start process of deprecating the -R flag. This was the old way of
performing a remote-to-remote copy that was basically executed scp on
the remote host. It barely worked (needing agent forwarding enabled or
usable credentials on the remote host) and has largely been replaced
by a better SFTP-protocol remote-to-remote copy that runs through the
host performing the copy.
We'll disable this option in a release or two; ok dtucker@
Implement a maximum number of KDF rounds that will be accepted when
writing an OpenSSH-format private key or when loading one. This limit
is set pretty high (1<<20), but ensures that a service that is passed a
bad key with an ridiculously high number of rounds will _eventually_
complete parsing it.
Also bump the default number of KDF rounds from 24 to 32 (this is a
linear increase, not like bcrypt(3) which is exponential).
Pointed out by Aris Adamantiadis
cherrypick fix for CPython CVE-2026-19445: Use-after-free of a
server-side SSLContext when sni_callback switches contexts. ok tb kmos
A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callback assigns a different context
to SSLSocket.context (the documented way to select a certificate per
server name) and nothing else keeps the original ssl.SSLContext alive.
Typical cases are servers that create an SSLContext per connection or
replace it while connections are open.
fix the bit length of ML-DSA 44/Ed25519 keys that was being
incorrectly reported as 256. The private key length for these
composite keys is 512 bits. This value is only used for display.
Spotted by Yiyue Wang
sftp: be stricter in accepting paths returned by the server for
SSH_FXP_REALPATH or SSH2_FXP_READDIR replies, as these can be
used in some situations to decide the destination path for recursive
transfers.
Report and patch from Junghoon Cho
handle max-pk-ok path identically when the incoming user is invalid;
avoids max-pk-ok feature presenting a username validity oracle
analysis and patch from Chris Rohlf in collaboration with Claude and
Anthropic Research
update net/libtorrent 0.16.24
- major bump due to removed symbols
- unbreaks tests by linking using static archive (from tj@)
approved by sthen@ and tested by and OK tj@
update net/rtorrent 0.16.24
- various security fixes (e.g., overflow, heap overflow and use-after-free)
- regen test/Makefile.in patch to remove a new, third instance of -ldl
approved by sthen@ and tested by and OK tj@
sys/qwz: avoid peer access after key waits
Do not retain a pointer into peer cipher state across key installation.
Installation can sleep while the peer is removed; dropping the failure
rollback avoids accessing freed peer memory.
OK: stsp@
sys/qwz: handle scan events during cancellation
Ignore late scan started events while cancellation is pending;
finish an aborting scan when firmware reports that startup failed.
OK: stsp@
sys/qwz: stop firmware scans on interface down
Based on sys/dev/ic/qwx.c,v 1.72
Abort firmware scans during interface stop, including scans still
starting; taer down started vdevs and remaining peers even when net80211
has not reached AUTH.
OK: stsp@
vmm(4): handle proper injection during mov ss/sti shadow on vmx
arm the interrupt window when we have something to inject but are in a mov ss
or sti interrupt shadow
ok dv
rpki-client: don't treat a duplicate CCR MFT as fatal
It is possible to concoct situations where two PPs serve byte identical
manifests. Then CCR generation errors with "CCR MFT tree corrupted".
Handle this situation gracefully and only warn about the weird situation.
There are more problems in the vicinity that need fixing but that's for
after the release.
Reported by eur1ka qq com. Diff is a tweaked version of the suggested fix.
ok job
Update p5-DBI to 1.654
1.654 - 2026-09-25, H.Merijn Brand & Robert Rothenberg
* Fix DBI::sql_type_cast on IV/NV (CVE-2026-88815) (reported by Raj)
* Fix FetchHashKeyName on IV/NV (CVE-2026-88816) (reported by Raj)
* Fix provided in META
With upstream patch for compilation under gcc.
ok sthen@
There is a hidden dep on databases/libhiredis that can cause a build
failure when junking between configure and build. Since enabling this
feature changes PLIST, disable for now and we can re-evaluate after
unlock.
OK lucas@ naddy@