OpenBSD/ports xfEehqetextproc/xml2rfc Makefile distinfo

   update to xml2rfc-3.34.1
VersionDeltaFile
1.24+2-2textproc/xml2rfc/distinfo
1.65+2-1textproc/xml2rfc/Makefile
+4-32 files

OpenBSD/ports oNNTQvFconverters/html2text distinfo Makefile, converters/html2text/patches patch-html2text_cpp

   update html2text to git head, including fixes for various leaks, overflows
   and out-of-bounds accesses which didn't make it into a release yet. ok tb
VersionDeltaFile
1.26+9-8converters/html2text/Makefile
1.2+5-5converters/html2text/patches/patch-html2text_cpp
1.5+2-2converters/html2text/distinfo
+16-153 files

OpenBSD/ports WiG0J5alang/gnucobol Makefile, lang/gnucobol/patches patch-configure

   use the bundled texinfo files, don't regenerate. (fails with newer texinfo)
VersionDeltaFile
1.15+16-5lang/gnucobol/Makefile
1.4+0-0lang/gnucobol/patches/patch-configure
+16-52 files

OpenBSD/ports qCK8g8Vx11/qt6/qtbase Makefile, x11/qt6/qtbase/patches patch-src_corelib_kernel_qcoreapplication_cpp

   x11/qt6/qtbase: getexecpath(3)

   Use getexecpath(3) for qAppFileName()

   Tweak and OK tb@
VersionDeltaFile
1.1+18-0x11/qt6/qtbase/patches/patch-src_corelib_kernel_qcoreapplication_cpp
1.56+1-0x11/qt6/qtbase/Makefile
+19-02 files

OpenBSD/ports kqrm0zFtelephony/py-phonenumbers distinfo Makefile

   update to py3-phonenumbers-9.0.39
VersionDeltaFile
1.47+13-13telephony/py-phonenumbers/Makefile
1.33+2-2telephony/py-phonenumbers/distinfo
+15-152 files

OpenBSD/ports b6MbFMnx11/oxygen-icons distinfo, x11/oxygen-icons/pkg PLIST

   Update oxygen-icons on 6.30.0
VersionDeltaFile
1.5+33-3x11/oxygen-icons/pkg/PLIST
1.5+2-2x11/oxygen-icons/distinfo
+35-52 files

OpenBSD/ports vFasu6zsecurity/openssl-ruby-tests distinfo Makefile, security/openssl-ruby-tests/pkg PLIST

   Update to openssl-ruby-tests 20260908
VersionDeltaFile
1.148+2-2security/openssl-ruby-tests/distinfo
1.169+2-2security/openssl-ruby-tests/Makefile
1.19+1-0security/openssl-ruby-tests/pkg/PLIST
+5-43 files

OpenBSD/ports mTYjWN6sysutils/py-command_runner Makefile distinfo

   update to py3-command_runner-1.7.6
VersionDeltaFile
1.4+2-2sysutils/py-command_runner/distinfo
1.9+1-1sysutils/py-command_runner/Makefile
+3-32 files

OpenBSD/ports hhGtP9vdevel/kf6/breeze-icons/pkg PLIST, devel/kf6/kcalendarcore/pkg PLIST

   Update KDE Frameworks to 6.30.0
VersionDeltaFile
1.12+0-52devel/kf6/purpose/pkg/PLIST
1.26+32-0devel/kf6/breeze-icons/pkg/PLIST
1.7+18-0devel/kf6/kcalendarcore/pkg/PLIST
1.31+2-2devel/kf6/kio/distinfo
1.20+2-2devel/kf6/kio/Makefile
1.28+2-2devel/kf6/kimageformats/distinfo
+56-5879 files not shown
+208-20285 files

OpenBSD/ports tppoPOmdevel/py-wrapt distinfo Makefile, devel/py-wrapt/pkg PLIST

   update to py3-wrapt-2.4.1
VersionDeltaFile
1.13+14-2devel/py-wrapt/pkg/PLIST
1.31+1-4devel/py-wrapt/Makefile
1.13+2-2devel/py-wrapt/distinfo
+17-83 files

OpenBSD/src NuD1iDhusr.bin/tmux layout.c

   Rather than allowing floating panes to remain outside the window and
   invisible after resize, move them and resize them so they are fully
   inside the window. GitHub issue 5582 from Noam Stolero.
VersionDeltaFile
1.100+49-2usr.bin/tmux/layout.c
+49-21 files

OpenBSD/ports hFc36CJdevel/py-build Makefile distinfo

   update to py3-build-1.6.1
VersionDeltaFile
1.15+2-2devel/py-build/distinfo
1.20+1-1devel/py-build/Makefile
+3-32 files

OpenBSD/ports By5QzNedevel/pcre2 distinfo Makefile, devel/pcre2/pkg PLIST

   update to pcre2-10.48
VersionDeltaFile
1.21.6.1+8-6devel/pcre2/Makefile
1.7.6.1+7-2devel/pcre2/pkg/PLIST
1.10.6.1+2-2devel/pcre2/distinfo
+17-103 files

OpenBSD/ports OLbnEEudevel/pcre2 distinfo Makefile, devel/pcre2/pkg PLIST

   update to pcre2-10.48, tweak/ok namn@

   various security-related fixes,
   https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48
VersionDeltaFile
1.23+5-5devel/pcre2/Makefile
1.12+2-2devel/pcre2/distinfo
1.9+1-0devel/pcre2/pkg/PLIST
+8-73 files

OpenBSD/ports N6sK1xccad/yosys distinfo Makefile, cad/yosys/patches patch-cmake_FindBISON_cmake

   update cad/yosys to 0.67

   from new MAINTAINER

   feedback by sthen@
   lightly tested and OK sebastia
VersionDeltaFile
1.8+213-82cad/yosys/pkg/PLIST
1.19+24-60cad/yosys/Makefile
1.1+21-0cad/yosys/pkg/README
1.5+14-2cad/yosys/distinfo
1.2+3-12cad/yosys/pkg/DESCR
1.1+12-0cad/yosys/patches/patch-cmake_FindBISON_cmake
+287-1564 files not shown
+299-15610 files

OpenBSD/ports Sj6M008x11/gtk+4 distinfo Makefile, x11/gtk+4/patches patch-gtk_gtkplacessidebar_c

   Update to gtk+4-4.22.5.
VersionDeltaFile
1.13+4-4x11/gtk+4/patches/patch-gtk_gtkplacessidebar_c
1.128+2-4x11/gtk+4/Makefile
1.71+2-2x11/gtk+4/distinfo
+8-103 files

OpenBSD/src oxrbnxfusr.sbin/rpki-client cms.c

   rpki-client: change return 0 to goto out

   This turns cms_parse_validate() into a single exit function and fixes
   a return 0 that should have been return NULL since the last commit.
VersionDeltaFile
1.69+2-2usr.sbin/rpki-client/cms.c
+2-21 files

OpenBSD/ports mElKCBpnet/samba Makefile distinfo

   Update to samba-4.24.7

   Changes: https://www.samba.org/samba/history/samba-4.24.7.html

   Tested and OK Ian McWilliam <kaosagnt AT gmail DOT com> (co-maintainer)
VersionDeltaFile
1.144+2-2net/samba/distinfo
1.380+1-1net/samba/Makefile
+3-32 files

OpenBSD/ports 7HuoxZrnet/samba Makefile distinfo

   Update to samba-4.24.7

   Changes: https://www.samba.org/samba/history/samba-4.24.7.html

   Tested and OK Ian McWilliam <kaosagnt AT gmail DOT com> (co-maintainer)
VersionDeltaFile
1.138.2.6+2-2net/samba/distinfo
1.372.2.6+1-1net/samba/Makefile
+3-32 files

OpenBSD/src NJjQBEisys/dev/pci/drm drm_prime.c, sys/dev/pci/drm/include/linux scatterlist.h

   unstub drm_prime_get_contiguous_size()

   called by xe, not currently used
VersionDeltaFile
1.12+4-1sys/dev/pci/drm/include/linux/scatterlist.h
1.14+0-4sys/dev/pci/drm/drm_prime.c
+4-52 files

OpenBSD/src V4lFtvgsys/dev/pci/drm drm_drv.c drm_linux.c, sys/dev/pci/drm/include/drm drm_device.h

   correct dma_tag_lookup() loop

   drm_cd.cd_ndevs[] has pointers to drm_softc not drm_device

   Currently, dma_tag_lookup() is only used by the apldcp/apldrm drivers.
   At the start of the softc for both of those is struct platform_device.
   If the loop doesn't match the the function argument is cast to
   struct platform_device *, so the problem was not noticed.

   discussed with kettenis@ and apldcp/apldrm tested on m1 mac mini
VersionDeltaFile
1.146+5-5sys/dev/pci/drm/drm_linux.c
1.207+0-6sys/dev/pci/drm/drm_drv.c
1.13+6-0sys/dev/pci/drm/include/drm/drm_device.h
+11-113 files

OpenBSD/ports 6sA9Ef2www/qobuz-dl Makefile distinfo

   www/qobuz-dl: update to 2.3.9
VersionDeltaFile
1.7+2-2www/qobuz-dl/distinfo
1.9+1-1www/qobuz-dl/Makefile
+3-32 files

OpenBSD/ports O4evjXLgames/flightgear Makefile.inc

   games/flightgear: mark as broken, undeclared identifier 'strtod_l'

   Packaging the data files is pointless without the simulator,
   so disable both.
VersionDeltaFile
1.13+2-0games/flightgear/Makefile.inc
+2-01 files

OpenBSD/src OapiK6wsys/nfs nfs_subs.c

   only allow an NFS server to set file type on a new vnode

   Otherwise, a malicous server could aid a local user in avoiding access
   controls.

   This reverts nfs_subs.c rev 1.3.  Which was part of a commit to fix the
   use of automount with direct maps.

   reported by Andrew Griffiths
   from jsg@

   this is errata/7.9/016_nfs.patch.sig
VersionDeltaFile
1.151.10.2+2-2sys/nfs/nfs_subs.c
+2-21 files

OpenBSD/src T49Kj4ksys/nfs nfs_subs.c

   only allow an NFS server to set file type on a new vnode

   Otherwise, a malicous server could aid a local user in avoiding access
   controls.

   This reverts nfs_subs.c rev 1.3.  Which was part of a commit to fix the
   use of automount with direct maps.

   reported by Andrew Griffiths
   from jsg@

   this is errata/7.8/052_nfs.patch.sig
VersionDeltaFile
1.151.4.2+2-2sys/nfs/nfs_subs.c
+2-21 files

OpenBSD/src 9ybGWAZsys/dev/wscons wsemul_vt100var.h wsemul_sun.c

   Clamp numeric arguments of terminal escape sequences to an arbitrary value of
   100,000. The existing logic would happily process as many digits as provided,
   which could make the values wraparound at 2**32, or be considered as negative
   values if cast to a signed type, leading to incorrect processing.

   Bug report by Acts1631.
   from miod@

   this is errata/7.9/017_wscons.patch.sig
VersionDeltaFile
1.48.6.1+28-6sys/dev/wscons/wsemul_vt100.c
1.37.12.1+17-4sys/dev/wscons/wsemul_sun.c
1.14.6.1+4-2sys/dev/wscons/wsemul_vt100var.h
+49-123 files

OpenBSD/src pw88066sys/dev/wscons wsemul_vt100var.h wsemul_sun.c

   Clamp numeric arguments of terminal escape sequences to an arbitrary value of
   100,000. The existing logic would happily process as many digits as provided,
   which could make the values wraparound at 2**32, or be considered as negative
   values if cast to a signed type, leading to incorrect processing.

   Bug report by Acts1631.
   from miod@

   this is errata/7.8/053_wscons.patch.sig
VersionDeltaFile
1.48.2.1+28-6sys/dev/wscons/wsemul_vt100.c
1.37.8.1+17-4sys/dev/wscons/wsemul_sun.c
1.14.2.1+4-2sys/dev/wscons/wsemul_vt100var.h
+49-123 files

OpenBSD/src jqMiVuWsys/uvm uvm_aobj.c

   sys/uvm: validate anonymous object pager requests

   uao_get() trusts the requested page range before allocating pages and
   looking up swap slots; an invalid request can therefore allocate a page
   outside the object and read beyond its swap slot array. Validate the
   request before page lookup or allocation, preserving optional fault
   clustering at the object boundary.

   Reject nonpositive page counts and starting page indices outside the
   object; require the entire range for PGO_ALLPAGES, or a centeridx within
   both the request and the object otherwise. Compare against the remaining
   page count in voff_t and derive pageidx from the validated firstpage,
   avoiding overflow in the bounds check and unchecked narrowing.

   Reported by Andrew Griffiths, thanks!
   from kirill@; OK kettenis@

   this is errata/7.9/018_shmat.patch.sig
VersionDeltaFile
1.122.2.1+36-3sys/uvm/uvm_aobj.c
+36-31 files

OpenBSD/src 7RgTghDsys/uvm uvm_aobj.c

   sys/uvm: validate anonymous object pager requests

   uao_get() trusts the requested page range before allocating pages and
   looking up swap slots; an invalid request can therefore allocate a page
   outside the object and read beyond its swap slot array. Validate the
   request before page lookup or allocation, preserving optional fault
   clustering at the object boundary.

   Reject nonpositive page counts and starting page indices outside the
   object; require the entire range for PGO_ALLPAGES, or a centeridx within
   both the request and the object otherwise. Compare against the remaining
   page count in voff_t and derive pageidx from the validated firstpage,
   avoiding overflow in the bounds check and unchecked narrowing.

   Reported by Andrew Griffiths, thanks!
   from kirill@; OK kettenis@

   this is errata/7.8/054_shmat.patch.sig
VersionDeltaFile
1.116.2.1+36-3sys/uvm/uvm_aobj.c
+36-31 files

OpenBSD/src tDu871Ysbin/fsck_ffs fsck.h extern.h

   use mode_t and symbolic settings; ok millert
VersionDeltaFile
1.36+4-3sbin/fsck_ffs/dir.c
1.36+2-2sbin/fsck_ffs/fsck.h
1.15+2-2sbin/fsck_ffs/extern.h
+8-73 files