OpenBSD/src 4q2xvL6 — usr.bin/tmux cmd-choose-tree.c tmux.1

   Add sort order flags to switch-mode, GitHub issue 5696 from harikp2002
   at gmail dot com.
VersionDeltaFile
1.5+18-3usr.bin/tmux/window-switch.c
1.1180+12-2usr.bin/tmux/tmux.1
1.59+4-3usr.bin/tmux/cmd-choose-tree.c
+34-83 files

OpenBSD/src Kun9eB6 — usr.bin/tmux tmux.1 options-table.c

   Show match count in copy mode, GitHub issue 5399.
VersionDeltaFile
1.436+103-16usr.bin/tmux/window-copy.c
1.251+7-3usr.bin/tmux/options-table.c
1.1179+4-2usr.bin/tmux/tmux.1
+114-213 files

OpenBSD/src EEKldtt — usr.bin/tmux spawn.c tmux.1

   Add window-default-command option to override default-command per
   window, from Meriel Sartha Mittelbach.
VersionDeltaFile
1.250+9-1usr.bin/tmux/options-table.c
1.1178+8-1usr.bin/tmux/tmux.1
1.55+4-2usr.bin/tmux/spawn.c
+21-43 files

OpenBSD/src hQTKFIY — regress/usr.bin/mandoc/char/space Makefile break.out_utf8

   test -T utf8 handling of the \: escape sequence
   related to term.c rev. 1.156
VersionDeltaFile
1.1+12-0regress/usr.bin/mandoc/char/space/break.out_utf8
1.15+2-2regress/usr.bin/mandoc/char/space/Makefile
+14-22 files

OpenBSD/src 6qXqQBW — usr.bin/mandoc term.c

   The point of the \: escape sequence is to allow an optional output
   line break, whatever the output mode may be.  It is not supposed
   to produce an output glyph.  Consequently, even in -T utf8 output
   mode, let it put the ASCII_BREAK control code into the output buffer,
   which works in TERMENC_UTF8 mode just as well as in TERMENC_ASCII
   mode, rather than trying to encode it as an UTF-8 code point.
VersionDeltaFile
1.156+4-2usr.bin/mandoc/term.c
+4-21 files

OpenBSD/src 39Y4VQ2 — sys/dev/pci if_mwx.c

   Implement mediaopt monitor for MT7925

   While doing so also improve mwx_dma_rx_dequeue() and remove the KASSERT
   since I triggered that one on MT7925. Further reduce debug noise.
VersionDeltaFile
1.42+86-20sys/dev/pci/if_mwx.c
+86-201 files

OpenBSD/src ggIXC41 — sys/dev/pci if_mwxreg.h

   Unify the UNI command tag definitions in one place and one form.
VersionDeltaFile
1.24+20-21sys/dev/pci/if_mwxreg.h
+20-211 files

OpenBSD/src XrgbRkG — usr.bin/tmux cmd-join-pane.c

   Do not change active pane if joining a pane to the same window. Reported
   by David le Blanc.
VersionDeltaFile
1.77+3-2usr.bin/tmux/cmd-join-pane.c
+3-21 files

OpenBSD/src agoMRF0 — sys/arch/amd64/conf RAMDISK_CD

   enable urndis(4) in the installer on amd64

   ok sthen@
VersionDeltaFile
1.218+2-1sys/arch/amd64/conf/RAMDISK_CD
+2-11 files

OpenBSD/src P5hU4T3 — sys/dev/pci if_mwx.c

   Fix refcnt bug in the tx path and ensure the node drops the refcnt once
   the packet was transmitted.

   Attach the ieee80211_node to the mwx_txwi struct and release the reference
   in mwx_txwi_put() if set. With this the hangs seen on MT7921 are mostly
   gone. Background scans would deassociate from the AP but not switch to
   the new AP because of this refcnt bug.
VersionDeltaFile
1.41+34-26sys/dev/pci/if_mwx.c
+34-261 files

OpenBSD/src 0UbOJae — share/man/man4 usb.4 ure.4

   man4: add RTL8159

   OK: kevlo@
VersionDeltaFile
1.12+13-5share/man/man4/ure.4
1.224+4-3share/man/man4/usb.4
+17-82 files

OpenBSD/src liSRr0L — sys/dev/usb if_urereg.h if_ure.c

   sys/ure: add preliminary support of RTL8159

   OK: kevlo@
VersionDeltaFile
1.38+77-35sys/dev/usb/if_ure.c
1.15+7-2sys/dev/usb/if_urereg.h
+84-372 files

OpenBSD/src ggr05i1 — sys/dev/usb usbdevs.h usbdevs_data.h

   regen
VersionDeltaFile
1.797+5-1sys/dev/usb/usbdevs_data.h
1.803+2-1sys/dev/usb/usbdevs.h
+7-22 files

OpenBSD/src 1OvSUF7 — sys/dev/usb usbdevs

   sys/usbdevs: add RTL8159
VersionDeltaFile
1.791+2-1sys/dev/usb/usbdevs
+2-11 files

OpenBSD/src Wrxu1s5 — usr.bin/ssh ssh-gss.h gss-serv.c

   ssh_gssapi_cleanup_global_client() needs a prototype

   ok dtucker@

   /usr/src/usr.bin/ssh/ssh/../ssh-gss.h:115:38: error: a function
   declaration without a prototype is deprecated in all versions of C
   [-Werror,-Wstrict-prototypes]
     115 | void ssh_gssapi_cleanup_global_client();
         |                                      ^
         |                                       void
   1 error generated.
VersionDeltaFile
1.19+2-2usr.bin/ssh/ssh-gss.h
1.40+2-2usr.bin/ssh/gss-serv.c
+4-42 files

OpenBSD/src 5KDp78L — usr.bin/tmux tty.c

   Fix tty_clamp_area with status lines at the top and a smaller client,
   GitHub issue 5697 from Yasuhiro Inami.
VersionDeltaFile
1.485+10-6usr.bin/tmux/tty.c
+10-61 files

OpenBSD/src 8HEEphv — lib/libssl d1_lib.c

   Avoid OPENSSL_assert(s->d1->mtu >= dtls1_min_mtu()) in dtls1_do_write()
   when custom BIO is used. The assert is tripped if custom BIO does not
   support QUERY_MTU operation and message is being retransmitted after
   timeout expires.

   Issue reported and patch submitted by
   "Pavel (Narayana OU)" (pd _at_ narayana _dot_ im)

   OK kenjiro@
VersionDeltaFile
1.71+3-2lib/libssl/d1_lib.c
+3-21 files

OpenBSD/src i3SsUx5 — sys/arch/i386/conf GENERIC RAMDISK_CD

   add uncm(4) to i386 GENERIC config, and uncm(4) and urndis(4) to RAMDISK_CD.
   ok deraadt
VersionDeltaFile
1.257+3-1sys/arch/i386/conf/RAMDISK_CD
1.867+2-1sys/arch/i386/conf/GENERIC
+5-22 files

OpenBSD/xenocara dSVi8iO — xserver/Xi xipassivegrab.c exevents.c, xserver/dix devices.c

   Merge fixes from upstream for Xserver issues:
   * CVE-2026-88812: XKB SetGeometry TextDoodad Double Free
   * CVE-2026-93515: Present Extension Cross-Window Notify Use-After-Free
   * CVE-2026-93516: XInput Passive Grab modifierDevice Use-After-Free
   * CVE-2026-93517: GLX RenderLarge Heap Buffer Overflow
   * CVE-2026-93518: XKB ResizeKeyType Numeric Truncation
   * CVE-2026-93519: XFixes Pointer Barrier Event List Buffer Overflow
   * CVE-2026-93520: XKB ChangeKeycodeRange Heap Out-of-Bounds Write
   * CVE-2026-93521: RandR ChangeProviderProperty Heap Buffer Overflow
   * CVE-2026-93522: Glamor CopyArea CPU-FBO Heap Buffer Overflow
   * CVE-2026-93523: XInput2 PassiveUngrabDevice Modifier Out-of-Bounds Write
   * CVE-2026-93524: XKB SetMap Key Width/Action Count Desync Out-Of-Bounds Read
   * CVE-2026-93536: GestureBuildSprite Use-After-Free
VersionDeltaFile
1.9+57-29xserver/Xi/xibarriers.c
1.37+36-0xserver/dix/devices.c
1.32+17-7xserver/Xi/exevents.c
1.12+24-0xserver/glamor/glamor_priv.h
1.17+12-0xserver/Xi/xipassivegrab.c
1.8+10-0xserver/glamor/glamor_transfer.c
+156-366 files not shown
+173-4612 files

OpenBSD/src 5DnHAfJ — regress/usr.bin/mandoc/mdoc/Bl badBd.out_html Makefile, usr.bin/mandoc mdoc_macro.c

   When a .Bd block is broken by an .It macro and hence implicitly ended,
   restore the ROFF_NOFILL global parser state to what is was before the block.
   This fixes an assertion failure in the HTML formatter triggered
   by the nonsensical sequence of macros .Bl .Bd -unfilled .It
   that kristaps@ found in the pam_smartcard(8) manual on macOS.
VersionDeltaFile
1.1+17-0regress/usr.bin/mandoc/mdoc/Bl/badBd.out_markdown
1.1+16-0regress/usr.bin/mandoc/mdoc/Bl/badBd.in
1.1+13-0regress/usr.bin/mandoc/mdoc/Bl/badBd.out_ascii
1.194+9-2usr.bin/mandoc/mdoc_macro.c
1.44+5-3regress/usr.bin/mandoc/mdoc/Bl/Makefile
1.1+5-0regress/usr.bin/mandoc/mdoc/Bl/badBd.out_html
+65-51 files not shown
+69-57 files

OpenBSD/src 9kaFSxY — usr.bin/tmux tmux.h tty-keys.c

   Parse terminal replies with keys and apply them only when finished, so
   that a preceding Escape can be handled correctly. GitHub issue 5676 from
   Joan Fabrégat.
VersionDeltaFile
1.216+286-245usr.bin/tmux/tty-keys.c
1.1453+11-1usr.bin/tmux/tmux.h
+297-2462 files

OpenBSD/src nNYFjI4 — usr.bin/tmux tmux.1

   Use the .Cm macro for keywords used as arguments to commands and options,
   mostly replacing dubious use of .Ic, but a few others as well;
   nicm@ agrees with the general direction.
VersionDeltaFile
1.1177+214-208usr.bin/tmux/tmux.1
+214-2081 files

OpenBSD/src vNhJcMc — sys/arch/amd64/conf RAMDISK_CD

   enable uncm(4) in the installer on amd64

   This gives us another way to do firmware-less installs over the network.
VersionDeltaFile
1.217+2-1sys/arch/amd64/conf/RAMDISK_CD
+2-11 files

OpenBSD/src ToF77yf — sys/arch/amd64/conf GENERIC

   typo + whitespace
VersionDeltaFile
1.542+2-2sys/arch/amd64/conf/GENERIC
+2-21 files

OpenBSD/src 5zT1sWD — share/man/man4 Makefile usb.4

   Add manual page for uncm(4).

   From Jan Schreiber
VersionDeltaFile
1.1+53-0share/man/man4/uncm.4
1.223+4-2share/man/man4/usb.4
1.882+3-2share/man/man4/Makefile
+60-43 files

OpenBSD/src 6lenFJI — sys/arch/amd64/conf GENERIC, sys/dev/usb usb.h files.usb

   add uncm(4), a driver for USB CDC NCM (i.e. USB phone tethering)

   Patch by Jan Schreiber

   ok deraadt@ brynet@

   Tested by Jan and myself with Android phones.
   Committed via uncm0
VersionDeltaFile
1.1+1,226-0sys/dev/usb/if_uncm.c
1.11+117-1sys/dev/usb/usbcdc.h
1.7+1-92sys/dev/usb/mbim.h
1.64+4-3sys/dev/usb/usb.h
1.151+6-1sys/dev/usb/files.usb
1.541+2-1sys/arch/amd64/conf/GENERIC
+1,356-986 files

OpenBSD/src NEXjGpO — usr.bin/tmux tmux.1

   Add table for destroy-unattached.
VersionDeltaFile
1.1176+9-2usr.bin/tmux/tmux.1
+9-21 files

OpenBSD/src znDzzPx — sys/arch/riscv64/riscv64 vector.c

   riscv64 vector support: actually restore vcsr/vstart

   The asm statements used to restore said csr mentioned the value to
   restore as an output operand, not an input operand. This hurts as we
   write what happens to be in the allocated register (here "a1") to
   the csr and then struct vreg.

   Issue spotted in build failures due to libgcrypt (mail/notmuch) and to
   libjpeg (games/neverball-data). The diff fixes the testsuite for
   both ports.

   ok jsing@ kettenis@
VersionDeltaFile
1.2+3-3sys/arch/riscv64/riscv64/vector.c
+3-31 files

OpenBSD/src prIlGDI — usr.bin/tmux tmux.h server-client.c

   Do not allow drags started on status line to trigger pane key bindings,
   GitHub issue 5692.
VersionDeltaFile
1.518+19-5usr.bin/tmux/server-client.c
1.1452+2-1usr.bin/tmux/tmux.h
+21-62 files

OpenBSD/src aHlczWs — sbin/isakmpd isakmp_cfg.c

   isakmpd: Bound the HASH coverage in cfg_verify_hash()

   The verifier assumed the HASH payload is the first payload and
   derived the covered length from the message length, reading past
   the end of the message when another payload precedes HASH.  Compute
   the covered range from the HASH payload's actual position and reject
   it if it extends past the message end.

   from markus@, ok me deraadt@
VersionDeltaFile
1.42+14-5sbin/isakmpd/isakmp_cfg.c
+14-51 files