OpenBSD/ports rtreQij — textproc/groff Makefile, textproc/groff/patches patch-contrib_mm_mmroff_pl patch-src_preproc_html_pre-html_cpp

   Backport three security fixes from the groff-1.24.2 release.
   OK naddy@ on a previous, minimally different version of this patch.

   From the groff-1.24.2 release announcement (September 28, 2026):
   "This release corrects command injection security vulnerabilities
   (CWE-78) in the mmroff, pdfmom, and pre-grohtml programs.  The last of
   these is a preprocessor that is run when groff or troff is run with the
   -T html or -T xhtml options.  The vulnerabilities are variously
   14-26 years old.  Malicious input can escape groff's default "safer"
   mode, running commands embedded in that input at the user's privilege
   level.  The groff development team recommends this release to any users
   who employ the named tools or GNU troff output formats with untrusted
   inputs.
   Man page rendering is not vulnerable unless rendering (X)HTML."
VersionDeltaFile
1.1+82-0textproc/groff/patches/patch-src_devices_gropdf_pdfmom_pl
1.3+35-12textproc/groff/patches/patch-src_roff_troff_input_cpp
1.1+39-0textproc/groff/patches/patch-src_preproc_html_pre-html_cpp
1.1+24-0textproc/groff/patches/patch-contrib_mm_mmroff_pl
1.53+1-1textproc/groff/Makefile
+181-135 files

OpenBSD/ports ZIx0pWO — mail/postfix/stable Makefile, security/sslscan Makefile

   bump ports with static links against security/openssl/3.5 in -stable
VersionDeltaFile
1.56.2.3+1-1sysutils/borgbackup/2.0/Makefile
1.86.2.3+1-1security/sslscan/Makefile
1.281.2.8+1-0mail/postfix/stable/Makefile
+3-23 files

OpenBSD/ports mJSFADA — security/openssl/3.5 Makefile distinfo, security/openssl/3.5/pkg PLIST

   MFC: Update to OpenSSL 3.5.9

   https://github.com/openssl/openssl/releases/tag/openssl-3.5.9
VersionDeltaFile
1.7.2.3+2-2security/openssl/3.5/distinfo
1.16.2.3+1-1security/openssl/3.5/Makefile
1.7.2.3+2-0security/openssl/3.5/pkg/PLIST
+5-33 files

OpenBSD/ports Pd8bpzp — mail/postfix/stable Makefile, security/sslscan Makefile

   bump ports with static link against security/openssl/3.5
VersionDeltaFile
1.64+2-0sysutils/borgbackup/2.0/Makefile
1.90+1-0security/sslscan/Makefile
1.289+1-0mail/postfix/stable/Makefile
+4-03 files

OpenBSD/ports Qu9OKte — security/openssl/3.5 Makefile distinfo, security/openssl/3.5/pkg PLIST

   Update to OpenSSL 3.5.9, ok naddy

   https://github.com/openssl/openssl/releases/tag/openssl-3.5.9
VersionDeltaFile
1.10+2-2security/openssl/3.5/distinfo
1.19+1-1security/openssl/3.5/Makefile
1.10+2-0security/openssl/3.5/pkg/PLIST
+5-33 files

OpenBSD/ports f8r12LY — security/openssl/4.0 Makefile distinfo, security/openssl/4.0/pkg PLIST

   Update to openssl 4.0.3, ok naddy

   https://github.com/openssl/openssl/releases/tag/openssl-4.0.3
VersionDeltaFile
1.5+2-2security/openssl/4.0/distinfo
1.8+1-1security/openssl/4.0/Makefile
1.5+2-0security/openssl/4.0/pkg/PLIST
+5-33 files

OpenBSD/ports Y4x5oOe — net/haproxy Makefile distinfo

   MFC: net/haproxy: update to 3.2.25

   Changes:
   https://www.haproxy.org/download/3.2/src/CHANGELOG

   from Mark Patruck
   ok sthen
VersionDeltaFile
1.93.2.6+2-2net/haproxy/distinfo
1.134.2.6+1-1net/haproxy/Makefile
+3-32 files

OpenBSD/ports Bt27Miq — net/haproxy Makefile distinfo

   net/haproxy: update to 3.2.25

   Changes:
   https://www.haproxy.org/download/3.2/src/CHANGELOG

   from Mark Patruck
   ok sthen
VersionDeltaFile
1.100+2-2net/haproxy/distinfo
1.141+1-1net/haproxy/Makefile
+3-32 files

OpenBSD/ports QD7Ipiv — www/mozilla-firefox distinfo, www/mozilla-firefox/patches patch-security_nss_lib_nss_nss_h patch-third_party_rust_nss-rs__cargo-checksum_json

   www/mozilla-firefox: MFC update to 157.0.

   see https://www.firefox.com/en-US/firefox/157.0/releasenotes/
   fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-97/
VersionDeltaFile
1.1.4.1+18-0www/mozilla-firefox/patches/patch-netwerk_socket_neqo_glue_src_lib_rs
1.1.2.1+16-0www/mozilla-firefox/patches/patch-security_manager_ssl_EnabledSignatureSchemes_h
1.1.2.1+15-0www/mozilla-firefox/patches/patch-third_party_rust_nss-rs_src_constants_rs
1.1.2.1+9-0www/mozilla-firefox/patches/patch-third_party_rust_nss-rs__cargo-checksum_json
1.1.6.7+2-2www/mozilla-firefox/patches/patch-security_nss_lib_nss_nss_h
1.397.2.22+2-2www/mozilla-firefox/distinfo
+62-47 files not shown
+66-813 files

OpenBSD/ports UqS89bh — www/firefox-esr Makefile distinfo

   www/firefox-esr: update to 140.17.0.

   see https://www.firefox.com/en-US/firefox/140.17.0/releasenotes/
   fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-99/

   last planned release in esr140 branch
VersionDeltaFile
1.180.2.8+4-4www/firefox-esr/distinfo
1.270.2.8+2-2www/firefox-esr/Makefile
+6-62 files

OpenBSD/ports FQIyF51 — www/firefox-esr Makefile distinfo, www/firefox-esr-i18n Makefile.inc distinfo

   www/firefox-esr: update to 153.4.0.

   see https://www.firefox.com/en-US/firefox/153.4.0/releasenotes/
   fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-100/

   ok naddy@
VersionDeltaFile
1.185+162-162www/firefox-esr-i18n/distinfo
1.190+4-4www/firefox-esr/distinfo
1.282+2-3www/firefox-esr/Makefile
1.197+1-1www/firefox-esr-i18n/Makefile.inc
+169-1704 files

OpenBSD/ports QcMMlzW — www/firefox-i18n Makefile.inc distinfo, www/mozilla-firefox distinfo Makefile

   www/mozilla-firefox: update to 157.0.

   see https://www.firefox.com/en-US/firefox/157.0/releasenotes/
   fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-97/

   bump REVISION to be ahead of 7.9-stable

   ok naddy@
VersionDeltaFile
1.409+164-164www/firefox-i18n/distinfo
1.423+4-4www/mozilla-firefox/distinfo
1.712+4-4www/mozilla-firefox/Makefile
1.364+1-1www/firefox-i18n/Makefile.inc
+173-1734 files

OpenBSD/ports hXBNbbY — net/libslirp Makefile distinfo, net/libslirp/patches patch-test_guestfwdtest_c patch-src_tcp_subr_c

   net/libslirp: update to 4.9.5

   Addressed CVE-2026-95507 and CVE-2026-95508

   OK: sthen@
VersionDeltaFile
1.4+2-2net/libslirp/distinfo
1.5+1-1net/libslirp/Makefile
1.2+0-0net/libslirp/patches/patch-test_guestfwdtest_c
1.2+0-0net/libslirp/patches/patch-src_tcp_subr_c
1.2+0-0net/libslirp/patches/patch-src_tcp_input_c
1.2+0-0net/libslirp/patches/patch-src_slirp_c
+3-31 files not shown
+3-37 files

OpenBSD/ports ru6m61H — www/chromium Makefile, www/ungoogled-chromium Makefile

   add missing bdep on graphics/vulkan-headers
VersionDeltaFile
1.259+1-0www/ungoogled-chromium/Makefile
1.936+1-0www/chromium/Makefile
+2-02 files

OpenBSD/ports FT72xiU — databases/pgbouncer Makefile distinfo, databases/pgbouncer/patches patch-lib_usual_tls_tls_conninfo_c patch-lib_usual_tls_tls_compat_c

   databases/pgbouncer: security update to 1.26.0

   see https://www.pgbouncer.org/2026/09/pgbouncer-1-26-0, fixes:

   * CVE-2026-19888: DoS due to crash, triggerable by unauthenticated
     clients. Caused by a SCRAM client-final-message without a nonce.
   * CVE-2026-6668: DoS due to infinite loop, triggerable by unauthenticated
     clients. Caused by an integer overflow in the packet buffer growth
     logic.
   *  CVE-2026-6669: DoS due to unbounded work during login, triggerable by a
     malicious PostgreSQL server. Caused by an unbounded SCRAM iteration
     count.

   ok naddy@
VersionDeltaFile
1.26+2-2databases/pgbouncer/distinfo
1.11+1-1databases/pgbouncer/patches/patch-etc_pgbouncer_ini
1.50+1-1databases/pgbouncer/Makefile
1.2+0-0databases/pgbouncer/patches/patch-lib_usual_tls_tls_conninfo_c
1.2+0-0databases/pgbouncer/patches/patch-lib_usual_tls_tls_compat_c
+4-45 files

OpenBSD/ports r60m9bi — graphics/digikam Makefile, graphics/exiv2 Makefile

   fix builds with ccache, ok rsadowski naddy
VersionDeltaFile
1.29+2-6net/litecoin/Makefile
1.61+2-6net/bitcoin/Makefile
1.15+0-5x11/qt6/Makefile.inc
1.89+0-5graphics/openimageio/Makefile
1.118+0-4graphics/digikam/Makefile
1.54+0-3graphics/exiv2/Makefile
+4-296 files

OpenBSD/ports 8jKbDXP — x11/qt5/qtbase Makefile, x11/qt5/qtbase/patches patch-src_corelib_kernel_qcoreapplication_cpp

   qt5/qtbase ports changes, ok rsadowski naddy

   - add getexecpath support to qt5/qtbase

   - fix builds with ccache; the way this was handled in qtbase could be
   simplified as it's already done by ports infrastructure, and the way
   it was done here previously isn't compatible with recent bsd.port.mk
   changes
VersionDeltaFile
1.1+17-0x11/qt5/qtbase/patches/patch-src_corelib_kernel_qcoreapplication_cpp
1.82+2-6x11/qt5/qtbase/Makefile
+19-62 files

OpenBSD/ports eMVEVJQ — print/texlive/texmf distinfo Makefile

   print/texlive: unbreak the minted latex package.

   Reported by espie@. OK sthen@.

   Thanks!
VersionDeltaFile
1.78+13-0print/texlive/texmf/Makefile
1.22+2-0print/texlive/texmf/distinfo
+15-02 files

OpenBSD/ports IYQJnE1 — www/chromium/patches patch-third_party_devtools-frontend_src_front_end_models_ai_assistance_BUILD_gn, www/ungoogled-chromium/patches patch-third_party_devtools-frontend_src_front_end_models_ai_assistance_BUILD_gn

   add missing dep to fix random build error; ok naddy@
VersionDeltaFile
1.1+12-0www/ungoogled-chromium/patches/patch-third_party_devtools-frontend_src_front_end_models_ai_assistance_BUILD_gn
1.1+12-0www/chromium/patches/patch-third_party_devtools-frontend_src_front_end_models_ai_assistance_BUILD_gn
+24-02 files

OpenBSD/ports TGidEk8 — print/libcupsfilters distinfo Makefile, print/libcupsfilters/patches patch-cupsfilters_pdftopdf_c patch-cupsfilters_pdf_c

   Update to a recent commit to unbreak several printing scenarii.
VersionDeltaFile
1.10+15-5print/libcupsfilters/Makefile
1.6+2-2print/libcupsfilters/distinfo
1.3+0-0print/libcupsfilters/patches/patch-cupsfilters_pdftopdf_c
1.2+0-0print/libcupsfilters/patches/patch-cupsfilters_pdf_c
+17-74 files

OpenBSD/ports FRuIsqX — telephony/resiprocate Makefile

   BDEP on vim|vim-classic for xxd, build problem reported by naddy
VersionDeltaFile
1.17+2-1telephony/resiprocate/Makefile
+2-11 files

OpenBSD/ports p9TCGsS — lang/python/3 distinfo, lang/python/3/files CHANGES.OpenBSD

   update to python-3.13.15, ok kmos
VersionDeltaFile
1.12.2.2+36-3lang/python/3/pkg/PLIST-tests
1.6.2.2+5-8lang/python/3/files/CHANGES.OpenBSD
1.5.2.2+3-4lang/python/3/patches/patch-configure_ac
1.11.2.2+2-2lang/python/3/distinfo
1.8.2.1+4-0lang/python/3/pkg/PLIST-idle
1.17.2.2+1-2lang/python/3/pkg/PLIST-main
+51-192 files not shown
+53-218 files

OpenBSD/ports g4FnbuY — lang/python/3 Makefile distinfo, lang/python/3/files CHANGES.OpenBSD

   update to python-3.14.7, ok kmos
VersionDeltaFile
1.17+69-0lang/python/3/pkg/PLIST-tests
1.8+5-8lang/python/3/files/CHANGES.OpenBSD
1.8+3-4lang/python/3/patches/patch-configure_ac
1.34+1-3lang/python/3/Makefile
1.15+2-2lang/python/3/distinfo
1.10+4-0lang/python/3/pkg/PLIST-idle
+84-172 files not shown
+86-208 files

OpenBSD/ports EkPYWhj — security/clusterssh distinfo Makefile

   update to 4.19
VersionDeltaFile
1.27+4-2security/clusterssh/Makefile
1.17+2-2security/clusterssh/distinfo
+6-42 files

OpenBSD/ports NorjchD — devel/cabal-install Makefile distinfo, devel/cabal-install/files openbsd.json

   devel/cabal-install: update to 3.18.1.0

   OK kili@
VersionDeltaFile
1.11+87-65devel/cabal-install/files/openbsd.json
1.23+34-30devel/cabal-install/distinfo
1.47+23-12devel/cabal-install/Makefile
+144-1073 files

OpenBSD/ports dlqx3PL — lang/ghc Makefile, lang/ghc/patches patch-testsuite_tests_lib_base_executablePath_hs patch-libraries_ghc-boot_GHC_BaseDir_hs

   lang/ghc: use getexecpath(3) for executablePath on OpenBSD

   getexecpath(3) is new in OpenBSD 8.0. Without it ghc-internal falls through
   to the argv[0] fallback and System.Environment.executablePath is Nothing.

   Also let ghc-boot use base's executablePath, choosing at run time so the port
   still builds with a bootstrap compiler whose base predates getexecpath(3),
   and mark openbsd as query-capable in the executablePath test.

   Bump REVISION for the getexecpath change

   System.Environment.executablePath goes from Nothing to a working query, and
   getExecutablePath from argv[0] to a canonicalized absolute path, so the
   package behaves differently and needs to be distinguishable.

   OK kili@
VersionDeltaFile
1.1+57-0lang/ghc/patches/patch-libraries_ghc-internal_src_GHC_Internal_System_Environment_ExecutablePath_hsc
1.1+47-0lang/ghc/patches/patch-libraries_ghc-boot_GHC_BaseDir_hs
1.1+19-0lang/ghc/patches/patch-testsuite_tests_lib_base_executablePath_hs
1.237+1-0lang/ghc/Makefile
+124-04 files

OpenBSD/ports 8CDocR9 — sysutils/broot Makefile crates.inc

   Update broot to 1.60.2.
VersionDeltaFile
1.47+126-158sysutils/broot/distinfo
1.37+62-78sysutils/broot/crates.inc
1.53+1-1sysutils/broot/Makefile
+189-2373 files

OpenBSD/ports SEXbWak — graphics/blender Makefile, graphics/blender/patches patch-intern_libmv_libmv_build_build_config_h patch-source_blender_blenlib_BLI_build_config_h

   Make blender build on sparc64

   patch from Brad Smith
VersionDeltaFile
1.1+45-0graphics/blender/patches/patch-source_blender_blenlib_BLI_build_config_h
1.1+32-0graphics/blender/patches/patch-intern_libmv_libmv_build_build_config_h
1.158+1-2graphics/blender/Makefile
+78-23 files

OpenBSD/ports 1APROMu — security/gnupg Makefile distinfo

   Revert to gnupg-2.5.22 because gnupg-2.5.23+ breaks mail/notmuch

   mail/notmuch uses gmime -> gpgme -> gnupg to decrypt PGP-encrypted
   messages, and check for that feature in it configure script.  Since

   commit 2e6549f5de5307e3e84c1ffa5e762d14266546ba
   gpg: Preliminary support for importing some rfc-9980 secret keys.

   gpg-agent now appears unable to export the "session key" used by notmuch
   tests, so gpg has no key to pass back to gpgme/gmime. The code in
   notmuch/configure mimics the code in notmuch/util/crypto.c so we can
   expect this to be an actual regression. Revert to the previous gnupg
   release to unbreak bulk builds and avoid regressions.

   Reported by sthen@
VersionDeltaFile
1.57+2-2security/gnupg/distinfo
1.153+2-1security/gnupg/Makefile
+4-32 files

OpenBSD/ports cbCc9Kg — geo/cdo distinfo Makefile

   Update cdo to 2.6.4. From maintainer Marco van Hulten, thanks.
   Improve WANTLIB while there.
VersionDeltaFile
1.4+5-5geo/cdo/Makefile
1.4+2-2geo/cdo/distinfo
+7-72 files