OpenBSD/src C1f1tNZ — regress/usr.sbin/rpki-client/openssl unistd.h

   rpki-client regress: this unistd.h hack needs to include x509.h
VersionDeltaFile
1.7+2-1regress/usr.sbin/rpki-client/openssl/unistd.h
+2-11 files

OpenBSD/src ydGmbba — lib/libexpat/lib xmltok.h xmltok_impl.c, lib/libexpat/tests basic_tests.c

   Backport fixes from libexpat version 2.8.5.

   Relevant for OpenBSD are security fixes #1282, bug fixes #1346
   #1371, other changes #1354 #1357 #1349 #1360 #1378.  Library bump
   is not necessary.
   CVE-2026-93990

   OK deraadt@

   this is errata/7.9/033_expat.patch.sig
VersionDeltaFile
1.9.4.3+342-0lib/libexpat/tests/basic_tests.c
1.20.4.2+138-64lib/libexpat/lib/xmltok.c
1.47.2.3+89-92lib/libexpat/lib/xmlparse.c
1.15.4.2+55-56lib/libexpat/lib/xmlrole.c
1.18.12.2+28-32lib/libexpat/lib/xmltok_impl.c
1.9.6.3+25-26lib/libexpat/lib/xmltok.h
+677-2706 files not shown
+716-31912 files

OpenBSD/src dGRHt22 — lib/libexpat/lib xmltok.h xmltok_impl.c, lib/libexpat/tests basic_tests.c

   Backport fixes from libexpat version 2.8.5.

   Relevant for OpenBSD are security fixes #1282, bug fixes #1346
   #1371, other changes #1354 #1357 #1349 #1360 #1378.  Library bump
   is not necessary.
   CVE-2026-93990

   OK deraadt@

   this is errata/7.8/069_expat.patch.sig
VersionDeltaFile
1.7.2.5+342-0lib/libexpat/tests/basic_tests.c
1.18.2.2+138-64lib/libexpat/lib/xmltok.c
1.44.2.6+89-92lib/libexpat/lib/xmlparse.c
1.13.6.2+55-56lib/libexpat/lib/xmlrole.c
1.18.6.2+28-32lib/libexpat/lib/xmltok_impl.c
1.9.2.3+25-26lib/libexpat/lib/xmltok.h
+677-2706 files not shown
+716-31912 files

OpenBSD/src hAu9Erc — sbin/isakmpd isakmpd.c message.c

   incorrect object being freed
   from Franz Bettag / Bettag Systems
   from deraadt@; OK markus@ hshoexer@ sthen@ mvs@

   IKEv1 short-HASH heap overflow; second approach for fix
   from Franz Bettag / Bettag Systems
   from deraadt@; OK sthen@ mvs@

   Franz Bettag sent a report & diff repairing the privsep monitor's
   dangerous file behavior in /var/run, and I was shocked at what it
   does.  isakmpd never had a proper diagnosis and control program like
   other daemons do, and instead accepts weird commands on a fifo and
   splats files dangerously.  Some path names can be manipulated.  This
   2600 line diff removes all of this session debugging mechanism which
   is the main cause of that unsafe design.  There are no reuseable parts
   in that code (it cannot be reconstructed into a proper control program
   interface).  As a result, the privsep monitor now has unveil to the
   config directory, and the network speaking process is "stdio sendfd
   route recvfd inet".  There is some loss of functionality, since some

    [22 lines not shown]
VersionDeltaFile
1.125.18.1+2-342sbin/isakmpd/sa.c
1.65.8.1+1-341sbin/isakmpd/log.c
1.83.14.1+64-187sbin/isakmpd/monitor.c
1.22.36.1+1-133sbin/isakmpd/field.c
1.129.40.1+4-120sbin/isakmpd/message.c
1.109.14.1+7-116sbin/isakmpd/isakmpd.c
+79-1,23928 files not shown
+166-1,81334 files

OpenBSD/src 3ns2n6b — sbin/isakmpd isakmpd.c message.c

   incorrect object being freed
   from Franz Bettag / Bettag Systems
   from deraadt@; OK markus@ hshoexer@ sthen@ mvs@

   IKEv1 short-HASH heap overflow; second approach for fix
   from Franz Bettag / Bettag Systems
   from deraadt@; OK sthen@ mvs@

   Franz Bettag sent a report & diff repairing the privsep monitor's
   dangerous file behavior in /var/run, and I was shocked at what it
   does.  isakmpd never had a proper diagnosis and control program like
   other daemons do, and instead accepts weird commands on a fifo and
   splats files dangerously.  Some path names can be manipulated.  This
   2600 line diff removes all of this session debugging mechanism which
   is the main cause of that unsafe design.  There are no reuseable parts
   in that code (it cannot be reconstructed into a proper control program
   interface).  As a result, the privsep monitor now has unveil to the
   config directory, and the network speaking process is "stdio sendfd
   route recvfd inet".  There is some loss of functionality, since some

    [22 lines not shown]
VersionDeltaFile
1.125.14.1+2-342sbin/isakmpd/sa.c
1.65.4.1+1-341sbin/isakmpd/log.c
1.83.10.1+64-187sbin/isakmpd/monitor.c
1.22.32.1+1-133sbin/isakmpd/field.c
1.129.36.1+4-120sbin/isakmpd/message.c
1.109.10.1+7-116sbin/isakmpd/isakmpd.c
+79-1,23928 files not shown
+166-1,81334 files

OpenBSD/src enC48MP — regress/usr.bin/mandoc/mdoc/Bd offset-empty.in offset-neg.in, regress/usr.bin/mandoc/mdoc/Bl offset.in width.out_ascii

   test macros in .Bl and .Bd -width and -offset arguments;
   related to mdoc_validate.c rev. 1.313
VersionDeltaFile
1.1+21-0regress/usr.bin/mandoc/mdoc/Bl/width.out_markdown
1.1+20-0regress/usr.bin/mandoc/mdoc/Bl/width.in
1.1+13-0regress/usr.bin/mandoc/mdoc/Bl/width.out_ascii
1.4+5-5regress/usr.bin/mandoc/mdoc/Bd/offset-neg.in
1.7+6-3regress/usr.bin/mandoc/mdoc/Bd/offset-empty.in
1.6+6-2regress/usr.bin/mandoc/mdoc/Bl/offset.in
+71-107 files not shown
+93-2413 files

OpenBSD/src 7hvqqHQ — usr.bin/mandoc mdoc_validate.c

   If the -width of a .Bl macro is of the form ".word text",
   use only the text for measuring the width, assuming the word is a macro,
   as a crude approximation of what groff_mdoc(7) does: it sets the
   argument in a diversion and measures the width of the diversion.

   Ugly formatting first reported by Franco Fichtner (DragonFly BSD) in 2013,
   this partial fix first suggested by me in the mandoc TODO file in 2013,
   then implemented by Eric van Gyzen (FreeBSD) in 2022.
   My fix committed here is slightly smaller than Eric's FreeBSD fix,
   does not need an extra function, and stays closer to groff behaviour.
VersionDeltaFile
1.313+32-13usr.bin/mandoc/mdoc_validate.c
+32-131 files

OpenBSD/src lnviTM9 — sys/dev/ic ufshci.c

   sys/ufshci: increase poll's wait to 500ms

   This matches Linux timeout and makes ufshci survives a suspend on
   HONOR MagicBook Art 14 Snapdragon

   500ms value which matches Linux suggested by kettenis@

   OK: mglocker@
VersionDeltaFile
1.50+2-2sys/dev/ic/ufshci.c
+2-21 files

OpenBSD/src MP0afmX — regress/usr.bin/ssh percent.sh

   Add test for proxycommand percent expansions.
VersionDeltaFile
1.24+20-4regress/usr.bin/ssh/percent.sh
+20-41 files

OpenBSD/src hfDfkLh — usr.sbin/vmd x86_vm.c

   vmd(8): fix mmio exit issue on old SVM machines

   fix a problem where we didn't pass any instruction length to insn_decode
   on some older opterons that don't have SVM decode assist.

   ok dv
VersionDeltaFile
1.28+2-1usr.sbin/vmd/x86_vm.c
+2-11 files

OpenBSD/src 80S1WVA — usr.sbin/rpki-client output-rtrx.c

   Use SOCK_NONBLOCK where we can.
   Handle errors for fcntl().
   CID 656886, CID 656887
   OK deraadt@ tb@
VersionDeltaFile
1.8+12-17usr.sbin/rpki-client/output-rtrx.c
+12-171 files

OpenBSD/src jPUgZXG — sbin/isakmpd policy.c

   The path generation must not contain '..' or '/' type patterns or it
   can walk upwards and sideways.  The privsep open() is now restricted by
   a single unveil() inside the config directory, but files in relative config
   directories can still be reached and create potentially confusing outcomes.
   This is half of a repair from Franz Bettag before I restructured the privsep
   to use unveil(), the other half of the repair is not needed because it applies
   to code that no longer exists.
   ok markus hshoexer bluhm, testing sthen mvs
VersionDeltaFile
1.107+9-1sbin/isakmpd/policy.c
+9-11 files

OpenBSD/src iGQVcL6 — usr.sbin/rtrd sockets.c

   Use SOCK_NONBLOCK and handle fcntl() failures.
   OK deraadt@
VersionDeltaFile
1.7+35-13usr.sbin/rtrd/sockets.c
+35-131 files

OpenBSD/src obmca7C — sbin/isakmpd message.c isakmpd.c

   Franz Bettag sent a report & diff repairing the privsep monitor's
   dangerous file behavior in /var/run, and I was shocked at what it
   does.  isakmpd never had a proper diagnosis and control program like
   other daemons do, and instead accepts weird commands on a fifo and
   splats files dangerously.  Some path names can be manipulated.  This
   2600 line diff removes all of this session debugging mechanism which
   is the main cause of that unsafe design.  There are no reuseable parts
   in that code (it cannot be reconstructed into a proper control program
   interface).  As a result, the privsep monitor now has unveil to the
   config directory, and the network speaking process is "stdio sendfd
   route recvfd inet".  There is some loss of functionality, since some
   users had gotten used to the decrepit debugging / logging interface to
   repair sessions which would not negotiate.
   This is almost completely unmaintained code from early OpenBSD days
   with an incorrect privsep design, and many users have migrated to
   using iked(8) which does IKEv2 protocol.  RFC9395 also provides valuable
   guidance here.  Everyone is urged to avoid using this program.  If IKEv1
   protocol is still a part of your life roll up sleeves and try to write a
   high-quality control interface using lessons from the IKEv2 iked(8) code.

    [2 lines not shown]
VersionDeltaFile
1.127+2-342sbin/isakmpd/sa.c
1.66+1-341sbin/isakmpd/log.c
1.85+64-187sbin/isakmpd/monitor.c
1.23+1-133sbin/isakmpd/field.c
1.110+7-116sbin/isakmpd/isakmpd.c
1.137+1-120sbin/isakmpd/message.c
+76-1,23928 files not shown
+132-1,81134 files

OpenBSD/src u815Prj — sbin/isakmpd x509.c

   knf
VersionDeltaFile
1.129+2-2sbin/isakmpd/x509.c
+2-21 files

OpenBSD/src Zbb4BO1 — sbin/isakmpd message.c ike_quick_mode.c

   IKEv1 short-HASH heap overflow; second approach for fix
   from Franz Bettag / Bettag Systems
   ok sthen mvs
VersionDeltaFile
1.117+22-1sbin/isakmpd/ike_quick_mode.c
1.136+4-1sbin/isakmpd/message.c
+26-22 files

OpenBSD/src Y0mnfRq — sbin/isakmpd policy.c

   incorrect object being freed
   from Franz Bettag / Bettag Systems
   ok markus hshoexer sthen mvs
VersionDeltaFile
1.105+3-3sbin/isakmpd/policy.c
+3-31 files

OpenBSD/src S17RePh — usr.bin/ssh servconf.c

   make StreamLocalBindMask properly first-match-wins; spotted
   while fixing bz4013
VersionDeltaFile
1.458+3-2usr.bin/ssh/servconf.c
+3-21 files

OpenBSD/src XU9VL1n — usr.bin/ssh readconf.c

   make StreamLocalBindMask properly respect Host/Match blocks
   and make it first-match-wins as documented. bz4013
VersionDeltaFile
1.418+4-2usr.bin/ssh/readconf.c
+4-21 files

OpenBSD/src tnhUD16 — lib/libexpat/lib xmltok.h xmltok_impl.c, lib/libexpat/tests basic_tests.c

   Backport fixes from libexpat version 2.8.5.

   Relevant for OpenBSD are security fixes #1282, bug fixes #1346
   #1371, other changes #1354 #1357 #1349 #1360 #1378.  Library bump
   is not necessary.
   CVE-2026-93990

   OK deraadt@
VersionDeltaFile
1.15+342-0lib/libexpat/tests/basic_tests.c
1.24+138-64lib/libexpat/lib/xmltok.c
1.53+89-92lib/libexpat/lib/xmlparse.c
1.18+55-56lib/libexpat/lib/xmlrole.c
1.21+28-32lib/libexpat/lib/xmltok_impl.c
1.12+25-26lib/libexpat/lib/xmltok.h
+677-2706 files not shown
+716-31912 files

OpenBSD/src p0fKWQ5 — usr.sbin/relayd relay_http.c

   relayd: do not treat a missing Host header as a url match

   Return RES_BAD if the request has no Host header, consistent with the
   handling of empty or malformed Host values.

   Spotted by Acts1631 (with diff), OK kirill@
VersionDeltaFile
1.107+2-2usr.sbin/relayd/relay_http.c
+2-21 files

OpenBSD/src aIftdTD — regress/usr.bin/mandoc/man/TH secsuffix.in secsuffix.out_ascii, regress/usr.bin/mandoc/mdoc/Dt Makefile secsuffix.out_ascii

   test handling of session suffixes in the .Dt and .TH macros;
   related to msec.c rev. 1.14
VersionDeltaFile
1.1+11-0regress/usr.bin/mandoc/mdoc/Dt/secsuffix.out_markdown
1.1+9-0regress/usr.bin/mandoc/mdoc/Dt/secsuffix.out_ascii
1.1+9-0regress/usr.bin/mandoc/mdoc/Dt/secsuffix.in
1.1+9-0regress/usr.bin/mandoc/man/TH/secsuffix.out_ascii
1.12+6-2regress/usr.bin/mandoc/mdoc/Dt/Makefile
1.1+6-0regress/usr.bin/mandoc/man/TH/secsuffix.in
+50-21 files not shown
+53-47 files

OpenBSD/src oNXiFxr — usr.bin/mandoc msec.c

   When converting a section identifier (for example, "1" or "1m") to
   a volume title (for example, "General Commands Manual" or "Maintenance
   Commands") and no exact match is found for the identifier, retry
   using only the first character of the identifier before giving up.

   For example, when using OpenBSD to format the Oracle Solaris ipmitool(1m)
   manual, which contains the line '.TH ipmitool 1m "29 June 2012"',
   use the section 1 volume title "General Commands Manual" rather
   than finding no title at all.  In general, this improves formatting
   of the page header line of manual pages using session suffixes that
   are not declared in msec.in on the formatting system.  That's useful
   everywhere for formatting foreign manual pages, but also for
   formatting native manuals on systems using many suffixes.

   I had this idea for a small improvement while looking at how FreeBSD
   customizes the companion file msec.in in their freebsd-src/contrib/mandoc
   directory.
VersionDeltaFile
1.14+21-2usr.bin/mandoc/msec.c
+21-21 files

OpenBSD/src Z4yOqkI — usr.bin/tmux screen-write.c window-visible.c

   Include menus when working out what parts of a pane are visible to avoid
   overwriting them, GitHub issue 5593.
VersionDeltaFile
1.6+76-87usr.bin/tmux/window-visible.c
1.298+30-9usr.bin/tmux/screen-write.c
+106-962 files

OpenBSD/src yG6iNCq — usr.bin/tmux cmd-display-message.c

   Modify display-message -c target-client to use the data relative to
   target-client, GitHub issue 5613 from Michael Grant.
VersionDeltaFile
1.67+4-6usr.bin/tmux/cmd-display-message.c
+4-61 files

OpenBSD/src 4UHrXAH — usr.bin/tmux options-table.c

   Quote session_alert in status-format[2], GitHub issue 5671.
VersionDeltaFile
1.248+3-3usr.bin/tmux/options-table.c
+3-31 files

OpenBSD/src rE7PRFL — usr.bin/tmux screen-write.c

   Only skip collecting text except for right margin when autowrap is off,
   from Jang-Ho Hwang.
VersionDeltaFile
1.297+7-2usr.bin/tmux/screen-write.c
+7-21 files

OpenBSD/src fTHiEbC — usr.sbin/rpki-client output-rtrx.c

   output-rtrx: place one brace on the proper line
VersionDeltaFile
1.7+2-3usr.sbin/rpki-client/output-rtrx.c
+2-31 files

OpenBSD/src hZaJrDQ — usr.bin/tmux spawn.c

   Change to the new working directory even if getcwd fails, GitHub issue 5658.
VersionDeltaFile
1.54+9-9usr.bin/tmux/spawn.c
+9-91 files

OpenBSD/src 2uHyEl0 — sys/dev/usb usb_subr.c

   sys/usb: validate USB endpoint and configuration lengths

   Reject undersized endpoint descriptors before accessing wMaxPacketSize;
   require wTotalLength to cover the configuration header and match the
   allocated size after the full fetch.

   Reported by Stuart Thomas

   OK: deraadt@
VersionDeltaFile
1.169+8-2sys/dev/usb/usb_subr.c
+8-21 files