OpenBSD/src VhWEB7eshare/man/man9 vnode.9

   vnode(9): remove v_inflight

   OK: deraadt@
VersionDeltaFile
1.37+2-3share/man/man9/vnode.9
+2-31 files

OpenBSD/ports 9oP06avwww/gitea distinfo Makefile, www/gitea/patches patch-custom_conf_app_example_ini

   www/gitea: update to 1.27.3

   It fixes numerous of security issue, for example CVE-2026-60004

   Diff from Anton Kasimov

   Ok: pvk@ (maintainer)
VersionDeltaFile
1.66.2.1+420-241www/gitea/pkg/PLIST
1.31.2.1+49-53www/gitea/patches/patch-custom_conf_app_example_ini
1.137.2.1+10-7www/gitea/Makefile
1.118.2.1+2-2www/gitea/distinfo
+481-3034 files

OpenBSD/src RNWJG7Hsys/dev/fdt com_fdt.c

   Call the activate function for com at fdt.

   ok mlarkin@, ok deraadt@
VersionDeltaFile
1.11+3-2sys/dev/fdt/com_fdt.c
+3-21 files

OpenBSD/ports FkbjXtUwww/py-openapi-core Makefile, www/py-openapi-core/patches patch-openapi_core___init___py patch-openapi_core__jsonschema_path_compat_py

   add compat shim for jsonschema-path >= 0.5

   jsonschema-path was updated to be compatible with python 3.14+ but
   that broke openapi_core which cannot be updated at this point
VersionDeltaFile
1.1+15-0www/py-openapi-core/patches/patch-openapi_core__jsonschema_path_compat_py
1.1+11-0www/py-openapi-core/patches/patch-openapi_core___init___py
1.6+3-0www/py-openapi-core/pkg/PLIST
1.7+1-1www/py-openapi-core/Makefile
+30-14 files

OpenBSD/ports fR71BCrshells/bash Makefile distinfo, shells/bash/pkg PLIST

   shells/bash: update to 5.3 patchlevel 20

   Also catch up with plist/wantlib changes bubbling up from gettext.
VersionDeltaFile
1.92+10-0shells/bash/distinfo
1.148+3-3shells/bash/Makefile
1.23+4-0shells/bash/pkg/PLIST
+17-33 files

OpenBSD/ports Wd2TCVvnet/avahi Makefile, net/avahi/patches patch-avahi-core_fdutil_c patch-avahi-daemon_main_c

   Rework this port a bit and tweak BDEP.
VersionDeltaFile
1.1+36-0net/avahi/patches/patch-avahi-utils_Makefile_am
1.1+33-0net/avahi/patches/patch-avahi-ui_Makefile_am
1.8+13-12net/avahi/patches/patch-avahi-compat-libdns_sd_warn_c
1.171+9-10net/avahi/Makefile
1.14+4-0net/avahi/patches/patch-avahi-daemon_main_c
1.5+0-0net/avahi/patches/patch-avahi-core_fdutil_c
+95-222 files not shown
+95-228 files

OpenBSD/ports kSPjvEAmultimedia/pipewire/wireplumber Makefile, multimedia/pipewire/wireplumber/patches patch-src_config_wireplumber_conf

   Install override config file where it belongs and don't use setpriority.
VersionDeltaFile
1.4+22-8multimedia/pipewire/wireplumber/patches/patch-src_config_wireplumber_conf
1.27+2-2multimedia/pipewire/wireplumber/Makefile
1.17+1-1multimedia/pipewire/wireplumber/pkg/PLIST
+25-113 files

OpenBSD/ports zFHrhtKmultimedia/pipewire/pipewire Makefile, multimedia/pipewire/pipewire/files 10-no-rtkit.conf

   Fix setpriority.
VersionDeltaFile
1.10+15-0multimedia/pipewire/pipewire/patches/patch-src_modules_module-rt_c
1.2+6-1multimedia/pipewire/pipewire/files/10-no-rtkit.conf
1.69+2-0multimedia/pipewire/pipewire/Makefile
+23-13 files

OpenBSD/src cQzMoaHregress/usr.sbin/vmd Makefile, regress/usr.sbin/vmd/agentx Makefile

   regress: vmd(8): add test for agentx snmpd binding

   OK bluhm@
VersionDeltaFile
1.1+92-0regress/usr.sbin/vmd/agentx/Makefile
1.4+2-2regress/usr.sbin/vmd/Makefile
+94-22 files

OpenBSD/src J2Qkq2fdistrib/miniroot install.sub

   On install images without timezone data, the set_timezone function
   returned before wait_cgiinfo was called. This meant the list of mirrors
   was downloaded, but never presented to the user.

   Call wait_cgiinfo in do_install directly (this more closely matches how
   do_upgrade does it).

   ok afresh1@
VersionDeltaFile
1.1292+4-2distrib/miniroot/install.sub
+4-21 files

OpenBSD/ports MtcH5l4security/acme.sh Makefile distinfo, security/acme.sh/pkg PLIST

   security/acme.sh: update to 3.1.5
VersionDeltaFile
1.7+13-1security/acme.sh/pkg/PLIST
1.7+2-2security/acme.sh/distinfo
1.8+1-1security/acme.sh/Makefile
+16-43 files

OpenBSD/src qiK4DWlsys/dev/usb if_urtw.c

   Ensure that urtw(4) always initializes ic->ic_bss->ni_chan.

   Patch by Matteo Bianchi
VersionDeltaFile
1.75+25-1sys/dev/usb/if_urtw.c
+25-11 files

OpenBSD/src keCtlpBsys/dev/pci if_iwx.c, sys/net80211 ieee80211_node.h ieee80211_node.c

   handle dynamic channel width changes correctly in iwx(4)

   Avoids fatal firmware error ADVANCED_SYSASSERT 0x20101A28, where the
   fw station on a PHY has a higher Tx rate scaling bandwidth than the PHY.
   Thanks to Johannes Berg for explaining the firmware error code to me.

   Problem reported and fix tested by Robert Palm.
VersionDeltaFile
1.230+54-35sys/dev/pci/if_iwx.c
1.217+27-1sys/net80211/ieee80211_node.c
1.103+3-1sys/net80211/ieee80211_node.h
+84-373 files

OpenBSD/ports oHPOkR0graphics/ffmpeg Makefile distinfo, graphics/ffmpeg/patches patch-libavcodec_mips_cabac_h

   graphics/ffmpeg: update to 9.0.2
VersionDeltaFile
1.346+2-2x11/mplayer/Makefile
1.76+2-2graphics/ffmpeg/distinfo
1.263+1-2graphics/ffmpeg/Makefile
1.2+0-0graphics/ffmpeg/patches/patch-libavcodec_mips_cabac_h
+5-64 files

OpenBSD/ports 3FNtFUXwww/webkitgtk4/patches patch-Source_WebKit_PlatformGTK_cmake

   Fix build race: WebKitDirectoryInputStreamData.h is generated by a custom
   command owned by the WebKitShared OBJECT sub-target, but included from a source
   compiled in the WebKitNetworkProcess sub-target, which has no dependency on it.

   tested by and ok tb@ who run into the race
VersionDeltaFile
1.1+16-0www/webkitgtk4/patches/patch-Source_WebKit_PlatformGTK_cmake
+16-01 files

OpenBSD/src 6ET3VCYlib/libc/gen execv.3

   Various content improvements for conciseness and precision,
   in part made possible because execvp(3) was split out.
   deraadt@ agreed with the direction.
VersionDeltaFile
1.6+41-46lib/libc/gen/execv.3
+41-461 files

OpenBSD/src 61pio6esys/sys proc.h

   Move include ptrace.h out of #ifdef _KERNEL

   Due to libkvm using this.

   Fixup for: Inline ps_ptstat pointee into struct process

   OK deraadt@
VersionDeltaFile
1.401+2-2sys/sys/proc.h
+2-21 files

OpenBSD/ports 3xKLgH3math/lean Makefile, math/lean/patches patch-src_util_lean_path_cpp patch-src_util_path_cpp

   Implement get_exe_location with getexecpath(3), functionally
   aequivalent with other OS' implementations, instead of previous
   hard-coded + SUBST_CMD workaround.

   ok tb@ (maintainer)
VersionDeltaFile
1.1+26-0math/lean/patches/patch-src_util_path_cpp
1.12+2-2math/lean/Makefile
1.3+0-0math/lean/patches/patch-src_util_lean_path_cpp
+28-23 files

OpenBSD/ports 0ZdwuGQgraphics/inkscape Makefile, graphics/inkscape/patches patch-src_path-prefix_cpp

   Use getexecpath(3) instead of getprogname(3) from previous workaround.
   This should now be functionally in line with the behaviour on other OS.
   ok rsadowski@ (maintainer)
VersionDeltaFile
1.4+10-8graphics/inkscape/patches/patch-src_path-prefix_cpp
1.131+1-1graphics/inkscape/Makefile
+11-92 files

OpenBSD/src Ggn6Pi6sys/kern kern_sysctl.c

   In sysctl KERN_PROC_ARGS "cnt" is an int, read directly from a userspace
   process. The while loop has a "cnt > 0" check, but on 32-bit platforms a value
   can overflow and result in the querying process having data written past the
   supplied buffer. Limit the number of elements in the array to ARG_MAX.

   ok deraadt@
VersionDeltaFile
1.497+12-1sys/kern/kern_sysctl.c
+12-11 files

OpenBSD/src QxwWvYEdistrib/miniroot install.sub

   the installer picks a partition from several options to stage the
   prefetched sets for upgrade/install.  Among the decisions it looks for
   at least 512M free.  However, today an amd64 snap is 792M.

   Bump the size we look for to 1024M free space.  Software has grown, we
   gotta grow with it.

   OK deraadt@
VersionDeltaFile
1.1291+4-4distrib/miniroot/install.sub
+4-41 files

OpenBSD/src nEUIoVvsys/arch/arm64/arm64 hibernate_asm.S hibernate_machdep.c, sys/arch/arm64/include hibernate_var.h

   Cleanup the arm64 hibernate code to fix some of the misunderstandings
   about how things are supposed to work.

   ok mlarkin@
VersionDeltaFile
1.3+91-113sys/arch/arm64/arm64/hibernate_machdep.c
1.2+33-26sys/arch/arm64/include/hibernate_var.h
1.2+21-11sys/arch/arm64/arm64/hibernate_asm.S
1.161+3-2sys/kern/subr_hibernate.c
+148-1524 files

OpenBSD/src JTpq6xbusr.sbin/rtrctl rtrctl.c rtrctl.8, usr.sbin/rtrd rtrd.c rtrd.8

   No need to document or explicitly implement -h, shorten the
   manual page and usage() accordingly; no functional change.
   Also delete an incorrect sentence that talked about "multiple -v",
   clarify where "rtrctl stats" output goes, and polish .Nm use
   in the SYNOPSIS.
   OK job@
VersionDeltaFile
1.3+4-9usr.sbin/rtrd/rtrd.8
1.4+4-7usr.sbin/rtrctl/rtrctl.8
1.5+2-3usr.sbin/rtrd/rtrd.c
1.5+2-3usr.sbin/rtrctl/rtrctl.c
+12-224 files

OpenBSD/src fVxUoNpregress/sys/arch/amd64/vmm vcpu.c, sys/arch/amd64/amd64 vmm_machdep.c

   Redesign vmm(4) to use files to manage vm ownership.

   Now when VMM_IOC_CREATE creates a new virtual machine, it provides
   the calling process a file descriptor to a file associated with the
   vm. Access to the vm via various ioctl(2) calls, like VMM_IOC_RUN
   and VMM_IOC_READREGS, now go through a file descriptor for that
   file. A process can fork/exec and keep the file descriptor open to
   allow inheritable access. (For now, we do not permit passing via
   sockets to disparate processes.)

   This solves a lot of lifecycle headaches, ties the lifetime of the
   vm to the userland processes using it, and removes the hacky use
   of pids and magic ids for controlling what a process with access
   to /dev/vmm can do to a vm.

   In vmd(8), the vmm process now takes sole responsibility for tracking
   vm's it has created and the kernel is no longer expected to provide
   this list back to vmd via the (now removed) VMM_IOC_INFO command.


    [10 lines not shown]
VersionDeltaFile
1.13+350-322sys/dev/vmm/vmm.c
1.143+51-109usr.sbin/vmd/vmm.c
1.10+37-85regress/sys/arch/amd64/vmm/vcpu.c
1.88+18-83sys/arch/amd64/amd64/vmm_machdep.c
1.135+35-42usr.sbin/vmd/vm.c
1.16+16-60sys/dev/vmm/vmm.h
+507-70130 files not shown
+740-90736 files

OpenBSD/src qfGTCnygnu/usr.bin/perl/cpan/podlators/lib/Pod Text.pm, gnu/usr.bin/perl/cpan/podlators/lib/Pod/Text Termcap.pm Color.pm

   Handle overly large margins that could exhaust memory and cpu

   This is CVE-2026-82560 for Pod::Text

   Upstream commit:
   https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f.patch
VersionDeltaFile
1.13+18-0gnu/usr.bin/perl/cpan/podlators/lib/Pod/Text.pm
1.9+11-1gnu/usr.bin/perl/cpan/podlators/lib/Pod/Text/Overstrike.pm
1.9+10-1gnu/usr.bin/perl/cpan/podlators/lib/Pod/Text/Termcap.pm
1.9+10-1gnu/usr.bin/perl/cpan/podlators/lib/Pod/Text/Color.pm
+49-34 files

OpenBSD/src X5OC9dlusr.sbin/rtrctl Makefile, usr.sbin/rtrd Makefile

   remove cc -W options not supported by all compilers
VersionDeltaFile
1.3+2-2usr.sbin/rtrd/Makefile
1.3+2-2usr.sbin/rtrctl/Makefile
+4-42 files

OpenBSD/src AdmIYeGdistrib/amd64/common install.md

   the check for efifb || ACPI >= 5 to decide if GPT booting is preferred
   is outdated and exposes consequences in new (-current) vmd which has
   ACPI >= 5 but no EFI / GPT support.  The right thing to do is check for
   efi0 driver attachment.  The tight floppy media lacks the efi0 driver,
   and will only do MBR for other reasons.
   issue discovered by phessler, ok mlarkin kettenis
VersionDeltaFile
1.67+3-4distrib/amd64/common/install.md
+3-41 files

OpenBSD/src 3o7yD8Dlib/libtls tls_verify.c tls_util.c

   libtls: insert empty line after #include <tls.h>

   requested by jsing
VersionDeltaFile
1.37+2-1lib/libtls/tls_verify.c
1.19+2-1lib/libtls/tls_util.c
1.17+2-1lib/libtls/tls_signer.c
1.55+2-1lib/libtls/tls_server.c
1.11+2-1lib/libtls/tls_peer.c
1.31+2-1lib/libtls/tls_ocsp.c
+12-66 files not shown
+24-1212 files

OpenBSD/src Hm1J3MAlib/libtls tls_util.c

   libtls: fix includes for tls_util.c

   discussed with jsing
VersionDeltaFile
1.18+2-2lib/libtls/tls_util.c
+2-21 files

OpenBSD/src 4iMdnE8lib/libtls tls_signer.c

   libtls: fix includes for tls_signer.c

   discussed with jsing
VersionDeltaFile
1.16+2-3lib/libtls/tls_signer.c
+2-31 files