NetBSD/src Zm0MSqs — doc CHANGES 3RDPARTY

   new OpenSSH
VersionDeltaFile
1.2264+3-3doc/3RDPARTY
1.3303+2-1doc/CHANGES
+5-42 files

NetBSD/src ENsI7wy — distrib/sets/lists/base shl.mi, distrib/sets/lists/debug shl.mi

   bump libssh for OpenSSH-10.6
VersionDeltaFile
1.1052+3-3distrib/sets/lists/base/shl.mi
1.416+2-2distrib/sets/lists/debug/shl.mi
+5-52 files

NetBSD/src or6zYdA — crypto/external/bsd/openssh/lib shlib_version Makefile

   bump, adjust syms and files
VersionDeltaFile
1.7+12-6crypto/external/bsd/openssh/lib/ssh.expsym
1.44+2-2crypto/external/bsd/openssh/lib/shlib_version
1.51+3-1crypto/external/bsd/openssh/lib/Makefile
+17-93 files

NetBSD/src wzms0dN — crypto/external/bsd/openssh/dist moduli.5 auth-pam.h

   put back added files
VersionDeltaFile
1.10+0-0crypto/external/bsd/openssh/dist/moduli.5
1.15+0-0crypto/external/bsd/openssh/dist/auth-pam.h
1.29+0-0crypto/external/bsd/openssh/dist/auth-pam.c
+0-03 files

NetBSD/src bfGeT3A — crypto/external/bsd/openssh/dist auth2-pubkey.c ssh.1

   Merge changes between OpenSSH-10.5 and OpenSSH-10.6
VersionDeltaFile
1.8+4,487-1,872crypto/external/bsd/openssh/dist/ed25519.c
1.4+182-52crypto/external/bsd/openssh/dist/misc-agent.c
1.50+114-66crypto/external/bsd/openssh/dist/channels.c
1.54+137-15crypto/external/bsd/openssh/dist/servconf.c
1.45+74-74crypto/external/bsd/openssh/dist/ssh.1
1.40+83-46crypto/external/bsd/openssh/dist/auth2-pubkey.c
+5,077-2,12571 files not shown
+6,144-2,63377 files

NetBSD/src UTogjjh — crypto/external/bsd/openssh/dist ssh.1 servconf.c

   Import OpeSSH-10.6 (previous was 10.5)

   OpenSSH 10.6 was released on 2026-10-06. It is available from the
   mirrors listed at https://www.openssh.com/.
   OpenSSH is a 100% complete SSH protocol 2.0 implementation and
   includes sftp client and server support.

   Recently the OpenSSH team have received a large number of security
   bug reports, many of which are findings from AI models or made with
   AI assistance. While many AI reports are determined not to have
   security impact when considered in the context of a realistic
   threat model, we very much welcome these reports, especially when
   combined with human triage, analysis, test-cases and particularly
   when accompanied by proposed fixes.

   ** We have seen a number of cases where a security bug identified
   ** by AI tools is subsequently independently discovered by a
   ** different researcher. This suggests that adversaries who do not
   ** report bugs to OSS projects are likely to be able to discover

    [334 lines not shown]
VersionDeltaFile
1.1.1.4+4,487-1,872crypto/external/bsd/openssh/dist/ed25519.c
1.1.1.4+265-174crypto/external/bsd/openssh/dist/ed25519.sh
1.1.1.3+182-52crypto/external/bsd/openssh/dist/misc-agent.c
1.1.1.42+113-64crypto/external/bsd/openssh/dist/channels.c
1.1.1.43+136-14crypto/external/bsd/openssh/dist/servconf.c
1.1.1.38+74-74crypto/external/bsd/openssh/dist/ssh.1
+5,257-2,25064 files not shown
+6,287-2,78070 files

NetBSD/src a3f1kkf — usr.sbin/wgconfig wgconfig.c

   usr/sbin/wgconfig: Increase ioctl buffer to 16384

   Previously, the buffer used for ioctl was 4096.  This worked for wg0
   configured for 7 hosts, but failed for 8, surely because the proplist
   to be returned was too big.  This is malloced and only in use for the
   duration of wgconfig, and thus of little consequence.

   One could improve this by doubling the allocation every failure and
   looping, or changing the kernel to report a needed length, but this
   change should help a lot of people.
VersionDeltaFile
1.8+3-3usr.sbin/wgconfig/wgconfig.c
+3-31 files

NetBSD/src nS7p0mN — libexec/httpd cgi-bozo.c

   httpd(8): Don't set the PWD environment for CGIs, just the actual
   working directory. This was based on a misunderstanding on my part.

   PR bin/58713 httpd: CGIs have wrong cwd
VersionDeltaFile
1.59+1-8libexec/httpd/cgi-bozo.c
+1-81 files

NetBSD/src lhAAyWd — doc CHANGES

   doc: last few weeks of changes
VersionDeltaFile
1.3302+18-2doc/CHANGES
+18-21 files

NetBSD/src swWRp06 — sys/arch/sparc64/sparc64 ofw_patch.c

   Remove misplaced break in V215 HDD GPIO case.
VersionDeltaFile
1.19+2-3sys/arch/sparc64/sparc64/ofw_patch.c
+2-31 files

NetBSD/src 0WX7do7 — sys/arch/aarch64/aarch64 cpufunc_asm_armv8.S, sys/arch/aarch64/include cpufunc.h

   aarch64: Add TLB invalidation functions for EL2.

   Add assembly implementations of three new EL2 TLB invalidation functions.
VersionDeltaFile
1.9+45-1sys/arch/aarch64/aarch64/cpufunc_asm_armv8.S
1.33+5-1sys/arch/aarch64/include/cpufunc.h
+50-22 files

NetBSD/src yMMDR11 — sys/arch/aarch64/include armreg.h

   aarch64: fix HPFAR_EL2_FIPA defines for various configurations

   HPFAR_EL2_FIPA is 36bits long when FEAT_D128 and FEAT_LPA aren't
   implemented, i.e. HPFAR_EL2[39:4]

   Add HPFAR_EL2_FIPA_LPA for when FEAT_D128 is not implemented and
   FEAT_LPA is.

   Provide HPFAR_EL2_FIPA_{D128_,LPA_,}BITS for the Faulting Intermediate
   Physical Address.

   Remove HPFAR_EL2_FIPA_BITSHIFT
VersionDeltaFile
1.82+8-4sys/arch/aarch64/include/armreg.h
+8-41 files

NetBSD/src Hw7AAmN — libexec/httpd cgi-bozo.c

   httpd(8): Per RFC 3875, set the PWD of child CGI processes to the
   location of the script that is being run.

   Right now this only works with the -c option (where previously PWD would
   have been unset in the child), processes invoked with -C already got a
   PWD, and the wrapper script can also handle setting it to something
   sensible.

   "looks good" mrg

   PR bin/58713 httpd: CGIs have wrong cwd
VersionDeltaFile
1.58+11-1libexec/httpd/cgi-bozo.c
+11-11 files

NetBSD/src NJVYRJQ — libexec/httpd bozohttpd.8

   bozohttpd.8: Clarify how the CGI options work.
VersionDeltaFile
1.103+11-6libexec/httpd/bozohttpd.8
+11-61 files

NetBSD/src CUbez9b — usr.bin/make/unit-tests varmod-mtime.mk cond-cmp-numeric-eq.mk

   tests/make: fix indentation of directives
VersionDeltaFile
1.10+3-3usr.bin/make/unit-tests/cond-cmp-numeric-eq.mk
1.18+2-2usr.bin/make/unit-tests/varmod-mtime.mk
+5-52 files

NetBSD/src O6ltIB5 — sys/fs/tmpfs tmpfs_mem.c

   PR kern/60601 - Avoid 32 bit wraparound on ILP32 hosts

   In tmpfs_bytes_max calculate avail_mem using 64 bit calculations,
   rather than one small piece being 32 bit only (and subject to
   simple overflow, entirely within reasonable values).

   Reported and diagnosed by Hashimoto Kenichi in PR kern/60601

   XXX - pullup -11 -10 (in a week or two).
VersionDeltaFile
1.15+4-3sys/fs/tmpfs/tmpfs_mem.c
+4-31 files

NetBSD/src VtlPZsD — share/locale/ctype zh_CN.GB18030.src

   zh_CN.GB18030 locale - fix reversed toupper/tolower mappings

   Correct reversed toupper/tolower mappings (MAPUPPER/MAPLOWER)
   MAPLOWER maps into lower case, MAPUPPER into upper case, not "from".
   While here add the (probably unneeded) identity toupper/tolower mappings.

   Reported by RVP@ in:
     https://mail-index.netbsd.org/tech-userlevel/2026/08/15/msg015003.html
VersionDeltaFile
1.3+5-3share/locale/ctype/zh_CN.GB18030.src
+5-31 files

NetBSD/src Fl7mZ42 — share/locale/ctype kk_KZ.PT154.src

   kk_KZ.PT154 locale: Add missing toupper/tolower mappings.

   This was missing a tolower mapping (MAPLOWER) from the lower case
   (ASCII) letters into themselves (which is required to work), and worse
   was also missing a toupper mapping (MAPUPPER) from the lower case (ASCII)
   letters into their upper case equivalents.

   Whether the actual (non ASCII) letter upper/lower mappings are all
   correct, I am not sure, but I very much doubt it.

   Detected and reported by RVP@ in:
    https://mail-index.netbsd.org/tech-userlevel/2026/08/15/msg015003.html
VersionDeltaFile
1.2+3-1share/locale/ctype/kk_KZ.PT154.src
+3-11 files

NetBSD/src DpAfWgR — share/mk bsd.own.mk

   bsd.own.mk: Respect USE_FORT even if defined after bsd.own.mk.

   Using (a chain of logic that boils down to)

   .if ${USE_FORT:Uno} != "no"
   CPPFLAGS+=   -D_FORTIFY_SOURCE=2
   .endif

   expands USE_FORT eagerly, so if USE_FORT was not already defined before
   including <bsd.own.mk>, it's too late after.

   Using (a chain of logic that boils down to)

   CPPFLAGS+=   ${${USE_FORT:Uno} != "no":?-D_FORTIFY_SOURCE=2:}

   expands USE_FORT lazily, so it's only when CPPFLAGS itself is expanded
   -- usually in a recipe, after all variable assignments, prerequisite
   lists, and .directives have been processed -- that USE_FORT is
   expanded.

    [9 lines not shown]
VersionDeltaFile
1.1488+2-4share/mk/bsd.own.mk
+2-41 files

NetBSD/src PjIc8Yu — lib/libc shlib_version

   libc: Add a note to shlib_version about nixing __ssp_protected_*.

   PR lib/60858: fortuitous embarrassment: fortify is all kinds of busted
VersionDeltaFile
1.302+2-1lib/libc/shlib_version
+2-11 files

NetBSD/src NUwjChS — include/ssp ssp.h, lib/libc/ssp ssp_redirect.c

   ssp.h: Stop creating references to useless __ssp_protected_* symbols.

   The ssp wrappers are useful _only_ when they are actually used for
   inline function call expansion; if the function is used for anything
   else like a function pointer, only the underlying library symbol
   should be used.

   To pacify linker complaints about spurious references to
   __ssp_protected_getcwd/read/readlink, we added equally spurious
   definitions of those symbols to libc without understanding why; it
   turns out it only happened because the ssp wrappers declared, e.g.:

   extern inline read(...) __RENAME(__ssp_protected_read);
   extern inline read(...) { <ssp check>; return __ssp_real_read(...); }

   The declaration with __RENAME caused the compiler to generate
   references, required by the linker to be resolved, to the symbol
   `__ssp_protected_read' when compiling code that takes the address of
   the function read() to pass around a function pointer.  Instead, the

    [15 lines not shown]
VersionDeltaFile
1.4+42-18lib/libc/ssp/ssp_redirect.c
1.17+1-2include/ssp/ssp.h
+43-202 files

NetBSD/src RASG13y — external/gpl2/texinfo/dist/lib system.h

   correct memchr() return
VersionDeltaFile
1.6+2-2external/gpl2/texinfo/dist/lib/system.h
+2-21 files

NetBSD/src 0t48DIW — external/gpl2/texinfo/dist/lib system.h

   PR/60859: Jan-Benedict-Glaw: Fill function prototypes to fix
   compiling issues with recent gcc on Debian unstable.
VersionDeltaFile
1.5+7-7external/gpl2/texinfo/dist/lib/system.h
+7-71 files

NetBSD/src N84j3Q2 — sys/arch/zaurus/conf GENERIC INSTALL

   zaurus: MOve COPTS="-Os" from INSTALL to GENERIC.

   INSTALL includes GENERIC, so no change to INSTALL.  But the reason
   for -Os (a size limitation of the bootloader, checked at build-time)
   appears to apply just as well to any kernel, not just INSTALL, and
   the recent change to flip on -ftrivial-auto-var-init bumped GENERIC
   over the limit too:

   Checking kernel size...
   Fatal: kernel size must be less than 5MB.
   Fatal: kernel size: 5247920, max kernel size: 5242880
   --- netbsd ---

   *** Failed target: netbsd
   *** In directory: /home/builds/ab/HEAD/zaurus/20261006081837Z-obj/home/source/ab/HEAD/src/sys/arch/zaurus/compile/GENERIC

   Setting COPTS="-Os" both tells the compiler to make smaller code, and
   turns off the -ftrivial-auto-var-init logic in Makefile.kern.inc,
   which with any luck should help fix the zaurus build.

    [2 lines not shown]
VersionDeltaFile
1.42+1-7sys/arch/zaurus/conf/INSTALL
1.98+6-1sys/arch/zaurus/conf/GENERIC
+7-82 files

NetBSD/src cH6iQ3P — doc 3RDPARTY

   openssh 10.6 out
VersionDeltaFile
1.2263+3-3doc/3RDPARTY
+3-31 files

NetBSD/src PShaCDH — sys/arch/mips/include intr.h, sys/arch/mips/mips spl_stubs.c

   mips: declare SPL stub functions in intr.h

   Move the .stub section attributes for the MIPS SPL functions from
   spl_stubs.c to intr.h, and add the splcheck declaration with __noubsan.
VersionDeltaFile
1.15+20-16sys/arch/mips/include/intr.h
1.4+2-19sys/arch/mips/mips/spl_stubs.c
+22-352 files

NetBSD/src VZ9qjVM — sys/conf Makefile.kern.inc

   sys: Disable -ftrivial-auto-var-init if -Os is in play.

   This should help avoid the code expansion that broke the zaurus and
   ews4800mips builds.

   PR kern/60839: use -ftrivial-auto-var-init
VersionDeltaFile
1.309+31-6sys/conf/Makefile.kern.inc
+31-61 files

NetBSD/src W5lBmlC — sys/kern sys_pipe.c

   pipe(2): Fix possible null pointer deref if pipe_create fails.

   Spotted by kre.

   Followup for:

   PR kern/59056: poll POLLHUP bugs
VersionDeltaFile
1.186+4-3sys/kern/sys_pipe.c
+4-31 files

NetBSD/src 3xTTLxS — sys/kern sys_pipe.c

   Pull up our braces.
VersionDeltaFile
1.185+3-3sys/kern/sys_pipe.c
+3-31 files

NetBSD/src SwIDa45 — sys/kern sys_pipe.c

   pipe(2): Fix possible use-after-free if both ends are closed at once.

   Followup for:

   PR kern/59056: poll POLLHUP bugs
VersionDeltaFile
1.184+29-7sys/kern/sys_pipe.c
+29-71 files