openssl/man/openssl-pkeyutl.1 M secure/usr.bin/openssl/man/openssl-prime.1 M secure/usr.bin/openssl/man/openssl-rand.1 M secure/usr.bin/openssl/man/openssl-rehash.1 M secure/usr.bin/openssl/man/openssl-req.1 M secure/usr.bin/openssl/man/openssl-rsa.1 M secure/usr.bin/openssl/man/openssl-rsautl.1 M secure/usr.bin/openssl/man/openssl-s_client.1 M secure/usr.bin/openssl/man/openssl-s_server.1 M secure/usr.bin/openssl/man/openssl-s_time.1 M secure/usr.bin/openssl/man/openssl-sess_id.1 M secure/usr.bin/openssl/man/openssl-skeyutl.1 M secure/usr.bin/openssl/man/openssl-smime.1 M secure/usr.bin/openssl/man/openssl-speed.1 M secure/usr.bin/openssl/man/openssl-spkac.1 M secure/usr.bin/openssl/man/openssl-srp.1 M secure/usr.bin/openssl/man/openssl-storeutl.1 M secure/usr.bin/openssl/man/openssl-ts.1 M secure/usr.bin/openssl/man/openssl-verification-options.1 M secure/usr.bin/openssl/man/openssl-verify.1 M secure/usr.bin/openssl/man/openssl-version.1 M secure/usr.bin/openssl/man/openssl-x509.1 M secure/usr.bin/openssl/man/openssl.1 M secure/usr.bin/openssl/man/tsget.1 _____________________________________________________________________________________________________________ Commit: 514ff9a982637aa7686c1862f44d90f9e7a2f4a1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=514ff9a982637aa7686c1862f44d90f9e7a2f4a1 Author: Enji Cooper (Sat 29 Aug 2026 02:28:12 BST) Committer: Enji Cooper (Tue 1 Sep 2026 09:16:05 BST) crypto/openssl: update to 3.5.8 This is a security bugfix release. Please see the related merge commit for more details. Maintainer note: `quic_ackm.h`'s conflict was resolved by taking the upstream version of the file verbatim. Conflicts: crypto/openssl/include/internal/quic_ackm.h MFC after: 3 days Merge commit '248da023ae5ea7292930ac5d715d88b87e2e6f46' (cherry picked from commit 78e936b2d0b5e6554425009199be31e76bc67c10) M crypto/openssl/CHANGES.md M crypto/openssl/CONTRIBUTING.md M crypto/openssl/NEWS.md M crypto/openssl/README-FIPS.md M crypto/openssl/VERSION.dat M crypto/openssl/apps/lib/apps.c M crypto/openssl/apps/lib/s_cb.c M crypto/openssl/apps/lib/vms_term_sock.c M crypto/openssl/apps/s_client.c D crypto/openssl/crypto/aes/aes_x86core.c M crypto/openssl/crypto/aes/asm/aesni-mb-x86_64.pl M crypto/openssl/crypto/aes/asm/aesni-sha1-x86_64.pl M crypto/openssl/crypto/aes/asm/aesni-sha256-x86_64.pl M crypto/openssl/crypto/aes/asm/aesni-xts-avx512.pl M crypto/openssl/crypto/armcap.c M crypto/openssl/crypto/asn1/a_d2i_fp.c M crypto/openssl/crypto/asn1/a_mbstr.c M crypto/openssl/crypto/asn1/asn1_gen.c M crypto/openssl/crypto/bio/bss_file.c M crypto/openssl/crypto/bn/asm/rsaz-2k-avx512.pl M crypto/openssl/crypto/bn/asm/rsaz-2k-avxifma.pl M crypto/openssl/crypto/bn/asm/rsaz-3k-avx512.pl M crypto/openssl/crypto/bn/asm/rsaz-3k-avxifma.pl M crypto/openssl/crypto/bn/asm/rsaz-4k-avx512.pl M crypto/openssl/crypto/bn/asm/rsaz-4k-avxifma.pl M crypto/openssl/crypto/bn/asm/rsaz-avx2.pl M crypto/openssl/crypto/bn/asm/rsaz-x86_64.pl M crypto/openssl/crypto/bn/asm/x86_64-mont.pl M crypto/openssl/crypto/bn/asm/x86_64-mont5.pl M crypto/openssl/crypto/bn/bn_add.c M crypto/openssl/crypto/bn/bn_exp.c M crypto/openssl/crypto/bn/bn_lib.c M crypto/openssl/crypto/chacha/asm/chacha-x86.pl M crypto/openssl/crypto/chacha/asm/chacha-x86_64.pl M crypto/openssl/crypto/cmp/cmp_protect.c M crypto/openssl/crypto/cmp/cmp_vfy.c M crypto/openssl/crypto/cms/cms_asn1.c M crypto/openssl/crypto/cms/cms_env.c M crypto/openssl/crypto/cms/cms_kari.c M crypto/openssl/crypto/cms/cms_local.h M crypto/openssl/crypto/cms/cms_pwri.c M crypto/openssl/crypto/cms/cms_smime.c M crypto/openssl/crypto/ct/ct_b64.c M crypto/openssl/crypto/ctype.c M crypto/openssl/crypto/dh/dh_backend.c M crypto/openssl/crypto/dh/dh_check.c M crypto/openssl/crypto/dsa/dsa_key.c M crypto/openssl/crypto/ec/asm/ecp_nistz256-x86_64.pl M crypto/openssl/crypto/ec/asm/x25519-x86_64.pl M crypto/openssl/crypto/ec/ec_key.c M crypto/openssl/crypto/err/openssl.txt M crypto/openssl/crypto/evp/exchange.c M crypto/openssl/crypto/ffc/ffc_params_generate.c M crypto/openssl/crypto/hmac/hmac.c M crypto/openssl/crypto/http/http_lib.c M crypto/openssl/crypto/ml_dsa/ml_dsa_encoders.c M crypto/openssl/crypto/ml_dsa/ml_dsa_key.c M crypto/openssl/crypto/ml_dsa/ml_dsa_matrix.c M crypto/openssl/crypto/ml_dsa/ml_dsa_sample.c M crypto/openssl/crypto/ml_dsa/ml_dsa_sign.c M crypto/openssl/crypto/ml_dsa/ml_dsa_vector.h M crypto/openssl/crypto/ml_kem/ml_kem.c M crypto/openssl/crypto/modes/asm/aes-gcm-avx512.pl M crypto/openssl/crypto/modes/asm/aesni-gcm-x86_64.pl M crypto/openssl/crypto/modes/asm/ghash-x86_64.pl M crypto/openssl/crypto/pem/pvkfmt.c M crypto/openssl/crypto/pkcs12/p12_add.c M crypto/openssl/crypto/pkcs12/p12_decr.c M crypto/openssl/crypto/pkcs12/p12_utl.c M crypto/openssl/crypto/pkcs7/pk7_doit.c M crypto/openssl/crypto/pkcs7/pk7_lib.c M crypto/openssl/crypto/poly1305/asm/poly1305-x86.pl M crypto/openssl/crypto/poly1305/asm/poly1305-x86_64.pl M crypto/openssl/crypto/rand/rand_lib.c M crypto/openssl/crypto/rsa/rsa_gen.c M crypto/openssl/crypto/rsa/rsa_ossl.c M crypto/openssl/crypto/sha/asm/sha1-586.pl M crypto/openssl/crypto/sha/asm/sha1-mb-x86_64.pl M crypto/openssl/crypto/sha/asm/sha1-x86_64.pl M crypto/openssl/crypto/sha/asm/sha256-586.pl M crypto/openssl/crypto/sha/asm/sha256-mb-x86_64.pl M crypto/openssl/crypto/sha/asm/sha512-x86_64.pl M crypto/openssl/crypto/sha/sha_riscv.c M crypto/openssl/crypto/slh_dsa/slh_dsa.c M crypto/openssl/crypto/slh_dsa/slh_dsa_hash_ctx.c M crypto/openssl/crypto/slh_dsa/slh_dsa_key.c M crypto/openssl/crypto/slh_dsa/slh_dsa_local.h M crypto/openssl/crypto/slh_dsa/slh_fors.c M crypto/openssl/crypto/slh_dsa/slh_hash.c M crypto/openssl/crypto/slh_dsa/slh_hypertree.c M crypto/openssl/crypto/slh_dsa/slh_wots.c M crypto/openssl/crypto/slh_dsa/slh_xmss.c M crypto/openssl/crypto/threads_win.c M crypto/openssl/crypto/x509/by_dir.c M crypto/openssl/crypto/x509/pcy_cache.c M crypto/openssl/crypto/x509/v3_akid.c M crypto/openssl/crypto/x509/v3_ncons.c M crypto/openssl/crypto/x509/x509_err.c M crypto/openssl/crypto/x509/x509_lu.c M crypto/openssl/crypto/x509/x509_vfy.c M crypto/openssl/crypto/x509/x_crl.c M crypto/openssl/crypto/x509/x_pubkey.c M crypto/openssl/doc/build.info M crypto/openssl/doc/internal/man3/DEFINE_LIST_OF.pod M crypto/openssl/doc/man1/openssl-pkeyutl.pod.in M crypto/openssl/doc/man1/openssl.pod M crypto/openssl/doc/man3/ASN1_INTEGER_get_int64.pod M crypto/openssl/doc/man3/ASN1_aux_cb.pod M crypto/openssl/doc/man3/ASN1_item_d2i_bio.pod M crypto/openssl/doc/man3/BIO_s_datagram.pod M crypto/openssl/doc/man3/BIO_s_file.pod M crypto/openssl/doc/man3/BN_generate_prime.pod M crypto/openssl/doc/man3/CMS_EncryptedData_decrypt.pod A crypto/openssl/doc/man3/NAME_CONSTRAINTS_check.pod A crypto/openssl/doc/man3/OPENSSL_armcap.pod M crypto/openssl/doc/man3/OPENSSL_init_crypto.pod M crypto/openssl/doc/man3/SSL_CTX_set1_curves.pod M crypto/openssl/doc/man3/SSL_CTX_set_msg_callback.pod M crypto/openssl/doc/man3/SSL_CTX_set_verify.pod M crypto/openssl/doc/man3/SSL_get_value_uint.pod M crypto/openssl/doc/man3/SSL_new.pod M crypto/openssl/doc/man3/SSL_poll.pod M crypto/openssl/doc/man3/X509_get_default_cert_file.pod M crypto/openssl/doc/man3/X509_verify_cert.pod M crypto/openssl/doc/man7/EVP_CIPHER-SM4.pod M crypto/openssl/doc/man7/EVP_SIGNATURE-ECDSA.pod M crypto/openssl/doc/man7/EVP_SIGNATURE-RSA.pod M crypto/openssl/doc/man7/fips_module.pod M crypto/openssl/doc/man7/openssl-core_dispatch.h.pod M crypto/openssl/doc/man7/openssl-env.pod M crypto/openssl/doc/man7/openssl-quic-concurrency.pod M crypto/openssl/doc/man7/openssl-threads.pod M crypto/openssl/doc/man7/provider-kem.pod M crypto/openssl/doc/man7/provider-signature.pod M crypto/openssl/fuzz/provider.c M crypto/openssl/include/internal/hashtable.h M crypto/openssl/include/internal/list.h M crypto/openssl/include/internal/quic_ackm.h M crypto/openssl/include/internal/quic_port.h M crypto/openssl/include/internal/quic_record_rx.h M crypto/openssl/include/internal/quic_ssl.h M crypto/openssl/include/openssl/ssl.h.in M crypto/openssl/include/openssl/x509err.h M crypto/openssl/providers/baseprov.c M crypto/openssl/providers/defltprov.c M crypto/openssl/providers/fips-sources.checksums M crypto/openssl/providers/fips.checksum M crypto/openssl/providers/fips/fipsprov.c M crypto/openssl/providers/implementations/ciphers/cipher_aes_gcm_siv_hw.c M crypto/openssl/providers/implementations/ciphers/cipher_aes_ocb.c M crypto/openssl/providers/implementations/ciphers/cipher_chacha20_poly1305.c M crypto/openssl/providers/implementations/ciphers/cipher_chacha20_poly1305_hw.c M crypto/openssl/providers/implementations/ciphers/ciphercommon_ccm.c M crypto/openssl/providers/implementations/encode_decode/encode_key2ms.c M crypto/openssl/providers/implementations/kem/ml_kem_kem.c M crypto/openssl/providers/implementations/kem/mlx_kem.c M crypto/openssl/providers/implementations/kem/rsa_kem.c M crypto/openssl/providers/implementations/keymgmt/dh_kmgmt.c M crypto/openssl/providers/implementations/keymgmt/ec_kmgmt.c M crypto/openssl/providers/implementations/keymgmt/ecx_kmgmt.c M crypto/openssl/providers/implementations/keymgmt/ml_dsa_kmgmt.c M crypto/openssl/providers/implementations/keymgmt/ml_kem_kmgmt.c M crypto/openssl/providers/implementations/keymgmt/mlx_kmgmt.c M crypto/openssl/providers/implementations/keymgmt/slh_dsa_kmgmt.c M crypto/openssl/providers/implementations/macs/cmac_prov.c M crypto/openssl/providers/implementations/macs/poly1305_prov.c M crypto/openssl/providers/implementations/rands/drbg_ctr.c M crypto/openssl/providers/implementations/rands/drbg_hash.c M crypto/openssl/providers/implementations/rands/drbg_hmac.c M crypto/openssl/providers/implementations/rands/seeding/rand_unix.c M crypto/openssl/providers/implementations/rands/test_rng.c M crypto/openssl/providers/implementations/signature/rsa_sig.c M crypto/openssl/providers/implementations/signature/slh_dsa_sig.c M crypto/openssl/providers/implementations/storemgmt/file_store_any2obj.c M crypto/openssl/ssl/quic/quic_ackm.c M crypto/openssl/ssl/quic/quic_impl.c M crypto/openssl/ssl/quic/quic_port.c M crypto/openssl/ssl/quic/quic_port_local.h M crypto/openssl/ssl/quic/quic_rx_depack.c M crypto/openssl/ssl/quic/quic_stream_map.c M crypto/openssl/ssl/record/methods/dtls_meth.c M crypto/openssl/ssl/record/methods/recmethod_local.h M crypto/openssl/ssl/record/methods/tls_common.c M crypto/openssl/ssl/record/rec_layer_s3.c M crypto/openssl/ssl/rio/poll_builder.c M crypto/openssl/ssl/rio/poll_builder.h M crypto/openssl/ssl/rio/poll_immediate.c M crypto/openssl/ssl/rio/rio_notifier.c M crypto/openssl/ssl/s3_lib.c M crypto/openssl/ssl/ssl_cert.c M crypto/openssl/ssl/ssl_lib.c M crypto/openssl/ssl/ssl_local.h M crypto/openssl/ssl/ssl_rsa.c M crypto/openssl/ssl/statem/extensions.c M crypto/openssl/ssl/statem/statem_clnt.c M crypto/openssl/ssl/statem/statem_lib.c M crypto/openssl/ssl/statem/statem_srvr.c M crypto/openssl/ssl/t1_lib.c M crypto/openssl/test/asn1_decode_test.c M crypto/openssl/test/build.info M crypto/openssl/test/ca_internals_test.c A crypto/openssl/test/certs/delta-crl-as-complete-ca.pem A crypto/openssl/test/certs/delta-crl-as-complete-delta-reasons.pem A crypto/openssl/test/certs/delta-crl-as-complete-delta.pem A crypto/openssl/test/certs/delta-crl-as-complete-leaf.pem A crypto/openssl/test/certs/server-ec-compressed-cert.pem A crypto/openssl/test/certs/server-ec-compressed-key.pem M crypto/openssl/test/cmp_client_test.c M crypto/openssl/test/cmp_protect_test.c M crypto/openssl/test/cmp_vfy_test.c M crypto/openssl/test/cmsapitest.c M crypto/openssl/test/crltest.c M crypto/openssl/test/endecode_test.c M crypto/openssl/test/evp_extra_test.c M crypto/openssl/test/evp_extra_test2.c A crypto/openssl/test/fipsidentity.cnf M crypto/openssl/test/helpers/quictestlib.c M crypto/openssl/test/helpers/quictestlib.h M crypto/openssl/test/helpers/ssltestlib.c M crypto/openssl/test/helpers/ssltestlib.h M crypto/openssl/test/hpke_test.c M crypto/openssl/test/http_test.c M crypto/openssl/test/list_test.c M crypto/openssl/test/p_test.c M crypto/openssl/test/pairwise_fail_test.c M crypto/openssl/test/pkcs12_api_test.c M crypto/openssl/test/pkcs7_test.c M crypto/openssl/test/punycode_test.c M crypto/openssl/test/quic_ackm_test.c M crypto/openssl/test/quic_multistream_test.c M crypto/openssl/test/quic_tserver_test.c M crypto/openssl/test/quicapitest.c M crypto/openssl/test/radix/quic_bindings.c M crypto/openssl/test/radix/quic_ops.c M crypto/openssl/test/radix/quic_tests.c A crypto/openssl/test/recipes/20-test_app_s_client.t M crypto/openssl/test/recipes/20-test_cli_fips.t M crypto/openssl/test/recipes/25-test_verify.t D crypto/openssl/test/recipes/30-test_evp_data/evprand.txt M crypto/openssl/test/recipes/30-test_pairwise_fail.t M crypto/openssl/test/recipes/65-test_cmp_msg.t A crypto/openssl/test/recipes/70-test_rio_poll_builder.t M crypto/openssl/test/recipes/70-test_sslrecords.t M crypto/openssl/test/recipes/80-test_cms.t A crypto/openssl/test/recipes/80-test_cms_data/authenticated_attrs.pem A crypto/openssl/test/recipes/80-test_cms_data/authenveloped_attrs.pem A crypto/openssl/test/recipes/80-test_cms_data/bad_authenveloped_attrs.pem M crypto/openssl/test/recipes/80-test_cmsapi.t M crypto/openssl/test/recipes/80-test_ssl_new.t A crypto/openssl/test/rio_poll_builder_test.c M crypto/openssl/test/rpktest.c M crypto/openssl/test/secmemtest.c A crypto/openssl/test/ssl-tests/33-compressed-spki.cnf A crypto/openssl/test/ssl-tests/33-compressed-spki.cnf.in M crypto/openssl/test/sslapitest.c M crypto/openssl/test/x509_test.c M crypto/openssl/util/missingcrypto.txt M crypto/openssl/util/other.syms M crypto/openssl/util/perl/TLSProxy/Proxy.pm _____________________________________________________________________________________________________________ Commit: 64d0098e311aa154d2c17328ea991efe1774099a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=64d0098e311aa154d2c17328ea991efe1774099a Author: Kevin Bowling (Tue 18 Aug 2026 01:33:46 BST) Committer: Kevin Bowling (Tue 1 Sep 2026 01:27:59 BST) bnxt(4): Cross-reference led(4) Point the identification LED documentation to led(4), which describes how to control /dev/led device nodes. Sponsored by: BBOX.io (cherry picked from commit af069400a8ea514c8e55f123cae478aee65e04d5) M share/man/man4/bnxt.4 _____________________________________________________________________________________________________________ Commit: 310c4c9bfb31371aa2f8f5355806631677f37420 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=310c4c9bfb31371aa2f8f5355806631677f37420 Author: Kevin Bowling (Wed 12 Aug 2026 02:29:31 BST) Committer: Kevin Bowling (Tue 1 Sep 2026 01:27:47 BST) ice: Add led(4) identification support Expose the firmware-controlled physical port identification LED through /dev/led/ice*. Use the AdminQ port-identification command to select blinking mode and restore the netlist-selected original mode before the interface is stopped. Sponsored by: BBOX.io (cherry picked from commit a781965b91ea390f9576ae42c35c842db74aab86) M share/man/man4/ice.4 M sys/dev/ice/ice_iflib.h M sys/dev/ice/if_ice_iflib.c _____________________________________________________________________________________________________________ Commit: b15ed4f7a75bd5f197202efc4023b2b87d3d95d3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b15ed4f7a75bd5f197202efc4023b2b87d3d95d3 Author: Nick Price (Sat 15 Aug 2026 03:05:59 BST) Committer: Ed Maste (Mon 31 Aug 2026 19:08:47 BST) aq(4): arm PHY thermal shutdown only where a sensor exists aq_fw2x_thermal_arm() reached for a copper PHY register that the fibre parts do not implement, so arming failed on every init and printed a warning for a capability the hardware cannot have. Return ENOTSUP when the firmware does not advertise a temperature sensor, matching aq_fw2x_get_temp(), and warn only for a genuine failure. Signed-off-by: Nick Price Accepted-by: adrian Approved-by: adrian (cherry picked from commit 6dbf809bafe1421fbf3cdd952748b15437b7c72a) M sys/dev/aq/aq_fw2x.c M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: af6139be560aec9bb76c0dbaf4724551a5125882 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=af6139be560aec9bb76c0dbaf4724551a5125882 Author: Nick Price (Sat 15 Aug 2026 03:05:07 BST) Committer: Ed Maste (Mon 31 Aug 2026 19:08:40 BST) aq(4): probe the D100 device ID The D100 device ID was defined and handled by aq_hw_capabilities(), but had no entry in aq_vendor_info_array[], so the driver never probed it and the card was left unattached. Add the missing entry; the table lists the fibre variant last within each group, so it follows D109 rather than sorting numerically. Signed-off-by: Nick Price Accepted-by: adrian Approved-by: adrian (cherry picked from commit 1a78f5ae3917b770bd958010dae86574b15d97ff) M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: 5c644402109ea0e3a7f3e002006ac95a3d387344 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5c644402109ea0e3a7f3e002006ac95a3d387344 Author: Nick Price (Sun 9 Aug 2026 20:47:31 BST) Committer: Ed Maste (Mon 31 Aug 2026 19:07:57 BST) aq(4): report link transitions and previously silent failures A link flap left nothing in the log to work from. Both the link up and link down messages were gated on bootverbose while the message for a speed change that keeps carrier was not, so a default kernel was silent about a flap yet loud about a downshift -- the inverse of what an operator wants. The generic message from if_link_state_change() carries no speed, so gating the driver's own left the negotiated rate unrecorded. Report both transitions unconditionally. Say more than the rate. aq_hw_get_link_state() already negotiates flow control and throws it away, and Atlantic 2 reports duplex and EEE in the same link status word the rate comes from; decode them through a new get_link_info firmware op and name all of it on the up transition. EEE matters for a flap: low power idle transitions are a common source of marginal link trouble on multi-gigabit copper, and whether it was active is otherwise invisible. Give the down transition a cause. The PHY global fault code was only consulted from the thermal state machine, so an ordinary link loss reported nothing at all. Read the fault code, the firmware link state and the PHY temperature once per transition and append whatever is available. The firmware raises a fault one poll after it drops the link, so a thermal trip usually shows only its temperature here and aq_thermal_poll() names it on the following poll; the temperature alone is enough to separate a hot PHY from a cable event. Warn before the PHY trips rather than only after. The Atlantic 2 health monitor word carries a hot warning bit next to the ready and fault bits that nothing decoded. Report both edges of it from the thermal poll, so an adapter that is approaching its shutdown threshold says so while the link is still up. Expose the firmware's own link transition counters. The Atlantic 2 A0 statistics layout opens with link_up and link_down, which were read out of the firmware on every statistics poll and discarded. Publish them as dev.aq.N.fw_link_up and fw_link_down so a single flap can be told from a link that has been flapping all night. The B0 layout has no equivalent, so the op reports ENOTSUP there and the nodes are not created, matching how the temperature node is handled. Stop announcing a link state that was never read. The return value of aq_hw_get_link_state() was discarded, so a failed read would have been announced as link down. No firmware backend can fail that call today -- all three decode a register with no error path -- but the caller no longer depends on that, and it says so once if it ever starts failing. Report the hardware failures that were being discarded. The driver already reports the errors it keeps, so what stayed quiet was the set of calls whose result was never examined at all. None of these are expected to fail, which is precisely why a failure needs to say so: each one leaves the interface running but misconfigured in a way that presents as a network problem rather than a driver problem. aq_if_init() discarded aq_hw_start(), aq_hw_rss_hash_set(), aq_hw_rss_set() and aq_hw_udp_rss_enable(), so a datapath that never started or an indirection table that was never programmed showed up only as an interface that passes no traffic or delivers every flow to one queue. aq_mc_filter_apply() discarded aq_hw_mac_addr_set(), so a multicast address the stack believes is programmed could silently not be; report the address that failed and leave the filter slot for the next one instead of burning it. aq_update_vlan_filters() reported only the last of its three register writes. aq_if_stop() discarded both ring stop calls and the MAC reset, and a MAC that did not reset can still be mastering the bus. aq_if_detach() and aq_if_suspend() discarded aq_hw_deinit(). The interrupt moderation update on a link speed change was dropped as well; it runs only on a transition, so reporting it cannot become noisy. aq_if_attach_pre() discarded aq_hw_capabilities(), which is the only behavioral change here: it now fails the attach rather than continuing with an unset media type and an empty link speed mask, which would attach an interface that can never negotiate a link. It returns an error only for a device the probe table does not cover, so it is not reachable in practice. Document the resulting sysctls, along with the existing temperature and tracing nodes, which had no manual page coverage. Tested on an AQC113C (Atlantic 2 B0, firmware 1.5.38). Link up reports "speed=10000, full-duplex, flowcontrol none, EEE off", and "speed=1000" after a forced renegotiation, so the rate and duplex are read rather than assumed. A cable pull reports "link DOWN, F/W link state 0, temp 59 C" with the PHY fault clause correctly absent, which is what separates a cable event from a thermal trip. The B0 interface reports ENOTSUP for the link counters, so those two nodes are correctly not created. Traffic is unaffected: ten flows spread over all eight RX queues with no errors and no drops. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58749 Signed-off-by: Nick Price (cherry picked from commit af3f2dd124f07342c273dc017bc5e73639e446a5) M share/man/man4/aq.4 M sys/dev/aq/aq2_fw.c M sys/dev/aq/aq2_hw.h M sys/dev/aq/aq_device.h M sys/dev/aq/aq_fw.h M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_irq.c M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: 098d9810d7da2f3f0c63e011741adebab9239049 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=098d9810d7da2f3f0c63e011741adebab9239049 Author: Nick Price (Sun 2 Aug 2026 23:45:03 BST) Committer: Ed Maste (Mon 31 Aug 2026 19:07:57 BST) aq(4): interface lifecycle and link-state fixes aq_if_init() programmed the address captured at attach, so an address set with "ifconfig ether" or by lagg(4) enslavement was never written to unicast filter slot 0: the interface transmitted with the new address but the MAC still filtered on the old one, so it received nothing. Copy the current if_getlladdr() the way the other iflib drivers do. The link state could latch UP forever. aq_if_stop() cleared linkup before calling aq_if_update_admin_status(), which suppressed the LINK_STATE_DOWN transition the "link was UP" branch would have made. Announce the down transition directly from aq_if_stop() instead, and do not poll the admin status there at all: the MAC has just been reset, so a stale link reading would re-announce the link as up. The admin task itself had to stop reporting a link on a stopped interface. iflib runs it while either IFF_DRV_RUNNING or IFF_DRV_OACTIVE is set, and iflib_stop() sets OACTIVE, so the task kept polling after the stop and re-announced LINK_STATE_UP behind the driver's back. Treat a non-running interface as having no link. A lagg(4) parent otherwise keeps hashing flows onto a port whose carrier is gone, because LAGG_PORTACTIVE tests if_link_state together with IFF_UP. Stop the rest of the task there as well: the PHY thermal poll and the initialization retry both end in iflib_request_reset(), and _task_fn_admin() acts on that with no test of its own, so either could re-initialize an interface the operator had just taken down. aq_if_update_admin_status() also only reacted to transitions in and out of zero speed, so an autoneg downshift that kept the link up left if_baudrate, ifmedia, RX pause and interrupt moderation programmed for the old speed. Track the announced speed and re-run that work when it changes. aq_if_suspend() resets the MAC and stops the rings, but iflib_device_suspend() only calls IFDI_SUSPEND and never stops the interface, leaving IFF_DRV_RUNNING set over a suspended device. Clear it. Signed-off-by: Nick Price Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58473 (cherry picked from commit c956cc0f033a4050fbca4e39fdace7276a588e15) M sys/dev/aq/aq_device.h M sys/dev/aq/aq_irq.c M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: 9a9026fac352ffa05b1b6b1bffab411e056f1f5b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9a9026fac352ffa05b1b6b1bffab411e056f1f5b Author: Nick Price (Sun 2 Aug 2026 23:44:53 BST) Committer: Ed Maste (Mon 31 Aug 2026 19:07:57 BST) aq(4): mailbox, flow-control and firmware error-handling fixes Fold the whole-driver-review correctness and hardening fixes for the firmware and hardware layers. Advance the firmware-mailbox address per word in aq_hw_fw_downld_dwords(): on B1 silicon each loop iteration waits for the mailbox address register to differ from the expected address, but it was set once and never moved, so after the first word every wait returned immediately and read stale data. Advance it four bytes per word. B0 is unaffected (it polls the busy bit). The same function also left err set to ETIMEDOUT after successfully force-recovering the RAM CPU semaphore; the transfer loop is guarded by "--cnt && !err", so it ran zero iterations and returned a timeout with an untouched buffer, making the recovery path dead code. aq_hw_get_mac_permanent() ignored the get_mac_addr() error and then examined a buffer the firmware op never wrote on failure. A fresh softc is zero, so the "invalid address" test fired, a random locally administered MAC was substituted, and err was overwritten with 0 -- a transient mailbox failure produced a card that attached with a different MAC every boot. Fail instead; the random-address fallback still covers a genuinely blank or multicast burned-in address. aq_fw1x_reset() discarded the same download's return value and then read transaction_id out of an uninitialized stack struct, so propagate that error too. Encode RX-only flow control as PAUSE|ASYM_PAUSE rather than PAUSE alone: firmware 2.x/3.x has no independent RX-only bit, so the old encoding advertised symmetric pause when RX-only was requested. The MPI_INIT path also never cleared the pause bits before OR-ing in the requested ones, so flow control could be enabled and never disabled; clear them first, as the Atlantic 2 and Linux implementations do. Reject single-vector MSI in aq_if_attach_post() the same way legacy INTx is rejected: ift_legacy_intr is NULL, so no driver filter would acknowledge the not-clear-on-read, auto-masked device interrupt status; every supported Atlantic device provides MSI-X. Propagate firmware and MDIO errors instead of discarding them. The fw2x MDIO primitive returned a data word with no way to report a controller timeout; give aq_fw2x_mdio_op() a status return and a data out-parameter, propagate it through phy_write/read/reset/thermal_arm, and stop advancing the thermal recovery state machine when a PHY reset fails. Use that error to end the PHY address scan early: aq_fw2x_init_phy_id() probed all 32 MDIO ports even when the controller itself was timing out, spending up to ten seconds under fw_mtx and the iflib context lock. aq_fw2x_reset() also drove the shared MIF mailbox without fw_mtx, unlike every other fw2x mailbox user, so it could interleave with the temperature sysctl and load the capability mask from the wrong window. aq_hw_mpi_set() can return ETIMEDOUT when the Atlantic 2 shared firmware buffer is not acknowledged; aq_hw_init() now aborts through its error path rather than enabling rings with an unaccepted link state, and aq_if_init() logs the later link-speed error. Retry a failed initialization instead of leaving the link down. ifdi_init has no return value, so iflib marks the interface running once aq_if_init() returns; a propagated firmware-ack failure would otherwise leave it running with no initialized hardware and no recovery. Record the failure and retry from the admin task via iflib_request_reset(), paced by the once-per-second timer, giving up after a bounded number of attempts. Ring and queue start failures are deliberately left to the existing diagnostic, since they leave the remaining queues usable. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58437 (cherry picked from commit b445000158d39a126f5fcd6e18bbc32248f0bc68) M sys/dev/aq/aq_device.h M sys/dev/aq/aq_fw1x.c M sys/dev/aq/aq_fw2x.c M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_irq.c M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: 8ac0e35d6b5bd0584abc1262be6874dd98512649 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8ac0e35d6b5bd0584abc1262be6874dd98512649 Author: Nick Price (Sun 2 Aug 2026 23:44:43 BST) Committer: Ed Maste (Mon 31 Aug 2026 19:07:57 BST) aq(4): clean up diagnostics and remove dead code Non-functional cleanup, no change in behavior. device_printf() already prefixes each line with the device name, so the inline "atlantic:" token in the status and error messages produced a doubled prefix and diverged from the trace macros; remove it so all output carries one uniform "aqN:" prefix. Compile the RX/TX descriptor tracers only when AQ_CFG_DEBUG_LVL > 2 and make them no-op macros otherwise, so the default build no longer pays a cross-TU call plus argument evaluation per descriptor. Drop enum aq_dev_state, struct aq_rx_filters, and struct aq_vlan_tag, which have no remaining references now that VLAN state lives in a bitstr_t. Replace the four identical aq_sysctl_print_{tx,rx}_{head,tail} handlers, each carrying a dead write path on a read-only oid, with one aq_sysctl_print_ring_ptr that selects the accessor from arg2. Reduce the thermal and PHY-recovery comments to single terse lines that keep the load-bearing register numbers and the A1-vs-A2 recovery difference. Signed-off-by: Nick Price Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58436 (cherry picked from commit ae7e2c9170f6f7e39ab3132eb72c89f9f6e3a4d6) M sys/dev/aq/aq_dbg.c M sys/dev/aq/aq_dbg.h M sys/dev/aq/aq_device.h M sys/dev/aq/aq_irq.c M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: fa12e6e1dee7a8e1a43aaaead07e4f32e58bb881 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fa12e6e1dee7a8e1a43aaaead07e4f32e58bb881 Author: Nick Price (Sun 2 Aug 2026 23:44:33 BST) Committer: Ed Maste (Mon 31 Aug 2026 19:07:57 BST) aq(4): PHY thermal-shutdown handling and correctness fixes Fold the thermal-protection work and the correctness fixes that landed alongside it. Report and auto-recover from PHY thermal shutdown. The Atlantic PHYs can autonomously shut down on over-temperature, latching global fault 0x8007 and dropping the link; Atlantic 2 ships this armed, Atlantic 1 disabled. Arm it on Atlantic 1 at interface init (1E.C478.A via the MAC's MDIO controller), and recover from a trip automatically: the admin-status poll detects the fault, logs the shutdown limit and measured temperature, and holds the link down until the PHY cools, then restores it -- Atlantic 1 needs a PHY reset (1E.2681.0) with the MAC firmware running plus a full re-init, Atlantic 2 recovers on the re-init alone. New firmware ops get_phy_fault, phy_reset, thermal_arm, and get_thermal_limit back the state machine in aq_if_update_admin_status(). Make that Atlantic 1 thermal MDIO path address-correct and fail-safe. The direct-MDIO helpers hardcoded the Clause-45 port address to 0, but it is strap-selectable: on a board whose PHY answers elsewhere every thermal op targeted nothing, so arming silently no-oped and the post-trip reset never cleared the latch. Discover the address by scanning ports 0..31 for a PMA/PMD identifier and form it as (phy_id << 5) | mmd, marking it valid only when a PHY actually answers. aq_fw2x_phy_read also returned 0 on a semaphore timeout, indistinguishable from a real 1E.C478 == 0, so thermal_arm could zero live provisioning bits; give the read an error return and gate thermal_arm and get_thermal_limit on it. Bound the multicast filter slot index. aq_mc_filter_apply() programmed slot count + 1 and bailed only at count == AQ_HW_MAC_MAX (33), one address too late, so a 33rd entry raced in between the if_llmaddr_count() snapshot and the if_foreach_llmaddr() walk drove an out-of-bounds MMIO write to slot 33. Fire the guard at AQ_HW_MAC_MAX - 1, and also reject index >= AQ_HW_MAC_MAX in aq_hw_mac_addr_set() where the slot becomes an RPF register offset. Correctness and safety fixes: initialize the sysctl context in attach_pre so the iflib fail-path detach cannot sysctl_ctx_free() an uninitialized list (a page fault when MSI/MSI-X is denied); range-check the Atlantic 2 action-resolver table index, taken verbatim from a firmware-supplied base, before writing the ART registers; and accumulate statistics deltas as unsigned, since AQ_SDELTA discarded a forward delta of 2^31 or more at 10G across a stretched admin poll. Signed-off-by: Nick Price Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58435 (cherry picked from commit b68f4667612ff8cde2fefc94f8b31377b128ea7e) M sys/dev/aq/aq2_fw.c M sys/dev/aq/aq2_hw.h M sys/dev/aq/aq_device.h M sys/dev/aq/aq_fw.h M sys/dev/aq/aq_fw2x.c M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_irq.c M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: 4c44da6e965e6a13ea75e3b3f9a2b5ee771c9b95 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4c44da6e965e6a13ea75e3b3f9a2b5ee771c9b95 Author: Nick Price (Sun 2 Aug 2026 23:44:16 BST) Committer: Ed Maste (Mon 31 Aug 2026 19:07:57 BST) aq(4): observability controls and sysctl/header hygiene Fold the driver's observability and infrastructure work. Make aq_device.h self-contained: it declares struct aq_dev in terms of iflib, bitstring, socket, and ethernet types but included none of the headers that define them, compiling only because every includer happened to pull those first. Include what it uses. No functional change. Make the debug controls per-instance. The debug and debug_categories sysctls were registered per device but pointed at file-scope globals, so writing dev.aq.1.debug also changed dev.aq.0.debug and a card could not be traced in isolation. Move the level and category mask into struct aq_dev, reach them through the aq_dev back-pointer in struct aq_hw (wired up in attach_pre before the first firmware trace and guarded against a NULL deref), emit through device_printf() so each line carries its unit, and seed initial values from per-unit device hints so attach can be traced. Expose the PHY die temperature as dev.aq.N.temperature through a new firmware get_temp op: Atlantic 1 v2 reads it through the mailbox MPI control/state toggle, Atlantic 2 from the phy_health_monitor block in the OUT window (located at 0x13620 and confirmed by its ready bit). Atlantic 1 v1 has no sensor and exposes no node. Because this is the first firmware accessor iflib does not serialise, add a per-instance mutex in struct aq_hw and take it across the v2 read-modify-write in set_mode(), get_stats(), get_mode(), and get_temp(); the v1 and Atlantic 2 paths do not need it and say so. Trace the Atlantic 2 firmware path, which previously emitted nothing at any debug level (aq2_fw.c did not even include aq_dbg.h): the boot handshake, reset policy, MAC address, and link mode set/read, using the existing dbg_init and dbg_fw categories, with the per-poll mode read at detail level. Scope the driver sysctls to a context freed at detach. They were registered on the device newbus context, which newbus tears down only after DEVICE_DETACH returns, yet iflib frees the rings and softc inside DEVICE_DETACH -- a sysctl read racing detach could touch freed memory. Give the driver its own sysctl_ctx_list and free it at the start of aq_if_detach, draining in-flight readers first. Signed-off-by: Nick Price Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58434 (cherry picked from commit 9e067f207dc2da57df49812809cc5034030f61d1) M sys/dev/aq/aq2_fw.c M sys/dev/aq/aq2_hw.h M sys/dev/aq/aq_dbg.c M sys/dev/aq/aq_dbg.h M sys/dev/aq/aq_device.h M sys/dev/aq/aq_fw.c M sys/dev/aq/aq_fw.h M sys/dev/aq/aq_fw1x.c M sys/dev/aq/aq_fw2x.c M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_main.c M sys/dev/aq/aq_ring.c _____________________________________________________________________________________________________________ Commit: 66375270f087f8a6d87670cc0b7dcced2259065f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=66375270f087f8a6d87670cc0b7dcced2259065f Author: Nick Price (Mon 20 Jul 2026 23:11:51 BST) Committer: Ed Maste (Mon 31 Aug 2026 18:40:14 BST) aq(4): Document the Atlantic 2 (AQC113/114/115/116) devices List every AQC part aq_vendor_info_array[] probes, each with the maximum speed aq_hw_capabilities() grants it. Only the Atlantic 2 parts link at 10 Megabit. The AQC100 and AQC100S are the only SFP+ controllers; the rest are twisted pair. Reviewed by: adrian, ziaee Signed-off-by: Nick Price Differential Revision: https://reviews.freebsd.org/D58144 (cherry picked from commit 1d89845e90867e2f970c651c342eb07da847b6e9) M share/man/man4/aq.4 _____________________________________________________________________________________________________________ Commit: 7d9bb766b5f6be9914be08bca520010cf272ed86 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7d9bb766b5f6be9914be08bca520010cf272ed86 Author: Nick Price (Sun 19 Jul 2026 17:48:23 BST) Committer: Ed Maste (Mon 31 Aug 2026 18:37:00 BST) aq(4): correct Atlantic 2 register access Four Atlantic 2 register-access corrections found in bring-up. B0 aggregate octet counters: the B0 firmware statistics interface reports only aggregate rx/tx good octets, not the per-cast breakdown A0 and Atlantic 1 provide, so every octet sysctl read a permanent zero while frame counters advanced. Populate the aggregate octet fields from the B0 buffer; aq_update_hw_stats() accumulates them directly when the per-cast octets are absent. Drop the duplicate attach-time MCP reboot: aq_hw_mpi_create() already reboots the A2 firmware to read its version and caps, then aq_hw_reset() immediately rebooted it again -- a full MCP restart plus several transaction-id-bracketed window reads, adding attach latency and a duplicate banner. Give aq_hw_reset() a reboot flag and pass reboot=false for A2 at attach; the load-bearing down/stop reboot (which resyncs A2 RX DMA across ifconfig down/up) keeps reboot=true. Skip Atlantic 1 register accesses on Atlantic 2: gate out the 0x7040 Atlantic 1 TPO write (which A2 lacks; already a no-op via the unset TPO2 feature, but Linux hw_atl2 omits it), and guard the aq_hw_mpi_read_stats() direct reads of reg_rx_dma_stat_counter7 (dpc) and the LRO counter (cprc) with !ATLANTIC2 -- those are Atlantic 1 codegen offsets that on Atlantic 2 land on unrelated registers and can report bogus input-drop / LRO counts. HW-validated on AQC107 <-> AQC113C: A1 stats unchanged, A2 IQDROPS stays 0, attach consumes one MCP reboot instead of two, bidirectional iperf3 clean. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58143 (cherry picked from commit c325b4024d61fe20f8140d6891074ca7276c4d58) M sys/dev/aq/aq2_fw.c M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: 73f2d66f8d3dd585607e7fc607daa69d04084aad URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=73f2d66f8d3dd585607e7fc607daa69d04084aad Author: Nick Price (Sun 19 Jul 2026 17:48:14 BST) Committer: Ed Maste (Mon 31 Aug 2026 18:37:00 BST) aq(4): program the Atlantic 2 multiqueue datapath Wire up the Atlantic 2 receive datapath: the action-resolver table (ART), multiqueue RSS, QoS, and interrupt moderation. RX action-resolver table: Atlantic 2 replaces Atlantic 1's discrete RX filter registers with an ART -- hardware computes a per-packet classification tag, then walks {tag, mask, action} rows to drop, assign a queue, or assign a TC. aq_hw_art_filter_set() installs one row under the ART semaphore; aq_hw_init_rx_path() enables the resolver, tags L2 unicast/broadcast, installs the unicast/all-multicast and VLAN drop rows, and assigns every 802.1p priority to TC 0 (mirroring the Atlantic 1 user-priority map, since our RX side is a single 8-ring group in TC 0). Tag every enabled VLAN filter in the per-filter resolver-tag field -- a register the BSD ports never write -- because the VLAN drop row matches resolver tag 0, so without it all tagged receive was dead under VLAN filtering. Promiscuous mode disables the drop rows rather than toggling the Atlantic 1 promiscuous bits; all ART callers surface a semaphore timeout consistently. The Atlantic 1 RX_TCP_RSS_HASH and TPO2 programming is gated to Atlantic 1. Multiqueue RSS and QoS: fill Atlantic 2's own per-TC redirection table (AQ2_RPF_RSS_REDIR), skipping the Atlantic 1 table and its write-enable handshake. Program Atlantic 2's smaller packet-buffer sizes, its wider data-TC credit/weight fields, and its ring-to-TC map, using aq_hw_active_tcs() for the TC loops. RSS hash types: the Atlantic 2 resolver has per-protocol hash-type enables in REDIR2, so build the mask from aq_rss_hashconfig() instead of hardcoding every protocol -- UDP 4-tuple hashing now follows the kernel policy (off by default) with no L3L4 flow-filter workaround, and aq_hw_udp_rss_enable() is skipped on Atlantic 2. The kernel-to-hardware hash-type mapping is a small static lookup table rather than a nine-branch chain, since the two bit spaces do not share a simple shift. Tx interrupt moderation: Atlantic 2's per-ring Tx moderation control register lives at a different address, but its field layout matches the value the driver already builds, so write that value straight to it; Rx moderation is shared. HW-validated on AQC107 <-> AQC113C: TCP RSS spreads across 7/8 RX queues under 16 parallel flows, rx_err=0. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58142 (cherry picked from commit 418e7fd13b5aa201c0f9eb65ab2f9a0c1810ba23) M sys/dev/aq/aq2_hw.h M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: 8b08cf8d20328d62c327b42bf7b9a46b7d227a88 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8b08cf8d20328d62c327b42bf7b9a46b7d227a88 Author: Nick Price (Sun 19 Jul 2026 17:48:05 BST) Committer: Ed Maste (Mon 31 Aug 2026 18:37:00 BST) aq(4): add Atlantic 2 (AQC113) device support Add support for the Marvell Atlantic 2 (AQC113/114/115/116) controllers, a new chip generation that is not register-compatible with the Atlantic 1 parts aq(4) supports today. Adapted from the OpenBSD/NetBSD if_aq driver. Register and device definitions (aq2_hw.h): the firmware handshake (MIF_BOOT / MCP_HOST_REQ_INT / MIF_HOST_FINISHED), the 0x12000/0x13000 firmware interface windows, and the action-resolver table (ART) that replaces Atlantic 1's discrete RX filters, plus the Atlantic 2 PCI device ids and the aq_is_atlantic2() helper. Reserve a chip-feature bit (AQ_HW_CHIP_ATLANTIC2) and add the aq_hw fields the firmware fills at boot (ART base index, statistics interface version A0/B0). The per-VLAN-filter resolver-tag field comes from the Linux driver; the BSD sources never write it. Firmware operations (aq_fwa2.c): Atlantic 2 talks to the management CPU through the 0x12000/0x13000 register windows plus the boot handshake, rather than Atlantic 1's mailbox in shared RAM. Implement that as a third aq_firmware_ops vtable (reset, set_mode, get_mode, get_mac_addr, get_stats); aq_fwa2_reboot() boots the firmware, selects the A2 ops, and reads the version and ART base index, failing fast on the crash-init / boot-failed bits. fwa2_set_mode advertises full duplex only (the media model exposes no half-duplex types) and writes and acks the link options before raising ACTIVE mode, so a forced media change does not begin negotiation with a stale rate mask. enum aq_fw_link_speed gains aq_fw_10M, which Atlantic 2 supports and Atlantic 1 does not. Probe and attach: list the device ids with their media types and link speeds (all copper; AQC113* up to 10G, AQC116C to 1G), populate hw->device_id, and tag the generation with AQ_HW_CHIP_ATLANTIC2 so IS_CHIP_FEATURE() recognises it uniformly. Branch firmware bring-up and reset on the generation: aq_hw_init_ucp() and aq_hw_reset() reboot the MCP instead of the Atlantic 1 RBL/FLB reset -- without a real datapath reset every stop/init cycle reprograms the rings on a live, desynced RX DMA engine and the receive path stays dead. aq_hw_init() programs the Atlantic 2 launch-time clock ratio in place of the Atlantic 1 MRRS / TX-DMA request-limit clamp. Add an AQ_LINK_10M capability bit (Atlantic 2 links at 10M, Atlantic 1 cannot), offer 10baseT media, and map IFM_10_T to aq_fw_10M. With every supported media type now present, replace the per-speed switch statements in aq_media.c with a single {link bit, fw rate, IFM_* subtype, Mbit/s} table -- one source of truth for the supported link speeds. With this an Atlantic 2 card probes, brings up its firmware, reads its MAC, and negotiates link; the RX action-resolver datapath comes next. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58141 (cherry picked from commit dc5c0fc51cf47d6dfc737343e06805db294258e9) M sys/conf/files A sys/dev/aq/aq2_fw.c A sys/dev/aq/aq2_hw.h M sys/dev/aq/aq_device.h M sys/dev/aq/aq_fw.h M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_main.c M sys/dev/aq/aq_media.c M sys/modules/aq/Makefile _____________________________________________________________________________________________________________ Commit: cda01e24d28fe56f282a37ffc9e494bddc01ff3f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cda01e24d28fe56f282a37ffc9e494bddc01ff3f Author: Jose Luis Duran (Tue 25 Aug 2026 18:27:28 BST) Committer: Jose Luis Duran (Mon 31 Aug 2026 18:29:51 BST) openssh: Fix shosts.equiv path in manual pages Change the path for the shosts.equiv file to consistently reflect /etc/ssh/shosts.equiv across all manual pages. This change stems from 35d4ccfb5576 ("Document FreeBSD defaults and paths.") Reviewed by: bcr, emaste Differential Revision: https://reviews.freebsd.org/D52203 (cherry picked from commit 336cc041a492b03fde96fd89915ae694cf31b551) M crypto/openssh/ssh.1 M crypto/openssh/sshd.8 _____________________________________________________________________________________________________________ Commit: 66c45406f5eda04039d8f9699b9cdab61e1cb7b4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=66c45406f5eda04039d8f9699b9cdab61e1cb7b4 Author: Jose Luis Duran (Mon 24 Aug 2026 21:45:50 BST) Committer: Jose Luis Duran (Mon 31 Aug 2026 18:29:29 BST) ministat.1: Match actual output Fix a documentation discrepancy, where the implementation was updated to use uncertainty propagation for the ratio of means, but the example output in the manual page was left unchanged. Update the manual page example from 70.7384% to 102.3% to reflect the actual output. While here, also update the example in the README. Reviewed by: ziaee Fixes: a304ad90e9ae ("Reduce the bogosity of ministat's % difference calculations.") MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D59157 (cherry picked from commit 595e665cb292a70f9d17b779c8ad0470ff3e3964) M usr.bin/ministat/README M usr.bin/ministat/ministat.1 _____________________________________________________________________________________________________________ Commit: 3da3a8379e002eca5940d0549b365a919424f5a8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3da3a8379e002eca5940d0549b365a919424f5a8 Author: Nick Price (Sun 19 Jul 2026 17:47:38 BST) Committer: Ed Maste (Mon 31 Aug 2026 18:17:13 BST) aq(4): remove dead code and tidy macros, diagnostics, and naming Non-functional cleanup, with two diagnostic corrections. Dead code: delete leftover commented-out AQ_DBG_ENTER/EXIT/PRINT calls (aq_hw.c, aq_fw2x.c, aq_irq.c, aq_main.c), a commented-out aq_nic_cfg local, the stale old-signature parameter blocks between the ring-init declarations and their bodies (aq_ring.c), a trailing note on a live statement, and the unused DumpHex() vendor debug helper (no callers; its body only compiled under AQ_CFG_DEBUG_LVL > 3). Register-write macros: parenthesize AQ_WRITE_REG_BIT's msk/shift/value arguments so a compound argument cannot mis-bind, give AQ_HW_FLUSH() an explicit hw parameter instead of capturing it from caller scope, and drop the duplicate lowercase aq_hw_write_reg[_bit] aliases (converting the 43 call sites to the uppercase spelling) so there is a single form. Diagnostics: the aq_log* family expanded through the base log macro, which ignored its level and printed unconditionally, while the error traces gated on a debug level that defaulted below LOG_ERR and so were suppressed -- backwards. Gate the base log macro the way the trace one does and default the level to lvl_error, so the once-per-event firmware reset / capability errors are visible by default while the verbose info/dump output stays opt-in. Naming: rename identifiers carried verbatim from the vendor import that do not match style -- names mixing an ALL-CAPS macro-style prefix with a lowercase tail, and a trailing underscore the vendor used as a "file-local" marker in place of static. - dbg_level_ / dbg_categories_ -> aq_dbg_level / aq_dbg_categories: these are real globals (the log/trace macros reference them from every translation unit), so the trailing underscore was never a stand-in for static; give them the aq_ namespace so the driver stops exporting generically-named global symbols. - log_base_ / trace_base_ -> aq_log_base / aq_trace_base: the internal macros behind the aq_log*/trace* families. - bootExitCode / flbStatus -> boot_exit_code / flb_status (aq_fw.c); flb_status now matches the identically-purposed variable already spelled that way in the sibling FLB-reset path. Cosmetic: terminate the ring/HW-init, MSI-X admin-handler, and media-change error messages with a newline so they are not garbled into adjacent dmesg output, and label the per-queue rx_bytes sysctl "RX Octets" (it was copy-pasted "TX Octets"). Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58140 (cherry picked from commit f1796e8781ca8a632ffa0861b2e09944d225c479) M sys/dev/aq/aq_dbg.c M sys/dev/aq/aq_dbg.h M sys/dev/aq/aq_fw.c M sys/dev/aq/aq_fw1x.c M sys/dev/aq/aq_fw2x.c M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_hw_llh.c M sys/dev/aq/aq_irq.c M sys/dev/aq/aq_main.c M sys/dev/aq/aq_media.c M sys/dev/aq/aq_ring.c _____________________________________________________________________________________________________________ Commit: 03037d0cfae560e2620c629e607eb21667cf0880 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=03037d0cfae560e2620c629e607eb21667cf0880 Author: Nick Price (Sun 19 Jul 2026 17:46:29 BST) Committer: Ed Maste (Mon 31 Aug 2026 18:17:13 BST) aq(4): harden the interrupt and MAC-statistics paths Firmware-statistics accounting and interrupt-routing fixes. Stats delta underflow: guard the MAC statistics delta accumulation against counter wrap or a firmware counter reset, so a snapshot smaller than the previous one does not underflow into a huge spurious delta. Skip stats on a failed read: aq_update_hw_stats() ignored aq_hw_mpi_read_stats()'s return and committed the on-stack mbox into last_stats unconditionally. On a failed read that snapshot is garbage or zero and poisons the delta baseline (a zeroed snapshot wipes last_stats, so the next good read double-counts). Check the return and skip the accumulation and the last_stats commit on failure. Mailbox/stats separation: struct aq_hw_stats served both as the raw fw1x MCP mailbox layout and as the driver's canonical stats snapshot, so any field added to it would silently shift the fw1x mailbox read. Give the fw1x mailbox its own raw layout in struct aq_hw_fw_mbox and let aq_hw_stats become purely driver-owned; with the coupling gone, add first-class aggregate octet fields (brc/btc) that Atlantic 2 B0 firmware can populate directly. No A1 behavior change. The raw block is a named struct (aq_fw1x_mbox_stats) with a _Static_assert tying its size to aq_hw_stats' matching prefix, so the fw1x memcpy cannot silently misalign if either field list drifts. Also drop the unused FW1X_MPI_STATE_ADR / FW1X_MPI_CONTROL_ADR macros and the redundant fw1x_get_stats() dpc assignment that the caller immediately overwrites. Per-speed interrupt moderation: aq_hw_interrupt_moderation_set() hardcoded speed_index = 0, so every link speed got the 10G timer pair and the other rows were dead. Record the negotiated rate and index the tables by ffs(speed) - 1, reordering the rows to match the enum aq_fw_link_speed bit positions so the index cannot drift from the enum. Rename the two per-speed timer tables (AQ_HW_NIC_timers_table_ {rx,tx}_ -> aq_itr_timers_{rx,tx}), function-local static arrays whose SCREAMING_CASE vendor names read like macros. Hardware error interrupts: route both hardware error causes (interrupt map register 0) to the admin vector so they are actually delivered. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58139 (cherry picked from commit 65fd3b4165eff52f3447c70db8d10ef67875c022) M sys/dev/aq/aq_fw1x.c M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_irq.c _____________________________________________________________________________________________________________ Commit: a0170642da744a1f6fa920e0b04fb3e8a2c9ff3b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a0170642da744a1f6fa920e0b04fb3e8a2c9ff3b Author: Nick Price (Sun 19 Jul 2026 17:41:49 BST) Committer: Ed Maste (Mon 31 Aug 2026 18:17:13 BST) aq(4): harden the attach, detach, and reset error paths Correct several attach/detach/reset paths that either swallowed failures or acted on undefined state. MSI-X attach-failure double-free: aq_if_msix_intr_assign() freed the per-RX-ring interrupts in its failure path and then returned an error, so iflib's IFDI_DETACH freed the same irq structures again -- bus_teardown_intr() on a dangling tag and bus_release_resource() on an already-released IRQ, panicking a box that should have simply failed to attach. Let iflib own the teardown; drop the failure-path loop and the now-dead index bookkeeping. Detach loop bound: aq_if_detach() freed the per-ring interrupts looping to isc_nrxqsets while indexing rx_rings[], which is sized by rx_rings_count; index by rx_rings_count to match every other RX-ring loop. AQ_HW_WAIT_FOR final poll: the macro derived its result from the loop counter rather than the condition, so a condition that became true on the last iteration reported ETIMEDOUT. Worst for the acquire-on-read firmware RAM semaphore, which was acquired in hardware but reported as a timeout. Return based on the last evaluation of the condition. RBL MAC reset SPI cleanup: mac_soft_reset_rbl() fired the global reset without first tearing down the SPI/flash interface, so a flash burst in flight left the SPI bus wedged, the RBL could not re-read flash, and the reset returned EBUSY -- fatal at attach ("MAC reset failed: 16"). Set bit 4 of the SPI control register (0x53c) before the global reset, as the sibling FLB path and the Linux driver do. Reset failure propagation: aq_hw_reset() discarded fw_ops->reset()'s return, so a failed attach-time fw2x capability read left fw_caps == 0 permanently and stats silently froze. Propagate the error so the reset fails and is retried. aq_hw_init failure propagation: aq_hw_init() discarded aq_hw_init_tx_path()/aq_hw_init_rx_path() returns and reported success, bringing the interface up half-initialized; capture both and goto err_exit (mainly the Atlantic 2 RX action-resolver path, which returns EBUSY on ART semaphore timeout). Link-state outputs: aq_hw_get_link_state() left *link_speed and *fc_neg unwritten on early-return paths, and the caller acts on them uninitialized, so a transient firmware get_mode() failure could fabricate a phantom link-up at a garbage speed and program a garbage RX-pause bit. Initialize both to safe link-down values before calling get_mode(). Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58138 (cherry picked from commit 557866b899b632ca4160953e5430cd9ccba8b570) M sys/dev/aq/aq_common.h M sys/dev/aq/aq_fw.c M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: 239718d5f48ef113e05654bcdc0390782d10244a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=239718d5f48ef113e05654bcdc0390782d10244a Author: Nick Price (Sun 19 Jul 2026 17:41:37 BST) Committer: Ed Maste (Mon 31 Aug 2026 18:17:13 BST) aq(4): honor the kernel RSS policy and add a TX traffic-class helper Align RX steering with the kernel RSS framework and factor out the active-traffic-class count. RSS key and indirection table: on an options RSS kernel the stack owns a canonical hash key and a hash-to-bucket indirection table binding each bucket to a CPU. aq programmed a random arc4rand() key and a plain i % rss_qs table, so the hash it stamped in iri_flowid and the queue it steered a flow to did not match the CPU the stack chose -- defeating RSS affinity. Under #ifdef RSS take the key from rss_getkey() and each entry from rss_get_indirection_to_bucket(), as e1000/ixgbe/ixl do; the non-RSS build keeps the random key and round-robin table. RSS hash-type policy: drop the private hw.aq.enable_rss_udp knob (RDTUN, default on) and add aq_rss_hashconfig(), which under options RSS returns rss_gethashconfig() and otherwise the same UDP-off default. UDP 4-tuple hashing scatters a fragmented datagram's pieces across queues because only the first fragment carries the L4 ports, so it is now off by default and re-enabled the standard way, via net.inet.rss.udp_4tuple, matching ix/ixl/mlx5. On Atlantic 1 the UDP-off action stays the existing L3L4 flow-filter workaround; only its policy source changes. TX traffic-class helper: factor the active-TC count (one per active 8-ring group, capped at HW_ATL_B0_TCS_MAX) out of aq_hw_qos_set() into aq_hw_active_tcs(), so there is a single definition of the policy; the Atlantic 2 RSS redirection table reuses it. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58137 (cherry picked from commit 9b4585afd31384573fcebd156d0e4af32bcddf9e) M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: dcfe983dd5fc0ebff5cd525cae49fedc0f524ebf URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=dcfe983dd5fc0ebff5cd525cae49fedc0f524ebf Author: Nick Price (Sun 19 Jul 2026 17:40:46 BST) Committer: Ed Maste (Mon 31 Aug 2026 18:17:12 BST) aq(4): drop errored RX frames instead of resetting the interface aq_isc_rxd_pkt_get() returned EBADMSG when a receive descriptor's MAC/receive-error bit (rx_stat bit 0) was set. iflib treats any error from isc_rxd_pkt_get() as a fatal ring fault and answers with IFC_DO_RESET -- a full interface reinitialization. A per-frame receive error is not a ring fault: on a marginal link or cable the Atlantic delivers errored frames continuously, so each one triggered another reset and the interface reset-stormed itself into carrying no traffic instead of merely dropping the bad frames. The Atlantic delivers errored frames to the host by design (Linux drops them in software via buff->is_error), and iflib offers no per-frame error return that isn't a reset. Follow the vmxnet3 model: on a receive error zero the fragment lengths and return success. iflib then discards the packet (assemble_segments() excludes zero-length fragments) while still recycling the descriptors through the refill path -- no reset. Also drop frames flagged with an RX-DMA fault (rdm_err), not just the MAC-error bit; and keep iri_len non-zero on that drop path, since iflib asserts iri_len != 0. The genuinely structural errors -- more segments than isc_rx_nsegments, or a pkt_len inconsistent with the descriptor count -- still return EBADMSG, since those indicate a confused ring where a reset is the right recovery. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58136 (cherry picked from commit 73cd4048807dc0b3a5329bfc9a80ea4bf2d975fd) M sys/dev/aq/aq_ring.c _____________________________________________________________________________________________________________ Commit: 1a8240f5524b9fbc035e5aa11e4a9419e5c56380 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1a8240f5524b9fbc035e5aa11e4a9419e5c56380 Author: Nick Price (Sun 19 Jul 2026 17:40:36 BST) Committer: Ed Maste (Mon 31 Aug 2026 18:17:12 BST) aq(4): expand and correct offloads, fix VLAN/multicast filtering Advertise the offloads the hardware already performs, correct the TX descriptor's L3 family selection, and correct the VLAN and multicast receive-filter paths. Offloads: advertise IFCAP_HWCSUM_IPV6 (adding CSUM_IP6_TCP/UDP/TSO to isc_tx_csum_flags) and IFCAP_VLAN_HWTSO, and enable the RX outer (S-VLAN) tag parse mode in aq_hw_offload_set(). TX descriptor L3 family: aq_setup_offloads() derived tx_desc_cmd_ipv4 from CSUM_IP|CSUM_TSO, but CSUM_TSO is (CSUM_IP_TSO|CSUM_IP6_TSO) and tcp_output() sets both bits without regard to address family, so an IPv6 TSO frame matched on CSUM_IP_TSO and went out with the IPv4 header-checksum command set on a frame that carries no IPv4 header. The checksum flags cannot distinguish the family; key the bit off IPI_TX_IPV4 instead, which iflib derives from the parsed ethertype, as the IPI_TX_INTR test below it already does. Plain IPv6 checksum offload was unaffected, as CSUM_IP6_TCP alone never matched the mask. RX VLAN tag stripping: ring init hardwired hardware tag stripping off while the RX path still set M_VLANTAG and the writeback tag for every tagged frame, so a tagged frame arrived with the tag in line while the mbuf claimed it stripped and ether_demux() parsed four bytes short of the payload. Program per-ring stripping from IFCAP_VLAN_HWTAGGING and set M_VLANTAG only under the same capability, so the two states stay coherent. VLAN filter and promiscuous edge cases: filter only when 1..16 VLANs are registered -- with none (or more than the 16 the table holds) fall back to VLAN-promiscuous and pass all tags, rather than dropping every tagged frame against an empty filter table; and keep VLAN-promiscuous set whenever the interface is IFF_PROMISC, so adding or removing a VLAN under promisc does not clear it and start dropping tagged frames. Multicast reconcile: ifdi_multi_set is declarative, but aq_if_multi_set() only added -- shrinking the list left accept-all-multicast latched or stale exact slots enabled, defeating hardware multicast filtering until a reinit. Clear the exact slots before reprogramming the current list, and always drive accept-all-multicast from the current state so a shrink clears it. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D58145 (cherry picked from commit dcede1ec9de3b24fc9fbeeebc99ca34d226995f9) M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_hw_llh.c M sys/dev/aq/aq_hw_llh.h M sys/dev/aq/aq_hw_llh_internal.h M sys/dev/aq/aq_main.c M sys/dev/aq/aq_ring.c _____________________________________________________________________________________________________________ Commit: 9101ea2b061efd9eabd01b7450d256d25a049e4d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9101ea2b061efd9eabd01b7450d256d25a049e4d Author: Nick Price (Sat 20 Jun 2026 20:03:37 BST) Committer: Ed Maste (Mon 31 Aug 2026 18:17:12 BST) aq(4): naming and exposure Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D57656 (cherry picked from commit e44579e23430ff2084b03c9b3d486f05e617e04f) M sys/dev/aq/aq_fw.c M sys/dev/aq/aq_fw.h M sys/dev/aq/aq_fw1x.c M sys/dev/aq/aq_fw2x.c M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: c81e5aa8a52e524eb7e6be2016025ebc910e10de URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c81e5aa8a52e524eb7e6be2016025ebc910e10de Author: Cy Schubert (Sun 16 Aug 2026 04:24:45 BST) Committer: Cy Schubert (Mon 31 Aug 2026 17:34:42 BST) sqlite3: Vendor import of sqlite3 3.53.3 Release notes at https://www.sqlite.org/releaselog/3_53_3.html. Obtained from: https://www.sqlite.org/2026/sqlite-autoconf-3530300.tar.gz Merge commit 'e698feec080925c6cffa9ec31be884daa5cea536' (cherry picked from commit 14e3daa72db7d6410877481a4ed2791603e2b99f) M contrib/sqlite3/VERSION M contrib/sqlite3/autosetup/sqlite-config.tcl M contrib/sqlite3/shell.c M contrib/sqlite3/sqlite3.c M contrib/sqlite3/sqlite3.h M contrib/sqlite3/sqlite3rc.h _____________________________________________________________________________________________________________ Commit: 3dccdfefdca85574a84a280bc852a9e3477e0837 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3dccdfefdca85574a84a280bc852a9e3477e0837 Author: Cy Schubert (Mon 25 May 2026 18:19:28 BST) Committer: Cy Schubert (Mon 31 Aug 2026 17:34:41 BST) sqlite3: Vendor import of sqlite3 3.53.1 Release notes at https://www.sqlite.org/releaselog/3_53_1.html. Obtained from: https://www.sqlite.org/2026/sqlite-autoconf-3530100.tar.g Merge commit 'b00eb376e3fb28e738f9370552dae9d92c1fdd76' into sqlite3 (cherry picked from commit 5b8f59e648431715e8f5f60ef09c0be4508b3ae6) M contrib/sqlite3/Makefile.in M contrib/sqlite3/Makefile.msc M contrib/sqlite3/VERSION M contrib/sqlite3/autosetup/README.md M contrib/sqlite3/autosetup/autosetup M contrib/sqlite3/autosetup/cc-shared.tcl M contrib/sqlite3/autosetup/jimsh0.c M contrib/sqlite3/autosetup/proj.tcl M contrib/sqlite3/autosetup/sqlite-config.tcl M contrib/sqlite3/autosetup/teaish/core.tcl M contrib/sqlite3/autosetup/teaish/tester.tcl A contrib/sqlite3/make.bat M contrib/sqlite3/shell.c M contrib/sqlite3/sqlite3.1 M contrib/sqlite3/sqlite3.c M contrib/sqlite3/sqlite3.h M contrib/sqlite3/sqlite3ext.h M contrib/sqlite3/sqlite3rc.h M contrib/sqlite3/tea/Makefile.in M contrib/sqlite3/tea/README.txt M contrib/sqlite3/tea/_teaish.tester.tcl.in M contrib/sqlite3/tea/configure D contrib/sqlite3/tea/doc/sqlite3.n M contrib/sqlite3/tea/generic/tclsqlite3.c M contrib/sqlite3/tea/teaish.tcl _____________________________________________________________________________________________________________ Commit: eaf43978093835391d17ff6cb9294579108e5c18 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=eaf43978093835391d17ff6cb9294579108e5c18 Author: Nick Price (Sat 20 Jun 2026 20:03:28 BST) Committer: Ed Maste (Mon 31 Aug 2026 17:17:58 BST) aq(4): add a runtime dev.aq.N.debug trace control The trace_* family (trace/trace_error/trace_warn/trace_detail, used in the F/W and init/config paths) was gated behind the compile-time AQ_CFG_DEBUG_LVL, which is 0, so the dbg_level_/dbg_categories_ runtime variables were dead and tracing could only be enabled by recompiling. Decouple trace_base_ from AQ_CFG_DEBUG_LVL so it is always compiled and gated purely at runtime on dbg_level_/dbg_categories_, make those two variables writable (no longer const, default level 0 = off), and expose them as dev.aq.N.debug (verbosity) and dev.aq.N.debug_categories (subsystem mask) sysctls. The datapath-heavy AQ_DBG_ENTER/PRINT/DUMP macros and the trace_aq_*_descr descriptor dumps stay behind AQ_CFG_DEBUG_LVL (still 0), so the per-packet paths are untouched -- trace_* is only used off the datapath. The two variables are global (the trace macros reference them directly), so the per-device sysctls share one backing store, which is fine for a debug knob. Validated on AQC107: dev.aq.0.debug defaults to 0 with no trace output; setting it to 6 emits the F/W init/reset/capabilities traces on the next F/W operation; setting it back to 0 silences them; traffic unaffected at line rate, rx_err=0. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D57440 (cherry picked from commit 76d0a25be3976634631bab975f4c2ddbc98f72a2) M sys/dev/aq/aq_dbg.c M sys/dev/aq/aq_dbg.h M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: bf5229dbbe158ffb7dc376293cefb20e5eb7af20 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bf5229dbbe158ffb7dc376293cefb20e5eb7af20 Author: Nick Price (Sat 20 Jun 2026 20:03:18 BST) Committer: Ed Maste (Mon 31 Aug 2026 17:17:57 BST) aq(4): take F/W statistics off the iflib core lock (kick-and-read) The once-per-second statistics refresh ran the whole F/W-mailbox transaction under iflib's CTX (sx) lock: fw2x_get_stats toggled the MPI STATISTICS control bit and busy-polled the state register for the acknowledgement (up to ~25 ms) before downloading the counters, so a slow F/W response blocked datapath reconfigure / ioctls for the duration. The per-cast and error counters have no direct-register source -- the reference Linux atlantic driver and our port both read them out of the F/W mailbox, and the MSM registers the chip exposes are never used for the periodic counters. So rather than poll, adopt the kick-and-read shape the iflib peer with the same constraint uses (vmxnet3): consume the snapshot the F/W produced for the *previous* request, then toggle the bit to request the next one -- no wait. The F/W finished that previous refresh ~1 s ago, so the download needs no poll, and the toggle write stays serialized against set_mode by the CTX lock exactly as before. This removes the 25 ms poll (and the toggle_mpi_ctrl_and_wait_ helper) from under the lock; only the fast 16-dword download remains. Cost: the counters lag one 1 s cycle, invisible for monitoring, and a torn read is already rejected by aq_update_hw_stats' monotonic-delta check. Validated on AQC107: a fixed 500 MiB RX transfer advances good_octets_rcvd by 549.6 MB -- 500 MiB plus the ~4.8% Ethernet framing overhead -- with rx_err=0 and traffic at line rate. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D57439 (cherry picked from commit a10151fa662c1d370861154e2f83e88a20be149c) M sys/dev/aq/aq_fw2x.c _____________________________________________________________________________________________________________ Commit: 4e40b09cd46aa6b458b18d455764a55710493e79 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4e40b09cd46aa6b458b18d455764a55710493e79 Author: Nick Price (Sat 20 Jun 2026 20:03:09 BST) Committer: Ed Maste (Mon 31 Aug 2026 17:17:57 BST) aq(4): modernize and de-Linuxify the vendor driver Dead-code removal, device_printf(9) logging, style(9) de-Linuxification, const F/W-ops tables, and readability cleanups. No change for valid traffic. Dead code and logging: - Remove the sub-gigabit TSO-masking block in the link-state ISR: it cleared IFCAP_TSO from the static isc_capabilities record (read only at attach / SIOCSIFCAP, never on the datapath), so it never gated TSO and only corrupted the validation mask. The Atlantic has no sub-gigabit TSO erratum. - Tidy the RX buffer-size handling: drop the dead switch(MCLBYTES) in aq_if_rx_queues_alloc, rename rx_max_frame_size -> rx_buf_size, and bound the per-fragment length from the wb.pkt_len writeback (EBADMSG on underflow or a final fragment longer than the RX buffer). - Drop every __FreeBSD__/__FreeBSD_version branch (FreeBSD 14.0 baseline); the pre-13 arms used pre-opaque-if_t APIs since removed and one never built. - Route all log messages through device_printf(9) (MAC via %6D), adding a device_t to struct aq_hw; drop the dead AQ_XXX_UNIMPLEMENTED_FUNCTION and aq_log_error macros and the per-ring init console spam. - Minor: comma -> semicolon in aq_if_attach_pre; (uint64_t) -> (uint32_t) TX high-word cast; MODULE_VERSION(atlantic, 1); remove unused/duplicate #includes. style(9) and types: - Remove all typedef'd struct/enum/union types (aq_dev_t, the speed/fc/ debug enums, the volatile RX/TX descriptor types, the firmware-file types) in favor of bare tags; for the DMA descriptors the volatile qualifier moves to the pointer/use sites. Drop the _s/_e tag suffixes and the "#define aq_hw_s aq_hw" alias. Rename the OOP-style *self parameter to hw. Replace usec_delay/msec_delay/ARRAY_SIZE/LOWORD with FreeBSD equivalents (BIT kept). __attribute__((__packed__)) -> __packed. F/W-ops vtable: - Rename the leftover hal parameter to hw; make aq_fw1x_ops/aq_fw2x_ops const (read-only data); drop the always-true "fw_ops &&" and always-present dispatch guards (only led_control, absent in F/W 1.x, keeps its NULL check). Readability: - aq_isc_rxd_pkt_get: fold the four identical RX-error blocks into one rx_err: label. aq_isc_rxd_available: hoist the shared descriptor advance out of the EOP test and drop the redundant continue. aq_hw_offload_set: drop the dead "int err = 0". Fix a stale "10 ms" comment on a 50 ms DELAY and the redundant literal parentheses. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D57438 (cherry picked from commit 5409e03a0ef1f2d71da94bedd433fbaa7b6b21f2) M sys/dev/aq/aq_common.h M sys/dev/aq/aq_dbg.c M sys/dev/aq/aq_dbg.h M sys/dev/aq/aq_device.h M sys/dev/aq/aq_fw.c M sys/dev/aq/aq_fw.h M sys/dev/aq/aq_fw1x.c M sys/dev/aq/aq_fw2x.c M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_hw_llh.c M sys/dev/aq/aq_irq.c M sys/dev/aq/aq_main.c M sys/dev/aq/aq_media.c M sys/dev/aq/aq_ring.c M sys/dev/aq/aq_ring.h _____________________________________________________________________________________________________________ Commit: 2cb719337fb79c5903873b164c55abcc940da91c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2cb719337fb79c5903873b164c55abcc940da91c Author: Nick Price (Sat 20 Jun 2026 20:03:00 BST) Committer: Ed Maste (Mon 31 Aug 2026 17:17:57 BST) aq(4): enable jumbo frames, software LRO, and suspend/resume - Configure the RX buffer size from the interface MTU and enable jumbo frames up to 9000 bytes, replacing the fixed standard-frame setup. - Advertise IFCAP_LRO so iflib coalesces received TCP segments with its software tcp_lro(9), like every other in-tree iflib driver (ix/igc/em/vmxnet3); aq does no hardware LRO. iflib builds the per-RX-queue LRO context unconditionally, so the capability bit is all that is required; enabled by default via isc_capenable, toggle at runtime with ifconfig. - Add suspend/shutdown/resume handlers, replacing the unimplemented- function placeholders. aq_if_shutdown/aq_if_suspend stop the interface and deinitialize the hardware; aq_if_resume re-resets the F/W, re-reads the mailbox address and re-selects fw_ops via aq_hw_mpi_create() before iflib re-inits, because the runtime init path (aq_hw_init) reuses the cached mailbox/fw_ops and a D3 power cycle can clear them. iflib calls IFDI_RESUME unconditionally, so this also covers resuming while the interface was administratively down. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D57437 (cherry picked from commit b64408358d7f27a69b84d9fd1e23e239e8bd00fc) M sys/dev/aq/aq_main.c M sys/dev/aq/aq_ring.c _____________________________________________________________________________________________________________ Commit: a02ea75c8d5b5e8802890ff21976b629cbc2a1b3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a02ea75c8d5b5e8802890ff21976b629cbc2a1b3 Author: Nick Pricenull (Sat 20 Jun 2026 20:02:52 BST) Committer: Ed Maste (Mon 31 Aug 2026 17:17:57 BST) aq(4): RX/TX and HW-path correctness and hardening Independent correctness fixes, plus robustness against a non-responding device, malformed descriptor writeback, and torn MMIO reads, and the move to the FreeBSD bus_space(9) register abstraction. Correctness: - aq_hw_ver_match returned true if any of major/minor/build was >= expected; compare lexicographically so e.g. 2.0.1 is correctly seen as older than 2.1.0. - The VLAN hardware-filter iteration used the vlan tag directly as the bitstring index; use vlan_tag + 1 so the active-VLAN bookkeeping lines up with the table. - aq_initmedia only registered IFM_AUTO in full-duplex/pause variants, so a bare "ifconfig aq0 media autoselect" matched no entry and returned ENXIO. Add the bare IFM_ETHER|IFM_AUTO entry, matching ix/em/igc/ixv. - Convert the per-ring diagnostic counters to counter(9): per-CPU, tear-free, no atomics on the increment path, fixing a data race and a 32-bit torn read against the locklessly-read sysctls. Drop three counters that were never populated (jumbo_pkts, tx_drops, tx_queue_full). Hardening and modernization: - Implement aq_hw_err_from_flags (previously a stub returning 0 that left ~24 call sites as no-ops): detect a non-responding device in the register read path (all-ones, confirmed against reg 0x10) and latch a sticky AQ_HW_FLAG_ERR_UNPLUG -> ENXIO; aq_if_init clears it so a transient detection cannot permanently wedge the device. - Bound the RX fragment loop in aq_isc_rxd_pkt_get (EBADMSG once i reaches isc_rx_nsegments) so a malformed never-EOP stream cannot write past the fragment array. - Bound the TX completion count in aq_isc_txd_credits_update against the raw HW head pointer (reject head >= tx_size) so a glitched head cannot make iflib free still-in-flight TX mbufs. - Remove the dead hardware-RSC branch in aq_isc_rxd_available; it followed wb.next_desp, a raw device value used as an index, but RSC is never enabled so rsc_cnt is always 0. Advance sequentially like the other in-tree iflib drivers; this drops the last raw-hardware-pointer dereference in the RX path. - Flush MMIO after interrupt-status acks (AQ_HW_FLUSH) so the write lands before the vector is re-armed under auto-mask-clear; retry the high word in read64_ against a torn lo/hi pair; document the non-atomic IMR read-modify-write in itr_irq_map_en_{rx,tx}_set. - Replace the raw-pointer MMIO (the Linux readl/writel idiom) with bus_space(9): store the BAR tag and handle in struct aq_hw and route AQ_READ_REG/AQ_WRITE_REG through bus_space_read_4/write_4. No functional change on amd64. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D57436 (cherry picked from commit 619934a5c165869604810ece91c2f2cb734fc3eb) M sys/dev/aq/aq_fw2x.c M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_irq.c M sys/dev/aq/aq_main.c M sys/dev/aq/aq_media.c M sys/dev/aq/aq_ring.c M sys/dev/aq/aq_ring.h _____________________________________________________________________________________________________________ Commit: 73760c8fcd61939f88d2b1f001d9d1e07b470940 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=73760c8fcd61939f88d2b1f001d9d1e07b470940 Author: Nick Price (Sat 20 Jun 2026 20:02:42 BST) Committer: Ed Maste (Mon 31 Aug 2026 17:17:57 BST) aq(4): adopt native FreeBSD errno convention Convert the driver's internal error-handling chain from the Linux negative-errno convention to FreeBSD positive errno everywhere. - All `return (-EXXX)` become `return (EXXX)`, `int err = -EXXX` loses the sign, and `if (err < 0)` checks become `if (err != 0)` across aq_fw.c, aq_fw1x.c, aq_fw2x.c and aq_hw.c. - mac_soft_reset_flb_ returns ETIMEDOUT/0 instead of a bool so it matches its RBL sibling. - The ETIME and EOK aliases in aq_common.h are removed; all sites use ETIMEDOUT and 0 directly, and the `rc = -rc` sign flips in aq_if_attach_pre are dropped. Turn AQ_HW_WAIT_FOR into a statement expression evaluating to 0 on success or ETIMEDOUT on timeout, assigned explicitly at all seven call sites, instead of silently assigning ETIMEDOUT to a variable named err in the caller scope. A statement expression rather than an inline function because every call must re-evaluate its condition each iteration -- one even assigns hw->mbox_addr as a side effect. Fix two correctness bugs surfaced by the conversion: - fw1x_get_stats gated its stats copy with `if (err >= 0)`, correct under negative errno but accepting every positive errno after the flip. Change to `if (err == 0)`. - fw2x_reset returned 0 regardless of capability-download failure, silently leaving fw_caps = 0. Return the real err. Harden aq_if_attach_pre: bit_alloc(4096, M_AQ, M_NOWAIT) was unchecked, so under OOM a later `ifconfig vlanN create` would NULL-deref the bitstring; check for NULL and fail with ENOMEM. The fail label's hardcoded `return (ENXIO)` becomes `return (rc)` so each error path reports its real errno. Remove the dead error checks in aq_hw_offload_set: the `if (err != 0) goto err_exit` blocks after the void tpo_/rpo_/tdm_ register-write helpers were unreachable (err is never set), and the real error capture is the aq_hw_err_from_flags call at the function tail. Drop the now-orphaned err_exit label. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D57435 (cherry picked from commit 40accc7235c2f0d2072f051099d183e7f21c2731) M sys/dev/aq/aq_common.h M sys/dev/aq/aq_fw.c M sys/dev/aq/aq_fw1x.c M sys/dev/aq/aq_fw2x.c M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: c2328207920578b12bd7fbb5fda31651874a7fa1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c2328207920578b12bd7fbb5fda31651874a7fa1 Author: Nick Pricenull (Sat 20 Jun 2026 20:02:34 BST) Committer: Ed Maste (Mon 31 Aug 2026 17:17:57 BST) aq(4): interrupt model and queue-count correctness Rework the MSI-X and queue-count handling to use the standard iflib interrupt model and to keep every ring serviced. - Cap isc_n{tx,rx}qsets_max at the RSS indirection-table size (HW_ATL_RSS_INDIRECTION_QUEUES_MAX, 8) instead of HW_ATL_B0_RINGS_MAX. RSS only steers RX traffic to eight rings, so on hosts with more CPUs the surplus TX rings never make progress: iflib flowid-steers TCP flows across every TX ring, and a flow landing on a surplus ring has its segments queued but never transmitted, hanging the connection. - Add a TX-specific ifdi_tx_queue_intr_enable that reads tx_rings[txqid]->msix. It was wired to the RX handler, which indexes rx_rings[] with the qid; safe only while tx_rings_count == rx_rings_count, otherwise the lookup walks past rx_rings[] and feeds a garbage msix value into the IRQ mask register. - Fix three MSI-X / admin-IRQ bugs: the TX softirq was attached to rx_rings[i]->irq (overwriting the RX handle and leaving the TX handle uninitialized); the admin-IRQ failure path dereferenced rx_rings[rx_rings_count], one past the end; and aq_linkstat_isr cleared the admin interrupt by writing the raw vector number instead of BIT(vector). - Allocate one IFLIB_INTR_RXTX vector per RX/TX queue pair like every other in-tree iflib driver (em/ix/igc, vmxnet3) instead of an IFLIB_INTR_RX vector per RX ring plus a hand-wrapped IFLIB_INTR_TX softirq per TX ring. iflib's iflib_fast_intr_rxtx() then services TX completions on the shared vector through isc_txd_credits_update(). Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D57434 (cherry picked from commit b065af196fdcab18d36caae214c905467723b3f1) M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_irq.c M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: 682aec20a2142c1cb45019905b732d61f9659efd URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=682aec20a2142c1cb45019905b732d61f9659efd Author: Nick Price (Sat 20 Jun 2026 20:02:22 BST) Committer: Ed Maste (Mon 31 Aug 2026 17:17:57 BST) aq(4): Fix RSS indirection table OOB write and queue distribution Two related fixes to `aq(4)`'s RSS indirection table handling: 1. Fix an out-of-bounds stack write in `aq_hw_rss_set()`. RSS table entries are 3 bits (8 queues max), but with more than 8 RX rings `rss_table[]` holds larger values; the 32-bit write then spills one `uint16_t` past `bitary[]` and corrupts the stack, so the NIC never links or the kernel panics. Mask each value to 3 bits and pack 16 bits at a time to keep the write in bounds. 2. Build the indirection table in `aq_if_attach_post()` with a modulo over `min(rx_rings_count, HW_ATL_RSS_INDIRECTION_QUEUES_MAX)` instead of `i & (rx_rings_count - 1)`, which assumed a power-of-two ring count. Reviewed by: adrian Differential Revision: https://reviews.freebsd.org/D57240 (cherry picked from commit 57f5252ff8a17aa837f677638cce5885b8a5fb3b) M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: 8b10eb844c4b3205683fa5a4599c274fd89c52d8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8b10eb844c4b3205683fa5a4599c274fd89c52d8 Author: Kristof Provost (Tue 21 Jul 2026 14:03:24 BST) Committer: Kristof Provost (Mon 31 Aug 2026 08:45:39 BST) pf: fix securelevel off-by-one cmd_securelevel is the securelevel at which the call should be denied. pf (write) calls should be denied at level 3 or up (not at 2 or up as it was), so increment these all by one. PR: 296838 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296838 ) MFC after: 4 weeks Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D58377 (cherry picked from commit d13dffa150d17dc239e164ea42ddab91e6fab466) M sys/netpfil/pf/pf_nl.c _____________________________________________________________________________________________________________ Commit: 8a6c20aee2fae9bca0c81dde271f7362c9ac3bb3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8a6c20aee2fae9bca0c81dde271f7362c9ac3bb3 Author: Kevin Bowling (Thu 30 Jul 2026 03:26:48 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:43:22 BST) igb: Guard register dump during queue setup The register-dump sysctl is installed before iflib allocates the queue arrays and remains visible while they are freed. Return ENXIO outside the queue lifetime instead of dereferencing a NULL or stale array. Sponsored by: BBOX.io (cherry picked from commit bcb62ec0e3d592892f0f304269ed2722d1bae75a) M sys/dev/e1000/if_em.c _____________________________________________________________________________________________________________ Commit: b91c0fc86c7d89124d4fcdeba2ad86e202c76fb8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b91c0fc86c7d89124d4fcdeba2ad86e202c76fb8 Author: Kevin Bowling (Wed 29 Jul 2026 00:29:35 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:42:37 BST) pci_iov: Permit non-ARI VFs on a secondary bus A non-zero VF device number does not always require ARI. The Intel 82576 and I350 [1] explicitly support a non-ARI layout that places VFs on the next bus. Check every requested VF RID and reject a non-zero device only when it is on the PF bus. This retains the ARI guard for invalid same-bus layouts while permitting the documented second-bus layout. [1] Intel I350 Datasheet, sections 7.8.2.6.1.2, 9.6.4.6 Sponsored by: BBOX.io (cherry picked from commit e795a31cb4d66368bdbe5ac7f61c0899d3ed39f8) M sys/dev/pci/pci_iov.c _____________________________________________________________________________________________________________ Commit: 7827d437dc88cc3bb341691fd0c04622175a371a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7827d437dc88cc3bb341691fd0c04622175a371a Author: Kevin Bowling (Sun 16 Aug 2026 08:02:25 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:37:19 BST) e1000: Recover from the 82574 PHY hang The shared code provides e1000_check_phy_82574() to recognize a PHY hang from saturated receive error and idle error counters, but em(4) never calls it. Run the check from timer driven admin work. Match Intel e1000e by requiring two consecutive positive samples before requesting a full iflib reset. MFC after: 2 weeks Sponsored by: BBOX.io (cherry picked from commit 81d5356799a1db1701cb3f91146131c34dede413) M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: b27c5cfc7e7673a2d63349261f483a0f3472af4c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b27c5cfc7e7673a2d63349261f483a0f3472af4c Author: Kevin Bowling (Wed 29 Jul 2026 10:11:19 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:36:29 BST) e1000: Sample statistics at timer cadence Mailbox and link interrupts share iflib admin service with the periodic timer. Mark timer-driven passes explicitly and run the hardware statistics sweep only for those samples instead of repeating 66 PF MMIO reads for every VF mailbox message. DTrace on the I350 DUT measured the PF sweep at about 79 us on average. The normal hz/2 timer continues to extend clear-on-read counters safely; exported counters may trail hardware by up to 500 ms. Sponsored by: BBOX.io (cherry picked from commit d2cd0b57532ba35fe39744a60d53b90e6f13b5e4) M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 640916dc50a6fd88eddad312f9e0e21404211f52 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=640916dc50a6fd88eddad312f9e0e21404211f52 Author: Kevin Bowling (Sun 16 Aug 2026 08:56:03 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:32:08 BST) igc: Propagate hardware initialization failures The reset helper discards igc_reset_hw and igc_init_hw errors. Runtime initialization then continues programming rings and filters, and iflib publishes the interface as running even though the controller did not reach a usable state. Initial attach similarly continues into NVM and MAC setup after a failed reset. Return errors from the reset helper. Fail attach when the controller cannot be reset or initialized, and report runtime failures through iflib_init_failed() so iflib leaves the interface stopped. Also stop register accesses and report the error when a stop path reset fails. A later successful initialization completes pending fatal error cleanup and re-arms FER. Cache a requested MAC address before reset, but let init_hw program RAR0 after reset succeeds. Let iflib perform its normal attach-post failure cleanup instead of releasing the same driver resources from both layers, and make queue cleanup idempotent. Sponsored by: BBOX.io (cherry picked from commit c82a015ede8d49aabc8bb253b7597b8db0f42524) M sys/dev/igc/if_igc.c _____________________________________________________________________________________________________________ Commit: df5bdb59bc89365d06296cab813cad33807e94e1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=df5bdb59bc89365d06296cab813cad33807e94e1 Author: Kevin Bowling (Sun 16 Aug 2026 08:55:37 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:31:48 BST) e1000: Propagate hardware initialization failures The reset helper discards reset_hw and init_hw errors. Runtime initialization then continues programming rings and filters, and iflib publishes the interface as running even though the controller did not reach a usable state. Initial attach similarly continues into NVM and MAC setup after a failed reset. Return errors from the reset helper. Fail attach when the controller cannot be reset or initialized, and report runtime failures through iflib_init_failed() so iflib leaves the interface stopped. Also stop register accesses and report the error when a stop-path reset fails. Sponsored by: BBOX.io (cherry picked from commit 41a0f7a0a447ef2092faadb35f6d4c3f80c088bf) M sys/dev/e1000/if_em.c _____________________________________________________________________________________________________________ Commit: d7f7fb0dacf2fe05b1a6d5184d86422bb1395281 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d7f7fb0dacf2fe05b1a6d5184d86422bb1395281 Author: Kevin Bowling (Sun 16 Aug 2026 07:58:18 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:28:03 BST) igb: Reinitialize through iflib after media changes A media change can require a complete controller reset. Resetting the controller directly from the admin task leaves iflib rings, filters, and interface state programmed for the pre-reset controller. Request an iflib reset for every media change. This already was done when SR-IOV was active; use the same lifecycle for the ordinary PF case. Sponsored by: BBOX.io (cherry picked from commit 6248e7de9d6c0f14294afc5792170a68de6a3b53) M sys/dev/e1000/if_em.c _____________________________________________________________________________________________________________ Commit: 9ff3e1cd31792202c0e7c7fdaf877e1fc6c54269 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9ff3e1cd31792202c0e7c7fdaf877e1fc6c54269 Author: Kevin Bowling (Sun 16 Aug 2026 06:40:44 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:28:02 BST) e1000: Report 82575 memory ECC errors 82575 exposes clear-on-read, saturating counters for corrected and uncorrected errors in the packet buffer and the receive and transmit descriptor handlers. Sample all three status registers together from the regular hardware statistics update. When an unrecoverable event interrupts first, count the values captured by the interrupt filter so the clear-on-read status is not lost before the admin task handles it. Expose packet buffer and descriptor handler counters under the existing memory_errors sysctl node. Hardware validation used an 82575EB revision 2 and the documented PBEEI, RDHEEI, and TDHEEI injectors. Correctable and uncorrectable TX/RX packet-buffer errors and receive/transmit descriptor-handler errors advanced the corresponding counters. The controls and accounting survived repeated recovery resets and an ordinary interface down/up. Sponsored by: BBOX.io (cherry picked from commit 7accd803e28cf6051cac69e614eec6f24d5c77cc) M sys/dev/e1000/if_em.c _____________________________________________________________________________________________________________ Commit: 06730a0673601f6828242f45261df6e383d406fa URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=06730a0673601f6828242f45261df6e383d406fa Author: Kevin Bowling (Sun 16 Aug 2026 06:39:31 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:27:59 BST) e1000: Recover from 82575 memory errors 82575 protects its packet buffer and receive and transmit descriptor handlers with ECC. Correctable errors are repaired in hardware. Packet data errors are contained to the affected packet, while the native RX_PBUR, TX_PBUR, RX_DHER, and TX_DHER interrupt causes report unrecoverable packet buffer or descriptor handler state. The affected traffic direction remains stopped until software resets the port. Enable the three ECC blocks and hardware memory error reaction after queue and filter initialization. Capture the clear-on-read status registers in the interrupt filter and keep all four native causes masked while the iflib admin task owns the event. Request port reinitialization for every native PBUR or DHER cause. Packet data errors that do not raise a native cause remain count-only and do not disrupt the port. The captured status registers provide diagnostics and accounting but do not independently initiate recovery. Hardware validation used an 82575EB revision 2 and the documented PBEEI, RDHEEI, and TDHEEI injectors. Correctable TX/RX packet data and descriptor fetch/writeback errors preserved traffic. Uncorrectable TX/RX packet buffer header and descriptor fetch/writeback errors each requested one reset, restored traffic, and rearmed every ECC control. Repeated recovery produced no watchdogs. Sponsored by: BBOX.io (cherry picked from commit 24917c22a330e8da350e8ef1a251a70abf0baf83) M sys/dev/e1000/e1000_defines.h M sys/dev/e1000/e1000_regs.h M sys/dev/e1000/if_em.c _____________________________________________________________________________________________________________ Commit: 0a3c4415a9b6e0c7c7039e84b69fcd95d1124984 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0a3c4415a9b6e0c7c7039e84b69fcd95d1124984 Author: Kevin Bowling (Fri 14 Aug 2026 00:15:39 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:24:10 BST) e1000: Report 82576 memory ECC errors 82576 exposes clear-on-read corrected error counters for RX, TX, switch, IPsec, descriptor-handler, PCIe retry, PCIe write, and MSI-X memories. The packet and descriptor memories also count uncorrectable errors. Sample each status register exactly once from the regular hardware statistics update and immediately before handling a memory-error interrupt. Group the counters by packet buffer, descriptor handler, and PCIe region. Skip the absent IPsec block on 82576NS. PRBESTS and PMSIXESTS are shared by both LAN ports. Attribute an indication to whichever attached port samples the clear-on-read register first so it is not counted twice. Hardware validation used an 82576EB revision 1. All nine implemented status registers reported their ECC-enable bit set. The sysctl counters remained clear across interface lifecycle, two-stream line-rate traffic, and NFER and FER cause injections. Each reset preserved the ECC enables while the driver restored PEINDM reactions. ICR cause injection does not corrupt SRAM, and the only documented data injector is specific to the IPsec packet buffer. Exact counter increments for the other memories were therefore validated against the register definitions rather than an injected ECC error. Sponsored by: BBOX.io (cherry picked from commit 17042fd31571c7ceb955570ef43c9921d4a80f21) M sys/dev/e1000/e1000_defines.h M sys/dev/e1000/e1000_regs.h M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 35e9e0d246a0164e6d548ea44d0200b59d0753c9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=35e9e0d246a0164e6d548ea44d0200b59d0753c9 Author: Kevin Bowling (Fri 14 Aug 2026 00:10:47 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:24:07 BST) e1000: Recover from 82576 memory errors 82576 reports fatal and non-fatal internal memory errors through ICR.FER and ICR.NFER and identifies the affected memory in its native PEIND layout. Fatal errors can stop transmit, receive, or both until software resets and reinitializes the port. Enable the controller-wide parity detector and implemented PEINDM reaction bits after hardware initialization, while preserving unrelated register state and omitting the absent IPsec memories on 82576NS. Enable both interrupt causes and capture the read-clear PEIND register in the interrupt filter. Keep the causes masked while the iflib admin task owns the event. Acknowledge non-fatal packet data errors without disrupting the port. Request normal port reinitialization for FER, a fatal PEIND source, or the memory hang indication. Do not apply the later I210/I350 register layout or their special PCIe parity reset order. Hardware validation used a dual-port 82576EB revision 1. Firmware left PEINDM at its 0x80000000 default; initialization explicitly programmed the parity-enable bit and produced 0xffffff07 on both ports. An NFER during two-stream TCP sustained line rate without a reset, watchdog, or carrier event. FER on the linked and disconnected ports each requested exactly one reset. The linked port resumed the existing TCP sessions after autonegotiation. PEINDM and both interrupt causes were restored after every reset. The injections set the ICR causes without corrupting SRAM, so their empty PEIND values deliberately exercised the unknown source path. Sponsored by: BBOX.io (cherry picked from commit 4c2dda4c70e210be4efb4527fc32fbb79f23d452) M sys/dev/e1000/e1000_defines.h M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 8b4ba2a11f4003735852f5e1371b21a3a727bd5f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8b4ba2a11f4003735852f5e1371b21a3a727bd5f Author: Kevin Bowling (Thu 13 Aug 2026 00:35:43 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:16:22 BST) e1000: Report corrected I350 ECC errors I350 does not interrupt for corrected internal ECC errors. Instead, the PCIe, DMA, packet buffer, loopback, and management memories expose sticky status bits in their region-specific status registers. Sample those bits with the regular hardware statistics update, preserve the RX and TX packet buffer ECC enable state while clearing RW1C indications, and expose counters grouped by memory region. Each counter records observed indication bits rather than exact error counts because repeated corrections between samples collapse into one sticky bit. On an I350 (8086:1521 revision 1), the ECC enables remained set. All corrected-error status registers remained clear across boot, interface down/up, three FER recovery resets, and bidirectional line-rate traffic. The device has no documented corrected error injector. Therefore, the per-region paths were validated against the register definitions rather than an injected SRAM error. Sponsored by: BBOX.io (cherry picked from commit 8367882d531313eea68966b07ddf917e39690b77) M sys/dev/e1000/e1000_defines.h M sys/dev/e1000/e1000_regs.h M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 7502726c3edf7f2052051f3c28200c6d21409b83 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7502726c3edf7f2052051f3c28200c6d21409b83 Author: Kevin Bowling (Thu 13 Aug 2026 00:34:56 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:16:12 BST) e1000: Recover from I350 memory errors I350 reports uncorrectable internal memory errors through ICR.FER and identifies the affected region in PEIND. Depending on the region and memory, hardware stops transmit, receive, or all PCIe and DMA traffic until the port is reset and reinitialized. Enable FER and all regional indication masks. Capture the read-clear status in the interrupt filter. Record the fatal PCIe, DMA, and LAN status registers, keep FER masked while recovery is pending, and expose per-region indication counters. Use the datasheet required port reset before master disable order for PCIe parity errors. Reset for PCIe, DMA, and traffic-affecting LAN errors. Statistics and VF-mailbox parity errors only require their status to be discarded and cleared; management-memory recovery remains under firmware control. Validated on an I350 (8086:1521 revision 1). Three software-set FER interrupts each advanced the unknown-region counter once, requested a single reset, restored carrier and traffic, and left FER rearmed without a watchdog. The software-set cause has no subordinate error status, so region attribution and region-specific clearing remain datasheet-based. Sponsored by: BBOX.io (cherry picked from commit 28bbe1d28d6f1e68e2ee3b34686ccb6114c42ca7) M sys/dev/e1000/e1000_defines.h M sys/dev/e1000/e1000_regs.h M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 1b008564a31b4baaaa3f9cb16fdf83c2b28967ba URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1b008564a31b4baaaa3f9cb16fdf83c2b28967ba Author: Kevin Bowling (Wed 12 Aug 2026 19:34:15 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:16:01 BST) e1000: Report corrected I210 and I211 ECC errors I210 and I211 do not interrupt for corrected internal ECC errors. Instead, the DMA packet-buffer and PCIe memories expose sticky status bits in PBECCSTS and PCIEECCSTS. Sample these bits with the regular hardware statistics update, preserve the I210/I211 PBECCSTS enable state while clearing its RW1C indication, and expose separate counters for the DMA packet buffer, PCIe transmit data, and PCIe retry buffer. The counters represent observed indications rather than exact error counts because multiple corrections between samples collapse into one sticky status bit. Hardware validation used an I210 revision 3. Unlike I225 and I226, the published I210/I211 register definitions do not expose self-clearing injectors for these corrected ECC memories. The three counter sysctls were present and remained zero under line-rate traffic and three fatal LAN parity recoveries. PBECCSTS.ECC_ENABLE remained set after every reset. Actual corrected-error accounting was therefore not injected. Sponsored by: BBOX.io (cherry picked from commit 0ea53a7123ffc1ea11daa748e7148ac8413fd2de) M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 21237fae3a1003bbb0b261f6045ce64481d9ac50 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=21237fae3a1003bbb0b261f6045ce64481d9ac50 Author: Kevin Bowling (Wed 12 Aug 2026 19:33:39 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:15:54 BST) e1000: Recover from I210 and I211 memory errors I210 and I211 report uncorrectable internal memory errors through ICR.FER and identify the affected region in PEIND. Depending on the region, hardware stops transmit or all PCIe and DMA traffic until the port is reset and reinitialized. Enable FER and all regional indication masks. Discard indication state left by firmware before enabling reactions, capture the read-clear status in the interrupt filter, and keep the cause masked while recovery is pending. Report the affected regions and expose per-region indication counters. Management-only errors remain under firmware control. PCIe region parity errors require a different recovery order from the normal reset path. Assert the port-local CTRL.RST bit, wait at least 3 ms, verify reset completion, disable master requests, clear PCIEERRSTS, and then enter normal port reinitialization. Do not use the device-wide CTRL.DEV_RST sequence used by I225 and I226. Hardware validation used an I210 revision 3 and the self-clearing LANPERRINJ retransmit-buffer bit 9. It injected a real parity error without synthesizing interrupt or status state. Three injections in one boot produced the following result each time: Observed hardware status Result PEIND 0x1, LANPERRSTS 0x200 Reset and recovered fatal_lan advanced exactly once per injection. All tests completed without a panic or watchdog, and FER and the LAN parity masks remained enabled after every recovery. Sponsored by: BBOX.io (cherry picked from commit 8d2d6284bb8ca168f6173c8836a40711b5f34e13) M sys/dev/e1000/e1000_defines.h M sys/dev/e1000/e1000_regs.h M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 78127a3ef671f16f554f9a5ba89d75c743e2e577 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=78127a3ef671f16f554f9a5ba89d75c743e2e577 Author: Kevin Bowling (Sun 9 Aug 2026 09:35:58 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:11:48 BST) ixgbe: Add missing mailbox API 1.6 definition The SR-IOV status change reports mailbox API 1.6 but omitted its enum definition, leaving main unable to compile. API 1.6 is an established ixgbe mailbox wire revision. Add it at the end of the revision enum, before the unknown sentinel as required by the stable numbering contract. Naming the revision does not enable negotiation or operations which will come with the E610 support. Reported by: Herbert J. Skuhra (cherry picked from commit 6a1703c112ff2904feb39288f0746c8f0a04f938) M sys/dev/ixgbe/ixgbe_mbx.h _____________________________________________________________________________________________________________ Commit: 95429a21431fd5aab82c175fee792cc268562da0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=95429a21431fd5aab82c175fee792cc268562da0 Author: Kevin Bowling (Wed 12 Aug 2026 19:30:08 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:09:39 BST) e1000: Report PCH packet buffer ECC statistics PCH packet buffer ECC status contains read-clear byte counters for corrected and uncorrected errors. Sample them with the regular hardware statistics update and account for the snapshot captured by the fatal error interrupt path. Expose the counters and the number of reset worthy interrupt indications under dev.em.N.memory_errors. Keeping the reset counter separate also preserves evidence when another status reader wins the read-clear race. Hardware validation used an I219-LM. Three documented ICS.ECCER injections advanced fatal_resets from zero to three, exactly once per reset. corrected_packet_buffer and uncorrected_packet_buffer remained zero, as expected because ICS does not inject a memory error or alter PBECCSTS. Sponsored by: BBOX.io (cherry picked from commit d7be8a3e229174bea06228b461da3b1825c6cc54) M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 02bf7486363c33a1a8b30c9e878df831a0613c4b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=02bf7486363c33a1a8b30c9e878df831a0613c4b Author: Kevin Bowling (Wed 12 Aug 2026 19:29:28 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 02:09:11 BST) e1000: Recover from PCH packet buffer ECC errors PCH LAN controllers beginning with I217 report uncorrectable packet buffer ECC errors through ICR.ECCER. Descriptor memory errors stop the MAC and require a reset before traffic can resume. Enable the interrupt on the PCH generations whose shared code setup enables packet buffer ECC. Capture the read-clear PBECCSTS value in the interrupt filter, mask ECCER while recovery is pending, and request an iflib reset from the admin task. Reenable the cause only after hardware initialization succeeds. Hardware validation used an I219-LM and the documented ICS.ECCER bit to generate the fatal interrupt. This synthesizes the interrupt cause but does not corrupt packet buffer memory or alter its ECC byte counters. Three injections in one boot each requested one reset and recovered traffic without a panic or watchdog. IMS.ECCER and PBECCSTS.ECC_ENABLE remained set after every reset. MFC after: 2 weeks Sponsored by: BBOX.io (cherry picked from commit 39762c840a15e1b32b2e1acaca18d98c030f7c17) M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 35b0fc1c077911423f4e6368d5e1ee323f13f1aa URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=35b0fc1c077911423f4e6368d5e1ee323f13f1aa Author: Kevin Bowling (Sun 16 Aug 2026 02:36:41 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 01:26:56 BST) ixv(4): Add a manual page Document supported virtual-function families, driver features, queue negotiation, PF-controlled policy, and media limitations. Sponsored by: BBOX.io (cherry picked from commit 1391e272de36f7aae2c800d96cc06762553d5027) M share/man/man4/Makefile A share/man/man4/ixv.4 _____________________________________________________________________________________________________________ Commit: 4f44e80e70254a7f8fca75b5d739b06fe0b7545d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4f44e80e70254a7f8fca75b5d739b06fe0b7545d Author: Kevin Bowling (Mon 10 Aug 2026 16:55:41 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 01:26:39 BST) ixgbe: Enable per-pool RSS on X550 family devices X550 family devices provide a separate RSS key, redirection table, and MRQC register for every VMDq pool. With SR-IOV enabled, the driver continued programming only the global RSS state and never selected MRQC.MULTIPLE_RSS. VF-local RSS programming was therefore ineffective. Enable multiple-RSS mode for X550, X552, X553, and E610. Initialize the PF pool's 64-entry key, redirection table, and RSS hash controls. Leave each VF pool untouched so its driver retains ownership of its RSS key and mapping. E610 folds IPv6 extension-header traffic into its base RSS selectors and reserves the legacy EX selector bits. Translate those requested hash types rather than programming reserved bits. With two E610 VFs active and four PF queue sets, eight fixed TCP flows distributed across all four PF receive queues. E610 uses the same per-pool mode according to the E610 Datasheet, sections 7.1.3.6.2 and 8.2.2.8.20-21. Sponsored by: Dirk-Willem van Gulik from Web Weaving (E610 hardware) Sponsored by: BBOX.io (cherry picked from commit 87406f8351664aa444851499cda83b00fdc07662) M sys/dev/ixgbe/if_ix.c _____________________________________________________________________________________________________________ Commit: 1b9749ac9c63032cb9a37d28a96e3f5e2bd417f5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1b9749ac9c63032cb9a37d28a96e3f5e2bd417f5 Author: Kevin Bowling (Mon 10 Aug 2026 16:12:24 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 01:26:29 BST) ixv: Preserve statistics across resets The VF statistics registers are free running and are not cleared on read. The existing code records attach time bases and pre-reset totals, but never uses either when publishing counters. It instead replaces the low hardware bits directly, so counters can inherit pre-attach traffic or jump backward after a reset. Accumulate modular 32- and 36-bit deltas, following DPDK, while keeping the software totals across planned resets. Establish a fresh hardware baseline after each successful reset and invalidate the sampling epoch when mailbox state is lost. Detect unsolicited PF resets explicitly so a reset while link is down cannot be mistaken for counter wrap. Remove the unused base and saved-reset bookkeeping. On E610, packet and octet counters remained monotonic across a VF FLR and a PF down/up cycle. Traffic after each reset advanced both RX and TX counters. Sponsored by: BBOX.io (cherry picked from commit cb85c4397bb3f57e60ab20c239b9339c4b752412) M sys/dev/ixgbe/if_ixv.c M sys/dev/ixgbe/ixgbe_vf.h _____________________________________________________________________________________________________________ Commit: 34208cb350760c8bf52f84635ca9d8a15756c4df URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=34208cb350760c8bf52f84635ca9d8a15756c4df Author: Kevin Bowling (Sat 1 Aug 2026 03:47:11 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 01:26:13 BST) ixgbe: Enable SR-IOV on E610 PFs E610 inherits the X550-family virtualization registers, anti-spoofing controls, and malicious-driver operations, but the frontend does not advertise SR-IOV and cannot negotiate the mailbox revision needed by E610 VFs. Initialize the X550-family PF/VF mailbox registers for E610 and use PFVFLREC for its VF reset events, following DPDK shared ixgbe code. Advertise the E610 SR-IOV capability, accept API 1.6 only on E610, carry the existing xcast and queue operations forward to that revision, and return the cached physical link speed and state with the three-dword E610 operation. Unsupported RSS and optional feature requests continue to receive explicit failures. SR-IOV activation also enables the existing X550-derived per-pool MDD recovery path on E610. Document the expanded protection and link-state coverage. Hardware validation created 63 VFs and rejected a 64th without flapping the running PF. Invalid TX and RX descriptor DMA independently asserted the offender's WQBR bit, gated only that VF, preserved sibling traffic, and recovered after the VF reset. FreeBSD ixv, FreeBSD DPDK, Linux ixgbevf, and Linux DPDK exercised the PF mailbox and data paths. Relnotes: yes Sponsored by: Dirk-Willem van Gulik from Web Weaving (E610 hardware) Sponsored by: BBOX.io (cherry picked from commit df02513fd44bcede0aa8833ae5c2af826f63ce10) M share/man/man4/ix.4 M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ixgbe_mbx.c M sys/dev/ixgbe/ixgbe_sriov.h _____________________________________________________________________________________________________________ Commit: 83866916004100b381cffcb514c37cffcc7fef29 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=83866916004100b381cffcb514c37cffcc7fef29 Author: Kevin Bowling (Sat 1 Aug 2026 03:41:56 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 01:26:02 BST) ixv: Support E610 mailbox API 1.6 E610 VFs no longer report the actual PF link state and speed through VFLINKS. They can consequently report the default 10 Gb/s speed even when the physical link uses another rate. Negotiate mailbox API 1.6 on E610 and request the PF link state with its three-dword operation. Retain VFLINKS as the fallback when an older PF rejects API 1.6. Permit API 1.6 in the inherited xcast and queue discovery helpers so negotiating the newer revision does not disable existing operations. Use GET_QUEUES to replace E610's one-queue fallback with the grant from the PF. The common path continues to use one iflib queue set per data MSI-X vector and caps the result at two queue pairs. Preserve mailbox transport errors so the driver can distinguish an explicit PF NACK from a transient timeout. A NACK means clear-to-send state was lost and requires a VF reset. Preserve the last confirmed link state across brief transport failures and publish link down after three consecutive failures. Poll E610 link state every two seconds, matching Intel's ixgbevf service timer, and phase VFs across the intervening iflib timer ticks. This avoids a mailbox polling herd when many VFs share a PF. Media-status queries return the cached state instead of starting another synchronous exchange. An admin interrupt caused by a mailbox reply only checks for an unsolicited PF reset, preventing a request/reply interrupt loop. Hardware validation on an E610 10GBASE-T PF exercised 63 VFs. Each VF negotiated API 1.6, two queue pairs, and three MSI-X vectors. Phased polling kept 31 active VFs idle, and all 63 recovered after a PF down/up cycle without watchdogs. Adapt the API 1.6 link-state operation from DPDK shared ixgbe code. The timeout and NACK distinction follows Intel ixgbevf 5.3.25. Sponsored by: Dirk-Willem van Gulik from Web Weaving (E610 hardware) Sponsored by: BBOX.io (cherry picked from commit 40367d1f3b8ff694ffc3e4bf3278ec2a762648d2) M sys/dev/ixgbe/if_ixv.c M sys/dev/ixgbe/ixgbe.h M sys/dev/ixgbe/ixgbe_mbx.h M sys/dev/ixgbe/ixgbe_vf.c M sys/dev/ixgbe/ixgbe_vf.h _____________________________________________________________________________________________________________ Commit: c4fe384e2c7be7929f87efd39656ac7e0591116c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c4fe384e2c7be7929f87efd39656ac7e0591116c Author: Kevin Bowling (Sun 16 Aug 2026 00:47:10 BST) Committer: Kevin Bowling (Sun 30 Aug 2026 01:25:52 BST) pci: Export pcie_flr_supported() Move the capability and quirk checks used by pcie_flr() into a public side effect free helper. This lets callers determine whether an FLR can be attempted before quiescing a device or saving state. The helper considers the advertised PCIe FLR capability and both the enable and disable FLR quirks. Sponsored by: BBOX.io (cherry picked from commit 5b48968c1a57bd1a7f086d7e09add59afa158340) M share/man/man9/pci.9 M sys/dev/pci/pci.c M sys/dev/pci/pcivar.h _____________________________________________________________________________________________________________ Commit: 3c6ea4597b26e5c3d91f2ce62f10542fbf4021a0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3c6ea4597b26e5c3d91f2ce62f10542fbf4021a0 Author: Jose Luis Duran (Fri 21 Aug 2026 20:14:03 BST) Committer: Jose Luis Duran (Sat 29 Aug 2026 21:57:24 BST) makefs: Fix atime tests on MS-DOS (FAT) file systems On FAT file systems, access time has a resolution of 1 day, so it is really the access date. Strip the time component from the epoch timestamp in order to check the access time. Reference: https://learn.microsoft.com/en-us/windows/win32/sysinfo/file-times Reviewed by: ngie MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D54584 (cherry picked from commit 2916ae647303e3bd92e533002a8e6c476417fe7f) M usr.sbin/makefs/tests/makefs_msdos_tests.sh _____________________________________________________________________________________________________________ Commit: 019d13dafed63bb923866b8e0be12163cecde3e6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=019d13dafed63bb923866b8e0be12163cecde3e6 Author: Jose Luis Duran (Fri 21 Aug 2026 20:02:04 BST) Committer: Jose Luis Duran (Sat 29 Aug 2026 21:56:56 BST) makefs: zfs: Allow the path vdev property to be set This allows specifying custom vdev paths (such as GPT labels like /dev/gpt/...) when creating ZFS filesystem images via makefs(8), rather than defaulting to /dev/null. Reviewed by: markj MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D59031 (cherry picked from commit 5fece2484324be52737e4cea86658a4b8d3107fc) M usr.sbin/makefs/makefs.8 M usr.sbin/makefs/tests/makefs_zfs_tests.sh M usr.sbin/makefs/zfs.c M usr.sbin/makefs/zfs/zfs.h _____________________________________________________________________________________________________________ Commit: bd0449aab23926b4724f4b5c91f008f2a60e58ca URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bd0449aab23926b4724f4b5c91f008f2a60e58ca Author: Christos Margiolis (Fri 21 Aug 2026 15:02:19 BST) Committer: Christos Margiolis (Sat 29 Aug 2026 12:14:27 BST) snd_uaudio: Use uDWord for the UAC2 sample rate uaudio20_set_speed() split the sample rate into bytes by hand. Use uDWord and USETDW() instead. No functional change intended. Sponsored by: The FreeBSD Foundation MFC after: 1 week Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D59066 (cherry picked from commit 5c3bc8ab427c8624b29cd9ac9265445002da3ba8) M sys/dev/sound/usb/uaudio.c _____________________________________________________________________________________________________________ Commit: f4b7be7c2be5c2be0798a989fe9379a471b59c6d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f4b7be7c2be5c2be0798a989fe9379a471b59c6d Author: Kevin Bowling (Sat 22 Aug 2026 02:13:12 BST) Committer: Kevin Bowling (Sat 29 Aug 2026 01:25:13 BST) snd_hdsp: Avoid allocation in the interrupt handler Cache PCM children instead of calling device_get_children() from the interrupt handler. Drain callbacks before child detach so cached pointers cannot outlive the PCM softc. Allocate the parent softc by its actual size. This mirrors snd_hdspe's interrupt dispatch and detach lifecycle. Reported by: christos (cherry picked from commit 74db53d5d7657d0508940d1193f05a39df85434a) M sys/dev/sound/pci/hdsp-pcm.c M sys/dev/sound/pci/hdsp.c M sys/dev/sound/pci/hdsp.h _____________________________________________________________________________________________________________ Commit: 0230605c42aed16dd6ea6858f20ca7b8b3e7f9f0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0230605c42aed16dd6ea6858f20ca7b8b3e7f9f0 Author: Olivier Certner (Thu 27 Aug 2026 11:43:40 BST) Committer: Olivier Certner (Fri 28 Aug 2026 21:55:02 BST) UPDATING: Fix entry for getgroups(2)/setgroups(2) Fix a typo, grammar, and generally rephrase for better clarity. Fixes: 3463f02706db ("UPDATING: add an entry for [gs]etgroups") MFC after: 1 day MFC to: stable/15 Sponsored by: The FreeBSD Foundation (cherry picked from commit b7cff2a8c47eb09968430e53cab8b05cf8897d3f) M UPDATING _____________________________________________________________________________________________________________ Commit: 1853976b752229b0a93b21a6bcc7691d177bceb3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1853976b752229b0a93b21a6bcc7691d177bceb3 Author: Jesús Daniel Colmenares Oviedo (Fri 28 Aug 2026 06:12:46 BST) Committer: Jesús Daniel Colmenares Oviedo (Fri 28 Aug 2026 16:59:56 BST) nullfs: Allow VSOCK to be mounted on top of another VSOCK In the world of containers, mounting a unix(4) socket is a common practice to allow communication between processes within containers. For example, both Podman and Docker can expose a unix(4) socket, and that same unix(4) socket can be mounted as a file accessible to a process inside a container, allowing that application to control Podman or Docker. Another example is PHP-FPM with NGINX, where, instead of using TCP/IP for communication between containers, a unix(4) socket is sufficient. However, nullfs(4) and all related components do not allow mounting a VSOCK on top of another. The current workaround involves creating the socket in a directory and mounting that directory. This is an option, though it does not provide a good user experience compared to directly mounting a VSOCK on top of another, since the application that creates the socket may create other sockets in that directory, and the user may not wish to share them, or, worse yet, applications that create unix(4) sockets may not provide any authentication at all, as they may assume that security at the file system level is sufficient. Reviewed by: dfr@ Approved by: dfr@ Relnotes: yes Differential Revision: https://reviews.freebsd.org/D59158 (cherry picked from commit 2c68ad49f13ddfa33735bd9bb6a3ca170a472ac0) M lib/libutil/mntopts.c M sbin/mount_nullfs/mount_nullfs.8 M sbin/mount_nullfs/mount_nullfs.c M sys/fs/nullfs/null_vfsops.c M sys/kern/vfs_cache.c M sys/kern/vfs_mount.c _____________________________________________________________________________________________________________ Commit: 0c9cc6ce2f2f46e0ca16fad42f2c0e065f2ef6db URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0c9cc6ce2f2f46e0ca16fad42f2c0e065f2ef6db Author: Alexander Ziaee (Mon 24 Aug 2026 21:23:31 BST) Committer: Alexander Ziaee (Fri 28 Aug 2026 05:52:06 BST) nvme.4: Canonicalize SYNOPSIS MFC after: 3 days (cherry picked from commit b863d38437af11c18a88de656404af8cefa35e63) M share/man/man4/nvme.4 _____________________________________________________________________________________________________________ Commit: 5012a1839d052defe044467b4c1ee7421dc09a22 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5012a1839d052defe044467b4c1ee7421dc09a22 Author: Kevin Bowling (Wed 12 Aug 2026 02:51:18 BST) Committer: Kevin Bowling (Fri 28 Aug 2026 03:11:56 BST) iflib: Initialize the VFLR task unconditionally The VFLR task was initialized only from drivers MSI-X interrupt assignment paths. ixl's legacy interrupt handler can nevertheless defer VFLR work, leaving an uninitialized task. Even with MSI-X, the admin interrupt was established before the task was initialized. Initialize it alongside the other private tasks. The existing detach check and private-taskqueue drains then cover its lifecycle for every interrupt mode and registration failure. Sponsored by: BBOX.io (cherry picked from commit b4208a67edc2eb7898a9ff2a6f3990c6852910e4) M sys/net/iflib.c _____________________________________________________________________________________________________________ Commit: be587e65687493c234ab9723840a1f9b2a8b0841 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=be587e65687493c234ab9723840a1f9b2a8b0841 Author: Kevin Bowling (Sat 8 Aug 2026 07:18:26 BST) Committer: Kevin Bowling (Fri 28 Aug 2026 03:11:45 BST) iflib: Add an admin task detach fail point Add an exact-device fail point immediately after the admin task checks IFC_IN_DETACH. This makes the detach race reproducible without affecting another interface. Use a bounded delay to keep the task active while detach enters the taskqueue drain. Mark the point nonsleepable as a safety backstop, and document a one-shot test for verifying that deregistration drains an already-running task before ether_ifdetach(). Reviewed by: gallatin, kgalazka Sponsored by: BBOX.io Differential Revision: https://reviews.freebsd.org/D58720 (cherry picked from commit ac56d36007a5a1a01fe69df370f272060e852e0b) M share/man/man4/iflib.4 M sys/net/iflib.c _____________________________________________________________________________________________________________ Commit: 92b851661bd024d2cb95e306537abaf2c972293f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=92b851661bd024d2cb95e306537abaf2c972293f Author: Nick Price (Sat 8 Aug 2026 07:17:16 BST) Committer: Kevin Bowling (Fri 28 Aug 2026 03:11:33 BST) iflib: Drain configuration tasks before interface detach iflib_device_deregister() sets IFC_IN_DETACH before removing the interface, but a task which already passed its detach check can still report a link change. This can re-arm if_linktask after ether_ifdetach() has drained it and leave work pending across queue teardown. Drain the entire private taskqueue before ether_ifdetach(). Drivers may register their own link-related configuration tasks there, so draining only the framework admin task leaves the same race for those drivers. Differential Revision: https://reviews.freebsd.org/D58452 Co-authored-by: Andrew Gallatin Co-authored-by: Kevin Bowling (cherry picked from commit ba353c8950d575f9d15b82c92658e660935fba25) M sys/net/iflib.c _____________________________________________________________________________________________________________ Commit: 1a13e217a82fdfd58065cd02b6961f6447aa1270 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1a13e217a82fdfd58065cd02b6961f6447aa1270 Author: Kevin Bowling (Sat 8 Aug 2026 05:33:25 BST) Committer: Kevin Bowling (Fri 28 Aug 2026 03:11:19 BST) iflib: Add registration failure injection points Add six device-scoped fail(9) points at the registration milestones needed to exercise each unwind path. An exact, runtime-only device selector prevents unrelated iflib devices from consuming an armed point. Mark the points non-sleepable because registration holds the ifnet and context locks. Document one-shot operation and bus-address reprobe so a failed attach can be recovered without another kernel build. Reviewed by: gallatin Sponsored by: BBOX.io Differential Revision: https://reviews.freebsd.org/D58722 (cherry picked from commit 90e7dbe5e2ca47baff4e4c6d9e892a0554eec4db) M share/man/man4/iflib.4 M sys/net/iflib.c _____________________________________________________________________________________________________________ Commit: 4a9daa081a6dbb2d27edf8fd0d34862f813979d0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4a9daa081a6dbb2d27edf8fd0d34862f813979d0 Author: Kevin Bowling (Sat 8 Aug 2026 05:14:53 BST) Committer: Kevin Bowling (Fri 28 Aug 2026 03:11:02 BST) iflib: Complete registration failure cleanup Pre-attach sysctls contain pointers into the iflib context. Any later registration failure that frees the context must first remove that sysctl tree. Failures after a successful IFDI_ATTACH_PRE also did not consistently call IFDI_DETACH or free the private taskqueue. In particular, routing a taskqueue creation failure through the context cleanup could free the driver softc while resources allocated by attach_pre remained live. Track successful interrupt and queue setup and use one common unwind path. Invoke IFDI_DETACH with IFNET_WLOCK dropped and release only resources whose setup completed. Leave a failed IFDI_ATTACH_PRE to unwind its own partial state, as required by the existing driver contract. A failed post-attach can follow driver registration of an SR-IOV schema. Remove that registration before detaching the interface and driver, matching normal deregistration, so a failed attach cannot leave a stale /dev/iov node or make the next attach report EBUSY. A successful attach_pre can now be followed by detach before driver queue allocation. Make the remaining queue-backed interrupt cleanup paths tolerate absent queue arrays. Mark a failed registration as detaching before draining the entire private taskqueue. Drivers can register configuration tasks there, and taskqueue_drain_all() does not wait for work queued during its drain. Make every current non-admin callback reject detaching contexts so late work cannot touch driver state. Drain tasks and call ether_ifdetach() with neither the ifnet nor context lock held. A callback already running may need either lock, while ether_ifdetach() acquires ifnet_detach_sx. Reacquire IFNET_WLOCK before the context lock to preserve the established lock order. The shared automatic core-offset allocator also lacked acquisition state. Late registration failures leaked its reference, while normal detach could decrement a reference belonging to another device when a configured offset or allocation failure meant that this context never acquired one. Record acquisition explicitly and release only references held. Reviewed by: gallatin Sponsored by: BBOX.io Differential Revision: https://reviews.freebsd.org/D58721 (cherry picked from commit fe00ca2f88718c7751b8953cc8ee7fc0dad0bbe1) M sys/dev/bnxt/bnxt_en/if_bnxt.c M sys/dev/enetc/if_enetc.c M sys/dev/igc/if_igc.c M sys/dev/ixgbe/if_sriov.c M sys/dev/vmware/vmxnet3/if_vmx.c M sys/net/iflib.c M sys/net/iflib.h _____________________________________________________________________________________________________________ Commit: 4fba78389e5a307c1060fd7785cb560397e82691 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4fba78389e5a307c1060fd7785cb560397e82691 Author: Sumit Saxena (Mon 13 Apr 2026 07:33:46 BST) Committer: Kevin Bowling (Fri 28 Aug 2026 03:10:52 BST) iflib: drain admin task and fix teardown order on register failure When IFDI_ATTACH_POST() fails (or netmap attach fails), iflib tears down with ether_ifdetach(), taskqueue_free(ifc_tq), and IFDI_DETACH(). CTX_LOCK is still held after ether_ifattach. ether_ifdetach() and taskqueue_drain(admin) must not run under CTX_LOCK. Teardown ordering (match iflib_device_deregister): - Free the per-interface admin taskqueue after IFDI_DETACH / IFDI_QUEUES_FREE, not before. - Drop IFNET_WLOCK() across IFDI_DETACH / IFDI_QUEUES_FREE so driver detach can sleep in LinuxKPI workqueue drain, then retake IFNET_WLOCK() before iflib_free_intr_mem and fail_unlock. Reviewed by: gallatin, kgalazka, #iflib Differential Revision: https://reviews.freebsd.org/D56316 (cherry picked from commit 439132310ae1f623f6c0a3dc241d0a34e98e040b) M sys/net/iflib.c _____________________________________________________________________________________________________________ Commit: 0fdbbfbe0877c191cec54797432bd2dcadec77fd URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0fdbbfbe0877c191cec54797432bd2dcadec77fd Author: Sreekanth Reddy (Mon 13 Apr 2026 07:28:08 BST) Committer: Kevin Bowling (Fri 28 Aug 2026 03:10:40 BST) iflib: Fix panic observed while doing sysctl -a with if_bnxt unload Observed below kernel panic calltrace while performing sysctl -a operation while unloading the if_bnxt driver, Fatal trap 9: general protection fault while in kernel mode KDB: stack backtrace: db_trace_self_wrapper() at db_trace_self_wrapper+0x2b/frame 0xfffffe02a7569940 vpanic() at vpanic+0x136/frame 0xfffffe02a7569a70 panic() at panic+0x43/frame 0xfffffe02a7569ad0 trap_fatal() at trap_fatal+0x68/frame 0xfffffe02a7569af0 calltrap() at calltrap+0x8/frame 0xfffffe02a7569af0 trap 0x9, rip = 0xffffffff80c0b411, rsp = 0xfffffe02a7569bc0, rbp = 0xfffffe02a7569be0 --- sysctl_handle_counter_u64() at sysctl_handle_counter_u64+0x61/frame 0xfffffe02a7569be0 sysctl_root_handler_locked() at sysctl_root_handler_locked+0x9c/frame 0xfffffe02a7569c30 sysctl_root() at sysctl_root+0x22f/frame 0xfffffe02a7569cb0 userland_sysctl() at userland_sysctl+0x196/frame 0xfffffe02a7569d50 sys___sysctl() at sys___sysctl+0x65/frame 0xfffffe02a7569e00 amd64_syscall() at amd64_syscall+0x169/frame 0xfffffe02a7569f30 fast_syscall_common() at fast_syscall_common+0xf8/frame 0xfffffe02a7569f30 Root Cause: iflib adds per-device sysctl nodes under the device tree using the device sysctl context. Some of those nodes are counter sysctl that point at fields inside txq→ift_br. When the if_bnxt driver is unloaded, iflib_device_deregister runs and calls iflib_tx_structures_free, which frees the txqs ift_br. The device sysctl tree is only freed when the device is destroyed. If sysctl -a runs during unload, it can still traverse the device tree and call sysctl_handle_counter_u64 for those nodes. The handler does counter_u64_fetch(*(counter_u64_t *)arg1). By then arg1 can point into freed memory and leads to use after free type kernel panic. Fix: flib now uses its own sysctl context for all iflib-related nodes instead of using device’s context. And iflib sysctl context is now removed before any queue/ring memory is freed. Reviewed by: gallatin, ssaxena, #iflib Differential Revision: https://reviews.freebsd.org/D55981 (cherry picked from commit d2b96f654a672f6059c5c623c276dcd76841ed12) M sys/net/iflib.c _____________________________________________________________________________________________________________ Commit: 724c344aededf3a5b1fd9d840d9e1ff0a7cd5b0e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=724c344aededf3a5b1fd9d840d9e1ff0a7cd5b0e Author: Dag-Erling Smørgrav (Wed 26 Aug 2026 18:34:18 BST) Committer: Dag-Erling Smørgrav (Thu 27 Aug 2026 07:33:50 BST) install: Fix two bugs in stdin code * Fix case where the source is - and the target exists. * Only call chflags() (to remove flags that might prevent us from replacing an existing target) in the exists case; otherwise, to_sb.st_flags is uninitialized. * Rename the source file in the stdin test case. * Extend null and stdin test cases to cover the case where the target already exists. PR: 297681 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297681 ) MFC after: 1 week Fixes: d34870708db9 ("install: Allow installing stdin") Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D59144 (cherry picked from commit a5ff4125cf08a83f7e67f498e423f3e354144327) M usr.bin/xinstall/tests/install_test.sh M usr.bin/xinstall/xinstall.c _____________________________________________________________________________________________________________ Commit: 9213578be26bea80095a7e6c624c76480c4ed2e6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9213578be26bea80095a7e6c624c76480c4ed2e6 Author: Dag-Erling Smørgrav (Thu 20 Aug 2026 14:57:56 BST) Committer: Dag-Erling Smørgrav (Thu 27 Aug 2026 07:33:50 BST) kern/sched: Hide scheduler selection from C++ The scheduler selection interface uses names that are reserved words in C++, causing problems for downstream projects that use C++ in the kernel. Work around this by hiding the interface from C++ compilers until we can come up with a better solution. Fixes: ce38acee8d0b ("Add kern/sched_shim.c") MFC after: 1 week Sponsored by: Klara, Inc. Sponsored by: NetApp, Inc. Reviewed by: siderop1_netapp.com, imp, kib Differential Revision: https://reviews.freebsd.org/D58991 (cherry picked from commit f2366851616083f923e8101363802678a03dc0b9) M sys/sys/sched.h _____________________________________________________________________________________________________________ Commit: 1e7d914ffcbee31a410822d002cc2650ca1076f3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1e7d914ffcbee31a410822d002cc2650ca1076f3 Author: Dag-Erling Smørgrav (Mon 17 Aug 2026 17:04:35 BST) Committer: Dag-Erling Smørgrav (Thu 27 Aug 2026 07:33:50 BST) yes: Avoid static initialization Our buffer is half a megabyte, but we are only initializing the first two bytes. Switching from static to dynamic initialization moves it from .data to .bss, greatly reducing the size of the binary. Fixes: cf74b63d61b4 ("yes: Completely overengineer") MFC after: 1 week Sponsored by: Klara, Inc. Reviewed by: kevans Differential Revision: https://reviews.freebsd.org/D58890 (cherry picked from commit 557ba0c2a5138ce026c0ea9cb02f374f97378b7c) M usr.bin/yes/yes.c _____________________________________________________________________________________________________________ Commit: 9f25a717ff5fb54d3456bb5abc74192b8ca0784e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9f25a717ff5fb54d3456bb5abc74192b8ca0784e Author: Dag-Erling Smørgrav (Thu 13 Aug 2026 13:28:09 BST) Committer: Dag-Erling Smørgrav (Thu 27 Aug 2026 07:33:50 BST) build: Use -f when copying sources If one of the source files we copy is non-writeable, cp will create a non-writeable copy. If the original is later modified, cp will fail to overwrite the copy since it is not writeable. Using cp -f ensures the copy always succeeds, as long as the object directory is writeable. MFC after: 1 week Sponsored by: Klara, Inc. Sponsored by: NetApp, Inc. (cherry picked from commit 336b6d11922ac3d080de50f789d40ff95b540cdf) M tools/build/Makefile _____________________________________________________________________________________________________________ Commit: b057c92506f8600bd0d703eae4337ce81bfbeea9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b057c92506f8600bd0d703eae4337ce81bfbeea9 Author: Kevin Bowling (Wed 12 Aug 2026 02:29:31 BST) Committer: Kevin Bowling (Thu 27 Aug 2026 06:16:56 BST) bnxt: Add led(4) identification support Query the firmware for the LEDs on each physical port and expose /dev/led/bnxt* only when alternate blinking is supported. Configure every LED in the advertised group for identification and restore its default firmware state before a function reset. This follows the DPDK and Linux bnxt HWRM identification paths. Reviewed against: DPDK, Linux Reviewed by: Sumit Saxena Sponsored by: BBOX.io (cherry picked from commit 98b5640786f874949e441bee7c4ad5740cd6a649) M share/man/man4/bnxt.4 M sys/dev/bnxt/bnxt_en/bnxt.h M sys/dev/bnxt/bnxt_en/bnxt_hwrm.c M sys/dev/bnxt/bnxt_en/bnxt_hwrm.h M sys/dev/bnxt/bnxt_en/if_bnxt.c _____________________________________________________________________________________________________________ Commit: 8a4fcb694526fdb64709e0382d92053a9d71e49a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8a4fcb694526fdb64709e0382d92053a9d71e49a Author: Jochen Neumeister (Wed 19 Aug 2026 11:07:03 BST) Committer: Lexi Winter (Wed 26 Aug 2026 10:56:32 BST) vmm: Emulate CPUID leaf 1Fh for guests On an Intel N150 host a guest started with sockets=1, cores=4, threads=1 reports "1 package(s) x 2 core(s) x 2 hardware threads" instead of four cores with one thread each, while the host itself detects its topology correctly. A FreeBSD guest picks the topology leaf in topo_probe_intel_0xb(), sys/x86/x86/mp_x86.c, and since 6badb512a94d it prefers leaf 1Fh over leaf 0Bh whenever cpu_high is 1Fh or higher. bhyve passes leaf 0 through unmodified, so the guest sees the maximum basic leaf of the host, which is 1Fh or above on Alder Lake and newer, and takes that path. x86_emulate_cpuid(), sys/amd64/vmm/x86.c, derives the topology from vm_get_topology() for leaves 1, 4 and 0Bh, but has no case for 1Fh, so the request ends up in default_leaf and the host values are returned verbatim. The guest therefore enumerates the topology of the host: with an SMT shift of 1 in the host's leaf 1Fh and four vCPUs this gives core_id_shift = 1 and pkg_id_shift = 2, which is exactly the reported 2 cores x 2 threads. Hosts whose maximum basic leaf is below 1Fh are unaffected, as the request is clamped to cpu_high before the switch statement. Leaf 1Fh uses the same level encoding as leaf 0Bh for the SMT and the core level, so handle both leaves in the same case. The module, tile and die levels are not emulated and terminate the enumeration, exactly as they already do for leaf 0Bh. PR: 297475 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297475 ) MFC after: 1 week Reported by: Richard Straka Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D58885 (cherry picked from commit 4b1974e9db63d6510406e4ef3e56c250edd2240a) M sys/amd64/vmm/x86.c M sys/amd64/vmm/x86.h _____________________________________________________________________________________________________________ Commit: 9c860aa2f5dc0e687e4a3c83de5280a715d89027 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9c860aa2f5dc0e687e4a3c83de5280a715d89027 Author: Lexi Winter (Mon 3 Aug 2026 15:10:25 BST) Committer: Lexi Winter (Wed 26 Aug 2026 10:56:12 BST) libelftc: Const correctness for C23 On some platforms, e.g. Linux Clang 22.1.8 / glibc 2.43, strchr() now implements the C23 behaviour where passing a const pointer to strchr() also returns a const pointer. This breaks libelftc during the bootstrap build, since it assumes the return value is always a mutable pointer. Since the returned pointer is never modified in either case, make it const. MFC after: 1 week Reviewed by: jkoshy, markj, dim, emaste Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58497 (cherry picked from commit 85b07e977b04fceec84783facdb308492f17b155) M contrib/elftoolchain/libelftc/libelftc_dem_arm.c M contrib/elftoolchain/libelftc/libelftc_dem_gnu2.c _____________________________________________________________________________________________________________ Commit: 198ab9e5acfaf367ff44a724f079a486eeef0b9f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=198ab9e5acfaf367ff44a724f079a486eeef0b9f Author: Lexi Winter (Mon 3 Aug 2026 15:09:39 BST) Committer: Lexi Winter (Wed 26 Aug 2026 10:56:12 BST) mandoc: Const correctness for C23 On some platforms, e.g. Linux Clang 22.1.8 / glibc 2.43, strchr() now implements the C23 behaviour where passing a const pointer to strchr() also returns a const pointer. This breaks mandoc during the bootstrap build, since it assumes the return value is always a mutable pointer. In read.c, make the existing temporary pointer const, and for the mandoc_asprintf() call, add a new mutable local. In mdoc.c and out.c, since the data is mutable and is mutated here, remove const from the temporary pointers. MFC after: 1 week Reviewed by: fuz Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58495 (cherry picked from commit 9f18614d5353ce513511ccbf59d09e76c93f7bc9) M contrib/mandoc/mdoc.c M contrib/mandoc/out.c M contrib/mandoc/read.c _____________________________________________________________________________________________________________ Commit: 4f5673b8aeb4c5cb6788fe832b1ac0888658ca20 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4f5673b8aeb4c5cb6788fe832b1ac0888658ca20 Author: Lexi Winter (Mon 3 Aug 2026 15:09:03 BST) Committer: Lexi Winter (Wed 26 Aug 2026 10:56:12 BST) m4: Const correctness for C23 On some platforms, e.g. Linux Clang 22.1.8 / glibc 2.43, strchr() now implements the C23 behaviour where passing a const pointer to strchr() also returns a const pointer. This breaks m4 during the bootstrap build, since it assumes the return value is always a mutable pointer. Since the returned value is never modified, simply make the temporary const. MFC after: 1 week Reviewed by: bapt, dim Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58494 (cherry picked from commit 1d94e2e0f2ee21d5a4596efc0570d06e3dea0a6e) M usr.bin/m4/misc.c _____________________________________________________________________________________________________________ Commit: ec58dba0ed806875f7e9da5b1475b85db52421fd URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ec58dba0ed806875f7e9da5b1475b85db52421fd Author: Lexi Winter (Mon 3 Aug 2026 15:08:13 BST) Committer: Lexi Winter (Wed 26 Aug 2026 10:56:12 BST) mkimg: Const correctness for C23 On some platforms, e.g. Linux Clang 22.1.8 / glibc 2.43, strchr() now implements the C23 behaviour where passing a const pointer to strchr() also returns a const pointer. This breaks mkimg during the bootstrap build, since it assumes the return value is always a mutable pointer. Make the existing 'sep' pointer const to fix the first case, and for the second, introduce a new non-const pointer for strchr, since we do modify the result in that case. MFC after: 1 week Reviewed by: markj Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58493 (cherry picked from commit 9fd8f5e761ba663c8e99eeff64c5a7fd7bcf1e05) M usr.bin/mkimg/mkimg.c _____________________________________________________________________________________________________________ Commit: 5b466d39237c711f1e2d65157970cc5f0637a55c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5b466d39237c711f1e2d65157970cc5f0637a55c Author: Lexi Winter (Mon 3 Aug 2026 15:07:09 BST) Committer: Lexi Winter (Wed 26 Aug 2026 10:56:12 BST) xinstall: Const correctness for C23 On some platforms, e.g. Linux Clang 22.1.8 / glibc 2.43, strchr() now implements the C23 behaviour where passing a const pointer to strchr() also returns a const pointer. This breaks xinstall during the bootstrap build, since it assumes the return value is always a mutable pointer. As the returned pointer is never used to modify the value, fix this by making the temporary variable const. MFC after: 1 week Reviewed by: ray, markj, emaste Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58492 (cherry picked from commit 2296c39a9ebc4f081d90b6554d8839e8cde8490a) M usr.bin/xinstall/xinstall.c _____________________________________________________________________________________________________________ Commit: 876f29df3e2ae25b7e9c225a12a1a7e293196a3e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=876f29df3e2ae25b7e9c225a12a1a7e293196a3e Author: Lexi Winter (Mon 3 Aug 2026 15:06:18 BST) Committer: Lexi Winter (Wed 26 Aug 2026 10:56:12 BST) sort: Const correctness for C23 On some platforms, e.g. Linux Clang 22.1.8 / glibc 2.43, strchr() now implements the C23 behaviour where passing a const pointer to strchr() also returns a const pointer. This breaks sort during the bootstrap build, since it assumes the return value is always a mutable pointer. As the returned pointer is never used to modify the value, fix this by making the temporary variable const. MFC after: 1 week Reviewed by: markj Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58491 (cherry picked from commit 78f842dda35b7280e8682f90506ff05b591c6b3a) M usr.bin/sort/sort.c _____________________________________________________________________________________________________________ Commit: 8c71eb51d2eec6f2a29eaa171b3f6ca51d8c76c6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8c71eb51d2eec6f2a29eaa171b3f6ca51d8c76c6 Author: Lexi Winter (Mon 3 Aug 2026 15:05:09 BST) Committer: Lexi Winter (Wed 26 Aug 2026 10:56:12 BST) libucl: Const correctness for C23 On some platforms, e.g. Linux Clang 22.1.8 / glibc 2.43, strchr() now implements the C23 behaviour where passing a const pointer to strchr() also returns a const pointer. This breaks libucl during the bootstrap build, since it assumes the return value is always a mutable pointer. Instead of assigning directly to params->prefix (which is const), use a non-const temporary variable and assign the result after we've done the modification. MFC after: 1 week Reviewed by: bofh, bapt Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58490 (cherry picked from commit bcee560d390eb8aa8fd0f08a7a0bffb6e77fffc6) M contrib/libucl/src/ucl_util.c _____________________________________________________________________________________________________________ Commit: 3dababd3277afee2a4ed734833b0de70dc6ce3b1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3dababd3277afee2a4ed734833b0de70dc6ce3b1 Author: Lexi Winter (Mon 3 Aug 2026 15:04:16 BST) Committer: Lexi Winter (Wed 26 Aug 2026 10:56:12 BST) rpcgen: Const correctness for C23 On some platforms, e.g. Linux Clang 22.1.8 / glibc 2.43, strchr() now implements the C23 behaviour where passing a const pointer to strchr() also returns a const pointer. This breaks rpcgen during the bootstrap build, since it assumes the return value is always a mutable pointer. For mkfile_output(), the pointed-to value is never modified, so fix this by making the pointer const as well. For open_log_file(), the current code modifies the supposedly const value in-place to remove the filename suffix, which happens to work but is wrong even in older versions of C. Change the code to use a printf "%.*s" format specifier to strip the suffix instead. MFC after: 1 week Reviewed by: brooks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58489 (cherry picked from commit cb2daf8ce116d475597d7ab95f2454ea54c968e6) M usr.bin/rpcgen/rpc_main.c M usr.bin/rpcgen/rpc_svcout.c _____________________________________________________________________________________________________________ Commit: d15778bbb91055d9cee22228e8b07bdab4795294 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d15778bbb91055d9cee22228e8b07bdab4795294 Author: Lexi Winter (Mon 3 Aug 2026 15:02:51 BST) Committer: Lexi Winter (Wed 26 Aug 2026 10:56:12 BST) libc: getopt{,_long}: Const correctness for C23 On some platforms, e.g. Linux Clang 22.1.8 / glibc 2.43, strchr() now implements the C23 behaviour where passing a const pointer to strchr() also returns a const pointer. This breaks getopt during the bootstrap build, since it assumes the return value is always a mutable pointer. Since the pointed-to value is never modified, fix this by making the pointer const. MFC after: 1 week Reviewed by: emaste Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58488 (cherry picked from commit f1d98862044f7748c6f930e9d4339abc166a5b16) M lib/libc/stdlib/getopt.c M lib/libc/stdlib/getopt_long.c _____________________________________________________________________________________________________________ Commit: 132e609c2ce5c72e9e04a5d6f3e0e9140e06ebd8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=132e609c2ce5c72e9e04a5d6f3e0e9140e06ebd8 Author: Kevin Bowling (Wed 26 Aug 2026 02:07:59 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 02:07:59 BST) igc: Restore the watchdog event counter The MFC of the fatal memory-error recovery dropped watchdog_events from the softc. The driver still increments it, includes it in IFCOUNTER_OERRORS, and exports it as the watchdog_timeouts sysctl. Fixes: ee9bbfca423f ("igc: Recover from fatal internal memory errors") M sys/dev/igc/if_igc.h _____________________________________________________________________________________________________________ Commit: e54458ceaad9413122c4c914dbf446c630e6b86c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e54458ceaad9413122c4c914dbf446c630e6b86c Author: Kevin Bowling (Wed 12 Aug 2026 02:29:31 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:56:52 BST) iflib: Allow conditional LED device support A driver class may implement LED control even though the capability is not available on every device or firmware version it supports. Add an optional capability method and consult it before creating the led(4) device. Default to supported so existing providers are unchanged. This will be used by bnxt which blends PF and VF in the same driver. (cherry picked from commit 2519e19f05e0c3e5925bf81b729b4c28f2ad1af6) M sys/net/ifdi_if.m M sys/net/iflib.c _____________________________________________________________________________________________________________ Commit: 12a27f82b370a049ac027203af9865ff63be9dbc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=12a27f82b370a049ac027203af9865ff63be9dbc Author: Kevin Bowling (Wed 12 Aug 2026 05:13:43 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:56:52 BST) igc: Report corrected internal ECC errors I225 and I226 do not interrupt for corrected internal ECC errors. Instead, the DMA packet buffer and PCIe memories expose sticky status bits in PBECCSTS and PCIEECCSTS. Sample these bits with the regular hardware statistics update, preserve the PBECCSTS ECC enable state while clearing its RW1C indication, and expose separate counters for the DMA packet buffer, PCIe transmit-data memory, and PCIe retry buffer. These counters represent observed indications rather than an exact error count because multiple corrections between samples collapse into one sticky status bit. Hardware validation used an I225-IT (rev 3) and a debug kernel that wrote only the documented self-clearing injection bits. Each test armed the injector, exercised the owning RAM with traffic, and compared the corresponding counter before and after. Coverage: Memory Observed result DMA packet buffer corrected_dma advanced once PCIe transmit data corrected_pcie_tx_data advanced once PCIe retry buffer No PCIe replay source; not exercised The retry-buffer injector requires a real PCIe replay to read the corrupted entry. The test root port exposed AER and DPC reporting but no protocol error injector, so ordinary traffic could not cover that case. Sponsored by: BBOX.io (cherry picked from commit 9f7633b932954162792e2caef4f6f0cd87e82f43) M sys/dev/igc/if_igc.c M sys/dev/igc/if_igc.h _____________________________________________________________________________________________________________ Commit: ee9bbfca423f8250479df7aaeac9a0ffe3bebd3b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ee9bbfca423f8250479df7aaeac9a0ffe3bebd3b Author: Kevin Bowling (Wed 12 Aug 2026 05:12:49 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:56:52 BST) igc: Recover from fatal internal memory errors I225 and I226 report uncorrectable internal memory errors through ICR.FER and identify the affected region in PEIND. Depending on the region, hardware stops transmit or all PCIe and DMA traffic until the port is reset and reinitialized. Enable the fatal error interrupt and capture its read clear status in the interrupt filter. Mask the cause while an iflib reset is pending, report the affected memory regions, and expose per region indication counters. PCIe region parity failures require a different recovery order from a normal reset: assert DEV_RST, wait at least 3 ms, disable PCIe master requests, clear PCIEERRSTS, and then reinitialize the port. Follow that sequence before entering the normal reset path and clear the remaining LAN status afterward. The I225/I226 PBECCSTS layout is unrelated to the PCH layout previously copied into the igc headers. Replace those unused definitions with the I225/I226 memory error register definitions. Hardware validation used an I225-IT revision 3 and a debug kernel that wrote only the documented self-clearing injection bits. It did not synthesize interrupt or status state. Coverage, notably DMA and Mgmt are not fully testable in my setup: Region Observed hardware status Result LAN PEIND 0x1, LANPERRSTS 0x200 Reset and recovered PCIe PEIND 0x4, PCIEERRSTS 0x8 Reset and recovered DMA DRPARC injection read back zero DFT-gated on test NIC Mgmt Host debug strap unavailable Not injectable The repeated LAN and PCIe tests recovered without a panic or watchdog. A PCIe-to-LAN sequence also verified that reset-time PEIND indications are drained before FER is unmasked. Sponsored by: BBOX.io (cherry picked from commit bbf93227fe9ee1f38b7db5477398c3564e5c84bc) M sys/dev/igc/if_igc.c M sys/dev/igc/if_igc.h M sys/dev/igc/igc_defines.h M sys/dev/igc/igc_regs.h _____________________________________________________________________________________________________________ Commit: 1dc515bfe52f130552ce0a9e3c805d1cc9a84363 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1dc515bfe52f130552ce0a9e3c805d1cc9a84363 Author: Kevin Bowling (Wed 12 Aug 2026 04:57:29 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:56:52 BST) ixgbe: Defer E610 thermal shutdown to iflib The E610 firmware event handler invoked ixgbe_if_stop() directly from IFDI_UPDATE_ADMIN_STATUS(). This reset the device without the iflib queue lifecycle and left the interface marked running after its hardware was stopped. Request an iflib reset instead. Fail the automatic initialization once so the reset transaction stops the interface and publishes that state. A later operator-requested initialization remains possible, matching the previous recovery policy without bypassing iflib. (cherry picked from commit 3aac283613bd3fd0228a06d6c854ca0bf190ecfb) M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/ixgbe.h _____________________________________________________________________________________________________________ Commit: 95cf012c8da1c5c1a0cf3ab564edc78b24b57de4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=95cf012c8da1c5c1a0cf3ab564edc78b24b57de4 Author: Kevin Bowling (Wed 12 Aug 2026 04:36:03 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:56:52 BST) ixgbe: Defer firmware recovery transitions to iflib The firmware-mode callout invoked ixgbe_if_stop() directly. This performed a full device reset without the iflib context lock or the iflib queue lifecycle. It could also poll the E610 firmware command interface from callout context while identification was active. Request an iflib reset from the callout instead. Reject initialization while firmware recovery remains active. This leaves the interface stopped and lets iflib publish that state. Request initialization when firmware exits recovery so an administratively-up interface can recover without operator intervention. (cherry picked from commit 43aa553ef45a4345bdfabadae40d811730151144) M sys/dev/ixgbe/if_ix.c _____________________________________________________________________________________________________________ Commit: 7ebe1e32f5d4ea8c92676ba11b238c1380032216 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7ebe1e32f5d4ea8c92676ba11b238c1380032216 Author: Kevin Bowling (Wed 12 Aug 2026 03:33:20 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:56:51 BST) ixgbe: Defer ECC recovery to iflib The link interrupt filter performed a full hardware reset in interrupt context. This bypassed iflib stop and initialization, including queue quiescence and restoration of temporary LED state. Record the ECC event in the administrative request mask and ask iflib to perform the reset from its taskqueue. Keep the ECC cause masked until reset so the intermediate admin pass cannot re-enable a sticky condition. Handle ECC independently of Flow Director and in legacy interrupt mode. Remove the redundant EICR write; the filter has already cleared the reported causes. Also remove the accompanying complement-mask update of mac.flags. It set every flag except DOUBLE_RESET_REQUIRED and had no place in ECC recovery. (cherry picked from commit c28f2c551daf07345ac78b74459efe1014c49464) M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/ixgbe.h M sys/dev/ixgbe/ixgbe_type.h _____________________________________________________________________________________________________________ Commit: ddee18ad56e90373ffa27937a251179befa26da4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ddee18ad56e90373ffa27937a251179befa26da4 Author: Kevin Bowling (Wed 12 Aug 2026 01:54:21 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:56:51 BST) ixl: Add led(4) identification support Expose each physical port identification LED through /dev/led/ixl*. Use the existing GPIO LED helpers for most devices and the PHY provisioning interface for X710 10GBASE-T adapters. Preserve and restore the original GPIO or PHY indication mode, including before the interface is stopped. (cherry picked from commit 8b2e75970c0328e7397290417cc06e9d9c763d2a) M share/man/man4/ixl.4 M sys/dev/ixl/if_ixl.c M sys/dev/ixl/ixl_pf.h M sys/dev/ixl/ixl_pf_iflib.c _____________________________________________________________________________________________________________ Commit: 623b7198c7a83499d72e10c2b132fbd6b9a5076f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=623b7198c7a83499d72e10c2b132fbd6b9a5076f Author: Kevin Bowling (Wed 12 Aug 2026 01:54:21 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:56:51 BST) ixgbe: Add led(4) identification support Expose the physical port identification LED through /dev/led/ix*. Save and restore the NVM-selected LEDCTL value around each request. The X550 operations also clear their PHY manual override before the register is restored. Use the dedicated firmware port-identification command on E610. Its interface selects between firmware blinking and the original mode rather than directly controlling LEDCTL. Restore the normal indication before a device stop or reset. (cherry picked from commit fb7e249ce4fd03fe53e4407efe661f9e94852bb6) M share/man/man4/ix.4 M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/ixgbe.h _____________________________________________________________________________________________________________ Commit: 63d782348e44f7635fcf9ff455d05490a8030e93 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=63d782348e44f7635fcf9ff455d05490a8030e93 Author: Kevin Bowling (Wed 12 Aug 2026 04:03:11 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:56:51 BST) igc: Remove invalid debug ring pointer iteration The debug routine reads queue registers by queue index. It also advanced unused pointers to rings embedded in queue structures. Those pointers had the wrong stride and could proceed beyond the ring object. Remove the unused pointer arithmetic. (cherry picked from commit 423927d6c3dc87628fc2a19f25b5b5c07b3b73e2) M sys/dev/igc/if_igc.c _____________________________________________________________________________________________________________ Commit: 5122a6181aa4268761cda41980af62c0245f1816 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5122a6181aa4268761cda41980af62c0245f1816 Author: Kevin Bowling (Wed 12 Aug 2026 01:33:18 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:56:51 BST) e1000: Fix the multiqueue debug register dump The debug routine advanced ring pointers as if rings were contiguous. They are embedded in queue structures, so rings beyond queue zero had the wrong stride. The bogus queue index could cause an invalid MMIO read and panic the machine. Index the queue arrays first and then select the embedded ring. (cherry picked from commit 7dd826171b69a01c234ba6e9117917398ba2705e) M sys/dev/e1000/if_em.c _____________________________________________________________________________________________________________ Commit: c43037f2bef77dff2d5c211b3bbf29236bb8eb58 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c43037f2bef77dff2d5c211b3bbf29236bb8eb58 Author: Kevin Bowling (Wed 12 Aug 2026 01:29:17 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:56:51 BST) e1000: Identify SerDes adapters with LED blink The generic LED on and off operations do not handle internal SerDes media, leaving the led(4) device ineffective on my I210 fiber port. Use the hardware blink operation for the on phase on internal SerDes. The off phase restores the saved OEM LED configuration as before. (cherry picked from commit 28f96cc3748fc46408cc6ab6172f09bc2182cad7) M sys/dev/e1000/if_em.c _____________________________________________________________________________________________________________ Commit: 37f1ac5b871b1e53a8f03917662b1e2b4f7eb493 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=37f1ac5b871b1e53a8f03917662b1e2b4f7eb493 Author: Kevin Bowling (Wed 12 Aug 2026 01:22:35 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:56:51 BST) igc: Add led(4) identification support I225 and I226 expose three programmable LED outputs. Use LED1 for adapter identification, following the convention in DPDK. Preserve the OEM configuration across identification requests. Restore the OEM configuration before a device reset so an active led(4) pattern cannot leave the output overridden across stop or detach. The LED mode values follow the Intel I225 Software User Manual. (cherry picked from commit 19f75b38199b9d30e85fab83e61ff36b0b9ed015) M share/man/man4/igc.4 M sys/dev/igc/if_igc.c M sys/dev/igc/if_igc.h M sys/dev/igc/igc_defines.h _____________________________________________________________________________________________________________ Commit: ce44f0bfe47d2473d7bc7e0c16c291a8bf18f567 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ce44f0bfe47d2473d7bc7e0c16c291a8bf18f567 Author: Kevin Bowling (Wed 12 Aug 2026 03:03:33 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:56:51 BST) igb(4): Document identification LED device nodes The shared em(4) manual page lists only the em device-node name. Document the /dev/led/igb* name as well. (cherry picked from commit fc0e6adb9d26f94616db5357afcbb585e4176c6d) M share/man/man4/em.4 _____________________________________________________________________________________________________________ Commit: ac1026c4c8afcd738f266da06a758f0272ddf7aa URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ac1026c4c8afcd738f266da06a758f0272ddf7aa Author: Konstantin Belousov (Wed 19 Aug 2026 03:14:00 BST) Committer: Konstantin Belousov (Wed 26 Aug 2026 01:44:11 BST) ofed/ipoib: convert to timer_setup linuxKPI (cherry picked from commit fdcb52d03688d92ba4962eea623292b0120e2293) M sys/ofed/drivers/infiniband/ulp/ipoib/ipoib_ib.c _____________________________________________________________________________________________________________ Commit: ff47081093c8d4c6c405cd8ddd41bbbbca32b6e4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ff47081093c8d4c6c405cd8ddd41bbbbca32b6e4 Author: Konstantin Belousov (Wed 19 Aug 2026 03:13:20 BST) Committer: Konstantin Belousov (Wed 26 Aug 2026 01:44:11 BST) mlx5(4): convert to timer_setup() linuxKPI (cherry picked from commit 814cd919981e98120c3065906092dca2546fdd74) M sys/dev/mlx5/mlx5_core/mlx5_health.c M sys/dev/mlx5/mlx5_ib/mlx5_ib_mr.c _____________________________________________________________________________________________________________ Commit: 1f1f7b638fef98da619d5c25ecf9452fbb9b96c5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1f1f7b638fef98da619d5c25ecf9452fbb9b96c5 Author: Konstantin Belousov (Wed 19 Aug 2026 22:53:55 BST) Committer: Konstantin Belousov (Wed 26 Aug 2026 01:44:10 BST) tests/sys/posixshm/posixshm_test.c::accounting fix after st_size changes (cherry picked from commit a1aa26b7db2c774b1da5eecb5505efd412ea7a23) M tests/sys/posixshm/posixshm_test.c _____________________________________________________________________________________________________________ Commit: 1d9c9fe8344969ea09b90105a0825e8105f4d9a9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1d9c9fe8344969ea09b90105a0825e8105f4d9a9 Author: Konstantin Belousov (Wed 19 Aug 2026 03:27:46 BST) Committer: Konstantin Belousov (Wed 26 Aug 2026 01:44:10 BST) shmfd: consistently return size in 512 byte blocks for fstat(2) st_blocks (cherry picked from commit 3a1bf59d195ced99c0f69774969d7090d21f6097) M lib/libsys/stat.2 M sys/kern/uipc_shm.c _____________________________________________________________________________________________________________ Commit: dbf07219675e9673964160c5e2d25a867ec93e29 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=dbf07219675e9673964160c5e2d25a867ec93e29 Author: Kevin Bowling (Wed 12 Aug 2026 01:12:51 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:25:08 BST) iflib: Create led(4) devices When a driver implements ifdi_led_func, have the framework create its led(4) device after attach completes and the ifnet and context locks are released. PR: 246885 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=246885 ) Reported by: jlduran Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D32389 (cherry picked from commit 6591a7f6919295f2ec2b463d1ae9554a8bbf6104) M sys/net/iflib.c _____________________________________________________________________________________________________________ Commit: e5db37bd060542d849dc3d975c7c597d7d28f210 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e5db37bd060542d849dc3d975c7c597d7d28f210 Author: Kevin Bowling (Wed 12 Aug 2026 01:12:15 BST) Committer: Kevin Bowling (Wed 26 Aug 2026 01:24:57 BST) iflib: Defer LED control to the device taskqueue led(4) invokes driver callbacks while holding its mutex, including from a callout. iflib_led_func() cannot acquire the sleepable context lock in those contexts without causing a lock-order reversal or sleeping from the callout. Record the latest requested state under the iflib state lock and enqueue the existing per-device taskqueue. The task can safely take the context lock before invoking the driver. Coalescing requests also avoids accumulating stale blink transitions when hardware access is slow. Destroy the LED device before draining its task so no new callback can race driver detach. (cherry picked from commit 952994751911d5d059d53e73eb874e00ee98b9ed) M sys/net/iflib.c _____________________________________________________________________________________________________________ Commit: 5990860ca841fddaef9acbb7e2cbbd372ce10081 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5990860ca841fddaef9acbb7e2cbbd372ce10081 Author: Mark Johnston (Mon 24 Aug 2026 19:15:38 BST) Committer: Mark Johnston (Tue 25 Aug 2026 16:47:13 BST) posixshm: Fix a TOCTOU race in the FIOSSHMLPGCNF handler The check for whether shm_lp_psind was assigned was unlocked. This race can be exploited to create an object with psind==2 but with only pagesizes[1] worth of pages populated. This in turn can be used to escalate privileges. Fix this by acquiring the rangelock earlier. In shm_mmap_large(), assert that we hold the rangelock. In shm_write(), annotate an unlocked load of shm_lp_psind. Approved by: so Security: FreeBSD-SA-26:63.posixshm Security: CVE-2026-58094 Reported by: tsune of GMO Cybersecurity by Ierae, Inc. working with TrendAI Zero Day Initiative Reviewed by: kib Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D59104 M sys/kern/uipc_shm.c M sys/sys/mman.h _____________________________________________________________________________________________________________ Commit: c7cec6fa6e4aeca7488130e17f4fd1ad2c476fa0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c7cec6fa6e4aeca7488130e17f4fd1ad2c476fa0 Author: Mark Johnston (Mon 24 Aug 2026 19:14:18 BST) Committer: Mark Johnston (Tue 25 Aug 2026 16:47:13 BST) tty: Revalidate after dropping the tty lock in ioctl handlers The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the proctree relock. After relocking the tty, it did not revalidate the tty state, and it could end up linking a doomed tty to the calling process' session. This race can be exploited to escalate privileges. TIOCSPGRP has a similar race, fix that too. Approved by: so Security: FreeBSD-SA-26:62.tty Security: CVE-2026-58093 Reported by: tsune of GMO Cybersecurity by Ierae, Inc. working with TrendAI Zero Day Initiative Reviewed by: kib Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D59126 M sys/kern/tty.c _____________________________________________________________________________________________________________ Commit: c5ad29cb6c62fb50164e953ea5ad017350db875c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c5ad29cb6c62fb50164e953ea5ad017350db875c Author: Gordon Tetlow (Mon 24 Aug 2026 23:07:40 BST) Committer: Mark Johnston (Tue 25 Aug 2026 16:47:12 BST) openssl: Fix multiple vulnerabilities This is a rollup commit from upstream to fix: Handle signature_algorithms_cert extension in key-only context Avoid double free of qrx in port_default_packet_handler() Avoid full read buffer allocation when buffering DTLS next-epoch records ssl/record/methods/dtls_meth.c: lower the unprocessed_rcds queue limit ssl/record: remove dead DTLS processed_rcds record queue Fix heap buffer overflow (8-byte OOB write) in AES-WRAP-PAD unwrap CMP unexpected sender DN used as format string in ERR_raise_data() Add test for CVE-2026-63073 Add a test for restricting growth in cmp cert cache Fix unbounded cert cache growth in cmp Don't store ACK-only frames in TX history for QUIC. Add test for CVE-2026-63076 Fix Remote NULL deref in ossl_cmp_calc_protection() via crafted protectionAlg Approved by: so Obtained from: OpenSSL Security: FreeBSD-SA-26:61.openssl Security: CVE-2026-14457 Security: CVE-2026-18798 Security: CVE-2026-54874 Security: CVE-2026-63072 Security: CVE-2026-63073 Security: CVE-2026-63074 Security: CVE-2026-63076 M crypto/openssl/crypto/cmp/cmp_protect.c M crypto/openssl/crypto/cmp/cmp_vfy.c M crypto/openssl/crypto/cms/cms_kari.c M crypto/openssl/include/internal/quic_ackm.h M crypto/openssl/include/internal/quic_record_rx.h M crypto/openssl/ssl/quic/quic_ackm.c M crypto/openssl/ssl/quic/quic_port.c M crypto/openssl/ssl/quic/quic_record_rx.c M crypto/openssl/ssl/quic/quic_txp.c M crypto/openssl/ssl/record/methods/dtls_meth.c M crypto/openssl/ssl/record/methods/recmethod_local.h M crypto/openssl/ssl/t1_lib.c M crypto/openssl/test/build.info A crypto/openssl/test/cmp_extracerts_dos_test.c M crypto/openssl/test/cmp_protect_test.c M crypto/openssl/test/cmp_vfy_test.c M crypto/openssl/test/recipes/65-test_cmp_msg.t M crypto/openssl/test/rpktest.c _____________________________________________________________________________________________________________ Commit: ae27dff4710b87f25a909e008cdbe822b5b61667 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ae27dff4710b87f25a909e008cdbe822b5b61667 Author: Mark Johnston (Mon 24 Aug 2026 19:13:29 BST) Committer: Mark Johnston (Tue 25 Aug 2026 16:47:12 BST) cred: Fix group_is_primary() This helper wasn't updated in commit be1f7435ef21, so in reality it was testing whether "gid" is the first supplemental group. If a user doesn't belong to a supplementary group, then it's testing an uninitialized slot; since ucreds are allocated with M_ZERO, this typically means that we're testing gid == 0. group_is_primary() has exactly one use, in mac_do. There, it's used to determine whether to keep the caller's current primary groups. This means that a rule such as gid=0>uid=0 will permit any credential with no supplementary groups. I believe this is mostly exploitable by daemons which have explicitly dropped privileges and called setgroups(0, NULL); logged in users will have a non-empty supplementary group list by virtue of having gone through initgroups(3). Fix group_is_primary(), and add a regression test. Approved by: so Security: FreeBSD-SA-26:59.mac_do Security: CVE-2026-58092 Reported by: Hazley Samsudin of GovTech CSG Fixes: be1f7435ef21 ("kern: start tracking cr_gid outside of cr_groups[]") Reviewed by: olce, kevans Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D59051 M sys/sys/ucred.h M tests/sys/mac/do/Makefile A tests/sys/mac/do/regression.c _____________________________________________________________________________________________________________ Commit: edff72e5f64cc04ae41a9da6336d0ec7779e48df URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=edff72e5f64cc04ae41a9da6336d0ec7779e48df Author: Mark Johnston (Mon 24 Aug 2026 16:20:32 BST) Committer: Mark Johnston (Tue 25 Aug 2026 16:47:12 BST) dsp: Fix a potential use-after-free in dsp_oss_syncstart() This function has a loop where it attempts to lock all channels in a group. If doing so would block, it releases all locks, sleeps for a bit, and tries again. However, once the syncgroup lock is dropped, nothing prevents the syncgroup structure from being freed. Fix the inner loop: after waking up, break out of it unconditionally and start everything again. I think the old code was also buggy and not well-exercised: after waking up we'd continue to try and continue locking channels. Then we'd try again from the beginning and fail to lock the channels we had already locked. Approved by: so Security: FreeBSD-SA-26:58.sound Security: CVE-2026-58091 Reported by: Hazley Samsudin of GovTech CSG Reviewed by: christos Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58912 M sys/dev/sound/pcm/channel.h M sys/dev/sound/pcm/dsp.c _____________________________________________________________________________________________________________ Commit: 87bb4aa63ac789dd2821753f04bae5c768f343df URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=87bb4aa63ac789dd2821753f04bae5c768f343df Author: Mark Johnston (Mon 24 Aug 2026 15:57:16 BST) Committer: Mark Johnston (Tue 25 Aug 2026 16:47:12 BST) hwpmc: Fix the execve handler When a process execve()s, pmc_process_exec() is supposed to evaluate whether the new image is setuid/setgid and if so, whether to detach PMCs. This was handled by pmc_can_attach(), which is effectively an open-coded copy of cr_xids_subset(). Unfortunately, the test of the result of this function was inverted, with the result that we'd detach PMCs only if the predicate said it was okay to do so. It appears the bug has always been there; it seems the intent was to return 0 on "success", i.e., it is okay to attach the PMCs, much like p_candebug(). Commits 1c3c698ba4c4 and 1c40b15971f0 obscured this a bit. I think this check is trying to be too clever. Let's make it simpler: simply do not attach PMCs unless the owner is privileged. This is how, e.g., ktrace works. I do not think it's worth trying to be more sophisticated than this unless we can generalize the policy in a way that's applicable to other subsystems. Also fix a bug at the end of pmc_process_exec(): pmc_detach_one_process() will call pmc_remove_process_descriptor() for us. Approved by: so Security: FreeBSD-SA-26:56.hwpmc Security: CVE-2026-58089 Reported by: netchild Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D59102 M sys/dev/hwpmc/hwpmc_mod.c M sys/kern/kern_exec.c _____________________________________________________________________________________________________________ Commit: dde735f47495a29458b9c9a2ba2fa7a213bccf78 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=dde735f47495a29458b9c9a2ba2fa7a213bccf78 Author: Christos Margiolis (Thu 23 Jul 2026 14:48:09 BST) Committer: Christos Margiolis (Tue 25 Aug 2026 12:55:21 BST) snd_uaudio: Define USB IDs in usbdevs No functional change intended. Sponsored by: The FreeBSD Foundation MFC after: 2 weeks (cherry picked from commit 3e67b90c55b44579c2f73c2fbdeac54087c7495f) M sys/dev/sound/usb/uaudio.c M sys/dev/usb/usbdevs _____________________________________________________________________________________________________________ Commit: ba00f716c1be82937507eec13b96cb8752d9b940 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ba00f716c1be82937507eec13b96cb8752d9b940 Author: Christos Margiolis (Thu 23 Jul 2026 22:54:46 BST) Committer: Christos Margiolis (Tue 25 Aug 2026 12:55:21 BST) sound: Retire sndcard_func sndcard_func is used as an ivar which passes around device info to the PCM and MIDI children in snd_csa(4) and snd_emu10kx(4). Simplify this and retire the need for sndcard_func, by 1) making an ivar only what used to be stored in sndcard_func->varinfo, 2) replacing sndcard_func->func with a child comparison, where needed, for instance in csa_detach(). sndcard_func is harmless in reality, but there is no reason to have the additional complexity. This way we also avoid the structure allocations. Sponsored by: The FreeBSD Foundation MFC after: 2 weeks (cherry picked from commit a753ca9c3f0644611e7dfb453af61896fed6c897) M sys/dev/sound/pci/csa.c M sys/dev/sound/pci/csamidi.c M sys/dev/sound/pci/csapcm.c M sys/dev/sound/pci/emu10kx-midi.c M sys/dev/sound/pci/emu10kx-pcm.c M sys/dev/sound/pci/emu10kx.c M sys/dev/sound/pci/emu10kx.h M sys/dev/sound/pcm/sound.h _____________________________________________________________________________________________________________ Commit: ac4c533936682cf8589da226db4d6bc0fb14bd6c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ac4c533936682cf8589da226db4d6bc0fb14bd6c Author: Martin Matuska (Tue 25 Aug 2026 10:57:08 BST) Committer: Martin Matuska (Tue 25 Aug 2026 10:57:08 BST) zfs: fix mismerge from 2c00a421637 D sys/module/zfs/zfs_config.h D sys/module/zfs/zfs_gitrev.h M sys/modules/zfs/zfs_config.h M sys/modules/zfs/zfs_gitrev.h _____________________________________________________________________________________________________________ Commit: 2c00a4216378d1c7d21cb983d1621a159c755c27 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2c00a4216378d1c7d21cb983d1621a159c755c27 Merge: af0e83d9acaa 71a9f9578616 Author: Martin Matuska (Tue 25 Aug 2026 08:55:56 BST) Committer: Martin Matuska (Tue 25 Aug 2026 08:56:48 BST) zfs: merge openzfs/zfs@71a9f9578 OpenZFS 2.4.4 Notable upstream pull request merges: #18544 eb4199c6a zio_ddt_write: compute have_dvas after taking dde_io_lock #18573 0da2e6b39 Update mtime/ctime when fallocate grows a file #18611 b021ebcdc zfs_ioctl: fix EBUSY race between quota queries and mount #18652 027940e0b zbookmark_compare: handle "marker" bookmarks with negative levels #18657 14ff1853c Fix race between device removal completion and pool export #18673 -multiple delegate: add send:encrypted permission #18688 5f84f4d81 Fix handling of _PC_HAS_HIDDENSYSTEM for FreeBSD #18693 7e8f6ad78 Clean up embedded slog metaslab across txgs #18706 5e8780ff9 ddt_log: Fix refcount tagging for begin/commit #18713 a2c02072f libzfs: fix MS_CRYPT/MS_OVERLAY collision with umount2(2) flags #18720 09a876a38 Fix insufficient locking in dedup verify #18724 a6f557c2c Fix reads for blocks freed after being cloned #18738 b4411799b Fix receive -x according to comment #18749 47f32602d Fix receive of split large blocks with a short trailing chunk #18795 d6bbb80ae Rate limit Direct I/O verify zevents #18802 f5330ea34 libzfs: fallback VDEV_UPATH to VDEV_PATH for non-DMxi devices #18822 292c190b8 libspl: Implement VERIFY_IMPLY and VERIFY_EQUIV #18827 36a398de2 L2ARC: bound the rebuild by the write hand on a first sweep #18833 a052ffc64 zed: let autoexpand see capacity changes on partitioned disks #18835 9623afdb9 mmp: skip non-writeable vdevs during activity check #18838 fee680504 DDT: Fix several bugs in pruning #18840 eb808b3f4 arc: add a few invariant checks in release builds #18841 cc010bbc3 zpool export: return EBUSY when zvol minors are in use #18848 5f9bea114 dmu_recv: Avoid potential null deref #18855 9683c86c4 mmp: do not require writes to mirror legs the config marks absent #18865 51421b0ef Fix DMU bonus hold leak on I/O error #18867 49086325b Add missing checks to zfs_clone_range_replay() #18868 223361144 libzfs: String trimming should not operate out of bounds #18869 17834383e libzfs: Do not call munmap() when mmap() fails #18871 bcf2999db libzfs: don't truncate a resolved vdev path in zpool_vdev_name() #18874 02861fdeb nvpair: Fix operator precedence #18876 ec565e143 nvpair: Improve native handling of unterminated strings #18877 88c5af639 nvpair: i_get_value_size() string array handling tweak #18883 8be87df61 libzfs: don't read a dataset handle after closing it in resume send #18886 c714cc5a3 Fix negative time overflows in DDT pruning #18892 -multiple zhack: add "mmp reclaim" to recover a pool stranded by MMP #18899 9926f72b8 CodeQL: Flag implicit compare-then-assign in branch conditions Obtained from: OpenZFS OpenZFS commit: 71a9f9578616a90c3c14bb59629fb4d31bfd68d1 OpenZFS tag: zfs-2.4.4 _____________________________________________________________________________________________________________ Commit: af0e83d9acaa24b51de507d5b01991cf7713783c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=af0e83d9acaa24b51de507d5b01991cf7713783c Author: Kirk McKusick (Mon 17 Aug 2026 20:15:09 BST) Committer: Kirk McKusick (Tue 25 Aug 2026 03:39:33 BST) Fix transposed arguments in call to calloc(). Reported by GCC 15 warning. No functional change intended. Submitted by: Pedro Giffuni (cherry picked from commit 2cefae4cf34e7d39fc3b27358d7d66a96b3b0056) M sbin/restore/symtab.c _____________________________________________________________________________________________________________ Commit: 0bc69050e40ea18c00a59687e5be14adb4d8b920 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0bc69050e40ea18c00a59687e5be14adb4d8b920 Author: Kevin Bowling (Tue 21 Jul 2026 04:31:57 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:33:01 BST) snd_hdspe: Avoid allocation in the interrupt handler Cache PCM children and drain interrupt callbacks before detach. Allocate the parent softc by its actual size. Reviewed by: br Differential Revision: https://reviews.freebsd.org/D58370 (cherry picked from commit 4c1004c00ff250f2a9e5bff5ae90c25d6b70feb3) M sys/dev/sound/pci/hdspe-pcm.c M sys/dev/sound/pci/hdspe.c M sys/dev/sound/pci/hdspe.h _____________________________________________________________________________________________________________ Commit: b5f46655e0cebb41d67178398707cebf338060ed URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b5f46655e0cebb41d67178398707cebf338060ed Author: Kevin Bowling (Tue 11 Aug 2026 20:41:07 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:30:56 BST) ixgbe: Avoid a signed shift while assembling the PHY ID The PHY identifier word is promoted to signed int when the cast is applied after the shift. Cast the 16-bit register value first so identifiers with their high bit set are assembled as unsigned data. (cherry picked from commit f4bf1da7bac80cbe3ec862f395c22a3c5d176312) M sys/dev/ixgbe/ixgbe_phy.c _____________________________________________________________________________________________________________ Commit: 4cfa05889cf006fcbe8e4081537bf6834a6e6dd5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4cfa05889cf006fcbe8e4081537bf6834a6e6dd5 Author: Kevin Bowling (Tue 11 Aug 2026 20:40:56 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:30:46 BST) igc: Avoid a signed shift while assembling the PHY ID The PHY identifier word is promoted to signed int when the cast is applied after the shift. Cast the 16-bit register value first so identifiers with their high bit set are assembled as unsigned data. (cherry picked from commit f5fd839fe688181e57171850ce51e4dec71e62fd) M sys/dev/igc/igc_phy.c _____________________________________________________________________________________________________________ Commit: 2a21a77a21134bcefeb35fc4d4b32532369ca65f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2a21a77a21134bcefeb35fc4d4b32532369ca65f Author: Kevin Bowling (Tue 11 Aug 2026 20:40:48 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:30:36 BST) e1000: Avoid signed shifts while assembling PHY IDs PHY identifier words are promoted to signed int when the cast is applied after the shift. Cast each 16-bit register value first so identifiers with their high bit set are assembled as unsigned data. (cherry picked from commit 13a7470096567480676e24545b3c1d6404f3f2ec) M sys/dev/e1000/e1000_82571.c M sys/dev/e1000/e1000_ich8lan.c M sys/dev/e1000/e1000_phy.c _____________________________________________________________________________________________________________ Commit: 89587517933f37a89d01f647222b33a2497546d4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=89587517933f37a89d01f647222b33a2497546d4 Author: Kevin Bowling (Tue 11 Aug 2026 20:39:52 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:30:19 BST) igc: Export EEE Low Power Idle counters The driver already accumulates the clear-on-read transmit and receive LPI event counters. Expose the 64-bit totals under the per-device eee sysctl node. (cherry picked from commit 13d78e4b9d0a27128319a1241f00f7ab9aa864bb) M sys/dev/igc/if_igc.c _____________________________________________________________________________________________________________ Commit: 0278a71ccd7f26c67a941b46fbf51ae6d9f71474 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0278a71ccd7f26c67a941b46fbf51ae6d9f71474 Author: Kevin Bowling (Tue 11 Aug 2026 20:36:33 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:30:10 BST) ixl: Avoid a signed PHY capability shift The PHY capability display examines all 32 bits of the firmware bitmap. Use an unsigned value so examining bit 31 does not shift a signed integer into its sign bit. (cherry picked from commit f7427f890c7f34d0842a35eb9df814adad11a95a) M sys/dev/ixl/ixl_pf_main.c _____________________________________________________________________________________________________________ Commit: 07deb662c395e99412b5bb034956b2f529aae6c1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=07deb662c395e99412b5bb034956b2f529aae6c1 Author: Kevin Bowling (Tue 11 Aug 2026 20:36:20 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:29:59 BST) e1000: Avoid a signed manageability VLAN bitmap shift A manageability VLAN can select bit 31 of its VFTA register. Use an unsigned value when constructing the register mask. (cherry picked from commit 392fbdcf2232f12cb973d00ae931740c72d970c6) M sys/dev/e1000/e1000_82571.c _____________________________________________________________________________________________________________ Commit: 43c32e31aa58c57ab50e7cde187c320d90a45a3e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=43c32e31aa58c57ab50e7cde187c320d90a45a3e Author: Kevin Bowling (Tue 11 Aug 2026 20:36:08 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:29:47 BST) ixgbe: Use unsigned register bitmap shifts VLAN, VMDq, and VF reset bit indices can reach 31. Use unsigned values when constructing their 32-bit register masks so the shifts do not operate on signed integers. (cherry picked from commit bf6feffef6c16559333048859b24547acea3dba5) M sys/dev/ixgbe/ixgbe_82598.c M sys/dev/ixgbe/ixgbe_common.c M sys/dev/ixgbe/ixgbe_mbx.c _____________________________________________________________________________________________________________ Commit: 2f2829310aba4530abbcc3e3f9f519fdb86b456c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2f2829310aba4530abbcc3e3f9f519fdb86b456c Author: Kevin Bowling (Tue 11 Aug 2026 20:34:50 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:29:36 BST) ixgbe: Avoid signed overflow in LED register masks LED index three shifts the blink bit into bit 31. Convert the base to the register width before shifting so the operation is unsigned. This is the ixgbe counterpart of the e1000 correction imported from DPDK commit 214cb0d7f1. (cherry picked from commit bbdd3c4692e2869817f77c359b4a2719e716921d) M sys/dev/ixgbe/ixgbe_type.h _____________________________________________________________________________________________________________ Commit: 5a7f59d3b8646680c5c871219497bd30854ab828 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5a7f59d3b8646680c5c871219497bd30854ab828 Author: Kevin Bowling (Tue 11 Aug 2026 20:34:40 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:29:26 BST) ixgbe: Avoid a signed shift while assembling the PBA number The EEPROM word is promoted to signed int before the left shift when the cast is applied to the complete expression. Cast the word first so all 16-bit values are shifted as unsigned data. This is the ixgbe counterpart of the e1000 correction imported from DPDK commit b932270c66. (cherry picked from commit baa6e3af8525244e65a404fa13306fbca7feae9c) M sys/dev/ixgbe/ixgbe_common.c _____________________________________________________________________________________________________________ Commit: 2c545fcf56dbacec8597fae9b59b2fc5e3ccb3cd URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2c545fcf56dbacec8597fae9b59b2fc5e3ccb3cd Author: Kevin Bowling (Tue 11 Aug 2026 20:34:29 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:29:16 BST) igc: Check PHY control register reads Do not modify a zero-initialized PHY control value when its preceding read failed. Leave the PHY unchanged when the void power helpers cannot read its current state. This follows the defensive checks added to the corresponding e1000 helpers. (cherry picked from commit 1121aaa0758baf04bed6f16d4157116b49c25000) M sys/dev/igc/igc_phy.c _____________________________________________________________________________________________________________ Commit: 360982b04b72b12bef0b74ecdc93a6687518f02d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=360982b04b72b12bef0b74ecdc93a6687518f02d Author: Barbara Skobiej (Tue 11 Aug 2026 20:34:13 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:29:05 BST) igc: fix data type in MAC hash DPDK commit message net/e1000/base: fix data type in MAC hash One of the bit shifts in MAC hash calculation triggers a static analysis warning about a potential overflow. Fix the data type to avoid this. Fixes: af75078fece3 ("first public release") Cc: stable@dpdk.org Signed-off-by: Barbara Skobiej Signed-off-by: Anatoly Burakov Acked-by: Bruce Richardson Obtained from: DPDK (458734aaac) (cherry picked from commit 3fc1786aa2a3f590453abb6ea2351a12e19f6b45) M sys/dev/igc/igc_mac.c _____________________________________________________________________________________________________________ Commit: fdfece486292a728394371c25b747129c379c055 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fdfece486292a728394371c25b747129c379c055 Author: Aleksandr Loktionov (Tue 11 Aug 2026 20:34:01 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:28:54 BST) igc: fix MAC address hash bit shift DPDK commit message net/e1000/base: fix MAC address hash bit shift In e1000_hash_mc_addr_generic() the expression: "mc_addr[4] >> 8 - bit_shift", right shifting "mc_addr[4]" shift by more than 7 bits always yields zero, so hash becomes not so different. Add initialization with bit_shift = 1, and add a loop condition to ensure bit_shift will be always in [1..8] range. Fixes: af75078fece3 ("first public release") Cc: stable@dpdk.org Signed-off-by: Aleksandr Loktionov Signed-off-by: Anatoly Burakov Acked-by: Bruce Richardson Obtained from: DPDK (1749e662f6) (cherry picked from commit cba56bc3427db0bb4efc3d0117cda4bdc7717f98) M sys/dev/igc/igc_mac.c _____________________________________________________________________________________________________________ Commit: df83413be3288c0c6b7d9be95f47933d2807204f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=df83413be3288c0c6b7d9be95f47933d2807204f Author: Amir Avivi (Tue 11 Aug 2026 20:33:49 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:28:44 BST) igc: fix iterator type DPDK commit message net/e1000/base: fix iterator type Fix static analysis warning about comparison between types of incompatible width, which might lead to an infinite loop due to overflow. Fixes: af75078fece3 ("first public release") Cc: stable@dpdk.org Signed-off-by: Amir Avivi Signed-off-by: Anatoly Burakov Acked-by: Bruce Richardson Obtained from: DPDK (3d36053991) (cherry picked from commit 5587cb18b168f57a4d68c7e58ec660ab2a5ce4da) M sys/dev/igc/igc_phy.c _____________________________________________________________________________________________________________ Commit: cce182c3b634daedb5d70842b732ddaff703ed62 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cce182c3b634daedb5d70842b732ddaff703ed62 Author: Kevin Bowling (Tue 11 Aug 2026 20:27:45 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:28:34 BST) ixgbe: Avoid a signed multicast bitmap shift The multicast vector bit can be 31. Use an unsigned value so setting the bit cannot shift a signed integer into its sign bit. (cherry picked from commit 8704d29c6cc86f0780dff3d3d17d744106776ad3) M sys/dev/ixgbe/ixgbe_common.c _____________________________________________________________________________________________________________ Commit: c1d2260a3e8caddf2a61567465f39a57d29ee6fc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c1d2260a3e8caddf2a61567465f39a57d29ee6fc Author: Kevin Bowling (Tue 11 Aug 2026 20:27:35 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:28:23 BST) igc: Avoid a signed multicast bitmap shift The multicast hash bit can be 31. Use an unsigned value so setting the bit cannot shift a signed integer into its sign bit. (cherry picked from commit 275ca86f6abffc4ee6e52a6daab06f5e5c21aa05) M sys/dev/igc/igc_mac.c _____________________________________________________________________________________________________________ Commit: daf690aca8421d14bc589d0b5b23f78ebd7a21e8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=daf690aca8421d14bc589d0b5b23f78ebd7a21e8 Author: Kevin Bowling (Tue 11 Aug 2026 18:38:39 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:28:13 BST) e1000: Preserve errors while disabling D0 LPLU Return a PHY write failure immediately when disabling D0 low-power link-up on 82571-family controllers. (cherry picked from commit b1da641d23a95c4e7f61b7a546938ec8fceb47e7) M sys/dev/e1000/e1000_82571.c _____________________________________________________________________________________________________________ Commit: f86489cec3da08c753fa6c75be3749fe5bffb5ae URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f86489cec3da08c753fa6c75be3749fe5bffb5ae Author: Kevin Bowling (Tue 11 Aug 2026 18:35:43 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:27:43 BST) e1000: Verify i210 and i211 multicast table writes The i210 and i211 can occasionally fail to accept multicast table writes, particularly while addresses are added and removed rapidly. Read the table back and rewrite mismatches for up to three passes. This prevents multicast reception from retaining stale filter state while keeping the workaround limited to the affected controllers. (cherry picked from commit bb8d0944b5d53863f00492b69b7bf13d2618fc95) M sys/dev/e1000/e1000_mac.c _____________________________________________________________________________________________________________ Commit: 0b59bbcd52dacdc7c4aeb0f29ef400f8e854b8a3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0b59bbcd52dacdc7c4aeb0f29ef400f8e854b8a3 Author: Kevin Bowling (Tue 11 Aug 2026 20:00:51 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:27:26 BST) e1000: Avoid a signed multicast bitmap shift The multicast hash bit can be 31. Use an unsigned value so setting the bit cannot shift a signed integer into its sign bit. (cherry picked from commit a86d65b2c99bab3fe46389b3b51ad27956dccfe9) M sys/dev/e1000/e1000_mac.c _____________________________________________________________________________________________________________ Commit: 4b1469832d8ba3d2d6b47be4c543e41610c6322d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4b1469832d8ba3d2d6b47be4c543e41610c6322d Author: Barbara Skobiej (Thu 6 Feb 2025 16:08:41 GMT) Committer: Kevin Bowling (Tue 25 Aug 2026 01:27:15 BST) e1000: fix data type in MAC hash DPDK commit message net/e1000/base: fix data type in MAC hash One of the bit shifts in MAC hash calculation triggers a static analysis warning about a potential overflow. Fix the data type to avoid this. Fixes: af75078fece3 ("first public release") Cc: stable@dpdk.org Signed-off-by: Barbara Skobiej Signed-off-by: Anatoly Burakov Acked-by: Bruce Richardson Obtained from: DPDK (458734aaac) (cherry picked from commit a09034d561cbb3792ecc0146b41d4794ab3bda37) M sys/dev/e1000/e1000_mac.c M sys/dev/e1000/e1000_vf.c _____________________________________________________________________________________________________________ Commit: 6b1f636ccceb262439f65157d18b87bcd16c7800 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6b1f636ccceb262439f65157d18b87bcd16c7800 Author: Aleksandr Loktionov (Thu 6 Feb 2025 16:08:40 GMT) Committer: Kevin Bowling (Tue 25 Aug 2026 01:27:04 BST) e1000: fix MAC address hash bit shift DPDK commit message net/e1000/base: fix MAC address hash bit shift In e1000_hash_mc_addr_generic() the expression: "mc_addr[4] >> 8 - bit_shift", right shifting "mc_addr[4]" shift by more than 7 bits always yields zero, so hash becomes not so different. Add initialization with bit_shift = 1, and add a loop condition to ensure bit_shift will be always in [1..8] range. Fixes: af75078fece3 ("first public release") Cc: stable@dpdk.org Signed-off-by: Aleksandr Loktionov Signed-off-by: Anatoly Burakov Acked-by: Bruce Richardson Obtained from: DPDK (1749e662f6) (cherry picked from commit e7ffea395ee8add21b2cce0806285131e12cc454) M sys/dev/e1000/e1000_mac.c M sys/dev/e1000/e1000_vf.c _____________________________________________________________________________________________________________ Commit: 6210ca3bd0d5eb5b6262df7173779361181af8e2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6210ca3bd0d5eb5b6262df7173779361181af8e2 Author: Barbara Skobiej (Thu 6 Feb 2025 16:08:45 GMT) Committer: Kevin Bowling (Tue 25 Aug 2026 01:26:51 BST) e1000: fix reset for 82580 DPDK commit message net/e1000/base: fix reset for 82580 Fix setting device reset status bit in e1000_reset_hw_82580() function for 82580 by first reading the register value, and then setting the device reset bit. Fixes: af75078fece3 ("first public release") Cc: stable@dpdk.org Signed-off-by: Barbara Skobiej Signed-off-by: Anatoly Burakov Acked-by: Bruce Richardson Obtained from: DPDK (88a1eb79ef) (cherry picked from commit 53e4711616041a668ab61f2ce86c9fa139ab67a9) M sys/dev/e1000/e1000_82575.c _____________________________________________________________________________________________________________ Commit: 9f5503e6410fcc165b9acf55a7cd7e3633c3a8cc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9f5503e6410fcc165b9acf55a7cd7e3633c3a8cc Author: Kevin Bowling (Tue 11 Aug 2026 19:59:19 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:26:33 BST) e1000: Export EEE Low Power Idle counters Accumulate the clear-on-read transmit and receive LPI event counters on EEE capable PCH and I350 family devices. Expose the 64-bit totals under the per-device eee sysctl node. (cherry picked from commit eff55e5e098b85855335d8df151787b6b034973f) M sys/dev/e1000/if_em.c _____________________________________________________________________________________________________________ Commit: 32694407f83257522213a66686126687a9a89a56 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=32694407f83257522213a66686126687a9a89a56 Author: Sasha Neftin (Fri 7 Feb 2025 12:45:14 GMT) Committer: Kevin Bowling (Tue 25 Aug 2026 01:26:20 BST) e1000: add LPI counters DPDK commit message net/e1000/base: add LPI counters Add new fields in structure to indicate if EEE LPI entries have been observed on Tx and Rx path. Signed-off-by: Sasha Neftin Signed-off-by: Anatoly Burakov Acked-by: Bruce Richardson Obtained from: DPDK (2e8078ee69) (cherry picked from commit d1c20195c0fae27b6b1d526c03d8844f200e5c86) M sys/dev/e1000/e1000_hw.h M sys/dev/e1000/e1000_mac.c _____________________________________________________________________________________________________________ Commit: c31056c7f90f22d61ed4f88c6c387a2b5137fd53 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c31056c7f90f22d61ed4f88c6c387a2b5137fd53 Author: Dima Ruinskiy (Thu 6 Feb 2025 16:08:46 GMT) Committer: Kevin Bowling (Tue 25 Aug 2026 01:25:41 BST) e1000: fix unchecked return DPDK commit message net/e1000/base: fix unchecked return Static analysis has detected a write that is not checked for errors, leading to ignored error return value. Add a check. Fixes: edcdb3c5f71b ("e1000/base: fix link flap on 82579") Cc: stable@dpdk.org Signed-off-by: Dima Ruinskiy Signed-off-by: Anatoly Burakov Acked-by: Bruce Richardson Obtained from: DPDK (b0b6b50c20) (cherry picked from commit c80aface0f4662c7dc46eed3fbb27b64ab931500) M sys/dev/e1000/e1000_ich8lan.c _____________________________________________________________________________________________________________ Commit: a8a7f8d148b520d5998563dc19f75145ccedfd55 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a8a7f8d148b520d5998563dc19f75145ccedfd55 Author: Kevin Bowling (Tue 11 Aug 2026 17:19:25 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:25:31 BST) e1000: Check PHY control register reads Do not modify a zero-initialized PHY control value when its preceding read failed. (cherry picked from commit c276a80a4e52c065ed631e498ed2c3d284b45c75) M sys/dev/e1000/e1000_phy.c _____________________________________________________________________________________________________________ Commit: a603d5679b60684e586822eb6b35015a6b13374c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a603d5679b60684e586822eb6b35015a6b13374c Author: Kevin Bowling (Tue 11 Aug 2026 17:19:02 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:25:20 BST) e1000: Allow more time for PCH ULP exit Firmware may take up to one second to unconfigure ULP, and affected Lenovo systems have required nearly two seconds. Allow 2.5 seconds before treating the transition as a PHY failure. This extends DPDK commit 7aa4c34581a5 using the field-tested bound from Linux commit 3cf31b1a9eff. (cherry picked from commit e49cb7f757f6db8976b0d247e6a897eab5867634) M sys/dev/e1000/e1000_ich8lan.c _____________________________________________________________________________________________________________ Commit: 93a2e498c1f4db38a6fe2dd1660999c00233beac URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=93a2e498c1f4db38a6fe2dd1660999c00233beac Author: Kevin Bowling (Tue 11 Aug 2026 17:18:33 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:25:10 BST) e1000: Compare decoded PCH LTR latencies The LTR encoding combines a value and a nonlinear scale, so encoded values cannot be compared directly. Decode both the device latency and the platform maximum before deciding whether to clamp the request. (cherry picked from commit 6058dfa40238e2cd6ac6f2377986fdff99d14686) M sys/dev/e1000/e1000_ich8lan.c _____________________________________________________________________________________________________________ Commit: 15d31c10a72d9cb79e7d9f0a83b64c02d4701e73 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=15d31c10a72d9cb79e7d9f0a83b64c02d4701e73 Author: Kevin Bowling (Tue 11 Aug 2026 17:18:06 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:24:59 BST) e1000: Reconfigure modern PCH K1 clock synchronization Meteor Lake and newer PCH generations can lose packets while the MAC and PHY clocks synchronize. Move K1 power-down to P1 and extend the PHY K1 exit timeout before PHY access and after reset. Use the longer 1 Gb/s PLL clock-gate timeout added by Linux so K1 can remain enabled without the power penalty of disabling it. Apply the workaround through the newer PTP and NVP generations. This follows DPDK commits ba54bdc79d94 and d88ef2356ecc, with the longer exit time observed in Linux 578294b8b60d. (cherry picked from commit 17d90d5b9350239a87e66a3612cb9b084b2d75e9) M sys/dev/e1000/e1000_ich8lan.c M sys/dev/e1000/e1000_ich8lan.h _____________________________________________________________________________________________________________ Commit: 01b8155b8c39d267fa56d52b1113e848a653ead5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=01b8155b8c39d267fa56d52b1113e848a653ead5 Author: Kevin Bowling (Tue 11 Aug 2026 17:15:28 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:24:49 BST) e1000: Retry transient MDIC failures on modern PCH Some Meteor Lake and newer systems sporadically fail an MDIC PHY transaction while the MAC and PHY clocks synchronize. Retry twice before reporting the transaction failure. Disable retries around PHY interface transitions where an MDI error is expected. Preserve and restore the configured retry count on every exit from those flows. This follows DPDK commit bdca22d62ff0, extended to the PTP and NVP PCH types. (cherry picked from commit df34ccfc913d6635e957c685d7452a05911eab89) M sys/dev/e1000/e1000_hw.h M sys/dev/e1000/e1000_ich8lan.c M sys/dev/e1000/e1000_phy.c M sys/dev/e1000/e1000_phy.h _____________________________________________________________________________________________________________ Commit: 6a31198b682bafca9d67743627dba55014832d88 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6a31198b682bafca9d67743627dba55014832d88 Author: Pawel Malinowski (Thu 6 Feb 2025 16:08:37 GMT) Committer: Kevin Bowling (Tue 25 Aug 2026 01:24:37 BST) e1000: fix semaphore timeout value DPDK commit message net/e1000/base: fix semaphore timeout value According to datasheet, software ownership of SWSM.SWESMBI bit should not exceed 100ms. Current implementation caused incorrect timeout counter values, where each iteration equals 50us delay. Because of that driver was allowed to wait for semaphore even for 1.5s. This might trigger DPC timeout. This implementation hardcodes value to 2000, which multiplied by 50us, gives 100ms of possible wait time. Fixes: af75078fece3 ("first public release") Cc: stable@dpdk.org Signed-off-by: Pawel Malinowski Signed-off-by: Anatoly Burakov Acked-by: Bruce Richardson Obtained from: DPDK (c8bcaf0f2a) (cherry picked from commit ea2e8b056b455e92830bd1bae56b4d72a42018c3) M sys/dev/e1000/e1000_defines.h M sys/dev/e1000/e1000_mac.c _____________________________________________________________________________________________________________ Commit: 4e0d9b6aff65ddb42eb397c6078b083fdd689e7b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4e0d9b6aff65ddb42eb397c6078b083fdd689e7b Author: Kevin Bowling (Tue 11 Aug 2026 19:58:17 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:24:24 BST) e1000: Separate hardware semaphore policies by family The shared semaphore helper accesses both the 82571 retry counter and the I210 one-time-clear flag. Those fields occupy overlapping members of the device-specific union. On 82571, incrementing the counter thus enables the I210 recovery and clears SMBI after the first timeout. Give 82571, generic 80003/82575, and I210/I211 users distinct acquire paths. Preserve the legacy peer-driver policy on 82571 and one-time recovery on I210. The separation follows the Intel e1000 base code in DPDK. (cherry picked from commit 26251926892585e0746c2b65227e56cf9b2fed58) M sys/dev/e1000/e1000_82571.c M sys/dev/e1000/e1000_82575.c M sys/dev/e1000/e1000_i210.c M sys/dev/e1000/e1000_i210.h M sys/dev/e1000/e1000_mac.c M sys/dev/e1000/e1000_mac.h _____________________________________________________________________________________________________________ Commit: 2902ca80121f6c679192d46b1b3a66df22b9811e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2902ca80121f6c679192d46b1b3a66df22b9811e Author: Kevin Bowling (Tue 11 Aug 2026 19:57:52 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:24:14 BST) e1000: Accept uninitialized Tiger Lake NVM checksums Some transitional Tiger Lake systems shipped with an uninitialized checksum word. Accept that state while continuing to validate newer read-only NVM images. (cherry picked from commit ccb8ad1f645eb77d393eb81ff1b86b213b74bc87) M sys/dev/e1000/e1000_defines.h M sys/dev/e1000/e1000_nvm.c _____________________________________________________________________________________________________________ Commit: d94f3e16141e830a51aff73cf21310e34b7f763c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d94f3e16141e830a51aff73cf21310e34b7f763c Author: Sasha Neftin (Fri 7 Feb 2025 12:45:22 GMT) Committer: Kevin Bowling (Tue 25 Aug 2026 01:23:59 BST) e1000: improve NVM checksum handling DPDK commit message net/e1000/base: improve NVM checksum handling When reading NVM checksum, we may encounter the following scenarios: - Checksum may be invalid, and can be updated - Checksum may be invalid but cannot be updated because NVM is read-only For the latter case, we should just ignore invalid checksum and not attempt to update it. Signed-off-by: Sasha Neftin Signed-off-by: Anatoly Burakov Acked-by: Bruce Richardson Obtained from: DPDK (5241c17f0d) (cherry picked from commit 8e8755e011955d12abab7c2be324429cccf0b975) M sys/dev/e1000/e1000_ich8lan.c _____________________________________________________________________________________________________________ Commit: 4ac5410914dcfc9d6c7d5a7a4fa2e5e8d6a81e1f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4ac5410914dcfc9d6c7d5a7a4fa2e5e8d6a81e1f Author: Menachem Fogel (Wed 20 May 2026 13:52:44 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:23:48 BST) e1000: fix NVM loop bounds and pointer access DPDK commit message net/e1000/base: fix NVM loop bounds and pointer access Improve the NVM checksum routines by ensuring loop bounds are compared at the correct integer width. Use array indexing instead of explicit pointer arithmetic. Fixes: af75078fece3 ("first public release") Cc: stable@dpdk.org Signed-off-by: Menachem Fogel Signed-off-by: Dima Ruinskiy Signed-off-by: Ciara Loftus Acked-by: Bruce Richardson Obtained from: DPDK (39fba42d04) (cherry picked from commit 0fc30789dff08d62c5c830e9aa8c5a0ca9080ad9) M sys/dev/e1000/e1000_82575.c M sys/dev/e1000/e1000_manage.c _____________________________________________________________________________________________________________ Commit: cd5aa46a92b67aafff4b1cc8f22e5b92d7765e09 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cd5aa46a92b67aafff4b1cc8f22e5b92d7765e09 Author: Lukasz Czapnik (Wed 20 May 2026 13:52:40 BST) Committer: Kevin Bowling (Tue 25 Aug 2026 01:23:37 BST) e1000: fix possible variable overflow DPDK commit message net/e1000/base: fix possible variable overflow Bits can be lost as temporary math is done on signed variables and the result is assigned to an unsigned variable. Cast to u32 to force the compiler to do operations on unsigned temporary variables. Fixes: af75078fece3 ("first public release") Cc: stable@dpdk.org Signed-off-by: Lukasz Czapnik Signed-off-by: Ciara Loftus Acked-by: Bruce Richardson Obtained from: DPDK (214cb0d7f1) (cherry picked from commit b3bdffd7a428e43934772850966a3f80638c666f) M sys/dev/e1000/e1000_mac.c _____________________________________________________________________________________________________________ Commit: e7731d8f155e9329f2f4862701037f7ca7a44876 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e7731d8f155e9329f2f4862701037f7ca7a44876 Author: Przemyslaw Ciesielski (Thu 6 Feb 2025 16:08:44 GMT) Committer: Kevin Bowling (Tue 25 Aug 2026 01:23:27 BST) e1000: fix NVM data type in bit shift DPDK commit message net/e1000/base: fix NVM data type in bit shift There is a static analysis warning due to wrong data types being used for NVM read data shifts. Fix it via explicit type cast. Fixes: 38db3f7f50bd ("e1000: update base driver") Cc: stable@dpdk.org Signed-off-by: Przemyslaw Ciesielski Signed-off-by: Anatoly Burakov Acked-by: Bruce Richardson Obtained from: DPDK (b932270c66) (cherry picked from commit 146ae81c6a5c72779bee81f1d5d5913491ae4eef) M sys/dev/e1000/e1000_nvm.c _____________________________________________________________________________________________________________ Commit: 253a2989cd5a0047963196e94ff727005bf3f405 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=253a2989cd5a0047963196e94ff727005bf3f405 Author: Amir Avivi (Thu 6 Feb 2025 16:08:39 GMT) Committer: Kevin Bowling (Tue 25 Aug 2026 01:23:16 BST) e1000: fix iterator type DPDK commit message net/e1000/base: fix iterator type Fix static analysis warning about comparison between types of incompatible width, which might lead to an infinite loop due to overflow. Fixes: af75078fece3 ("first public release") Cc: stable@dpdk.org Signed-off-by: Amir Avivi Signed-off-by: Anatoly Burakov Acked-by: Bruce Richardson Obtained from: DPDK (3d36053991) (cherry picked from commit 15a0db2101cd67eccd0be2ddf1ad18be1ea5afd0) M sys/dev/e1000/e1000_phy.c _____________________________________________________________________________________________________________ Commit: adf4c3336c319cd14de9f45a7a44465aca3a9f36 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=adf4c3336c319cd14de9f45a7a44465aca3a9f36 Author: Christos Margiolis (Fri 21 Aug 2026 01:47:03 BST) Committer: Christos Margiolis (Mon 24 Aug 2026 21:47:13 BST) bcm2835_audio: Remove wrong chn_intr() chn_trigger() calls bcmchan_trigger() with the channel lock held. However, bcmchan_trigger() calls chn_intr(), which also tries to lock, which results in a lock recursion panic. chn_intr() is meant to be called by the interrupt handler and not inside CHANNEL_TRIGGER() methods. Remove the call altogether, the bcm2835_worker_play_start() call that comes after is enough. Fixes: 69cab2d1bfb5 ("Fix locking in bcm2835_audio driver") Reported by: Marco Devesas Campos Tested by: Marco Devesas Campos Sponsored by: The FreeBSD Foundation MFC after: 3 days Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D59055 (cherry picked from commit f0778a6f9ba7045239a0055ebfbd7965d1f162c9) M sys/arm/broadcom/bcm2835/bcm2835_audio.c _____________________________________________________________________________________________________________ Commit: 3f73758036c7be2572d73bb72914801db06f5f4f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3f73758036c7be2572d73bb72914801db06f5f4f Author: Doug Ambrisko (Mon 22 Jun 2026 19:45:42 BST) Committer: Doug Ambrisko (Mon 24 Aug 2026 19:48:45 BST) zfskeys - only prompt if zfskeys and zfskeys_prompt are enabled By default don't block booting with a prompt if a zpool needs a keyboard password to unlock it. To enable prompting for keyboard password during boot require: zfskeys_enable="YES" zfskeys_prompt_enable="YES" to both be enabled. This returns to POLA of prior behaviour. PR: 296130 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296130 ) Reviewed by: kevans Differential Revision: https://reviews.freebsd.org/D57750 (cherry picked from commit 276a3dacdb60b65d65301aced5d8443cc5d27ea2) M libexec/rc/rc.conf M libexec/rc/rc.d/zfskeys _____________________________________________________________________________________________________________ Commit: dd2da25523462dc37db2c55dcb6a14ad6f1fed2b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=dd2da25523462dc37db2c55dcb6a14ad6f1fed2b Author: Mark Johnston (Mon 24 Aug 2026 15:46:28 BST) Committer: Mark Johnston (Mon 24 Aug 2026 19:47:31 BST) ppp: Fix a buffer overflow in the endpoint discriminator set command Reported by: Reo Shiseki MFC after: 3 days Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D59054 (cherry picked from commit 6cb7e368daab6f166b7c8e26367ea6fee4cdd03a) M usr.sbin/ppp/mp.c _____________________________________________________________________________________________________________ Commit: 1bb1d38e4160836c048b79b922a1a3f980e9128b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1bb1d38e4160836c048b79b922a1a3f980e9128b Author: Mark Johnston (Mon 24 Aug 2026 18:05:28 BST) Committer: Mark Johnston (Mon 24 Aug 2026 18:06:24 BST) Revert "atomic: Implement atomic_{set,clear}_8 in _atomic_subword.h" This commit fails to compile for powerpc64le. Just revert it as it's only a cleanup motivated by adding support for KASAN to riscv. This is a direct commit to stable/15. This reverts commit 318915568443f1fdb65faab0f559c872f09628c6. Reported by: jenkins M sys/sys/_atomic_subword.h M sys/vm/vm_page.c _____________________________________________________________________________________________________________ Commit: 0f9fda8fb7b7f8c0fb7619a076a6c4b0dda0b67b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0f9fda8fb7b7f8c0fb7619a076a6c4b0dda0b67b Author: Gleb Smirnoff (Fri 14 Nov 2025 16:01:47 GMT) Committer: Mark Johnston (Mon 24 Aug 2026 16:26:22 BST) unix/stream: fix instant panic w/o INVARIANTS A stupid microoptimization I made leaving empty STAILQ inconsistent is a brainfart that is related to much earlier version of this code, where it was safe to do so. Pointy hat to: glebius Fixes: 69f61cee2efb1eec0640ca7de9b2d51599569a5d (cherry picked from commit 82d8a5029a80a77166dca098b8fedb10d84e4e38) M sys/kern/uipc_usrreq.c _____________________________________________________________________________________________________________ Commit: bf22e0dd97a484eff4fde057a98d0ae102b90903 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bf22e0dd97a484eff4fde057a98d0ae102b90903 Author: Gleb Smirnoff (Fri 14 Nov 2025 02:39:48 GMT) Committer: Mark Johnston (Mon 24 Aug 2026 16:26:22 BST) unix/stream: fix a race with MSG_PEEK on SOCK_SEQPACKET with MSG_EOR The pr_soreceive method first scans the buffer holding the both I/O sx(9) and socket buffer mutex(9) and after figuring out how much needs to be copied out drops the mutex. Since the other side may only append to the buffer, it is safe to continue the operation holding the sx(9) only. However, the code had a bug that it used pointer in the very last mbuf as marker of the place where to stop. This worked both in a case when we drain a buffer completely (marker points at NULL) and in a case when we wanted to stop at MSG_EOR (marker points at next mbuf after MSG_EOR). However, this pointer is not consistent after we dropped the socket buffer mutex. Rewrite the logic to use the data length as bounds for the copyout cycle. Provide a test case that reproduces the race. Note that the race is very hard to hit, thus test will pass on unmodified kernel as well. In a virtual machine I needed to add tsleep(9) for 10 nanoseconds into the middle of function to be able to reproduce. PR: 290658 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=290658 ) Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D53632 Fixes: d15792780760ef94647af9b377b5f0a80e1826bc (cherry picked from commit 69f61cee2efb1eec0640ca7de9b2d51599569a5d) M sys/kern/uipc_usrreq.c M tests/sys/kern/unix_seqpacket_test.c _____________________________________________________________________________________________________________ Commit: 6edbfb48fc1ac02ef12b3ae9e0955ff317c286a3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6edbfb48fc1ac02ef12b3ae9e0955ff317c286a3 Author: Mark Johnston (Fri 24 Jul 2026 22:12:33 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:55 BST) uma: Enqueue full buckets in FIFO order when KASAN is configured We want to defer reuse of free objects, and this is a trivial way to promote that. Suggested by: rlibby Reviewed by: rlibby, alc MFC after: 1 month Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58312 (cherry picked from commit 492cfbe9e2f831fff290e019dae66345146978bd) M sys/vm/uma_core.c _____________________________________________________________________________________________________________ Commit: 646a9f2a13ef5e11d0033207edcacce14d496bab URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=646a9f2a13ef5e11d0033207edcacce14d496bab Author: Mark Johnston (Fri 24 Jul 2026 22:12:21 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:55 BST) uma: Avoid allocating from free buckets when KASAN is enabled When uma_zalloc_arg() hits an empty alloc bucket in the per-CPU cache, it tries swapping the alloc and free buckets in the hope that the free bucket has some items available. If not, it has to lock the zone. Disable this behaviour when KASAN is configured in order to further defer reuse of freed items. This forces a free item to go to the per-domain full bucket cache before it becomes accessible to the allocator. Reviewed by: rlibby MFC after: 1 month Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58270 (cherry picked from commit 666eab3afc52bf20d57c24e98a6aa667433fb7c2) M sys/vm/uma_core.c _____________________________________________________________________________________________________________ Commit: 01f6dff4ac58d4e9573d0b698276bcbd9e2cd643 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=01f6dff4ac58d4e9573d0b698276bcbd9e2cd643 Author: Mark Johnston (Fri 24 Jul 2026 22:12:10 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:55 BST) uma: Make an effort to defer reuse of items when KASAN is enabled When KASAN is configured, make uma_zfree_arg() free items to the per-CPU free bucket, rather than to the alloc bucket. This means that the item won't be recycled immediately the next time a thread goes to allocate an item from that zone on the same CPU. In other words, the item will stay in a quarantine state longer, which helps make KASAN's use-after-free detection more reliable. Reviewed by: rlibby MFC after: 1 month Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58269 (cherry picked from commit 990989c31b4637a23e64598a3d9929079bb9a8de) M sys/vm/uma_core.c _____________________________________________________________________________________________________________ Commit: 4b94ab9b7c5e30cd650c63c029eaac25e3908c18 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4b94ab9b7c5e30cd650c63c029eaac25e3908c18 Author: Mark Johnston (Fri 24 Jul 2026 22:11:58 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:54 BST) uma: Factor out the implementations of uma_zfree_{arg,smr}() The two function both free an item to a UMA zone, but uma_zfree_arg() does so in such as way as to ensure that the item will be the first one returned by a subsequent allocation, while uma_zfree_smr() must defer reuse of the item and therefore never frees to the per-CPU alloc bucket. When KASAN is enabled, we actually want uma_zfree_arg() to behave like uma_zfree_smr(): to improve the reliability of use-after-free detection, reuse of the newly freed item should be deferred for some time. Refactor a bit to make it easier to improve KASAN along these lines: introduce two helper functions, cache_free_item() and cache_free_smr(), which handle most of the work of interacting with the per-CPU caches. A subsequent commit will let uma_zfree_arg() use cache_free_smr() when KASAN is enabled. No functional change intended. Reviewed by: rlibby MFC after: 1 month Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58268 (cherry picked from commit 6337ca19a3637aa72eddf4d62a2eaf7d8df51638) M sys/vm/uma_core.c _____________________________________________________________________________________________________________ Commit: be37b1e0ba7944a77bddc9124f1f4a57195ef37d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=be37b1e0ba7944a77bddc9124f1f4a57195ef37d Author: Mark Johnston (Fri 7 Aug 2026 15:47:06 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:54 BST) netmap: Fix a race in kqueue registration We need to acquire the netmap global lock earlier, to avoid racing with the NETMAP_REQ_REGISTER ioctl handler. Reported by: syzkaller Reviewed by: vmaffione MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58677 (cherry picked from commit 6de818285f066c6705816674c671761dc09bff90) M sys/dev/netmap/netmap_freebsd.c _____________________________________________________________________________________________________________ Commit: a8bde73c4bdee4ee6dba3bd85e61346ad76370fe URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a8bde73c4bdee4ee6dba3bd85e61346ad76370fe Author: Mark Johnston (Fri 7 Aug 2026 15:46:52 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:54 BST) netmap: Fix driver name handling if_initname() requires the caller to ensure that the lifetime of the interface's name buffer contains that of the ifnet itself. netmap_vi_create() wasn't respecting that; we were instead passing the stack-allocated buffer provided by the ioctl handler. While here, add a check to avoid assuming that the caller-provided buffer is nul-terminated. Reported by: syzkaller Reviewed by: vmaffione MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58676 (cherry picked from commit 800d5b7a8a4f5665ced0453e090f8d563366bd47) M sys/dev/netmap/netmap_kern.h M sys/dev/netmap/netmap_vale.c _____________________________________________________________________________________________________________ Commit: bc232869fafeee66dbd773e4ab546dc9aac40471 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bc232869fafeee66dbd773e4ab546dc9aac40471 Author: Mark Johnston (Thu 13 Aug 2026 15:57:54 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:54 BST) unix: Fix mchain handling in uipc_sosend_stream_or_seqpacket() Empty mchains cannot be copied with simple assignment. I think this bug is mostly harmless: if mcnext is empty, then it won't be accessed again before it is reinitialized in the next loop iteration. So the bug only trips an assertion in INVARIANTS kernels and won't be visible otherwise. Add a regression test which triggers this corner case. Reported by: Jan Bramkamp Fixes: d15792780760 ("unix: new implementation of unix/stream & unix/seqpacket") Reviewed by: glebius MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58791 (cherry picked from commit 79e0b69ce8af7d115496991ef66e525a03e9f4fe) M sys/kern/uipc_usrreq.c M tests/sys/kern/unix_passfd_test.c _____________________________________________________________________________________________________________ Commit: 65e2c2279b62dc4107f0a02b0570d35c9203d96f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=65e2c2279b62dc4107f0a02b0570d35c9203d96f Author: Mark Johnston (Tue 11 Aug 2026 17:42:41 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:54 BST) in_mcast: Fix uninitialized variable usage in inm_merge() When the first loop in inm_merge() hits an error, generally because it hit some limit on the number of source filters for a multicast group, inm_merge() tries to atomically roll back changes to the group source filter list. To roll back, it iterates over the global source filter list for the multicast group, starting at the last entry that we updated ("nims"). But, if we have not yet updated any entries, this variable is uninitialized. Initialize it to NULL, so that RB_FOREACH_REVERSE_FROM doesn't visit any source filters in this case. All of the above applies to the v6 case. Reported by: Daniel Birtwhistle MFC after: 1 week Sponsored by: The FreeBSD Foundation (cherry picked from commit b9db5a5b16477863654f92ec653e8464528ef981) M sys/netinet/in_mcast.c M sys/netinet6/in6_mcast.c _____________________________________________________________________________________________________________ Commit: 1b4e0a4467f9f4fb9b3fa5cd8b0597e435a813ef URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1b4e0a4467f9f4fb9b3fa5cd8b0597e435a813ef Author: Mark Johnston (Tue 11 Aug 2026 15:10:23 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:54 BST) vm_object: Augment an assertion in vm_object_split() In some private discussion it was pointed out that vm_object_split()'s pattern of dropping the source object lock looks dangerous in that the initial assumption that OBJ_ONEMAPPING is set may become false. In practice I believe that the map lock holds this flag stable, but let's assert that. Reviewed by: alc, kib MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D58766 (cherry picked from commit 12857d8f4269af7df85605b48ae5e7b2fd810fde) M sys/vm/vm_object.c _____________________________________________________________________________________________________________ Commit: 3a8af1908560f0733baeb7a5750ecfb87a37facd URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3a8af1908560f0733baeb7a5750ecfb87a37facd Author: Mark Johnston (Fri 31 Jul 2026 13:56:31 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:54 BST) malloc: Fix domainset usage in malloc_domainset() for large allocs We should of course pass the provided domainset rather than copying what plain malloc() does. Fixes: 89deca0a3361 ("malloc: make malloc_large closer to standalone") Reviewed by: rlibby MFC after: 3 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58316 (cherry picked from commit 0aca7ce7af35fdf87db2b8866c623b0c275ee3e9) M sys/kern/kern_malloc.c _____________________________________________________________________________________________________________ Commit: c75520c5ec46e2faa208a0d7ac5b4c864afc8c5a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c75520c5ec46e2faa208a0d7ac5b4c864afc8c5a Author: Mark Johnston (Fri 31 Jul 2026 20:47:10 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:54 BST) uma: Fix KMSAN integration with malloc zones In commit 459aa032e872 I dropped kmsan_mark() calls from malloc() on the basis that UMA and kmem_malloc() would handle updates of the KMSAN shadow map. However, I missed that UMA explicitly does not handle this. Modify UMA to only omit origin map updates for malloc zones. Fixes: 459aa032e872 ("malloc: Refactor redzone and sanitizer handling") Reviewed by: rlibby Differential Revision: https://reviews.freebsd.org/D58574 (cherry picked from commit ea7d35526878ebf82f10080795e462d007485bf1) M sys/vm/uma_core.c _____________________________________________________________________________________________________________ Commit: 283a3b762dcc6825a40ec9cd4239fbfc7b2455dc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=283a3b762dcc6825a40ec9cd4239fbfc7b2455dc Author: Mark Johnston (Fri 31 Jul 2026 13:55:59 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:54 BST) malloc: Refactor redzone and sanitizer handling malloc_large() duplicates redzone and KASAN handling that is also present in malloc() and malloc_domainset(). Refactor the implementations to reduce this a bit. Also normalize KMSAN map handling: make malloc() and malloc_domainset() consistent, and do not update the KMSAN shadow map, as we can rely on UMA and kmem_malloc() to handle that. Reviewed by: rlibby MFC after: 3 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58272 (cherry picked from commit 459aa032e87275ebe10847592ea2ddea0c3ed693) M sys/kern/kern_malloc.c _____________________________________________________________________________________________________________ Commit: 4400dcf2b1eb3b54b55efdf9e27cac139c66717a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4400dcf2b1eb3b54b55efdf9e27cac139c66717a Author: Mark Johnston (Fri 31 Jul 2026 13:55:48 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:54 BST) uma: Insert KASAN redzones after slab-allocated items Without this, KASAN has the deficiency that inter-object overflows are not detected most of the time[*] when keg_layout() is able to perfectly pack a slab. Try to overcome this by adjusting the allocation size to include a redzone following the object. With this change, we automatically get a redzone following each item, so any overflow into the redzone will trigger a panic. Most of UMA doesn't need to know about this: at slab allocation time, the whole slab is poisoned, and then kasan_mark_item_valid() will unpoison only the buffer that is available to the consumer. Note that in most zones, most objects will follow another object's redzone, so there is some protection against underflow as well. It might be worthwhile to provide a stronger guarantee here. Add an assertion to item_ctor() that the returned item is properly aligned. I couldn't see any pre-existing checks which verify this. Reviewed by: rlibby MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58271 (cherry picked from commit f51a5e1d9c415d97b86f0f2c8da9cc9ad9dc683b) M sys/vm/uma_core.c _____________________________________________________________________________________________________________ Commit: 318915568443f1fdb65faab0f559c872f09628c6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=318915568443f1fdb65faab0f559c872f09628c6 Author: Mark Johnston (Mon 3 Aug 2026 15:02:33 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:54 BST) atomic: Implement atomic_{set,clear}_8 in _atomic_subword.h Reimplement atomic_{set,clear}_16 using atomic_set_32. Remove emulation of these operations from vm_page.c. Reviewed by: alc, kib MFC after: 2 weeks Differential Revision: https://reviews.freebsd.org/D58580 (cherry picked from commit fb63bc67483ee52245d6161150702974da3d001c) M sys/sys/_atomic_subword.h M sys/vm/vm_page.c _____________________________________________________________________________________________________________ Commit: 06833c3e98137c70309a0c92a96425f521e88c50 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=06833c3e98137c70309a0c92a96425f521e88c50 Author: Mark Johnston (Mon 10 Aug 2026 15:41:33 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:54 BST) unix: Fix some bugs in the SOCK_STREAM receive path The main problem is with the handling of errors from unp_externalize(). It turns out that this was quite broken, and unfortunately it's easy to trigger such errors (e.g., by setting a low per-process fd limit with setrlimit()). In non-peek mode, uipc_soreceive_stream_or_seqpacket() cuts a bunch of mbufs from the head of the socket buffer, to be consumed by userspace. When unp_externalize() returns an error, we splice the removed mbuf chain back onto the head of the socket buffer. This is expensive, but that's ok since such errors are rare. The problem is that this cutting is not correctly implemented: it does not clear the "next" pointer for the last mbuf in the chain, so it still points to the first mbuf still resident in the socket buffer. This means that mc_init_m() creates a chain that still includes the rest of the socket buffer, so splicing the chain back into the socket buffer does not work properly. Fix this: fully detach the control chain from the socket buffer so that we can safely use mc_init_m(). Then, incrementally add data mbufs, taking care to handle "part". Fix some related bugs while here: - Don't swallow the error if unp_externalize() fails and there's nothing left in the socket buffer (i.e., control->m_next == NULL). - Roll back changes to the partially read mbuf. Reviewed by: glebius MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58695 (cherry picked from commit 3b93d3597cc336d5637e12ade8642d589cb0bc8a) M sys/kern/uipc_usrreq.c M sys/sys/mbuf.h M tests/sys/kern/unix_passfd_test.c _____________________________________________________________________________________________________________ Commit: e7070407aa8eae85bc412b9fd80865628b69f22d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e7070407aa8eae85bc412b9fd80865628b69f22d Author: Gleb Smirnoff (Wed 15 Oct 2025 21:01:25 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:54 BST) unix/stream: plug a corner case when control externalization failed while peer has closed its end. Reported by: syzbot+ffcc3612ea266e36604e@syzkaller.appspotmail.com (cherry picked from commit 4548b9f3a8167a340a5086ed51a76d932c9ab3cc) M sys/kern/uipc_usrreq.c _____________________________________________________________________________________________________________ Commit: 08933bbc499fbc6a29149da15024ad9ba4e0cdc9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=08933bbc499fbc6a29149da15024ad9ba4e0cdc9 Author: Mark Johnston (Mon 10 Aug 2026 16:59:10 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:54 BST) riscv/atomic: Provide some additional aliases These are already available and having them defined helps keep the KASAN atomic(9) interceptors uniform. Reviewed by: mhorne MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58680 (cherry picked from commit 4f87828402912a7e451fdbe53161c68faa489128) M sys/riscv/include/atomic.h _____________________________________________________________________________________________________________ Commit: 9e107eba08b162d22435096874852417ba8e9e67 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9e107eba08b162d22435096874852417ba8e9e67 Author: Mark Johnston (Mon 10 Aug 2026 15:41:22 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:53 BST) unix: Simplify uipc_detach() uipc_close() handles detaching a unix socket from the vnode to which it's bound, if any, so doing the same in uipc_detach() is redundant. Moreover, it's conceptually wrong that uipc_detach() might need to handle this: detach happens when there are no remaining references to the socket, and that should include the vnode's reference, even though it's not explicitly counted. No functional change intended. Reviewed by: John Ericson , glebius MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58675 (cherry picked from commit e27d36e038bf0d681d19a07d3512e0dc5adb20c7) M sys/kern/uipc_usrreq.c _____________________________________________________________________________________________________________ Commit: b994e68f44cfe589b98c05a2e46503255e4756b9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b994e68f44cfe589b98c05a2e46503255e4756b9 Author: Mark Johnston (Mon 10 Aug 2026 15:41:04 BST) Committer: Mark Johnston (Mon 24 Aug 2026 16:17:53 BST) unix: Fix a missing initialization in uipc_sosend_stream_or_seqpacket() This could be triggered by an in-kernel sender, of which I can't find any examples. Fixes: d15792780760 ("unix: new implementation of unix/stream & unix/seqpacket") Reviewed by: glebius MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58673 (cherry picked from commit 6dfd710963da7fe6086bcfb705b32b6a3646848f) M sys/kern/uipc_usrreq.c _____________________________________________________________________________________________________________ Commit: 750cc050291298b462abd099191cb995057eb34e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=750cc050291298b462abd099191cb995057eb34e Author: Martin Matuska (Thu 30 Jul 2026 09:13:34 BST) Committer: Martin Matuska (Mon 24 Aug 2026 10:20:52 BST) libarchive: merge from vendor branch libarchive 3.8.9 ChangeLog: https://github.com/libarchive/libarchive/compare/v3.8.7...v3.8.9 Obtained from: libarchive Vendor commit: 27cbc7827172698143e440801fc0ba39ccb4f1f5 MFC after: 2 weeks (cherry picked from commit 185becb1e1bd2657c156f78aeb52edac05ba5fb5) M contrib/libarchive/FREEBSD-Xlist M contrib/libarchive/NEWS M contrib/libarchive/SECURITY.md D contrib/libarchive/build/ci/github_actions/install-macos-dependencies.sh M contrib/libarchive/cpio/cpio.c M contrib/libarchive/cpio/test/test_extract_cpio_absolute_paths.c M contrib/libarchive/cpio/test/test_format_newc.c M contrib/libarchive/libarchive/archive.h M contrib/libarchive/libarchive/archive_acl.c M contrib/libarchive/libarchive/archive_acl_private.h M contrib/libarchive/libarchive/archive_check_magic.c M contrib/libarchive/libarchive/archive_cmdline.c M contrib/libarchive/libarchive/archive_crc32.h M contrib/libarchive/libarchive/archive_cryptor.c M contrib/libarchive/libarchive/archive_cryptor_private.h M contrib/libarchive/libarchive/archive_digest.c M contrib/libarchive/libarchive/archive_digest_private.h M contrib/libarchive/libarchive/archive_endian.h M contrib/libarchive/libarchive/archive_entry.c M contrib/libarchive/libarchive/archive_entry.h M contrib/libarchive/libarchive/archive_entry_link_resolver.c M contrib/libarchive/libarchive/archive_entry_sparse.c M contrib/libarchive/libarchive/archive_entry_strmode.c M contrib/libarchive/libarchive/archive_entry_xattr.c M contrib/libarchive/libarchive/archive_hmac.c M contrib/libarchive/libarchive/archive_hmac_private.h A contrib/libarchive/libarchive/archive_integer.h M contrib/libarchive/libarchive/archive_match.c M contrib/libarchive/libarchive/archive_options.c M contrib/libarchive/libarchive/archive_pack_dev.c M contrib/libarchive/libarchive/archive_parse_date.c M contrib/libarchive/libarchive/archive_pathmatch.c M contrib/libarchive/libarchive/archive_private.h M contrib/libarchive/libarchive/archive_random.c M contrib/libarchive/libarchive/archive_read.c M contrib/libarchive/libarchive/archive_read_append_filter.c M contrib/libarchive/libarchive/archive_read_data_into_fd.c M contrib/libarchive/libarchive/archive_read_disk_entry_from_file.c M contrib/libarchive/libarchive/archive_read_disk_posix.c M contrib/libarchive/libarchive/archive_read_disk_set_standard_lookup.c M contrib/libarchive/libarchive/archive_read_filter.3 M contrib/libarchive/libarchive/archive_read_open.3 M contrib/libarchive/libarchive/archive_read_open_fd.c M contrib/libarchive/libarchive/archive_read_open_file.c M contrib/libarchive/libarchive/archive_read_open_filename.c M contrib/libarchive/libarchive/archive_read_open_memory.c M contrib/libarchive/libarchive/archive_read_private.h M contrib/libarchive/libarchive/archive_read_support_filter_all.c M contrib/libarchive/libarchive/archive_read_support_filter_bzip2.c M contrib/libarchive/libarchive/archive_read_support_filter_compress.c M contrib/libarchive/libarchive/archive_read_support_filter_grzip.c M contrib/libarchive/libarchive/archive_read_support_filter_gzip.c M contrib/libarchive/libarchive/archive_read_support_filter_lrzip.c M contrib/libarchive/libarchive/archive_read_support_filter_lz4.c M contrib/libarchive/libarchive/archive_read_support_filter_lzop.c M contrib/libarchive/libarchive/archive_read_support_filter_program.c M contrib/libarchive/libarchive/archive_read_support_filter_rpm.c M contrib/libarchive/libarchive/archive_read_support_filter_uu.c M contrib/libarchive/libarchive/archive_read_support_filter_xz.c M contrib/libarchive/libarchive/archive_read_support_filter_zstd.c M contrib/libarchive/libarchive/archive_read_support_format_7zip.c M contrib/libarchive/libarchive/archive_read_support_format_all.c M contrib/libarchive/libarchive/archive_read_support_format_ar.c M contrib/libarchive/libarchive/archive_read_support_format_cab.c M contrib/libarchive/libarchive/archive_read_support_format_cpio.c M contrib/libarchive/libarchive/archive_read_support_format_iso9660.c M contrib/libarchive/libarchive/archive_read_support_format_lha.c M contrib/libarchive/libarchive/archive_read_support_format_mtree.c M contrib/libarchive/libarchive/archive_read_support_format_rar.c M contrib/libarchive/libarchive/archive_read_support_format_rar5.c M contrib/libarchive/libarchive/archive_read_support_format_raw.c M contrib/libarchive/libarchive/archive_read_support_format_tar.c M contrib/libarchive/libarchive/archive_read_support_format_warc.c M contrib/libarchive/libarchive/archive_read_support_format_xar.c M contrib/libarchive/libarchive/archive_read_support_format_zip.c M contrib/libarchive/libarchive/archive_string.c M contrib/libarchive/libarchive/archive_time.c M contrib/libarchive/libarchive/archive_util.3 M contrib/libarchive/libarchive/archive_util.c M contrib/libarchive/libarchive/archive_version_details.c M contrib/libarchive/libarchive/archive_write.c M contrib/libarchive/libarchive/archive_write_add_filter.c M contrib/libarchive/libarchive/archive_write_add_filter_b64encode.c M contrib/libarchive/libarchive/archive_write_add_filter_bzip2.c M contrib/libarchive/libarchive/archive_write_add_filter_compress.c M contrib/libarchive/libarchive/archive_write_add_filter_grzip.c M contrib/libarchive/libarchive/archive_write_add_filter_gzip.c M contrib/libarchive/libarchive/archive_write_add_filter_lrzip.c M contrib/libarchive/libarchive/archive_write_add_filter_lz4.c M contrib/libarchive/libarchive/archive_write_add_filter_lzop.c M contrib/libarchive/libarchive/archive_write_add_filter_program.c M contrib/libarchive/libarchive/archive_write_add_filter_uuencode.c M contrib/libarchive/libarchive/archive_write_add_filter_xz.c M contrib/libarchive/libarchive/archive_write_add_filter_zstd.c M contrib/libarchive/libarchive/archive_write_disk_posix.c M contrib/libarchive/libarchive/archive_write_disk_set_standard_lookup.c M contrib/libarchive/libarchive/archive_write_filter.3 M contrib/libarchive/libarchive/archive_write_format.3 M contrib/libarchive/libarchive/archive_write_private.h M contrib/libarchive/libarchive/archive_write_set_format_7zip.c M contrib/libarchive/libarchive/archive_write_set_format_ar.c M contrib/libarchive/libarchive/archive_write_set_format_cpio_binary.c M contrib/libarchive/libarchive/archive_write_set_format_cpio_newc.c M contrib/libarchive/libarchive/archive_write_set_format_cpio_odc.c M contrib/libarchive/libarchive/archive_write_set_format_gnutar.c M contrib/libarchive/libarchive/archive_write_set_format_iso9660.c M contrib/libarchive/libarchive/archive_write_set_format_mtree.c M contrib/libarchive/libarchive/archive_write_set_format_pax.c M contrib/libarchive/libarchive/archive_write_set_format_raw.c M contrib/libarchive/libarchive/archive_write_set_format_shar.c M contrib/libarchive/libarchive/archive_write_set_format_ustar.c M contrib/libarchive/libarchive/archive_write_set_format_v7tar.c M contrib/libarchive/libarchive/archive_write_set_format_warc.c M contrib/libarchive/libarchive/archive_write_set_format_xar.c M contrib/libarchive/libarchive/archive_write_set_format_zip.c M contrib/libarchive/libarchive/archive_write_set_options.3 M contrib/libarchive/libarchive/libarchive-formats.5 M contrib/libarchive/libarchive/test/read_open_memory.c A contrib/libarchive/libarchive/test/test_acl_from_text_overread.c A contrib/libarchive/libarchive/test/test_acl_nfs4_null_id_overflow.c A contrib/libarchive/libarchive/test/test_acl_nfs4_text.c A contrib/libarchive/libarchive/test/test_acl_posix1e_text.c M contrib/libarchive/libarchive/test/test_archive_match_path.c M contrib/libarchive/libarchive/test/test_archive_parse_date.c M contrib/libarchive/libarchive/test/test_archive_pathmatch.c A contrib/libarchive/libarchive/test/test_archive_pathmatch_oob.c A contrib/libarchive/libarchive/test/test_archive_pathmatch_oob_bracket.bin.uu A contrib/libarchive/libarchive/test/test_archive_pathmatch_oob_strchr.bin.uu M contrib/libarchive/libarchive/test/test_archive_read_close_twice.c D contrib/libarchive/libarchive/test/test_archive_read_set_option.c M contrib/libarchive/libarchive/test/test_archive_read_set_options.c A contrib/libarchive/libarchive/test/test_archive_seek_data_unsupported.c M contrib/libarchive/libarchive/test/test_archive_string.c M contrib/libarchive/libarchive/test/test_archive_string_conversion.c A contrib/libarchive/libarchive/test/test_archive_string_conversion_overread.c A contrib/libarchive/libarchive/test/test_archive_write_add_filter.c M contrib/libarchive/libarchive/test/test_archive_write_add_filter_by_name.c M contrib/libarchive/libarchive/test/test_archive_write_set_format_by_name.c M contrib/libarchive/libarchive/test/test_archive_write_set_format_filter_by_ext.c D contrib/libarchive/libarchive/test/test_archive_write_set_format_option.c D contrib/libarchive/libarchive/test/test_archive_write_set_option.c M contrib/libarchive/libarchive/test/test_archive_write_set_options.c M contrib/libarchive/libarchive/test/test_compat_bzip2.c M contrib/libarchive/libarchive/test/test_compat_cpio.c M contrib/libarchive/libarchive/test/test_compat_gtar.c M contrib/libarchive/libarchive/test/test_compat_gtar_large.c M contrib/libarchive/libarchive/test/test_compat_gzip.c M contrib/libarchive/libarchive/test/test_compat_lz4.c M contrib/libarchive/libarchive/test/test_compat_lzip.c M contrib/libarchive/libarchive/test/test_compat_lzma.c M contrib/libarchive/libarchive/test/test_compat_lzop.c M contrib/libarchive/libarchive/test/test_compat_mac.c M contrib/libarchive/libarchive/test/test_compat_perl_archive_tar.c M contrib/libarchive/libarchive/test/test_compat_plexus_archiver_tar.c M contrib/libarchive/libarchive/test/test_compat_solaris_pax_sparse.c M contrib/libarchive/libarchive/test/test_compat_tar_directory.c M contrib/libarchive/libarchive/test/test_compat_tar_hardlink.c M contrib/libarchive/libarchive/test/test_compat_xz.c M contrib/libarchive/libarchive/test/test_compat_zip.c M contrib/libarchive/libarchive/test/test_compat_zstd.c M contrib/libarchive/libarchive/test/test_entry.c M contrib/libarchive/libarchive/test/test_fuzz.c A contrib/libarchive/libarchive/test/test_fuzz_consumer.h M contrib/libarchive/libarchive/test/test_gnutar_filename_encoding.c M contrib/libarchive/libarchive/test/test_open_filename.c M contrib/libarchive/libarchive/test/test_pax_filename_encoding.c M contrib/libarchive/libarchive/test/test_pax_xattr_header.c A contrib/libarchive/libarchive/test/test_read_data_into_fd_size_exceeds_declared.c A contrib/libarchive/libarchive/test/test_read_data_into_fd_size_exceeds_declared_deflate.zip.uu A contrib/libarchive/libarchive/test/test_read_data_into_fd_size_exceeds_declared_stored.zip.uu M contrib/libarchive/libarchive/test/test_read_data_large.c M contrib/libarchive/libarchive/test/test_read_disk_directory_traversals.c R065 contrib/libarchive/libarchive/test/test_archive_write_set_filter_option.c contrib/libarchive/libarchive/test/test_read_files_compressed.c A contrib/libarchive/libarchive/test/test_read_files_compressed.part01.uu A contrib/libarchive/libarchive/test/test_read_files_compressed.part02.uu M contrib/libarchive/libarchive/test/test_read_filter_compress.c M contrib/libarchive/libarchive/test/test_read_filter_grzip.c M contrib/libarchive/libarchive/test/test_read_filter_gzip_recursive.c M contrib/libarchive/libarchive/test/test_read_filter_lrzip.c R066 contrib/libarchive/libarchive/test/test_archive_read_set_filter_option.c contrib/libarchive/libarchive/test/test_read_filter_lz4_raw.c A contrib/libarchive/libarchive/test/test_read_filter_lz4_raw_skip.uu M contrib/libarchive/libarchive/test/test_read_filter_lzop.c M contrib/libarchive/libarchive/test/test_read_filter_lzop_multiple_parts.c M contrib/libarchive/libarchive/test/test_read_filter_program.c M contrib/libarchive/libarchive/test/test_read_filter_uudecode_raw.c R069 contrib/libarchive/libarchive/test/test_archive_read_close_twice_open_fd.c contrib/libarchive/libarchive/test/test_read_filter_zstd_raw.c A contrib/libarchive/libarchive/test/test_read_filter_zstd_raw_loop.uu M contrib/libarchive/libarchive/test/test_read_format_7zip.c A contrib/libarchive/libarchive/test/test_read_format_7zip_archive_properties.7z.uu M contrib/libarchive/libarchive/test/test_read_format_7zip_encryption_data.c M contrib/libarchive/libarchive/test/test_read_format_7zip_encryption_header.c M contrib/libarchive/libarchive/test/test_read_format_7zip_encryption_partially.c A contrib/libarchive/libarchive/test/test_read_format_7zip_entries_oom.7z.uu A contrib/libarchive/libarchive/test/test_read_format_7zip_entries_oom.c A contrib/libarchive/libarchive/test/test_read_format_7zip_folders_oom.7z.uu A contrib/libarchive/libarchive/test/test_read_format_7zip_folders_oom.c M contrib/libarchive/libarchive/test/test_read_format_7zip_issue2765.c M contrib/libarchive/libarchive/test/test_read_format_7zip_malformed.c A contrib/libarchive/libarchive/test/test_read_format_7zip_malformed4.7z.uu A contrib/libarchive/libarchive/test/test_read_format_7zip_malformed_numfiles_oom.7z.uu M contrib/libarchive/libarchive/test/test_read_format_7zip_packinfo_digests.c A contrib/libarchive/libarchive/test/test_read_format_7zip_sfx_boundary_elf.elf.uu A contrib/libarchive/libarchive/test/test_read_format_7zip_sfx_boundary_pe.exe.uu M contrib/libarchive/libarchive/test/test_read_format_cab.c M contrib/libarchive/libarchive/test/test_read_format_cab_filename.c A contrib/libarchive/libarchive/test/test_read_format_cab_lzx_16bit.c A contrib/libarchive/libarchive/test/test_read_format_cab_lzx_16bit.cab.uu A contrib/libarchive/libarchive/test/test_read_format_cab_lzx_e8.c A contrib/libarchive/libarchive/test/test_read_format_cab_lzx_e8.cab.uu A contrib/libarchive/libarchive/test/test_read_format_cab_mszip_oob.c A contrib/libarchive/libarchive/test/test_read_format_cab_multi.c A contrib/libarchive/libarchive/test/test_read_format_cab_multi.p1.cab.uu A contrib/libarchive/libarchive/test/test_read_format_cab_multi.p2.cab.uu M contrib/libarchive/libarchive/test/test_read_format_cpio_afio.c A contrib/libarchive/libarchive/test/test_read_format_cpio_afio_header.part1.cpio.uu A contrib/libarchive/libarchive/test/test_read_format_cpio_afio_header.part2.cpio.uu M contrib/libarchive/libarchive/test/test_read_format_cpio_bin_bz2.c M contrib/libarchive/libarchive/test/test_read_format_cpio_bin_gz.c M contrib/libarchive/libarchive/test/test_read_format_cpio_filename.c M contrib/libarchive/libarchive/test/test_read_format_cpio_svr4_bzip2_rpm.c M contrib/libarchive/libarchive/test/test_read_format_cpio_svr4_gzip.c M contrib/libarchive/libarchive/test/test_read_format_cpio_svr4_gzip_rpm.c A contrib/libarchive/libarchive/test/test_read_format_cpio_symlink_trailer.c A contrib/libarchive/libarchive/test/test_read_format_cpio_symlink_trailer.cpio.uu M contrib/libarchive/libarchive/test/test_read_format_gtar_filename.c M contrib/libarchive/libarchive/test/test_read_format_gtar_gz.c M contrib/libarchive/libarchive/test/test_read_format_gtar_redundant_L.c M contrib/libarchive/libarchive/test/test_read_format_gtar_sparse.c A contrib/libarchive/libarchive/test/test_read_format_gtar_sparse_reuse.tar.uu M contrib/libarchive/libarchive/test/test_read_format_gtar_sparse_skip_entry.c M contrib/libarchive/libarchive/test/test_read_format_huge_rpm.c A contrib/libarchive/libarchive/test/test_read_format_iso_joliet_utf16be_overflow.c A contrib/libarchive/libarchive/test/test_read_format_iso_joliet_utf16be_overflow.iso.uu A contrib/libarchive/libarchive/test/test_read_format_iso_rockridge_ce_loop.iso.Z.uu A contrib/libarchive/libarchive/test/test_read_format_iso_rockridge_zf_overflow.c A contrib/libarchive/libarchive/test/test_read_format_iso_rockridge_zf_overflow.iso.uu R096 contrib/libarchive/libarchive/test/test_read_format_isojoliet_bz2.c contrib/libarchive/libarchive/test/test_read_format_isojoliet_compress.c A contrib/libarchive/libarchive/test/test_read_format_isorr_ce_loop.c R098 contrib/libarchive/libarchive/test/test_read_format_isorr_bz2.c contrib/libarchive/libarchive/test/test_read_format_isorr_compress.c R098 contrib/libarchive/libarchive/test/test_read_format_isorr_new_bz2.c contrib/libarchive/libarchive/test/test_read_format_isorr_new_compress.c R098 contrib/libarchive/libarchive/test/test_read_format_isozisofs_bz2.c contrib/libarchive/libarchive/test/test_read_format_isozisofs_compress.c M contrib/libarchive/libarchive/test/test_read_format_lha.c M contrib/libarchive/libarchive/test/test_read_format_lha_bugfix_0.c M contrib/libarchive/libarchive/test/test_read_format_lha_filename.c M contrib/libarchive/libarchive/test/test_read_format_lha_filename_utf16.c A contrib/libarchive/libarchive/test/test_read_format_lha_symlink_missing_target.c A contrib/libarchive/libarchive/test/test_read_format_lha_symlink_missing_target.lzh.uu M contrib/libarchive/libarchive/test/test_read_format_mtree.c M contrib/libarchive/libarchive/test/test_read_format_pax_bz2.c M contrib/libarchive/libarchive/test/test_read_format_rar.c A contrib/libarchive/libarchive/test/test_read_format_rar3_lowdist_reset.rar.uu M contrib/libarchive/libarchive/test/test_read_format_rar5.c A contrib/libarchive/libarchive/test/test_read_format_rar5_bad_filter.c A contrib/libarchive/libarchive/test/test_read_format_rar5_bad_tables.c A contrib/libarchive/libarchive/test/test_read_format_rar5_bad_tables.rar.uu A contrib/libarchive/libarchive/test/test_read_format_rar5_block_hdr_fail_loop.c A contrib/libarchive/libarchive/test/test_read_format_rar5_bytes_remaining_underflow.rar.uu A contrib/libarchive/libarchive/test/test_read_format_rar5_main_block_extra_bytes.rar.uu A contrib/libarchive/libarchive/test/test_read_format_rar5_skip_block_extra_bytes.rar.uu A contrib/libarchive/libarchive/test/test_read_format_rar5_unpacked_size_exceeds_declared.rar.uu M contrib/libarchive/libarchive/test/test_read_format_rar_encryption.c M contrib/libarchive/libarchive/test/test_read_format_rar_encryption_data.c M contrib/libarchive/libarchive/test/test_read_format_rar_encryption_header.c M contrib/libarchive/libarchive/test/test_read_format_rar_encryption_partially.c M contrib/libarchive/libarchive/test/test_read_format_rar_invalid1.c A contrib/libarchive/libarchive/test/test_read_format_rar_newsub_rr_over_1m.rar.uu M contrib/libarchive/libarchive/test/test_read_format_rar_overflow.c A contrib/libarchive/libarchive/test/test_read_format_rar_seek_data_cursor0.rar.uu A contrib/libarchive/libarchive/test/test_read_format_rar_unbound_staticdata.rar.uu R062 contrib/libarchive/libarchive/test/test_archive_read_close_twice_open_filename.c contrib/libarchive/libarchive/test/test_read_format_tar_acl_oob_read.c A contrib/libarchive/libarchive/test/test_read_format_tar_acl_oob_read.tar.uu M contrib/libarchive/libarchive/test/test_read_format_tar_concatenated.c M contrib/libarchive/libarchive/test/test_read_format_tar_empty_filename.c M contrib/libarchive/libarchive/test/test_read_format_tar_empty_pax.c M contrib/libarchive/libarchive/test/test_read_format_tar_empty_with_gnulabel.c M contrib/libarchive/libarchive/test/test_read_format_tar_filename.c M contrib/libarchive/libarchive/test/test_read_format_tar_mac_metadata.c M contrib/libarchive/libarchive/test/test_read_format_tar_pax_g_large.c M contrib/libarchive/libarchive/test/test_read_format_tar_pax_large_attr.c M contrib/libarchive/libarchive/test/test_read_format_tar_pax_negative_time.c A contrib/libarchive/libarchive/test/test_read_format_tar_pax_sun_holesdata.c A contrib/libarchive/libarchive/test/test_read_format_tar_pax_sun_holesdata.tar.uu A contrib/libarchive/libarchive/test/test_read_format_tar_pax_timestamps.c A contrib/libarchive/libarchive/test/test_read_format_tar_pax_timestamps.tar.uu A contrib/libarchive/libarchive/test/test_read_format_tar_timestamp_overflow.c A contrib/libarchive/libarchive/test/test_read_format_tar_timestamp_overflow.tar.uu M contrib/libarchive/libarchive/test/test_read_format_tgz.c M contrib/libarchive/libarchive/test/test_read_format_ustar_filename.c M contrib/libarchive/libarchive/test/test_read_format_warc.c M contrib/libarchive/libarchive/test/test_read_format_xar.c A contrib/libarchive/libarchive/test/test_read_format_xar_atou64_overread.xar.uu A contrib/libarchive/libarchive/test/test_read_format_xar_base64_oob.xar.uu A contrib/libarchive/libarchive/test/test_read_format_xar_large_mode.xar.uu A contrib/libarchive/libarchive/test/test_read_format_xar_parse_time_overread.xar.uu M contrib/libarchive/libarchive/test/test_read_format_zip.c M contrib/libarchive/libarchive/test/test_read_format_zip_7075_utf8_paths.c M contrib/libarchive/libarchive/test/test_read_format_zip_comment_stored.c M contrib/libarchive/libarchive/test/test_read_format_zip_encryption_data.c M contrib/libarchive/libarchive/test/test_read_format_zip_encryption_header.c M contrib/libarchive/libarchive/test/test_read_format_zip_encryption_partially.c M contrib/libarchive/libarchive/test/test_read_format_zip_filename.c M contrib/libarchive/libarchive/test/test_read_format_zip_jar.c M contrib/libarchive/libarchive/test/test_read_format_zip_mac_metadata.c M contrib/libarchive/libarchive/test/test_read_format_zip_malformed.c M contrib/libarchive/libarchive/test/test_read_format_zip_nested.c M contrib/libarchive/libarchive/test/test_read_format_zip_nofiletype.c M contrib/libarchive/libarchive/test/test_read_format_zip_padded.c A contrib/libarchive/libarchive/test/test_read_format_zip_pkware_unix.zip.uu A contrib/libarchive/libarchive/test/test_read_format_zip_ppmd8_aes256_streaming.zipx.uu M contrib/libarchive/libarchive/test/test_read_format_zip_sfx.c A contrib/libarchive/libarchive/test/test_read_format_zip_size_exceeds_declared.c A contrib/libarchive/libarchive/test/test_read_format_zip_size_exceeds_declared_deflate.zip.uu A contrib/libarchive/libarchive/test/test_read_format_zip_size_exceeds_declared_stored.zip.uu A contrib/libarchive/libarchive/test/test_read_format_zip_symlink_unsupported_compression.c A contrib/libarchive/libarchive/test/test_read_format_zip_symlink_unsupported_compression.zip.uu M contrib/libarchive/libarchive/test/test_read_format_zip_traditional_encryption_data.c A contrib/libarchive/libarchive/test/test_read_format_zip_uncompressed_size_off_by_4gib.c A contrib/libarchive/libarchive/test/test_read_format_zip_uncompressed_size_off_by_4gib.zip.uu M contrib/libarchive/libarchive/test/test_read_format_zip_winzip_aes.c A contrib/libarchive/libarchive/test/test_read_format_zip_winzip_aes256_large_bzip2.zip.uu A contrib/libarchive/libarchive/test/test_read_format_zip_winzip_aes256_large_lzma.zip.uu A contrib/libarchive/libarchive/test/test_read_format_zip_winzip_aes256_large_ppmd.zip.uu A contrib/libarchive/libarchive/test/test_read_format_zip_winzip_aes256_large_xz.zip.uu A contrib/libarchive/libarchive/test/test_read_format_zip_winzip_aes256_large_zstd.zip.uu M contrib/libarchive/libarchive/test/test_read_format_zip_winzip_aes_large.c M contrib/libarchive/libarchive/test/test_read_format_zip_with_invalid_traditional_eocd.c M contrib/libarchive/libarchive/test/test_read_format_zip_zip64.c A contrib/libarchive/libarchive/test/test_read_format_zip_zipx_encrypted.c A contrib/libarchive/libarchive/test/test_read_format_zip_zipx_lzma_oom.c A contrib/libarchive/libarchive/test/test_read_format_zip_zipx_lzma_oom.zipx.uu M contrib/libarchive/libarchive/test/test_read_pax_empty_val_no_nl.c M contrib/libarchive/libarchive/test/test_read_pax_xattr_rht_security_selinux.c M contrib/libarchive/libarchive/test/test_read_pax_xattr_schily.c M contrib/libarchive/libarchive/test/test_read_set_format.c M contrib/libarchive/libarchive/test/test_sparse_basic.c M contrib/libarchive/libarchive/test/test_ustar_filename_encoding.c M contrib/libarchive/libarchive/test/test_write_disk_appledouble.c M contrib/libarchive/libarchive/test/test_write_disk_hfs_compression.c M contrib/libarchive/libarchive/test/test_write_disk_mac_metadata.c M contrib/libarchive/libarchive/test/test_write_disk_no_hfs_compression.c M contrib/libarchive/libarchive/test/test_write_disk_secure.c M contrib/libarchive/libarchive/test/test_write_disk_secure744.c M contrib/libarchive/libarchive/test/test_write_disk_secure745.c M contrib/libarchive/libarchive/test/test_write_disk_secure746.c M contrib/libarchive/libarchive/test/test_write_disk_secure_noabsolutepaths.c M contrib/libarchive/libarchive/test/test_write_filter_b64encode.c M contrib/libarchive/libarchive/test/test_write_filter_bzip2.c M contrib/libarchive/libarchive/test/test_write_filter_gzip.c M contrib/libarchive/libarchive/test/test_write_filter_lrzip.c M contrib/libarchive/libarchive/test/test_write_filter_lz4.c M contrib/libarchive/libarchive/test/test_write_filter_lzip.c M contrib/libarchive/libarchive/test/test_write_filter_lzma.c M contrib/libarchive/libarchive/test/test_write_filter_lzop.c M contrib/libarchive/libarchive/test/test_write_filter_uuencode.c M contrib/libarchive/libarchive/test/test_write_filter_xz.c M contrib/libarchive/libarchive/test/test_write_filter_zstd.c M contrib/libarchive/libarchive/test/test_write_format_7zip.c M contrib/libarchive/libarchive/test/test_write_format_7zip_empty.c M contrib/libarchive/libarchive/test/test_write_format_7zip_large.c M contrib/libarchive/libarchive/test/test_write_format_gnutar.c M contrib/libarchive/libarchive/test/test_write_format_gnutar_filenames.c A contrib/libarchive/libarchive/test/test_write_format_gnutar_huge.c M contrib/libarchive/libarchive/test/test_write_format_iso9660.c M contrib/libarchive/libarchive/test/test_write_format_iso9660_boot.c A contrib/libarchive/libarchive/test/test_write_format_iso9660_bugs.c M contrib/libarchive/libarchive/test/test_write_format_iso9660_empty.c M contrib/libarchive/libarchive/test/test_write_format_iso9660_filename.c A contrib/libarchive/libarchive/test/test_write_format_iso9660_joliet_id.c A contrib/libarchive/libarchive/test/test_write_format_iso9660_joliet_overflow.bin.uu A contrib/libarchive/libarchive/test/test_write_format_iso9660_null_deref.bin.uu R051 contrib/libarchive/libarchive/test/test_archive_read_set_format_option.c contrib/libarchive/libarchive/test/test_write_format_iso9660_rockridge.c A contrib/libarchive/libarchive/test/test_write_format_iso9660_rockridge_overflow.c A contrib/libarchive/libarchive/test/test_write_format_iso9660_underflow.bin.uu M contrib/libarchive/libarchive/test/test_write_format_iso9660_zisofs.c A contrib/libarchive/libarchive/test/test_write_format_iso9660_zisofs_overflow.c M contrib/libarchive/libarchive/test/test_write_format_mtree.c A contrib/libarchive/libarchive/test/test_write_format_mtree_absolute.c A contrib/libarchive/libarchive/test/test_write_format_mtree_dotdot.c A contrib/libarchive/libarchive/test/test_write_format_mtree_null_deref.bin.uu A contrib/libarchive/libarchive/test/test_write_format_mtree_null_deref.c M contrib/libarchive/libarchive/test/test_write_format_mtree_preset_digests.c M contrib/libarchive/libarchive/test/test_write_format_pax.c A contrib/libarchive/libarchive/test/test_write_format_pax_align.c A contrib/libarchive/libarchive/test/test_write_format_tar_empty_dirname.c M contrib/libarchive/libarchive/test/test_write_format_tar_ustar.c M contrib/libarchive/libarchive/test/test_write_format_warc.c M contrib/libarchive/libarchive/test/test_write_format_xar.c A contrib/libarchive/libarchive/test/test_write_format_xar_bugs.c M contrib/libarchive/libarchive/test/test_write_format_xar_empty.c A contrib/libarchive/libarchive/test/test_write_format_xar_fflags.c A contrib/libarchive/libarchive/test/test_write_format_xar_strcpy_overlap.bin.uu A contrib/libarchive/libarchive/test/test_write_format_xar_underflow.bin.uu M contrib/libarchive/libarchive/test/test_write_format_zip.c R097 contrib/libarchive/libarchive/test/test_write_format_zip_compression_lzmaxz.c contrib/libarchive/libarchive/test/test_write_format_zip_compression_lzma_xz.c A contrib/libarchive/libarchive/test/test_write_format_zip_empty_pathname.c A contrib/libarchive/libarchive/test/test_write_format_zip_long_pathname.c M contrib/libarchive/libarchive/test/test_write_format_zip_windows_path.c M contrib/libarchive/libarchive/test/test_write_format_zip_zip64.c M contrib/libarchive/libarchive/test/test_write_read_format_zip.c M contrib/libarchive/libarchive/xxhash.c A contrib/libarchive/libarchive_fe/lafe_fnmatch.c A contrib/libarchive/libarchive_fe/lafe_fnmatch.h M contrib/libarchive/tar/bsdtar.h M contrib/libarchive/tar/read.c M contrib/libarchive/tar/subst.c M contrib/libarchive/tar/test/test_option_P_upper.c M contrib/libarchive/tar/test/test_option_mtime.c M contrib/libarchive/tar/test/test_option_s.c A contrib/libarchive/tar/test/test_option_stdout_size_exceeds_declared.c A contrib/libarchive/tar/test/test_option_stdout_size_exceeds_declared_deflate.zip.uu A contrib/libarchive/tar/test/test_option_stdout_size_exceeds_declared_stored.zip.uu M contrib/libarchive/tar/test/test_stdio.c M contrib/libarchive/tar/util.c M contrib/libarchive/tar/write.c M contrib/libarchive/test_utils/test_main.c M contrib/libarchive/test_utils/test_utils.c M contrib/libarchive/unzip/bsdunzip.c M contrib/libarchive/unzip/bsdunzip_platform.h M contrib/libarchive/unzip/test/test_I.c M contrib/libarchive/unzip/test/test_P_encryption.c A contrib/libarchive/unzip/test/test_f.c A contrib/libarchive/unzip/test/test_f_new.zip.uu A contrib/libarchive/unzip/test/test_f_old.zip.uu A contrib/libarchive/unzip/test/test_symlink.c A contrib/libarchive/unzip/test/test_symlink_1.zip.uu A contrib/libarchive/unzip/test/test_symlink_2.zip.uu A contrib/libarchive/unzip/test/test_symlink_dotdot.c A contrib/libarchive/unzip/test/test_symlink_dotdot.zip.uu A contrib/libarchive/unzip/test/test_u.c A contrib/libarchive/unzip/test/test_u_new.zip.uu A contrib/libarchive/unzip/test/test_u_old.zip.uu M lib/libarchive/tests/Makefile M usr.bin/tar/tests/Makefile M usr.bin/unzip/tests/Makefile _____________________________________________________________________________________________________________ Commit: 86255d85e228d0e7e7b18c225e86b9040da17656 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=86255d85e228d0e7e7b18c225e86b9040da17656 Author: Kevin Bowling (Mon 24 Aug 2026 09:18:43 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 09:18:43 BST) ixl: Fix build after VF reset changes VF_FLAG_INITIALIZED belongs to the SR-IOV status-reporting interface, which was not merged to stable/15. The VF reset MFCs accidentally kept two status-only clears without the flag definition or the corresponding set operation. Remove the clears rather than pulling the unrelated reporting interface into stable/15. They do not participate in hardware reset sequencing. Fixes: d252dd2a841c ("ixl: Rebuild VF resources after a PF reset") Fixes: 1319574637fb ("ixl: Quiesce VF DMA before a PF reset") M sys/dev/ixl/ixl_pf_iov.c _____________________________________________________________________________________________________________ Commit: ef676ecff1c36b9273394c5628313e65ba420a20 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ef676ecff1c36b9273394c5628313e65ba420a20 Author: Kristof Provost (Fri 7 Aug 2026 15:07:09 BST) Committer: Kristof Provost (Mon 24 Aug 2026 08:17:28 BST) pfsync: handle large MTU pfsync interfaces pfsync packets were allocated with m_get2(), which can't return packets larger than MJUMPAGESIZE. As a result 9k MTU pfsync interfaces simply didn't work. Use m_get3(), which can allocate sufficiently large mbufs. Extend the pfsync:bulk test case to provoke this problem. PR: 297307 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297307 ) MFC after: 2 weeks Sponsored by: Rubicon Communications, LLC ("Netgate") (cherry picked from commit 7e2781fdcfdbe489cc07572d33dc36bca06a342d) M sys/netpfil/pf/if_pfsync.c M tests/sys/netpfil/pf/pfsync.sh _____________________________________________________________________________________________________________ Commit: 008259bb83551cf3d61f273b9bab682e00fa7940 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=008259bb83551cf3d61f273b9bab682e00fa7940 Author: Cy Schubert (Tue 18 Aug 2026 00:23:32 BST) Committer: Cy Schubert (Mon 24 Aug 2026 06:35:13 BST) ipfilter: Fix checksum update for NAT_DIVERTOUT When taking a snapshot of the before ip_len (s1) for comparison with the after-translated ip_len (s2), we must convert it from network to host byte order before we can use it. Add the missing ntohs() call. PR: 296944 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296944 ) MFC after: 3 days (cherry picked from commit c08a97fa27b914988ef092352872b2f455abb7c3) M sys/netpfil/ipfilter/netinet/ip_nat.c _____________________________________________________________________________________________________________ Commit: dfbc676666f94bc58ab963b57334179775a83653 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=dfbc676666f94bc58ab963b57334179775a83653 Author: Kevin Bowling (Mon 10 Aug 2026 17:02:16 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:52:19 BST) ixgbe: Recognize production X550 PHY IDs According to Linux 5f1c3589b0f0, the X550 PHY classifier still matches an alpha silicon ID, while the shared definitions contain the two production IDs. This can leave production hardware on the generic probing path and issue unnecessary PHY queries. (cherry picked from commit 392f0af6685a06e89fecdc38cc2e910d2b84d738) M sys/dev/ixgbe/ixgbe_phy.c _____________________________________________________________________________________________________________ Commit: dc670f157cc435c20859aa61731618c5032e2d30 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=dc670f157cc435c20859aa61731618c5032e2d30 Author: Kevin Bowling (Mon 10 Aug 2026 16:53:10 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:52:07 BST) ixgbe: Preserve the full VF RSS domain in the shared RETA The 82599 and X540 share the global RSS redirection table between the PF and its VFs. Programming that table from the PF queue count prevents a VF from using queue indices absent from the PF layout. A one-queue PF consequently directs every flow for a two- or four-queue VF to queue zero. Program at least four queue indices while SR-IOV is active. Each pool PSRTYPE.RQPL field masks the shared table to the queue subset available to that function, so the PF can continue using fewer queues. (cherry picked from commit 8b668bc7e7c8b0a1bcb018360a4aafa445ff554f) M sys/dev/ixgbe/if_ix.c _____________________________________________________________________________________________________________ Commit: 7316de43009550eff8348c763f842efb742c5e6e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7316de43009550eff8348c763f842efb742c5e6e Author: Kevin Bowling (Mon 10 Aug 2026 17:29:24 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:51:57 BST) ixgbe: Add 10GBase-BX BiDi SFP+ module support 10G-BX optics use paired wavelengths to carry 10 Gb/s Ethernet over a single strand of single-mode fiber. Their 10G compliance byte is empty, so identify them from the SFF-8472 nominal signaling rate and single-mode reach fields. When an EEPROM also advertises 1G BASE-BX10, give the complete 10G bitrate and reach signature precedence. Otherwise retain FreeBSD's permissive 1G-BX identification rather than requiring a nominal 1.3 GBd rate. Relnotes: yes (cherry picked from commit f9ce33b0d8ef233063bd6c27bdba2580f97d9094) M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/ixgbe_82599.c M sys/dev/ixgbe/ixgbe_phy.c M sys/dev/ixgbe/ixgbe_phy.h M sys/dev/ixgbe/ixgbe_type.h M sys/dev/ixgbe/ixgbe_x550.c _____________________________________________________________________________________________________________ Commit: 7dd9e379c0238e5612fd3db1a2deb207ad10dc58 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7dd9e379c0238e5612fd3db1a2deb207ad10dc58 Author: Kevin Bowling (Mon 10 Aug 2026 17:28:14 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:51:47 BST) net: Add ifmedia support for 10GBase-BX BiDi 10GBase-BX uses paired wavelengths to carry both directions over a single strand of single-mode fiber. The optics must be paired so that the transmit and receive wavelengths cross over. (cherry picked from commit 4220b52453c9701922955dcc1c1e1554d6a9f3ae) M sys/net/if_media.h _____________________________________________________________________________________________________________ Commit: 66972c47226128ed56e0258d7873f2fde72ad44a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=66972c47226128ed56e0258d7873f2fde72ad44a Author: Kevin Bowling (Mon 10 Aug 2026 16:12:43 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:51:35 BST) ixgbe: Expose EEE LPI event counters X550-family devices provide clear-on-read counters for transmit and receive Low Power Idle events. Accumulate each register once in the normal statistics poll and expose the monotonic totals below the eee sysctl node. Document the counters together with the existing EEE control. Obtained from: Intel ix 3.4.39 (cherry picked from commit ff86fd4f36618dacf1628180034c312c70294276) M share/man/man4/ix.4 M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/ixgbe_type.h _____________________________________________________________________________________________________________ Commit: aa7d9c250b8ca33eb808e028d6bb211cec5a5912 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=aa7d9c250b8ca33eb808e028d6bb211cec5a5912 Author: Kevin Bowling (Mon 10 Aug 2026 16:11:01 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:51:25 BST) ixv: Report multigigabit link speeds The VF link-status path can receive 2.5 and 5 Gb/s speed bits from X550-family PFs, but media reporting has no cases for them. The bootverbose message also assumes every non-10-Gb/s link is 1 Gb/s. Expose the corresponding ifmedia subtypes and derive the diagnostic speed through the shared link-speed conversion helper. (cherry picked from commit a884921abbaf52ff862a32ff6806bf071974faa6) M sys/dev/ixgbe/if_ixv.c _____________________________________________________________________________________________________________ Commit: c8d38edfa266266a2ad20595c248124b3c4e138d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c8d38edfa266266a2ad20595c248124b3c4e138d Author: Kevin Bowling (Mon 10 Aug 2026 16:09:56 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:51:15 BST) ixgbe: Compare flow control against requested mode The flow-control sysctl represents the configured policy, while current_mode is the mode negotiated with the link partner. Comparing a new request with current_mode can needlessly reprogram an unchanged policy or skip a requested policy change that happens to match the current negotiation result. Compare with requested_mode before deciding that no update is needed. (cherry picked from commit c410551b9feadf9b65f920fd25714fcda8299a56) M sys/dev/ixgbe/if_ix.c _____________________________________________________________________________________________________________ Commit: c7f0473df2ed901f9c6559fb152c457dc4296c13 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c7f0473df2ed901f9c6559fb152c457dc4296c13 Author: Kevin Bowling (Mon 10 Aug 2026 16:09:41 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:51:04 BST) ixgbe: Validate EEPROM checksum section bounds The generic checksum walker trusts NVM section pointers and lengths and iterates with a 16-bit index. A corrupt section that crosses the end of the EEPROM can wrap the index and leave the driver in an effectively unbounded read loop during attach. Validate each non-empty section against the discovered EEPROM word size before reading it, and use widened arithmetic for the inclusive end and iterator. (cherry picked from commit be3e1068ea8699fb719691453899ca20a601fe1d) M sys/dev/ixgbe/ixgbe_common.c _____________________________________________________________________________________________________________ Commit: 7ea168178477c211dc288e7e04165dca53f6a307 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7ea168178477c211dc288e7e04165dca53f6a307 Author: Kevin Bowling (Mon 10 Aug 2026 16:09:29 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:50:20 BST) ixgbe: Restore missed packet accounting missed_rx and total_missed_rx are never populated. As a result, the GPRC erratum workaround does not remove missed packets and iqdrops always remains zero. The rx_missed_packets sysctl and input-error total also expose only MPC bank zero. Read and accumulate all eight MPC banks. Use the interval total to correct GPRC and the cumulative total for iqdrops, input errors, and the aggregate sysctl. This matches DPDK's coverage of the hardware banks. (cherry picked from commit 660099c985e8bfc931b01398715441c90cf0d4db) M sys/dev/ixgbe/if_ix.c _____________________________________________________________________________________________________________ Commit: 09132e3cc15d6202cbc67310e5399358256baf4b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=09132e3cc15d6202cbc67310e5399358256baf4b Author: Kevin Bowling (Mon 10 Aug 2026 16:08:49 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:50:10 BST) ixgbe: Preserve VF jumbo frame size across PF resets sc->max_frame_size represents the largest frame requested by the PF or an active VF. The MTU callback replaces it with the PF frame size, so a subsequent reinitialization can program MHADD below an active VF's jumbo-frame request. Recompute the aggregate before hardware initialization and use it when programming MHADD. Recompute after each VF LPE request as well, so a reduced request can lower the hardware limit when no other function needs the previous value. (cherry picked from commit 877f0ee40c2af801c5ca758a37b3ebddc560dad2) M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/if_sriov.c _____________________________________________________________________________________________________________ Commit: 1319574637fb15f3ce176ce1638e25db05340c9a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1319574637fb15f3ce176ce1638e25db05340c9a Author: Kevin Bowling (Mon 10 Aug 2026 12:56:57 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:49:57 BST) ixl: Quiesce VF DMA before a PF reset A PF reset has a warning interval before the hardware reset begins. Cooperative VF drivers respond to the reset event by stopping and releasing their receive buffers, but notifying VFs did not stop the hardware queues. An active VF could therefore DMA through its old rings into freed mbuf clusters during the warning interval. Put every enabled VF in reset, drain its PCIe transactions, disable its queues, wait for receive queue shutdown, and drain transactions again before tearing down the PF HMC and AdminQ. Hold VFs in reset again while rebuilding the firmware topology. Release VF reset before programming the replacement VSI and queue mappings, since VF reset clears those registers, and publish VFACTIVE only after reconstruction succeeds. Leave a VF held in reset if rebuilding it fails. Fixes: 983e628a0c47 ("ixl: Rebuild VF resources after a PF reset") (cherry picked from commit 0048dfddc049f3ef050ba16544f42503d5c42db8) M sys/dev/ixl/ixl_pf.h M sys/dev/ixl/ixl_pf_iflib.c M sys/dev/ixl/ixl_pf_iov.c _____________________________________________________________________________________________________________ Commit: 924a15ac2f19b98a40d71ebe15b973e3865ab4a6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=924a15ac2f19b98a40d71ebe15b973e3865ab4a6 Author: Kevin Bowling (Mon 10 Aug 2026 11:54:26 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:49:42 BST) iavf: Resume AdminQ processing after PF reset A PF reset indication leaves IAVF_STATE_RESET_PENDING set while the VF recreates its AdminQ and negotiates new resources. The ordinary AdminQ task refuses to consume messages while that state is set. Consequently, the first DISABLE_QUEUES reply after successful mailbox rediscovery remains in the receive queue and initialization times out. Later retries and manual interface restarts repeat the same cycle. Clear the stale reset indication once VERSION and GET_VF_RESOURCES have succeeded, before enabling interrupts and resuming normal virtchnl requests. (cherry picked from commit 02fbb1ce07f60fab82e21e5bbe2dae85f024bb55) M sys/dev/iavf/if_iavf_iflib.c _____________________________________________________________________________________________________________ Commit: 5c8421c6746556302e034caacbd0c0e942af6a81 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5c8421c6746556302e034caacbd0c0e942af6a81 Author: Kevin Bowling (Mon 10 Aug 2026 05:00:46 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:49:31 BST) iavf: Do not publish link-up while stopped A PF link event remains cached while a VF is administratively down. Media status queries called iavf_update_link_status() and published that cached state as link-up, while the stopped admin path immediately published link-down. Consumers reacting to link events could turn this into an unbounded notification loop and prevent interface detach from draining its link-state task. Keep the cached PF state, but only publish link-up after iflib has marked the VF running. A subsequent admin pass publishes the cached state after a successful initialization. (cherry picked from commit 46241b7d6647dfc2fc557c02804d20b9f05af5c4) M sys/dev/iavf/if_iavf_iflib.c _____________________________________________________________________________________________________________ Commit: 0f3586ea6ddedddccb699a8ed793764c1c71609e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0f3586ea6ddedddccb699a8ed793764c1c71609e Author: Kevin Bowling (Mon 10 Aug 2026 04:46:24 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:49:05 BST) ixl: Track and recover MDD-blocked VFs The hardware identifies each VF with TX and RX malicious-driver status latches, but the driver combined all events into one counter and reported only the last VF found. It also did not record that hardware had blocked the VF, leaving the condition invisible to management tools. Consume every PF and VF latch, keep per-direction VF counters, rate-limit per-VF diagnostics, and report the blocked and traffic-enabled state via the VF status interface. Clear the software block only after a successful VF or PF reset reconstructs its resources. Match Linux i40e policy by leaving a detected VF blocked by default. Add an opt-in hw.ixl.mdd_auto_reset_vf tunable that notifies and resets the VF for installations that prefer availability. DPDK provides the register clear and per-VF attribution precedent; Linux provides the recovery policy. (cherry picked from commit 93f1065920d806400ace6b60b025faf91926bdaa) M share/man/man4/ixl.4 M sys/dev/ixl/if_ixl.c M sys/dev/ixl/ixl_pf.h M sys/dev/ixl/ixl_pf_iov.c M sys/dev/ixl/ixl_pf_main.c _____________________________________________________________________________________________________________ Commit: 2c9361015cd17476a238756b10906f92e0ffe562 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2c9361015cd17476a238756b10906f92e0ffe562 Author: Kevin Bowling (Mon 10 Aug 2026 04:41:08 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:48:23 BST) ixl: Report PF initialization failures to iflib ixl_if_init() returned early after AdminQ reconstruction, LAA, or VSI initialization failures. Since IFDI_INIT has no return value, iflib then marked the interface RUNNING and enabled its interrupts and timers despite the incomplete hardware state. Use iflib_init_failed() on each incomplete path. Also stop at the first ring-enable error and tear down any partially enabled rings before reporting failure. This keeps the interface stopped and makes a later initialization attempt start from a bounded state. (cherry picked from commit f008b582c9f1e1a636e88a5f330ff3a167094440) M sys/dev/ixl/if_ixl.c M sys/dev/ixl/ixl_pf_iflib.c _____________________________________________________________________________________________________________ Commit: d252dd2a841cb43949b16bf622ce3c4033451539 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d252dd2a841cb43949b16bf622ce3c4033451539 Author: Kevin Bowling (Mon 10 Aug 2026 04:38:40 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:48:12 BST) ixl: Rebuild VF resources after a PF reset A PF or EMP reset destroys the firmware switch topology, including every VF VSI. The driver rebuilt only its PF VSI and left configured VFs with stale switch element and VSI identifiers. Notify VFs before a driver initiated reset, recreate the IOV VEB, and rebuild each configured VF VSI and queue mapping after the PF switch is restored. Keep a VF out of VFACTIVE if its reconstruction fails so one failure cannot expose incomplete resources or prevent the PF and other VFs from recovering. Invalidate cached VF firmware identifiers and runtime state before recreating the VEB. If VEB creation itself fails, teardown and mailbox paths can no longer use pre-reset SEIDs or VSI data. Factor the common VEB setup out of IOV initialization so initial setup and post-reset reconstruction use the same topology and filter sequence. (cherry picked from commit 983e628a0c47afb47d201ce629e9619fb751254d) M sys/dev/ixl/ixl_pf.h M sys/dev/ixl/ixl_pf_iflib.c M sys/dev/ixl/ixl_pf_iov.c M sys/dev/ixl/ixl_pf_main.c _____________________________________________________________________________________________________________ Commit: 3be664785727b3ffda30a6f96e3784c96f8fc616 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3be664785727b3ffda30a6f96e3784c96f8fc616 Author: Kevin Bowling (Mon 10 Aug 2026 04:34:59 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:47:46 BST) ixl: Enforce VF VLAN policy Add access and trunk VLAN policy to the SR-IOV schema. Access VFs use a hardware PVID and cannot alter their VLAN membership. Trunk VFs may register up to 16 VLANs, while VLAN 0 remains implicitly admitted for untagged and priority-tagged traffic. Enable hardware VLAN anti-spoofing and maintain the MAC-by-VLAN filter cross-product used by DPDK. Apply Linux's untrusted-VF limits of 18 MAC addresses and 16 VLANs so one guest cannot consume the shared PF filter table without bound. Report the effective policy through the VF status interface and document the iovctl schema. Relnotes: yes (cherry picked from commit e2daa5c06c2febacf141f9fd3a6a18cf86df8fe1) M share/man/man4/ixl.4 M sys/dev/ixl/ixl_pf.h M sys/dev/ixl/ixl_pf_iov.c M sys/dev/ixl/ixl_pf_iov.h _____________________________________________________________________________________________________________ Commit: fceec25b3066eabf340bac7183d95ed25a947c54 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fceec25b3066eabf340bac7183d95ed25a947c54 Author: Kevin Bowling (Mon 10 Aug 2026 04:21:01 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:46:15 BST) ixl: Make VF reset resource reconstruction fallible Treat each stage of VF reset and VSI reconstruction as fallible. Keep the VF out of VFACTIVE when PCIe drain, reset completion, VSI release, or VSI allocation fails, following the DPDK PF reset model. Propagate initial reset failures back through pci_iov_vf_add and unwind the VF queue allocation. Free the old software filter list before initializing a replacement VSI. ixl_init_filters() previously replaced the list head without freeing its entries, so every VF FLR leaked all MAC and VLAN filter objects. Reset the associated counters and VLAN bitmap with the list. Avoid allocating an initial VSI only to destroy it during the required initial VF reset, and remove redundant broadcast/filter programming from VSI setup. Also delete a partially created VSI when later Admin Queue setup fails. (cherry picked from commit ee52b925fa08158e510d5dddfd1c8fa26f120575) M sys/dev/ixl/ixl_pf_iflib.c M sys/dev/ixl/ixl_pf_iov.c _____________________________________________________________________________________________________________ Commit: 517e013cbad7a4c2190d08aa0808e6e44b05badb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=517e013cbad7a4c2190d08aa0808e6e44b05badb Author: Kevin Bowling (Mon 10 Aug 2026 04:15:17 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:46:04 BST) ixl: Validate VF virtchnl configuration Bound variable-length virtchnl messages before computing their expected length, following the newer Intel virtchnl implementation. Validate VF ring sizes and alignments before programming HMC contexts. DPDK uses 128-byte ring alignment and 64 through 8160 descriptors; the virtchnl ABI further specifies TX multiples of 8 and RX multiples of 32. Preserve the 4096-descriptor limit on X722. Validate queue bitmaps before changing any rings, validate all queue and interrupt contexts before applying a request, and reject invalid RSS table entries. Also avoid sending an ACK after VLAN-strip setup fails and reply to delete-VLAN errors with the correct opcode. These checks prevent malformed or oversized requests from an untrusted VF from partially programming resources outside its allocation. (cherry picked from commit e779914354db5cb3a20f4ec894d08b0f81d05ba2) M sys/dev/ixl/ixl_pf_iov.c M sys/dev/ixl/virtchnl.h _____________________________________________________________________________________________________________ Commit: 9028edf79e50f664dc71c40aaf8ed84d7b5e779e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9028edf79e50f664dc71c40aaf8ed84d7b5e779e Author: Kevin Bowling (Mon 10 Aug 2026 05:53:55 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:45:30 BST) pci_iov: Roll back failed VF enumeration pci_iov_enumerate_vfs() logged a failed VF creation or driver configuration but still reported the whole SR-IOV configuration as successful. The PF remained enabled with the requested NumVFs and driver state even though one or more VF children were absent. Make VF enumeration atomic. Delete children created by the failed attempt, invoke the PF driver cleanup, disable VF memory space and VF Enable, release the IOV resources, and return the original error to iovctl. Also treat failure to create a VF child as an error instead of silently accepting a partial configuration. (cherry picked from commit 4b195f1a25d5003117653a1a323ad19561dc8705) M sys/dev/pci/pci_iov.c _____________________________________________________________________________________________________________ Commit: f8de23b148705b3c6d1c8803202d7b79bbdde8a9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f8de23b148705b3c6d1c8803202d7b79bbdde8a9 Author: Kevin Bowling (Mon 10 Aug 2026 05:53:08 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:45:20 BST) ixl: Initialize VF sysctl contexts before use The VF array is zeroed at allocation, but its sysctl contexts were only populated after each VF was successfully added. If VF setup failed, IOV teardown still passed every requested VF context to sysctl_ctx_free(). An untouched context is not an initialized empty TAILQ and caused a page fault during teardown. Initialize every VF context with the array so both successful setup and partial-failure cleanup have a valid lifetime. (cherry picked from commit ae122c5443882ae4d3d19aacfcfd16a2c8d7b688) M sys/dev/ixl/ixl_pf_iov.c _____________________________________________________________________________________________________________ Commit: 8ba13711773628c6e78ab0904e1a41f700179ca2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8ba13711773628c6e78ab0904e1a41f700179ca2 Author: Kevin Bowling (Mon 10 Aug 2026 08:31:56 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:45:08 BST) iavf: Honor iflib transmit completion batching iavf uses descriptor writeback by default. Hardware writes completion status into a transmit descriptor only when it completes a descriptor marked RS. iavf marked every packet RS even though its report-status queue recorded and inspected only descriptors selected by iflib. The other completion writes could not help reclaim descriptors. iflib marks selected packets with IPI_TX_INTR as completion checkpoints. It forces a checkpoint as deferred work or ring pressure grows. Retain EOP on every packet, but set RS only at those checkpoints. The deprecated head-writeback option on 700-series VFs gets the same batching: each RS checkpoint permits hardware to publish the completed ring head. DPDK uses the same sparse RS design. Let iflib choose the adaptive interval for FreeBSD. This is a PCIe/memory bandwidth savings. (cherry picked from commit 8eb4403e9d4a35f33a0ce41067ccb1924c6960dd) M sys/dev/iavf/iavf_txrx_iflib.c _____________________________________________________________________________________________________________ Commit: 6b02c24b33df53ffa9b5fe45e676261a2c305232 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6b02c24b33df53ffa9b5fe45e676261a2c305232 Author: Kevin Bowling (Mon 10 Aug 2026 08:31:48 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:44:57 BST) ixl: Honor iflib transmit completion batching ixl uses head writeback by default. Hardware publishes the transmit ring head through DMA only after completing a descriptor marked RS. Marking every packet requested much more frequent head updates than iflib needs to reclaim descriptors. iflib marks selected packets with IPI_TX_INTR as completion checkpoints. It forces a checkpoint as deferred work or ring pressure grows. Retain EOP on every packet, but set RS only at those checkpoints. This batches head writebacks while preserving bounded descriptor reclamation. The optional descriptor writeback mode benefits as well. ixl already recorded only IPI_TX_INTR descriptors in its report-status queue, so status written for every other packet was not inspected. DPDK uses the same sparse RS design. Let iflib choose the adaptive interval for FreeBSD. This is a PCIe/memory bandwidth savings. (cherry picked from commit dd32931271c784caf2c51e27f24514093b81429c) M sys/dev/ixl/ixl_txrx.c _____________________________________________________________________________________________________________ Commit: c4a5be18e23687a283016328cb87b3b5b7bd6a14 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c4a5be18e23687a283016328cb87b3b5b7bd6a14 Author: Kevin Bowling (Sun 9 Aug 2026 10:36:12 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:44:44 BST) iavf: Recover when PF communication is unavailable A PF reset or loss of virtchnl service can make visible interface initialization wait up to ten seconds and then return from the void ifdi_init callback. Iflib consequently marks the interface running even though its queues were not initialized, and no retry is scheduled when the PF returns. Check reset readiness without polling during reinitialization, propagate queue-message submission errors, and bound a silent enable or disable to one mailbox timeout. Report unsuccessful initialization to iflib and publish link-down state without polling the stopped mailbox. A VFLR also discards the Admin Queue and permits the PF to replace the VF VSI. Track when full virtchnl rediscovery is required, renegotiate the API version, refresh and validate the VF resources before using a cached VSI ID, and replay the MAC and VLAN filters cleared by reset. Bound each runtime discovery attempt while preserving the existing attach-time wait. While the VF remains administratively up, retry complete initialization after 250 ms, one second, four seconds, and then at a capped eight-second interval. (cherry picked from commit e9a4d3969a3164d41d41480bacd3520fcf05ccbf) M sys/dev/iavf/iavf_iflib.h M sys/dev/iavf/iavf_lib.c M sys/dev/iavf/iavf_lib.h M sys/dev/iavf/iavf_vc_common.c M sys/dev/iavf/iavf_vc_common.h M sys/dev/iavf/if_iavf_iflib.c _____________________________________________________________________________________________________________ Commit: 453cc1d7d37c36d05595fd22cdeb7a9ec1304b13 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=453cc1d7d37c36d05595fd22cdeb7a9ec1304b13 Author: Kevin Bowling (Mon 10 Aug 2026 01:40:16 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:44:30 BST) e1000: Correct 82542 flow-control mode handling The 82542-specific setup routine unconditionally reads the NVM default, overwriting a flow-control mode selected by software. It also removes transmit PAUSE support from all 82542 revisions even though the hardware restriction applies only to rev 2.0. Resolve the NVM default only when requested, scope the transmit restriction to rev 2.0, and replace integer bit masking of the enum with explicit valid mode transitions. This restores the behavior from before the Intel shared-code split and resolves -Wassign-enum. Reported by: glebius (cherry picked from commit 2f1d9ab96214db2ec6ce30c44b55a89a7eaa8f6a) M sys/dev/e1000/e1000_82542.c _____________________________________________________________________________________________________________ Commit: 147c4fee8d4a9f3003fe352fc038588bf2becabb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=147c4fee8d4a9f3003fe352fc038588bf2becabb Author: Kevin Bowling (Sun 9 Aug 2026 10:38:21 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:44:20 BST) ice: Report initialization failures to iflib The primary and mirror-VSI ifdi_init callbacks can return early when reset state or hardware queue and filter setup prevents initialization. Iflib then marks the interface running and enables interrupts although the driver did not finish bringing it up. Report each non-detach failure through iflib_init_failed(). Keep the existing ice reset and subinterface-reinitialization machinery responsible for scheduling recovery. (cherry picked from commit dcdc00a41d3e4be0e75eb625cd3a23d5a927ed15) M sys/dev/ice/if_ice_iflib.c _____________________________________________________________________________________________________________ Commit: 33bc5805a8a92ccfd4605aa9fd389b2951dd37d2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=33bc5805a8a92ccfd4605aa9fd389b2951dd37d2 Author: Kevin Bowling (Sun 9 Aug 2026 10:37:20 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:44:05 BST) bnxt: Report initialization failures to iflib HWRM failures currently return from the void ifdi_init callback. iflib then marks the interface running and enables interrupts despite an incomplete ring or VNIC setup. Move the hardware setup into an error-returning helper. The ifdi_init wrapper can report failure through iflib_init_failed(), while firmware recovery can propagate the same error through bnxt_open(). Also clear the initialized state after partial setup is torn down. (cherry picked from commit cb0e8f5fb6de03428137c096b1c8b62710829029) M sys/dev/bnxt/bnxt_en/if_bnxt.c _____________________________________________________________________________________________________________ Commit: 7c79970bb8e61e38ec5cc3c688abd6154e57be04 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7c79970bb8e61e38ec5cc3c688abd6154e57be04 Author: Kevin Bowling (Sun 9 Aug 2026 12:34:58 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:43:53 BST) ixgbe: Enable PF RSS across queues with SR-IOV PSRTYPE is indexed by pool in VMDq+RSS mode, and its RQPL field selects the number of receive queues available within the pool. The PF occupies the last pool, but the driver programmed pool zero and left the PF RQPL value at zero. As a result, all PF receive traffic was directed to its first queue while SR-IOV was enabled. Program PSRTYPE for the PF pool and encode its allocated receive queue count. (cherry picked from commit 49f9143d9a37a4646c9f4ddac53b97dde04e3fa3) M sys/dev/ixgbe/if_ix.c _____________________________________________________________________________________________________________ Commit: 178f66da816e7114ccce07e2d7a6d8150a5d902d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=178f66da816e7114ccce07e2d7a6d8150a5d902d Author: Kevin Bowling (Sun 9 Aug 2026 08:16:57 BST) Committer: Kevin Bowling (Mon 24 Aug 2026 01:43:40 BST) ixv: Recover when the PF mailbox is unavailable A failed VF reset or mailbox API negotiation currently returns from the void ifdi_init callback. Iflib then marks the interface running even though ixv left its adapter stopped. Stopped media queries can continue polling the PF, and no timer remains active to retry when the PF returns. Track mailbox readiness and report unsuccessful initialization to iflib. Stopped admin and media-status passes now publish cached link-down state without touching the mailbox. While the VF remains administratively up, retry complete initialization after 250 ms, one second, four seconds, and then at a capped eight-second interval. Preserve the requested MAC across reset, then program it once after mailbox API negotiation. The previous two pre-reset requests each could wait a full mailbox timeout after an established PF disappeared, holding the iflib context lock for about two seconds before the reset handshake. Avoid a redundant VF reset in the stop half of an immediate iflib reinitialization. Also remove the stop-time RAR mailbox request: reset has already discarded CTS at that point, and successful initialization restores the current address. Retain a reset for an ordinary administrative stop when the mailbox was established. (cherry picked from commit 0e56ccb5d86618994f884da21dfce692ad21e458) M sys/dev/ixgbe/if_ixv.c M sys/dev/ixgbe/ixgbe.h _____________________________________________________________________________________________________________ Commit: 30909e8f561d0d5ed767e20d8501dae915cfc441 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=30909e8f561d0d5ed767e20d8501dae915cfc441 Author: Kevin Bowling (Sun 16 Aug 2026 02:35:44 BST) Committer: Kevin Bowling (Sun 23 Aug 2026 01:24:12 BST) ixgbe: Correct the PFVFRSSRK index range comment PFVFRSSRK contains ten 32-bit RSS key words, numbered 0 through 9. The previous inclusive range incorrectly ended at 10. Sponsored by: BBOX.io (cherry picked from commit f177ff939a91a3d710752438b13aff53d5afc725) M sys/dev/ixgbe/ixgbe_type.h _____________________________________________________________________________________________________________ Commit: 65506894371fcd550660c2ffb28fb3998fdbeeba URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=65506894371fcd550660c2ffb28fb3998fdbeeba Author: Kevin Bowling (Sat 1 Aug 2026 03:42:28 BST) Committer: Kevin Bowling (Sun 23 Aug 2026 01:24:01 BST) ixv: Reject unsupported E610 Hyper-V VFs E610 Hyper-V VFs use PCI configuration space communication instead of the native PF/VF mailbox. The generic E610 match currently attaches native mailbox operations to those devices, and the imported Hyper-V subdevice identifier is incorrect. Correct the subdevice identifier to 0x00ff, as used by DPDK shared ixgbe code, and reject that subtype until ixv has a complete Hyper-V operations table. Sponsored by: BBOX.io (cherry picked from commit 08c41a679b281505eb7f1fd0cb528f3c1fe87fed) M sys/dev/ixgbe/if_ixv.c M sys/dev/ixgbe/ixgbe_type.h _____________________________________________________________________________________________________________ Commit: 926bb8bbdee2ca3ed8b499cbd5dd2b04ab127a33 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=926bb8bbdee2ca3ed8b499cbd5dd2b04ab127a33 Author: Kevin Bowling (Sun 9 Aug 2026 08:16:56 BST) Committer: Kevin Bowling (Sun 23 Aug 2026 01:23:47 BST) iflib: Support recoverable initialization failure The ifdi_init method cannot report an error, so iflib always marks an interface running and enables its interrupts after the callback returns. Drivers whose hardware initialization depends on an unavailable peer can only return early and leave a falsely running interface. Add iflib_init_failed() so a callback can leave the interface stopped. Also add a conditional reset request for asynchronous recovery: it is discarded if the interface is administratively down when the admin task runs, preventing a queued retry from resurrecting a stopped interface. Do not restore saved driver flags after an MTU or capability change when initialization failed. Restoring the pre-init flags would overwrite the stopped result with stale RUNNING state. Document that reset requests require the caller to schedule the admin task, that output remains blocked during recovery, and that iflib rather than the driver owns the driver flags. (cherry picked from commit 9328a7eedba115040312bd1ea368371a0dbd0cac) M share/man/man9/Makefile M share/man/man9/iflibdd.9 M share/man/man9/iflibdi.9 M sys/net/iflib.c M sys/net/iflib.h _____________________________________________________________________________________________________________ Commit: 79f020ffcad205ef82b0a098fd356dbbc5fba8cd URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=79f020ffcad205ef82b0a098fd356dbbc5fba8cd Author: Andre Albsmeier (Sat 17 Aug 2024 10:20:00 BST) Committer: Michael Osipov (Sat 22 Aug 2026 22:12:10 BST) daemon(8): Add option to write pidfile w/o supervising it Co-authored-by: Michael Osipov PR: 280487 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=280487 ) Reviewed by: kevans, michaelo MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D46313 (cherry picked from commit fe06e383cc64fce8b604d21f8526b91fa6aecc39) M usr.sbin/daemon/daemon.8 M usr.sbin/daemon/daemon.c _____________________________________________________________________________________________________________ Commit: fd7171d78f3b7b8d5d84c3e566bac3f272ac7773 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fd7171d78f3b7b8d5d84c3e566bac3f272ac7773 Author: Alexander Leidinger (Fri 14 Aug 2026 08:42:47 BST) Committer: Alexander Leidinger (Sat 22 Aug 2026 11:43:17 BST) rc.d/bgfsck: use the correct variable name The name of the script and the name used internally for rc.conf differ, as such the hardcoded disabling of service jails for the didn't work. Fix by using the correct name. Fixes: f99f0ee14e3af rc.d: add a service jails config to all base system services (cherry picked from commit 84d8d2878a6efbb2c97a591054f1fc42b7d406ab) M libexec/rc/rc.d/bgfsck _____________________________________________________________________________________________________________ Commit: 0bee17af48ddd09ff3fa83e6e3b537b89d131bb0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0bee17af48ddd09ff3fa83e6e3b537b89d131bb0 Author: Alexander Leidinger (Fri 14 Aug 2026 08:49:35 BST) Committer: Alexander Leidinger (Sat 22 Aug 2026 11:43:01 BST) etc/rc.subr: svcj - use the filename for services We have ports and basesystem services, where the internal name and the filename differ. While the documentation recommends to keep them in sync, the reality is different. For service jails use the basename of the service filename. Fixes: 2efbd48 rc: add service jails framework Suggested by: joneum MFC after: 1 week MFC to: stable/15 (cherry picked from commit d0f0a3b89b932b776b76278fa6885f19e8b30cbb) M libexec/rc/rc.subr _____________________________________________________________________________________________________________ Commit: 70ec66dde79fe0ea625fe0ba087dbae0b7ff91c6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=70ec66dde79fe0ea625fe0ba087dbae0b7ff91c6 Author: Gordon Bergling (Mon 17 Aug 2026 06:57:15 BST) Committer: Gordon Bergling (Sat 22 Aug 2026 06:19:59 BST) bluetooth(4): Fix a typo in a kernel message in l2cap - s/staring/starting/ (cherry picked from commit 8e968c5ff4112387c87f7afdf79d873a6f475b21) M sys/netgraph/bluetooth/l2cap/ng_l2cap_llpi.c _____________________________________________________________________________________________________________ Commit: 489f9ed6a0a63dfd100247e51bfccba706564cb4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=489f9ed6a0a63dfd100247e51bfccba706564cb4 Author: Roman Bogorodskiy (Wed 22 Jul 2026 18:02:47 BST) Committer: Roman Bogorodskiy (Sat 22 Aug 2026 06:06:07 BST) bhyve: document missing options in bhyve_config(5) Document a few options that are currently supported but not covered in bhyve_config(5): - vcpu.N.cpuset - domains.N.{size,cpus,domain_policy} - console (for arm64 and riscv) MFC after: 1 week Reviewed by: bnovkov, jhb Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58399 (cherry picked from commit a257e2dc9c6ecd3db41e1aa27a5297a0f328694a) M usr.sbin/bhyve/bhyve_config.5 _____________________________________________________________________________________________________________ Commit: 32a1a451bc4aadcea95e3e7bb4a209850adc1c77 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=32a1a451bc4aadcea95e3e7bb4a209850adc1c77 Author: Kevin Bowling (Tue 11 Aug 2026 16:21:49 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:59:30 BST) e1000: Add Nova Lake I219 support Add support for future client platform (cherry picked from commit 698c3b0ce1e788415173639366ae89ae7b7903ca) M sys/dev/e1000/e1000_api.c M sys/dev/e1000/e1000_hw.h M sys/dev/e1000/e1000_ich8lan.c M sys/dev/e1000/if_em.c _____________________________________________________________________________________________________________ Commit: c36c27a30f8ce63315d46f7266a04f3f633cd772 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c36c27a30f8ce63315d46f7266a04f3f633cd772 Author: Kevin Bowling (Sat 8 Aug 2026 11:44:36 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:37:46 BST) ixv: Negotiate VF queue-set limits ixv uses one queue set on 82599 and X540 VFs and assumes two on X550-family VFs. The PF reports the queues assigned to each VF with GET_QUEUES after mailbox API 1.1 negotiation. Query the PF during attach. Bound symmetric iflib queue sets by the PF grant and available MSI-X data vectors. Retain one queue set per data vector: ixgbe VFs expose at most three vectors and one is reserved for the mailbox. The hardware permits each pool to use a subset of its RSS queues, so a two-queue ceiling is valid when the PF assigns four. This enables the second data vector on 82599 and X540 while avoiding an assumed second queue when an X550-family VF is granted only one. Keep the existing family limits if the mailbox is unavailable or the PF uses an older API. (cherry picked from commit 98fad621ed697586782e488afdc05252c060fec3) M sys/dev/ixgbe/if_ixv.c _____________________________________________________________________________________________________________ Commit: 889b421a098649ffce2badae0e7b49fbe1467209 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=889b421a098649ffce2badae0e7b49fbe1467209 Author: Kevin Bowling (Sat 8 Aug 2026 12:10:18 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:37:28 BST) ix/ixv: Match Tx writeback thresholds to iflib PTHRESH controls when the device prefetches transmit descriptors, HTHRESH controls how many host descriptors must be ready, and WTHRESH controls completion writeback batching. iflib places RS on selected descriptors and reclaims through those checkpoints. The data sheets require WTHRESH to be zero when software uses RS. Clear WTHRESH while retaining the established PTHRESH 32 and HTHRESH 1 fetch policy. This also follows DPDK in pairing sparse RS descriptors with WTHRESH zero. DPDK defaults to 32/0/0, while Linux ixgbevf uses 32/1/8. The 32/1/0 setting preserves FreeBSD's prefetch policy and the data-sheet requirement that HTHRESH be nonzero when PTHRESH is used. (cherry picked from commit 0baf0fabdb5e60e917458f85706707ee92683080) M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/if_ixv.c M sys/dev/ixgbe/ixgbe.h _____________________________________________________________________________________________________________ Commit: 2b696953e130f7ccce42d45f92a4e3ee3a6729a1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2b696953e130f7ccce42d45f92a4e3ee3a6729a1 Author: Kevin Bowling (Sat 8 Aug 2026 12:30:40 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:34:47 BST) igc: Correct descriptor control programming The transmit-ring setup was copied from the e1000 path. On I225 and I226, bits 22 through 24 are reserved and bit 25 enables the queue; it is not a legacy low-water threshold. Correct the field masks, remove the nonapplicable legacy definitions, and program only defined fields. Use PTHRESH=8 and HTHRESH=1. Keep WTHRESH at zero so the hardware honors sparse RS descriptors issued by iflib. Linux and DPDK use a writeback threshold of 16, but request status on every packet. A nonzero threshold makes hardware ignore individual RS bits and is unsuitable for the iflib completion model. The receive-ring setup likewise used a magic mask that left bit 20 of the five-bit WTHRESH field untouched. Define the receive threshold fields and replace them exactly before installing the established PTHRESH=8, HTHRESH=8, WTHRESH=4 policy. (cherry picked from commit e2aff50727cbe4cb5e99f825c2c6bd8a4915de67) M sys/dev/igc/if_igc.c M sys/dev/igc/igc_defines.h _____________________________________________________________________________________________________________ Commit: 51cae2cbf19a20b5fd4877713ce0eb55fdde5691 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=51cae2cbf19a20b5fd4877713ce0eb55fdde5691 Author: Kevin Bowling (Sat 8 Aug 2026 13:27:37 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:34:28 BST) igb: Program Rx descriptor thresholds by family 82576 specification-update erratum 26 says MSI-X EITR expiration can fail to trigger receive descriptor writeback. A WTHRESH above one can therefore leave received packets invisible until the threshold fills. The shared threshold macros selected policy by enum ordering, so an 82576 VF fell into the generic WTHRESH=4 case. VFs always use MSI-X and require the same WTHRESH=1 workaround as the PF. Use PTHRESH=8 for 82575 and 82576 PFs and VFs, matching DPDK and the current Linux PF driver. The legacy FreeBSD PF and Linux igbvf value of 16 thrashes limited descriptor cache; no specification or erratum requires it. Retain the i354 PTHRESH=12 exception. Enumerate every supported igb PF and VF MAC type so each receives its intended policy. Also clear every threshold bit before installing the new values. The old mask retained the high WTHRESH bit, and 82575 uses six-bit fields while later controllers use five-bit fields. (cherry picked from commit bd4182a2c96eb8329de54448a96bbd15f14238da) M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 07d27349c11082ecd9a43b5e5b9b2306941d5ac6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=07d27349c11082ecd9a43b5e5b9b2306941d5ac6 Author: Kevin Bowling (Sat 8 Aug 2026 12:29:44 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:32:30 BST) igb: Match Tx descriptor control to iflib iflib requests transmit completion status only on selected descriptors. Program a zero writeback threshold so igb hardware honors those sparse RS bits instead of writing back every descriptor in threshold-sized batches. Use the existing family specific prefetch threshold: eight descriptors on most controllers and 20 on I354, with a host threshold of one. These values match the Intel-derived Linux and DPDK drivers. Their nonzero writeback settings are not appropriate here because those drivers set RS on every packet. A zero writeback threshold also avoids depending on interrupt timer flushes affected by 82576 specification update erratum 26. Remove the old IGB_TX_WTHRESH macro as well. It has had no callers since the iflib conversion, so its 82575 conditional no longer implements any policy. (cherry picked from commit fddc393d93169b428fe64e9513ee463b5154b62a) M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 1dac1e0a05b313f5c4ca4ceb3c6d96bc8034a981 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1dac1e0a05b313f5c4ca4ceb3c6d96bc8034a981 Author: Kevin Bowling (Sat 8 Aug 2026 13:26:23 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:31:48 BST) e1000: Correct Rx descriptor threshold programming Jumbo receive tuning on integrated controllers enabled PTHRESH without a nonzero HTHRESH, contrary to the hardware programming requirements. It also covered only the integrated MAC generations present when the workaround was added. Enumerate every jumbo-capable ICH and PCH type and program PTHRESH=3 with HTHRESH=1. Linux fixed the same HTHRESH omission in b701cacdbcfb. The 82574 path combined threshold values with the reset values using bitwise OR. Requesting WTHRESH=4 while the reset value was one thus programmed five. Clear the complete threshold fields before installing the established PTHRESH=32, HTHRESH=4, WTHRESH=4 descriptor-granularity policy. MFC after: 2 weeks (cherry picked from commit abe22383f1b144f0868aa0654ec4514d36f7a4f5) M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 59709be69b0700e0e7e539a9aae8962712cba851 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=59709be69b0700e0e7e539a9aae8962712cba851 Author: Kevin Bowling (Sat 8 Aug 2026 12:48:43 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:27:29 BST) e1000: Program Tx descriptor control by family TXDCTL programming is family dependent. 82543 erratum 35 and 82544 erratum 20 require WTHRESH to remain zero; a nonzero value can corrupt descriptor writebacks and hang the controller. Leave all descriptor-control thresholds at their reset values on 82542, 82543, and 82544. On the remaining em controllers, retain the established PTHRESH=31, HTHRESH=1, WTHRESH=1, and descriptor granularity policy. Several legacy specification updates identify full descriptor writeback as a workaround for transmit descriptor-queue errata. TXDCTL bit 22 is also family dependent. It is COUNT_DESC on the 82571 family and 80003ES2LAN. Intel shared initialization explicitly sets raw bit 22 on both transmit queues of every supported ICH/PCH generation, although the integrated public documentation marks it reserved. Preserve that required setting when iflib programs the thresholds, as DPDK does. Clearing it caused a persistent I219 transmit stall under descriptor pressure. The combined em/igb setup also wrote LWTHRESH=1 on every em controller. The driver does not enable the TXD_LOW interrupt controlled by that field. Enumerate every supported em MAC type and leave the unused low-water threshold disabled. This keeps the legacy descriptor-writeback safety policies separate from igb sparse-RS operation while programming only the fields appropriate to each family. (cherry picked from commit 66baeec9f8a4c4b1609d255b62e3572e0618747f) M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 5724d23404bf6ed40559b31be258c6b8bf16f9e1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5724d23404bf6ed40559b31be258c6b8bf16f9e1 Author: Kevin Bowling (Sat 8 Aug 2026 12:09:21 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:27:19 BST) ixv: Advertise SCTP checksum offload The shared ixgbe transmit path already creates SCTP context descriptors, and the hardware exposes the same checksum capability to VFs. Advertise it through iflib as the PF driver does. (cherry picked from commit 4a13b8a7c5611059384309fdebad8e0fb49a73c2) M sys/dev/ixgbe/if_ixv.c _____________________________________________________________________________________________________________ Commit: b789ad49b5139cea90c058dcf397fa58f7c9655b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b789ad49b5139cea90c058dcf397fa58f7c9655b Author: Kevin Bowling (Sat 8 Aug 2026 12:10:41 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:27:04 BST) ixv: Remove unused loader tunables The flow_control and hdr_split variables have never been read. VF flow control is controlled by the PF, while implementing header split would require receive-path support that ixv does not provide. (cherry picked from commit 8eeb25899afd7818d99ce1500be27ae8d992131f) M sys/dev/ixgbe/if_ixv.c _____________________________________________________________________________________________________________ Commit: b60342f85deeaf2fe2c3e283d44c479740001a9f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b60342f85deeaf2fe2c3e283d44c479740001a9f Author: Kevin Bowling (Sat 8 Aug 2026 12:11:09 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:26:53 BST) ixgbe: Reject Flow Director with SR-IOV The iflib Flow Director path does not assign filters using the absolute queue and pool identifiers required by SR-IOV. Reject the combination during preflight validation rather than allowing an unsupported configuration to alter the PF receive path. The loader tunable is fixed before VFs can be created, so validation also prevents the reverse ordering of this combination. (cherry picked from commit c017bceda48c766780ab1d2239b296242fcf9cf2) M share/man/man4/ix.4 M sys/dev/ixgbe/if_sriov.c _____________________________________________________________________________________________________________ Commit: c6f76e9d5561626fddc6656b4a0f5f70afc88458 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c6f76e9d5561626fddc6656b4a0f5f70afc88458 Author: Kevin Bowling (Thu 6 Aug 2026 07:43:47 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:26:38 BST) amd_iommu: Honor disabled interrupt remapping Do not instantiate an interrupt-remapping context for a unit whose IRTE support is disabled. In that mode the caller must retain the ordinary interrupt path. Reviewed by: kib Differential Revision: https://reviews.freebsd.org/D58725 (cherry picked from commit 9f4df9fc1ba8841a28584ed1323fc8cc9e54c9bc) M sys/x86/iommu/amd_intrmap.c _____________________________________________________________________________________________________________ Commit: e234bdff9874b8fbe54858acae015af9d5eb8164 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e234bdff9874b8fbe54858acae015af9d5eb8164 Author: Kevin Bowling (Thu 6 Aug 2026 12:06:00 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:26:22 BST) vmm: Tear down the IOMMU before AMD-Vi detach Register the vmm module handler after both the bundled device drivers and SMP. On platforms without EARLY_AP_STARTUP, SI_SUB_SMP follows SI_SUB_DRIVERS; using the later subsystem preserves the smp_rendezvous() requirement. The resulting reverse unload order performs IOMMU cleanup while every IVHD softc remains valid. Refuse an independent IVHD detach while translation state remains initialized. (cherry picked from commit 42d54a8fd4665b97f56f91f450e310c61d4aee2c) M sys/amd64/vmm/amd/ivrs_drv.c M sys/amd64/vmm/io/iommu.c M sys/amd64/vmm/io/iommu.h M sys/dev/vmm/vmm_dev.c _____________________________________________________________________________________________________________ Commit: 4de039377942323062ca712dccd9a155a3532e67 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4de039377942323062ca712dccd9a155a3532e67 Author: Kevin Bowling (Thu 6 Aug 2026 07:42:55 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:26:08 BST) ixgbe: Drain events for inactive VFs The aggregate VF mailbox poll includes only VFs whose driver configuration completed. A configured VF slot whose vf_add callback failed can nevertheless report reset, request, or acknowledgement events. Because the mailbox handler skips inactive entries, such an event remains latched and can retrigger administrative work indefinitely. Build the poll masks from every configured VF index and consume reset, message, and acknowledgement events for inactive entries without treating them as usable VFs. Use the index rather than the pool because early vf_add errors precede pool initialization. Also include E610 PFVFLREC in aggregate reset sampling. (cherry picked from commit 5017a241b987d365beb2c35faf0017b6afef2b64) M sys/dev/ixgbe/if_sriov.c _____________________________________________________________________________________________________________ Commit: 7df3a9c641f5bbb49fdd157e2afce12376dd3f0f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7df3a9c641f5bbb49fdd157e2afce12376dd3f0f Author: Kevin Bowling (Thu 6 Aug 2026 09:22:21 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:25:56 BST) ixgbe: Handle deferred link-status requests The iflib conversion records link-status interrupts in the administrative request mask, but the administrative task did not consume them. Timer polling usually hid the omission; frequent mailbox interrupts could continually rearm that timer and leave cached link state down after hardware recovered. Claim request batches atomically, process link-setup dependencies, and sample hardware before publishing link state. Bound each invocation to eight batches and requeue residual work so a continuous producer cannot monopolize the admin taskqueue. Queue every link-related request from the legacy interrupt path. Unlike MSI-X, its threaded continuation services RX and does not enqueue the admin task. This restores the event-driven behavior of ix-3.4.39. Fixes: b2c1e8e62049 ("ix(4): Run {mod,msf,mbx,fdir,phy}_task in if_update_admin_status") (cherry picked from commit 2b763a82f9f21b722b50830bc22af2b2acf36746) M sys/dev/ixgbe/if_ix.c _____________________________________________________________________________________________________________ Commit: 7ce4b30f2f69efd0bf0fe003790da8ad1927e961 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7ce4b30f2f69efd0bf0fe003790da8ad1927e961 Author: Kevin Bowling (Thu 6 Aug 2026 09:22:11 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:25:45 BST) ixv: Tolerate temporary PF mailbox unavailability A PF can be resetting, handling a slow link event, or deliberately withholding mailbox CTS while its VFs enumerate. Keep the VF attached when the reset handshake is temporarily unavailable so a later if_init can retry. Never leave VF hardware running without a negotiated mailbox API: start hardware only after reset succeeds, stop it when negotiation fails in attach or init, and defer later recovery through iflib. This prevents a tight reset loop while preserving recovery when the PF returns. (cherry picked from commit 26e3a8045ec7e2abfea9e2e49577c5e2c4226df1) M sys/dev/ixgbe/if_ixv.c _____________________________________________________________________________________________________________ Commit: 2eaebe07e287091f3dc8bba3edb7b96c27cef947 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2eaebe07e287091f3dc8bba3edb7b96c27cef947 Author: Kevin Bowling (Sat 8 Aug 2026 05:14:53 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:25:29 BST) enic: Correct queue and attach resource ownership Completion queues are allocated by attach_pre but released by queues_free. An iflib failure between those stages leaks the allocation, while the original size expression also underallocates the array. Move completion queue allocation into the TX queue callback, correct its size, and unwind it with TX state if RX allocation fails. Make interrupt cleanup tolerate an unavailable array and reuse the array allocated during device initialization instead of replacing and leaking it. Release the DMA, multicast, and lock resources owned by a successful attach_pre during detach. Avoid allocating the statistics DMA area a second time near the end of attach_pre. (cherry picked from commit a97e1c2450ae62a73a3e0a2a2284e591cd82180a) M sys/dev/enic/if_enic.c _____________________________________________________________________________________________________________ Commit: da51be33158f9c42e5dff66412866e27b1262034 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=da51be33158f9c42e5dff66412866e27b1262034 Author: Kevin Bowling (Sat 8 Aug 2026 05:14:53 BST) Committer: Kevin Bowling (Sat 22 Aug 2026 01:25:12 BST) axgbe: Align channel lifetime with queue allocation DMA channels are allocated by attach_pre but released by queues_free. When iflib fails after attach_pre and before queue allocation, neither the old detach nor queues_free path releases them. Allocate channels with the TX queue state and make queues_free tolerate partially allocated rings. Use it to unwind allocation failures so TX rings are also released when RX allocation fails. An early detach can also precede PHY initialization and interrupt assignment. Skip absent PHY and channel state, and release the locks owned by attach_pre on both failure and detach. (cherry picked from commit 65228a835267191ba692c2699b18913a388b4d20) M sys/dev/axgbe/if_axgbe_pci.c _____________________________________________________________________________________________________________ Commit: 71a9f9578616a90c3c14bb59629fb4d31bfd68d1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=71a9f9578616a90c3c14bb59629fb4d31bfd68d1 Author: Tony Hutter (Wed 12 Aug 2026 21:57:00 BST) Committer: Tony Hutter (Fri 21 Aug 2026 17:19:47 BST) Tag zfs-2.4.4 META file and changelog updated. Signed-off-by: Tony Hutter M META _____________________________________________________________________________________________________________ Commit: 8f8bc4f261eb5075ea896a19982ff0bb5b2f2d80 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8f8bc4f261eb5075ea896a19982ff0bb5b2f2d80 Author: Tony Hutter (Fri 21 Aug 2026 17:17:48 BST) Committer: Tony Hutter (Fri 21 Aug 2026 17:19:47 BST) [zfs-2.4.4] Add 'capsh' to commands.cfg Add missing 'capsh' to commands.cfg. It was included in master with 7839c4b5e1 but that was not backported to this branch. Signed-off-by: Tony Hutter M tests/zfs-tests/include/commands.cfg _____________________________________________________________________________________________________________ Commit: 0c5eb09a236472abdb8ac18f59211a4bb4f0fcdf URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0c5eb09a236472abdb8ac18f59211a4bb4f0fcdf Author: Dag-Erling Smørgrav (Mon 29 Jun 2026 20:17:52 BST) Committer: Dag-Erling Smørgrav (Fri 21 Aug 2026 17:03:30 BST) OptionalObsoleteFiles: Add missing headers The header files for dialog, figpar, dpv were never listed. Fixes: bc6c827078b7 ("OptionalObsoleteFiles: Add figpar to dialog section") (cherry picked from commit acf6518a2d6f33fb56c861861cbad0c0cb56817e) M tools/build/mk/OptionalObsoleteFiles.inc _____________________________________________________________________________________________________________ Commit: d701acea1e638304aa8099dd54ea6a639c31490d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d701acea1e638304aa8099dd54ea6a639c31490d Author: Kevin Bowling (Fri 14 Aug 2026 06:16:41 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:34:12 BST) pci: Do not reconcile MPS across PCI domains A PCI function can provide a host bridge into a synthetic PCI domain. Intel VMD does this: the host facing VMD function remains in its original domain while the hidden Root Ports and endpoints appear in a separate domain. The VMD function's Device Control does not describe an upstream link in that synthetic hierarchy. The hierarchy wide cold pass incorrectly used the VMD function's MPS to reprogram the hidden ports and their endpoints. Stop both cold reconciliation and runtime path walks at a PCI domain boundary. The real Root Ports within the VMD domain continue to reconcile their endpoints normally. Reviewed by: imp Tested by: Michael Butler Fixes: 8e9fe9996a1f ("pci: Reconcile MPS before attaching PCIe devices") Sponsored by: BBOX.io Differential Revision: https://reviews.freebsd.org/D58837 (cherry picked from commit 57293f4541cdea8e4158f751a4439f69b3ec1711) M sys/dev/pci/pci.c _____________________________________________________________________________________________________________ Commit: 118ab673a94737c8585f545896b1acfe9da577be URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=118ab673a94737c8585f545896b1acfe9da577be Author: Kevin Bowling (Thu 6 Aug 2026 09:21:45 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:33:38 BST) ixgbe: Quiesce VFs across PF reset Stop VF transmit and receive in hardware, clear PF-side mailbox CTS, and notify active VFs before resetting a PF. A PF reset invalidates VF queue state, so the no-CTS control message makes cooperative VFs discard stale state and renegotiate after the PF returns. The hardware queue gates synchronously prevent further VF DMA. Do not hold the exclusive iflib context lock for a fixed VF-watchdog interval after the reset. Report the PF link transition directly instead of dispatching mailbox work from the stop path, which could otherwise re-enable VF I/O mid-reset. The CTS, PF-control, and VF queue controls follow the reset mechanisms used by DPDK. (cherry picked from commit aea4240ef5834fb4a47f80c659c80f902cb4bb06) M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ixgbe_sriov.h _____________________________________________________________________________________________________________ Commit: 79abd5ab0d58c8b84ed2034fc6d6120a49e919f4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=79abd5ab0d58c8b84ed2034fc6d6120a49e919f4 Author: Kevin Bowling (Wed 5 Aug 2026 15:14:44 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:33:22 BST) ixgbe: Use PF MTU for 82599 VF jumbo policy The shared maximum frame size is raised by VF LPE requests, so it cannot describe the PF MTU when enforcing the 82599 PF/VF jumbo restriction. Consult the PF ifnet MTU instead. Also correct the API 1.1 and later comparison so a jumbo VF is enabled when, and only when, the PF itself uses a jumbo MTU. This matches the policy implemented by DPDK. (cherry picked from commit 2a803e6f349c3d6cf770089f8a71bc5139308465) M sys/dev/ixgbe/if_sriov.c _____________________________________________________________________________________________________________ Commit: 990f2ad47fa1af2e4e05abc86631a8ba6725165b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=990f2ad47fa1af2e4e05abc86631a8ba6725165b Author: Kevin Bowling (Wed 5 Aug 2026 15:33:32 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:33:03 BST) ixgbe: Apply the 82599 D3 link workaround only for D3 ixgbe_stop_mac_link_on_d3_82599() implements the workaround for 82599 erratum 33. It forces incompatible auto-negotiation settings before the device enters D3, and reset clears them when returning to D0. ixgbe_if_stop() is also used for ordinary interface reconfiguration and recovery. Those paths do not enter D3 and should not program this power-management workaround. They continue to stop the adapter and disable the transmit laser. Move the call to ixgbe_setup_low_power_mode(), after ixgbe_if_stop(). This preserves the required ordering for detach, shutdown, and suspend while avoiding the D3 settings during ordinary restarts. (cherry picked from commit d025b84268ec18d55c2d3088729cf4ad7673ecac) M sys/dev/ixgbe/if_ix.c _____________________________________________________________________________________________________________ Commit: cb93472911c75e2163e3f96302b68d88894c4f62 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cb93472911c75e2163e3f96302b68d88894c4f62 Author: Kevin Bowling (Thu 6 Aug 2026 09:21:06 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:32:48 BST) ixv: Defer reset after mailbox failure When link polling loses mailbox clear-to-send or times out, request an iflib reset instead of continuing with stale VF state. The driver callback runs after iflib samples reset requests, so requeue the admin task to make iflib consume the request on its next pass rather than waiting for an unrelated timer or interrupt. (cherry picked from commit 2a2867c89a7ec2d89ad0a1be8847bb9dc0a4a9f0) M sys/dev/ixgbe/if_ixv.c _____________________________________________________________________________________________________________ Commit: de91b2a0c3938d10c79d8184090dc11d31b27858 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=de91b2a0c3938d10c79d8184090dc11d31b27858 Author: Kevin Bowling (Thu 6 Aug 2026 12:05:13 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:32:33 BST) ixgbe: quarantine repeatedly faulting legacy VFs A guest can reinitialize after a VF function-level reset and repeatedly strand an 82599 or X540 PF with invalid descriptor DMA targets. Count only distinct Received Master Abort events accepted by the qualified transmit-stall detector and quarantine the VF after five events. Preserve quarantine across PF reinitialization, reject reset mailbox requests, and keep transmit, receive, and clear-to-send disabled. Recreating SR-IOV clears quarantine. Expose the affected pools through a read-only bitmap. After a successful quarantine FLR, leave the function in post-FLR configuration, explicitly keep decode and bus mastering disabled, verify the Command register, and refresh its PCI-layer cache so a later restore cannot re-enable the function. This addresses CVE-2021-33061 on 82599. Apply the same bounded-failure policy to X540 as defense in depth; the CVE does not list X540. Intel documents the 82599 issue in: http://iommu.com/datasheets/ethernet/controllers-nics/intel/ixgbe/Intel_82599_Application_Note_655276.pdf Security: CVE-2021-33061 (cherry picked from commit 31285bddf21e986e006e5405acc2c4626e43d190) M share/man/man4/ix.4 M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ixgbe.h M sys/dev/ixgbe/ixgbe_sriov.h _____________________________________________________________________________________________________________ Commit: 4f03553d09055792567f6f135caa108918ce2b7c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4f03553d09055792567f6f135caa108918ce2b7c Author: Kevin Bowling (Thu 6 Aug 2026 12:04:58 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:32:16 BST) ixgbe: Recover legacy VFs from invalid DMA targets 82599 and X540 lack the X550 malicious-driver detector. Detect a VF whose PCI status reports a received master abort while its transmit ring has outstanding descriptors and makes no progress across consecutive samples. Consume the accepted PCI status latch, gate that VF I/O, and recover one pending VF per task pass with round-robin selection. This prevents an unreadable function from starving detection or recovery of other VFs. Save the complete writable VF PCI configuration before FLR, restore it afterward, and verify the hardware-backed Command state. Preserve the first good snapshot and pending state across reset events until restore and verification succeed. Introduce a common I/O-disabled policy bitmask so later quarantine policy can extend traffic gating without duplicating fault-state checks. (cherry picked from commit fe02e14c8843939abf4f5beb1f9d9db68e9df937) M share/man/man4/ix.4 M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ixgbe.h M sys/dev/ixgbe/ixgbe_sriov.h _____________________________________________________________________________________________________________ Commit: 063f937407938322b0d5c19777487ce83e00aae5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=063f937407938322b0d5c19777487ce83e00aae5 Author: Kevin Bowling (Fri 7 Aug 2026 14:30:06 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:31:59 BST) pci: Skip PF SR-IOV state handling for VFs A VF's pci_devinfo references its PF's pcicfg_iov for resource bookkeeping, but only the PF implements the SR-IOV capability. pci_cfg_save() and pci_cfg_restore() treated any non-NULL cfg.iov as an owned capability and accessed the PF capability offset in VF configuration space. Saving a VF could therefore replace the shared PF settings with unrelated VF register values. Skip SR-IOV capability save and restore for PCICFG_VF children. The generic PCI and PCIe state of the VF remains preserved. This is also required by drivers that save VF state around a PF-driven function-level reset. (cherry picked from commit 78547d542f776d366c36b5a2fc747ddfe99523c6) M sys/dev/pci/pci.c _____________________________________________________________________________________________________________ Commit: 516fa3d3cda36b31e631ee3bfe66a65eb471bdcc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=516fa3d3cda36b31e631ee3bfe66a65eb471bdcc Author: Kevin Bowling (Sat 1 Aug 2026 07:43:08 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:31:44 BST) ixgbe: force receive drops on every VF queue PFQDE is indexed by absolute receive queue, but the driver programs one index per VF. Only the first quarter or half of the VF queues therefore have queue-drop isolation, depending on the virtualization mode. The flow-control path can also clear those bits even though SR-IOV requires them independently of the PF pause policy. Program every queue in a VF pool before enabling receive for that VF. For an X550-family VF with an administrative port VLAN, also hide the VLAN tag as the hardware requires. Keep PF flow-control changes confined to the PF SRRCTL registers, and clear the VF queue settings when SR-IOV is torn down and the queues can be reassigned to the PF. (cherry picked from commit 4383ab82b0bbaf1c78ecdf4eb7628f1e154db24b) M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/if_sriov.c _____________________________________________________________________________________________________________ Commit: ad9149c3aabe36d3de29c261a20298cec1abddfc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ad9149c3aabe36d3de29c261a20298cec1abddfc Author: Kevin Bowling (Fri 31 Jul 2026 14:16:36 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:31:28 BST) ixgbe: recover from X550 malicious-driver events The shared X550 code provides malicious-driver detection, event decoding, and per-pool recovery operations, but the PF never enables or services them. A malformed VF descriptor can therefore go undetected and avoid the per-pool recovery path supplied by the MAC. Configure IOV state while VF DMA remains disabled, then enable MDD and activate the VFs only after PF queue initialization is complete. On an MDD event, withdraw mailbox CTS and gate the VF pool through PFVFTE and PFVFRE. Retain the per-queue WQBR blocks until the VF enters a new reset epoch; PFVFTE can still permit descriptor fetches into the internal queue, so releasing WQBR early would allow a hostile VF to retrigger MDD before it resets. Send the non-CTS reset notification after servicing the VF mailbox. Let a posted VF request win mailbox arbitration, defer notification if the pass produced a response, and retry failed notifications from the periodic admin pass. Poll WQBR so recovery does not depend on another mailbox interrupt edge, while suppressing already-fenced pools. Latch a PF reset request until the next hardware initialization. The X550 datasheet defines every bit of WQBR_RX and WQBR_TX as a queue bit, so an all-ones value is valid. Reject it only when IXGBE_STATUS, which has reserved-zero bits, also reads as all ones and confirms dead MMIO. Temporarily disable MDD around live multiqueue SRRCTL drop-mode updates, which hardware otherwise reports as queue-context changes. Serialize that window with the iflib context lock and resample pending work after MDD is restored. Apply the per-pool recovery model used by igb(4) in a2ed165f0049 to the existing DPDK-derived X550 hooks. The same register interface is documented for X552 and X553, so cover the entire X550 family. Document that VF traffic remains disabled until the reset handshake completes. Relnotes: yes (cherry picked from commit dda6a00a5202154b4f83925b8e08bdb03228d4ce) M share/man/man4/ix.4 M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ixgbe.h M sys/dev/ixgbe/ixgbe_mbx.c M sys/dev/ixgbe/ixgbe_sriov.h M sys/dev/ixgbe/ixgbe_x550.c _____________________________________________________________________________________________________________ Commit: 0d89982115b873070112199f7a266da31a260f0c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0d89982115b873070112199f7a266da31a260f0c Author: Kevin Bowling (Sat 1 Aug 2026 07:03:17 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:31:12 BST) ixgbe: complete PF cleanup after VF FLR The 82599, X540, and X550 documentation identifies VF registers which retain state across VFLR and must be reconfigured before a VF is reused. The VF reset path already initializes its queue-owned registers, but the PF only cleared VF mailbox memory and transmit head write-back addresses after a cooperative mailbox reset. A bare hardware VFLR therefore left both behind on affected devices. Move TDWBA cleanup into the common reset path. Clear CTS when VFLR invalidates the mailbox session, and accept only VF_RESET during the reset pass before restoring VF traffic. Clear VFMBMEM through the PFU/VFU semaphore. Recheck VFREQ while holding PFU so a reset event cannot erase a request posted between the initial mailbox check and the clear. Dispatch an already-read message even if the residual clear fails, but keep cleanup pending until a synchronized clear succeeds. Retry cleanup in the same admin pass after a failed message read or clear. The 82599 also retains VFMAILBOX.VFU across VFLR. Leave a VF-owned mailbox intact initially so a live post-reset writer can finish. Retry cleanup from the admin timer and, after a two-second grace period, use PFMAILBOX.RVFU only when VFU remains set and no request has been posted. Clear the mailbox under PFU afterward. This recovers an abandoned pre-reset owner without sleeping under the iflib context lock or immediately stealing from a new reset request. Suppress mailbox dispatch once iflib has cleared IFF_DRV_RUNNING so a pending reset request cannot re-enable VF traffic inside the PF stop path. Periodically sample aggregate VFREQ, VFACK, and VFLR registers, masked to active VFs, so work suppressed across a stop/restart and a bare 82599 VFLR without EICR_MAILBOX are both discovered without another interrupt edge. (cherry picked from commit 33fdcdb18eb61f089b9a4786ef7aa9224ad0722c) M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ixgbe.h M sys/dev/ixgbe/ixgbe_mbx.c M sys/dev/ixgbe/ixgbe_mbx.h M sys/dev/ixgbe/ixgbe_sriov.h M sys/dev/ixgbe/ixgbe_vf.c _____________________________________________________________________________________________________________ Commit: 2483c7dded33c9d98437863775f43d7c4d464195 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2483c7dded33c9d98437863775f43d7c4d464195 Author: Kevin Bowling (Thu 6 Aug 2026 12:05:32 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:30:57 BST) ixgbe: Validate SR-IOV before restarting the PF A deterministic IOV configuration error currently reaches the driver only after iflib has stopped the PF. The required cleanup restart then causes an avoidable carrier flap. Follow the igb pattern and validate the request in the PCI IOV method before entering the restart transaction. Reject queue layouts wider than the selected virtualization pool before they can alias unrelated 82599 registers. (cherry picked from commit 703c756a2d298e5841471eb7d4d40f95a0dafe50) M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ixgbe_sriov.h _____________________________________________________________________________________________________________ Commit: 57a732245fd1e67d4fc1fcf6a411e80a0381bdc0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=57a732245fd1e67d4fc1fcf6a411e80a0381bdc0 Author: Kevin Bowling (Thu 6 Aug 2026 12:03:35 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:30:39 BST) ixgbe: restart iflib around SR-IOV reconfiguration The IOV callback changes the PF pool, virtualization mode, and hardware queue indices while iflib still considers the old queue layout live. Teardown likewise leaves the software pool and mode at their SR-IOV values. Use iflib stop/mutate/restart transactions for both transitions. Disable VF DMA and PCI VF Enable before queue reuse, let outstanding transactions drain, and restore the non-IOV pool and queue indices on teardown. Remove the redundant driver-local pci_iov_detach() wrapper; iflib already performs that check centrally before the driver detach callback. It may be possible to avoid some restart in the future on this hardware pausing DMA and remapping rings but not pursued yet. (cherry picked from commit 86199f1a74abc76c3bb1ed15ccee7df3cabf3d7b) M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ixgbe_sriov.h _____________________________________________________________________________________________________________ Commit: e66dcff1385dc08bff1eb87c847f9e0d262dbe64 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e66dcff1385dc08bff1eb87c847f9e0d262dbe64 Author: Kevin Bowling (Thu 6 Aug 2026 07:42:26 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:30:23 BST) pci: Optionally disable endpoints with unsafe MPS Keep warn-only behavior as the default. Add an opt-in policy that clears endpoint decoding and bus mastering when a newly discovered function cannot match its active path, while never disabling bridge functions and their subtrees. (cherry picked from commit 114f4a68f21345e1e6680b7acf1bf733d9047002) M share/man/man4/pci.4 M sys/dev/pci/pci.c _____________________________________________________________________________________________________________ Commit: dd0d0b4f24ab600951dc44e0c3ba7ae6dda0178b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=dd0d0b4f24ab600951dc44e0c3ba7ae6dda0178b Author: Kevin Bowling (Thu 6 Aug 2026 07:41:41 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:30:06 BST) pci: Add a hierarchy-wide MPS limit Add a boot-time ceiling for MPS reconciliation. Apply it only while an entire cold-enumerated link can be configured consistently, and leave an established active path unchanged. (cherry picked from commit 673cb5265a2df2228982fc220f4e7ea62ab765b2) M share/man/man4/pci.4 M sys/dev/pci/pci.c _____________________________________________________________________________________________________________ Commit: 1e6635b9a35e2dacdac04310243fcf71dc11a556 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1e6635b9a35e2dacdac04310243fcf71dc11a556 Author: Kevin Bowling (Thu 6 Aug 2026 07:40:55 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:29:46 BST) pci: Reconcile MPS before attaching PCIe devices Reconcile each newly enumerated link as a unit before child drivers attach. Firmware may leave Bus Master Enable set after handoff, so use the bus attachment state rather than that bit to identify the cold phase. Preserve an established hierarchy during rescan and hot-add. Refuse a reduction below a switch because recursive enumeration may already have made a sibling subtree live; lowering only the local port or Root Port would produce an inconsistent path. Report capability and active-use conflicts distinctly. Handle OFW PCI buses that clone the generic enumeration path. (cherry picked from commit 8e9fe9996a1fbdb79033b082e6a96b9e1266e33f) M share/man/man4/pci.4 M sys/dev/pci/pci.c M sys/dev/pci/pci_private.h M sys/dev/pci/pcivar.h M sys/powerpc/ofw/ofw_pcibus.c _____________________________________________________________________________________________________________ Commit: d14c8d154df067a83a63397d1cd99c068a8632ea URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d14c8d154df067a83a63397d1cd99c068a8632ea Author: Kevin Bowling (Thu 6 Aug 2026 10:36:43 BST) Committer: Kevin Bowling (Fri 21 Aug 2026 01:29:25 BST) pci: Preserve adjusted PCIe control state The PCI bus changes live capability registers after the initial configuration snapshot has been saved. A later driver reprobe restores that snapshot and can silently undo the adjustment. Update the cached Device Control and Root Control bits together with pcie_adjust_config() writes. Route the persistent Maximum Read Request setter and the bus-owned AER control changes through that helper as well, so they share the same restore semantics as MPS reconciliation. Document the persistent-write contract. Merge only explicitly adjusted bits into the saved image so unrelated or transient bits observed during the hardware read-modify-write cannot become persistent. (cherry picked from commit a9752e9ac8a635f49ca058dd7268298840c7e915) M share/man/man9/pci.9 M sys/dev/pci/pci.c _____________________________________________________________________________________________________________ Commit: 8c5e28db94fdfd22a4ef25d5522740efedc7f9cc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8c5e28db94fdfd22a4ef25d5522740efedc7f9cc Author: Rob Norris (Thu 20 Aug 2026 06:11:48 BST) Committer: Tony Hutter (Fri 21 Aug 2026 00:34:13 BST) ZTS: device access tests Tests that zpool create, add, attach and import all properly enforce the restrictions on the calling user to access device nodes. Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Rob Norris Closes #18960 M tests/runfiles/linux.run M tests/zfs-tests/tests/Makefile.am A tests/zfs-tests/tests/functional/device_access/cleanup.ksh A tests/zfs-tests/tests/functional/device_access/device_access.kshlib A tests/zfs-tests/tests/functional/device_access/device_access_add.ksh A tests/zfs-tests/tests/functional/device_access/device_access_attach.ksh A tests/zfs-tests/tests/functional/device_access/device_access_create.ksh A tests/zfs-tests/tests/functional/device_access/device_access_import.ksh A tests/zfs-tests/tests/functional/device_access/setup.ksh _____________________________________________________________________________________________________________ Commit: 90c5f63087846555b933cc57f5b7d174909b8eb9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=90c5f63087846555b933cc57f5b7d174909b8eb9 Author: Rob Norris (Mon 17 Aug 2026 13:09:50 BST) Committer: Tony Hutter (Fri 21 Aug 2026 00:34:13 BST) vdev_disk: use calling cred to check for device access bdev_file_open_by_path() does not do any kind of credential check on the given device path, so we need to do our own. We temporarily swap in the passed in credential as the task credential, then call kern_path() and inode_permission(), which together will ensure the credential can both see and access the given path. For the reopening case, we use the kernel credential. The idea here is that since the device was already open, we shouldn't fail to reopen just because the calling user can't see it, which would prevent device removal, offline, online, etc. Include some light reorganising in the error paths, since we might not always have a device handle to carry the current error. Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Rob Norris Closes #18960 M module/os/linux/zfs/vdev_disk.c _____________________________________________________________________________________________________________ Commit: 2900998b5c169f972a321edf0e7942c88cc6f7d7 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2900998b5c169f972a321edf0e7942c88cc6f7d7 Author: Rob Norris (Wed 19 Aug 2026 04:06:23 BST) Committer: Tony Hutter (Fri 21 Aug 2026 00:34:13 BST) vdev_file: use calling cred to check for device access Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Rob Norris Closes #18960 M module/zfs/vdev_file.c _____________________________________________________________________________________________________________ Commit: 07f76455bf94a18e992661ea6b8430acf14b5177 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=07f76455bf94a18e992661ea6b8430acf14b5177 Author: Rob Norris (Wed 19 Aug 2026 04:05:56 BST) Committer: Tony Hutter (Fri 21 Aug 2026 00:34:13 BST) zfs_file_open: add cred arg, use it to check access If we're opening a file on behalf of the user, we need to ensure that that user actually has access to it. Add a credential parameter to zfs_file_open() and use it when opening the file. Existing callers use kcred for now to get the same behaviour as before. Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Rob Norris Closes #18960 M include/sys/zfs_file.h M lib/libzpool/kernel.c M module/os/freebsd/zfs/zfs_file_os.c M module/os/linux/zfs/zfs_file_os.c M module/zfs/spa_config.c M module/zfs/vdev_file.c _____________________________________________________________________________________________________________ Commit: 907dd00bf926493927826883e74326a15905adb4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=907dd00bf926493927826883e74326a15905adb4 Author: Rob Norris (Fri 14 Aug 2026 08:15:21 BST) Committer: Tony Hutter (Fri 21 Aug 2026 00:34:13 BST) vdev_open: pass credential to check for permission to open device This commit adds a cred_t parameter to vdev_open() and threads it through to all the vdev_op_open callbacks. The default is CRED(), ie the credential of the calling task, which is usually some userspace control process calling ioctl(). To handle the parallel vdev open case, we take additional and additional reference to the cred for each task, and pass it down to vdev_open(). Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Rob Norris Closes #18960 M include/sys/vdev.h M include/sys/vdev_impl.h M module/os/freebsd/zfs/vdev_geom.c M module/os/linux/zfs/vdev_disk.c M module/zfs/spa.c M module/zfs/vdev.c M module/zfs/vdev_draid.c M module/zfs/vdev_file.c M module/zfs/vdev_indirect.c M module/zfs/vdev_mirror.c M module/zfs/vdev_missing.c M module/zfs/vdev_raidz.c M module/zfs/vdev_root.c _____________________________________________________________________________________________________________ Commit: 6ebae07fa9953d0fbe06bbb726bee4ed53d55019 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6ebae07fa9953d0fbe06bbb726bee4ed53d55019 Author: Rob Norris (Fri 14 Aug 2026 03:51:15 BST) Committer: Tony Hutter (Fri 21 Aug 2026 00:34:13 BST) secpolicy_zfs: add a note about the power of CAP_SYS_ADMIN Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Rob Norris Closes #18959 M module/os/linux/zfs/policy.c _____________________________________________________________________________________________________________ Commit: d3a101bbc0e0dfdc958c743e692262b022d17e1a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d3a101bbc0e0dfdc958c743e692262b022d17e1a Author: Rob Norris (Fri 14 Aug 2026 03:42:20 BST) Committer: Tony Hutter (Fri 21 Aug 2026 00:34:13 BST) secpolicy_sys_config: only permit a global zone credential Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Rob Norris Closes #18959 M module/os/linux/zfs/policy.c _____________________________________________________________________________________________________________ Commit: 19db2358a1a4e0e778bf250275761f2b4ce665e1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=19db2358a1a4e0e778bf250275761f2b4ce665e1 Author: Rob Norris (Fri 14 Aug 2026 03:39:16 BST) Committer: Tony Hutter (Fri 21 Aug 2026 00:34:13 BST) secpolicy_zinject: only permit a global zone credential Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Rob Norris Closes #18959 M module/os/linux/zfs/policy.c _____________________________________________________________________________________________________________ Commit: 91a8d72d71cb63f283cf10bd3205985b63c9c033 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=91a8d72d71cb63f283cf10bd3205985b63c9c033 Author: Rob Norris (Fri 14 Aug 2026 03:24:20 BST) Committer: Tony Hutter (Fri 21 Aug 2026 00:34:13 BST) secpolicy_nfs: remove, not used Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Rob Norris Closes #18959 M include/os/freebsd/spl/sys/policy.h M include/os/linux/zfs/sys/policy.h M module/os/freebsd/spl/spl_policy.c M module/os/linux/zfs/policy.c _____________________________________________________________________________________________________________ Commit: 76aeadddd4a6dd2a1dcf1ba3a09cc0adaf1f663c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=76aeadddd4a6dd2a1dcf1ba3a09cc0adaf1f663c Author: Rob Norris (Mon 17 Aug 2026 02:32:29 BST) Committer: Tony Hutter (Fri 21 Aug 2026 00:34:13 BST) ZTS: test secpolicy_zinject correctly limits namespace access Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Rob Norris Closes #18959 M tests/runfiles/linux.run M tests/zfs-tests/tests/Makefile.am A tests/zfs-tests/tests/functional/user_namespace/user_namespace_secpolicy_zinject.ksh _____________________________________________________________________________________________________________ Commit: 92b8a665b4974223f8137f0ebe9fb3db2000ae61 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=92b8a665b4974223f8137f0ebe9fb3db2000ae61 Author: Rob Norris (Mon 17 Aug 2026 02:32:29 BST) Committer: Tony Hutter (Fri 21 Aug 2026 00:34:13 BST) ZTS: test secpolicy_sys_config correctly limits namespace access Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Rob Norris Closes #18959 M tests/runfiles/linux.run M tests/zfs-tests/tests/Makefile.am A tests/zfs-tests/tests/functional/user_namespace/user_namespace_secpolicy_sys_config.ksh _____________________________________________________________________________________________________________ Commit: 602794cc2b0f8f6354d0afe20decf4fdc8cb6173 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=602794cc2b0f8f6354d0afe20decf4fdc8cb6173 Author: Rob Norris (Wed 1 Jul 2026 08:53:32 BST) Committer: Tony Hutter (Fri 21 Aug 2026 00:34:13 BST) config: detect idmap method via generic_permission test Since the switch from implicit to explicit userns, and to idmap, happened right across the kernel in major releases, so it is enough to use a single test and apply the results everywhere. generic_permission() is a nice simple function with a simple interface, so useful for an unambiguous test. Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18769 A config/kernel-idmap.m4 M config/kernel.m4 _____________________________________________________________________________________________________________ Commit: aeec95683f25c75e8569fd645cde8daf982dae36 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=aeec95683f25c75e8569fd645cde8daf982dae36 Author: Gordon Bergling (Mon 17 Aug 2026 06:48:33 BST) Committer: Gordon Bergling (Thu 20 Aug 2026 07:01:44 BST) nullfs(4): Fix a typo in a source code comment - s/modifing/modifying/ (cherry picked from commit 27c70deb3d260b48bee8f3c4c975fd2de64264fb) M sys/fs/nullfs/null_vnops.c _____________________________________________________________________________________________________________ Commit: 4fb09e9250df5e0baf879006704e79d08a4053e6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4fb09e9250df5e0baf879006704e79d08a4053e6 Author: Gordon Bergling (Mon 17 Aug 2026 06:54:10 BST) Committer: Gordon Bergling (Thu 20 Aug 2026 07:01:26 BST) ichwd(4): Fix a typo in a source code comment - s/modifing/modifying/ (cherry picked from commit 8362aecdeb2548813942a7e604543c71f5a10271) M sys/dev/ichwd/i6300esbwd.c _____________________________________________________________________________________________________________ Commit: 40547107684af68a30af52cacdf194187429264b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=40547107684af68a30af52cacdf194187429264b Author: Gordon Bergling (Mon 17 Aug 2026 06:53:07 BST) Committer: Gordon Bergling (Thu 20 Aug 2026 07:01:03 BST) fxp(4): Fix a typo in a source code comment - s/modifing/modifying/ (cherry picked from commit c47b430c6ea3aa8d133af0af426d018bae3b7018) M sys/dev/fxp/rcvbundl.h _____________________________________________________________________________________________________________ Commit: 9e6248142f797af042df72e03cb7ea540d6f1213 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9e6248142f797af042df72e03cb7ea540d6f1213 Author: Gordon Bergling (Mon 17 Aug 2026 06:55:17 BST) Committer: Gordon Bergling (Thu 20 Aug 2026 07:00:30 BST) ipfw(4): Fix a typo in a source code comment - s/varaiables/variables/ (cherry picked from commit 251e6ef40203a6f911d7f4daacf3075de7f870c0) M sys/netpfil/ipfw/dn_sched_fq_pie.c _____________________________________________________________________________________________________________ Commit: bbf233910587fd36a46459102d46bd70f5c0b8dd URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bbf233910587fd36a46459102d46bd70f5c0b8dd Author: Gordon Bergling (Mon 17 Aug 2026 06:47:17 BST) Committer: Gordon Bergling (Thu 20 Aug 2026 07:00:12 BST) msun: Fix a typo in a source code comment - s/uneccessarily/unnecessarily/ Obtained from: NetBSD (cherry picked from commit cd4aae2fa9d35015248c445752e23800e75e8517) M lib/msun/src/catrig.c _____________________________________________________________________________________________________________ Commit: 352cf5b11b9214e1b4e70c32d185bc7c2efb78e6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=352cf5b11b9214e1b4e70c32d185bc7c2efb78e6 Author: Gordon Bergling (Mon 17 Aug 2026 06:51:05 BST) Committer: Gordon Bergling (Thu 20 Aug 2026 06:59:53 BST) swap_pager: Fix a typo in a source code comment - s/errornous/erroneous/ (cherry picked from commit 88293bdd1eefb4bf518e1764d370b4a2321afdd1) M sys/vm/swap_pager.c _____________________________________________________________________________________________________________ Commit: c3b7f922d887e3f9a4e334562ebdd66b968d0b84 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c3b7f922d887e3f9a4e334562ebdd66b968d0b84 Author: Gordon Bergling (Mon 17 Aug 2026 06:52:09 BST) Committer: Gordon Bergling (Thu 20 Aug 2026 06:59:34 BST) ppbus(4): Fix a typo in a source code comment - s/predifined/predefined/ (cherry picked from commit 709bd45a1b3a5ca21e05995c0c01f0ee8e7e8c38) M sys/dev/ppbus/ppb_msq.h _____________________________________________________________________________________________________________ Commit: 9e07bfac7d22497716620d2730a89f7100a00159 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9e07bfac7d22497716620d2730a89f7100a00159 Author: Michael Heller (Wed 5 Aug 2026 02:22:27 BST) Committer: Tony Hutter (Thu 20 Aug 2026 01:34:50 BST) mmp: tell a failed uberblock claim apart from remote activity When the claim could not write to every device the config expects present, spa_activity_check_claim() replaced the error from mmp_claim_uberblock() with EREMOTEIO, so an operator whose peer died together with its mirror legs was told another host holds the pool, which sends them looking for a host that is not there. Report the cause instead. A shortfall has two causes worth telling apart, so mmp_claim_uberblock() now counts the writes it issues alongside the ones that succeed. A leaf the config expects present but which cannot be written is never issued one, so too few issued means a device is absent, which persists across retries and is what "zhack mmp reclaim" recovers; that returns ENODEV. Enough issued but too few good means the writes reached present devices and failed, which a retry may clear; that stays EIO. The issued count is gated exactly as the good count is so the two describe the same set of leaves. Both get a case in spa_ld_activity_result() and both still return EREMOTEIO to userspace, as the ENXIO case already does, and the cause travels to userspace in ZPOOL_CONFIG_MMP_RESULT so zpool(8) can say which one it was and, for ENODEV, name the recovery. ZPOOL_CONFIG_MMP_STATE stays MMP_STATE_ACTIVE for both even though nothing is active. An older zpool(8) knows only the two existing states and reaches zfs_error_aux() with an uninitialized buffer for anything else, so the state is kept as one it understands. An older zpool(8) against this kernel therefore prints what it prints today, and a newer zpool(8) against an older kernel finds no cause reported and falls back to the same text. The paths where the claim genuinely detects another host still return EREMOTEIO and are unaffected. Also correct the comment above the write count, which still described the fixed two writes per mirror that 8cdd9b2b7 replaced with one write per leg the config expects present. mmp_degraded_import.ksh asserted on the old message in the two cases which are now ENODEV, and is updated with them. The zhack case asserts both directions, since a message that stops being emitted fails silently: the shortfall must be reported, and it must not be reported as another host holding the pool. Reviewed-by: Brian Behlendorf Signed-off-by: Michael Heller Closes #18892 M lib/libzfs/libzfs_pool.c M man/man1/zhack.1 M module/zfs/mmp.c M module/zfs/spa.c M tests/zfs-tests/tests/functional/mmp/mmp_degraded_import.ksh M tests/zfs-tests/tests/functional/mmp/mmp_zhack_reclaim.ksh _____________________________________________________________________________________________________________ Commit: fb7d409286d78a9e470fd06966c8d8d07bc89e5c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fb7d409286d78a9e470fd06966c8d8d07bc89e5c Author: Michael Heller (Tue 4 Aug 2026 11:48:36 BST) Committer: Tony Hutter (Thu 20 Aug 2026 01:34:50 BST) ZTS: add coverage for zhack mmp reclaim Six scenarios: a stranded pool is recovered and the claim then accepts it, a live host sharing a leg is still refused, both top-level vdevs are counted after a recovery, a pool without multihost is left alone, a log vdev leg is not touched, and a raidz member is not touched. Every recovery assertion re-imports as a third hostid. zhack exports cleanly under its own hostid, so importing again as the same host takes the exported-and-matching-hostid path, skips the activity check entirely, and would leave the claim unexercised and the test vacuous. The assertions read req_writes and good_writes from the claim's own dbgmsg line, which 20176224e added. That is the only observable of the claim arithmetic, at the cost of coupling the test to a debug message this change does not control. mmp_pool_destroy() used a bare "pgrep zhack", which matches any process whose name merely contains zhack. A ksh script named mmp_zhack_reclaim.ksh has comm "mmp_zhack_recla", so the helper found the running test and killed it. Match the process name exactly. Reviewed-by: Brian Behlendorf Signed-off-by: Michael Heller Closes #18892 M tests/runfiles/linux.run M tests/zfs-tests/tests/Makefile.am M tests/zfs-tests/tests/functional/mmp/mmp.kshlib A tests/zfs-tests/tests/functional/mmp/mmp_zhack_reclaim.ksh _____________________________________________________________________________________________________________ Commit: bc53c75223a40dddd85efa8c273481d14c6298bc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bc53c75223a40dddd85efa8c273481d14c6298bc Author: Michael Heller (Tue 4 Aug 2026 11:48:36 BST) Committer: Tony Hutter (Thu 20 Aug 2026 01:34:50 BST) zhack: add "mmp reclaim" to recover a pool stranded by MMP When a host fails together with the mirror legs attached to it, the surviving labels still describe those legs as present, so the MMP uberblock claim keeps demanding a write to every one of them and no later import can satisfy it. The pool cannot be imported by any host again. Add "zhack mmp reclaim", which imports once with the claim's required write count relaxed for the mirror legs this host cannot open, marks those leaves offline so that the ordinary imports which follow succeed, and exports. The relaxation is confined to userspace. mmp_claim_relaxed is declared under #ifndef _KERNEL, and module/Kbuild.in builds the module with -D_KERNEL, so the flag cannot exist in a kernel module. libzpool does not define _KERNEL and so gets the check. This follows the zfeature_checks_disable pattern zhack already uses around the same import, and is stronger, since that flag does exist in the kernel. Only the number of required writes changes. The write, the wait and the re-read of the activity check are untouched, so a competing host which shares any leg with this one is still detected and the import is refused. A live host whose legs are all invisible from here cannot be detected by any write-and-read scheme, so this stays a manual operation which assumes the peer has been fenced. Legs are forgiven only under a top-level mirror, which is where the relaxation lives, and exactly those legs are marked offline. A raidz or draid member is required as parity+1 in aggregate and never demanded individually, so an absent one does not raise the requirement and is left alone. Offline is used rather than removed because it persists unconditionally, is already excluded from the claim, and has "zpool online" as its inverse when the hardware returns. Reviewed-by: Brian Behlendorf Suggested-by: Brian Behlendorf Signed-off-by: Michael Heller Closes #18892 M cmd/zhack.c M include/sys/mmp.h M man/man1/zhack.1 M module/zfs/mmp.c _____________________________________________________________________________________________________________ Commit: d9031a262b3633378212cb0b12f6da57906ab52b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d9031a262b3633378212cb0b12f6da57906ab52b Author: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> (Wed 5 Aug 2026 23:13:22 BST) Committer: Tony Hutter (Thu 20 Aug 2026 01:34:50 BST) Make systemd-udev-settle optional for the import units systemd-udev-settle.service has been deprecated for years, recent systemd releases warn about it at boot, and distributions have begun shipping without it, which turns the hard Requires= in zfs-import-cache and zfs-import-scan into a broken import: a Requires= on a masked or removed unit keeps the service from ever starting. Issue #10891. Demote the dependency to Wants= and keep the After= ordering. Where the settle unit exists and completes, the boot is what it always was: Wants= pulls settle in, the import waits for it, and the device-symlink guarantee it provided is intact. Where it is masked or gone the wish is quietly dropped and the import runs anyway, which beats not importing at all. One deliberate behavior change: if settle itself fails, on a system so large that enumeration overruns its timeout, the old Requires= cancelled the import while the new units go ahead at the timeout mark with whatever has been enumerated by then. Settle-less boots lose the wait for the udev queue, so the import units gain two ordering edges in its place. After=systemd-udev-trigger.service makes sure the coldplug events are at least queued. After=systemd-modules-load.service closes a condition race the settle wait used to hide: both import units gate on ConditionPathIsDirectory=/sys/module/zfs, and without the multi-second settle delay that condition could be evaluated before modules-load.d had finished loading zfs.ko, silently skipping the import on an otherwise healthy boot. Beyond that, a device whose symlink appears a moment too late is only covered by the short zfs_vdev_open_timeout_ms open-retry window; waiting for exactly the devices a pool needs is what the per-pool import work (#18486) is shaped to solve, and this stays the minimal step that keeps settle-less systems importing today. The stray After=systemd-udev-settle lines in zfs-mount, zfs-mount@ and zfs-volume-wait were only ordering hints against a unit that may not exist, so they simply go away. Tests: on a systemd 259 VM with a cachefile pool, rebooted with the rendered unit: settle available, the boot pulls it in and the pool imports as before; settle masked, the boot comes up with no failed units and the pool still imports, where a masked settle previously kept zfs-import-cache from starting at all. Reviewed-by: Brian Behlendorf Signed-off-by: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> Issue #10891 Closes #18832 M etc/systemd/system/zfs-import-cache.service.in M etc/systemd/system/zfs-import-scan.service.in M etc/systemd/system/zfs-mount.service.in M etc/systemd/system/zfs-mount@.service.in M etc/systemd/system/zfs-volume-wait.service.in _____________________________________________________________________________________________________________ Commit: 6c7be416facb9b14717d9b5d92b3d0c40f476028 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6c7be416facb9b14717d9b5d92b3d0c40f476028 Author: Tony Hutter (Tue 18 Aug 2026 01:18:17 BST) Committer: Tony Hutter (Wed 19 Aug 2026 22:42:55 BST) Linux 7.2 compat: META Update the META file to reflect compatibility with the 7.2 kernel. Reviewed-by: Brian Behlendorf Signed-off-by: Tony Hutter Closes #18941 M META _____________________________________________________________________________________________________________ Commit: c714cc5a3406518e4d510b81457186b4d45eaa27 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c714cc5a3406518e4d510b81457186b4d45eaa27 Author: Alexander Motin (Sun 9 Aug 2026 18:17:53 BST) Committer: Tony Hutter (Wed 19 Aug 2026 22:42:55 BST) Fix negative time overflows in DDT pruning - Account DDT entries created after prune start to histogram bin 0 (now) instead of the last one (long ago) due to negative overflow. - Return error when requested to prune for more days than passed since the epoch. Reviewed-by: Brian Behlendorf Signed-off-by: Alexander Motin Closes #18886 M module/zfs/ddt.c _____________________________________________________________________________________________________________ Commit: 051cfda25114b191e305e8c33b4d838812a7960b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=051cfda25114b191e305e8c33b4d838812a7960b Author: Philip Paeps (Sun 16 Aug 2026 03:24:29 BST) Committer: Philip Paeps (Wed 19 Aug 2026 02:22:32 BST) libexpat: update AUTHORS section of libbsdxml.3 The eXpat project has changed maintainers since this section was written in 2002. Update it to reflect reality. Discussed with: Sebastian Pipping Reviewed by: bcr Differential Revision: https://reviews.freebsd.org/D58835 (cherry picked from commit 5e6c894510fc66c18d69164d591184a2d23b16e5) M lib/libexpat/libbsdxml.3 _____________________________________________________________________________________________________________ Commit: 330b8d685e585e1c6aa41106dd66a7e4256f2068 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=330b8d685e585e1c6aa41106dd66a7e4256f2068 Author: Philip Paeps (Tue 11 Aug 2026 00:30:15 BST) Committer: Philip Paeps (Wed 19 Aug 2026 02:22:24 BST) contrib/expat: import expat 2.8.3 Changes: https://github.com/libexpat/libexpat/blob/R_2_8_3/expat/Changes Security: CVE-2026-72522 (cherry picked from commit 207d96dabfec14d7b3699747abb539ab3c1118ab) M contrib/expat/Changes M contrib/expat/Makefile.am M contrib/expat/Makefile.in M contrib/expat/README.md M contrib/expat/configure.ac M contrib/expat/doc/reference.html M contrib/expat/doc/xmlwf.1 M contrib/expat/doc/xmlwf.xml M contrib/expat/examples/element_declarations.c M contrib/expat/examples/elements.c M contrib/expat/examples/outline.c M contrib/expat/lib/ascii.h M contrib/expat/lib/asciitab.h M contrib/expat/lib/expat.h M contrib/expat/lib/expat_external.h M contrib/expat/lib/fallthrough.h M contrib/expat/lib/iasciitab.h M contrib/expat/lib/internal.h M contrib/expat/lib/latin1tab.h M contrib/expat/lib/memory_sanitizer.h M contrib/expat/lib/nametab.h M contrib/expat/lib/random_arc4random.c M contrib/expat/lib/random_arc4random.h M contrib/expat/lib/random_arc4random_buf.c M contrib/expat/lib/random_arc4random_buf.h M contrib/expat/lib/random_dev_urandom.c M contrib/expat/lib/random_dev_urandom.h M contrib/expat/lib/random_getentropy.c M contrib/expat/lib/random_getentropy.h M contrib/expat/lib/random_getrandom.c M contrib/expat/lib/random_getrandom.h M contrib/expat/lib/random_rand_s.c M contrib/expat/lib/random_rand_s.h M contrib/expat/lib/siphash.h M contrib/expat/lib/utf8tab.h M contrib/expat/lib/xcsinc.c M contrib/expat/lib/xmlparse.c M contrib/expat/lib/xmlrole.c M contrib/expat/lib/xmlrole.h M contrib/expat/lib/xmltok.c M contrib/expat/lib/xmltok.h M contrib/expat/lib/xmltok_impl.c M contrib/expat/lib/xmltok_impl.h M contrib/expat/lib/xmltok_ns.c M contrib/expat/tests/acc_tests.c M contrib/expat/tests/acc_tests.h M contrib/expat/tests/alloc_tests.c M contrib/expat/tests/alloc_tests.h M contrib/expat/tests/basic_tests.c M contrib/expat/tests/basic_tests.h M contrib/expat/tests/chardata.c M contrib/expat/tests/chardata.h M contrib/expat/tests/common.c M contrib/expat/tests/common.h M contrib/expat/tests/dummy.c M contrib/expat/tests/dummy.h M contrib/expat/tests/handlers.c M contrib/expat/tests/handlers.h M contrib/expat/tests/memcheck.c M contrib/expat/tests/memcheck.h M contrib/expat/tests/minicheck.c M contrib/expat/tests/minicheck.h M contrib/expat/tests/misc_tests.c M contrib/expat/tests/misc_tests.h M contrib/expat/tests/ns_tests.c M contrib/expat/tests/ns_tests.h M contrib/expat/tests/nsalloc_tests.c M contrib/expat/tests/nsalloc_tests.h M contrib/expat/tests/runtests.c M contrib/expat/tests/structdata.c M contrib/expat/tests/structdata.h M contrib/expat/xmlwf/codepage.c M contrib/expat/xmlwf/codepage.h M contrib/expat/xmlwf/ct.c M contrib/expat/xmlwf/filemap.h M contrib/expat/xmlwf/readfilemap.c M contrib/expat/xmlwf/unixfilemap.c M contrib/expat/xmlwf/win32filemap.c M contrib/expat/xmlwf/xmlfile.c M contrib/expat/xmlwf/xmlfile.h M contrib/expat/xmlwf/xmlmime.c M contrib/expat/xmlwf/xmlmime.h M contrib/expat/xmlwf/xmltchar.h M contrib/expat/xmlwf/xmlwf.c M contrib/expat/xmlwf/xmlwf_helpgen.py M contrib/expat/xmlwf/xmlwf_helpgen.sh M lib/libexpat/expat_config.h M lib/libexpat/libbsdxml.3 _____________________________________________________________________________________________________________ Commit: 0256ea4dfed859e03cf727501af9506ceb8de72a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0256ea4dfed859e03cf727501af9506ceb8de72a Author: Tuukka Pasanen (Mon 9 Feb 2026 08:21:25 GMT) Committer: Ed Maste (Tue 18 Aug 2026 20:52:06 BST) nvmecontrol: Add SPDX-License-Identifier tags Reviewed by: emaste Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55275 (cherry picked from commit f8517c21d57f1db005c0d15e14d16252e8e4bfd0) M sbin/nvmecontrol/modules/wdc/wdc.c M sbin/nvmecontrol/power.c _____________________________________________________________________________________________________________ Commit: ef55753315dd28acf1304ad064ebc6c5de61d110 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ef55753315dd28acf1304ad064ebc6c5de61d110 Author: Tuukka Pasanen (Mon 9 Feb 2026 08:14:10 GMT) Committer: Ed Maste (Tue 18 Aug 2026 20:52:05 BST) decryptcore: Add SPDX-License-Identifier tag Reviewed by: emaste Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55270 (cherry picked from commit 299d3e944a15cbffc8ed16a49869e1eaec1fb493) M sbin/decryptcore/decryptcore.c _____________________________________________________________________________________________________________ Commit: 228b4106eb4c45d30312ce713c84fba9a2527d09 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=228b4106eb4c45d30312ce713c84fba9a2527d09 Author: Tuukka Pasanen (Mon 16 Feb 2026 09:02:51 GMT) Committer: Ed Maste (Tue 18 Aug 2026 20:52:05 BST) bhyve: Add SPDX-License-Identifier tag Reviewed by: emaste Sponsored by: The FreeBSD Foundation (cherry picked from commit 499d0f04f55e52327d624d27ead3a0d16e3b465a) M usr.sbin/bhyve/amd64/atkbdc.h _____________________________________________________________________________________________________________ Commit: cd9810f00e5722f6487fbc763c46390357133921 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cd9810f00e5722f6487fbc763c46390357133921 Author: Christos Margiolis (Tue 11 Aug 2026 19:35:27 BST) Committer: Christos Margiolis (Tue 18 Aug 2026 20:34:31 BST) sound: Use unsigned long instead of legacy u_long No functional change intended. Sponsored by: The FreeBSD Foundation MFC after: 1 week (cherry picked from commit afe56ee24679d6584acf02dd17f6ed52c052abe7) M sys/dev/sound/midi/midi.c M sys/dev/sound/pci/csa.c M sys/dev/sound/pci/csamidi.c M sys/dev/sound/pci/csapcm.c M sys/dev/sound/pci/csavar.h M sys/dev/sound/pci/vibes.c M sys/dev/sound/pcm/buffer.c M sys/dev/sound/pcm/dsp.c M sys/dev/sound/pcm/mixer.c M sys/dev/sound/pcm/mixer.h M sys/dev/sound/sndstat.c M sys/dev/sound/usb/uaudio.c _____________________________________________________________________________________________________________ Commit: fd8ca3d51d81cbb00a117d5220cad230777f4d33 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fd8ca3d51d81cbb00a117d5220cad230777f4d33 Author: Li-Wen Hsu (Sat 15 Aug 2026 13:59:19 BST) Committer: Li-Wen Hsu (Tue 18 Aug 2026 14:59:41 BST) share/man/man4: Move non-USB man pages out of MK_USB block uart(4), unix(4), veriexec(4) and the gzero(4) MLINK are not USB things, but they were in the .if ${MK_USB} != "no" block. So if we build with WITHOUT_USB, these man pages are lost. Move them out of the block. Sponsored by: The FreeBSD Foundation (cherry picked from commit 1100d9eca9cb2860c58633a9176dd11a30850da4) M share/man/man4/Makefile _____________________________________________________________________________________________________________ Commit: 3f3f452b907d9bab35381994b135a4090466c1f3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3f3f452b907d9bab35381994b135a4090466c1f3 Author: Mateusz Piotrowski <0mp@FreeBSD.org> (Fri 31 Jul 2026 10:22:44 BST) Committer: Mateusz Piotrowski <0mp@FreeBSD.org> (Tue 18 Aug 2026 10:05:57 BST) pmcstat.8: Add a missing ERRORS section header MFC after: 3 days Sponsored by: fme AG (cherry picked from commit 5729a0b45cd1a24c8b82d161de4711b4e004498d) M usr.sbin/pmcstat/pmcstat.8 _____________________________________________________________________________________________________________ Commit: c62065236a7054b4a98dd46b876fda79dead45fc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c62065236a7054b4a98dd46b876fda79dead45fc Author: Xin LI (Sat 15 Aug 2026 06:55:38 BST) Committer: Xin LI (Tue 18 Aug 2026 03:21:58 BST) MFV: less v704. (cherry picked from commit fa0dc4f0f96a1b77d4be7bcdbf965897cda14521) M contrib/less/NEWS M contrib/less/README M contrib/less/ch.c M contrib/less/charset.c M contrib/less/charset.h M contrib/less/cmd.h M contrib/less/cmdbuf.c M contrib/less/command.c M contrib/less/decode.c M contrib/less/edit.c M contrib/less/filename.c M contrib/less/forwback.c M contrib/less/funcs.h M contrib/less/help.c M contrib/less/input.c M contrib/less/jump.c A contrib/less/less-osc8-open.sh M contrib/less/less.h M contrib/less/less.hlp M contrib/less/less.nro M contrib/less/lessecho.nro M contrib/less/lesskey.nro M contrib/less/lesskey_parse.c M contrib/less/line.c M contrib/less/lsystem.c M contrib/less/main.c M contrib/less/mark.c M contrib/less/optfunc.c M contrib/less/opttbl.c M contrib/less/os.c M contrib/less/output.c M contrib/less/pattern.c M contrib/less/pattern.h M contrib/less/position.c M contrib/less/prompt.c M contrib/less/regexp.c M contrib/less/regexp.h M contrib/less/screen.c M contrib/less/search.c M contrib/less/tags.c M contrib/less/ttyin.c M contrib/less/version.c M usr.bin/less/Makefile M usr.bin/less/defines.h _____________________________________________________________________________________________________________ Commit: 6000eb72a5ba44069bf5290a3504db892cb6dfdb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6000eb72a5ba44069bf5290a3504db892cb6dfdb Author: Kevin Bowling (Tue 11 Aug 2026 16:23:51 BST) Committer: Kevin Bowling (Tue 18 Aug 2026 02:29:43 BST) e1000: Disable autonomous PCH power gating after reset Panther Point changed the reset value of CTRL_EXT.DPG_EN to enable autonomous power gating. Clear it after hardware reset on Panther Point and Nova Point controllers to prevent unexpected Tx/Rx hangs, packet loss, or corruption. (cherry picked from commit 0979b0430c2d728e595841ecba30b63972794fe9) M sys/dev/e1000/e1000_defines.h M sys/dev/e1000/e1000_ich8lan.c _____________________________________________________________________________________________________________ Commit: 508a2324d36e8966f9483b9cf27ae39344342f86 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=508a2324d36e8966f9483b9cf27ae39344342f86 Author: Pawel Sobczyk (Tue 11 Aug 2026 16:11:22 BST) Committer: Kevin Bowling (Tue 18 Aug 2026 02:29:43 BST) ice(4): Add support for E835 CNSA 2.0 adapters Added support for E835 adapters with post-quantum cryptographic (PQC) algorithms in firmware/software signage and in SPDM attestation. Signed-off-by: Pawel Sobczyk Reviewed by: Miłosz Linkiewicz Differential Revision: https://reviews.freebsd.org/D57868 (cherry picked from commit 8194c32827e9c3867d4b295edca9842b71608526) M sys/dev/ice/ice_drv_info.h _____________________________________________________________________________________________________________ Commit: a43b61a1ba453c95018c0cb0042f823863e3ac69 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a43b61a1ba453c95018c0cb0042f823863e3ac69 Author: Jose Luis Duran (Tue 11 Aug 2026 23:34:16 BST) Committer: Jose Luis Duran (Tue 18 Aug 2026 01:30:35 BST) makefs: Allow "legacy" as a valid ZFS mountpoint Allow "legacy" alongside "none" as a valid value for the ZFS mountpoint property, matching zfsprops(7). Reviewed by: imp, markj MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D58781 (cherry picked from commit 59d6422d6f21fd5cf4709ce9fcada54d3925a4f6) M usr.sbin/makefs/tests/makefs_zfs_tests.sh M usr.sbin/makefs/zfs/dsl.c _____________________________________________________________________________________________________________ Commit: 886de9ef5a60f9b3aaeff7afe1f36a2af99781c2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=886de9ef5a60f9b3aaeff7afe1f36a2af99781c2 Author: Jose Luis Duran (Tue 11 Aug 2026 23:27:30 BST) Committer: Jose Luis Duran (Tue 18 Aug 2026 01:30:20 BST) makefs: tests: Fix a missing slash in multi_dataset_4 Fix a typo in the ZFS multi_dataset_4 test, where a path separator was missing. Reported by: markj MFC after: 1 week (cherry picked from commit 889d08f6b61da4724a6f718be7ec8d47824bc602) M usr.sbin/makefs/tests/makefs_zfs_tests.sh _____________________________________________________________________________________________________________ Commit: de3fa71eccfacc23f75dd080d209d907e66d64eb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=de3fa71eccfacc23f75dd080d209d907e66d64eb Author: Ed Maste (Wed 18 Feb 2026 19:20:12 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:54 BST) Correct Identifer typo in SPDX tags (cherry picked from commit 07d29f9c177e731e4497bedf5fde09176c90b444) M sbin/conscontrol/conscontrol.8 M share/man/man4/ahd.4 M share/man/man4/smb.4 M usr.bin/man/manpath.1 M usr.sbin/devinfo/devinfo.8 M usr.sbin/kbdcontrol/kbdcontrol.1 _____________________________________________________________________________________________________________ Commit: eb0290fa44bdd8f5029094760c9501d5a067a196 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=eb0290fa44bdd8f5029094760c9501d5a067a196 Author: Tuukka Pasanen (Mon 16 Feb 2026 09:46:12 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:54 BST) ypserv: Add SPDX-License-Identifier tags Reviewed by: emaste Sponsored by: The FreeBSD Foundation (cherry picked from commit ac8189e6de8fb5de31d5b662f1d406f27285ac74) M usr.sbin/ypserv/common/yplib_host.c M usr.sbin/ypserv/common/yplib_host.h _____________________________________________________________________________________________________________ Commit: 7a4607e32edb7ee63938ea478751d11102b11d0a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7a4607e32edb7ee63938ea478751d11102b11d0a Author: Tuukka Pasanen (Mon 16 Feb 2026 09:45:25 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:54 BST) yppush: Add SPDX-License-Identifier tag Reviewed by: emaste Sponsored by: The FreeBSD Foundation (cherry picked from commit d6bec77ad8f80438f10bb3fe7a8bc8e9265e2858) M usr.sbin/yppush/yppush_extern.h _____________________________________________________________________________________________________________ Commit: f91e12471811c22c8e4dc101b4fd19039e84eab5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f91e12471811c22c8e4dc101b4fd19039e84eab5 Author: Tuukka Pasanen (Mon 16 Feb 2026 09:43:58 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:54 BST) virtual_oss: Add SPDX-License-Identifier tags Reviewed by: emaste Sponsored by: The FreeBSD Foundation (cherry picked from commit 6d5a428056b52c7ce47b01d6af8aaaff6feecfdd) M usr.sbin/virtual_oss/virtual_bt_speaker/bt_speaker.c M usr.sbin/virtual_oss/virtual_equalizer/equalizer.c M usr.sbin/virtual_oss/virtual_oss/audio_delay.c M usr.sbin/virtual_oss/virtual_oss/backend.h M usr.sbin/virtual_oss/virtual_oss/compressor.c M usr.sbin/virtual_oss/virtual_oss/ctl.c M usr.sbin/virtual_oss/virtual_oss/eq.c M usr.sbin/virtual_oss/virtual_oss/format.c M usr.sbin/virtual_oss/virtual_oss/httpd.c M usr.sbin/virtual_oss/virtual_oss/int.h M usr.sbin/virtual_oss/virtual_oss/main.c M usr.sbin/virtual_oss/virtual_oss/mul.c M usr.sbin/virtual_oss/virtual_oss/ring.c M usr.sbin/virtual_oss/virtual_oss/virtual_oss.c M usr.sbin/virtual_oss/virtual_oss/virtual_oss.h M usr.sbin/virtual_oss/virtual_oss_cmd/command.c _____________________________________________________________________________________________________________ Commit: d5de38e798fb18e047e90722a5a1832d0c09ee37 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d5de38e798fb18e047e90722a5a1832d0c09ee37 Author: Tuukka Pasanen (Mon 9 Feb 2026 08:38:13 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:53 BST) sync: Add SPDX-License-Identifier tags Reviewed by: immp Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55216 (cherry picked from commit 0486b5243f094160fd782c1dc15f28392072b259) M bin/sync/sync.c _____________________________________________________________________________________________________________ Commit: 95f82df147c9f88b09ae29b7ff05c5de69ba5be7 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=95f82df147c9f88b09ae29b7ff05c5de69ba5be7 Author: Tuukka Pasanen (Mon 9 Feb 2026 08:11:41 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:53 BST) stty: Add SPDX-License-Identifier tags Reviewed by: imp Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55217 (cherry picked from commit 743a7f954c2720fa318e9e1f7ca1c549977560f9) M bin/stty/cchar.c M bin/stty/extern.h M bin/stty/gfmt.c M bin/stty/key.c M bin/stty/modes.c M bin/stty/print.c M bin/stty/stty.c M bin/stty/stty.h M bin/stty/util.c _____________________________________________________________________________________________________________ Commit: 3e522f28ad48baeea52351f9b1f93ec37daba229 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3e522f28ad48baeea52351f9b1f93ec37daba229 Author: Tuukka Pasanen (Mon 9 Feb 2026 08:11:04 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:53 BST) sleep: Add SPDX-License-Identifier tags Reviewed by: imp Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55215 (cherry picked from commit f4eccc3add7b91532396970913792fa264fc5430) M bin/sleep/sleep.c _____________________________________________________________________________________________________________ Commit: 8d2aee9ae95db71a730fff88f8b69aa46af3d6e4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8d2aee9ae95db71a730fff88f8b69aa46af3d6e4 Author: Tuukka Pasanen (Mon 9 Feb 2026 08:10:25 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:53 BST) sh: Add SPDX-License-Identifier tags Reviewed by: imp Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55213 (cherry picked from commit 632c73b4bfd48b89b7c2318079fd50835b8b5016) M bin/sh/alias.c M bin/sh/alias.h M bin/sh/arith.h M bin/sh/arith_yacc.c M bin/sh/arith_yacc.h M bin/sh/arith_yylex.c M bin/sh/cd.c M bin/sh/cd.h M bin/sh/error.c M bin/sh/error.h M bin/sh/eval.c M bin/sh/eval.h M bin/sh/exec.c M bin/sh/exec.h M bin/sh/expand.c M bin/sh/expand.h M bin/sh/histedit.c M bin/sh/input.c M bin/sh/input.h M bin/sh/jobs.c M bin/sh/jobs.h M bin/sh/mail.c _____________________________________________________________________________________________________________ Commit: c8e1d0ac62a6fb1bd892a6213b7ee44a0b9dfd1e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c8e1d0ac62a6fb1bd892a6213b7ee44a0b9dfd1e Author: Tuukka Pasanen (Mon 9 Feb 2026 08:09:45 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:53 BST) setfacl: Add SPDX-License-Identifier tags Reviewed by: imp Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55212 (cherry picked from commit 575e89cb1786a00387e9c1391055263068c4e0ae) M bin/setfacl/file.c M bin/setfacl/mask.c M bin/setfacl/merge.c M bin/setfacl/remove.c M bin/setfacl/setfacl.c M bin/setfacl/setfacl.h M bin/setfacl/util.c _____________________________________________________________________________________________________________ Commit: 5c81b93758c493632db8ceb272fbcd0dd3cf6bb2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5c81b93758c493632db8ceb272fbcd0dd3cf6bb2 Author: Tuukka Pasanen (Mon 16 Feb 2026 08:55:27 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:53 BST) resizewin: Add SPDX-License-Identifier tags Reviewed by: emaste Sponsored by: The FreeBSD Foundation (cherry picked from commit c33076859fa319396beb10470ad4101f1c3c5571) M usr.bin/resizewin/resizewin.c _____________________________________________________________________________________________________________ Commit: 48a89d2950cbb17838c82e0e18caebf8e7c83177 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=48a89d2950cbb17838c82e0e18caebf8e7c83177 Author: Tuukka Pasanen (Mon 9 Feb 2026 08:09:10 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:52 BST) pwait: Add SPDX-License-Identifier tags Reviewed by: imp Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55211 (cherry picked from commit 0a1fd13e73200756b61d06c949622b4f6bba7dad) M bin/pwait/pwait.c _____________________________________________________________________________________________________________ Commit: e20dfac7c296364c92b3586de8c9a909584c8ce1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e20dfac7c296364c92b3586de8c9a909584c8ce1 Author: Tuukka Pasanen (Mon 9 Feb 2026 08:07:32 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:52 BST) kenv: Add SPDX-License-Identifier tags Reviewed by: imp Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55210 (cherry picked from commit 5705d171dacc69bcdbfc17849a9dc898249dae2e) M bin/kenv/kenv.c _____________________________________________________________________________________________________________ Commit: bc362fd9839381d11655b814b7914c2bc8f960aa URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bc362fd9839381d11655b814b7914c2bc8f960aa Author: Tuukka Pasanen (Mon 9 Feb 2026 08:18:34 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:52 BST) ifconfig: Add SPDX-License-Identifier tags Reviewed by: emaste Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55272 (cherry picked from commit d685228989020f7bceebdaf6ea79be09305d2954) M sbin/ifconfig/ifipsec.c M sbin/ifconfig/ifstf.c M sbin/ifconfig/sfp.c _____________________________________________________________________________________________________________ Commit: f5c5358a53501941c007d72b35bf9d8a9a321b6f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f5c5358a53501941c007d72b35bf9d8a9a321b6f Author: Tuukka Pasanen (Mon 9 Feb 2026 08:06:07 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:52 BST) getfacl: Add SPDX-License-Identifier tags Reviewed by: imp Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55209 (cherry picked from commit 6e8bb77b4c23837d95ba9fb50b41b948c21cbdc3) M bin/getfacl/getfacl.c _____________________________________________________________________________________________________________ Commit: b541d1c0f5744af946c2c4c74d4f74d6c3e14608 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b541d1c0f5744af946c2c4c74d4f74d6c3e14608 Author: Tuukka Pasanen (Mon 9 Feb 2026 08:27:55 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:52 BST) etdump: Add SPDX-License-Identifier tags Reviewed by: emaste Sponsored by: The FreeBSD Foundation (cherry picked from commit 2d1c5f43a2a5a4d3021530c7048e72f39b2ab8d0) M usr.bin/etdump/etdump.c M usr.bin/etdump/etdump.h M usr.bin/etdump/output_shell.c M usr.bin/etdump/output_text.c _____________________________________________________________________________________________________________ Commit: efcc0dda3a8acb5f7c4899d88a1df193c52e99ea URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=efcc0dda3a8acb5f7c4899d88a1df193c52e99ea Author: Tuukka Pasanen (Mon 9 Feb 2026 08:05:17 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:51 BST) ed: Add SPDX-License-Identifier tags Reviewed by: imp Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55208 (cherry picked from commit 9eeab27c56db507f88c3334172e62357c092707e) M bin/ed/buf.c M bin/ed/ed.h M bin/ed/glbl.c M bin/ed/io.c M bin/ed/main.c M bin/ed/re.c M bin/ed/sub.c M bin/ed/undo.c _____________________________________________________________________________________________________________ Commit: 4cbb609637b6e102b0ed5f97f01168795596020c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4cbb609637b6e102b0ed5f97f01168795596020c Author: Tuukka Pasanen (Mon 9 Feb 2026 08:26:19 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:51 BST) diff: Add SPDX-License-Identifier tag Reviewed by: emaste Sponsored by: The FreeBSD Foundation (cherry picked from commit 878cee8d9b9b4c7c5530b0960306c04b1b691325) M usr.bin/diff/diff.h _____________________________________________________________________________________________________________ Commit: 0447e27d046198ca57b287b8b5fb8815cf1ef5c2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0447e27d046198ca57b287b8b5fb8815cf1ef5c2 Author: Tuukka Pasanen (Mon 9 Feb 2026 08:17:45 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:51 BST) devmatch: Add SPDX-License-Identifier tag Reviewed by: emaste Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55271 (cherry picked from commit 835813c88ab6e44590c2d47e2d66fe153cf9dfc5) M sbin/devmatch/devmatch.c _____________________________________________________________________________________________________________ Commit: d2cac456096948da123d39cf56bca60200e47bd7 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d2cac456096948da123d39cf56bca60200e47bd7 Author: Tuukka Pasanen (Mon 9 Feb 2026 08:03:08 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:51 BST) date: Add SPDX-License-Identifier tags Reviewed by: imp Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55207 (cherry picked from commit 62269b2f23859a20bc6a68ca64648217c421c616) M bin/date/vary.c M bin/date/vary.h _____________________________________________________________________________________________________________ Commit: 01e90357f223bac2a47303adc276850d3083b406 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=01e90357f223bac2a47303adc276850d3083b406 Author: Tuukka Pasanen (Mon 9 Feb 2026 08:00:56 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:51 BST) csh: Add SPDX-License-Identifier tags Reviewed by: imp Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D55206 (cherry picked from commit 10a8680b4e9a728a20825d1c8425487bc1a43700) M bin/csh/iconv_stub.c M bin/csh/iconv_stub.h _____________________________________________________________________________________________________________ Commit: 86b8502ea84bdd908fff3858096d1ee039fe3e09 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=86b8502ea84bdd908fff3858096d1ee039fe3e09 Author: Tuukka Pasanen (Mon 9 Feb 2026 08:23:16 GMT) Committer: Ed Maste (Mon 17 Aug 2026 14:07:51 BST) beep: Add SPDX-License-Identifier tag Reviewed by: emaste Sponsored by: The FreeBSD Foundation (cherry picked from commit 7e313584ab1075195ab735c1452375cf2388b162) M usr.bin/beep/beep.c _____________________________________________________________________________________________________________ Commit: fb81f8e010df1f3a8cd37f081d43d9b918491125 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fb81f8e010df1f3a8cd37f081d43d9b918491125 Author: Nimish Jain (Fri 7 Aug 2026 14:11:15 BST) Committer: Mark Johnston (Mon 17 Aug 2026 13:07:42 BST) riscv/vmm: allow vmm to be built in kernel Fixes: ed85203fb7a0 ("vmm: Deduplicate VM and vCPU state management code") Reviewed by: markj MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D58697 (cherry picked from commit 5afb49180c2a5de83c106f7c07e5548622e3abad) M sys/conf/files.riscv _____________________________________________________________________________________________________________ Commit: 582e01321ac6204f3560674c290a58ed89de39f5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=582e01321ac6204f3560674c290a58ed89de39f5 Author: Mark Johnston (Fri 31 Jul 2026 15:22:46 BST) Committer: Mark Johnston (Mon 17 Aug 2026 13:07:41 BST) bhyve: tpm: Avoid printing a message when clearing the cancel bit Some drivers do this routinely, e.g., FreeBSD's tpm20 does this every time it sends a command in tpmcrb_transmit(). This causes the console to fill up with messages. Instead, only print a warning if the cancel bit is set to one. Reviewed by: corvink MFC after: 2 weeks Differential Revision: https://reviews.freebsd.org/D52425 (cherry picked from commit 1c1a3646a1c86624e67a42636894fd1685386cf1) M usr.sbin/bhyve/tpm_intf_crb.c _____________________________________________________________________________________________________________ Commit: f2c99600cbdfa9df93fd0566f49bb001495c91c8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f2c99600cbdfa9df93fd0566f49bb001495c91c8 Author: Mark Johnston (Fri 31 Jul 2026 15:20:00 BST) Committer: Mark Johnston (Mon 17 Aug 2026 13:07:41 BST) tests/libc: Fix fortify_source uio tests Some of the preadv() and readv() tests were not initializing the iovecs they pass to the system call. When the system call is expected to fail, that's fine since the FORTIFY_SOURCE checks cause the process to be aborted. However, in the rest of the test cases, the (p)readv() call could cause spurious test failures, e.g., when an uninitialized iov entry points to the current stack frame and the canary gets overwritten. Modify the tests to explicitly initialize iov entries to avoid this. The "iov" variants don't have this problem, so leave them alone. Reviewed by: kevans MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58289 (cherry picked from commit 1719b754a9ec88fcf0f5f4b001b1b5d5d6db5819) M lib/libc/tests/secure/fortify_uio_test.c M lib/libc/tests/secure/generate-fortify-tests.lua _____________________________________________________________________________________________________________ Commit: 873ba78dfe6d644d1de124a096f46aaae5a9599e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=873ba78dfe6d644d1de124a096f46aaae5a9599e Author: Sujithra Periasamy (Fri 7 Aug 2026 14:07:20 BST) Committer: Mark Johnston (Mon 17 Aug 2026 13:07:41 BST) gve: Implement AQ batching for queue creation and destruction Currently, the FreeBSD driver configures and destroys queues sequentially by issuing individual Admin Queue (AQ) commands. During queue teardown (e.g., interface reset), disabling queues one by one leaves the device in a partially configured state. Because the device does not yet know that the driver is in the process of fully unconfiguring all queues, this intermediate state can trigger transient error logs (such as when queue 0 is disabled while other queues are still active). Modify the driver to use Admin Queue batching for both the creation and destruction of TX and RX queues. Commands are now queued and kicked together, ensuring the queue configuration changes are applied atomically and preventing transient errors from being logged. Signed-off-by: Sujithra Periasamy Reviewed by: markj MFC after: 1 week Sponsored by: Google Differential Revision: https://reviews.freebsd.org/D58696 (cherry picked from commit 36d57489ca07642dec31390e90c25b2a0ca9313e) M sys/dev/gve/gve_adminq.c _____________________________________________________________________________________________________________ Commit: 9c13f8c473333653aa83c56e37ea109e11d2b14c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9c13f8c473333653aa83c56e37ea109e11d2b14c Author: Nimish Jain (Tue 4 Aug 2026 21:35:54 BST) Committer: Mark Johnston (Mon 17 Aug 2026 13:07:41 BST) lib9p: fix compilation errors in example server Reviewed by: markj MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D58634 (cherry picked from commit e6b038456b2b740b7bc41accc36fa85839e79cc3) M contrib/lib9p/example/Makefile M contrib/lib9p/example/server.c _____________________________________________________________________________________________________________ Commit: 730e18a4607cdec7ace37808455acda0585f31fa URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=730e18a4607cdec7ace37808455acda0585f31fa Author: Mark Johnston (Tue 4 Aug 2026 14:35:35 BST) Committer: Mark Johnston (Mon 17 Aug 2026 13:07:41 BST) rawip: Fix handling of checksums in rip6_input() A v6 raw socket may ask the kernel to validate the checksum of an inbound packet. If it does, and the validation fails, we discard the packet, but this isn't really right: other raw sockets may wish to receive a copy of the packet anyway. Rework checksum handling to address this problem, and use a flag to avoid computing the checksum more than once for a given packet. Fixes: de2d47842e880281 ("SMR protection for inpcbs") Reviewed by: pouria, glebius Reported by: Yunzhi Ke MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58559 (cherry picked from commit 196874ce2e97e3e6425493b1d501e716b356bc36) M sys/netinet6/raw_ip6.c _____________________________________________________________________________________________________________ Commit: af488533df8075a4d231773edf8db715f03ab2bf URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=af488533df8075a4d231773edf8db715f03ab2bf Author: Mark Johnston (Tue 4 Aug 2026 14:42:53 BST) Committer: Mark Johnston (Mon 17 Aug 2026 13:07:41 BST) ctl.4: Document the assumption that CTL HA runs only on trusted networks The CTL High Availablity clustering feature allows a pair of hosts to implement transparent failover. The implementation uses a TCP connection to exchange messages. There is no authentication mechanism and the protocol itself embeds kernel pointers in the messages exchanged between HA hosts. This property (of CTL_MSG_DATAMOVE messages specifically), as well as insufficient validation of inbound messages, mean that anyone able to access a CTL HA port is able to remotely execute code on that host. Provide a warning to this effect in the CTL man page. Reported by: Ryan of Calif.io Reviewed by: ziaee, ken, mav MFC after: 3 days Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58622 (cherry picked from commit 3c8f8432b6f653128016c6aaf826e1efb7ee1cec) M share/man/man4/ctl.4 _____________________________________________________________________________________________________________ Commit: 6e59c4eb574b8014f580c777876037dae4de7e22 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6e59c4eb574b8014f580c777876037dae4de7e22 Author: Mark Johnston (Wed 8 Jul 2026 18:13:01 BST) Committer: Mark Johnston (Mon 17 Aug 2026 13:07:41 BST) epoch: Fix epoch_drain_callbacks() This function is supposed to wait until all pending callbacks have been executed. This is useful in some contexts where we tear down some context (like a VNET jail and its associated UMA zones) synchronously, and we want to make sure that all pending asynchronous callbacks (which may free objects to said UMA zones) have run first. The implementation schedules a callback on each CPU and waits for them all to run. This assumes that, on a given CPU, callbacks are executed in the order that they are pushed. This assumption depends on the implementation of epoch_call_task() and ck_epoch_poll_deferred(), and it is not true in general. Callbacks are pushed onto a per-CPU stack in LIFO order. ck_epoch_poll_deferred() first pulls out the callbacks from epoch - 2, which are always safe to execute, and in so doing reorders them such that the oldest callback as at the top of the stack, so in this case, epoch_call_task() will execute them in order. However, ck_epoch_poll_deferred() may determine that it is safe to execute callbacks from epoch - 1 (or even from the current epoch if there are no active readers), and in this case it will push those callbacks onto the returned stack. This means that epoch_call_task() will invoke those newer destructors before the older ones, which means that epoch_drain_callbacks() may return early. Fix the correctness problem by simply doing all of this twice: once the first callback is invoked, we know that all of the callbacks that were pending at the time that epoch_drain_callbacks() was called are scheduled to be executed, so when the second callback is executed we know that they must be finished. This is slow, but it is already slow, and the slowness is less noticeable after commit dce56594991. I note that in an ideal world, this function would not exist, and all of the teardown would happen asynchronously, rather than the current mismash of synchronous and asynchronous cleanup. PR: 290201 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=290201 ) Reviewed by: glebius MFC after: 1 month Differential Revision: https://reviews.freebsd.org/D58030 (cherry picked from commit 7bf11a2f0c9ad7af00996105fd34e61f1040402b) M sys/kern/subr_epoch.c _____________________________________________________________________________________________________________ Commit: 7e6d8a8b8fb66597f30067b6eb56b1c0a6ac2d50 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7e6d8a8b8fb66597f30067b6eb56b1c0a6ac2d50 Author: Mark Johnston (Tue 28 Jul 2026 00:03:47 BST) Committer: Mark Johnston (Mon 17 Aug 2026 13:07:41 BST) proc: Copy the p_reapsubtree field explicitly during fork p_reapsubtree lives in the p_startcopy/p_endcopy block of struct proc, which is copied during fork without any synchronization. However, the field is not stable except when the proctree lock is held, and indeed may change if p1's reaper exits or explicitly releases its reaper status. This state change can race with fork() and leave the child with an incorrect p_reapsubtree field. Close the race: explicitly copy the field under the proctree lock during fork. Reported by: syzkaller Reviewed by: kib MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58482 (cherry picked from commit 8616b7dc3850758eb39a5b63f41f56c05403380b) M sys/kern/kern_fork.c _____________________________________________________________________________________________________________ Commit: baa7ab7f484bb8895d42900c74bc63d5e92e0266 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=baa7ab7f484bb8895d42900c74bc63d5e92e0266 Author: Mark Johnston (Mon 3 Aug 2026 21:44:14 BST) Committer: Mark Johnston (Mon 17 Aug 2026 13:07:40 BST) ip_mroute: Don't assume that a multicast router is running The SIOCGETSGCNT handler may be invoked in this scenario, and if no router has initialized the lookup table, we'll have mfct->mfchashtbl == NULL. PR: 297148 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297148 ) Reported by: Robert Morris MFC after: 1 week Sponsored by: The FreeBSD Foundation (cherry picked from commit 1c0d2f0b1a98526e4f1f5a051ce6904b4c3164e1) M sys/netinet/ip_mroute.c _____________________________________________________________________________________________________________ Commit: f310b83defebddcb0fab9fbb4d9629ea8d0a2f04 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f310b83defebddcb0fab9fbb4d9629ea8d0a2f04 Author: Kevin Bowling (Mon 3 Aug 2026 11:57:39 BST) Committer: Kevin Bowling (Mon 17 Aug 2026 01:25:39 BST) igc: Add VLAN hardware filtering Borrow the e1000 VLAN filter table Ambiguous presence of the feature by Intel was settled by DPDK and emperical testing. Relnotes: yes (cherry picked from commit 8f779f159e2198c85b4fcb8685989879a9330104) M share/man/man4/igc.4 M sys/dev/igc/if_igc.c M sys/dev/igc/if_igc.h _____________________________________________________________________________________________________________ Commit: 49c6cf85f732c15253f9d2bdcab6a5915b7ba65d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=49c6cf85f732c15253f9d2bdcab6a5915b7ba65d Author: Kevin Bowling (Mon 3 Aug 2026 11:31:36 BST) Committer: Kevin Bowling (Mon 17 Aug 2026 01:25:23 BST) igc: Correct hardware error statistics Track RERC separately instead of adding receive errors to the collision count, and read the previously omitted RXERRC register. Include RFC in input errors because CRCERRS does not count bad-CRC runts, implementing the I225 length-error accounting workaround alongside RUC and ROC. Stop treating host transmit MAC discards as receive errors. Expose both RERC and HTDPMC as dedicated MAC statistics so their overlapping counts remain available without corrupting aggregate interface counters. (cherry picked from commit a108ee9138a698f212d6d6832d54e88ce6786617) M sys/dev/igc/if_igc.c M sys/dev/igc/igc_hw.h M sys/dev/igc/igc_mac.c M sys/dev/igc/igc_regs.h _____________________________________________________________________________________________________________ Commit: 3fab6b25469a8eb3f49c933079bf42c5c13c0081 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3fab6b25469a8eb3f49c933079bf42c5c13c0081 Author: Kevin Bowling (Mon 3 Aug 2026 11:28:49 BST) Committer: Kevin Bowling (Mon 17 Aug 2026 01:25:10 BST) igc: Work around I225 v1 minimum IPG erratum I225 v1 cannot receive the minimum inter-packet gap required at 2.5 Gb/s. For affected back-to-back links, Intel recommends using a 15-byte transmit IPG instead of 12 bytes. Program TIPG.IPGT to 0xb for pre-v2 I225 devices at 2.5 Gb/s and restore the default at lower speeds. Avoid penalizing fixed I225 and I226 parts. (cherry picked from commit 709426551c6a3607fb5a33f5b8dbb87cfa9c8125) M sys/dev/igc/if_igc.c M sys/dev/igc/igc_defines.h _____________________________________________________________________________________________________________ Commit: 8c81b3bdd6b0fb0e6dc1c3fa3432151d5f26dfaf URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8c81b3bdd6b0fb0e6dc1c3fa3432151d5f26dfaf Author: Kevin Bowling (Tue 28 Jul 2026 22:53:18 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 23:18:47 BST) iflib: Add restart transactions for IOV reconfiguration Some devices remap the PF queues when entering or leaving SR-IOV. Add opt-in PCI IOV helpers that hold the iflib context lock across the complete stop, driver callback, and restart transaction. Existing drivers continue to use the non-restarting helpers. Sponsored by: BBOX.io (cherry picked from commit f8fa2d77bc305bec519f9f02afe211e903c57573) M sys/net/iflib.c M sys/net/iflib.h _____________________________________________________________________________________________________________ Commit: eceddfb6d935aef22b419e2f1fc3225da482b659 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=eceddfb6d935aef22b419e2f1fc3225da482b659 Author: Kevin Bowling (Mon 10 Aug 2026 16:56:03 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 21:57:52 BST) ixgbe: Report the management packet drop counter The management_pkts_drpd sysctl was wired to MNGPTC, making it an alias of management_pkts_txd, instead of MNGPDC. (cherry picked from commit 435cde959c8823ff38c699d1bc8655918fda57dd) M sys/dev/ixgbe/if_ix.c _____________________________________________________________________________________________________________ Commit: 45aac708880c56d4e1dfe67b314beeaf31d1dd43 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=45aac708880c56d4e1dfe67b314beeaf31d1dd43 Author: Kevin Bowling (Thu 6 Aug 2026 09:21:35 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 21:57:42 BST) ixgbe: Re-enable the SFP laser during initialization ixgbe_if_stop() disables the transmit laser on every 82599 SFP fiber port, but the iflib initialization path did not re-enable it. Re-enable the laser before deferred SFP module setup so interface reinitialization cannot leave either single-speed or multispeed optics dark. The hardware wrapper is a no-op when laser control is unavailable. The placement follows Intel ix-3.4.39; this version deliberately applies to every SFP port affected by the stop path. (cherry picked from commit 545779a99290b7b7d94dece6c096ce230be91ff9) M sys/dev/ixgbe/if_ix.c _____________________________________________________________________________________________________________ Commit: 5cd4954f328331384510486a023e6f03d08ec6a9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5cd4954f328331384510486a023e6f03d08ec6a9 Author: Kevin Bowling (Thu 6 Aug 2026 12:03:28 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 21:56:45 BST) iflib: Permit SR-IOV configuration on a down interface Drivers which remap PF queues need a stop/mutate/restart transaction only when the interface has live queues. Permit their IOV initialization callback while the interface is administratively down and leave it down afterward. This restores the standard boot-time iovctl.conf workflow and lets other opt-in drivers configure VFs before netif brings the PF up. (cherry picked from commit 2cf580c694f6f392531a63f01c3fb89c0244f89a) M sys/net/iflib.c _____________________________________________________________________________________________________________ Commit: cd6f4b3456c63cf6d46b7500acafdc3981829164 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cd6f4b3456c63cf6d46b7500acafdc3981829164 Author: Kevin Bowling (Thu 6 Aug 2026 07:38:06 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 21:46:50 BST) pci: Permit function-level reset of 82599 VFs Intel 82599 supports FLR on VFs but reports FLR support only in the PF Device Capabilities register. The VF register therefore leaves the FLR Capable bit clear, and pcie_flr() rejects the reset. Intel documents the zeroed VF PCIe capability structure as erratum 35 in the 82599 Specification Update (B0=Yes; NoFix). Add a positive FLR quirk for the 82599 VF. Keep the capability check for every other function, so an unknown nonconforming VF cannot make pcie_flr() report success when its reset request was ignored. SR-IOV requires VFs to support FLR, but a clear capability bit cannot distinguish the 82599's misadvertisement from a VF that fails to implement it. (cherry picked from commit ee776a8e291cb73845a8611d3dec5a2a966106b9) M sys/dev/pci/pci.c _____________________________________________________________________________________________________________ Commit: cafdeed9d5d8fc3ac2a9172dc904f3c98df29280 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cafdeed9d5d8fc3ac2a9172dc904f3c98df29280 Author: Kevin Bowling (Thu 6 Aug 2026 07:39:20 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 21:46:10 BST) pci: Ignore SR-IOV VFs when tuning MPS The VF Device Control MPS and MRRS fields are reserved and preserved. VF transactions use the PF MPS, so a hardwired VF value must not be used to retune the shared PCIe hierarchy. Document the previously undocumented tuning knob and clarify why a VF may continue to display its reserved hardwired value. This fixes an instant crash/reboot on my Zen3 system with 82599 VFs. (cherry picked from commit 5aab6164161db397d84e5fff88e1af1a9e405875) M share/man/man4/pci.4 M sys/dev/pci/pci.c _____________________________________________________________________________________________________________ Commit: 5dfc962adec25a370d61684747ee288c96073c33 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5dfc962adec25a370d61684747ee288c96073c33 Author: Kevin Bowling (Fri 31 Jul 2026 14:07:27 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 21:45:54 BST) ixv: reconcile VLAN filters through the mailbox VLAN registration callbacks only update the software shadow, leaving the PF unaware until a later full initialization. Initialization then retries each failed request in a tight loop, while skipping replay entirely when local hardware filtering is disabled. Send additions and removals as soon as the desired state changes, independent of the VF local-filter capability. Replay the desired memberships after reset and retry a bounded batch per timer tick. Stop after the first failure so a silent PF can consume only one mailbox timeout per pass, while a responsive PF can drain several requests. Treat the retry window as a no-progress deadline: advance it when pending work succeeds so a large backlog can drain, but leave entries dormant after a sustained failure. A successful mailbox request wakes a dormant backlog. Dispatch timer-driven retries only while iflib marks the VF running, so a stale timer tick cannot restore PF VLAN state after the stop path resets the VF. Because the callbacks now update the PF or retain failed work for retry, do not restart the VF for VLAN configuration changes. This avoids resetting and flapping the interface for every VLAN addition or removal. Also keep receive VLAN stripping synchronized in both the enabled and disabled cases. Adapt the bounded VLAN reconciliation scheme from igb VF commit fdce3830d9a6 to the ixgbe VF mailbox. (cherry picked from commit 9d871fa96a6e5dff533bc7685fc72d51f55cfd18) M sys/dev/ixgbe/if_ixv.c M sys/dev/ixgbe/ixgbe.h _____________________________________________________________________________________________________________ Commit: 626a367c2b7201ad11c9577d07909ed14ea2a317 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=626a367c2b7201ad11c9577d07909ed14ea2a317 Author: Kevin Bowling (Fri 31 Jul 2026 13:58:01 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 21:45:40 BST) ixgbe: implement VF secondary MAC filters The PF advertises the legacy SET_MACVLAN mailbox request but always rejects it. The request installs secondary unicast addresses. Allocate an owned RAR pool for VF secondary addresses, reserve low entries for PF filters, and place VF-primary addresses at the top of the usable RAR range. Reject address collisions and cap each VF at three secondary filters so one guest cannot exhaust the shared table. Clear secondary filters on VF or PF reset and on SR-IOV teardown. This hardware can anti-spoof only the VF primary source address. Reject secondary filters while MAC anti-spoofing is configured, so installing them requires an explicit administrative policy choice. Report optional filter-table allocation failure without disabling SR-IOV. Adapt the owned-RAR allocation and reset-cleanup model from igb(4) in a2ed165f0049 to DPDK's ixgbe SET_MACVLAN mailbox semantics. Relnotes: yes (cherry picked from commit 6404ef10d62999d6ac16b0fb25bbdcb463b866a2) M share/man/man4/ix.4 M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ixgbe.h M sys/dev/ixgbe/ixgbe_sriov.h _____________________________________________________________________________________________________________ Commit: 1ff14169af4b69c75446c417448a8347bdb64bec URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1ff14169af4b69c75446c417448a8347bdb64bec Author: Kevin Bowling (Fri 31 Jul 2026 13:53:13 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 21:45:28 BST) ixgbe: enforce VF promiscuity and multicast policy The allow-promisc IOV property is advertised but ignored, and the PF rejects the xcast request used by modern VFs. Negotiate mailbox APIs 1.2 and 1.3, implement pool-scoped xcast modes, and require allow-promisc for requested all-multicast or unicast-promiscuous modes. The VF mailbox can carry only 30 multicast hashes. When ixv has a larger list, request the API 1.2 all-multicast xcast mode instead of extending the legacy SET_MULTICAST message. The PF grants that fallback only to VFs configured with allow-promisc; otherwise ixv reports that only the first 30 addresses are active. Reset xcast state with the VF and have ixv replay the mode implied by its interface flags after multicast updates. Follow DPDK's ixgbe API 1.2/1.3 xcast contract, with allow-promisc policy adapted from igb(4) in a2ed165f0049. Relnotes: yes (cherry picked from commit 660ea2c4dafe9c2206c95fe57ecd8972d6395952) M sys/dev/ixgbe/if_ixv.c M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ixgbe.h M sys/dev/ixgbe/ixgbe_sriov.h M sys/dev/ixgbe/ixgbe_vf.c _____________________________________________________________________________________________________________ Commit: df7e516da45ad8e5ba5c449630adeb317b79b42e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=df7e516da45ad8e5ba5c449630adeb317b79b42e Author: Kevin Bowling (Thu 6 Aug 2026 09:21:16 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 21:45:13 BST) ixgbe: Preserve priority-tagged traffic with SR-IOV VID 0 carries only 802.1p priority and does not identify VLAN membership. Keep VFTA bit zero in the persistent PF shadow table so reset and SR-IOV replay admit priority-tagged frames while VLAN filtering is enabled. In virtualization mode, also reserve VLVF slot zero and restore PF and eligible VF pool memberships. A VFTA hit alone admits the tag globally but does not deliver it to the correct pools. This matches the priority-tag treatment in em/igb. (cherry picked from commit caa08ed331da02a91f95472193e25e573c0ae1e3) M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ix_txrx.c _____________________________________________________________________________________________________________ Commit: 06a514be60c814d558629cf7fbfca4936c8137b6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=06a514be60c814d558629cf7fbfca4936c8137b6 Author: Kevin Bowling (Fri 31 Jul 2026 13:47:03 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 21:45:00 BST) ixgbe: preserve VLAN ownership with SR-IOV The VF VLAN capability is checked but never granted, and no SR-IOV configuration property exposes the existing default-VLAN support. PF VLAN updates also replace VFTA registers from a PF-only shadow, erasing live VF filters. Expose access VLAN and trunk policy through the IOV schema. Track each VF VLAN as desired state, restore the administrative VLAN after reset, and use the native VLVF helper for incremental PF and VF ownership changes. Keep VLAN filtering enabled while SR-IOV is active. When PF hardware filtering is disabled, admit every VLAN to the PF without bypassing per-pool VF isolation. Reconstruct VLVF and the shared VFTA from PF and VF desired state after reset or a filtering-mode transition, and restore PF-only state on teardown. When the last VF leaves a VLAN still owned by the PF, free its VLVF slot while retaining the shared VFTA bit. This prevents a trunk VF from exhausting the 64-entry VLVF table by cycling VLAN memberships. Adapt the VLAN ownership model introduced for igb(4) in a2ed165f0049 to ixgbe's native VLVF machinery. Match Linux receive semantics by exposing a stripped VLAN tag only when that VID was registered by the VF. A PF-assigned port VLAN is an administrative tag and must be delivered to the VF as untagged traffic; otherwise the stack dispatches it to a nonexistent VLAN interface and access-VLAN receive traffic is blackholed. Relnotes: yes (cherry picked from commit a81f97aecbfda71fe0b423678732e863571793e2) M share/man/man4/ix.4 M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ix_txrx.c M sys/dev/ixgbe/ixgbe.h _____________________________________________________________________________________________________________ Commit: 59bd5fc94c54f4f02e515627f556bd97dfa38bcf URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=59bd5fc94c54f4f02e515627f556bd97dfa38bcf Author: Kevin Bowling (Fri 31 Jul 2026 13:34:36 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 21:44:47 BST) ixgbe: enforce configured VF anti-spoofing The SR-IOV schema advertises MAC anti-spoofing and enables it by default, but the VF configuration was never consumed and the hardware policy remained disabled. Record the configured policy and apply MAC and VLAN anti-spoofing throughout VF initialization and reset. On X550-family devices, also protect the LLDP and flow-control Ethertypes and enable per-VF spoof-event accounting. Remove the driver-owned state during SR-IOV teardown. Adapt the anti-spoof configuration lifecycle used by igb(4) in a2ed165f0049 to the ixgbe hardware controls. Relnotes: yes (cherry picked from commit 7d3d6309398ebeb4d60e35535160c722cd25f9bb) M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ixgbe_sriov.h _____________________________________________________________________________________________________________ Commit: bc00b347ab9d2f5e26a0646a621fa03d57051a73 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bc00b347ab9d2f5e26a0646a621fa03d57051a73 Author: Kevin Bowling (Fri 31 Jul 2026 12:53:17 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 21:44:35 BST) ixgbe: rebuild the shared multicast table The MTA is shared by the PF and all VFs. The VF mailbox handler only ORs new bits, so hashes survive list removal and VF reset. Conversely, PF multicast updates replace the whole table with PF-only state and discard live VF filters. Rebuild the table from the PF list and every active VF whenever either changes. Clear VF multicast state during reset and PF reinitialization, and remove all VF hashes on SR-IOV teardown. Keep the software shadow and multicast control state synchronized, and avoid writes to unchanged MTA registers. Adapt the aggregate desired-state rebuild introduced for igb(4) in a2ed165f0049 and its write-elision scheme from 350211ab1782 to ixgbe's shared MTA. (cherry picked from commit 1a180b4c86fc7534596cfbe451e25e403db81666) M sys/dev/ixgbe/if_ix.c M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ixgbe.h M sys/dev/ixgbe/ixgbe_sriov.h _____________________________________________________________________________________________________________ Commit: 07b73c334990b62f0817aadbf0685ebf462bd053 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=07b73c334990b62f0817aadbf0685ebf462bd053 Author: Kevin Bowling (Fri 31 Jul 2026 13:59:24 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 21:44:22 BST) ixv: reconcile the PF-approved MAC address The shared VF set-RAR helper restores hw.mac.addr when the PF rejects a requested address, but ixv ignores the error and leaves the interface link-layer address unchanged. Subsequent initialization repeats the rejected request while the interface appears to use an address the PF will not deliver. Refresh the permanent address returned by the PF after every successful reset handshake. Copy the resulting PF-approved address back to the interface and emit the normal link-layer address notification without re-entering the driver initialization path. This also recovers from a prior mailbox transport failure or a PF-side reassignment. Adapt the igb VF address reconciliation added in a6bb3850e7c6. (cherry picked from commit 4c03feacd17199a4d8689e4415992111c99e6220) M sys/dev/ixgbe/if_ixv.c _____________________________________________________________________________________________________________ Commit: cc03ff9a2ba063c8a83ea6e221f12ad7b1b5ca11 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cc03ff9a2ba063c8a83ea6e221f12ad7b1b5ca11 Author: Kevin Bowling (Fri 31 Jul 2026 13:58:30 BST) Committer: Kevin Bowling (Sun 16 Aug 2026 21:44:08 BST) ixv: defer every admin-vector interrupt The VF admin vector carries both link and PF mailbox causes, but the filter schedules the admin task only for link-status changes. Defer administration for every interrupt so reset and control notifications are serviced promptly. (cherry picked from commit 5e05c40aff53f2adb366b3c30ff5b98aac0bb54a) M sys/dev/ixgbe/if_ixv.c _____________________________________________________________________________________________________________ Commit: 5614daf09f71232b1118d2687228d5dc2b9ce520 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5614daf09f71232b1118d2687228d5dc2b9ce520 Author: Dag-Erling Smørgrav (Fri 14 Aug 2026 09:23:47 BST) Committer: Dag-Erling Smørgrav (Sun 16 Aug 2026 21:24:58 BST) ifnet: Restore previous size of if_afdata Struct ifnet contains an array if_afdata of AF_MAX pointers to address information for each possible address family. Since 2013, when AF_MAX was inadvertently changed to be equal to the highest possible value, instead of one more than the highest possible value, this array has been too small in theory, but this never mattered in practice because the higher address families were not assignable to interfaces. My recent commit which corrected the value of AF_MAX had the side effect of breaking the KBI by changing the size and layout of struct ifnet. This manifested itself as kernel panics when using third-party network drivers and went unnoticed in main because if_afdata no longer exists there. Address the issue for stable/15 and stable/14 by keeping the correct value of AF_MAX but deliberately making if_afdata off by one, restoring its previous size. Fixes: ddd850aa7720 ("sys/socket.h: Fix AF_MAX") Sponsored by: Klara, Inc. Sponsored by: NetApp, Inc. Reviewed by: glebius Differential Revision: https://reviews.freebsd.org/D58840 M sys/net/if.c M sys/net/if_private.h _____________________________________________________________________________________________________________ Commit: bd68debe812400263684e9e9aa85d8bd50956e56 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bd68debe812400263684e9e9aa85d8bd50956e56 Author: Dag-Erling Smørgrav (Thu 13 Aug 2026 22:45:58 BST) Committer: Dag-Erling Smørgrav (Sun 16 Aug 2026 21:24:58 BST) libifconfig: Fix table size Tables that have one element per protocol or address family were previously sized by AF_MAX + 1 since AF_MAX was off by one. Now that AF_MAX has been corrected, we need to apply the opposite correction to these tables. Fixes: ddd850aa7720 ("sys/socket.h: Fix AF_MAX") MFC after: 3 days Sponsored by: Klara, Inc. Sponsored by: NetApp, Inc. Reviewed by: kevans Differential Revision: https://reviews.freebsd.org/D58827 (cherry picked from commit 79a6ad63e6afdfa00d0e625996bddf91e9f217c3) M lib/libifconfig/libifconfig_internal.h _____________________________________________________________________________________________________________ Commit: fb81855f198198a9035bf68196dba5f67662d0ff URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fb81855f198198a9035bf68196dba5f67662d0ff Author: Dag-Erling Smørgrav (Thu 13 Aug 2026 22:45:53 BST) Committer: Dag-Erling Smørgrav (Sun 16 Aug 2026 21:24:58 BST) routing: Fix table sizes Tables that have one element per protocol or address family were previously sized by AF_MAX + 1 since AF_MAX was off by one. Now that AF_MAX has been corrected, we need to apply the opposite correction to these tables. Fixes: ddd850aa7720 ("sys/socket.h: Fix AF_MAX") MFC after: 3 days Sponsored by: Klara, Inc. Sponsored by: NetApp, Inc. Reviewed by: pouria, kevans, glebius Differential Revision: https://reviews.freebsd.org/D58826 (cherry picked from commit 6c41d928bcd763ec60d55bec2886c05b03cf9e6a) M sys/net/route/route_tables.c _____________________________________________________________________________________________________________ Commit: bd514a3f0bf14946ec4cab02227ef6b5a24aaa7f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bd514a3f0bf14946ec4cab02227ef6b5a24aaa7f Author: Konstantin Belousov (Sun 16 Aug 2026 17:33:00 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 17:33:00 BST) libsysdecode: reduce diff to main Noted by: des Fixes: c6d7f60df1d6 (MFC of "libsysdecode: Recognize NOTE_PDSIGCHLD") M lib/libsysdecode/flags.c _____________________________________________________________________________________________________________ Commit: cfc5ebfeb889a0e894f94bfe45ee1ba4338ececb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cfc5ebfeb889a0e894f94bfe45ee1ba4338ececb Author: Konstantin Belousov (Fri 31 Jul 2026 07:55:17 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:40 BST) tests/sys/capsicum: adjust tests for the new reaping behavior (cherry picked from commit 77d6c45afdca8a524a88edfb3097d4d9dc90b583) M tests/sys/capsicum/procdesc.cc M tests/sys/capsicum/syscalls.h _____________________________________________________________________________________________________________ Commit: 3bd40a3915a1716ca6091b960e41b2e2a2f85900 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3bd40a3915a1716ca6091b960e41b2e2a2f85900 Author: Alan Somers (Thu 29 Jan 2026 20:39:20 GMT) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:39 BST) capsicum-tests: remove Linux support (cherry picked from commit fba81b33aabff74ad03d5f9f9663c176cf060fa6) M tests/sys/capsicum/README.md M tests/sys/capsicum/capability-fd-pair.cc M tests/sys/capsicum/capability-fd.cc M tests/sys/capsicum/capmode.cc M tests/sys/capsicum/capsicum-freebsd.h D tests/sys/capsicum/capsicum-linux.h M tests/sys/capsicum/capsicum-rights.h M tests/sys/capsicum/capsicum-test-main.cc M tests/sys/capsicum/capsicum-test.cc M tests/sys/capsicum/capsicum.h M tests/sys/capsicum/fcntl.cc M tests/sys/capsicum/ioctl.cc M tests/sys/capsicum/linux.cc M tests/sys/capsicum/openat.cc M tests/sys/capsicum/procdesc.cc M tests/sys/capsicum/sctp.cc M tests/sys/capsicum/select.cc M tests/sys/capsicum/smoketest.c M tests/sys/capsicum/socket.cc M tests/sys/capsicum/syscalls.h M tests/sys/capsicum/sysctl.cc M tests/sys/capsicum/waittest.c _____________________________________________________________________________________________________________ Commit: 08adf7c06815d4ea6d6cd592cbc629f09e27194d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=08adf7c06815d4ea6d6cd592cbc629f09e27194d Author: Konstantin Belousov (Wed 5 Aug 2026 17:33:19 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:39 BST) pddupfd.2: fix errno value returned for non-procdesc argument (cherry picked from commit dfdd8af5a8de8f193747f5ec13cd501106823d2d) M lib/libsys/pdfork.2 _____________________________________________________________________________________________________________ Commit: 83fa3c3ad84405df0ccbe5e65491df63b24782a0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=83fa3c3ad84405df0ccbe5e65491df63b24782a0 Author: Konstantin Belousov (Wed 5 Aug 2026 09:04:49 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:39 BST) pdkill(2), pdgetpid(2): return EBADF if the file type is not procdesc PR: 297293 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297293 ) (cherry picked from commit e8b9b6b9f31c463137b4104550bfb3286a43703a) M sys/kern/kern_exit.c M sys/kern/kern_sig.c M sys/kern/sys_procdesc.c M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: d510a58af69cc6a06909595275526ad185972347 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d510a58af69cc6a06909595275526ad185972347 Author: Konstantin Belousov (Wed 29 Jul 2026 06:29:21 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:38 BST) tests/sys/kern: adjust tests for the new reaping behavior (cherry picked from commit a96f285b5953f6ff3adb3ab43433ba9e15a9aa46) M tests/sys/kern/pdwait.c M tests/sys/kern/procdesc.c M tests/sys/kern/ptrace_test.c M tests/sys/kern/reaper.c _____________________________________________________________________________________________________________ Commit: dd1252e300636b40cc10473cda8d93032e26e12c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=dd1252e300636b40cc10473cda8d93032e26e12c Author: Olivier Cochard (Thu 30 Jul 2026 15:28:42 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:38 BST) tests/procdesc: Fix race in pdopenpid_pdwait_only_one (cherry picked from commit 727a83e90098e1c0fc4acdcf9b8099a70e6ea2b2) M tests/sys/kern/procdesc.c _____________________________________________________________________________________________________________ Commit: 0d4429925d85939b1757f78d135060278e8217f6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0d4429925d85939b1757f78d135060278e8217f6 Author: Konstantin Belousov (Tue 7 Jul 2026 06:49:54 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:37 BST) pddupfd(2): add basic test (cherry picked from commit 23e94b040b9b99f097c113fc8576576ffec0486f) M tests/sys/kern/procdesc.c _____________________________________________________________________________________________________________ Commit: fe74f9b33b4b1b3e809a5cac5f67564a4910f65e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fe74f9b33b4b1b3e809a5cac5f67564a4910f65e Author: Mark Johnston (Tue 7 Jul 2026 15:14:39 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:37 BST) tests/procdesc: Add some test cases for pdopenpid() (cherry picked from commit 0083a4d6224f1290af31528b55ba27c51e27ba46) M tests/sys/kern/procdesc.c _____________________________________________________________________________________________________________ Commit: c20ccfc06adecb0a9316ad574e34e875ad3f3552 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c20ccfc06adecb0a9316ad574e34e875ad3f3552 Author: Konstantin Belousov (Tue 21 Jul 2026 21:03:46 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:36 BST) pdwait(2), wait(2): document interaction between pdopenpid() and waitpid() (cherry picked from commit c49198534a9b823c18c8b9e67e3b16a2d0fa27ad) M lib/libsys/pdfork.2 M lib/libsys/wait.2 _____________________________________________________________________________________________________________ Commit: 9d6498310f5c49668a3ed402dc307345c8f0a2ea URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9d6498310f5c49668a3ed402dc307345c8f0a2ea Author: Konstantin Belousov (Wed 15 Jul 2026 18:30:51 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:36 BST) processes: add zombie references, each of them prevents reap (cherry picked from commit bcdb6ba94d08554eeb9bde4d2468707a612f5d90) M sys/kern/kern_exit.c M sys/kern/kern_fork.c M sys/kern/sys_procdesc.c M sys/sys/proc.h M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: ecdc9cfea64c987bfb1a2382b7e263016005cd54 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ecdc9cfea64c987bfb1a2382b7e263016005cd54 Author: Konstantin Belousov (Tue 28 Jul 2026 01:31:51 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:35 BST) pdwait(2): change handling of the exited processes (cherry picked from commit 7da4edd300984abe67ff503828c1674a28e4b8b0) M sys/kern/kern_exit.c M sys/kern/sys_procdesc.c M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: eabe343afe62a80b8317913e899f63e8e874c46b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=eabe343afe62a80b8317913e899f63e8e874c46b Author: Konstantin Belousov (Thu 23 Jul 2026 03:14:54 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:35 BST) kern/kern_exit.c: make wait_fill_siginfo/wrusage global (cherry picked from commit a24674ecab24abf6cc84262059b3e28bb0cd3a04) M sys/kern/kern_exit.c M sys/sys/proc.h _____________________________________________________________________________________________________________ Commit: a3b8ff99b54679f2a1b5da7f8cf52992adb34840 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a3b8ff99b54679f2a1b5da7f8cf52992adb34840 Author: Mark Johnston (Fri 24 Jul 2026 21:06:16 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:34 BST) procdesc: Remove dead code (cherry picked from commit 9a7bd3309bec08802e8c18c03669812ec3352534) M sys/kern/kern_exit.c M sys/kern/sys_procdesc.c M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: 4435b4fbe0d04718705de623ad68d79f44295d9d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4435b4fbe0d04718705de623ad68d79f44295d9d Author: Mark Johnston (Fri 24 Jul 2026 21:05:26 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:34 BST) procdesc: Disallow pddupfd() of non-passable files (cherry picked from commit 91e11c8f2b38eb1d1f3a1d57b27378fb2c6ab3c1) M lib/libsys/pdfork.2 M sys/kern/sys_procdesc.c _____________________________________________________________________________________________________________ Commit: 945995c5e3f1a4985b4eb2160de952c3ee77d99c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=945995c5e3f1a4985b4eb2160de952c3ee77d99c Author: Konstantin Belousov (Tue 28 Jul 2026 00:37:44 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:34 BST) kern_pdwait(): print the process pointer through pd (cherry picked from commit 2e259c209f6912bc99e18bbfb55dd10554b3b11d) M sys/kern/kern_exit.c _____________________________________________________________________________________________________________ Commit: c6d7f60df1d625b6ebf7099b87bfdd52776802fe URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c6d7f60df1d625b6ebf7099b87bfdd52776802fe Author: Dag-Erling Smørgrav (Tue 21 Jul 2026 22:56:56 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:33 BST) libsysdecode: Recognize NOTE_PDSIGCHLD (cherry picked from commit a931431a1deca75079f034b74a63c2774f83be8d) M lib/libsysdecode/flags.c _____________________________________________________________________________________________________________ Commit: 404eeb14f95788b1cf3d1bbac2cb50b30dfcc622 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=404eeb14f95788b1cf3d1bbac2cb50b30dfcc622 Author: Konstantin Belousov (Sat 18 Jul 2026 18:31:31 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:33 BST) procdesc: report NOTE_PDSIGCHLD for traced and stopped process (cherry picked from commit b328975b9d7c475cd99107ca407df04366cc38af) M sys/kern/sys_procdesc.c _____________________________________________________________________________________________________________ Commit: 0e3a044e4c4b0af4f25db6695d9340a7a7e57c2d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0e3a044e4c4b0af4f25db6695d9340a7a7e57c2d Author: Konstantin Belousov (Fri 17 Jul 2026 06:38:57 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:33 BST) kqueue.2: document EVFILT_PROCDESC support for NOTE_FORK (cherry picked from commit 3f88f6b89942a7f3aa6bb682b02b7307d060b52f) M lib/libsys/kqueue.2 _____________________________________________________________________________________________________________ Commit: f86fd0a1af0b56af991c3740deccca349f0b9466 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f86fd0a1af0b56af991c3740deccca349f0b9466 Author: Konstantin Belousov (Thu 16 Jul 2026 01:49:02 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:32 BST) EVFILT_PROCDESC: support NOTE_FORK (cherry picked from commit e8d4d754e1c73b01c89580a26c22f982415c694a) M sys/kern/kern_fork.c M sys/kern/sys_procdesc.c M sys/sys/event.h M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: 6ea35ec38acf99278fae979356b9d5700c07e9d1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6ea35ec38acf99278fae979356b9d5700c07e9d1 Author: Konstantin Belousov (Thu 16 Jul 2026 08:50:34 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:32 BST) fget_procdesc(): change error for non-procdesc type from EBADF to EINVAL (cherry picked from commit e18844223d1eabb7e435ff9da20d88915d3f4675) M sys/kern/sys_procdesc.c _____________________________________________________________________________________________________________ Commit: e8008c0fc1a37ddd464e1f1f28024113323a299a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e8008c0fc1a37ddd464e1f1f28024113323a299a Author: Konstantin Belousov (Wed 15 Jul 2026 21:57:44 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:32 BST) kern/sys_process.c: remove extra () (cherry picked from commit fed49793ddd197e3dd86c8456b39f569ab74b54c) M sys/kern/sys_process.c _____________________________________________________________________________________________________________ Commit: 4a1744caf8446cb892b573c4ce91383f3243b811 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4a1744caf8446cb892b573c4ce91383f3243b811 Author: Konstantin Belousov (Wed 15 Jul 2026 18:30:51 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:31 BST) sys/proc.h: remove spurious blank lines (cherry picked from commit a48a27532567b3ec2178110994f5cea245a54ac2) M sys/sys/proc.h _____________________________________________________________________________________________________________ Commit: 1b148ecb7433971dd31869cfd6d0c25f1bad85f7 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1b148ecb7433971dd31869cfd6d0c25f1bad85f7 Author: Konstantin Belousov (Wed 15 Jul 2026 18:01:20 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:31 BST) kern: change several int types to bools (cherry picked from commit 1f5fe8ad5293aad0308010d408dfdec6ab19e176) M sys/kern/kern_exit.c M sys/kern/sys_procdesc.c M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: c66b6867d4b90b12e1cd0789cb60ec0959d99a05 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c66b6867d4b90b12e1cd0789cb60ec0959d99a05 Author: Konstantin Belousov (Wed 8 Jul 2026 15:21:58 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:30 BST) kern: add fget_procdesc() (cherry picked from commit 97de8330e1683e41883887d19ea489bda90e5c61) M sys/kern/kern_exit.c M sys/kern/kern_sig.c M sys/kern/sys_procdesc.c M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: 75ccdf8cff485db1f8c9653df6e706bbb9227372 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=75ccdf8cff485db1f8c9653df6e706bbb9227372 Author: Konstantin Belousov (Sat 11 Jul 2026 16:50:26 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:30 BST) pdwait(2): make debugging events functional (cherry picked from commit 0f1718e0d588375d6ab6be52f5253fe143c5c75f) M sys/kern/sys_procdesc.c _____________________________________________________________________________________________________________ Commit: 74141b7e1ec2c61fc6a8877428d912204f139ce3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=74141b7e1ec2c61fc6a8877428d912204f139ce3 Author: Konstantin Belousov (Fri 10 Jul 2026 16:26:50 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:29 BST) kqueue.2: document NOTE_PDSIGCHLD (cherry picked from commit 4cd67a0eea4eba63cf50a45a4665d8700df8d188) M lib/libsys/kqueue.2 _____________________________________________________________________________________________________________ Commit: 547751e4efcef869344d4ea8d4906f3b7817ff4f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=547751e4efcef869344d4ea8d4906f3b7817ff4f Author: Konstantin Belousov (Thu 9 Jul 2026 12:08:45 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:29 BST) procdesc: add NOTE_PDSIGCHLD (cherry picked from commit 2a5e58c59694bc719d7ab82abb1c65ee2045329d) M sys/kern/kern_sig.c M sys/kern/sys_procdesc.c M sys/sys/event.h M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: 8b7b37139f0cfb72aebe7573404a450c1d314b94 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8b7b37139f0cfb72aebe7573404a450c1d314b94 Author: Konstantin Belousov (Wed 8 Jul 2026 07:08:55 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:28 BST) pdfork.2: grammar (cherry picked from commit a2426d1cd89e8cee08612951c133663dd8834838) M lib/libsys/pdfork.2 _____________________________________________________________________________________________________________ Commit: faba4689274867d1427615c07c48277aae3a1f4c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=faba4689274867d1427615c07c48277aae3a1f4c Author: Konstantin Belousov (Tue 26 May 2026 02:24:54 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:28 BST) kern/sys_process.c: clean up includes (cherry picked from commit f87f97d4c9b30dde1cdb3d72dfd699aed9c307e1) M sys/kern/sys_process.c _____________________________________________________________________________________________________________ Commit: 8c57cf9d0d6b0918aa8d5508f91806b012b53b3a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8c57cf9d0d6b0918aa8d5508f91806b012b53b3a Author: Konstantin Belousov (Thu 21 May 2026 20:13:18 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:28 BST) Regen. (cherry picked from commit 080a7fe981783590bf7f0ff39eb44dc2eecd58a2) M lib/libsys/_libsys.h M lib/libsys/syscalls.map M sys/compat/freebsd32/freebsd32_syscall.h M sys/compat/freebsd32/freebsd32_syscalls.c M sys/compat/freebsd32/freebsd32_sysent.c M sys/compat/freebsd32/freebsd32_systrace_args.c M sys/kern/init_sysent.c M sys/kern/syscalls.c M sys/kern/systrace_args.c M sys/sys/syscall.h M sys/sys/syscall.mk M sys/sys/sysproto.h _____________________________________________________________________________________________________________ Commit: 55fdf7561cc4d7048a46264b115987c4ac03baab URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=55fdf7561cc4d7048a46264b115987c4ac03baab Author: Konstantin Belousov (Fri 22 May 2026 11:09:01 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:27 BST) pdfork.2: document pddupfd() (cherry picked from commit c20558e5c9dadfdddc879ee50a65d14beb4992b9) M lib/libsys/Makefile.sys M lib/libsys/pdfork.2 _____________________________________________________________________________________________________________ Commit: db3b6e4413cba234e796eeb90d4a99eee02fa145 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=db3b6e4413cba234e796eeb90d4a99eee02fa145 Author: Konstantin Belousov (Thu 21 May 2026 20:19:57 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:27 BST) libsys: export pddupfd(2) (cherry picked from commit 2a41a8f64ba12c0d446bf1d4ed1334610f013773) M lib/libsys/Symbol.sys.map M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: 61f4a89823b7db38c0e997a135522f1838bfdb86 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=61f4a89823b7db38c0e997a135522f1838bfdb86 Author: Konstantin Belousov (Thu 21 May 2026 20:12:45 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:26 BST) kern: add pddupfd(2) (cherry picked from commit 1ad21a6521827473dc6692646e9c760a5b0521cd) M sys/kern/kern_descrip.c M sys/kern/sys_procdesc.c M sys/kern/syscalls.master _____________________________________________________________________________________________________________ Commit: f04e79a28a14ddae9bf1781432a020ef3466d236 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f04e79a28a14ddae9bf1781432a020ef3466d236 Author: Konstantin Belousov (Thu 21 May 2026 20:12:22 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:26 BST) Add CAP_PDDUPFD capability (cherry picked from commit 046a4efe78addafcd4810974d6c71c1cdd591b6b) M sys/kern/subr_capability.c M sys/sys/caprights.h M sys/sys/capsicum.h _____________________________________________________________________________________________________________ Commit: e3a6c0514fa86b1331d8ecd40dbd87d71b768260 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e3a6c0514fa86b1331d8ecd40dbd87d71b768260 Author: Konstantin Belousov (Thu 21 May 2026 20:11:02 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:26 BST) sys/capsicum.h: fix comment for CAP_PDWAIT (cherry picked from commit 193fd496995d7d22d65c424716e8308fa769aa0a) M sys/sys/capsicum.h _____________________________________________________________________________________________________________ Commit: 9fefa628025cbd0f44bab388607b61adf14167d8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9fefa628025cbd0f44bab388607b61adf14167d8 Author: Konstantin Belousov (Sat 23 May 2026 08:03:17 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:25 BST) fget_remote(): return fcaps and fde_flags if requested (cherry picked from commit 77b6adbe5e351d1907e14d21c49291ff40ba879a) M sys/kern/kern_descrip.c M sys/kern/kern_event.c M sys/kern/sys_generic.c M sys/sys/file.h _____________________________________________________________________________________________________________ Commit: a105154d6617c0c31237a65d5516e60da30277fa URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a105154d6617c0c31237a65d5516e60da30277fa Author: Konstantin Belousov (Tue 7 Jul 2026 03:00:13 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:25 BST) Regen M lib/libsys/_libsys.h M lib/libsys/syscalls.map M sys/compat/freebsd32/freebsd32_syscall.h M sys/compat/freebsd32/freebsd32_syscalls.c M sys/compat/freebsd32/freebsd32_sysent.c M sys/compat/freebsd32/freebsd32_systrace_args.c M sys/kern/init_sysent.c M sys/kern/syscalls.c M sys/kern/systrace_args.c M sys/sys/syscall.h M sys/sys/syscall.mk M sys/sys/sysproto.h _____________________________________________________________________________________________________________ Commit: c217af1e6e53e96f41619cfcc2e61fc722359d11 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c217af1e6e53e96f41619cfcc2e61fc722359d11 Author: Konstantin Belousov (Tue 7 Jul 2026 09:05:20 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:24 BST) pdfork.2: grammar (cherry picked from commit 849a51ac8371f45a61e93c7b5787da93cf751c75) M lib/libsys/pdfork.2 _____________________________________________________________________________________________________________ Commit: 8c17b933a8699037e4e080fe1b36ebbf9a9e32b2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8c17b933a8699037e4e080fe1b36ebbf9a9e32b2 Author: Konstantin Belousov (Thu 21 May 2026 18:33:43 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:24 BST) pdfork.2: document pdopenpid(2) (cherry picked from commit 3e8b68c26e2b108dac96517ef8fd26fe7dce5bcd) M lib/libsys/Makefile.sys M lib/libsys/pdfork.2 _____________________________________________________________________________________________________________ Commit: 9b54abf7eed8fd06fe7d8cf27fe64d3d2d17d472 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9b54abf7eed8fd06fe7d8cf27fe64d3d2d17d472 Author: Konstantin Belousov (Mon 25 May 2026 18:49:50 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:23 BST) pdfork.2: clarify that PD_DAEMON acts on current file (cherry picked from commit 5a5affd457eb3ab89b57c9c512a8843d9011133f) M lib/libsys/pdfork.2 _____________________________________________________________________________________________________________ Commit: 513ebe011bf5406429d935c43007e3b67e6484c3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=513ebe011bf5406429d935c43007e3b67e6484c3 Author: Konstantin Belousov (Wed 20 May 2026 03:05:02 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:23 BST) pdfork.2: document EINVAL for pdwait(2) (cherry picked from commit 1cced493289962858c961b06b161b44ca43e7ac7) M lib/libsys/pdfork.2 _____________________________________________________________________________________________________________ Commit: 641ae0ebbd71b6a8695b5a4aeec86387bfd2861c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=641ae0ebbd71b6a8695b5a4aeec86387bfd2861c Author: Konstantin Belousov (Wed 20 May 2026 03:05:02 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:22 BST) libsys: export pdopenpid(2) (cherry picked from commit d6ff3bb3de91a2f1980c24e748ea5dc16b0987fd) M lib/libsys/Symbol.sys.map M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: db1ef2a140ae333ad89511b69aeb928eb45e6806 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=db1ef2a140ae333ad89511b69aeb928eb45e6806 Author: Konstantin Belousov (Wed 20 May 2026 03:14:24 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:22 BST) sys: add AUE_PDOPENPID (cherry picked from commit 606061ea463dd1d7c3664b296e569b4b25d0f275) M sys/bsm/audit_kevents.h M sys/kern/sys_procdesc.c M sys/kern/syscalls.master M sys/security/audit/audit_bsm.c _____________________________________________________________________________________________________________ Commit: 43c9d80a4443c2497d663d0b050375253e39e966 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=43c9d80a4443c2497d663d0b050375253e39e966 Author: Konstantin Belousov (Wed 20 May 2026 03:04:02 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:21 BST) kern: add pdopenpid(2) (cherry picked from commit 5c32aa785184bb1e646b0b4c73d3c5fd9a6b8951) M sys/kern/sys_procdesc.c M sys/kern/syscalls.master M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: 886aadb639415308a696a49a35066e536cdc1caf URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=886aadb639415308a696a49a35066e536cdc1caf Author: Konstantin Belousov (Mon 25 May 2026 18:48:03 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:21 BST) procdesc: make PD_DAEMON per-file (cherry picked from commit c0e1201aaba8860bdcfd754e35024a85ceb1580a) M sys/kern/sys_procdesc.c M sys/sys/file.h M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: cd349e1bcd21bbf9fd8834550cb6b8305977472c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cd349e1bcd21bbf9fd8834550cb6b8305977472c Author: Konstantin Belousov (Thu 21 May 2026 01:47:20 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:21 BST) procdesc: track count of open files (cherry picked from commit 18b6bb5231bf1c927a6f8de24e466764fe1f7470) M sys/kern/kern_exit.c M sys/kern/sys_procdesc.c M sys/sys/procdesc.h _____________________________________________________________________________________________________________ Commit: baf3b132b572e7cc7963425304d49043926c2c6f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=baf3b132b572e7cc7963425304d49043926c2c6f Author: Konstantin Belousov (Fri 5 Jun 2026 02:42:44 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:20 BST) sys_procdesc: extract procdesc_destroy() (cherry picked from commit 90b560f7bae649f9770e787d9e268401a1319493) M sys/kern/sys_procdesc.c _____________________________________________________________________________________________________________ Commit: 69d29fedc1bd7f98796a00a8338d1c9555f4dc1e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=69d29fedc1bd7f98796a00a8338d1c9555f4dc1e Author: Konstantin Belousov (Wed 20 May 2026 03:03:32 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:20 BST) sys_procdesc: extract pdtofdflags() (cherry picked from commit 974770199877ae7aa912b6dced909429c52dea93) M sys/kern/sys_procdesc.c _____________________________________________________________________________________________________________ Commit: 1cdfd599002bb5ae6c4407a4dddc4b10930e07fb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1cdfd599002bb5ae6c4407a4dddc4b10930e07fb Author: Konstantin Belousov (Wed 20 May 2026 03:02:54 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:20 BST) sys_procdesc: extract procdesc_alloc() (cherry picked from commit 599d021224f2af3fc0befdbd6b804a328dd556f9) M sys/kern/sys_procdesc.c _____________________________________________________________________________________________________________ Commit: 983a9f7a1276550ba107ff97e199c833c09372a1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=983a9f7a1276550ba107ff97e199c833c09372a1 Author: Konstantin Belousov (Fri 14 Aug 2026 06:00:21 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:19 BST) compat/freebsd32: set uio_rw for trailer's uio in freebsd32_sendfile() PR: 297516 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297516 ) (cherry picked from commit 4b17776d9afd0009ac8547126c59c97eda0f3fc9) M sys/compat/freebsd32/freebsd32_misc.c _____________________________________________________________________________________________________________ Commit: 75bf78a0ed8d3e108532c8893f5dad8bdb2b0b3e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=75bf78a0ed8d3e108532c8893f5dad8bdb2b0b3e Author: Konstantin Belousov (Fri 14 Aug 2026 06:46:07 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:19 BST) kern/sys_process.c: make vmspace_rwmem() similar to io functions PR: 297512 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297512 ) (cherry picked from commit 1a71d24ecd0dbaf61fd2a44166e9be07c328b198) M sys/kern/sys_process.c _____________________________________________________________________________________________________________ Commit: c9b5dd2eb8200eb9be6795fd2b0774991d85e1ef URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c9b5dd2eb8200eb9be6795fd2b0774991d85e1ef Author: Konstantin Belousov (Fri 14 Aug 2026 06:23:22 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:18 BST) kern/kern_proc.c: do not throw out read data in get_ps_strings() PR: 297512 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297512 ) (cherry picked from commit f6000e9dd934db9fefc31eaa07a7d8fa9277484e) M sys/kern/kern_proc.c _____________________________________________________________________________________________________________ Commit: cd5c35f504f550e5e94f172cbe154d49f36c241c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cd5c35f504f550e5e94f172cbe154d49f36c241c Author: Konstantin Belousov (Fri 14 Aug 2026 00:18:18 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:18 BST) netipsec/xform_ipcomp.c: fix sockaddr type set in ipcomp6_nonexp_encapcheck() (cherry picked from commit 01d4e3c1d3ffa14041d8faa3a7a6e6509e73af84) M sys/netipsec/xform_ipcomp.c _____________________________________________________________________________________________________________ Commit: fffaf471280bf6f9e73603d84361a101e1160330 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fffaf471280bf6f9e73603d84361a101e1160330 Author: Konstantin Belousov (Tue 4 Aug 2026 16:52:53 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:18 BST) PF_KEY socket: limit the length of copied socket address PR: 297264 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297264 ) (cherry picked from commit cba481a7bff2fcf31420ee8b2714660e2666452b) M sys/netipsec/key.c _____________________________________________________________________________________________________________ Commit: e4ce2c12f9947242b68070f22b6b168ef6447188 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e4ce2c12f9947242b68070f22b6b168ef6447188 Author: Konstantin Belousov (Fri 14 Aug 2026 00:25:21 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:18 BST) netipsec/key.c::key_checksockaddrs(): constify src/dst address buffer pointers (cherry picked from commit fbe9aa7ebfcd6d89b298cc7a23de02d119367221) M sys/netipsec/key.c _____________________________________________________________________________________________________________ Commit: ff2cddb26686e0097c09dfb37c7c447d29425f20 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ff2cddb26686e0097c09dfb37c7c447d29425f20 Author: Konstantin Belousov (Sat 8 Aug 2026 20:01:20 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:17 BST) linuxkpi: stop inlining accesses to curthread->td_lkpi_task (cherry picked from commit 6747bf7e223e5400af1c434618b14debd8dca0cf) M sys/compat/linuxkpi/common/include/linux/sched.h M sys/compat/linuxkpi/common/src/linux_compat.c _____________________________________________________________________________________________________________ Commit: 2520c8bd2c42f4333bc1f4b94a78efa625bc97c9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2520c8bd2c42f4333bc1f4b94a78efa625bc97c9 Author: Konstantin Belousov (Fri 7 Aug 2026 20:48:31 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:17 BST) tty: do not recurse on ttydev_close() (cherry picked from commit e2cfbd498af88a211b0b347861cfd989e57cd1fb) M sys/kern/tty.c M sys/sys/tty.h _____________________________________________________________________________________________________________ Commit: eab97e63f4dfa24a251bf23165059a2aa7f0ccf1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=eab97e63f4dfa24a251bf23165059a2aa7f0ccf1 Author: Abdelkader Boudih (Fri 7 Aug 2026 23:57:07 BST) Committer: Konstantin Belousov (Sun 16 Aug 2026 03:41:16 BST) kqueue: avoid closing a file under the knlist lock (cherry picked from commit 4c4bad4421fb1a300178767f71215cc5f5e0bfb6) M sys/kern/kern_event.c _____________________________________________________________________________________________________________ Commit: 9de55e815b062d84caeb277e756f51da106646e8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9de55e815b062d84caeb277e756f51da106646e8 Author: Chris Longros (Fri 14 Aug 2026 16:45:18 BST) Committer: Ed Maste (Fri 14 Aug 2026 16:46:18 BST) Bump __FreeBSD_version to 1501502 Bump the version after the amd64 FRED KBI change was merged to stable/15. Fixes: 5e1fdbdf938b ("amd64: FRED support") Reviewed by: emaste Differential Revision: https://reviews.freebsd.org/D58743 M sys/sys/param.h _____________________________________________________________________________________________________________ Commit: 930edc25568a09845e070a2d18c6df9cec0867c7 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=930edc25568a09845e070a2d18c6df9cec0867c7 Author: Eric van Gyzen (Sat 4 Oct 2025 13:23:41 BST) Committer: Eric van Gyzen (Fri 14 Aug 2026 14:18:10 BST) if_vmx: fix panic during kldload Just like vmxnet3_intr_disable_all, iflib may invoke this routine before vmxnet3_attach_post() has run, which is before the top-level shared data area is initialized and the device made aware of it. PR: 294312 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=294312 ) Sponsored by: Dell Inc. (cherry picked from commit 01b0690c495e1043a72cae9ee945f9f2c2adc216) M sys/dev/vmware/vmxnet3/if_vmx.c _____________________________________________________________________________________________________________ Commit: 88c5af6390f066340a468675ccc1de7bc2040ed3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=88c5af6390f066340a468675ccc1de7bc2040ed3 Author: Richard Yao (Sat 8 Aug 2026 00:34:36 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) nvpair: i_get_value_size() string array handling tweak The strnlen() function needs to be given the length of the remaining region to behave as intended, but it was given the length of the total region on packed strings. Reported-by: Grok 4.5 Build Beta Reviewed-by: Brian Behlendorf Reviewed-by: Alek Pinchuk Signed-off-by: Richard Yao Closes #18877 M module/nvpair/nvpair.c _____________________________________________________________________________________________________________ Commit: ec565e143c7c4b57c025c9f8fec972ae0de4b21a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ec565e143c7c4b57c025c9f8fec972ae0de4b21a Author: Richard Yao (Sat 8 Aug 2026 00:20:23 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) nvpair: Improve native handling of unterminated strings This continues the work done in 59dc88602e23a436440e4164c6d9401da8f0dff2 and parallels what is already done for XDR encoding. Reported-by: Grok 4.5 Build Beta Reviewed-by: Brian Behlendorf Reviewed-by: Alek Pinchuk Signed-off-by: Richard Yao Closes #18876 M module/nvpair/nvpair.c _____________________________________________________________________________________________________________ Commit: 9926f72b8f5eeb732639b483706fe39204ad4b4c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9926f72b8f5eeb732639b483706fe39204ad4b4c Author: Richard Yao (Fri 7 Aug 2026 21:36:48 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) CodeQL: Flag implicit compare-then-assign in branch conditions Implicit compare-then-assign in branch conditions is buggy since developers often mean assign-then-compare, but sometimes actually mean compare-then-assign. GCC's -Wparentheses was originally meant to catch assignment in place of comparison, requiring an extra set of parentheses to turn this off. This had the happy coincidence of making developers explicit about assign-then-compare vs compare-then-assign. An outer level of extra parentheses will inhibit -Wparentheses warnings. This often results in assign-then-compare being made explicit, but instead of turning `if (x = foo() < 0)` into `if ((x = foo()) < 0)`, a developer might write `if ((x = foo() < 0))`, which turns off the warning, without fixing the problem. This happened in openzfs/zfs#18874. There are other potential variations, such as `if ((x = (foo()) < 0))`, which also suppresses GCC's warning, but fails to actually do anything since the intended explicit parentheses to specify compare-then-assign are around the right operand of the boolean operator, rather than around the boolean operator, yet we have the additional parentheses needed to silence GCC's -Wparentheses. In the `if ((x = (foo()) < 0))` case, the intent was to make compare-then-assign explicit, and a typo caused it to fail to become explicit. That is not a bug, but it makes it unclear what the developer intended, which is problematic in itself. This probably merits a bug report to GCC requesting a more intelligent diagnostic that will treat compare-then-assign differently from assignment in a branch condition. However, that is a slow process, this has already bitten us once and with CodeQL, we can add our own check to the PR process so that we catch other instances of this issue during review, rather than some time later. Given that assign-then-compare in branch conditions requires that parentheses be added in such a way that the compiler AST no longer contains an implicit compare-then-assign, we only need to check for an implicit compare-then-assign in order to implement this check. Although the likelihood of compound assignment being present in this bug pattern is low, the same logic follows, so the check also will catch this pattern on compound assignment. This check handles conditions in if, while, do, for, ?:, && and ||. switch statements are intentionally ignored, since using assign-then-compare in a switch statement would turn the switch statement into a if-else. That is pointless, so allowing an implicit compare-then-assign in switch statements is problem-free. Coincidentally, GCC's -Wparentheses does not apply to switch statements either. Finally, this considers all comparison operators, rather than just the < operator used in the examples in this commit message. The CodeQL check was written by Grok 4.5 Build Beta after several iterations of prompt engineering and follow-up prompts to give it corrections. It has also been subjected to a test suite of 19 true positives and 17 true negatives to verify its behavior. It successfully detected all true positives and fails to detect any true negatives. It has also been applied not only to the OpenZFS codebase, but also the Linux kernel and curl codebases, where it had zero detections. Related queries in CodeQL were also run against the test suite, but had zero detections. The query appears to be a well made query that has a very high signal-to-noise ratio. It might be worth submitting to upstream CodeQL for inclusion, but I would rather add it to our own repository so we can begin benefiting from it today. Assisted-by: Grok 4.5 Build Beta Reviewed-by: Brian Behlendorf Signed-off-by: Richard Yao Closes #18899 M .github/codeql-cpp.yml A .github/codeql/custom-queries/cpp/AssignmentOfComparisonAsCondition.ql _____________________________________________________________________________________________________________ Commit: bda84a4fb68df584616c8c70a5d525a5527094be URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bda84a4fb68df584616c8c70a5d525a5527094be Author: Rob Norris (Fri 24 Jul 2026 01:58:03 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) Linux 5.19/6.17: handle differences in how to flush delay workqueue Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18847 A config/kernel-workqueue.m4 M config/kernel.m4 M include/os/linux/Makefile.am A include/os/linux/kernel/linux/workqueue_compat.h _____________________________________________________________________________________________________________ Commit: c4e020c1563a5deee76582db01a923149838c345 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c4e020c1563a5deee76582db01a923149838c345 Author: Rob Norris (Fri 10 Jul 2026 04:48:58 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) Linux 6.3: follow_down() gains flags arg We need the flags arg to trigger the snapshot mount. For earlier kernels, we can emulate it with vfs_path_lookup() Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18847 D config/kernel-follow-down-one.m4 A config/kernel-follow-down.m4 M config/kernel.m4 M include/os/linux/kernel/linux/vfs_compat.h _____________________________________________________________________________________________________________ Commit: 81afa83d0bcb3a7c5b84eefef020e7ce7768aab9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=81afa83d0bcb3a7c5b84eefef020e7ce7768aab9 Author: Rob Norris (Tue 14 Apr 2026 08:10:23 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) Linux 6.18 compat: vfs_parse_fs_string() takes 3 args Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18847 M config/kernel-fs-context.m4 M config/kernel.m4 M include/os/linux/kernel/linux/vfs_compat.h _____________________________________________________________________________________________________________ Commit: 02861fdeb76e4221b428d4cbc6680bc8380d3061 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=02861fdeb76e4221b428d4cbc6680bc8380d3061 Author: Richard Yao (Wed 5 Aug 2026 00:44:46 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) nvpair: Fix operator precedence 59dc88602e23a436440e4164c6d9401da8f0dff2 made a mistake when doing a check, which can cause us to continue processing when we should return EFAULT. Reported-by: Grok 4.5 Build Beta Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: Richard Yao Closes #18874 M module/nvpair/nvpair.c _____________________________________________________________________________________________________________ Commit: dffd011d96d42c4e8db4b33d8d5b1f9037a3ba55 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=dffd011d96d42c4e8db4b33d8d5b1f9037a3ba55 Author: mkhllr <75820586+mkhllr@users.noreply.github.com> (Wed 5 Aug 2026 00:39:11 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) ZTS: don't read a command's exit status as a missing binary log_neg_expect() treats an exit status of 127 as a missing binary and fails before it looks at what the command printed. That is only a convention of the shell, and a command is free to return 127 for its own reasons. fio returns the number of jobs which failed, so a run of 127 failing jobs is reported as though fio were not installed. no_space/enospc_rm fills a pool with 200 fio jobs and requires them to fail with ENOSPC. How many of them get that far varies with timing, and on the occasions it comes to exactly 127 the test fails with fio ... unexpectedly exited 127 (File not found) even though the output holds the expected message. A dozen runs here landed between 183 and 199, and the failure seen in CI reported 127. Only read 127 as a missing binary when the expected output is absent. A command which printed what was asked of it plainly ran, so nothing which passed before can start failing. Reviewed-by: Brian Behlendorf Signed-off-by: Michael Heller Closes #18726 Closes #18882 M tests/test-runner/include/logapi.shlib _____________________________________________________________________________________________________________ Commit: 96eafcf17e2e551e0ddf955add746f77cfa1a067 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=96eafcf17e2e551e0ddf955add746f77cfa1a067 Author: crass (Tue 4 Aug 2026 22:41:54 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) build: Fix release detection when build dir is not source dir When building outside of the root source directory, configure fails to detect that the source for the build is a git repository because the build directory is checked if it is a git repository. Instead check source directory and use the source directory for generating the release. Check for the .nogitrelease file in the source directory too. Reviewed-by: Brian Behlendorf Signed-off-by: Glenn Washburn Closes #18891 M config/zfs-meta.m4 _____________________________________________________________________________________________________________ Commit: 3e8965e780d8de9beab929e1444f01b1489ba339 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3e8965e780d8de9beab929e1444f01b1489ba339 Author: Michael Heller (Mon 3 Aug 2026 08:07:30 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) CI: don't fail a passing job when a log reader has already exited Once a VM's tests finish the runner kills that VM's log reader. If the reader is already gone, kill reports ESRCH, and since the script runs under set -eu that ends it and the job is reported failed after the tests have already passed. That is what turned the fedora44 run in https://github.com/openzfs/zfs/actions/runs/30772421272 red: vm1: Results Summary vm1: PASS 1151 vm1: FAIL 2 vm1: SKIP 6 ... qemu-6-tests.sh: line 143: kill: (20700) - No such process ##[error]Process completed with exit code 1. All 13 failures in that run were on the expected list and neither VM reported an unexpected one, so no test result was affected. Only the exit status was wrong. The preceding commit removes the race that killed the reader, so this should no longer be reachable, but a reader can still die for reasons this script does not control and losing a whole run to the cleanup step is a poor trade. The message is left on stderr rather than discarded, because a reader exiting early means live output was lost and that is worth seeing. Reviewed-by: Brian Behlendorf Signed-off-by: Michael Heller Closes #18885 M .github/workflows/scripts/qemu-6-tests.sh _____________________________________________________________________________________________________________ Commit: 9a84f3b5dd54ceafe1f15011ecd324d7654e12ec URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9a84f3b5dd54ceafe1f15011ecd324d7654e12ec Author: Michael Heller (Mon 3 Aug 2026 08:05:01 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) CI: publish the per-VM test counter atomically Each VM's log reader keeps a running test count in /tmp/ctr-vm$ID and reads every other VM's counter to print the combined progress figure. The counter is published with a plain redirect, which truncates the file before it writes, so a reader can see it empty. `read` then returns 1, and because the reader inherits set -eu that ends the reader subshell. The VM keeps running and its results are recovered later from the artifact, but its output stops being prefixed into the live log from that point on, with nothing said about why. Seen on fedora44 in https://github.com/openzfs/zfs/actions/runs/30772421272. vm2's last prefixed line is refreserv/cleanup at 01:57, carrying counter 745, while vm1 keeps reporting vm2 frozen at 746 for the remaining 38 minutes: the reader incremented the counter and died before printing that line. vm2 itself ran on until 02:14 and its 899/11/6 summary never reached the live log. Publish through a temporary file and rename instead. A reader then sees either the old value or the new one. Racing a writer against a reader 20000 times reproduces 10805 failed reads with the redirect and none with the rename. Reviewed-by: Brian Behlendorf Signed-off-by: Michael Heller Closes #18885 M .github/workflows/scripts/qemu-6-tests.sh _____________________________________________________________________________________________________________ Commit: 67d36b8075a18b5177c4968ac8b68dcefa7c67c5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=67d36b8075a18b5177c4968ac8b68dcefa7c67c5 Author: George Melikov (Tue 4 Aug 2026 21:34:40 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) man: zvol_request_sync is not ignored under blk-mq The zfs.4 entry for zvol_request_sync claims it "is ignored when running on a kernel that supports block multiqueue (blk-mq)". This has never been true. The sentence and the blk-mq support it describes landed in the same commit (6f73d0216 "zvol: Support blk-mq for better performance"), which added if (zvol_request_sync) force_sync = 1; to zvol_request_impl() -- the function shared by both submission paths, reached from zvol_submit_bio() and from zvol_mq_queue_rq() alike. No blk-mq guard was added there then, and none exists now. Taken literally the sentence is worse than inaccurate: HAVE_BLK_MQ was removed in 9601eeea1 because every supported kernel has blk-mq, so the documented condition is always satisfied and the parameter would never do anything. Verified on 6.12.101 by counting call sites with kprobes during an fio run. zvol_write() is reached either via the taskq, through zvol_write_task(), or directly, so the two are a clean discriminator: config zvol_write zvol_write_task zvol_tq CPU bio, default 1477413 1477413 7902 jiffies bio, sync=1 3873491 0 0 blk-mq, default 2787187 2787187 7948 jiffies blk-mq, sync=1 3816106 0 0 With zvol_request_sync=1 no task is ever dispatched and the zvol taskq threads get no CPU, on either path. Replace the sentence with an accurate one. Reviewed-by: Brian Behlendorf Signed-off-by: George Melikov Closes #18887 M man/man4/zfs.4 _____________________________________________________________________________________________________________ Commit: 8be87df6156256f590251c17ef0fde78edc6b64e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8be87df6156256f590251c17ef0fde78edc6b64e Author: mkhllr <75820586+mkhllr@users.noreply.github.com> (Tue 4 Aug 2026 21:25:41 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) libzfs: don't read a dataset handle after closing it in resume send zfs_send_resume_impl_cb_impl() closes the dataset handle before its error switch and then reads zhp->zfs_name again in the ESRCH case. zfs_name is an array declared inside struct zfs_handle, so the free() at the end of zfs_close() releases it along with the handle, and lzc_exists() copies out of the freed block. The close dates from the original resume send. The ESRCH case was added three years later with redacted send, below a handle that was no longer live. The path is reachable: dsl_bookmark_lookup() returns ESRCH when the incremental source is a bookmark that has gone away, which a resume can lose a race with. Keep a copy of the name alongside the error message that is already formatted before the close, and test that instead. Reported-by: RigelYoung <43904538+RigelYoung@users.noreply.github.com> Reviewed-by: Rob Norris Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: Michael Heller Closes #18870 Closes #18883 M lib/libzfs/libzfs_sendrecv.c _____________________________________________________________________________________________________________ Commit: 62a341175fdb2303b3373de224ea9eba05ffe0d8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=62a341175fdb2303b3373de224ea9eba05ffe0d8 Author: Michael Heller (Thu 30 Jul 2026 02:44:59 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) ZTS: add coverage for the MMP claim on a degraded mirror Add mmp_degraded_import, which verifies the uberblock claim requires a write only to those mirror legs the pool configuration still expects to be present. A healthy mirror is claimed, a mirror with an offlined leg is claimed and imports degraded, and a mirror with a leg this host cannot open, and which the configuration does not mark absent, is refused. The degraded and unreachable cases repeat on a three-way mirror, where the number of legs the configuration expects and the number this host can reach come apart. Reviewed-by: Brian Behlendorf Signed-off-by: Michael Heller Closes #18855 M tests/runfiles/linux.run M tests/zfs-tests/tests/Makefile.am A tests/zfs-tests/tests/functional/mmp/mmp_degraded_import.ksh _____________________________________________________________________________________________________________ Commit: 9683c86c42d37af79fbb4617bf863628ff35ff9a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9683c86c42d37af79fbb4617bf863628ff35ff9a Author: Michael Heller (Thu 30 Jul 2026 02:44:59 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) mmp: do not require writes to mirror legs the config marks absent The MMP uberblock claim requires one good write per configured leaf of each top-level vdev. For a mirror it required two writes unconditionally (MIN(MAX(children, 1), 2)), so a mirror with a leg that is persistently offline, faulted, or removed could produce only one good write and the activity-check claim failed with EIO. A degraded mirror could therefore not be imported with multihost=on, blocking HA failover. Count only the legs the pool config still expects to be present, and require a write to every one of them. A leg taken out of service is recorded persistently in the config and is seen the same way by every host, so it is not required. A leg merely unreachable from the importing host keeps none of those states and stays required, so a host that can see only some of the legs of an otherwise healthy mirror still fails the claim and cannot split the pool. The previous cap of two writes was a compromise made because requiring every child was too strict for wide mirrors, in particular where a leg is left offline for long periods as part of a backup strategy. Consulting the config covers that case directly, so the cap is no longer needed: on a three-way mirror with one leg unreachable and not marked absent, a cap of two would accept the claim while another host holding the third leg could accept it as well. Reviewed-by: Brian Behlendorf Signed-off-by: Michael Heller Closes #18855 M module/zfs/mmp.c _____________________________________________________________________________________________________________ Commit: 22336114452d7a8809b1ef0e19dc96fa78955ce9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=22336114452d7a8809b1ef0e19dc96fa78955ce9 Author: Richard Yao (Mon 3 Aug 2026 16:20:34 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) libzfs: String trimming should not operate out of bounds Forward slashes are trimmed from ZPOOL_IMPORT_PATH, but if someone sets a ZPOOL_IMPORT_PATH that is only forward slashes, our trim code will underflow the string, causing an out of bounds operation. Similarly, the SMB code could potentially trim a string consisting of only new line characters until it experiences the same bug. The same fix is applied to it. These are memory bugs, but I suspect that it is very unlikely that they would cause a problem, since the probability that an out of bounds write would follow the out of bounds read should be low. That said, going out of bounds is undefined behavior, which could cause incorrect code generation should a compiler look at it wrong, so let us fix this. Reported-by: Grok 4.5 Build Beta Signed-off-by: Richard Yao Reviewed-by: Rob Norris Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Closes #18868 M lib/libshare/os/linux/smb.c M lib/libzutil/zutil_device_path.c _____________________________________________________________________________________________________________ Commit: bcf2999dbd197aafd387679c5f80736ea818c0f3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bcf2999dbd197aafd387679c5f80736ea818c0f3 Author: mkhllr <75820586+mkhllr@users.noreply.github.com> (Fri 31 Jul 2026 21:06:11 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) libzfs: don't truncate a resolved vdev path in zpool_vdev_name() zpool_vdev_name() copied the result of realpath() into a 64 byte stack buffer shared with the short formatted names, so a vdev whose resolved path was longer than 63 bytes was reported cut short by zpool status -L and anything else asking for VDEV_NAME_FOLLOW_LINKS. The cut is made at a byte boundary, so a multi-byte character straddling it is left as invalid UTF-8, which also makes zpool status -j -L emit JSON a parser rejects. Resolve straight into a buffer of the right size. realpath() fills a caller supplied buffer of at least PATH_MAX, as it is used elsewhere in libzutil, which also removes the intermediate allocation. The other three users of that buffer format a guid, a raidz name, or a draid name, and none of them can exceed its length. Reviewed-by: Brian Behlendorf Signed-off-by: Michael Heller Closes #18851 Closes #18871 M lib/libzfs/libzfs_pool.c M tests/runfiles/common.run M tests/zfs-tests/tests/Makefile.am A tests/zfs-tests/tests/functional/cli_root/zpool_status/zpool_status_009_pos.ksh _____________________________________________________________________________________________________________ Commit: 17834383e58453d0e334a4068a8f830cbaadb251 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=17834383e58453d0e334a4068a8f830cbaadb251 Author: Richard Yao (Fri 31 Jul 2026 21:04:57 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) libzfs: Do not call munmap() when mmap() fails Reported-by: Grok 4.5 Build Beta Reviewed-by: Igor Kozhukhov Reviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Richard Yao Closes #18869 M lib/libzfs/libzfs_pool.c _____________________________________________________________________________________________________________ Commit: 49086325ba7f9651ec540ea446dc1e64c280786a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=49086325ba7f9651ec540ea446dc1e64c280786a Author: Richard Yao (Fri 31 Jul 2026 21:03:38 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) Add missing checks to zfs_clone_range_replay() zfs_clone_range() does a few error checks that we are missing in zfs_clone_range_replay(). Reported-by: Grok 4.5 Build Beta Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Richard Yao Closes #18867 M module/zfs/zfs_vnops.c _____________________________________________________________________________________________________________ Commit: 51421b0efbc818d366a7ef627883250ffd639c07 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=51421b0efbc818d366a7ef627883250ffd639c07 Author: Richard Yao (Fri 31 Jul 2026 21:02:41 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) Fix DMU bonus hold leak on I/O error brt_vdev_load() will leak the DMU bonus hold on an error from dmu_read() because the corresponding dmu_buf_rele() is not called in the error path. Reported-by: Grok 4.5 Build Beta Reviewed-by: Igor Kozhukhov Reviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Richard Yao Closes #18865 M module/zfs/brt.c _____________________________________________________________________________________________________________ Commit: b00191f3fa1c24e787717b76e6567b1eb22b3e10 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b00191f3fa1c24e787717b76e6567b1eb22b3e10 Author: wangzhaolong89 (Tue 28 Jul 2026 23:28:09 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) zfs: fix stale POSIX ACL cache after rollback An online zfs rollback rezgets live znodes and clears the OpenZFS ACL cache, but leaves the Linux VFS inode POSIX ACL cache intact. A later non-root permission check can use an ACL added after the snapshot. Reproduce by snapshotting a POSIX ACL file whose group mode bits require a VFS ACL check, granting a named user read access, holding the inode active, and rolling the mounted filesystem back. The named user remains able to read until cache eviction. Invalidate both the access and default VFS POSIX ACL caches from zfs_rezget(), alongside the existing private cache invalidation, so subsequent permission checks reload the recovered on-disk ACL. Reviewed-by: Brian Behlendorf Signed-off-by: Wang Zhaolong Closes #18837 M module/os/linux/zfs/zfs_znode_os.c M tests/runfiles/linux.run M tests/zfs-tests/tests/Makefile.am M tests/zfs-tests/tests/functional/acl/acl_common.kshlib M tests/zfs-tests/tests/functional/acl/posix/posix_004_pos.ksh A tests/zfs-tests/tests/functional/acl/posix/posix_005_pos.ksh _____________________________________________________________________________________________________________ Commit: a052ffc647e200ac5068828ce72dec067908978b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a052ffc647e200ac5068828ce72dec067908978b Author: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> (Mon 27 Jul 2026 23:15:49 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) zed: let autoexpand see capacity changes on partitioned disks Growing a disk under a whole-disk vdev never triggers autoexpand (#12505). The kernel reports a capacity change on the disk itself and nothing for the partitions, whose sizes did not change. But since zfs owns the whole disk it carries a partition table, and zed_udev_monitor() drops any disk-with-partitions event on the assumption that a partition event will follow. For a resize none ever does, so the ESC_DEV_DLE event that zfsdle_vdev_online() needs is never generated and the pool stays at the old size until someone runs zpool online -e by hand. This is the common case for cloud disks grown online. Pass change events through when udev marks them RESIZE=1. On the matching side a disk-level event has no vdev guid to search by (the label lives on the partition), and udev provides no ID_PATH on some buses, so the physical path lookup can also come up empty. When that happens, read the ZFS label off the whole-disk partition and match by the pool and vdev guids stored in it. Unlike matching the config path textually, this works no matter which name the pool was imported with (by-id, by-path or a bare device node), and a stale device path in an unrelated pool's config cannot steal the event, since the label names the owning pool. The fallback only runs for guid-less disk events and only accepts a whole-disk vdev that is not a spare or l2cache device. The new zpool_expand_006_pos test covers this end to end on a scsi_debug disk. zpool_expand_001_pos already grows a scsi_debug disk the same way but keeps passing on an unpatched zed, because block_device_wait issues a bare udevadm trigger, which re-sends change events for the zfs_member partitions and hands zed the vdev guid the resize itself never delivered. The new test drains the pool-creation udev traffic and then only settles, so zed sees what a production resize generates: one RESIZE=1 change event on the disk. Multipath maps take a different path through zed_udev_monitor() and still need the manual online; that is unchanged here, and the same goes for other device-mapper vdevs, whose partitions live on separate dm nodes the fallback cannot derive from the map's name. Disks with no devid source at all (virtio-blk, Xen) also stay out of scope: their events are dropped earlier for lack of any device identifier, and widening that is its own discussion. Tests: zpool_expand_006_pos fails against unpatched zed and passes with the fix; a pool imported by /dev/disk/by-id expands from the bare disk event with "matched vdev ... by the label" in the zed log; the zpool_expand group passes. Reviewed-by: Brian Behlendorf Signed-off-by: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> Closes #12505 Closes #18833 M cmd/zed/agents/zfs_mod.c M cmd/zed/zed_disk_event.c M tests/runfiles/linux.run M tests/zfs-tests/tests/Makefile.am A tests/zfs-tests/tests/functional/cli_root/zpool_expand/zpool_expand_006_pos.ksh _____________________________________________________________________________________________________________ Commit: cc010bbc34915310c6f31ca001a66f16b2ca3265 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cc010bbc34915310c6f31ca001a66f16b2ca3265 Author: HeonJe Lee (Mon 27 Jul 2026 23:00:39 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) zpool export: return EBUSY when zvol minors are in use When a zvol block device is open (e.g., mounted by the OS), exporting the pool can hang indefinitely in zvol_remove_minors_impl() which calls cv_wait(&zv->zv_removing_cv) with no timeout. This is because the open holder never closes the device, so the condition variable is never signaled. Fix this by taking an additional spa reference in zvol_first_open() and releasing it in zvol_last_close(). With this reference, spa_export_common() will return EBUSY via the existing spa_refcount_zero() check, matching the behavior already provided for mounted ZFS datasets. Additionally, move the zvol_remove_minors() call in spa_export_common() to after the spa_refcount_zero() check. Previously it was called before the check, which could still hang if a zvol was open. Reviewed-by: Brian Behlendorf Signed-off-by: Heonje LEE Closes #18841 M module/zfs/spa.c M module/zfs/zvol.c M tests/runfiles/common.run M tests/zfs-tests/tests/Makefile.am A tests/zfs-tests/tests/functional/cli_root/zpool_export/zpool_export_005_neg.ksh _____________________________________________________________________________________________________________ Commit: 8ff555ea8a4a319c2632e589172dda761d5f66a9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8ff555ea8a4a319c2632e589172dda761d5f66a9 Author: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> (Mon 20 Jul 2026 16:09:39 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) ZTS: make file_check actually compare the resume test results file_check guards every comparison with a check that the snapshot directory exists on both sides, and the resume tests receive with -u, so the receive side is never mounted and the .zfs snapshot paths never exist. The function has been quietly comparing nothing in rsend_019-022, rsend_024, rsend_030 and send-c_resume, so the resume test family verified that receives succeed but not that the received data matches. Mount both sides before diffing (some tests also unmount the send side), still compare only the snapshots both sides carry since several tests send just one of them, and fail loudly when nothing at all was compared so the check cannot rot back into a no-op. Two callers needed their expectations fixed once the checks came alive: rsend_024 streams from the head rather than a snapshot, so it now diffs the mounted heads directly, and the first file_check in send_partial_dataset pointed at a partial dataset with no snapshots, so it now compares against the dataset the stream came from. Tests: rsend group passes with the comparisons active, twice in a row on one module load. Reviewed-by: Brian Behlendorf Signed-off-by: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> Closes #18834 M tests/zfs-tests/tests/functional/rsend/rsend.kshlib M tests/zfs-tests/tests/functional/rsend/rsend_024_pos.ksh M tests/zfs-tests/tests/functional/rsend/send_partial_dataset.ksh _____________________________________________________________________________________________________________ Commit: 51423455a75298d243aa37b550627f3e31b37c2e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=51423455a75298d243aa37b550627f3e31b37c2e Author: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> (Mon 20 Jul 2026 16:09:39 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) ZTS: save ZAP_MICRO_MAX_SIZE before the large microzap tests change it send_large_microzap_incremental and send_large_microzap_transitive set zap_micro_max_size to 1M and call restore_tunable in cleanup, but restore_tunable is a silent no-op unless save_tunable stored the old value first, which neither test ever did. The tunable therefore stays at 1M until the module is reloaded, and any later run of the rsend group on the same module fails seven tests (rsend_019-022, rsend_024, rsend_030 and send-c_resume): their setup creates directories large enough to become large microzaps, and plain zfs send then refuses the stream without -L. CI never reruns a group on a loaded module, so this only bites people iterating locally. Tests: rsend group run twice back to back on one module load; before the change the second run fails the seven tests above, after it both runs pass. Reviewed-by: Brian Behlendorf Signed-off-by: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> Closes #18834 M tests/zfs-tests/tests/functional/rsend/send_large_microzap_incremental.ksh M tests/zfs-tests/tests/functional/rsend/send_large_microzap_transitive.ksh _____________________________________________________________________________________________________________ Commit: 5f9bea1147865bf5620a959137526dd6989fcb99 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5f9bea1147865bf5620a959137526dd6989fcb99 Author: Igor Ostapenko (Fri 24 Jul 2026 21:01:58 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) dmu_recv: Avoid potential null deref Compilers are smart enough to deref only if the first && operand is true, so this is mostly to avoid false positives from sanitizers. Sponsored-by: Klara, Inc. Sponsored-by: Wasabi Technology, Inc. Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Igor Ostapenko Closes #18848 M module/zfs/dmu_recv.c _____________________________________________________________________________________________________________ Commit: fee6805042b38397fa6eff3bb61f706f816ad79e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fee6805042b38397fa6eff3bb61f706f816ad79e Author: Alexander Motin (Fri 24 Jul 2026 21:01:02 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) DDT: Fix several bugs in pruning - Fix variables types to avoid overflows after 2B entries. - Make ddt_prune_walk() code some more symmetrical. - Fix zero oldest on exact target to histogram value match. - Make bin 0 properly start from 0, not 1 hour. - Take as a cutoff base a time of histogram build start. Reviewed-by: Brian Behlendorf Signed-off-by: Alexander Motin Closes #18838 M module/zfs/ddt.c _____________________________________________________________________________________________________________ Commit: af55dd36c59118bbcec09e0314242f93a9e05927 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=af55dd36c59118bbcec09e0314242f93a9e05927 Author: Garth Snyder (Fri 24 Jul 2026 17:44:13 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) cstyle: better tolerance for struct literals `cstyle.pl` currently doesn't have much patience for code such as: ``` *myvar = (mystruct_t) { .ms_field = 42, .ms_other_field = "chow time" }; ``` The first line is a Catch-22. If there's a space before the curly brace, then it's an illegal cast because of the trailing space. If there isn't a space, then it's an illegal curly brace without a preceding space. Either way, tagging the first line as `/* CSTYLED */` gets you nowhere because `cstyle.pl` doesn't understand the structure. It sees the fields as continuation lines and complains about the indentation. This PR makes three changes: - It allows the first line with a space between the type and the brace. - It adds first lines of this type to the same category as structs, enums, and unions. Indentation is tracked, but no particular style of indentation is enforced. - It modifies a few clauses in `lib/libefi/rdwr_efi.c` that used to squeak through `cstyle.pl` but are now (correctly?) detected. These are of the form `(int) sizeof (type_t)`. I've changed these to `(int)(sizeof (type_t))`. Easy to reverse if the original form is in fact preferred. Reviewed-by: Brian Behlendorf Signed-off-by: Garth Snyder Closes: #18839 M lib/libefi/rdwr_efi.c M scripts/cstyle.pl _____________________________________________________________________________________________________________ Commit: 292c190b897fad96c07e99259d90fe81f0753774 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=292c190b897fad96c07e99259d90fe81f0753774 Author: Ryan Moeller (Fri 17 Jul 2026 23:00:38 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) libspl: Implement VERIFY_IMPLY and VERIFY_EQUIV The libspl debug header is missing VERIFY_IMPLY and VERIFY_EQUIV macros and instead directly implements IMPLY and EQUIV. Break out the VERIFY definitions to match the kernel macros and facilitate code sharing between kernel and userland. Sponsored-by: Cybersecure Pty Ltd Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Ryan Moeller Closes #18822 M lib/libspl/include/assert.h _____________________________________________________________________________________________________________ Commit: 9623afdb9f35bf7b5c537884affccde844403e73 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9623afdb9f35bf7b5c537884affccde844403e73 Author: mkhllr <75820586+mkhllr@users.noreply.github.com> (Wed 22 Jul 2026 22:45:26 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) mmp: skip non-writeable vdevs during activity check The import-time MMP activity check added by c710f8792 writes an uberblock to each top-level vdev and requires a matching number of good writes before the pool is claimed. Two vdev types that carry no writeable device break this: - A hole vdev (left by removing a log) and an indirect vdev (left by removing a data device) are counted in the required-write total but can never be written, so good_writes never reaches req_writes. The activity check then spuriously fails and the pool is reported as held by another host with hostid 0. - mmp_claim_uberblock() also issues a zio_flush() to the root vdev after the writes. zio_flush() recurses to every leaf, and an indirect vdev is a childless top-level vdev, so it is issued a ZIO_TYPE_FLUSH. That trips the ZIO_TYPE_WRITE assertion in vdev_indirect_io_start() and panics. Skip hole and indirect vdevs when counting required writes, and skip non-concrete vdevs in zio_flush() as they have no device to flush. Add hole, indirect, log, cache, and spare vdevs to the pool used by the mmp_inactive_import, mmp_exported_import, and mmp_concurrent_import tests so the activity check exercises these vdev types. The enriched layout is opt-in, leaving multihost_history on the simple two-device pool it relies on. Reviewed-by: Brian Behlendorf Signed-off-by: Michael Heller Closes #18823 Closes #18835 M module/zfs/mmp.c M module/zfs/zio.c M tests/zfs-tests/tests/functional/mmp/mmp.kshlib M tests/zfs-tests/tests/functional/mmp/mmp_concurrent_import.ksh M tests/zfs-tests/tests/functional/mmp/mmp_exported_import.ksh M tests/zfs-tests/tests/functional/mmp/mmp_inactive_import.ksh _____________________________________________________________________________________________________________ Commit: 5e2957f7bae2ce8b780cb4b5abb0d874cb89bac1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5e2957f7bae2ce8b780cb4b5abb0d874cb89bac1 Author: Toomas Soome (Wed 22 Jul 2026 17:47:03 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) zdb: output refcounts from verify_spacemap_refcounts() Output information about refcounts when there is refcount mismatch. Use plain uint64_t even as the values are expected to not be large. Also use unsigned as we should never get negative refcounts there. Reviewed-by: Allan Jude Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Toomas Soome Closes #18809 M cmd/zdb/zdb.c _____________________________________________________________________________________________________________ Commit: 36a398de222704a7581c3781ec70570d9cc77bab URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=36a398de222704a7581c3781ec70570d9cc77bab Author: Nick Price (Tue 21 Jul 2026 19:23:27 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) L2ARC: bound the rebuild by the write hand on a first sweep l2arc_log_blkptr_valid() ends with (!evicted || dev->l2ad_first), which disables the eviction-overlap test entirely on a first sweep. That test is meaningless in that state, since l2arc_evict() returns immediately and l2ad_evict never advances off l2ad_start, but dropping it leaves the log block bounded only by device geometry. On a first sweep only the region below the write hand has been written, so a block at or beyond l2ad_hand describes data this incarnation never wrote. l2arc_hdr_restore() performs no per-entry validation, so every such entry inflates arcstat_l2_psize and, via vdev_space_update(), the cache vdev's vs_alloc. Nothing reconciles it because l2arc_evict() never runs on a first sweep, and once vs_alloc exceeds vs_space the unclamped subtraction in zpool(8) wraps and the device reports 16.0E free. Stale entries also let the L2ARC read offsets that were never written, which then fail checksum verification. Removing and re-adding a cache vdev is enough to set this up: l2arc_add_vdev() resets l2ad_hand to l2ad_start while the previous incarnation's log blocks remain higher up the device, and the backward walk then crosses l2ad_start and wraps into them. Bound the first-sweep case by the write hand instead of disabling the check, and state the geometry conditions once rather than duplicating them across both branches. The 16.0E symptom has been reported since 2015. #10224 carries the only prior analysis, which suspected a leak in l2arc_evict() and was closed incidentally by #9789 rather than by a fix. It is also open on FreeBSD as PR 250323. External-issue: https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=250323 Reviewed-by: Ameer Hamza Reviewed-by: Alexander Motin Signed-off-by: Nick Price Closes #3114 Closes #3400 Closes #5583 Closes #10224 Closes #12779 Closes #18827 M module/zfs/arc.c _____________________________________________________________________________________________________________ Commit: d37f629ce8fbf49d1f47dd9eec26b8fb1ca56784 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d37f629ce8fbf49d1f47dd9eec26b8fb1ca56784 Author: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> (Fri 17 Jul 2026 19:03:34 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) ZTS: make zpool_iostat_interval_all teardown deterministic zpool_iostat_interval_all runs "zpool iostat" in the background at a 0.1s interval and compares its output, parsed into a sequence of chunks, against a fixed expected sequence as pools are created, imported, exported and destroyed. Every step changes the visible pool list by exactly one pool except the teardown, which used a single "zpool export -a". export -a exports the pools one after another rather than atomically, so there is a brief window in which one pool is already gone and the other is not. At the 0.1s sampling interval iostat occasionally catches that intermediate single-pool state and emits an extra chunk that is not in the expected sequence, and the test fails. Whether a sample lands in the window depends on timing, which is why it shows up as a flake. Export the two pools explicitly, one at a time, and add the intermediate single-pool state to the expected output, the same way the imports and destroys elsewhere in the test already change one pool at a time. The teardown transition is now deterministic. Drop the test from the zts-report.py.in "maybe" list. Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> Closes #18273 Closes #18776 M tests/zfs-tests/tests/functional/cli_root/zpool_iostat/zpool_iostat_interval_all.ksh _____________________________________________________________________________________________________________ Commit: f5330ea341b02843f28ab9c221df8e82e6de46e0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f5330ea341b02843f28ab9c221df8e82e6de46e0 Author: Kili (Thu 16 Jul 2026 17:45:46 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) libzfs: fallback VDEV_UPATH to VDEV_PATH for non-DM devices When zfs_get_underlying_path() returns NULL for a non-DM device (e.g. NVMe), the zfs_prepare_disk script was getting an empty VDEV_UPATH. Per the man page, VDEV_UPATH should fall back to VDEV_PATH when there is no underlying path. Reviewed-by: Brian Behlendorf Signed-off-by: MISAPOR LAB Closes #18439 Closes #18802 M lib/libzfs/libzfs_util.c _____________________________________________________________________________________________________________ Commit: a6f557c2cb58499dc3e09f5b91b1b3e4aa9b0c4f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a6f557c2cb58499dc3e09f5b91b1b3e4aa9b0c4f Author: Alexander Motin (Wed 15 Jul 2026 19:02:32 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) Fix reads for blocks freed after being cloned PR #18421 fixed a case when reads for blocks cloned after being freed could return zeroes. But it created an opposite problem, when reads for blocks freed after being cloned could return non- zero content from the cloning. This patch fixes the problem by creating a more specialized form of dnode_block_freed(), taking into account the TXG when the cloning has happened and checking frees only in TXGs after. Reviewed-by: Brian Behlendorf Reviewed-by: Gary Guo Signed-off-by: Alexander Motin Closes #18421 Closes #18724 M include/sys/dnode.h M module/zfs/dbuf.c M module/zfs/dnode.c _____________________________________________________________________________________________________________ Commit: d6bbb80aedda2482950585a10e70cbd9d9d92482 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d6bbb80aedda2482950585a10e70cbd9d9d92482 Author: mkhllr <75820586+mkhllr@users.noreply.github.com> (Tue 14 Jul 2026 21:48:10 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) Rate limit Direct I/O verify zevents Each vdev initializes a vdev_dio_verify_rl rate limiter (governed by zfs_dio_write_verify_events_per_second), but zio_dio_chksum_verify_error_report() never consults it, so dio_verify_rd and dio_verify_wr zevents are posted with no rate limiting. A workload that repeatedly trips the Direct I/O verify can therefore produce an unbounded flood of zevents. Gate both ereport posts through zfs_ratelimit(&vd->vdev_dio_verify_rl), as is already done for the other per-vdev ereports (checksum, delay, deadman). The vs_dio_verify_errors vdev stat still increments on every event, so the true count remains observable via zpool status -d. The dio_write_verify test checks on every iteration that a dio_verify_wr zevent was posted. With rate limiting now in effect the shared limiter window is exhausted after the first iteration, so later iterations observe zero events and the test fails. Raise zfs_dio_write_verify_events_per_second for the duration of that test (restored in cleanup), adding the matching tunables.cfg alias, so the events stay observable. Reviewed-by: Brian Behlendorf Signed-off-by: Michael Heller Closes #18795 M module/zfs/zio.c M tests/zfs-tests/include/tunables.cfg M tests/zfs-tests/tests/functional/direct/dio_write_verify.ksh _____________________________________________________________________________________________________________ Commit: c778b1e394e7ff55787bc2eaf3964750e92c85c0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c778b1e394e7ff55787bc2eaf3964750e92c85c0 Author: Alexander Moch (Mon 13 Jul 2026 21:03:42 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) CI: Update Alpine Linux runner to 3.24.1 Update the Alpine Linux CI runner from 3.23.2 to 3.24.1. This refreshes the runner to the latest Alpine release while keeping the existing CI configuration unchanged. Reviewed-by: Brian Behlendorf Signed-off-by: Alexander Moch Closes #18790 M .github/workflows/scripts/qemu-2-start.sh M .github/workflows/scripts/qemu-3-deps-vm.sh M .github/workflows/zfs-qemu.yml _____________________________________________________________________________________________________________ Commit: 920b3b6bab0770fcf3113bae01606db7c8089e6b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=920b3b6bab0770fcf3113bae01606db7c8089e6b Author: Alexander Moch (Mon 13 Jul 2026 19:58:15 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) Remove libuutil from the pull request template and fix headings - libuutil was removed in adb316f41. - Normalize section headers to title case. - Drop the trailing colon on "Checklist". Reviewed-by: Brian Behlendorf Reviewed-by: George Melikov Signed-off-by: Alexander Moch Closes #18791 M .github/PULL_REQUEST_TEMPLATE.md _____________________________________________________________________________________________________________ Commit: 7d8a1e9d26f07703f4aa39407543bc4166598cd3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7d8a1e9d26f07703f4aa39407543bc4166598cd3 Author: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> (Sat 11 Jul 2026 18:38:23 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) ZTS: fix zpool_initialize_multiple_pools suspend race zpool_initialize_multiple_pools verifies that "zpool initialize -a -s" suspends initializing on all four pools. It starts initializing and, without slowing it down, expects every pool to still be initializing when the suspend runs. On fast storage a pool can finish initializing before the suspend, so "zpool initialize -a -s" reports "there is no active initialization" and the pool's status is "completed" rather than "suspended". The suspend command then fails the test intermittently. Throttle zfs_initialize_chunk_size before the suspend phase, the same way the zpool_wait_initialize_* tests do, so initializing stays active through the suspend and cancel checks. The earlier phases that wait for initializing to finish ("zpool wait" and "-w -a") are left at the default chunk size so they still complete promptly. The chunk size is saved and restored, and the pools are destroyed before it is restored so a running initialize thread never sees a larger value than the buffer it allocated at the smaller size. Reviewed-by: Brian Behlendorf Signed-off-by: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> Closes #18777 M tests/zfs-tests/tests/functional/cli_root/zpool_initialize/zpool_initialize_multiple_pools.ksh _____________________________________________________________________________________________________________ Commit: 2e590aff67e20df1f6385bb31ac4b26b3c66844f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2e590aff67e20df1f6385bb31ac4b26b3c66844f Author: tiehexue (Fri 10 Jul 2026 23:22:56 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) CI: Fix race caused by shared ctr file updates CTR is shared between the VMs and used as a global counter. This uncoordinated shared access can result in a CI failure due to the racing updates. From the log: `qemu-6-tests.sh: line 27: 1` `6: syntax error in expression (error token is "6")` Resolve the issue by using separate ctr files by appending the ID. The output now prints the total test cases count along with each VMs individual count. Reviewed-by: Tino Reichardt Reviewed-by: Brian Behlendorf Signed-off-by: tiehexue Closes #18778 M .github/workflows/scripts/qemu-6-tests.sh _____________________________________________________________________________________________________________ Commit: 7009da595dc0f66d06015a6081c1b04a250fada2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7009da595dc0f66d06015a6081c1b04a250fada2 Author: Rob Norris (Thu 2 Jul 2026 02:24:57 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) zpl_inode: remove zpl_rename no-flags variants Removed in 4.9. Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18769 M config/kernel-rename.m4 M module/os/linux/zfs/zpl_ctldir.c M module/os/linux/zfs/zpl_inode.c _____________________________________________________________________________________________________________ Commit: 990b9a3d5d13d5bd0679ecdb361f7f7d0236c3a4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=990b9a3d5d13d5bd0679ecdb361f7f7d0236c3a4 Author: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> (Fri 10 Jul 2026 21:37:21 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) ZTS: stop zpool_initialize tests racing initialize to completion zpool_initialize_import_export and zpool_initialize_suspend_resume start initializing a one-disk pool, wait a fixed couple of seconds, and then expect initializing to still be running so it can be observed across an export/import and suspended. On a small or fast vdev the default 1 MiB initialize chunk lets the whole disk finish within that window, after which "zpool initialize -s" fails with "there is no active initialization" and the test fails. Throttle initializing with zfs_initialize_chunk_size, exactly as the zpool_wait_initialize_* tests already do, so it stays active long enough to observe regardless of vdev size or speed. The tunable is saved and restored per test. Cleanup destroys the pool before restoring the chunk size: the initialize thread rereads zfs_initialize_chunk_size on every write but allocates its fill buffer once at the smaller size, so raising it back while the thread is still running would issue a write larger than that buffer. With this both tests pass reliably, so drop their entries from the zts-report.py.in maybe list (#11948, #17311). Tests: ran both tests against the reproduced race in a VM -- with the default chunk size the suspend step fails with "there is no active initialization"; with the smaller chunk size initializing is still running across the export/import and suspend, and the tunable is restored on exit. Reviewed-by: Brian Behlendorf Signed-off-by: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> Closes #11948 Closes #17311 Closes #18771 M tests/test-runner/bin/zts-report.py.in M tests/zfs-tests/tests/functional/cli_root/zpool_initialize/zpool_initialize_import_export.ksh M tests/zfs-tests/tests/functional/cli_root/zpool_initialize/zpool_initialize_suspend_resume.ksh _____________________________________________________________________________________________________________ Commit: d3cb4d1c6b906a797b1aabe93f42a3648b6f61a2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d3cb4d1c6b906a797b1aabe93f42a3648b6f61a2 Author: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> (Fri 10 Jul 2026 21:35:01 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) ZTS: migration/setup: clear stale zfs_member label before new_fs During a full ZTS run functional/migration/setup fails intermittently when it mounts the non-ZFS device. That device is often one an earlier test used as a pool vdev. 'zpool destroy' leaves the vdev labels in place and new_fs only overwrites the front of the device, so the trailing labels can survive. libblkid then probes the device as ambiguous (both the new filesystem and zfs_member) and the auto-detecting mount refuses, which setup reports as a spurious failure. Wipe any residual signatures with wipefs before laying down the new filesystem so the device carries a single, unambiguous type, and let udev settle before the mount. Skip the wipe in the single-disk case, where the non-ZFS device is the same one the test pool was just created on, so the live pool is left untouched. Verified on Linux: after a pool create and destroy the scratch device still carries a zfs_member label (blkid -p reports zfs_member); a wipefs -a removes it so the following new_fs is the only signature and the mount succeeds. The functional/migration group passes with the change. Reviewed-by: Brian Behlendorf Signed-off-by: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> Closes #18492 Closes #18753 M tests/zfs-tests/tests/functional/migration/setup.ksh _____________________________________________________________________________________________________________ Commit: 47f32602d7a21a4defbff565c00182cb355dc9f6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=47f32602d7a21a4defbff565c00182cb355dc9f6 Author: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> (Thu 9 Jul 2026 18:15:31 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) Fix receive of split large blocks with a short trailing chunk A dataset with a large recordsize can store a single-block file whose block size is not a power of two. When such a block is sent without large blocks (no -L), the sender splits it into SPA_OLD_MAXBLOCKSIZE (128K) chunks, and the final chunk is smaller than the block size. flush_write_batch_impl() already handles any WRITE record whose size differs from the object's block size by doing a normal dmu_write(), but it first asserted the record was always larger than the block size. The shorter trailing chunk violates that assertion, so receiving such a stream panicked the receive_writer thread on debug builds; production builds took the correct dmu_write() path and were unaffected. Drop the assertion and describe both size-mismatch cases in the comment; the dmu_write() path already handles a record smaller than the block size. Add an rsend test that sends such a block without -L (initial and incremental, plain and compressed) and verifies the received file matches. Reviewed-by: Brian Behlendorf Signed-off-by: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> Issue #17829 Closes #18749 M module/zfs/dmu_recv.c M tests/runfiles/common.run M tests/zfs-tests/tests/Makefile.am A tests/zfs-tests/tests/functional/rsend/send_split_large_block.ksh _____________________________________________________________________________________________________________ Commit: b4411799bdff8b1470d75bfe802ab831cb886c15 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b4411799bdff8b1470d75bfe802ab831cb886c15 Author: Richard Kojedzinszky (Thu 9 Jul 2026 16:56:32 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) Fix receive -x according to comment The old condition skipped the -x for ANY property whose source wasn't explicitly ZPROP_SOURCE_VAL_RECVD - which caught inherited/default properties too, not just locally-set ones. The new condition correctly skips only when the property is locally-set on the destination (source == fsname), which is the documented intent. Reviewed-by: Brian Behlendorf Signed-off-by: Richard Kojedzinszky Closes #18737 Closes #18738 M lib/libzfs/libzfs_sendrecv.c M tests/runfiles/common.run M tests/zfs-tests/tests/Makefile.am A tests/zfs-tests/tests/functional/cli_root/zfs_receive/zfs_receive-x_props_alternation.ksh _____________________________________________________________________________________________________________ Commit: 910ff1a4e9eb7c9322e61a2d723e347551e81004 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=910ff1a4e9eb7c9322e61a2d723e347551e81004 Author: Brian Behlendorf (Wed 8 Jul 2026 22:35:46 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) Add SECURITY.md policy file Add a basic SECURITY.md file to establish the repository's security reporting policy. Includes guidance for reporting security issues and what to expect. Reviewed-by: Allan Jude Reviewed-by: George Melikov Signed-off-by: Brian Behlendorf Closes #18766 M .gitignore A SECURITY.md _____________________________________________________________________________________________________________ Commit: 977a37cd51b687acd9213cb841158021f83ea0fa URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=977a37cd51b687acd9213cb841158021f83ea0fa Author: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> (Wed 8 Jul 2026 17:51:03 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) linux: batch DMU reads of non-resident pages in mappedread() When a range being read has at least one page in the page cache, zfs_read() routes the whole chunk through mappedread(), which falls back to a separate dmu_read_uio_dbuf() call for every non-resident PAGE_SIZE piece. Since cached pages outlive munmap(), a file which was mapped at some point may sit mostly outside the page cache and still pay this cost: one DMU call per 4K page instead of one per chunk, measured in #16031 as a 4-10x sequential read slowdown. Commit 39be46f43 ("Linux 5.18+ compat: Detect filemap_range_has_page") fixed the detection side so fully uncached chunks bypass mappedread() again, but a chunk holding even one resident page still degrades to page-sized DMU reads for everything else. Instead of issuing one DMU read per absent page, probe the page cache with find_get_page() and extend the read over the whole run of non-resident pages which follows, restoring chunk-sized DMU reads for the uncached parts of a mapped file. A page can be faulted in after it was observed absent and before the DMU read covering it completes, but this is safe for the same reason the existing single-page window is. zfs_read() holds the znode rangelock as reader across mappedread(), so the DMU contents of the range are stable: zfs_write(), zfs_putpage() and truncation all require the writer lock, and zfs_getpage() fills concurrently faulted pages from those same contents. A faulted page can only diverge from the DMU once dirtied through a writable mapping, making that store concurrent with this read, for which returning the pre-store data is a valid outcome. Stores which completed before the read began cannot be missed: a dirty page cannot be cleaned and reclaimed while the reader lock is held (writeback takes the writer lock), so it is still found resident, or zfs_putpage() already copied its data into the DMU. FreeBSD's mappedread() has the same per-page fallback and could be batched the same way in a follow-up. Measured in a VM with a 1 GiB file held in the ARC and read sequentially with dd: one resident page per 1 MiB read request degrades throughput from ~11.4 GB/s (no resident pages) to ~5.7 GB/s on the baseline, and this change restores ~11.4 GB/s; one resident page per 32 MiB chunk, read in 32 MiB requests, improves from ~5.4 GB/s to ~7.3 GB/s. Reads of a fully resident file are unaffected (~20 GB/s before and after). All tests in the ZTS mmap group pass, including the mmap_read and mmap_seek cases. Reviewed-by: Brian Behlendorf Signed-off-by: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> Closes #16031 Closes #18741 M module/os/linux/zfs/zfs_vnops_os.c _____________________________________________________________________________________________________________ Commit: d49cdddcef064668ad1d401fe3a16e8d71954fbd URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d49cdddcef064668ad1d401fe3a16e8d71954fbd Author: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> (Tue 7 Jul 2026 21:09:32 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) Linux: fix zfs_write() infinite loop on unfaultable buffer On Linux, zfs_write() copies from the source buffer with page faults disabled while the transaction is open, relying on zfs_uio_prefaultpages() to make the pages resident beforehand. When dmu_write_uio_dbuf() returns EFAULT, the retry path only subtracts the bytes consumed so far from the prefault accounting. On zero progress pfbytes does not change, the "pfbytes < nbytes" check never triggers another prefault, and the loop retries the same failing copy. If the buffer can never be faulted in again, e.g. the owning process was torn down while a thread was in pwrite(2), that thread spins unkillably at 100% CPU holding the file range lock, blocking every other accessor of the file. This is a regression from commit b0cbc1aa9a ("Use big transactions for small recordsize writes."), which dropped the unconditional re-prefault the EFAULT path had carried since commit 779a6c0bf6 ("deadlock between mm_sem and tx assign in zfs_write() and page fault"). Restore those semantics by resetting pfbytes on EFAULT, as suggested in the issue analysis: the next iteration then faults the pages back in before retrying, and for a permanently inaccessible buffer zfs_uio_prefaultpages() fails, breaking the loop with EFAULT, which is already propagated to userspace. Transient faults, such as mmap'ed source pages evicted under memory pressure, retry as before. Built and tested on Linux aarch64: the ZTS mmap and write-path groups pass and a munmap-versus-write stress run leaves no stuck writers. The teardown race itself is not reproducible on demand, so the retry paths were also checked by inspection against the reproducers in the issue. Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: MorganaFuture <103630661+MorganaFuture@users.noreply.github.com> Closes #17129 Closes #18740 M module/zfs/zfs_vnops.c _____________________________________________________________________________________________________________ Commit: 68c8dbe42ea8b119b6e16f66bfb22ac901cb4756 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=68c8dbe42ea8b119b6e16f66bfb22ac901cb4756 Author: crass (Tue 7 Jul 2026 19:23:00 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) build: Fix for building dist target outside of project root Do not change the working directory when doing copying because $distdir is a path relative to the working directory, and thus not valid after changing the working directory. This previously worked, when configure was run from the project root, because @srcdir@ was the same as the build working directory. Reviewed-by: Brian Behlendorf Signed-off-by: Glenn Washburn Closes #18744 M module/Makefile.in _____________________________________________________________________________________________________________ Commit: d77d40e05e710bdefbe7c1af46bb7a8d78c7fe70 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d77d40e05e710bdefbe7c1af46bb7a8d78c7fe70 Author: Brian Behlendorf (Mon 6 Jul 2026 12:17:51 BST) Committer: Tony Hutter (Thu 13 Aug 2026 17:40:04 BST) ZTS: ctime_001_pos increase tolerance The ctime_001_pos test checks that timestamp updates occur for a file after performing certain operations (read, write, chown, etc). The test case allowed for a +4 second tolerance in the timestamp value which is generous but up to +7 second discrepencies have been seen in the CI. Bump the tolerance to +10 seconds to prevent these false positives. As long as the value increases and is reasonably close to the expected value consider that to be sufficient. Reviewed-by: Christos Longros Reviewed-by: Alexander Motin Signed-off-by: Brian Behlendorf Closes #18733 M tests/zfs-tests/cmd/ctime.c _____________________________________________________________________________________________________________ Commit: 6b25004d1d181ea520d79ed5ce5710a9350fd35b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6b25004d1d181ea520d79ed5ce5710a9350fd35b Author: Gordon Bergling (Mon 10 Aug 2026 10:30:19 BST) Committer: Gordon Bergling (Thu 13 Aug 2026 06:02:10 BST) ipfilter(4): Fix a typo in a source code comment - s/pointr/pointer/ Obtained from: NetBSD (cherry picked from commit f98d856f613b3d8ac564d03dbe0011bd9eaab757) M sys/netpfil/ipfilter/netinet/fil.c _____________________________________________________________________________________________________________ Commit: 7fd3c8d6028827b5becb2010baf43923841b3029 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7fd3c8d6028827b5becb2010baf43923841b3029 Author: Nick Price (Sun 19 Jul 2026 03:27:36 BST) Committer: Nick Price (Thu 13 Aug 2026 03:00:13 BST) dpaa2: Apply if_flags and MAC filters in dpaa2_ni_init() make sure interface flags and filters are reprogrammed during init(). The config isn't pushed into the hardware when the interface is down but the flags are still being set, so we need to do the initial programming ourselves. This fixes bridge and multicast behavior. PR: 292006 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=292006 ) Reported by: jhibbits Approved by: adrian Reviewed by: jhibbits Differential Revision: https://reviews.freebsd.org/D58330 (cherry picked from commit dc12e3e0e72a73f1ad1a14d8d0fa4e2147151720) Signed-off-by: Nick Price M sys/dev/dpaa2/dpaa2_ni.c _____________________________________________________________________________________________________________ Commit: 70f48109503b0e17ff7e2e2a493af8b8d0397f01 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=70f48109503b0e17ff7e2e2a493af8b8d0397f01 Author: Konstantin Belousov (Mon 10 Aug 2026 19:09:11 BST) Committer: Konstantin Belousov (Thu 13 Aug 2026 01:34:41 BST) vm/vm_phys.c: allow PHYS_TO_VM_PAGE(0) for registered fictitious page @0 PR: 296348 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296348 ) (cherry picked from commit 6a8558cf9f0190cb166042f97d2c883d822e66b2) M sys/vm/vm_phys.c _____________________________________________________________________________________________________________ Commit: 42dbbaf748ea18195174854dae0831180af3e256 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=42dbbaf748ea18195174854dae0831180af3e256 Author: Konstantin Belousov (Fri 31 Jul 2026 05:12:17 BST) Committer: Konstantin Belousov (Thu 13 Aug 2026 01:34:41 BST) dounmount(9): temporarily enable recursion for the covered vnode lock PR: 297174 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297174 ) (cherry picked from commit 9f5c4ef32812afb4573a278e6eafe5040f839d13) M sys/kern/vfs_mount.c _____________________________________________________________________________________________________________ Commit: 2389370c75c132147fbfa99289a2cbc10a8a43ea URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2389370c75c132147fbfa99289a2cbc10a8a43ea Author: Konstantin Belousov (Fri 31 Jul 2026 05:11:05 BST) Committer: Konstantin Belousov (Thu 13 Aug 2026 01:34:41 BST) lockmgr(9): add lockcanrecurse(9) (cherry picked from commit 1d97ad676d586aa5d91227ebaa39bd9c3b1d68fe) M sys/kern/kern_lock.c M sys/sys/lockmgr.h M sys/sys/vnode.h _____________________________________________________________________________________________________________ Commit: 8bb41568feee63d8a1e5f161bcada15052068094 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8bb41568feee63d8a1e5f161bcada15052068094 Author: Konstantin Belousov (Thu 6 Aug 2026 22:22:48 BST) Committer: Konstantin Belousov (Thu 13 Aug 2026 01:34:40 BST) ptrace_test: require debug.ptrace_transparent_attach enabled for its test (cherry picked from commit b0a85cb9df01b1b56bbd530b3c3ae85e6964a9c6) M tests/sys/kern/Makefile M tests/sys/kern/ptrace_test.c _____________________________________________________________________________________________________________ Commit: a2c02072f054bff572f171d2923e73621f0d419c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a2c02072f054bff572f171d2923e73621f0d419c Author: Ameer Hamza (Mon 29 Jun 2026 12:25:46 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) libzfs: fix MS_CRYPT/MS_OVERLAY collision with umount2(2) flags MS_CRYPT and MS_OVERLAY are libzfs-internal mount flags, but their values (0x8 and 0x4) aliased the umount2(2) flags UMOUNT_NOFOLLOW and MNT_EXPIRE. A consumer that legitimately set UMOUNT_NOFOLLOW therefore had that bit read as MS_CRYPT, so libzfs unloaded the dataset's encryption key as a side effect. Move both flags to high bits unused by umount2(2) and strip them before the unmount syscall in do_unmount() (umount2(2) on Linux, unmount(2) on FreeBSD) and in cmd/zfs. MS_CRYPT is a compile-time macro, so consumers that set it (for example truenas_pylibzfs) must be rebuilt against the new header. Reviewed-by: Brian Behlendorf Signed-off-by: Ameer Hamza Closes #18713 M cmd/zfs/zfs_main.c M lib/libspl/include/os/freebsd/sys/mount.h M lib/libspl/include/os/linux/sys/mount.h M lib/libzfs/os/freebsd/libzfs_zmount.c M lib/libzfs/os/linux/libzfs_mount_os.c _____________________________________________________________________________________________________________ Commit: 09a876a38830f98d7bea97d77997d186b8baef91 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=09a876a38830f98d7bea97d77997d186b8baef91 Author: Alexander Motin (Wed 1 Jul 2026 21:50:17 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) Fix insufficient locking in dedup verify Introduction of dde_io_lock removed global DDT lock acquisition from write completion. As result, white ZIO ABD could be freed while zio_ddt_collision() is comparing against it. Taking there dde_io_lock should fix the issue. Reviewed-by: Brian Behlendorf Signed-off-by: Alexander Motin Closes #17960 Closes #18712 Closes #18720 M module/zfs/zio.c _____________________________________________________________________________________________________________ Commit: 51b907812823df3074d66c493f1afe442749521c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=51b907812823df3074d66c493f1afe442749521c Author: Rob Norris (Wed 1 Jul 2026 02:23:23 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) zpl_ctldir: remove comments describing ancient kernel behaviour Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18722 M module/os/linux/zfs/zpl_ctldir.c _____________________________________________________________________________________________________________ Commit: ad8b10f83fd54ffd563fef945391c90273aa0793 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ad8b10f83fd54ffd563fef945391c90273aa0793 Author: Rob Norris (Tue 30 Jun 2026 19:16:13 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) Linux 7.2: zpl_super: convert to sget_fc() The old sget() superblock matcher has been removed in favour of the fscontext-based sget_fc(). This converts to it. Its largely a signature change, no functional change. sget_fc() has existed since fscontext was introduced, so there's no need for separate feature tests. Sponsored-by: TrueNAS Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18677 D config/kernel-sget-args.m4 M config/kernel.m4 M module/os/linux/zfs/zpl_super.c _____________________________________________________________________________________________________________ Commit: edf191fe49191ce665645167e46dd28fc9e089f5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=edf191fe49191ce665645167e46dd28fc9e089f5 Author: Rob Norris (Tue 30 Jun 2026 19:14:12 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) linux/abd: remove BIO support functions Not used since the "classic" vdev_disk implementation was removed in 5764e218ba. Sponsored-by: TrueNAS Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18719 M include/os/linux/zfs/sys/abd_os.h M module/os/linux/zfs/abd_os.c _____________________________________________________________________________________________________________ Commit: f4977e472b9da80dedc536f4cdc3c445bbd622c5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f4977e472b9da80dedc536f4cdc3c445bbd622c5 Author: tiehexue (Tue 30 Jun 2026 19:13:08 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) Using net/cloud-init to unpin specific python These days freebsd 15/16 fail when fetching py311-cloud-init. Switch to net/cloud-init to avoid python version pinning. Reviewed-by: Brian Behlendorf Signed-off-by: tiehexue Closes #18717 M .github/workflows/scripts/qemu-2-start.sh _____________________________________________________________________________________________________________ Commit: bc35c81062563739614783e113c2c25266ddb476 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bc35c81062563739614783e113c2c25266ddb476 Author: Brian Behlendorf (Tue 30 Jun 2026 18:49:14 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) linux: handle mmap read beyond file size When performing a mmap read past the end of a file there is no data to read, so simply zero-fill the page and return success. zfs_getpage() limits the range lock appropriately to cover the offset being read. Reported-by: Iliya Polihronov (@vnsavage) (Automattic) Reviewed-by: Alexander Motin Signed-off-by: Brian Behlendorf Closes #18715 M module/os/linux/zfs/zfs_vnops_os.c _____________________________________________________________________________________________________________ Commit: 14ff1853cdb0abc2964d4013a3d032d507e580c4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=14ff1853cdb0abc2964d4013a3d032d507e580c4 Author: Prakash Surya (Sat 27 Jun 2026 21:56:56 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) Fix race between device removal completion and pool export vdev_remove_complete() finalizes a device removal in two phases under the spa lock framework. Between the two phases it called spa_vdev_exit(), which drops both the config locks (SCL_ALL) and spa_namespace_lock and blocks on a txg sync. By that point vdev_remove_replace_with_indirect() has already set svr->svr_thread = NULL, and that is the only thing the export path (spa_export_common() -> spa_async_suspend() -> spa_vdev_remove_suspend()) waits on. Once the namespace lock is dropped, a concurrent export or destroy can acquire it and set spa->spa_export_thread. When the removal thread re-enters for its second phase via spa_vdev_enter(), it trips the ASSERT0P(spa->spa_export_thread) assertion. Hold spa_namespace_lock across both phases instead of dropping and re-taking it: the intermediate spa_vdev_exit() becomes spa_vdev_config_exit(), which drops only SCL_ALL and syncs the txg while keeping the namespace lock held, and the second spa_vdev_enter() becomes spa_vdev_config_enter(). Because the namespace lock is never dropped between the phases, a concurrent export blocks in spa_namespace_enter() and cannot set spa_export_thread until removal finalization is done. This mirrors the multi-phase locking pattern already used by the attach/detach and split paths in spa.c. Reviewed-by: Brian Behlendorf Signed-off-by: Prakash Surya Closes #18657 M module/zfs/vdev_removal.c _____________________________________________________________________________________________________________ Commit: 894c103d93219f37265dbcf0aaf9f22a3229c5f9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=894c103d93219f37265dbcf0aaf9f22a3229c5f9 Author: Brian Behlendorf (Sat 27 Jun 2026 21:54:57 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) CI: Increase default watchdog NMI timeout on Linux When the watchdog driver is configured and enabled an NMI will be generated when the watchdogd process fails to regularly reset the watchdog timer. Given the heavily virtualized and potentially over-subscribed nature of the CI environment increase the default timeout to 120 seconds (normally defaults to 30 seconds). Reviewed-by: Christos Longros Signed-off-by: Brian Behlendorf Closes #18704 M .github/workflows/scripts/qemu-6-tests.sh _____________________________________________________________________________________________________________ Commit: 5e8780ff962ba990006bacc27248d640612f051b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5e8780ff962ba990006bacc27248d640612f051b Author: Igor Ostapenko (Fri 26 Jun 2026 23:08:32 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) ddt_log: Fix refcount tagging for begin/commit Sponsored-by: Klara, Inc. Sponsored-by: Wasabi Technology, Inc. Reviewed-by: Rob Norris Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: Igor Ostapenko Closes #18706 M module/zfs/ddt_log.c _____________________________________________________________________________________________________________ Commit: 0da2e6b397bdd6ba51f765f8dd8ef699eb9d07dc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0da2e6b397bdd6ba51f765f8dd8ef699eb9d07dc Author: Ameer Hamza (Wed 24 Jun 2026 19:40:49 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) Update mtime/ctime when fallocate grows a file Growing a file with fallocate updated its size but left mtime/ctime unchanged and didn't log the change. A fallocate that changes the file size should update mtime/ctime, and the change should be logged so it survives a crash. Pass log=TRUE to zfs_freesp() on the extend path so it updates the timestamps and logs the size change, matching zfs_space(). Punch-hole and zero-range already use this path and are unaffected. Reviewed-by: Rob Norris Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: Ameer Hamza Closes #18573 M module/os/linux/zfs/zpl_file.c M tests/runfiles/linux.run M tests/zfs-tests/tests/Makefile.am A tests/zfs-tests/tests/functional/fallocate/fallocate_extend_timestamps.ksh _____________________________________________________________________________________________________________ Commit: 1dd19c3d8da2071455733f431a368a4975217b81 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1dd19c3d8da2071455733f431a368a4975217b81 Author: Alek P (Wed 24 Jun 2026 18:16:15 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) honor file argument in file_wait_event grep the log path passed by the caller instead of always using ZED_DEBUG_LOG. Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: Alek Pinchuk Closes #18700 M tests/zfs-tests/tests/functional/events/events_common.kshlib _____________________________________________________________________________________________________________ Commit: 5599bb7802865e98f96435f1c615d83ef73fb786 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5599bb7802865e98f96435f1c615d83ef73fb786 Author: Christos Longros <98426896+chrislongros@users.noreply.github.com> (Tue 23 Jun 2026 14:01:01 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) README: update supported FreeBSD release to 15.1 Our CI runners moved to FreeBSD 15.1 in 0a4b59765 (#18667), but the README still lists 15.0. Update it to match the CI version. Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Christos Longros Closes #18696 M README.md _____________________________________________________________________________________________________________ Commit: 7e8f6ad78dc882a237852b4dbece4018ac01e9e6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7e8f6ad78dc882a237852b4dbece4018ac01e9e6 Author: Nick Price (Mon 22 Jun 2026 23:44:20 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) Clean up embedded slog metaslab across txgs On a read-write import, metaslab_set_fragmentation() can dirty a metaslab via vdev_dirty() while still in the txg==0 load path when its space map has an unexpected bonus size (e.g. a makefs-created pool whose space-map dnodes use the boot loader's 24-byte space_map_phys_t with nblkptr=3, giving db_size=64). If that metaslab is then selected as the embedded slog, vdev_metaslab_init() only removed it from vdev_ms_list when txg != 0, so the txg==0 case left it queued and metaslab_fini() tripped VERIFY(!txg_list_member(&vd->vdev_ms_list, msp, t)). Remove slog_ms from the dirty list for every TXG_SIZE slot before metaslab_fini() so the cleanup is correct regardless of txg. Reported on FreeBSD as PR 281520: External-issue: https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281520 Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: Nick Price Closes #18693 M module/zfs/vdev.c _____________________________________________________________________________________________________________ Commit: e2a344702d5310debeb19bf30a203544325d69c0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e2a344702d5310debeb19bf30a203544325d69c0 Author: Richard Yao (Mon 22 Jun 2026 22:56:34 BST) Committer: Tony Hutter (Wed 12 Aug 2026 22:32:42 BST) initramfs-zfs should not try to copy directories We had find only return files from the beginning for libgcc.so, but not libfetch/libcurl. This oversight affected a user when vmware installed its own libcurl.so.4 in a directory called libcurl.so.4, since our code then tried to copy a directory, which fails. Reviewed-by: Chris Longros Reviewed-by: Brian Behlendorf Suggested-by: Carsten Härle Signed-off-by: Richard Yao Closes #18582 Closes #18686 M contrib/initramfs/hooks/zfs.in _____________________________________________________________________________________________________________ Commit: e22491cb9bdc84a425fab63c1351f576e018e16b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e22491cb9bdc84a425fab63c1351f576e018e16b Author: Abdelkader Boudih (Wed 5 Aug 2026 05:40:58 BST) Committer: Kevin Bowling (Wed 12 Aug 2026 21:29:50 BST) igc: defer sysctl-driven reinit to the admin task igc_sysctl_eee() and igc_sysctl_dmac() called igc_if_init() directly. Request the reset through iflib instead, and skipping while the interface is down; the new value is picked up by the next init. Unlike e1000, igc has no ASSERT_CTX_LOCK_HELD and no acquire_swflag path, so the defect is silent here rather than an assertion failure. While here also remove unnecessary igc_if_init uses: iflib_if_init_locked() already runs after IFDI_RESUME and IFDI_MEDIA_CHANGE, so the trailing *_if_init() only added an unstopped IFDI_INIT that the following iflib_stop() undoes. Differential Revision: https://reviews.freebsd.org/D58629 (cherry picked from commit 30ccf2f48c11e54fc0540510dcec7cd006a2c366) M sys/dev/igc/if_igc.c _____________________________________________________________________________________________________________ Commit: cbedee9bdcda72bba3cceead8272c9b75ab90512 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cbedee9bdcda72bba3cceead8272c9b75ab90512 Author: Abdelkader Boudih (Wed 5 Aug 2026 05:34:13 BST) Committer: Kevin Bowling (Wed 12 Aug 2026 21:29:17 BST) e1000: defer sysctl-driven reinit to the admin task Request the reset through iflib and let the admin task perform the stop/init under the context lock, matching what the VF and SR-IOV paths already do. The assertion is compiled out without INVARIANTS, where the same write instead resets the MAC and takes the ICH software flag while the queues stay live and an ioctl or the admin task may be running. While here also remove unnecessary em_if_init uses: iflib_if_init_locked() already runs after IFDI_RESUME and IFDI_MEDIA_CHANGE, so the trailing *_if_init() only added an unstopped IFDI_INIT that the following iflib_stop() undoes. Differential Revision: https://reviews.freebsd.org/D58628 (cherry picked from commit abdde8b602813753e423610b39be6806da5647e2) M sys/dev/e1000/if_em.c _____________________________________________________________________________________________________________ Commit: b0c292621eb61ba4e88d5868fa7cba4911f2a172 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b0c292621eb61ba4e88d5868fa7cba4911f2a172 Author: Dag-Erling Smørgrav (Sat 8 Aug 2026 01:10:23 BST) Committer: Dag-Erling Smørgrav (Wed 12 Aug 2026 20:17:22 BST) du: Print progress information to stderr * On SIGINFO, print the current path to stderr rather than stdout. * Do so immediately, instead of the next time we finish a directory. * Document this behavior in the manual page. PR: 296861 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296861 ) MFC after: 1 week Fixes: d1588599c024 ("Report the next directory being scanned ...") Reviewed by: wollman Differential Revision: https://reviews.freebsd.org/D58702 (cherry picked from commit fd79bf63442eefd2c3bfb695a377dbd705f5cc6d) M usr.bin/du/du.1 M usr.bin/du/du.c _____________________________________________________________________________________________________________ Commit: df9c6721f819621bada10f1bfcdc3b47a4fe995b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=df9c6721f819621bada10f1bfcdc3b47a4fe995b Author: Dag-Erling Smørgrav (Wed 5 Aug 2026 09:50:47 BST) Committer: Dag-Erling Smørgrav (Wed 12 Aug 2026 20:15:47 BST) pseudofs: Don't purge the cache on shutdown This is a waste of time and results in a use-after-free if linsysfs is loaded and a USB network interface is in use, since USB devices are disconnected at shutdown, which triggers a call into linsysfs, which then tries to destroy a pseudofs node which has already been purged. MFC after: 1 week Reviewed by: glebius Differential Revision: https://reviews.freebsd.org/D58359 (cherry picked from commit 4ebcdb8dd9a7bdddbc97ff6ee47e0a7556c76b5a) M sys/fs/pseudofs/pseudofs.c _____________________________________________________________________________________________________________ Commit: 79cf64a2b8e1a3427a7ed133e132cfd747453c1f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=79cf64a2b8e1a3427a7ed133e132cfd747453c1f Author: Dag-Erling Smørgrav (Tue 4 Aug 2026 19:27:21 BST) Committer: Dag-Erling Smørgrav (Wed 12 Aug 2026 20:15:47 BST) unbound: Update to 1.26.0 Release notes at https://community.nlnetlabs.nl/t/unbound-1-26-0-released Merge commit '84ffc29dc8ddb0c946db5cb3b3c1310bec6a9e6c' (cherry picked from commit 7a789145f88a6aceacc59029a0cafe7de7aeefea) M contrib/unbound/README.md M contrib/unbound/ax_pthread.m4 M contrib/unbound/cachedb/cachedb.c M contrib/unbound/compat/getentropy_osx.c M contrib/unbound/compat/inet_pton.c M contrib/unbound/config.guess M contrib/unbound/config.h.in M contrib/unbound/config.sub M contrib/unbound/configure M contrib/unbound/configure.ac M contrib/unbound/daemon/cachedump.c M contrib/unbound/daemon/daemon.c M contrib/unbound/daemon/remote.c M contrib/unbound/daemon/remote.h M contrib/unbound/daemon/stats.c M contrib/unbound/daemon/worker.c M contrib/unbound/dns64/dns64.c M contrib/unbound/dnscrypt/dnscrypt.c M contrib/unbound/dnstap/dnstap.c M contrib/unbound/dnstap/dnstap.h M contrib/unbound/dnstap/dtstream.c M contrib/unbound/dnstap/unbound-dnstap-socket.c M contrib/unbound/doc/Changelog M contrib/unbound/doc/README M contrib/unbound/doc/example.conf M contrib/unbound/doc/example.conf.in M contrib/unbound/doc/libunbound.3 M contrib/unbound/doc/libunbound.3.in M contrib/unbound/doc/unbound-anchor.8 M contrib/unbound/doc/unbound-anchor.8.in M contrib/unbound/doc/unbound-checkconf.8 M contrib/unbound/doc/unbound-checkconf.8.in M contrib/unbound/doc/unbound-control.8 M contrib/unbound/doc/unbound-control.8.in M contrib/unbound/doc/unbound-control.rst M contrib/unbound/doc/unbound-host.1 M contrib/unbound/doc/unbound-host.1.in M contrib/unbound/doc/unbound.8 M contrib/unbound/doc/unbound.8.in M contrib/unbound/doc/unbound.conf.5 M contrib/unbound/doc/unbound.conf.5.in M contrib/unbound/doc/unbound.conf.rst M contrib/unbound/edns-subnet/addrtree.c M contrib/unbound/edns-subnet/subnetmod.c M contrib/unbound/ipsecmod/ipsecmod-whitelist.c M contrib/unbound/ipsecmod/ipsecmod.c M contrib/unbound/ipset/ipset.c M contrib/unbound/iterator/iter_delegpt.c M contrib/unbound/iterator/iter_delegpt.h M contrib/unbound/iterator/iter_resptype.c M contrib/unbound/iterator/iter_resptype.h M contrib/unbound/iterator/iter_scrub.c M contrib/unbound/iterator/iter_scrub.h M contrib/unbound/iterator/iter_utils.c M contrib/unbound/iterator/iter_utils.h M contrib/unbound/iterator/iterator.c M contrib/unbound/iterator/iterator.h M contrib/unbound/libunbound/context.h M contrib/unbound/libunbound/libunbound.c M contrib/unbound/libunbound/libworker.c A contrib/unbound/libunbound/remote.h M contrib/unbound/libunbound/worker.h M contrib/unbound/respip/respip.c M contrib/unbound/services/authzone.c M contrib/unbound/services/authzone.h M contrib/unbound/services/cache/dns.c M contrib/unbound/services/cache/rrset.c M contrib/unbound/services/listen_dnsport.c M contrib/unbound/services/localzone.c M contrib/unbound/services/localzone.h M contrib/unbound/services/mesh.c M contrib/unbound/services/mesh.h M contrib/unbound/services/outside_network.c M contrib/unbound/services/outside_network.h M contrib/unbound/services/rpz.c M contrib/unbound/sldns/keyraw.c M contrib/unbound/sldns/str2wire.c M contrib/unbound/smallapp/unbound-anchor.c M contrib/unbound/smallapp/unbound-checkconf.c M contrib/unbound/smallapp/worker_cb.c M contrib/unbound/util/config_file.c M contrib/unbound/util/config_file.h M contrib/unbound/util/configlexer.c M contrib/unbound/util/configlexer.lex M contrib/unbound/util/configparser.c M contrib/unbound/util/configparser.h M contrib/unbound/util/configparser.y M contrib/unbound/util/data/msgencode.c M contrib/unbound/util/data/msgparse.c M contrib/unbound/util/data/msgreply.c M contrib/unbound/util/data/packed_rrset.c M contrib/unbound/util/data/packed_rrset.h M contrib/unbound/util/fptr_wlist.c M contrib/unbound/util/fptr_wlist.h M contrib/unbound/util/iana_ports.inc M contrib/unbound/util/module.h M contrib/unbound/util/net_help.c M contrib/unbound/util/netevent.c M contrib/unbound/util/netevent.h M contrib/unbound/util/proxy_protocol.c M contrib/unbound/util/proxy_protocol.h M contrib/unbound/util/shm_side/shm_main.c M contrib/unbound/util/tube.c M contrib/unbound/validator/autotrust.c M contrib/unbound/validator/val_anchor.c M contrib/unbound/validator/val_neg.c M contrib/unbound/validator/val_nsec.c M contrib/unbound/validator/val_nsec3.c M contrib/unbound/validator/val_secalgo.c M contrib/unbound/validator/val_sigcrypt.c M contrib/unbound/validator/val_utils.c M contrib/unbound/validator/val_utils.h M contrib/unbound/validator/validator.c M lib/libunbound/config.h _____________________________________________________________________________________________________________ Commit: 0477871a55e1ea153bac23360338c3342201897f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0477871a55e1ea153bac23360338c3342201897f Author: Philippe Michaud-Boudreault (Wed 22 Jul 2026 09:39:30 BST) Committer: Dag-Erling Smørgrav (Wed 12 Aug 2026 20:15:47 BST) tarfs: remove unused 'ino' in mount structure. Differential Revision: https://reviews.freebsd.org/D57898 (cherry picked from commit 54e6dec44b6dd264b19e50439a58b33cab4c10c3) M sys/fs/tarfs/tarfs.h _____________________________________________________________________________________________________________ Commit: decee0c77aca79d28114485a518abe2a30042f37 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=decee0c77aca79d28114485a518abe2a30042f37 Author: Tony Hutter (Mon 22 Jun 2026 21:26:39 BST) Committer: Tony Hutter (Wed 12 Aug 2026 18:25:25 BST) CI: Re-allow workflow_dispatch on zfs-qemu Allow zfs-qemu to be invoked from a workflow_dispatch event (a.k.a, manually running a workflow). This may have been accidentally disabled in 1916c2c55. Reviewed-by: Chris Longros Reviewed-by: Brian Behlendorf Signed-off-by: Tony Hutter Closes #18680 M .github/workflows/zfs-qemu.yml _____________________________________________________________________________________________________________ Commit: b021ebcdc9d99e66a0a619d2aa789e8896412f58 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b021ebcdc9d99e66a0a619d2aa789e8896412f58 Author: HeonJe Lee (Mon 22 Jun 2026 21:25:12 BST) Committer: Tony Hutter (Wed 12 Aug 2026 18:25:17 BST) zfs_ioctl: fix EBUSY race between quota queries and mount zfsvfs_hold() fell back to zfsvfs_create() -> dmu_objset_own() (exclusive) for unmounted datasets. A concurrent zfs_domount() also calls dmu_objset_own(), causing EBUSY on the same dataset. Introduce zfsvfs_create_hold() using dmu_objset_hold() (shared hold) instead. Shared holds do not conflict with exclusive owns, eliminating the race. The release path (zfsvfs_rele, zfsvfs_create_impl error) uses dmu_objset_ds()->ds_owner to determine whether to disown or rele, avoiding the need for an extra flag in zfsvfs_t. Added tests userspace_005, groupspace_005, projectspace_006 (50 iter race test). Reviewed-by: Brian Behlendorf Reviewed-by: Tony Hutter Signed-off-by: HeonJe Lee Closes #18611 M include/os/freebsd/zfs/sys/zfs_vfsops_os.h M include/os/linux/zfs/sys/zfs_vfsops_os.h M module/os/freebsd/zfs/zfs_vfsops.c M module/os/linux/zfs/zfs_vfsops.c M module/zfs/zfs_ioctl.c M tests/runfiles/common.run M tests/zfs-tests/tests/Makefile.am A tests/zfs-tests/tests/functional/projectquota/projectspace_006_pos.ksh A tests/zfs-tests/tests/functional/userquota/groupspace_005_pos.ksh A tests/zfs-tests/tests/functional/userquota/userspace_005_pos.ksh _____________________________________________________________________________________________________________ Commit: 5f84f4d81031ce03538d4c39c7cb69086013243b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5f84f4d81031ce03538d4c39c7cb69086013243b Author: rmacklem <64620010+rmacklem@users.noreply.github.com> (Mon 22 Jun 2026 14:29:24 BST) Committer: Tony Hutter (Wed 12 Aug 2026 18:25:09 BST) Fix handling of _PC_HAS_HIDDENSYSTEM for FreeBSD The hidden and system flags are only supported for ZFS pools if the z_use_fuids is true. Fix zfs_freebsd_pathconf() to check this. Reviewed-by: Alexander Motin Signed-off-by: Rick Macklem Closes #18688 M module/os/freebsd/zfs/zfs_vnops_os.c _____________________________________________________________________________________________________________ Commit: 3c27e3395d29d4323aed48436989f3b027697ba8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3c27e3395d29d4323aed48436989f3b027697ba8 Author: Tony Hutter (Wed 17 Jun 2026 17:45:38 BST) Committer: Tony Hutter (Wed 12 Aug 2026 18:25:01 BST) Linux 7.1 compat: META (#18682) Update the META file to reflect compatibility with the 7.1 kernel. Signed-off-by: Tony Hutter Signed-off-by: Rob Norris Reviewed-by: Chris Longros M META _____________________________________________________________________________________________________________ Commit: fa7e71e6e579417d279296f0f40c5b58334120f1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fa7e71e6e579417d279296f0f40c5b58334120f1 Author: Christos Longros <98426896+chrislongros@users.noreply.github.com> (Tue 16 Jun 2026 17:00:32 BST) Committer: Tony Hutter (Wed 12 Aug 2026 18:24:55 BST) Update our CI runners to the newest FreeBSD 15.1 RELEASE (#18667) Signed-off-by: Christos Longros Reviewed-by: Alexander Motin Reviewed-by: Tony Hutter M .github/workflows/README.md M .github/workflows/scripts/qemu-2-start.sh M .github/workflows/zfs-qemu.yml _____________________________________________________________________________________________________________ Commit: 4fe728852f3dde94f05114f24d23ee7343cd60bb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4fe728852f3dde94f05114f24d23ee7343cd60bb Author: Tony Hutter (Fri 12 Jun 2026 17:28:47 BST) Committer: Tony Hutter (Wed 12 Aug 2026 18:24:48 BST) CI: Have zfs-build-packages workflow build tarballs on Alma (#18662) Previously, zfs-build-packages would only build source tarballs on Fedora due to problems with building them on RHEL 7. That's a relic of the past now, as we haven't supported RHEL 7 since it went EOL in 2024. With this change, we now build the tarballs on both Alma and Fedora. Signed-off-by: Tony Hutter Reviewed-by: Olaf Faaland Reviewed-by: Chris Longros M .github/workflows/scripts/qemu-4-build-vm.sh _____________________________________________________________________________________________________________ Commit: 0192f4ad5019e7b2b6b900b97c4c2d306713228c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0192f4ad5019e7b2b6b900b97c4c2d306713228c Author: Maxim Konovalov (Mon 3 Aug 2026 19:08:07 BST) Committer: Sergey A. Osokin (Wed 12 Aug 2026 13:26:42 BST) bsd-family-tree: add NetBSD 11.0 (cherry picked from commit 396e6d69955669b564cb605418e9d8025b3592bd) M share/misc/bsd-family-tree _____________________________________________________________________________________________________________ Commit: 76789228d0890771c3ad22f2aad5b0150d86aaef URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=76789228d0890771c3ad22f2aad5b0150d86aaef Author: Maxim Konovalov (Tue 16 Jun 2026 13:34:28 BST) Committer: Sergey A. Osokin (Wed 12 Aug 2026 13:26:19 BST) bsd-family-tree: add FreeBSD 15.1 (cherry picked from commit f8b5df434e419e00272bfce343bf7da239081276) M share/misc/bsd-family-tree _____________________________________________________________________________________________________________ Commit: 6886e8a9a0aaef8d5666933c40d5dc4a3d098b70 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6886e8a9a0aaef8d5666933c40d5dc4a3d098b70 Author: giacomo (Wed 15 Jul 2026 12:34:34 BST) Committer: Christos Margiolis (Tue 11 Aug 2026 19:24:04 BST) snd_uaudio: Don't let an idle stream reprogram a shared UAC2 clock Some UAC2 devices expose a single Clock Source entity that is shared between their playback and capture interfaces (it appears in both the output and input clock bitmaps). On such a device uaudio(4) programs the sample rate for both directions when a stream starts. If playback runs at a 44.1 kHz-family rate while the idle capture channel is left at its 48 kHz-family default, the capture SET_CUR(UA20_CS_SAM_FREQ_CONTROL) is issued after the playback one and overwrites the rate on the shared clock. The device then runs at ~48 kHz while the playback stream carries 44.1 kHz data. Consuming samples faster than they arrive, the device repeatedly runs out of data, loses sync with the playback stream, and re-locks onto it (audible dropouts, front-panel play/idle flicker). The 48 kHz family is unaffected because both directions then agree on the rate. Fix it in three parts: - Add a shared-clock guard: before issuing SET_CUR to a clock id, if that clock is shared between playback and capture and the other direction is already streaming at a different rate, skip it. The first active stream owns the clock; a later one follows it. - When the recording channel is auto-started only as a source of jitter information for asynchronous playback, align its nominal rate to the playback rate before starting it, so it neither reprograms the shared clock to a conflicting rate nor produces mismatched frame sizes. - Always submit the explicit-feedback SYNC transfer so dev.pcm.%d.feedback_rate stays live as a diagnostic even when a capture stream is present. Reproduced on an OKTO RESEARCH DAC8 STEREO (0x152a:0x88c5), whose vestigial capture interface never streams; the same device plays the 44.1 kHz family correctly under Linux's snd-usb-audio. As a side effect, this patch also fixes the sample rate bug mentioned in the BUGS section of sound(4)'s man page, where a device needs to have the same sample rate set for both playback and recording in order to work properly. PR: 295933 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=295933 ) Assisted-By: Claude Opus 4.8 (claude-opus-4-8) Signed-off-by: giacomo MFC after: 2 weeks Reviewed by: christos Pull-Request: https://github.com/freebsd/freebsd-src/pull/2323 (cherry picked from commit 755685dd665ef209912c59da6a7d0e7f2c9f464b) M sys/dev/sound/usb/uaudio.c _____________________________________________________________________________________________________________ Commit: a46b8546b1c8cafc529024aa87ce82ceb7bf84cb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a46b8546b1c8cafc529024aa87ce82ceb7bf84cb Author: giacomo (Wed 15 Jul 2026 13:10:54 BST) Committer: Christos Margiolis (Tue 11 Aug 2026 19:24:04 BST) cuse: Fix server reference leak in cuse_client_open() If the server is closing (or the device node is going away), or if devfs_set_cdevpriv() fails, cuse_client_open() returns with the server reference taken at the top of the function still held and the newly allocated client still linked on pcs->hcli. Since cuse_client_free() has not been registered as the cdevpriv destructor at that point, nothing ever undoes this work: every open() that races the is_closing window permanently leaks one server reference and one cuse_client. A leaked reference is fatal on server exit: cuse_server_free() busy-waits in an uninterruptible pause("W", hz) loop until pcs->refs drops to 1, which now never happens, so the exiting server process (e.g. virtual_oss(8)) is left wedged in state "D", immune to SIGKILL, cuse.ko is pinned (kldunload hangs too), and only a reboot recovers. Before 634e578ac7b0 the is_closing error path dropped the reference by calling devfs_clear_cdevpriv(), which ran the cuse_client_free() destructor. That commit moved devfs_set_cdevpriv() after the is_closing check to fix the panic paths, but left both error returns without any cleanup. Fix by calling cuse_client_free() directly on both error paths. The client is fully constructed and linked on pcs->hcli at these points, which is exactly the state cuse_client_free() expects. PR: 296291 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296291 ) Fixes: 634e578ac7b0 ("cuse: Fix cdevpriv bugs in cuse_client_open()") Assisted-By: Claude Opus 4.8 (claude-opus-4-8) Signed-off-by: giacomo MFC after: 2 weeks Reviewed by: christos Pull-Request: https://github.com/freebsd/freebsd-src/pull/2324 (cherry picked from commit d83e42234f76504a1ff7f4309ad629b6644bfb16) M sys/fs/cuse/cuse.c _____________________________________________________________________________________________________________ Commit: cda2abf4f137f4570c940d9b2221ccb8230e0b20 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cda2abf4f137f4570c940d9b2221ccb8230e0b20 Author: Christos Margiolis (Mon 27 Jul 2026 16:52:09 BST) Committer: Christos Margiolis (Tue 11 Aug 2026 19:24:04 BST) sound: Add missing newline in dsp_make_dev()'s device_printf() Sponsored by: The FreeBSD Foundation MFC after: 1 week (cherry picked from commit 2a2705a637cd67d0add7fe795fef9b7a722d76bd) M sys/dev/sound/pcm/dsp.c _____________________________________________________________________________________________________________ Commit: a5b10ce45d678be3c771c686cc3949db2faf55aa URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a5b10ce45d678be3c771c686cc3949db2faf55aa Author: Christos Margiolis (Mon 27 Jul 2026 15:31:10 BST) Committer: Christos Margiolis (Tue 11 Aug 2026 19:24:03 BST) sound: Propagate error value from dsp_make_dev() It is better to propagate it to pcm_register(), and later to the device drivers, than to simply ignore it and return ENXIO. Sponsored by: The FreeBSD Foundation MFC after: 1 week (cherry picked from commit a46c92aad16bf6c9d6c3967c8af3e8b3bdb59cda) M sys/dev/sound/pcm/dsp.c _____________________________________________________________________________________________________________ Commit: 7af4af4ddf13b52713d163df17402d4b2423d325 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7af4af4ddf13b52713d163df17402d4b2423d325 Author: Christos Margiolis (Thu 23 Jul 2026 22:05:42 BST) Committer: Christos Margiolis (Tue 11 Aug 2026 19:21:37 BST) sound: Stop using legacy u_int types No functional change intended. Sponsored by: The FreeBSD Foundation MFC after: 1 week (cherry picked from commit 95439b803fce86958e1db1927a8405bf939edda4) M sys/dev/sound/macio/aoa.c M sys/dev/sound/macio/davbus.c M sys/dev/sound/macio/i2s.c M sys/dev/sound/macio/onyx.c M sys/dev/sound/macio/snapper.c M sys/dev/sound/macio/tumbler.c M sys/dev/sound/pci/als4000.c M sys/dev/sound/pci/cmi.c M sys/dev/sound/pci/cs4281.c M sys/dev/sound/pci/csa.c M sys/dev/sound/pci/csamidi.c M sys/dev/sound/pci/csapcm.c M sys/dev/sound/pci/csareg.h M sys/dev/sound/pci/csavar.h M sys/dev/sound/pci/emu10k1.c M sys/dev/sound/pci/emu10kx-pcm.c M sys/dev/sound/pci/envy24.c M sys/dev/sound/pci/envy24ht.c M sys/dev/sound/pci/fm801.c M sys/dev/sound/pci/hda/hdaa.c M sys/dev/sound/pci/maestro3.c M sys/dev/sound/pci/neomagic-coeff.h M sys/dev/sound/pci/neomagic.c M sys/dev/sound/pci/solo.c M sys/dev/sound/pci/spicds.c M sys/dev/sound/pci/t4dwave.c M sys/dev/sound/pci/via82c686.c M sys/dev/sound/pci/vibes.c M sys/dev/sound/pcm/ac97.c M sys/dev/sound/pcm/ac97.h M sys/dev/sound/pcm/ac97_if.m M sys/dev/sound/pcm/buffer.c M sys/dev/sound/pcm/buffer.h M sys/dev/sound/pcm/channel.c M sys/dev/sound/pcm/channel.h M sys/dev/sound/pcm/channel_if.m M sys/dev/sound/pcm/dsp.c M sys/dev/sound/pcm/feeder.c M sys/dev/sound/pcm/feeder.h M sys/dev/sound/pcm/feeder_if.m M sys/dev/sound/pcm/mixer.c M sys/dev/sound/pcm/mixer.h M sys/dev/sound/pcm/mixer_if.m M sys/dev/sound/pcm/sound.h _____________________________________________________________________________________________________________ Commit: 44b054dba523b390db9a3b54ceb71aa4af65d6db URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=44b054dba523b390db9a3b54ceb71aa4af65d6db Author: Kevin Bowling (Fri 24 Jul 2026 14:57:27 BST) Committer: Christos Margiolis (Tue 11 Aug 2026 19:17:51 BST) sound: Scale PCM secondary buffers by byte rate The fixed 128 KiB secondary buffer cap dates from stereo-sized streams. High channel-count or high sample-width OSS streams can consume most of that budget in one graph quantum, leaving too little room for capture catch-up or playback headroom. Keep 128 KiB as the low-rate floor, but derive the effective soft-ring cap from the channel byte rate, clamped to 4 MiB. Use that per-channel cap when resizing the soft buffer and when clamping SNDCTL_DSP_SETFRAGMENT requests. Also clamp SNDCTL_DSP_LOW_WATER to the current soft-buffer size so an impossible readiness threshold cannot make poll/select wait forever. MFC after: 3 weeks Reviewed by: christos Differential Revision: https://reviews.freebsd.org/D58064 (cherry picked from commit 967e86d1ef2ac8711c0ae7be353a9c08186f4e6f) M sys/dev/sound/pcm/channel.c M sys/dev/sound/pcm/channel.h M sys/dev/sound/pcm/dsp.c _____________________________________________________________________________________________________________ Commit: 0484b6a01a0e4eab1c77f7fb7c65eb64ad5dd408 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0484b6a01a0e4eab1c77f7fb7c65eb64ad5dd408 Author: Konstantin Belousov (Tue 4 Aug 2026 07:26:56 BST) Committer: Konstantin Belousov (Tue 11 Aug 2026 12:00:02 BST) autofs: try to avoid waiting for timeouts of in-flight requests for forced unmounts (cherry picked from commit d3c3a705b5e6689798057b764713bfc0e3b69f6a) M sys/fs/autofs/autofs_vfsops.c _____________________________________________________________________________________________________________ Commit: e84f15568e42027d3452a2813200a3e1449a135a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e84f15568e42027d3452a2813200a3e1449a135a Author: Konstantin Belousov (Mon 3 Aug 2026 18:41:46 BST) Committer: Konstantin Belousov (Tue 11 Aug 2026 12:00:02 BST) autofs_lookup(): busy the mount point around autofs_trigger() PR: 294361 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=294361 ) (cherry picked from commit b95a859483f1ac0671bde55c0a2fc46f4db5ba4b) M sys/fs/autofs/autofs_vnops.c _____________________________________________________________________________________________________________ Commit: 80d732d6409907efb586c621238f5c43c77690f8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=80d732d6409907efb586c621238f5c43c77690f8 Author: Kristof Provost (Mon 3 Aug 2026 15:05:28 BST) Committer: Kristof Provost (Tue 11 Aug 2026 09:33:56 BST) pf: attempt to handle overlapping group and interface names pf assumes that network groups and network interfaces share a namespace (that is, a name is unused, a group or an interface, never both a the same time). Unfortunately this assumption was broken when interface renaming was introduced. Attempt to cope with this rather than panicking. Note that this is a band-aid, not a full solution. The correct fix is for the network stack to go back to enforcing a single namespace for groups and interfaces. PR: 297220 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297220 ) Reported by: Robert Morris MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate") (cherry picked from commit d2a5b5a86a92e86f77737273ab4b2e99da63c21d) M sys/netpfil/pf/pf_if.c M tests/sys/netpfil/pf/names.sh _____________________________________________________________________________________________________________ Commit: e4e4d1b5ed7b8a7239eb33fd27e32bafc63768db URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e4e4d1b5ed7b8a7239eb33fd27e32bafc63768db Author: Kristof Provost (Tue 2 Sep 2025 09:46:26 BST) Committer: Kristof Provost (Tue 11 Aug 2026 09:33:56 BST) pf: check if a group has a kif before dereferencing it It's possible for interface groups to not have had a pfi_kkif assigned to them, so before we pass that pointer to pfi_kkif_update() we must check if it's actually set. We've seen panics such as this, where we get an address update for an interface that belongs to a group without associated pfi_kkif: Tracing pid 12 tid 100034 td 0xfffff80100d2a000 kdb_enter() at kdb_enter+0x33/frame 0xfffffe0067eed340 panic() at panic+0x43/frame 0xfffffe0067eed3a0 trap_pfault() at trap_pfault+0x3c9/frame 0xfffffe0067eed3f0 calltrap() at calltrap+0x8/frame 0xfffffe0067eed3f0 --- trap 0xc, rip = 0xffffffff8102ebd5, rsp = 0xfffffe0067eed4c0, rbp = 0xfffffe0067eed500 --- pfi_kkif_update() at pfi_kkif_update+0x15/frame 0xfffffe0067eed500 pfi_kkif_update() at pfi_kkif_update+0x1fc/frame 0xfffffe0067eed550 pfi_ifaddr_event() at pfi_ifaddr_event+0x82/frame 0xfffffe0067eed5a0 srcaddr_change_event() at srcaddr_change_event+0xa7/frame 0xfffffe0067eed610 in6_update_ifa() at in6_update_ifa+0xd52/frame 0xfffffe0067eed790 in6_ifadd() at in6_ifadd+0x29a/frame 0xfffffe0067eed8b0 nd6_ra_input() at nd6_ra_input+0xf65/frame 0xfffffe0067eeda90 icmp6_input() at icmp6_input+0x3c8/frame 0xfffffe0067eedc10 ip6_input() at ip6_input+0xa15/frame 0xfffffe0067eedcf0 sppp_input() at sppp_input+0x502/frame 0xfffffe0067eedd80 pppoe_data_input() at pppoe_data_input+0x1e7/frame 0xfffffe0067eeddf0 swi_net() at swi_net+0x128/frame 0xfffffe0067eede60 ithread_loop() at ithread_loop+0x239/frame 0xfffffe0067eedef0 fork_exit() at fork_exit+0x7b/frame 0xfffffe0067eedf30 fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe0067eedf30 Note that pf doesn't assign pfi_kkif objects to groups created before pf has fully started (see V_pf_vnet_active check in pfi_attach_group_event()), which is one possible way for this to happen. Reported by: garga Sponsored by: Rubicon Communications, LLC ("Netgate") (cherry picked from commit dc0cf0648c8d28ab4914c798a4cff8256ae94ee5) M sys/netpfil/pf/pf_if.c _____________________________________________________________________________________________________________ Commit: 164a5a08767e4f864164506ca5597eb42035ee1a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=164a5a08767e4f864164506ca5597eb42035ee1a Author: Xin LI (Sun 26 Jul 2026 03:17:55 BST) Committer: Xin LI (Tue 11 Aug 2026 04:06:54 BST) release/Makefile.gce: migrate gsutil usages to gcloud CLI Google Cloud recommends migrating from gsutil to gcloud storage CLI. Update gce-do-upload target to use `gcloud storage buckets create` and `gcloud storage cp` instead of `gsutil mb` and `gsutil cp` commands. PR: conf/297016 (cherry picked from commit 4174cc2f69d36105a735b19fadc9c18497b02b1a) M release/Makefile.gce _____________________________________________________________________________________________________________ Commit: a8c598de78fd9ef6724d5f9366bc4b03fd5cbf9c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a8c598de78fd9ef6724d5f9366bc4b03fd5cbf9c Author: Bojan Novković (Mon 23 Feb 2026 15:30:26 GMT) Committer: Bojan Novković (Mon 10 Aug 2026 17:06:02 BST) mpool/mpool_get.c: Avoid clobbering 'errno' when handling 'pread' errors POSIX.1-2024 states that the 'free' function "shall not modify errno if ptr is a null pointer or a pointer previously returned as if by malloc() and not yet deallocated". However this is a fairly recent addition and non-compliant allocators might still clobber 'errno', causing 'mpool_get' to return the wrong error code. Fix this by saving and restoring 'errno' after calling 'free'. Sponsored by: Klara, Inc. Reviewed by: obiwac Differential Revision: https://reviews.freebsd.org/D55463 MFC after: 1 week (cherry picked from commit bce0c14fe19defeef4f02cfebc018e9adf979783) M lib/libc/db/mpool/mpool.c _____________________________________________________________________________________________________________ Commit: 803887970ab6dca9a2eab6ef5d8cddf50f8621fd URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=803887970ab6dca9a2eab6ef5d8cddf50f8621fd Author: Bojan Novković (Fri 13 Mar 2026 11:03:26 GMT) Committer: Bojan Novković (Mon 10 Aug 2026 17:06:01 BST) libc/db: Remove unused hash functions in hash_func.c Prune unused code hidden behind 'notdef', bringing us in sync with the changes in OpenBSD. Despite the `__default_hash` function pointer having external linkage, no ABI change is expected since it was never exported. Sponsored by: Klara, Inc. Differential Revision: https://reviews.freebsd.org/D55842 Reviewed by: allanjude, des MFC after: 2 weeks (cherry picked from commit c09ccfc2665bef0d81d1db4e3713e4f2a0b5a064) M lib/libc/db/hash/extern.h M lib/libc/db/hash/hash_func.c _____________________________________________________________________________________________________________ Commit: 429e2c587b3a510e908b4833354ce66cc9a9185c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=429e2c587b3a510e908b4833354ce66cc9a9185c Author: Slawa Olhovchenkov (Mon 13 Jul 2026 17:02:43 BST) Committer: Bojan Novković (Mon 10 Aug 2026 17:04:38 BST) bhyve: Fix some leaks in usr.sbin/bhyve/block_if.c Modify `blockif_open` to properly release a partially initialized `blockif_ctxt` structure on error. Differential Revision: https://reviews.freebsd.org/D57887 Reviewed by: novel, bnovkov, glebius Tested by: bnovkov MFC after: 2 weeks (cherry picked from commit 0228338fc9c6d2243fe4fd3259286d2fbc6df786) M usr.sbin/bhyve/block_if.c _____________________________________________________________________________________________________________ Commit: 75d74cc26f5527cba244112cfe3cfbffd31e987b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=75d74cc26f5527cba244112cfe3cfbffd31e987b Author: Jane Smith (Tue 21 Jul 2026 20:45:25 BST) Committer: Bojan Novković (Mon 10 Aug 2026 17:04:32 BST) cat: Fix a NULL pointer dereference Check the `fdopen` return value before calling `cook_cat`. Reviewed by: markj, bnovkov Differential Revision: https://reviews.freebsd.org/D57741 MFC after: 1 week (cherry picked from commit 9724f3f8974957d2cd15f6b796c347ca50250954) M bin/cat/cat.c _____________________________________________________________________________________________________________ Commit: bb68e4ac1250cd764681db501db36daf6757ea9a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bb68e4ac1250cd764681db501db36daf6757ea9a Author: Bojan Novković (Fri 5 Jun 2026 18:31:01 BST) Committer: Bojan Novković (Mon 10 Aug 2026 17:04:23 BST) bhyve: Document vCPU range pinning This change documents the recently introduced changes to -p that allow users to specify CPU ranges instead of having to specify each individual mapping. While we're here, move the -p examples to the EXAMPLES section. Reviewed by: bcr MFC after: 2 weeks Differential Revision: https://reviews.freebsd.org/D57480 (cherry picked from commit 23c99b64918eddb6084ffe4347faf95f82661c47) M usr.sbin/bhyve/bhyve.8 _____________________________________________________________________________________________________________ Commit: f760059545b178313dec7bc9528016d7520bac6d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f760059545b178313dec7bc9528016d7520bac6d Author: Antranig Vartanian (Fri 5 Jun 2026 16:34:18 BST) Committer: Bojan Novković (Mon 10 Aug 2026 17:04:18 BST) bhyve(8): allow cpu pinning using N-M:X-Y ranges bhyve's -p allows to pin guest's virtual CPU vcpu to hostcpu, however this becomes very tedious work when you have to pin more than a single CPU. This allows to pass a range to -p, e.g. -p 0-3:4-7 which will pin the cpus 0:4, 1:5, 2:6, 3:7. The ranges must be equal and the CPU numbers must be ascending. Sponsored by: Armenian Bioinformatics Institute Reviewed by: corvink, markj Tested by: bnovkov MFC after: 3 weeks Differential Revision: https://reviews.freebsd.org/D54937 (cherry picked from commit 8f6c577c9f706aea6f138fa1bec27029d4ab587d) M usr.sbin/bhyve/aarch64/bhyverun_machdep.c M usr.sbin/bhyve/amd64/bhyverun_machdep.c M usr.sbin/bhyve/bhyverun.c M usr.sbin/bhyve/riscv/bhyverun_machdep.c _____________________________________________________________________________________________________________ Commit: e5d63cec57a57f8403ccb09f73297877ef471175 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e5d63cec57a57f8403ccb09f73297877ef471175 Author: Bojan Novković (Thu 18 Jun 2026 03:03:55 BST) Committer: Bojan Novković (Mon 10 Aug 2026 17:04:06 BST) uart: Add support for the Intel XScale controller The ns8250 driver avoids clearing IER bit 0x10 to account for the split "receiver time-out interrupt enable" bit, but it never sets it in `ier_rxbits` even though a comment in `ns8250_init` implies so. Fix this by setting `IER_RXTMOUT` if we've matched an XScale uart. Differential Revision: https://reviews.freebsd.org/D57629 Reviewed by: imp MFC after: 2 weeks (cherry picked from commit 1665954e508f74588108e96c30b90d1a88807faa) M sys/dev/uart/uart_dev_ns8250.c _____________________________________________________________________________________________________________ Commit: 6d30c183117fb5797d889fb3865e6a0b9d17ae06 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6d30c183117fb5797d889fb3865e6a0b9d17ae06 Author: Kevin Bowling (Sat 1 Aug 2026 13:41:22 BST) Committer: Kevin Bowling (Mon 10 Aug 2026 01:42:12 BST) ixgbe: supply PF transmit contexts under SR-IOV X550-family malicious-driver detection validates the transmit context selected by a data descriptor with Check Context set. ixgbe sets that bit on every transmit data descriptor, but ordinary PF packets without a VLAN or checksum offload do not create a context descriptor. The empty context then reports an invalid MAC-header length and blocks the PF queue as soon as MDD is enabled. Create the existing context descriptor for every PF packet while SR-IOV is active. This supplies the required MAC-header length and keeps MDD from mistaking normal PF traffic for a malicious-driver event. (cherry picked from commit 0787b1f5b8bdfcaed97eeee7bfbd7f14ac162b0d) M sys/dev/ixgbe/ix_txrx.c _____________________________________________________________________________________________________________ Commit: d444d82ad831b3ce12cfd4980f3213b508342297 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d444d82ad831b3ce12cfd4980f3213b508342297 Author: Mateusz Piotrowski <0mp@FreeBSD.org> (Wed 20 May 2026 13:36:40 BST) Committer: Mateusz Piotrowski <0mp@FreeBSD.org> (Sun 9 Aug 2026 22:14:25 BST) d.7: Document no support for ddi_pathnam(), getmajor(), and getminor() MFC after: 3 days (cherry picked from commit d04da19acbef62f8aee36f5350470dcbf5ba2931) M share/man/man7/d.7 _____________________________________________________________________________________________________________ Commit: be97ef6e94a65630242f4abb5847f27feca21ffd URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=be97ef6e94a65630242f4abb5847f27feca21ffd Author: Minsoo Choo (Thu 2 Jul 2026 20:47:33 BST) Committer: Robert Clausecker (Sun 9 Aug 2026 10:29:50 BST) libc/merge.c: use memcpy() for copying Currently mergesort() uses ICOPY_*() to copy data as four byte blocks instead of one byte. However, this is only achievable when both size and base arguments are aligned to four bytes. Use of memcpy() is ideal as 1) it is cleaner and 2) the library will use SIMD for copying when the hardware supports it. Compared to ICOPY_*(), SIMD can support up to 64 bytes. When the SIMD-backed memcpy() find the address is unaligned, it can first copy data up to the nearest aligned address, and then use SIMD operations for faster transfer. Thus memcpy() can give better performance than mergesort()'s own implementation. This is benchmarked on amd64 where there isn't a SIMD-backed implementation yet. However, the baseline implementation in assembly already delivers better performance in unaligned cases although there is some performance drops in aligned cases. The benchmark results and script is available in the Phabricator review. Ideally, more performance improvements will come when amd64 gets SIMD implementation of memcpy(). Signed-off-by: Minsoo Choo Reviewed by: fuz MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D58002 (cherry picked from commit 00a79975c062650ba15e432e30776d42fc44fbaa) M lib/libc/stdlib/merge.c _____________________________________________________________________________________________________________ Commit: 192a5eeab8d1d9a55b1eb37d08aa26fdf7f486ec URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=192a5eeab8d1d9a55b1eb37d08aa26fdf7f486ec Author: Ahmad Khalifa (Sat 1 Aug 2026 10:26:44 BST) Committer: Ahmad Khalifa (Sat 8 Aug 2026 18:52:15 BST) vfs_mountroot: unmute console in interactive prompt If boot_mute is set the system appears to hang during the mountroot prompt. Temporarily unmute the console so the prompt is visible. Reviewed by: kib MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D58549 (cherry picked from commit e96f1cbd690e68594fc8812de634f43c6711aa97) M sys/kern/vfs_mountroot.c _____________________________________________________________________________________________________________ Commit: c3a70b0319d9ace70c9229e306f114893df1d714 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c3a70b0319d9ace70c9229e306f114893df1d714 Author: Pouria Mousavizadeh Tehrani (Wed 5 Aug 2026 09:27:54 BST) Committer: Pouria Mousavizadeh Tehrani (Sat 8 Aug 2026 07:13:59 BST) rtadvd(8): Fix RA flag inconsistency messages During flag inconsistency report, we handle rai->rai_otherflg as a bool, but the value is 0x40. Make it a simple number comparison. PR: 295995 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=295995 ) Reviewed by: markj, Faraz Vahedi MFC after: 3 days Differential Revision: https://reviews.freebsd.org/D58672 (cherry picked from commit 200de1b70e2b4f809d1d3a4c430db80b24124468) M usr.sbin/rtadvd/rtadvd.c _____________________________________________________________________________________________________________ Commit: fd9a9cbcdf27e8dabec9c4ce3edf4c4f868f0cf2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fd9a9cbcdf27e8dabec9c4ce3edf4c4f868f0cf2 Author: Kevin Bowling (Mon 3 Aug 2026 10:55:15 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:37:45 BST) igc: Disable PCIe L1.2 on I225 I225 devices can incorrectly enter L1 substates while CLKREQ# is asserted, both while idle and in D3. Disable ASPM and PCI-PM L1.2 on I225 to prevent the resulting packet loss. Keep the I226 workaround ASPM-only because it addresses a separate traffic exit latency observation. PR: 265714 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=265714 ) (cherry picked from commit 4a28d390f5fbae2483e88805559881b04ccf9a80) M sys/dev/igc/if_igc.c M sys/dev/igc/igc_base.c M sys/dev/igc/igc_base.h _____________________________________________________________________________________________________________ Commit: cf788fbe85ff7e995ee3ff535327eac62c14b3df URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cf788fbe85ff7e995ee3ff535327eac62c14b3df Author: Michael Adler (Sat 1 Aug 2026 00:54:00 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:37:34 BST) igc: Apply ASPM L1.2 workaround to all I226 devices Classify I226_LMVP and I226_BLANK_NVM as I226 silicon so they receive the I226-specific ASPM L1.2 workaround. PR: 279245 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=279245 ) Pull-Request: https://github.com/freebsd/freebsd-src/pull/2318 (cherry picked from commit cecb0f45cb83349c60514da38fddce83ad042468) M sys/dev/igc/igc_base.c _____________________________________________________________________________________________________________ Commit: c38cbf6be189bf0db87e3a92832ebe7248c5ee2f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c38cbf6be189bf0db87e3a92832ebe7248c5ee2f Author: Kevin Bowling (Tue 28 Jul 2026 12:26:28 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:37:23 BST) ixgbe: clear VF head write-back state on reset VF reset and FLR do not clear the transmit head write-back address registers. A previous VF driver can therefore leave DMA write-back enabled with a stale address for the next driver instance. After consuming the reset request and disabling the VF queues, clear the address registers for each queue belonging to that VF. Derive the queue count from the active IOV mode so peer queue state is not touched. Linux commit dbf231af81a7 documents the hardware behavior. The FreeBSD implementation follows the local queue mapping and register interfaces. (cherry picked from commit 6f940ca879cbf691ddf5605d852770cef27847b2) M sys/dev/ixgbe/if_sriov.c _____________________________________________________________________________________________________________ Commit: a00379eb18720b2922f6e003a4bcd915cde47e00 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a00379eb18720b2922f6e003a4bcd915cde47e00 Author: Kevin Bowling (Tue 28 Jul 2026 12:25:48 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:37:12 BST) ixgbe: dispatch PBA string reads through EEPROM ops E610 installs a device-specific PBA string reader, but the public API always calls the generic implementation. Dispatch through the EEPROM operation table so device overrides are honored. Initialize the generic operation for devices that use the ordinary EEPROM representation. Obtained from: Intel ix 3.4.39 (cherry picked from commit 9cf1aa6e68e4b9dd4a77c67b7b902b9221198e7a) M sys/dev/ixgbe/ixgbe_api.c M sys/dev/ixgbe/ixgbe_common.c _____________________________________________________________________________________________________________ Commit: 6452e39b45c3cf0dcfccd0432948f12fcb99396a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6452e39b45c3cf0dcfccd0432948f12fcb99396a Author: Kevin Bowling (Tue 28 Jul 2026 12:21:37 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:37:02 BST) ixgbe: avoid signed shift when assembling ETrack ID Obtained from: Intel ix 3.4.39 (cherry picked from commit 86869d77658aef48b2bab3e57517f88d7bd5389d) M sys/dev/ixgbe/ixgbe_common.c _____________________________________________________________________________________________________________ Commit: cc7a40b2b54aef5aa6fcc34f4448ecf0fd1bbd5d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cc7a40b2b54aef5aa6fcc34f4448ecf0fd1bbd5d Author: Kevin Bowling (Tue 28 Jul 2026 12:21:14 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:36:51 BST) ixgbe: fix host interface timeout detection The host-interface polling loop was scaled from milliseconds to microseconds, but its terminal test was left using the unscaled timeout. Completion at that intermediate iteration can be reported as a timeout, while actual expiry is not recognized and can accept stale status. Test against the scaled loop bound used by the polling loop. Fixes: f46d75c90f5f ("ixgbe: improve MDIO performance by reducing semaphore/IPC delays") (cherry picked from commit db2bf4553ce32fdcae00f6e7392a6c2010247dd6) M sys/dev/ixgbe/ixgbe_common.c _____________________________________________________________________________________________________________ Commit: 91ddf485200d30df5dfea9caa91604e14c3bcd28 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=91ddf485200d30df5dfea9caa91604e14c3bcd28 Author: Wei Zhao (Tue 28 Jul 2026 12:20:32 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:36:40 BST) ixgbe: disable VF multicast reception for empty list Clear ROMPE for an empty list and enable it only for a nonempty list. FreeBSD already clears ROMPE when resetting a VF, so that part of the DPDK change is not needed. DPDK commit message net/ixgbe: fix over using multicast table for VF VMOLR.ROMPE allows a VF to receive packets matching the shared multicast table. Leaving it enabled after the VF removes its last multicast address lets PF or peer-VF table entries continue selecting that VF. Signed-off-by: Wei Zhao Acked-by: Qi Zhang Obtained from: DPDK (dc5a6e7422) (cherry picked from commit 786c71845f80b8bf733d07f9155de9740a8cbc19) M sys/dev/ixgbe/if_sriov.c _____________________________________________________________________________________________________________ Commit: b1220a1701ecf216f6fe0daa0c056c0fb156bc8c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b1220a1701ecf216f6fe0daa0c056c0fb156bc8c Author: Kevin Bowling (Tue 28 Jul 2026 12:20:08 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:36:28 BST) ixgbe: check negotiated API for VF queue query The GET_QUEUES handler switches on msg[0], which contains the mailbox command rather than the negotiated API version. It therefore cannot reject API 1.0 or an unnegotiated VF as intended. Switch on the API version stored for the VF. (cherry picked from commit 8d1d32942b810d613be45ea78939872711803c3b) M sys/dev/ixgbe/if_sriov.c _____________________________________________________________________________________________________________ Commit: 0169449b2215e07915d6052524887c64831e6c6d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0169449b2215e07915d6052524887c64831e6c6d Author: Kevin Bowling (Tue 28 Jul 2026 12:19:47 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:36:17 BST) ixgbe: reject VF requests before CTS A VF that sends a non-reset request before completing reset negotiation has not received CTS. The PF ignores the request but currently reports success, leaving the VF with a false view of the programmed state. Return failure for the ignored request. This restores the behavior lost when the mailbox helpers were renamed. Fixes: 36c516b31136 ("ixgbe: update if_sriov to use the new mailbox apis") (cherry picked from commit 9fc83caf48e710c3f6457cab4bdb5e6c76e8be51) M sys/dev/ixgbe/if_sriov.c _____________________________________________________________________________________________________________ Commit: 36465977968f8cc5270d25b603e0a03fcae093d2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=36465977968f8cc5270d25b603e0a03fcae093d2 Author: Kevin Bowling (Tue 28 Jul 2026 12:10:09 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:36:04 BST) ixgbe: avoid signed overflow in pause time calculation pause_time is promoted to signed int before multiplication. Its default value of 65535 multiplied by 65537 exceeds INT_MAX and triggers UBSAN, even though the result is assigned to a u32. Make the multiplier unsigned so the calculation has the intended u32 semantics. Linux commit 3b70683fc4d6 reported the failure in the generic path and used the same mechanical correction. The 82598-specific flow control operation contains the identical expression, so correct it as well. (cherry picked from commit 35374c3ec69aa87561431e6236706c485bdeeacc) M sys/dev/ixgbe/ixgbe_82598.c M sys/dev/ixgbe/ixgbe_common.c _____________________________________________________________________________________________________________ Commit: b6bff124973e231237ed8c4df6144b7cb3a81d33 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b6bff124973e231237ed8c4df6144b7cb3a81d33 Author: Kevin Bowling (Tue 28 Jul 2026 12:09:39 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:35:52 BST) ixgbe: fix unaligned access in ixgbe_update_flash_X550() ixgbe_host_interface_command() treats its buffer as a u32 array. The local union contained only byte-sized fields, giving it one-byte stack alignment and allowing unaligned accesses on strict-align systems. Add a u32 member to the union to provide the required alignment and pass that member to ixgbe_host_interface_command(). No functional change is expected on x86. Obtained from: Intel ix 3.4.39 (cherry picked from commit 8fa2a7503468abb5f863729c4e244d738239503d) M sys/dev/ixgbe/ixgbe_type.h M sys/dev/ixgbe/ixgbe_x550.c _____________________________________________________________________________________________________________ Commit: a6c653e32642d4729b5f3200c4c09e002b08799e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a6c653e32642d4729b5f3200c4c09e002b08799e Author: Stephen Douthit (Tue 28 Jul 2026 12:09:02 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:35:42 BST) ixgbe: retry incoherent SFP identifier reads FreeBSD's I2C helper already retries failed transactions. Limit this new outer loop to successful reads with an invalid identifier so that retry budget is not multiplied. DPDK commit message net/ixgbe: retry misbehaving SFP read Some XGS-PON SFPs ACK I2C reads and return uninitialized data while their microcontroller boots. A bogus identifier can cause an otherwise working module to be marked unsupported. Retry the identifier read several times, checking for both successful I2C completion and a valid SFP identifier. Signed-off-by: Stephen Douthit Signed-off-by: Jeff Daly Reviewed-by: Haiyue Wang Obtained from: DPDK (774263bb4e) (cherry picked from commit 985bef0c4474abe8ebc3b0def601db8ceff2a690) M sys/dev/ixgbe/ixgbe_phy.c _____________________________________________________________________________________________________________ Commit: 8be1e05513de1d5f0f159155fbe3bcb0a5f0b8fa URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8be1e05513de1d5f0f159155fbe3bcb0a5f0b8fa Author: Barbara Skobiej (Tue 28 Jul 2026 12:08:12 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:35:30 BST) ixgbe: check EEPROM read in 82599 D3 path DPDK commit message net/ixgbe/base: fix unchecked return value Check the return value from ixgbe_read_eeprom() before using the control word to configure link disable during D3. Fixes: b7ad3713b958 ("ixgbe/base: allow to disable link on D3") Cc: stable@dpdk.org Signed-off-by: Barbara Skobiej Signed-off-by: Anatoly Burakov Acked-by: Bruce Richardson Obtained from: DPDK (eb3684b191) (cherry picked from commit a8598143803d8db60568844cae86b0f330e49a1e) M sys/dev/ixgbe/ixgbe_82599.c _____________________________________________________________________________________________________________ Commit: 44193b7f8e2f814c7777ca8bf7cdac62793011b3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=44193b7f8e2f814c7777ca8bf7cdac62793011b3 Author: Daniil Iskhakov (Tue 28 Jul 2026 12:07:33 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:35:16 BST) ixgbe: avoid flow control counter overflow DPDK commit message net/ixgbe: fix flow control frame byte adjustment LXONTXC and LXOFFTXC are 32-bit counters for transmitted XON and XOFF packets. Their deltas are summed and used to adjust the transmitted packet and byte counters. Perform the addition in 64 bits so it cannot wrap before the result is used for the byte adjustment. Found by Linux Verification Center (linuxtesting.org) with SVACE. Fixes: af75078fece3 ("first public release") Cc: stable@dpdk.org Signed-off-by: Daniil Iskhakov Acked-by: Bruce Richardson Obtained from: DPDK (bdf8608559) (cherry picked from commit 21e03ab39603fbab4bcef1dd61fe75e9e9276079) M sys/dev/ixgbe/if_ix.c _____________________________________________________________________________________________________________ Commit: 9603e94ff5151c1f0250bbad17b1616e0e667cf3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9603e94ff5151c1f0250bbad17b1616e0e667cf3 Author: Dan Nowlin (Tue 28 Jul 2026 12:07:01 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:34:59 BST) ixgbe: copy ACI buffer before command retry DPDK commit message net/ixgbe/base: add missing buffer copy for ACI Add the missing buffer copy in ixgbe_aci_send_cmd(). The retry path saves the original descriptor and allocates storage for the command buffer so both can be restored before another attempt. It did not copy the original command buffer into that storage. Fixes: 25b48e569f2f Cc: stable@dpdk.org Signed-off-by: Dan Nowlin Signed-off-by: Yuan Wang Acked-by: Bruce Richardson Obtained from: DPDK (37239792b0) (cherry picked from commit e45178957d3a25a162279687d82ce791d8253f97) M sys/dev/ixgbe/ixgbe_e610.c _____________________________________________________________________________________________________________ Commit: 8f6561e8adbd07f52278b5a404c72d5c9643b471 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8f6561e8adbd07f52278b5a404c72d5c9643b471 Author: Kevin Bowling (Tue 28 Jul 2026 12:06:23 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:34:24 BST) ixv: fix multicast address enumeration if_foreach_llmaddr() adds each callback return value to its running count. Returning the incremented count made the address indices grow as 0, 1, 3, 7, and so on, eventually writing beyond the multicast address array. Return one address per callback and stop copying when the array is full, matching the ixv-1.6.12 driver. Fixes: ff06a8dbb677 ("Mechanically convert ixgbe(4) to IfAPI") (cherry picked from commit 6020de5ad154d54c8b9a838f28612c2182330c67) M sys/dev/ixgbe/if_ixv.c _____________________________________________________________________________________________________________ Commit: d86590b7713e09b56b8eba990baace27059c458c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d86590b7713e09b56b8eba990baace27059c458c Author: Kevin Bowling (Fri 31 Jul 2026 11:41:02 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:34:12 BST) ixgbe: fail fast on VF-held PF mailboxes The active PF mailbox operations use the legacy helpers. The mailbox API import changed check_for_msg into a read-only probe and added up to 2,000 500-microsecond lock retries. If a VF leaves VFU set, the PF cannot acquire the lock, busy-waits for up to one second, and leaves VFREQ pending so the delay can repeat. Give the legacy checker its old consume-on-check behavior so a failed read does not leave VFREQ asserted. If VFU is already set, fail immediately instead of retrying, while preserving retries for PF-side contention. Do not force RVFU, which would discard peer transaction state. (cherry picked from commit 2a678cfeb5838978ef3a1907c686142d03237e15) M sys/dev/ixgbe/ixgbe_mbx.c _____________________________________________________________________________________________________________ Commit: 15253bd66b15f35afd7515a0dee62d4d6682dab4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=15253bd66b15f35afd7515a0dee62d4d6682dab4 Author: Kevin Bowling (Tue 28 Jul 2026 10:27:24 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:34:00 BST) ixgbe: respect peer mailbox ownership A VF currently treats an existing VFU bit as a successful acquisition, while the PF checks its own PFU bit before claiming the mailbox. Check both the local and peer ownership bits before setting local ownership. This prevents same-side callers from sharing the mailbox and avoids an acquisition attempt while the peer owns it. VFLR does not clear VFMAILBOX.VFU. Clear stale VF ownership and cached mailbox status after the reset indication settles and before sending the reset request, so the ownership check cannot strand a reinitialized VF. Adapt only the live ownership checks from Intel ix 3.4.39. Do not import its upgraded-mailbox changes, which are not active in FreeBSD. Obtained from: Intel ix 3.4.39 (cherry picked from commit 409601911b327426a34a6f28b31fdd5d95d1d275) M sys/dev/ixgbe/ixgbe_mbx.c M sys/dev/ixgbe/ixgbe_vf.c _____________________________________________________________________________________________________________ Commit: 573ae898a731d37b6dea9f4f9fa044b20866372d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=573ae898a731d37b6dea9f4f9fa044b20866372d Author: Kevin Bowling (Tue 28 Jul 2026 10:21:47 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:33:50 BST) ixgbe: isolate VF reset state IXGBE_VF_INDEX() selects a 32-VF register bank. PFMBMEM() selects one mailbox per VF, while ixgbe_toggle_txdctl() calculates queue offsets from a VF number. Passing the bank index aliases VF1-31 to VF0 and VF32-63 to VF1. Resetting one VF can therefore clear the peer mailbox and leave its transmit queues disabled. The VF raises its reset event before posting its mailbox request. The PF checks reset events before mailbox messages. If both are pending, clearing PFMBMEM during generic reset handling can erase the request before ixgbe_read_mbx() consumes it. Clear the mailbox only from the reset-message handler after the request has been read. Use the VF number for queue toggling and document that API contract. (cherry picked from commit 4b67335676b09249c8ef5ea5508655c0b5733618) M sys/dev/ixgbe/if_sriov.c M sys/dev/ixgbe/ixgbe_api.c M sys/dev/ixgbe/ixgbe_api.h M sys/dev/ixgbe/ixgbe_common.c M sys/dev/ixgbe/ixgbe_type.h _____________________________________________________________________________________________________________ Commit: a9d71b76c647575c57d1e008b48f6b203ce184ac URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a9d71b76c647575c57d1e008b48f6b203ce184ac Author: Michael Adler (Thu 9 Jul 2026 18:02:37 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:33:39 BST) igc: Disable ASPM L1.2 on I226 to prevent RX stalls I226 parts advertise support for the PCIe L1.2 link substate, but a hardware erratum makes the exit latency from that low-power state longer than the packet buffer can absorb under load. This stalls the inbound packet stream. Disabling ASPM system-wide (BIOS or OS ASPM policy) does not fix it. The L1.2 enable bit must be cleared directly in the device's own PCIe L1 PM extended capability. Add igc_is_device_id_i226() to identify affected parts and igc_disable_broken_aspm_l1_2() to clear the ASPM L1.2 enable bit on attach and after resume, since PCIe config space can be reset across a suspend/resume cycle. Adapted from the Linux igc driver: 0325143b59c6 igc: disable L1.2 PCI-E link substate to avoid performance issue 1468c1f97cf3 igc: fix disabling L1.2 PCI-E link substate on I226 on init Signed-off-by: Michael Adler PR: 279245 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=279245 ) Reviewed by: Jim Thompson Pull-Request: https://github.com/freebsd/freebsd-src/pull/2318 (cherry picked from commit 9d30fd353dd3eacb095ce98cb9c91ec015b9af64) M sys/dev/igc/if_igc.c M sys/dev/igc/igc_base.c M sys/dev/igc/igc_base.h _____________________________________________________________________________________________________________ Commit: 56cdca658ce721c4651c91bd5dbe5fd6243769a1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=56cdca658ce721c4651c91bd5dbe5fd6243769a1 Author: Michael Adler (Thu 9 Jul 2026 18:00:32 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:33:28 BST) pci: Add L1 PM definitions Add register/bit definitions for the L1 PM substates capability (PCIZ_L1PM) to pcireg.h. Signed-off-by: Michael Adler Pull-Request: https://github.com/freebsd/freebsd-src/pull/2318 (cherry picked from commit 04f8a6aeeba5cbaa48be7134765ee49d5b1b9857) M sys/dev/pci/pcireg.h _____________________________________________________________________________________________________________ Commit: ebb6b8e7e27367437be0248058920023803d9aac URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ebb6b8e7e27367437be0248058920023803d9aac Author: Kevin Bowling (Fri 31 Jul 2026 08:02:22 BST) Committer: Kevin Bowling (Sat 8 Aug 2026 01:33:13 BST) e1000: restrict conventional PCI DMA to 32 bits Some conventional PCI e1000 configurations hang when given DMA addresses above 4 GB, particularly on systems using AMD HyperTransport-to-PCI bridges. Linux has restricted e1000 to DMA32 in PCI mode since 2011 for the same failure class in commit e508be174ad36b0cf9b324cd04978c2b13c21502. Set iflib's DMA width after determining the negotiated bus type. This covers descriptor and packet-buffer mappings while preserving 64-bit DMA for PCI-X and PCIe devices and providing a conditional tunable. PR: 297064 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297064 ) Reported by: Alexander Leidinger Tested by: Alexander Leidinger (cherry picked from commit 41759495769dff87cd4ebbb257d4054128ea5b42) M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 891d63642bafca88914c27130c36487c0bb22b7e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=891d63642bafca88914c27130c36487c0bb22b7e Author: Zhang Qiyue (Sun 12 Jul 2026 07:26:36 BST) Committer: Enji Cooper (Fri 7 Aug 2026 22:32:13 BST) libc: tests: add static to resolve -Wmissing-prototypes The function create_staticobj() is only used inside this translation unit. Clang produces a -Wmissing-prototypes warning during standard buildworld. This warning will become a fatal compile error if MK_WERROR is enabled for hardened builds. PR: 285870 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=285870 ) Fixes: ee9ce1078 ("libc: tests: add some tests for __cxa_atexit...") Signed-off-by: Zhang Qiyue Reviewed-by: ngie Pull-Request: https://github.com/freebsd/freebsd-src/pull/2321 (cherry picked from commit 64038db825d64fb4827fc8ee264ea0fa1a046d82) M lib/libc/tests/stdlib/libatexit/libatexit.cc _____________________________________________________________________________________________________________ Commit: fdd93a36ebf26546cb103a1fad1f4ea54a891f31 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fdd93a36ebf26546cb103a1fad1f4ea54a891f31 Author: Colin Percival (Fri 7 Aug 2026 16:49:49 BST) Committer: Colin Percival (Fri 7 Aug 2026 16:53:28 BST) Revert "release: Ship firmware from kmods repo on DVD" This was a good idea, but we don't build metapackages in the kmods repo so it ends up breaking the release build. I might resurrect this change if/when the kmods repo includes the wifi-firmware-kmod metapackage. This reverts commit bda8028146694ee490543b35e3349e060936fde4. MFC after: 1 second (cherry picked from commit ca0cff79320d49d3f10bd3aa3c472fa450a5c494) M release/pkg_repos/release-dvd.conf M release/scripts/pkg-stage.sh _____________________________________________________________________________________________________________ Commit: c0f892003486548a8f68e86b467b7e84f56b9fe0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c0f892003486548a8f68e86b467b7e84f56b9fe0 Author: Dag-Erling Smørgrav (Tue 4 Aug 2026 10:55:22 BST) Committer: Dag-Erling Smørgrav (Fri 7 Aug 2026 16:46:41 BST) sys/socket.h: Fix AF_MAX AF_MAX was always intended to be one more than the greatest allocated value. Jeff broke this in 2013. Unfortunately, a bunch of people then decided to adapt to the mistake instead of correcting it. Fixes: 863c7e45628d (" - Reserve a special AF for SDP. The one we were incorrectly using before was taken by another AF.") MFC after: 3 days Sponsored by: Klara, Inc. Sponsored by: NetApp, Inc. Reviewed by: kevans, glebius Differential Revision: https://reviews.freebsd.org/D58597 (cherry picked from commit ddd850aa7720f77b6605599655df898b16ed74cc) M lib/libifconfig/libifconfig.c M lib/libifconfig/libifconfig_internal.c M sys/kern/vfs_export.c M sys/net/route.c M sys/net/route/route_ddb.c M sys/net/route/route_helpers.c M sys/net/rtsock.c M sys/netlink/route/rt.c M sys/sys/socket.h _____________________________________________________________________________________________________________ Commit: bcee81bcf1b0599bf90238714440e8b4b5ec39c7 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bcee81bcf1b0599bf90238714440e8b4b5ec39c7 Author: Dag-Erling Smørgrav (Tue 28 Jul 2026 13:08:48 BST) Committer: Dag-Erling Smørgrav (Fri 7 Aug 2026 16:44:36 BST) mbuf: Parenthesize macro arguments MFC after: 1 week Sponsored by: Klara, Inc. Sponsored by: NetApp, Inc. (cherry picked from commit 744cc514567d33d38986f0ff7de009f786acc180) M sys/sys/mbuf.h _____________________________________________________________________________________________________________ Commit: 8ce50d778757766d237d31e2d7fcea611fd3e204 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8ce50d778757766d237d31e2d7fcea611fd3e204 Author: Alexander Ziaee (Tue 4 Aug 2026 15:04:23 BST) Committer: Alexander Ziaee (Fri 7 Aug 2026 15:58:19 BST) manuals: Fix more Fx and nearby mechanical typos Fix compiler warnings related to the Fx macro, as well as all other mechanical typos that were visible within one screenful of them. These cause rendering glitches on various toolchains with various of the five and a half decades of rich output formats and tooling manpages scale to. The *x macro set specifies operating systems. These macros take the rest of the line as an argument. Sometimes, a space was not used to separate the argument of Fx and the trailing period. Others had other parts of the sentence supplied as an argument to Fx. While here, fix the other mechanical typos visible on those specific screenfulls. Correct section typo AUTHOR to AUTHORS, markup utilities with Sy, and apply line break after the end of a sentence. PR: 297248 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297248 ) MFC after: 3 days Reported by: wosch (are you sure that's all of the broken Fx'es?) Fixes: ff2bc641599a ("Fix Fx and nearby mechanical typos") Fixes: d790b16bbf0c ("add man pages for stdbit functions") Fixes: 6c57e368eb17 ("implement C23 memalignment()") Fixes: b06338167d64 ("ROUTE_MPATH and FIB_ALGO") Fixes: 7e1affa242ca ("revise divert-to and divert-reply") (cherry picked from commit 82c013fb59114b228cbc59536914be1c1772c69c) M lib/libc/stdbit/stdc_first_leading_zero.3 M lib/libc/stdlib/memalignment.3 M sbin/route/route.8 M share/man/man5/pf.conf.5 _____________________________________________________________________________________________________________ Commit: 6e8f4f422fea2cfc1a7b524b69be7ee090bdac06 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6e8f4f422fea2cfc1a7b524b69be7ee090bdac06 Author: Alexander Ziaee (Tue 4 Aug 2026 00:31:25 BST) Committer: Alexander Ziaee (Fri 7 Aug 2026 15:58:15 BST) manuals: Fix Fx and nearby mechanical typos Fix compiler warnings related to the Fx macro, as well as all other mechanical typos that were visible within one screenful of them. These cause rendering glitches on various toolchains with various of the five and a half decades of rich output formats and tooling manpages scale to. The *x macro set specifies operating systems. These macros take the rest of the line as an argument. Sometimes, a space was not used to separate the argument of Fx and the trailing period. Another, FreeBSD Foundation was misrepresented as an operating system version instead of an author. Two more had other parts of the sentence supplied as an argument to Fx. While I had those open, fix the other mechancial typos visible on those specific screenfulls. Fix a list width glitch, correct section typo AUTHOR to AUTHORS, and switch AUTHORS sections containing prose to prose-mode so that they wrap freely when rendered. PR: 297248 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297248 ) MFC after: 3 days Fixes: d39e310c7d6a ("man/man3: add stdbit.3") Fixes: d790b16bbf0c ("add man pages for stdbit functions") Fixes: b61850c4e6f6 ("net.link.bridge.member_ifaddrs to false") Reported by: wosch (groff is complaining about incorrect Fx usage) (cherry picked from commit ff2bc641599a7845f597ad02ccfc98c5467fa948) M contrib/elftoolchain/strings/strings.1 M lib/libc/stdbit/stdc_bit_ceil.3 M lib/libc/stdbit/stdc_bit_floor.3 M lib/libc/stdbit/stdc_bit_width.3 M lib/libc/stdbit/stdc_count_ones.3 M lib/libc/stdbit/stdc_count_zeros.3 M lib/libc/stdbit/stdc_first_leading_one.3 M lib/libc/stdbit/stdc_first_leading_zero.3 M lib/libc/stdbit/stdc_first_trailing_one.3 M lib/libc/stdbit/stdc_first_trailing_zero.3 M lib/libc/stdbit/stdc_has_single_bit.3 M lib/libc/stdbit/stdc_leading_ones.3 M lib/libc/stdbit/stdc_leading_zeros.3 M lib/libc/stdbit/stdc_trailing_ones.3 M lib/libc/stdbit/stdc_trailing_zeros.3 M lib/libsys/lio_listio.2 M share/man/man3/stdbit.3 M share/man/man4/bridge.4 M share/man/man4/bxe.4 M share/man/man4/inet.4 M share/man/man4/sume.4 M usr.bin/elfctl/elfctl.1 M usr.bin/ipcrm/ipcrm.1 _____________________________________________________________________________________________________________ Commit: 542c98fba38644b1261bbbfa4816ad53d10b6e72 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=542c98fba38644b1261bbbfa4816ad53d10b6e72 Author: Mark Johnston (Fri 31 Jul 2026 14:13:26 BST) Committer: Mark Johnston (Fri 7 Aug 2026 13:50:56 BST) ppp: Reject invalid endpoint discriminator options Per RFC1717 section 5.1.3, the option length must be at least three. Processing an undersized option would trigger a large out-of-bounds write. PR: 271910 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=271910 ) Reported by: Robert Morris Reported by: Décio Brandão (0xDBJ) Reviewed by: emaste MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58554 (cherry picked from commit b9d07a4308226b683b64827e0aaed1180e0da996) M usr.sbin/ppp/lcp.c _____________________________________________________________________________________________________________ Commit: 2947a48bea3b720e58f3a2e1d6740789e9cc259a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2947a48bea3b720e58f3a2e1d6740789e9cc259a Author: Konstantin Belousov (Thu 30 Jul 2026 10:45:51 BST) Committer: Konstantin Belousov (Fri 7 Aug 2026 11:27:34 BST) amd64: try to fix the build with old clang that does not know about FRED (cherry picked from commit 72952bf6a307391e127d3ab4a6f073664ce62d89) M sys/amd64/amd64/exception.S _____________________________________________________________________________________________________________ Commit: 408031fd85cd72e8f65e5d375272d5a49e2e00ef URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=408031fd85cd72e8f65e5d375272d5a49e2e00ef Author: Mark Johnston (Tue 21 Jul 2026 16:30:56 BST) Committer: Konstantin Belousov (Fri 7 Aug 2026 11:27:33 BST) amd64: Remove a prototype for an unimplemented function (cherry picked from commit f42c68291d6803abc404fa8d6915a9f5de3a3448) M sys/amd64/include/md_var.h _____________________________________________________________________________________________________________ Commit: 9076627050c572736ef8cad0363eca3c993cc8f4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9076627050c572736ef8cad0363eca3c993cc8f4 Author: Mark Johnston (Tue 21 Jul 2026 16:29:33 BST) Committer: Konstantin Belousov (Fri 7 Aug 2026 11:27:33 BST) amd64: Fix an off-by-one in the fred_ipi_handlers definition (cherry picked from commit 55c240eada966b4595cbf93bf0641073713c5b99) M sys/x86/x86/local_apic.c _____________________________________________________________________________________________________________ Commit: 5e1fdbdf938bf452912312ff61a31d75d9ce55d2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5e1fdbdf938bf452912312ff61a31d75d9ce55d2 Author: Konstantin Belousov (Fri 13 Feb 2026 11:24:40 GMT) Committer: Konstantin Belousov (Fri 7 Aug 2026 11:27:33 BST) amd64: FRED support (cherry picked from commit 6e93f5e4d6932c423b89dff8fc08d86f8bdeb7b9) M sys/amd64/amd64/cpu_switch.S M sys/amd64/amd64/db_trace.c M sys/amd64/amd64/exception.S M sys/amd64/amd64/genassym.c M sys/amd64/amd64/initcpu.c M sys/amd64/amd64/machdep.c M sys/amd64/amd64/mp_machdep.c M sys/amd64/amd64/trap.c M sys/amd64/amd64/vm_machdep.c M sys/amd64/include/md_var.h M sys/amd64/include/pcb.h M sys/amd64/vmm/intel/vmx.c M sys/amd64/vmm/vmm.c M sys/amd64/vmm/vmm_lapic.c M sys/amd64/vmm/vmm_lapic.h M sys/dev/hyperv/vmbus/x86/vmbus_x86.c M sys/i386/i386/machdep.c M sys/kern/kern_thread.c M sys/x86/include/apicvar.h M sys/x86/include/frame.h M sys/x86/include/x86_var.h M sys/x86/x86/local_apic.c _____________________________________________________________________________________________________________ Commit: 1203141df81a54d3f80a53650853ab49288d6218 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1203141df81a54d3f80a53650853ab49288d6218 Author: Konstantin Belousov (Thu 21 May 2026 18:37:47 BST) Committer: Konstantin Belousov (Fri 7 Aug 2026 10:27:15 BST) procdesc_exit(): assert that _exit() was called (cherry picked from commit aa1694e23401762c661da11bbf9016a368d37fbe) M sys/kern/sys_procdesc.c _____________________________________________________________________________________________________________ Commit: ef225a9dda66fc4902f1fbbd08fab808d44d8882 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ef225a9dda66fc4902f1fbbd08fab808d44d8882 Author: Konstantin Belousov (Fri 31 Jul 2026 03:04:05 BST) Committer: Konstantin Belousov (Fri 7 Aug 2026 10:27:15 BST) proc_realparent(): do not mark the child as orphan when reparenting to p_opptr pid (cherry picked from commit 833bdae6c58bcede4d9d5e64612b34295558de0b) M sys/kern/kern_exit.c _____________________________________________________________________________________________________________ Commit: af495ad4a98acfb391184c4f16d68e314a3b92e7 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=af495ad4a98acfb391184c4f16d68e314a3b92e7 Author: Konstantin Belousov (Tue 21 Jul 2026 20:54:14 BST) Committer: Konstantin Belousov (Fri 7 Aug 2026 10:27:14 BST) proc_realparent(): assert that an orphaned child has real parent != parent (cherry picked from commit 8cef3c9b768a4a6d63a7754f6a46315532687305) M sys/kern/kern_exit.c _____________________________________________________________________________________________________________ Commit: 6ce4a4dea4df18c1d91d4d5f2d98aa2ff54285d3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6ce4a4dea4df18c1d91d4d5f2d98aa2ff54285d3 Author: Kyle Evans (Sat 1 Aug 2026 04:34:37 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:37:49 BST) stdio: *memstream: grow the buffer by 1.5x on write This improves performance by reducing the number of allocations as we write into the memstream, both in the fully buffered case with larger memstreams and also more trivially in the line- and un-buffered case as they flush back to the underlying buffer more often. The inspiration for this was taken from Apple's implementation in https://github.com/apple-oss-distributions/libc, but expanded to include wmemstream for consistency. I've added a test for the bug that I hit in libder that caused me to notice this in the first place, and fixed that bug in this version. Reviewed by: des, jhb (both slightly previous version) Sponsored by: Klara, Inc. (cherry picked from commit a3a884c0d43ab02187022be9ae9084e6c725ba68) M lib/libc/stdio/open_memstream.c M lib/libc/stdio/open_wmemstream.c M lib/libc/tests/stdio/open_memstream2_test.c M lib/libc/tests/stdio/open_wmemstream_test.c _____________________________________________________________________________________________________________ Commit: 3d29c3a3ec9951ab2b40b9f470f40b24f1f6cfa7 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3d29c3a3ec9951ab2b40b9f470f40b24f1f6cfa7 Author: Kyle Evans (Sat 1 Aug 2026 04:34:37 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:37:43 BST) stdio: *memstream: decouple the buffer size from the stream length It's useful to be able to track both facts with a single variable, but it also makes it more difficult to change how the buffer size scales. As an example, Apple's implementation seems to scale the buffer size by 1.5x on growth, presumably in an attempt to reduce trips into realloc(). This might be questionable in the face of stdio buffering, but avoiding serious churn in the line- or un-buffered case is a net positive if doing so isn't incredibly invasive. Reviewed by: des, jhb, obiwac Sponsored by: Klara, Inc. (cherry picked from commit 781defc7eb061a82b1e3e8dbc6b34993f23e79a6) M lib/libc/stdio/open_memstream.c M lib/libc/stdio/open_wmemstream.c _____________________________________________________________________________________________________________ Commit: c675e0710ea6c3f8608fcb356ea49ae81e0aefd8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c675e0710ea6c3f8608fcb356ea49ae81e0aefd8 Author: Kyle Evans (Sat 1 Aug 2026 04:34:37 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:37:17 BST) stdio: *memstream: slightly streamline growth function Inverting the condition after realloc*() is a minor cleanup, but makes the success path a little cleaner to ease a future change. Reviewed by: des, jhb Sponsored by: Klara, Inc. (cherry picked from commit 28327c58ee6de7ddbdcf0e56352b257d37f2103d) M lib/libc/stdio/open_memstream.c M lib/libc/stdio/open_wmemstream.c _____________________________________________________________________________________________________________ Commit: 10904e0c2b4cc3b5f4c3e46fb22a2e8cf781c977 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=10904e0c2b4cc3b5f4c3e46fb22a2e8cf781c977 Author: Kyle Evans (Tue 21 Jul 2026 17:57:47 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:36:39 BST) hid: u2f: stop interrupts on last-close This fixes an issue with the Solo2 (and likely some of the Nitrokey family) where hangs would occur with OpenSSH- it issues a CANCEL prior to closing the device unconditionally, and without draining the read endpoint we end up seeing the response to that CANCEL the next time OpenSSH tries to connect. This throws the entire command/response sequence out of whack. This call used to break Yubikeys in some situations, but the fix that landed in 28d85db46b48 ("xhci: Do not drop and add bits in xhci") seems to have addressed that- presumably we sometimes end up stopping the command and desyncing at the controller level. This probably implies that we need a SYNCWRITE HID quirk, but that requires a little more work in usbhid_sync_xfer() and this doesn't seem to cause any problems in normal usage. Reviewed by: aokblast, wulf (cherry picked from commit 2e3892671a6fe2bceff6a9d8b439e7acd27dc28a) M sys/dev/hid/u2f.c _____________________________________________________________________________________________________________ Commit: a76cac3a2062d4be107b4dabda0fcdedf71db340 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a76cac3a2062d4be107b4dabda0fcdedf71db340 Author: Kyle Evans (Sun 12 Jul 2026 20:50:24 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:36:24 BST) usbdump: add -t to omit timestamps Matches tcpdump naming, but without getting more intense as you add more -t. This slightly reduces the post-processing needed on usbdump output to diff two transactions. Reviewed by: adrian (cherry picked from commit 87fb416ac8828d07fdf23a2c0d35d88efafce2af) M usr.sbin/usbdump/usbdump.8 M usr.sbin/usbdump/usbdump.c _____________________________________________________________________________________________________________ Commit: 1ce0ad4b3aa51f5f030444c0466ec5c0a47b6c91 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1ce0ad4b3aa51f5f030444c0466ec5c0a47b6c91 Author: Kyle Evans (Sun 12 Jul 2026 15:51:05 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:36:18 BST) rockchip: fix stack overflow in rk8xx_rtc Presumably surfaced by -fstack-protector-strong, rk8xx_settime was triggering SSP when ntpd set the time on the RockPro64, at the very least. A minor oops meant that the weeks mask was getting tossed into the wrong field, and the mask was never populated. The mask is 0x7 for all three of these, thus overflowing the `data` array in settime by one byte. PR: 296719 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296719 ) Reported by: jsm, "Tenkawa" on Discord Reviewed by: mmel (cherry picked from commit d387a43ec8e2663b2d8bc0c8cb02d3a2ff14b6e6) M sys/dev/iicbus/pmic/rockchip/rk805.c M sys/dev/iicbus/pmic/rockchip/rk808.c M sys/dev/iicbus/pmic/rockchip/rk817.c _____________________________________________________________________________________________________________ Commit: 29a68ae63caca205772e570ea6f6045ffb74c912 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=29a68ae63caca205772e570ea6f6045ffb74c912 Author: Kyle Evans (Tue 30 Jun 2026 20:12:10 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:36:14 BST) kern: syscall_thread_enter() cannot fail Attempting to handle the error gracefully can easily result in missing SIGSYS, so this was made to always succeed in 39024a89146 ("syscalls: fix missing SIGSYS for several ENOSYS errors") and returns the nosys entry on failure. Drop the pretense of returning an error and clean up a few dead error paths. Reviewed by: kib, markj (cherry picked from commit eca26803d880060555393ab89b44b967cd467a0e) M sys/kern/kern_sig.c M sys/kern/kern_syscalls.c M sys/kern/subr_syscall.c M sys/sys/sysent.h _____________________________________________________________________________________________________________ Commit: 240bd2eeb21f959f7340402211c0bf43a58d31b5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=240bd2eeb21f959f7340402211c0bf43a58d31b5 Author: Kyle Evans (Tue 30 Jun 2026 17:51:57 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:36:07 BST) evdev: use a prometheus-safe label for ev_sysctl_tree Prometheus doesn't allow spaces, let's normalize this to what we use elsewhere for consistency. The sysctl exporter could probably do this itself, but let's decouple that from the immediate problem: matching the label between the exported data and in-tree is nice for greppability. PR: 296179 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296179 ) Reviewed by: asomers, wulf (cherry picked from commit cb8bda40695f5d402f334f48795b1ab27b72dce5) M sys/dev/evdev/evdev.c _____________________________________________________________________________________________________________ Commit: f58af5d9c538130d5bcdfabe1d94b56f32aa6fff URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f58af5d9c538130d5bcdfabe1d94b56f32aa6fff Author: Kyle Evans (Thu 25 Jun 2026 04:08:05 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:36:03 BST) kern: osd: trash a slot's methods upon deregistration This both lets us quickly identify a slot that's been deallocated while debugging, and forces us to take a fault if something tries to call one of the methods anyways somehow with osd_destructors[slot - 1] == NULL. Reviewed by: imp, jamie (cherry picked from commit 4ffa7e126ed0081b804bda6fb71a60acf49dabda) M sys/kern/kern_osd.c _____________________________________________________________________________________________________________ Commit: 3e0270c52875faefad6ddce7285f8c8047d423ef URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3e0270c52875faefad6ddce7285f8c8047d423ef Author: Kyle Evans (Thu 25 Jun 2026 04:08:05 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:35:54 BST) kern: osd: abstract away the math for locating a slot method It's relatively simple, but we'll do it a couple of times; pull it out into a macro. Reviewed by: imp (previous version), jamie (cherry picked from commit 72ebcfae48c42cb28ab6142980416082f8d70abc) M sys/kern/kern_osd.c _____________________________________________________________________________________________________________ Commit: da9d26a215a644e9e8a31f3c47309f6cce350380 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=da9d26a215a644e9e8a31f3c47309f6cce350380 Author: Kyle Evans (Mon 22 Jun 2026 21:22:25 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:35:30 BST) kern: add a security knob to disable unprivileged access to kenv We sometimes store sensitive things in the kenv that get zapped, but we really shouldn't rely on that zapping to actually happen. Most unprivileged processes don't really need to read from the kernel environment in the first place, so add a knob that allows it to be disabled. Note that we consider jailed root to be unprivileged from this perspective; they have their own meta/env concepts and we should encourage users to take advantage of those for passing information to jails. Relnotes: yes (The capability to disable unpriv access exists) "Hey we should do something about that": dch Reviewed by: imp, ziaee, zlei (all slightly previous version) (cherry picked from commit 4fd518fcb2bbee4c8c41215d6993b923ef57a0e5) M bin/kenv/kenv.1 M lib/libsys/kenv.2 M share/man/man7/security.7 M sys/kern/kern_environment.c M sys/sys/priv.h _____________________________________________________________________________________________________________ Commit: 6834c2660904ef6d1fdade32e2dddda55778b989 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6834c2660904ef6d1fdade32e2dddda55778b989 Author: Kyle Evans (Sat 20 Jun 2026 14:55:26 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:35:25 BST) adjtime(2): document that delta can be NULL The current verbiage somewhat indicates that always adjusts the time, which hasn't been true as far back as I had the energy to `git blame`. Reviewed by: imp (cherry picked from commit 8ed580b1d3811e73e25db3d8a9fd235156c65387) M lib/libsys/adjtime.2 _____________________________________________________________________________________________________________ Commit: 70c07351df58980e768abffd78dea01159391e26 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=70c07351df58980e768abffd78dea01159391e26 Author: Kyle Evans (Sat 20 Jun 2026 14:55:26 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:34:51 BST) rights(4): fix our representation of the unused bits The current format seems to be a little confusing, and the version of it for index 0 was broken by the below-referenced commit. Break our UNUSED macros out into one per unused bit to enumerate the entirety of the space and make it easier to claim an unused one. Fixes: b165e9e3ea4e327fc ("Add fchroot(2)") Reviewed by: oshogbo (previous version), kib, markj (cherry picked from commit 57fefbee1f959d0c65376dbdad309d01c182d710) M sys/sys/capsicum.h _____________________________________________________________________________________________________________ Commit: 2b25a0ebb48dc2340e1e15d1a05b89d7df036b38 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2b25a0ebb48dc2340e1e15d1a05b89d7df036b38 Author: Kyle Evans (Fri 19 Jun 2026 05:03:30 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:34:46 BST) socket: remove tautological condition in so_unsplice() so2rele was introduced in 1000cc4a0d3 and it was necessary there, but the cleanup in a837d1fe49e0255 rendered it redundant if our own KASSERT is to be believed: we've asserted that `so2->so_splice_back == sp` and `sp` has been dereferenced above, so there's no condition left where we shouldn't release the socket reference at the end. Indeed, the change in so_splice() to NULL out sp->dst removes that possible state of a partially constructed splice: if sp->dst is set, it has been ref'd. Reviewed by: gallatin, markj (cherry picked from commit 8a3d28375450946e4b0de239c9239df54c22d298) M sys/kern/uipc_socket.c _____________________________________________________________________________________________________________ Commit: 690207d4efc1560bf3fced49065c1ce621a2c67f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=690207d4efc1560bf3fced49065c1ce621a2c67f Author: Kyle Evans (Wed 17 Jun 2026 23:40:46 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:34:41 BST) build: provide a FORTIFY_SOURCE. override For native files we can do more minimal fixes to avoid this large of a hammer, but for third party files it may not be worth the effort to try and patch them. NetBSD has the original _FORTIFY_SOURCE implementation that ours is based on, for instance, but tests sourced from there can't do an __ssp_real(foo) without being certain that `foo` actually has a fortified definition. This change does always define _FORTIFY_SOURCE as a result, so gate it on CFLAGS not already containing _FORTIFY_SOURCE definitions. This re-applies c46a0b59071614, but without re-defining _FORTIFY_SOURCE needlessly. PR: 294881 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=294881 ) Reviewed by: markj, sjg (both previous version) (cherry picked from commit 13184a69faa700319ab16357cd39708a0e89fc15) M share/mk/bsd.sys.mk _____________________________________________________________________________________________________________ Commit: f7d84c7b3858089def5d91b829118313ee681ce9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f7d84c7b3858089def5d91b829118313ee681ce9 Author: Quentin Thébault (Sun 14 Jun 2026 17:34:51 BST) Committer: Kyle Evans (Fri 7 Aug 2026 00:34:29 BST) evdev: add devnum sysctl Add a sysctl entry for the evdev device number (devnum) to allow libudev-devd to populate the corresponding device information fields (MAJOR and MINOR) when running in a jail with no input devices exposed through devfs. Signed-off-by: Quentin Thébault Reviewed by: wulf Sponsored by: Defenso (cherry picked from commit 746c374aa94b46712e6defb3ab56dd2d6ad8db64) M sys/dev/evdev/evdev.c M sys/dev/evdev/evdev_private.h _____________________________________________________________________________________________________________ Commit: 6db7fa3765aea89329830c892547695e477d3bfc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6db7fa3765aea89329830c892547695e477d3bfc Author: Ed Maste (Tue 21 Jul 2026 20:19:40 BST) Committer: Ed Maste (Thu 6 Aug 2026 23:19:06 BST) loader: Allocate trampoline as EfiLoaderCode, not Data Firmware on a test machine applied NX to non-code allocations, which resulted in a fault when jumping to the trampoline. Reviewed by: kib Tested by: Jim Huang Chen Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58383 (cherry picked from commit 2b1df6149e8a2d50a09d13c64d1574dad91e10b1) M stand/efi/loader/arch/amd64/elf64_freebsd.c _____________________________________________________________________________________________________________ Commit: eb808b3f41d4b24eed9017fe4a79d4cf4c3afe16 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=eb808b3f41d4b24eed9017fe4a79d4cf4c3afe16 Author: Andriy Tkachuk (Tue 28 Jul 2026 23:29:55 BST) Committer: Brian Behlendorf (Thu 6 Aug 2026 22:14:06 BST) arc: add a few invariant checks in release builds Convert a couple ASSERTs invariants to VERIFYs to enforce them in release builds to be able to root-case #18782 kernel panic, whenever it happens again. Reviewed-by: Brian Behlendorf Signed-off-by: Andriy Tkachuk Closes #18840 (cherry picked from commit 023d44b9ef68f1eff6b97d98c6a16cdb4b93cf76) M module/zfs/arc.c _____________________________________________________________________________________________________________ Commit: 6154eec89acb3aa6561f2e8ba365115a8056591d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6154eec89acb3aa6561f2e8ba365115a8056591d Author: Rick Macklem (Tue 4 Aug 2026 16:55:24 BST) Committer: Rick Macklem (Thu 6 Aug 2026 20:46:22 BST) nfs_commonkrpc.c: Get rid of NFSv4.0 delegation cruft Delegations in NFSv4.0 never worked well and, since the NFSv4.0 protocol is now deprecated, use of delegations for NFSv4.0 is disabled as far as the client can do so. It turns out that some Illumos NFSv4.0 server issues delegations anyhow (even when the callback path is specified as 0.0.0.0) and this can cause use after free problems. This patch deleted some cruft that did an nfsrpc_openrpc() call recursively when an NFSv4.0 server failed to issue a delegation when it had previously done so. This code was only meant to be an optimization and would have been rarely exercised. Since this recursive call of nfsrpc_openrpc() is in some of the backtraces in the bugzilla PR, getting rid of the cruft makes sense. It is not known if this helps w.r.t. the use after free problems at this time. PR: 297233 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297233 ) (cherry picked from commit 8f20299b473af6132e0f146d7f634640993aeb81) M sys/fs/nfsclient/nfs_clrpcops.c _____________________________________________________________________________________________________________ Commit: 037232c2001528995d75556c8e2007c686e50134 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=037232c2001528995d75556c8e2007c686e50134 Author: Rick Macklem (Tue 4 Aug 2026 00:57:38 BST) Committer: Rick Macklem (Thu 6 Aug 2026 20:45:02 BST) nfs_commonkrpc.c: Fix recovery that was broken by 4d80d4913e79 Commit 4d80d4913e79 added a check for nfsess_defunct already being set. This was incorrect because, once set, nfsess_defunct remains set and an additional recovery might be needed. This patch reverts this part of 4d80d4913e79. PR: 297252 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297252 ) (cherry picked from commit 5ab48fb9f7ac43fb1242a678312a02df5d4d5b53) M sys/fs/nfs/nfs_commonkrpc.c _____________________________________________________________________________________________________________ Commit: 9facb187c9aa02ced20338bf69c6f6e59ac1030a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9facb187c9aa02ced20338bf69c6f6e59ac1030a Author: Jessica Clarke (Wed 29 Jul 2026 15:09:42 BST) Committer: Jessica Clarke (Thu 6 Aug 2026 19:02:34 BST) link_elf: Make phdrs first page check actually fatal Otherwise we'll print an error but carry on regardless, presumably destined to walk off the end of the mapping. Reported by: thebugfixers@pm.me MFC after: 1 week (cherry picked from commit 1e39a314d870e312f623199e146eda6bdbc293a3) M sys/kern/link_elf.c _____________________________________________________________________________________________________________ Commit: ac26e70f96c0d4acd9b1ece52c8768784f2586f8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ac26e70f96c0d4acd9b1ece52c8768784f2586f8 Author: Jessica Clarke (Tue 28 Jul 2026 12:54:04 BST) Committer: Jessica Clarke (Thu 6 Aug 2026 19:02:34 BST) Merge commit 6b0a46958c56 from llvm-project (by Piotr Kubaj): [libunwind][PPC64] Fix unw_getcontext corrupting callee-saved VSX registers on LE (#198371) This is the first of two independent fixes for libunwind on ppc64le (ELFv2 ABI, little-endian), where two separate bugs together cause SIGSEGV during backtracing. This commit addresses the VSX register corruption; the TOC-restore fault is handled in a follow-up. Both were discovered while debugging lang/rust build failures with RUST_BACKTRACE=1 on FreeBSD/powerpc64le (IBM POWER9). On ppc64le, `unw_getcontext` saves each VS register with an in-place `xxswapd n, n` followed by `stxvd2x`. The swap is needed because `stxvd2x` stores doublewords in the wrong order on LE. However, the macro never applies a second `xxswapd` to restore the register after the store, so all 64 VS registers are permanently corrupted on return from `unw_getcontext`. This affects every callee-saved VSX register: f14-f31 (VSR14-VSR31) and VR20-VR31 (VSR52-VSR63). After `_Unwind_Backtrace` returns, any code that uses these registers sees wrong values. In practice this manifests as SIGSEGV inside hashbrown's `reserve_rehash`: VR20-VR31 are corrupted before a SIMD comparison loop runs, producing an out-of-bounds access. Fix: add a second `xxswapd n, n` after the `stxvd2x` store. Since `xxswapd` is its own inverse, the pair is a no-op on the architectural register while still writing the correctly byte-swapped value to memory. MFC after: 1 week (cherry picked from commit 70509d1d9cba254dfd5b3dd83d8a011b5e125788) M contrib/llvm-project/libunwind/src/UnwindRegistersSave.S _____________________________________________________________________________________________________________ Commit: 310a5a993ac8ffba2edcdb8152688620c2f5e56f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=310a5a993ac8ffba2edcdb8152688620c2f5e56f Author: Jessica Clarke (Mon 27 Jul 2026 17:54:04 BST) Committer: Jessica Clarke (Thu 6 Aug 2026 19:02:32 BST) Merge commit 26bf39cdba0b from llvm-project (by Jessica Clarke): [ELF][PowerPC] Don't assume TOC pointer is valid in IPLT entries (#207555) Unlike normal PLT entries, IPLT entries can be called indirectly even when in PIEs/DSOs, and so there's no guarantee on what's in the TOC pointer register at that time. Therefore we must emit variants of the existing code that work without it, whether r12-relative (playing the same role as MIPS's $25) in the same number of instructions, or first retrieving PC in an i386-like manner, being careful not to clobber LR. On 32-bit PowerPC even direct calls to IPLT entries face the same issue, since we'd use the TOC base of the resolver, which may not be the same as the caller, even within the same object. Normal canonical PLTs still look broken on 64-bit PowerPC as they use the TOC pointer register too, and similarly on 32-bit PowerPC for PIEs. We should probably treat these cases the same as PIE on i386 (except including PDEs for 64-bit PowerPC), where it's an error due to the use of %ebx in PLT entries. Bump LLD_FREEBSD_VERSION for this fix as otherwise an existing system linker will be deemed new enough to use and produce broken kernels for TARGET=powerpc (regardless of TARGET_ARCH/MACHINE/MACHINE_ARCH) builds. PR: 294369 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=294369 ) MFC after: 1 week (cherry picked from commit b68f2fe1932cbc9809245e2c5a2db2bc0944cc5d) M contrib/llvm-project/lld/ELF/Arch/PPC.cpp M contrib/llvm-project/lld/ELF/Arch/PPC64.cpp M contrib/llvm-project/lld/ELF/Thunks.cpp M contrib/llvm-project/lld/ELF/Thunks.h M lib/clang/include/lld/Common/Version.inc _____________________________________________________________________________________________________________ Commit: bf61c2737559aad0f00c7e7a2e7c75b0c472979c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bf61c2737559aad0f00c7e7a2e7c75b0c472979c Author: Jessica Clarke (Mon 27 Jul 2026 17:53:53 BST) Committer: Jessica Clarke (Thu 6 Aug 2026 19:02:04 BST) Merge commit cbf48349e3e1 from llvm-project (by Jessica Clarke): [NFC][ELF][PPC64] Pass address not offset to writePPC64LoadAndBranch (#212275) Every caller currently subtracts the TOC base in its argument, so move that into common code inside writePPC64LoadAndBranch. This will also allow a different computation to be used in some cases in a future commit. Note that offset is now unsigned not signed; even previously, all arguments were uint64_t, and all uses are unsigned, so making it signed doesn't make much sense. MFC after: 1 week (cherry picked from commit bcbcd7303009344dc1051e4601284620bca29be8) M contrib/llvm-project/lld/ELF/Arch/PPC64.cpp M contrib/llvm-project/lld/ELF/Thunks.cpp M contrib/llvm-project/lld/ELF/Thunks.h _____________________________________________________________________________________________________________ Commit: 6184b31972ff8cb3e93d5618c73744f0687efcc4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6184b31972ff8cb3e93d5618c73744f0687efcc4 Author: Jessica Clarke (Sat 18 Jul 2026 00:57:15 BST) Committer: Jessica Clarke (Thu 6 Aug 2026 19:02:04 BST) arm64/vmm: Fix vgic_v3 dropping EOI for disabled IRQs Now that IRQs can properly be disabled by GICD_ICENABLERn, an EOI for a disabled IRQ ends up being lost, since we don't assign it to a list register and don't enable maintenance interrupts for such cases. As a result, we keep the IRQ active, which stops it from ever being delivered again (which would be true even if we supported the active and pending state). Keep disabled but active IRQs around in list registers so we can see the EOI having taken place in a future sync (noting that since we already don't create list registers in active and pending state there are no concerns with causing a disabled IRQ to be delivered). Fixes: 47e073941f4e ("Import the kernel parts of bhyve/arm64") MFC after: 1 week (cherry picked from commit 123dfd378959aecc97cfc1d9b457453194d6f25b) M sys/arm64/vmm/io/vgic_v3.c _____________________________________________________________________________________________________________ Commit: b029b0d0e69c10ad8a4d0830fcf09bc2017f8970 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b029b0d0e69c10ad8a4d0830fcf09bc2017f8970 Author: Jessica Clarke (Sat 18 Jul 2026 00:55:21 BST) Committer: Jessica Clarke (Thu 6 Aug 2026 19:02:04 BST) arm64/vmm: Fix vgic_v3 copy paste error for writing to GICD_ICENABLERn Otherwise we try to disable the wrong IRQ. Fixes: 47e073941f4e ("Import the kernel parts of bhyve/arm64") MFC after: 1 week (cherry picked from commit 422a530c80080f2585ecefe812d609079b851fe3) M sys/arm64/vmm/io/vgic_v3.c _____________________________________________________________________________________________________________ Commit: 560cf46476e0538f75e8aea4d2ab3a8291dc3e1f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=560cf46476e0538f75e8aea4d2ab3a8291dc3e1f Author: Jessica Clarke (Mon 6 Jul 2026 17:25:48 BST) Committer: Jessica Clarke (Thu 6 Aug 2026 19:02:04 BST) libllvmminimal: Fix building with LLVM < 21 on riscv64 On most architectures we end up not needing ABIBreak.cpp as, although some of the sources here do reference EnableABIBreakingChecks (or, if assertions are disabled, DisableABIBreakingChecks) at a source level, we compile with -ffunction-sections and -fdata-sections, and link with --gc-sections, and it happens to be the case that all references can be GC'ed. However, prior to LLVM 21, the RISC-V backend did not apply -fdata-sections to .sdata, where references to these symbols end up, and for some files we're building with such references we end up not being able to GC .sdata due to the other unrelated data in it, meaning that we do in fact need to build ABIBreak.cpp. Whilst we could make this conditional on the architecture, it's a tiny file, and it's a bit fragile to rely on GC behaviour, so just include it unconditionally. Reviewed by: dim, emaste Fixes: 770cf0a5f02d ("Fixups after llvm-project main llvmorg-21-init-19288-gface93e724f4 merge") MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D58044 (cherry picked from commit 7a0b9e30a5ba07066caffba51fa82ca3782a5da1) M lib/clang/libllvmminimal/Makefile _____________________________________________________________________________________________________________ Commit: 52fcb9a9126e501f52f4aed6dcaa0f9df950a9ee URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=52fcb9a9126e501f52f4aed6dcaa0f9df950a9ee Author: Jessica Clarke (Fri 1 May 2026 17:55:28 BST) Committer: Jessica Clarke (Thu 6 Aug 2026 19:02:04 BST) lib/clang: Fix bootstrapping on macOS after LLVM 21 merge Fixes: 770cf0a5f02d ("Fixups after llvm-project main llvmorg-21-init-19288-gface93e724f4 merge") MFC after: 1 month (cherry picked from commit 50bd6ee0cce9d3959828b0267b06ea0403781f41) M lib/clang/include/llvm/Config/config.h _____________________________________________________________________________________________________________ Commit: 998989431213c4d98cc3df87a3e0efe5378641e6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=998989431213c4d98cc3df87a3e0efe5378641e6 Author: Mark Johnston (Thu 6 Aug 2026 17:22:11 BST) Committer: Mark Johnston (Thu 6 Aug 2026 17:23:08 BST) vm: Remove a reference to an undefined memattr This is a direct commit to stable/15. Reported by: jenkins Fixes: c4ea6b08e24e ("vm_phys: Add a sysctl to dump registered fictitious memory ranges") M sys/arm64/include/vm.h _____________________________________________________________________________________________________________ Commit: 7f1009d61c3e70b34af749d4d7f21c5e152b3baf URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7f1009d61c3e70b34af749d4d7f21c5e152b3baf Author: Pouria Mousavizadeh Tehrani (Fri 17 Jul 2026 17:11:42 BST) Committer: Bojan Novković (Thu 6 Aug 2026 17:18:25 BST) net/if.c: Add fib-aware ifa_ifwithaddr() Add FIB selection logic by introducing ifa_ifwithaddr_fib() to support FIB-specific lookups. Then have ifa_ifwithaddr() wrap it with RT_ALL_FIBS. Also, do the same for ifa_ifwithaddr_check(). Reviewed by: glebius, bnovkov Differential Revision: https://reviews.freebsd.org/D58305 (cherry picked from commit b00d30950cde27eda8f51523a40f2c05a38daac1) M sys/net/if.c M sys/net/if_var.h _____________________________________________________________________________________________________________ Commit: 978b9026b01852bc78289fd2c8c747c78441b5f1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=978b9026b01852bc78289fd2c8c747c78441b5f1 Author: Bojan Novković (Wed 15 Jul 2026 14:47:01 BST) Committer: Bojan Novković (Thu 6 Aug 2026 16:25:24 BST) bind(2): Lookup local address in current FIB if '*.bind_all_fibs' is active When a protocol-specific 'bind_all_fibs' tunable is set to 0, a listening socket will only receive traffic originating from the FIB it was bound to. However, there are no checks to determine whether an address exists in the target FIB when binding the socket, which can lead to a situation where a socket and the address it was bound to belong to different FIBs. Prevent this footgun by looking up the requested address in the current FIB if 'bind_all_fibs' is active and returning an error if the address does not exist. Sponsored by: Stormshield Sponsored by: Klara, Inc. Differential Revision: https://reviews.freebsd.org/D58281 Reviewed by: glebius, pouria, markj MFC after: 2 weeks (cherry picked from commit 948ad32ae1e0811f45e1d38f26636fefed5051f0) M sys/netinet/in_pcb.c M sys/netinet/raw_ip.c M sys/netinet6/in6_pcb.c M sys/netinet6/raw_ip6.c M tests/sys/netinet/Makefile A tests/sys/netinet/fib_bind.py _____________________________________________________________________________________________________________ Commit: 78dfadaa0618e8b261e813f13f563563dd0ee535 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=78dfadaa0618e8b261e813f13f563563dd0ee535 Author: Mark Johnston (Mon 3 Aug 2026 16:18:25 BST) Committer: Mark Johnston (Thu 6 Aug 2026 14:24:43 BST) ppp: Avoid overflow when formatting endpoint discriminator options Each byte of the address is represented by a pair of characters, so we should be multiplying len by 2 when figuring out how much buffer space we have. Previously, a sufficiently large option could cause an overflow of the global "result" buffer. Reported by: Joshua Rogers Tested by: Décio Brandão (0xDBJ) MFC after: 3 days Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58555 (cherry picked from commit e004ff15f87e6aa8f2aa13cd5600ae13457b95f1) M usr.sbin/ppp/mp.c _____________________________________________________________________________________________________________ Commit: c68c7059a586f05e725255234fac37ba1c89668d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c68c7059a586f05e725255234fac37ba1c89668d Author: Mark Johnston (Wed 29 Jul 2026 14:19:08 BST) Committer: Mark Johnston (Thu 6 Aug 2026 14:24:43 BST) ipsec: Fix a lock leak in ipsec_chkreplay() Reported by: Chris Jarrett-Davies of the OpenAI Codex Security Team Reviewed by: pouria, kp Fixes: 0361f165f219 ("ipsec: replace SECASVAR mtx by rmlock") MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58521 (cherry picked from commit b6823a973737f06ea6cf0ea5a3083383af2ba5a4) M sys/netipsec/ipsec.c _____________________________________________________________________________________________________________ Commit: 9d2e5039ee18eb9545b26a8934e650c1f06139cb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9d2e5039ee18eb9545b26a8934e650c1f06139cb Author: Mark Johnston (Wed 29 Jul 2026 19:45:36 BST) Committer: Mark Johnston (Thu 6 Aug 2026 14:24:43 BST) ktls: Propagate EPG_FLAG_ANON to mapped mbufs Otherwise ktls_mbuf_crypto_state() will reject mbufs created by _mb_unmapped_to_ext(), which arises when transmitting packets through an interface that doesn't support unmapped mbufs, and the loopback interface in particular. PR: 296498 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296498 ) Fixes: 3444414cb463 ("ktls: Don't attempt to modify non-anonymous mbufs on the receive path") Reviewed by: gallatin, jhb MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57557 (cherry picked from commit 815976ee14121bafe8a8ab002459d32f8928f2de) M sys/kern/kern_mbuf.c M sys/kern/uipc_ktls.c M sys/sys/mbuf.h _____________________________________________________________________________________________________________ Commit: 096b8244dad4b1af6665fc22a2065a1df2ea5fa1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=096b8244dad4b1af6665fc22a2065a1df2ea5fa1 Author: Mark Johnston (Sun 19 Jul 2026 15:09:27 BST) Committer: Mark Johnston (Thu 6 Aug 2026 14:24:43 BST) vm: Make sure NULL is defined for vm_memattr_name() Fixes: a7e483ee146a ("vm_phys: Add a sysctl to dump registered fictitious memory ranges") (cherry picked from commit 11edc985cd9c2e1dcceccb7e929c6921b4e20c9b) M sys/amd64/include/vm.h M sys/arm/include/vm.h M sys/arm64/include/vm.h M sys/i386/include/vm.h M sys/powerpc/include/vm.h M sys/riscv/include/vm.h _____________________________________________________________________________________________________________ Commit: 9cc432da231b6fd977954df806dd0e003cbbe088 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9cc432da231b6fd977954df806dd0e003cbbe088 Author: Mark Johnston (Sun 19 Jul 2026 03:33:08 BST) Committer: Mark Johnston (Thu 6 Aug 2026 14:24:43 BST) arm64: Fix the build Fixes: a7e483ee146a ("vm_phys: Add a sysctl to dump registered fictitious memory ranges") (cherry picked from commit 91b419bc7e15f2138cb211c4d7c5be118c377c20) M sys/arm64/include/vm.h _____________________________________________________________________________________________________________ Commit: c4ea6b08e24e23302f0910b0ec3cf3fc1038143f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c4ea6b08e24e23302f0910b0ec3cf3fc1038143f Author: Mark Johnston (Sun 19 Jul 2026 01:29:40 BST) Committer: Mark Johnston (Thu 6 Aug 2026 14:24:43 BST) vm_phys: Add a sysctl to dump registered fictitious memory ranges I've wanted this a couple of times in the past. Save the memattr in the fictitious memory segment structure so that we can report it from the sysctl handler, and add conversion routines for each platform. Reviewed by: kib MFC after: 2 weeks Differential Revision: https://reviews.freebsd.org/D58283 (cherry picked from commit a7e483ee146a93ac89357676fdb9af62ac58b4bc) M sys/amd64/include/vm.h M sys/arm/include/vm.h M sys/arm64/include/vm.h M sys/i386/include/vm.h M sys/powerpc/include/vm.h M sys/riscv/include/vm.h M sys/vm/vm_phys.c _____________________________________________________________________________________________________________ Commit: 1ede9ecfe61017cc28ebeb4e65506ed0efa59408 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1ede9ecfe61017cc28ebeb4e65506ed0efa59408 Author: Mark Johnston (Wed 29 Jul 2026 13:43:55 BST) Committer: Mark Johnston (Thu 6 Aug 2026 14:24:43 BST) kqueue: Associate marker knotes with a queue Otherwise the assertion in KQ_FLUX_SLEEP_WMESG may fail. kqueue_fork_copy() already handles this. Fixes: 1f4b0ea4f3eb ("kqueue: Add a helper macro for sleeping on in-flux knotes") Reported by: syzkaller Reported by: kbowling Reviewed by: kib Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58516 (cherry picked from commit 9a9349ea1da2d80e979fa87b430551d8f6dac7f4) M sys/kern/kern_event.c _____________________________________________________________________________________________________________ Commit: 31d9493fbb2c7e38dc151bce30a4cd26efa680ae URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=31d9493fbb2c7e38dc151bce30a4cd26efa680ae Author: Mark Johnston (Tue 28 Jul 2026 00:12:16 BST) Committer: Mark Johnston (Thu 6 Aug 2026 14:24:43 BST) kqueue: Add a helper macro for sleeping on in-flux knotes Other in-flux operations are implemented by this set of macros, so we should do the same for sleeping. No functional change intended. Reviewed by: kib MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58443 (cherry picked from commit 1f4b0ea4f3eb1b8a885eff8bd0d332156f0c3e1f) M sys/kern/kern_event.c _____________________________________________________________________________________________________________ Commit: b35a7db4829ab9826bc428fc3ceaa766bbc0f519 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b35a7db4829ab9826bc428fc3ceaa766bbc0f519 Author: Mark Johnston (Fri 24 Jul 2026 21:06:40 BST) Committer: Mark Johnston (Thu 6 Aug 2026 14:24:42 BST) kqueue: Allocate marker knotes on the stack The scan marker was originally stack-allocated. In commit 1c0f9af5b5224, it became heap-allocated since the marker is visible to other threads and a scanning thread's stack may be swapped out. Now that kernel stacks can no longer be swapped out, we can avoid these heap allocations. Reviewed by: kib MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58402 (cherry picked from commit bb933b1d1846b3a984670b8cd65450c3333188f6) M sys/kern/kern_event.c _____________________________________________________________________________________________________________ Commit: 31765e2322398b83805b9f491ef0ff1f1939dc77 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=31765e2322398b83805b9f491ef0ff1f1939dc77 Author: Mark Johnston (Mon 27 Jul 2026 20:00:49 BST) Committer: Mark Johnston (Thu 6 Aug 2026 14:24:42 BST) rpcinfo: Fix residual warnings and bump WARNS Reviewed by: emaste MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58442 (cherry picked from commit 95a3301ce144aecce5de88fb4e2905c440533fb8) M usr.bin/rpcinfo/Makefile M usr.bin/rpcinfo/rpcinfo.c _____________________________________________________________________________________________________________ Commit: 3101f41273440ba869626b472ae84b14fc4dc7a9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3101f41273440ba869626b472ae84b14fc4dc7a9 Author: Mark Johnston (Mon 27 Jul 2026 19:59:08 BST) Committer: Mark Johnston (Thu 6 Aug 2026 13:52:28 BST) rpcinfo: Fix buffer overflows Several functions were using sprintf() to write RPC server-controlled data to a stack buffer. Adopt some minimal changes from NetBSD to avoid the potential overflows. Security: CVE-2026-16277 Security: CVE-2026-16461 Reviewed by: khorben MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58441 (cherry picked from commit 152ba2d3c5ff00382260a48653855072d524cfb8) M usr.bin/rpcinfo/rpcinfo.c _____________________________________________________________________________________________________________ Commit: fd58b2ba0910c2442b91025e3c495ef3289f429d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fd58b2ba0910c2442b91025e3c495ef3289f429d Author: Mark Johnston (Fri 24 Jul 2026 21:05:06 BST) Committer: Mark Johnston (Thu 6 Aug 2026 13:52:28 BST) netinet6/nd6: Sprinkle missing prefix refcounting When we drop the prefix lock to call nd6_prefix_offlink() or nd6_prefix_onlink(), make sure to keep the correpsonding prefix structure alive. It is possible for a concurrent nd6_timer() to expire the prefix while the lock is dropped. Reported by: Maik Muench of Secfault Security Reviewed by: pouria, zlei MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58423 (cherry picked from commit 76ca489e0f147e9bd90408ea562087e84ed6f479) M sys/netinet6/nd6_rtr.c _____________________________________________________________________________________________________________ Commit: ffad04235a767852aaac3f1fce673a9c78c2753b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ffad04235a767852aaac3f1fce673a9c78c2753b Author: Mark Johnston (Fri 10 Jul 2026 21:25:54 BST) Committer: Mark Johnston (Thu 6 Aug 2026 13:52:28 BST) syslogd: Limit rights on procdescs Reviewed by: jfree, kib MFC after: 3 weeks Differential Revision: https://reviews.freebsd.org/D58160 (cherry picked from commit 24816abb8740c387ad4aba4ad2fa4c23b191c351) M usr.sbin/syslogd/syslogd.c _____________________________________________________________________________________________________________ Commit: 30758138f2e36d89bc30cb686796ccc4dfa8b475 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=30758138f2e36d89bc30cb686796ccc4dfa8b475 Author: Mark Johnston (Fri 24 Jul 2026 21:06:05 BST) Committer: Mark Johnston (Thu 6 Aug 2026 13:52:28 BST) unix: Preserve FD_RESOLVE_BENEATH when passing an fd The FD_RESOLVE_BENEATH flag is supposed to be sticky. It's set when you receive an fd from a different jail and preserved by openat() etc.. However, if you send the fd to yourself, the flag is stripped since SCM_RIGHTS message don't preserve file descriptor flags. Fix this by preserving those flags and checking for UF_RESOLVE_BENEATH in restrict_rights(). Fixes: 350ba9672a7f ("unix: Set O_RESOLVE_BENEATH on fds transferred between jails") Reviewed by: kib MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58317 (cherry picked from commit 586e2b3d89d6e70ab7e4a88497b5f36d78719423) M sys/kern/uipc_usrreq.c M tests/sys/kern/unix_passfd_test.c _____________________________________________________________________________________________________________ Commit: 73b576abf509f1cb057954937dd2809a5ba7a2dc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=73b576abf509f1cb057954937dd2809a5ba7a2dc Author: Mark Johnston (Fri 24 Jul 2026 21:04:45 BST) Committer: Mark Johnston (Thu 6 Aug 2026 13:52:28 BST) kthread: Fix a thread leak Fixes: 963629923308 ("kthread_add(): do not allow to attach the thread to a dead or dying process") Reviewed by: kib MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58433 (cherry picked from commit c7917e72fe80e2e168b3812718b5fcd497c0e3b8) M sys/kern/kern_kthread.c _____________________________________________________________________________________________________________ Commit: e1070148f676876e224e63502dc51b69358aea33 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e1070148f676876e224e63502dc51b69358aea33 Author: Mark Johnston (Wed 15 Jul 2026 15:59:22 BST) Committer: Mark Johnston (Thu 6 Aug 2026 13:52:28 BST) linker: Recognize SHT_INIT_ARRAY sections as constructor sections We do this already for ET_REL files, but it was missed here. Note that this function operates only on dynamically loaded files, not on preloaded files. Reviewed by: kib MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58245 (cherry picked from commit 83181995593ac61796d7be63dcb241f5d80faa73) M sys/kern/link_elf.c _____________________________________________________________________________________________________________ Commit: 984a3970b16fd603bba7554b4a4c7449550bd5cb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=984a3970b16fd603bba7554b4a4c7449550bd5cb Author: Mark Johnston (Wed 15 Jul 2026 15:58:32 BST) Committer: Mark Johnston (Thu 6 Aug 2026 13:52:28 BST) stand: Recognize SHT_INIT_ARRAY sections as constructor sections Pass such a section to the kernel using modinfo, otherwise link_elf.c won't execute constructors for the file. This is required for KASAN, otherwise redzones for global buffers are not poisoned during boot. Reviewed by: kib MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58244 (cherry picked from commit 4b0ae7e001a97e5449835bb8a2e6c2e6f53aac39) M stand/common/load_elf.c _____________________________________________________________________________________________________________ Commit: 7eb4c67be503176d4824d8eaccd70ae942569e54 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7eb4c67be503176d4824d8eaccd70ae942569e54 Author: Mark Johnston (Wed 22 Jul 2026 01:17:56 BST) Committer: Mark Johnston (Thu 6 Aug 2026 13:52:27 BST) loader: Fix error handling after an allocation failure MFC after: 1 week (cherry picked from commit 5001af647b3b263aeb3d4fa7a6c2690399265202) M stand/efi/loader/arch/amd64/elf64_freebsd.c _____________________________________________________________________________________________________________ Commit: f1cf1447e56a5998c7e6db1b9668c4da77911be4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f1cf1447e56a5998c7e6db1b9668c4da77911be4 Author: Mark Johnston (Tue 21 Jul 2026 23:30:53 BST) Committer: Mark Johnston (Thu 6 Aug 2026 13:52:27 BST) exec: Avoid overflow when computing the size of the exec map On a test system with 1024 cores the size of exec map exceeds 4GB, and all of the operands in the size calculation are 32-bit integers. Tested by: Jim Huang Chen MFC after: 1 week Sponsored by: AMD (hardware) (cherry picked from commit 2efe148a2a321d4c9ed46bdb166f710b2cb21529) M sys/vm/vm_init.c _____________________________________________________________________________________________________________ Commit: 9ac39192d49643def7958961e4a55f9f9d4b0c11 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9ac39192d49643def7958961e4a55f9f9d4b0c11 Author: Michael Tuexen (Mon 3 Aug 2026 12:07:32 BST) Committer: Michael Tuexen (Thu 6 Aug 2026 10:07:41 BST) tcp: improve SEG.SEQ validation for RST segments A RST segment can be sent in response to (a) received segment or (b) by the upper layer protocol. The SEG.SEQ validation consists of two checks: (1) the in-window check of SEG.SEQ and (2) the exact match check of SEG.SEQ. For the in-window check (1), the left edge of the window needs to be based on tp->last_ack_sent to cover the delayed ACK case, whereas the right edge needs to be based on tp->rcv_nxt + tp->rcv_wnd. This both assumes that tp->rcv_wnd is not zero. For the special case of tp->rcv_wnd being zero, add checks against tp->last_ack_sent for (a) and on tp->rcv_nxt for (b). This applies to all TCP stacks. When the exact match (2) of SEG.SEQ is performed, it should be based on tp->last_ack_sent for (a) and on tp->rcv_nxt for (b). To cover both, check for both. Add this only to the base stack, since the RACK and BBR stacks already do this. PR: 296594 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296594 ) Reviewed by: rscheff Sponsored by: Netflix, Inc. Differential Revision: https://reviews.freebsd.org/D58594 (cherry picked from commit c9df1a6cf9be9d44eacc8616ebba1cd19010c7fc) M sys/netinet/tcp_input.c M sys/netinet/tcp_stacks/rack_bbr_common.c _____________________________________________________________________________________________________________ Commit: e8d1cee437414dd9bb3c779ff0a0c234fb7d411e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e8d1cee437414dd9bb3c779ff0a0c234fb7d411e Author: Michael Tuexen (Tue 28 Jul 2026 21:15:22 BST) Committer: Michael Tuexen (Thu 6 Aug 2026 10:07:02 BST) tcp: improve handling of stopped timers When a TCP timer is stopped, t_timers[] is set to SBT_MAX. Adding the corresponding t_precisions[], if it is not zero, would result in overflows in tcp_timer_next(). To avoid this, skip stopped timers. The problem was identified while debugging uperf by Lukas Book and an initial patch was provided by him. The committed patch was suggested by glebius. The problem can be observed by running netstat -nxptcp and looking for negative timer values and by observing very long running timers in some cases. Reported by: Lukas Book Reviewed by: glebius Differential Revision: https://reviews.freebsd.org/D58484 (cherry picked from commit 52b7cbcb78c14e89f6faec8da5acc2caa3d37208) M sys/netinet/tcp_timer.c _____________________________________________________________________________________________________________ Commit: cad0d577251632bc9c7f808121ea9b0220474dbd URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cad0d577251632bc9c7f808121ea9b0220474dbd Author: Michael Tuexen (Wed 1 Jul 2026 17:07:04 BST) Committer: Michael Tuexen (Thu 6 Aug 2026 10:05:08 BST) tests: fix checksum computation This fixes an endianness bug in sys/netinet/ip_reass_test. Just use the code from RFC 1071. Reported by: glebius Reviewed by: glebius, Timo Völker Sponsored by: Netflix, Inc. Differential Revision: https://reviews.freebsd.org/D57988 (cherry picked from commit fbc039e512c3bb1635ad20cc8f70ad608ea818b7) M tests/sys/netinet/ip_reass_test.c _____________________________________________________________________________________________________________ Commit: a2d2f7a97074fe72c165e792d0590afcac64d7f3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a2d2f7a97074fe72c165e792d0590afcac64d7f3 Author: Timo Völker (Mon 29 Jun 2026 21:03:46 BST) Committer: Michael Tuexen (Thu 6 Aug 2026 10:04:24 BST) loopback: use new names for checksum offloading flags No functional change intended. Reviewed by: tuexen Differential Revision: https://reviews.freebsd.org/D57945 (cherry picked from commit bcf4e3c001f5ec9cc206b0d81f0954559d1424d8) M sys/net/if_loop.c _____________________________________________________________________________________________________________ Commit: a5423ccd1c26e8558ee9af47086b57189875a066 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a5423ccd1c26e8558ee9af47086b57189875a066 Author: Jana Smith (Sun 28 Jun 2026 12:04:05 BST) Committer: Michael Tuexen (Thu 6 Aug 2026 10:03:36 BST) rack_bbr_common: don't use stale pointer after m_pullup() Reviewed by: tuexen Differential Revision: https://reviews.freebsd.org/D57816 (cherry picked from commit be23edc1e4028e32a46e8fe7118de787fd5d79a2) M sys/netinet/tcp_stacks/rack_bbr_common.c _____________________________________________________________________________________________________________ Commit: 265b3e15abf62089a830a3bd07ef79f6a9ad44b3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=265b3e15abf62089a830a3bd07ef79f6a9ad44b3 Author: Timo Völker (Sun 28 Jun 2026 11:50:15 BST) Committer: Michael Tuexen (Thu 6 Aug 2026 10:02:40 BST) loopback: improve checksum offloading * Allow disabling IFCAP_RXCSUM_IPV6 or IFCAP_TXCSUM_IPV6. * Do not pretend the checksum is correct by setting the LO_CSUM_SET flags if IFCAP_RXCSUM_IPV6 or IFCAP_RXCSUM is enabled. Instead, remove the LO_CSUM_SET flags (in case they have been set somehow) if IFCAP_RXCSUM_IPV6 or IFCAP_RXCSUM is disabled. * Do not unset the transmit checksum offload flags LO_CSUM_FEATURES or LO_CSUM_FEATURES6 since they now have a meaning for the receive path. Reviewed by: glebius, pouria, tuexen Okayed by: bz Differential Revision: https://reviews.freebsd.org/D57518 (cherry picked from commit d6c4cea7740d5c5c673a06ba37e4f1bdcddb2ece) M share/man/man4/lo.4 M sys/net/if_loop.c _____________________________________________________________________________________________________________ Commit: f059fcf3d1d85562ff21a348fec0573aa76d3648 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f059fcf3d1d85562ff21a348fec0573aa76d3648 Author: Timo Völker (Sun 28 Jun 2026 11:39:10 BST) Committer: Michael Tuexen (Thu 6 Aug 2026 10:02:00 BST) virtio_pci_modern: Remove endianness conversion for config space The bus_* functions already handle converting from PCI endianness (i.e. little-endian) to native endianness when accessing the config space (see ofw_pcib_bus_get_bus_tag), so converting again with virtio_htogX/virtio_gtohX undoes any byte-swapping and breaks big-endian systems. They should only be used for operating on shared memory. Note part of this reverts commit fb53b42e36a9 ("virtio-modern: fix PCI common read/write functions on big endian targets"). PR: 294706 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=294706 ) Reviewed by: adrian, tuexen Fixes: fb53b42e36a9 ("virtio-modern: fix PCI common read/write functions on big endian targets") Fixes: 9da9560c4dd3 ("virtio: Add VirtIO PCI modern (V1) support") Differential Revision: https://reviews.freebsd.org/D57392 (cherry picked from commit 07b5d1ca52b113cecad3cda73ff5e782d8f4d07d) M sys/dev/virtio/pci/virtio_pci_modern.c _____________________________________________________________________________________________________________ Commit: 9f49131806eb77e35934699654b74d378fe20f0e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9f49131806eb77e35934699654b74d378fe20f0e Author: Michael Tuexen (Wed 17 Jun 2026 14:46:56 BST) Committer: Michael Tuexen (Thu 6 Aug 2026 10:01:46 BST) tcp: cleanup resource handling in SYN handling Handle cred, ipopts, and maclabel using the same pattern: allocate at the beginning and set to NULL when the object is transferred to a struct syncache. When exiting the function, free these objects if not transferred or when transferred to the on-stack struct syncache. This makes use of a new function syncache_release(). This fixes a use after free problem: ipopts should only be freed, if the on-stack struct syncache is used and the pointer in this structure still points to the allocated ipopts. If the ipopts are moved from the struct syncache to the struct inpcb in syncache_socket(), which is called by syncache_tfo_expand(), the pointer in the struct syncache is set to NULL. In a FreeBSD default setup this problem is mitigated by 1. TCP fast open support on the server side not being enabled (the sysctl-variable net.inet.tcp.fastopen.server_enable is 0). 2. Incoming IP packet with source routing options are not being processed by the host stack (the sysctl-variable net.inet.ip.accept_sourceroute is 0). Only if these two sysctl-variables are changed, a FreeBSD system is affected, if a server actually using TCP fast open is running. Reported by: Yuxiang Yang, Yizhou Zhao, Xuewei Feng, Qi Li, and Ke Xu from Tsinghua University using GLM5.1 from Z.ai Reviewed by: markj, rscheff Sponsored by: Netflix, Inc. Differential Revision: https://reviews.freebsd.org/D57374 (cherry picked from commit 1ed2bf1e0052df8dd6b429fc4ddd1908005f39ef) M sys/netinet/tcp_syncache.c _____________________________________________________________________________________________________________ Commit: 1f3b673d17c81711fcf28ce2ed3354a0dde1fd05 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1f3b673d17c81711fcf28ce2ed3354a0dde1fd05 Author: Konstantin Belousov (Mon 27 Jul 2026 17:58:31 BST) Committer: Konstantin Belousov (Thu 6 Aug 2026 09:59:45 BST) kern_execve(): avoid storing non-VDIR into p_textdvp (cherry picked from commit 930f2e4da96487f18a82f912275c6302c39b9bd2) M sys/kern/kern_exec.c _____________________________________________________________________________________________________________ Commit: fbdb8728d327b8f9f3239ce2733bfd31ce13514c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fbdb8728d327b8f9f3239ce2733bfd31ce13514c Author: Kevin Bowling (Wed 29 Jul 2026 05:23:30 BST) Committer: Kevin Bowling (Thu 6 Aug 2026 08:38:27 BST) igb: Stop writing the legacy TADV register TADV is an em-class interrupt delay register and is absent from the 82575 and later register model. The igb attach path does not expose or initialize that control, but transmit initialization still wrote its zero valued storage into a reserved queue-window offset. Apply the same igb_mac_min boundary already used for TIDV and the absolute-delay sysctls. Sponsored by: BBOX.io (cherry picked from commit c637d474045a41b1763c17a8b4b7763d4159504f) M sys/dev/e1000/if_em.c _____________________________________________________________________________________________________________ Commit: 908706b949b10844e636013a2d10ccea46c290df URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=908706b949b10844e636013a2d10ccea46c290df Author: Kevin Bowling (Thu 30 Jul 2026 05:37:08 BST) Committer: Kevin Bowling (Thu 6 Aug 2026 08:37:22 BST) igb: Reprogram descriptor queues while disabled Disable each igb-class transmit and receive queue and flush before changing its descriptor-ring registers. Restore the head and tail indices that Intel documents as surviving a VF reset. Use the igb queue-enable control instead of programming legacy TXDCTL granularity, low-water, and reserved bits that do not belong to the 82575 and later. Sponsored by: BBOX.io (cherry picked from commit f879d1cd7df3c5afa69428cc2b07e1675d7776c9) M sys/dev/e1000/if_em.c _____________________________________________________________________________________________________________ Commit: 86000d1af36eb58f48d7e4241ebd2f9d7f2c2073 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=86000d1af36eb58f48d7e4241ebd2f9d7f2c2073 Author: Kevin Bowling (Wed 29 Jul 2026 03:57:46 BST) Committer: Kevin Bowling (Thu 6 Aug 2026 08:35:00 BST) igb: Correct I350 loopback VLAN byte order I350 loopback receive descriptors report VLAN tags byte-swapped for both PFs and VFs. The receive path handled the PF device types but omitted e1000_vfadapt_i350, causing an admitted VF VLAN packet to be delivered untagged to the VF parent. Include the I350 VF type in the existing correction. This matches the dedicated IGB_RXQ_FLAG_LB_BSWAP_VLAN handling in DPDK igbvf. Sponsored by: BBOX.io (cherry picked from commit 7eb7ff6459219e802d51add3ba9d1d9d874db561) M sys/dev/e1000/igb_txrx.c _____________________________________________________________________________________________________________ Commit: 98588007421144a968f0de4212a803cd0d7e143c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=98588007421144a968f0de4212a803cd0d7e143c Author: Kevin Bowling (Wed 29 Jul 2026 00:30:28 BST) Committer: Kevin Bowling (Thu 6 Aug 2026 08:34:23 BST) pci_iov: Clear NumVFs when configuration fails pci_iov_config() programs NumVFs before validating the final VF RID layout and allocating all generic resources. A subsequent error ran the driver uninit callback but left the hardware NumVFs register programmed while the software VF count returned to zero. Clear NumVFs in the error path after the driver uninit callback, matching normal SR-IOV teardown ordering. This prevents stale hardware state after a failed configuration and permits a clean retry. Sponsored by: BBOX.io (cherry picked from commit 621498b58cdab36a237d5f0b5c902952ad743fa9) M sys/dev/pci/pci_iov.c _____________________________________________________________________________________________________________ Commit: 2733e053372b67c86e65699c67c934460b8f36c4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2733e053372b67c86e65699c67c934460b8f36c4 Author: Li-Wen Hsu (Wed 17 Dec 2025 10:34:14 GMT) Committer: Li-Wen Hsu (Thu 6 Aug 2026 02:44:53 BST) tests/lorder_test: Update test case description from copy/paste MFC after: 3 days Sponsored by: The FreeBSD Foundation (cherry picked from commit 5a674a0694836616eaaff448345823594742ad76) M usr.bin/lorder/tests/lorder_test.sh _____________________________________________________________________________________________________________ Commit: e6b49d71f25932b043575535cbe35c917bd71768 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e6b49d71f25932b043575535cbe35c917bd71768 Author: Li-Wen Hsu (Sat 27 Jun 2026 03:26:05 BST) Committer: Li-Wen Hsu (Thu 6 Aug 2026 02:40:09 BST) libdtrace: Fix dt_print_sym() not printing symbols in non-oformat mode dt_print_sym() fills the symbol string via snprintf() in non-oformat mode but the guarding `dtp->dt_oformat != 0 &&` for the dt_printf() call causes the symbol is computed but never emitted. This fixes tests: - common.profile-n.t_dtrace_contrib.tst_sym_ksh - common.profile-n.t_dtrace_contrib.tst_func_ksh Reviewed by: markj Fixes: 93f27766a7e1 ("dtrace: Add the 'oformat' libdtrace option") MFC after: 3 days Event: Halifax Hackathon 202606 Location: Room 208, Computer Science Building, Dalhousie University Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57895 (cherry picked from commit 8e61d8707f8a10acc143210089fea2502a3f2922) M cddl/contrib/opensolaris/lib/libdtrace/common/dt_consume.c _____________________________________________________________________________________________________________ Commit: 424d07c5260b46835fdec9dcba7cb68685a5c5f1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=424d07c5260b46835fdec9dcba7cb68685a5c5f1 Author: Li-Wen Hsu (Fri 31 Jul 2026 19:05:03 BST) Committer: Li-Wen Hsu (Thu 6 Aug 2026 02:35:23 BST) rc.d/bthidd: Correct load_kld invocations Pass a single module name to load_kld for kbdmux and vkbd, allowing bthidd_prestart to load both modules successfully. Fixes: cfe1962a1925 (rc: Fix improper use of load_kld) MFC after: 3 days Sponsored by: The FreeBSD Foundation (cherry picked from commit b5fe1bc5c6e4b483aacadddd8bdf37aa12c89982) M libexec/rc/rc.d/bthidd _____________________________________________________________________________________________________________ Commit: fc0d50a6d9ad4c9391343ba357b17f51fbfabd47 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fc0d50a6d9ad4c9391343ba357b17f51fbfabd47 Author: Sean Eric Fagan (Mon 27 Jul 2026 20:18:36 BST) Committer: Sean Eric Fagan (Wed 5 Aug 2026 22:22:56 BST) sleep: Fix man page about IGINFO output Reviewed by: des MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D58483 (cherry picked from commit 24983c4e9f9934282e8d81381095da819ad97c63) M bin/sleep/sleep.1 _____________________________________________________________________________________________________________ Commit: 6a2f1e3a06bc4e70eb60ac37b77cf6f3c7d9d8a3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6a2f1e3a06bc4e70eb60ac37b77cf6f3c7d9d8a3 Author: Andre Albsmeier (Sat 1 Aug 2026 00:27:23 BST) Committer: Alexander Ziaee (Wed 5 Aug 2026 16:54:25 BST) nvmecontrol.8: Explain non-operational power modes `nvmecontrol power -l ...` lists the available power modes. Non-operational modes are marked with an asterisk. While here, add to the "nvmecontrol power" synopsis. MFC after: 3 days Reviewed by: dab, imp, michaelo, ziaee Differential Revision: https://reviews.freebsd.org/D58480 (cherry picked from commit 868158f7fd2a172ef22f1b6b682cc1d38e54cf63) M sbin/nvmecontrol/nvmecontrol.8 _____________________________________________________________________________________________________________ Commit: 70c87c092c33d702643599816db44d53bfed0235 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=70c87c092c33d702643599816db44d53bfed0235 Author: Alexander Ziaee (Tue 30 Jun 2026 15:12:03 BST) Committer: Alexander Ziaee (Wed 5 Aug 2026 16:54:25 BST) ctfmerge.1: Fix uniqlabel typos The flag is -D, but it was written as a second -d. Add a period too. MFC after: 3 days (cherry picked from commit 4f293e32e4529617dd05bd64fd3c22a57a56a355) M cddl/usr.bin/ctfmerge/ctfmerge.1 _____________________________________________________________________________________________________________ Commit: 565061836e1dabb7c115ea4026307097ca41c7f0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=565061836e1dabb7c115ea4026307097ca41c7f0 Author: Wolfram Schneider (Tue 30 Jun 2026 14:20:41 BST) Committer: Alexander Ziaee (Wed 5 Aug 2026 16:54:24 BST) ctfmerge.1: Import ENVIRONMENT from NetBSD Import the ENVIRONMENT section from NetBSD, minus the variable that our ctfmerge does not have. Alphabetize them, polish grammar and alignment, and add the variables to the man database. While here, remove whitespace from the end of some lines to quiet linter. MFC after: 3 days PR: 291186 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=291186 ) Co-authored-by: Alexander Ziaee Obtained from: NetBSD (christos , 8a0c0d8) Differential Revision: https://reviews.freebsd.org/D54054 (cherry picked from commit 32cf24b725fdf899fb642c47004b69fcfae9b9db) M cddl/usr.bin/ctfmerge/ctfmerge.1 _____________________________________________________________________________________________________________ Commit: 2cdb856e35fd3b4090714f905c640a9429abcc2a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2cdb856e35fd3b4090714f905c640a9429abcc2a Author: Oleksandr Kryvulia (Mon 29 Jun 2026 10:51:18 BST) Committer: Alexander Ziaee (Wed 5 Aug 2026 16:54:24 BST) pf.conf.5: Fix typo Fix small typo in pf.conf(5) MFC after: 3 days Reviewed by: ziaee Differential Revision: https://reviews.freebsd.org/D57938 (cherry picked from commit bbc2d15857b8c44cf8558bf00663b508d421c94c) M share/man/man5/pf.conf.5 _____________________________________________________________________________________________________________ Commit: 279fdaaf5ad7344a2c83a8dc13c59e13610fd4a4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=279fdaaf5ad7344a2c83a8dc13c59e13610fd4a4 Author: Artem Bunichev (Mon 29 Jun 2026 01:42:30 BST) Committer: Alexander Ziaee (Wed 5 Aug 2026 16:54:24 BST) iwlwifi.4, rtw88.4, rtw89.4: Fix xref typos MFC after: 3 days Reviewed by: bz, ziaee Fixes: 0a2f7683bf0c ("man: iwlwifi/rtw88/rtw89: update man pages for Linux v7.0 based updates") Differential Revision: https://reviews.freebsd.org/D57720 (cherry picked from commit d036b3b348d3f7be21f79461d7ad48e97b088ba8) M share/man/man4/iwlwifi.4 M share/man/man4/rtw88.4 M share/man/man4/rtw89.4 _____________________________________________________________________________________________________________ Commit: c553a4283c53db0b0972f4a7240ecb5b9df4ee1c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c553a4283c53db0b0972f4a7240ecb5b9df4ee1c Author: Alexander Ziaee (Sun 28 Jun 2026 22:27:35 BST) Committer: Alexander Ziaee (Wed 5 Aug 2026 16:54:20 BST) padlock.4: Update slightly for 64-bit hardware - Change the document description to "Via and Zhaoxin CPU crypto driver" - Add a HARDWARE section mentioning these in the hardware release note This manual still needs desperate help, but just this little bit could have saved a lot of confusion. I'd write more if I had information. PR: 295517 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=295517 ) Fixes: 14b8531c4ccb8 (Restore padlock_rng the the amd64 build) MFC after: 3 days (to 15 only) Reviewed by: bcr, asomers Differential Revision: https://reviews.freebsd.org/D57920 (cherry picked from commit 380c6f59c4f87dbc45a67983d927700ca7e22be2) M share/man/man4/padlock.4 _____________________________________________________________________________________________________________ Commit: abe9c47be9ca52cdd8609f0185f728482f50f638 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=abe9c47be9ca52cdd8609f0185f728482f50f638 Author: Konstantin Belousov (Mon 27 Jul 2026 14:41:09 BST) Committer: Konstantin Belousov (Wed 5 Aug 2026 07:12:48 BST) statfs(2): allow to interrupt busying (cherry picked from commit b72f9bfc4513e3e286fb3fc2d07ebdd94ed7ac57) M sys/kern/vfs_syscalls.c _____________________________________________________________________________________________________________ Commit: 5adc7b1c9141cd002d5b3864c707530a5cce52f1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5adc7b1c9141cd002d5b3864c707530a5cce52f1 Author: Konstantin Belousov (Mon 27 Jul 2026 14:40:23 BST) Committer: Konstantin Belousov (Wed 5 Aug 2026 07:12:48 BST) vfs_busy(): add MBF_PCATCH flag to allow interrupting the sleep (cherry picked from commit fb4d7bd4b7676963f9f37ff47f315f8c3652538b) M sys/kern/vfs_subr.c M sys/sys/mount.h _____________________________________________________________________________________________________________ Commit: 5bdb00b44fbdf8ac95283a0c0fd35d248b3cb0fe URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5bdb00b44fbdf8ac95283a0c0fd35d248b3cb0fe Author: Konstantin Belousov (Sun 2 Aug 2026 15:57:37 BST) Committer: Konstantin Belousov (Wed 5 Aug 2026 07:12:47 BST) stat.2: enhance the description of st_blocks (cherry picked from commit 4c58eef12d30ec699c86d9ab8939253adbf35e79) M lib/libsys/stat.2 _____________________________________________________________________________________________________________ Commit: 8b62109453362e477791751a9754b9287ff76595 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8b62109453362e477791751a9754b9287ff76595 Author: Mark Johnston (Fri 31 Jul 2026 20:47:20 BST) Committer: Konstantin Belousov (Wed 5 Aug 2026 07:12:47 BST) ptrace: Propagate errors from set_fpregs() (cherry picked from commit 1932bd20ed53f2e695a576cffd183937ed25de3f) M sys/kern/imgact_elf.c _____________________________________________________________________________________________________________ Commit: aea04a88aaa9a61d0049eb5db39188c39267217f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=aea04a88aaa9a61d0049eb5db39188c39267217f Author: Konstantin Belousov (Thu 30 Jul 2026 04:57:34 BST) Committer: Konstantin Belousov (Wed 5 Aug 2026 07:08:57 BST) amd64: do not allow to set reserved bits in MXCSR for ptrace(PT_SETFPREGS) (cherry picked from commit cef05c5a62ba63eda222eed083972bfaa1449ac2) M sys/amd64/amd64/exec_machdep.c _____________________________________________________________________________________________________________ Commit: 15a0a7d525cf8e306f9f202496f67bee12026660 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=15a0a7d525cf8e306f9f202496f67bee12026660 Author: Jose Luis Duran (Wed 29 Jul 2026 17:11:53 BST) Committer: Jose Luis Duran (Wed 5 Aug 2026 01:25:31 BST) boot0cfg: Also allow a file as a trailing argument Modify the disk check to allow arbitrary files as the trailing argument instead of requiring a live GEOM disk provider. This enables modifying a boot0 binary file in-place before flashing it to a disk via gpart bootcode, or using it directly as an argument to mkimg's partition specification, as these tools cannot directly adjust the parameters of the boot0 boot manager. Reviewed by: imp, jhb MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D57310 (cherry picked from commit 4007d914e7973bca8ac488ab50aca56964eed90f) M usr.sbin/boot0cfg/boot0cfg.8 M usr.sbin/boot0cfg/boot0cfg.c _____________________________________________________________________________________________________________ Commit: c6fb3ad1533b23ab72e9a15593153c6676447f28 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c6fb3ad1533b23ab72e9a15593153c6676447f28 Author: Kevin Bowling (Sat 1 Aug 2026 03:38:54 BST) Committer: Kevin Bowling (Tue 4 Aug 2026 19:40:58 BST) ixl: enforce the assigned VF MAC address When allow-set-mac is disabled, the MAC filter validation condition rejects the assigned VF unicast address while allowing any different unicast address. The equality test was accidentally inverted when this code moved to the boolean address helper. Accept multicast and the assigned unicast address, and reject other unicast addresses as intended. Fixes: 7d4dceec1030 ("ixl(4): Fix VLAN HW filtering") (cherry picked from commit d2309d9d6dc6d5a9141314652d6c96ab46a9a62c) M sys/dev/ixl/ixl_pf_iov.c _____________________________________________________________________________________________________________ Commit: 60dd46db19f473af7aa505c0d8dcf9bb69847019 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=60dd46db19f473af7aa505c0d8dcf9bb69847019 Author: Olivier Houchard (Fri 24 Jul 2026 00:47:21 BST) Committer: Olivier Houchard (Tue 4 Aug 2026 11:27:09 BST) arm64: Use the fault handler when one is provided In align_abort() and tag_check_abort(), if we got a fault while in kernel, do not panic if a fault handler has been provided. We may get such a fault when trying to read or write userland data, it can at least happen with _umtx_op() if an unaligned pointer is provided. Instead, just let the fault handler deal with it. MFC After: 1 week Approved by: andrew Differential Revision: https://reviews.freebsd.org/D58426 (cherry picked from commit c6f5d8fb269fd67a8206420b4e7d67a93bc80733) Signed-off-by: Olivier Houchard M sys/arm64/arm64/trap.c _____________________________________________________________________________________________________________ Commit: 410403d2e9ea5152206d18271e54c717b8b1fcb1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=410403d2e9ea5152206d18271e54c717b8b1fcb1 Author: Olivier Cochard (Tue 28 Jul 2026 20:13:53 BST) Committer: Olivier Cochard (Tue 4 Aug 2026 10:33:05 BST) e1000: report UDP RSS hash type on igb/em {em,igb}_determine_rsstype() mapped only the TCP and bare-IP RSS descriptor types; the UDP types returned M_HASHTYPE_NONE. The hardware does hash UDP, but with a NONE hashtype iflib skips its flowid-based TX queue spread, so all forwarded UDP egressed on a single queue and serialized transmit on one core. Add the three UDP cases (IPV4_UDP, IPV6_UDP, IPV6_UDP_EX) so egress spreads across all TX queues. Reviewed by: kbowling, gallatin Approved by: kbowling MFC after: 1 week Sponsored by: Netflix Differential Revision: https://reviews.freebsd.org/D58513 (cherry picked from commit 285c749f575ed7f9e60555037f23ac673084c62a) M sys/dev/e1000/em_txrx.c M sys/dev/e1000/igb_txrx.c _____________________________________________________________________________________________________________ Commit: 38af24ed0811c5ab693096cbb9e57ef29892afa3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=38af24ed0811c5ab693096cbb9e57ef29892afa3 Author: Olivier Cochard (Tue 28 Jul 2026 20:06:27 BST) Committer: Olivier Cochard (Tue 4 Aug 2026 10:28:08 BST) hwpmc: fix event allocation on pre-Zen AMD CPUs amd_allocate_pmc() chose the pmu-events code path whenever pmc_cpuid was non-empty, and rejected any allocation lacking PMC_F_EV_PMU. But pmc_cpuid is set for every AMD CPU, while the pmu-events tables only cover Zen and later. On older families (K8, Bobcat, Jaguar/16h, Bulldozer) libpmc finds no pmu-events entry and falls back to the legacy path, which never sets PMC_F_EV_PMU. Reviewed by: mhorne Approved by: mhorne MFC after: 1 week Sponsored by: Netflix Differential Revision: https://reviews.freebsd.org/D58468 (cherry picked from commit 6c4d9b9af1a3b247bf82a4228c835d106f535613) M sys/dev/hwpmc/hwpmc_amd.c _____________________________________________________________________________________________________________ Commit: e96ecc712e85af65a728f70a84ca46df7c8a5d67 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e96ecc712e85af65a728f70a84ca46df7c8a5d67 Author: Kristofer Peterson (Mon 16 Feb 2026 15:53:47 GMT) Committer: Jilles Tjoelker (Mon 3 Aug 2026 22:37:37 BST) bin/sh: Fix history long line truncation/corruption When reading from standard input with editline history enabled, increase buffer size to accomodate long lines so that history is recorded correctly. Cleanup el_gets() handling avoiding potentially dangerous retention of pointers to editline buffers across calls. Ensure struct parsefile objects are properly zero initialised when created. Remove push argument from setinputstring() and simplify logic as it was always called with a value of one and as was written was potentially dangerous if ever called with a value of zero. This commit does not fix long lines when history is enabled but editing is not (e.g. if there is no terminal). MFC after: 3 weeks Pull Request: https://github.com/freebsd/freebsd-src/pull/2028 Signed-off-by: Kristofer Peterson (cherry picked from commit 95e4fce8f0c4fc6bf828288b1d63faf0f1300198) M bin/sh/eval.c M bin/sh/input.c M bin/sh/input.h M bin/sh/parser.c _____________________________________________________________________________________________________________ Commit: 7503cd109bff5882779788c9864030f461445375 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7503cd109bff5882779788c9864030f461445375 Author: Enji Cooper (Wed 22 Jul 2026 20:53:31 BST) Committer: Alexander Leidinger (Mon 3 Aug 2026 18:29:26 BST) tests/sys/pmc: only build if MK_PMC != no This unbreaks the build when pmc support is explicitly disabled via the aforementioned build knob. MFC after: 10 days Fixes: 2cfd82f74 ("hwpmc: add regression tests for ...") Differential Revision: https://reviews.freebsd.org/D58401 (cherry picked from commit a18e773d2776a65c1a2a0418cbec9cf5ef526b53) M tests/sys/Makefile _____________________________________________________________________________________________________________ Commit: d5e51b56c248e179dca588089ab349c72160d6bd URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d5e51b56c248e179dca588089ab349c72160d6bd Author: Alexander Leidinger (Sun 19 Jul 2026 13:15:20 BST) Committer: Alexander Leidinger (Mon 3 Aug 2026 18:29:26 BST) hwpmc: add regression tests for detaching a live process-mode PMC Attach a process-mode counting PMC to the current process, start it, then detach and release it while it is still loaded on the hardware - the case that previously leaked the PMC's runcount reference and wedged pmc_wait_for_pmc_idle() at release. A second case does the same from a multi-threaded process so the sibling threads' references have to be drained too. The tests need an allocatable process-mode counting event and skip where none is available (hwpmc(4) not loaded, or a VM without a vPMU). Reviewed by: adrian MFC after: 2 weeks Assisted-by: Claude Code (Fable 5) Differential Revision: https://reviews.freebsd.org/D58343 (cherry picked from commit 3c3f886e4bc7619f7847ad0d0f996088ddf5915a) M tests/sys/pmc/Makefile A tests/sys/pmc/pmc_detach_test.c _____________________________________________________________________________________________________________ Commit: 48c9e91856c32424c96c737564d05d89f5e730e9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=48c9e91856c32424c96c737564d05d89f5e730e9 Author: Alexander Leidinger (Sun 19 Jul 2026 12:39:27 BST) Committer: Alexander Leidinger (Mon 3 Aug 2026 18:29:25 BST) hwpmc: drain a process-mode PMC's runcount when a live target detaches A process-mode PMC's runcount tracks how many CPUs currently have it loaded in hardware. It is decremented only by the context-switch-out and process-exit reclaim paths, both of which the scheduler invokes only for processes flagged P_HWPMC. Detaching a target that still has the PMC live in hardware dropped the target and cleared P_HWPMC without taking the PMC off the hardware or dropping the runcount reference, so the reference leaked. A subsequent release then spun in pmc_wait_for_pmc_idle() forever waiting for the runcount to reach zero: on an INVARIANTS kernel this panics ("waiting too long for pmc to be free"), otherwise it is an unkillable loop holding the hwpmc lock. Any process able to allocate a PMC can trigger this by attaching a counting PMC to itself and detaching it before releasing. Take the PMC off the hardware and drop the runcount reference as part of detaching, before P_HWPMC is cleared: reclaim it from the detaching thread's own CPU directly, and, when the detach removes the PMC's last target, wait for any references held by the target's other threads to drain while P_HWPMC is still set (they can no longer reload it). Reviewed by: adrian MFC after: 2 weeks Assisted-by: Claude Code (Fable 5) Differential Revision: https://reviews.freebsd.org/D58342 (cherry picked from commit 86fa065f1862f3b638efa1868523878d9db14ada) M sys/dev/hwpmc/hwpmc_mod.c _____________________________________________________________________________________________________________ Commit: 6f7bdac868c7cae2806331f0f13925a5dda4f36e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6f7bdac868c7cae2806331f0f13925a5dda4f36e Author: Alexander Leidinger (Sun 19 Jul 2026 09:08:48 BST) Committer: Alexander Leidinger (Mon 3 Aug 2026 18:29:25 BST) hwpmc: add regression tests for counting-PMC counter wraparound Exercise a process-mode counting PMC whose accumulated count crosses, or already exceeds, the range of the underlying hardware counter. Before the previous commit, the first context switch after the hardware counter wrapped panicked INVARIANTS kernels with "negative increment" and silently corrupted the accumulated count on other kernels. The tests need a hardware counting event backed by a counter narrower than 64 bits and skip where none is available (hwpmc(4) not loaded, or a VM without a vPMU). Reviewed by: adrian MFC after: 2 weeks Assisted-by: Claude Code (Fable 5) Differential Revision: https://reviews.freebsd.org/D58341 (cherry picked from commit 2cfd82f747c04f68f679824ba627460e87ab3848) M etc/mtree/BSD.tests.dist M tests/sys/Makefile A tests/sys/pmc/Makefile A tests/sys/pmc/pmc_wrap_test.c _____________________________________________________________________________________________________________ Commit: 1e0ae0d055d2f91db5a9c2cf19459621b470b294 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1e0ae0d055d2f91db5a9c2cf19459621b470b294 Author: Alexander Leidinger (Sun 19 Jul 2026 08:38:52 BST) Committer: Alexander Leidinger (Mon 3 Aug 2026 18:29:24 BST) hwpmc: handle counter wraparound for process-mode counting PMCs The accumulated count of a process-mode counting PMC is kept in a 64-bit software counter and seeded into the hardware counter at every context switch in. Hardware counters are narrower than that - each PMC class discovers and records its own counter width, e.g. 48 bits on current x86 (queried from CPUID on Intel, architectural on AMD) - so once the accumulated count approaches the end of the hardware counter range, the counter wraps during a time slice and the value read back at switch out is smaller than the value seeded. The increment was computed assuming a full 64-bit counter: on INVARIANTS kernels a long enough counting run panics with "negative increment" the moment the accumulated count first crosses the hardware counter range, and on other kernels the totals silently lose a full counter range per wrap. Compute the increment modulo the per-class hardware counter width instead, in both places that accumulate switch-out deltas. Reviewed by: adrian MFC after: 2 weeks Assisted-by: Claude Code (Fable 5) Differential Revision: https://reviews.freebsd.org/D58340 (cherry picked from commit e42703f5c4b2d3a869b17e2cb8670f1b6359c8cf) M sys/dev/hwpmc/hwpmc_mod.c _____________________________________________________________________________________________________________ Commit: 6eb614c82fada8e6a19764ebffaffbe228087eb5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6eb614c82fada8e6a19764ebffaffbe228087eb5 Author: Dag-Erling Smørgrav (Mon 27 Jul 2026 19:51:50 BST) Committer: Dag-Erling Smørgrav (Mon 3 Aug 2026 12:32:12 BST) pwait: Fix pwait_normal test case Reported by: markj Fixes: e115066370dc ("pwait: Test the new -r option") (cherry picked from commit 51c0cdb04919f776516a7fac8529e7279ea5efad) M bin/pwait/tests/pwait_reap.c _____________________________________________________________________________________________________________ Commit: 48f73970d1edd9fcf0a7e6f702adda107ac55a39 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=48f73970d1edd9fcf0a7e6f702adda107ac55a39 Author: Dag-Erling Smørgrav (Mon 27 Jul 2026 11:26:41 BST) Committer: Dag-Erling Smørgrav (Mon 3 Aug 2026 12:32:12 BST) Bump dates Fixes: c8f5e6819d4d ("pwait: Optionally wait until process is reaped") Fixes: eddd8aa99ca8 ("pwait: Add a SIGINFO handler") Fixes: 356d0b79cf6f ("rc.subr: Fix premature return from wait_for_pids") (cherry picked from commit 9d852922f6687ce9a699efe5e09e3634923b2b60) M UPDATING M bin/pwait/pwait.1 M lib/libsys/kqueue.2 _____________________________________________________________________________________________________________ Commit: 237ab146975b42472b86ed73ba64bc7a69881092 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=237ab146975b42472b86ed73ba64bc7a69881092 Author: Dag-Erling Smørgrav (Mon 27 Jul 2026 11:15:47 BST) Committer: Dag-Erling Smørgrav (Mon 3 Aug 2026 12:32:12 BST) rc.subr: Fix premature return from wait_for_pids Use pwait's new -r option to wait until the target processes have not only terminated, but also been reaped. PR: 293183 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=293183 ) MFC after: 1 week Sponsored by: Klara, Inc. Sponsored by: NetApp, Inc. Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D58391 (cherry picked from commit 356d0b79cf6fc693ed1a5564232e240ce15ccb8a) M UPDATING M libexec/rc/rc.subr M libexec/rc/tests/rc_subr_test.sh _____________________________________________________________________________________________________________ Commit: e87afada8e8ad34e9ddb91073ec112835f1ef57d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e87afada8e8ad34e9ddb91073ec112835f1ef57d Author: Dag-Erling Smørgrav (Mon 27 Jul 2026 11:15:41 BST) Committer: Dag-Erling Smørgrav (Mon 3 Aug 2026 12:32:12 BST) pwait: Test the new -r option Test that pwait without -r reports a process as soon as it terminates, while pwait with -r does not report it until it has been reaped. MFC after: 1 week Sponsored by: Klara, Inc. Sponsored by: NetApp, Inc. Reviewed by: kib Differential Revision: https://reviews.freebsd.org/D58385 (cherry picked from commit e115066370dcfec410d914362756d09c268a5b4e) M bin/pwait/tests/Makefile A bin/pwait/tests/pwait_reap.c _____________________________________________________________________________________________________________ Commit: 236794f7c22966c2d0612da30b22c8c8737f2aeb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=236794f7c22966c2d0612da30b22c8c8737f2aeb Author: Dag-Erling Smørgrav (Mon 27 Jul 2026 11:15:36 BST) Committer: Dag-Erling Smørgrav (Mon 3 Aug 2026 12:32:12 BST) pwait: Add a SIGINFO handler On SIGINFO, print a space-separated list or remaining processes to standard error. MFC after: 1 week Sponsored by: Klara, Inc. Sponsored by: NetApp, Inc. Reviewed by: kib, markj Differential Revision: https://reviews.freebsd.org/D58386 (cherry picked from commit eddd8aa99ca84c85faea5761af800b5b089d6ba1) M bin/pwait/pwait.1 M bin/pwait/pwait.c _____________________________________________________________________________________________________________ Commit: 600d57daeaec22c3b459a2a894e30ceca1a9c4cb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=600d57daeaec22c3b459a2a894e30ceca1a9c4cb Author: Dag-Erling Smørgrav (Mon 27 Jul 2026 11:15:31 BST) Committer: Dag-Erling Smørgrav (Mon 3 Aug 2026 12:32:12 BST) pwait: Optionally wait until process is reaped If the new -r option is specified, wait until the target process not only terminates but is reaped. MFC after: 1 week Sponsored by: Klara, Inc. Sponsored by: NetApp, Inc. Reviewed by: kib, markj Differential Revision: https://reviews.freebsd.org/D58314 (cherry picked from commit c8f5e6819d4d81906c4a1641b5c9f02d8730481c) M bin/pwait/pwait.1 M bin/pwait/pwait.c _____________________________________________________________________________________________________________ Commit: 4ce8f2940a6a62b4d79b54d9d9a0c1acaca0ad5c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4ce8f2940a6a62b4d79b54d9d9a0c1acaca0ad5c Author: Dag-Erling Smørgrav (Mon 27 Jul 2026 11:15:26 BST) Committer: Dag-Erling Smørgrav (Mon 3 Aug 2026 12:32:12 BST) kqueue: Add NOTE_REAP Add a NOTE_REAP event for EVFILTER_PROC which provides a notification when the process is reaped. MFC after: 1 week Sponsored by: Klara, Inc. Sponsored by: NetApp, Inc. Reviewed by: kib, markj Differential Revision: https://reviews.freebsd.org/D58313 (cherry picked from commit 2bacbbecb165dd761ea7ec2fc35630db61508cdf) M lib/libsys/kqueue.2 M lib/libsysdecode/flags.c M sys/kern/kern_event.c M sys/kern/kern_exit.c M sys/kern/sys_procdesc.c M sys/sys/event.h _____________________________________________________________________________________________________________ Commit: c78190d2144ec2574bca0ba619a0b26b87371216 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c78190d2144ec2574bca0ba619a0b26b87371216 Author: Dag-Erling Smørgrav (Sat 25 Jul 2026 13:44:35 BST) Committer: Dag-Erling Smørgrav (Mon 3 Aug 2026 12:32:11 BST) pwait: Don't use init as a target The time_unit test case uses PID 1 as a target for pwait. This doesn't work in a jail. Since all we need is a process that we know won't die while the test is running, we may as well use ourselves. MFC after: 1 week Sponsored by: Klara, Inc. Sponsored by: NetApp, Inc. Reviewed by: ngie Differential Revision: https://reviews.freebsd.org/D58418 (cherry picked from commit 5922e9d7e72bfa8a85b0f37bcfd1a8b5d866ec3b) M bin/pwait/tests/pwait_test.sh _____________________________________________________________________________________________________________ Commit: eeba99aff03b49ade60189fb0567eefb899a8454 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=eeba99aff03b49ade60189fb0567eefb899a8454 Author: Dag-Erling Smørgrav (Thu 23 Jul 2026 07:06:32 BST) Committer: Dag-Erling Smørgrav (Mon 3 Aug 2026 12:32:11 BST) kqueue: Fix delivery of unwanted events In both procdesc_kqops_event() and filt_proc(), the event variable can have more than one bit set. This means that: * We cannot compare it directly with NOTE_EXIT; we must binary-and them instead. * We cannot binary-or it with the report mask; we must binary-and it with the request mask first. MFC after: 1 week Fixes: 2a5e58c59694 ("procdesc: add NOTE_PDSIGCHLD") Fixes: b328975b9d7c ("procdesc: report NOTE_PDSIGCHLD for traced and stopped process") Reviewed by: kib, markj Differential Revision: https://reviews.freebsd.org/D58395 (cherry picked from commit 4627fe9e5afc0dce4469f5964f5d4b0e49a24274) M sys/kern/kern_event.c M sys/kern/sys_procdesc.c _____________________________________________________________________________________________________________ Commit: c4e25212639ad4c219a85415ade68611dee3277e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c4e25212639ad4c219a85415ade68611dee3277e Author: Dag-Erling Smørgrav (Wed 22 Jul 2026 13:23:53 BST) Committer: Dag-Erling Smørgrav (Mon 3 Aug 2026 12:32:11 BST) unbound: Update to 1.25.2 Release notes at https://community.nlnetlabs.nl/t/unbound-1-25-2-released Merge commit 'c68e7bcd81d62e9f5364c6da22fd9917976acf85' Security: CVE-2026-14586 Security: CVE-2026-32665 Security: CVE-2026-40691 Security: CVE-2026-41637 Security: CVE-2026-42955 Security: CVE-2026-44621 Security: CVE-2026-44687 Security: CVE-2026-44690 Security: CVE-2026-46582 Security: CVE-2026-50045 Security: CVE-2026-50046 Security: CVE-2026-50243 Security: CVE-2026-50248 Security: CVE-2026-50251 Security: CVE-2026-50252 Security: CVE-2026-52863 Security: CVE-2026-54478 Security: CVE-2026-55708 Security: CVE-2026-55717 Security: CVE-2026-55973 Security: CVE-2026-55990 Security: CVE-2026-55991 Security: CVE-2026-56416 Security: CVE-2026-56444 (cherry picked from commit e27b1cae848219d07f0a12a48990af0558b4cced) M contrib/unbound/config.guess M contrib/unbound/config.sub M contrib/unbound/configure M contrib/unbound/configure.ac M contrib/unbound/daemon/daemon.c M contrib/unbound/daemon/daemon.h M contrib/unbound/daemon/remote.c M contrib/unbound/daemon/worker.c M contrib/unbound/daemon/worker.h M contrib/unbound/dnscrypt/dnscrypt.c M contrib/unbound/dnscrypt/dnscrypt.h M contrib/unbound/dnstap/unbound-dnstap-socket.c M contrib/unbound/doc/README M contrib/unbound/doc/example.conf M contrib/unbound/doc/example.conf.in M contrib/unbound/doc/libunbound.3 M contrib/unbound/doc/libunbound.3.in M contrib/unbound/doc/unbound-anchor.8 M contrib/unbound/doc/unbound-anchor.8.in M contrib/unbound/doc/unbound-checkconf.8 M contrib/unbound/doc/unbound-checkconf.8.in M contrib/unbound/doc/unbound-control.8 M contrib/unbound/doc/unbound-control.8.in M contrib/unbound/doc/unbound-host.1 M contrib/unbound/doc/unbound-host.1.in M contrib/unbound/doc/unbound.8 M contrib/unbound/doc/unbound.8.in M contrib/unbound/doc/unbound.conf.5 M contrib/unbound/doc/unbound.conf.5.in M contrib/unbound/doc/unbound.conf.rst M contrib/unbound/iterator/iter_donotq.c M contrib/unbound/iterator/iterator.c M contrib/unbound/libunbound/libworker.c M contrib/unbound/libunbound/libworker.h M contrib/unbound/respip/respip.c M contrib/unbound/services/authzone.c M contrib/unbound/services/cache/dns.c M contrib/unbound/services/cache/rrset.c M contrib/unbound/services/listen_dnsport.c M contrib/unbound/services/listen_dnsport.h M contrib/unbound/services/localzone.h M contrib/unbound/services/mesh.c M contrib/unbound/services/mesh.h M contrib/unbound/services/outside_network.c M contrib/unbound/services/outside_network.h M contrib/unbound/smallapp/worker_cb.c M contrib/unbound/util/data/msgparse.c M contrib/unbound/util/data/packed_rrset.c M contrib/unbound/util/fptr_wlist.c M contrib/unbound/util/module.h M contrib/unbound/util/netevent.c M contrib/unbound/util/netevent.h M contrib/unbound/validator/val_sigcrypt.c M contrib/unbound/validator/val_utils.c M contrib/unbound/validator/val_utils.h M contrib/unbound/validator/validator.c M lib/libunbound/config.h _____________________________________________________________________________________________________________ Commit: 25d1f68e513bb567497de26cb65840f434f227ee URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=25d1f68e513bb567497de26cb65840f434f227ee Author: Rick Macklem (Mon 27 Jul 2026 15:16:29 BST) Committer: Rick Macklem (Mon 3 Aug 2026 02:01:39 BST) nfs_commonkrpc.c: Handle NFSERR_DELAY for Sequence correctly Unlike RFC5661 (the original NFSv4.1 RFC), RFC8881 specifies that a NFS4ERR_DELAY reply to the SEQUENCE operation requires a reply using the same slot/sequence#. This patch fixes handling of this case, so it conforms to RFC8881. (cherry picked from commit 6901cbbd5a2c00d378a7f87426b36d6ee6ce0aa2) M sys/fs/nfs/nfs_commonkrpc.c _____________________________________________________________________________________________________________ Commit: 0aa72376d73bef2612f308a6de8b33e9584894de URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0aa72376d73bef2612f308a6de8b33e9584894de Author: Konstantin Belousov (Sun 26 Jul 2026 22:45:07 BST) Committer: Konstantin Belousov (Mon 3 Aug 2026 01:23:17 BST) geom_zero(4): reset the uio vector on each uiomove() PR: 297062 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297062 ) (cherry picked from commit 34ca5a9e7362b0c820fe339daa2b8d06c58b6fea) M sys/geom/zero/g_zero.c _____________________________________________________________________________________________________________ Commit: 7d243813ca639d464b3c7baa1953bc41f89031f9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7d243813ca639d464b3c7baa1953bc41f89031f9 Author: Konstantin Belousov (Sun 26 Jul 2026 02:59:05 BST) Committer: Konstantin Belousov (Mon 3 Aug 2026 01:23:17 BST) tests/libpthread: add pthread_cond_clockwait(3) tests (cherry picked from commit 10ea2300bf29cdcaf12182e8b722f6becb0da1fb) M contrib/netbsd-tests/lib/libpthread/t_condwait.c _____________________________________________________________________________________________________________ Commit: d62a413e76bdfc8a9c92d4c5b5fea89bb132811c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d62a413e76bdfc8a9c92d4c5b5fea89bb132811c Author: Konstantin Belousov (Sun 26 Jul 2026 00:56:03 BST) Committer: Konstantin Belousov (Mon 3 Aug 2026 01:23:17 BST) pthread_cond_timedwait.3: document pthread_cond_clockwait(3) (cherry picked from commit e7015a3834abe0956e9a8ec6ec4b8e75ea7d71ab) M share/man/man3/Makefile M share/man/man3/pthread_cond_timedwait.3 _____________________________________________________________________________________________________________ Commit: ff36771c13e993862b6a5c38462f870825b58068 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ff36771c13e993862b6a5c38462f870825b58068 Author: Konstantin Belousov (Sun 26 Jul 2026 00:53:11 BST) Committer: Konstantin Belousov (Mon 3 Aug 2026 01:23:16 BST) pthread_cond_timedwait.3: use .Fo/.Fc for long arguments list (cherry picked from commit 6d3db07a2e2f4288b7e54af8e8371f9a022e751f) M share/man/man3/pthread_cond_timedwait.3 _____________________________________________________________________________________________________________ Commit: 4dcfa6d003e027be54d78ad14601170ae3a625f2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4dcfa6d003e027be54d78ad14601170ae3a625f2 Author: Konstantin Belousov (Sun 26 Jul 2026 00:45:11 BST) Committer: Konstantin Belousov (Mon 3 Aug 2026 01:23:16 BST) libthr: implement pthread_cond_clockwait(3) (cherry picked from commit e1136fbcab184b8fb87456ca0d115d502bab6643) M include/pthread.h M lib/libthr/pthread.map M lib/libthr/thread/thr_barrier.c M lib/libthr/thread/thr_cond.c M lib/libthr/thread/thr_umtx.c M lib/libthr/thread/thr_umtx.h _____________________________________________________________________________________________________________ Commit: d32bf064e951837cf815062afa3bfcc24279ebae URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d32bf064e951837cf815062afa3bfcc24279ebae Author: Konstantin Belousov (Sun 26 Jul 2026 01:07:37 BST) Committer: Konstantin Belousov (Mon 3 Aug 2026 01:23:15 BST) libthr/thread/thr_cond.c: some style (cherry picked from commit 149d3e5fcb76bff86d4343b7378258e9a6d3e25b) M lib/libthr/thread/thr_cond.c _____________________________________________________________________________________________________________ Commit: 0737ff2da5f447f581db0ab5fb615820749a3c83 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0737ff2da5f447f581db0ab5fb615820749a3c83 Author: Konstantin Belousov (Sat 25 Jul 2026 22:37:55 BST) Committer: Konstantin Belousov (Mon 3 Aug 2026 01:23:15 BST) libthr/thread/thr_umtx.c: style _thr_ucond_wait() (cherry picked from commit 196cc005b197ab8bf5044c3fc457697986a14b39) M lib/libthr/thread/thr_umtx.c _____________________________________________________________________________________________________________ Commit: 671e2cb6a2376015660441cf5ea97d520621e6ee URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=671e2cb6a2376015660441cf5ea97d520621e6ee Author: Konstantin Belousov (Sun 26 Jul 2026 01:00:30 BST) Committer: Konstantin Belousov (Mon 3 Aug 2026 01:23:15 BST) _umtx_op.2: document the CVWAIT_UMTX_TIME flag for the UMTX_OP_CV_WAIT_UC request (cherry picked from commit f4a05f37936e422b1e8f4f127253562d3f58f50c) M lib/libsys/_umtx_op.2 _____________________________________________________________________________________________________________ Commit: 16015bf932bde4ab4cb174634ba6ef48fdad5fdc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=16015bf932bde4ab4cb174634ba6ef48fdad5fdc Author: Konstantin Belousov (Sat 25 Jul 2026 23:30:37 BST) Committer: Konstantin Belousov (Mon 3 Aug 2026 01:23:14 BST) umtx_op(2): add the CVWAIT_UMTX_TIME flag for the UMTX_OP_CV_WAIT_UC request (cherry picked from commit d738f66fab9208ee3bccea5fed293d8ce3ee5ca3) M sys/kern/kern_umtx.c M sys/sys/umtx.h _____________________________________________________________________________________________________________ Commit: c878cb7effe775a063ac790d7c0e24e51f9c72ed URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c878cb7effe775a063ac790d7c0e24e51f9c72ed Author: Dag-Erling Smørgrav (Thu 23 Jul 2026 07:21:08 BST) Committer: Dag-Erling Smørgrav (Sun 2 Aug 2026 20:59:52 BST) cp: Correct description of SIGINFO The manual page claimed that SIGINFO caused information to be printed to stdout, when in fact it is printed to stderr, as one would expect. This has been true ever since the feature was first added in 2003. MFC after: 1 week Fixes: 00d321a2b395 ("Add a SIGINFO handler.") Reviewed by: jilles Differential Revision: https://reviews.freebsd.org/D58392 (cherry picked from commit 5dc400ff452b0259f0c50474255ebe6e5e02edb9) M bin/cp/cp.1 _____________________________________________________________________________________________________________ Commit: 433412518830e54a879072cfe3f1324ecc42335f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=433412518830e54a879072cfe3f1324ecc42335f Author: Dag-Erling Smørgrav (Wed 22 Jul 2026 09:37:56 BST) Committer: Dag-Erling Smørgrav (Sun 2 Aug 2026 20:59:24 BST) kyua-debug: Add -P option Add -P as shorthand for --pause-before-cleanup. MFC after: 1 week Reviewed by: ngie Differential Revision: https://reviews.freebsd.org/D56613 (cherry picked from commit 7c51da13ae55dc98e9cc1b794e1fe6fc001d7f42) M contrib/kyua/cli/cmd_debug.cpp M contrib/kyua/doc/kyua-debug.1.in _____________________________________________________________________________________________________________ Commit: f904310efdb9fe5e92d7855e2d75dc0dcc6b27f9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f904310efdb9fe5e92d7855e2d75dc0dcc6b27f9 Author: Dag-Erling Smørgrav (Thu 30 Jul 2026 17:36:27 BST) Committer: Dag-Erling Smørgrav (Sun 2 Aug 2026 20:54:45 BST) libfetch: Further improve connection polling * Reorganize the connection loop to make it a little more readable * Start the timeout clock earlier * Correctly calculate the poll timeout before calling poll() * Don't leak the socket on failure Fixes: 848f360c8f9a ("libfetch: Apply timeout to connection attempts") Fixes: b02e02958dad ("libfetch: Fix handling of connection failures") MFC after: 3 days Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D58512 (cherry picked from commit 351ed134887fe5b8da39d22fcb267c96ab009ca2) M lib/libfetch/common.c _____________________________________________________________________________________________________________ Commit: 21101f52147ed077350c1d3a489007c02887eb0d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=21101f52147ed077350c1d3a489007c02887eb0d Author: Mark Johnston (Mon 27 Jul 2026 19:58:34 BST) Committer: Dag-Erling Smørgrav (Sun 2 Aug 2026 20:54:45 BST) libfetch: Fix handling of connection failures After commit 848f360c8f9a, if one tries to connect to a closed port, fetch reports "Operation now in progress", which is rather confusing. Return a more useful error message, restoring the old behaviour. Fixes: 848f360c8f9a ("libfetch: Apply timeout to connection attempts") Reviewed by: des MFC after: 3 days Differential Revision: https://reviews.freebsd.org/D58481 (cherry picked from commit b02e02958dad2d5ce3675cbc18b9a94635d09e66) M lib/libfetch/common.c _____________________________________________________________________________________________________________ Commit: f923f4739628fc5c80907dad8b69ae9b38269cd0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f923f4739628fc5c80907dad8b69ae9b38269cd0 Author: Pouria Mousavizadeh Tehrani (Thu 30 Jul 2026 14:41:51 BST) Committer: Pouria Mousavizadeh Tehrani (Sun 2 Aug 2026 14:19:47 BST) if_vxlan(4): Fix panic by validating unused drvspec values Add validation for unused parameter values in the gap between VXLAN_PARAM_WITH_LOCAL_ADDR4 and VXLAN_PARAM_WITH_LOCAL_ADDR6 to prevent panics. PR: 297151 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297151 ) Reported by: Robert Morris Reviewed by: markj MFC after: 3 days Differential Revision: https://reviews.freebsd.org/D58552 (cherry picked from commit c4d7745cd90fc99af3cbccfda7e11798ea7d187b) M sys/net/if_vxlan.c _____________________________________________________________________________________________________________ Commit: a5a16ba5f1791e1be87fede24887b469a9a0d911 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a5a16ba5f1791e1be87fede24887b469a9a0d911 Author: Alexander Leidinger (Sun 19 Jul 2026 08:38:52 BST) Committer: Alexander Leidinger (Sun 2 Aug 2026 13:12:07 BST) nullfs: close a race when syncing inotify flags from the lower vnode After a bypassed VOP, nullfs mirrors the lower vnode's inotify state onto the upper vnode. The flags were checked with lockless reads before being updated with the asserting flag set/unset primitives, so two threads syncing the same vnode concurrently (or a sync racing a watch being established) could both decide to make the same change; the loser then trips the "flags already set" assertion on an INVARIANTS kernel. On other kernels the race is harmless. Keep the lockless check as the fast path, but re-make the decision under the vnode interlock before actually changing the flags. Reproduced in a 4-CPU VM with one thread cycling an inotify watch on a lower-filesystem file while several threads stat(2) the same file through a nullfs mount: the unpatched INVARIANTS kernel panics under this load, the patched kernel runs it to completion. Fixes: f1f230439fa4 ("vfs: Initial revision of inotify") MFC after: 2 weeks Differential Revision: D58344 Reviewed by: markj Assisted-by: Claude Code (Fable 5) (cherry picked from commit d6915bffb7b68d9b55fa3db4e5709463549c379e) M sys/fs/nullfs/null_vnops.c _____________________________________________________________________________________________________________ Commit: afb2563fea724cba4e7e9028cded7e4e87775a63 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=afb2563fea724cba4e7e9028cded7e4e87775a63 Author: Roman Bogorodskiy (Thu 23 Jul 2026 17:16:36 BST) Committer: Roman Bogorodskiy (Sun 2 Aug 2026 11:48:17 BST) bhyve: tidy up bhyve_config.5 There are few warnings reported by mandoc -Tlint: bhyve_config.5:255:31: WARNING: new sentence, new line bhyve_config.5:257:43: WARNING: new sentence, new line bhyve_config.5:422:2: WARNING: missing section argument: Xr nm_open bhyve_config.5:469:24: WARNING: skipping no-space macro bhyve_config.5:483:2: WARNING: wrong number of cells: 2 columns, 4 cells bhyve_config.5:484:2: WARNING: wrong number of cells: 2 columns, 4 cells bhyve_config.5:541:24: WARNING: skipping no-space macro - "new sentence, new line" is a trivial formatting fix. - "missing section": there is actually no nm_open() manual page, so use .Nm instead of .Xr for it. - "no-space macro": format without .Oc and .Ns, similarly to how it is already done in bhyve.8 for VNC addresses. - "wrong number of cells": also a trivial fix. Reviewed by: jhb Sponsored by: The FreeBSD Foundation MFC after: 3 days Differential Revision: https://reviews.freebsd.org/D58415 (cherry picked from commit a2e5bac81e045f9991a997733391ddf1f19e40a8) M usr.sbin/bhyve/bhyve_config.5 _____________________________________________________________________________________________________________ Commit: a5b3b049fb37517b3efe50a87daf9eb02a6f0e47 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a5b3b049fb37517b3efe50a87daf9eb02a6f0e47 Author: Kevin Bowling (Sun 26 Jul 2026 01:10:38 BST) Committer: Kevin Bowling (Sun 2 Aug 2026 05:22:20 BST) igc(4): document adaptive interrupt moderation Describe the disabled, adaptive, and low-latency settings and their interrupt-rate tradeoffs. (cherry picked from commit 297394e995e5ea1ea9bc85e609ca116255d51e97) M share/man/man4/igc.4 _____________________________________________________________________________________________________________ Commit: adaa4c666ceedbed855e013700cc6cc9bf4c3749 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=adaa4c666ceedbed855e013700cc6cc9bf4c3749 Author: Kevin Bowling (Sun 26 Jul 2026 01:01:06 BST) Committer: Kevin Bowling (Sun 2 Aug 2026 05:22:08 BST) igc: count TSO wire segments in the AIM counters The transmit path bills one packet of ipi_len bytes per request. For TSO that is the whole unsegmented payload, up to 64 KiB, rather than a packet size that appears on the wire. Count the segments the hardware emits and the header carried by each segment. Non-TSO accounting is unchanged. (cherry picked from commit e389a05164ccb1dd41ee8d7f09203b475322dd72) M sys/dev/igc/igc_txrx.c _____________________________________________________________________________________________________________ Commit: 169f8c6a8470ca50b76567560b2c5e36dded8109 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=169f8c6a8470ca50b76567560b2c5e36dded8109 Author: Kevin Bowling (Sun 26 Jul 2026 01:00:22 BST) Committer: Kevin Bowling (Sun 2 Aug 2026 05:21:56 BST) igc: use packet-size AIM Use the packet-size calculation introduced for igb(4) in a69ed8dfb381 and retained there until the iflib conversion in f2d6ace4a684. It derives interrupt holdoff from average packet size, so RSS queue count does not change its behavior. The calculation follows the pre-iflib igb code. Retain igc's normal and low-latency rate caps, and keep the current setting when an interval has no usable sample. (cherry picked from commit 01e7acd38d411c78caba1c4078bb3683f586e1c2) M sys/dev/igc/if_igc.c M sys/dev/igc/if_igc.h _____________________________________________________________________________________________________________ Commit: a00bd480ea729f886f9e8b214b3bb06497b22637 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a00bd480ea729f886f9e8b214b3bb06497b22637 Author: Kevin Bowling (Sun 26 Jul 2026 00:58:58 BST) Committer: Kevin Bowling (Sun 2 Aug 2026 05:21:44 BST) igc: synchronize interrupt moderation state Keep the saved EITR value synchronized with hardware across reinitialization. Correct EITR encoding, decoding, and MSI-X register selection, and reject nonpositive fallback rates. Apply the packet-buffer fallback without permanently disabling AIM. (cherry picked from commit e35533457530bb9db655e6137c2eea790e18b97b) M sys/dev/igc/if_igc.c M sys/dev/igc/if_igc.h _____________________________________________________________________________________________________________ Commit: d93ee053130629115bb178e936160bfd86bb41e1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d93ee053130629115bb178e936160bfd86bb41e1 Author: Kevin Bowling (Sun 26 Jul 2026 00:57:42 BST) Committer: Kevin Bowling (Sun 2 Aug 2026 05:21:29 BST) igc: make AIM counter sampling coherent Sample free-running counters by delta instead of clearing them from the interrupt filter, which can race their producers. Publish byte and packet counts together at the TX and RX doorbells so each sample is coherent. Aggregate every TX ring assigned to the interrupt vector so unequal RX and TX queue counts are safe. Count RX bytes only after a frame is accepted. (cherry picked from commit 2290ea7f4311e899019fe77bf7c7775033af6b24) M sys/dev/igc/if_igc.c M sys/dev/igc/if_igc.h M sys/dev/igc/igc_txrx.c _____________________________________________________________________________________________________________ Commit: 37513bf193d9ab0fd768621256c0d0b3bcb1ba14 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=37513bf193d9ab0fd768621256c0d0b3bcb1ba14 Author: Kevin Bowling (Sun 26 Jul 2026 00:56:29 BST) Committer: Kevin Bowling (Sun 2 Aug 2026 05:21:17 BST) igc: fix RX accounting for multi-descriptor packets The receive path adds the running packet length to rx_bytes for every descriptor. A packet spanning descriptors of length l1, l2, and l3 is therefore counted as 3*l1 + 2*l2 + l3. Add each descriptor length once. Single-descriptor accounting remains unchanged. (cherry picked from commit bbf0372feeb321a5bfeff7b1e79576ab01240441) M sys/dev/igc/igc_txrx.c _____________________________________________________________________________________________________________ Commit: 871efe1300e3db4c6f49d751d37108592cec869b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=871efe1300e3db4c6f49d751d37108592cec869b Author: Kevin Bowling (Sat 25 Jul 2026 23:09:48 BST) Committer: Kevin Bowling (Sun 2 Aug 2026 05:21:05 BST) em(4): document adaptive interrupt moderation Describe the disabled, adaptive, and low-latency settings and their interrupt-rate tradeoffs. (cherry picked from commit b6b379b94781da5d4328f6f57273fbe7bd9dc687) M share/man/man4/em.4 _____________________________________________________________________________________________________________ Commit: 38450872031c92b5eb8cbc0f99d1261468fe3205 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=38450872031c92b5eb8cbc0f99d1261468fe3205 Author: Kevin Bowling (Sat 25 Jul 2026 13:33:38 BST) Committer: Kevin Bowling (Sun 2 Aug 2026 05:20:51 BST) e1000: count TSO wire segments in the AIM counters The transmit paths billed one packet of ipi_len bytes per request. For TSO that is the whole unsegmented payload, up to 64KB, so the average size the moderation calculation sees is not a size that appears on the wire. Count the segments the hardware will put on the wire and the header each of them carries. Non-TSO accounting is unchanged. (cherry picked from commit 072e0983d7bce80356740324973993393e77023a) M sys/dev/e1000/em_txrx.c M sys/dev/e1000/igb_txrx.c _____________________________________________________________________________________________________________ Commit: 5b380c2b183c915925d08c5535d17e4391251acb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5b380c2b183c915925d08c5535d17e4391251acb Author: Kevin Bowling (Sun 26 Jul 2026 00:49:31 BST) Committer: Kevin Bowling (Sun 2 Aug 2026 05:20:25 BST) e1000: restore packet-size AIM Restore the packet-size calculation introduced in a69ed8dfb381 and used by igb(4) until the iflib conversion in f2d6ace4a684. It derives interrupt holdoff from average packet size, so RSS queue count does not change its behavior. The calculation follows the pre-iflib code. Retain the current normal and low-latency rate caps, and keep the current setting when an interval has no usable sample. Fixes: 3e501ef89667 ("e1000: Re-add AIM") (cherry picked from commit dc4a5087b160c1a94d135ab636642defe2c71c20) M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 1c8d599a4ed88ecd88aaeaab17662b91f3f28ad7 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1c8d599a4ed88ecd88aaeaab17662b91f3f28ad7 Author: Kevin Bowling (Sun 26 Jul 2026 00:49:03 BST) Committer: Kevin Bowling (Sun 2 Aug 2026 05:20:00 BST) e1000: synchronize interrupt moderation state Keep the saved EITR and PBA values synchronized with hardware across reinitialization. Correct EITR encoding, decoding, and MSI-X register selection, and reject nonpositive fallback rates. Treat only sub-gigabit links as sub-gigabit and apply the packet-buffer fallback without permanently disabling AIM. (cherry picked from commit 6ef368a29b11ebc769e7929566809b75ae2c1e90) M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: e8cf1bfe07b0743adf6c9aa54309efde64a9dfa2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e8cf1bfe07b0743adf6c9aa54309efde64a9dfa2 Author: Kevin Bowling (Sun 26 Jul 2026 00:48:15 BST) Committer: Kevin Bowling (Sun 2 Aug 2026 05:19:46 BST) e1000: make AIM counter sampling coherent Sample free-running counters by delta instead of clearing them from the interrupt filter, which can race their producers. Publish byte and packet counts together at the TX and RX doorbells so each sample is coherent. Aggregate every TX ring assigned to the interrupt vector so unequal RX and TX queue counts are safe. Count RX bytes only after a frame is accepted. (cherry picked from commit bc5e7b0cbbb555ffebc7d73b273c421f9ee24c23) M sys/dev/e1000/em_txrx.c M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h M sys/dev/e1000/igb_txrx.c _____________________________________________________________________________________________________________ Commit: 9ddd9ff24bb1ebd0a432702d0057ad66a7277478 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9ddd9ff24bb1ebd0a432702d0057ad66a7277478 Author: Ed Maste (Tue 10 Mar 2026 21:13:31 GMT) Committer: Ed Maste (Sat 1 Aug 2026 16:30:12 BST) vidcontrol: Disallow -i mode with vt(4) vt(4) does not (currently) support changing the video mode. Report that -i mode is not supported rather than printing an empty list. PR: 207411 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=207411 ) Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58163 (cherry picked from commit c3e38c0093f2dbfafdfcc585a2f06b0313e7f6b1) M usr.sbin/vidcontrol/vidcontrol.c _____________________________________________________________________________________________________________ Commit: dd075ff0b08800fb56246837ee437189e18e3d65 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=dd075ff0b08800fb56246837ee437189e18e3d65 Author: Arthur Kiyanovski (Tue 14 Jul 2026 20:38:34 BST) Committer: Arthur Kiyanovski (Sat 1 Aug 2026 15:06:36 BST) ena: Update driver version to v2.8.4 Bug Fixes: * Fix false 'missing TX completions' warnings due to timestamp race * Put taskqueues into correct NUMA domain if !RSS Minor Changes: * Batch RX statistics updates * Swap RX/TX completions cleanup order Submitted by: Arthur Kiyanovski MFC after: 2 weeks Sponsored by: Amazon, Inc. Reviewed by: cperciva Differential Revision: https://reviews.freebsd.org/D58242 (cherry picked from commit 605e699cd6ca4feae6c73c5c5ea8337054897116) M sys/dev/ena/ena.h _____________________________________________________________________________________________________________ Commit: ff519eadf2228d97818be080ee18faec95e606c4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ff519eadf2228d97818be080ee18faec95e606c4 Author: Gilad Ben Yakov (Sun 21 Jun 2026 13:45:38 BST) Committer: Arthur Kiyanovski (Sat 1 Aug 2026 15:06:36 BST) ena: Fix false 'missing TX completions' warnings due to timestamp race Sporadic 'Found a Tx that wasn't completed on time' warnings appear under sustained TX load, always reporting '1 msecs since last cleanup' despite the 5-second timeout threshold. The per-packet TX timestamp uses struct bintime (128 bits: two 64-bit fields sec and frac) which is read and written non-atomically. A race exists between the missing TX completion check (check_missing_comp_in_tx_queue reading the timestamp) and the TX submit path or cleanup path writing it on another CPU. Since the two fields are not updated atomically, the check can observe a partially written timestamp - one field from the old value and one from the new. This can produce a timestamp with {sec=0, frac=valid}, causing the check to compute a time offset equal to system uptime and falsely exceeding the 5-second timeout. Confirmed by instrumentation showing all occurrences had sec=0 with valid frac/mbuf, cleanup_running=0, and ticks==last_cleanup_ticks. Replace struct bintime with sbintime_t (a single 64-bit value) for tx_buf->timestamp. An aligned 64-bit store/load cannot be torn on 64-bit architectures. Additionally, snapshot the timestamp into a local variable in the check path to prevent a read-then-read race where the timestamp could be zeroed between the zero-check and the offset calculation. Testing: On m6i.large (FreeBSD 15.0-RELEASE-p6 amd64, 2 IO queues), two instances with MTU 1500. Ran iperf -P 20 -u -b 320kpps (CPU saturated at ~7 Gbps aggregate). Without the fix: 8 warnings in 6 hours (first at ~72 min). With the fix: 0 warnings after 20+ hours under identical conditions. Fixes: 9b8d05b8ac78 ("Add support for Amazon Elastic Network Adapter (ENA) NIC") Submitted by: Gilad Ben Yakov MFC after: 2 weeks Sponsored by: Amazon, Inc. Reviewed by: cperciva Differential Revision: https://reviews.freebsd.org/D58241 (cherry picked from commit 74bcb1151bb94279a4269fc842aa2be00800545e) M sys/dev/ena/ena.c M sys/dev/ena/ena.h M sys/dev/ena/ena_datapath.c _____________________________________________________________________________________________________________ Commit: ae462f7fc72a2211665ffa4d4fde11a53ab1c16b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ae462f7fc72a2211665ffa4d4fde11a53ab1c16b Author: David Arinzon (Thu 16 Apr 2026 12:22:04 BST) Committer: Arthur Kiyanovski (Sat 1 Aug 2026 15:06:36 BST) ena: Batch RX statistics updates Move per-packet counter_enter/counter_exit pairs out of the RX processing loop and batch them into a single update after the loop completes. Previously, each received packet triggered two separate counter_enter/counter_exit blocks -- one for bytes and one for packet count. This commit accumulates totals in local variables and updates all four counters (ring and hw stats for both packets and bytes) in a single counter_enter/counter_exit block after the loop. Also move the stats update to after the refill and LRO flush so that the error path (goto update_stats) and the normal path converge at the same label, avoiding code duplication. Submitted by: David Arinzon MFC after: 2 weeks Sponsored by: Amazon, Inc. Reviewed by: cperciva Differential Revision: https://reviews.freebsd.org/D58240 (cherry picked from commit 3ba01cb4c61cc1e29c4d1d7ea4b73cdffb5ce3c2) M sys/dev/ena/ena_datapath.c _____________________________________________________________________________________________________________ Commit: 109a12abcb57ca8919e0142fe12608e25c07aace URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=109a12abcb57ca8919e0142fe12608e25c07aace Author: Arthur Kiyanovski (Tue 14 Jul 2026 21:20:06 BST) Committer: Arthur Kiyanovski (Sat 1 Aug 2026 15:06:36 BST) ena: Swap cleanup order As RX processing is heavier than TX completions processing, swap the order and process TX completions first, in order to avoid starving the completions and causing potential missing TX completions. Submitted by: Ofir Tabachnik MFC after: 2 weeks Sponsored by: Amazon, Inc. Reviewed by: cperciva Differential Revision: https://reviews.freebsd.org/D58239 (cherry picked from commit f08def9ed97f45700eb0611a3fd9240210c9303e) M sys/dev/ena/ena_datapath.c _____________________________________________________________________________________________________________ Commit: 03125b959758a5bfed0e4f10aa36a33fed279097 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=03125b959758a5bfed0e4f10aa36a33fed279097 Author: Kevin Bowling (Sat 25 Jul 2026 12:02:36 BST) Committer: Kevin Bowling (Sat 1 Aug 2026 01:24:33 BST) e1000: fix rx accounting for multi-descriptor packets The receive paths accumulate ri->iri_len across the descriptors making up a packet, then add that running total to rxr->rx_bytes on every iteration of the loop. A packet spanning descriptors of length l1, l2 and l3 thus contributes 3*l1 + 2*l2 + l3 instead of l1 + l2 + l3. Single descriptor packets, the common case, are accounted correctly, so this only shows up on jumbo frames. Add the per descriptor length instead. iflib memsets the if_rxd_info before each isc_rxd_pkt_get() call, so summing len gives the same total as the final iri_len, and the frame error path that returns without incrementing rx_packets keeps counting bytes exactly as before. (cherry picked from commit 41a46c2d46aa4078c597ce3a0d19323cab988277) M sys/dev/e1000/em_txrx.c M sys/dev/e1000/igb_txrx.c _____________________________________________________________________________________________________________ Commit: ec14a029fe73f7274668c41fa9e8073f3cf367ec URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ec14a029fe73f7274668c41fa9e8073f3cf367ec Author: Kevin Bowling (Sat 25 Jul 2026 22:00:10 BST) Committer: Kevin Bowling (Sat 1 Aug 2026 01:24:13 BST) e1000: Defer link-up notification until after TSO reset em_automask_tso() changes the enabled TSO capabilities when the link moves between 10/100 and 1000 Mb/s. A running interface must be reinitialized to apply the new capability set. Do not publish LINK_STATE_UP until the requested iflib reset has completed. Replace link_active with an explicit state machine that distinguishes the physical link, its publication to iflib, and an outstanding reset barrier. Preserve that barrier across a link flap with DOWN_RESET_PENDING, and only publish DOWN if UP was previously published. Only request a reset for a running interface or for an initialization while the interface is administratively up. In other states the next initialization will apply the capability changes, avoiding a reset request that iflib's admin task could discard. Reviewed by: Faraz Vahedi Fixes: 2ddf24f8f525 ("e1000: Automask TSO on lem(4)/em(4) 10/100 Ethernet") (cherry picked from commit 0bd6a167c1561f01c227b1c428a3d8adf0e38833) M sys/dev/e1000/if_em.c M sys/dev/e1000/if_em.h _____________________________________________________________________________________________________________ Commit: 7bea49bd865dc147d53272d0bb19f7caf3ede574 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7bea49bd865dc147d53272d0bb19f7caf3ede574 Author: Bjoern A. Zeeb (Mon 27 Jul 2026 15:33:52 BST) Committer: Bjoern A. Zeeb (Fri 31 Jul 2026 18:45:37 BST) mt76: mt7921: update man page Adjust the man page to what other LinuxKPI wlan man pages say and look like as it has been a while since I wrote it. The man page is not yet hooked up to the build on purpose as the driver is not yet enabled in the tree. Sponsored by: The FreeBSD Foundation Reviewed by: ziaee (earlier version) Differential Revision: https://reviews.freebsd.org/D58479 (cherry picked from commit 3afa2628ccd22f81527406bbf6a4dca54d964afc) M share/man/man4/mt7921.4 _____________________________________________________________________________________________________________ Commit: 42b89d49b7ab87054615b422518d53015953bc27 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=42b89d49b7ab87054615b422518d53015953bc27 Author: Jim Chen (Mon 27 Jul 2026 14:01:23 BST) Committer: Bjoern A. Zeeb (Fri 31 Jul 2026 18:45:33 BST) mt76: update script to to deal with 7921 and 7925 flavors Update the mt76/zzz_fw_ports_fwget.sh script to set fwget to download mt7921 and mt7925 rather than the these days non-existent mt792x flavor. Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57242 (cherry picked from commit b1f3726f7a677ae230135d19491ce97f2866e7c2) M sys/contrib/dev/mediatek/mt76/zzz_fw_ports_fwget.sh _____________________________________________________________________________________________________________ Commit: 3b569c3e1ec629896ebaaf7268223585cd152512 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3b569c3e1ec629896ebaaf7268223585cd152512 Author: Jim Chen (Mon 27 Jul 2026 13:47:53 BST) Committer: Bjoern A. Zeeb (Fri 31 Jul 2026 18:45:25 BST) fwget: update MediaTek firmware listings to match ports Update fwget(8) to download wifi-firmware-mt76-kmod-mt7921, and wifi-firmware-mt76-kmod-mt7925 firmware packages instead of the no longer available mt792x version. Add another PCI vendor to recognize ITTIM IDs for mt7921-based MediaTek cards. (bz reduced the license in the ittim file to an SPDX tag and updated the commit message, given this is only half the work from the review) Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57242 (cherry picked from commit 7925256edc74a8c60435dce1c2c2a8f3dd1ef1a3) M usr.sbin/fwget/pci/pci A usr.sbin/fwget/pci/pci_network_ittim M usr.sbin/fwget/pci/pci_network_mediatek _____________________________________________________________________________________________________________ Commit: 2389c5d8b4715140897bf9670536ab0968eb1a8d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2389c5d8b4715140897bf9670536ab0968eb1a8d Author: Kevin Bowling (Sat 25 Jul 2026 11:43:28 BST) Committer: Kevin Bowling (Fri 31 Jul 2026 01:50:08 BST) e1000: fix 82574 MSI-X interrupt throttling em_newitr() and the per-queue interrupt_rate sysctl both tested que->msix to decide whether an 82574 is running in MSI-X mode. 0 is a valid MSI-X vector so queue 0 was misclassified as legacy/MSI. Test sc->intr_type == IFLIB_INTR_MSIX instead. While here, index the tx EITR read by tque->msix rather than tque->me so it matches the register em_newitr() actually writes; the two differ once tx_num_queues exceeds rx_num_queues. Also seed que->itr_setting in em_initialize_receive_unit() with the rate the hardware was just programmed with. Otherwise an itr_setting left over from AIM across an interface re-init makes the change detection in em_newitr() suppress the write that would restore it, leaving the hardware at the default rate while software believes otherwise. Fixes: 3e501ef89667 ("e1000: Re-add AIM") (cherry picked from commit 941113a0097ea047bd493f7f78b384718249779d) M sys/dev/e1000/if_em.c _____________________________________________________________________________________________________________ Commit: ac2ebda1afd5b17314cdd457812804a417ab0a49 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ac2ebda1afd5b17314cdd457812804a417ab0a49 Author: Lexi Winter (Thu 30 Jul 2026 14:39:25 BST) Committer: Lexi Winter (Thu 30 Jul 2026 18:09:01 BST) packages/tests: Fix gtest dependency The MFC of 1d0ae66d3c21 (packages subdir build) added a dependency from FreeBSD-tests on FreeBSD-googletest. However, the googletest package doesn't exist in 15 because the relevant commit wasn't MFC'd. This caused a broken and unresolvable dependency. Replace the incorrect googletest dependency with a dependency on utilities. This is a direct commit to stable/15. Fixes: 1d0ae66d3c21 ("packages: Convert world to a subdir build") Reviewed by: cperciva Reported by: Mark Millard Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58553 M packages/tests/Makefile _____________________________________________________________________________________________________________ Commit: 9b6287c7e18ae43a126b24f4bf202e78af43527e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9b6287c7e18ae43a126b24f4bf202e78af43527e Author: Cy Schubert (Thu 16 Jul 2026 17:28:15 BST) Committer: Cy Schubert (Thu 30 Jul 2026 15:04:29 BST) krb5: Install profile.h again Commit 1876de606eb8 exposed missing symbols that the port security/krb5 installed that the base system did not install. Part of the solution was to make libprofile.so private (not libprofile.a) just as the port does, Red Hat Enterprise Linux does, and as installing MIT KRB5 by hand does. The actual fix for this was to put symbols and their corresponding functions into the correct librarires, i.e. libkrb5.so and othes, just as the port, Red Hat, and manually installed via tarball do. Unfortunately INTERNALLIB disables the include of bsd.incs.mk and the install of header files. This is still needed to install profile.h into /usr/include (just as the port installs it into ${LOCALBASE}/include and RHEL installs it in /usr/include). This commit fixes this by installing profile.h into /usr/include from the krb5/include Makfile. Reported by: fluffy Tested by: fluffy Reviewed by: fluffy Fixes: 1876de606eb8 Differential Revision: https://reviews.freebsd.org/D58286 (cherry picked from commit cf3eeeb75ceb7428c351218e6bd755e11613a633) M krb5/include/Makefile M krb5/util/profile/Makefile A krb5/util/profile/Makefile.profile _____________________________________________________________________________________________________________ Commit: bf0ffcaa564949f2eb086a05f718d2f358c7afec URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bf0ffcaa564949f2eb086a05f718d2f358c7afec Author: Konstantin Belousov (Tue 28 Jul 2026 02:00:17 BST) Committer: Konstantin Belousov (Thu 30 Jul 2026 03:52:11 BST) mknod.2: properly document root requirements PR: 297082 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297082 ) (cherry picked from commit a3b5937da6159bcdaf4e635a0ad20013d4c3734d) M lib/libsys/mknod.2 _____________________________________________________________________________________________________________ Commit: 361ee195955f492ce283b2bd8bd07d864b9f6b43 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=361ee195955f492ce283b2bd8bd07d864b9f6b43 Author: Konstantin Belousov (Mon 27 Jul 2026 15:14:51 BST) Committer: Konstantin Belousov (Thu 30 Jul 2026 03:50:49 BST) mknod.2: update the man page PR: 297082 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=297082 ) (cherry picked from commit 4090d103b0c31b44b269e0ccf758be5cfba3f60c) M lib/libsys/mknod.2 _____________________________________________________________________________________________________________ Commit: 26cad57094d1088ddb94abb64b2c2eb7dc91f0f6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=26cad57094d1088ddb94abb64b2c2eb7dc91f0f6 Author: Konstantin Belousov (Sat 25 Jul 2026 21:02:24 BST) Committer: Konstantin Belousov (Thu 30 Jul 2026 03:50:49 BST) pthread_cond_wait.3: describe spurious wakeups (cherry picked from commit 3c6f63902b037e36648fae435d4d5f56f9dc389b) M share/man/man3/pthread_cond_wait.3 _____________________________________________________________________________________________________________ Commit: 23216f6309c6368324fa7aefa8385a7b63b0be3b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=23216f6309c6368324fa7aefa8385a7b63b0be3b Author: Lexi Winter (Sun 19 Jul 2026 13:45:43 BST) Committer: Lexi Winter (Wed 29 Jul 2026 20:42:12 BST) certctl: Enforce 0444 mode on new files When writing to a file, call fchmod() to ensure the file mode matches the intended mode, which is 0444. This was already done when replacing an existing file, but not when creating a new file, which meant if the process umask was 077, the resulting certificates and bundle would be unreadable by unprivileged users. MFC after: 1 week Reviewed by: des Differential Revision: https://reviews.freebsd.org/D58304 (cherry picked from commit 02f174179a538f89185d275b4e64277baf3acc50) M usr.sbin/certctl/certctl.c _____________________________________________________________________________________________________________ Commit: 008d3bafa124fc0751cbacbd0557cb1927856624 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=008d3bafa124fc0751cbacbd0557cb1927856624 Author: Mark Johnston (Mon 27 Jul 2026 16:42:49 BST) Committer: Mark Johnston (Wed 29 Jul 2026 18:48:13 BST) coredump: Don't assume that the number of ELF segments is consistent In an ELF coredump, each dumped vm_map_entry is represented by a segment. __elfN(coredump) first computes the number of segments by looping over the vm_map entries (in each_dumpable_segment()), then allocates a buffer to hold the ELF header and program headers, then loops over the entries again to populate the program headers. each_dumpable_segment() holds the vm_map read lock, but that lock is dropped between the two calls. If the map is shared with another process, via rfork(), then the map can change. cb_put_phdr() did not account for this, and so could write out of bounds. Add a check to prevent this; simply do not write out excess segments. Approved by: so Security: FreeBSD-SA-26:55.elf Security: CVE-2026-58088 Reported by: Maik Muench of Secfault Security Reviewed by: kib, emaste Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58416 M sys/kern/imgact_elf.c _____________________________________________________________________________________________________________ Commit: e2585687890e449850497b6f018b1fd53d944611 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e2585687890e449850497b6f018b1fd53d944611 Author: Mark Johnston (Mon 27 Jul 2026 16:41:30 BST) Committer: Mark Johnston (Wed 29 Jul 2026 18:48:13 BST) sysvsem: Fix a TOCTOU race in semctl({GET,SET}ALL) These commands take a snapshot of the size of a semaphore set, then drop the lock and malloc an appropriately sized array before reacquiring the lock. A comment explains why this is (probably) safe. Unfortunately, it's wrong; it is indeed possible for a malicious userspace to create and destroy 2^{15} sets in the window where the lock is dropped. This race can lead to out-of-bounds reads and writes, and that can be exploited to elevate privileges. Replace the assertions with runtime checks. Approved by: so Security: FreeBSD-SA-26:54.sysvsem Security: CVE-2026-58087 Reported by: Maik Muench of Secfault Security Reviewed by: kib Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58421 M sys/kern/sysv_sem.c _____________________________________________________________________________________________________________ Commit: fb432f55a7b8bfcdc1ec4a24b1c861f15b867da5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fb432f55a7b8bfcdc1ec4a24b1c861f15b867da5 Author: Alexander Leidinger (Fri 17 Jul 2026 22:33:00 BST) Committer: Mark Johnston (Wed 29 Jul 2026 18:48:13 BST) jail: restore ktrace privileges for jailed root Commit 4be491e1b9b3 ("jail: Optionally allow audit session state to be configured in a jail") removed the #if 0 around the audit cases in prison_priv_check() and added the PR_ALLOW_SETAUDIT check under them. This unintentionally captured the preceding case PRIV_KTRACE, which used to fall through the disabled block into the unconditional return (0) of the credential cases: since then, jailed root only has ktrace privileges (tracing processes with changed credentials, see ktrcanset()) when the unrelated allow.setaudit knob is enabled, and conversely gains them when that audit knob is turned on. Give PRIV_KTRACE back its own unconditional return (0), matching its comment and the pre-4be491e1b9b3 behaviour. Approved by: so Security: FreeBSD-SA-26:53.ktrace Security: CVE-2026-58086 Fixes: 4be491e1b9b3 ("jail: Optionally allow audit session state to be configured in a jail") Reviewed by: markj Assisted-by: Claude Code (Fable 5) M sys/kern/kern_jail.c _____________________________________________________________________________________________________________ Commit: 4c40cb62935fbda670aaa69929dbf4e83cc3a1df URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4c40cb62935fbda670aaa69929dbf4e83cc3a1df Author: John Baldwin (Mon 27 Jul 2026 16:37:43 BST) Committer: Mark Johnston (Wed 29 Jul 2026 18:48:13 BST) wg(4): Add a test that the driver handles a decryption failure The test uses a fail point to inject a decryption error in OCF while sending a ping across the tunnel. The driver should then fail to respond to the ping and increment the input error counter on the interface. Approved by: so Security: FreeBSD-SA-26:52.if_wg Security: CVE-2026-58085 Reviewed by: markj Sponsored by: Chelsio Communications M etc/mtree/BSD.tests.dist M tests/sys/net/Makefile A tests/sys/net/wg/Makefile A tests/sys/net/wg/if_wg_nojail.sh _____________________________________________________________________________________________________________ Commit: dbd55933cbcb8d801a6e813a2dbbcf19f4e0f75f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=dbd55933cbcb8d801a6e813a2dbbcf19f4e0f75f Author: John Baldwin (Mon 27 Jul 2026 16:36:55 BST) Committer: Mark Johnston (Wed 29 Jul 2026 18:48:13 BST) wg(4): Check for crypto operation errors In particular, handle authentication errors due to bad MACs when decrypting packets. Since the current dispatch code assumes synchronous OCF sessions by design, explicitly reject any created OCF session that is not synchronous. Software sessions are always synchronous in practice, so this should be a nop. Approved by: so Security: FreeBSD-SA-26:52.if_wg Security: CVE-2026-58085 Reviewed by: markj Sponsored by: Chelsio Communications M sys/dev/wg/wg_crypto.c _____________________________________________________________________________________________________________ Commit: cd144735858a8721898ff3f3904b41546c78de5d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cd144735858a8721898ff3f3904b41546c78de5d Author: John Baldwin (Mon 27 Jul 2026 16:36:22 BST) Committer: Mark Johnston (Wed 29 Jul 2026 18:48:13 BST) OCF: Add a fail point to inject EBADMSG decryption errors Approved by: so Security: FreeBSD-SA-26:52.if_wg Security: CVE-2026-58085 Reviewed by: markj Sponsored by: Chelsio Communications M sys/opencrypto/crypto.c _____________________________________________________________________________________________________________ Commit: cb7cb40ae47b3d62317f3a554e9a491d4a105eb4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cb7cb40ae47b3d62317f3a554e9a491d4a105eb4 Author: Mark Johnston (Mon 27 Jul 2026 16:28:50 BST) Committer: Mark Johnston (Wed 29 Jul 2026 18:48:13 BST) kqueue: Avoid enqueuing an already-enqueued knote knotes with a non-trivial f_copy implementation may be activated before kqueue_fork_copy_knote() is finished. In particular, it may be enqueued at the time that kqueue_fork_copy_knote() calls knote_enqueue(). Guard against this. Add a test case which triggers the race. Fix several other problems with the replication of knote state: - Make sure only the KN_ACTIVE and KN_DISABLED status flags are inherited, the rest should not be copied. - Ignore marker knotes. - Ignore knotes for kqueues. They cannot be safely copied into the child without more work, as kqueues are inherently local to a process; on fork, we need to ensure that such knotes are patched to reference the new kqueue, not the original. - Try to keep knote state stable by holding the kqueue and knlist locks while copying. Approved by: so Security: FreeBSD-SA-26:50.kqueue Security: CVE-2026-58083 Reviewed by: kib Reported by: Hazley Samsudin of GovTech CSG Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58223 M sys/kern/kern_event.c M sys/sys/event.h M tests/sys/kqueue/kqueue_fork.c _____________________________________________________________________________________________________________ Commit: d68de8c2cd953a8df9db63ae50a9eb3e7f6d96dc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d68de8c2cd953a8df9db63ae50a9eb3e7f6d96dc Author: Kristof Provost (Tue 21 Jul 2026 14:10:16 BST) Committer: Kristof Provost (Wed 29 Jul 2026 08:21:15 BST) authpf(8) read_config() should chop off trailing white space if administrator mistakenly types into configuration file anchor=authpf_test where 'authpf_test' is followed by white space, the authpf(8) is going to use anchor 'authpf_test ' instead of the 'authpf_test' which is defined in pf.conf(5) as 'anchor authpf_test/*' issue kindly reported and patch submitted by Avinash Duduskar OK sashan@ PR: 296958 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296958 ) MFC after: 1 week Obtained from: OpenBSD, sashan , 2d12a8e44d Sponsored by: Rubicon Communications, LLC ("Netgate") (cherry picked from commit 04f25ef716f74d6bb7941750091c6cb4b51d0b4d) M contrib/pf/authpf/authpf.c _____________________________________________________________________________________________________________ Commit: e7381649048feb2e30f2aef2dac0e4924e7d815a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e7381649048feb2e30f2aef2dac0e4924e7d815a Author: Colin Percival (Tue 28 Jul 2026 02:43:30 BST) Committer: Colin Percival (Wed 29 Jul 2026 01:33:09 BST) make-pkg-package.sh: Fix build for pkg 2.8.0 We used to pass CONFIGURE_ARGS to the make command which builds pkg, but ports/ports-mgmt/pkg/Makefile has its own CONFIGURE_ARGS and the version we were providing at the command line didn't contain the --mandir setting which was added to the port with pkg 2.8.0. This broke release builds. Instead of passing --prefix=${LOCALBASE} via CONFIGURE_ARGS, pass PREFIX=${LOCALBASE}; the port Makefile passes that value through to its configure script. We also used to pass a --host parameter, but that seems to have become unnecessary at some point in the past decade. MFC after: 1 day Sponsored by: Amazon (cherry picked from commit 8d92f32ae011719b322b9943d01529cebef741f0) M release/scripts/make-pkg-package.sh _____________________________________________________________________________________________________________ Commit: 08dbff58cd2136a8686067e188bc657f995b99b6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=08dbff58cd2136a8686067e188bc657f995b99b6 Author: Ed Maste (Fri 14 Nov 2025 19:52:12 GMT) Committer: Ed Maste (Tue 28 Jul 2026 14:47:00 BST) aq(4): Add man page Reviewed by: ziaee Relnotes: Yes Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D53840 (cherry picked from commit fb1994e03c88cf087e61f7aa608dd82531e3a4e8) M share/man/man4/Makefile A share/man/man4/aq.4 _____________________________________________________________________________________________________________ Commit: 031d15d1257708c606491ad5a9b2a6c2f4bca8f8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=031d15d1257708c606491ad5a9b2a6c2f4bca8f8 Author: Ed Maste (Thu 13 Nov 2025 19:05:38 GMT) Committer: Ed Maste (Tue 28 Jul 2026 14:47:00 BST) aq(4): Add build infrastructure Reviewed by: adrian Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D53839 (cherry picked from commit 75177aebf0397af36b1f28f6b6e64207ec3d8188) (cherry picked from commit 7f3da1f800f77150fab2a07ce9cafdca41b29ee9) M sys/conf/files M sys/modules/Makefile A sys/modules/aq/Makefile _____________________________________________________________________________________________________________ Commit: 15671c24adbed3460e62da38103c10d12c105647 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=15671c24adbed3460e62da38103c10d12c105647 Author: Ed Maste (Mon 4 May 2026 16:33:24 BST) Committer: Ed Maste (Tue 28 Jul 2026 14:29:50 BST) usbdevs: Add Microchip 10BASE-T1S eval board USB vendor:product 184f:0051 Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D56794 (cherry picked from commit 707ee7ff952c5aa50884f96f7ed26f756c9723b5) M sys/dev/usb/usbdevs _____________________________________________________________________________________________________________ Commit: d4b36d6b18384010aa7aa0387ea1bba1c8758e29 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d4b36d6b18384010aa7aa0387ea1bba1c8758e29 Author: Dimitry Andric (Tue 28 Jul 2026 14:04:22 BST) Committer: Dimitry Andric (Tue 28 Jul 2026 14:04:22 BST) Revert "Add a few missed files to ObsoleteFiles.inc" This reverts commit 2e089a89812b56329741cd8dc2d272405a6e73ff, because some of the directories and files are still being installed. M ObsoleteFiles.inc _____________________________________________________________________________________________________________ Commit: 6afb2b8e2fa7608b9e3e3ec2035319cca00481ce URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6afb2b8e2fa7608b9e3e3ec2035319cca00481ce Author: Siva Mahadevan (Wed 22 Jul 2026 02:27:11 BST) Committer: Alexander Leidinger (Tue 28 Jul 2026 11:04:53 BST) tests/exterr_test: use ATF_REQUIRE_FEATURE to check exterr_strings This keeps the skipped test message consistent with others. Reviewed by: netchild MFC after: 3 days Sponsored by: The FreeBSD Foundation (cherry picked from commit 3e946566c134e039f9c777eaa1232a32e383692c) M tests/sys/kern/Makefile M tests/sys/kern/exterr_test.c _____________________________________________________________________________________________________________ Commit: 81011ca4c0a8ba7e7911b128c187de38efa3c59d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=81011ca4c0a8ba7e7911b128c187de38efa3c59d Author: Alexander Leidinger (Tue 21 Jul 2026 21:39:57 BST) Committer: Alexander Leidinger (Tue 28 Jul 2026 11:04:52 BST) exterror tests: harden the checks Skip the message-content check on kernels that do not advertise the exterr_strings feature, and pin the output format by clearing EXTERROR_VERBOSE. Reviewed by: kib MFC after: 1 week Assisted-by: Claude Code (Fable 5) Differential Revision: https://reviews.freebsd.org/D58322 (cherry picked from commit 1092aba1260ce5efb0d718352aa22158605c7506) M tests/sys/kern/exterr_test.c _____________________________________________________________________________________________________________ Commit: c724b26acd59fe5078c5e64e707303ef9c2c522c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c724b26acd59fe5078c5e64e707303ef9c2c522c Author: Alexander Leidinger (Tue 21 Jul 2026 21:39:56 BST) Committer: Alexander Leidinger (Tue 28 Jul 2026 11:04:41 BST) exterror: advertise error strings via kern.features.exterr_strings Allow userland, in particular test cases for EXTERROR conversions, to detect at run time whether extended errors include the descriptive message strings, which depends on the EXTERR_STRINGS kernel option and cannot be probed in any other way. Reviewed by: kib MFC after: 1 week Assisted-by: Claude Code (Fable 5) Differential Revision: https://reviews.freebsd.org/D58321 (cherry picked from commit c8db6d4b63f18c81557628ad0d3f715bea46cc99) M share/man/man9/exterror.9 M sys/kern/sys_generic.c _____________________________________________________________________________________________________________ Commit: 91110e5b2438f23bb529a7af5d5cd1681366181d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=91110e5b2438f23bb529a7af5d5cd1681366181d Author: Dag-Erling Smørgrav (Wed 22 Jul 2026 07:04:18 BST) Committer: Dag-Erling Smørgrav (Tue 28 Jul 2026 10:32:28 BST) install: Fix typo MFC after: 1 week Reported by: markj Fixes: d34870708db9 ("install: Allow installing stdin") (cherry picked from commit 0eef3d01c22a5e00cd2cf10c34871eddbfd22aa0) M usr.bin/xinstall/xinstall.c _____________________________________________________________________________________________________________ Commit: c8a0269f74b687d7d96c0d33d0cc26df10a83142 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c8a0269f74b687d7d96c0d33d0cc26df10a83142 Author: Dag-Erling Smørgrav (Tue 21 Jul 2026 09:03:49 BST) Committer: Dag-Erling Smørgrav (Tue 28 Jul 2026 10:32:28 BST) install: Code cleanup This is mainy focused on using bool for booleans but also renames some variables for clarity, adds some explicit comparisons, adds some braces, with miscellanous style fixes thrown in. MFC after: 1 week Reviewed by: imp Differential Revision: https://reviews.freebsd.org/D58355 (cherry picked from commit 134ddd372f8213885dd828ab38cec2384fd451db) M usr.bin/xinstall/xinstall.c _____________________________________________________________________________________________________________ Commit: 993df5472e52f1fce7d527fcd35a5d0a7d51dde0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=993df5472e52f1fce7d527fcd35a5d0a7d51dde0 Author: Dag-Erling Smørgrav (Tue 21 Jul 2026 09:03:44 BST) Committer: Dag-Erling Smørgrav (Tue 28 Jul 2026 10:32:28 BST) install: Allow installing stdin If from_name is "/dev/stdin" or "-" and the target is not a directory, skip the comparison and copy data from standard input to the target. MFC after: 1 week Reviewed by: imp Differential Revision: https://reviews.freebsd.org/D58348 (cherry picked from commit d34870708db9fa1eb8e29b5e085b755de1189b1f) M usr.bin/xinstall/install.1 M usr.bin/xinstall/tests/install_test.sh M usr.bin/xinstall/xinstall.c _____________________________________________________________________________________________________________ Commit: baf4c5992c0a1021b8036afa5429374b5b62d878 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=baf4c5992c0a1021b8036afa5429374b5b62d878 Author: Aleksandr Rybalko (Mon 8 Jun 2026 15:32:05 BST) Committer: Dag-Erling Smørgrav (Tue 28 Jul 2026 10:30:21 BST) install: drop obsolete file size limit for -C Removes the file size limit for -C comparisons. The limit was meant to prevent oversized mmap allocations, which is no longer relevant as mmap is no longer used here (removed by a0439a1b820fa0e742c00d095f5f5c06f5f19432, review D44809). Credit to bdrewery. See: https://reviews.freebsd.org/D57230 Reviewed by: bdrewery, glebius, ziaee Approved by: glebius (mentor) Obtained from: Fudo Security MFC after: 2 weeks Sponsored by: Fudo Security Differential Revision: https://reviews.freebsd.org/D57503 (cherry picked from commit 9d10b4d2c9e86d8f6ff1b654f468381a4a4cad6d) M usr.bin/xinstall/Makefile M usr.bin/xinstall/install.1 M usr.bin/xinstall/xinstall.c _____________________________________________________________________________________________________________ Commit: 2879ea7c29678ddaf4164c897b1086ad67224b9c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2879ea7c29678ddaf4164c897b1086ad67224b9c Author: Aleksandr Rybalko (Wed 27 May 2026 13:07:47 BST) Committer: Dag-Erling Smørgrav (Tue 28 Jul 2026 10:30:21 BST) install: Bump compare size limit (128MB) to support large binaries Preserve metadata and prevent redundant disk writes during builds with the install's -C (compare) flag. The previous historical comparison limit of 16MB is insufficient for modern toolchains, frequently choked or bypassed by a large base components like LLVM/Clang, kernels, Rust apps, and large runtime libraries. By leaving matching files alone, install keeps their modification timestamps intact. make(1) safely ignores those files on subsequent runs. Base examples: 15.0 amd64 GENERIC kernel - 28MB, clang - 105MB, lldb - 97MB, etc. Reviewed by: glebius Approved by: glebius (mentor) Obtained from: Fudo Security MFC after: 2 weeks Sponsored by: Fudo Security Differential Revision: https://reviews.freebsd.org/D57271 (cherry picked from commit 5a8e0e03ae86b449f29626b4f9db25d17c89b273) M usr.bin/xinstall/xinstall.c _____________________________________________________________________________________________________________ Commit: 5fb605771bcd1545f465bdaaac27e7488fb5bb08 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5fb605771bcd1545f465bdaaac27e7488fb5bb08 Author: Aleksandr Rybalko (Mon 25 May 2026 08:53:20 BST) Committer: Dag-Erling Smørgrav (Tue 28 Jul 2026 10:30:21 BST) install: add -z option Introduces the -z flag, enabling users to set a custom file size limit for pre-installation change checks and avoiding future hard-coded limit modifications. Reviewed by: glebius Approved by: glebius (mentor) Obtained from: Fudo Security MFC after: 2 weeks Sponsored by: Fudo Security Differential Revision: https://reviews.freebsd.org/D57230 (cherry picked from commit 97cad013a50a4012328e11424ed2350c1efc036c) M usr.bin/xinstall/Makefile M usr.bin/xinstall/install.1 M usr.bin/xinstall/xinstall.c _____________________________________________________________________________________________________________ Commit: 3f99b452687c1b6eac1ec41bc885518f260f446f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3f99b452687c1b6eac1ec41bc885518f260f446f Author: Dag-Erling Smørgrav (Tue 21 Jul 2026 09:03:05 BST) Committer: Dag-Erling Smørgrav (Tue 28 Jul 2026 10:22:21 BST) nvme: Explicitly cast caddr_t values Sponsored by: Klara, Inc. Sponsored by: NetApp, Inc. MFC after: 1 week Fixes: 6d0001d44490 ("nvme: add support for DIOCGIDENT") Reviewed by: bnovkov, imp Differential Revision: https://reviews.freebsd.org/D58357 (cherry picked from commit bd30d1ad78e152d0a963bc873643a911321cca6e) M sys/dev/nvme/nvme_ns.c _____________________________________________________________________________________________________________ Commit: 0bed75d1e810fa343f3600171c511d0e822ac603 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0bed75d1e810fa343f3600171c511d0e822ac603 Author: Dag-Erling Smørgrav (Tue 21 Jul 2026 08:59:43 BST) Committer: Dag-Erling Smørgrav (Tue 28 Jul 2026 10:22:21 BST) wpa: Define CONFIG_DEBUG_FILE globally We defined CONFIG_DEBUG_FILE only in libwpautils, not in wpa_supplicant, so all it did was enable code that never got called. Enable it at the top level so it also applies to wpa_supplicant(8), and the -f option mentioned in the manual page now actually works. PR: 281617 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=281617 ) MFC after: 1 week Reviewed by: cy Differential Revision: https://reviews.freebsd.org/D57723 (cherry picked from commit 67518c9f565b61bc5eebe33b6a956e2cc9b3f223) M usr.sbin/wpa/Makefile.inc M usr.sbin/wpa/src/utils/Makefile _____________________________________________________________________________________________________________ Commit: ee9a8a9730beab01d94f7d675c82d195a91876d6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ee9a8a9730beab01d94f7d675c82d195a91876d6 Author: Richard Scheffenegger (Tue 21 Jul 2026 15:51:02 BST) Committer: Richard Scheffenegger (Tue 28 Jul 2026 09:28:59 BST) tcp_hostcache: explicitly typecast atomic_load_int to (int) for comparison Sponsored by: NetApp, Inc. MFC after: 1 week Reviewed By: tuexen, #transport, markj Differential Revision: https://reviews.freebsd.org/D58360 (cherry picked from commit f22b08443f6ae3620dd14ade4e2376b8531fd6f3) M sys/netinet/tcp_hostcache.c _____________________________________________________________________________________________________________ Commit: c8e8fa04dc05a1f23be4d618b52d68b6d2820aac URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c8e8fa04dc05a1f23be4d618b52d68b6d2820aac Author: Gordon Bergling (Sun 12 Jul 2026 11:25:01 BST) Committer: Gordon Bergling (Tue 28 Jul 2026 06:36:09 BST) tcp_bblog.4: Add a manual page for TCP Blackbox Logging The tcp_bblog facility provides structured logging of TCP stack activity for debugging and performance analysis. It is implemented in the kernel and allows per-connection tracing of TCP events with low overhead. Reviewed by: tuexen, ziaee Relnotes: yes Differential Revision: https://reviews.freebsd.org/D56252 (cherry picked from commit 62e22d7cfc1ca1c25bede6aaeca370c163a9a1ef) M share/man/man4/Makefile A share/man/man4/tcp_bblog.4 _____________________________________________________________________________________________________________ Commit: 3701716fdc45c203951f44d01710da310204b629 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3701716fdc45c203951f44d01710da310204b629 Author: Mark Johnston (Fri 17 Jul 2026 13:57:06 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:32 BST) vm_page: Fix dequeue on arches with weak ordering A vm_page's a.queue field records the page queue index for the page queue to which the page belongs. The PGA_ENQUEUED flag indicates whether the page is actually enqueued in that queue's TAILQ. When modifying the a.queue field, you need to hold the page queue lock for the queue corresponding to the old value, unless the old value is PQ_NONE. Suppose a managed page is freed. vm_page_free_prep() calls vm_page_dequeue_deferred(), which checks whether the page belongs to a queue; if so it schedules an asynchronous dequeue operation so that page queue lock acquisitions can be batched if possible. The dequeue operation must be completed before the page's plinks.q fields are reused. So, during page allocation, we call vm_page_dequeue() to finish the dequeue operation. Similarly, since the buddy allocator uses the plinks.q fields for its own internal linkage, vm_freelist_add() calls vm_page_dequeue(). _vm_page_pqstate_commit_dequeue() is the function which actually removes the page from its queue. It sets a.queue = PG_NONE and removes the page from its queue. However, the update to the page's atomic state is relaxed, so on systems with store reordering, it may race with a concurrent enqueue of the page into the buddy queues (probably more likely) or a page queue. Fix this: use a release store to update the page's queue state in _vm_page_pqstate_commit_dequeue(), and make sure that vm_page_dequeue() uses an acquire load when comparing m->a.queue == PQ_NONE. PR: 296767 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296767 ) Reported and tested by: pkubaj Reviewed by: alc, kib MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D58261 (cherry picked from commit d809a10218884162ed47c658233746c53a98b1aa) M sys/vm/vm_page.c M sys/vm/vm_page.h _____________________________________________________________________________________________________________ Commit: aa3989f2932a52d7c606e15f353c90670141b7cf URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=aa3989f2932a52d7c606e15f353c90670141b7cf Author: Hareshx Sankar Raj (Wed 24 Jun 2026 16:08:16 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:32 BST) qat: driver updates to enhance qat infrastructure - Updated QAT infrastructure FW version/AE mask/num_banks fields to facilitate integration of future QAT products. - Exposed service as sym;asym instead of cy for gen4 - Enhanced cpaGetInstances() for accurate instance retrieval - Added 57-bit virtual address support to lac_lock_free_stack - Minor bug fixes and improvements Signed-off-by: Hareshx Sankar Raj Reviewed by: markj MFC after: 1 month Differential Revision: https://reviews.freebsd.org/D57746 (cherry picked from commit 682f135f5de39cfc24cfd529ea8a161e94c76c8e) M sys/contrib/dev/qat/LICENSE M sys/dev/qat/include/adf_gen4vf_hw_csr_data.h M sys/dev/qat/include/common/adf_accel_devices.h M sys/dev/qat/include/common/adf_common_drv.h M sys/dev/qat/include/common/adf_gen2_hw_data.h M sys/dev/qat/include/common/adf_gen4_hw_data.h M sys/dev/qat/include/common/adf_uio.h M sys/dev/qat/include/common/adf_uio_control.h M sys/dev/qat/qat_api/common/crypto/sym/include/lac_sym_cipher_defs.h M sys/dev/qat/qat_api/common/crypto/sym/lac_sym_alg_chain.c M sys/dev/qat/qat_api/common/crypto/sym/lac_sym_dp.c M sys/dev/qat/qat_api/common/ctrl/sal_get_instances.c M sys/dev/qat/qat_api/common/utils/lac_lock_free_stack.h M sys/dev/qat/qat_api/device/dev_info.c M sys/dev/qat/qat_api/include/icp_sal_versions.h M sys/dev/qat/qat_api/qat_kernel/src/lac_adf_interface_freebsd.c M sys/dev/qat/qat_api/qat_kernel/src/lac_symbols.c M sys/dev/qat/qat_common/adf_accel_engine.c M sys/dev/qat/qat_common/adf_cfg_device.c M sys/dev/qat/qat_common/adf_ctl_drv.c M sys/dev/qat/qat_common/adf_freebsd_admin.c M sys/dev/qat/qat_common/adf_freebsd_cnvnr_ctrs_dbg.c M sys/dev/qat/qat_common/adf_freebsd_uio.c M sys/dev/qat/qat_common/adf_freebsd_ver_dbg.c M sys/dev/qat/qat_common/adf_fw_counters.c M sys/dev/qat/qat_common/adf_gen2_hw_data.c M sys/dev/qat/qat_common/adf_gen4_hw_data.c M sys/dev/qat/qat_common/adf_gen4_timer.c M sys/dev/qat/qat_common/adf_gen4vf_hw_csr_data.c M sys/dev/qat/qat_common/adf_heartbeat.c M sys/dev/qat/qat_common/adf_transport.c M sys/dev/qat/qat_common/qat_hal.c M sys/dev/qat/qat_hw/qat_200xx/adf_200xx_hw_data.c M sys/dev/qat/qat_hw/qat_200xx/adf_drv.c M sys/dev/qat/qat_hw/qat_4xxx/adf_4xxx_hw_data.c M sys/dev/qat/qat_hw/qat_4xxx/adf_drv.c M sys/dev/qat/qat_hw/qat_4xxxvf/adf_4xxxvf_hw_data.c M sys/dev/qat/qat_hw/qat_c3xxx/adf_c3xxx_hw_data.c M sys/dev/qat/qat_hw/qat_c3xxx/adf_drv.c M sys/dev/qat/qat_hw/qat_c4xxx/adf_c4xxx_ae_config.c M sys/dev/qat/qat_hw/qat_c4xxx/adf_c4xxx_hw_data.c M sys/dev/qat/qat_hw/qat_c4xxx/adf_c4xxx_res_part.c M sys/dev/qat/qat_hw/qat_c4xxx/adf_drv.c M sys/dev/qat/qat_hw/qat_c62x/adf_c62x_hw_data.c M sys/dev/qat/qat_hw/qat_c62x/adf_drv.c M sys/dev/qat/qat_hw/qat_dh895xcc/adf_dh895xcc_hw_data.c M sys/dev/qat/qat_hw/qat_dh895xcc/adf_drv.c _____________________________________________________________________________________________________________ Commit: cfa60056259a3b41e505d068c62e992747aa4923 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cfa60056259a3b41e505d068c62e992747aa4923 Author: Mark Johnston (Wed 8 Jul 2026 18:12:54 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:32 BST) taskqueue: Avoid unbounded epoch read sections The taskqueue thread loop tries to avoid entering and exiting net epoch read sections for every task. This reduces the overhead of net epoch integration, but the implementation wasn't bounding the length of the read section, so a busy taskqueue thread could hold an epoch open for an unbounded period. This is easy to achieve with the epair task, for instance. Bound the number of tasks that we'll execute without observing the global epoch, and provide a sysctl to control it. Let the default bound be eight. Reviewed by: glebius MFC after: 2 weeks Differential Revision: https://reviews.freebsd.org/D58031 (cherry picked from commit a58590631ccc0fa5bdbbdf88021c6878d644d128) M sys/kern/subr_gtaskqueue.c M sys/kern/subr_taskqueue.c M sys/sys/taskqueue.h _____________________________________________________________________________________________________________ Commit: c6e62f8dde4728617612734f7cf0cac3434cdf07 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c6e62f8dde4728617612734f7cf0cac3434cdf07 Author: Mark Johnston (Wed 15 Jul 2026 16:04:46 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:32 BST) iflib: Remove an unused field from struct iflib_rxq Reported by: Alexander Sideropoulos MFC after: 1 week (cherry picked from commit fc09c7fee23b3cf3ddc95105ef6ef41d7956232f) M sys/net/iflib.c _____________________________________________________________________________________________________________ Commit: a4b5ff57ef85031ba52feb70c754ba77f7c92cb0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a4b5ff57ef85031ba52feb70c754ba77f7c92cb0 Author: Mark Johnston (Fri 17 Jul 2026 14:08:33 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:32 BST) ktimer: Check for errors from realtimer_gettime() clock_gettime(CLOCK_TAI) can fail, leaving *ovalue uninitialized. Reported by: Hazley Samsudin of GovTech CSG MFC after: 3 days Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58225 (cherry picked from commit 2f1ec7d159cbe56d40e7b6d7fc4188c9079e1783) M sys/kern/kern_time.c _____________________________________________________________________________________________________________ Commit: fc14b7cb9f133572c6bbf48c72de59692bee7f31 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fc14b7cb9f133572c6bbf48c72de59692bee7f31 Author: Mark Johnston (Mon 6 Jul 2026 14:21:43 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:31 BST) dtrace: Fix DOF section-specific validation The entry size of the probe section is assumed to be at least sizeof(dof_probe_t) by the loop further below. enoff_sec->dofs_entsize was not being validated at all. When multiplying an index by a table entry size, make sure the multiplication can't overflow. Fix an off-by-one when validating the translated probe argument array. Make sure that the probe argument argvs are valid string offsets even if the argument count is zero. Reviewed by: christos MFC after: 2 weeks Sponsored by: CHERI Research Centre Differential Revision: https://reviews.freebsd.org/D57979 (cherry picked from commit 7f5fa76367d78e47d483fdf2cc72e5823d0f7807) M sys/cddl/contrib/opensolaris/uts/common/dtrace/dtrace.c _____________________________________________________________________________________________________________ Commit: 9ce4cdd7d2d3885a73e8940a1fd3913d493695dc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9ce4cdd7d2d3885a73e8940a1fd3913d493695dc Author: Mark Johnston (Mon 6 Jul 2026 14:21:24 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:31 BST) dtrace: Improve DOF string table validation The check for a nul terminator implicitly assumes that the section size is positive. Make the assumption explicit. Reviewed by: christos MFC after: 2 weeks Sponsored by: CHERI Research Centre Differential Revision: https://reviews.freebsd.org/D57977 (cherry picked from commit b56b601c5ba603031312b9bc7ae895ecb0dcdaec) M sys/cddl/contrib/opensolaris/uts/common/dtrace/dtrace.c _____________________________________________________________________________________________________________ Commit: 0c829bb55a86b696e6a6c66da28d856cb5c06772 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0c829bb55a86b696e6a6c66da28d856cb5c06772 Author: Mark Johnston (Mon 6 Jul 2026 14:21:08 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:31 BST) dtrace: Fix DOF section bounds validation We must ensure that each DOF section does not overlap with the DOF header or section table. Otherwise the relocations processed in the second pass over sections can manipulate DOF metadata, leading to OOB writes. Reviewed by: christos MFC after: 2 weeks Sponsored by: CHERI Research Centre Differential Revision: https://reviews.freebsd.org/D57976 (cherry picked from commit 8dc98f4d25a31a8dfddbcc18eb0ee2e0f005ec15) M sys/cddl/contrib/opensolaris/uts/common/dtrace/dtrace.c _____________________________________________________________________________________________________________ Commit: 912c1a2aa8ec8fe1ea402446d2105bb4c392b59b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=912c1a2aa8ec8fe1ea402446d2105bb4c392b59b Author: Mark Johnston (Mon 6 Jul 2026 14:20:33 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:31 BST) dtrace: Improve DOF section size validation The loop which validates each DOF section assumes that the section header is present, so the section size must be at least as large as the header, otherwise a small OOB access is possible. Reviewed by: christos MFC after: 2 weeks Sponsored by: CHERI Research Centre Differential Revision: https://reviews.freebsd.org/D57975 (cherry picked from commit c1b6ebc2b7584f93cea4d818468b2aee74475674) M sys/cddl/contrib/opensolaris/uts/common/dtrace/dtrace.c _____________________________________________________________________________________________________________ Commit: 5af72e6ab368e1765606ce9f3fcf1946bfd38bbc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5af72e6ab368e1765606ce9f3fcf1946bfd38bbc Author: Mark Johnston (Wed 8 Jul 2026 18:11:05 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:31 BST) netmap: Don't assume that user-provided strings are nul-terminated MFC after: 1 week Sponsored by: The FreeBSD Foundation (cherry picked from commit e1ab35148dd425340a88a2acaf10b972cb119f8f) M sys/dev/netmap/netmap_bdg.c _____________________________________________________________________________________________________________ Commit: 3def10a6c0afd4606ee09a8d68aea49c3adfb443 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3def10a6c0afd4606ee09a8d68aea49c3adfb443 Author: Mark Johnston (Wed 8 Jul 2026 18:12:21 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:31 BST) timefd: Correct the required rights for timerfd_gettime() Reviewed by: jfree MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58084 (cherry picked from commit de6193cf7d2c0c31e5ccafd098275a629a5ea49e) M sys/kern/sys_timerfd.c _____________________________________________________________________________________________________________ Commit: 0551f7bec1497af87657a0f0e80eea690c30bdd0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0551f7bec1497af87657a0f0e80eea690c30bdd0 Author: Mark Johnston (Wed 8 Jul 2026 19:06:00 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:31 BST) inotify: Fix comment typos MFC after: 1 week (cherry picked from commit 3e123be2305a30369f63bcee22ca5e0db527f320) M sys/kern/vfs_inotify.c M sys/sys/inotify.h _____________________________________________________________________________________________________________ Commit: 57d193d62956a0b045a281081cec29f50881b6b6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=57d193d62956a0b045a281081cec29f50881b6b6 Author: Mark Johnston (Tue 30 Jun 2026 20:19:50 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:31 BST) syslogd: Handle connection errors when setting up forwarding sockets Since syslogd was converted to run in a Capsicum sandbox, it needs to explicitly connect() its forwarding sockets rather than using sendmsg(). At the time syslogd starts during boot, some of its forwarding destinations may not be routable, in which case connect() fails. Fix this by making connect() failures non-fatal, and use cap_net to lazily connect sockets once something actually tries logging to the destination. Add a regression test. Reported by: ae Reviewed by: ae Discussed with: jfree Fixes: 4ecbee2760f7 ("syslogd: Open forwarding socket descriptors") MFC after: 2 weeks Differential Revision: https://reviews.freebsd.org/D57394 (cherry picked from commit 8a62a5f77b10ddfa593c4a3d7751cf9bac3bb1b3) M usr.sbin/syslogd/syslogd.c M usr.sbin/syslogd/syslogd_cap_config.c M usr.sbin/syslogd/tests/Makefile M usr.sbin/syslogd/tests/syslogd_test.sh _____________________________________________________________________________________________________________ Commit: bcabd6089f3bb7102f32ce40a4d715d50f8093af URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bcabd6089f3bb7102f32ce40a4d715d50f8093af Author: Mark Johnston (Tue 7 Jul 2026 23:52:56 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:31 BST) linux/futex: Don't load a timeout when try-locking a mutex linux_sys_futex() does not copyin a timespec for the timeout if the operation is LINUX_FUTEX_TRYLOCK_PI, presumably because it doesn't make sense to specify a timeout for a try-lock operation. However, this means that we pass a userspace timespec pointer to linux_umtx_abs_timeout_init(). Modify linux_futex_lock_pi() to not initialize the timeout if we're try-locking. Reviewed by: kib, dchagin Reported by: Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li, and Ke Xu from Tsinghua University using GLM-5.2 from Z.ai MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58061 (cherry picked from commit 407c7c339adb429efcb6658accd16399031c34ca) M sys/compat/linux/linux_futex.c _____________________________________________________________________________________________________________ Commit: ee4316c0c3575948bb6d8eb654b07932ba51736f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ee4316c0c3575948bb6d8eb654b07932ba51736f Author: Mark Johnston (Mon 6 Jul 2026 16:42:52 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:31 BST) vfs: Fix resource leaks in kern_symlinkat() Fixes: 2ec2ba7e232d ("vfs: Add VFS/syscall support for Solaris style extended attributes") Reported by: Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li, and Ke Xu from Tsinghua University using GLM-5.2 from Z.ai Reviewed by: rmacklem, kib MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58053 (cherry picked from commit 58c73727d6e49de1fc4f4bc90621146cae8db2bc) M sys/kern/vfs_syscalls.c _____________________________________________________________________________________________________________ Commit: 54dd524f0ba7d3c0d6b76ed00b0faf4d71803532 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=54dd524f0ba7d3c0d6b76ed00b0faf4d71803532 Author: Mark Johnston (Mon 6 Jul 2026 13:50:51 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:31 BST) inotify.2: Fix formatting and lint MFC after: 1 week (cherry picked from commit 92dfe30ba254b50a74e14f33ad1d2a0c03393960) M lib/libsys/inotify.2 _____________________________________________________________________________________________________________ Commit: 8496ed27ab065ca404d7dc9e599023d14b00f5e8 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8496ed27ab065ca404d7dc9e599023d14b00f5e8 Author: Mark Johnston (Mon 6 Jul 2026 13:51:11 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:31 BST) jaildesc: Publish the new fd only after the jaildesc is initialized jaildesc_alloc() finishes initializing the file structure only after it is made visible from the file descriptor table via finit(). In that window, other threads could try to perform operations on the descriptor and thus access an incompletely initialized jaildesc. Defer the finit() call until locks are initialized. While here, simplify the error path for falloc_caps(). Reported by: Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li, and Ke Xu from Tsinghua University using GLM-5.2 from Z.ai Reviewed by: jamie MFC after: 1 week Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58049 (cherry picked from commit 38dd686b9336e2de5deadc5f8cb5e46a845b0dd9) M sys/kern/kern_jaildesc.c _____________________________________________________________________________________________________________ Commit: 92ae96d9f38a6a2a9e80d388831a831083873752 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=92ae96d9f38a6a2a9e80d388831a831083873752 Author: Mark Johnston (Wed 8 Jul 2026 18:09:42 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:31 BST) tests/inotify: Make an error message more useful MFC after: 3 days (cherry picked from commit 836a76ad95be2fcf2cd116d754c5888a731d57aa) M tests/sys/kern/inotify_test.c _____________________________________________________________________________________________________________ Commit: 5b2bc9cf1cab8861956606f02e0fc854c54c0921 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5b2bc9cf1cab8861956606f02e0fc854c54c0921 Author: Mark Johnston (Fri 3 Jul 2026 20:31:15 BST) Committer: Mark Johnston (Mon 27 Jul 2026 18:34:30 BST) tests/if_wg: Let wg_vnet_parent_routing run in a VNET jail MFC after: 1 week (cherry picked from commit 0dbd497fff17416728c9c98f27a0612c89c7143c) M tests/sys/net/if_wg.sh _____________________________________________________________________________________________________________ Commit: 698e0c419895da2d0d12c5f4d61d85a1d91b6b9d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=698e0c419895da2d0d12c5f4d61d85a1d91b6b9d Author: Mark Johnston (Thu 12 Feb 2026 22:10:36 GMT) Committer: Mark Johnston (Mon 27 Jul 2026 18:29:04 BST) zvol: Fix uses of uninitialized variables in zvol_rename_minors_impl() Reported-by: GitHub Copilot Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Mark Johnston Closes #18191 (cherry picked from commit 943a05528494b2f4585541089606796476fb229e) M sys/contrib/openzfs/module/zfs/zvol.c _____________________________________________________________________________________________________________ Commit: bde29083d0590bd55d0726405a81169109b1265e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bde29083d0590bd55d0726405a81169109b1265e Author: Mark Johnston (Mon 9 Feb 2026 14:54:44 GMT) Committer: Mark Johnston (Mon 27 Jul 2026 18:29:03 BST) zvol: Hold the zvol state writer lock when renaming Otherwise nothing serializes updates to the global zvol hash table. Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Mark Johnston Closes #18191 (cherry picked from commit d7b8eef9d281f6831ac7d9cb27362509ec434fb2) M sys/contrib/openzfs/module/os/freebsd/zfs/zvol_os.c M sys/contrib/openzfs/module/os/linux/zfs/zvol_os.c M sys/contrib/openzfs/module/zfs/zvol.c _____________________________________________________________________________________________________________ Commit: f6745503ded7cc938a52d6916277da12c5b31d4f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f6745503ded7cc938a52d6916277da12c5b31d4f Author: Mark Johnston (Mon 2 Feb 2026 01:55:04 GMT) Committer: Mark Johnston (Mon 27 Jul 2026 18:29:03 BST) Make zvol_set_common() block until the operation has completed This is motivated by a FreeBSD AIO test case which create a zvol with -o volmode=dev, then immediately tries to open the zvol device file. The open occasionally fails with ENOENT. When a zvol is created without the volmode setting, zvol_create_minors() blocks until the task is finished, at which point OS-dependent code will have created a device file. However, zvol_set_common() may cause the device file to be destroyed and re-created, at least on FreeBSD, if the voltype switches from GEOM to DEV. In this case, we do not block waiting for the operation to finish, causing the test failure. Fix the problem by making zvol_set_common() block until the operation has finished. In FreeBSD zvol code, use g_waitidle() to block until asynchronous GEOM operations are done. This fixes a secondary race where zvol_os_remove_minor() does not block until the zvol device file is removed, and the subsequent zvol_os_create_minor() fails because the (to-be-destroyed) device file already exists. Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Mark Johnston Closes #18191 (cherry picked from commit d736868672cb3df197d2ddcfef29ac14edf4ee20) M sys/contrib/openzfs/module/os/freebsd/zfs/zvol_os.c M sys/contrib/openzfs/module/zfs/zvol.c _____________________________________________________________________________________________________________ Commit: ae6db85b3c14771c920185b516e0bb5e8a65912c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ae6db85b3c14771c920185b516e0bb5e8a65912c Author: Mark Johnston (Mon 2 Feb 2026 01:37:22 GMT) Committer: Mark Johnston (Mon 27 Jul 2026 18:29:03 BST) FreeBSD: Fix zvol teardown races zvol_geom_open() may be called to taste an orphaned provider. The test for pp->private == NULL there is racy as no locks are synchronizing the test. Use the GEOM topology lock to interlock the pp->private == NULL test with the zvol state checks. This establishes a new lock order but I believe this is necessary. Set pp->private = NULL under the GEOM topology lock instead of the per-zvol state lock. Modify zvol_os_rename_minor() to drop the zvol state lock to avoid a lock order reversal with the topology lock. Also reverse the order of tests in zvol_geom_open() and zvol_cdev_open() as at least zvol_geom_open() may race with zvol_os_remove_minor(), which sets zv->zv_zso = NULL. Testing for ZVOL_REMOVING first avoids a race which can lead to a NULL pointer dereference. Add a new OS-specific flag to handle the case where zvol_geom_open() drops all locks in order to avoid a lock order reversal when acquiring the suspend lock as the open count transitions 0->1. I don't see anything preventing zvol_os_remove_minor() from racing there. Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Mark Johnston Closes #18191 (cherry picked from commit 6de1457a2d0ea9c95edddb9e2d3d8780ae79da3f) M sys/contrib/openzfs/module/os/freebsd/zfs/zvol_os.c _____________________________________________________________________________________________________________ Commit: 1ad1e7b13d94a5060e47b3070b55c9b110d702b9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1ad1e7b13d94a5060e47b3070b55c9b110d702b9 Author: Ed Maste (Wed 4 Jun 2025 14:33:30 BST) Committer: Ed Maste (Mon 27 Jul 2026 14:35:46 BST) beinstall: Avoid chrooting into new world The new world may use system calls that are not in the currently-running kernel, so we cannot chroot into the new environment to run `make installworld`, `etcupdate`, etc. Partially revert commit 16702050ac95 ("beinstall: perform pre-installworld steps") and switch back to using DESTDIR for installworld and so on. Reported by: olivier Reviewed by: olivier Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D50682 (cherry picked from commit 7fde3e62231ac397a779e4fef729908c5ef6f53a) M tools/build/beinstall.sh _____________________________________________________________________________________________________________ Commit: d85e97c16f0340df686acdb3b71f4eaf1049ab98 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d85e97c16f0340df686acdb3b71f4eaf1049ab98 Author: Alexander Leidinger (Sat 27 Jun 2026 14:44:33 BST) Committer: Alexander Leidinger (Mon 27 Jul 2026 10:39:27 BST) rc.d: fix lockd and statd flags processing after scvj The documented flags are named differently than the script name, this requires special handling of the flags. The Service Jails feature requires the handling of the variable to be differently than it was initially. The change back then did not work, which resulted in the flags to be ignored. This commit fixes the issue in head. This affects 15.0 and 15.1 too. PR: 296233 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296233 ) Reported by: Robert Blayzor Tested by: Robert Blayzor Fixes: f99f0ee14e3af81c2 - rc.d: add a service jails config to all base system services MFC after: 1 month MFC to: 15-stable (cherry picked from commit d05d60e958bca778ea193932facb026c48d7ca0b) M libexec/rc/rc.d/lockd M libexec/rc/rc.d/statd _____________________________________________________________________________________________________________ Commit: 49233a1fce025a32cbe790d4c0091b68292d30a6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=49233a1fce025a32cbe790d4c0091b68292d30a6 Author: Jose Luis Duran (Mon 13 Jul 2026 13:25:30 BST) Committer: Jose Luis Duran (Mon 27 Jul 2026 04:41:27 BST) mkimg: Add ms-basic-data alias for GPT While preparing GPT-schemed RaspberryPi images for the NanoBSD Reimagined GSoC 2026 project, a discrepancy was identified between mkimg(1) and gpart(8) regarding Microsoft Basic Data partitions (GUID !ebd0a0a2-b9e5-4433-87c0-68b6b72699c7). Currently, mkimg(1) relies on the MBR-centric name "ntfs" to identify this partition type under the GPT scheme. Conversely, gpart(8) identifies this type as "ms-basic-data". To allow automation scripts (such as those consuming from gpart backup) to use a common partition type across tools, add ALIAS_MS_BASIC_DATA as a valid alias. This is part of a larger effort to avoid a custom, MBR-based image generation logic for embedded SoCs like the Raspberry Pi, standardizing on GPT layouts across all supported FreeBSD embedded devices. Reviewed by: imp MFC after: 2 weeks Differential Revision: https://reviews.freebsd.org/D58198 (cherry picked from commit 67f1c082b5ec37e2060b74e6f1f952ed38761468) M usr.bin/mkimg/gpt.c M usr.bin/mkimg/scheme.c M usr.bin/mkimg/scheme.h _____________________________________________________________________________________________________________ Commit: 57ce5fafdf8c3a39904ffdf7b4314595fee685ba URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=57ce5fafdf8c3a39904ffdf7b4314595fee685ba Author: Giuseppe Lettieri (Mon 13 Jul 2026 13:24:16 BST) Committer: Jose Luis Duran (Mon 27 Jul 2026 04:41:08 BST) libnetmap: fix extra indirection in nmreq_remove_option Reviewed by: zlei, vmaffione Obtained from: https://github.com/luigirizzo/netmap/commit/7d9177ed9a121e66bf4eaa0acb5d574e408297da MFC after: 2 weeks Differential Revision: https://reviews.freebsd.org/D58151 (cherry picked from commit 141b6645204966a0e1ae10dd059c670e2a58e6e1) M lib/libnetmap/nmreq.c _____________________________________________________________________________________________________________ Commit: cf4bb6f4aa7f39e66434f73d65bd08261deea792 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cf4bb6f4aa7f39e66434f73d65bd08261deea792 Author: Jose Luis Duran (Mon 13 Jul 2026 13:23:14 BST) Committer: Jose Luis Duran (Mon 27 Jul 2026 04:40:43 BST) libnetmap: fix error path in nmport_extmem_from_file Reviewed by: zlei, vmaffione Obtained from: https://github.com/luigirizzo/netmap/commit/b52a2bcae35e56548acfb0849b248a1e4b0c0c3b MFC after: 2 weeks Differential Revision: https://reviews.freebsd.org/D58150 (cherry picked from commit fcaf15e54162fe14483fdf4ac28c67c51e424441) M lib/libnetmap/nmport.c _____________________________________________________________________________________________________________ Commit: 88409417be8847b94fa2702eb727d6102f620af2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=88409417be8847b94fa2702eb727d6102f620af2 Author: Konstantin Belousov (Sun 19 Jul 2026 02:14:39 BST) Committer: Konstantin Belousov (Mon 27 Jul 2026 01:28:44 BST) kern_ptrace(): reduce code duplication (cherry picked from commit 9b21a52495758294e3a50542a59bc47a0c184173) M sys/kern/sys_process.c _____________________________________________________________________________________________________________ Commit: 2cbf21fc2dbe94eaf49221796bdc1cd44717a515 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2cbf21fc2dbe94eaf49221796bdc1cd44717a515 Author: Konstantin Belousov (Sat 18 Jul 2026 17:29:10 BST) Committer: Konstantin Belousov (Mon 27 Jul 2026 01:28:44 BST) thread_stopped(): style (cherry picked from commit 2038232e3e40cfc3dedba1a9f4a66984448eca1e) M sys/kern/kern_sig.c _____________________________________________________________________________________________________________ Commit: 18ea9571f7a423059b7f34903ebb0201afed660a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=18ea9571f7a423059b7f34903ebb0201afed660a Author: Konstantin Belousov (Wed 22 Jul 2026 10:36:17 BST) Committer: Konstantin Belousov (Mon 27 Jul 2026 01:28:43 BST) getpgrp(2), getsid(2): allow to call on zombies (cherry picked from commit 8f320c2bc473a775ea9a55d17fa61f729e593867) M sys/kern/kern_prot.c _____________________________________________________________________________________________________________ Commit: 1e5d774279e193eba2fb36386b637f994eba038f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1e5d774279e193eba2fb36386b637f994eba038f Author: Konstantin Belousov (Mon 20 Jul 2026 23:09:59 BST) Committer: Konstantin Belousov (Mon 27 Jul 2026 01:28:43 BST) kern/sys_ptrace: do not skip P2_PTRACEREQ wait for PT_CLEARSTEP/PT_GET_CHILDREN (cherry picked from commit eca7b25c101a240472c4c274e725bc294284c827) M sys/kern/sys_process.c _____________________________________________________________________________________________________________ Commit: 4c6c49af2deef5befcb71bc77a4f4e9ed2fac55a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4c6c49af2deef5befcb71bc77a4f4e9ed2fac55a Author: Konstantin Belousov (Fri 17 Jul 2026 21:12:13 BST) Committer: Konstantin Belousov (Mon 27 Jul 2026 01:28:42 BST) ptrace.2: document PT_GET_CHILDREN (cherry picked from commit 6dbeaf1afaba52ba224f24773cbaac6317e11ff2) M lib/libsys/ptrace.2 _____________________________________________________________________________________________________________ Commit: c0addb9e88e77fd26e6215c87ac98a0233ec7a46 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c0addb9e88e77fd26e6215c87ac98a0233ec7a46 Author: Konstantin Belousov (Fri 17 Jul 2026 15:57:04 BST) Committer: Konstantin Belousov (Mon 27 Jul 2026 01:28:42 BST) ptrace(2): add PT_GET_CHILDREN (cherry picked from commit d3b7bbee9275d5a3c58a9e75d1fffc60a9333352) M sys/compat/freebsd32/freebsd32_misc.c M sys/kern/sys_process.c M sys/sys/ptrace.h _____________________________________________________________________________________________________________ Commit: 643fe6ba676de7708e7e21b3badf393f6eca2961 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=643fe6ba676de7708e7e21b3badf393f6eca2961 Author: Konstantin Belousov (Wed 15 Jul 2026 14:42:44 BST) Committer: Konstantin Belousov (Mon 27 Jul 2026 01:28:42 BST) ptrace.2: Document PT_SET_SC_RET (cherry picked from commit f967dd04c880e9c9c68cd20de135d77b3ca1c26d) M lib/libsys/ptrace.2 _____________________________________________________________________________________________________________ Commit: 03c5b4d8768bac1febafdbfaa6d43aab2f3c5ac9 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=03c5b4d8768bac1febafdbfaa6d43aab2f3c5ac9 Author: Konstantin Belousov (Wed 15 Jul 2026 03:23:17 BST) Committer: Konstantin Belousov (Mon 27 Jul 2026 01:28:41 BST) ptrace(2): PT_SET_SC_RET request (cherry picked from commit fd5faa5629aed98f4daee84063da3494c4d1eee9) M sys/compat/freebsd32/freebsd32_misc.c M sys/kern/subr_syscall.c M sys/kern/sys_process.c M sys/sys/proc.h M sys/sys/ptrace.h _____________________________________________________________________________________________________________ Commit: 02b4a95522c9028a47dbe3571563cda72e115875 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=02b4a95522c9028a47dbe3571563cda72e115875 Author: Konstantin Belousov (Sun 12 Jul 2026 12:56:13 BST) Committer: Konstantin Belousov (Mon 27 Jul 2026 01:26:15 BST) lookup: do not return vp_crossmp as dvp for mount over the reg file (cherry picked from commit 29d1a3248a6da1ed9f1a46d7d525fb779306a90f) M sys/kern/vfs_lookup.c M sys/kern/vfs_syscalls.c _____________________________________________________________________________________________________________ Commit: 398702278762c407adaab3d9f314ecb2d356d12b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=398702278762c407adaab3d9f314ecb2d356d12b Author: Konstantin Belousov (Fri 20 Mar 2026 23:27:18 GMT) Committer: Konstantin Belousov (Mon 27 Jul 2026 01:26:15 BST) x86 xen: provide the prototype for xen_arch_intr_handle_upcall() in x86/apicvar.h (cherry picked from commit 0e5b1384df10e9b9700047cb79c347874212d2a9) M sys/x86/include/apicvar.h M sys/x86/xen/xen_arch_intr.c _____________________________________________________________________________________________________________ Commit: 038a73790cb6b13cd03912758ead742540465e6b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=038a73790cb6b13cd03912758ead742540465e6b Author: Bjoern A. Zeeb (Tue 14 Jul 2026 07:39:12 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:49:21 BST) mt76: disable debugfs due to missing piece still in review Until D57524 is not reviewed and committed we will have a missing function declaration which prevents us to compile (in) debugfs for mt76 core and mt7921. Temporary disable debugfs again. Sponsored by: The FreeBSD Foundation (cherry picked from commit c589dc4ef77d8e165e449a861c3705002ca4a762) M sys/modules/mt76/core/Makefile M sys/modules/mt76/mt7921/Makefile _____________________________________________________________________________________________________________ Commit: ea8db6b6d98c5ebfb3c340ca78f96beceb2ac269 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ea8db6b6d98c5ebfb3c340ca78f96beceb2ac269 Author: Bjoern A. Zeeb (Sat 11 Jul 2026 14:40:29 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:49:16 BST) mt76: further adjust debugfs compile time options The debugfs options between the various modules (core and chipsets) are not 100% de-coupled. This means we may run into unresolveable symbols at load time of the modules if we enable certain options generally or for core but not for the chipset. For now: always build the core module with debugfs support. Migrate the CONFIG_MAC80211_DEBUGFS flag into the Makefile of each chipset so we can individually turn it on. Sponsored by: The FreeBSD Foundation (cherry picked from commit ec17c2454bf03f954e460bfe3c95e35f638ba71e) M sys/modules/mt76/Makefile.inc M sys/modules/mt76/core/Makefile M sys/modules/mt76/mt7615/Makefile M sys/modules/mt76/mt7915/Makefile M sys/modules/mt76/mt7921/Makefile M sys/modules/mt76/mt7925/Makefile M sys/modules/mt76/mt7996/Makefile _____________________________________________________________________________________________________________ Commit: 66891eda352010338b625f77ec5db01f67e7e1b1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=66891eda352010338b625f77ec5db01f67e7e1b1 Author: Bjoern A. Zeeb (Sat 18 Jul 2026 12:54:42 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:49:11 BST) LinuxKPI: page pool updates and add to the build Split implementation out from the header files. This "page pool" is the very minimalistic version we need in order to support packets on mt76. We allocate the page pool in order to have the meta data available of which we only make limited use. This implementation does no pooling, it does no page fragments for now, it always hands out a full page and frees it upon return. It is written in a way that it can be in the tree before the 'struct page' work it depends on has landed in order to reduce friction for people who want to try mt7921 (or others later) upfront. We use the same #ifdef as in the struct page work for that reason so one knob will turn everything on or off. Once the struct page work has landed and settled we can start filling this with more complexity. In the unlikely event that in the mean time any other consumer would start showing up they will have to be aware that the current code as-is essentially is a NOP without the 'struct page' work. A WARN_ONCE() will notify them. Sponsored by: The FreeBSD Foundation (cherry picked from commit e591a76621430d6d29f2580e2dec8991e450ed5e) M sys/compat/linuxkpi/common/include/net/page_pool/helpers.h M sys/compat/linuxkpi/common/include/net/page_pool/types.h A sys/compat/linuxkpi/common/src/linuxkpi_page_pool.c M sys/conf/files M sys/modules/linuxkpi/Makefile _____________________________________________________________________________________________________________ Commit: 7e06bfdd1489e00d9fe72e596462670002d93bba URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7e06bfdd1489e00d9fe72e596462670002d93bba Author: Bjoern A. Zeeb (Fri 17 Jul 2026 14:12:56 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:49:06 BST) LinuxKPI: page.h: resort lines Two of the "page macros" can be abstracted elsewhere in the upcoming struct page work, so sort them away from the four which are here to stay. No functional change. Sponsored by: The FreeBSD Foundation Reviewed by: emaste Differential Revision: https://reviews.freebsd.org/D58299 (cherry picked from commit 0b8d22019dcf708a8d047817963658783cd53c46) M sys/compat/linuxkpi/common/include/linux/page.h _____________________________________________________________________________________________________________ Commit: 86da56e65f8cdfdc7a2fb503a37a18765564b891 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=86da56e65f8cdfdc7a2fb503a37a18765564b891 Author: Bjoern A. Zeeb (Fri 17 Jul 2026 14:09:01 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:49:02 BST) LinuxKPI: page.h: use atop() and ptoa() instead of PAGE_SHIFT With upcoming changes to 'struct page' this will make the lines easier to read by using the predefined macros from param.h. Sponsored by: The FreeBSD Foundation Reviewed by: markj, kib Differential Revision: https://reviews.freebsd.org/D58298 (cherry picked from commit f45506c6a6f4742cd5129d636902b61045c4754b) M sys/compat/linuxkpi/common/include/linux/page.h _____________________________________________________________________________________________________________ Commit: 9a52d308257b42e8309adb41a640ec57f5533b83 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9a52d308257b42e8309adb41a640ec57f5533b83 Author: Bjoern A. Zeeb (Fri 17 Jul 2026 13:58:32 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:48:58 BST) LinuxKPI: prefer struct page [*] over struct vm_page[_t] LinuxKPI is based on Linux 'struct page' which is currently aliased to struct vm_page. Upcoming changes may change that so start using 'struct page *' instead vm_page_t to make future changes transparent. This is a continuation of 9e9c682ff3a1 and should be a NOP. Sponsored by: The FreeBSD Foundation Reviewed by: emaste (no objections) Differential Revision: https://reviews.freebsd.org/D58297 (cherry picked from commit ac4b43b7b9dd2dac5d7caf5d4c7aa0d670d38aec) M sys/compat/linuxkpi/common/src/linux_page.c _____________________________________________________________________________________________________________ Commit: b17957b9d165dbde267213cbb9469739197213d4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b17957b9d165dbde267213cbb9469739197213d4 Author: Bjoern A. Zeeb (Fri 17 Jul 2026 13:53:16 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:48:52 BST) LinuxKPI: move clear_page() within the linux/page.h file clear_page() would normally live in asm/page.h but adding the file and fixing the dependencies would be too much for a single line. Move the function to the end of the file with a clear separator and make it clear that it does not operate on a 'struct page' but on a page address by changing the argument name and leaving a comment. The function is currently used by at least mthca(4) as the only in-tree consumer, and drm-kmod ttm_pool.c. No functional changes. Sponsored by: The FreeBSD Foundation Reviewed by: emaste Differential Revision: https://reviews.freebsd.org/D58296 (cherry picked from commit 0845efe88b355547b103dca90e69e46a3ebdd016) M sys/compat/linuxkpi/common/include/linux/page.h _____________________________________________________________________________________________________________ Commit: b85f7753dac542664d68d44d4cf75674a3cba44f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b85f7753dac542664d68d44d4cf75674a3cba44f Author: Bjoern A. Zeeb (Fri 17 Jul 2026 13:26:13 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:48:49 BST) LinuxKPI: sg_page() remove superfluous () Sponsored by: The FreeBSD Foundation Reviewed by: emaste Differential Revision: https://reviews.freebsd.org/D58295 (cherry picked from commit fe1784004d6e43b3080ab7b7115ee0ea3ba317f2) M sys/compat/linuxkpi/common/include/linux/scatterlist.h _____________________________________________________________________________________________________________ Commit: a7d0df951c90612e6bc04cb22333df4aff1361d1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a7d0df951c90612e6bc04cb22333df4aff1361d1 Author: Bjoern A. Zeeb (Wed 27 May 2026 02:26:02 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:48:44 BST) LinuxKPI: pci: fix dma handle type in match function dma_addr_t is a vm_paddr_t which is a uint of some width. Rather than passing pointers of it around pass the value. Comparing the addresses of different storage for the same dma handle (the actual bug here) will not work when passed to the devres match function. Sponsored by: The FreeBSD Foundation Fixes: 0a575891211ef ("implement dmam_free_coherent()") Differential Revision: https://reviews.freebsd.org/D58285 (cherry picked from commit 2099bf27126f6fef10128c3cd0ea8476c88b28c5) M sys/compat/linuxkpi/common/src/linux_pci.c _____________________________________________________________________________________________________________ Commit: 94ab8de14f0a8fd07b3f1e216ec3f42a8d51ccaf URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=94ab8de14f0a8fd07b3f1e216ec3f42a8d51ccaf Author: Bjoern A. Zeeb (Tue 21 Jul 2026 20:54:04 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:48:40 BST) LinuxKPI: 802.11: always lock around (*set_{frag,rts}_threshold) We would lock the downcalls during normal operation but not during vap (vif) creation as there was no need for locking. Add the missing locking there as drivers seem to always expect it (by assertion) and cannot distinguish between state. Add the assertions to the downcalls as we need both of them locked and both of them can sleep. PR: 296185 ("rtw89(4) freezes the system with INVARIANTS kernel") Debugged by: Artem Bunichev (temcbun gmail.com) Sponsored by: The FreeBSD Foundation (cherry picked from commit 5d479b75a8944faeabb367d1234a9fc3fefa8df1) M sys/compat/linuxkpi/common/src/linux_80211.c M sys/compat/linuxkpi/common/src/linux_80211_macops.c _____________________________________________________________________________________________________________ Commit: 912251ac6b186aa2716ddd51bde9a0e1f6b3c2e3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=912251ac6b186aa2716ddd51bde9a0e1f6b3c2e3 Author: Bjoern A. Zeeb (Fri 17 Jul 2026 21:59:08 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:48:33 BST) LinuxKPI: 802.11: stop ieee80211_start_tx_ba_session() if no HT supported rtw89(4) would constantly try to start a TX BlockACK session even if no HT or higher was available. The only way to stop this (currently) is to return -EINVAL instead of any other error. Note: we should investigate if/when to call (*set_tid_config)() as that will also offer the ability to forbid BA. Sponsored by: The FreeBSD Foundation Reported by: arved, bnovkov Tested by: bnovkov (cherry picked from commit 8a1600428e937a41b65869c78ce847f7cabbad24) M sys/compat/linuxkpi/common/src/linux_80211.c _____________________________________________________________________________________________________________ Commit: b37a29f849402f417f2144c886ce523d78f76ab7 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b37a29f849402f417f2144c886ce523d78f76ab7 Author: Bjoern A. Zeeb (Fri 17 Jul 2026 12:02:45 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:48:29 BST) LinuxKPI: skbuff: add initial page pool support Add an internal flag which is set by skb_mark_for_recycle() and upon "skb_free" then selects whether the skb is freed or returned to the page pool. There will likely be more details to figure out once the LinuxKPI page work is done and we support more of the page pool than the bare minimum. Sponsored by: The FreeBSD Foundation (cherry picked from commit e4795d3dbee71c463429e2901dad111fbc2d08fc) M sys/compat/linuxkpi/common/include/linux/skbuff.h M sys/compat/linuxkpi/common/src/linux_skbuff.c _____________________________________________________________________________________________________________ Commit: 36ed9a84d17b58b83612bb4ec32bddfc56f991b2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=36ed9a84d17b58b83612bb4ec32bddfc56f991b2 Author: Bjoern A. Zeeb (Tue 3 Feb 2026 22:13:24 GMT) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:48:25 BST) LinuxKPI: skbuff: add reference counting to the skb Sponsored by: The FreeBSD Foundation (cherry picked from commit cb13e826ec45e11e964e1921d281e0a06ca5e152) M sys/compat/linuxkpi/common/src/linux_skbuff.c _____________________________________________________________________________________________________________ Commit: be02517f6f19a6b8c8f4e850c992c9cd749713bf URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=be02517f6f19a6b8c8f4e850c992c9cd749713bf Author: Bjoern A. Zeeb (Tue 3 Feb 2026 22:13:24 GMT) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:48:19 BST) LinuxKPI: skbuff: add support for frags in linuxkpi_skb_copy() Sponsored by: The FreeBSD Foundation (cherry picked from commit 1e4ec01603c4b1e0b0eb524f28f731eb5cb5f6dc) M sys/compat/linuxkpi/common/src/linux_skbuff.c _____________________________________________________________________________________________________________ Commit: 4352733e639897d271e4246fe8f6203ac9c05ab0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4352733e639897d271e4246fe8f6203ac9c05ab0 Author: Bjoern A. Zeeb (Tue 3 Feb 2026 22:13:24 GMT) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:48:13 BST) LinuxKPI: skbuff: implement __skb_linearize() skb_linearize() is used by mt7921, mt7925, and in the general mt76 tx dma code. __skb_linearize() is used in the general iwlwifi TX code but given the way we currently create TX skbs in LinuxKPI 802.11 we never hit that case. Sponsored by: The FreeBSD Foundation (cherry picked from commit 9de11cc26ab61d7f80e8af84dbc55d8cbd6f832d) M sys/compat/linuxkpi/common/include/linux/skbuff.h M sys/compat/linuxkpi/common/src/linux_skbuff.c _____________________________________________________________________________________________________________ Commit: 271a6593acf314e618ec17c657bd4ed75dab8d3f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=271a6593acf314e618ec17c657bd4ed75dab8d3f Author: Bjoern A. Zeeb (Tue 3 Feb 2026 22:13:24 GMT) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:48:09 BST) LinuxKPI: skbuff: implement napi_build_skb() Implement napi_build_skb() around linuxkpi_build_skb(). Sponsored by: The FreeBSD Foundation (cherry picked from commit b36460e5ec4659d0fa14b35c9342c5a154b3db7d) M sys/compat/linuxkpi/common/include/linux/skbuff.h _____________________________________________________________________________________________________________ Commit: 299f6dc8bb718249db8f7317d1d7b89ccaf1cba3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=299f6dc8bb718249db8f7317d1d7b89ccaf1cba3 Author: Bjoern A. Zeeb (Tue 3 Feb 2026 22:13:24 GMT) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:48:05 BST) LinuxKPI: skbuff: add skb_put_zero() Add skb_put_zero() as a simple wrapper around __skb_put_zero(). Sponsored by: The FreeBSD Foundation (cherry picked from commit 32c983449a7c802bf47578d5304c6d505db7821a) M sys/compat/linuxkpi/common/include/linux/skbuff.h _____________________________________________________________________________________________________________ Commit: f16c8e3dda5da9bb0d0e4504b70647d8f0ad5301 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f16c8e3dda5da9bb0d0e4504b70647d8f0ad5301 Author: Bjoern A. Zeeb (Tue 3 Feb 2026 22:13:24 GMT) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:48:00 BST) LinuxKPI: skbuff: improve debugging Deal with SKB_TRACE_FMT optional arguments; while here properly indent. Add KASSERT to __skb_unlink() to catch incorrect skbuffs encountered while debugging a wireless driver (which had other pre-conditions failing). Sponsored by: The FreeBSD Foundation (cherry picked from commit e5bcf7b99fcbe06d381525ffdd5027b846cdc1d3) M sys/compat/linuxkpi/common/include/linux/skbuff.h _____________________________________________________________________________________________________________ Commit: dada5634d4d2b02fd0f171cb3df93719ec94fda5 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=dada5634d4d2b02fd0f171cb3df93719ec94fda5 Author: Bjoern A. Zeeb (Sat 11 Jul 2026 14:35:31 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:47:54 BST) LinuxKPI: 802.11: lkpi_80211_txq_tx_one() only pass sta if added to drv If we are doing a direct (*tx) downcall, only pass sta as meta data if it was added to the driver (via the state machine). This prevents us passing a sta not known to the driver leading to possible follow-up complications/errors. This will usually happen if (a) we are doing software scanning, or (b) if net80211 decides to change the ni from under us and sends a packet with the new ni. Adjust a debug statement before to also have the added_to_drv field in it to ease debugging. Sponsored by: The FreeBSD Foundation (cherry picked from commit c6e70c68d2ce5cfbcace251ef6ed2f1eae912a74) M sys/compat/linuxkpi/common/src/linux_80211.c _____________________________________________________________________________________________________________ Commit: 19a8d8f55f070cf2c351e8c1bfe17efafd1f4f32 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=19a8d8f55f070cf2c351e8c1bfe17efafd1f4f32 Author: Bjoern A. Zeeb (Tue 2 Jun 2026 00:59:01 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:47:48 BST) LinuxKPI: pci detach: implement a proper detach (release) path There are two paths in the LinuxKPI PCI code to instantiate a "pdev" (LinuxKPI pci_dev). One is using the FreeBSD bus framework and the pdev will be the softc. This commit starts cleaning up the detach path for just that case to the best possible. So far we did a lot of the work in linux_pci_detach_device(), which is the internal handler of the detach function and little in the (*release) callback (devres cleanup only). The problem with that is, that we tear down resources which later in the devres cleanup are needed. With them not being there anymore we panic, e.g., in lkpi_dma_unmap < lkpi_dmam_free_coherent < lkpi_devres_release_free_list. The solution is to migrate most of the cleanup work into the (*release) callback, which will automatically be called when the device (kobj) reference drops to zero. The only work which should be done immediately is to let the dirver do its cleanup; this has to happen before we try to teardown the resources, but also we do want this to happen when detach is called (the first time). One problem we have with the deferred cleanup of the remaining parts is that we do not know upon calling pci_dev_put() whether this cleared the last reference and triggered the cleanup or not but we cannot return from the detach function with pending resources and dangling pointers, which then may be used. In order to work around this, we clear the (*release) callback function when it is run and check for that in the detach routine. If the (*release) callback was not run, we refuse to detach (force would be needed) as we'd rather keep the device than risk a follow-up panic on leaked resources. Given this should not happen in a well programmed world, I believe it is fine to take that and log it to let the user know. Try to leave a few comments behind to help with understanding in the future. With this we can unload the mt7921 driver (or shutdown the system) without panic. Sponsored by: The FreeBSD Foundation Reviewed by: dumbbell Differential Revision: https://reviews.freebsd.org/D57429 (cherry picked from commit 66b25ddf9125b2f3707e0f22b01b47bdff463fa7) M sys/compat/linuxkpi/common/src/linux_pci.c _____________________________________________________________________________________________________________ Commit: 38734f88a643b139f4d7ecbb53a590db9d678e58 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=38734f88a643b139f4d7ecbb53a590db9d678e58 Author: Bjoern A. Zeeb (Mon 1 Jun 2026 05:58:00 BST) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:47:43 BST) LinuxKPI: fix lkpi_pci_get_device() reference counting on device In case we are passed an "odev" (a device to start the search from), that device would have an extra reference. The best way to illustrate this is to look at for_each_pci_dev(), which will return one device after the other. Upon first return we return a pdev with a reference. That pdev is then passed in as odev on the next call. If we do not clear the reference it will be leaked. Sponsored by: The FreeBSD Foundation Fixes: 910cf345d0ee9 ("LinuxKPI: pci: implement ...") Reviewed by: dumbbell, emaste Differential Revision: https://reviews.freebsd.org/D57428 (cherry picked from commit f9a37065b6948831f62a33fd0c68c96985b01a41) M sys/compat/linuxkpi/common/src/linux_pci.c _____________________________________________________________________________________________________________ Commit: cb143e517654d8f69939addd6aaf427f3b547a9e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cb143e517654d8f69939addd6aaf427f3b547a9e Author: Bjoern A. Zeeb (Wed 21 Jan 2026 13:53:34 GMT) Committer: Bjoern A. Zeeb (Sun 26 Jul 2026 17:47:36 BST) LinuxKPI: add system_percpu_wq In Linux v6.17 system_wq was replaced (renamed to) system_percpu_wq, with the old name still present. We just alias system_percpu_wq to linux_system_short_wq like we do for system_wq to keep both around for the forseeable future. Note: the original system_wq was a per-cpu queue upstream as well based on my understanding but we never implemented it as such. That means we are still lacking a per-cpu implementation for system_percpu_wq but at least we do not change the status-quo of the LinuxKPI implementation with this. Note2: we should add a check somewhere for LINUXKPI_VESION >= 61700 to print a warning if anyone still uses the system_wq to detect any possible sami-native or out-of-tree drivers relying on this and not properly updating. Sponsored by: The FreeBSD Foundation Reviewed by: dumbbell; emaste (comments on previous review) Differential Revision: https://reviews.freebsd.org/D57730 (cherry picked from commit 058ce52660fb52ada41462d339fb1ce6aca48cf3) M sys/compat/linuxkpi/common/include/linux/workqueue.h M sys/compat/linuxkpi/common/src/linux_work.c _____________________________________________________________________________________________________________ Commit: 74051cfb3d18bf6881afb8f19c3c0ccdfc2424ff URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=74051cfb3d18bf6881afb8f19c3c0ccdfc2424ff Author: Ed Maste (Wed 20 Apr 2022 15:12:06 BST) Committer: Ed Maste (Sun 26 Jul 2026 17:35:27 BST) readelf: Add support for ELF package metadata note We don't use this note type today, but as a general purpose ELF diagnostic tool readelf(1) ought to decode it. References: https://fedoraproject.org/wiki/Changes/Package_information_on_ELF_objects https://systemd.io/ELF_PACKAGE_METADATA/ Reviewed by: fuz Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D47524 (cherry picked from commit c18512056301fa97dd31c4cc9a78e18f1aa8b2d5) M contrib/elftoolchain/readelf/readelf.c _____________________________________________________________________________________________________________ Commit: 7a62840e9c5a5a30c6234c9186326ca2f05b4102 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7a62840e9c5a5a30c6234c9186326ca2f05b4102 Author: Dag-Erling Smørgrav (Wed 29 Apr 2026 16:14:13 BST) Committer: Dag-Erling Smørgrav (Sat 25 Jul 2026 18:16:15 BST) bc: Fix tests Stop generating test scripts at build time. The dc test script is broken and simply fixing the code that generates it won't help as there is no reliable way to ensure it gets regenerated if it already exists in the object tree. MFC after: 1 week Reviewed by: se Differential Revision: https://reviews.freebsd.org/D56511 (cherry picked from commit 67a63eae7b2d10d29983c9698894f1bfff4ffc6e) M tools/build/depend-cleanup.sh M usr.bin/gh-bc/tests/Makefile A usr.bin/gh-bc/tests/bc_tests.sh A usr.bin/gh-bc/tests/dc_tests.sh _____________________________________________________________________________________________________________ Commit: 58e2ad53b989267bceabfd4ef928bf16e4ee3fe2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=58e2ad53b989267bceabfd4ef928bf16e4ee3fe2 Author: Dag-Erling Smørgrav (Mon 13 Jul 2026 07:42:40 BST) Committer: Dag-Erling Smørgrav (Sat 25 Jul 2026 18:09:23 BST) tail: Allow repetitive or contraditory options Unlike its GNU counterpart, our tail(1) has always errored out if given repetitive or contradictory options, even prior to Keith Bostic's 1991 reimplementation. There is no good reason to continue to do so, not even tradition, since many other commands (including head(1)) simply apply the rightmost option in cases like this. MFC after: 1 week Reviewed by: allanjude, markj Differential Revision: https://reviews.freebsd.org/D58192 (cherry picked from commit 9fc14dbe4897c4541113b9ba98236fbd7eb75380) M usr.bin/tail/tail.c _____________________________________________________________________________________________________________ Commit: 8c2e1dee383cd23d205b5eb3f591057b209e6ed1 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8c2e1dee383cd23d205b5eb3f591057b209e6ed1 Author: Dag-Erling Smørgrav (Thu 9 Jul 2026 09:22:09 BST) Committer: Dag-Erling Smørgrav (Sat 25 Jul 2026 18:09:23 BST) tzcode: Update to 2026c MFC after: 1 week (cherry picked from commit 28f617de7d9b9c708eacb3c2c13e5287e1b7354d) M contrib/tzcode/Makefile M contrib/tzcode/NEWS M contrib/tzcode/localtime.c M contrib/tzcode/newctime.3 M contrib/tzcode/newstrftime.3 M contrib/tzcode/newtzset.3 M contrib/tzcode/private.h M contrib/tzcode/theory.html M contrib/tzcode/tz-art.html M contrib/tzcode/tz-how-to.html M contrib/tzcode/tz-link.html M contrib/tzcode/version M contrib/tzcode/zdump.c M contrib/tzcode/zic.8 M contrib/tzcode/zic.c _____________________________________________________________________________________________________________ Commit: 3ebb70fcf91e50ef1caee178b991f709216ff9f4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3ebb70fcf91e50ef1caee178b991f709216ff9f4 Author: ShengYi Hung (Sat 25 Jul 2026 16:27:50 BST) Committer: ShengYi Hung (Sat 25 Jul 2026 16:27:50 BST) stand: Fix build failure due to old EDK2 interface In 43b8edb320519, we change EFI_GRAPHICS_OUTPUT_PROTOCOL from EFI_GRAPHICS_OUTPUT. However, this patch is not MFC to stable/15. As a result, we need to use the old interface to prevent compile failure. Fixes: 1802f2ca7215 Sponsored by: The FreeBSD Foundation M stand/common/gfx_fb.c _____________________________________________________________________________________________________________ Commit: 8f7ea6b7d1973d0e371ba48e63c31c851f6a72bf URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8f7ea6b7d1973d0e371ba48e63c31c851f6a72bf Author: ShengYi Hung (Sun 19 Jul 2026 15:00:27 BST) Committer: ShengYi Hung (Sat 25 Jul 2026 14:13:24 BST) hwpstate_intel: Minimize ifdef for i386 build Reported by: jrtc27 Fixes: bdc0f7678257 MFC after: 3 days Sponsored by: The FreeBSD Foundation (cherry picked from commit 02c440e204041e92da403a64b70c2e1fdf3a4f73) M sys/x86/cpufreq/hwpstate_intel.c _____________________________________________________________________________________________________________ Commit: 592bf24126623d5c6b3ba689077cd4565b61058a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=592bf24126623d5c6b3ba689077cd4565b61058a Author: Harry Schmalzb (Mon 13 Jul 2026 06:29:34 BST) Committer: ShengYi Hung (Sat 25 Jul 2026 14:13:24 BST) hwpstate_intel: Fix i386 build Reviewed by: olce Fixes: 7b26353a59d6 MFC after: 3 days Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58208 (cherry picked from commit bdc0f7678257eaa739b9c816285504470e71e3de) M sys/x86/cpufreq/hwpstate_intel.c _____________________________________________________________________________________________________________ Commit: 493676d3b2717c12ee09d84a5b73758f75a66278 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=493676d3b2717c12ee09d84a5b73758f75a66278 Author: ShengYi Hung (Fri 10 Jul 2026 10:21:11 BST) Committer: ShengYi Hung (Sat 25 Jul 2026 14:13:24 BST) kvm: Support non-default CPUID leaf KVM does not always use 0x40000000 as its CPUID base. For example, QEMU adds a 0x100 offset when nested virtualization is detected and the host exposes Hyper-V enlightenment hints. To accommodate this behavior, switch the detection logic to use the CPUID leaf returned by do_cpuid(), making the implementation more flexible. See: https://github.com/qemu/qemu/blob/master/target/i386/kvm/kvm.c#L2300 Reviewed by: kib MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58146 (cherry picked from commit 86691d52a6d3796ad36ba474cf0a9493f6d99202) M sys/x86/include/kvm.h _____________________________________________________________________________________________________________ Commit: 4a1a1bf3afc7643356ed7d139cbdad47a9efc4c4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4a1a1bf3afc7643356ed7d139cbdad47a9efc4c4 Author: ShengYi Hung (Wed 24 Jun 2026 15:31:03 BST) Committer: ShengYi Hung (Sat 25 Jul 2026 14:13:24 BST) stand: Fix shadow buffer offset handling The shadow buffer is addressed relative to `tg_origin`, which includes the padding offset, whereas `gfxfb_blt` operates on coordinates without that offset. To make `gfx_fb_copy_area` emulate the behavior of `gfxfb_blt`, the source coordinates must include the padding offset, while the destination coordinates must not. The original implementation omitted the offset from the source coordinates; this change corrects that. Additionally, `gfx_fb_cons_display` already applies the padding offset, so the redundant adjustment is removed. PR: 296246 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296246 ) Reported by: 2khramtsov@gmail.com Reviewed by: imp Tested by: 2khramtsov@gmail.com, junchoon@dec.sakura.ne.jp, naito.yuichiro_@gmail.com Fixes: 32da2f23ae4d MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57821 (cherry picked from commit 76aa776b5f47ecd0d45336e22795fef98af57d2f) M stand/common/gfx_fb.c _____________________________________________________________________________________________________________ Commit: 1802f2ca72155858d0c35e4e00d203c6fc0873bf URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1802f2ca72155858d0c35e4e00d203c6fc0873bf Author: ShengYi Hung (Sun 31 May 2026 16:07:51 BST) Committer: ShengYi Hung (Sat 25 Jul 2026 14:13:24 BST) stand: Bulk operations on each gfxfb_blt if shadow buffer enabled Previously, gfxfb_blt flushed the framebuffer on every call. Since a single drawing operation may invoke gfxfb_blt multiple times, this can result in unnecessary flushes. Instead, write updates to the shadow buffer (when present) and mark the affected area as dirty. Flushing is deferred so multiple gfxfb_blt calls can be coalesced into a single update. As before, only the dirty region is flushed. This fixes the slow bootloader problem in some platforms. Reviewed by: imp, adrian, obiwac Tested by: obiwac, jrm MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57373 (cherry picked from commit 32da2f23ae4d18888d34682b0ddb49ec80c0bb26) M stand/common/gfx_fb.c M stand/common/gfx_fb.h M stand/ficl/gfx_loader.c M stand/liblua/gfx_utils.c _____________________________________________________________________________________________________________ Commit: 73a7f5ab5fb92481b142d22f20cac5423c91eace URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=73a7f5ab5fb92481b142d22f20cac5423c91eace Author: Roman Bogorodskiy (Sat 25 Apr 2026 17:03:58 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:24 BST) packages: make bhyve depend on acpi bhyve(8) on amd64 needs iasl(8) to run, otherwise it fails with: /bin/sh: /usr/sbin/iasl: not found bhyve: BASL failed @ build_dsdt:484 Failed to execute basl_compile(ctx, basl_fwrite_dsdt): Unknown error: 32512 bhyve: BASL failed @ acpi_build:899 Failed to execute build_dsdt(ctx): Unknown error: 32512 Assertion failed: (error == 0), function bhyve_init_platform_late, file /home/pkgbuild/worktrees/main/usr.sbin/bhyve/amd64/bhyverun_machdep.c, line 394. Register the "acpi" package which provides iasl(8) as a dependency for bhyve on amd64. Reviewed by: markj (previous revision), ivy Differential Revision: https://reviews.freebsd.org/D56498 Sponsored by: The FreeBSD Foundation (cherry picked from commit 8a9c94cd59eed09477049635663a7113ab0582a5) M packages/bhyve/Makefile _____________________________________________________________________________________________________________ Commit: 477500eb4490befd29e085454590039bf6383115 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=477500eb4490befd29e085454590039bf6383115 Author: Brad Davis (Mon 15 Jun 2026 18:59:19 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:24 BST) packages: Fix building packages when WITHOUT_BLOCKLIST is set Reviewed by: emaste MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D57601 (cherry picked from commit cd0a101b01d685092d073a367f0e7374f7259256) M packages/Makefile _____________________________________________________________________________________________________________ Commit: a0871fcc004d830e13535e84dab1ccd3eaebd2a6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a0871fcc004d830e13535e84dab1ccd3eaebd2a6 Author: Lexi Winter (Fri 17 Jul 2026 12:04:47 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:24 BST) packages/sound: Add dependency on bsdconfig Since the devd rules use sysrc, bsdconfig should be installed. MFC after: 3 days (cherry picked from commit 82aca8ef0dd73a09e46271158f822a7e49082cd0) M packages/sound/Makefile _____________________________________________________________________________________________________________ Commit: b5a144b5afdd78f16209a03e5c578be68aa9db9f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b5a144b5afdd78f16209a03e5c578be68aa9db9f Author: Lexi Winter (Wed 6 May 2026 15:45:54 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:24 BST) README.md: Add packages/ directory Fixes: bb75b0d581f7 ("packages: Convert world to a subdir build") MFC after: 2 weeks Reviewed by: des, emaste Differential Revision: https://reviews.freebsd.org/D56839 (cherry picked from commit e3e5b86e3b9e00f1fe89e54d13dcd665e63eb4c6) M README.md _____________________________________________________________________________________________________________ Commit: f948e6bda88c9f7c294e09528cc431f168c2b3b6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f948e6bda88c9f7c294e09528cc431f168c2b3b6 Author: Lexi Winter (Tue 5 May 2026 01:31:20 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:23 BST) packages: Make create-sets.sh more robust during release Commit d1c176fedfc9 made create-sets.sh exit when it encounters an error, instead of creating an empty repository. However, this turns out to cause some issues: 1. A package not having any sets is considered an error, but during the release build, we stuff a 'pkg' package into the repository which doesn't have any sets, which causes a failure. Avoid this by simply ignoring the pkg package. 2. No error was printed in this case, which made the problem hard to diagnose. Add an explicit error message. 3. A similar problem occurred running on a repository which already contained sets, which is not usually done during the build, but is not necessarly an inappropriate thing to do. Fix this one by ignoring set packages when looking for sets. While here, fix another issue that might cause packages to be wrongly skipped if the path to the repository contains a '-' character, since we didn't strip the path before testing the package name. PR: 294966 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=294966 ) Fixes: d1c176fedfc9 ("packages: Make create-sets.sh more robust") MFC after: 2 weeks Reported by: Alastair Hogge Reviewed by: emaste Sponsored by: https://www.patreon.com/bsdivy Differential Revision: https://reviews.freebsd.org/D56792 (cherry picked from commit 8e8d87856241f69c277dc5fab48c5c66312475d6) M release/packages/create-sets.sh _____________________________________________________________________________________________________________ Commit: f8b81bfc76d8e3c8ceb11e7285d0c04cb62a802e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f8b81bfc76d8e3c8ceb11e7285d0c04cb62a802e Author: Lexi Winter (Tue 28 Apr 2026 20:42:39 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:23 BST) Makefile.inc1: Only copy locales to INSTALLTMP on FreeBSD Makefile.inc1 copies locales to ${INSTALLTMP} to avoid issues when running make installworld on a live system. However, this can break on non-FreeBSD systems, e.g. on openSUSE where /usr/share/locales has mode 0555, which means after we copy it, we can't delete it, so the build fails. Since this functionality is only useful when installing over a live system, disable it when the build host is not FreeBSD. MFC after: 2 weeks Reviewed by: kevans, emaste Sponsored by: https://www.patreon.com/bsdivy Differential Revision: https://reviews.freebsd.org/D56677 (cherry picked from commit 4429630d1ca9d90c886bae1eaa0d8ee32d0fee12) M Makefile.inc1 _____________________________________________________________________________________________________________ Commit: 121e955d6164bfc4a09b990b786d254b99cc6a95 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=121e955d6164bfc4a09b990b786d254b99cc6a95 Author: Lexi Winter (Tue 28 Apr 2026 20:39:14 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:23 BST) packages: Make create-sets.sh more robust Use ${PKG_CMD} rather than bare 'pkg' to fix the build when pkg is not in the tools path. Provide a default in case it's not set for some reason (e.g., running the script by hand). Since set -- $(...) does not trigger an exit from set -e if the command fails, this failure was silent and resulted in sets not being built correctly if we failed to run pkg. Use a temporary variable, which does trigger set -e, to fail correctly. MFC after: 2 weeks Reviewed by: sjg Sponsored by: https://www.patreon.com/bsdivy Differential Revision: https://reviews.freebsd.org/D56676 (cherry picked from commit d1c176fedfc99d61c1dc8037ab549bec48c17bea) M release/packages/create-sets.sh _____________________________________________________________________________________________________________ Commit: a020a88c13d936928698d3677bb7d3768a597313 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a020a88c13d936928698d3677bb7d3768a597313 Author: Lexi Winter (Tue 28 Apr 2026 20:38:36 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:23 BST) llvm: Move libprivatelldb to the lldb package Set PACKAGE=lldb in lldb.pre.mk rather than in individual Makefiles; change lib/clang/Makefile.inc from PACKAGE=clang to PACKAGE?=clang to avoid overwriting it. This is safe to MFC to stable/15 since the moved library will be picked up automatically by pkg. MFC after: 2 weeks Reviewed by: emaste Sponsored by: https://www.patreon.com/bsdivy Differential Revision: https://reviews.freebsd.org/D56674 (cherry picked from commit 7970815be40b1fa604a6554f5ee0f95f834454b5) M lib/clang/Makefile.inc M lib/clang/liblldb/Makefile M lib/clang/lldb.pre.mk M usr.bin/clang/lldb-server/Makefile M usr.bin/clang/lldb/Makefile _____________________________________________________________________________________________________________ Commit: 58c08517ce5dea7515837c8c4f24d3beefe48403 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=58c08517ce5dea7515837c8c4f24d3beefe48403 Author: Lexi Winter (Tue 28 Apr 2026 20:37:33 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:23 BST) acpi: Remove userland bits on non-ACPI platforms ACPI is only supported on amd64, arm64 and i386. Don't install the power_profile rc script or devd configuration on other platforms. This avoids creating a useless FreeBSD-acpi package on those platforms. MFC after: 2 weeks Reviewed by: imp Sponsored by: https://www.patreon.com/bsdivy Differential Revision: https://reviews.freebsd.org/D56650 (cherry picked from commit c4b244af42a1f20937939a824b753a92c9c0a46f) M libexec/rc/rc.d/Makefile D packages/Makefile.arm D packages/Makefile.powerpc M packages/Makefile.riscv64 M packages/acpi/Makefile M sbin/devd/Makefile M tools/build/mk/OptionalObsoleteFiles.inc _____________________________________________________________________________________________________________ Commit: 9b6e6b2923de5702dbdb645a1d336641ece8acce URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=9b6e6b2923de5702dbdb645a1d336641ece8acce Author: Lexi Winter (Mon 27 Apr 2026 23:15:13 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:23 BST) packages: Fix clang conditional Various src.conf options can cause us to build something that ends up in the clang package, but MK_TOOLCHAIN is not one of them; copy the proper conditional from lib/Makefile to decide if we need to build the package. This fixes the build when LLVM/clang is entirely disabled. Fixes: bb75b0d581f7 ("packages: Convert world to a subdir build") MFC after: 2 weeks Reviewed by: emaste Sponsored by: https://www.patreon.com/bsdivy Differential Revision: https://reviews.freebsd.org/D56657 (cherry picked from commit e6d112bbbbf0b09f0f18a85a0a3c6d5a49aff653) M packages/Makefile _____________________________________________________________________________________________________________ Commit: d2ce6ed7f553164f4f504b1a46cf06336c525674 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d2ce6ed7f553164f4f504b1a46cf06336c525674 Author: Lexi Winter (Mon 27 Apr 2026 22:29:43 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:23 BST) Makefile.inc1: Always use ${PKG_CMD} Previously we had a mix of ${PKG_CMD} and bare 'pkg', which is wrong, and breaks the build when 'pkg' isn't in the tools path, e.g. when cross-building. MFC after: 2 weeks Reviewed by: wosch, emaste Sponsored by: https://www.patreon.com/bsdivy Differential Revision: https://reviews.freebsd.org/D56655 (cherry picked from commit b866d05ea2860f9ccc27c75ff0501372896b5bf2) M Makefile.inc1 _____________________________________________________________________________________________________________ Commit: 0851f28403e3eaefd0973eac1d4287765a70d517 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0851f28403e3eaefd0973eac1d4287765a70d517 Author: Lexi Winter (Mon 27 Apr 2026 22:26:45 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:23 BST) Makefile.inc1: Use ln -n instead of ln -h We support both -h and -n, but GNU coreutils only supports -n, so use that instead. This fixes the package build on Linux. MFC after: 2 weeks Reviewed by: (wosch, imp) (previous version), emaste Better fix than the original patch suggested by: jrtc27 Sponsored by: https://www.patreon.com/bsdivy Differential Revision: https://reviews.freebsd.org/D56656 (cherry picked from commit d455c4bb69eca975854262207687db50a5edc434) M Makefile.inc1 _____________________________________________________________________________________________________________ Commit: 21419de0a45dca22a950555c82fe14b6d5192a46 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=21419de0a45dca22a950555c82fe14b6d5192a46 Author: Lexi Winter (Mon 27 Apr 2026 06:45:48 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:23 BST) packages: Don't build quotacheck if WITHOUT_QUOTAS=yes PR: 294775 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=294775 ) Fixes: bb75b0d581f7 ("packages: Convert world to a subdir build") MFC after: 2 weeks Reported by: Alastair Hogge Sponsored by: https://www.patreon.com/bsdivy Differential Revision: https://reviews.freebsd.org/D56635 (cherry picked from commit 221b1d4156a2bfe71a473e5abf6a739c063e60d8) M packages/Makefile _____________________________________________________________________________________________________________ Commit: b04fa0f8b8c562c7f8af9ad762ffcd31e6d63745 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b04fa0f8b8c562c7f8af9ad762ffcd31e6d63745 Author: Lexi Winter (Sun 26 Apr 2026 17:47:27 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:23 BST) apm: Only install rc script on i386 The apm(8) rc script only works on i386, but it's installed on all platforms. Only install it on i386, which avoids creating a useless FreeBSD-apm package on other platforms. While here, build the acpi package on i386. Relnotes: yes MFC after: 2 weeks Reviewed by: imp Sponsored by: https://www.patreon.com/bsdivy Differential Revision: https://reviews.freebsd.org/D56629 (cherry picked from commit b7daab8be1d4555f23a297e60e4128c01caabf82) M libexec/rc/rc.d/Makefile M packages/Makefile.arm M packages/Makefile.arm64 A packages/Makefile.i386 M packages/Makefile.powerpc M packages/Makefile.riscv64 M packages/apm/Makefile M tools/build/mk/OptionalObsoleteFiles.inc _____________________________________________________________________________________________________________ Commit: 1d0ae66d3c21c22787686fa95330cbdd94d0289b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1d0ae66d3c21c22787686fa95330cbdd94d0289b Author: Lexi Winter (Fri 24 Apr 2026 15:10:01 BST) Committer: Lexi Winter (Sat 25 Jul 2026 14:01:23 BST) packages: Convert world to a subdir build Instead of driving the world package build from Makefile.inc1, use a subdir build where each package has a subdirectory under packages/ using the new . Convert some metadata that was previously in the UCL files (e.g. sets and dependencies) to Makefile variables. Build the packages under objdir (not repodir), and use the new stagepackages target to copy them to repodir when creating the repository. Determine an explicit list of packages to build in packages/Makefile based on enabled src.conf options, and add logic to abort the build if we attempt to build an empty package. This inverts the previous logic in Makefile.inc1 which would simply skip empty packages. There are a few advantages to doing it this way: * The package build works more like the rest of the build system, so it's more accessible to developers. * We can customise the packages we build based on src.conf options, e.g. skipping a package entirely, or adjusting its dependencies based on what it actually requires. * We have a specific list of packages that we want to build, and an unexpectedly missing package results in a build error, instead of silently producing a broken repository. * It's possible to build (and in the future, install) an individual package without having to rebuild the entire repository. This doesn't apply to the dtb, kernel-* or src-* packages; those have their own build systems in Makefile.inc1 and will be converted later. MFC after: 4 weeks (stable/15 only) Reviewed by: jlduran, sjg, brooks Sponsored by: https://www.patreon.com/bsdivy Sponsored by: The FreeBSD Foundation (MFC only) Differential Revision: https://reviews.freebsd.org/D56087 (cherry picked from commit bb75b0d581f74e22a68d7868ad1f5da1146a8de0) M Makefile.inc1 A packages/Makefile A packages/Makefile.amd64 A packages/Makefile.arm A packages/Makefile.arm64 A packages/Makefile.powerpc A packages/Makefile.riscv64 A packages/acct/Makefile R096 release/packages/ucl/acct-all.ucl packages/acct/acct.ucl A packages/acpi/Makefile R097 release/packages/ucl/acpi-all.ucl packages/acpi/acpi.ucl A packages/apm/Makefile R097 release/packages/ucl/apm-all.ucl packages/apm/apm.ucl A packages/at/Makefile R096 release/packages/ucl/at-all.ucl packages/at/at.ucl A packages/atf/Makefile R097 release/packages/ucl/atf-all.ucl packages/atf/atf.ucl A packages/audit/Makefile R097 release/packages/ucl/audit-all.ucl packages/audit/audit.ucl A packages/autofs/Makefile R096 release/packages/ucl/autofs-all.ucl packages/autofs/autofs.ucl A packages/bhyve/Makefile R097 release/packages/ucl/bhyve-all.ucl packages/bhyve/bhyve.ucl A packages/blocklist/Makefile R096 release/packages/ucl/blocklist-all.ucl packages/blocklist/blocklist.ucl A packages/bluetooth/Makefile R097 release/packages/ucl/bluetooth-all.ucl packages/bluetooth/bluetooth.ucl A packages/bmake/Makefile R097 release/packages/ucl/bmake-all.ucl packages/bmake/bmake.ucl A packages/bootloader/Makefile R097 release/packages/ucl/bootloader-all.ucl packages/bootloader/bootloader.ucl A packages/bsdconfig/Makefile R095 release/packages/ucl/bsdconfig-all.ucl packages/bsdconfig/bsdconfig.ucl A packages/bsdinstall/Makefile R097 release/packages/ucl/bsdinstall-all.ucl packages/bsdinstall/bsdinstall.ucl A packages/bsnmp/Makefile R097 release/packages/ucl/bsnmp-all.ucl packages/bsnmp/bsnmp.ucl A packages/bzip2/Makefile R088 release/packages/ucl/bzip2-all.ucl packages/bzip2/bzip2.ucl A packages/caroot/Makefile R080 release/packages/ucl/caroot.ucl packages/caroot/caroot.ucl R096 release/packages/ucl/caroot-all.ucl packages/caroot/common.ucl A packages/ccdconfig/Makefile R096 release/packages/ucl/ccdconfig-all.ucl packages/ccdconfig/ccdconfig.ucl A packages/certctl/Makefile R097 release/packages/ucl/certctl-all.ucl packages/certctl/certctl.ucl A packages/clang/Makefile R093 release/packages/ucl/clang-all.ucl packages/clang/clang.ucl A packages/clibs/Makefile R095 release/packages/ucl/clibs-all.ucl packages/clibs/clibs.ucl A packages/console-tools/Makefile R097 release/packages/ucl/console-tools-all.ucl packages/console-tools/console-tools.ucl A packages/cron/Makefile R096 release/packages/ucl/cron-all.ucl packages/cron/cron.ucl A packages/csh/Makefile R097 release/packages/ucl/csh-all.ucl packages/csh/csh.ucl A packages/ctf/Makefile R096 release/packages/ucl/ctf-all.ucl packages/ctf/ctf.ucl A packages/ctl/Makefile R098 release/packages/ucl/ctl-all.ucl packages/ctl/ctl.ucl A packages/cxgbe-tools/Makefile R097 release/packages/ucl/cxgbe-tools-all.ucl packages/cxgbe-tools/cxgbe-tools.ucl A packages/devd/Makefile R097 release/packages/ucl/devd-all.ucl packages/devd/devd.ucl A packages/devmatch/Makefile R097 release/packages/ucl/devmatch-all.ucl packages/devmatch/devmatch.ucl A packages/dhclient/Makefile R096 release/packages/ucl/dhclient-all.ucl packages/dhclient/dhclient.ucl A packages/diff3/Makefile R067 release/packages/ucl/diff3-all.ucl packages/diff3/diff3.ucl A packages/dma/Makefile R097 release/packages/ucl/dma-all.ucl packages/dma/dma.ucl A packages/dtrace/Makefile R097 release/packages/ucl/dtrace-all.ucl packages/dtrace/dtrace.ucl A packages/dwatch/Makefile R098 release/packages/ucl/dwatch-all.ucl packages/dwatch/dwatch.ucl A packages/ee/Makefile R095 release/packages/ucl/ee-all.ucl packages/ee/ee.ucl A packages/efi-tools/Makefile R097 release/packages/ucl/efi-tools-all.ucl packages/efi-tools/efi-tools.ucl A packages/examples/Makefile R095 release/packages/ucl/examples-all.ucl packages/examples/examples.ucl A packages/fd/Makefile R097 release/packages/ucl/fd-all.ucl packages/fd/fd.ucl A packages/fetch/Makefile R096 release/packages/ucl/fetch-all.ucl packages/fetch/fetch.ucl A packages/firmware-iwm/Makefile R096 release/packages/ucl/firmware-iwm-all.ucl packages/firmware-iwm/firmware-iwm.ucl A packages/flua/Makefile R095 release/packages/ucl/flua-all.ucl packages/flua/flua.ucl A packages/ftp/Makefile R095 release/packages/ucl/ftp-all.ucl packages/ftp/ftp.ucl A packages/fwget/Makefile R097 release/packages/ucl/fwget-all.ucl packages/fwget/fwget.ucl A packages/games/Makefile R095 release/packages/ucl/games-all.ucl packages/games/games.ucl A packages/geom/Makefile R097 release/packages/ucl/geom-all.ucl packages/geom/geom.ucl A packages/ggate/Makefile R097 release/packages/ucl/ggate-all.ucl packages/ggate/ggate.ucl A packages/gssd/Makefile R096 release/packages/ucl/gssd-all.ucl packages/gssd/gssd.ucl A packages/hast/Makefile R096 release/packages/ucl/hast-all.ucl packages/hast/hast.ucl A packages/hostapd/Makefile R097 release/packages/ucl/hostapd-all.ucl packages/hostapd/hostapd.ucl A packages/hyperv-tools/Makefile R096 release/packages/ucl/hyperv-tools-all.ucl packages/hyperv-tools/hyperv-tools.ucl A packages/inetd/Makefile R095 release/packages/ucl/inetd-all.ucl packages/inetd/inetd.ucl A packages/ipf/Makefile R096 release/packages/ucl/ipf-all.ucl packages/ipf/ipf.ucl A packages/ipfw/Makefile R096 release/packages/ucl/ipfw-all.ucl packages/ipfw/ipfw.ucl A packages/iscsi/Makefile R097 release/packages/ucl/iscsi-all.ucl packages/iscsi/iscsi.ucl A packages/jail/Makefile R096 release/packages/ucl/jail-all.ucl packages/jail/jail.ucl A packages/kerberos-kdc/Makefile R096 release/packages/ucl/kerberos-kdc-all.ucl packages/kerberos-kdc/kerberos-kdc.ucl A packages/kerberos/Makefile R096 release/packages/ucl/kerberos-all.ucl packages/kerberos/kerberos.ucl A packages/kernel-man/Makefile R095 release/packages/ucl/kernel-man.ucl packages/kernel-man/kernel-man.ucl A packages/kyua/Makefile R098 release/packages/ucl/kyua-all.ucl packages/kyua/kyua.ucl A packages/lib9p/Makefile R095 release/packages/ucl/lib9p-all.ucl packages/lib9p/lib9p.ucl A packages/libarchive/Makefile R097 release/packages/ucl/libarchive-all.ucl packages/libarchive/libarchive.ucl A packages/libbegemot/Makefile R097 release/packages/ucl/libbegemot-all.ucl packages/libbegemot/libbegemot.ucl A packages/libblocksruntime/Makefile R095 release/packages/ucl/libblocksruntime-all.ucl packages/libblocksruntime/libblocksruntime.ucl A packages/libbsdstat/Makefile R095 release/packages/ucl/libbsdstat-all.ucl packages/libbsdstat/libbsdstat.ucl A packages/libcasper/Makefile R095 release/packages/ucl/libcasper-all.ucl packages/libcasper/libcasper.ucl A packages/libcompat/Makefile R095 release/packages/ucl/libcompat-all.ucl packages/libcompat/libcompat.ucl A packages/libcompiler_rt/Makefile R065 release/packages/ucl/libcompiler_rt-all.ucl packages/libcompiler_rt/libcompiler_rt.ucl A packages/libcuse/Makefile R096 release/packages/ucl/libcuse-all.ucl packages/libcuse/libcuse.ucl A packages/libdwarf/Makefile R097 release/packages/ucl/libdwarf-all.ucl packages/libdwarf/libdwarf.ucl A packages/libevent1/Makefile R095 release/packages/ucl/libevent1-all.ucl packages/libevent1/libevent1.ucl A packages/libexecinfo/Makefile R095 release/packages/ucl/libexecinfo-all.ucl packages/libexecinfo/libexecinfo.ucl A packages/libipt/Makefile R085 release/packages/ucl/libipt-all.ucl packages/libipt/libipt.ucl A packages/libldns/Makefile R095 release/packages/ucl/libldns-all.ucl packages/libldns/libldns.ucl A packages/libmagic/Makefile R095 release/packages/ucl/libmagic-all.ucl packages/libmagic/libmagic.ucl A packages/libmilter/Makefile R086 release/packages/ucl/libmilter-all.ucl packages/libmilter/libmilter.ucl A packages/libpathconv/Makefile R095 release/packages/ucl/libpathconv-all.ucl packages/libpathconv/libpathconv.ucl A packages/librpcsec_gss/Makefile R097 release/packages/ucl/librpcsec_gss-all.ucl packages/librpcsec_gss/librpcsec_gss.ucl A packages/librss/Makefile R080 release/packages/ucl/librss-all.ucl packages/librss/librss.ucl A packages/libsqlite3/Makefile R095 release/packages/ucl/libsqlite3-all.ucl packages/libsqlite3/libsqlite3.ucl A packages/libthread_db/Makefile R095 release/packages/ucl/libthread_db-all.ucl packages/libthread_db/libthread_db.ucl A packages/libucl/Makefile R095 release/packages/ucl/libucl-all.ucl packages/libucl/libucl.ucl A packages/libvgl/Makefile R097 release/packages/ucl/libvgl-all.ucl packages/libvgl/libvgl.ucl A packages/libvmmapi/Makefile R095 release/packages/ucl/libvmmapi-all.ucl packages/libvmmapi/libvmmapi.ucl A packages/libyaml/Makefile R095 release/packages/ucl/libyaml-all.ucl packages/libyaml/libyaml.ucl A packages/lld/Makefile R095 release/packages/ucl/lld-all.ucl packages/lld/lld.ucl A packages/lldb/Makefile R094 release/packages/ucl/lldb-all.ucl packages/lldb/lldb.ucl A packages/local-unbound/Makefile R094 release/packages/ucl/local-unbound-all.ucl packages/local-unbound/common.ucl R087 release/packages/ucl/local-unbound.ucl packages/local-unbound/local-unbound.ucl A packages/locales/Makefile R095 release/packages/ucl/locales-all.ucl packages/locales/locales.ucl A packages/lp/Makefile R096 release/packages/ucl/lp-all.ucl packages/lp/lp.ucl A packages/mandoc/Makefile R095 release/packages/ucl/mandoc-all.ucl packages/mandoc/mandoc.ucl A packages/mlx-tools/Makefile R098 release/packages/ucl/mlx-tools-all.ucl packages/mlx-tools/mlx-tools.ucl A packages/mtree/Makefile R097 release/packages/ucl/mtree-all.ucl packages/mtree/mtree.ucl A packages/natd/Makefile R096 release/packages/ucl/natd-all.ucl packages/natd/natd.ucl A packages/ncurses/Makefile R093 release/packages/ucl/ncurses-all.ucl packages/ncurses/ncurses.ucl A packages/netmap/Makefile R096 release/packages/ucl/netmap-all.ucl packages/netmap/netmap.ucl A packages/newsyslog/Makefile R096 release/packages/ucl/newsyslog-all.ucl packages/newsyslog/newsyslog.ucl A packages/nfs/Makefile R096 release/packages/ucl/nfs-all.ucl packages/nfs/nfs.ucl A packages/ntp/Makefile R097 release/packages/ucl/ntp-all.ucl packages/ntp/ntp.ucl A packages/nuageinit/Makefile R097 release/packages/ucl/nuageinit-all.ucl packages/nuageinit/nuageinit.ucl A packages/nvme-tools/Makefile R097 release/packages/ucl/nvme-tools-all.ucl packages/nvme-tools/nvme-tools.ucl A packages/openssl/Makefile R097 release/packages/ucl/openssl-all.ucl packages/openssl/openssl.ucl A packages/pam/Makefile R096 release/packages/ucl/pam-all.ucl packages/pam/pam.ucl A packages/periodic/Makefile R076 release/packages/ucl/periodic.ucl packages/periodic/periodic.ucl A packages/pf/Makefile R096 release/packages/ucl/pf-all.ucl packages/pf/pf.ucl A packages/pkg-bootstrap/Makefile R095 release/packages/ucl/pkg-bootstrap-all.ucl packages/pkg-bootstrap/pkg-bootstrap.ucl A packages/pkgconf/Makefile A packages/pmc/Makefile R091 release/packages/ucl/pmc-all.ucl packages/pmc/pmc.ucl A packages/powerd/Makefile R089 release/packages/ucl/powerd-all.ucl packages/powerd/powerd.ucl A packages/ppp/Makefile R096 release/packages/ucl/ppp-all.ucl packages/ppp/ppp.ucl A packages/quotacheck/Makefile R097 release/packages/ucl/quotacheck-all.ucl packages/quotacheck/quotacheck.ucl A packages/rc/Makefile R077 release/packages/ucl/rc.ucl packages/rc/rc.ucl A packages/rcmds/Makefile R095 release/packages/ucl/rcmds-all.ucl packages/rcmds/rcmds.ucl A packages/rdma/Makefile R095 release/packages/ucl/rdma-all.ucl packages/rdma/rdma.ucl A packages/rescue/Makefile R097 release/packages/ucl/rescue-all.ucl packages/rescue/rescue.ucl A packages/resolvconf/Makefile R097 release/packages/ucl/resolvconf-all.ucl packages/resolvconf/resolvconf.ucl A packages/rip/Makefile R095 release/packages/ucl/rip-all.ucl packages/rip/rip.ucl A packages/runtime/Makefile R095 release/packages/ucl/runtime-all.ucl packages/runtime/common.ucl R083 release/packages/ucl/runtime.ucl packages/runtime/runtime.ucl A packages/sendmail/Makefile R096 release/packages/ucl/sendmail-all.ucl packages/sendmail/sendmail.ucl A packages/smbutils/Makefile R097 release/packages/ucl/smbutils-all.ucl packages/smbutils/smbutils.ucl A packages/sound/Makefile R097 release/packages/ucl/sound-all.ucl packages/sound/sound.ucl A packages/ssh/Makefile R095 release/packages/ucl/ssh-all.ucl packages/ssh/ssh.ucl A packages/syscons-data/Makefile R096 release/packages/ucl/syscons-data-all.ucl packages/syscons-data/syscons-data.ucl A packages/syslogd/Makefile R096 release/packages/ucl/syslogd-all.ucl packages/syslogd/syslogd.ucl A packages/tcpd/Makefile R096 release/packages/ucl/tcpd-all.ucl packages/tcpd/tcpd.ucl A packages/telnet/Makefile R096 release/packages/ucl/telnet-all.ucl packages/telnet/telnet.ucl A packages/tests/Makefile R084 release/packages/ucl/tests.ucl packages/tests/tests.ucl A packages/toolchain/Makefile R097 release/packages/ucl/toolchain-all.ucl packages/toolchain/toolchain.ucl A packages/ufs/Makefile R098 release/packages/ucl/ufs-all.ucl packages/ufs/ufs.ucl A packages/utilities/Makefile R095 release/packages/ucl/utilities-all.ucl packages/utilities/common.ucl R071 release/packages/ucl/utilities.ucl packages/utilities/utilities.ucl A packages/vi/Makefile R095 release/packages/ucl/vi-all.ucl packages/vi/vi.ucl A packages/vt-data/Makefile R096 release/packages/ucl/vt-data-all.ucl packages/vt-data/vt-data.ucl A packages/wpa/Makefile R098 release/packages/ucl/wpa-all.ucl packages/wpa/wpa.ucl A packages/xz/Makefile R095 release/packages/ucl/xz-all.ucl packages/xz/xz.ucl A packages/yp/Makefile R096 release/packages/ucl/yp-all.ucl packages/yp/yp.ucl A packages/zfs/Makefile R096 release/packages/ucl/zfs-all.ucl packages/zfs/zfs.ucl A packages/zlib/Makefile R094 release/packages/ucl/zlib-all.ucl packages/zlib/zlib.ucl A packages/zoneinfo/Makefile R093 release/packages/ucl/zoneinfo-all.ucl packages/zoneinfo/zoneinfo.ucl A packages/zstd/Makefile R096 release/packages/ucl/zstd-all.ucl packages/zstd/zstd.ucl D release/packages/ucl/at.ucl D release/packages/ucl/bluetooth.ucl D release/packages/ucl/bsdconfig.ucl D release/packages/ucl/bsdinstall.ucl D release/packages/ucl/certctl.ucl D release/packages/ucl/clang.ucl D release/packages/ucl/clibs.ucl D release/packages/ucl/devd.ucl D release/packages/ucl/dhclient.ucl D release/packages/ucl/newsyslog.ucl D release/packages/ucl/periodic-all.ucl D release/packages/ucl/rc-all.ucl D release/packages/ucl/rcmds.ucl D release/packages/ucl/sendmail.ucl D release/packages/ucl/tests-all.ucl D release/packages/ucl/yp.ucl A share/mk/bsd.pkg.mk A share/mk/bsd.pkg.pre.mk M share/mk/bsd.subdir.mk _____________________________________________________________________________________________________________ Commit: 508af47d2f9f0379b4d82da0b829ac089221982f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=508af47d2f9f0379b4d82da0b829ac089221982f Author: Rick Macklem (Sat 11 Jul 2026 20:30:51 BST) Committer: Rick Macklem (Sat 25 Jul 2026 02:20:03 BST) nfsd: Commit missing patches for c52bcd09c2a6 Oops, I missed the other files for the commit. This should fix the build. Pointy hat goes on me. (cherry picked from commit 30d4d3db431a5df8084048c4d31e98e74d2f225a) M sys/fs/nfs/nfs_var.h M sys/fs/nfsserver/nfs_nfsdsocket.c _____________________________________________________________________________________________________________ Commit: 3ad71ccbc58fe3d99e8af7f4246f4a85a0ef370d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3ad71ccbc58fe3d99e8af7f4246f4a85a0ef370d Author: Rick Macklem (Sat 11 Jul 2026 16:49:12 BST) Committer: Rick Macklem (Sat 25 Jul 2026 02:19:03 BST) nfsd: Garbage collect stray NFSv4 state When a file is deleted on the NFS server by another client, any NFSv4 state related to that file is left stranded. This happens because the NFSv4 operations that free the state use a CFH, which is set by a PutFH operation. However, the PutFH fails with ESTALE because the file has been deleted. This patch adds a function called nfsrv_freestrandedstate() that frees all the NFSv4 state related to a file and calls this function when PutFH will be replying ESTALE. While here, a helper function was defined to handle free'ng of the nfslockfile structure and replaces the two places where nearly identical code does this. (cherry picked from commit c52bcd09c2a6736fe841fd72e3cfb74de5a35b03) M sys/fs/nfsserver/nfs_nfsdstate.c _____________________________________________________________________________________________________________ Commit: 4c150f34242e3ab71aad6670203486424d20bb6f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=4c150f34242e3ab71aad6670203486424d20bb6f Author: Siva Mahadevan (Wed 22 Jul 2026 02:58:58 BST) Committer: Siva Mahadevan (Sat 25 Jul 2026 01:56:49 BST) powerpc64: enable extended error strings in GENERIC64* configs These kernconfs were missed in the previous commit. PR: 289236 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=289236 ) Reviewed by: kib Fixes: f38cbefef8090f3363e5685c5a3b30ffbf1d3ad0 MFC after: 3 days Sponsored by: The FreeBSD Foundation (cherry picked from commit afa048d159f64e1c609475314e19fb030ffd595f) M sys/powerpc/conf/GENERIC64 M sys/powerpc/conf/GENERIC64LE _____________________________________________________________________________________________________________ Commit: e1e6a16abfd8d99a3dc2d15d7a79b8270e497c15 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e1e6a16abfd8d99a3dc2d15d7a79b8270e497c15 Author: Siva Mahadevan (Tue 30 Jun 2026 17:40:00 BST) Committer: Siva Mahadevan (Sat 25 Jul 2026 01:56:48 BST) tests/netpfil: start ipfilter for ipfnat firewall type This requested fix[0] was not complete before the change was committed. Cleans up this error message when running tests[1]: "Cannot 'start' ipfilter. Set ipfilter_enable to YES in /etc/rc.conf or use 'onestart' instead of 'start'." [0] https://reviews.freebsd.org/D21065?id=60288#inline-131488 [1] https://ci.freebsd.org/job/FreeBSD-main-amd64-test/28917/testReport/sys.netpfil.common/rdr/ipfnat_local_redirect/ Fixes: f97a8a36153a9 MFC after: 3 days Sponsored by: The FreeBSD Foundation (cherry picked from commit afbb7dc0a51e4d4c227bdf00770d1ad821cf9889) M tests/sys/netpfil/common/utils.subr _____________________________________________________________________________________________________________ Commit: daf364fa3482f47bf93802610c914e3f994a742b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=daf364fa3482f47bf93802610c914e3f994a742b Author: Ed Maste (Wed 7 Jan 2026 16:16:45 GMT) Committer: Ed Maste (Fri 24 Jul 2026 17:00:19 BST) aq(4): style(9) cleanup (cherry picked from commit 668423f75b4d9006f16847b415c861defb8267d7) M sys/dev/aq/aq_common.h M sys/dev/aq/aq_dbg.c M sys/dev/aq/aq_device.h M sys/dev/aq/aq_fw.c M sys/dev/aq/aq_fw1x.c M sys/dev/aq/aq_fw2x.c M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_hw_llh.c M sys/dev/aq/aq_media.c M sys/dev/aq/aq_ring.c _____________________________________________________________________________________________________________ Commit: 06a2734728b1ec19daa63ad78b6e1cd46ec8d871 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=06a2734728b1ec19daa63ad78b6e1cd46ec8d871 Author: Ed Maste (Wed 19 Nov 2025 15:34:25 GMT) Committer: Ed Maste (Fri 24 Jul 2026 17:00:19 BST) aq(4): Style, whitespace and misc cleanup The compiled objects do not change other than a few diagnostic messages that include __LINE__. Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D54304 (cherry picked from commit 96156003ec0c70de88a448d48d8e9bd37913589f) M sys/dev/aq/aq_common.h M sys/dev/aq/aq_dbg.c M sys/dev/aq/aq_dbg.h M sys/dev/aq/aq_device.h M sys/dev/aq/aq_fw.c M sys/dev/aq/aq_fw.h M sys/dev/aq/aq_fw1x.c M sys/dev/aq/aq_fw2x.c M sys/dev/aq/aq_hw.c M sys/dev/aq/aq_hw.h M sys/dev/aq/aq_hw_llh.c M sys/dev/aq/aq_hw_llh.h M sys/dev/aq/aq_hw_llh_internal.h M sys/dev/aq/aq_irq.c M sys/dev/aq/aq_main.c M sys/dev/aq/aq_media.c M sys/dev/aq/aq_ring.c M sys/dev/aq/aq_ring.h _____________________________________________________________________________________________________________ Commit: b22b15981dbed61cac32cc5325fb073019e8aa69 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b22b15981dbed61cac32cc5325fb073019e8aa69 Author: Ed Maste (Thu 13 Nov 2025 22:20:13 GMT) Committer: Ed Maste (Fri 24 Jul 2026 17:00:19 BST) aq(4): Use standard ETHER_ADDR_LEN definition No need for a bespoke #define. (cherry picked from commit 8c64625d90792462289686e0209a9f3fff67fc9b) M sys/dev/aq/aq_common.h M sys/dev/aq/aq_fw1x.c M sys/dev/aq/aq_fw2x.c M sys/dev/aq/aq_hw.h _____________________________________________________________________________________________________________ Commit: df0b7816837c654fa3c0fb2744f4a4ab017193f6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=df0b7816837c654fa3c0fb2744f4a4ab017193f6 Author: Ed Maste (Thu 13 Nov 2025 19:05:08 GMT) Committer: Ed Maste (Fri 24 Jul 2026 17:00:19 BST) aq(4): Use sys, not userland, headers And remove some unused definitions. Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D54152 (cherry picked from commit d2850435f18c81479f79bd23ea8d4b997dbc0521) M sys/dev/aq/aq_common.h M sys/dev/aq/aq_dbg.h M sys/dev/aq/aq_fw.c M sys/dev/aq/aq_fw1x.c M sys/dev/aq/aq_fw2x.c M sys/dev/aq/aq_hw.h _____________________________________________________________________________________________________________ Commit: 1fecb10f94284b38702aafcc243d0c3dce5c286a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1fecb10f94284b38702aafcc243d0c3dce5c286a Author: Ed Maste (Thu 13 Nov 2025 14:15:38 GMT) Committer: Ed Maste (Fri 24 Jul 2026 17:00:18 BST) aq(4): Fix VLAN tag test Previously emitted a compiler warning "warning: bitwise comparison always evaluates to false." Looking at the OpenBSD driver (which is based on this code) it looks like the VLAN flag should be set if either of these bits is. In the OpenBSD driver these are AQ_RXDESC_TYPE_VLAN and AQ_RXDESC_TYPE_VLAN2 rather than a magic number 0x60. Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D53836 (cherry picked from commit 8666fda1afb03b3a88e57a20d76da8e7910b6407) M sys/dev/aq/aq_ring.c _____________________________________________________________________________________________________________ Commit: bd6af817274c1b6019858ac49e0b5d89d74f6506 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bd6af817274c1b6019858ac49e0b5d89d74f6506 Author: Ed Maste (Wed 12 Nov 2025 23:45:37 GMT) Committer: Ed Maste (Fri 24 Jul 2026 17:00:18 BST) aq(4): Remove unimplemented functions aq_if_priv_ioctl and aq_if_debug have prototypes but are not yet implemented. Just remove the commented-out DEVMETHODs and the unused prototypes, to clear a build-time warning; the DEVMETHODs and prototypes can be readded if / when they are implemented. (cherry picked from commit 0156be41a1eb8e0408819466b912181aa7966df9) M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: 539bc9a232014435a2a54569ca37973a3f28e201 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=539bc9a232014435a2a54569ca37973a3f28e201 Author: John Baldwin (Thu 13 Nov 2025 03:23:27 GMT) Committer: Ed Maste (Fri 24 Jul 2026 17:00:18 BST) aq(4): Remove unused DRIVER_MODULE devclass (cherry picked from commit 2b587c0c8a933cd110ae579366644a280c509b7f) M sys/dev/aq/aq_main.c _____________________________________________________________________________________________________________ Commit: c9ee056af737e79e1748a430f091aefb1ba31b90 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c9ee056af737e79e1748a430f091aefb1ba31b90 Author: Olivier Cochard (Thu 13 Nov 2025 03:17:03 GMT) Committer: Ed Maste (Fri 24 Jul 2026 17:00:18 BST) aq(4): Port to IfAPI Direct access to struct ifnet members is not possible in FreeBSD 15; accessors must be used. These exist in all supported FreeBSD versions, so we do not need to make this conditional. (cherry picked from commit 4756f5ff8f10cdda925cab60c0b66606698e49ee) M sys/dev/aq/aq_main.c M sys/dev/aq/aq_media.c M sys/dev/aq/aq_ring.c _____________________________________________________________________________________________________________ Commit: f6e84c71798c907794c9550e88fb85ae3917b260 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f6e84c71798c907794c9550e88fb85ae3917b260 Author: Rozhuk Ivan (Wed 26 Oct 2022 13:37:57 BST) Committer: Ed Maste (Fri 24 Jul 2026 17:00:18 BST) aq(4): Remove #include of user header pause() has 2 different definition in unistd.h and sys/systm.h (cherry picked from commit 14eb7ec7b7135ad1a3448590cbe70b1368b40ec7) M sys/dev/aq/aq_hw.c _____________________________________________________________________________________________________________ Commit: 56e056aad5612788c440629b033ce1fb3dbcc05e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=56e056aad5612788c440629b033ce1fb3dbcc05e Author: Ed Maste (Thu 13 Nov 2025 18:48:54 GMT) Committer: Ed Maste (Fri 24 Jul 2026 17:00:18 BST) sys: Import snapshot of Aquantia ACQ107 vendor driver Obtained from https://github.com/Aquantia/aqtion-freebsd commit c61d27b1d94af72c642deefa0595884481ea7377. This is not using a vendor branch. The formerly-upstream repo is abandoned and I do not believe it will receive updates. This initial import serves as a snapshot of the vendor code, but from here we will iterate on it in the tree as our own code. Bug fixes, code cleanup, and build infrastructure will follow. NetBSD and OpenBSD have derivatives of this driver (with additional hardware support). We can look to changes in those drivers, and the Linux driver, to add support here. Reviewed by: adrian Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D53813 (cherry picked from commit 493d26c58e732dcfcdd87993ef71880adfe9d0cb) A sys/dev/aq/aq_common.h A sys/dev/aq/aq_dbg.c A sys/dev/aq/aq_dbg.h A sys/dev/aq/aq_device.h A sys/dev/aq/aq_fw.c A sys/dev/aq/aq_fw.h A sys/dev/aq/aq_fw1x.c A sys/dev/aq/aq_fw2x.c A sys/dev/aq/aq_hw.c A sys/dev/aq/aq_hw.h A sys/dev/aq/aq_hw_llh.c A sys/dev/aq/aq_hw_llh.h A sys/dev/aq/aq_hw_llh_internal.h A sys/dev/aq/aq_irq.c A sys/dev/aq/aq_main.c A sys/dev/aq/aq_media.c A sys/dev/aq/aq_ring.c A sys/dev/aq/aq_ring.h _____________________________________________________________________________________________________________ Commit: cff985d49b4bc3b9bb33653557ca5956fa070ce4 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=cff985d49b4bc3b9bb33653557ca5956fa070ce4 Author: Ed Maste (Fri 22 May 2026 19:08:58 BST) Committer: Ed Maste (Fri 24 Jul 2026 16:45:58 BST) vtfontcvt: Avoid dead store in add_char The fallback glyph is stored at index 0, and does not need to be inserted into a mapping. Previously there was a dead store of add_glyph's return value for the fallback case, which upset Clang's static analyzer. Now, cast the return value to (void) to make it clear this is intentional. Also change add_glyph's fallback parameter to a c99 bool to make its use more clear. Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57174 (cherry picked from commit b273481f2a840a05e4039655be99528e1fa9388c) M usr.bin/vtfontcvt/vtfontcvt.c _____________________________________________________________________________________________________________ Commit: 815c4396c74bb783fb0525908b2695e1b2dcc8bb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=815c4396c74bb783fb0525908b2695e1b2dcc8bb Author: Olivier Certner (Fri 24 Jul 2026 05:41:02 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:41:02 BST) .git-blame-ignore-revs: Fix hash for sys/kern/kern_cpu.c whitespace changes Really fill in the hash of the MFCed commit, removing the placeholder I forgot to update before commit. This is a direct commit to stable/15. Fixes: bd13516d400b (".git-blame-ignore-revs: sys/kern/kern_cpu.c whitespace changes") Sponsored by: The FreeBSD Foundation M .git-blame-ignore-revs _____________________________________________________________________________________________________________ Commit: f02f552ad788f6936e82e209f7c695655fea478b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f02f552ad788f6936e82e209f7c695655fea478b Author: Ryan Libby (Sun 19 Jul 2026 21:05:58 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:39 BST) i386: provide PCPU pc_small_core for amd64 compat Provide pc_small_core for i386 too to fix an i386 build break from x86 code referring to it. It won't be set. Reviewed by: aokblast, kib Fixes: 7b26353a59d6 ("hwpstate_intel: Disable package control on hybrid CPU") Differential Revision: https://reviews.freebsd.org/D58335 (cherry picked from commit 29d15d658d175139196d821b123c30a5b58e135e) M sys/i386/include/pcpu.h _____________________________________________________________________________________________________________ Commit: f594f06fa98351e115544546afb992af9140b014 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f594f06fa98351e115544546afb992af9140b014 Author: Olivier Certner (Tue 7 Jul 2026 14:34:21 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:39 BST) acpi_cpu(4): Call ACPI_GET_FEATURES() on a reset 'features' variable This is to prevent child drivers from using the features returned by previous drivers (in an arbitrary order). None of the existing ones do that, so this is purely defensive. MFC after: 2 weeks Sponsored by: The FreeBSD Foundation (cherry picked from commit 664ad9ac4c9047d29d5f37d43174e1b469e2ec80) M sys/dev/acpica/acpi_cpu.c _____________________________________________________________________________________________________________ Commit: 45254c2df093617dfd22336d177b4aece317699c URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=45254c2df093617dfd22336d177b4aece317699c Author: Olivier Certner (Thu 2 Jul 2026 15:26:21 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:39 BST) x86/local_apic.c: Fiddle with thermal LVT slot only if supported The thermal LVT slot does not necessarily exist. According to Intel's Software Developers Manual, for Intel processors supporting 64-bit operation (amd64), probably even the earliest ones should have a local APIC with such a slot (the slot was introduced with Pentium 4 and Xeon processors according to the manual, and the 64-bit implementation in some later versions of them). AMD's Architecture Programmer's Manual also seems to imply that all AMD processors supporting amd64 should have the slot too. So this change may not be needed when i386's code is dropped, but it does not hurt to have it, and it might ease possible MFCs. Change the signature of lapic_enable_thermal() so that it can report failure (if there is no local APIC or if there is no thermal LVT slot). Reviewed by: bnovkov, kib MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58086 (cherry picked from commit c18ec05395b36bdd12b0129533a553f27eb9b067) M sys/x86/include/apicvar.h M sys/x86/x86/local_apic.c _____________________________________________________________________________________________________________ Commit: 93dbde1542606eda4eb601caf715241869f47966 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=93dbde1542606eda4eb601caf715241869f47966 Author: Olivier Certner (Wed 8 Jul 2026 13:59:28 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:38 BST) x86/local_apic.c: Factor out version read and max LVT slot computation This makes the code slightly more compact and easier to read. No functional change intended. Reviewed by: bnovkov MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D58110 (cherry picked from commit 060ecf296664fd150328ac6dcdc24764a427bc3a) M sys/x86/x86/local_apic.c _____________________________________________________________________________________________________________ Commit: 49f19f3fab6ebd1a336cfa3aa05b0766f76a3094 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=49f19f3fab6ebd1a336cfa3aa05b0766f76a3094 Author: Ryan Libby (Sun 19 Jul 2026 04:19:52 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:38 BST) i386: supply thermal interrupt handler This fixes a build break for i386. Reviewed by: kib, olce, Koine Yuusuke Fixes: 87ba088fa310 ("x86/local_apic.c: Add support for installing a thermal interrupt handler") Differential Revision: https://reviews.freebsd.org/D58332 (cherry picked from commit cb325dcedfa291c9bfe350a513694df3776a17a4) M sys/i386/i386/apic_vector.S _____________________________________________________________________________________________________________ Commit: de695c62190f61f512a54a6140397a6bf1315e94 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=de695c62190f61f512a54a6140397a6bf1315e94 Author: Olivier Certner (Thu 2 Jul 2026 14:05:09 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:38 BST) x86/local_apic.c: Thermal interrupt support: Additional style fixes Rename handler function type 'lapic_thermal_handle_function' to the shorter 'lapic_thermal_handler_t'. Move it closer to the function declaration block where it is used. Make it a true function type (no pointer) and add explicit pointer marks on usage. Rename 'lapic_thermal_function_value' to the more immediately clear 'lapic_thermal_function_arg'. In lapic_thermal_enable(), use 'func_arg' as the argument name for the handler argument, which at least refers to function 'func', rather than the generic 'value'. Finally, rename the global handler variable from 'lapic_thermal_function_ptr' to the shorter 'lapic_thermal_function' (dynamic functions can be referenced only through a pointer). MFC with: 87ba088fa310 ("x86/local_apic.c: Add support for installing a thermal interrupt handler") Sponsored by: The FreeBSD Foundation (cherry picked from commit e1f4a8cb8656e64a1fe2b1ab519821b14c4985a0) M sys/x86/include/apicvar.h M sys/x86/x86/local_apic.c _____________________________________________________________________________________________________________ Commit: 272c6a3c0af4df9a9f7a94c7000bf7f2e6ce5e0e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=272c6a3c0af4df9a9f7a94c7000bf7f2e6ce5e0e Author: Koine Yuusuke (Wed 1 Jul 2026 16:28:21 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:37 BST) x86/local_apic.c: Add support for installing a thermal interrupt handler The thermal interrupt is initially masked. Thermal interrupt handling is enabled by calling lapic_enable_thermal(), which installs a (single) handler. [olce: Wrote the commit message.] Reviewed by: kib, olce MFC after: 2 weeks Differential Revision: https://reviews.freebsd.org/D44454 (cherry picked from commit 87ba088fa3108dd180008a04f25760ec71476c87) M sys/amd64/amd64/apic_vector.S M sys/x86/include/apicvar.h M sys/x86/x86/local_apic.c _____________________________________________________________________________________________________________ Commit: 952eb3db7f5c5662052c96658a71a412f12dacbd URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=952eb3db7f5c5662052c96658a71a412f12dacbd Author: Artem Bunichev (Sun 5 Jul 2026 20:01:36 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:37 BST) ps.1: Fix broken comment line While here, remove the long-unused dash in the first line. Reviewed by: ziaee, olce Fixes: ddf144a04b53 ("ps.1: Revamp: Explain general principles, update to match reality") MFC after: 1 day Differential Revision: https://reviews.freebsd.org/D58038 (cherry picked from commit 759ce9a2b38e1de70c14c81dee7e245bf0bc6b94) M bin/ps/ps.1 _____________________________________________________________________________________________________________ Commit: 387646c15b6fc359c0dba773a9676fef879c20ee URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=387646c15b6fc359c0dba773a9676fef879c20ee Author: Olivier Certner (Fri 26 Jun 2026 22:23:57 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:37 BST) files: riscv, arm64: Remove redundant 'ofw_cpu.c' Should have been removed when that line was moved from 'files.arm' to 'files'. Fixes: 14e1a2cd295d ("Move ofw_cpu file to the main files conf file.") MFC after: 2 weeks Event: Halifax Hackathon 202606 Location: Seat 36K in AC667, over Maine near Canadian border Sponsored by: The FreeBSD Foundation (cherry picked from commit 10213f01773f22ab948ec1e87c880b1d19a1fc45) M sys/conf/files.arm64 M sys/conf/files.riscv _____________________________________________________________________________________________________________ Commit: f58b90f17ecbe6babeafc07ec563bfd5a5f5057f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f58b90f17ecbe6babeafc07ec563bfd5a5f5057f Author: Olivier Certner (Fri 26 Jun 2026 16:21:41 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:36 BST) acpi_timer(4): Remove unused 'acpi_timer_disabled' boolean Same reason as for the previous commit to acpi_cpu(4). This boolean is not used anywhere. Disabling acpi_timer(4) can be done through the regular ACPI disable mechanism (using the 'debug.acpi.disabled' tunable, see acpi_disabled()). Reviewed by: emaste (implicit) Fixes: ac3ede5371af ("x86/xen: remove PVHv1 code") MFC after: 3 days Event: Halifax Hackathon 202606 Location: Dalhousie CS Faculty building Sponsored by: The FreeBSD Foundation (cherry picked from commit ad26a56cf2f55967cc73d04a6ea17c27892d3141) M sys/dev/acpica/acpi_timer.c M sys/x86/include/init.h _____________________________________________________________________________________________________________ Commit: f7b8a6f156c356704fb694ac57b58cb8126d85e6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f7b8a6f156c356704fb694ac57b58cb8126d85e6 Author: Olivier Certner (Fri 26 Jun 2026 16:12:58 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:36 BST) acpi_hpet(4): Remove unused 'acpi_hpet_disabled' boolean Same reason as for the previous commit to acpi_cpu(4). This boolean is not used anywhere. Disabling acpi_hpet(4) can be done through the regular ACPI disable mechanism (using the 'debug.acpi.disabled' tunable, see acpi_disabled()). Reviewed by: emaste (implicit) Fixes: ac3ede5371af ("x86/xen: remove PVHv1 code") MFC after: 3 days Event: Halifax Hackathon 202606 Location: Dalhousie CS Faculty building Sponsored by: The FreeBSD Foundation (cherry picked from commit 25df388574ac1d295f4014825de0df1d65cbdc53) M sys/dev/acpica/acpi_hpet.c M sys/x86/include/init.h _____________________________________________________________________________________________________________ Commit: ec59a50a60a3aade4921c80cfcd060a09596ec93 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ec59a50a60a3aade4921c80cfcd060a09596ec93 Author: Olivier Certner (Fri 26 Jun 2026 15:40:50 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:35 BST) acpi_cpu(4): Remove unused 'acpi_cpu_disabled' boolean It is not used anywhere. Disabling acpi_cpu(4) can be done through the regular ACPI disable mechanism (using the 'debug.acpi.disabled' tunable, see acpi_disabled()). Reviewed by: emaste, obiwac Fixes: ac3ede5371af ("x86/xen: remove PVHv1 code") MFC after: 3 days Event: Halifax Hackathon 202606 Location: Dalhousie CS Faculty building Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57888 (cherry picked from commit 98a77972381c6bb5ceda375fd1db7dccb3a1c89e) M sys/dev/acpica/acpi_cpu.c M sys/x86/include/init.h _____________________________________________________________________________________________________________ Commit: d0fc89b3ba933100dbf8e22b5e94363d6ec88847 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=d0fc89b3ba933100dbf8e22b5e94363d6ec88847 Author: Olivier Certner (Fri 19 Jun 2026 02:51:32 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:35 BST) sched_ule: Fix off by one in preempt_thresh definition Since 'preempt_thresh' is set to PRI_MIN_KERN by default, and comparison of the considered thread's priority with that threshold is done with '<=', PRI_MIN_KERN threads actually can preempt other threads, contrary to other non-interrupt kernel ones (between PRI_MIN_KERN + 1 and PRI_MAX_KERN). So, replace the comparison operator '<=' by '<'. The alternative would be to change the default value, but changing the comparison instead has the benefit to be consistent with the 0 setting (which forbids preemption entirely), since allowing only threads with priority 0 to preempt becomes possible. Consequently, we also change the default value for the FULL_PREEMPTION option by adding 1 to PRI_MAX_IDLE (in practice, that does not make any difference in the current setting, since no preemption will happen if the new priority value is not strictly lower than the current one, and PRI_MAX_IDLE is PRI_MAX, the highest possible priority). Reviewed by: markj Fixes: ae7a6b38d53f ("ULE 3.0: Fine grain scheduler locking and affinity improvements. (...)") MFC after: 2 weeks Event: Halifax Hackathon 202606 Location: jrm@'s dining room Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57828 (cherry picked from commit 961f4814286820f242d8d5407b9fd7238e896936) M sys/kern/sched_ule.c _____________________________________________________________________________________________________________ Commit: bd13516d400b97c4178d0c7b5b405444b32e63e3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=bd13516d400b97c4178d0c7b5b405444b32e63e3 Author: Olivier Certner (Thu 25 Jun 2026 02:25:31 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:35 BST) .git-blame-ignore-revs: sys/kern/kern_cpu.c whitespace changes Event: Halifax Hackathon 202606 Location: jrm@'s kitchen Sponsored by: The FreeBSD Foundation (cherry picked from commit 5f43a84d049ec3451c7c5fa5b4f00a299d5f4c34) M .git-blame-ignore-revs _____________________________________________________________________________________________________________ Commit: 22f80045a1869c3dd66aef0284fae32093ba5816 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=22f80045a1869c3dd66aef0284fae32093ba5816 Author: ShengYi Hung (Thu 25 Jun 2026 02:13:17 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:34 BST) cpufreq: Fix the incorrect format Event: Halifax Hackathon 202606 Location: jrm@'s dining room Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57275 (cherry picked from commit 35255280e51ca8f7a8f350b944aa6ffe42a7e5b5) M sys/kern/kern_cpu.c _____________________________________________________________________________________________________________ Commit: 87b46f92268b1944021b6d388c160ef0392a4c57 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=87b46f92268b1944021b6d388c160ef0392a4c57 Author: Olivier Certner (Tue 16 Jun 2026 17:11:58 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:34 BST) sched_ule: sched_clock(): Remove a superfluous space MFC after: 1 week Event: Halifax Hackathon 202606 Sponsored by: The FreeBSD Foundation (cherry picked from commit 5f376d52f2c86fd19e3f774a02c4b0debeb3f2cf) M sys/kern/sched_ule.c _____________________________________________________________________________________________________________ Commit: 0fc121a6c13e82ec6cbeaecf90fc49ca11691796 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=0fc121a6c13e82ec6cbeaecf90fc49ca11691796 Author: Olivier Certner (Mon 15 Jun 2026 22:07:00 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:34 BST) sched_ule: sched_priority(): More accurate __unused annotation Change a '__unused' to '__diagused', which is more precise for that use. No functional change. MFC after: 1 week Event: Halifax Hackathon 202606 Sponsored by: The FreeBSD Foundation (cherry picked from commit 83a6946595829407c80075f33e49329d1b621522) M sys/kern/sched_ule.c _____________________________________________________________________________________________________________ Commit: 13db1010fd22e6a444efe19852d56546a3379326 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=13db1010fd22e6a444efe19852d56546a3379326 Author: Olivier Certner (Thu 4 Jun 2026 08:10:29 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:33 BST) acpi: Suffix acpi_sleep_enable() with '_locked' For clarification. This function assumes that the acpi mutex is held, contrary to acpi_sleep_disable(). No functional change (intended). Reviewed by: obiwac Event: Halifax Hackathon 202606 Sponsored by: The FreeBSD Foundation Pull Request: https://github.com/OlCe2/freebsd-src/pull/8 (cherry picked from commit 3b3911aaf834824f2de0db9fc7d0b9e2b3c089b4) M sys/dev/acpica/acpi.c _____________________________________________________________________________________________________________ Commit: 490d561de6da6d7508d9ef0084e70e85019c0804 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=490d561de6da6d7508d9ef0084e70e85019c0804 Author: Olivier Certner (Wed 3 Jun 2026 21:30:22 BST) Committer: Olivier Certner (Fri 24 Jul 2026 05:33:26 BST) acpi: Constify thanks to AcpiGetHandle() taking a constant pathname Make the ACPI interface's functions evaluate_object() and get_property() take a constant pathname (by substituting ACPI_STRING with 'const char *'). This allows to remove some __DECONST(). No functional change (intended). Reviewed by: obiwac Event: Halifax Hackathon 202606 Sponsored by: The FreeBSD Foundation Pull Request: https://github.com/OlCe2/freebsd-src/pull/8 (cherry picked from commit a12d069ef37fd60538b6f46372b194e6cf117250) M sys/dev/acpica/acpi.c M sys/dev/acpica/acpi_if.m M sys/dev/acpica/acpivar.h _____________________________________________________________________________________________________________ Commit: c715fbb8b7e4926b93d7949b4d51ab07334d0b84 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c715fbb8b7e4926b93d7949b4d51ab07334d0b84 Author: Christos Margiolis (Sat 11 Jul 2026 13:57:35 BST) Committer: Christos Margiolis (Tue 21 Jul 2026 23:28:12 BST) snd_uaudio: Initialize mixer_lock with MTX_RECURSE Fixes: fc9dc8482396 ("snd_uaudio: Lock usbd_transfer_start() in uaudio_mixer_ctl_set()") PR: 296682 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296682 ) Sponsored by: The FreeBSD Foundation MFC after: 3 days (cherry picked from commit 954001a9dd363da9184706657eb34f9622bb220f) M sys/dev/sound/usb/uaudio.c _____________________________________________________________________________________________________________ Commit: ced89d9c04d450c1dad7fe5f21c1b2afca306046 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ced89d9c04d450c1dad7fe5f21c1b2afca306046 Author: Justin Hibbits (Wed 10 Jun 2026 14:50:14 BST) Committer: Justin Hibbits (Tue 21 Jul 2026 21:23:00 BST) watchdog: Fix a couple type issues * Force the type of the literal `1` passed to nstosbt() to ensure it's a 64-bit type (or larger). Otherwise it gets inconveniently typed to int, resulting in truncation. * Use `flsll()` when converting sbt to power-of-2-nanoseconds to fix 32-bit compatibility. PR: 292616 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=292616 ) Obtained from: Hewlett Packard Enterprise Fixes: 26d6617f3 ("watchdog: Convert to using sbintime_t format") (cherry picked from commit d08cb1dc17486920c1506f175d77259e0ac3f3a3) M sys/dev/watchdog/watchdog.c _____________________________________________________________________________________________________________ Commit: 520105c23a890140de6ad3e8f99c5e4b01d09891 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=520105c23a890140de6ad3e8f99c5e4b01d09891 Author: Dag-Erling Smørgrav (Mon 13 Jul 2026 07:43:56 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 18:03:38 BST) libfetch: Reduce copying Reduce the amount of copying we do when performing buffered reads. MFC after: 1 week Reviewed by: op Differential Revision: https://reviews.freebsd.org/D58113 (cherry picked from commit 60382b4a04fa39e9bf65b964b1b7b4bed6eaa56a) M lib/libfetch/common.c M lib/libfetch/common.h M lib/libfetch/ftp.c M lib/libfetch/http.c _____________________________________________________________________________________________________________ Commit: 07868145600dcb91dd0083fab36310fe5a5ef39d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=07868145600dcb91dd0083fab36310fe5a5ef39d Author: Dag-Erling Smørgrav (Mon 13 Jul 2026 07:43:51 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 18:03:38 BST) libfetch: Make fetch_ref an inline Make fetch_ref() an inline and provide a fetch_deref(). MFC after: 1 week Reviewed by: op Differential Revision: https://reviews.freebsd.org/D57944 (cherry picked from commit d4e0e1fbc237f0765b9f32b291c087348031c921) M lib/libfetch/common.c M lib/libfetch/common.h M lib/libfetch/ftp.c _____________________________________________________________________________________________________________ Commit: 98bfed530cbf860a5c729d97adf42628cefb55cb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=98bfed530cbf860a5c729d97adf42628cefb55cb Author: Dag-Erling Smørgrav (Mon 13 Jul 2026 07:43:46 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 18:03:38 BST) fetch: Stop setting an alarm Now that fetchTimeout works reliably, setting an alarm is not only no longer necessary but counterproductive, as it will trigger even if the connection is not actually stalled but merely slow. While here, improve the wording of the manual page's description of the various options for setting a timeout. MFC after: 1 week Reviewed by: op Differential Revision: https://reviews.freebsd.org/D57911 (cherry picked from commit 3dddfe29248c47d1a80dc96a76a308ae910b2a24) M usr.bin/fetch/fetch.1 M usr.bin/fetch/fetch.c _____________________________________________________________________________________________________________ Commit: a69d2866617293013234ab2fdeea68b4175cca88 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a69d2866617293013234ab2fdeea68b4175cca88 Author: Dag-Erling Smørgrav (Mon 13 Jul 2026 07:43:42 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 18:03:38 BST) libfetch: Document fetchTimeout Document the global fetchTimeout variable, now that it works reliably. MFC after: 1 week Reviewed by: op Differential Revision: https://reviews.freebsd.org/D57910 (cherry picked from commit 27b411734c75a7a5abe641d7fbb99dfc622e9aba) M lib/libfetch/fetch.3 _____________________________________________________________________________________________________________ Commit: ad7a1446c1e646eea86e36731b91e05e37026549 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ad7a1446c1e646eea86e36731b91e05e37026549 Author: Dag-Erling Smørgrav (Mon 13 Jul 2026 07:43:37 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 18:03:37 BST) libfetch: Apply timeout to connection attempts Mark the socket non-blocking before connecting and poll for completion, applying fetchTimeout if set. MFC after: 1 week Reviewed by: op Differential Revision: https://reviews.freebsd.org/D57909 (cherry picked from commit 848f360c8f9ae8d1d97c61f5d63fc624926d5dcd) M lib/libfetch/common.c _____________________________________________________________________________________________________________ Commit: fdef039f608b72acd67ad3e34fc2f0f3aba406c6 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fdef039f608b72acd67ad3e34fc2f0f3aba406c6 Author: Dag-Erling Smørgrav (Mon 13 Jul 2026 07:43:33 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 18:03:37 BST) libfetch: Add read buffering Previously, we would read FTP control connection messages and HTTP reponse headers one character at a time. Now, we read as much as will fit in our buffer and look for a newline. If there is data left over, it will be reused by the next fetch_getln() call. This also requires the addition of a fetch_bufread() which takes the buffer into account, otherwise the start of the HTTP response body will be stuck in the buffer after we read the last line of the header. This should noticeably improve HTTP performance, especially for small transfers. MFC after: 1 week Reviewed by: op Differential Revision: https://reviews.freebsd.org/D57907 (cherry picked from commit a1978277379cf65f1339ab062f335c6f1fa6239f) M lib/libfetch/common.c M lib/libfetch/common.h M lib/libfetch/ftp.c M lib/libfetch/http.c _____________________________________________________________________________________________________________ Commit: b56f3ea3b3f3a12d308b8ae22d4be1d9862929a7 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b56f3ea3b3f3a12d308b8ae22d4be1d9862929a7 Author: Dag-Erling Smørgrav (Mon 13 Jul 2026 07:43:28 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 18:03:37 BST) libfetch: Overhaul socket read / write * Make fetch_ssl_read() and fetch_ssl_write() behave more like read(2) and write(2), and drop fetch_socket_read() in favor of read(2). * Don't request POLLERR, it's implied. * Don't needlessly set errno, it's relatively costly. * Always check for EAGAIN from writev(2), otherwise we will abort on a short write instead of proceeding to poll(2). * Always check for EAGAIN from poll(2) even though it can't happen on FreeBSD; POSIX says it can, and it might in the future. * Rewrite fetch_read() and fetch_writev() to be more similar to each other. The main difference is that a partial read is treated as success while a partial write is treated as failure. PR: 296316 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296316 ) MFC after: 1 week Reviewed by: op Differential Revision: https://reviews.freebsd.org/D57906 (cherry picked from commit 32c341bd1c8b1154128f62fafa6988ed29db564a) M lib/libfetch/common.c M lib/libfetch/common.h _____________________________________________________________________________________________________________ Commit: a4f38a57e2e5739f3732218b461109f77deb71a3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=a4f38a57e2e5739f3732218b461109f77deb71a3 Author: Siva Mahadevan (Tue 23 Jun 2026 18:12:16 BST) Committer: Siva Mahadevan (Tue 21 Jul 2026 16:32:17 BST) awk/tests: xfail inf-nan-torture on riscv64 The fix for this is being tracked upstream here: https://github.com/onetrueawk/awk/issues/269 While here, just cd into $SRCDIR while executing tests, since the test engine isolates every testcase's working directory. This ensures that the xfail actually applies to the next command. Reviewed by: mhorne MFC after: 3 days Sponsored by: The FreeBSD Foundation (cherry picked from commit d0b1a389003b1e6ff5bcf35a7c04654ea7ff87bd) M usr.bin/awk/tests/bugs-fixed/bug_fix_test.sh _____________________________________________________________________________________________________________ Commit: 5aa70e0478a472b0da9290d73aedf00428bdbce2 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5aa70e0478a472b0da9290d73aedf00428bdbce2 Author: Siva Mahadevan (Thu 9 Jul 2026 16:26:32 BST) Committer: Siva Mahadevan (Tue 21 Jul 2026 16:32:17 BST) bsdinstall/netconfig: use a better heuristic for wlan dev desc For devices like the rtw88, they will show up in `ifconfig -l` as rtw880, rtw881, etc. We want to query the rtw88.0 and rtw88.1 sysctl respectively, not rtw.880. Chances are that there aren't more than 9 wlan devices using the same driver. Use a better heuristic to get the device description. Reviewed by: bz MFC after: 3 days Sponsored by: The FreeBSD Foundation (cherry picked from commit c4b0b13cadac46b7c2cdfeeedeffa596c62568fa) M usr.sbin/bsdinstall/scripts/netconfig _____________________________________________________________________________________________________________ Commit: f4b82c7f40bc7ecadc759f76f6b66921010603ab URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f4b82c7f40bc7ecadc759f76f6b66921010603ab Author: Dag-Erling Smørgrav (Mon 6 Jul 2026 13:23:55 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 09:54:42 BST) libc/resolv: Dead code and style cleanup Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D57928 (cherry picked from commit 4805b88edb009e53c4fee159138d2cbe0c848da7) M lib/libc/resolv/res_init.c _____________________________________________________________________________________________________________ Commit: 22ee851d26025004f1a73b51a6838fbebfd5aeb0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=22ee851d26025004f1a73b51a6838fbebfd5aeb0 Author: Dag-Erling Smørgrav (Mon 6 Jul 2026 13:23:50 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 09:54:41 BST) resolv.h: Remove unused parts Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D57927 (cherry picked from commit 3f15998d25da08677d2c40bc2240de293aec4205) M include/resolv.h _____________________________________________________________________________________________________________ Commit: 506c2dee1777030b1ba5cf63e01d3108bde59c9b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=506c2dee1777030b1ba5cf63e01d3108bde59c9b Author: Dag-Erling Smørgrav (Mon 6 Jul 2026 13:23:43 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 09:54:41 BST) libc/resolv: Add no-debug and no-rotate options These are simply the reverse of the debug and rotate options. Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D57926 (cherry picked from commit 60827d7885016861dc02caa45f3ce873ad2a020e) M lib/libc/resolv/res_init.c M share/man/man5/resolver.5 _____________________________________________________________________________________________________________ Commit: 55f219b3f7667b2a7d4f69753d64e331590458b3 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=55f219b3f7667b2a7d4f69753d64e331590458b3 Author: Dag-Erling Smørgrav (Mon 6 Jul 2026 13:23:37 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 09:54:41 BST) libc/resolv: Reimplement the sortlist parser When we switched from the BIND4 resolver to the BIND9 resolver, the sortlist parser was inadvertently disabled due to a missing #define, and nobody seemed to notice. The sorting code remained enabled in the resolver, but there was no way to set a sort order. Reimplement the sortlist parser, but correctly, and update the manual accordingly. The new parser accepts IPv4 and IPv6 addresses with or without a mask or prefix length, just like the old one, except IPv6 support was a bit wonky in the original code. Fixes: 5342d17f09a8 ("Update the resolver in libc to BIND9's one.") Relnotes: yes Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D57925 (cherry picked from commit fbe0257b5613f457af42f82efb2e3bc9395d0557) M lib/libc/resolv/Makefile.inc M lib/libc/resolv/res_init.c M share/man/man5/resolver.5 _____________________________________________________________________________________________________________ Commit: 3e448886f5637eb108528d2c48d39ce638b76741 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=3e448886f5637eb108528d2c48d39ce638b76741 Author: Dag-Erling Smørgrav (Mon 6 Jul 2026 13:23:33 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 09:54:41 BST) libc/resolv: Refactor the configuration parser This was previously all a single loop in res_init(), apart from option parsing which we cleaned up in a previous commit. Break it out into separate functions for reading the configuration line by line, setting the default domain, setting the search list, and adding a nameserver to the nameserver list. Sprinkle bounds checks and code comments all around. The sortlist code, which has been disabled for the past 20 years, will be dealt with in a separate commit. MFC after: 1 week Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D57924 (cherry picked from commit ffeb56905ed6a7ac759367096d6dc0596e82e03f) M lib/libc/resolv/res_init.c _____________________________________________________________________________________________________________ Commit: 491337c8a21abf120661db6bc5727474c247e184 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=491337c8a21abf120661db6bc5727474c247e184 Author: Dag-Erling Smørgrav (Mon 6 Jul 2026 13:23:29 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 09:54:41 BST) libc/resolv: Refactor the option parser Start the loop by finding the end of the option name, the name-value separator (if any), and the end of the option. Use those pointers to simplify matching the option name and parsing the option value, and validate option names and values more strictly. This means that: * We no longer accept trailing garbage in an option name or value. For instance, we would previously interpret “edns0123” as “edns0” and “timeout:3xyz” as “timeout:3”. This was actually quite lucky because we also failed to recognize the newline at the end of the option line as a whitespace character. * For options that take a numerical argument, we would previously accept negative values and treat non-numerical arguments as 0, while large numerical arguments would be capped to the option's maximum permitted value. Now, any failure to parse the argument, including overflow, results in the option being left unchanged. MFC after: 1 week Relnotes: yes Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D57923 (cherry picked from commit 9bfdfecd27359130aa4ef63fc0aa32f98f9e7b50) M lib/libc/resolv/res_init.c _____________________________________________________________________________________________________________ Commit: 6d734869e83d32792b37a3b947490202fa838e82 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=6d734869e83d32792b37a3b947490202fa838e82 Author: Dag-Erling Smørgrav (Mon 6 Jul 2026 13:23:24 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 09:54:40 BST) libc/resolv: Drop Solaris 2 compatibility MFC after: 1 week Reviewed by: kevans, markj Differential Revision: https://reviews.freebsd.org/D57922 (cherry picked from commit aba9fffebf97d631f85e904813ff35ed031a3bac) M lib/libc/nameser/ns_parse.c M lib/libc/resolv/res_comp.c M lib/libc/resolv/res_init.c _____________________________________________________________________________________________________________ Commit: 5bdba2e06a43b8239317cd747931577f9d182a1d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5bdba2e06a43b8239317cd747931577f9d182a1d Author: Dag-Erling Smørgrav (Mon 6 Jul 2026 13:23:20 BST) Committer: Dag-Erling Smørgrav (Tue 21 Jul 2026 09:54:40 BST) resolver(5): Overhaul * Modernize the markup * Describe the comment syntax * Drop obsolete advice * Capitalize sentences * Improve the language * Replace no_tld_query with no-tld-query; both are supported, but all the other multi-word options use hyphens rather than underscores. * Add missing ENVIRONMENT section * Redo the example MFC after: 1 week Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D57921 (cherry picked from commit 4319e4bf42f2f5a71ac32cb18cef8f7677fdf7f7) M share/man/man5/resolver.5 _____________________________________________________________________________________________________________ Commit: acee62f17750557525a27c18d2de9330a0264bae URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=acee62f17750557525a27c18d2de9330a0264bae Author: Colin Percival (Sun 28 Jun 2026 00:33:46 BST) Committer: Colin Percival (Tue 21 Jul 2026 04:16:41 BST) ena: Put taskqueues into correct domain if !RSS When compiled without 'options RSS', the ena driver created taskqueues using taskqueue_start_threads_cpuset passing a mask value of NULL, both in the ena_setup_tx_resources path (for enqueues) and in the ena_create_io_queues path (for the completion-processing). In the default configuration, on most EC2 instances, this results in taskqueues running in the right NUMA domain, but only by accident; in non-default configurations (e.g. with with multiple EBS volumes attached and associated NVMe taskqueues) the taskqueues may land in the wrong NUMA domain even on instance types where the one-EBS-one-ENA case produces the desired results. Set (struct ena_que)->domain and use that to inform the choice of CPU sets. On a c8gn.48xlarge EC2 instance this doubles throughput on a 32-TCP-stream benchmark. Reviewed by: akiyano MFC after: 7 days Sponsored by: Amazon Differential Revision: https://reviews.freebsd.org/D57918 (cherry picked from commit 2e21f7e8140447c2dcbc964ff3482f12f9bd6683) M sys/dev/ena/ena.c _____________________________________________________________________________________________________________ Commit: 94b21dade6773c0b73261e2ffc69be3d3a13a9cb URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=94b21dade6773c0b73261e2ffc69be3d3a13a9cb Author: Rick Macklem (Tue 7 Jul 2026 01:10:11 BST) Committer: Rick Macklem (Tue 21 Jul 2026 02:26:39 BST) nfsd: Optionally enable use of M_EXTPG mbufs for read replies A test site determined that, for a Mellanox NIC which can handle M_EXTPG mbufs, an improvement of 5-15% for read rate could be achieved if the read reply was in M_EXTPG mbufs. A patch that tried to determine if the outbound NIC supported M_EXTPG mbufs (IFCAP_MEXTPG) did not pass review. However, it does appear that this can be useful for NFS-over-RDMA. (Which just happen to use NICs that do support M_EXTPG mbufs.) As such, this patch enables them is xp_extpg is set to true, which is never for now, but might be set true for RDMA or when vfs.nfsd.enable_mextpg is set non-zero. (It is 0 by default, so this is never enabled by default at this time.) (cherry picked from commit d516e52373e1768ea84bf1ca220671a44f413abe) M sys/fs/nfs/nfs.h M sys/fs/nfsserver/nfs_nfsdkrpc.c M sys/fs/nfsserver/nfs_nfsdport.c M sys/fs/nfsserver/nfs_nfsdserv.c M sys/rpc/svc.h _____________________________________________________________________________________________________________ Commit: 14d1ad2a37afac412338eefa8b07722d3415c369 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=14d1ad2a37afac412338eefa8b07722d3415c369 Author: Sourojeet A (Wed 8 Jul 2026 13:57:34 BST) Committer: Ed Maste (Mon 20 Jul 2026 21:57:42 BST) linuxkpi: Add pm_runtime_resume_and_get pm_runtime_resume_and_get is used by new versions of amdgpu, and began use between Linux kernel version 6.12, and 6.14. Reviewed by: dumbbell Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D57463 (cherry picked from commit 7e1245aafeece1a56af292c2652c6b835ccb6f10) M sys/compat/linuxkpi/common/include/linux/pm_runtime.h _____________________________________________________________________________________________________________ Commit: 009e83b5ebf3024df7378ec2645c49281a910d31 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=009e83b5ebf3024df7378ec2645c49281a910d31 Author: Ariel Ehrenberg (Mon 15 Jun 2026 09:27:56 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:10 BST) mlx5ib: use the eventfd_ctx API for DEVX event subscriptions (cherry picked from commit 40cc9de950f7e6ba2049467fa05c46b9161f49a5) M sys/dev/mlx5/mlx5_ib/mlx5_ib_devx.c _____________________________________________________________________________________________________________ Commit: fab43c031ccd4a630a38ef558ac77d40e4bc142d URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fab43c031ccd4a630a38ef558ac77d40e4bc142d Author: Ariel Ehrenberg (Mon 15 Jun 2026 09:16:30 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:10 BST) mlx5ib: initialize DEVX subscription state before the eventfd fdget() (cherry picked from commit 9c7629d69cebafba3eea6787d3bfc100d60c3b19) M sys/dev/mlx5/mlx5_ib/mlx5_ib_devx.c _____________________________________________________________________________________________________________ Commit: 86cdda181e4e98ec7b9b96d2d03f4eb92df4c14e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=86cdda181e4e98ec7b9b96d2d03f4eb92df4c14e Author: Ariel Ehrenberg (Mon 15 Jun 2026 20:00:47 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:09 BST) mlx5: propagate the DEVX uid through SRQ create and destroy (cherry picked from commit 07f780cb7f8eab1aa6e84d3ed6785144d0d3cc47) M sys/dev/mlx5/driver.h M sys/dev/mlx5/mlx5_core/mlx5_srq.c M sys/dev/mlx5/mlx5_ifc.h _____________________________________________________________________________________________________________ Commit: 012c852efd27a55dd1cd479b06efd7fb65945c56 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=012c852efd27a55dd1cd479b06efd7fb65945c56 Author: Ariel Ehrenberg (Mon 15 Jun 2026 09:16:17 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:09 BST) mlx5: guard against a NULL CQ event handler in mlx5_cq_event() (cherry picked from commit 284e06dec78ffbbf8919dc0aa11073ecabba7176) M sys/dev/mlx5/mlx5_core/mlx5_cq.c _____________________________________________________________________________________________________________ Commit: 7b0e4a73ebb6c475be2933a40485dea97c8df2af URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=7b0e4a73ebb6c475be2933a40485dea97c8df2af Author: Ariel Ehrenberg (Mon 15 Jun 2026 09:15:54 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:09 BST) mlx5: pass the full EQE to the DEVX event notifier (cherry picked from commit 0e9bbbdcbea8edc6ad259a9428234b494014bc4e) M sys/dev/mlx5/mlx5_core/mlx5_eq.c _____________________________________________________________________________________________________________ Commit: e611f58ae3618d1aa8b1e2738a11e2334faa432f URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e611f58ae3618d1aa8b1e2738a11e2334faa432f Author: Ariel Ehrenberg (Mon 8 Jun 2026 11:56:16 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:08 BST) ofed/ib_uverbs: release rdma_user_mmap entry ref in rdma_umap_close() (cherry picked from commit a7298669cd53a9fc8446c53db6872bc2f64c508d) M sys/ofed/drivers/infiniband/core/ib_uverbs_main.c _____________________________________________________________________________________________________________ Commit: 2c713c35b4304eca5e940db6eed2519071e3a87e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=2c713c35b4304eca5e940db6eed2519071e3a87e Author: Ariel Ehrenberg (Mon 8 Jun 2026 11:56:04 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:08 BST) mlx5ib: advertise write-combining support for dynamic BlueFlame UARs (cherry picked from commit 80902b8b7cd409ade11048dc78212e7d43475c65) M sys/dev/mlx5/mlx5_ib/mlx5_ib_main.c _____________________________________________________________________________________________________________ Commit: c15fa820881d31dfe64d9c06922dca466ae147df URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c15fa820881d31dfe64d9c06922dca466ae147df Author: Ariel Ehrenberg (Mon 8 Jun 2026 11:55:47 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:07 BST) mlx5ib: encode dynamic UAR mmap offsets in the reserved command range (cherry picked from commit 631e57d54c137e9393c47075db09a6c7fb84c6ed) M sys/dev/mlx5/mlx5_ib/mlx5_ib.h M sys/dev/mlx5/mlx5_ib/mlx5_ib_main.c _____________________________________________________________________________________________________________ Commit: c122d64b5ab2ff77ab4fc3478885bdb316cdfc54 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c122d64b5ab2ff77ab4fc3478885bdb316cdfc54 Author: Ariel Ehrenberg (Thu 4 Jun 2026 16:46:28 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:07 BST) mlx5ib: allocate IB queue counters as a shared resource (cherry picked from commit 412aa220aeb920dcbc0f2b3effbbb51ad41c7fc3) M sys/dev/mlx5/mlx5_ib/mlx5_ib_main.c _____________________________________________________________________________________________________________ Commit: e3f260ad661476798e19d126875836075b893345 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e3f260ad661476798e19d126875836075b893345 Author: Ariel Ehrenberg (Thu 4 Jun 2026 16:46:17 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:06 BST) mlx5: mark completion EQs as a shared resource for DEVX uids (cherry picked from commit bfe14bfeb8dcefc606bdf76c40987467bbd36d92) M sys/dev/mlx5/mlx5_core/mlx5_eq.c M sys/dev/mlx5/mlx5_ifc.h _____________________________________________________________________________________________________________ Commit: 8d198bba057c3a2c5822b390ad91bc79e264d839 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8d198bba057c3a2c5822b390ad91bc79e264d839 Author: Ariel Ehrenberg (Thu 4 Jun 2026 16:07:52 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:06 BST) mlx5ib: implement the MLX5_IB_OBJECT_UAR ioctl object (cherry picked from commit b7ca46b161d869c839b1d4a544f64d5661a9082f) M sys/dev/mlx5/mlx5_ib/mlx5_ib_main.c M sys/dev/mlx5/mlx5_ifc.h _____________________________________________________________________________________________________________ Commit: f7280623cdfe24bf7cc28fe7d5c5f03fa10f9650 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=f7280623cdfe24bf7cc28fe7d5c5f03fa10f9650 Author: Ariel Ehrenberg (Tue 9 Jun 2026 12:20:23 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:05 BST) mlx5_ib: register DEVX objects in the uverbs ioctl parse tree (cherry picked from commit 705d6cf4bf25f7b87f017322e04c6a1a37f1fac0) M sys/dev/mlx5/mlx5_ib/mlx5_ib.h M sys/dev/mlx5/mlx5_ib/mlx5_ib_main.c _____________________________________________________________________________________________________________ Commit: 8d518f4b482f64449b2bbb36a7c4627e80a3a93a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=8d518f4b482f64449b2bbb36a7c4627e80a3a93a Author: Ariel Ehrenberg (Tue 9 Jun 2026 12:20:08 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:05 BST) mlx5_ib: do not consume CMD/PAGE_REQUEST events in the DEVX notifier (cherry picked from commit 2e3b3ce881490adcef17905450d0402030975051) M sys/dev/mlx5/mlx5_core/mlx5_eq.c M sys/dev/mlx5/mlx5_ib/mlx5_ib_devx.c _____________________________________________________________________________________________________________ Commit: ea6c3833438a23cda53d79e08cd693d49cdcb549 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=ea6c3833438a23cda53d79e08cd693d49cdcb549 Author: Konstantin Belousov (Tue 2 Jun 2026 22:59:16 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:05 BST) mlx5: extend mlx5_ib_create_cq struct with fields from the current Linux ABI (cherry picked from commit 716bb8d3d40250b0b2b40480dc062abfab5665ed) M sys/ofed/include/uapi/rdma/mlx5-abi.h _____________________________________________________________________________________________________________ Commit: fcee136ce0569314a07835171afb115081e1f0fa URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=fcee136ce0569314a07835171afb115081e1f0fa Author: Konstantin Belousov (Wed 8 Jul 2026 20:21:00 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:04 BST) kern_writefile(): fix several regressions (cherry picked from commit 1364d8fd9b25d6d3e9618e7be073a1a1b41aa19c) M sys/kern/kern_sendfile.c M sys/kern/sys_generic.c M sys/sys/syscallsubr.h _____________________________________________________________________________________________________________ Commit: 1712dc691e0a24b578aa263edec9b2c99e26c9dc URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=1712dc691e0a24b578aa263edec9b2c99e26c9dc Author: Konstantin Belousov (Wed 8 Jul 2026 15:54:25 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:03 BST) kern_filewrite(): unconditionally calculate cnt, it is used by callers (cherry picked from commit b72397da275b098365532133688d555b842bad4f) M sys/kern/sys_generic.c _____________________________________________________________________________________________________________ Commit: e19778bd3e98e46021271f7a95c9647b0ec6e95e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=e19778bd3e98e46021271f7a95c9647b0ec6e95e Author: Konstantin Belousov (Sat 4 Jul 2026 03:29:56 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:26:03 BST) sendfile: stop abusing kern_writev() (cherry picked from commit dfad790c8ccad05ff603ceaa5b2efe4205b38e1c) M sys/kern/kern_sendfile.c M sys/kern/sys_generic.c M sys/sys/syscallsubr.h _____________________________________________________________________________________________________________ Commit: 842e271b7b8bf8a3bb039db57dce2107600ab883 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=842e271b7b8bf8a3bb039db57dce2107600ab883 Author: Konstantin Belousov (Thu 16 Jul 2026 07:49:21 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:24:27 BST) amd64 efirt: register all runtime regions as fictitious PR: 296348 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296348 ) (cherry picked from commit a2f50c4b32d1c126cf2309dab61d27d6329908f8) M sys/amd64/amd64/efirt_machdep.c _____________________________________________________________________________________________________________ Commit: c7663578a278fa7ef76e035f197bc0cb462af198 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=c7663578a278fa7ef76e035f197bc0cb462af198 Author: Konstantin Belousov (Fri 10 Jul 2026 20:02:54 BST) Committer: Konstantin Belousov (Mon 20 Jul 2026 21:24:26 BST) init(8): extract reroot transient code into reroot_seed (cherry picked from commit 4c9f648852629d757165796bb3cd97bb84a0e483) M sbin/Makefile M sbin/init/Makefile M sbin/init/init.c A sbin/init/reroot_seed.embed.s A sbin/reroot_seed/Makefile A sbin/reroot_seed/reroot_seed.c _____________________________________________________________________________________________________________ Commit: 047effac79ef4cafda6a920e9ec352cf9a152bba URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=047effac79ef4cafda6a920e9ec352cf9a152bba Author: Yusuke Ichiki (Fri 17 Jul 2026 15:58:42 BST) Committer: Cy Schubert (Mon 20 Jul 2026 17:29:35 BST) man: Fix RFC 1918 network prefix lengths According to RFC 1918, the following IP prefixes are reserved for private internets: 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 This PR fixes the prefix lengths in references to private networks ("RFC 1918 networks", "the standard private IP address ranges"). The changes are limited to man pages. Signed-off-by: Yusuke Ichiki Pull Request: https://github.com/freebsd/freebsd-src/pull/2328 (cherry picked from commit 1403ca10189c47ad1de3915eeb030deddc114685) M sbin/ipf/ippool/ippool.5 M sys/netinet/libalias/libalias.3 _____________________________________________________________________________________________________________ Commit: b4711ce4184cab06ed9f5ea6ad4d1153ff84ae5b URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=b4711ce4184cab06ed9f5ea6ad4d1153ff84ae5b Author: Ka Ho Ng (Mon 13 Jul 2026 01:21:01 BST) Committer: Ka Ho Ng (Mon 20 Jul 2026 04:47:43 BST) Add sbintime.9 manual page sbintime.9 is a manual page that documents the usage of sbintime_t and its helper functions. MFC after: 1 week Reviewed by: ziaee, markj Differential Revision: https://reviews.freebsd.org/D57931 (cherry picked from commit c3f6c655dd155f4c84ce743c86e07d9f0b6b348a) M share/man/man9/Makefile M share/man/man9/callout.9 M share/man/man9/microtime.9 A share/man/man9/sbintime.9 _____________________________________________________________________________________________________________ Commit: 55b9f788d348d0e31478fe86c12ee8ca3f21469e URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=55b9f788d348d0e31478fe86c12ee8ca3f21469e Author: Peter Eriksson (Mon 6 Jul 2026 20:33:22 BST) Committer: Rick Macklem (Mon 20 Jul 2026 02:45:54 BST) acl_from_text.c: Allow negative uid/gid numbers to be handled getfacl / acl_to_text() incorrectly prints uid/gid numbers as signed integers. This causes uid / gid numbers larger than 2G (2147483648) to print as negative numbers. The libc acl_from_text() function does not handle negative numbers. This diff adds a backwards compatiblity fix to allow negative numbers... (cherry picked from commit d7d71341ae7d79886143a9ce427dca0e858eda97) M lib/libc/posix1e/acl_from_text.c _____________________________________________________________________________________________________________ Commit: 299bbb762db7c6971ad68de412830dee8c0bae0a URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=299bbb762db7c6971ad68de412830dee8c0bae0a Author: Rick Macklem (Sat 4 Jul 2026 23:00:02 BST) Committer: Rick Macklem (Sat 18 Jul 2026 02:15:17 BST) nfs_clstate.c: Fix handling of delegation upgrades Commit 016570c4463d modified the client to handle the upgrade of a read delegation to a write delegation, where the server provides the same delegation stateid to the client. However, it failed to check if the delegation structure was currently in use. Without this patch, if the structure was in use, a use after free could occur. This patch handles the "in use" case by copying the necessary fields into the current/old structure and free's the new one instead of the old one that is "in use". PR: 296224 ( https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296224 ) (cherry picked from commit fe6677e7f440d1aa52de036639efc55047ab9a2b) M sys/fs/nfs/nfsclstate.h M sys/fs/nfsclient/nfs_clstate.c _____________________________________________________________________________________________________________ Commit: 672345cd24e131f171df469d902165963dab4557 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=672345cd24e131f171df469d902165963dab4557 Author: Konstantin Belousov (Thu 18 Jun 2026 19:40:40 BST) Committer: Konstantin Belousov (Sat 18 Jul 2026 01:27:25 BST) tmpfs: implement AT_RENAME_EXCHANGE (cherry picked from commit 7e06c33151e7664f6d664ee282d8da1985ce94aa) M sys/fs/tmpfs/tmpfs_vnops.c _____________________________________________________________________________________________________________ Commit: feb4c9d089bf6505408997ad132d816865262de0 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=feb4c9d089bf6505408997ad132d816865262de0 Author: Konstantin Belousov (Thu 18 Jun 2026 21:01:35 BST) Committer: Konstantin Belousov (Sat 18 Jul 2026 01:27:24 BST) tmpfs: extract tmpfs_rename_check/set_parent() from tmpfs_rename() (cherry picked from commit 5e0b96e728af9916ac59d65e37155a95e06c3b5e) M sys/fs/tmpfs/tmpfs_vnops.c _____________________________________________________________________________________________________________ Commit: 5dc55cc4591ef9d7aecc934a69351259cba99a10 URL: https://git.freebsd.catflap.wales/src/stable-15/commit/?id=5dc55cc4591ef9d7aecc934a69351259cba99a10 Author: Konstantin Belousov (Fri 19 Jun 2026 09:11:18 BST) Committer: Konstantin Belousov (Sat 18 Jul 2026 01:27:24 BST) tmpfs_rename(): style (cherry picked from commit 631b8ff9318a83b985d3a8a790dd0fc1bab9d5cd) M sys/fs/tmpfs/tmpfs_vnops.c ____________________________________________________________________________________________________________