OpenBSD/src p0fKWQ5 — usr.sbin/relayd relay_http.c

   relayd: do not treat a missing Host header as a url match

   Return RES_BAD if the request has no Host header, consistent with the
   handling of empty or malformed Host values.

   Spotted by Acts1631 (with diff), OK kirill@
VersionDeltaFile
1.107+2-2usr.sbin/relayd/relay_http.c
+2-21 files

OpenBSD/src aIftdTD — regress/usr.bin/mandoc/man/TH secsuffix.in secsuffix.out_ascii, regress/usr.bin/mandoc/mdoc/Dt Makefile secsuffix.out_ascii

   test handling of session suffixes in the .Dt and .TH macros;
   related to msec.c rev. 1.14
VersionDeltaFile
1.1+11-0regress/usr.bin/mandoc/mdoc/Dt/secsuffix.out_markdown
1.1+9-0regress/usr.bin/mandoc/mdoc/Dt/secsuffix.out_ascii
1.1+9-0regress/usr.bin/mandoc/mdoc/Dt/secsuffix.in
1.1+9-0regress/usr.bin/mandoc/man/TH/secsuffix.out_ascii
1.12+6-2regress/usr.bin/mandoc/mdoc/Dt/Makefile
1.1+6-0regress/usr.bin/mandoc/man/TH/secsuffix.in
+50-21 files not shown
+53-47 files

OpenBSD/src oNXiFxr — usr.bin/mandoc msec.c

   When converting a section identifier (for example, "1" or "1m") to
   a volume title (for example, "General Commands Manual" or "Maintenance
   Commands") and no exact match is found for the identifier, retry
   using only the first character of the identifier before giving up.

   For example, when using OpenBSD to format the Oracle Solaris ipmitool(1m)
   manual, which contains the line '.TH ipmitool 1m "29 June 2012"',
   use the section 1 volume title "General Commands Manual" rather
   than finding no title at all.  In general, this improves formatting
   of the page header line of manual pages using session suffixes that
   are not declared in msec.in on the formatting system.  That's useful
   everywhere for formatting foreign manual pages, but also for
   formatting native manuals on systems using many suffixes.

   I had this idea for a small improvement while looking at how FreeBSD
   customizes the companion file msec.in in their freebsd-src/contrib/mandoc
   directory.
VersionDeltaFile
1.14+21-2usr.bin/mandoc/msec.c
+21-21 files

OpenBSD/src Z4yOqkI — usr.bin/tmux screen-write.c window-visible.c

   Include menus when working out what parts of a pane are visible to avoid
   overwriting them, GitHub issue 5593.
VersionDeltaFile
1.6+76-87usr.bin/tmux/window-visible.c
1.298+30-9usr.bin/tmux/screen-write.c
+106-962 files

OpenBSD/src yG6iNCq — usr.bin/tmux cmd-display-message.c

   Modify display-message -c target-client to use the data relative to
   target-client, GitHub issue 5613 from Michael Grant.
VersionDeltaFile
1.67+4-6usr.bin/tmux/cmd-display-message.c
+4-61 files

OpenBSD/src 4UHrXAH — usr.bin/tmux options-table.c

   Quote session_alert in status-format[2], GitHub issue 5671.
VersionDeltaFile
1.248+3-3usr.bin/tmux/options-table.c
+3-31 files

OpenBSD/src rE7PRFL — usr.bin/tmux screen-write.c

   Only skip collecting text except for right margin when autowrap is off,
   from Jang-Ho Hwang.
VersionDeltaFile
1.297+7-2usr.bin/tmux/screen-write.c
+7-21 files

OpenBSD/src fTHiEbC — usr.sbin/rpki-client output-rtrx.c

   output-rtrx: place one brace on the proper line
VersionDeltaFile
1.7+2-3usr.sbin/rpki-client/output-rtrx.c
+2-31 files

OpenBSD/src hZaJrDQ — usr.bin/tmux spawn.c

   Change to the new working directory even if getcwd fails, GitHub issue 5658.
VersionDeltaFile
1.54+9-9usr.bin/tmux/spawn.c
+9-91 files

OpenBSD/src 2uHyEl0 — sys/dev/usb usb_subr.c

   sys/usb: validate USB endpoint and configuration lengths

   Reject undersized endpoint descriptors before accessing wMaxPacketSize;
   require wTotalLength to cover the configuration header and match the
   allocated size after the full fetch.

   Reported by Stuart Thomas

   OK: deraadt@
VersionDeltaFile
1.169+8-2sys/dev/usb/usb_subr.c
+8-21 files

OpenBSD/src EXaDdF0 — usr.bin/tmux screen-write.c

   Sync redraw should use the given rows not the scroll region now.
VersionDeltaFile
1.296+3-3usr.bin/tmux/screen-write.c
+3-31 files

OpenBSD/src lC01jP7 — usr.bin/tmux cmd-join-pane.c tmux.h

   Instead of redrawing the entire pane or scene when moving or redrawing a
   pane, add damage rectangles and redraw only the affected spans. From
   Michael Grant.
VersionDeltaFile
1.163+287-16usr.bin/tmux/screen-redraw.c
1.384+56-3usr.bin/tmux/window.c
1.517+32-11usr.bin/tmux/server-client.c
1.295+20-8usr.bin/tmux/screen-write.c
1.1451+16-2usr.bin/tmux/tmux.h
1.76+9-3usr.bin/tmux/cmd-join-pane.c
+420-436 files not shown
+451-5912 files

OpenBSD/src CtWHgIz — sbin/isakmpd TO-DO README

   these files are completely historical and not helping improve things
VersionDeltaFile
1.27+1-1sbin/isakmpd/TO-DO
1.21+1-1sbin/isakmpd/README
1.6+1-1sbin/isakmpd/QUESTIONS
1.26+1-1sbin/isakmpd/DESIGN-NOTES
1.17+1-1sbin/isakmpd/BUGS
+5-55 files

OpenBSD/src HPhu32F — sys/dev/ic qwz.c

   sys/qwz: backport of olatile casts from qwx

   Backport of sys/dev/ic/qwx.c,v 1.114

   OK: stsp@
VersionDeltaFile
1.91+5-3sys/dev/ic/qwz.c
+5-31 files

OpenBSD/src O1JGzv6 — sys/dev/ic qwz.c

   sys/qwz: backport sync DMA memory from qwx

   Backport of sys/dev/ic/qwx.c,v 1.140 and 1.146

   OK: stsp@
VersionDeltaFile
1.90+9-2sys/dev/ic/qwz.c
+9-21 files

OpenBSD/src j76D4Rj — usr.bin/tmux tmux.h server-client.c

   Do not leak client if lost before configuration is loaded, and do not load
   multiple times. GitHub issues 5661 and 5662 from Alexandre Fiori.
VersionDeltaFile
1.92+27-3usr.bin/tmux/cfg.c
1.516+2-3usr.bin/tmux/server-client.c
1.1450+2-1usr.bin/tmux/tmux.h
+31-73 files

OpenBSD/src KE4qSlp — usr.bin/tmux cmd-swap-pane.c

   Restore the zoom when swap-pane refuses a floating pane, GitHub issue
   5660 from Alexandre Fiori.
VersionDeltaFile
1.56+8-3usr.bin/tmux/cmd-swap-pane.c
+8-31 files

OpenBSD/src lblECaS — usr.bin/tmux cmd-copy-mode.c

   Do not use client for copy-mode -S if NULL, reported by Martin Vlach.
VersionDeltaFile
1.55+3-1usr.bin/tmux/cmd-copy-mode.c
+3-11 files

OpenBSD/src Nqr5vWt — sys/dev/ic qwx.c

   also sync qwx DMA memory before updating the ring pointer via sc->ops.write32
VersionDeltaFile
1.146+3-1sys/dev/ic/qwx.c
+3-11 files

OpenBSD/src gsNf0rK — sys/net pf_table.c pf.c

   pf(4): pfr_insert_kentry() always needs PF_LOCK()

   pfr_insert_kentry() inserts an IP address into a table. The table's
   consistency is protected by PF_LOCK(). Unfortunately, PF_LOCK()
   protection is missing for the code path executed on behalf
   of the overload action in a pf rule. The overload action instructs
   the firewall to insert the packet's source address into the table specified
   as the overload action parameter. That particular code path in
   pf_test() function runs without any lock protection.

   The bug was introduced in revision 1.1074 and remained unnoticed
   until now, when it was kindly reported by alf (a.schlichting () lemarit ! com>)

   OK henning@, OK dlg@, OK jmatthew@
VersionDeltaFile
1.1242+14-4sys/net/pf.c
1.151+3-1sys/net/pf_table.c
+17-52 files

OpenBSD/src i6ugJKo — usr.sbin/httpd server.c httpd.conf.5

   httpd: add header block/drop rules for request filtering

   With this incoming requests can also be rejected based on the value of a
   request header. Valid options are:

   header block name value code [arg]
           Close the connection with an error response when a
           request header matches.  Both name and value are shell-
           style patterns and are matched case-insensitively against
           the header name and value.  code must be a valid HTTP
           status code.  For codes in the 3xx range, arg is required
           and sent as the "Location" header.  It must start with
           "http://" or "https://".  For all other codes, arg is
           optional and used as the log message identifying the
           rule.

   header drop name value
           Silently close the connection without sending a response
           when a request header matches, using the same pattern

    [10 lines not shown]
VersionDeltaFile
1.78+126-1usr.sbin/httpd/config.c
1.139+102-1usr.sbin/httpd/parse.y
1.172+50-1usr.sbin/httpd/server_http.c
1.137+35-2usr.sbin/httpd/httpd.conf.5
1.185+36-1usr.sbin/httpd/httpd.h
1.140+21-1usr.sbin/httpd/server.c
+370-71 files not shown
+390-87 files

OpenBSD/src ROswo2p — regress/usr.sbin/relayd args-http-chunked-trailer-unterminated.pl

   Test unterminated chunk trailer lines against the header length limit
VersionDeltaFile
1.1+29-0regress/usr.sbin/relayd/args-http-chunked-trailer-unterminated.pl
+29-01 files

OpenBSD/src amMY1R3 — usr.sbin/relayd relay_http.c

   relayd: apply the header length limit to chunk size and trailer lines

   Chunk size and trailer lines were not limited, so a line without line
   ending could be buffered without bound. Limit each chunk size line and
   the whole trailer to the configured header length and close the
   session if they exceed it.

   Spotted by Acts1631 (with diff), OK kirill@
VersionDeltaFile
1.106+22-1usr.sbin/relayd/relay_http.c
+22-11 files

OpenBSD/src B7c26gT — usr.sbin/relayd relay_http.c

   relayd: apply the header length limit to unterminated lines

   The limit was only checked for complete lines, so a header line
   without line ending could be buffered without bound. Reject such
   lines with 413 as soon as they exceed the limit.

   Spotted by Acts1631 (with diff), OK kirill@
VersionDeltaFile
1.105+11-1usr.sbin/relayd/relay_http.c
+11-11 files

OpenBSD/src qY0VmOp — sys/arch/amd64/amd64 cpu.c, sys/arch/i386/i386 machdep.c

   don't access the DE_CFG MSR when running on a hypervisor

   Sebastian Albert encountered a KVM hosting provider where trying
   to access the MSR resulted in a protection fault.
   DE_CFG is not documented in AMD's 'AMD64 Architecture Programmer's Manual'.

   ok brynet@ mlarkin@
VersionDeltaFile
1.681+3-2sys/arch/i386/i386/machdep.c
1.208+3-2sys/arch/amd64/amd64/cpu.c
+6-42 files

OpenBSD/src FBg6M1V — sys/dev/ic qwz.c

   sys/qwz: spoted one more negative errno
VersionDeltaFile
1.89+2-2sys/dev/ic/qwz.c
+2-21 files

OpenBSD/src XZCn7q2 — usr.sbin/vmd i8259.c

   vmd(8): change a log_warnx to a log_debug

   no functional change, just quieting a chatty log message.
VersionDeltaFile
1.25+2-2usr.sbin/vmd/i8259.c
+2-21 files

OpenBSD/src 9WuS1qh — sys/dev/ic qwzvar.h qwz.c

   sys/qwz: fix REO queue lifetime

   Track REO completions before publication and wait for peer unmap,
   deletion, and cache flushes before reusing queue DMA. Submission errors
   and timeouts retain ownership; hardware failures block reuse until cold
   cleanup. HAL error conventions and flush semantics follow ath12k;
   tracking and the reuse barrier adapt qwz's retained pool.
VersionDeltaFile
1.88+163-155sys/dev/ic/qwz.c
1.29+14-12sys/dev/ic/qwzvar.h
+177-1672 files

OpenBSD/src 3ULWshX — sys/dev/ic qwzreg.h qwz.c

   sys/qwz: fix WCN7850 REO layout

   Use WCN7850 REO tags and 64-bit TLV headers so commands and completions
   use the correct offsets. Correct the status ring size and clear command
   payloads before reuse.

   The layout follows Linux ath12k's WCN7850 definitions.

   OK: stsp@
VersionDeltaFile
1.87+98-69sys/dev/ic/qwz.c
1.19+17-17sys/dev/ic/qwzreg.h
+115-862 files

OpenBSD/src gzFWZwd — sys/dev/ic qwz.c

   sys/qwz: configure negotiated HT SMPS

   Backport of sys/dev/ic/qwx.c,v 1.92

   OK: stsp@
VersionDeltaFile
1.86+37-9sys/dev/ic/qwz.c
+37-91 files