Reattempt the upgrade to gnupg-2.5.24
Upstream published a fix for regression that broke mail/notmuch
configure. Updating now means smaller steps if we need an update for
a security issue in the next 8.0 OpenBSD release. ok sthen@ naddy@
sys/qwz: preserve decoded radiotap frequency
Management RX parameters already contain a hostorder chanel
frequency. Avoid decoding it again before writing the little endian
radiotap field.
OK: stsp@
sys/qwz: report radiotap channels and rates
Based on sys/dev/ic/qwx.c,v 1.93 and sys/dev/ic/qwxvar.h,v 1.31
Populate radiotap channel and rate fields with WCN7850 RX rate decoding.
Use QWZ presence masks and omit unavailable timestamps, noise and
signal strength for data frames.
Correct 54 Mb/s encoding from 104 to 108 in 500 kb/s.
OK: stsp@
sys/qwz: drain REO RX exceptions
Based on sys/dev/ic/qwx.c,v 1.33
Drain REO RX exceptions using descriptor layouts and qwz cookie.
Reclaim packet buffers, return link descriptors and replenish RX,
checking bank bounds and release ring space.
OK: stsp@
sys/qwz: handle WBM RX errors
Based on sys/dev/ic/qwx.c,v 1.35 and sys/dev/ic/qwxvar.h,v 1.18 ,
sys/dev/ic/qwx.c,v 1.89 , sys/dev/ic/qwx.c,v 1.121 and sys/dev/ic/qwxvar.h,v 1.36
Process WBM RX releases using WCN7850 descriptor and cookie formats.
Deliver valid null queue frames through existing RX processing, clear
mbuf pointers after delivery, and then replenish descriptors
OK: stsp@
sys/qwz: report hardware RX aggregation
Based on sys/dev/ic/qwx.c,v 1.85 and sys/dev/ic/qwx.c,v 1.90
Report hardware deaggregation and reordering after successful RX
reconstruction; allow repaeted sequence numbers for later A-MSDU
subframes and clear the AMSDU QoS bit.
OK: stsp@
start process of deprecating the -R flag. This was the old way of
performing a remote-to-remote copy that was basically executed scp on
the remote host. It barely worked (needing agent forwarding enabled or
usable credentials on the remote host) and has largely been replaced
by a better SFTP-protocol remote-to-remote copy that runs through the
host performing the copy.
We'll disable this option in a release or two; ok dtucker@
Implement a maximum number of KDF rounds that will be accepted when
writing an OpenSSH-format private key or when loading one. This limit
is set pretty high (1<<20), but ensures that a service that is passed a
bad key with an ridiculously high number of rounds will _eventually_
complete parsing it.
Also bump the default number of KDF rounds from 24 to 32 (this is a
linear increase, not like bcrypt(3) which is exponential).
Pointed out by Aris Adamantiadis
cherrypick fix for CPython CVE-2026-19445: Use-after-free of a
server-side SSLContext when sni_callback switches contexts. ok tb kmos
A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callback assigns a different context
to SSLSocket.context (the documented way to select a certificate per
server name) and nothing else keeps the original ssl.SSLContext alive.
Typical cases are servers that create an SSLContext per connection or
replace it while connections are open.
fix the bit length of ML-DSA 44/Ed25519 keys that was being
incorrectly reported as 256. The private key length for these
composite keys is 512 bits. This value is only used for display.
Spotted by Yiyue Wang
sftp: be stricter in accepting paths returned by the server for
SSH_FXP_REALPATH or SSH2_FXP_READDIR replies, as these can be
used in some situations to decide the destination path for recursive
transfers.
Report and patch from Junghoon Cho
handle max-pk-ok path identically when the incoming user is invalid;
avoids max-pk-ok feature presenting a username validity oracle
analysis and patch from Chris Rohlf in collaboration with Claude and
Anthropic Research
update net/libtorrent 0.16.24
- major bump due to removed symbols
- unbreaks tests by linking using static archive (from tj@)
approved by sthen@ and tested by and OK tj@
update net/rtorrent 0.16.24
- various security fixes (e.g., overflow, heap overflow and use-after-free)
- regen test/Makefile.in patch to remove a new, third instance of -ldl
approved by sthen@ and tested by and OK tj@
sys/qwz: avoid peer access after key waits
Do not retain a pointer into peer cipher state across key installation.
Installation can sleep while the peer is removed; dropping the failure
rollback avoids accessing freed peer memory.
OK: stsp@
sys/qwz: handle scan events during cancellation
Ignore late scan started events while cancellation is pending;
finish an aborting scan when firmware reports that startup failed.
OK: stsp@
sys/qwz: stop firmware scans on interface down
Based on sys/dev/ic/qwx.c,v 1.72
Abort firmware scans during interface stop, including scans still
starting; taer down started vdevs and remaining peers even when net80211
has not reached AUTH.
OK: stsp@