OpenBSD/src 7mGHwJMsys/arch/amd64/include i82489reg.h, sys/arch/i386/include i82489reg.h

   include tsc deadline bit in lapic timer mode mask
   ok dv@ mlarkin@
VersionDeltaFile
1.6+2-2sys/arch/i386/include/i82489reg.h
1.8+2-2sys/arch/amd64/include/i82489reg.h
+4-42 files

OpenBSD/src NU6LETVlib/libcrypto/man X509_check_ca.3, lib/libcrypto/x509 x509_purp.c

   Align X509_chack_ca() with modern OpenSSL

   We have been documenting for quite a while that this API is broken and
   that callers need to ensure proper caching of extensions using the usual
   X509_check_purpose() trick. Since the API can't indicate errors, choose
   to err on the safe side and report a CA only after successful caching of
   extensions.

   Reported by Frank Denis and others

   ok beck, discussed with jsing
VersionDeltaFile
1.9+4-4lib/libcrypto/man/X509_check_ca.3
1.46+3-2lib/libcrypto/x509/x509_purp.c
+7-62 files

OpenBSD/ports fFG5xWasysutils/packer Makefile modules.inc

   Update to packer-1.16.1.
VersionDeltaFile
1.76+172-142sysutils/packer/distinfo
1.32+63-48sysutils/packer/modules.inc
1.84+1-1sysutils/packer/Makefile
+236-1913 files

OpenBSD/ports WYp73BGnet/py-boto3 Makefile distinfo

   Update to py3-boto3-1.43.98.
VersionDeltaFile
1.665+2-2net/py-boto3/distinfo
1.678+1-1net/py-boto3/Makefile
+3-32 files

OpenBSD/ports TkOrXiunet/py-botocore Makefile distinfo

   Update to py3-botocore-1.43.98.
VersionDeltaFile
1.882+2-2net/py-botocore/distinfo
1.892+1-1net/py-botocore/Makefile
+3-32 files

OpenBSD/ports 0UEzGr5misc/gramps Makefile distinfo, misc/gramps/pkg PLIST

   Update to gramps-6.0.8.
VersionDeltaFile
1.28+2-2misc/gramps/distinfo
1.39+3-0misc/gramps/pkg/PLIST
1.74+1-1misc/gramps/Makefile
+6-33 files

OpenBSD/ports LVHKoqZx11/gnome/gcr Makefile

   Tweak comment; no pkg change.
VersionDeltaFile
1.86+1-1x11/gnome/gcr/Makefile
+1-11 files

OpenBSD/ports XH5JnJtx11/gnome/gdm Makefile, x11/gnome/gdm/pkg PLIST

   Fix a 10-year long warning by installing the dconf profile under the right
   name.
VersionDeltaFile
1.359+3-1x11/gnome/gdm/Makefile
1.112+1-1x11/gnome/gdm/pkg/PLIST
+4-22 files

OpenBSD/ports KuaR06nsysutils/consolekit/patches patch-src_ck-sysdeps-unix_c

   race condition introduced by aja@
VersionDeltaFile
1.19+0-0sysutils/consolekit/patches/patch-src_ck-sysdeps-unix_c
+0-01 files

OpenBSD/ports aAmqzo2sysutils/consolekit Makefile distinfo, sysutils/consolekit/patches patch-src_ck-inhibit-manager_c patch-libconsolekit_sd-login_h

   update to 1.2.7
VersionDeltaFile
1.23+2-2sysutils/consolekit/distinfo
1.115+1-2sysutils/consolekit/Makefile
1.8+0-0sysutils/consolekit/patches/patch-src_ck-inhibit-manager_c
1.2+0-0sysutils/consolekit/patches/patch-libconsolekit_sd-login_h
1.2+0-0sysutils/consolekit/patches/patch-libconsolekit_sd-compat_c
+3-45 files

OpenBSD/ports TYy7nwIaudio/umurmur Makefile distinfo

   Update to umurmur-0.5.1.

   From Andrew Kloet (MAINTAINER)
VersionDeltaFile
1.13.14.2+2-2audio/umurmur/distinfo
1.33.2.2+1-1audio/umurmur/Makefile
+3-32 files

OpenBSD/ports WWrFtKFsysutils/consolekit Makefile, sysutils/consolekit/patches patch-src_ck-sysdeps-unix_c

   Stop playing with XDG_RUNTIME_DIR.
VersionDeltaFile
1.18+37-31sysutils/consolekit/patches/patch-src_ck-sysdeps-unix_c
1.114+1-1sysutils/consolekit/Makefile
+38-322 files

OpenBSD/ports gU8pjfvaudio/umurmur Makefile distinfo

   Update to umurmur-0.5.1.

   From Andrew Kloet (MAINTAINER)
VersionDeltaFile
1.16+2-2audio/umurmur/distinfo
1.37+1-1audio/umurmur/Makefile
+3-32 files

OpenBSD/ports GNCfLjMprint/sile Makefile

   Update gentium RUN_DEPENDS to new location. Update SITES* and HOMEPAGE.
VersionDeltaFile
1.16+5-5print/sile/Makefile
+5-51 files

OpenBSD/ports n9RgEPyfonts Makefile, fonts/abyssinica distinfo Makefile

   Finish moving sil.org fonts.
VersionDeltaFile
1.101+1-11fonts/Makefile
1.14+0-0fonts/alkalami/Makefile
1.5+0-0fonts/abyssinica/pkg/PLIST
1.2+0-0fonts/abyssinica/pkg/DESCR
1.4+0-0fonts/abyssinica/distinfo
1.17+0-0fonts/abyssinica/Makefile
+1-1139 files not shown
+1-1145 files

OpenBSD/ports kSgvkdbfonts/sil-fonts Makefile.inc Makefile, fonts/sil-fonts/dai-banna/pkg PLIST-main

   Consolidate sil.org-developed fonts into a single subdirectory.
VersionDeltaFile
1.1+37-0fonts/sil-fonts/Makefile
1.1+23-0fonts/sil-fonts/lisubosa/pkg/PLIST-main
1.1+21-0fonts/sil-fonts/Makefile.inc
1.1+18-0fonts/sil-fonts/lisubosa/pkg/PLIST-web
1.1+18-0fonts/sil-fonts/gentium/pkg/PLIST-main
1.1+18-0fonts/sil-fonts/dai-banna/pkg/PLIST-main
+135-0406 files not shown
+1,695-0412 files

OpenBSD/ports yytTEbBx11/gnome/keyring Makefile

   Update to pam_keyring.
VersionDeltaFile
1.155+8-1x11/gnome/keyring/Makefile
+8-11 files

OpenBSD/src DYPymKwusr.sbin/ocspcheck ocspcheck.c

   ocspcheck: do not use OCSP_TRUSTOTHER

   Like in libtls, ensure that the provided OCSP staple is validated by an
   OCSP trust chain to the root.

   From Acts1631

   ok beck kenjiro
VersionDeltaFile
1.37+2-3usr.sbin/ocspcheck/ocspcheck.c
+2-31 files

OpenBSD/ports PSzrndogames/angrydd Makefile

   distfile no longer hosted here
VersionDeltaFile
1.27+1-2games/angrydd/Makefile
+1-21 files

OpenBSD/src wG6XuAJlib/libtls tls_ocsp.c

   libtls: fix OCSP responder authorization bypass

   If a CA revokes a valid TLS server cert using OCSP, a client configured to
   require a valid OCSP staple should always reject that cert. If the server's
   private key has been compromised, it was possible to bypass this requirement.

   The problem is the behavior of OCSP_TRUSTOTHER which skips chain
   validation for the OCSP trust chain to the root and the checking that
   the staple was signed by a CA of the validating chain. So remove this flag.

   This only affects callers of tls_config_ocsp_require_stapling(). In OpenBSD
   base these are reachable in OpenBSD base via opt-in behaviors of nc(1) -T
   and ftp(1) -S via the "muststaple" keyword. No ports call these functions.

   Reported by Acts1631 and Jiho Kim

   ok beck kenjiro
VersionDeltaFile
1.30+2-10lib/libtls/tls_ocsp.c
+2-101 files

OpenBSD/src qwvBCC1usr.sbin/dhcpd dhcp.c

   avoid double frees; ok krw@
VersionDeltaFile
1.59+1-3usr.sbin/dhcpd/dhcp.c
+1-31 files

OpenBSD/src eRIvb7Xlib/libcrypto/objects objects.txt obj_mac.num

   Add OID for id-ct-rpkiErikSegmentIndex

   Reference: draft-ietf-sidrops-rpki-erik-protocol-05

   See also SMI Security for S/MIME CMS Content Type (1.2.840.113549.1.9.16.1)
   https://www.iana.org/assignments/smi-numbers#security-smime-1

   OK tb@
VersionDeltaFile
1.47+1-0lib/libcrypto/objects/objects.txt
1.42+1-0lib/libcrypto/objects/obj_mac.num
+2-02 files

OpenBSD/ports M7jVrAedatabases/mariadb Makefile, databases/mariadb/patches patch-configure_cmake patch-mysys_my_getexe_c

   use getexecpath() in MariaDB, from Brad
VersionDeltaFile
1.3+9-22databases/mariadb/patches/patch-config_h_cmake
1.2+15-5databases/mariadb/patches/patch-mysys_my_getexe_c
1.1+13-0databases/mariadb/patches/patch-configure_cmake
1.170+1-0databases/mariadb/Makefile
+38-274 files

OpenBSD/ports hebtSSzdevel/p5-Devel-Leak-Object distinfo Makefile, devel/p5-Devel-Leak-Object/pkg DESCR

   update p5-Devel-Leak-Object to 1.02
VersionDeltaFile
1.7+11-6devel/p5-Devel-Leak-Object/Makefile
1.2+2-2devel/p5-Devel-Leak-Object/distinfo
1.3+1-1devel/p5-Devel-Leak-Object/pkg/DESCR
+14-93 files

OpenBSD/ports BdWmxMjlang/ruby/4.0 Makefile distinfo, lang/ruby/4.0/patches patch-compile_c

   Update to Ruby 4.0.7

   This includes fixes for:

   CVE-2026-80212: Memory exhaustion through malicious DNS responses
   CVE-2026-80213: Hostname validation bypass
VersionDeltaFile
1.8+11-11lang/ruby/4.0/pkg/PLIST-main
1.6+5-0lang/ruby/4.0/pkg/PLIST-ri_docs
1.5+2-2lang/ruby/4.0/patches/patch-compile_c
1.8+2-2lang/ruby/4.0/distinfo
1.13+1-1lang/ruby/4.0/Makefile
+21-165 files

OpenBSD/ports 6Rcu2eydevel/codex Makefile distinfo

   devel/codex: update to 0.155.1
VersionDeltaFile
1.51+2-2devel/codex/distinfo
1.53+1-1devel/codex/Makefile
+3-32 files

OpenBSD/ports Jn4jrP2lang/dmd distinfo Makefile, lang/dmd/patches patch-dmd_druntime_Makefile patch-dmd_druntime_src_core_sys_posix_netinet_in__d

   lang/dmd: update to 2.113.0

   Here I switched dmd to use gdc over gdmd as bootstrap compiler.
VersionDeltaFile
1.11+21-33lang/dmd/pkg/PLIST
1.22+5-12lang/dmd/Makefile
1.1+17-0lang/dmd/patches/patch-dmd_compiler_src_dmd_cpreprocess_d
1.1+12-0lang/dmd/patches/patch-dmd_druntime_src_core_sys_posix_netinet_in__d
1.14+4-6lang/dmd/distinfo
1.3+2-2lang/dmd/patches/patch-dmd_druntime_Makefile
+61-535 files not shown
+64-5611 files

OpenBSD/ports iRErLVylang/gdmd distinfo Makefile

   lang/gdmd: update to 20260801

   Since gdc in gcc was fixed, it can be linked back to build.

   It also works well enough to be used as bootstrap compiler for lang/dmd
VersionDeltaFile
1.7+3-6lang/gdmd/Makefile
1.2+2-2lang/gdmd/distinfo
+5-82 files

OpenBSD/ports MNsgp0mwww/p5-XML-Feed Makefile distinfo

   update p5-XML-Feed to 1.0.1
VersionDeltaFile
1.7+2-2www/p5-XML-Feed/distinfo
1.16+2-1www/p5-XML-Feed/Makefile
+4-32 files

OpenBSD/src JbwBhFPsys/netinet tcp_input.c

   Recalulate the TCP SACK list after memory exhaustion.

   Acts1631 found that tcp(4) can advertise SACK blocks for data that
   it has discarded when the global TCP reassembly pool is exhausted.
   This can make a sender omit missing data from fast recovery and
   wait for its retransmission timer.

   This commit clears the receiver SACK report whenever the reassembly
   allocation fails, before either path can discard queued data.  It
   also returns -1 when the new input segment itself is discarded.
   The caller maps that value back to zero TCP flags but does not add
   the discarded range to the SACK report.  On the reuse path, the
   accepted current segment is still passed to tcp_update_sack_list(),
   after the stale report has been cleared.

   from Acts1631; discussed with claudio@ tb@
VersionDeltaFile
1.469+13-4sys/netinet/tcp_input.c
+13-41 files