OpenBSD/src hdBBbzy — usr.sbin/rpki-client output-rtrx.c

   correct include order
VersionDeltaFile
1.3+2-2usr.sbin/rpki-client/output-rtrx.c
+2-21 files

OpenBSD/src znFsEwI — usr.sbin/rpki-client output-rtrx.c

   use __packed; ok rcovelli
VersionDeltaFile
1.2+11-13usr.sbin/rpki-client/output-rtrx.c
+11-131 files

OpenBSD/src Mf8hmAy — usr.sbin/rpki-client Makefile extern.h

   Add option -r to output tables directly to the rtrd(8) controller socket.
   OK deraadt@
VersionDeltaFile
1.1+541-0usr.sbin/rpki-client/output-rtrx.c
1.314+11-4usr.sbin/rpki-client/main.c
1.48+12-1usr.sbin/rpki-client/output.c
1.144+7-3usr.sbin/rpki-client/rpki-client.8
1.300+7-1usr.sbin/rpki-client/extern.h
1.42+2-1usr.sbin/rpki-client/Makefile
+580-106 files

OpenBSD/ports TcDrRW9 — games/devilutionx Makefile, games/devilutionx/patches patch-Source_dvlnet_tcp_server_cpp

   missed cvs add to go with devilutiomx/Makefile r1.21, unbreaking
   newer asio. from Brad.
VersionDeltaFile
1.1+15-0games/devilutionx/patches/patch-Source_dvlnet_tcp_server_cpp
1.23+1-1games/devilutionx/Makefile
+16-12 files

OpenBSD/ports rtreQij — textproc/groff Makefile, textproc/groff/patches patch-contrib_mm_mmroff_pl patch-src_preproc_html_pre-html_cpp

   Backport three security fixes from the groff-1.24.2 release.
   OK naddy@ on a previous, minimally different version of this patch.

   From the groff-1.24.2 release announcement (September 28, 2026):
   "This release corrects command injection security vulnerabilities
   (CWE-78) in the mmroff, pdfmom, and pre-grohtml programs.  The last of
   these is a preprocessor that is run when groff or troff is run with the
   -T html or -T xhtml options.  The vulnerabilities are variously
   14-26 years old.  Malicious input can escape groff's default "safer"
   mode, running commands embedded in that input at the user's privilege
   level.  The groff development team recommends this release to any users
   who employ the named tools or GNU troff output formats with untrusted
   inputs.
   Man page rendering is not vulnerable unless rendering (X)HTML."
VersionDeltaFile
1.1+82-0textproc/groff/patches/patch-src_devices_gropdf_pdfmom_pl
1.3+35-12textproc/groff/patches/patch-src_roff_troff_input_cpp
1.1+39-0textproc/groff/patches/patch-src_preproc_html_pre-html_cpp
1.1+24-0textproc/groff/patches/patch-contrib_mm_mmroff_pl
1.53+1-1textproc/groff/Makefile
+181-135 files

OpenBSD/ports ZIx0pWO — mail/postfix/stable Makefile, security/sslscan Makefile

   bump ports with static links against security/openssl/3.5 in -stable
VersionDeltaFile
1.56.2.3+1-1sysutils/borgbackup/2.0/Makefile
1.86.2.3+1-1security/sslscan/Makefile
1.281.2.8+1-0mail/postfix/stable/Makefile
+3-23 files

OpenBSD/ports mJSFADA — security/openssl/3.5 Makefile distinfo, security/openssl/3.5/pkg PLIST

   MFC: Update to OpenSSL 3.5.9

   https://github.com/openssl/openssl/releases/tag/openssl-3.5.9
VersionDeltaFile
1.7.2.3+2-2security/openssl/3.5/distinfo
1.16.2.3+1-1security/openssl/3.5/Makefile
1.7.2.3+2-0security/openssl/3.5/pkg/PLIST
+5-33 files

OpenBSD/ports Pd8bpzp — mail/postfix/stable Makefile, security/sslscan Makefile

   bump ports with static link against security/openssl/3.5
VersionDeltaFile
1.64+2-0sysutils/borgbackup/2.0/Makefile
1.90+1-0security/sslscan/Makefile
1.289+1-0mail/postfix/stable/Makefile
+4-03 files

OpenBSD/ports Qu9OKte — security/openssl/3.5 Makefile distinfo, security/openssl/3.5/pkg PLIST

   Update to OpenSSL 3.5.9, ok naddy

   https://github.com/openssl/openssl/releases/tag/openssl-3.5.9
VersionDeltaFile
1.10+2-2security/openssl/3.5/distinfo
1.19+1-1security/openssl/3.5/Makefile
1.10+2-0security/openssl/3.5/pkg/PLIST
+5-33 files

OpenBSD/ports f8r12LY — security/openssl/4.0 Makefile distinfo, security/openssl/4.0/pkg PLIST

   Update to openssl 4.0.3, ok naddy

   https://github.com/openssl/openssl/releases/tag/openssl-4.0.3
VersionDeltaFile
1.5+2-2security/openssl/4.0/distinfo
1.8+1-1security/openssl/4.0/Makefile
1.5+2-0security/openssl/4.0/pkg/PLIST
+5-33 files

OpenBSD/src AMEral4 — lib/libcrypto/x509 x509_crld.c

   set_dist_point_name(): tiny tweak to restore previous behavior

   Allocate fnm before allocating *pdp. This way a second call to to
   set_dist_point_name() has a tiny little chance of succeeding.

   ok beck ("I strongly suspect this will never matter anywhere.")
VersionDeltaFile
1.13+4-4lib/libcrypto/x509/x509_crld.c
+4-41 files

OpenBSD/src th8490E — lib/libcrypto/man x509v3.cnf.5, lib/libcrypto/x509 x509_purp.c x509_crld.c

   libcrypto: remove support for nameRelativeToCRLIssuer

   Drop support for nameRelativeToCRLIssuer from the CRL Distribution Point
   extension. Per RFC 5280, 4.2.1.13, conforming CAs SHOULD not use it, which
   is sound advice since this garbage was eating memory for breakfast before
   signature thanks to the wonderful gem that is the extension cache.

   One has to wonder why this was needed in libcrypto... This isn't worth
   fixing so off to the bit bucket it goes.

   from tb, ok beck jsing

   libssl: Avoid potential overread on interrupted retransmission in DTLS

   from OpenSSL via jsing

   this is errata/7.8/060_libressl.patch.sig
VersionDeltaFile
1.10.2.1+14-76lib/libcrypto/x509/x509_crld.c
1.44.2.1+1-17lib/libcrypto/x509/x509_purp.c
1.8.14.1+2-7lib/libcrypto/man/x509v3.cnf.5
1.85.2.2+2-1lib/libssl/d1_both.c
+19-1014 files

OpenBSD/src h9H2JBQ — usr.bin/tmux format.c

   Add NULL checks for clients that may not have identified yet, GitHub
   issue 5663.
VersionDeltaFile
1.424+4-4usr.bin/tmux/format.c
+4-41 files

OpenBSD/src xrz726N — lib/libcrypto/man x509v3.cnf.5, lib/libcrypto/x509 x509_purp.c x509_crld.c

   libcrypto: remove support for nameRelativeToCRLIssuer

   Drop support for nameRelativeToCRLIssuer from the CRL Distribution Point
   extension. Per RFC 5280, 4.2.1.13, conforming CAs SHOULD not use it, which
   is sound advice since this garbage was eating memory for breakfast before
   signature thanks to the wonderful gem that is the extension cache.

   One has to wonder why this was needed in libcrypto... This isn't worth
   fixing so off to the bit bucket it goes.

   from tb, ok beck jsing

   libssl: Avoid potential overread on interrupted retransmission in DTLS

   from OpenSSL via jsing

   this is errata/7.9/024_libressl.patch.sig
VersionDeltaFile
1.11.2.1+14-76lib/libcrypto/x509/x509_crld.c
1.44.4.1+1-17lib/libcrypto/x509/x509_purp.c
1.8.18.1+2-7lib/libcrypto/man/x509v3.cnf.5
1.85.6.2+2-1lib/libssl/d1_both.c
+19-1014 files

OpenBSD/ports Y4x5oOe — net/haproxy Makefile distinfo

   MFC: net/haproxy: update to 3.2.25

   Changes:
   https://www.haproxy.org/download/3.2/src/CHANGELOG

   from Mark Patruck
   ok sthen
VersionDeltaFile
1.93.2.6+2-2net/haproxy/distinfo
1.134.2.6+1-1net/haproxy/Makefile
+3-32 files

OpenBSD/ports Bt27Miq — net/haproxy Makefile distinfo

   net/haproxy: update to 3.2.25

   Changes:
   https://www.haproxy.org/download/3.2/src/CHANGELOG

   from Mark Patruck
   ok sthen
VersionDeltaFile
1.100+2-2net/haproxy/distinfo
1.141+1-1net/haproxy/Makefile
+3-32 files

OpenBSD/src 7xrpfsI — lib/libcrypto/man x509v3.cnf.5, lib/libcrypto/x509 x509_purp.c x509_crld.c

   libcrypto: remove support for nameRelativeToCRLIssuer

   Drop support for nameRelativeToCRLIssuer from the CRL Distribution Point
   extension. Per RFC 5280, 4.2.1.13, conforming CAs SHOULD not use it, which
   is sound advice since this garbage was eating memory for breakfast before
   signature thanks to the wonderful gem that is the extension cache.

   One has to wonder why this was needed in libcrypto... This isn't worth
   fixing, so off to the bit bucket it goes.

   ok beck jsing
VersionDeltaFile
1.12+14-76lib/libcrypto/x509/x509_crld.c
1.47+1-17lib/libcrypto/x509/x509_purp.c
1.9+2-7lib/libcrypto/man/x509v3.cnf.5
+17-1003 files

OpenBSD/src Fvzp3vz — usr.bin/tmux format.c

   Do not format times that localtime_r and ctime_r cannot convert, from
   Alexandre Fiori.
VersionDeltaFile
1.423+7-5usr.bin/tmux/format.c
+7-51 files

OpenBSD/ports QD7Ipiv — www/mozilla-firefox distinfo, www/mozilla-firefox/patches patch-security_nss_lib_nss_nss_h patch-third_party_rust_nss-rs__cargo-checksum_json

   www/mozilla-firefox: MFC update to 157.0.

   see https://www.firefox.com/en-US/firefox/157.0/releasenotes/
   fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-97/
VersionDeltaFile
1.1.4.1+18-0www/mozilla-firefox/patches/patch-netwerk_socket_neqo_glue_src_lib_rs
1.1.2.1+16-0www/mozilla-firefox/patches/patch-security_manager_ssl_EnabledSignatureSchemes_h
1.1.2.1+15-0www/mozilla-firefox/patches/patch-third_party_rust_nss-rs_src_constants_rs
1.1.2.1+9-0www/mozilla-firefox/patches/patch-third_party_rust_nss-rs__cargo-checksum_json
1.1.6.7+2-2www/mozilla-firefox/patches/patch-security_nss_lib_nss_nss_h
1.397.2.22+2-2www/mozilla-firefox/distinfo
+62-47 files not shown
+66-813 files

OpenBSD/ports UqS89bh — www/firefox-esr Makefile distinfo

   www/firefox-esr: update to 140.17.0.

   see https://www.firefox.com/en-US/firefox/140.17.0/releasenotes/
   fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-99/

   last planned release in esr140 branch
VersionDeltaFile
1.180.2.8+4-4www/firefox-esr/distinfo
1.270.2.8+2-2www/firefox-esr/Makefile
+6-62 files

OpenBSD/ports FQIyF51 — www/firefox-esr Makefile distinfo, www/firefox-esr-i18n Makefile.inc distinfo

   www/firefox-esr: update to 153.4.0.

   see https://www.firefox.com/en-US/firefox/153.4.0/releasenotes/
   fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-100/

   ok naddy@
VersionDeltaFile
1.185+162-162www/firefox-esr-i18n/distinfo
1.190+4-4www/firefox-esr/distinfo
1.282+2-3www/firefox-esr/Makefile
1.197+1-1www/firefox-esr-i18n/Makefile.inc
+169-1704 files

OpenBSD/ports QcMMlzW — www/firefox-i18n Makefile.inc distinfo, www/mozilla-firefox distinfo Makefile

   www/mozilla-firefox: update to 157.0.

   see https://www.firefox.com/en-US/firefox/157.0/releasenotes/
   fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-97/

   bump REVISION to be ahead of 7.9-stable

   ok naddy@
VersionDeltaFile
1.409+164-164www/firefox-i18n/distinfo
1.423+4-4www/mozilla-firefox/distinfo
1.712+4-4www/mozilla-firefox/Makefile
1.364+1-1www/firefox-i18n/Makefile.inc
+173-1734 files

OpenBSD/src akz0Dly — usr.bin/tmux format.c

   Add a maximum repeat size as well as count.
VersionDeltaFile
1.422+6-3usr.bin/tmux/format.c
+6-31 files

OpenBSD/src Vzw3izS — sys/dev/ic qwz.c

   sys/qwz: reclaim incomplete RX batches

   Process and replenish reaped buffers even when the batch contains no
   complete MSDU. Error only and incomplete bacthes must not leave buffers
   or descriptors on temporary lists.

   OK: stsp@
VersionDeltaFile
1.56+1-5sys/dev/ic/qwz.c
+1-51 files

OpenBSD/src so3WdBF — sys/dev/ic qwz.c

   sys/qwz: check RX slots before allocating

   Backport of sys/dev/ic/qwx.c,v 1.117

   OK: stsp@
VersionDeltaFile
1.55+5-5sys/dev/ic/qwz.c
+5-51 files

OpenBSD/src 3TlFWRn — sys/dev/ic qwz.c

   sys/qwz: retain unused RX descriptors

   Draw RX descriptors from the free list only when the caller supplies
   none. Return unused descriptors on every refill exit, including
   allocation failures and a full ring. This fixes qwz-specific ownership.

   OK: stsp@
VersionDeltaFile
1.54+18-23sys/dev/ic/qwz.c
+18-231 files

OpenBSD/src 2RZNj49 — sys/dev/pci if_qwz_pci.c

   sys/qwz: stop MHI on full power-down

   Backport of sys/dev/pci/if_qwx_pci.c,v 1.39

   OK: stsp@
VersionDeltaFile
1.16+127-32sys/dev/pci/if_qwz_pci.c
+127-321 files

OpenBSD/src lTz42j4 — sys/dev/pci if_qwz_pci.c

   sys/qwz: reset MHI ring accounting

   Backport of sys/dev/pci/if_qwx_pci.c,v 1.34 and sys/dev/pci/if_qwx_pci.c,v 1.38

   OK: stsp@
VersionDeltaFile
1.15+3-1sys/dev/pci/if_qwz_pci.c
+3-11 files

OpenBSD/src phih5np — sys/dev/pci if_qwz_pci.c

   sys/qwz: reuse RDDM buffers

   Based on sys/dev/pci/if_qwx_pci.c,v 1.31

   Reuse the RDDM data and vector buffers on repeated MHI starts to avoid
   leaking their allocations. Reprogram the BHIE RX vector after startup
   clears its registers; returning early would leave them unset.

   OK: stsp@
VersionDeltaFile
1.14+17-13sys/dev/pci/if_qwz_pci.c
+17-131 files

OpenBSD/src cJB7tZH — sys/dev/ic qwz.c

   sys/qwz: reject invalid firmware peer IDs

   Reject invalid peer IDs so an unassociated node cannot match a
   pending firmware peer. Peer-map events resolve pending peers by
   address.

   OK: stsp@
VersionDeltaFile
1.53+4-1sys/dev/ic/qwz.c
+4-11 files