sys/qwz: unwind cold startup failures
Based on sys/dev/ic/qwx.c,v 1.134
Track powerup and completed core initialization so failed cold starts
reset hardware before reclaiming initialized DMA resources. Release
partial TX allocations and RX rings; ordinary interface down and up
continues to retain firmware.
OK: stsp@
sys/qwz: skip uninitialized CE polling
Based on sys/dev/ic/qwx.c,v 1.135
Track successful CE initialization to decide whether completion
polling is valid; provide dircet TX buffer reclamation for cold
cleanup after hardware reset, when ring polling is no longer safe.
OK: stsp@
sys/qwz: retain HAL allocations on resume
Based on sys/dev/ic/qwx.c,v 1.97 and sys/dev/ic/qwx.c,v 1.136
Preserve HAL allocation pointers across reinitialization: reuse qwz
allocated ring configuration and claer retained pointer memory. On
failure, free only allocations made by the current attempt.
OK: stsp@
update to png-1.6.59, fixing use-after-free of zlib input in
png_read_end() after incomplete zTXt, iTXt or iCCP decompression
https://github.com/pnggroup/libpng/security/advisories/GHSA-qvg3-h654-xq3j
ok matthieu who has verified that this is not reachable from xenocara's
use of the static-linked copy
set -u _nsd / _unbound as appropriate when running nsd-control /
unbound-control through doas, to match the existing pkg-readme.
from Atanas Vladimirov.
For allocations between half a page and a page (which are moved
towards the end) we don't clear the proper region with freezero().
Instead, the clearing is done from the start of the page. So fix that.
Reported by Acts1631
ok deraadt@
Fix softraid rebuild on disks with 4096-byte sectors.
Problem found, suggested diffs, and testing by Dariusz Swiderski.
ok claudio@ "makes release" deraadt@
Backport three security fixes from the groff-1.24.2 release.
OK naddy@ on a previous, minimally different version of this patch.
From the groff-1.24.2 release announcement (September 28, 2026):
"This release corrects command injection security vulnerabilities
(CWE-78) in the mmroff, pdfmom, and pre-grohtml programs. The last of
these is a preprocessor that is run when groff or troff is run with the
-T html or -T xhtml options. The vulnerabilities are variously
14-26 years old. Malicious input can escape groff's default "safer"
mode, running commands embedded in that input at the user's privilege
level. The groff development team recommends this release to any users
who employ the named tools or GNU troff output formats with untrusted
inputs.
Man page rendering is not vulnerable unless rendering (X)HTML."