OpenBSD/src eabIbK0 — libexec/ld.so ld.so.1 library_subr.c

   surprised this page did not Xr ldd 1
VersionDeltaFile
1.56+12-2libexec/ld.so/library_subr.c
1.26+3-2libexec/ld.so/ld.so.1
+15-42 files

OpenBSD/src 2ynya8Y — sbin/isakmpd udp.c

   using sizeof is recommended practice
VersionDeltaFile
1.97+3-3sbin/isakmpd/udp.c
+3-31 files

OpenBSD/src gtrwOTs — usr.sbin/rpc.statd statd.c

   O_NONBLOCK is the modern name (with 2 legacy userland defines and 2 legacy
   kernel defines, not sure when all of that will collapse)
VersionDeltaFile
1.7+2-2usr.sbin/rpc.statd/statd.c
+2-21 files

OpenBSD/src ZtRZoWY — usr.sbin/rtrd hash.c commands.c

   more knf
VersionDeltaFile
1.6+4-24usr.sbin/rtrd/cache.c
1.5+5-15usr.sbin/rtrd/commands.c
1.4+1-2usr.sbin/rtrd/hash.c
+10-413 files

OpenBSD/src PTVPsju — regress/lib/libcrypto/objects objectstest.c

   objectstest: succeded -> succeeded
VersionDeltaFile
1.9+2-2regress/lib/libcrypto/objects/objectstest.c
+2-21 files

OpenBSD/src RI5eRcb — regress/usr.sbin/rpki-client Makefile.inc

   rpki-client regress: link bytestring API to the build
VersionDeltaFile
1.51+2-2regress/usr.sbin/rpki-client/Makefile.inc
+2-21 files

OpenBSD/src 4arpZzi — usr.sbin/rpki-client Makefile

   rpki-client: link bytestring API to the build

   ok beck
VersionDeltaFile
1.43+4-1usr.sbin/rpki-client/Makefile
+4-11 files

OpenBSD/src 4WI3rIb — usr.sbin/rpki-client bs_ber.c bs_cbb.c

   rpki-client: add a copy of libcrypto's bytestring API

   This will be used to replace the terrible CMS API from libcrypto. Longer
   term this might also be used to implement better parsers for certs, CRLs
   and the signed objects' eContent.

   discussed with claudio and job
   ok beck
VersionDeltaFile
1.1+616-0usr.sbin/rpki-client/bs_cbs.c
1.1+573-0usr.sbin/rpki-client/bytestring.h
1.1+490-0usr.sbin/rpki-client/bs_cbb.c
1.1+270-0usr.sbin/rpki-client/bs_ber.c
+1,949-04 files

OpenBSD/src WtI5fVl — lib/libcrypto/bytestring bytestring.h, lib/libssl bytestring.h

   libcrypto/bytestring.h: make parentheses line up again

   whitespace-only change
VersionDeltaFile
1.30+11-11lib/libssl/bytestring.h
1.10+11-11lib/libcrypto/bytestring/bytestring.h
+22-222 files

OpenBSD/src eihZpxP — lib/libcrypto/bytestring bytestring.h, lib/libssl bytestring.h

   libcrypto/bytestring: add some missing tag classes

   This adds tags for NULL, PrintableString, UTCTime, and GeneralizedTime with
   names matching BoringSSL.

   ok kenjiro
VersionDeltaFile
1.29+5-1lib/libssl/bytestring.h
1.9+5-1lib/libcrypto/bytestring/bytestring.h
+10-22 files

OpenBSD/src swx6bAd — lib/libcrypto/bytestring bytestring.h, lib/libssl bytestring.h

   libcrypto/bytestring: remove LIBRESSL_INTERNAL from bytestring.h

   This currently marks the LibreSSL-specific additions to this API. It has
   no effect other than getting in the way of other projects wanting to use
   this since it is always compiled with LIBRESSL_INTERNAL.

   ok kenjiro
VersionDeltaFile
1.28+1-3lib/libssl/bytestring.h
1.8+1-3lib/libcrypto/bytestring/bytestring.h
+2-62 files

OpenBSD/src huuBdUT — sys/kern sysv_shm.c

   sysv_shm: claim the vm_shm slot after uvm_map(), not before

   sys_shmat() chose a free slot in the per-vmspace vm_shm array, then slept
   in uvm_map(), then published into the slot it had chosen.  Nothing marked
   the slot taken across the sleep, so a sibling thread entering sys_shmat()
   scanned the same array, found the same slot still reading -1, and took it
   too.  Both uvm_map() calls succeed at different addresses and the thread
   that stores last wins; the other mapping is left with no vm_shm entry, so
   shmdt() returns EINVAL for it and shmexit() cannot drop its shm_nattch.
   The permanently raised count keeps IPC_RMID from deallocating the segment,
   which then sits in shmsegs[] reachable by nobody; 128 of those and
   shmget() returns ENOSPC system-wide.

   uvm_map() is the only sleep between choosing the slot and filling it in,
   so moving the scan below the map closes the window without a reserved
   state that shmdt(), shmexit() and shmfork() would each have to learn
   about.  EMFILE is now discovered after the mapping exists, so that path
   undoes it.


    [9 lines not shown]
VersionDeltaFile
1.92+26-17sys/kern/sysv_shm.c
+26-171 files

OpenBSD/src C1f1tNZ — regress/usr.sbin/rpki-client/openssl unistd.h

   rpki-client regress: this unistd.h hack needs to include x509.h
VersionDeltaFile
1.7+2-1regress/usr.sbin/rpki-client/openssl/unistd.h
+2-11 files

OpenBSD/src ydGmbba — lib/libexpat/lib xmltok.h xmltok_impl.c, lib/libexpat/tests basic_tests.c

   Backport fixes from libexpat version 2.8.5.

   Relevant for OpenBSD are security fixes #1282, bug fixes #1346
   #1371, other changes #1354 #1357 #1349 #1360 #1378.  Library bump
   is not necessary.
   CVE-2026-93990

   OK deraadt@

   this is errata/7.9/033_expat.patch.sig
VersionDeltaFile
1.9.4.3+342-0lib/libexpat/tests/basic_tests.c
1.20.4.2+138-64lib/libexpat/lib/xmltok.c
1.47.2.3+89-92lib/libexpat/lib/xmlparse.c
1.15.4.2+55-56lib/libexpat/lib/xmlrole.c
1.18.12.2+28-32lib/libexpat/lib/xmltok_impl.c
1.9.6.3+25-26lib/libexpat/lib/xmltok.h
+677-2706 files not shown
+716-31912 files

OpenBSD/src dGRHt22 — lib/libexpat/lib xmltok.h xmltok_impl.c, lib/libexpat/tests basic_tests.c

   Backport fixes from libexpat version 2.8.5.

   Relevant for OpenBSD are security fixes #1282, bug fixes #1346
   #1371, other changes #1354 #1357 #1349 #1360 #1378.  Library bump
   is not necessary.
   CVE-2026-93990

   OK deraadt@

   this is errata/7.8/069_expat.patch.sig
VersionDeltaFile
1.7.2.5+342-0lib/libexpat/tests/basic_tests.c
1.18.2.2+138-64lib/libexpat/lib/xmltok.c
1.44.2.6+89-92lib/libexpat/lib/xmlparse.c
1.13.6.2+55-56lib/libexpat/lib/xmlrole.c
1.18.6.2+28-32lib/libexpat/lib/xmltok_impl.c
1.9.2.3+25-26lib/libexpat/lib/xmltok.h
+677-2706 files not shown
+716-31912 files

OpenBSD/src hAu9Erc — sbin/isakmpd isakmpd.c message.c

   incorrect object being freed
   from Franz Bettag / Bettag Systems
   from deraadt@; OK markus@ hshoexer@ sthen@ mvs@

   IKEv1 short-HASH heap overflow; second approach for fix
   from Franz Bettag / Bettag Systems
   from deraadt@; OK sthen@ mvs@

   Franz Bettag sent a report & diff repairing the privsep monitor's
   dangerous file behavior in /var/run, and I was shocked at what it
   does.  isakmpd never had a proper diagnosis and control program like
   other daemons do, and instead accepts weird commands on a fifo and
   splats files dangerously.  Some path names can be manipulated.  This
   2600 line diff removes all of this session debugging mechanism which
   is the main cause of that unsafe design.  There are no reuseable parts
   in that code (it cannot be reconstructed into a proper control program
   interface).  As a result, the privsep monitor now has unveil to the
   config directory, and the network speaking process is "stdio sendfd
   route recvfd inet".  There is some loss of functionality, since some

    [22 lines not shown]
VersionDeltaFile
1.125.18.1+2-342sbin/isakmpd/sa.c
1.65.8.1+1-341sbin/isakmpd/log.c
1.83.14.1+64-187sbin/isakmpd/monitor.c
1.22.36.1+1-133sbin/isakmpd/field.c
1.129.40.1+4-120sbin/isakmpd/message.c
1.109.14.1+7-116sbin/isakmpd/isakmpd.c
+79-1,23928 files not shown
+166-1,81334 files

OpenBSD/src 3ns2n6b — sbin/isakmpd isakmpd.c message.c

   incorrect object being freed
   from Franz Bettag / Bettag Systems
   from deraadt@; OK markus@ hshoexer@ sthen@ mvs@

   IKEv1 short-HASH heap overflow; second approach for fix
   from Franz Bettag / Bettag Systems
   from deraadt@; OK sthen@ mvs@

   Franz Bettag sent a report & diff repairing the privsep monitor's
   dangerous file behavior in /var/run, and I was shocked at what it
   does.  isakmpd never had a proper diagnosis and control program like
   other daemons do, and instead accepts weird commands on a fifo and
   splats files dangerously.  Some path names can be manipulated.  This
   2600 line diff removes all of this session debugging mechanism which
   is the main cause of that unsafe design.  There are no reuseable parts
   in that code (it cannot be reconstructed into a proper control program
   interface).  As a result, the privsep monitor now has unveil to the
   config directory, and the network speaking process is "stdio sendfd
   route recvfd inet".  There is some loss of functionality, since some

    [22 lines not shown]
VersionDeltaFile
1.125.14.1+2-342sbin/isakmpd/sa.c
1.65.4.1+1-341sbin/isakmpd/log.c
1.83.10.1+64-187sbin/isakmpd/monitor.c
1.22.32.1+1-133sbin/isakmpd/field.c
1.129.36.1+4-120sbin/isakmpd/message.c
1.109.10.1+7-116sbin/isakmpd/isakmpd.c
+79-1,23928 files not shown
+166-1,81334 files

OpenBSD/src enC48MP — regress/usr.bin/mandoc/mdoc/Bd offset-empty.in offset-neg.in, regress/usr.bin/mandoc/mdoc/Bl offset.in width.out_ascii

   test macros in .Bl and .Bd -width and -offset arguments;
   related to mdoc_validate.c rev. 1.313
VersionDeltaFile
1.1+21-0regress/usr.bin/mandoc/mdoc/Bl/width.out_markdown
1.1+20-0regress/usr.bin/mandoc/mdoc/Bl/width.in
1.1+13-0regress/usr.bin/mandoc/mdoc/Bl/width.out_ascii
1.4+5-5regress/usr.bin/mandoc/mdoc/Bd/offset-neg.in
1.7+6-3regress/usr.bin/mandoc/mdoc/Bd/offset-empty.in
1.6+6-2regress/usr.bin/mandoc/mdoc/Bl/offset.in
+71-107 files not shown
+93-2413 files

OpenBSD/src 7hvqqHQ — usr.bin/mandoc mdoc_validate.c

   If the -width of a .Bl macro is of the form ".word text",
   use only the text for measuring the width, assuming the word is a macro,
   as a crude approximation of what groff_mdoc(7) does: it sets the
   argument in a diversion and measures the width of the diversion.

   Ugly formatting first reported by Franco Fichtner (DragonFly BSD) in 2013,
   this partial fix first suggested by me in the mandoc TODO file in 2013,
   then implemented by Eric van Gyzen (FreeBSD) in 2022.
   My fix committed here is slightly smaller than Eric's FreeBSD fix,
   does not need an extra function, and stays closer to groff behaviour.
VersionDeltaFile
1.313+32-13usr.bin/mandoc/mdoc_validate.c
+32-131 files

OpenBSD/src lnviTM9 — sys/dev/ic ufshci.c

   sys/ufshci: increase poll's wait to 500ms

   This matches Linux timeout and makes ufshci survives a suspend on
   HONOR MagicBook Art 14 Snapdragon

   500ms value which matches Linux suggested by kettenis@

   OK: mglocker@
VersionDeltaFile
1.50+2-2sys/dev/ic/ufshci.c
+2-21 files

OpenBSD/src MP0afmX — regress/usr.bin/ssh percent.sh

   Add test for proxycommand percent expansions.
VersionDeltaFile
1.24+20-4regress/usr.bin/ssh/percent.sh
+20-41 files

OpenBSD/src hfDfkLh — usr.sbin/vmd x86_vm.c

   vmd(8): fix mmio exit issue on old SVM machines

   fix a problem where we didn't pass any instruction length to insn_decode
   on some older opterons that don't have SVM decode assist.

   ok dv
VersionDeltaFile
1.28+2-1usr.sbin/vmd/x86_vm.c
+2-11 files

OpenBSD/src 80S1WVA — usr.sbin/rpki-client output-rtrx.c

   Use SOCK_NONBLOCK where we can.
   Handle errors for fcntl().
   CID 656886, CID 656887
   OK deraadt@ tb@
VersionDeltaFile
1.8+12-17usr.sbin/rpki-client/output-rtrx.c
+12-171 files

OpenBSD/src jPUgZXG — sbin/isakmpd policy.c

   The path generation must not contain '..' or '/' type patterns or it
   can walk upwards and sideways.  The privsep open() is now restricted by
   a single unveil() inside the config directory, but files in relative config
   directories can still be reached and create potentially confusing outcomes.
   This is half of a repair from Franz Bettag before I restructured the privsep
   to use unveil(), the other half of the repair is not needed because it applies
   to code that no longer exists.
   ok markus hshoexer bluhm, testing sthen mvs
VersionDeltaFile
1.107+9-1sbin/isakmpd/policy.c
+9-11 files

OpenBSD/src iGQVcL6 — usr.sbin/rtrd sockets.c

   Use SOCK_NONBLOCK and handle fcntl() failures.
   OK deraadt@
VersionDeltaFile
1.7+35-13usr.sbin/rtrd/sockets.c
+35-131 files

OpenBSD/src obmca7C — sbin/isakmpd message.c isakmpd.c

   Franz Bettag sent a report & diff repairing the privsep monitor's
   dangerous file behavior in /var/run, and I was shocked at what it
   does.  isakmpd never had a proper diagnosis and control program like
   other daemons do, and instead accepts weird commands on a fifo and
   splats files dangerously.  Some path names can be manipulated.  This
   2600 line diff removes all of this session debugging mechanism which
   is the main cause of that unsafe design.  There are no reuseable parts
   in that code (it cannot be reconstructed into a proper control program
   interface).  As a result, the privsep monitor now has unveil to the
   config directory, and the network speaking process is "stdio sendfd
   route recvfd inet".  There is some loss of functionality, since some
   users had gotten used to the decrepit debugging / logging interface to
   repair sessions which would not negotiate.
   This is almost completely unmaintained code from early OpenBSD days
   with an incorrect privsep design, and many users have migrated to
   using iked(8) which does IKEv2 protocol.  RFC9395 also provides valuable
   guidance here.  Everyone is urged to avoid using this program.  If IKEv1
   protocol is still a part of your life roll up sleeves and try to write a
   high-quality control interface using lessons from the IKEv2 iked(8) code.

    [2 lines not shown]
VersionDeltaFile
1.127+2-342sbin/isakmpd/sa.c
1.66+1-341sbin/isakmpd/log.c
1.85+64-187sbin/isakmpd/monitor.c
1.23+1-133sbin/isakmpd/field.c
1.110+7-116sbin/isakmpd/isakmpd.c
1.137+1-120sbin/isakmpd/message.c
+76-1,23928 files not shown
+132-1,81134 files

OpenBSD/src u815Prj — sbin/isakmpd x509.c

   knf
VersionDeltaFile
1.129+2-2sbin/isakmpd/x509.c
+2-21 files

OpenBSD/src Zbb4BO1 — sbin/isakmpd message.c ike_quick_mode.c

   IKEv1 short-HASH heap overflow; second approach for fix
   from Franz Bettag / Bettag Systems
   ok sthen mvs
VersionDeltaFile
1.117+22-1sbin/isakmpd/ike_quick_mode.c
1.136+4-1sbin/isakmpd/message.c
+26-22 files

OpenBSD/src Y0mnfRq — sbin/isakmpd policy.c

   incorrect object being freed
   from Franz Bettag / Bettag Systems
   ok markus hshoexer sthen mvs
VersionDeltaFile
1.105+3-3sbin/isakmpd/policy.c
+3-31 files

OpenBSD/src S17RePh — usr.bin/ssh servconf.c

   make StreamLocalBindMask properly first-match-wins; spotted
   while fixing bz4013
VersionDeltaFile
1.458+3-2usr.bin/ssh/servconf.c
+3-21 files