NetBSD/pkgsrc-wip ed23a9d — visidata TODO

visidata: Add reference to recent CVEs
DeltaFile
+3-0visidata/TODO
+3-01 files

NetBSD/pkgsrc-wip 2f4e1da — py-patool TODO

py-patool: Add reference to CVE-2026-106057
DeltaFile
+1-1py-patool/TODO
+1-11 files

NetBSD/pkgsrc-wip 080567e — llama.cpp TODO

llama.cpp: Add reference to CVE-2026-107183
DeltaFile
+1-1llama.cpp/TODO
+1-11 files

NetBSD/pkgsrc-wip 03832b0 — busybox TODO

busybox: Add reference to CVE-2026-108119
DeltaFile
+1-1busybox/TODO
+1-11 files

NetBSD/pkgsrc 6wuQ3Ma — editors/emacs modules.mk

   emacs: bugfix for modules.mk

   From Showta Ishizaki
VersionDeltaFile
1.44+3-1editors/emacs/modules.mk
+3-11 files

NetBSD/pkgsrc nZKaGxj — audio/xmmix distinfo, audio/xmmix/patches patch-ab

   xmmix: fix ioctl cmd type error in do_ioctl() wrapper

   xmmix's do_ioctl() ioctl wrapper function typed the second arg
   of ioctl ("unsigned long request") as "int cmd" instead.  this
   type conversion mangled the request value being passed to the
   ioctl syscall and resulted in an "Invalid argument" error for
   a FIOASYNC request on /dev/mixer.   resolve by changing do_ioctl()
   from "int cmd" to "unsigned int cmd" to match ioctl() man page.
VersionDeltaFile
1.3+23-15audio/xmmix/patches/patch-ab
1.11+2-2audio/xmmix/distinfo
+25-172 files

NetBSD/pkgsrc-wip 24a01a9 — . TODO

TODO: + py-pyside6-6.12.0.
DeltaFile
+1-0TODO
+1-01 files

NetBSD/pkgsrc JDPEZOc — doc TODO

   doc/TODO: + python-3.15.0.
VersionDeltaFile
1.28120+2-1doc/TODO
+2-11 files

NetBSD/pkgsrc e7t2z2x — graphics/openjpeg DESCR

   openjpeg: fix year
VersionDeltaFile
1.4+1-1graphics/openjpeg/DESCR
+1-11 files

NetBSD/pkgsrc B5OZ03O — doc CHANGES-2026

   doc: Updated net/knot to 3.6.1
VersionDeltaFile
1.6830+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc HkL60Md — net/knot distinfo, net/knot/patches patch-tests_libknot_test_cookies.c patch-tests_knot_test__semantic__check.in

   knot: Update to 3.6.1

   Features:
   mod-ecs: new module for setting the ECS scope prefix length (Thanks to Branko Mijuskovic)

   Improvements:
   knotd: additional SOA consistency checks when processing incoming XFR
   knotd: DDNS over 0-RTT QUIC/TLS is forbidden
   knotd: new warning if difference(-no-serial) is enabled on a secondary zone
   knotc: control blocking timeout is per full command, not per each zone
   kdig: backward compatibility for +noidn as an alias for +noidnout
   libknot: extra checks for malformed IPv4 and TCP packets in XDP filter (Thanks to Joshua Rogers)
   src,tests: various compatibility fixes for SmartOS #980
   doc: various improvements

   Bugfixes:
   knotd: missing synchronization between catalog reload and worker suspension
   knotd: race condition between pausing/resuming events, zonedb update, and reload/conf-commit
   knotd: non-consumed DoT 0-RTT early data can cause memory exhaustion (Thanks to Yuxiao Wu)

    [19 lines not shown]
VersionDeltaFile
1.61+3-8net/knot/distinfo
1.2+1-1net/knot/patches/patch-tests_libknot_test_cookies.c
1.2+1-1net/knot/patches/patch-tests_knot_test__semantic__check.in
1.2+1-1net/knot/patches/patch-tests_contrib_test_atomic.c
1.2+1-1net/knot/patches/patch-src_contrib_ucw_mempool.c
1.2+1-1net/knot/patches/patch-src_contrib_time.c
+8-132 files not shown
+10-158 files

NetBSD/pkgsrc q3EM8ML — doc pkg-vulnerabilities

   doc: Add CVE-2026-107570 affecting "mail/mutt"
VersionDeltaFile
1.801+2-1doc/pkg-vulnerabilities
+2-11 files

NetBSD/pkgsrc xrBMOxW — doc CHANGES-2026

   doc: Updated textproc/enchant2 to 2.8.21nb3
VersionDeltaFile
1.6829+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc CGxYAEu — textproc/enchant2 Makefile

   enchant2: groff is troubled in macOS bulk builds, so just use mandoc everywhere

   Bump PKGREVISION.
VersionDeltaFile
1.65+12-3textproc/enchant2/Makefile
+12-31 files

NetBSD/pkgsrc mHHLj3c — doc CHANGES-2026

   Note update of the "mutt" package to version 2.4.3
VersionDeltaFile
1.6828+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc okoMJY5 — mail/mutt Makefile distinfo

   mail/mutt: Update to version 2.4.3

   This release fixes two bugs.  One of them is for CVE-2026-107570, fixing an
   OOB heap write.  This is triggered by a specially crafted Content-Header line
   in an email that is used as a template for a new email, via <resend-message>.
   Thanks to Calif.io, in collaboration with Anthropic for sending me a detailed
   write up and suggested patch.

   The full set of changes are:

   7752d93f  Fix OOB heap write in convert_file_from_to().
   4364e5b0  Fix mutt_signed_handler() goodsig setting.
VersionDeltaFile
1.130+4-4mail/mutt/distinfo
1.302+2-2mail/mutt/Makefile
+6-62 files

NetBSD/pkgsrc Yi8VHnc — graphics/openjpeg DESCR

   graphics/openjpeg: Note that upstream considers the repo unmaintained

   https://github.com/uclouvain/openjpeg/commit/06bbae8b5d5e57f8c28fe862b80a9464b320e314
VersionDeltaFile
1.3+3-0graphics/openjpeg/DESCR
+3-01 files

NetBSD/pkgsrc 2mHqzCp — emulators/ntvcm distinfo, emulators/ntvcm/patches patch-makefile

   Drop lto linker optimization option, it appears to cause spurious
   build problems on NetBSD 11, at least.
VersionDeltaFile
1.2+3-3emulators/ntvcm/patches/patch-makefile
1.4+2-2emulators/ntvcm/distinfo
+5-52 files

NetBSD/pkgsrc Fxspuxu — doc CHANGES-2026

   doc: Updated net/dnscontrol to 5.4.0
VersionDeltaFile
1.6827+2-1doc/CHANGES-2026
+2-11 files

NetBSD/pkgsrc kdogxM9 — net/dnscontrol Makefile go-modules.mk

   dnscontrol: Update to 5.4.0

   Changelog
   Provider-specific changes:
   89188fe: feat(p/BUNNYDNS): make the provider safe to run concurrently (#4980) (@jfexyz)
   2b9883e: feat(p/DNSOVERHTTPS): mark the provider as verified for concurrency (#4981) (@jfexyz)
   New features:
   7e201d7: feat(cloudpress): add CloudPress DNS provider (#4390) (@arnoschoon)
   c16964f: feat: Stage 5: Add SupportedTypes and exhaustive provider validation (#4967) (@TomOnTime)
   1a6b48a: feat: Stage 6a: support domain-specific DNS provider metadata (#4975) (@TomOnTime)
   b45d6dd: feat: Suppress "Serially checking"/"Serially Gathering " messages unless --full flag used (#4978) (@jfexyz)
   0136f8c: feat: add SKIP_AUDIT modifier (#4971) (@GZTimeWalker)
   c9bf25d: feat: reduce messages if all providers are concurrent (--full overrides) (#4979) (@TomOnTime)
   8d96a60: feat: stage 6b: add direct REGISTRAR/SERVICE syntax (#4976) (@TomOnTime)
   Refactoring:
   d2f5fb9: refactor: Stage 2: Adopt new way for providers to register, test with 4 providers (#4956) (@TomOnTime)
   93b3df7: refactor: Stage 3: Migrate remaining providers to providers.Register (#4965) (@TomOnTime)
   76ddb69: refactor: Stage 4: Remove legacy provider registrations, accessors, etc (#4966) (@TomOnTime)
   ed4a220: refactor: Stage 6: Adopt SupportedTypes across providers (#4968) (@TomOnTime)
VersionDeltaFile
1.16+147-147net/dnscontrol/distinfo
1.17+48-48net/dnscontrol/go-modules.mk
1.52+1-1net/dnscontrol/Makefile
+196-1963 files

NetBSD/pkgsrc-wip c13a7bd — crush Makefile distinfo

crush: Update to 0.98.1

Changelog
Fixed
8584922: fix: route newer Copilot models through the Responses API (#4048) (@DaVinci42)
DeltaFile
+3-22crush/COMMIT_MSG
+3-3crush/distinfo
+1-1crush/Makefile
+7-263 files

NetBSD/src Dk0lIiv — doc CHANGES-10.3

   Tickets #1352 - #1354, #1356
VersionDeltaFile
1.1.2.9+30-1doc/CHANGES-10.3
+30-11 files

NetBSD/pkgsrc-wip 8319e7a — fuse-smbnetfs PLIST distinfo, fuse-smbnetfs/files README.pkgsrc

fuse-smbnetfs: tested with a real SMB2/3 share; MESSAGE -> README.pkgsrc; update distinfo
DeltaFile
+54-0fuse-smbnetfs/files/README.pkgsrc
+0-20fuse-smbnetfs/MESSAGE
+14-2fuse-smbnetfs/TODO
+11-0fuse-smbnetfs/Makefile
+1-1fuse-smbnetfs/distinfo
+1-0fuse-smbnetfs/PLIST
+81-236 files

NetBSD/src KRrjbj1 — external/gpl3/gcc/dist/gcc/config/arm arm.h arm.md

   Pull up following revision(s) (requested by riastradh in ticket #515):

        external/gpl3/gcc/dist/gcc/config/arm/arm.cc: revision 1.2
        external/gpl3/gcc/dist/gcc/config/arm/arm.cc: revision 1.3
                (applied to arm.c)
        external/gpl3/gcc/dist/gcc/config/arm/arm.md: revision 1.24
        external/gpl3/gcc/dist/gcc/config/arm/arm.h: revision 1.27
        (all via patch)

   gcc/arm: For -mtp=soft, ensure stack alignment even in leaves.

   The option -mtp=soft, which is the default on earmv5, makes queries
   to the thread pointer, for access to static (`initial-exec')
   thread-local storage, go through the C runtime subroutine
   __aeabi_read_tp.  (For earmv>=6, we use the cp15 register via a
   single instruction.)

   Thus procedures which gcc thinks of as leaf procedures that use
   __aeabi_read_tp are not really leaf procedures -- and even though

    [113 lines not shown]
VersionDeltaFile
1.12.2.1+15-1external/gpl3/gcc/dist/gcc/config/arm/arm.c
1.20.2.1+4-1external/gpl3/gcc/dist/gcc/config/arm/arm.md
1.24.2.1+2-0external/gpl3/gcc/dist/gcc/config/arm/arm.h
+21-23 files

NetBSD/src Spv8Yfl — doc CHANGES-11.1

   Tickets #514 and #515
VersionDeltaFile
1.1.2.21+19-1doc/CHANGES-11.1
+19-11 files

NetBSD/src bnt4y5W — external/gpl3/gcc/dist/gcc/config/arm arm.h arm.md

   Pull up following revision(s) (requested by riastradh in ticket #515):

        external/gpl3/gcc/dist/gcc/config/arm/arm.cc: revision 1.2
        external/gpl3/gcc/dist/gcc/config/arm/arm.cc: revision 1.3
        external/gpl3/gcc/dist/gcc/config/arm/arm.md: revision 1.24
        external/gpl3/gcc/dist/gcc/config/arm/arm.h: revision 1.27

   gcc/arm: For -mtp=soft, ensure stack alignment even in leaves.

   The option -mtp=soft, which is the default on earmv5, makes queries
   to the thread pointer, for access to static (`initial-exec')
   thread-local storage, go through the C runtime subroutine
   __aeabi_read_tp.  (For earmv>=6, we use the cp15 register via a
   single instruction.)

   Thus procedures which gcc thinks of as leaf procedures that use
   __aeabi_read_tp are not really leaf procedures -- and even though
   __aeabi_read_tp itself doesn't use the stack pointer at all,
   resolving the symbol may take a detour through the dynamic linker,

    [111 lines not shown]
VersionDeltaFile
1.1.1.3.2.1+15-1external/gpl3/gcc/dist/gcc/config/arm/arm.cc
1.22.2.1+4-1external/gpl3/gcc/dist/gcc/config/arm/arm.md
1.25.4.1+2-0external/gpl3/gcc/dist/gcc/config/arm/arm.h
+21-23 files

NetBSD/src WY4yf1T — libexec/ld.elf_so Makefile, share/mk bsd.lib.mk bsd.kmodule.mk

   Pull up following revision(s) (requested by riastradh in ticket #514):

        share/mk/bsd.prog.mk: revision 1.360
        share/mk/bsd.lib.mk: revision 1.424
        share/mk/bsd.prog.mk: revision 1.361
        tests/libexec/ld.elf_so/Makefile: revision 1.33
        tests/lib/csu/Makefile: revision 1.14
        share/mk/bsd.kmodule.mk: revision 1.87
        share/mk/bsd.kmodule.mk: revision 1.88
        libexec/ld.elf_so/Makefile: revision 1.152

   bsd.prog.mk: Fix parallel builds of debug data.

   Previously, we had one rule to generate foo, and another rule to
   derive foo.debug from it with objcopy -- and then rewrite foo _in
   place_ to strip the debug data with objcopy.

   This is wrong -- one rule should never overwrite another rule's
   target; this violates the contract with make(1), and can lead it to

    [45 lines not shown]
VersionDeltaFile
1.356.2.3+33-10share/mk/bsd.prog.mk
1.86.4.1+21-14share/mk/bsd.kmodule.mk
1.151.2.3+6-12libexec/ld.elf_so/Makefile
1.419.2.3+2-2share/mk/bsd.lib.mk
1.28.2.5+2-1tests/libexec/ld.elf_so/Makefile
1.12.2.1+2-1tests/lib/csu/Makefile
+66-406 files

NetBSD/src 242YahS — libexec/ld.elf_so headers.c, sys/arch/mips/include elf_machdep.h

   Pull up following revision(s) (requested by riastradh in ticket #1354):

        libexec/ld.elf_so/headers.c: revision 1.73
        tests/libexec/ld.elf_so/t_rtld_r_debug.c: revision 1.4
        tests/libexec/ld.elf_so/t_rtld_r_debug.c: revision 1.5
        tests/libexec/ld.elf_so/t_rtld_r_debug.c: revision 1.7
        tests/libexec/ld.elf_so/t_rtld_r_debug.c: revision 1.8
        tests/libexec/ld.elf_so/t_rtld_r_debug.c: revision 1.9
        tests/libexec/ld.elf_so/t_dlinfo.c: revision 1.7
        tests/libexec/ld.elf_so/t_rtld_r_debug.c: revision 1.10
        tests/libexec/ld.elf_so/t_dlinfo.c: revision 1.8
        tests/libexec/ld.elf_so/t_rtld_r_debug.c: revision 1.11
        sys/arch/mips/include/elf_machdep.h: revision 1.21

   rtld tests: Don't use RZ for dlinfo.

   Use
           ATF_REQUIRE_EQ_MSG(dlinfo(...), 0, "dlinfo: %s", dlerror())
   instead, in order to accurately report the error on failure.  RZ is

    [64 lines not shown]
VersionDeltaFile
1.3.6.1+52-18tests/libexec/ld.elf_so/t_rtld_r_debug.c
1.70.2.3+36-6libexec/ld.elf_so/headers.c
1.6.10.1+11-10tests/libexec/ld.elf_so/t_dlinfo.c
1.20.34.1+2-1sys/arch/mips/include/elf_machdep.h
+101-354 files

NetBSD/pkgsrc QekTgLV — x11/kitty PLIST

   kitty: launcher/kitten does not get installed on darwin
VersionDeltaFile
1.44+2-2x11/kitty/PLIST
+2-21 files

NetBSD/src lYV9YMJ — tests/lib/librumphijack t_tcpip.sh

   Pull up following revision(s) (requested by riastradh in ticket #1353):

        tests/lib/librumphijack/t_tcpip.sh: revision 1.23
        tests/lib/librumphijack/t_tcpip.sh: revision 1.25
        tests/lib/librumphijack/t_tcpip.sh: revision 1.26

   tests/lib/librumphijack: Avoid trying to run rpcbind as non-root.

   Can probably make this work through rumphijack, but there's no sense
   in even trying the test if we can't, so let's reduce the unprivileged
   false alarms.


   t_tcpip: Mark ssh test xfail.

   PR bin/59278: tests/lib/librumphijack/t_tcpip:ssh failing since
   openssh 10.0 update



    [2 lines not shown]
VersionDeltaFile
1.21.2.1+31-2tests/lib/librumphijack/t_tcpip.sh
+31-21 files