OpenBSD/src GyCKF5ulib/libssl tls13_client.c

   Send illegal parameter alerts for various HelloRetryRequest violations.

   Be more RFC compliant and send illegal parameter alerts when the client
   receives a HelloRetryRequest that requests a group that we did not offer
   or a group that we sent a key share for in the ClientHello. These were
   annotated as missing, but not previously implemented.

   Prompted by a report from the tlspuffin team.

   ok tb@
VersionDeltaFile
1.107+10-6lib/libssl/tls13_client.c
+10-61 files

OpenBSD/ports 3xwr4AUshells/atuin distinfo crates.inc

   shells/atuin: update to 18.16.1
VersionDeltaFile
1.7+412-314shells/atuin/distinfo
1.7+205-156shells/atuin/crates.inc
1.8+1-1shells/atuin/Makefile
+618-4713 files

OpenBSD/src rrFF8chregress/lib/libssl/renegotiation renegotiation_test.c Makefile

   Improve renegotation regress.

   Include coverage of Renegotiation Indication and legacy connection
   handling.
VersionDeltaFile
1.4+106-18regress/lib/libssl/renegotiation/renegotiation_test.c
1.3+3-2regress/lib/libssl/renegotiation/Makefile
+109-202 files

OpenBSD/src d9ZIpEylib/libssl/man SSL_CTX_set_options.3

   Mop up SSL_CTX_set_options(3).

   SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS is now a no-op, tidy up
   SSL_OP_LEGACY_SERVER_CONNECT and reflect the current state of SSL_OP_ALL
   Delete the entire "SECURE RENEGOTIATION" section that contained ancient
   ramblings.

   ok beck@ tb@
VersionDeltaFile
1.18+5-89lib/libssl/man/SSL_CTX_set_options.3
+5-891 files

OpenBSD/src 2yaCHYClib/libssl ssl_lib.c ssl.h

   Remove SSL_OP_LEGACY_SERVER_CONNECT from default options.

   Remove SSL_OP_LEGACY_SERVER_CONNECT from the default SSL options and the
   SSL_OP_ALL define. This means that we will now refuse to connect to a
   TLSv1.2 server if it does not support the Renegotiation Indication (RI)
   extension. This prevents a class of attacks against TLS clients that are
   talking to TLSv1.2-only servers that permit client initiated renegotiation.

   Raised by Lucca Hirschi et al from Inria.

   ok beck@ tb@
VersionDeltaFile
1.335+2-6lib/libssl/ssl_lib.c
1.251+2-3lib/libssl/ssl.h
+4-92 files

OpenBSD/ports ixkmdb5editors/jmigpin-editor distinfo modules.inc

   editors/jmigpin-editor: update to 3.13
VersionDeltaFile
1.4+128-56editors/jmigpin-editor/distinfo
1.4+34-16editors/jmigpin-editor/modules.inc
1.4+1-1editors/jmigpin-editor/Makefile
+163-733 files

OpenBSD/ports axIrmIYwww/dufs crates.inc

   www/dufs: remove unexpected output from crates.inc

   pointed by espie@

   no build changes
VersionDeltaFile
1.2+0-2www/dufs/crates.inc
+0-21 files

OpenBSD/src duRZSlmshare/man/man5 cargo-module.5

   cargo-module.5: document more variables

   From Andrew Kloet andrew kloet.net
VersionDeltaFile
1.11+85-2share/man/man5/cargo-module.5
+85-21 files

OpenBSD/ports vi0SkKVgames/rocksndiamonds distinfo Makefile

   Update to rocksndiamonds-4.4.2.1.
VersionDeltaFile
1.61+2-2games/rocksndiamonds/distinfo
1.79+1-1games/rocksndiamonds/Makefile
+3-32 files

OpenBSD/ports mINkE8Ndevel/sbt distinfo Makefile

   devel/sbt: update to 1.12.12
VersionDeltaFile
1.28+2-2devel/sbt/distinfo
1.28+1-1devel/sbt/Makefile
+3-32 files

OpenBSD/ports cSxqd8Ddevel/tig distinfo Makefile

   Update tig to 2.6.1.
VersionDeltaFile
1.34+2-2devel/tig/distinfo
1.51+1-2devel/tig/Makefile
+3-42 files

OpenBSD/ports VYdyLnKx11/xsettingsd Makefile distinfo, x11/xsettingsd/patches patch-CMakeLists_txt

   update to xsettingsd-1.0.4
VersionDeltaFile
1.18+3-4x11/xsettingsd/Makefile
1.8+2-2x11/xsettingsd/distinfo
1.3+0-0x11/xsettingsd/patches/patch-CMakeLists_txt
+5-63 files

OpenBSD/ports O414wETmultimedia/yle-dl distinfo Makefile, multimedia/yle-dl/pkg PLIST

   update to yle-dl-20260520, from Timo Myyra (maintainer)
VersionDeltaFile
1.22+2-2multimedia/yle-dl/distinfo
1.20+3-0multimedia/yle-dl/pkg/PLIST
1.44+1-1multimedia/yle-dl/Makefile
+6-33 files

OpenBSD/ports G86FJDyeditors/libreoffice distinfo Makefile, editors/libreoffice/patches patch-external_xmlsec_openbsd_patch patch-external_xmlsec_ExternalProject_xmlsec_mk

   update to 26.2.4.2
VersionDeltaFile
1.138+34-34editors/libreoffice/distinfo
1.344+14-14editors/libreoffice/Makefile
1.1+15-0editors/libreoffice/patches/patch-external_xmlsec_openbsd_patch
1.1+12-0editors/libreoffice/patches/patch-external_xmlsec_ExternalProject_xmlsec_mk
1.90+11-1editors/libreoffice/pkg/PLIST-main
1.1+11-0editors/libreoffice/patches/patch-external_xmlsec_UnpackedTarball_xmlsec_mk
+97-496 files

OpenBSD/ports IuJkYD3lang/gcc/16 Makefile distinfo, lang/gcc/16/pkg PFRAG.128BIT-ada PLIST-ada

   lang/gcc/16: added i386 bootstrap; updated plist for i386
VersionDeltaFile
1.2+149-0lang/gcc/16/pkg/PFRAG.128BIT-ada
1.2+0-149lang/gcc/16/pkg/PLIST-ada
1.2+25-0lang/gcc/16/pkg/PFRAG.X86-main
1.3+4-4lang/gcc/16/Makefile
1.2+2-0lang/gcc/16/distinfo
+180-1535 files

OpenBSD/ports wJmAiJyx11/kde-plasma/oxygen Makefile, x11/kde-plasma/oxygen/pkg PLIST

   Remove oxygen Qt5/KDE5 support
VersionDeltaFile
1.20+11-34x11/kde-plasma/oxygen/Makefile
1.17+8-12x11/kde-plasma/oxygen/pkg/PLIST
+19-462 files

OpenBSD/ports KhAxJbzx11/kde-applications/kdenlive Makefile

   Remove USE_WXNEEDED, qtwebengine is no longer used
VersionDeltaFile
1.48+1-4x11/kde-applications/kdenlive/Makefile
+1-41 files

OpenBSD/ports HnkIQ7Rx11/kde-applications/kdenlive Makefile

   Fix typo and remove min mlt version

   Typo spotted by espie@, thanks
VersionDeltaFile
1.47+5-4x11/kde-applications/kdenlive/Makefile
+5-41 files

OpenBSD/ports S2Zz27nsysutils/opentofu Makefile, sysutils/opentofu/pkg README PLIST

   Add README to build in-house providers.
VersionDeltaFile
1.1+63-0sysutils/opentofu/pkg/README
1.2+1-0sysutils/opentofu/pkg/PLIST
1.43+1-0sysutils/opentofu/Makefile
+65-03 files

OpenBSD/ports EWOfNwNsysutils/terraform Makefile

   Drop maintainer, I have moved to opentofu.
VersionDeltaFile
1.156+1-2sysutils/terraform/Makefile
+1-21 files

OpenBSD/ports Jvo7nxZlang/gcc/11 Makefile distinfo

   lang/gcc/11: added new i386 bootstrap; explain that it required for dlang
VersionDeltaFile
1.67+2-2lang/gcc/11/Makefile
1.19+2-2lang/gcc/11/distinfo
+4-42 files

OpenBSD/ports RXFU7fmnet/ssldump Makefile

   drop junk variables (renamed to "comment out" while checking if they're still
   needed during the update). spotted by espie.
VersionDeltaFile
1.25+0-5net/ssldump/Makefile
+0-51 files

OpenBSD/src x1Yx9L4usr.sbin/relayd ssl.c ca.c

   relayd: drain OpenSSL error queue on TLS failures

   Borrowed from smtpd. Without draining we just log "RSA_meth_dup failed"
   and lose the actual reason.

   Wire ssl_error() into ca_engine_init(), which also kills a dead
   RSA_meth_free() on a NULL pointer there, and into ssl_load_key()s fail
   path.

   Tweaks and OK tb
VersionDeltaFile
1.41+16-1usr.sbin/relayd/ssl.c
1.54+4-2usr.sbin/relayd/ca.c
1.286+2-1usr.sbin/relayd/relayd.h
+22-43 files

OpenBSD/src 34r7bgBusr.sbin/relayd ca.c

   relayd: remove from and toptr to simplify

   feedback and OK claudio
VersionDeltaFile
1.53+8-12usr.sbin/relayd/ca.c
+8-121 files

OpenBSD/src cJgMLlOusr.sbin/relayd relayd.c config.c

   relayd: use ibuf_get_string() and ibuf_get_data() to read imsg payloads

   Drop the local get_string() and read variable-length string and binary
   payloads through the ibuf getters instead of the raw imsg->data pointer.

   ibuf_get_string() no longer trims the input at the first non-printable
   byte like the old get_string() did; the payloads come from the parent
   over privsep imsg.

   idea and ok claudio
VersionDeltaFile
1.201+11-18usr.sbin/relayd/relayd.c
1.53+7-12usr.sbin/relayd/config.c
1.285+2-3usr.sbin/relayd/relayd.h
+20-333 files

OpenBSD/src 8oEyL01usr.sbin/relayd control.c

   fix knfmt
VersionDeltaFile
1.68+2-2usr.sbin/relayd/control.c
+2-21 files

OpenBSD/src 5HQcdhGusr.sbin/relayd proc.c relayd.h

   Check error in proc_forward_imsg
VersionDeltaFile
1.55+3-5usr.sbin/relayd/proc.c
1.284+2-2usr.sbin/relayd/relayd.h
+5-72 files

OpenBSD/src YpPwkICusr.sbin/relayd relayd.c relayd.h

   relayd: read parent_dispatch_pfe() payloads via the imsg getters

   Use imsg_get_data() for the fixed-size messages and imsg_get_ibuf() for
   the variable-length IMSG_CTL_RELOAD path, taking the config name from
   the ibuf via ibuf_data()/ibuf_size().

   Remove IMSG_SIZE_CHECK and IMSG_DATA_SIZE, no consumer left.


   OK claudio
VersionDeltaFile
1.200+31-13usr.sbin/relayd/relayd.c
1.283+1-7usr.sbin/relayd/relayd.h
+32-202 files

OpenBSD/ports g0zRi3gmisc/brltty Makefile, misc/brltty/files pcm_audio.c

   misc/brltty: update to 6.9.1

   with and ok volker@
VersionDeltaFile
1.7+732-138misc/brltty/pkg/PLIST
1.1+140-0misc/brltty/files/pcm_audio.c
1.27+72-35misc/brltty/Makefile
1.6+27-8misc/brltty/patches/patch-configure
1.3+10-11misc/brltty/patches/patch-Programs_Makefile_in
1.1+17-0misc/brltty/patches/patch-Programs_auth_c
+998-1929 files not shown
+1,011-19415 files

OpenBSD/src EFy1aSsusr.sbin/relayd ca.c

   relayd: use imsg_get_ibuf() for variable-length CA key operations

   The IMSG_CA_PRIVENC/PRIVDEC messages carry a ctl_keyop header followed
   by cko_flen (request) or cko_tlen (response) trailing bytes, so the
   exact-size imsg_get_data() cannot be used. Read the header with
   imsg_get_ibuf() + ibuf_get() and take the payload from the same ibuf
   via ibuf_data()/ibuf_size().

   Tweaks (in a different commit) and OK claudio
VersionDeltaFile
1.52+37-18usr.sbin/relayd/ca.c
+37-181 files