OpenBSD/src r6WfOCYusr.bin/mandoc manpath.c

   avoid needlessly discarding a const qualifier in a pointer assignment;
   no functional change; small ugliness found in a build log
   sent in by Xose Vazquez Perez <xose.vazquez at gmail.com>
VersionDeltaFile
1.35+5-5usr.bin/mandoc/manpath.c
+5-51 files

OpenBSD/src qjPMSIgsys/dev/pci/drm/i915 i915_driver.c, sys/dev/pci/drm/i915/display intel_display_device.c

   read gmd_id slightly later to avoid mapping pci bar twice
VersionDeltaFile
1.35+16-16sys/dev/pci/drm/i915/i915_driver.c
1.6+2-16sys/dev/pci/drm/i915/display/intel_display_device.c
+18-322 files

OpenBSD/src Gt9xTrcusr.sbin/ldpd ldpd.c lde.c

   Handle IMSG_CTL_LOG_VERBOSE like bgpd with imsg_get_data instead of an
   unchecked memcpy.

   OK tb@
VersionDeltaFile
1.82+6-4usr.sbin/ldpd/ldpd.c
1.87+6-4usr.sbin/ldpd/lde.c
+12-82 files

OpenBSD/src 31rUXs4usr.sbin/ripd ripd.c rde.c

   Handle IMSG_CTL_LOG_VERBOSE like bgpd with imsg_get_data instead of an
   unchecked memcpy.

   OK tb@
VersionDeltaFile
1.47+6-4usr.sbin/ripd/ripd.c
1.34+6-4usr.sbin/ripd/rde.c
+12-82 files

OpenBSD/src f4EACuHusr.sbin/ospf6d rde.c ospf6d.c

   Handle IMSG_CTL_LOG_VERBOSE like bgpd with imsg_get_data instead of an
   unchecked memcpy.

   OK tb@
VersionDeltaFile
1.100+6-4usr.sbin/ospf6d/rde.c
1.64+6-4usr.sbin/ospf6d/ospf6d.c
+12-82 files

OpenBSD/src 50zEOunusr.sbin/ospfd rde.c ospfd.c

   Handle IMSG_CTL_LOG_VERBOSE like bgpd with imsg_get_data instead of an
   unchecked memcpy.

   OK tb@
VersionDeltaFile
1.122+6-4usr.sbin/ospfd/rde.c
1.128+6-4usr.sbin/ospfd/ospfd.c
+12-82 files

OpenBSD/src 1sOINz3usr.sbin/dvmrpd rde.c dvmrpd.c

   Handle IMSG_CTL_LOG_VERBOSE like bgpd with imsg_get_data instead of an
   unchecked memcpy.

   Reported by Shibo, Hugo Systopia Team
   OK tb@
VersionDeltaFile
1.42+6-4usr.sbin/dvmrpd/rde.c
1.37+6-4usr.sbin/dvmrpd/dvmrpd.c
+12-82 files

OpenBSD/src 79AMjwHusr.bin/tmux client.c tmux.h

   If writing a file fails, propagate the error to the server via a new
   message. Use a client flag rather than bumping the protocol version.
   GitHub issue 5451.
VersionDeltaFile
1.22+68-18usr.bin/tmux/file.c
1.3+8-2usr.bin/tmux/tmux-protocol.h
1.503+5-1usr.bin/tmux/server-client.c
1.1423+3-2usr.bin/tmux/tmux.h
1.167+2-2usr.bin/tmux/client.c
+86-255 files

OpenBSD/src nDVjWvBusr.bin/tmux tty-keys.c tty-features.c

   Add default terminal features for Rio, GitHub issue 5489 from Raphael
   Amorim.
VersionDeltaFile
1.41+13-1usr.bin/tmux/tty-features.c
1.212+3-1usr.bin/tmux/tty-keys.c
+16-22 files

OpenBSD/src g6UVwNlusr.bin/tmux menu.c

   Remove flags from both keys for menus, GitHub issue 5484.
VersionDeltaFile
1.70+4-2usr.bin/tmux/menu.c
+4-21 files

OpenBSD/src NDk3bNlusr.bin/tmux cmd-break-pane.c

   Attach window to session earlier so resize cannot cause customize mode
   to blow up. Reported by Marcel Partap.
VersionDeltaFile
1.76+5-4usr.bin/tmux/cmd-break-pane.c
+5-41 files

OpenBSD/src pxQSEUOusr.bin/tmux prompt.c

   Do not copy too many positions when deleting, GitHub issue 5478 from
   Uzair Aftab.
VersionDeltaFile
1.6+2-2usr.bin/tmux/prompt.c
+2-21 files

OpenBSD/src 6RsQoYhshare/man/man7 roff.7

   ourput -> output
VersionDeltaFile
1.107+2-2share/man/man7/roff.7
+2-21 files

OpenBSD/src yOpor9yusr.bin/sndiod midi.c

   correct test for non-NULL; ok ratchov@
VersionDeltaFile
1.46+2-2usr.bin/sndiod/midi.c
+2-21 files

OpenBSD/src hyeQFctshare/man/man7 roff.7, usr.bin/mandoc roff.h roff.c

   Ignore various roff(7) requests that are new in groff-1.23 and groff-1.24.
   Most of these only serve debugging purposes, and some are related to
   features that are not relevant in manual pages and that we do not support
   in the first place.

   Two special cases are notable: .msoquiet is ignored because insecure
   (just like .mso already was), and .soquiet is treated as an exact
   alias for .so, without suppressing any diagnostics, because in manual
   pages, missing include files are never harmless.

   List of requests that needed checking provided by G. Branden Robinson.
VersionDeltaFile
1.106+46-4share/man/man7/roff.7
1.279+23-10usr.bin/mandoc/roff.c
1.60+13-2usr.bin/mandoc/roff.h
+82-163 files

OpenBSD/src MLpze73regress/lib/libm/lgamma lgamma.c

   regress/lib/libmlgamma: remove no longer needed __POSIX_VISIBLE 201403

   These days we default to POSIX 2024 with XSI extensions. The original define
   was only needed when our default was POSIX 2008 and we needed to advance to
   a newer standard to run this test.
VersionDeltaFile
1.4+1-4regress/lib/libm/lgamma/lgamma.c
+1-41 files

OpenBSD/src H9pmgTgregress/usr.bin/mandoc/roff/string stringup.out_utf8 stringup.out_ascii, share/man/man7 roff.7

   groff-1.23.0 invented new roff(7) requests .stringup and .stringdown that
   change the case of the named user-defined string in place.  I haven't seen
   them used in any manual page yet and - like for all roff(7) requests - do
   not recommend using them, but i chose to implement them anyway because that
   was almost as trivial as it would have been to mark them as unsupported.

   G. Branden Robinson reminded me of the new feature.
VersionDeltaFile
1.278+33-2usr.bin/mandoc/roff.c
1.105+15-2share/man/man7/roff.7
1.11+11-5regress/usr.bin/mandoc/roff/string/Makefile
1.1+16-0regress/usr.bin/mandoc/roff/string/stringup.in
1.1+9-0regress/usr.bin/mandoc/roff/string/stringup.out_utf8
1.1+9-0regress/usr.bin/mandoc/roff/string/stringup.out_ascii
+93-94 files not shown
+114-1010 files

OpenBSD/src ZWVfJXLusr.bin/mandoc manpath.c

   Stop clobbering the return value of getenv(3) with strtok(3).
   The getenv(3) manual discourages tampering with the returned string.
   Instead, copy the value to the heap such that it can be safely modified.

   This fixes a bug that Luca Del Re <l.osd at ldr.name>
   found on Alpine Linux and reported to bsd.lv.

   The consequence of the bug was likely implementation-dependent, but
   on both OpenBSD and Alpine Linux, the first colon after the first
   byte of the MANPATH variable was set to NUL in the actual environment
   of the man(1) process, and this truncated value would later be
   passed to the pager child process by execv(3).  Hence, while
   MANPATH=:mypath1 worked as expected, the pager would only see
   MANPATH=mypath1 if man(1) saw any of the following:
   MANPATH=mypath1:
   MANPATH=mypath1:mypath2
   MANPATH=mypath1::mypath2
VersionDeltaFile
1.34+22-16usr.bin/mandoc/manpath.c
+22-161 files

OpenBSD/src RQvhqQVsys/kern kern_pledge.c

   Don't panic if ni_pledge is unset in pledge_namei.

   ok deraadt
VersionDeltaFile
1.360+2-2sys/kern/kern_pledge.c
+2-21 files

OpenBSD/src vHXtXv5sys/kern vfs_syscalls.c

   Consistently guard against NULL vp->v_mount in vfs_syscalls.c

   OK kirill@

   Reported-by: syzbot+5c4d0d721f4b850a14d6 at syzkaller.appspotmail.com
VersionDeltaFile
1.388+7-7sys/kern/vfs_syscalls.c
+7-71 files

OpenBSD/src vZZn2gKsys/dev/usb usb_subr.c

   Trim trailing \n from usb descriptor strings

   deraadt@ "I like this"
VersionDeltaFile
1.167+6-4sys/dev/usb/usb_subr.c
+6-41 files

OpenBSD/src A7Afikqsys/kern exec_subr.c

   A specially crafted ELF interpreter binary can trigger a KASSERT() in
   vmcmd_map_readvn().  While this points at some deficiencies in
   elf_load_file(), we have no intention to supporting such weirdly crafted
   binaries (even if they're technically valid).  So return EINVAL instead.

   ok deraadt@
VersionDeltaFile
1.72+3-2sys/kern/exec_subr.c
+3-21 files

OpenBSD/src W7vry7fgnu/usr.bin/binutils-2.17/bfd libbfd.h bfd-in2.h, gnu/usr.bin/binutils-2.17/include/elf sparc.h

   ld.bfd: add SPARC64 GOTDATA relocation support

   Tested and feedback by claudio@

   OK: kettenis@
VersionDeltaFile
1.8+53-9gnu/usr.bin/binutils-2.17/bfd/elfxx-sparc.c
1.5+10-0gnu/usr.bin/binutils-2.17/bfd/reloc.c
1.2+6-0gnu/usr.bin/binutils-2.17/include/elf/sparc.h
1.9+5-0gnu/usr.bin/binutils-2.17/bfd/libbfd.h
1.13+5-0gnu/usr.bin/binutils-2.17/bfd/bfd-in2.h
+79-95 files

OpenBSD/src dSTYjwtsys/kern tty.c

   TIOCGSID can dereference a freed t_session, because we are storing s_leader
   in the wrong place.  This is a cold hard crash crashes.  Some folk are
   looking at fixing this properly but it will take some time, so in the meantime
   we should just fail the ioctl.
   From Acts1632, ok kettenis
VersionDeltaFile
1.185+3-1sys/kern/tty.c
+3-11 files

OpenBSD/src oOiNnExbin/ksh vi.c

   ksh: allow editing empty line with 'v' in vi-mode

   ok tb@
VersionDeltaFile
1.71+1-3bin/ksh/vi.c
+1-31 files

OpenBSD/src on662UGsys/arch/arm64/dev aplns.c simplebus.c

   Specify the correct "read" and "write" bits to the NVMMU based on the
   opcode of the NVMe command.  Drop the opcode itself, since it isn't needed.
   This allows us to drop the magic "null check" bit that is no longer
   supported by the firmware that Apple ships with newer macOS releases.
   Based on work done by Sven Peter over at Asahi Linux.

   ok jmatthew@
VersionDeltaFile
1.24+59-1sys/arch/arm64/dev/simplebus.c
1.20+5-9sys/arch/arm64/dev/aplns.c
+64-102 files

OpenBSD/src yHN4jWAusr.bin/ssh sshd.8

   Refer to id_mldsa44_ed25519.pub in the pubkey list. bz#3989.
VersionDeltaFile
1.331+3-3usr.bin/ssh/sshd.8
+3-31 files

OpenBSD/src EgCIGaagnu/usr.bin/perl regexp.h regexec.c

   Fix out-of-bounds heap reads and writes in perl regex

   Perl versions through 5.45.1 have out-of-bounds heap reads and writes
   during regular expression matching via an undersized superlinear cache
   in S_regmatch

   This is CVE-2026-15534

   https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0
   https://github.com/Perl/perl5/commit/54cf3d44cbbedd17d774e9a37921963e8fd5d0cb
VersionDeltaFile
1.33+19-12gnu/usr.bin/perl/regexec.c
1.22+2-2gnu/usr.bin/perl/regexp.h
+21-142 files

OpenBSD/src J6FEI0ksys/dev/fdt dwpcie.c

   Add support for the Spacemit K3 PCIe controller.
VersionDeltaFile
1.64+140-11sys/dev/fdt/dwpcie.c
+140-111 files

OpenBSD/src SCmKL3Rsys/arch/riscv64/dev smtcomphy.c

   Add support for the K3 PCIe/USB3 combo PHY.
VersionDeltaFile
1.4+172-4sys/arch/riscv64/dev/smtcomphy.c
+172-41 files