OpenBSD/src WLehLp3regress/usr.bin/ssh/unittests/sshkey mktestdata.sh, regress/usr.bin/ssh/unittests/sshkey/testdata mldsa44_ed25519_2 mldsa44_ed25519_1

   replace testing of vendor PQ signature algorithm
   "ssh-mldsa44-ed25519 at openssh.com" with the IANA-registered
   "ssh-mldsa44-ed25519"
VersionDeltaFile
1.2+75-76regress/usr.bin/ssh/unittests/sshsig/testdata/mldsa44-ed25519.sig
1.2+56-57regress/usr.bin/ssh/unittests/sshkey/testdata/mldsa44_ed25519_1_pw
1.2+56-56regress/usr.bin/ssh/unittests/sshsig/testdata/mldsa44-ed25519
1.2+56-56regress/usr.bin/ssh/unittests/sshkey/testdata/mldsa44_ed25519_2
1.2+56-56regress/usr.bin/ssh/unittests/sshkey/testdata/mldsa44_ed25519_1
1.14+3-3regress/usr.bin/ssh/unittests/sshkey/mktestdata.sh
+302-30412 files not shown
+317-32018 files

OpenBSD/src GfZZnkEusr.bin/ssh myproposal.h sshd.8

   IANA has allocated a non-vendor codepoint for ssh-mldsa44-ed25519,
   so use it instead of the vendored "@openssh.com" name.

   Note: this replaces the vendored name, which was only marked as
   experimental and not enabled by default.cw

   If you have ssh-mldsa44-ed25519 at openssh.com keys manually configured
   in sshd, then you will need to remove them from sshd_config and
   restart.
VersionDeltaFile
1.403+9-9usr.bin/ssh/sshd_config.5
1.429+9-9usr.bin/ssh/ssh_config.5
1.5+4-4usr.bin/ssh/ssh-mldsa-eddsa.c
1.332+3-3usr.bin/ssh/sshd.8
1.171+3-3usr.bin/ssh/ssh-keyscan.c
1.81+2-2usr.bin/ssh/myproposal.h
+30-306 files

OpenBSD/ports Ql3rSt5databases/ruby-sequel Makefile distinfo, databases/ruby-sequel/pkg PLIST

   Update to Sequel 5.108.0
VersionDeltaFile
1.43+2-2databases/ruby-sequel/distinfo
1.59+1-1databases/ruby-sequel/Makefile
1.45+1-0databases/ruby-sequel/pkg/PLIST
+4-33 files

OpenBSD/ports wot82Rhdevel/codex Makefile distinfo, devel/codex/patches patch-codex-rs_core_src_config_mod_rs patch-codex-rs_Cargo_toml

   devel/codex: update to 0.152.1
VersionDeltaFile
1.37+3-3devel/codex/patches/patch-codex-rs_Cargo_toml
1.45+2-2devel/codex/distinfo
1.39+1-1devel/codex/patches/patch-codex-rs_core_src_config_mod_rs
1.47+1-1devel/codex/Makefile
+7-74 files

OpenBSD/ports JPgGhbenet/telemt Makefile crates.inc

   update to telemt 3.5.5
VersionDeltaFile
1.12+8-4net/telemt/distinfo
1.9+3-1net/telemt/crates.inc
1.13+1-1net/telemt/Makefile
+12-63 files

OpenBSD/ports Leee2fplang/gcc/16 distinfo Makefile, lang/gcc/16/patches patch-gcc_ada_Makefile_rtl

   lang/gcc/16: add dlang support and update plist at powerpc
VersionDeltaFile
1.17+4-4lang/gcc/16/Makefile
1.2+2-3lang/gcc/16/patches/patch-gcc_ada_Makefile_rtl
1.9+2-2lang/gcc/16/distinfo
1.3+1-0lang/gcc/16/pkg/PFRAG.powerpc-main
+9-94 files

OpenBSD/ports yxcAnzMlang/gcc/11 Makefile

   lang/gcc/11: add dlang support at powerpc
VersionDeltaFile
1.72+1-1lang/gcc/11/Makefile
+1-11 files

OpenBSD/ports LKFA1D3mail/p5-Mail-DMARC distinfo Makefile, mail/p5-Mail-DMARC/pkg PLIST

   update to 2.20260827
VersionDeltaFile
1.8+14-0mail/p5-Mail-DMARC/pkg/PLIST
1.25+2-10mail/p5-Mail-DMARC/Makefile
1.18+2-2mail/p5-Mail-DMARC/distinfo
+18-123 files

OpenBSD/ports G3FGkKZmisc/bible-kjv Makefile distinfo

   misc/bible-kjv: maintenance update to 4.44
VersionDeltaFile
1.15+2-2misc/bible-kjv/distinfo
1.19+1-1misc/bible-kjv/Makefile
+3-32 files

OpenBSD/src qbV78Ewusr.bin/tmux window-switch.c

   Create screen before zoom may need to use it.
VersionDeltaFile
1.4+4-4usr.bin/tmux/window-switch.c
+4-41 files

OpenBSD/src MpbvVbEusr.bin/tmux screen-redraw.c server-client.c

   Do not allow cursor on/off to escape synchronized updates.
VersionDeltaFile
1.158+3-5usr.bin/tmux/screen-redraw.c
1.510+6-2usr.bin/tmux/server-client.c
+9-72 files

OpenBSD/src OyOV0BAsys/dev/pci/drm/apple apple_drv.c

   drm: apple: Switch back to drm_atomic_helper_commit_tail_rpm()

   From Janne Grunau
   bd8ce96f6e76b98940352b18fe735a7943471ed7 in AsahiLinux/linux

   This implictly gets rid of drm_atomic_helper_wait_for_flip_done()
   and makes graphical output on Apple Silicon machines noticably
   snappier.

   ok kettenis@ jsg@
VersionDeltaFile
1.5+1-21sys/dev/pci/drm/apple/apple_drv.c
+1-211 files

OpenBSD/ports cm6Pls5lang/erlang/27 distinfo Makefile, lang/erlang/28 distinfo Makefile

   lang/erlang: Update to 27.3.4.17, 28.5.0.6 and 29.0.6

   Fixes CVE-2026-75538 among several other bugs
VersionDeltaFile
1.8+15-15lang/erlang/29/Makefile
1.26+15-15lang/erlang/28/Makefile
1.36+15-15lang/erlang/27/Makefile
1.7+4-4lang/erlang/29/distinfo
1.22+4-4lang/erlang/28/distinfo
1.30+4-4lang/erlang/27/distinfo
+57-576 files

OpenBSD/ports fajl8qBdevel/sccache crates.inc Makefile

   devel/sccache: update to 0.17.0
VersionDeltaFile
1.18+4-4devel/sccache/distinfo
1.17+1-1devel/sccache/crates.inc
1.23+1-1devel/sccache/Makefile
+6-63 files

OpenBSD/ports wFjUAVTdevel/esbuild distinfo Makefile

   devel/esbuild: Update to 0.28.2

   from Igor Zornik (Maintainer), thanks
VersionDeltaFile
1.22+5-4devel/esbuild/Makefile
1.21+2-2devel/esbuild/distinfo
+7-62 files

OpenBSD/ports vVAeV3Mnet/barrier Makefile

   mark net/barrier BROKEN, old software wants old devel/gtest

   Their CMake goo includes bundles missing from the autogenerated tarball,
   there is no knob to disable tests, we don't run them (NO_TEST=yes),
   but instead nuke the CMake goo and hope for system gtest to work,
   which now fails due to newer devel/gtest requiring C++17.

   barrier is C++14, its last release is five years old and we're behind,
   upstream's last commit was four years ago...
VersionDeltaFile
1.10+1-0net/barrier/Makefile
+1-01 files

OpenBSD/ports G42xod0graphics/blender Makefile

   graphics/blender: add missing dependency on libspnav

   While here explicitely disable optional dependencies not yet ported.

   ok rsadowski@
VersionDeltaFile
1.155+31-16graphics/blender/Makefile
+31-161 files

OpenBSD/ports 30K6mruaudio/chromaprint Makefile

   disable tests, bundled gtest reaches into now too new system gtest headers
VersionDeltaFile
1.25+3-1audio/chromaprint/Makefile
+3-11 files

OpenBSD/ports JPKI7whdevel/zizmor Makefile crates.inc

   Update to zizmor 1.30.0

   https://github.com/zizmorcore/zizmor/releases/tag/v1.30.0
VersionDeltaFile
1.9+88-90devel/zizmor/distinfo
1.8+43-44devel/zizmor/crates.inc
1.12+1-1devel/zizmor/Makefile
+132-1353 files

OpenBSD/ports 6usTqK1www/librewolf Makefile, www/librewolf/patches patch-config_makefiles_rust_mk patch-mozconfig

   www/librewolf: bump SO_VERSION, refresh patches, from MAINTAINER
VersionDeltaFile
1.3+2-2www/librewolf/patches/patch-mozconfig
1.17+2-1www/librewolf/Makefile
1.2+1-1www/librewolf/patches/patch-config_makefiles_rust_mk
+5-43 files

OpenBSD/ports OFwY3L1devel/mergiraf Makefile crates.inc

   Update to mergiraf 0.19.1

   https://codeberg.org/mergiraf/mergiraf/releases/tag/v0.19.1
VersionDeltaFile
1.7+26-22devel/mergiraf/distinfo
1.7+12-10devel/mergiraf/crates.inc
1.8+1-1devel/mergiraf/Makefile
+39-333 files

OpenBSD/src uAU578llib/libexpat README.md Changes, lib/libexpat/lib xmltok.h xmlparse.c

   Update libexpat to version 2.8.4

   Relevant for OpenBSD are security fixes #1321 #1331 #1322, other
   changes #1315 #1325 #1334 #1340 #1319 #1320.  Library bump is not
   necessary.
   CVE-2026-66046 CVE-2026-76641 CVE-2026-76957

   OK tb@
VersionDeltaFile
1.52+189-64lib/libexpat/lib/xmlparse.c
1.14+79-0lib/libexpat/tests/basic_tests.c
1.40+65-0lib/libexpat/Changes
1.15+57-1lib/libexpat/tests/misc_tests.c
1.11+2-2lib/libexpat/lib/xmltok.h
1.30+1-1lib/libexpat/README.md
+393-683 files not shown
+396-709 files

OpenBSD/ports VgbnRWYmail/p5-MIME-Types Makefile distinfo

   update p5-MIME-Types to 2.30
VersionDeltaFile
1.26+2-2mail/p5-MIME-Types/distinfo
1.32+2-1mail/p5-MIME-Types/Makefile
+4-32 files

OpenBSD/src 8n0XnX3usr.bin/mandoc cgi.c

   Use unveil(2) and clamp down on pledge(2).
   The main() program establishes a baseline, allowing the maximum
   that might ever be needed: stdio rpath and read access to the MAN_DIR.
   The top level page generators (pg_show, pg_search) narrow unveil(2)
   to the specific manual page tree selected by the user.
   When the selected manual page file has been opened, the pledge is narrowed
   to just stdio (in resp_catman, resp_format, pg_searchres, pg_index).
   Except for internal errors and bad requests, which error out early,
   exactly one of these narrowing codepaths is always trodden.
VersionDeltaFile
1.124+82-3usr.bin/mandoc/cgi.c
+82-31 files

OpenBSD/ports tqZc1eEnet/p5-Net-DNS Makefile distinfo

   update p5-Net-DNS to 1.57
   CVE-2026-64194 CVE-2026-64193
VersionDeltaFile
1.93+4-4net/p5-Net-DNS/distinfo
1.119+1-1net/p5-Net-DNS/Makefile
+5-52 files

OpenBSD/ports LlI6YFjtextproc/p5-PPIx-Regexp Makefile distinfo

   update p5-PPIx-Regexp to 0.092
   no functional change
VersionDeltaFile
1.17+2-2textproc/p5-PPIx-Regexp/distinfo
1.25+2-1textproc/p5-PPIx-Regexp/Makefile
+4-32 files

OpenBSD/ports FZyN3Buwww/librewolf/pkg PLIST

   www/librewolf: glxtest, vulkantest & vaapitest merged into gfxtest cf #1949093
VersionDeltaFile
1.4+1-3www/librewolf/pkg/PLIST
+1-31 files

OpenBSD/src TWWsMSYusr.bin/tmux window-copy.c

   When changing selection-mode to line, set up the selection start and end
   correctly, GitHub issue 5545.
VersionDeltaFile
1.429+63-2usr.bin/tmux/window-copy.c
+63-21 files

OpenBSD/src k103sDHusr.bin/tmux tmux.h options-table.c

   Extend word commands to use any Unicode whitespace character, GitHub
   issue 5562 from Hongyi Zhao.
VersionDeltaFile
1.72+67-1usr.bin/tmux/utf8.c
1.158+21-13usr.bin/tmux/grid.c
1.1163+11-6usr.bin/tmux/tmux.1
1.244+3-2usr.bin/tmux/options-table.c
1.1433+2-1usr.bin/tmux/tmux.h
+104-235 files

OpenBSD/ports 04BV9Ovnet/p5-Net-Daemon distinfo Makefile, net/p5-Net-Daemon/pkg DESCR

   update p5-Net-Daemon to 0.52
VersionDeltaFile
1.24+10-6net/p5-Net-Daemon/Makefile
1.2+7-7net/p5-Net-Daemon/pkg/DESCR
1.10+2-2net/p5-Net-Daemon/distinfo
+19-153 files