OpenBSD/ports YyaS8EEdatabases/py-peewee distinfo Makefile, databases/py-peewee/pkg PLIST

   update to py3-peewee-4.0.9
VersionDeltaFile
1.28+13-4databases/py-peewee/pkg/PLIST
1.20+2-2databases/py-peewee/distinfo
1.47+1-2databases/py-peewee/Makefile
+16-83 files

OpenBSD/src RuxIYOlusr.sbin/nsd configure config.h.in, usr.sbin/nsd/doc RELNOTES

   merge NSD 4.14.3 (why they regenerated autoconf files with an older version,
   I do not know...)
VersionDeltaFile
1.65+1,314-1,822usr.sbin/nsd/configure
1.2+804-373usr.sbin/nsd/simdzone/configure
1.48+115-125usr.sbin/nsd/config.h.in
1.6+77-147usr.sbin/nsd/config.sub
1.6+22-75usr.sbin/nsd/config.guess
1.20+25-0usr.sbin/nsd/doc/RELNOTES
+2,357-2,54210 files not shown
+2,403-2,57316 files

OpenBSD/ports 3210UK7textproc/ktextaddons Makefile distinfo, textproc/ktextaddons/pkg PLIST

   Update ktextaddons to 2.1.0
VersionDeltaFile
1.13+393-26textproc/ktextaddons/pkg/PLIST
1.14+10-3textproc/ktextaddons/Makefile
1.13+2-2textproc/ktextaddons/distinfo
+405-313 files

OpenBSD/src jHlrFekusr.sbin/nsd configure config.h.in, usr.sbin/nsd/simdzone configure config.sub

   import NSD 4.14.3
VersionDeltaFile
1.1.1.30+1,311-1,819usr.sbin/nsd/configure
1.1.1.4+331-410usr.sbin/nsd/simdzone/configure
1.1.1.27+115-125usr.sbin/nsd/config.h.in
1.1.1.3+77-147usr.sbin/nsd/simdzone/config.sub
1.1.1.4+77-147usr.sbin/nsd/config.sub
1.1.1.4+22-75usr.sbin/nsd/config.guess
+1,933-2,72317 files not shown
+2,084-2,84523 files

OpenBSD/ports J9ofVyXsecurity/p5-Crypt-OpenSSL-X509 distinfo Makefile

   update p5-Crypt-OpenSSL-X509 to 2.1.2
VersionDeltaFile
1.15+2-2security/p5-Crypt-OpenSSL-X509/distinfo
1.22+1-1security/p5-Crypt-OpenSSL-X509/Makefile
+3-32 files

OpenBSD/src RM3CucEusr.sbin/nsd options.c rdata.c

   Fix CVE-2026-12244, CVE-2026-12245, CVE-2026-12246 and CVE-2026-12490

   - CVE-2026-12244: A specially crafted SVCB RR can cause a heap
     overflow of up to 65509 attacker controlled bytes.
   - CVE-2026-12245: If NSD is configured with DNS over TLS, a
     client that performs a TLS action, closing the connection early,
     causes a crash and restart of the server process. An attacker can
     keep all children in a crash-restart loop denying DoT service.
   - CVE-2026-12246: The RR type APL rdata address, if too large,
     causes out of bounds write on the stack, when the zonefile is written
     out.
   - CVE-2026-12490: Secondaries authenticated by a client
     certificate to transfer a zone over TLS, can bypass verification by
     transferring over TCP.

   OK sthen
VersionDeltaFile
1.34+36-6usr.sbin/nsd/options.c
1.21+15-4usr.sbin/nsd/rdata.c
1.55+1-1usr.sbin/nsd/nsd.conf.5.in
1.57+1-1usr.sbin/nsd/server.c
1.33+1-0usr.sbin/nsd/options.h
+54-125 files

OpenBSD/ports IeMnjjiwww/p5-HTTP-Date distinfo Makefile

   update p5-HTTP-Date to 6.07
VersionDeltaFile
1.3+2-2www/p5-HTTP-Date/distinfo
1.7+2-1www/p5-HTTP-Date/Makefile
+4-32 files

OpenBSD/src OdH8Qajusr.bin/tmux window-client.c window-tree.c

   Another couple of bits look nicer in grey.
VersionDeltaFile
1.45+20-20usr.bin/tmux/window-client.c
1.86+4-4usr.bin/tmux/window-tree.c
+24-242 files

OpenBSD/src rt5unRHusr.bin/tmux mode-tree.c window-client.c

   Apply better colours to various builtin bits in modes.
VersionDeltaFile
1.93+165-91usr.bin/tmux/mode-tree.c
1.44+77-50usr.bin/tmux/window-client.c
1.85+62-35usr.bin/tmux/window-tree.c
1.28+21-12usr.bin/tmux/window-customize.c
1.49+15-8usr.bin/tmux/window-buffer.c
1.223+14-5usr.bin/tmux/options-table.c
+354-2013 files not shown
+373-2079 files

OpenBSD/src UIeL0U4usr.sbin/rpki-client filemode.c parser.c

   Some more #include consistency.

   Prompted by job
VersionDeltaFile
1.84+2-2usr.sbin/rpki-client/filemode.c
1.182+2-2usr.sbin/rpki-client/parser.c
1.87+2-2usr.sbin/rpki-client/repo.c
1.105+2-1usr.sbin/rpki-client/http.c
+8-74 files

OpenBSD/src sqineuLusr.sbin/rpki-client nca.c

   nca.c: more missing includes

   sys/types.h for ssize_t, stdlib.h for *alloc/free and stdio.h for fprintf.

   ok job
VersionDeltaFile
1.4+4-1usr.sbin/rpki-client/nca.c
+4-11 files

OpenBSD/ports TLgZuuvtextproc/p5-List-SomeUtils-XS Makefile distinfo, textproc/p5-List-SomeUtils-XS/pkg PLIST

   update p5-List-SomeUtils-XS to 0.59
   CVE-2026-12844
VersionDeltaFile
1.8+6-6textproc/p5-List-SomeUtils-XS/Makefile
1.4+2-2textproc/p5-List-SomeUtils-XS/distinfo
1.3+1-1textproc/p5-List-SomeUtils-XS/pkg/PLIST
+9-93 files

OpenBSD/src ZAQD8mnusr.sbin/rpki-client nca.c

   Fix includes for -portable

   OK tb@
VersionDeltaFile
1.3+3-3usr.sbin/rpki-client/nca.c
+3-31 files

OpenBSD/ports 1cJ46Fpdatabases/sqlcipher Makefile

   databases/sqlcipher: add column metadata and unlock notify extensions

   as discussed with and ok tb@ to enable future net/flare-messenger updates
VersionDeltaFile
1.22+5-2databases/sqlcipher/Makefile
+5-21 files

OpenBSD/ports RZhPMfudevel/qbs Makefile distinfo, devel/qbs/pkg PLIST

   Update qbs to 3.3.0
VersionDeltaFile
1.49+2-2devel/qbs/Makefile
1.36+2-2devel/qbs/distinfo
1.27+1-0devel/qbs/pkg/PLIST
+5-43 files

OpenBSD/src 09CyNYIusr.sbin/radiusd radiusd.c

   Fixed a null dereference when authentication-filter and configured and
   pap is used.   diff from iij.
VersionDeltaFile
1.63+2-2usr.sbin/radiusd/radiusd.c
+2-21 files

OpenBSD/ports vuMLzLicomms/gnuradio Makefile, comms/gnuradio/patches patch-cmake_Modules_GnuradioConfig_cmake_in

   fix some boost 1.91 update fallout, to allow dependent ports to build

   OK tb@
VersionDeltaFile
1.1+12-0comms/gnuradio/patches/patch-cmake_Modules_GnuradioConfig_cmake_in
1.32+1-1comms/gnuradio/Makefile
+13-12 files

OpenBSD/ports T7CVai6x11/kde-plasma/kdeplasma-addons distinfo crates.inc, x11/kde-plasma/kdeplasma-addons/files cxxbridge-cargo.lock

   Update KDE Plasma to 6.7.1

   Upstream has meraged almost all of our OpenBSD-related PRs.

   https://kde.org/announcements/plasma/6/6.7.0/
VersionDeltaFile
1.1+601-0x11/kde-plasma/kdeplasma-addons/files/cxxbridge-cargo.lock
1.34+328-2x11/kde-plasma/kdeplasma-addons/distinfo
1.1+164-0x11/kde-plasma/kdeplasma-addons/crates.inc
1.18+117-6x11/kde-plasma/oxygen/pkg/PLIST
1.26+58-54x11/kde-plasma/plasma-workspace/pkg/PLIST
1.23+47-5x11/kde-plasma/kdeplasma-addons/Makefile
+1,315-6797 files not shown
+1,642-309103 files

OpenBSD/src CPpxbg0usr.bin/ssh ssh-keyscan.1

   mention that ssh-keyscan output is only as trustworthy as the
   network between it and the SSH server; ok markus@
VersionDeltaFile
1.54+11-2usr.bin/ssh/ssh-keyscan.1
+11-21 files

OpenBSD/ports K4r2Gejcomms/libhidapi Makefile distinfo, comms/libhidapi/patches patch-libusb_hid_c patch-README_md

   Update libhidapi to 0.15.0
VersionDeltaFile
1.4+4-4comms/libhidapi/patches/patch-libusb_hid_c
1.13+3-5comms/libhidapi/Makefile
1.3+2-2comms/libhidapi/distinfo
1.2+1-1comms/libhidapi/patches/patch-README_md
1.4+1-1comms/libhidapi/patches/patch-hidapi_hidapi_h
1.2+1-1comms/libhidapi/patches/patch-hidtest_test_c
+12-146 files

OpenBSD/src ufjGkQMlib/libc/asr getaddrinfo_async.c

   Return statically built addresses when hostname == NULL  It always
   returns IPv4 and IPv6 addresses when hostname == NULL; previously, it
   returned only the address of the selected address family defined by
   "family" in resolv.conf.

   ok florian
VersionDeltaFile
1.69+38-44lib/libc/asr/getaddrinfo_async.c
+38-441 files

OpenBSD/src 2tAcTS4regress/lib/libcrypto/x509 Makefile

   With x509_vfy.c 1.153, the x509_crl regress passes
VersionDeltaFile
1.29+1-3regress/lib/libcrypto/x509/Makefile
+1-31 files

OpenBSD/src qvUatWrlib/libcrypto/x509 x509_vfy.c

   x509_vfy: sync get_crl_sk() with BoringSSL and OpenSSL

   Among CRLs with the same score prefer the one with the most recent
   lastUpdate (RFC 5280 thisUpdate). This pulls in OpenSSL commits
   626aa248, e032117d, 8b7c51a0 from 2016, so before the license change.
   This uses the annoying ASN1_TIME_diff() API, but there is no better
   way, really. Every other ASN1_TIME API will be just as awkward.

   This fixes the currently failing x509_crl test cases.

   ok kenjiro
VersionDeltaFile
1.153+18-6lib/libcrypto/x509/x509_vfy.c
+18-61 files

OpenBSD/src SaIW5tsregress/lib/libcrypto/x509 Makefile x509_crl.c

   x509_crl regress: enable the failing test and mark as XFAIL
VersionDeltaFile
1.28+3-1regress/lib/libcrypto/x509/Makefile
1.2+1-3regress/lib/libcrypto/x509/x509_crl.c
+4-42 files

OpenBSD/ports Bqn19n2www/chromium/patches patch-v8_src_objects_simd_cc, www/iridium/patches patch-v8_src_objects_simd_cc

   unbreak build on arm64 until the compiler is actually fixed

   fatal error: error in backend: Cannot implicitly convert a scalable size to a fixed-width size in `TypeSize::operator ScalarTy()`
   clang++: error: clang frontend command failed with exit code 70 (use -v to see invocation)
VersionDeltaFile
1.3+22-94www/chromium/patches/patch-v8_src_objects_simd_cc
1.1+28-0www/ungoogled-chromium/patches/patch-v8_src_objects_simd_cc
1.1+28-0www/iridium/patches/patch-v8_src_objects_simd_cc
+78-943 files

OpenBSD/src 1Aug5JBsbin/iked radius.c

   Prevent authenticated RADIUS CP attribute mapping overflowing rr_cfg.
   Reported by / the original diff from Andrew Griffiths

   ok markus
VersionDeltaFile
1.15+28-13sbin/iked/radius.c
+28-131 files

OpenBSD/ports WzKejamsecurity/rust-openssl-tests distinfo crates.inc

   Update to rust-openssl-tests 20260626
VersionDeltaFile
1.210+10-10security/rust-openssl-tests/distinfo
1.172+4-4security/rust-openssl-tests/crates.inc
1.218+2-2security/rust-openssl-tests/Makefile
+16-163 files

OpenBSD/ports UGOd1XJsecurity/openssl-ruby-tests Makefile distinfo

   Update to openssl-ruby-tests 20260625
VersionDeltaFile
1.168+2-2security/openssl-ruby-tests/Makefile
1.147+2-2security/openssl-ruby-tests/distinfo
+4-42 files

OpenBSD/ports 8HtycvOsecurity/wycheproof Makefile distinfo

   Update to wycheproof 20260625
VersionDeltaFile
1.9+2-2security/wycheproof/Makefile
1.9+2-2security/wycheproof/distinfo
+4-42 files

OpenBSD/src Qh039bBlib/libc/asr getaddrinfo_async.c

   Make getaddrinfo(3) check hnok_lenient() earlier.

   r1.60 added special handling for localhost names; this was done before the
   hnok_lenient() check, ensure this validation applies to localhost names too.

   ok florian
VersionDeltaFile
1.68+12-9lib/libc/asr/getaddrinfo_async.c
+12-91 files