OpenBSD/src gsNf0rK — sys/net pf_table.c pf.c

   pf(4): pfr_insert_kentry() always needs PF_LOCK()

   pfr_insert_kentry() inserts an IP address into a table. The table's
   consistency is protected by PF_LOCK(). Unfortunately, PF_LOCK()
   protection is missing for the code path executed on behalf
   of the overload action in a pf rule. The overload action instructs
   the firewall to insert the packet's source address into the table specified
   as the overload action parameter. That particular code path in
   pf_test() function runs without any lock protection.

   The bug was introduced in revision 1.1074 and remained unnoticed
   until now, when it was kindly reported by alf (a.schlichting () lemarit ! com>)

   OK henning@, OK dlg@, OK jmatthew@
VersionDeltaFile
1.1242+14-4sys/net/pf.c
1.151+3-1sys/net/pf_table.c
+17-52 files

OpenBSD/src i6ugJKo — usr.sbin/httpd server.c httpd.conf.5

   httpd: add header block/drop rules for request filtering

   With this incoming requests can also be rejected based on the value of a
   request header. Valid options are:

   header block name value code [arg]
           Close the connection with an error response when a
           request header matches.  Both name and value are shell-
           style patterns and are matched case-insensitively against
           the header name and value.  code must be a valid HTTP
           status code.  For codes in the 3xx range, arg is required
           and sent as the "Location" header.  It must start with
           "http://" or "https://".  For all other codes, arg is
           optional and used as the log message identifying the
           rule.

   header drop name value
           Silently close the connection without sending a response
           when a request header matches, using the same pattern

    [10 lines not shown]
VersionDeltaFile
1.78+126-1usr.sbin/httpd/config.c
1.139+102-1usr.sbin/httpd/parse.y
1.172+50-1usr.sbin/httpd/server_http.c
1.137+35-2usr.sbin/httpd/httpd.conf.5
1.185+36-1usr.sbin/httpd/httpd.h
1.140+21-1usr.sbin/httpd/server.c
+370-71 files not shown
+390-87 files

OpenBSD/src ROswo2p — regress/usr.sbin/relayd args-http-chunked-trailer-unterminated.pl

   Test unterminated chunk trailer lines against the header length limit
VersionDeltaFile
1.1+29-0regress/usr.sbin/relayd/args-http-chunked-trailer-unterminated.pl
+29-01 files

OpenBSD/src amMY1R3 — usr.sbin/relayd relay_http.c

   relayd: apply the header length limit to chunk size and trailer lines

   Chunk size and trailer lines were not limited, so a line without line
   ending could be buffered without bound. Limit each chunk size line and
   the whole trailer to the configured header length and close the
   session if they exceed it.

   Spotted by Acts1631 (with diff), OK kirill@
VersionDeltaFile
1.106+22-1usr.sbin/relayd/relay_http.c
+22-11 files

OpenBSD/src B7c26gT — usr.sbin/relayd relay_http.c

   relayd: apply the header length limit to unterminated lines

   The limit was only checked for complete lines, so a header line
   without line ending could be buffered without bound. Reject such
   lines with 413 as soon as they exceed the limit.

   Spotted by Acts1631 (with diff), OK kirill@
VersionDeltaFile
1.105+11-1usr.sbin/relayd/relay_http.c
+11-11 files

OpenBSD/src qY0VmOp — sys/arch/amd64/amd64 cpu.c, sys/arch/i386/i386 machdep.c

   don't access the DE_CFG MSR when running on a hypervisor

   Sebastian Albert encountered a KVM hosting provider where trying
   to access the MSR resulted in a protection fault.
   DE_CFG is not documented in AMD's 'AMD64 Architecture Programmer's Manual'.

   ok brynet@ mlarkin@
VersionDeltaFile
1.681+3-2sys/arch/i386/i386/machdep.c
1.208+3-2sys/arch/amd64/amd64/cpu.c
+6-42 files

OpenBSD/src FBg6M1V — sys/dev/ic qwz.c

   sys/qwz: spoted one more negative errno
VersionDeltaFile
1.89+2-2sys/dev/ic/qwz.c
+2-21 files

OpenBSD/src XZCn7q2 — usr.sbin/vmd i8259.c

   vmd(8): change a log_warnx to a log_debug

   no functional change, just quieting a chatty log message.
VersionDeltaFile
1.25+2-2usr.sbin/vmd/i8259.c
+2-21 files

OpenBSD/src 9WuS1qh — sys/dev/ic qwzvar.h qwz.c

   sys/qwz: fix REO queue lifetime

   Track REO completions before publication and wait for peer unmap,
   deletion, and cache flushes before reusing queue DMA. Submission errors
   and timeouts retain ownership; hardware failures block reuse until cold
   cleanup. HAL error conventions and flush semantics follow ath12k;
   tracking and the reuse barrier adapt qwz's retained pool.
VersionDeltaFile
1.88+163-155sys/dev/ic/qwz.c
1.29+14-12sys/dev/ic/qwzvar.h
+177-1672 files

OpenBSD/src 3ULWshX — sys/dev/ic qwzreg.h qwz.c

   sys/qwz: fix WCN7850 REO layout

   Use WCN7850 REO tags and 64-bit TLV headers so commands and completions
   use the correct offsets. Correct the status ring size and clear command
   payloads before reuse.

   The layout follows Linux ath12k's WCN7850 definitions.

   OK: stsp@
VersionDeltaFile
1.87+98-69sys/dev/ic/qwz.c
1.19+17-17sys/dev/ic/qwzreg.h
+115-862 files

OpenBSD/src gzFWZwd — sys/dev/ic qwz.c

   sys/qwz: configure negotiated HT SMPS

   Backport of sys/dev/ic/qwx.c,v 1.92

   OK: stsp@
VersionDeltaFile
1.86+37-9sys/dev/ic/qwz.c
+37-91 files

OpenBSD/src Z6QGo5P — sys/dev/ic qwz.c

   sys/qwz: prepare peers before association requests

   Backport of sys/dev/ic/qwx.c,v 1.94, sys/dev/ic/qwx.c,v 1.118

   OK: stsp@
VersionDeltaFile
1.85+53-9sys/dev/ic/qwz.c
+53-91 files

OpenBSD/src rv0gTGO — sys/dev/ic qwz.c

   sys/qwz: keep data interrupts through association

   Backport of sys/dev/ic/qwx.c,v 1.125

   OK: stsp@
VersionDeltaFile
1.84+3-9sys/dev/ic/qwz.c
+3-91 files

OpenBSD/src XDiZ4Go — sys/dev/ic qwz.c

   sys/qwz: clear node flags during deauthentication

   Backport of sys/dev/ic/qwx.c,v 1.113

   OK: stsp@
VersionDeltaFile
1.83+8-1sys/dev/ic/qwz.c
+8-11 files

OpenBSD/src 1wHpLZN — sys/dev/ic qwz.c

   sys/qwz: update RSSI from TX acknowledgments

   Backport of sys/dev/ic/qwx.c,v 1.98

   OK: stsp@
VersionDeltaFile
1.82+11-1sys/dev/ic/qwz.c
+11-11 files

OpenBSD/src vhjcUuF — share/zoneinfo/datfiles zone1970.tab zone.tab

   Update to 2026egtz from https://github.com/JodaOrg/global-tz
    o Manitoba moves to permanent -05 on 2026-10-31.
    o In 1925 Ireland fell back on 09-20 not 10-04.
VersionDeltaFile
1.95+101-21share/zoneinfo/datfiles/northamerica
1.98+27-5share/zoneinfo/datfiles/europe
1.11+5-2share/zoneinfo/datfiles/zonenow.tab
1.37+2-2share/zoneinfo/datfiles/zone1970.tab
1.84+2-2share/zoneinfo/datfiles/zone.tab
+137-325 files

OpenBSD/src URaPdZc — sys/dev/ic qwx.c

   Don't use negative errno values in qwx(4). Spotted by kirill@
VersionDeltaFile
1.145+3-3sys/dev/ic/qwx.c
+3-31 files

OpenBSD/src 3mFaKkz — usr.sbin/rpki-client nca.c

   rpki-client: do not fatal after RB_INSERT() into the NCA trees

   rpki-client is generally a bit too quick to error out and a repeated source
   of problems has been errx after RB_INSERT() (one fixed just yesterday).

   The first of these is probably not reachable but do that for good measure.
   The other one was shown to be reachable in somewhat contrived setups by
   eur1ka, which means rpki-client would refuse to start.

   ok claudio
VersionDeltaFile
1.13+13-4usr.sbin/rpki-client/nca.c
+13-41 files

OpenBSD/src IauPJJU — usr.sbin/rpki-client nca.c

   rpki-client: factor a nonfunc_ca_free() out of nca_tree_remove_cert()

   ok claudio
VersionDeltaFile
1.12+17-8usr.sbin/rpki-client/nca.c
+17-81 files

OpenBSD/src GXeQmMd — usr.sbin/rpki-client repo.c

   Track the nofetch variable by TAL.

   This matches better with the MAX_REPO_PER_TAL limit which is already tracked
   by TAL and with that a TAL hitting the limit will not affect the other TALs.

   Reported by eur1ka
   OK tb@
VersionDeltaFile
1.92+13-9usr.sbin/rpki-client/repo.c
+13-91 files

OpenBSD/ports Lwgj5Si — security/gnupg Makefile distinfo, security/gnupg/patches patch-g10_import_c

   Reattempt the upgrade to gnupg-2.5.24

   Upstream published a fix for regression that broke mail/notmuch
   configure. Updating now means smaller steps if we need an update for
   a security issue in the next 8.0 OpenBSD release. ok sthen@ naddy@
VersionDeltaFile
1.1+19-0security/gnupg/patches/patch-g10_import_c
1.58+2-2security/gnupg/distinfo
1.154+2-1security/gnupg/Makefile
+23-33 files

OpenBSD/src yoBk83h — sys/dev/pci if_qwz_pci.c

   sys/qwz: retain cached firmware filenames

   Backport of sys/dev/pci/if_qwx_pci.c,v 1.29

   OK: stsp@
VersionDeltaFile
1.20+6-7sys/dev/pci/if_qwz_pci.c
+6-71 files

OpenBSD/src JcsuhEc — sys/dev/ic qwz.c

   sys/qwz: preserve decoded radiotap frequency

   Management RX parameters already contain a hostorder chanel
   frequency. Avoid decoding it again before writing the little endian
   radiotap field.

   OK: stsp@
VersionDeltaFile
1.81+2-2sys/dev/ic/qwz.c
+2-21 files

OpenBSD/src 8y252HD — sys/dev/ic qwzvar.h qwz.c

   sys/qwz: report radiotap channels and rates

   Based on sys/dev/ic/qwx.c,v 1.93 and sys/dev/ic/qwxvar.h,v 1.31

   Populate radiotap channel and rate fields with WCN7850 RX rate decoding.
   Use QWZ presence masks and omit unavailable timestamps, noise and
   signal strength for data frames.

   Correct 54 Mb/s encoding from 104 to 108 in 500 kb/s.

   OK: stsp@
VersionDeltaFile
1.80+96-5sys/dev/ic/qwz.c
1.28+20-4sys/dev/ic/qwzvar.h
+116-92 files

OpenBSD/src DT0oJtU — sys/dev/ic qwz.c

   sys/qwz: count discarded RX packets

   Backport of sys/dev/ic/qwx.c,v 1.91 and sys/dev/ic/qwx.c,v 1.95

   OK: stsp@
VersionDeltaFile
1.79+3-1sys/dev/ic/qwz.c
+3-11 files

OpenBSD/ports m3H7lWy — www/chromium Makefile distinfo, www/chromium/patches patch-chrome_browser_picture_in_picture_picture_in_picture_window_manager_cc patch-third_party_test_fonts_fontconfig_BUILD_gn

   update to 154.0.8037.92; ok naddy@
VersionDeltaFile
1.498+4-4www/chromium/distinfo
1.6+2-2www/chromium/patches/patch-third_party_test_fonts_fontconfig_BUILD_gn
1.5+2-2www/chromium/patches/patch-third_party_fontconfig_include_meson-config_h
1.5+2-2www/chromium/patches/patch-content_browser_web_contents_web_contents_impl_cc
1.8+1-1www/chromium/patches/patch-chrome_browser_picture_in_picture_picture_in_picture_window_manager_cc
1.937+1-1www/chromium/Makefile
+12-123 files not shown
+14-149 files

OpenBSD/src oLOBjhK — sys/dev/ic qwzreg.h qwz.c

   sys/qwz: drain REO RX exceptions

   Based on sys/dev/ic/qwx.c,v 1.33

   Drain REO RX exceptions using descriptor layouts and qwz cookie.
   Reclaim packet buffers, return link descriptors and replenish RX,
   checking bank bounds and release ring space.

   OK: stsp@
VersionDeltaFile
1.78+101-156sys/dev/ic/qwz.c
1.18+6-1sys/dev/ic/qwzreg.h
+107-1572 files

OpenBSD/src cWsbVhu — sys/dev/ic qwzvar.h qwz.c

   sys/qwz: read RX metadata from MPDU TLVs

   Read sequence numbers and TIDs from WCN7850 MPDU descriptors.

   OK: stsp@
VersionDeltaFile
1.77+7-7sys/dev/ic/qwz.c
1.27+1-2sys/dev/ic/qwzvar.h
+8-92 files

OpenBSD/src F5gphRM — sys/dev/ic qwzvar.h qwzreg.h

   sys/qwz: handle WBM RX errors

   Based on sys/dev/ic/qwx.c,v 1.35 and sys/dev/ic/qwxvar.h,v 1.18 ,
   sys/dev/ic/qwx.c,v 1.89 , sys/dev/ic/qwx.c,v 1.121 and sys/dev/ic/qwxvar.h,v 1.36

   Process WBM RX releases using WCN7850 descriptor and cookie formats.

   Deliver valid null queue frames through existing RX processing, clear
   mbuf pointers after delivery, and then replenish descriptors

   OK: stsp@
VersionDeltaFile
1.76+139-111sys/dev/ic/qwz.c
1.17+24-1sys/dev/ic/qwzreg.h
1.26+4-1sys/dev/ic/qwzvar.h
+167-1133 files

OpenBSD/src aupJ4oI — sys/dev/ic qwz.c

   sys/qwz: report hardware RX aggregation

   Based on sys/dev/ic/qwx.c,v 1.85 and sys/dev/ic/qwx.c,v 1.90

   Report hardware deaggregation and reordering after successful RX
   reconstruction; allow repaeted sequence numbers for later A-MSDU
   subframes and clear the AMSDU QoS bit.

   OK: stsp@
VersionDeltaFile
1.75+30-6sys/dev/ic/qwz.c
+30-61 files