sys/ufshci: increase poll's wait to 500ms
This matches Linux timeout and makes ufshci survives a suspend on
HONOR MagicBook Art 14 Snapdragon
500ms value which matches Linux suggested by kettenis@
OK: mglocker@
vmd(8): fix mmio exit issue on old SVM machines
fix a problem where we didn't pass any instruction length to insn_decode
on some older opterons that don't have SVM decode assist.
ok dv
The path generation must not contain '..' or '/' type patterns or it
can walk upwards and sideways. The privsep open() is now restricted by
a single unveil() inside the config directory, but files in relative config
directories can still be reached and create potentially confusing outcomes.
This is half of a repair from Franz Bettag before I restructured the privsep
to use unveil(), the other half of the repair is not needed because it applies
to code that no longer exists.
ok markus hshoexer bluhm, testing sthen mvs
Franz Bettag sent a report & diff repairing the privsep monitor's
dangerous file behavior in /var/run, and I was shocked at what it
does. isakmpd never had a proper diagnosis and control program like
other daemons do, and instead accepts weird commands on a fifo and
splats files dangerously. Some path names can be manipulated. This
2600 line diff removes all of this session debugging mechanism which
is the main cause of that unsafe design. There are no reuseable parts
in that code (it cannot be reconstructed into a proper control program
interface). As a result, the privsep monitor now has unveil to the
config directory, and the network speaking process is "stdio sendfd
route recvfd inet". There is some loss of functionality, since some
users had gotten used to the decrepit debugging / logging interface to
repair sessions which would not negotiate.
This is almost completely unmaintained code from early OpenBSD days
with an incorrect privsep design, and many users have migrated to
using iked(8) which does IKEv2 protocol. RFC9395 also provides valuable
guidance here. Everyone is urged to avoid using this program. If IKEv1
protocol is still a part of your life roll up sleeves and try to write a
high-quality control interface using lessons from the IKEv2 iked(8) code.
[2 lines not shown]
Backport fixes from libexpat version 2.8.5.
Relevant for OpenBSD are security fixes #1282, bug fixes #1346
#1371, other changes #1354 #1357 #1349 #1360 #1378. Library bump
is not necessary.
CVE-2026-93990
OK deraadt@
relayd: do not treat a missing Host header as a url match
Return RES_BAD if the request has no Host header, consistent with the
handling of empty or malformed Host values.
Spotted by Acts1631 (with diff), OK kirill@
When converting a section identifier (for example, "1" or "1m") to
a volume title (for example, "General Commands Manual" or "Maintenance
Commands") and no exact match is found for the identifier, retry
using only the first character of the identifier before giving up.
For example, when using OpenBSD to format the Oracle Solaris ipmitool(1m)
manual, which contains the line '.TH ipmitool 1m "29 June 2012"',
use the section 1 volume title "General Commands Manual" rather
than finding no title at all. In general, this improves formatting
of the page header line of manual pages using session suffixes that
are not declared in msec.in on the formatting system. That's useful
everywhere for formatting foreign manual pages, but also for
formatting native manuals on systems using many suffixes.
I had this idea for a small improvement while looking at how FreeBSD
customizes the companion file msec.in in their freebsd-src/contrib/mandoc
directory.
sys/usb: validate USB endpoint and configuration lengths
Reject undersized endpoint descriptors before accessing wMaxPacketSize;
require wTotalLength to cover the configuration header and match the
allocated size after the full fetch.
Reported by Stuart Thomas
OK: deraadt@
Instead of redrawing the entire pane or scene when moving or redrawing a
pane, add damage rectangles and redraw only the affected spans. From
Michael Grant.