Backport three security fixes from the groff-1.24.2 release.
OK naddy@ on a previous, minimally different version of this patch.
From the groff-1.24.2 release announcement (September 28, 2026):
"This release corrects command injection security vulnerabilities
(CWE-78) in the mmroff, pdfmom, and pre-grohtml programs. The last of
these is a preprocessor that is run when groff or troff is run with the
-T html or -T xhtml options. The vulnerabilities are variously
14-26 years old. Malicious input can escape groff's default "safer"
mode, running commands embedded in that input at the user's privilege
level. The groff development team recommends this release to any users
who employ the named tools or GNU troff output formats with untrusted
inputs.
Man page rendering is not vulnerable unless rendering (X)HTML."
databases/pgbouncer: security update to 1.26.0
see https://www.pgbouncer.org/2026/09/pgbouncer-1-26-0, fixes:
* CVE-2026-19888: DoS due to crash, triggerable by unauthenticated
clients. Caused by a SCRAM client-final-message without a nonce.
* CVE-2026-6668: DoS due to infinite loop, triggerable by unauthenticated
clients. Caused by an integer overflow in the packet buffer growth
logic.
* CVE-2026-6669: DoS due to unbounded work during login, triggerable by a
malicious PostgreSQL server. Caused by an unbounded SCRAM iteration
count.
ok naddy@
qt5/qtbase ports changes, ok rsadowski naddy
- add getexecpath support to qt5/qtbase
- fix builds with ccache; the way this was handled in qtbase could be
simplified as it's already done by ports infrastructure, and the way
it was done here previously isn't compatible with recent bsd.port.mk
changes
lang/ghc: use getexecpath(3) for executablePath on OpenBSD
getexecpath(3) is new in OpenBSD 8.0. Without it ghc-internal falls through
to the argv[0] fallback and System.Environment.executablePath is Nothing.
Also let ghc-boot use base's executablePath, choosing at run time so the port
still builds with a bootstrap compiler whose base predates getexecpath(3),
and mark openbsd as query-capable in the executablePath test.
Bump REVISION for the getexecpath change
System.Environment.executablePath goes from Nothing to a working query, and
getExecutablePath from argv[0] to a canonicalized absolute path, so the
package behaves differently and needs to be distinguishable.
OK kili@