CVSROOT: /cvs Module name: ports Changes by: namn@cvs.openbsd.org 2026/09/30 14:22:30 Modified files: net/rtorrent : Makefile distinfo net/rtorrent/patches: patch-test_Makefile_in Log message: update net/rtorrent 0.16.24 - various security fixes (e.g., overflow, heap overflow and use-after-free) - regen test/Makefile.in patch to remove a new, third instance of -ldl approved by sthen@ and tested by and OK tj@ CVSROOT: /cvs Module name: ports Changes by: namn@cvs.openbsd.org 2026/09/30 14:27:21 Modified files: net/libtorrent : Makefile distinfo Added files: net/libtorrent/patches: patch-test_Makefile_in Log message: update net/libtorrent 0.16.24 - major bump due to removed symbols - unbreaks tests by linking using static archive (from tj@) approved by sthen@ and tested by and OK tj@ CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/09/30 14:44:06 Modified files: sys/conf : newvers.sh Log message: 8.0 -current development CVSROOT: /cvs Module name: www Changes by: sthen@cvs.openbsd.org 2026/09/30 14:47:47 Modified files: faq : current.html Log message: mention geolite->dbip change in ports CVSROOT: /cvs Module name: src Changes by: rcovelli@cvs.openbsd.org 2026/09/30 14:48:11 Modified files: usr.sbin/rpki-client: main.c Log message: Now that we open early we can remove unix pledge OK deraadt@ CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/09/30 20:01:51 Modified files: usr.bin/ssh : auth2-pubkey.c Log message: handle max-pk-ok path identically when the incoming user is invalid; avoids max-pk-ok feature presenting a username validity oracle analysis and patch from Chris Rohlf in collaboration with Claude and Anthropic Research CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/09/30 20:18:26 Modified files: . : 80.html Log message: spelling CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/09/30 20:47:41 Modified files: . : 80.html Log message: update base and xenocara component versions CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/09/30 21:11:49 Modified files: usr.bin/ssh : sftp-client.c sftp.c Log message: sftp: be stricter in accepting paths returned by the server for SSH_FXP_REALPATH or SSH2_FXP_READDIR replies, as these can be used in some situations to decide the destination path for recursive transfers. Report and patch from Junghoon Cho CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/09/30 21:40:35 Modified files: . : 80.html Log message: update ports versions CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/09/30 21:54:19 Modified files: . : 80.html Log message: no loongson for 8.0 CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/09/30 22:17:39 Modified files: usr.bin/ssh : ssh-mldsa-eddsa.c Log message: fix the bit length of ML-DSA 44/Ed25519 keys that was being incorrectly reported as 256. The private key length for these composite keys is 512 bits. This value is only used for display. Spotted by Yiyue Wang CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/09/30 23:53:25 Modified files: lang/python/3 : Makefile Added files: lang/python/3/patches: patch-Modules__ssl_c Log message: cherrypick fix for CPython CVE-2026-19445: Use-after-free of a server-side SSLContext when sni_callback switches contexts. ok tb kmos A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open. CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/09/30 23:54:02 Modified files: lang/python/3 : Tag: OPENBSD_7_9 Makefile Added files: lang/python/3/patches: Tag: OPENBSD_7_9 patch-Modules__ssl_c Log message: cherrypick fix for CPython CVE-2026-19445: Use-after-free of a server-side SSLContext when sni_callback switches contexts. ok tb kmos CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/01 00:30:05 Modified files: . : 80.html Log message: Thunderbird 153.4.0 CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/01 01:07:49 Modified files: usr.bin/ssh : sshkey.c Log message: Implement a maximum number of KDF rounds that will be accepted when writing an OpenSSH-format private key or when loading one. This limit is set pretty high (1<<20), but ensures that a service that is passed a bad key with an ridiculously high number of rounds will _eventually_ complete parsing it. Also bump the default number of KDF rounds from 24 to 32 (this is a linear increase, not like bcrypt(3) which is exponential). Pointed out by Aris Adamantiadis CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/01 01:08:05 Modified files: usr.bin/ssh : ssh-keygen.1 Log message: mention default KDF rounds is now 32 CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/01 01:10:56 Modified files: usr.bin/ssh : scp.c Log message: start process of deprecating the -R flag. This was the old way of performing a remote-to-remote copy that was basically executed scp on the remote host. It barely worked (needing agent forwarding enabled or usable credentials on the remote host) and has largely been replaced by a better SFTP-protocol remote-to-remote copy that runs through the host performing the copy. We'll disable this option in a release or two; ok dtucker@ CVSROOT: /cvs Module name: src Changes by: otto@cvs.openbsd.org 2026/10/01 01:16:45 Modified files: lib/libc/sys : send.2 Log message: Describe what sendmmsg(2) actually does and fix prototype. ok deraadt@ CVSROOT: /cvs Module name: www Changes by: claudio@cvs.openbsd.org 2026/10/01 03:13:56 Modified files: . : mail.html openbgpd : index.html mail.html build/mirrors : openbgpd-ftp.html.head Log message: The openbgpd github organization was moved from "openbgpd-portable" to "openbgpd". Adjust various links. Diff provided by Clara Engler (cve (at) cve cx) CVSROOT: /cvs Module name: www Changes by: claudio@cvs.openbsd.org 2026/10/01 03:15:05 Modified files: openbgpd : ftp.html Log message: Regen after github url change CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:11:41 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: report hardware RX aggregation Based on sys/dev/ic/qwx.c,v 1.85 and sys/dev/ic/qwx.c,v 1.90 Report hardware deaggregation and reordering after successful RX reconstruction; allow repaeted sequence numbers for later A-MSDU subframes and clear the AMSDU QoS bit. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:13:03 Modified files: sys/dev/ic : qwz.c qwzreg.h qwzvar.h Log message: sys/qwz: handle WBM RX errors Based on sys/dev/ic/qwx.c,v 1.35 and sys/dev/ic/qwxvar.h,v 1.18 , sys/dev/ic/qwx.c,v 1.89 , sys/dev/ic/qwx.c,v 1.121 and sys/dev/ic/qwxvar.h,v 1.36 Process WBM RX releases using WCN7850 descriptor and cookie formats. Deliver valid null queue frames through existing RX processing, clear mbuf pointers after delivery, and then replenish descriptors OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:13:53 Modified files: sys/dev/ic : qwz.c qwzvar.h Log message: sys/qwz: read RX metadata from MPDU TLVs Read sequence numbers and TIDs from WCN7850 MPDU descriptors. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:14:55 Modified files: sys/dev/ic : qwz.c qwzreg.h Log message: sys/qwz: drain REO RX exceptions Based on sys/dev/ic/qwx.c,v 1.33 Drain REO RX exceptions using descriptor layouts and qwz cookie. Reclaim packet buffers, return link descriptors and replenish RX, checking bank bounds and release ring space. OK: stsp@ CVSROOT: /cvs Module name: ports Changes by: robert@cvs.openbsd.org 2026/10/01 04:15:01 Modified files: www/chromium : Makefile distinfo www/chromium/patches: patch-chrome_browser_picture_in_picture_picture_in_picture_window_manager_cc patch-content_browser_web_contents_web_contents_impl_cc patch-gpu_command_buffer_service_gles2_cmd_decoder_cc patch-gpu_command_buffer_service_shared_image_external_vk_image_backing_factory_cc patch-third_party_fontconfig_include_meson-config_h patch-third_party_test_fonts_fontconfig_BUILD_gn Removed files: www/chromium/patches: patch-third_party_test_fonts_fontconfig_generate_fontconfig_caches_cc Log message: update to 154.0.8037.92; ok naddy@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:15:51 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: count discarded RX packets Backport of sys/dev/ic/qwx.c,v 1.91 and sys/dev/ic/qwx.c,v 1.95 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:16:43 Modified files: sys/dev/ic : qwz.c qwzvar.h Log message: sys/qwz: report radiotap channels and rates Based on sys/dev/ic/qwx.c,v 1.93 and sys/dev/ic/qwxvar.h,v 1.31 Populate radiotap channel and rate fields with WCN7850 RX rate decoding. Use QWZ presence masks and omit unavailable timestamps, noise and signal strength for data frames. Correct 54 Mb/s encoding from 104 to 108 in 500 kb/s. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:17:30 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: preserve decoded radiotap frequency Management RX parameters already contain a hostorder chanel frequency. Avoid decoding it again before writing the little endian radiotap field. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:18:14 Modified files: sys/dev/pci : if_qwz_pci.c Log message: sys/qwz: retain cached firmware filenames Backport of sys/dev/pci/if_qwx_pci.c,v 1.29 OK: stsp@ CVSROOT: /cvs Module name: ports Changes by: jca@cvs.openbsd.org 2026/10/01 06:04:07 Modified files: security/gnupg : Makefile distinfo Added files: security/gnupg/patches: patch-g10_import_c Log message: Reattempt the upgrade to gnupg-2.5.24 Upstream published a fix for regression that broke mail/notmuch configure. Updating now means smaller steps if we need an update for a security issue in the next 8.0 OpenBSD release. ok sthen@ naddy@ CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/01 07:06:56 Modified files: usr.sbin/rpki-client: repo.c Log message: Track the nofetch variable by TAL. This matches better with the MAX_REPO_PER_TAL limit which is already tracked by TAL and with that a TAL hitting the limit will not affect the other TALs. Reported by eur1ka OK tb@ CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/01 07:12:16 Modified files: . : errata.html errata20.html errata21.html errata22.html errata23.html errata24.html errata25.html errata26.html errata27.html errata28.html errata29.html errata30.html errata31.html errata32.html errata33.html errata34.html errata35.html errata36.html errata37.html errata38.html errata39.html errata40.html errata41.html errata42.html errata43.html errata44.html errata45.html errata46.html errata47.html errata48.html errata49.html errata50.html errata51.html errata52.html errata53.html errata54.html errata55.html errata56.html errata57.html errata58.html errata59.html errata60.html errata61.html errata62.html errata63.html errata64.html errata65.html errata66.html errata67.html errata68.html errata69.html errata70.html errata71.html errata72.html errata73.html errata74.html errata75.html errata76.html errata77.html errata78.html errata79.html Added files: . : errata80.html Log message: add errata80 CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/01 07:12:42 Modified files: . : plus.html plus20.html plus21.html plus22.html plus23.html plus24.html plus25.html plus26.html plus27.html plus28.html plus29.html plus30.html plus31.html plus32.html plus33.html plus34.html plus35.html plus36.html plus37.html plus38.html plus39.html plus40.html plus41.html plus42.html plus43.html plus44.html plus45.html plus46.html plus47.html plus48.html plus49.html plus50.html plus51.html plus52.html plus53.html plus54.html plus55.html plus56.html plus57.html plus58.html plus59.html plus60.html plus61.html plus62.html plus63.html plus64.html plus65.html plus66.html plus67.html plus68.html plus69.html plus70.html plus71.html plus72.html plus73.html plus74.html plus75.html plus76.html plus77.html plus78.html plus79.html Added files: . : plus80.html Log message: add plus80 CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/01 07:25:54 Modified files: usr.sbin/rpki-client: nca.c Log message: rpki-client: factor a nonfunc_ca_free() out of nca_tree_remove_cert() ok claudio CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/01 07:31:14 Modified files: usr.sbin/rpki-client: nca.c Log message: rpki-client: do not fatal after RB_INSERT() into the NCA trees rpki-client is generally a bit too quick to error out and a repeated source of problems has been errx after RB_INSERT() (one fixed just yesterday). The first of these is probably not reachable but do that for good measure. The other one was shown to be reachable in somewhat contrived setups by eur1ka, which means rpki-client would refuse to start. ok claudio CVSROOT: /cvs Module name: src Changes by: stsp@cvs.openbsd.org 2026/10/01 07:39:35 Modified files: sys/dev/ic : qwx.c Log message: Don't use negative errno values in qwx(4). Spotted by kirill@ CVSROOT: /cvs Module name: src Changes by: millert@cvs.openbsd.org 2026/10/01 10:33:26 Modified files: share/zoneinfo/datfiles: europe northamerica zone.tab zone1970.tab zonenow.tab Log message: Update to 2026egtz from https://github.com/JodaOrg/global-tz o Manitoba moves to permanent -05 on 2026-10-31. o In 1925 Ireland fell back on 09-20 not 10-04. CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:26:07 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: update RSSI from TX acknowledgments Backport of sys/dev/ic/qwx.c,v 1.98 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:26:51 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: clear node flags during deauthentication Backport of sys/dev/ic/qwx.c,v 1.113 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:27:39 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: keep data interrupts through association Backport of sys/dev/ic/qwx.c,v 1.125 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:28:42 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: prepare peers before association requests Backport of sys/dev/ic/qwx.c,v 1.94, sys/dev/ic/qwx.c,v 1.118 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:29:43 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: configure negotiated HT SMPS Backport of sys/dev/ic/qwx.c,v 1.92 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:30:30 Modified files: sys/dev/ic : qwz.c qwzreg.h Log message: sys/qwz: fix WCN7850 REO layout Use WCN7850 REO tags and 64-bit TLV headers so commands and completions use the correct offsets. Correct the status ring size and clear command payloads before reuse. The layout follows Linux ath12k's WCN7850 definitions. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:37:59 Modified files: sys/dev/ic : qwz.c qwzvar.h Log message: sys/qwz: fix REO queue lifetime Track REO completions before publication and wait for peer unmap, deletion, and cache flushes before reusing queue DMA. Submission errors and timeouts retain ownership; hardware failures block reuse until cold cleanup. HAL error conventions and flush semantics follow ath12k; tracking and the reuse barrier adapt qwz's retained pool. CVSROOT: /cvs Module name: src Changes by: mlarkin@cvs.openbsd.org 2026/10/01 15:49:49 Modified files: usr.sbin/vmd : i8259.c Log message: vmd(8): change a log_warnx to a log_debug no functional change, just quieting a chatty log message. CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 16:35:08 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: spoted one more negative errno CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/01 17:51:29 Modified files: sys/arch/i386/i386: machdep.c sys/arch/amd64/amd64: cpu.c Log message: don't access the DE_CFG MSR when running on a hypervisor Sebastian Albert encountered a KVM hosting provider where trying to access the MSR resulted in a protection fault. DE_CFG is not documented in AMD's 'AMD64 Architecture Programmer's Manual'. ok brynet@ mlarkin@ CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/01 19:29:30 Modified files: . : 80.html Log message: add rkotp(4) and sambat(4) CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/01 19:44:47 Modified files: . : 80.html Log message: arm64 hibernate support is new for 8.0, don't mention fixes CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/01 19:49:19 Modified files: . : 80.html Log message: don't mention pkgconf version twice CVSROOT: /cvs Module name: src Changes by: rsadowski@cvs.openbsd.org 2026/10/01 22:03:47 Modified files: usr.sbin/relayd: relay_http.c Log message: relayd: apply the header length limit to unterminated lines The limit was only checked for complete lines, so a header line without line ending could be buffered without bound. Reject such lines with 413 as soon as they exceed the limit. Spotted by Acts1631 (with diff), OK kirill@ CVSROOT: /cvs Module name: src Changes by: rsadowski@cvs.openbsd.org 2026/10/01 22:18:48 Modified files: usr.sbin/relayd: relay_http.c Log message: relayd: apply the header length limit to chunk size and trailer lines Chunk size and trailer lines were not limited, so a line without line ending could be buffered without bound. Limit each chunk size line and the whole trailer to the configured header length and close the session if they exceed it. Spotted by Acts1631 (with diff), OK kirill@ CVSROOT: /cvs Module name: src Changes by: rsadowski@cvs.openbsd.org 2026/10/01 22:34:27 Added files: regress/usr.sbin/relayd: args-http-chunked-trailer-unterminated.pl Log message: Test unterminated chunk trailer lines against the header length limit CVSROOT: /cvs Module name: src Changes by: rsadowski@cvs.openbsd.org 2026/10/01 22:47:07 Modified files: usr.sbin/httpd : config.c httpd.c httpd.conf.5 httpd.h parse.y server.c server_http.c Log message: httpd: add header block/drop rules for request filtering With this incoming requests can also be rejected based on the value of a request header. Valid options are: header block name value code [arg] Close the connection with an error response when a request header matches. Both name and value are shell- style patterns and are matched case-insensitively against the header name and value. code must be a valid HTTP status code. For codes in the 3xx range, arg is required and sent as the "Location" header. It must start with "http://" or "https://". For all other codes, arg is optional and used as the log message identifying the rule. header drop name value Silently close the connection without sending a response when a request header matches, using the same pattern rules as block. Based on a diff from Purple Rain from SecBSD, who wrote a initial version to block Ai- and other Scraper. Also requested and tested by Mischa. Tested by Purple Rain, Mischa and others, thanks Feedback by Lloyd, Christian Schulte, thanks OK kirill@ CVSROOT: /cvs Module name: src Changes by: sashan@cvs.openbsd.org 2026/10/02 03:40:22 Modified files: sys/net : pf.c pf_table.c Log message: pf(4): pfr_insert_kentry() always needs PF_LOCK() pfr_insert_kentry() inserts an IP address into a table. The table's consistency is protected by PF_LOCK(). Unfortunately, PF_LOCK() protection is missing for the code path executed on behalf of the overload action in a pf rule. The overload action instructs the firewall to insert the packet's source address into the table specified as the overload action parameter. That particular code path in pf_test() function runs without any lock protection. The bug was introduced in revision 1.1074 and remained unnoticed until now, when it was kindly reported by alf (a.schlichting () lemarit ! com>) OK henning@, OK dlg@, OK jmatthew@ CVSROOT: /cvs Module name: ports Changes by: giovanni@cvs.openbsd.org 2026/10/02 05:03:16 Modified files: www/apache-httpd: Makefile distinfo www/apache-httpd/pkg: PLIST Removed files: www/apache-httpd/patches: patch-server_mpm_unix_c Log message: security update to 2.4.69 20 CVE fixed, details at https://httpd.apache.org/security/vulnerabilities_24.html ok sthen@ CVSROOT: /cvs Module name: src Changes by: stsp@cvs.openbsd.org 2026/10/02 05:24:18 Modified files: sys/dev/ic : qwx.c Log message: also sync qwx DMA memory before updating the ring pointer via sc->ops.write32 CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 06:12:51 Modified files: usr.bin/tmux : cmd-copy-mode.c Log message: Do not use client for copy-mode -S if NULL, reported by Martin Vlach. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 06:23:44 Modified files: usr.bin/tmux : cmd-swap-pane.c Log message: Restore the zoom when swap-pane refuses a floating pane, GitHub issue 5660 from Alexandre Fiori. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 06:28:07 Modified files: usr.bin/tmux : cfg.c server-client.c tmux.h Log message: Do not leak client if lost before configuration is loaded, and do not load multiple times. GitHub issues 5661 and 5662 from Alexandre Fiori. CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/02 06:28:20 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: backport sync DMA memory from qwx Backport of sys/dev/ic/qwx.c,v 1.140 and 1.146 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/02 06:41:35 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: backport of olatile casts from qwx Backport of sys/dev/ic/qwx.c,v 1.114 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/02 06:48:20 Removed files: sbin/isakmpd : BUGS DESIGN-NOTES QUESTIONS README TO-DO Log message: these files are completely historical and not helping improve things CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 06:48:52 Modified files: usr.bin/tmux : cmd-attach-session.c cmd-join-pane.c cmd-resize-pane.c cmd-split-window.c layout.c screen-redraw.c screen-write.c server-client.c tmux.h tty.c window-copy.c window.c Log message: Instead of redrawing the entire pane or scene when moving or redrawing a pane, add damage rectangles and redraw only the affected spans. From Michael Grant. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 06:53:26 Modified files: usr.bin/tmux : screen-write.c Log message: Sync redraw should use the given rows not the scroll region now. CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/02 07:18:07 Modified files: sys/dev/usb : usb_subr.c Log message: sys/usb: validate USB endpoint and configuration lengths Reject undersized endpoint descriptors before accessing wMaxPacketSize; require wTotalLength to cover the configuration header and match the allocated size after the full fetch. Reported by Stuart Thomas OK: deraadt@ CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 07:20:42 Modified files: usr.bin/tmux : spawn.c Log message: Change to the new working directory even if getcwd fails, GitHub issue 5658. CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/02 08:13:44 Modified files: usr.sbin/rpki-client: output-rtrx.c Log message: output-rtrx: place one brace on the proper line CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 08:16:42 Modified files: usr.bin/tmux : screen-write.c Log message: Only skip collecting text except for right margin when autowrap is off, from Jang-Ho Hwang. CVSROOT: /cvs Module name: ports Changes by: robert@cvs.openbsd.org 2026/10/02 08:17:25 Modified files: www/ungoogled-chromium: Makefile distinfo www/ungoogled-chromium/patches: patch-chrome_browser_picture_in_picture_picture_in_picture_window_manager_cc patch-content_browser_web_contents_web_contents_impl_cc patch-gpu_command_buffer_service_gles2_cmd_decoder_cc patch-gpu_command_buffer_service_shared_image_external_vk_image_backing_factory_cc patch-third_party_fontconfig_include_meson-config_h patch-third_party_test_fonts_fontconfig_BUILD_gn Removed files: www/ungoogled-chromium/patches: patch-third_party_test_fonts_fontconfig_generate_fontconfig_caches_cc Log message: update to 154.0.8037.92; ok naddy@ CVSROOT: /cvs Module name: ports Changes by: robert@cvs.openbsd.org 2026/10/02 08:18:13 Modified files: x11/mate/settings-daemon: Makefile x11/mate/settings-daemon/pkg: PLIST Log message: add missing @sample for org.mate.SettingsDaemon.DateTimeMechanism.conf; ok naddy@ CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 09:04:27 Modified files: usr.bin/tmux : options-table.c Log message: Quote session_alert in status-format[2], GitHub issue 5671. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 09:13:07 Modified files: usr.bin/tmux : cmd-display-message.c Log message: Modify display-message -c target-client to use the data relative to target-client, GitHub issue 5613 from Michael Grant. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/02 09:20:41 Modified files: usr.bin/tmux : screen-write.c window-visible.c Log message: Include menus when working out what parts of a pane are visible to avoid overwriting them, GitHub issue 5593. CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/02 10:43:17 Modified files: usr.bin/mandoc : msec.c Log message: When converting a section identifier (for example, "1" or "1m") to a volume title (for example, "General Commands Manual" or "Maintenance Commands") and no exact match is found for the identifier, retry using only the first character of the identifier before giving up. For example, when using OpenBSD to format the Oracle Solaris ipmitool(1m) manual, which contains the line '.TH ipmitool 1m "29 June 2012"', use the section 1 volume title "General Commands Manual" rather than finding no title at all. In general, this improves formatting of the page header line of manual pages using session suffixes that are not declared in msec.in on the formatting system. That's useful everywhere for formatting foreign manual pages, but also for formatting native manuals on systems using many suffixes. I had this idea for a small improvement while looking at how FreeBSD customizes the companion file msec.in in their freebsd-src/contrib/mandoc directory. CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/02 10:48:01 Modified files: regress/usr.bin/mandoc/man/TH: Makefile regress/usr.bin/mandoc/mdoc/Dt: Makefile Added files: regress/usr.bin/mandoc/man/TH: secsuffix.in secsuffix.out_ascii regress/usr.bin/mandoc/mdoc/Dt: secsuffix.in secsuffix.out_ascii secsuffix.out_markdown Log message: test handling of session suffixes in the .Dt and .TH macros; related to msec.c rev. 1.14 CVSROOT: /cvs Module name: src Changes by: rsadowski@cvs.openbsd.org 2026/10/02 12:06:20 Modified files: usr.sbin/relayd: relay_http.c Log message: relayd: do not treat a missing Host header as a url match Return RES_BAD if the request has no Host header, consistent with the handling of empty or malformed Host values. Spotted by Acts1631 (with diff), OK kirill@ CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/02 16:47:02 Modified files: lib/libexpat : Changes lib/libexpat/lib: internal.h xmlparse.c xmlrole.c xmlrole.h xmltok.c xmltok.h xmltok_impl.c xmltok_ns.c lib/libexpat/tests: basic_tests.c memcheck.c nsalloc_tests.c Log message: Backport fixes from libexpat version 2.8.5. Relevant for OpenBSD are security fixes #1282, bug fixes #1346 #1371, other changes #1354 #1357 #1349 #1360 #1378. Library bump is not necessary. CVE-2026-93990 OK deraadt@ CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/02 18:46:29 Modified files: usr.bin/ssh : readconf.c Log message: make StreamLocalBindMask properly respect Host/Match blocks and make it first-match-wins as documented. bz4013 CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/02 18:46:58 Modified files: usr.bin/ssh : servconf.c Log message: make StreamLocalBindMask properly first-match-wins; spotted while fixing bz4013 CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/02 19:06:40 Modified files: sbin/isakmpd : policy.c Log message: incorrect object being freed from Franz Bettag / Bettag Systems ok markus hshoexer sthen mvs CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/02 19:14:34 Modified files: sbin/isakmpd : ike_quick_mode.c message.c Log message: IKEv1 short-HASH heap overflow; second approach for fix from Franz Bettag / Bettag Systems ok sthen mvs CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/02 19:15:47 Modified files: sbin/isakmpd : x509.c Log message: knf CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/02 19:31:30 Modified files: sbin/isakmpd : conf.c conf.h connection.c connection.h exchange.c exchange.h field.c field.h ike_auth.c ipsec.c isakmpd.8 isakmpd.c log.c log.h message.c message.h monitor.c monitor.h nat_traversal.c pf_key_v2.c policy.c sa.c sa.h timer.c timer.h transport.c transport.h udp.c udp_encap.c ui.c ui.h util.c util.h virtual.c Log message: Franz Bettag sent a report & diff repairing the privsep monitor's dangerous file behavior in /var/run, and I was shocked at what it does. isakmpd never had a proper diagnosis and control program like other daemons do, and instead accepts weird commands on a fifo and splats files dangerously. Some path names can be manipulated. This 2600 line diff removes all of this session debugging mechanism which is the main cause of that unsafe design. There are no reuseable parts in that code (it cannot be reconstructed into a proper control program interface). As a result, the privsep monitor now has unveil to the config directory, and the network speaking process is "stdio sendfd route recvfd inet". There is some loss of functionality, since some users had gotten used to the decrepit debugging / logging interface to repair sessions which would not negotiate. This is almost completely unmaintained code from early OpenBSD days with an incorrect privsep design, and many users have migrated to using iked(8) which does IKEv2 protocol. RFC9395 also provides valuable guidance here. Everyone is urged to avoid using this program. If IKEv1 protocol is still a part of your life roll up sleeves and try to write a high-quality control interface using lessons from the IKEv2 iked(8) code. Great conversations and help from Franz Bettag finding code to delete. comments & tests from sthen mvs robert; also ok markus bluhm hshoexer CVSROOT: /cvs Module name: src Changes by: rcovelli@cvs.openbsd.org 2026/10/02 19:32:37 Modified files: usr.sbin/rtrd : sockets.c Log message: Use SOCK_NONBLOCK and handle fcntl() failures. OK deraadt@ CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/02 19:38:25 Modified files: sbin/isakmpd : policy.c Log message: The path generation must not contain '..' or '/' type patterns or it can walk upwards and sideways. The privsep open() is now restricted by a single unveil() inside the config directory, but files in relative config directories can still be reached and create potentially confusing outcomes. This is half of a repair from Franz Bettag before I restructured the privsep to use unveil(), the other half of the repair is not needed because it applies to code that no longer exists. ok markus hshoexer bluhm, testing sthen mvs CVSROOT: /cvs Module name: src Changes by: rcovelli@cvs.openbsd.org 2026/10/02 20:45:47 Modified files: usr.sbin/rpki-client: output-rtrx.c Log message: Use SOCK_NONBLOCK where we can. Handle errors for fcntl(). CID 656886, CID 656887 OK deraadt@ tb@ CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/02 21:23:40 Modified files: . : 80.html Log message: httpd8() -> httpd(8) CVSROOT: /cvs Module name: src Changes by: mlarkin@cvs.openbsd.org 2026/10/02 22:10:50 Modified files: usr.sbin/vmd : x86_vm.c Log message: vmd(8): fix mmio exit issue on old SVM machines fix a problem where we didn't pass any instruction length to insn_decode on some older opterons that don't have SVM decode assist. ok dv CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/02 22:25:19 Modified files: . : 80.html Log message: previous release was 7.9 CVSROOT: /cvs Module name: src Changes by: dtucker@cvs.openbsd.org 2026/10/02 23:08:49 Modified files: regress/usr.bin/ssh: percent.sh Log message: Add test for proxycommand percent expansions. CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/03 00:36:08 Modified files: . : 80.html Log message: em(1) -> em(4) CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/03 03:41:30 Modified files: sys/dev/ic : ufshci.c Log message: sys/ufshci: increase poll's wait to 500ms This matches Linux timeout and makes ufshci survives a suspend on HONOR MagicBook Art 14 Snapdragon 500ms value which matches Linux suggested by kettenis@ OK: mglocker@ CVSROOT: /cvs Module name: www Changes by: tb@cvs.openbsd.org 2026/10/03 05:23:34 Modified files: . : 80.html Log message: libressl 4.4.0 these are essentially the portable release notes, with the portable bits compressed to an absolute minimum, as there were way too many of those (thanks Kartik and Kenjiro) CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/03 08:03:49 Modified files: usr.bin/mandoc : mdoc_validate.c Log message: If the -width of a .Bl macro is of the form ".word text", use only the text for measuring the width, assuming the word is a macro, as a crude approximation of what groff_mdoc(7) does: it sets the argument in a diversion and measures the width of the diversion. Ugly formatting first reported by Franco Fichtner (DragonFly BSD) in 2013, this partial fix first suggested by me in the mandoc TODO file in 2013, then implemented by Eric van Gyzen (FreeBSD) in 2022. My fix committed here is slightly smaller than Eric's FreeBSD fix, does not need an extra function, and stays closer to groff behaviour. CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/03 08:20:33 Modified files: regress/usr.bin/mandoc/mdoc/Bd: offset-empty.in offset-empty.out_ascii offset-empty.out_markdown offset-neg.in offset-neg.out_ascii offset-neg.out_markdown regress/usr.bin/mandoc/mdoc/Bl: Makefile offset.in offset.out_ascii offset.out_markdown Added files: regress/usr.bin/mandoc/mdoc/Bl: width.in width.out_ascii width.out_markdown Log message: test macros in .Bl and .Bd -width and -offset arguments; related to mdoc_validate.c rev. 1.313 CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/03 11:35:09 Modified files: sbin/isakmpd : Tag: OPENBSD_7_8 conf.c conf.h connection.c connection.h exchange.c exchange.h field.c field.h ike_auth.c ike_quick_mode.c ipsec.c isakmpd.8 isakmpd.c log.c log.h message.c message.h monitor.c monitor.h pf_key_v2.c policy.c sa.c sa.h timer.c timer.h transport.c transport.h udp.c udp_encap.c ui.c ui.h util.c util.h virtual.c Log message: incorrect object being freed from Franz Bettag / Bettag Systems from deraadt@; OK markus@ hshoexer@ sthen@ mvs@ IKEv1 short-HASH heap overflow; second approach for fix from Franz Bettag / Bettag Systems from deraadt@; OK sthen@ mvs@ Franz Bettag sent a report & diff repairing the privsep monitor's dangerous file behavior in /var/run, and I was shocked at what it does. isakmpd never had a proper diagnosis and control program like other daemons do, and instead accepts weird commands on a fifo and splats files dangerously. Some path names can be manipulated. This 2600 line diff removes all of this session debugging mechanism which is the main cause of that unsafe design. There are no reuseable parts in that code (it cannot be reconstructed into a proper control program interface). As a result, the privsep monitor now has unveil to the config directory, and the network speaking process is "stdio sendfd route recvfd inet". There is some loss of functionality, since some users had gotten used to the decrepit debugging / logging interface to repair sessions which would not negotiate. This is almost completely unmaintained code from early OpenBSD days with an incorrect privsep design, and many users have migrated to using iked(8) which does IKEv2 protocol. RFC9395 also provides valuable guidance here. Everyone is urged to avoid using this program. If IKEv1 protocol is still a part of your life roll up sleeves and try to write a high-quality control interface using lessons from the IKEv2 iked(8) code. Great conversations and help from Franz Bettag finding code to delete. from deraadt@; comments & tests from sthen@ mvs@ robert@; also OK markus@ bluhm@ hshoexer@ The path generation must not contain '..' or '/' type patterns or it can walk upwards and sideways. The privsep open() is now restricted by a single unveil() inside the config directory, but files in relative config directories can still be reached and create potentially confusing outcomes. This is half of a repair from Franz Bettag before I restructured the privsep to use unveil(), the other half of the repair is not needed because it applies to code that no longer exists. from deraadt@; OK markus@ hshoexer@ bluhm@; testing sthen@ mvs@ this is errata/7.8/067_isakmpd.patch.sig CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/03 11:35:48 Modified files: sbin/isakmpd : Tag: OPENBSD_7_9 conf.c conf.h connection.c connection.h exchange.c exchange.h field.c field.h ike_auth.c ike_quick_mode.c ipsec.c isakmpd.8 isakmpd.c log.c log.h message.c message.h monitor.c monitor.h pf_key_v2.c policy.c sa.c sa.h timer.c timer.h transport.c transport.h udp.c udp_encap.c ui.c ui.h util.c util.h virtual.c Log message: incorrect object being freed from Franz Bettag / Bettag Systems from deraadt@; OK markus@ hshoexer@ sthen@ mvs@ IKEv1 short-HASH heap overflow; second approach for fix from Franz Bettag / Bettag Systems from deraadt@; OK sthen@ mvs@ Franz Bettag sent a report & diff repairing the privsep monitor's dangerous file behavior in /var/run, and I was shocked at what it does. isakmpd never had a proper diagnosis and control program like other daemons do, and instead accepts weird commands on a fifo and splats files dangerously. Some path names can be manipulated. This 2600 line diff removes all of this session debugging mechanism which is the main cause of that unsafe design. There are no reuseable parts in that code (it cannot be reconstructed into a proper control program interface). As a result, the privsep monitor now has unveil to the config directory, and the network speaking process is "stdio sendfd route recvfd inet". There is some loss of functionality, since some users had gotten used to the decrepit debugging / logging interface to repair sessions which would not negotiate. This is almost completely unmaintained code from early OpenBSD days with an incorrect privsep design, and many users have migrated to using iked(8) which does IKEv2 protocol. RFC9395 also provides valuable guidance here. Everyone is urged to avoid using this program. If IKEv1 protocol is still a part of your life roll up sleeves and try to write a high-quality control interface using lessons from the IKEv2 iked(8) code. Great conversations and help from Franz Bettag finding code to delete. from deraadt@; comments & tests from sthen@ mvs@ robert@; also OK markus@ bluhm@ hshoexer@ The path generation must not contain '..' or '/' type patterns or it can walk upwards and sideways. The privsep open() is now restricted by a single unveil() inside the config directory, but files in relative config directories can still be reached and create potentially confusing outcomes. This is half of a repair from Franz Bettag before I restructured the privsep to use unveil(), the other half of the repair is not needed because it applies to code that no longer exists. from deraadt@; OK markus@ hshoexer@ bluhm@; testing sthen@ mvs@ this is errata/7.9/031_isakmpd.patch.sig CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/03 11:49:34 Modified files: lib/libexpat : Tag: OPENBSD_7_8 Changes lib/libexpat/lib: Tag: OPENBSD_7_8 internal.h xmlparse.c xmlrole.c xmlrole.h xmltok.c xmltok.h xmltok_impl.c xmltok_ns.c lib/libexpat/tests: Tag: OPENBSD_7_8 basic_tests.c memcheck.c nsalloc_tests.c Log message: Backport fixes from libexpat version 2.8.5. Relevant for OpenBSD are security fixes #1282, bug fixes #1346 #1371, other changes #1354 #1357 #1349 #1360 #1378. Library bump is not necessary. CVE-2026-93990 OK deraadt@ this is errata/7.8/069_expat.patch.sig CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/03 11:50:11 Modified files: lib/libexpat : Tag: OPENBSD_7_9 Changes lib/libexpat/lib: Tag: OPENBSD_7_9 internal.h xmlparse.c xmlrole.c xmlrole.h xmltok.c xmltok.h xmltok_impl.c xmltok_ns.c lib/libexpat/tests: Tag: OPENBSD_7_9 basic_tests.c memcheck.c nsalloc_tests.c Log message: Backport fixes from libexpat version 2.8.5. Relevant for OpenBSD are security fixes #1282, bug fixes #1346 #1371, other changes #1354 #1357 #1349 #1360 #1378. Library bump is not necessary. CVE-2026-93990 OK deraadt@ this is errata/7.9/033_expat.patch.sig CVSROOT: /cvs Module name: www Changes by: kirill@cvs.openbsd.org 2026/10/03 12:33:27 Modified files: . : 80.html Log message: Added specific improvments for HONOR's MagicBook CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/03 13:15:49 Modified files: regress/usr.sbin/rpki-client/openssl: unistd.h Log message: rpki-client regress: this unistd.h hack needs to include x509.h CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/03 19:44:27 Modified files: . : 80.html Log message: Chromium 154.0.8037.92 CVSROOT: /cvs Module name: www Changes by: deraadt@cvs.openbsd.org 2026/10/03 21:22:31 Modified files: . : 80.html plus.html Log message: AES cpu instructions is what made it faster.. CVSROOT: /cvs Module name: src Changes by: gnezdo@cvs.openbsd.org 2026/10/03 22:45:55 Modified files: sys/kern : sysv_shm.c Log message: sysv_shm: claim the vm_shm slot after uvm_map(), not before sys_shmat() chose a free slot in the per-vmspace vm_shm array, then slept in uvm_map(), then published into the slot it had chosen. Nothing marked the slot taken across the sleep, so a sibling thread entering sys_shmat() scanned the same array, found the same slot still reading -1, and took it too. Both uvm_map() calls succeed at different addresses and the thread that stores last wins; the other mapping is left with no vm_shm entry, so shmdt() returns EINVAL for it and shmexit() cannot drop its shm_nattch. The permanently raised count keeps IPC_RMID from deallocating the segment, which then sits in shmsegs[] reachable by nobody; 128 of those and shmget() returns ENOSPC system-wide. uvm_map() is the only sleep between choosing the slot and filling it in, so moving the scan below the map closes the window without a reserved state that shmdt(), shmexit() and shmfork() would each have to learn about. EMFILE is now discovered after the mapping exists, so that path undoes it. While here, balance the uao reference on the uvm_map() failure path: a failed uvm_map() does not consume the caller reference, so two were outstanding and the deallocate arm dropped only one. r1.88 already unpublishes the segment before shm_deallocate_segment(), so the detach can be done unconditionally and first. OK mvs@ Reported-by: Acts1631 CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/04 03:15:09 Modified files: lib/libcrypto/bytestring: bytestring.h lib/libssl : bytestring.h Log message: libcrypto/bytestring: remove LIBRESSL_INTERNAL from bytestring.h This currently marks the LibreSSL-specific additions to this API. It has no effect other than getting in the way of other projects wanting to use this since it is always compiled with LIBRESSL_INTERNAL. ok kenjiro CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/04 03:19:19 Modified files: lib/libcrypto/bytestring: bytestring.h lib/libssl : bytestring.h Log message: libcrypto/bytestring: add some missing tag classes This adds tags for NULL, PrintableString, UTCTime, and GeneralizedTime with names matching BoringSSL. ok kenjiro CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/04 03:23:40 Modified files: lib/libcrypto/bytestring: bytestring.h lib/libssl : bytestring.h Log message: libcrypto/bytestring.h: make parentheses line up again whitespace-only change CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/04 03:37:56 Added files: usr.sbin/rpki-client: bs_ber.c bs_cbb.c bs_cbs.c bytestring.h Log message: rpki-client: add a copy of libcrypto's bytestring API This will be used to replace the terrible CMS API from libcrypto. Longer term this might also be used to implement better parsers for certs, CRLs and the signed objects' eContent. discussed with claudio and job ok beck CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/04 03:39:02 Modified files: usr.sbin/rpki-client: Makefile Log message: rpki-client: link bytestring API to the build ok beck CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/04 03:40:27 Modified files: regress/usr.sbin/rpki-client: Makefile.inc Log message: rpki-client regress: link bytestring API to the build CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/04 04:18:13 Modified files: regress/lib/libcrypto/objects: objectstest.c Log message: objectstest: succeded -> succeeded CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 07:31:56 Modified files: usr.sbin/rtrd : cache.c commands.c hash.c Log message: more knf CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 07:33:33 Modified files: usr.sbin/rpc.statd: statd.c Log message: O_NONBLOCK is the modern name (with 2 legacy userland defines and 2 legacy kernel defines, not sure when all of that will collapse) CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 07:44:51 Modified files: sbin/isakmpd : udp.c Log message: using sizeof is recommended practice CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 08:24:54 Modified files: libexec/ld.so : ld.so.1 library_subr.c Log message: surprised this page did not Xr ldd 1 CVSROOT: /cvs Module name: www Changes by: bcook@cvs.openbsd.org 2026/10/04 10:54:37 Modified files: libressl : index.html releases.html Log message: LibreSSL 4.2.2, 4.3.3, 4.4.0rc1 CVSROOT: /cvs Module name: www Changes by: schwarze@cvs.openbsd.org 2026/10/04 12:01:03 Modified files: . : 80.html Log message: Diverse small improvements: * mention import of rtrctl(8) * remove entries for three minor rtrd(8) fixes; it wasn't in 7.9 and its addition to 8.0 is listed in another entry * remove a duplicate entry regarding httpd(8) server flags * remove entry for a mandoc(1) regression that wasn't in 7.9 but only happened in -current for a few weeks * unveil(2) changes don't affect mandoc(1), talk about man(1) instead * add many missing manual page links * fix broken smte(4) manual page link * fix indentation of three subheaders in the OpenSSH section * remove a couple of duplicate subheader lines * remove one stray word and one instance of s/nul byte/NUL byte/ CVSROOT: /cvs Module name: www Changes by: schwarze@cvs.openbsd.org 2026/10/04 12:19:33 Modified files: . : innovations.html Log message: add getexecpath(3), watch(1), rtrd(8), rtrctl(8) CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 13:32:14 Modified files: libexec/ld.so : library_subr.c Log message: Oops, this proposal isn't ready yet. accidental commit spotted by by caspar CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 13:53:46 Modified files: usr.bin/ypwhich: ypwhich.c Log message: remove accidental test code from 1994 which neutered parts of the intended behaviour. ok miod CVSROOT: /cvs Module name: src Changes by: krw@cvs.openbsd.org 2026/10/04 15:12:18 Modified files: sys/uvm : uvm_swap.c Log message: Reserve a 16K-byte gap at the start of a swap partition. Swap currently reserves PAGE_SIZE (4K, 8K or 16K depending on arch) bytes as potential space for a disklabel and boot code. A disklabel can be placed in the first or second DEV_BSIZE bytes of swap, with some arch's needing up to 6 * DEV_BSIZE additional bytes for boot code and arch dependent disklabel info. New disklabel code will need to store a bigger disklabel structure in 3 * DEV_BSIZE bytes of the *FIRST VIABLE PARTITION WITH A GAP*. VIABLE PARTITIONS are filesystems (ffs and swap in particular) which have a sufficiently large gap. Increasing the swap partition gap makes it much more likely that those bytes will be available. Suggested by & ok deraadt@ CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/04 18:43:41 Modified files: sys/dev/pci/drm: drm_atomic_uapi.c Log message: drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr From Thadeu Lima de Souza Cascardo daefd7ff159b0d1fb8c9e64430dcbe2aca1bdd09 in linux-6.18.y/6.18.54 9eb1a393c89a79c4210230d23e7d88d239c61d7b in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/04 18:46:45 Modified files: sys/dev/pci/drm/amd/amdgpu: nbio_v7_9.c Log message: drm/amdgpu: check ras and obj before dereference From Dmitriy Chumachenko 37583946d8751f8e285c467d770ac0b609b82a23 in linux-6.18.y/6.18.54 723d4dc628d764b19cf9efca14b82cca5ff020c9 in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/04 18:49:52 Modified files: sys/dev/pci/drm/amd/amdgpu: amdgpu_device.c Log message: drm/amdgpu: fix rmmio iounmap skipped on device removal From Chengjun Yao cd55dde2b63789a3dafe982c89844f537501d096 in linux-6.18.y/6.18.54 5155002b03b24ba3ef91c5c313b8cf0171b24904 in mainline linux CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 18:51:56 Modified files: usr.sbin/rarpd : rarpd.c Log message: NULL not 0 CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/04 18:52:22 Modified files: sys/dev/pci/drm/amd/amdgpu: amdgpu_dma_buf.c Log message: drm/amdgpu: lock bo before calling amdgpu_vm_bo_update_shared From Pierre-Eric Pelloux-Prayer 801d8647dcb0d34f0654b11f932e4ed365092c5e in linux-6.18.y/6.18.54 36ffc58b8a8704e690a0ce679db26baa5759256f in mainline linux CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 18:53:57 Modified files: sys/kern : vfs_syscalls.c Log message: remove very unneccessary temporary variable CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/04 18:54:24 Modified files: sys/dev/pci/drm/amd/amdgpu: amdgpu_dma_buf.c Log message: drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments From Mike Lothian aeaa7bdc0ea2c725331a423575bb7f93c040f8fb in linux-6.18.y/6.18.54 636139603b99d2e3a18a46cf3f8d39313ce8042e in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/04 20:35:19 Modified files: sbin/isakmpd : isakmpd.8 Log message: remove comma after final SEE ALSO reference CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/04 20:49:26 Modified files: lib/libc/sys : open.2 Log message: the 1.57 chunk mentioning O_CREAT and O_DIRECTORY failed to use .Dv CVSROOT: /cvs Module name: src Changes by: dtucker@cvs.openbsd.org 2026/10/05 00:03:40 Modified files: usr.bin/ssh : readconf.c Log message: Further restrict the characters allowed in a command-line supplied user name, disallowing '$' and '\'. Reported by SecBuddyF KeenLab Tencent (CodeBuddy Security). CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/05 01:10:24 Modified files: usr.sbin/rpki-client: nca.c Log message: rpki-client: remove my copyright from nca.c The first iteration was based on my code but not a lot of that remains. This is clearly Job's baby. discussed with job CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/05 01:17:49 Modified files: usr.sbin/bgpd : parse.y Log message: Const correct the return value of the strchr call. In C23 the strchr family of functions returns a const char * if the input string is const. OK tb@ CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/05 01:18:11 Modified files: usr.sbin/bgpctl: parser.c Log message: Const correct the return value of the strchr call. In C23 the strchr family of functions returns a const char * if the input string is const. OK tb@ CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/05 01:18:51 Modified files: usr.sbin/bgpd : bgpd.8 Log message: Add RFC 6811 - BGP Prefix Origin Validation to the STANDARDS section OK tb@ CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/05 01:22:17 Modified files: usr.sbin/bgpd : bgpd.8 Log message: Properly sort RFC by number. Noticied by tb@ CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 01:27:31 Modified files: sys/dev/pci/drm/amd/display/amdgpu_dm: amdgpu_dm.c amdgpu_dm.h amdgpu_dm_crtc.c amdgpu_dm_helpers.c amdgpu_dm_irq.c amdgpu_dm_irq.h Log message: drm/amd/display: Atomize IRQ register read/modify/write ops From Leo Li 2945d3eb73d614c974a653a79e9a7a7e909db5ef in linux-6.18.y/6.18.55 63e19ef3ddab806c472748c825f4dc88dcd994e8 in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 01:30:39 Modified files: sys/dev/pci/drm/i915/display: intel_cursor.c intel_display_types.h intel_psr.c skl_universal_plane.c Log message: drm/i915/psr: Clear stale sel fetch enable bits on sel fetch disable From Nemesa Garg 8b661a045082ca756dfd09a4d47f7c1466deb472 in linux-6.18.y/6.18.55 2777ec9852277a06ae68fee0c4f1a32783e4a999 in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 01:33:15 Modified files: sys/dev/pci/drm/i915/gem: i915_gem_object.c Log message: drm/i915: fix incorrect RCU teardown order From Christian Koenig cc890d3f1b15bf6481dc7270fba0b4fbba572813 in linux-6.18.y/6.18.55 d2da6696e0c4e60414706e607029d0bb0330c67e in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 01:35:27 Modified files: sys/dev/pci/drm/i915/display: intel_dp_mst.c Log message: drm/i915/dp_mst: Fix configuring FEC for a disconnected stream From Imre Deak 369f4e32643746b35189ad2ceefa2307577ca4e7 in linux-6.18.y/6.18.55 acbe9a3b60b9a6ace8ef11fe898f586251c84592 in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 01:37:51 Modified files: sys/dev/pci/drm/i915/display: intel_dp_mst.c intel_dp_mst.h intel_link_bw.c Log message: drm/i915/dp_mst: Fix configuring TUs for a disconnected stream From Imre Deak fe933dda0bb1814cbc4e68a9b21792f8b959d8c3 in linux-6.18.y/6.18.55 a443e0b8d647c1401b110d9f919d8c6cb8607260 in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 01:52:15 Modified files: sys/dev/pci/drm/amd/display/amdgpu_dm: amdgpu_dm.c Log message: drm/amd/display: Fix dc stream excess put in dm_update_crtc_state() From Wentao Liang 89a11c7efe387294aab342c3ddcdff0a4744cb0a in linux-6.18.y/6.18.55 c5fd4eaad50d620c7e09ac2082b2fb55ee54170e in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 01:55:51 Modified files: sys/dev/pci/drm/amd/amdgpu: amdgpu_vm.c Log message: drm/amdgpu: Fix last_update fence leak in amdgpu_vm_init() From Wentao Liang 0bfb0419a1480d71b53bb65f656764318993974c in linux-6.18.y/6.18.55 b4f7b4459b1b155e4c4977a6482b5df2cf08758c in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 01:57:40 Modified files: sys/dev/pci/drm/amd/amdgpu: amdgpu_debugfs.c Log message: drm/amdgpu: Fix runtime PM leak in amdgpu_debugfs_test_ib_show() From Wentao Liang c28e74395ab09922bbf5be42bc5a6ed1ba4f3c37 in linux-6.18.y/6.18.55 2b86ab1bd6673c525adda88819d7658ba9e784ec in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 01:59:51 Modified files: sys/dev/pci/drm/amd/amdgpu: amdgpu_ring.c Log message: drm/amdgpu: Fix vmid_wait fence leak in amdgpu_ring_init() From Wentao Liang c83261854e19a58ff80d6ae46715f0b0ed9e8776 in linux-6.18.y/6.18.55 aea841bc62a76242396610d22d8ff40c13065f64 in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 02:02:00 Modified files: sys/dev/pci/drm/i915/display: intel_psr.c intel_quirks.c intel_quirks.h Log message: drm/i915/psr: Disable Panel Replay on Dell XPS 14 DA14260 as a quirk From Jouni Hogander 782b5210e89e76ddaa228ec64a1620244dd2ccfc in linux-6.18.y/6.18.55 45c77d4bf8d4d15453d709b9b828e498898e0751 in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 02:03:50 Modified files: sys/dev/pci/drm/i915/display: intel_psr.c intel_quirks.c intel_quirks.h Log message: drm/i915/psr: Fixes for Dell XPS DA14260 quirk From Jouni Hogander 66f814e8af4627c769c4d148bb8efb48cef79571 in linux-6.18.y/6.18.55 1de647abdfda9dc307503d0a85152161850ba52c in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 02:05:44 Modified files: sys/dev/pci/drm/i915/display: intel_psr.c intel_quirks.c intel_quirks.h Log message: drm/i915/psr: Disable PSR2 on Xiaomi Book Pro 14 2026 as a quirk From Jouni Hogander 97e40aa29c10c72cb4fc02c39a63a64e3f17705d in linux-6.18.y/6.18.55 5e79af5db00b2a5f4667aaf16cfe4ecb7759383b in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 02:07:57 Modified files: sys/dev/pci/drm/i915/display: intel_quirks.c Log message: drm/i915/quirks: Limit eDP rate to HBR2 on HP Pavilion Plus 14-ew1 From Ankit Nautiyal 13f299763f6c065210206ea0f17a149ec6c500bd in linux-6.18.y/6.18.55 5271d81f99dd01d983d439930eb056952485e15e in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 02:09:57 Modified files: sys/dev/pci/drm/amd/amdgpu: amdgpu_acpi.c Log message: drm/amdgpu: Fix acpi device leak in amdgpu_acpi_enumerate_xcc() From Wentao Liang 817dd706ee6165812225581bebda038153120ba3 in linux-6.18.y/6.18.55 a997baa61179b450bd55c4810c7ccfed3b753a54 in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 02:14:58 Modified files: sys/dev/pci/drm: drm_client_event.c drm_modeset_helper.c sys/dev/pci/drm/amd/amdgpu: amdgpu_device.c sys/dev/pci/drm/clients: drm_fbdev_client.c drm_log.c sys/dev/pci/drm/i915: i915_driver.c sys/dev/pci/drm/include/drm: drm_client.h drm_client_event.h sys/dev/pci/drm/radeon: radeon_device.c Log message: drm/client: Remove holds_console_lock parameter from suspend/resume From Thomas Zimmermann 0589706ace3bdd47a821d66036d36402918cc2a7 in linux-6.18.y/6.18.55 7910d69376cde30e5871970d97d1a2e360568474 in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 02:20:26 Modified files: sys/dev/fdt : rkdrm.c sys/dev/pci/drm: drm_client_event.c drm_fb_helper.c drm_file.c sys/dev/pci/drm/amd/amdgpu: amdgpu_drv.c sys/dev/pci/drm/apple: apldrm.c sys/dev/pci/drm/clients: drm_fbdev_client.c sys/dev/pci/drm/i915: i915_driver.c sys/dev/pci/drm/include/drm: drm_client.h drm_client_event.h drm_fb_helper.h sys/dev/pci/drm/radeon: radeon_drv.c Log message: drm/client: Pass force parameter to client restore From Thomas Zimmermann 933145e2bbb4cab6007b26d17f7f1722f14c5440 in linux-6.18.y/6.18.55 943240d342f148896733eb6c7b223a08aa1f520a in mainline linux CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/05 02:22:54 Modified files: sys/dev/pci/drm/clients: drm_fbdev_client.c Log message: drm/client: fix restore of partially initialized client From shechenglong fcbedba553a9c430079ee225df2dc7ab556a2f83 in linux-6.18.y/6.18.55 1fca688e9443003e33cf30453e7a7560367656c9 in mainline linux CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/05 02:32:24 Modified files: usr.bin/tmux : utf8-combined.c utf8.c Log message: Adjust widths of a few codepoints incorrectly set to double width, from Sidney Cammeresi. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/05 02:41:23 Modified files: usr.bin/tmux : screen-write.c Log message: Do not lose a pending pane resize when entering the alternate screen, from mml00 dot work at gmail dot com. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/05 02:45:27 Modified files: usr.bin/tmux : tty.c Log message: Fix color range check, from Vaibhav Aggarwal. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/05 03:03:11 Modified files: usr.bin/tmux : options-table.c Log message: Use window-status-separator in second and theird status lines, GitHub issue 5672. Also match width of session name correctly. CVSROOT: /cvs Module name: src Changes by: sthen@cvs.openbsd.org 2026/10/05 03:12:56 Modified files: etc/examples : iked.conf Log message: add a section to examples/iked.conf showing use of the peer's srcid to distinguish between clients with different configurations where it's not possible to separate by IP address (e.g. for clients on dynamic IP, or multiple clients behind a single NAT). CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/05 03:54:05 Modified files: usr.bin/ssh : version.h Log message: openssh-10.6 CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/05 04:59:37 Modified files: usr.bin/tmux : format.c Log message: Check format time in format_skip1 before the loop as well. CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/05 06:05:40 Modified files: sys/dev/pci : if_mwx.c if_mwxreg.h Log message: First bits of scan code for the MT7925 chip. Only 2GHz is currently scanned and then it is stuck on the auth frame. Diff is already large enough. Most bits from a diff by mlarkin@ CVSROOT: /cvs Module name: ports Changes by: pvk@cvs.openbsd.org 2026/10/05 06:54:11 Modified files: www/gitea : Makefile distinfo www/gitea/patches: patch-custom_conf_app_example_ini www/gitea/pkg : PLIST Log message: Update gitea 1.27.3 - > 28.0.0 Changelogs: https://github.com/go-gitea/gitea/releases/ CVSROOT: /cvs Module name: ports Changes by: pvk@cvs.openbsd.org 2026/10/05 06:54:39 Modified files: security/vault : Makefile distinfo Log message: Update vault 2.1.0 -> 2.1.1 Changelogs: https://github.com/hashicorp/vault/releases/ CVSROOT: /cvs Module name: ports Changes by: pvk@cvs.openbsd.org 2026/10/05 06:55:07 Modified files: security/keycloak: Makefile distinfo security/keycloak/pkg: PLIST Log message: Update keycloak 26.7.3 -> 26.8.0 Changelogs: https://github.com/keycloak/keycloak/releases/ Release notes: https://www.keycloak.org/docs/latest/release_notes/index.html Upgrading guide: https://www.keycloak.org/docs/26.8.0/upgrading/ CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/05 07:45:49 Modified files: usr.bin/tmux : cmd-parse.y Log message: Do not always perform environment variable assignments inside %else, GitHub issue 5688 from Tushar Muralidharan. CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/05 07:47:05 Modified files: sys/dev/pci : if_mwx.c Log message: Hack up mt7925_mcu_hw_scan() to support 5Ghz channels as well. A better solution is needed when more channels are needed. The HW can scan 64 channels in one command which is enough for now. Also the probe req template need work but again this can wait. CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/05 07:53:04 Modified files: usr.bin/tcpbench: tcpbench.c Log message: use SOCK_NONBLOCK instead of fcntl O_NONBLOCK; ok djm CVSROOT: /cvs Module name: ports Changes by: naddy@cvs.openbsd.org 2026/10/05 07:54:13 Modified files: security/keycloak: Makefile distinfo security/keycloak/pkg: PLIST security/vault : Makefile distinfo www/gitea : Makefile distinfo www/gitea/patches: patch-custom_conf_app_example_ini www/gitea/pkg : PLIST Log message: revert unapproved commit during release lock CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/05 08:13:08 Modified files: usr.sbin/ntpd : control.c ntpd.h Log message: use accept4() with SOCK_NONBLOCK instead of seperate fcntl with O_NONBLOCK ok bcook CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/05 08:25:12 Modified files: usr.sbin/iscsid: connection.c control.c iscsid.h util.c Log message: use SOCK_NONBLOCK instead of fcntl O_NONBLOCK ok claudio CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/05 09:42:49 Modified files: lib/libz : gzwrite.c Log message: zlib: fix buffer overwrite in non-blocking gzwrite Upstream commit df84af25 CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/05 09:52:25 Modified files: usr.bin/tmux : window-copy.c Log message: Fix mouse drag selection on the top and bottom lines in vi mode, GitHub issue 5667 from David Schweikert. CVSROOT: /cvs Module name: src Changes by: miod@cvs.openbsd.org 2026/10/05 10:13:15 Modified files: sys/dev/wscons : wsdisplay.c Log message: Do not allow screen deletion while a VT switch is in progress. If done asynchronously, depending on the display driver implementation of the switching primitives, this could open a race with a risk of memory corruption. Problem found and fix provided by Acts1631. CVSROOT: /cvs Module name: src Changes by: mvs@cvs.openbsd.org 2026/10/05 12:43:46 Modified files: sys/dev/pci : if_iwi.c Log message: Fix iwi(4) build with IWI_DEBUG set. Use %td modifier for pointers difference. From Nazarenko Mykyta. CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/05 14:15:20 Modified files: regress/lib/libz: Makefile utils_unittest.cc Log message: zlib regress: unit test that segfaults without gzwrite.c 1.7 based on https://gist.github.com/thesmartshadow/e0b9481792afb7c31e86fee1ff084490 CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/05 14:27:37 Modified files: sys/dev/fdt : qcgpio_fdt.c Log message: sys/qcgpio: fix GPIO wakeup masking during suspend The suspend path disables pins marked for wakeup while leaving other GPIO interrupts enabled. Here, I reverse the condition to preserve wakeup sources and mask ordinary interrupts; restore the saved configuration on resume. OK: kettenis@ CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/05 14:34:28 Modified files: regress/lib/libz: utils_unittest.cc Log message: zlib regress: improve comment to state what it tests (gzwrite.c r1.7) CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/05 14:53:38 Modified files: sys/dev/wscons : Tag: OPENBSD_7_8 wsdisplay.c Log message: Do not allow screen deletion while a VT switch is in progress. If done asynchronously, depending on the display driver implementation of the switching primitives, this could open a race with a risk of memory corruption. Problem found and fix provided by Acts1631. from miod@ this is errata/7.8/070_wsdisplay.patch.sig CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/05 14:54:02 Modified files: sys/dev/wscons : Tag: OPENBSD_7_9 wsdisplay.c Log message: Do not allow screen deletion while a VT switch is in progress. If done asynchronously, depending on the display driver implementation of the switching primitives, this could open a race with a risk of memory corruption. Problem found and fix provided by Acts1631. from miod@ this is errata/7.9/034_wsdisplay.patch.sig CVSROOT: /cvs Module name: src Changes by: mlarkin@cvs.openbsd.org 2026/10/05 17:07:37 Modified files: usr.sbin/vmd : parse.y priv.c vm.conf.5 vmd.c vmd.h Log message: vmd(8): better handling of virtual switch descriptions in vm.conf, switch definitions can now include the keyword 'description': switch myswitch { description "foo" interface veb0 } will cause vmd to change the host veb0 interface description to "foo". switch myswitch { description interface veb0 } eg "description" by itself without a provided description, will simulate the 8.0 and previous behavior; vmd will change the host veb0 interface description to "switch%d-%s", where %d is the numerical index of the switch in vm.conf and %s is the name of the switch (in this case, myswitch): "switch1-myswitch". switch myswitch { interface veb0 } without any "description" keyword will cause vmd to not set any description on the host veb0 interface. this is suitable for situations where the administrator has already placed a description for said interface in /etc/hostname.veb0 and does not want it altered by vmd. note this change does not alter vmd behavior for descriptions on VM tapX interfaces on the host. that behavior remains the same as 8.0 and before. worked on with deraadt ok deraadt CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/06 00:55:41 Modified files: usr.sbin/rpki-client: extern.h main.c output-rtrx.c Log message: Close rtrx socket in child processes since it is opened up early. OK tb@ rcovelli@ CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/06 01:57:41 Modified files: usr.bin/tmux : window-copy.c Log message: Redraw selections after scrolling to line boundaries, GitHub issue 5689 from bugreporter23 at gmail dot com. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/06 02:01:54 Modified files: usr.bin/tmux : tmux.1 Log message: Improve text about status lines, GitHub issue 5677. CVSROOT: /cvs Module name: src Changes by: job@cvs.openbsd.org 2026/10/06 02:19:58 Modified files: usr.bin/watch : watch.c Log message: Remove 'output from previous run as dimmed text' feature The dimmed text does not display correctly on xterm with white background and the console. Requested by / OK naddy@ CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/06 02:26:23 Modified files: usr.bin/tmux : window-copy.c Log message: Fix redraw and selection position when changing selection mode. CVSROOT: /cvs Module name: src Changes by: hshoexer@cvs.openbsd.org 2026/10/06 03:58:54 Modified files: sbin/isakmpd : isakmp_cfg.c Log message: isakmpd: Bound the HASH coverage in cfg_verify_hash() The verifier assumed the HASH payload is the first payload and derived the covered length from the message length, reading past the end of the message when another payload precedes HASH. Compute the covered range from the HASH payload's actual position and reject it if it extends past the message end. from markus@, ok me deraadt@ CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/06 04:55:55 Modified files: usr.bin/tmux : server-client.c tmux.h Log message: Do not allow drags started on status line to trigger pane key bindings, GitHub issue 5692. CVSROOT: /cvs Module name: src Changes by: jca@cvs.openbsd.org 2026/10/06 05:10:05 Modified files: sys/arch/riscv64/riscv64: vector.c Log message: riscv64 vector support: actually restore vcsr/vstart The asm statements used to restore said csr mentioned the value to restore as an output operand, not an input operand. This hurts as we write what happens to be in the allocated register (here "a1") to the csr and then struct vreg. Issue spotted in build failures due to libgcrypt (mail/notmuch) and to libjpeg (games/neverball-data). The diff fixes the testsuite for both ports. ok jsing@ kettenis@ CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/06 05:30:31 Modified files: usr.bin/tmux : tmux.1 Log message: Add table for destroy-unattached. CVSROOT: /cvs Module name: www Changes by: djm@cvs.openbsd.org 2026/10/06 05:52:24 Added files: openssh/txt : release-10.6 Log message: openssh-10.6 CVSROOT: /cvs Module name: www Changes by: djm@cvs.openbsd.org 2026/10/06 05:52:58 Modified files: build : Makefile build/mirrors : openssh-ftp.html.head openssh : ftp.html index.html openbsd.html releasenotes.html openssh/txt : release-10.6 Log message: openssh-10.6 CVSROOT: /cvs Module name: www Changes by: djm@cvs.openbsd.org 2026/10/06 06:05:03 Modified files: openssh : releasenotes.html openssh/txt : release-10.6 Log message: remove stray unicode dropping CVSROOT: /cvs Module name: src Changes by: stsp@cvs.openbsd.org 2026/10/06 06:31:56 Modified files: sys/arch/amd64/conf: GENERIC sys/dev/usb : files.usb mbim.h usb.h usbcdc.h Added files: sys/dev/usb : if_uncm.c Log message: add uncm(4), a driver for USB CDC NCM (i.e. USB phone tethering) Patch by Jan Schreiber ok deraadt@ brynet@ Tested by Jan and myself with Android phones. Committed via uncm0 CVSROOT: /cvs Module name: src Changes by: stsp@cvs.openbsd.org 2026/10/06 06:38:31 Modified files: share/man/man4 : Makefile usb.4 Added files: share/man/man4 : uncm.4 Log message: Add manual page for uncm(4). From Jan Schreiber CVSROOT: /cvs Module name: src Changes by: sthen@cvs.openbsd.org 2026/10/06 06:46:30 Modified files: sys/arch/amd64/conf: GENERIC Log message: typo + whitespace CVSROOT: /cvs Module name: src Changes by: stsp@cvs.openbsd.org 2026/10/06 07:04:10 Modified files: sys/arch/amd64/conf: RAMDISK_CD Log message: enable uncm(4) in the installer on amd64 This gives us another way to do firmware-less installs over the network. CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/06 11:17:07 Modified files: build/openssh : releases.pl openssh : releasenotes.html security.html specs.html openssh/txt : draft-ietf-secsh-connect-15.txt draft-ietf-secsh-transport-14.txt preauth.adv release-1.2.3p1 release-10.6 release-2.5.1p2 release-2.9.9 release-3.2.2 release-3.2.3 release-4.0 release-4.1 release-4.7 release-4.9 release-5.6 release-5.7 release-5.8 release-6.3 release-6.5 release-6.6 release-7.0 release-7.1p2 release-7.5 release-8.0 release-8.2 release-8.6 release-9.1 release-9.3p2 release-9.4 release-9.6 release-9.8 release-9.9 rfc1349.txt rfc1928.txt rfc4335.txt socks4.protocol socks4a.protocol Log message: fix a large number of typos and spelling errors CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/06 11:31:08 Modified files: opensmtpd : donations.html security.html opensmtpd/announces: release-5.4.1.txt release-5.4.4.txt release-5.4.6.txt release-6.0.0.txt release-6.0.2.txt release-6.4.0.txt release-6.6.0.txt release-6.7.0p1.txt release-7.4.0p0.txt release-7.5.0p0.txt release-7.6.0p0.txt opensmtpd/presentations/asiabsdcon2013-smtpd: index.html Log message: fix typos and spelling errors CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/06 11:42:41 Modified files: build : mirrors.dat Log message: rsync entries without a trailing slash cause problems CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/06 11:43:31 Modified files: openbgpd : users.html Log message: fix typos CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/06 11:44:28 Modified files: . : ftp.html openbgpd : ftp.html openntpd : portable.html openssh : ftp.html portable.html rpki-client : portable.html Log message: regen CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/06 11:45:26 Modified files: usr.bin/tmux : tmux.1 Log message: Use the .Cm macro for keywords used as arguments to commands and options, mostly replacing dubious use of .Ic, but a few others as well; nicm@ agrees with the general direction. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/06 11:49:45 Modified files: usr.bin/tmux : tmux.h tty-keys.c Log message: Parse terminal replies with keys and apply them only when finished, so that a preceding Escape can be handled correctly. GitHub issue 5676 from Joan Fabrégat. CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/06 12:15:45 Modified files: build/mirrors : rpki-client-portable.html.head openntpd : index.html manual.html openntpd/txt : release-5.7p1.txt release-5.7p2.txt release-5.7p3.txt release-5.7p4.txt release-5.9p1.txt release-6.0p1.txt release-6.1p1.txt release-6.2p1.txt release-6.2p2.txt release-6.2p3.txt release-6.8p1.txt release-7.9p1.txt openrtrd : index.html rpki-client : portable.html Log message: fix typos and spelling errors CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/06 14:31:54 Modified files: usr.bin/mandoc : mdoc_macro.c regress/usr.bin/mandoc/mdoc/Bl: Makefile Added files: regress/usr.bin/mandoc/mdoc/Bl: badBd.in badBd.out_ascii badBd.out_html badBd.out_lint badBd.out_markdown Log message: When a .Bd block is broken by an .It macro and hence implicitly ended, restore the ROFF_NOFILL global parser state to what is was before the block. This fixes an assertion failure in the HTML formatter triggered by the nonsensical sequence of macros .Bl .Bd -unfilled .It that kristaps@ found in the pam_smartcard(8) manual on macOS. CVSROOT: /cvs Module name: www Changes by: naddy@cvs.openbsd.org 2026/10/06 16:34:59 Modified files: . : 80.html Log message: amd64 and i386 package count CVSROOT: /cvs Module name: www Changes by: deraadt@cvs.openbsd.org 2026/10/06 20:45:17 Modified files: . : plus.html Log message: more changes, from Brett Mahar CVSROOT: /cvs Module name: xenocara Changes by: matthieu@cvs.openbsd.org 2026/10/06 20:51:16 Modified files: xserver/Xi : exevents.c xibarriers.c xipassivegrab.c xserver/dix : devices.c xserver/glamor : glamor_priv.h glamor_transfer.c xserver/glx : glxcmds.c xserver/include: xkbstr.h xserver/present: present_notify.c xserver/xkb : XKBAlloc.c XKBMAlloc.c xkb.c Log message: Merge fixes from upstream for Xserver issues: * CVE-2026-88812: XKB SetGeometry TextDoodad Double Free * CVE-2026-93515: Present Extension Cross-Window Notify Use-After-Free * CVE-2026-93516: XInput Passive Grab modifierDevice Use-After-Free * CVE-2026-93517: GLX RenderLarge Heap Buffer Overflow * CVE-2026-93518: XKB ResizeKeyType Numeric Truncation * CVE-2026-93519: XFixes Pointer Barrier Event List Buffer Overflow * CVE-2026-93520: XKB ChangeKeycodeRange Heap Out-of-Bounds Write * CVE-2026-93521: RandR ChangeProviderProperty Heap Buffer Overflow * CVE-2026-93522: Glamor CopyArea CPU-FBO Heap Buffer Overflow * CVE-2026-93523: XInput2 PassiveUngrabDevice Modifier Out-of-Bounds Write * CVE-2026-93524: XKB SetMap Key Width/Action Count Desync Out-Of-Bounds Read * CVE-2026-93536: GestureBuildSprite Use-After-Free CVSROOT: /cvs Module name: src Changes by: sthen@cvs.openbsd.org 2026/10/06 21:46:12 Modified files: sys/arch/i386/conf: GENERIC RAMDISK_CD Log message: add uncm(4) to i386 GENERIC config, and uncm(4) and urndis(4) to RAMDISK_CD. ok deraadt CVSROOT: /cvs Module name: www Changes by: deraadt@cvs.openbsd.org 2026/10/06 22:26:57 Modified files: . : 73.html 79.html Log message: repair line breaks CVSROOT: /cvs Module name: src Changes by: sashan@cvs.openbsd.org 2026/10/07 01:09:51 Modified files: lib/libssl : d1_lib.c Log message: Avoid OPENSSL_assert(s->d1->mtu >= dtls1_min_mtu()) in dtls1_do_write() when custom BIO is used. The assert is tripped if custom BIO does not support QUERY_MTU operation and message is being retransmitted after timeout expires. Issue reported and patch submitted by "Pavel (Narayana OU)" (pd _at_ narayana _dot_ im) OK kenjiro@ CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/07 01:34:59 Modified files: usr.bin/tmux : tty.c Log message: Fix tty_clamp_area with status lines at the top and a smaller client, GitHub issue 5697 from Yasuhiro Inami. CVSROOT: /cvs Module name: src Changes by: robert@cvs.openbsd.org 2026/10/07 03:00:11 Modified files: usr.bin/ssh : gss-serv.c ssh-gss.h Log message: ssh_gssapi_cleanup_global_client() needs a prototype ok dtucker@ /usr/src/usr.bin/ssh/ssh/../ssh-gss.h:115:38: error: a function declaration without a prototype is deprecated in all versions of C [-Werror,-Wstrict-prototypes] 115 | void ssh_gssapi_cleanup_global_client(); | ^ | void 1 error generated. CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/07 03:29:51 Modified files: sys/dev/usb : usbdevs Log message: sys/usbdevs: add RTL8159 CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/07 03:34:34 Modified files: sys/dev/usb : usbdevs.h usbdevs_data.h Log message: regen CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/07 03:36:53 Modified files: sys/dev/usb : if_ure.c if_urereg.h Log message: sys/ure: add preliminary support of RTL8159 OK: kevlo@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/07 03:39:37 Modified files: share/man/man4 : ure.4 usb.4 Log message: man4: add RTL8159 OK: kevlo@ CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/07 04:59:36 Modified files: sys/dev/pci : if_mwx.c Log message: Fix refcnt bug in the tx path and ensure the node drops the refcnt once the packet was transmitted. Attach the ieee80211_node to the mwx_txwi struct and release the reference in mwx_txwi_put() if set. With this the hangs seen on MT7921 are mostly gone. Background scans would deassociate from the AP but not switch to the new AP because of this refcnt bug. CVSROOT: /cvs Module name: src Changes by: stsp@cvs.openbsd.org 2026/10/07 05:14:53 Modified files: sys/arch/amd64/conf: RAMDISK_CD Log message: enable urndis(4) in the installer on amd64 ok sthen@ CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/07 06:02:21 Modified files: usr.bin/tmux : cmd-join-pane.c Log message: Do not change active pane if joining a pane to the same window. Reported by David le Blanc. CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/07 06:05:51 Modified files: sys/dev/pci : if_mwxreg.h Log message: Unify the UNI command tag definitions in one place and one form. CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/07 06:14:36 Modified files: sys/dev/pci : if_mwx.c Log message: Implement mediaopt monitor for MT7925 While doing so also improve mwx_dma_rx_dequeue() and remove the KASSERT since I triggered that one on MT7925. Further reduce debug noise. CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/07 06:39:12 Modified files: usr.bin/mandoc : term.c Log message: The point of the \: escape sequence is to allow an optional output line break, whatever the output mode may be. It is not supposed to produce an output glyph. Consequently, even in -T utf8 output mode, let it put the ASCII_BREAK control code into the output buffer, which works in TERMENC_UTF8 mode just as well as in TERMENC_ASCII mode, rather than trying to encode it as an UTF-8 code point. CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/07 06:44:06 Modified files: regress/usr.bin/mandoc/char/space: Makefile Added files: regress/usr.bin/mandoc/char/space: break.out_utf8 Log message: test -T utf8 handling of the \: escape sequence related to term.c rev. 1.156 CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/07 06:55:41 Modified files: usr.bin/tmux : options-table.c spawn.c tmux.1 Log message: Add window-default-command option to override default-command per window, from Meriel Sartha Mittelbach. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/07 06:59:50 Modified files: usr.bin/tmux : options-table.c tmux.1 window-copy.c Log message: Show match count in copy mode, GitHub issue 5399. CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/07 07:13:49 Modified files: usr.bin/tmux : cmd-choose-tree.c tmux.1 window-switch.c Log message: Add sort order flags to switch-mode, GitHub issue 5696 from harikp2002 at gmail dot com. CVSROOT: /cvs Module name: src Changes by: krw@cvs.openbsd.org 2026/10/07 09:51:55 Modified files: usr.sbin/dhcpd : options.c Log message: Discard packets with unsupported htype's. Potential problem pointed out by Acts1631. ok tb@ CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/07 09:56:51 Modified files: usr.bin/mandoc : term.c Log message: When rendering the \l (horizontal line) escape sequence, correctly determine whether a drawing glyph is specified before the delimiter closing the escape sequence. The code only compared the first input byte of the candidate to the last input byte of the opening delimiter, treating the candidate as a drawing glyph on mismatch, which only worked correctly for single-byte delimiters. When an escape sequence is used as a delimiter, that escape sequence was erroneously used as the drawing glyph, too. Instead of needlessly and incorrectly trying to compare the opening and closing delimiters, use the argument information returned from mandoc_escape(): if a2roffsu() consumed the whole argument, use the default drawing glyph; otherwise, use the rest of the argument as the drawing glyph. CVSROOT: /cvs Module name: xenocara Changes by: bluhm@cvs.openbsd.org 2026/10/07 09:59:34 Modified files: xserver/Xi : Tag: OPENBSD_7_8 exevents.c xibarriers.c xipassivegrab.c xserver/dix : Tag: OPENBSD_7_8 devices.c xserver/glamor : Tag: OPENBSD_7_8 glamor_priv.h glamor_transfer.c xserver/glx : Tag: OPENBSD_7_8 glxcmds.c xserver/include: Tag: OPENBSD_7_8 xkbstr.h xserver/present: Tag: OPENBSD_7_8 present_notify.c xserver/xkb : Tag: OPENBSD_7_8 XKBAlloc.c XKBMAlloc.c xkb.c Log message: Merge fixes from upstream for Xserver issues: * CVE-2026-88812: XKB SetGeometry TextDoodad Double Free * CVE-2026-93515: Present Extension Cross-Window Notify Use-After-Free * CVE-2026-93516: XInput Passive Grab modifierDevice Use-After-Free * CVE-2026-93517: GLX RenderLarge Heap Buffer Overflow * CVE-2026-93518: XKB ResizeKeyType Numeric Truncation * CVE-2026-93519: XFixes Pointer Barrier Event List Buffer Overflow * CVE-2026-93520: XKB ChangeKeycodeRange Heap Out-of-Bounds Write * CVE-2026-93521: RandR ChangeProviderProperty Heap Buffer Overflow * CVE-2026-93522: Glamor CopyArea CPU-FBO Heap Buffer Overflow * CVE-2026-93523: XInput2 PassiveUngrabDevice Modifier Out-of-Bounds Write * CVE-2026-93524: XKB SetMap Key Width/Action Count Desync Out-Of-Bounds Read * CVE-2026-93536: GestureBuildSprite Use-After-Free from matthieu@ this is errata/7.8/068_xserver.patch.sig CVSROOT: /cvs Module name: xenocara Changes by: bluhm@cvs.openbsd.org 2026/10/07 10:00:56 Modified files: xserver/Xi : Tag: OPENBSD_7_9 exevents.c xibarriers.c xipassivegrab.c xserver/dix : Tag: OPENBSD_7_9 devices.c xserver/glamor : Tag: OPENBSD_7_9 glamor_priv.h glamor_transfer.c xserver/glx : Tag: OPENBSD_7_9 glxcmds.c xserver/include: Tag: OPENBSD_7_9 xkbstr.h xserver/present: Tag: OPENBSD_7_9 present_notify.c xserver/xkb : Tag: OPENBSD_7_9 XKBAlloc.c XKBMAlloc.c xkb.c Log message: Merge fixes from upstream for Xserver issues: * CVE-2026-88812: XKB SetGeometry TextDoodad Double Free * CVE-2026-93515: Present Extension Cross-Window Notify Use-After-Free * CVE-2026-93516: XInput Passive Grab modifierDevice Use-After-Free * CVE-2026-93517: GLX RenderLarge Heap Buffer Overflow * CVE-2026-93518: XKB ResizeKeyType Numeric Truncation * CVE-2026-93519: XFixes Pointer Barrier Event List Buffer Overflow * CVE-2026-93520: XKB ChangeKeycodeRange Heap Out-of-Bounds Write * CVE-2026-93521: RandR ChangeProviderProperty Heap Buffer Overflow * CVE-2026-93522: Glamor CopyArea CPU-FBO Heap Buffer Overflow * CVE-2026-93523: XInput2 PassiveUngrabDevice Modifier Out-of-Bounds Write * CVE-2026-93524: XKB SetMap Key Width/Action Count Desync Out-Of-Bounds Read * CVE-2026-93536: GestureBuildSprite Use-After-Free from matthieu@ this is errata/7.9/032_xserver.patch.sig CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/07 10:26:15 Modified files: usr.bin/mandoc : roff_escape.c Log message: Fix handling of special character escape sequences used as escape sequence argument delimiters. When a first inner escape sequence is used as the opening delimiter of the argument of an outer escape sequence, the code parses the argument looking for a second inner escape sequence. If the characters after the escape character of the first and second matched, the code treated the second as the closing delimiter. That resulted in prematurely ending the argument if the first and second referred to different special characters. Instead, if the first is a special character, only treat the second as the closing delimiter if the first and second are completely equal. Otherwise, threat the second as part of the argument and keep parsing the argument for a matching delimiter. For escape sequence argument delimiters that are not special characters, nothing changes: non-character escapes continue to match in a delimiter role as long as their name characters match, even if their arguments differ. CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/07 10:31:46 Modified files: regress/usr.bin/mandoc/roff/esc: l.in l.out_ascii l.out_lint Log message: systematically test using special character escape sequences as argument delimiters of an escape sequence argument, even if the argument contains a different special character; related to roff_escape.c rev. 1.18 CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/07 10:57:34 Modified files: usr.bin/mandoc : chars.c Log message: Map \: to U+200B (breaking) ZERO WIDTH SPACE. This isn't used for terminal output, where \: merely influences line breaking but does not produce any output character, but it improves HTML output. CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/07 11:02:55 Modified files: regress/usr.bin/mandoc/char/space: Makefile break.in break.out_ascii break.out_utf8 Added files: regress/usr.bin/mandoc/char/space: break.out_html Log message: test \: in -T html; related to mandoc/chars.c rev. 1.52 CVSROOT: /cvs Module name: www Changes by: bluhm@cvs.openbsd.org 2026/10/07 11:13:52 Modified files: . : errata78.html errata79.html Log message: Release isakmpd xserver expat wsdisplay errata. CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/07 11:25:06 Modified files: share/man/man4 : usb.4 Log message: This page contains the unusual case of a word that is 50 characters long. Sprinkle some \: (optional line break points) inside that word to allow for nicer line breaking. Normally, manual page authors do not need to worry about such details. While here, also break an overlong input line. No text change. CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:38:45 Modified files: math/calc : Makefile distinfo math/calc/patches: patch-Makefile Log message: update to calc-2.17.0.2 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:38:50 Modified files: security/libmodsecurity: Makefile distinfo security/libmodsecurity/patches: patch-examples_multiprocess_c_Makefile_in patch-examples_multithread_Makefile_in patch-examples_reading_logs_via_rule_message_Makefile_in patch-examples_reading_logs_with_offset_Makefile_in patch-examples_simple_example_using_c_Makefile_in patch-examples_using_bodies_in_chunks_Makefile_in patch-src_Makefile_in patch-src_parser_Makefile_in patch-test_Makefile_in patch-test_benchmark_Makefile_in Log message: update to libmodsecurity-3.0.17 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:38:54 Modified files: sysutils/py-pipx: Makefile distinfo Log message: update to py3-pipx-1.17.8 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:39:02 Modified files: sysutils/py-platformdirs: Makefile distinfo sysutils/py-platformdirs/pkg: PLIST Log message: update to py3-platformdirs-4.12.2 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:39:07 Modified files: security/py-blake3: Makefile crates.inc distinfo Log message: update to py3-blake3-1.0.10 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:39:11 Modified files: security/py-gnupg: Makefile distinfo Log message: update to py3-gnupg-0.5.7 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:39:14 Modified files: security/py-krb5: Makefile distinfo security/py-krb5/patches: patch-pyproject_toml security/py-krb5/pkg: PLIST Log message: update to py3-krb5-0.10.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:39:17 Modified files: security/py-spnego: Makefile distinfo Log message: update to py3-spnego-0.12.3 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:39:26 Modified files: textproc/py-fpdf2: Makefile distinfo Log message: update to py3-fpdf2-2.8.9 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:39:30 Modified files: devel/py-virtualenv: Makefile distinfo Log message: update to py3-virtualenv-21.14.5 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:39:34 Modified files: net/py-fqdn : Makefile distinfo net/py-fqdn/pkg: PLIST Removed files: net/py-fqdn/patches: patch-setup_cfg Log message: update to py3-fqdn-1.6.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:39:39 Modified files: textproc/py-charset-normalizer: Makefile distinfo textproc/py-charset-normalizer/pkg: PLIST Log message: update to py3-charset-normalizer-3.5.2 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:39:43 Modified files: textproc/py-dateparser: Makefile distinfo textproc/py-dateparser/pkg: PLIST Log message: update to py3-dateparser-1.4.3 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:39:46 Modified files: devel/py-click : Makefile distinfo devel/py-click/pkg: PLIST Log message: update to py3-click-8.5.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:39:49 Modified files: devel/indi : Makefile distinfo devel/indi/pkg : PLIST-main Removed files: devel/indi/patches: patch-drivers_telescope_CMakeLists_txt patch-indiserver_LocalDvrInfo_cpp patch-indiserver_RemoteDvrInfo_cpp patch-indiserver_TcpServer_cpp patch-libs_indicore_indicom_c Log message: update to indi-2.2.5 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:39:52 Modified files: graphics/ImageMagick: Makefile distinfo Log message: update to ImageMagick-6.9.13.57 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:39:55 Modified files: databases/redis/bsd: Makefile distinfo databases/redis/bsd/patches: patch-deps_linenoise_linenoise_c patch-redis_conf patch-sentinel_conf patch-src_Makefile patch-src_config_c patch-src_server_h patch-tests_support_util_tcl Removed files: databases/redis/bsd/patches: patch-deps_hiredis_Makefile Log message: update to redis-7.2.16 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:00 Modified files: databases/py-redis: Makefile distinfo databases/py-redis/pkg: PLIST Removed files: databases/py-redis/patches: patch-tests_conftest_py patch-tests_entraid_utils_py patch-tests_test_asyncio_conftest_py patch-tests_test_asyncio_test_credentials_py patch-tests_test_credentials_py Log message: update to py3-redis-8.1.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:03 Modified files: net/rdapper : Makefile distinfo Log message: update to rdapper-1.26 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:06 Modified files: audio/faad : Makefile distinfo Log message: update to faad-2.11.4 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:09 Modified files: security/py-cryptodome-test-vectors: Makefile distinfo security/py-cryptodome-test-vectors/pkg: PLIST Log message: update to py3-cryptodome-test-vectors-1.0.22 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:12 Modified files: security/py-cryptodomex: Makefile distinfo Log message: update to py3-cryptodomex-3.24.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:15 Modified files: security/py-cryptodome: Makefile distinfo Log message: update to py3-cryptodome-3.24.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:18 Modified files: devel/py-pdm-backend: Makefile distinfo devel/py-pdm-backend/pkg: PLIST Log message: update to py3-pdm-backend-2.5.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:21 Modified files: devel/py-pbr : Makefile distinfo devel/py-pbr/pkg: PLIST Log message: update to py3-pbr-7.1.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:25 Modified files: devel/py-tabulate: Makefile distinfo devel/py-tabulate/pkg: PLIST Log message: update to py3-tabulate-0.10.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:28 Modified files: devel/py-wcwidth: Makefile distinfo devel/py-wcwidth/pkg: PLIST Log message: update to py3-wcwidth-0.9.2 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:32 Modified files: devel/py-uv-dynamic-versioning: Makefile distinfo devel/py-uv-dynamic-versioning/pkg: PLIST Log message: update to py3-uv-dynamic-versioning-0.14.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:35 Modified files: sysutils/py-dotenv: Makefile distinfo Log message: update to py3-dotenv-1.2.4 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:38 Modified files: sysutils/py-lockfile: Makefile Log message: update to py3-lockfile-0.12.2 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:41 Modified files: sysutils/ansible-lint: Makefile distinfo sysutils/ansible-lint/patches: patch-src_ansiblelint_config_py Log message: update to ansible-lint-26.1.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:45 Modified files: databases/py-shillelagh: Makefile distinfo Log message: update to py3-shillelagh-1.4.5 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:49 Modified files: devel/py-uharfbuzz: Makefile distinfo Log message: update to py3-uharfbuzz-0.56.2 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:53 Modified files: devel/py-billiard: Makefile distinfo Log message: update to py3-billiard-4.3.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:56 Modified files: sysutils/borgmatic: Makefile distinfo Log message: update to borgmatic-2.1.10 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:40:59 Modified files: benchmarks/hyperfine: Makefile crates.inc distinfo Log message: update to hyperfine-1.21.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:41:02 Modified files: devel/py-bitstruct: Makefile distinfo Log message: update to py3-bitstruct-8.23.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:41:08 Modified files: sysutils/diffoscope: Makefile distinfo sysutils/diffoscope/pkg: PLIST Log message: update to diffoscope-332 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:41:12 Modified files: textproc/yq : Makefile distinfo textproc/yq/pkg: PLIST Log message: update to yq-4.4.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:41:16 Modified files: net/py-ripe.atlas.cousteau: Makefile distinfo Log message: update to py3-ripe.atlas.cousteau-2.3.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:41:19 Modified files: net/py-ripe.atlas.sagan: Makefile distinfo Log message: update to py3-ripe.atlas.sagan-2.0.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:41:22 Modified files: net/py-ripe.atlas.tools: Makefile distinfo Log message: update to ripe.atlas.tools-3.4.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:42:24 Modified files: devel/py-jsonref: Makefile devel/py-jsonref/pkg: PLIST Log message: regen plist after pdm update CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:43:08 Log message: import ports/devel/py-vcs-versioning, ok tb vcs-versioning provides core VCS versioning functionality, originally part of setuptools-scm, but extracted as a standalone library that can be used independently. Status: Vendor Tag: sthen Release Tags: sthen_20261007 N ports/devel/py-vcs-versioning/Makefile N ports/devel/py-vcs-versioning/distinfo N ports/devel/py-vcs-versioning/pkg/DESCR N ports/devel/py-vcs-versioning/pkg/PLIST No conflicts created by this import CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:44:31 Modified files: devel : Makefile Log message: +py-vcs-versioning CVSROOT: /cvs Module name: ports Changes by: tb@cvs.openbsd.org 2026/10/07 13:46:07 Modified files: net/rrdp-tools : Makefile distinfo net/rrdp-tools/pkg: PLIST Log message: Update to rrdp-tools 0.5.1, ok job https://github.com/ties/rpki-rrdp-tools-py/blob/main/CHANGELOG.md#v051 CVSROOT: /cvs Module name: xenocara Changes by: jca@cvs.openbsd.org 2026/10/07 13:46:22 Modified files: . : MODULES Log message: Mention latest fixes merged from upstream xserver Mostly useful to trigger the git conversion process. Requested by tb@ CVSROOT: /cvs Module name: ports Changes by: bket@cvs.openbsd.org 2026/10/07 13:47:27 Modified files: security/vaultwarden: Makefile crates.inc distinfo Log message: Update to vaultwarden-1.37.4 This release contains security fixes: - Organization member revocation [GHSA-69q9-v8p6-xvx3] - Two-factor authentication [GHSA-7jg8-8m5x-6j9r] - Organization invitations [GHSA-v576-3wvq-xh3c] - Attachments [GHSA-q5x6-grh5-fqgc] - Organization event logs [GHSA-64mc-4p6f-r7x9] - Cipher sharing [GHSA-7ccc-c43j-4p36] - Organization API key [GHSA-qwx4-wcv4-mpcv] Changes: https://github.com/dani-garcia/vaultwarden/releases/tag/1.37.4 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:47:40 Modified files: devel/py-setuptools_scm: Makefile distinfo devel/py-setuptools_scm/pkg: PLIST Log message: update to py3-setuptools_scm-10.3.4 CVSROOT: /cvs Module name: ports Changes by: bket@cvs.openbsd.org 2026/10/07 13:48:05 Modified files: databases/py-borgstore: Makefile distinfo Log message: Update to py-borgstore-0.7.0 Changes: https://github.com/borgbackup/borgstore/blob/0.7.0/docs/changes.rst CVSROOT: /cvs Module name: ports Changes by: bket@cvs.openbsd.org 2026/10/07 13:48:33 Modified files: devel/py-borghash: Makefile distinfo Log message: Update to py-borghash-0.2.1 Changes: https://github.com/borgbackup/borghash/blob/0.2.1/CHANGES.rst CVSROOT: /cvs Module name: ports Changes by: bket@cvs.openbsd.org 2026/10/07 13:49:07 Modified files: sysutils/borgbackup/2.0: Makefile distinfo sysutils/borgbackup/2.0/pkg: PLIST Log message: Update to borgbackup-2.0.0beta25 Changes: https://github.com/borgbackup/borg/blob/2.0.0b25/docs/changes.rst#version-200b25-2026-09-27 CVSROOT: /cvs Module name: ports Changes by: sebastia@cvs.openbsd.org 2026/10/07 13:50:18 Modified files: comms/soapysdr : Makefile Log message: Explicitly disable hidden dep on doxygen reported by tb@ CVSROOT: /cvs Module name: ports Changes by: tb@cvs.openbsd.org 2026/10/07 13:50:49 Modified files: textproc/check-jsonschema: Makefile distinfo textproc/check-jsonschema/pkg: PLIST Log message: Update to check-jsonschema 0.38.2 https://github.com/python-jsonschema/check-jsonschema/releases/tag/0.38.1 https://github.com/python-jsonschema/check-jsonschema/releases/tag/0.38.2 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:56:58 Modified files: astro/py-astropy: Makefile astro/py-astropy/pkg: PLIST databases/py-borgstore: Makefile databases/py-borgstore/pkg: PLIST devel/mercurial: Makefile devel/mercurial/pkg: PLIST-main devel/py-borghash: Makefile devel/py-borghash/pkg: PLIST devel/py-importlib-metadata: Makefile devel/py-importlib-metadata/pkg: PLIST devel/py-prance: Makefile devel/py-prance/pkg: PLIST devel/py-pure_eval: Makefile devel/py-pure_eval/pkg: PLIST devel/py-python-lsp-server: Makefile devel/py-python-lsp-server/pkg: PLIST devel/py-test-astropy: Makefile devel/py-test-astropy/pkg: PLIST devel/py-wbem : Makefile devel/py-wbem/pkg: PLIST net/py-portend : Makefile net/py-portend/pkg: PLIST security/badkeys: Makefile security/badkeys/pkg: PLIST sysutils/borgbackup/1.4: Makefile sysutils/borgbackup/1.4/pkg: PLIST sysutils/borgbackup/2.0: Makefile sysutils/borgbackup/2.0/pkg: PLIST sysutils/py-shtab: Makefile sysutils/py-shtab/pkg: PLIST textproc/codespell: Makefile textproc/codespell/pkg: PLIST textproc/py-cssutils: Makefile textproc/py-cssutils/pkg: PLIST Log message: update plists following setuptools_scm update CVSROOT: /cvs Module name: ports Changes by: tb@cvs.openbsd.org 2026/10/07 13:58:01 Modified files: devel/mergiraf : Makefile crates.inc distinfo Log message: Update to mergiraf 0.20.0 https://codeberg.org/mergiraf/mergiraf/releases/tag/v0.20.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 13:58:38 Modified files: lang/python/3 : python.port.mk Log message: add support for MODPY_PYTEST_IGNORE for simpler skipping of tests CVSROOT: /cvs Module name: ports Changes by: tb@cvs.openbsd.org 2026/10/07 13:59:03 Modified files: sysutils/aarch64-esr-decoder: Makefile crates.inc distinfo Log message: Update to aarch64-esr-decoder 0.2.5 CVSROOT: /cvs Module name: src Changes by: sthen@cvs.openbsd.org 2026/10/07 13:59:11 Modified files: share/man/man5 : python-module.5 Log message: document MODPY_PYTEST_IGNORE CVSROOT: /cvs Module name: www Changes by: job@cvs.openbsd.org 2026/10/07 13:59:20 Modified files: . : mail.html openssh : list.html releasenotes.html report.html security.html openssh/txt : release-10.0 release-10.1 release-10.2 release-10.3 release-10.4 release-10.5 release-10.6 release-5.0 release-5.1 release-5.2 release-5.3 release-5.4 release-5.5 release-5.6 release-5.7 release-5.8 release-5.8p2 release-5.9 release-6.0 release-6.1 release-6.2 release-6.2p2 release-6.3 release-6.4 release-6.5 release-6.6 release-6.7 release-6.8 release-6.9 release-7.0 release-7.1 release-7.1p2 release-7.2 release-7.2p2 release-7.3 release-7.4 release-7.5 release-7.6 release-7.7 release-7.8 release-7.9 release-8.0 release-8.1 release-8.2 release-8.3 release-8.4 release-8.5 release-8.6 release-8.7 release-8.8 release-8.9 release-9.0 release-9.1 release-9.2 release-9.3 release-9.3p2 release-9.4 release-9.5 release-9.6 release-9.7 release-9.8 release-9.9 release-9.9p2 Log message: Mechanical replace: openssh@openssh.com -> openssh@openssh.org discussed with deraadt@ CVSROOT: /cvs Module name: ports Changes by: tb@cvs.openbsd.org 2026/10/07 14:00:43 Modified files: devel/jjui : Makefile distinfo modules.inc Log message: Update to jjui 0.10.10 https://github.com/idursun/jjui/releases/tag/v0.10.10 CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/07 14:01:17 Modified files: sys/net : pf.c Log message: In pf(4) check extension header length. pf_walk_header6() advances the packet offset for each IPv6 extension header. It was not checked that this does not exceed the packet length if no next header was processed. When used with af-to rules, this could trigger a panic: m_copydata: null mbuf. from Acts1631; OK henning@ sashan@ CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 14:02:50 Modified files: lang/python/3 : python.port.mk Log message: bump setuptools_scm version in MODPY_PYBUILD BDEP because some plists with the newer version have changed CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 14:03:20 Modified files: lang/python/3 : Makefile distinfo lang/python/3/patches: patch-configure_ac lang/python/3/pkg: PLIST-idle PLIST-tests Removed files: lang/python/3/patches: patch-Modules__ssl_c Log message: update to python-3.14.8, ok kmos CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 14:04:14 Modified files: lang/python/3 : Tag: OPENBSD_7_9 Makefile distinfo lang/python/3/patches: Tag: OPENBSD_7_9 patch-configure_ac lang/python/3/pkg: Tag: OPENBSD_7_9 PLIST-idle PLIST-tests Removed files: lang/python/3/patches: Tag: OPENBSD_7_9 patch-Modules__ssl_c Log message: update to python-3.13.16, ok kmos CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 14:06:20 Modified files: textproc/py-xmltodict: Makefile distinfo Log message: update to py3-xmltodict-1.0.4, ok jung (dropping maintainer) CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 14:09:02 Modified files: net/ngrep : Makefile distinfo net/ngrep/patches: patch-ngrep_c net/ngrep/pkg : DESCR PLIST Log message: update to ngrep-1.49.0, add tcpkill flavour CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 14:09:29 Modified files: net : Makefile Log message: build ngrep,tcpkill CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 14:10:35 Modified files: emulators/bochs: Makefile emulators/bochs/patches: patch-bochs_configure_ac Log message: fix bochs deps for debug flavour CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 14:11:03 Modified files: emulators : Makefile Log message: link bochs,debug,no_x11 and bochs,no_x11 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 14:11:46 Modified files: sysutils/salt : Makefile.inc sysutils/salt/3008: Makefile Log message: set PORTROACH CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 14:23:31 Modified files: x11/tigervnc : Makefile distinfo Log message: build tigervnc against newer xserver CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 14:23:46 Modified files: x11/tigervnc : Tag: OPENBSD_8_0 Makefile distinfo Log message: build tigervnc against newer xserver CVSROOT: /cvs Module name: ports Changes by: tb@cvs.openbsd.org 2026/10/07 14:29:45 Modified files: net/iamb : Makefile Log message: iamb: set USE_NOEXECONLY to unbreak. Tested by Enzo Nicosia, ok sthen CVSROOT: /cvs Module name: ports Changes by: tb@cvs.openbsd.org 2026/10/07 14:30:49 Modified files: net/iamb : Tag: OPENBSD_8_0 Makefile Log message: MFC: iamb: set USE_NOEXECONLY to unbreak. Tested by Enzo Nicosia, ok sthen CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 14:35:31 Modified files: telephony/sngrep: Makefile distinfo telephony/sngrep/patches: patch-src_capture_c Log message: update to sngrep-1.9.0 CVSROOT: /cvs Module name: www Changes by: naddy@cvs.openbsd.org 2026/10/07 14:57:10 Modified files: openssh/txt : release-10.6 Log message: fix the name of the PubkeyAuthOptions directive CVSROOT: /cvs Module name: ports Changes by: jca@cvs.openbsd.org 2026/10/07 15:01:32 Modified files: net/openvpn : Makefile distinfo Log message: SECURITY update to openvpn-2.7.8 Issues that affect us: 1. Check for NULL-Bytes in certificate subjects - refuse all such certificates now as "invalid" (CVE-2026-84790). 2. options: fix unsigned underflow when clearing domain_search_list (CVE-2026-88964) Full ChangeLog: https://github.com/OpenVPN/openvpn/blob/v2.7.8/Changes.rst CVSROOT: /cvs Module name: ports Changes by: jca@cvs.openbsd.org 2026/10/07 15:02:44 Modified files: net/openvpn : Tag: OPENBSD_8_0 Makefile distinfo Log message: SECURITY update to openvpn-2.7.8 Issues that affect us: 1. Check for NULL-Bytes in certificate subjects - refuse all such certificates now as "invalid" (CVE-2026-84790). 2. options: fix unsigned underflow when clearing domain_search_list (CVE-2026-88964) Full ChangeLog: https://github.com/OpenVPN/openvpn/blob/v2.7.8/Changes.rst CVSROOT: /cvs Module name: src Changes by: dv@cvs.openbsd.org 2026/10/07 15:08:34 Modified files: usr.sbin/vmd : x86_mmio.c Log message: Add truncation detection to vmd's instruction decoder. vmd(8) ultimately needs a way to deal with instructions that cross page boundaries. This is a baby step to get there by fixing up the decoder logic to detect when we're out of fetched instruction bytes but not done decoding an instruction. Next steps will be to add in cross-page fetching and injecting #PF if the next page is paged out and we weren't able to decode with just the bytes from the first page. These state machine changes uncovered some issues with 16-bit addressing and decoding that got fixed along the way. ok mlarkin@ CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 16:15:23 Modified files: devel/py-tz : Makefile distinfo Log message: update to py3-tz-2026.5 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 16:15:47 Modified files: devel/py-tz : Tag: OPENBSD_8_0 Makefile distinfo Log message: update to py3-tz-2026.5 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 16:16:17 Modified files: devel/py-tzdata: Makefile distinfo Log message: update to py3-tzdata-2026.5 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 16:16:34 Modified files: devel/py-tzdata: Tag: OPENBSD_8_0 Makefile distinfo Log message: update to py3-tzdata-2026.5 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 16:17:21 Modified files: mail/fetchmail : Makefile distinfo Log message: update to fetchmail-6.6.9 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 16:17:47 Modified files: mail/fetchmail : Tag: OPENBSD_8_0 Makefile distinfo Log message: update to fetchmail-6.6.9 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 16:18:21 Modified files: mail/rspamd : Makefile distinfo mail/rspamd/pkg: PLIST Log message: update to rspamd-4.2.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 16:18:47 Modified files: mail/rspamd : Tag: OPENBSD_8_0 Makefile distinfo mail/rspamd/pkg: Tag: OPENBSD_8_0 PLIST Log message: update to rspamd-4.2.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 16:20:26 Modified files: x11/freerdp : Makefile distinfo x11/freerdp/patches: patch-channels_rdpsnd_client_rdpsnd_main_c patch-winpr_CMakeLists_txt Log message: update to freerdp-3.32.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/07 16:20:51 Modified files: x11/freerdp : Tag: OPENBSD_8_0 Makefile distinfo x11/freerdp/patches: Tag: OPENBSD_8_0 patch-channels_rdpsnd_client_rdpsnd_main_c patch-winpr_CMakeLists_txt Log message: update to freerdp-3.32.1 CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/07 16:29:49 Modified files: usr.bin/ssh : myproposal.h Log message: enable ssh-mldsa44-ed25519 as an allowed CA signature algorithm; missed in previous commit to reenable the algorithm CVSROOT: /cvs Module name: src Changes by: mlarkin@cvs.openbsd.org 2026/10/07 17:06:26 Modified files: usr.sbin/vmd : vioblk.c vionet.c vioscsi.c virtio.c virtio.h Log message: vmd(8): better virtio vq validation add some queue size checks and reject malformed descriptor chains. also make viornd consume all pending buffers from last_avail. ok dv CVSROOT: /cvs Module name: ports Changes by: naddy@cvs.openbsd.org 2026/10/07 17:26:43 Modified files: lang/python/3 : python.port.mk Log message: typo in dependency spec CVSROOT: /cvs Module name: ports Changes by: kurt@cvs.openbsd.org 2026/10/07 18:23:56 Modified files: devel/jdk/11 : Makefile devel/jdk/17 : Makefile devel/jdk/21 : Makefile devel/jdk/25 : Makefile devel/jdk/25/pkg: PLIST Added files: devel/jdk/11/patches: patch-make_launcher_LauncherCommon_gmk patch-make_lib_CoreLibraries_gmk patch-make_lib_Lib-java_instrument_gmk devel/jdk/17/patches: patch-make_common_modules_LauncherCommon_gmk patch-make_modules_java_base_lib_CoreLibraries_gmk patch-make_modules_java_instrument_Lib_gmk devel/jdk/21/patches: patch-make_common_modules_LauncherCommon_gmk patch-make_modules_java_base_lib_CoreLibraries_gmk patch-make_modules_java_instrument_Lib_gmk devel/jdk/25/patches: patch-make_common_JdkNativeCompilation_gmk patch-make_modules_java_base_lib_CoreLibraries_gmk Log message: We support $ORIGIN fully now. Remove static linking work-arounds. CVSROOT: /cvs Module name: ports Changes by: kirill@cvs.openbsd.org 2026/10/07 19:47:29 Modified files: net/ejabberd : Makefile distinfo modules.inc Log message: net/ejabberd: update to 26.09 CVSROOT: /cvs Module name: ports Changes by: landry@cvs.openbsd.org 2026/10/08 00:09:47 Modified files: security/nss : Makefile distinfo Log message: security/nss: update to 3.131, will be required for firefox 159. bump minor for addition of CERT_GetDERCertTrust & _PK11_DERPrivateKeyToPrivateKeyInfo symbols see https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_131.html CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/08 00:29:32 Modified files: usr.bin/tmux : cmd-parse.y Log message: Fix commands being lost when chained with assignment, GitHub issue 5702 from Jeong, Heon CVSROOT: /cvs Module name: ports Changes by: otto@cvs.openbsd.org 2026/10/08 00:29:43 Modified files: net/powerdns_recursor: Makefile distinfo Log message: Update to PowerDNS Recursor 5.4.7 CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/08 00:44:16 Modified files: usr.bin/tmux : cmd-parse.y Log message: Track allocations in yacc to avoid leaking when parsing commands, GitHub issue 5632 from Jeong, Heon. CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 00:44:25 Modified files: net/py-fqdn : Makefile net/py-fqdn/pkg: PLIST Log message: fix plist for newer setuptools_scm CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 00:46:13 Added files: security/py-gnupg/patches: patch-pyproject_toml Log message: missed cvs add CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/08 01:06:26 Modified files: usr.bin/tmux : cmd-load-buffer.c spawn.c window.c Log message: Fix bugs with empty panes and load-buffer -w, GitHub issue 5701 from Alexandre Fiori. CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/08 01:14:36 Modified files: sys/dev/pci : if_mwx.c Log message: Not enabling deep sleep in ASSOC state really helps to establish a WIFI connection. Especially during roaming. Also remove a very noisy debug printf. CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 01:15:08 Modified files: audio/whisper.cpp: Makefile distinfo Log message: update to whisper.cpp-1.9.5 CVSROOT: /cvs Module name: ports Changes by: tb@cvs.openbsd.org 2026/10/08 01:21:47 Added files: www/py-httptools/patches: patch-pyproject_toml Log message: py-httptools: remove upper bound on setuptools CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/08 01:50:05 Modified files: usr.bin/tmux : grid-reader.c grid.c input.c key-bindings.c spawn.c tmux.1 tmux.h window-buffer.c window-copy.c window-customize.c Log message: Add commands to copy mode to select, pipe and open OSC 133 command output, from Michael Grant. CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:05:51 Modified files: devel/ipython : Makefile distinfo Log message: update to ipython-9.17.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:07:48 Modified files: devel/py-pbr : Makefile distinfo Log message: update to py3-pbr-7.1.3 CVSROOT: /cvs Module name: ports Changes by: landry@cvs.openbsd.org 2026/10/08 02:07:53 Modified files: www/mozilla-firefox: Makefile distinfo www/firefox-i18n: Makefile.inc distinfo Log message: www/mozilla-firefox: update to 157.0.1. see https://www.firefox.com/en-US/firefox/157.0.1/releasenotes/ fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-104/ CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:10:51 Modified files: devel/py-pyproject-api: Makefile distinfo Log message: update to py3-pyproject_api-1.11.4 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:14:17 Modified files: net/py-idna : Makefile distinfo Log message: update to py3-idna-3.20, add missing TDEP CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:21:47 Modified files: security/yubico/yubikey-manager: Makefile distinfo Removed files: security/yubico/yubikey-manager/patches: patch-pyproject_toml Log message: update to yubikey-manager-5.9.2 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:25:19 Modified files: databases/postgresql-plr: Makefile distinfo databases/postgresql-plr/pkg: PLIST Log message: update to postgresql-plr-8.4.8.9 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:25:30 Modified files: security/py-spnego: Makefile distinfo Log message: update to py3-spnego-0.12.4 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:25:58 Modified files: net/py-websockets: Makefile distinfo Log message: update to py3-websockets-17.2 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:32:59 Modified files: www/newsraft : Makefile distinfo www/newsraft/pkg: PLIST Log message: update to newsraft-0.38 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:33:03 Modified files: www/newsraft : Tag: OPENBSD_8_0 Makefile distinfo www/newsraft/pkg: Tag: OPENBSD_8_0 PLIST Log message: update to newsraft-0.38 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:33:12 Modified files: www/gumbo : Tag: OPENBSD_8_0 Makefile distinfo Log message: update to gumbo-0.14.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:34:03 Modified files: www/gumbo : Makefile distinfo Log message: update to gumbo-0.14.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:35:11 Modified files: sysutils/freeipmi: Makefile distinfo Log message: update to freeipmi-1.6.20 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:35:18 Modified files: sysutils/freeipmi: Tag: OPENBSD_8_0 Makefile distinfo Log message: update to freeipmi-1.6.20 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:36:15 Modified files: telephony/sngrep: Tag: OPENBSD_8_0 Makefile distinfo telephony/sngrep/patches: Tag: OPENBSD_8_0 patch-src_capture_c Log message: update to sngrep-1.9.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:47:45 Modified files: www/librewolf : Makefile distinfo Added files: www/librewolf/patches: patch-js_src_gc_Memory_cpp patch-js_src_gc_Memory_h patch-js_src_wasm_WasmStacks_cpp Log message: update to librewolf-157.0-1, from Leah Rowe (maintainer) CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:48:50 Modified files: www/librewolf : Tag: OPENBSD_8_0 Makefile distinfo Added files: www/librewolf/patches: Tag: OPENBSD_8_0 patch-js_src_gc_Memory_cpp patch-js_src_gc_Memory_h patch-js_src_wasm_WasmStacks_cpp Log message: update to librewolf-157.0-1, from Leah Rowe (maintainer) CVSROOT: /cvs Module name: ports Changes by: landry@cvs.openbsd.org 2026/10/08 02:52:11 Modified files: www/mozilla-firefox: Tag: OPENBSD_8_0 Makefile distinfo Log message: www/mozilla-firefox: MFC update to 157.0.1. see https://www.firefox.com/en-US/firefox/157.0.1/releasenotes/ fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-104/ CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 02:57:09 Added files: audio/py-tagpy/patches: patch-setup_py Log message: preemptively fix for newer setuptools CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 03:24:37 Modified files: www/puppetboard: Makefile www/puppetboard/patches: patch-puppetboard_version_py Log message: drop setuptools RDEP, installed files don't refer to it or pkg_resources update comment in version.py patch, this should probably use MODPY_PYBUILD not cp -r to install CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 03:26:05 Modified files: net/bird/2 : Makefile distinfo Log message: update to bird-2.19.3 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 03:26:08 Modified files: net/bird/3 : Makefile distinfo Log message: update to bird-3.3.3 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 03:26:14 Modified files: net/bird/2 : Tag: OPENBSD_8_0 Makefile distinfo Log message: update to bird-2.19.3 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 03:26:17 Modified files: net/bird/3 : Tag: OPENBSD_8_0 Makefile distinfo Log message: update to bird-3.3.3 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 03:27:21 Modified files: net/kea : Makefile distinfo net/kea/patches: patch-meson_build Log message: update to kea-3.2.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 03:27:28 Modified files: net/kea : Tag: OPENBSD_8_0 Makefile distinfo net/kea/patches: Tag: OPENBSD_8_0 patch-meson_build Log message: update to kea-3.2.1 CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/08 03:31:34 Modified files: sys/dev/pci : if_mwx.c if_mwxreg.h Log message: Implement MT7925 specific mcu_set_rts_thresh and mac_tx_free functions. With this MT7925 can associate to open APs in 11a/b/g modes. In my tests 11a works well, 2GHz 11g is very slow which is maybe because of all the 2GHz noise on that channel. Committed over my MT7925. CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/08 03:33:56 Modified files: share/man/man4 : Makefile Added files: share/man/man4 : mwx.4 Log message: Add mwx(4) manpage CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 03:34:02 Modified files: sysutils/py-filelock: Makefile distinfo sysutils/py-filelock/pkg: PLIST Log message: update to py3-filelock-4.0.11 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 03:44:59 Modified files: devel/libuv : Makefile distinfo Removed files: devel/libuv/patches: patch-src_unix_openbsd_c patch-test_test-get-currentexe_c Log message: update to libuv-1.53.0, from Brad CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 03:45:43 Modified files: sysutils/py-mitogen: Makefile distinfo Log message: update to py3-mitogen-0.3.54 CVSROOT: /cvs Module name: ports Changes by: kirill@cvs.openbsd.org 2026/10/08 03:52:04 Modified files: net/ejabberd : Tag: OPENBSD_8_0 Makefile distinfo modules.inc Log message: net/ejabberd: update to 26.09 It also fixes unauthenticated Remote Code Execution on ejabberd see: https://github.com/processone/ejabberd/releases/tag/26.09 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 04:02:30 Modified files: www/py-autobahn: Makefile distinfo www/py-autobahn/pkg: PFRAG.nvx PLIST Removed files: www/py-autobahn/patches: patch-autobahn_nvx__utf8validator_py Log message: update to py3-autobahn-26.7.1, ok tb stops using pkg_resources at runtime CVSROOT: /cvs Module name: ports Changes by: kirill@cvs.openbsd.org 2026/10/08 04:03:39 Modified files: devel/codex : Makefile crates.inc distinfo devel/codex/patches: patch-codex-rs_Cargo_toml patch-codex-rs_chatgpt_src_lib_rs patch-codex-rs_core_src_config_mod_rs patch-codex-rs_core_src_tools_handlers_apply_patch_rs patch-codex-rs_features_src_lib_rs Log message: devel/codex: update to 0.161.0 CVSROOT: /cvs Module name: ports Changes by: kirill@cvs.openbsd.org 2026/10/08 04:26:21 Modified files: net/rate-mirrors: Makefile crates.inc distinfo Log message: net/rate-mirrors: update to 0.33.0 Diff from Laurent Cheylus CVSROOT: /cvs Module name: ports Changes by: tb@cvs.openbsd.org 2026/10/08 04:27:13 Modified files: x11/arandr : Makefile x11/arandr/patches: patch-setup_py x11/arandr/pkg : PLIST Log message: arandr: add diff from gentoo to prepare for setuptools update "go ahead" edd (maintainer) CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 04:39:06 Modified files: devel/capstone/python: Makefile Added files: devel/capstone/python/patches: patch-bindings_python_capstone___init___py Removed files: devel/capstone/python/patches: patch-capstone___init___py Log message: don't override WRKDIST which is already correct; set WRKSRC to a subdir instead. update patch to match. CVSROOT: /cvs Module name: ports Changes by: tb@cvs.openbsd.org 2026/10/08 04:40:33 Modified files: devel/jujutsu : Makefile crates.inc distinfo devel/jujutsu/patches: patch-cli_tests_test_converge_command_rs devel/jujutsu/pkg: PLIST Log message: Update to jujutsu 0.46.0 Now with support for colocated workspaces and labeled diff hunks (finally) https://github.com/jj-vcs/jj/releases/tag/v0.46.0 CVSROOT: /cvs Module name: ports Changes by: tb@cvs.openbsd.org 2026/10/08 04:44:29 Removed files: devel/jujutsu/patches: patch-cli_tests_test_converge_command_rs Log message: jujutsu: forgot to remove empty patch CVSROOT: /cvs Module name: ports Changes by: fcambus@cvs.openbsd.org 2026/10/08 05:26:24 Modified files: net/dbip : Makefile.inc net/dbip/asn : distinfo net/dbip/city : distinfo net/dbip/country: distinfo Log message: Update dbip to 2026.10. CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 05:32:22 Modified files: editors/vim : Makefile net/librenms : Makefile www/squid : Makefile www/nextcloud/33: Makefile lang/php/8.3 : Makefile lang/lucee/v6 : Makefile Log message: drop "keep above 7.9-stable" comments CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 05:33:24 Modified files: devel/ccache : Makefile distinfo Added files: devel/ccache/patches: patch-unittest_test_argprocessing_cpp Log message: update to ccache-4.14.1 CVSROOT: /cvs Module name: ports Changes by: tb@cvs.openbsd.org 2026/10/08 05:48:54 Modified files: devel/jjui : Makefile distinfo modules.inc Log message: Update to jjui 0.10.11 https://github.com/idursun/jjui/releases/tag/v0.10.11 CVSROOT: /cvs Module name: xenocara Changes by: jca@cvs.openbsd.org 2026/10/08 06:06:48 Modified files: . : MODULES Log message: Fixup previous As explained by matthieu@ the intent of this file is to track the latest version available *upstream*, not the version we have. Here matthieu@ plans to merge the full update to xserver-21.1.25 etc soon. CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/08 06:42:37 Modified files: share/man/man4 : mwx.4 Log message: Drop the wording on firmware distribution that comes from manual pages for Intel wireless drivers. ok claudio@ CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/08 06:44:45 Modified files: share/man/man4 : mwx.4 Log message: Mediatek -> MediaTek; ok claudio@ CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/08 06:45:35 Modified files: share/man/man4 : pci.4 Log message: Xr mwx CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 06:48:18 Modified files: productivity : Makefile productivity/radicale: Makefile distinfo productivity/radicale/patches: patch-config patch-radicale_config_py productivity/radicale/pkg: PLIST README Removed files: productivity/radicale/patches: patch-logging patch-rights productivity/radicale/pkg: MESSAGE productivity/radicale2: Makefile distinfo productivity/radicale2/patches: patch-config patch-radicale_config_py productivity/radicale2/pkg: DESCR PLIST README radicale.rc Log message: merge productivity/radicale2 into productivity/radicale, we've been warning for long enough now. (sticking with same outdated version for now). CVSROOT: /cvs Module name: ports Changes by: fcambus@cvs.openbsd.org 2026/10/08 06:58:48 Modified files: sysutils/broot : Makefile crates.inc distinfo Log message: Update broot to 1.61.0. CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 07:07:40 Modified files: devel/py-click-plugins: Makefile distinfo Added files: devel/py-click-plugins/pkg: MESSAGE Log message: update to py3-click-plugins-1.1.1.2 See https://github.com/click-contrib/click-plugins - click-plugins is deprecated as a standalone distribution. Downstream users (in ports, these are gnuradio, py-fiona, py-supermercado, py-celery) should vendor it instead. CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 07:13:17 Modified files: www/py-genshi : Makefile distinfo www/py-genshi/pkg: PLIST Log message: update to py3-genshi-0.7.11 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 07:26:22 Modified files: devel/py-iso639: Makefile distinfo devel/py-iso639/pkg: DESCR PLIST Log message: update to py3-iso639-2026.7.23 (different pypi project, but the old one is 10y-abandoned and unused in ports) CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 07:40:20 Modified files: devel/capstone : Makefile.inc devel/capstone/main: distinfo devel/capstone/main/patches: patch-cs_c patch-include_capstone_capstone_h devel/capstone/python: Makefile distinfo devel/capstone/python/patches: patch-bindings_python_capstone___init___py devel/capstone/python/pkg: PLIST Added files: devel/capstone/python/patches: patch-bindings_python_Makefile Log message: update to capstone-5.0.9, ok benoit CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 07:42:21 Modified files: devel/capstone : Tag: OPENBSD_8_0 Makefile.inc devel/capstone/main: Tag: OPENBSD_8_0 distinfo devel/capstone/main/patches: Tag: OPENBSD_8_0 patch-cs_c patch-include_capstone_capstone_h devel/capstone/python: Tag: OPENBSD_8_0 Makefile distinfo devel/capstone/python/pkg: Tag: OPENBSD_8_0 PLIST Added files: devel/capstone/python/patches: Tag: OPENBSD_8_0 patch-bindings_python_Makefile patch-bindings_python_capstone___init___py Removed files: devel/capstone/python/patches: Tag: OPENBSD_8_0 patch-capstone___init___py Log message: update to capstone-5.0.9, ok benoit CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 07:46:55 Modified files: x11/py-pyglet : Makefile Log message: pyglet: update HOMEPAGE and tidy. (this is a bit overdue an update) CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 07:54:15 Modified files: www/py-repoze-who: Makefile distinfo www/py-repoze-who/pkg: PLIST Log message: update to py3-repoze-who-3.2.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 08:00:26 Modified files: databases/py-sqlobject: Makefile distinfo databases/py-sqlobject/pkg: PLIST Log message: update to py3-sqlobject-3.13.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 08:10:22 Modified files: devel/py-wcwidth: Makefile Log message: wcwidth moved from hatchling to setuptools because it started buikding a C extension; fix MODPY_PYBUILD. build failure reported by aja. CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/08 08:31:49 Modified files: share/man/man5 : python-module.5 Log message: minor polishing of macro use for consistency with port-modules(5) and bsd.port.mk(5), no text change: .Cm for make(1) targets, module names, and keywords/fixed strings .Ev for make(1) variables .Pa for file names .Fl for command line flags OK sthen@ CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 08:31:55 Modified files: devel/py-incremental: Makefile Log message: fix RDEP, this switched from pkg_resources to packaging to fetch version CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/08 08:32:35 Modified files: sys/dev/pci : if_mwx.c if_mwxreg.h Log message: Implement the functions to add and delete keys for MT7925. CVSROOT: /cvs Module name: ports Changes by: volker@cvs.openbsd.org 2026/10/08 08:37:59 Modified files: sysutils/moor : Makefile distinfo modules.inc Log message: sysutils/moor: Update to 2.19.2 From Maintainer Lydia Sobot, thanks CVSROOT: /cvs Module name: ports Changes by: volker@cvs.openbsd.org 2026/10/08 08:39:05 Modified files: sysutils/chezmoi: Makefile distinfo modules.inc Log message: sysutils/chezmoi: Update to 2.73.0 CVSROOT: /cvs Module name: ports Changes by: volker@cvs.openbsd.org 2026/10/08 08:40:37 Modified files: textproc/delta : Makefile distinfo Log message: textproc/delta: Update to 0.20.1 From Maintainter Laurent Cheylus, thanks CVSROOT: /cvs Module name: ports Changes by: volker@cvs.openbsd.org 2026/10/08 08:42:04 Modified files: wayland/mango : Makefile distinfo Log message: wayland/mango: Update to 0.17.5 CVSROOT: /cvs Module name: ports Changes by: volker@cvs.openbsd.org 2026/10/08 08:44:22 Modified files: wayland/wayvnc : Makefile distinfo Log message: wayland/wayvnc: Update to 0.10.2 CVSROOT: /cvs Module name: ports Changes by: volker@cvs.openbsd.org 2026/10/08 08:45:19 Modified files: net/neatvnc : Makefile distinfo Log message: net/neatvnc: Update to 1.0.3 CVSROOT: /cvs Module name: ports Changes by: tb@cvs.openbsd.org 2026/10/08 08:52:01 Modified files: lang/unicon : Makefile distinfo lang/unicon/patches: patch-configure_ac patch-src_h_config_h patch-src_h_sys_h patch-src_iconc_ccomp_c patch-tests_Makefile_test lang/unicon/pkg: PLIST Removed files: lang/unicon/patches: patch-ipl_cfuncs_fpoll_c patch-src_runtime_fmonitr_r patch-src_runtime_rsys_r patch-tests_posix_tcp_icn Log message: Update to unicon 13.3beta2, from espie CVSROOT: /cvs Module name: ports Changes by: volker@cvs.openbsd.org 2026/10/08 08:52:30 Modified files: wayland/xwayland: Makefile distinfo Log message: wayland/xwayland: Update to 24.1.14 From yaydn (at) protonmail ok matthieu@ CVSROOT: /cvs Module name: ports Changes by: volker@cvs.openbsd.org 2026/10/08 09:02:56 Modified files: lang/gleam : Makefile crates.inc distinfo lang/gleam/patches: patch-compiler-cli_src_beam_compiler_rs patch-compiler-cli_src_run_rs patch-compiler-cli_src_shell_rs patch-compiler-core_src_build_project_compiler_rs patch-compiler-core_src_error_rs Added files: lang/gleam/patches: patch-modcargo-crates_psm-0_1_32_src_arch_aarch64_armasm_asm patch-modcargo-crates_psm-0_1_32_src_arch_aarch_aapcs64_s patch-modcargo-crates_psm-0_1_32_src_arch_x86_64_s patch-modcargo-crates_psm-0_1_32_src_arch_x86_s Removed files: lang/gleam/patches: patch-modcargo-crates_psm-0_1_26_src_arch_aarch64_armasm_asm patch-modcargo-crates_psm-0_1_26_src_arch_aarch_aapcs64_s patch-modcargo-crates_psm-0_1_26_src_arch_x86_64_s patch-modcargo-crates_psm-0_1_26_src_arch_x86_s Log message: lang/gleam: Update to 1.19.1 CVSROOT: /cvs Module name: ports Changes by: volker@cvs.openbsd.org 2026/10/08 09:06:33 Modified files: shells/nushell : Makefile crates.inc distinfo Removed files: shells/nushell/patches: patch-Cargo_toml patch-tests_repl_test_config_path_rs Log message: shells/nushell: Update to 0.116.1 CVSROOT: /cvs Module name: www Changes by: krw@cvs.openbsd.org 2026/10/08 09:34:20 Modified files: . : 80.html Log message: Some re/softraid/esp fixes in 8.0. CVSROOT: /cvs Module name: src Changes by: schwarze@cvs.openbsd.org 2026/10/08 09:36:40 Modified files: share/man/man4 : pci.4 ohci.4 Log message: remove references to loongson-only drivers that we no longer ship; OK miod@ visa@ CVSROOT: /cvs Module name: ports Changes by: bket@cvs.openbsd.org 2026/10/08 10:40:20 Modified files: sysutils/xxhash: Makefile distinfo sysutils/xxhash/patches: patch-Makefile patch-xxhash_h Log message: Update to xxhash-0.8.4 Changes: https://github.com/Cyan4973/xxHash/releases/tag/v0.8.4 Tested by sthen@ on aarch64 and i386, by jca@ on riscv64, by tb@ on sparc64, and by me on amd64. OK sthen@, jca@, tb@ CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 10:43:49 ports/devel/py-zc-lockfile/patches Update of /cvs/ports/devel/py-zc-lockfile/patches In directory cvs.openbsd.org:/tmp/cvs-serv49578/patches Log Message: Directory /cvs/ports/devel/py-zc-lockfile/patches added to the repository CVSROOT: /cvs Module name: ports Changes by: bket@cvs.openbsd.org 2026/10/08 10:45:29 Modified files: security/vaultwarden: Tag: OPENBSD_8_0 Makefile crates.inc distinfo Log message: Update to vaultwarden-1.37.4 This release contains security fixes: - Organization member revocation [GHSA-69q9-v8p6-xvx3] - Two-factor authentication [GHSA-7jg8-8m5x-6j9r] - Organization invitations [GHSA-v576-3wvq-xh3c] - Attachments [GHSA-q5x6-grh5-fqgc] - Organization event logs [GHSA-64mc-4p6f-r7x9] - Cipher sharing [GHSA-7ccc-c43j-4p36] - Organization API key [GHSA-qwx4-wcv4-mpcv] Changes: https://github.com/dani-garcia/vaultwarden/releases/tag/1.37.4 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 10:47:22 ports/devel/py-zopetesting/patches Update of /cvs/ports/devel/py-zopetesting/patches In directory cvs.openbsd.org:/tmp/cvs-serv54201/patches Log Message: Directory /cvs/ports/devel/py-zopetesting/patches added to the repository CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 10:48:32 Modified files: devel/py-zopetesting: Makefile distinfo devel/py-zopetesting/pkg: PLIST Added files: devel/py-zopetesting/patches: patch-pyproject_toml Log message: update to py3-zopetesting-6.2, stops using pkg_resources CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 10:49:00 Modified files: devel/py-zc-lockfile: Makefile distinfo devel/py-zc-lockfile/pkg: PLIST Added files: devel/py-zc-lockfile/patches: patch-pyproject_toml Log message: update to py3-zc-lockfile-4.0, stops using pkg_resources CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 11:14:16 Modified files: security : Makefile Removed files: security/py-axolotl: Makefile distinfo security/py-axolotl/pkg: DESCR PLIST security/py-axolotl-curve25519: Makefile distinfo security/py-axolotl-curve25519/patches: patch-curve25519module_c security/py-axolotl-curve25519/pkg: DESCR PLIST Log message: drop py-axolotl and py-axolotl-curve25519, imported in 6.5, never used, untouched upstream since 2018, broken with current py-protobuf CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 11:16:06 Modified files: devel/quirks : Makefile devel/quirks/files: Quirks.pm Log message: quirks for py-axolotl, py-axolotl-curve25519 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 11:19:22 Modified files: www/py-mastodon.py: Makefile Log message: add comment with the normalized distname format for newer versions CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 11:22:13 Modified files: devel/py-bencode: Makefile distinfo devel/py-bencode/pkg: PLIST Removed files: devel/py-bencode/patches: patch-setup_cfg Log message: update to py3-bencode-4.1.0 switch to github upstream for tests CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 11:26:54 Modified files: devel/quirks : Makefile devel/quirks/files: Quirks.pm devel : Makefile Removed files: devel/py-straight.plugin: Makefile distinfo devel/py-straight.plugin/pkg: DESCR PLIST Log message: drop devel/py-straight.plugin, used to be needed for building Ansible docs, but not any more. doesn't work with py314. CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 11:28:56 Modified files: devel/py-wheezy.template: Makefile distinfo devel/py-wheezy.template/pkg: PLIST Log message: update to py3-wheezy.template-3.2.5 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 11:30:39 ports/devel/py-zopecomponent/patches Update of /cvs/ports/devel/py-zopecomponent/patches In directory cvs.openbsd.org:/tmp/cvs-serv18968/patches Log Message: Directory /cvs/ports/devel/py-zopecomponent/patches added to the repository CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 11:30:58 Modified files: devel/py-zopecomponent: Makefile distinfo devel/py-zopecomponent/pkg: PLIST Added files: devel/py-zopecomponent/patches: patch-pyproject_toml Log message: update to py3-zopecomponent-7.1, drops use of pkg_resources CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 11:32:27 Modified files: devel/py-zopeevent: Makefile distinfo devel/py-zopeevent/pkg: PLIST Log message: update to py3-zopeevent-6.2, drops use of pkg_resources CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 11:34:05 Modified files: devel/py-zopeinterface: Makefile distinfo devel/py-zopeinterface/pkg: PLIST Removed files: devel/py-zopeinterface/patches: patch-pyproject_toml Log message: update to py3-zopeinterface-8.6, drops use of pkg_resources CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 11:36:59 Modified files: www/py-repoze-lru: Makefile distinfo www/py-repoze-lru/pkg: PLIST Log message: update to py3-repoze-lru-0.8, drop pkg_resources CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/08 11:40:48 Modified files: faq/pf : nat.html Log message: add missing

tag CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/08 11:41:40 Modified files: . : security.html Log message: add errata80 link CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 11:43:34 Modified files: www/py-formencode: Makefile distinfo www/py-formencode/pkg: PLIST Log message: update to py3-formencode-2.1.1, drops use of pkg_resources CVSROOT: /cvs Module name: src Changes by: miod@cvs.openbsd.org 2026/10/08 12:19:31 Modified files: sys/dev/wscons : wsdisplay.c Log message: Better malloc() bounds check and low-memory behaviour in WSDISPLAYIO_LDFONT ioctl. Shortcomings reported by Acts1631. CVSROOT: /cvs Module name: ports Changes by: bket@cvs.openbsd.org 2026/10/08 12:47:44 Modified files: sysutils : Makefile devel/quirks : Makefile devel/quirks/files: Quirks.pm Removed files: sysutils/bupstash: Makefile distinfo sysutils/bupstash/pkg: DESCR PLIST Log message: Remove bupstash Backup software handles critical data and therefore requires a healthy and actively maintained upstream. With upstream development inactive since June 2023, there is insufficient confidence in its long-term maintenance, compatibility, and security. Users already had been warned via DESCR that the tool is unmaintained and may be removed. OK sthen@, gonzalo@ CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/08 12:49:06 Modified files: sys/dev/pci : if_mwx.c Log message: Sprinkle some #ifndef IEEE80211_STA_ONLY around to make this compile as part of RAMDISK_CD CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/08 12:54:03 Modified files: sys/arch/amd64/conf: GENERIC RAMDISK_CD Log message: add mwx(4), a driver for Mediatek MT792x wifi devices CVSROOT: /cvs Module name: ports Changes by: sebastia@cvs.openbsd.org 2026/10/08 14:25:53 Log message: import sevenzipjbinding 7-Zip-JBinding is a free cross-platform java binding of 7-Zip free compress/decompress library. Needed as dependency for upcoming Autopsy port various feedback and suggestions, and final OK kurt@ Status: Vendor Tag: sebastia Release Tags: sebastia_20261008 N ports/archivers/sevenzipjbinding/Makefile N ports/archivers/sevenzipjbinding/distinfo N ports/archivers/sevenzipjbinding/patches/patch-CMakeLists_txt N ports/archivers/sevenzipjbinding/patches/patch-cmake_FindJavaExtended_cmake N ports/archivers/sevenzipjbinding/patches/patch-jbinding-cpp_CMakeLists_txt N ports/archivers/sevenzipjbinding/patches/patch-p7zip_CPP_7zip_Archive_Wim_WimHandler_cpp N ports/archivers/sevenzipjbinding/pkg/DESCR N ports/archivers/sevenzipjbinding/pkg/PLIST No conflicts created by this import CVSROOT: /cvs Module name: ports Changes by: sebastia@cvs.openbsd.org 2026/10/08 14:26:43 Modified files: archivers : Makefile Log message: Hook up sevenzipjbinding CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/08 14:37:05 Modified files: sys/net : pf.c Log message: In pf(4) check AH header length. pf_walk_header() advances the packet offset for each AH extension header. It was not checked that this does not exceed the packet length if no next header was processed. Fix it like in IPv6. OK henning@ sashan@ CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/08 14:58:24 Modified files: usr.bin/pkgconf/cli: core.c usr.bin/pkgconf/libpkgconf: config.h libpkgconf.h usr.bin/pkgconf/man: pkgconf.1 Log message: Update to pkgconf 3.0.8 No binary change apart from the version number bump. CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/08 14:59:06 Modified files: regress/usr.bin/pkgconf: Makefile Makefile.lite regress/usr.bin/pkgconf/t/basic: builtin-pkg-config-pc_path-variable.test builtin-pkgconf-pc_path-variable.test regress/usr.bin/pkgconf/tests/api: test-oom-spdxtool.c Log message: pkgconf regress: update to 3.0.8 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 15:17:09 Modified files: sysutils/py-ansible-libssh: Makefile distinfo sysutils/py-ansible-libssh/pkg: PLIST Log message: update to py3-ansible-libssh-1.4.0, ok denis CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 15:22:05 Modified files: devel/py-incremental: Makefile Log message: fix RDEP CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 15:34:19 Modified files: net/synapse : Makefile Log message: drop setuptools RDEP, synapse removed use of pkg_resources a while ago ok renaud CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 15:45:30 Added files: devel/py-makefun/patches: patch-setup_py Log message: take patch from a PR to drop use of pkg_resources durimg build CVSROOT: /cvs Module name: ports Changes by: fcambus@cvs.openbsd.org 2026/10/08 16:59:07 Modified files: benchmarks/hyperfine: Makefile crates.inc distinfo Log message: Update hyperfine to 2.0.0. CVSROOT: /cvs Module name: ports Changes by: fcambus@cvs.openbsd.org 2026/10/08 17:25:10 Modified files: archivers/lzip/tarlz: Makefile distinfo Log message: Update tarlz to 0.31. CVSROOT: /cvs Module name: ports Changes by: fcambus@cvs.openbsd.org 2026/10/08 17:30:56 Modified files: www/newsboat : Makefile crates.inc distinfo www/newsboat/patches: patch-Makefile Log message: Update newsboat to 2.45. CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/08 18:49:50 Modified files: usr.sbin/httpd : Makefile usr.sbin/smtpd/smtpctl: Makefile usr.sbin/smtpd/smtpd-ca: Makefile usr.sbin/smtpd/smtpd-control: Makefile usr.sbin/smtpd/smtpd-dispatcher: Makefile usr.sbin/smtpd/smtpd-lka: Makefile usr.sbin/smtpd/smtpd-queue: Makefile usr.sbin/smtpd/smtpd-scheduler: Makefile usr.sbin/smtpd/smtpd: Makefile Log message: we may as well install the relinked binaries as x,og-r ok millert dgl CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 21:44:54 Modified files: devel/py-zc-lockfile: Makefile Log message: unbreak previous, drop RDEP accidentally committed that won't be needed for this now anyway CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 23:37:31 Modified files: games/pokerth : Makefile Log message: redo "legacy" handling; FLAVOR must be set _before_ pulling in bsd.port.arch.mk CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/08 23:37:51 Modified files: games/pokerth : Tag: OPENBSD_8_0 Makefile Log message: redo "legacy" handling; FLAVOR must be set _before_ pulling in bsd.port.arch.mk CVSROOT: /cvs Module name: ports Changes by: bket@cvs.openbsd.org 2026/10/08 23:52:41 Modified files: devel/gdb : Makefile lang/php/8.3 : Makefile lang/php/8.4 : Makefile lang/php/8.5 : Makefile net/py-grpcio : Makefile net/rsync : Makefile Log message: Bump REVISION: updated header-only dependency sysutils/xxhash Feedback and OK sthen@ CVSROOT: /cvs Module name: ports Changes by: robert@cvs.openbsd.org 2026/10/09 00:06:39 Modified files: www/chromium : Makefile distinfo www/chromium/patches: patch-BUILD_gn patch-base_BUILD_gn patch-base_allocator_partition_allocator_partition_alloc_gni patch-base_allocator_partition_allocator_src_partition_alloc_BUILD_gn patch-base_allocator_partition_allocator_src_partition_alloc_page_allocator_internals_posix_cc patch-base_allocator_partition_allocator_src_partition_alloc_partition_alloc_base_rand_util_posix_cc patch-base_allocator_partition_allocator_src_partition_alloc_partition_root_cc patch-base_files_file_path_watcher_h patch-base_files_file_util_unittest_cc patch-base_memory_platform_shared_memory_region_h patch-base_memory_platform_shared_memory_region_posix_cc patch-base_process_process_posix_cc patch-base_system_sys_info_h patch-build_config_BUILDCONFIG_gn patch-build_config_clang_BUILD_gn patch-build_config_compiler_BUILD_gn patch-build_config_linux_libdrm_BUILD_gn patch-build_linux_strip_binary_gni patch-build_toolchain_gcc_toolchain_gni patch-chrome_app_chrome_main_delegate_cc patch-chrome_browser_about_flags_cc patch-chrome_browser_apps_platform_apps_platform_app_launch_cc patch-chrome_browser_background_extensions_background_mode_manager_cc patch-chrome_browser_browser_features_cc patch-chrome_browser_browser_process_impl_cc patch-chrome_browser_browser_process_impl_h patch-chrome_browser_browsing_data_chrome_browsing_data_remover_delegate_cc patch-chrome_browser_chrome_browser_interface_binders_cc patch-chrome_browser_chrome_browser_interface_binders_webui_cc patch-chrome_browser_chrome_browser_interface_binders_webui_parts_desktop_cc patch-chrome_browser_chrome_browser_main_cc patch-chrome_browser_chrome_browser_main_linux_cc patch-chrome_browser_chrome_browser_main_linux_h patch-chrome_browser_chrome_content_browser_client_cc patch-chrome_browser_chrome_content_browser_client_navigation_throttles_cc patch-chrome_browser_component_updater_registration_cc patch-chrome_browser_component_updater_wasm_tts_engine_component_installer_cc patch-chrome_browser_download_chrome_download_manager_delegate_cc patch-chrome_browser_download_download_file_picker_cc patch-chrome_browser_download_download_item_model_cc patch-chrome_browser_enterprise_connectors_connectors_service_cc patch-chrome_browser_enterprise_connectors_device_trust_device_trust_connector_service_factory_cc patch-chrome_browser_enterprise_util_managed_browser_utils_cc patch-chrome_browser_extensions_BUILD_gn patch-chrome_browser_extensions_api_enterprise_reporting_private_enterprise_reporting_private_api_cc patch-chrome_browser_extensions_api_passwords_private_passwords_private_delegate_impl_cc patch-chrome_browser_extensions_api_runtime_chrome_runtime_api_delegate_cc patch-chrome_browser_extensions_api_settings_private_prefs_util_cc patch-chrome_browser_extensions_api_tabs_tabs_api_cc patch-chrome_browser_extensions_external_provider_impl_cc patch-chrome_browser_file_system_access_chrome_file_system_access_permission_context_cc patch-chrome_browser_flag_descriptions_h patch-chrome_browser_glic_glic_settings_util_desktop_cc patch-chrome_browser_glic_host_guest_util_cc patch-chrome_browser_glic_public_features_cc patch-chrome_browser_glic_service_glic_instance_impl_cc patch-chrome_browser_glic_widget_glic_widget_cc patch-chrome_browser_global_features_cc patch-chrome_browser_global_features_h patch-chrome_browser_intranet_redirect_detector_h patch-chrome_browser_media_galleries_media_file_system_registry_cc patch-chrome_browser_media_webrtc_desktop_media_picker_controller_cc patch-chrome_browser_memory_details_cc patch-chrome_browser_metrics_BUILD_gn patch-chrome_browser_metrics_chrome_browser_main_extra_parts_metrics_cc patch-chrome_browser_metrics_chrome_browser_main_extra_parts_metrics_h patch-chrome_browser_metrics_power_process_monitor_cc patch-chrome_browser_metrics_power_process_monitor_h patch-chrome_browser_net_profile_network_context_service_cc patch-chrome_browser_new_tab_page_modules_file_suggestion_drive_service_cc patch-chrome_browser_notifications_notification_display_service_impl_cc patch-chrome_browser_password_manager_chrome_password_manager_client_cc patch-chrome_browser_policy_chrome_browser_cloud_management_controller_desktop_cc patch-chrome_browser_policy_configuration_policy_handler_list_factory_cc patch-chrome_browser_policy_policy_value_and_status_aggregator_cc patch-chrome_browser_prefs_browser_prefs_cc patch-chrome_browser_prefs_pref_service_incognito_allowlist_cc patch-chrome_browser_private_verification_tokens_BUILD_gn patch-chrome_browser_private_verification_tokens_private_verification_tokens_service_cc patch-chrome_browser_private_verification_tokens_private_verification_tokens_service_factory_cc patch-chrome_browser_private_verification_tokens_private_verification_tokens_url_loader_throttle_cc patch-chrome_browser_profiles_chrome_browser_main_extra_parts_profiles_cc patch-chrome_browser_profiles_profile_impl_cc patch-chrome_browser_renderer_context_menu_render_view_context_menu_cc patch-chrome_browser_resources_settings_autofill_page_passwords_passwords_shared_css patch-chrome_browser_safe_browsing_chrome_password_protection_service_cc patch-chrome_browser_sessions_session_restore_cc patch-chrome_browser_sharing_sharing_handler_registry_impl_cc patch-chrome_browser_signin_chrome_signin_client_cc patch-chrome_browser_supervised_user_classify_url_navigation_throttle_cc patch-chrome_browser_supervised_user_supervised_user_browser_utils_cc patch-chrome_browser_supervised_user_supervised_user_browser_utils_h patch-chrome_browser_supervised_user_supervised_user_navigation_observer_cc patch-chrome_browser_sync_chrome_sync_controller_builder_cc patch-chrome_browser_sync_sync_service_factory_cc patch-chrome_browser_task_manager_sampling_task_group_h patch-chrome_browser_task_manager_sampling_task_manager_impl_cc patch-chrome_browser_ui_accelerator_table_cc patch-chrome_browser_ui_actions_chrome_action_id_h patch-chrome_browser_ui_autofill_chrome_autofill_client_cc patch-chrome_browser_ui_browser_actions_cc patch-chrome_browser_ui_browser_command_controller_cc patch-chrome_browser_ui_browser_commands_cc patch-chrome_browser_ui_browser_window_internal_browser_window_features_cc patch-chrome_browser_ui_browser_window_public_browser_window_features_h patch-chrome_browser_ui_browser_window_public_create_browser_window_h patch-chrome_browser_ui_chrome_pages_cc patch-chrome_browser_ui_infobars_browser_infobar_registry_cc patch-chrome_browser_ui_prefs_pref_watcher_cc patch-chrome_browser_ui_sad_tab_cc patch-chrome_browser_ui_signin_signin_view_controller_cc patch-chrome_browser_ui_signin_signin_view_controller_h patch-chrome_browser_ui_startup_bad_flags_prompt_cc patch-chrome_browser_ui_startup_startup_browser_creator_cc patch-chrome_browser_ui_startup_startup_browser_creator_impl_cc patch-chrome_browser_ui_startup_url_util_cc patch-chrome_browser_ui_tab_helpers_cc patch-chrome_browser_ui_tabs_public_tab_features_h patch-chrome_browser_ui_tabs_tab_features_cc patch-chrome_browser_ui_task_manager_task_manager_columns_h patch-chrome_browser_ui_task_manager_task_manager_table_model_cc patch-chrome_browser_ui_test_test_browser_ui_cc patch-chrome_browser_ui_toolbar_app_menu_icon_controller_cc patch-chrome_browser_ui_toolbar_app_menu_model_cc patch-chrome_browser_ui_ui_features_cc patch-chrome_browser_ui_ui_features_h patch-chrome_browser_ui_views_data_sharing_collaboration_controller_delegate_desktop_cc patch-chrome_browser_ui_views_frame_browser_view_cc patch-chrome_browser_ui_views_frame_browser_widget_cc patch-chrome_browser_ui_views_frame_contents_web_view_cc patch-chrome_browser_ui_views_frame_horizontal_tab_strip_region_view_cc patch-chrome_browser_ui_views_frame_layout_browser_view_app_layout_impl_cc patch-chrome_browser_ui_views_frame_layout_browser_view_tabbed_layout_impl_cc patch-chrome_browser_ui_views_frame_system_menu_model_builder_cc patch-chrome_browser_ui_views_hung_renderer_view_cc patch-chrome_browser_ui_views_location_bar_location_bar_view_cc patch-chrome_browser_ui_views_new_tab_footer_footer_controller_cc patch-chrome_browser_ui_views_passwords_password_bubble_view_base_cc patch-chrome_browser_ui_views_profiles_avatar_toolbar_button_state_manager_cc patch-chrome_browser_ui_views_profiles_first_run_flow_controller_cc patch-chrome_browser_ui_views_profiles_profile_menu_coordinator_cc patch-chrome_browser_ui_views_profiles_profile_menu_view_cc patch-chrome_browser_ui_views_profiles_profile_picker_view_cc patch-chrome_browser_ui_views_profiles_signin_view_controller_delegate_views_cc patch-chrome_browser_ui_views_profiles_signin_view_controller_delegate_views_h patch-chrome_browser_ui_views_tabs_common_tab_group_header_view_cc patch-chrome_browser_ui_views_tabs_dragging_tab_drag_controller_cc patch-chrome_browser_ui_views_tabs_tab_cc patch-chrome_browser_ui_views_toolbar_toolbar_view_cc patch-chrome_browser_ui_views_user_education_browser_user_education_service_cc patch-chrome_browser_ui_views_web_apps_web_app_integration_test_driver_cc patch-chrome_browser_ui_web_applications_app_browser_controller_cc patch-chrome_browser_ui_webui_app_home_app_home_page_handler_cc patch-chrome_browser_ui_webui_browser_webui_browser_window_cc patch-chrome_browser_ui_webui_chrome_web_ui_configs_cc patch-chrome_browser_ui_webui_cr_components_searchbox_searchbox_handler_cc patch-chrome_browser_ui_webui_infobar_internals_infobar_internals_handler_cc patch-chrome_browser_ui_webui_interstitials_interstitial_ui_cc patch-chrome_browser_ui_webui_intro_intro_ui_cc patch-chrome_browser_ui_webui_settings_settings_localized_strings_provider_cc patch-chrome_browser_ui_webui_settings_site_settings_handler_cc patch-chrome_browser_ui_webui_side_panel_customize_chrome_customize_chrome_page_handler_cc patch-chrome_browser_ui_webui_signin_profile_picker_handler_cc patch-chrome_browser_ui_webui_user_education_internals_user_education_internals_page_handler_impl_cc patch-chrome_browser_ui_window_sizer_window_sizer_cc patch-chrome_browser_visited_url_ranking_visited_url_ranking_service_factory_cc patch-chrome_browser_web_applications_commands_launch_web_app_command_cc patch-chrome_common_chrome_features_cc patch-chrome_common_chrome_features_h patch-chrome_common_chrome_paths_cc patch-chrome_common_chrome_switches_h patch-chrome_common_controlled_frame_controlled_frame_cc patch-chrome_common_extensions_extension_constants_h patch-chrome_common_pref_names_h patch-chrome_common_url_constants_h patch-chrome_common_webui_url_constants_cc patch-chrome_common_webui_url_constants_h patch-chrome_renderer_chrome_content_renderer_client_cc patch-chrome_utility_services_cc patch-components_BUILD_gn patch-components_autofill_content_renderer_at_memory_handler_cc patch-components_autofill_core_browser_foundations_browser_autofill_manager_cc patch-components_autofill_core_browser_suggestions_payments_credit_card_suggestion_generator_cc patch-components_autofill_core_common_autofill_payments_features_cc patch-components_cbor_BUILD_gn patch-components_commerce_core_commerce_feature_list_cc patch-components_device_signals_core_common_platform_utils_cc patch-components_enterprise_browser_reporting_chrome_profile_request_generator_cc patch-components_feature_engagement_public_feature_configurations_cc patch-components_feature_engagement_public_feature_constants_cc patch-components_feature_engagement_public_feature_constants_h patch-components_feature_engagement_public_feature_list_cc patch-components_feature_engagement_public_feature_list_h patch-components_gwp_asan_crash_handler_crash_analyzer_cc patch-components_metrics_metrics_log_cc patch-components_optimization_guide_core_optimization_guide_util_cc patch-components_password_manager_core_browser_features_password_features_cc patch-components_password_manager_core_browser_features_password_features_h patch-components_password_manager_core_browser_password_autofill_manager_h patch-components_password_manager_core_browser_password_manual_fallback_flow_h patch-components_password_manager_core_browser_password_store_login_database_async_helper_cc patch-components_password_manager_core_common_password_manager_pref_names_h patch-components_policy_core_browser_policy_pref_mapping_test_cc patch-components_private_verification_tokens_BUILD_gn patch-components_private_verification_tokens_common_BUILD_gn patch-components_signin_internal_identity_manager_account_capabilities_list_h patch-components_signin_public_base_signin_switches_cc patch-components_signin_public_base_signin_switches_h patch-components_signin_public_identity_manager_account_capabilities_cc patch-components_signin_public_identity_manager_account_capabilities_h patch-components_soda_soda_util_cc patch-components_startup_metric_utils_browser_startup_metric_utils_cc patch-components_startup_metric_utils_browser_startup_metric_utils_h patch-components_supervised_user_core_common_features_cc patch-components_sync_base_features_cc patch-components_user_education_views_help_bubble_view_cc patch-components_variations_service_variations_service_cc patch-components_viz_host_gpu_host_impl_cc patch-components_viz_service_display_embedder_skia_output_surface_impl_cc patch-components_viz_service_frame_sinks_root_compositor_frame_sink_impl_cc patch-components_viz_service_gl_gpu_service_impl_cc patch-components_viz_service_gl_gpu_service_impl_h patch-content_app_BUILD_gn patch-content_app_content_main_runner_impl_cc patch-content_browser_BUILD_gn patch-content_browser_browser_child_process_host_impl_cc patch-content_browser_browser_main_loop_cc patch-content_browser_child_process_launcher_helper_linux_cc patch-content_browser_child_thread_type_switcher_linux_cc patch-content_browser_devtools_protocol_system_info_handler_cc patch-content_browser_gpu_compositor_util_cc patch-content_browser_gpu_gpu_data_manager_impl_cc patch-content_browser_gpu_gpu_data_manager_impl_h patch-content_browser_gpu_gpu_data_manager_impl_private_cc patch-content_browser_gpu_gpu_data_manager_impl_private_h patch-content_browser_gpu_gpu_process_host_cc patch-content_browser_media_frameless_media_interface_proxy_h patch-content_browser_renderer_host_render_process_host_impl_cc patch-content_browser_renderer_host_render_process_host_impl_h patch-content_browser_renderer_host_render_process_host_impl_receiver_bindings_cc patch-content_browser_renderer_host_render_view_host_impl_cc patch-content_browser_renderer_host_render_widget_host_view_aura_cc patch-content_browser_renderer_host_render_widget_host_view_aura_h patch-content_browser_renderer_host_render_widget_host_view_event_handler_cc patch-content_browser_service_host_utility_process_host_cc patch-content_browser_service_host_utility_sandbox_delegate_cc patch-content_browser_web_contents_slow_web_preference_cache_cc patch-content_browser_web_contents_web_contents_impl_cc patch-content_browser_zygote_host_zygote_host_impl_linux_cc patch-content_browser_zygote_host_zygote_host_impl_linux_h patch-content_common_features_cc patch-content_common_features_h patch-content_gpu_gpu_child_thread_cc patch-content_gpu_gpu_main_cc patch-content_public_common_content_features_cc patch-content_renderer_render_thread_impl_cc patch-content_shell_BUILD_gn patch-content_shell_browser_shell_browser_main_parts_cc patch-content_utility_services_cc patch-content_utility_utility_main_cc patch-device_gamepad_public_cpp_gamepad_features_cc patch-device_gamepad_public_cpp_gamepad_features_h patch-extensions_browser_api_api_browser_context_keyed_service_factories_cc patch-extensions_common_features_feature_cc patch-gpu_command_buffer_client_test_shared_image_interface_cc patch-gpu_command_buffer_service_dawn_context_provider_cc patch-gpu_command_buffer_service_gles2_cmd_decoder_cc patch-gpu_command_buffer_service_shared_context_state_cc patch-gpu_command_buffer_service_shared_context_state_h patch-gpu_command_buffer_service_shared_image_shared_image_factory_cc patch-gpu_command_buffer_service_shared_image_shared_image_manager_cc patch-gpu_command_buffer_service_webgpu_decoder_impl_cc patch-gpu_config_gpu_finch_features_cc patch-gpu_ipc_service_gpu_init_cc patch-headless_lib_browser_headless_web_contents_impl_cc patch-media_base_media_switches_cc patch-media_base_media_switches_h patch-media_gpu_chromeos_mailbox_video_frame_converter_cc patch-media_gpu_chromeos_video_decoder_pipeline_cc patch-media_media_options_gni patch-media_mojo_mojom_BUILD_gn patch-media_mojo_mojom_video_frame_mojom_traits_cc patch-media_video_mappable_shared_image_video_frame_pool_cc patch-media_webrtc_audio_processor_cc patch-mojo_public_tools_bindings_mojom_gni patch-net_BUILD_gn patch-net_base_features_cc patch-net_proxy_resolution_proxy_config_service_linux_cc patch-net_websockets_websocket_basic_stream_adapters_test_cc patch-pdf_pdfium_pdfium_engine_cc patch-remoting_host_daemon_process_cc patch-remoting_host_ipc_desktop_environment_cc patch-remoting_host_ipc_desktop_environment_h patch-remoting_host_it2me_it2me_host_cc patch-remoting_host_peer_session_impl_cc patch-remoting_host_remoting_me2me_host_cc patch-remoting_protocol_webrtc_transport_cc patch-sandbox_policy_features_cc patch-sandbox_policy_features_h patch-sandbox_policy_sandbox_type_cc patch-services_network_BUILD_gn patch-services_network_network_context_cc patch-services_network_network_context_h patch-services_network_network_service_cc patch-services_network_network_service_h patch-services_network_public_cpp_BUILD_gn patch-services_network_public_mojom_BUILD_gn patch-services_screen_ai_public_cpp_utilities_cc patch-services_screen_ai_screen_ai_service_impl_cc patch-services_tracing_public_cpp_stack_sampling_tracing_sampler_profiler_cc patch-services_viz_public_mojom_BUILD_gn patch-services_webnn_public_cpp_webnn_sandbox_init_cc patch-skia_ext_font_utils_cc patch-third_party_angle_BUILD_gn patch-third_party_angle_src_libANGLE_Display_cpp patch-third_party_blink_common_features_cc patch-third_party_blink_renderer_controller_blink_initializer_cc patch-third_party_blink_renderer_core_execution_context_navigator_base_cc patch-third_party_blink_renderer_core_exported_web_view_impl_cc patch-third_party_blink_renderer_core_frame_web_frame_test_cc patch-third_party_blink_renderer_core_html_canvas_canvas_async_blob_creator_cc patch-third_party_blink_renderer_core_layout_layout_view_cc patch-third_party_blink_renderer_core_scroll_scrollbar_theme_aura_cc patch-third_party_blink_renderer_modules_webgl_webgl_rendering_context_base_cc patch-third_party_blink_renderer_modules_webgpu_gpu_canvas_context_cc patch-third_party_blink_renderer_platform_BUILD_gn patch-third_party_blink_renderer_platform_fonts_BUILD_gn patch-third_party_blink_renderer_platform_fonts_skia_font_cache_skia_cc patch-third_party_blink_renderer_platform_graphics_canvas_2d_resource_provider_cc patch-third_party_blink_renderer_platform_graphics_canvas_non_2d_resource_provider_cc patch-third_party_blink_renderer_platform_runtime_enabled_features_json5 patch-third_party_crashpad_crashpad_client_crashpad_client_posix_cc patch-third_party_crashpad_crashpad_util_posix_close_multiple_cc patch-third_party_iamf_tools_src_iamf_cli_codec_opus_utils_cc patch-third_party_perfetto_src_base_android_utils_cc patch-third_party_perfetto_src_base_string_utils_cc patch-third_party_webrtc_BUILD_gn patch-third_party_webrtc_rtc_base_cpu_info_cc patch-tools_gn_build_gen_py patch-tools_perf_chrome_telemetry_build_BUILD_gn patch-ui_accessibility_accessibility_features_cc patch-ui_accessibility_accessibility_features_h patch-ui_accessibility_ax_node_cc patch-ui_base_ui_base_features_cc patch-ui_base_ui_base_features_h patch-ui_compositor_compositor_cc patch-ui_gfx_font_util_cc patch-ui_gl_BUILD_gn patch-ui_gl_gl_switches_cc patch-ui_gtk_printing_print_dialog_gtk_cc patch-ui_ozone_platform_wayland_BUILD_gn patch-ui_ozone_platform_wayland_host_wayland_frame_manager_cc patch-ui_views_BUILD_gn patch-ui_views_controls_textfield_textfield_cc patch-ui_views_controls_textfield_textfield_h patch-ui_views_focus_focus_manager_cc patch-ui_views_widget_widget_cc patch-ui_webui_webui_features_gni patch-v8_BUILD_gn patch-v8_src_api_api_cc patch-v8_src_execution_isolate_cc patch-v8_src_flags_flags_cc Added files: www/chromium/patches: patch-chrome_browser_background_omnibox_everywhere_omnibox_everywhere_background_mode_manager_cc patch-chrome_browser_sessions_session_service_cc patch-chrome_browser_ui_toasts_toast_service_cc patch-chrome_browser_ui_views_scheduled_restart_scheduled_restart_bubble_controller_cc patch-chrome_browser_ui_views_toolbar_webui_toolbar_web_view_cc patch-chrome_browser_ui_webui_new_tab_page_new_tab_page_handler_cc patch-components_autofill_core_browser_suggestions_payments_payments_suggestion_generator_util_cc patch-content_app_initialize_mojo_core_cc patch-content_public_common_zygote_zygote_handle_h patch-device_bluetooth_BUILD_gn patch-mojo_core_embedder_configuration_h patch-net_cert_ev_root_ca_metadata_h patch-third_party_blink_renderer_platform_graphics_gpu_webgpu_shared_image_cache_cc patch-v8_tools_metagen_metagen_py Removed files: www/chromium : crates.inc www/chromium/patches: patch-chrome_browser_picture_in_picture_picture_in_picture_window_manager_cc patch-device_bluetooth_cast_bluetooth_gni patch-modcargo-crates_psm-0_1_31_src_arch_aarch64_armasm_asm patch-modcargo-crates_psm-0_1_31_src_arch_aarch_aapcs64_s patch-modcargo-crates_psm-0_1_31_src_arch_x86_64_s patch-modcargo-crates_psm-0_1_31_src_arch_x86_s patch-rollup_rust_bindings_napi_Cargo_toml patch-rollup_rust_bindings_napi_src_lib_rs patch-third_party_blink_renderer_platform_graphics_gpu_webgpu_shared_image_wrapper_cache_cc patch-third_party_devtools-frontend_src_front_end_models_ai_assistance_BUILD_gn patch-third_party_devtools-frontend_src_node_modules_rollup_dist_native_js patch-third_party_pdfium_BUILD_gn Log message: update to 155.0.8059.39 CVSROOT: /cvs Module name: src Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 00:25:07 Modified files: etc/rc.d : rc.subr Log message: Randonly, when starting a daemon that sets rc_bg=YES, we may end up with: /etc/rc.d/foo: kill: 123456: no such process There's a race in the rc.subr(8) system where we can end up killing a non existing process (which PID may already be reused by another one). The reason is that rc_alarm timer sends a SIGALRM to all children of rc_cmd to detach rc_start. But the timer is also a child... and can then die while rc_cmd() is about to kill it; that's when you get the error (as it's already gone). Re-implement so the timer ignore SIGALRM and let it get killed by rc_cmd. My tests confirm this fixes the issue, so commit it early in the release process to make sure this does not introduce any regression. reported on bugs@ by adfsilva at gmail dot com ok kn@ CVSROOT: /cvs Module name: ports Changes by: robert@cvs.openbsd.org 2026/10/09 00:32:42 Modified files: mail/grommunio/gromox: Makefile distinfo mail/grommunio/gromox/patches: patch-exch_exmdb_db_engine_cpp patch-mda_exmdb_local_exmdb_local_cpp mail/grommunio/gromox/pkg: PLIST-main Removed files: mail/grommunio/gromox/patches: patch-exch_ews_serialization_cpp patch-exch_ews_structures_cpp patch-lib_mapi_rop_util_cpp Log message: update to 3.12 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 01:11:26 Modified files: databases/mariadb: Makefile Added files: databases/mariadb/patches: patch-storage_innobase_dict_dict0dict_cc Log message: cherrypick upstream commit to avoid snprintf overlap, from Brad. https://jira.mariadb.org/browse/MDEV-41221 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 01:12:01 Modified files: databases/mariadb: Tag: OPENBSD_8_0 Makefile Added files: databases/mariadb/patches: Tag: OPENBSD_8_0 patch-storage_innobase_dict_dict0dict_cc Log message: cherrypick upstream commit to avoid snprintf overlap, from Brad. https://jira.mariadb.org/browse/MDEV-41221 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 01:23:01 Added files: databases/galera/patches: patch-cmake_asio_cmake Log message: galera: don't fail build if too-new asio is present. from Brad. CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 01:25:07 Modified files: infrastructure/bin: update-plist Log message: use existing IsFile from the base class rather than defining an extra method that does the same thing. from espie. CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 02:05:34 Modified files: devel/py-setproctitle: Makefile distinfo Log message: update to py3-setproctitle-1.3.8 CVSROOT: /cvs Module name: src Changes by: dtucker@cvs.openbsd.org 2026/10/09 02:06:28 Modified files: usr.bin/ssh : sshd_config.5 Log message: Fix typo in ssh-mldsa44-ed25519. bz#4027, from alarrosa@suse.com CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 02:15:40 Modified files: www/webkitgtk4 : Makefile distinfo www/webkitgtk4/patches: patch-Source_WebKit_UIProcess_gtk_AcceleratedBackingStore_cpp Removed files: www/webkitgtk4/patches: patch-Source_WebDriver_WebDriverService_cpp Log message: Update to webkitgtk{41,60}-2.54.1. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 02:15:48 Modified files: www/webkitgtk4 : Tag: OPENBSD_8_0 Makefile distinfo www/webkitgtk4/patches: Tag: OPENBSD_8_0 patch-Source_WebKit_UIProcess_gtk_AcceleratedBackingStore_cpp Removed files: www/webkitgtk4/patches: Tag: OPENBSD_8_0 patch-Source_WebDriver_WebDriverService_cpp Log message: Maintenance update to webkitgtk{41,60}-2.54.1. CVSROOT: /cvs Module name: src Changes by: dtucker@cvs.openbsd.org 2026/10/09 02:25:28 Modified files: usr.bin/ssh : ssh_config.5 Log message: Missing comma. bz#4015, from calestyo@scientia.org. CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/09 02:34:39 Modified files: usr.sbin/rpki-client: cert.c extern.h filemode.c parser.c x509.c Log message: rpki-client: rework handling of the expire time The expire time for certificates was added as a hack for filemode and has been unused in normal mode. We can use it to track the expiry time along the validating chain of all objects by setting it when validating CAs. TAs expire with their not after, intermediate CAs and EE certs expire at the minimum of their notafter, their CRL's nextupdate and their issuer's expire time. Signed objects inherit the expire time from their EE cert (this can be handled more cleanly later on). This way we do not need to grab a lock to determine the expire time of any object and we can stop walking up the validation chain and look up the same CRLs over and over again. ok job CVSROOT: /cvs Module name: src Changes by: job@cvs.openbsd.org 2026/10/09 02:36:50 Modified files: usr.sbin/rpki-client: aspa.c cert.c extern.h mft.c parser.c roa.c spl.c Log message: Keep track of the certid of the issuer in a given product Will be used to sync a tree of CAs between parser & main process. OK tb@ CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/09 04:05:12 Modified files: usr.sbin/rpki-client: extern.h main.c mft.c parser.c Log message: rpki-client: merge mft certid and isuserid The latter was never set and they mean the same thing anyway. ok job CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/09 04:16:02 Modified files: usr.bin/tmux : server-client.c Log message: Clear session when freeing client, GitHub issue 5712 from Jeong, Heon. CVSROOT: /cvs Module name: src Changes by: dtucker@cvs.openbsd.org 2026/10/09 04:48:43 Modified files: usr.bin/ssh : servconf.c Log message: Add missing sentinel to multistate_keepalives. bz#4028 from dambi@tio.cz. CVSROOT: /cvs Module name: ports Changes by: kirill@cvs.openbsd.org 2026/10/09 04:59:27 Modified files: lang/gcc : Makefile.inc Log message: lang/gcc: add my mirror for gcc bootstraps Discussed with sthen@ CVSROOT: /cvs Module name: ports Changes by: kirill@cvs.openbsd.org 2026/10/09 05:03:46 Modified files: lang/gcc/16 : Makefile distinfo lang/gcc/16/patches: patch-gcc_config_rs6000_openbsd_h Log message: lang/gcc/16: macppc without BFD we use RELOCATABLE_NEEDS_FIXUP at powerpc64 as well CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:08:49 Modified files: net/py-impacket: Makefile distinfo net/py-impacket/pkg: PLIST Removed files: net/py-impacket/patches: patch-examples_goldenPac_py patch-examples_nmapAnswerMachine_py patch-examples_raiseChild_py Log message: update to py3-impacket-0.13.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:14:39 Modified files: devel/py-test-forked: Makefile distinfo Log message: update to py3-test-forked-1.7.5 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:20:53 Modified files: devel/py-test-xprocess: Makefile Log message: drop unneeded devel/py-py dep CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:22:15 Modified files: devel/py-fields: Makefile Log message: drop unneeded devel/py-py tdep (tests are broken anyway, but this doesn't help) CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:22:30 Modified files: devel/py-cffi : Makefile Log message: drop unneeded devel/py-py tdep CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:24:03 Modified files: devel : Makefile devel/quirks : Makefile devel/quirks/files: Quirks.pm Removed files: devel/py-py : Makefile distinfo devel/py-py/pkg: DESCR PLIST Log message: drop py-py, no longer needed CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:24:59 Modified files: graphics/openjp2: Makefile Added files: graphics/openjp2/patches: patch-src_lib_openjp2_dwt_c patch-src_lib_openjp2_j2k_c patch-src_lib_openjp2_pi_c Log message: openjp2: add some vuln fixes from upstream commits and PRs CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:25:21 Modified files: graphics/openjp2: Tag: OPENBSD_8_0 Makefile Added files: graphics/openjp2/patches: Tag: OPENBSD_8_0 patch-src_lib_openjp2_dwt_c patch-src_lib_openjp2_j2k_c patch-src_lib_openjp2_pi_c Log message: openjp2: add some vuln fixes from upstream commits and PRs CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:25:48 Modified files: www/py-beaker : Makefile distinfo www/py-beaker/pkg: PLIST Log message: update to py3-beaker-1.14.1 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:34:10 Modified files: comms/gnuradio : Makefile Log message: drop unused BDEP on click-plugins CVSROOT: /cvs Module name: ports Changes by: jca@cvs.openbsd.org 2026/10/09 05:37:51 Modified files: devel/highway : Makefile Log message: Reenable RVV code that it compiles Brad backported an llvm fix for the type mismatch that was plaguing the riscv vector intrinsics. Also Brad added runtime detection to this port through elf_aux_info(3) earlier this summer, so we can now enable the RVV code in highway. But don't drop -DHWY_CMAKE_RVV=OFF, because it would make unconditional use of RVV through CFLAGS, and OpenBSD/riscv64 doesn't assume RVV support / RVA23. CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:48:57 Modified files: sysutils/py-celery: Makefile distinfo Log message: update to py3-celery-5.6.3 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:49:04 Modified files: devel/py-test-celery: Makefile distinfo Log message: update to py3-test-celery-1.3.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:49:19 Modified files: net/py-kombu : Makefile distinfo net/py-kombu/pkg: PLIST Log message: update to py3-kombu-5.6.2 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:51:51 Log message: import ports/net/py-pika, ok tb Pika is a pure-Python implementation of the AMQP 0-9-1 protocol including RabbitMQ's extensions. Status: Vendor Tag: sthen Release Tags: sthen_20261009 N ports/net/py-pika/Makefile N ports/net/py-pika/distinfo N ports/net/py-pika/pkg/DESCR N ports/net/py-pika/pkg/PLIST No conflicts created by this import CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:52:09 Modified files: net : Makefile Log message: +py-pika CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:54:56 Modified files: mail/mutt : Makefile distinfo Log message: update to mutt-2.4.3, including fix for CVE-2026-107570, OOB heap write triggered by a specially crafted Content-Header line in an email that is used as a template for a new email, via . CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 05:55:08 Modified files: mail/mutt : Tag: OPENBSD_8_0 Makefile distinfo Log message: update to mutt-2.4.3, including fix for CVE-2026-107570, OOB heap write triggered by a specially crafted Content-Header line in an email that is used as a template for a new email, via . CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 06:18:06 Modified files: productivity/radicale: Makefile distinfo productivity/radicale/patches: patch-config patch-radicale_config_py productivity/radicale/pkg: DESCR PLIST README radicale.rc Log message: update to radicale-3.8.3, this is a long-overdue major upgrade (2.1.2 before) the storage format is compatible with 2.x, however configuration will require adjustment. see notes in pkg-readme or upstream docs. https://github.com/Kozea/Radicale/blob/master/CHANGELOG.md#upgrade-checklist based on various work from ports@, in particular from Tim (TronDD). CVSROOT: /cvs Module name: www Changes by: sthen@cvs.openbsd.org 2026/10/09 06:21:40 Modified files: faq : current.html Log message: note radicale major version upgrade. I have added a "post-openbsd 8.0 starts here" marker. CVSROOT: /cvs Module name: ports Changes by: tb@cvs.openbsd.org 2026/10/09 06:43:44 Modified files: devel/cargo-insta: Makefile crates.inc distinfo Log message: Update to cargo-insta 1.49.0 https://github.com/mitsuhiko/insta/releases/tag/1.49.0 CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 07:06:15 Modified files: audio/rgain : Makefile distinfo audio/rgain/patches: patch-setup_cfg audio/rgain/pkg: PLIST Removed files: audio/rgain/patches: patch-setup_py Log message: update to a git checkout of audio/rgain, which includes dropping pkg_resources set PORTROACH to something in the vague hope that it may pick up a future release CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 07:06:45 Modified files: audio/rgain : Makefile Log message: missing site: in PORTROACH tag CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/09 07:11:12 Modified files: distrib/sets/lists/man: mi Log message: sync CVSROOT: /cvs Module name: src Changes by: nicm@cvs.openbsd.org 2026/10/09 07:12:14 Modified files: usr.bin/tmux : cmd-attach-session.c cmd-bind-key.c cmd-break-pane.c cmd-capture-pane.c cmd-choose-tree.c cmd-command-prompt.c cmd-confirm-before.c cmd-copy-mode.c cmd-detach-client.c cmd-display-menu.c cmd-display-message.c cmd-find-window.c cmd-if-shell.c cmd-join-pane.c cmd-kill-pane.c cmd-kill-server.c cmd-kill-session.c cmd-kill-window.c cmd-list-buffers.c cmd-list-clients.c cmd-list-commands.c cmd-list-keys.c cmd-list-panes.c cmd-list-sessions.c cmd-list-windows.c cmd-load-buffer.c cmd-lock-server.c cmd-move-window.c cmd-new-session.c cmd-new-window.c cmd-paste-buffer.c cmd-pipe-pane.c cmd-refresh-client.c cmd-rename-session.c cmd-rename-window.c cmd-resize-pane.c cmd-resize-window.c cmd-respawn-pane.c cmd-respawn-window.c cmd-rotate-window.c cmd-run-shell.c cmd-save-buffer.c cmd-select-layout.c cmd-select-pane.c cmd-select-window.c cmd-send-keys.c cmd-server-access.c cmd-set-buffer.c cmd-set-environment.c cmd-set-option.c cmd-show-environment.c cmd-show-messages.c cmd-show-options.c cmd-show-prompt-history.c cmd-source-file.c cmd-split-window.c cmd-swap-pane.c cmd-swap-window.c cmd-switch-client.c cmd-unbind-key.c cmd-wait-for.c options-table.c tmux.1 tmux.h Log message: Add a one line description text to each command, originally from someone in GitHub issue 5438. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 07:29:35 Modified files: devel/appstream: Makefile distinfo devel/appstream/patches: patch-src_as-system-info_c devel/appstream/pkg: PLIST-main Log message: Update to appstream-1.2.1. CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/09 07:39:17 Modified files: distrib/amd64/iso: Makefile Log message: install media growth CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 07:45:13 Modified files: net/librenms : Makefile Added files: net/librenms/patches: patch-scripts_dynamic_check_requirements_py Log message: neuter librenms/scripts/dynamic_check_requirements.py which used pkg_resources (removed from setuptools 82). it's pretty pointless anyway (especially in os packaging), though it is still called from LibreNMS/Validations/Python.php re https://github.com/librenms/librenms/pull/17560 CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 07:49:40 Modified files: devel/harfbuzz : Makefile distinfo Log message: Update to harfbuzz-14.6.0. CVSROOT: /cvs Module name: src Changes by: bluhm@cvs.openbsd.org 2026/10/09 07:56:57 Modified files: regress/lib/libexpat: Makefile Removed files: lib/libexpat/tests: runtestspp.cpp regress/lib/libexpat/runtestspp: Makefile Log message: Remove extra C++ test. Upstream does not support it anymore. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 07:57:52 Modified files: graphics/openexr: Makefile distinfo Log message: Update to openexr-3.5.2. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 07:59:13 Modified files: graphics/py-cairo: Makefile distinfo Log message: Update to py3-cairo-1.29.2. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 07:59:39 Modified files: misc/hwdata : Makefile distinfo Log message: Update to hwdata-0.412. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:01:20 Modified files: multimedia/pipewire/wireplumber: Makefile distinfo multimedia/pipewire/wireplumber/pkg: PLIST Log message: Update to wireplumber-0.5.18. CVSROOT: /cvs Module name: ports Changes by: lucas@cvs.openbsd.org 2026/10/09 08:03:09 Modified files: databases/victoriametrics: Makefile distinfo databases/victoriametrics/pkg: PLIST Log message: databases/victoriametrics: update to 1.153.0 ok sthen CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:04:13 Modified files: print/cups : Makefile distinfo print/cups/patches: patch-backend_ipp_c patch-scheduler_ipp_c Log message: SECURITY update to cups-2.4.20. CVSROOT: /cvs Module name: ports Changes by: lucas@cvs.openbsd.org 2026/10/09 08:05:11 Modified files: net/haproxy : Makefile distinfo net/haproxy/pkg: PLIST Log message: net/haproxy: update to 3.4.6 Changes: https://www.haproxy.org/download/3.4/src/CHANGELOG tested by Mark Patruck ok sthen CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:06:44 Modified files: devel/harfbuzz : Tag: OPENBSD_8_0 Makefile distinfo Log message: Update to harfbuzz-14.5.1. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:07:38 Modified files: net/netatalk3 : Makefile distinfo Log message: Update to netatalk-4.6.1. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:12:41 Modified files: x11/dbus-glib : Makefile distinfo x11/dbus-glib/pkg: PLIST Log message: Update to dbus-glib-0.116. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:14:47 Modified files: x11/gnome/orca : Makefile distinfo Log message: Update to orca-50.3. CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/09 08:15:30 Modified files: usr.sbin/rpki-client: crl.c Log message: rpki-client: CRL Number draft is now RFC 9829 CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:19:06 Modified files: print/cups : Tag: OPENBSD_8_0 Makefile distinfo print/cups/patches: Tag: OPENBSD_8_0 patch-backend_ipp_c patch-scheduler_ipp_c Log message: Update to cups-2.4.20. CVE-2025-55480, CVE-2026-61702, CVE-2026-87875, CVE-2026-87876, CVE-2026-55453, CVE-2026-55467, CVE-2026-105326 CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:20:17 Modified files: devel/libgsf : Tag: OPENBSD_8_0 Makefile distinfo Log message: Bugfix update to libgsf-1.14.60. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:20:55 Modified files: net/netatalk3 : Tag: OPENBSD_8_0 Makefile distinfo Log message: Bugfix update to netatalk-4.6.1. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:21:29 Modified files: x11/gnome/orca : Tag: OPENBSD_8_0 Makefile distinfo Log message: Bugfix update to orca-50.3. CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/09 08:25:43 Modified files: . : plus80.html plus.html Log message: move stuff to plus80 CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:28:37 Modified files: x11/gnome/glycin: Makefile crates.inc distinfo Log message: Update to glycin-2.2.2. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:28:45 Modified files: x11/gnome/glycin: Tag: OPENBSD_8_0 Makefile crates.inc distinfo Log message: Bugfix update to glycin-2.2.2. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:29:03 Modified files: devel/libsoup3 : Makefile distinfo devel/libsoup3/pkg: PLIST Log message: Update to libsoup3-3.8.0. CVSROOT: /cvs Module name: ports Changes by: kirill@cvs.openbsd.org 2026/10/09 08:39:58 Modified files: devel/codex : Makefile crates.inc distinfo devel/codex/patches: patch-codex-rs_Cargo_toml patch-codex-rs_apply-patch_src_lib_rs patch-codex-rs_core_src_config_mod_rs patch-codex-rs_core_src_tools_handlers_apply_patch_rs patch-codex-rs_features_src_lib_rs Log message: devel/codex: update to 0.162.0 CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:47:25 Modified files: astro/stellarium: Makefile distinfo astro/stellarium/patches: patch-CMakeLists_txt astro/stellarium/pkg: PLIST Log message: Update to stellarium-26.3. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 08:48:07 Modified files: textproc/libical: Makefile distinfo textproc/libical/patches: patch-CMakeLists_txt patch-src_test_regression-storage_c textproc/libical/pkg: PLIST-main Added files: textproc/libical/patches: patch-src_libical_CMakeLists_txt Log message: Update to libical-4.0.6. CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/09 08:51:36 Modified files: usr.bin/sndiod : listen.c Log message: use accept4() with SOCK_NONBLOCK rather than fcntl O_NONBLOCK ok ratchov CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/09 09:06:56 Modified files: usr.bin/fgen : fgen.l Log message: unveil() and pledge() are pretty easy to add CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/09 09:09:14 Modified files: usr.sbin/ftp-proxy: ftp-proxy.c Log message: use SOCK_STREAM instead of fcntl O_NONBLOCK CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/09 09:12:06 Modified files: usr.sbin/ypbind: ypbind.c Log message: use the err.h family of functions CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/09 09:13:08 Modified files: usr.sbin/ypbind: ypbind.c Log message: Use O_NOFOLLOW for the binding dir open CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/10/09 09:15:43 Modified files: usr.sbin/ypbind: ypbind.c Log message: I am pretty sure two unveil() and pledge "stdio rpath wpath inet dns" will work here. commiting to collect feedback. CVSROOT: /cvs Module name: ports Changes by: volker@cvs.openbsd.org 2026/10/09 09:37:43 Modified files: wayland/mango : Makefile distinfo wayland/mango/patches: patch-assets_config_conf patch-meson_build patch-src_dispatch_bind_c wayland/mango/pkg: PLIST Added files: wayland/mango/patches: patch-assets_config_toml Log message: wayland/mango: Update to 0.18.0 CVSROOT: /cvs Module name: src Changes by: mlarkin@cvs.openbsd.org 2026/10/09 09:42:51 Modified files: usr.sbin/vmd : x86_vm.c Log message: vmd(8): add extra mmio region this adds a no-op (reads return FFs, writes discarded) mmio region between the end of guest RAM and 4GB. specifically recent i686 linux bootloaders/kernels do what appear to be errant probes of high PAs in the > 0xc0000000 range, and vmd treats all mmio accesses to unmapped regions as fatal. this diff adds a region to cover any gap, such that accesses to those addresses trap to vmd, which then does what real hw would do. other hypervisors do similar things. this allieviates the need to assign 4GB ram to these VMs which was previously needed to work around the problem. ok dv CVSROOT: /cvs Module name: ports Changes by: bket@cvs.openbsd.org 2026/10/09 09:48:11 Modified files: sysutils/rclone: Makefile distinfo Log message: Update to rclone-1.75.2 Addresses multiple security vulnerabilities across protocol implementations, core dependencies, and service interfaces. Changes: https://rclone.org/changelog/#v1-75-2-2026-10-09 CVSROOT: /cvs Module name: ports Changes by: bket@cvs.openbsd.org 2026/10/09 09:51:02 Modified files: sysutils/rclone: Tag: OPENBSD_8_0 Makefile distinfo Log message: Update to rclone-1.75.2 Addresses multiple security vulnerabilities across protocol implementations, core dependencies, and service interfaces. Changes: https://rclone.org/changelog/#v1-75-2-2026-10-09 CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 10:02:46 Modified files: graphics/gthumb: Makefile distinfo graphics/gthumb/pkg: PLIST Added files: graphics/gthumb/patches: patch-src_lib_exiv2-utils_cpp patch-src_lib_util_h Removed files: graphics/gthumb/patches: patch-gthumb_gth-browser_c Log message: Update to gthumb-4.0. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 10:09:07 Modified files: net/sshuttle : Makefile Log message: Drop maintainer. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 10:11:50 Modified files: textproc/meld : Makefile distinfo Log message: Update to meld-3.24.1. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 10:13:34 Modified files: sysutils/libvirt: Makefile distinfo Log message: Update to libvirt-12.8.0. CVSROOT: /cvs Module name: ports Changes by: ajacoutot@cvs.openbsd.org 2026/10/09 10:13:42 Modified files: sysutils/libvirt-python: Makefile distinfo Log message: Update to py3-libvirt-12.8.0. CVSROOT: /cvs Module name: src Changes by: miod@cvs.openbsd.org 2026/10/09 10:27:55 Modified files: sys/lib/libz : zutil.c Log message: Comment out zlibVersion() and zlibCompileFlags(), unused in the kernel. ok tb@ CVSROOT: /cvs Module name: src Changes by: miod@cvs.openbsd.org 2026/10/09 10:31:32 Modified files: sys/conf : param.c Log message: Remove unused kernel global utsname. tweak&ok dgl@ CVSROOT: /cvs Module name: src Changes by: miod@cvs.openbsd.org 2026/10/09 10:33:14 Modified files: sys/crypto : arc4.c arc4.h blf.c blf.h Log message: Remove unused rc4_getbytes() and Blowfish_expandstate(). ok tb@ CVSROOT: /cvs Module name: src Changes by: miod@cvs.openbsd.org 2026/10/09 10:33:50 Modified files: sys/isofs/cd9660: cd9660_node.h cd9660_vnops.c Log message: Remove unused cd9660_mmap() and cd9660_seek(). ok tb@ CVSROOT: /cvs Module name: src Changes by: miod@cvs.openbsd.org 2026/10/09 10:35:28 Modified files: sys/kern : vfs_bio.c sys/sys : buf.h Log message: Remove global prototype for bufcache_getcleanbuf(), and only compile it #ifdef HIBERNATE, for it is not used anywhere else. ok deraadt@ CVSROOT: /cvs Module name: src Changes by: miod@cvs.openbsd.org 2026/10/09 10:36:24 Modified files: sys/net : bridgectl.c if_bridge.h Log message: Remove unused bridge_tunneluntag(). ok bluhm@ CVSROOT: /cvs Module name: src Changes by: miod@cvs.openbsd.org 2026/10/09 10:42:33 Modified files: usr.sbin/pcidump: pcidump.c Log message: Abort enhanced capability loop if reading all ones from the device instead of looping infinitely; this value isn't allowed by the spec, but there are devices behaving that way, from Intel no less. ok deraadt@ CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/10/09 11:03:52 Modified files: security/py-truststore: Makefile Log message: remove TDEPs which aren't referenced at all in the distfile or upstream repo (unbreaking sqlports after axolotl removal): devel/py-test-rerunfailures security/py-axolotl security/py-axolotl-curve25519