databases/pgbouncer: security update to 1.26.0
see https://www.pgbouncer.org/2026/09/pgbouncer-1-26-0, fixes:
* CVE-2026-19888: DoS due to crash, triggerable by unauthenticated
clients. Caused by a SCRAM client-final-message without a nonce.
* CVE-2026-6668: DoS due to infinite loop, triggerable by unauthenticated
clients. Caused by an integer overflow in the packet buffer growth
logic.
* CVE-2026-6669: DoS due to unbounded work during login, triggerable by a
malicious PostgreSQL server. Caused by an unbounded SCRAM iteration
count.
ok naddy@
revert changing some busy waits to tsleep
landry's ThinkPad T470s (Kaby Lake) with external HDMI monitor could
no longer run X, stuck in a loop of:
'modeset(0): hotplug event: connector 106's link-state is BAD'
qt5/qtbase ports changes, ok rsadowski naddy
- add getexecpath support to qt5/qtbase
- fix builds with ccache; the way this was handled in qtbase could be
simplified as it's already done by ports infrastructure, and the way
it was done here previously isn't compatible with recent bsd.port.mk
changes
On Qualcomm X2 SoCs we need to explicitly configure the DBI
and ATU register windows in the PARF wrapper, otherwise they
are silently ignored.
This fixes a timeout in dwpcie_atu_config and makes the NVME
attach on my HP Elitebook X G2q.
ok kettenis@ patrick@
qwx: fall back to world channels if the regulatory event fails
If the first regulatory channel list event cannot be processed, qwx
attaches with an empty channel list and cannot scan. Populate the
ath11k world channel set in that case. Unlike qwz, keep channels an
earlier event configured, and leave ieee80211_channel_init() to
qwx_init() as before.
From qwz 6f139a5bd.
OK stsp@
qwx: parse the regulatory ext channel list event
Replace the stub with the 2 GHz/5 GHz part of ath11k's parser. 6 GHz
rules, including any the firmware appends to the 5 GHz list, are
ignored. Firmware only sends this event if the host advertises
WMI_CFG_HOST_SERVICE_FLAG_REG_CC_EXT, which qwx does not do yet.
From qwz 901b347bb.
OK stsp@