CVSROOT: /cvs Module name: ports Changes by: namn@cvs.openbsd.org 2026/09/30 14:22:30 Modified files: net/rtorrent : Makefile distinfo net/rtorrent/patches: patch-test_Makefile_in Log message: update net/rtorrent 0.16.24 - various security fixes (e.g., overflow, heap overflow and use-after-free) - regen test/Makefile.in patch to remove a new, third instance of -ldl approved by sthen@ and tested by and OK tj@ CVSROOT: /cvs Module name: ports Changes by: namn@cvs.openbsd.org 2026/09/30 14:27:21 Modified files: net/libtorrent : Makefile distinfo Added files: net/libtorrent/patches: patch-test_Makefile_in Log message: update net/libtorrent 0.16.24 - major bump due to removed symbols - unbreaks tests by linking using static archive (from tj@) approved by sthen@ and tested by and OK tj@ CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/09/30 14:44:06 Modified files: sys/conf : newvers.sh Log message: 8.0 -current development CVSROOT: /cvs Module name: www Changes by: sthen@cvs.openbsd.org 2026/09/30 14:47:47 Modified files: faq : current.html Log message: mention geolite->dbip change in ports CVSROOT: /cvs Module name: src Changes by: rcovelli@cvs.openbsd.org 2026/09/30 14:48:11 Modified files: usr.sbin/rpki-client: main.c Log message: Now that we open early we can remove unix pledge OK deraadt@ CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/09/30 20:01:51 Modified files: usr.bin/ssh : auth2-pubkey.c Log message: handle max-pk-ok path identically when the incoming user is invalid; avoids max-pk-ok feature presenting a username validity oracle analysis and patch from Chris Rohlf in collaboration with Claude and Anthropic Research CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/09/30 20:18:26 Modified files: . : 80.html Log message: spelling CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/09/30 20:47:41 Modified files: . : 80.html Log message: update base and xenocara component versions CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/09/30 21:11:49 Modified files: usr.bin/ssh : sftp-client.c sftp.c Log message: sftp: be stricter in accepting paths returned by the server for SSH_FXP_REALPATH or SSH2_FXP_READDIR replies, as these can be used in some situations to decide the destination path for recursive transfers. Report and patch from Junghoon Cho CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/09/30 21:40:35 Modified files: . : 80.html Log message: update ports versions CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/09/30 21:54:19 Modified files: . : 80.html Log message: no loongson for 8.0 CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/09/30 22:17:39 Modified files: usr.bin/ssh : ssh-mldsa-eddsa.c Log message: fix the bit length of ML-DSA 44/Ed25519 keys that was being incorrectly reported as 256. The private key length for these composite keys is 512 bits. This value is only used for display. Spotted by Yiyue Wang CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/09/30 23:53:25 Modified files: lang/python/3 : Makefile Added files: lang/python/3/patches: patch-Modules__ssl_c Log message: cherrypick fix for CPython CVE-2026-19445: Use-after-free of a server-side SSLContext when sni_callback switches contexts. ok tb kmos A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open. CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/09/30 23:54:02 Modified files: lang/python/3 : Tag: OPENBSD_7_9 Makefile Added files: lang/python/3/patches: Tag: OPENBSD_7_9 patch-Modules__ssl_c Log message: cherrypick fix for CPython CVE-2026-19445: Use-after-free of a server-side SSLContext when sni_callback switches contexts. ok tb kmos CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/01 00:30:05 Modified files: . : 80.html Log message: Thunderbird 153.4.0 CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/01 01:07:49 Modified files: usr.bin/ssh : sshkey.c Log message: Implement a maximum number of KDF rounds that will be accepted when writing an OpenSSH-format private key or when loading one. This limit is set pretty high (1<<20), but ensures that a service that is passed a bad key with an ridiculously high number of rounds will _eventually_ complete parsing it. Also bump the default number of KDF rounds from 24 to 32 (this is a linear increase, not like bcrypt(3) which is exponential). Pointed out by Aris Adamantiadis CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/01 01:08:05 Modified files: usr.bin/ssh : ssh-keygen.1 Log message: mention default KDF rounds is now 32 CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/01 01:10:56 Modified files: usr.bin/ssh : scp.c Log message: start process of deprecating the -R flag. This was the old way of performing a remote-to-remote copy that was basically executed scp on the remote host. It barely worked (needing agent forwarding enabled or usable credentials on the remote host) and has largely been replaced by a better SFTP-protocol remote-to-remote copy that runs through the host performing the copy. We'll disable this option in a release or two; ok dtucker@ CVSROOT: /cvs Module name: src Changes by: otto@cvs.openbsd.org 2026/10/01 01:16:45 Modified files: lib/libc/sys : send.2 Log message: Describe what sendmmsg(2) actually does and fix prototype. ok deraadt@ CVSROOT: /cvs Module name: www Changes by: claudio@cvs.openbsd.org 2026/10/01 03:13:56 Modified files: . : mail.html openbgpd : index.html mail.html build/mirrors : openbgpd-ftp.html.head Log message: The openbgpd github organization was moved from "openbgpd-portable" to "openbgpd". Adjust various links. Diff provided by Clara Engler (cve (at) cve cx) CVSROOT: /cvs Module name: www Changes by: claudio@cvs.openbsd.org 2026/10/01 03:15:05 Modified files: openbgpd : ftp.html Log message: Regen after github url change CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:11:41 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: report hardware RX aggregation Based on sys/dev/ic/qwx.c,v 1.85 and sys/dev/ic/qwx.c,v 1.90 Report hardware deaggregation and reordering after successful RX reconstruction; allow repaeted sequence numbers for later A-MSDU subframes and clear the AMSDU QoS bit. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:13:03 Modified files: sys/dev/ic : qwz.c qwzreg.h qwzvar.h Log message: sys/qwz: handle WBM RX errors Based on sys/dev/ic/qwx.c,v 1.35 and sys/dev/ic/qwxvar.h,v 1.18 , sys/dev/ic/qwx.c,v 1.89 , sys/dev/ic/qwx.c,v 1.121 and sys/dev/ic/qwxvar.h,v 1.36 Process WBM RX releases using WCN7850 descriptor and cookie formats. Deliver valid null queue frames through existing RX processing, clear mbuf pointers after delivery, and then replenish descriptors OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:13:53 Modified files: sys/dev/ic : qwz.c qwzvar.h Log message: sys/qwz: read RX metadata from MPDU TLVs Read sequence numbers and TIDs from WCN7850 MPDU descriptors. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:14:55 Modified files: sys/dev/ic : qwz.c qwzreg.h Log message: sys/qwz: drain REO RX exceptions Based on sys/dev/ic/qwx.c,v 1.33 Drain REO RX exceptions using descriptor layouts and qwz cookie. Reclaim packet buffers, return link descriptors and replenish RX, checking bank bounds and release ring space. OK: stsp@ CVSROOT: /cvs Module name: ports Changes by: robert@cvs.openbsd.org 2026/10/01 04:15:01 Modified files: www/chromium : Makefile distinfo www/chromium/patches: patch-chrome_browser_picture_in_picture_picture_in_picture_window_manager_cc patch-content_browser_web_contents_web_contents_impl_cc patch-gpu_command_buffer_service_gles2_cmd_decoder_cc patch-gpu_command_buffer_service_shared_image_external_vk_image_backing_factory_cc patch-third_party_fontconfig_include_meson-config_h patch-third_party_test_fonts_fontconfig_BUILD_gn Removed files: www/chromium/patches: patch-third_party_test_fonts_fontconfig_generate_fontconfig_caches_cc Log message: update to 154.0.8037.92; ok naddy@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:15:51 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: count discarded RX packets Backport of sys/dev/ic/qwx.c,v 1.91 and sys/dev/ic/qwx.c,v 1.95 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:16:43 Modified files: sys/dev/ic : qwz.c qwzvar.h Log message: sys/qwz: report radiotap channels and rates Based on sys/dev/ic/qwx.c,v 1.93 and sys/dev/ic/qwxvar.h,v 1.31 Populate radiotap channel and rate fields with WCN7850 RX rate decoding. Use QWZ presence masks and omit unavailable timestamps, noise and signal strength for data frames. Correct 54 Mb/s encoding from 104 to 108 in 500 kb/s. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:17:30 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: preserve decoded radiotap frequency Management RX parameters already contain a hostorder chanel frequency. Avoid decoding it again before writing the little endian radiotap field. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:18:14 Modified files: sys/dev/pci : if_qwz_pci.c Log message: sys/qwz: retain cached firmware filenames Backport of sys/dev/pci/if_qwx_pci.c,v 1.29 OK: stsp@ CVSROOT: /cvs Module name: ports Changes by: jca@cvs.openbsd.org 2026/10/01 06:04:07 Modified files: security/gnupg : Makefile distinfo Added files: security/gnupg/patches: patch-g10_import_c Log message: Reattempt the upgrade to gnupg-2.5.24 Upstream published a fix for regression that broke mail/notmuch configure. Updating now means smaller steps if we need an update for a security issue in the next 8.0 OpenBSD release. ok sthen@ naddy@ CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/01 07:06:56 Modified files: usr.sbin/rpki-client: repo.c Log message: Track the nofetch variable by TAL. This matches better with the MAX_REPO_PER_TAL limit which is already tracked by TAL and with that a TAL hitting the limit will not affect the other TALs. Reported by eur1ka OK tb@ CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/01 07:12:16 Modified files: . : errata.html errata20.html errata21.html errata22.html errata23.html errata24.html errata25.html errata26.html errata27.html errata28.html errata29.html errata30.html errata31.html errata32.html errata33.html errata34.html errata35.html errata36.html errata37.html errata38.html errata39.html errata40.html errata41.html errata42.html errata43.html errata44.html errata45.html errata46.html errata47.html errata48.html errata49.html errata50.html errata51.html errata52.html errata53.html errata54.html errata55.html errata56.html errata57.html errata58.html errata59.html errata60.html errata61.html errata62.html errata63.html errata64.html errata65.html errata66.html errata67.html errata68.html errata69.html errata70.html errata71.html errata72.html errata73.html errata74.html errata75.html errata76.html errata77.html errata78.html errata79.html Added files: . : errata80.html Log message: add errata80 CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/01 07:12:42 Modified files: . : plus.html plus20.html plus21.html plus22.html plus23.html plus24.html plus25.html plus26.html plus27.html plus28.html plus29.html plus30.html plus31.html plus32.html plus33.html plus34.html plus35.html plus36.html plus37.html plus38.html plus39.html plus40.html plus41.html plus42.html plus43.html plus44.html plus45.html plus46.html plus47.html plus48.html plus49.html plus50.html plus51.html plus52.html plus53.html plus54.html plus55.html plus56.html plus57.html plus58.html plus59.html plus60.html plus61.html plus62.html plus63.html plus64.html plus65.html plus66.html plus67.html plus68.html plus69.html plus70.html plus71.html plus72.html plus73.html plus74.html plus75.html plus76.html plus77.html plus78.html plus79.html Added files: . : plus80.html Log message: add plus80 CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/01 07:25:54 Modified files: usr.sbin/rpki-client: nca.c Log message: rpki-client: factor a nonfunc_ca_free() out of nca_tree_remove_cert() ok claudio CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/01 07:31:14 Modified files: usr.sbin/rpki-client: nca.c Log message: rpki-client: do not fatal after RB_INSERT() into the NCA trees rpki-client is generally a bit too quick to error out and a repeated source of problems has been errx after RB_INSERT() (one fixed just yesterday). The first of these is probably not reachable but do that for good measure. The other one was shown to be reachable in somewhat contrived setups by eur1ka, which means rpki-client would refuse to start. ok claudio CVSROOT: /cvs Module name: src Changes by: stsp@cvs.openbsd.org 2026/10/01 07:39:35 Modified files: sys/dev/ic : qwx.c Log message: Don't use negative errno values in qwx(4). Spotted by kirill@ CVSROOT: /cvs Module name: src Changes by: millert@cvs.openbsd.org 2026/10/01 10:33:26 Modified files: share/zoneinfo/datfiles: europe northamerica zone.tab zone1970.tab zonenow.tab Log message: Update to 2026egtz from https://github.com/JodaOrg/global-tz o Manitoba moves to permanent -05 on 2026-10-31. o In 1925 Ireland fell back on 09-20 not 10-04. CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:26:07 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: update RSSI from TX acknowledgments Backport of sys/dev/ic/qwx.c,v 1.98 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:26:51 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: clear node flags during deauthentication Backport of sys/dev/ic/qwx.c,v 1.113 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:27:39 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: keep data interrupts through association Backport of sys/dev/ic/qwx.c,v 1.125 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:28:42 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: prepare peers before association requests Backport of sys/dev/ic/qwx.c,v 1.94, sys/dev/ic/qwx.c,v 1.118 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:29:43 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: configure negotiated HT SMPS Backport of sys/dev/ic/qwx.c,v 1.92 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:30:30 Modified files: sys/dev/ic : qwz.c qwzreg.h Log message: sys/qwz: fix WCN7850 REO layout Use WCN7850 REO tags and 64-bit TLV headers so commands and completions use the correct offsets. Correct the status ring size and clear command payloads before reuse. The layout follows Linux ath12k's WCN7850 definitions. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:37:59 Modified files: sys/dev/ic : qwz.c qwzvar.h Log message: sys/qwz: fix REO queue lifetime Track REO completions before publication and wait for peer unmap, deletion, and cache flushes before reusing queue DMA. Submission errors and timeouts retain ownership; hardware failures block reuse until cold cleanup. HAL error conventions and flush semantics follow ath12k; tracking and the reuse barrier adapt qwz's retained pool. CVSROOT: /cvs Module name: src Changes by: mlarkin@cvs.openbsd.org 2026/10/01 15:49:49 Modified files: usr.sbin/vmd : i8259.c Log message: vmd(8): change a log_warnx to a log_debug no functional change, just quieting a chatty log message. CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 16:35:08 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: spoted one more negative errno CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/01 17:51:29 Modified files: sys/arch/i386/i386: machdep.c sys/arch/amd64/amd64: cpu.c Log message: don't access the DE_CFG MSR when running on a hypervisor Sebastian Albert encountered a KVM hosting provider where trying to access the MSR resulted in a protection fault. DE_CFG is not documented in AMD's 'AMD64 Architecture Programmer's Manual'. ok brynet@ mlarkin@ CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/01 19:29:30 Modified files: . : 80.html Log message: add rkotp(4) and sambat(4) CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/01 19:44:47 Modified files: . : 80.html Log message: arm64 hibernate support is new for 8.0, don't mention fixes CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/01 19:49:19 Modified files: . : 80.html Log message: don't mention pkgconf version twice CVSROOT: /cvs Module name: src Changes by: rsadowski@cvs.openbsd.org 2026/10/01 22:03:47 Modified files: usr.sbin/relayd: relay_http.c Log message: relayd: apply the header length limit to unterminated lines The limit was only checked for complete lines, so a header line without line ending could be buffered without bound. Reject such lines with 413 as soon as they exceed the limit. Spotted by Acts1631 (with diff), OK kirill@ CVSROOT: /cvs Module name: src Changes by: rsadowski@cvs.openbsd.org 2026/10/01 22:18:48 Modified files: usr.sbin/relayd: relay_http.c Log message: relayd: apply the header length limit to chunk size and trailer lines Chunk size and trailer lines were not limited, so a line without line ending could be buffered without bound. Limit each chunk size line and the whole trailer to the configured header length and close the session if they exceed it. Spotted by Acts1631 (with diff), OK kirill@ CVSROOT: /cvs Module name: src Changes by: rsadowski@cvs.openbsd.org 2026/10/01 22:34:27 Added files: regress/usr.sbin/relayd: args-http-chunked-trailer-unterminated.pl Log message: Test unterminated chunk trailer lines against the header length limit CVSROOT: /cvs Module name: src Changes by: rsadowski@cvs.openbsd.org 2026/10/01 22:47:07 Modified files: usr.sbin/httpd : config.c httpd.c httpd.conf.5 httpd.h parse.y server.c server_http.c Log message: httpd: add header block/drop rules for request filtering With this incoming requests can also be rejected based on the value of a request header. Valid options are: header block name value code [arg] Close the connection with an error response when a request header matches. Both name and value are shell- style patterns and are matched case-insensitively against the header name and value. code must be a valid HTTP status code. For codes in the 3xx range, arg is required and sent as the "Location" header. It must start with "http://" or "https://". For all other codes, arg is optional and used as the log message identifying the rule. header drop name value Silently close the connection without sending a response when a request header matches, using the same pattern rules as block. Based on a diff from Purple Rain from SecBSD, who wrote a initial version to block Ai- and other Scraper. Also requested and tested by Mischa. Tested by Purple Rain, Mischa and others, thanks Feedback by Lloyd, Christian Schulte, thanks OK kirill@ CVSROOT: /cvs Module name: src Changes by: sashan@cvs.openbsd.org 2026/10/02 03:40:22 Modified files: sys/net : pf.c pf_table.c Log message: pf(4): pfr_insert_kentry() always needs PF_LOCK() pfr_insert_kentry() inserts an IP address into a table. The table's consistency is protected by PF_LOCK(). Unfortunately, PF_LOCK() protection is missing for the code path executed on behalf of the overload action in a pf rule. The overload action instructs the firewall to insert the packet's source address into the table specified as the overload action parameter. That particular code path in pf_test() function runs without any lock protection. The bug was introduced in revision 1.1074 and remained unnoticed until now, when it was kindly reported by alf (a.schlichting () lemarit ! com>) OK henning@, OK dlg@, OK jmatthew@ CVSROOT: /cvs Module name: ports Changes by: giovanni@cvs.openbsd.org 2026/10/02 05:03:16 Modified files: www/apache-httpd: Makefile distinfo www/apache-httpd/pkg: PLIST Removed files: www/apache-httpd/patches: patch-server_mpm_unix_c Log message: security update to 2.4.69 20 CVE fixed, details at https://httpd.apache.org/security/vulnerabilities_24.html ok sthen@ CVSROOT: /cvs Module name: src Changes by: stsp@cvs.openbsd.org 2026/10/02 05:24:18 Modified files: sys/dev/ic : qwx.c Log message: also sync qwx DMA memory before updating the ring pointer via sc->ops.write32 CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 06:12:51 Modified files: usr.bin/tmux : cmd-copy-mode.c Log message: Do not use client for copy-mode -S if NULL, reported by Martin Vlach. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 06:23:44 Modified files: usr.bin/tmux : cmd-swap-pane.c Log message: Restore the zoom when swap-pane refuses a floating pane, GitHub issue 5660 from Alexandre Fiori. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 06:28:07 Modified files: usr.bin/tmux : cfg.c server-client.c tmux.h Log message: Do not leak client if lost before configuration is loaded, and do not load multiple times. GitHub issues 5661 and 5662 from Alexandre Fiori. CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/02 06:28:20 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: backport sync DMA memory from qwx Backport of sys/dev/ic/qwx.c,v 1.140 and 1.146 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/02 06:41:35 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: backport of olatile casts from qwx Backport of sys/dev/ic/qwx.c,v 1.114 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/02 06:48:20 Removed files: sbin/isakmpd : BUGS DESIGN-NOTES QUESTIONS README TO-DO Log message: these files are completely historical and not helping improve things CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 06:48:52 Modified files: usr.bin/tmux : cmd-attach-session.c cmd-join-pane.c cmd-resize-pane.c cmd-split-window.c layout.c screen-redraw.c screen-write.c server-client.c tmux.h tty.c window-copy.c window.c Log message: Instead of redrawing the entire pane or scene when moving or redrawing a pane, add damage rectangles and redraw only the affected spans. From Michael Grant. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 06:53:26 Modified files: usr.bin/tmux : screen-write.c Log message: Sync redraw should use the given rows not the scroll region now. CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/02 07:18:07 Modified files: sys/dev/usb : usb_subr.c Log message: sys/usb: validate USB endpoint and configuration lengths Reject undersized endpoint descriptors before accessing wMaxPacketSize; require wTotalLength to cover the configuration header and match the allocated size after the full fetch. Reported by Stuart Thomas OK: deraadt@ CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 07:20:42 Modified files: usr.bin/tmux : spawn.c Log message: Change to the new working directory even if getcwd fails, GitHub issue 5658. CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/02 08:13:44 Modified files: usr.sbin/rpki-client: output-rtrx.c Log message: output-rtrx: place one brace on the proper line CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 08:16:42 Modified files: usr.bin/tmux : screen-write.c Log message: Only skip collecting text except for right margin when autowrap is off, from Jang-Ho Hwang. CVSROOT: /cvs Module name: ports Changes by: robert@cvs.openbsd.org 2026/10/02 08:17:25 Modified files: www/ungoogled-chromium: Makefile distinfo www/ungoogled-chromium/patches: patch-chrome_browser_picture_in_picture_picture_in_picture_window_manager_cc patch-content_browser_web_contents_web_contents_impl_cc patch-gpu_command_buffer_service_gles2_cmd_decoder_cc patch-gpu_command_buffer_service_shared_image_external_vk_image_backing_factory_cc patch-third_party_fontconfig_include_meson-config_h patch-third_party_test_fonts_fontconfig_BUILD_gn Removed files: www/ungoogled-chromium/patches: patch-third_party_test_fonts_fontconfig_generate_fontconfig_caches_cc Log message: update to 154.0.8037.92; ok naddy@ CVSROOT: /cvs Module name: ports Changes by: robert@cvs.openbsd.org 2026/10/02 08:18:13 Modified files: x11/mate/settings-daemon: Makefile x11/mate/settings-daemon/pkg: PLIST Log message: add missing @sample for org.mate.SettingsDaemon.DateTimeMechanism.conf; ok naddy@ CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 09:04:27 Modified files: usr.bin/tmux : options-table.c Log message: Quote session_alert in status-format[2], GitHub issue 5671. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 09:13:07 Modified files: usr.bin/tmux : cmd-display-message.c Log message: Modify display-message -c target-client to use the data relative to target-client, GitHub issue 5613 from Michael Grant. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 09:20:41 Modified files: usr.bin/tmux : screen-write.c window-visible.c Log message: Include menus when working out what parts of a pane are visible to avoid overwriting them, GitHub issue 5593. CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/02 10:43:17 Modified files: usr.bin/mandoc : msec.c Log message: When converting a section identifier (for example, "1" or "1m") to a volume title (for example, "General Commands Manual" or "Maintenance Commands") and no exact match is found for the identifier, retry using only the first character of the identifier before giving up. For example, when using OpenBSD to format the Oracle Solaris ipmitool(1m) manual, which contains the line '.TH ipmitool 1m "29 June 2012"', use the section 1 volume title "General Commands Manual" rather than finding no title at all. In general, this improves formatting of the page header line of manual pages using session suffixes that are not declared in msec.in on the formatting system. That's useful everywhere for formatting foreign manual pages, but also for formatting native manuals on systems using many suffixes. I had this idea for a small improvement while looking at how FreeBSD customizes the companion file msec.in in their freebsd-src/contrib/mandoc directory. CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/02 10:48:01 Modified files: regress/usr.bin/mandoc/man/TH: Makefile regress/usr.bin/mandoc/mdoc/Dt: Makefile Added files: regress/usr.bin/mandoc/man/TH: secsuffix.in secsuffix.out_ascii regress/usr.bin/mandoc/mdoc/Dt: secsuffix.in secsuffix.out_ascii secsuffix.out_markdown Log message: test handling of session suffixes in the .Dt and .TH macros; related to msec.c rev. 1.14 CVSROOT: /cvs Module name: src Changes by: rsadowski@cvs.openbsd.org 2026/10/02 12:06:20 Modified files: usr.sbin/relayd: relay_http.c Log message: relayd: do not treat a missing Host header as a url match Return RES_BAD if the request has no Host header, consistent with the handling of empty or malformed Host values. Spotted by Acts1631 (with diff), OK kirill@ CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/02 16:47:02 Modified files: lib/libexpat : Changes lib/libexpat/lib: internal.h xmlparse.c xmlrole.c xmlrole.h xmltok.c xmltok.h xmltok_impl.c xmltok_ns.c lib/libexpat/tests: basic_tests.c memcheck.c nsalloc_tests.c Log message: Backport fixes from libexpat version 2.8.5. Relevant for OpenBSD are security fixes #1282, bug fixes #1346 #1371, other changes #1354 #1357 #1349 #1360 #1378. Library bump is not necessary. CVE-2026-93990 OK deraadt@ CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/02 18:46:29 Modified files: usr.bin/ssh : readconf.c Log message: make StreamLocalBindMask properly respect Host/Match blocks and make it first-match-wins as documented. bz4013 CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/02 18:46:58 Modified files: usr.bin/ssh : servconf.c Log message: make StreamLocalBindMask properly first-match-wins; spotted while fixing bz4013 CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/02 19:06:40 Modified files: sbin/isakmpd : policy.c Log message: incorrect object being freed from Franz Bettag / Bettag Systems ok markus hshoexer sthen mvs CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/02 19:14:34 Modified files: sbin/isakmpd : ike_quick_mode.c message.c Log message: IKEv1 short-HASH heap overflow; second approach for fix from Franz Bettag / Bettag Systems ok sthen mvs CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/02 19:15:47 Modified files: sbin/isakmpd : x509.c Log message: knf CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/02 19:31:30 Modified files: sbin/isakmpd : conf.c conf.h connection.c connection.h exchange.c exchange.h field.c field.h ike_auth.c ipsec.c isakmpd.8 isakmpd.c log.c log.h message.c message.h monitor.c monitor.h nat_traversal.c pf_key_v2.c policy.c sa.c sa.h timer.c timer.h transport.c transport.h udp.c udp_encap.c ui.c ui.h util.c util.h virtual.c Log message: Franz Bettag sent a report & diff repairing the privsep monitor's dangerous file behavior in /var/run, and I was shocked at what it does. isakmpd never had a proper diagnosis and control program like other daemons do, and instead accepts weird commands on a fifo and splats files dangerously. Some path names can be manipulated. This 2600 line diff removes all of this session debugging mechanism which is the main cause of that unsafe design. There are no reuseable parts in that code (it cannot be reconstructed into a proper control program interface). As a result, the privsep monitor now has unveil to the config directory, and the network speaking process is "stdio sendfd route recvfd inet". There is some loss of functionality, since some users had gotten used to the decrepit debugging / logging interface to repair sessions which would not negotiate. This is almost completely unmaintained code from early OpenBSD days with an incorrect privsep design, and many users have migrated to using iked(8) which does IKEv2 protocol. RFC9395 also provides valuable guidance here. Everyone is urged to avoid using this program. If IKEv1 protocol is still a part of your life roll up sleeves and try to write a high-quality control interface using lessons from the IKEv2 iked(8) code. Great conversations and help from Franz Bettag finding code to delete. comments & tests from sthen mvs robert; also ok markus bluhm hshoexer CVSROOT: /cvs Module name: src Changes by: rcovelli@cvs.openbsd.org 2026/10/02 19:32:37 Modified files: usr.sbin/rtrd : sockets.c Log message: Use SOCK_NONBLOCK and handle fcntl() failures. OK deraadt@ CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/02 19:38:25 Modified files: sbin/isakmpd : policy.c Log message: The path generation must not contain '..' or '/' type patterns or it can walk upwards and sideways. The privsep open() is now restricted by a single unveil() inside the config directory, but files in relative config directories can still be reached and create potentially confusing outcomes. This is half of a repair from Franz Bettag before I restructured the privsep to use unveil(), the other half of the repair is not needed because it applies to code that no longer exists. ok markus hshoexer bluhm, testing sthen mvs CVSROOT: /cvs Module name: src Changes by: rcovelli@cvs.openbsd.org 2026/10/02 20:45:47 Modified files: usr.sbin/rpki-client: output-rtrx.c Log message: Use SOCK_NONBLOCK where we can. Handle errors for fcntl(). CID 656886, CID 656887 OK deraadt@ tb@ CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/02 21:23:40 Modified files: . : 80.html Log message: httpd8() -> httpd(8) CVSROOT: /cvs Module name: src Changes by: mlarkin@cvs.openbsd.org 2026/10/02 22:10:50 Modified files: usr.sbin/vmd : x86_vm.c Log message: vmd(8): fix mmio exit issue on old SVM machines fix a problem where we didn't pass any instruction length to insn_decode on some older opterons that don't have SVM decode assist. ok dv CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/02 22:25:19 Modified files: . : 80.html Log message: previous release was 7.9 CVSROOT: /cvs Module name: src Changes by: dtucker@cvs.openbsd.org 2026/10/02 23:08:49 Modified files: regress/usr.bin/ssh: percent.sh Log message: Add test for proxycommand percent expansions. CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/03 00:36:08 Modified files: . : 80.html Log message: em(1) -> em(4) CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/03 03:41:30 Modified files: sys/dev/ic : ufshci.c Log message: sys/ufshci: increase poll's wait to 500ms This matches Linux timeout and makes ufshci survives a suspend on HONOR MagicBook Art 14 Snapdragon 500ms value which matches Linux suggested by kettenis@ OK: mglocker@ CVSROOT: /cvs Module name: www Changes by: tb@cvs.openbsd.org 2026/10/03 05:23:34 Modified files: . : 80.html Log message: libressl 4.4.0 these are essentially the portable release notes, with the portable bits compressed to an absolute minimum, as there were way too many of those (thanks Kartik and Kenjiro) CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/03 08:03:49 Modified files: usr.bin/mandoc : mdoc_validate.c Log message: If the -width of a .Bl macro is of the form ".word text", use only the text for measuring the width, assuming the word is a macro, as a crude approximation of what groff_mdoc(7) does: it sets the argument in a diversion and measures the width of the diversion. Ugly formatting first reported by Franco Fichtner (DragonFly BSD) in 2013, this partial fix first suggested by me in the mandoc TODO file in 2013, then implemented by Eric van Gyzen (FreeBSD) in 2022. My fix committed here is slightly smaller than Eric's FreeBSD fix, does not need an extra function, and stays closer to groff behaviour. CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/03 08:20:33 Modified files: regress/usr.bin/mandoc/mdoc/Bd: offset-empty.in offset-empty.out_ascii offset-empty.out_markdown offset-neg.in offset-neg.out_ascii offset-neg.out_markdown regress/usr.bin/mandoc/mdoc/Bl: Makefile offset.in offset.out_ascii offset.out_markdown Added files: regress/usr.bin/mandoc/mdoc/Bl: width.in width.out_ascii width.out_markdown Log message: test macros in .Bl and .Bd -width and -offset arguments; related to mdoc_validate.c rev. 1.313 CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/03 11:35:09 Modified files: sbin/isakmpd : Tag: OPENBSD_7_8 conf.c conf.h connection.c connection.h exchange.c exchange.h field.c field.h ike_auth.c ike_quick_mode.c ipsec.c isakmpd.8 isakmpd.c log.c log.h message.c message.h monitor.c monitor.h pf_key_v2.c policy.c sa.c sa.h timer.c timer.h transport.c transport.h udp.c udp_encap.c ui.c ui.h util.c util.h virtual.c Log message: incorrect object being freed from Franz Bettag / Bettag Systems from deraadt@; OK markus@ hshoexer@ sthen@ mvs@ IKEv1 short-HASH heap overflow; second approach for fix from Franz Bettag / Bettag Systems from deraadt@; OK sthen@ mvs@ Franz Bettag sent a report & diff repairing the privsep monitor's dangerous file behavior in /var/run, and I was shocked at what it does. isakmpd never had a proper diagnosis and control program like other daemons do, and instead accepts weird commands on a fifo and splats files dangerously. Some path names can be manipulated. This 2600 line diff removes all of this session debugging mechanism which is the main cause of that unsafe design. There are no reuseable parts in that code (it cannot be reconstructed into a proper control program interface). As a result, the privsep monitor now has unveil to the config directory, and the network speaking process is "stdio sendfd route recvfd inet". There is some loss of functionality, since some users had gotten used to the decrepit debugging / logging interface to repair sessions which would not negotiate. This is almost completely unmaintained code from early OpenBSD days with an incorrect privsep design, and many users have migrated to using iked(8) which does IKEv2 protocol. RFC9395 also provides valuable guidance here. Everyone is urged to avoid using this program. If IKEv1 protocol is still a part of your life roll up sleeves and try to write a high-quality control interface using lessons from the IKEv2 iked(8) code. Great conversations and help from Franz Bettag finding code to delete. from deraadt@; comments & tests from sthen@ mvs@ robert@; also OK markus@ bluhm@ hshoexer@ The path generation must not contain '..' or '/' type patterns or it can walk upwards and sideways. The privsep open() is now restricted by a single unveil() inside the config directory, but files in relative config directories can still be reached and create potentially confusing outcomes. This is half of a repair from Franz Bettag before I restructured the privsep to use unveil(), the other half of the repair is not needed because it applies to code that no longer exists. from deraadt@; OK markus@ hshoexer@ bluhm@; testing sthen@ mvs@ this is errata/7.8/067_isakmpd.patch.sig CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/03 11:35:48 Modified files: sbin/isakmpd : Tag: OPENBSD_7_9 conf.c conf.h connection.c connection.h exchange.c exchange.h field.c field.h ike_auth.c ike_quick_mode.c ipsec.c isakmpd.8 isakmpd.c log.c log.h message.c message.h monitor.c monitor.h pf_key_v2.c policy.c sa.c sa.h timer.c timer.h transport.c transport.h udp.c udp_encap.c ui.c ui.h util.c util.h virtual.c Log message: incorrect object being freed from Franz Bettag / Bettag Systems from deraadt@; OK markus@ hshoexer@ sthen@ mvs@ IKEv1 short-HASH heap overflow; second approach for fix from Franz Bettag / Bettag Systems from deraadt@; OK sthen@ mvs@ Franz Bettag sent a report & diff repairing the privsep monitor's dangerous file behavior in /var/run, and I was shocked at what it does. isakmpd never had a proper diagnosis and control program like other daemons do, and instead accepts weird commands on a fifo and splats files dangerously. Some path names can be manipulated. This 2600 line diff removes all of this session debugging mechanism which is the main cause of that unsafe design. There are no reuseable parts in that code (it cannot be reconstructed into a proper control program interface). As a result, the privsep monitor now has unveil to the config directory, and the network speaking process is "stdio sendfd route recvfd inet". There is some loss of functionality, since some users had gotten used to the decrepit debugging / logging interface to repair sessions which would not negotiate. This is almost completely unmaintained code from early OpenBSD days with an incorrect privsep design, and many users have migrated to using iked(8) which does IKEv2 protocol. RFC9395 also provides valuable guidance here. Everyone is urged to avoid using this program. If IKEv1 protocol is still a part of your life roll up sleeves and try to write a high-quality control interface using lessons from the IKEv2 iked(8) code. Great conversations and help from Franz Bettag finding code to delete. from deraadt@; comments & tests from sthen@ mvs@ robert@; also OK markus@ bluhm@ hshoexer@ The path generation must not contain '..' or '/' type patterns or it can walk upwards and sideways. The privsep open() is now restricted by a single unveil() inside the config directory, but files in relative config directories can still be reached and create potentially confusing outcomes. This is half of a repair from Franz Bettag before I restructured the privsep to use unveil(), the other half of the repair is not needed because it applies to code that no longer exists. from deraadt@; OK markus@ hshoexer@ bluhm@; testing sthen@ mvs@ this is errata/7.9/031_isakmpd.patch.sig CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/03 11:49:34 Modified files: lib/libexpat : Tag: OPENBSD_7_8 Changes lib/libexpat/lib: Tag: OPENBSD_7_8 internal.h xmlparse.c xmlrole.c xmlrole.h xmltok.c xmltok.h xmltok_impl.c xmltok_ns.c lib/libexpat/tests: Tag: OPENBSD_7_8 basic_tests.c memcheck.c nsalloc_tests.c Log message: Backport fixes from libexpat version 2.8.5. Relevant for OpenBSD are security fixes #1282, bug fixes #1346 #1371, other changes #1354 #1357 #1349 #1360 #1378. Library bump is not necessary. CVE-2026-93990 OK deraadt@ this is errata/7.8/069_expat.patch.sig CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/03 11:50:11 Modified files: lib/libexpat : Tag: OPENBSD_7_9 Changes lib/libexpat/lib: Tag: OPENBSD_7_9 internal.h xmlparse.c xmlrole.c xmlrole.h xmltok.c xmltok.h xmltok_impl.c xmltok_ns.c lib/libexpat/tests: Tag: OPENBSD_7_9 basic_tests.c memcheck.c nsalloc_tests.c Log message: Backport fixes from libexpat version 2.8.5. Relevant for OpenBSD are security fixes #1282, bug fixes #1346 #1371, other changes #1354 #1357 #1349 #1360 #1378. Library bump is not necessary. CVE-2026-93990 OK deraadt@ this is errata/7.9/033_expat.patch.sig CVSROOT: /cvs Module name: www Changes by: kirill@cvs.openbsd.org 2026/10/03 12:33:27 Modified files: . : 80.html Log message: Added specific improvments for HONOR's MagicBook CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/03 13:15:49 Modified files: regress/usr.sbin/rpki-client/openssl: unistd.h Log message: rpki-client regress: this unistd.h hack needs to include x509.h CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/03 19:44:27 Modified files: . : 80.html Log message: Chromium 154.0.8037.92 CVSROOT: /cvs Module name: www Changes by: deraadt@cvs.openbsd.org 2026/10/03 21:22:31 Modified files: . : 80.html plus.html Log message: AES cpu instructions is what made it faster.. CVSROOT: /cvs Module name: src Changes by: gnezdo@cvs.openbsd.org 2026/10/03 22:45:55 Modified files: sys/kern : sysv_shm.c Log message: sysv_shm: claim the vm_shm slot after uvm_map(), not before sys_shmat() chose a free slot in the per-vmspace vm_shm array, then slept in uvm_map(), then published into the slot it had chosen. Nothing marked the slot taken across the sleep, so a sibling thread entering sys_shmat() scanned the same array, found the same slot still reading -1, and took it too. Both uvm_map() calls succeed at different addresses and the thread that stores last wins; the other mapping is left with no vm_shm entry, so shmdt() returns EINVAL for it and shmexit() cannot drop its shm_nattch. The permanently raised count keeps IPC_RMID from deallocating the segment, which then sits in shmsegs[] reachable by nobody; 128 of those and shmget() returns ENOSPC system-wide. uvm_map() is the only sleep between choosing the slot and filling it in, so moving the scan below the map closes the window without a reserved state that shmdt(), shmexit() and shmfork() would each have to learn about. EMFILE is now discovered after the mapping exists, so that path undoes it. While here, balance the uao reference on the uvm_map() failure path: a failed uvm_map() does not consume the caller reference, so two were outstanding and the deallocate arm dropped only one. r1.88 already unpublishes the segment before shm_deallocate_segment(), so the detach can be done unconditionally and first. OK mvs@ Reported-by: Acts1631 CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/04 03:15:09 Modified files: lib/libcrypto/bytestring: bytestring.h lib/libssl : bytestring.h Log message: libcrypto/bytestring: remove LIBRESSL_INTERNAL from bytestring.h This currently marks the LibreSSL-specific additions to this API. It has no effect other than getting in the way of other projects wanting to use this since it is always compiled with LIBRESSL_INTERNAL. ok kenjiro CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/04 03:19:19 Modified files: lib/libcrypto/bytestring: bytestring.h lib/libssl : bytestring.h Log message: libcrypto/bytestring: add some missing tag classes This adds tags for NULL, PrintableString, UTCTime, and GeneralizedTime with names matching BoringSSL. ok kenjiro CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/04 03:23:40 Modified files: lib/libcrypto/bytestring: bytestring.h lib/libssl : bytestring.h Log message: libcrypto/bytestring.h: make parentheses line up again whitespace-only change CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/04 03:37:56 Added files: usr.sbin/rpki-client: bs_ber.c bs_cbb.c bs_cbs.c bytestring.h Log message: rpki-client: add a copy of libcrypto's bytestring API This will be used to replace the terrible CMS API from libcrypto. Longer term this might also be used to implement better parsers for certs, CRLs and the signed objects' eContent. discussed with claudio and job ok beck CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/04 03:39:02 Modified files: usr.sbin/rpki-client: Makefile Log message: rpki-client: link bytestring API to the build ok beck CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/04 03:40:27 Modified files: regress/usr.sbin/rpki-client: Makefile.inc Log message: rpki-client regress: link bytestring API to the build CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/04 04:18:13 Modified files: regress/lib/libcrypto/objects: objectstest.c Log message: objectstest: succeded -> succeeded CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 07:31:56 Modified files: usr.sbin/rtrd : cache.c commands.c hash.c Log message: more knf CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 07:33:33 Modified files: usr.sbin/rpc.statd: statd.c Log message: O_NONBLOCK is the modern name (with 2 legacy userland defines and 2 legacy kernel defines, not sure when all of that will collapse) CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 07:44:51 Modified files: sbin/isakmpd : udp.c Log message: using sizeof is recommended practice CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 08:24:54 Modified files: libexec/ld.so : ld.so.1 library_subr.c Log message: surprised this page did not Xr ldd 1 CVSROOT: /cvs Module name: www Changes by: bcook@cvs.openbsd.org 2026/10/04 10:54:37 Modified files: libressl : index.html releases.html Log message: LibreSSL 4.2.2, 4.3.3, 4.4.0rc1 CVSROOT: /cvs Module name: www Changes by: schwarze@cvs.openbsd.org 2026/10/04 12:01:03 Modified files: . : 80.html Log message: Diverse small improvements: * mention import of rtrctl(8) * remove entries for three minor rtrd(8) fixes; it wasn't in 7.9 and its addition to 8.0 is listed in another entry * remove a duplicate entry regarding httpd(8) server flags * remove entry for a mandoc(1) regression that wasn't in 7.9 but only happened in -current for a few weeks * unveil(2) changes don't affect mandoc(1), talk about man(1) instead * add many missing manual page links * fix broken smte(4) manual page link * fix indentation of three subheaders in the OpenSSH section * remove a couple of duplicate subheader lines * remove one stray word and one instance of s/nul byte/NUL byte/ CVSROOT: /cvs Module name: www Changes by: schwarze@cvs.openbsd.org 2026/10/04 12:19:33 Modified files: . : innovations.html Log message: add getexecpath(3), watch(1), rtrd(8), rtrctl(8) CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 13:32:14 Modified files: libexec/ld.so : library_subr.c Log message: Oops, this proposal isn't ready yet. accidental commit spotted by by caspar CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 13:53:46 Modified files: usr.bin/ypwhich: ypwhich.c Log message: remove accidental test code from 1994 which neutered parts of the intended behaviour. ok miod CVSROOT: /cvs Module name: src Changes by: krw@cvs.openbsd.org 2026/10/04 15:12:18 Modified files: sys/uvm : uvm_swap.c Log message: Reserve a 16K-byte gap at the start of a swap partition. Swap currently reserves PAGE_SIZE (4K, 8K or 16K depending on arch) bytes as potential space for a disklabel and boot code. A disklabel can be placed in the first or second DEV_BSIZE bytes of swap, with some arch's needing up to 6 * DEV_BSIZE additional bytes for boot code and arch dependent disklabel info. New disklabel code will need to store a bigger disklabel structure in 3 * DEV_BSIZE bytes of the *FIRST VIABLE PARTITION WITH A GAP*. VIABLE PARTITIONS are filesystems (ffs and swap in particular) which have a sufficiently large gap. Increasing the swap partition gap makes it much more likely that those bytes will be available. Suggested by & ok deraadt@ CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/04 18:43:41 Modified files: sys/dev/pci/drm: drm_atomic_uapi.c Log message: drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr From Thadeu Lima de Souza Cascardo daefd7ff159b0d1fb8c9e64430dcbe2aca1bdd09 in linux-6.18.y/6.18.54 9eb1a393c89a79c4210230d23e7d88d239c61d7b in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/04 18:46:45 Modified files: sys/dev/pci/drm/amd/amdgpu: nbio_v7_9.c Log message: drm/amdgpu: check ras and obj before dereference From Dmitriy Chumachenko 37583946d8751f8e285c467d770ac0b609b82a23 in linux-6.18.y/6.18.54 723d4dc628d764b19cf9efca14b82cca5ff020c9 in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/04 18:49:52 Modified files: sys/dev/pci/drm/amd/amdgpu: amdgpu_device.c Log message: drm/amdgpu: fix rmmio iounmap skipped on device removal From Chengjun Yao cd55dde2b63789a3dafe982c89844f537501d096 in linux-6.18.y/6.18.54 5155002b03b24ba3ef91c5c313b8cf0171b24904 in mainline linux CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 18:51:56 Modified files: usr.sbin/rarpd : rarpd.c Log message: NULL not 0 CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/04 18:52:22 Modified files: sys/dev/pci/drm/amd/amdgpu: amdgpu_dma_buf.c Log message: drm/amdgpu: lock bo before calling amdgpu_vm_bo_update_shared From Pierre-Eric Pelloux-Prayer 801d8647dcb0d34f0654b11f932e4ed365092c5e in linux-6.18.y/6.18.54 36ffc58b8a8704e690a0ce679db26baa5759256f in mainline linux CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 18:53:57 Modified files: sys/kern : vfs_syscalls.c Log message: remove very unneccessary temporary variable CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/04 18:54:24 Modified files: sys/dev/pci/drm/amd/amdgpu: amdgpu_dma_buf.c Log message: drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments From Mike Lothian aeaa7bdc0ea2c725331a423575bb7f93c040f8fb in linux-6.18.y/6.18.54 636139603b99d2e3a18a46cf3f8d39313ce8042e in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/04 20:35:19 Modified files: sbin/isakmpd : isakmpd.8 Log message: remove comma after final SEE ALSO reference CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 20:49:26 Modified files: lib/libc/sys : open.2 Log message: the 1.57 chunk mentioning O_CREAT and O_DIRECTORY failed to use .Dv CVSROOT: /cvs Module name: src Changes by: dtucker@cvs.openbsd.org 2026/10/05 00:03:40 Modified files: usr.bin/ssh : readconf.c Log message: Further restrict the characters allowed in a command-line supplied user name, disallowing '$' and '\'. Reported by SecBuddyF KeenLab Tencent (CodeBuddy Security).