OpenBSD/ports loKkDbFdevel/py-pip distinfo Makefile, devel/py-pip/pkg PLIST

   update to py3-pip-26.2
VersionDeltaFile
1.42+34-3devel/py-pip/pkg/PLIST
1.50+2-2devel/py-pip/distinfo
1.84+3-1devel/py-pip/Makefile
+39-63 files

OpenBSD/ports YIeiW8hwww/librewolf Makefile distinfo, www/librewolf/patches patch-lw_policies_json

   www/librewolf: update to 153.0.1-1, from yaydn
VersionDeltaFile
1.7+2-2www/librewolf/distinfo
1.5+1-1www/librewolf/patches/patch-lw_policies_json
1.7+1-1www/librewolf/Makefile
+4-43 files

OpenBSD/ports kepjMTcmail/stalwart crates.inc distinfo, mail/stalwart/patches patch-tests_src_lib_rs patch-tests_Cargo_toml

   mail/stalwart: update to 0.16.15.

   see:
   https://github.com/stalwartlabs/stalwart/releases/tag/v0.16.15
   https://github.com/stalwartlabs/stalwart/releases/tag/v0.16.14
   https://github.com/stalwartlabs/stalwart/releases/tag/v0.16.13
   https://github.com/stalwartlabs/stalwart/releases/tag/v0.16.12
VersionDeltaFile
1.28+298-310mail/stalwart/distinfo
1.25+149-154mail/stalwart/crates.inc
1.2+8-8mail/stalwart/patches/patch-crates_jmap_src_registry_mapping_bootstrap_rs
1.6+4-4mail/stalwart/patches/patch-tests_src_lib_rs
1.11+4-4mail/stalwart/patches/patch-tests_Cargo_toml
1.11+4-4mail/stalwart/patches/patch-crates_main_src_main_rs
+467-4844 files not shown
+472-48910 files

OpenBSD/src 5xjCgItusr.sbin/lpd proc.c

   Convert imsg_get to imsgbuf_get. lpd is currently not built still lets
   fix it now.
VersionDeltaFile
1.8+4-4usr.sbin/lpd/proc.c
+4-41 files

OpenBSD/src LxgjNn0usr.sbin/lpd engine_lpr.c

   Fix some compiler warnings. Both times a variable is assigned to but never
   used.
VersionDeltaFile
1.3+2-5usr.sbin/lpd/engine_lpr.c
+2-51 files

OpenBSD/src u1JWsgAusr.bin/ftp fetch.c

   Print TLS and short read errors to stderr and not stdout

   Code paths that are not only used in interactive mode should log to
   stderr. Adjust some TLS and a short file read error to use warnx.

   Diff by Pontus Stenetorp (pontus at stenetorp dot se)
   OK deraadt@ tb@
VersionDeltaFile
1.223+6-7usr.bin/ftp/fetch.c
+6-71 files

OpenBSD/src VfB4IwMlib/libutil imsg-buffer.c

   let's fix some lets
   OK tb@
VersionDeltaFile
1.40+4-4lib/libutil/imsg-buffer.c
+4-41 files

OpenBSD/src 1HUiuzXlib/libutil imsg-buffer.c

   Correct EMSGSIZE handling in msgbuf_read to retry without control message

   In msgbuf_read() the EMSGSIZE handling needs to retry without the control
   buffer so that the message is read without the fd and forcing the kernel
   to close the buffer). Else the call will fail immediatly again and the
   system will busy loop.

   OK tb@
VersionDeltaFile
1.39+8-4lib/libutil/imsg-buffer.c
+8-41 files

OpenBSD/src C2Rqu8dlib/libutil imsg-buffer.c

   Change overflow check in ibuf_get_strbuf

   ibuf_get_strbuf is too picky about the terminating NUL byte.
   If the sender did not use ibuf_add_strbuf() then the buffer may
   not be padded with 0 at the end. This triggers the EOVERFLOW case
   even though the string is probably short enough.

   Make ibuf_get_strbuf more robust by checking the string length.
   If the string is shorter than the buffer pad the rest with 0. On
   overflow force a '\0' byte at the end and return EOVERFLOW.

   OK tb@
VersionDeltaFile
1.38+8-3lib/libutil/imsg-buffer.c
+8-31 files

OpenBSD/src FYhJqWKusr.sbin/ospfd neighbor.c

   Rewrite the XXX comment in nbr_act_delete() to be more clear on why the
   crypt_seq_num is reset here.
VersionDeltaFile
1.52+8-2usr.sbin/ospfd/neighbor.c
+8-21 files

OpenBSD/ports NwNCMFtgeo/pygeoapi Makefile distinfo, geo/pygeoapi/pkg PLIST

   geo/pygeoapi: update to 0.24.0

   see https://github.com/geopython/pygeoapi/releases/tag/0.24.0
VersionDeltaFile
1.21+2-2geo/pygeoapi/distinfo
1.24+4-0geo/pygeoapi/pkg/PLIST
1.38+1-1geo/pygeoapi/Makefile
+7-33 files

OpenBSD/src ilpQRO3usr.sbin/relayctl relayctl.8

   relayctl.8: name|id is required, not optional

   OK kirill@
VersionDeltaFile
1.34+8-8usr.sbin/relayctl/relayctl.8
+8-81 files

OpenBSD/src UZJBYKmusr.sbin/relayctl relayctl.c

   relayctl: switch to imsg_get_* API

   Use imsg_get_data() with size validation instead of casting imsg->data
   directly and imsg_get_type/len/id/pid() instead of imsg->hdr.* acc

   Structs like rdr/table/host.... carry embedded string buffers like name, label.
   When such a struct crosses a privilege boundary the receiver cannot Structs
   that the string is actually NUL terminated, so force a '\0' in the last byte
   after imsg_get_data(). Not strictly required here because relayd is the sender,
   but a good habit for imsg consumers.

   embedded string buffer hint by claudio@, OK claudio@
VersionDeltaFile
1.66+82-64usr.sbin/relayctl/relayctl.c
+82-641 files

OpenBSD/src bX94seZshare/misc zipcodes

   more zip codes for Frisco TX and Mechanicsburg PA
   from Tim Chase
VersionDeltaFile
1.15+5-1share/misc/zipcodes
+5-11 files

OpenBSD/ports GWQK8HLnet/monitoring-plugins Makefile distinfo, net/monitoring-plugins/patches patch-plugins_check_ntp_time_c patch-plugins_check_snmp_d_check_snmp_helpers_c

   update to monitoring-plugins-3.0.2, from Alvar Penning
VersionDeltaFile
1.3+2-2net/monitoring-plugins/patches/patch-plugins_check_snmp_d_check_snmp_helpers_c
1.20+2-2net/monitoring-plugins/distinfo
1.63+1-1net/monitoring-plugins/Makefile
1.5+0-0net/monitoring-plugins/patches/patch-plugins_check_ntp_time_c
+5-54 files

OpenBSD/ports JtephoWsysutils/terragrunt Makefile distinfo

   Update to terragrunt-1.1.2.
VersionDeltaFile
1.114+727-696sysutils/terragrunt/modules.inc
1.397+296-198sysutils/terragrunt/distinfo
1.404+1-1sysutils/terragrunt/Makefile
+1,024-8953 files

OpenBSD/src pitkWxhusr.bin/ssh ssh-mldsa-eddsa.c

   Use ssh_mldsa44_ed25519_cleanup consistently to avoid calling freezero with the wrong size.

   With help from tb@

   ok tb, dtucker@
VersionDeltaFile
1.4+4-11usr.bin/ssh/ssh-mldsa-eddsa.c
+4-111 files

OpenBSD/ports J9v3JZEsysutils/gemini-cli Makefile distinfo, sysutils/gemini-cli/pkg PLIST

   Update to gemini-cli-0.53.0.
VersionDeltaFile
1.33+48-48sysutils/gemini-cli/pkg/PLIST
1.34+2-2sysutils/gemini-cli/distinfo
1.36+1-1sysutils/gemini-cli/Makefile
+51-513 files

OpenBSD/src rfuH5ozusr.bin/ssh kexmlkem768ecdh.c

   Fix $OpenBSD marker for easier syncing.
VersionDeltaFile
1.3+1-1usr.bin/ssh/kexmlkem768ecdh.c
+1-11 files

OpenBSD/ports MBayIGndevel/glib2 distinfo Makefile, devel/glib2/pkg PLIST

   Update to glib2-2.88.3.
VersionDeltaFile
1.415+7-7devel/glib2/Makefile
1.146+2-2devel/glib2/pkg/PLIST
1.192+2-2devel/glib2/distinfo
+11-113 files

OpenBSD/src zvT58Ovusr.bin/ssh kexmlkem768ecdh.c kexgen.c

   Make mlkem768ecdh build with OPENSSL=no.  ok djm@
VersionDeltaFile
1.14+12-12usr.bin/ssh/kexgen.c
1.2+2-0usr.bin/ssh/kexmlkem768ecdh.c
+14-122 files

OpenBSD/ports mGnxParx11/xfce4/xfce4-panel Makefile distinfo, x11/xfce4/xfce4-panel/pkg PLIST

   x11/xfce4/xfce4-panel: update to 4.20.8.

   see https://gitlab.xfce.org/xfce/xfce4-panel/-/raw/xfce4-panel-4.20.8/NEWS
VersionDeltaFile
1.49+2-2x11/xfce4/xfce4-panel/distinfo
1.44+4-0x11/xfce4/xfce4-panel/pkg/PLIST
1.106+1-1x11/xfce4/xfce4-panel/Makefile
+7-33 files

OpenBSD/ports BRGgUyzx11/xfce4/xfce4-settings distinfo Makefile, x11/xfce4/xfce4-settings/pkg PLIST

   x11/xfce4/xfce4-settings: update to 4.20.5.

   see https://gitlab.xfce.org/xfce/xfce4-settings/-/raw/xfce4-settings-4.20.5/NEWS
VersionDeltaFile
1.39+2-2x11/xfce4/xfce4-settings/distinfo
1.75+2-2x11/xfce4/xfce4-settings/Makefile
1.27+1-0x11/xfce4/xfce4-settings/pkg/PLIST
+5-43 files

OpenBSD/ports XUiSxaex11/xfce4/tumbler distinfo Makefile

   x11/xfce4/tumbler: update to 4.20.2.

   see https://gitlab.xfce.org/xfce/tumbler/-/raw/tumbler-4.20.2/NEWS
VersionDeltaFile
1.59+3-4x11/xfce4/tumbler/Makefile
1.25+2-2x11/xfce4/tumbler/distinfo
+5-62 files

OpenBSD/ports Ha6UrNYx11/xfce4/xfce4-power-manager distinfo Makefile, x11/xfce4/xfce4-power-manager/pkg PLIST

   x11/xfce4/xfce4-power-manager: update to 4.20.1.

   see https://gitlab.xfce.org/xfce/xfce4-power-manager/-/raw/xfce4-power-manager-4.20.1/NEWS
VersionDeltaFile
1.19+2-2x11/xfce4/xfce4-power-manager/distinfo
1.49+2-2x11/xfce4/xfce4-power-manager/Makefile
1.17+1-0x11/xfce4/xfce4-power-manager/pkg/PLIST
+5-43 files

OpenBSD/src WjZgZiAusr.sbin/acme-client base64.c

   Handle '=' padding in base64url encoded EAB keys.

   bentley@ found one in the wild and confirmed that this makes it work
VersionDeltaFile
1.11+5-1usr.sbin/acme-client/base64.c
+5-11 files

OpenBSD/src MD65C3gusr.bin/ssh ssh-ed25519.c

   pass back errors from ed25519 key generation, which theoretically
   can fail. From Dimitri John Ledkov via GHPR702.

   ok deraadt@ dtucker@
VersionDeltaFile
1.23+3-2usr.bin/ssh/ssh-ed25519.c
+3-21 files

OpenBSD/src uDVLsWHusr.bin/ssh auth2-pubkey.c auth2-hostbased.c

   Move check of public key type against allowed algorithms to before
   parsing of the key sent by the peer.

   This removes at least some key parsing and verification paths from
   the pre-auth attack surface.

   Suggested by Christopher Paul Rohlf of Anthropic, ok deraadt@
VersionDeltaFile
1.58+7-6usr.bin/ssh/auth2-hostbased.c
1.127+6-6usr.bin/ssh/auth2-pubkey.c
+13-122 files

OpenBSD/ports LDqdALenet/samba Makefile distinfo

   Update to samba-4.24.5

   Security release addressing CTDB protocol bounds checking issues
   (CVE-2026-58224). AD and DNS/KDC vulnerabilities do not affect standard
   OpenBSD builds. Details:
   https://www.samba.org/samba/history/samba-4.24.5.html

   Tested by Ian McWilliam (maintainer).
VersionDeltaFile
1.142+2-2net/samba/distinfo
1.378+1-1net/samba/Makefile
+3-32 files

OpenBSD/ports OeWj9Zwnet/samba Makefile distinfo

   Update to samba-4.24.5

   Security release addressing CTDB protocol bounds checking issues
   (CVE-2026-58224). AD and DNS/KDC vulnerabilities do not affect standard
   OpenBSD builds. Details:
   https://www.samba.org/samba/history/samba-4.24.5.html

   Tested by Ian McWilliam (maintainer).
VersionDeltaFile
1.138.2.4+2-2net/samba/distinfo
1.372.2.4+1-1net/samba/Makefile
+3-32 files