OpenBSD/src V1nIVFm — usr.sbin/rtrd rtrd.h

   knf
VersionDeltaFile
1.4+47-93usr.sbin/rtrd/rtrd.h
+47-931 files

OpenBSD/src h63RKal — usr.sbin/rtrctl rtrctl.c, usr.sbin/rtrd rtrd.h

   rather than a local defintion, use __packed provided by cdefs.h, because
   other -portable software is also happy with that approach
VersionDeltaFile
1.3+36-38usr.sbin/rtrd/rtrd.h
1.6+14-16usr.sbin/rtrctl/rtrctl.c
+50-542 files

OpenBSD/src EeDnDGC — sys/arch/amd64/amd64 cpu.c

   don't mix silicon debug test with fast strings

   fixes a mistake introduced when code was moved into cpu_fix_msrs()
   in cpu.c rev 1.160

   from daniel@, ok deraadt@
VersionDeltaFile
1.207+4-3sys/arch/amd64/amd64/cpu.c
+4-31 files

OpenBSD/src lAKY4Q6 — lib/libcrypto/asn1 a_object.c, lib/libcrypto/bn bn_convert.c bn_add.c

   libcrypto: avoid undefined behavior with zero-length buffers

   Avoid UBSan failures caused by null pointers in zero-length operations.

   - Avoid zero-offset arithmetic on null BIGNUM data
   - Return early for zero-length BIGNUM output
   - Avoid passing a null destination to strlcpy
   - Skip memcmp for empty test vectors

   ok beck
VersionDeltaFile
1.30+23-1lib/libcrypto/bn/bn_add.c
1.57+9-1lib/libcrypto/asn1/a_object.c
1.10+2-2regress/lib/libcrypto/bn/bn_convert.c
1.26+3-1lib/libcrypto/bn/bn_convert.c
+37-54 files

OpenBSD/src XaJ5n0A — lib/libcrypto/evp bio_b64.c

   Report invalid base64 BIO state as an internal error

   The base64 BIO filter uses OPENSSL_assert() for several internal buffer
   state checks. OPENSSL_assert() calls OpenSSLDie() on failure, which
   terminates the process instead of returning an error to the caller.

   Replace these assertions with explicit checks that raise
   ERR_R_INTERNAL_ERROR on the BIO error queue and return an error from
   b64_read(), b64_write(), or b64_ctrl(). This preserves the internal state
   checks while allowing callers to handle the failure through the BIO API.

   ok tb joshua beck
VersionDeltaFile
1.31+74-21lib/libcrypto/evp/bio_b64.c
+74-211 files

OpenBSD/src NYzz6FW — usr.bin/ssh scp.c

   Disallow nul byte in received scp -O filename.  Not reachable in normal
   operation since a nul would cause a filename mismatch, but potentially
   possible if being used an unusual configuration such as a custom filter.

   Reported by Chua Wei Xun <weixun.chua at e-cq.net>, ok djm@
VersionDeltaFile
1.277+3-1usr.bin/ssh/scp.c
+3-11 files

OpenBSD/src 2oanbyg — sys/arch/arm64/dev aplmca.c

   The apple,nclusters property is a remnant of early bringup and never made
   it in the official bindings.  Drop it and calculate the number of clusters
   from the register area size.  Fixes out-of-bounds access on SoCs that
   provide less than 6 clusters.

   ok patrick@, jsg@
VersionDeltaFile
1.9+2-2sys/arch/arm64/dev/aplmca.c
+2-21 files

OpenBSD/ports EkPYWhj — security/clusterssh distinfo Makefile

   update to 4.19
VersionDeltaFile
1.27+4-2security/clusterssh/Makefile
1.17+2-2security/clusterssh/distinfo
+6-42 files

OpenBSD/ports NorjchD — devel/cabal-install Makefile distinfo, devel/cabal-install/files openbsd.json

   devel/cabal-install: update to 3.18.1.0

   OK kili@
VersionDeltaFile
1.11+87-65devel/cabal-install/files/openbsd.json
1.23+34-30devel/cabal-install/distinfo
1.47+23-12devel/cabal-install/Makefile
+144-1073 files

OpenBSD/ports dlqx3PL — lang/ghc Makefile, lang/ghc/patches patch-testsuite_tests_lib_base_executablePath_hs patch-libraries_ghc-boot_GHC_BaseDir_hs

   lang/ghc: use getexecpath(3) for executablePath on OpenBSD

   getexecpath(3) is new in OpenBSD 8.0. Without it ghc-internal falls through
   to the argv[0] fallback and System.Environment.executablePath is Nothing.

   Also let ghc-boot use base's executablePath, choosing at run time so the port
   still builds with a bootstrap compiler whose base predates getexecpath(3),
   and mark openbsd as query-capable in the executablePath test.

   Bump REVISION for the getexecpath change

   System.Environment.executablePath goes from Nothing to a working query, and
   getExecutablePath from argv[0] to a canonicalized absolute path, so the
   package behaves differently and needs to be distinguishable.

   OK kili@
VersionDeltaFile
1.1+57-0lang/ghc/patches/patch-libraries_ghc-internal_src_GHC_Internal_System_Environment_ExecutablePath_hsc
1.1+47-0lang/ghc/patches/patch-libraries_ghc-boot_GHC_BaseDir_hs
1.1+19-0lang/ghc/patches/patch-testsuite_tests_lib_base_executablePath_hs
1.237+1-0lang/ghc/Makefile
+124-04 files

OpenBSD/ports 8CDocR9 — sysutils/broot Makefile crates.inc

   Update broot to 1.60.2.
VersionDeltaFile
1.47+126-158sysutils/broot/distinfo
1.37+62-78sysutils/broot/crates.inc
1.53+1-1sysutils/broot/Makefile
+189-2373 files

OpenBSD/ports SEXbWak — graphics/blender Makefile, graphics/blender/patches patch-intern_libmv_libmv_build_build_config_h patch-source_blender_blenlib_BLI_build_config_h

   Make blender build on sparc64

   patch from Brad Smith
VersionDeltaFile
1.1+45-0graphics/blender/patches/patch-source_blender_blenlib_BLI_build_config_h
1.1+32-0graphics/blender/patches/patch-intern_libmv_libmv_build_build_config_h
1.158+1-2graphics/blender/Makefile
+78-23 files

OpenBSD/ports 1APROMu — security/gnupg Makefile distinfo

   Revert to gnupg-2.5.22 because gnupg-2.5.23+ breaks mail/notmuch

   mail/notmuch uses gmime -> gpgme -> gnupg to decrypt PGP-encrypted
   messages, and check for that feature in it configure script.  Since

   commit 2e6549f5de5307e3e84c1ffa5e762d14266546ba
   gpg: Preliminary support for importing some rfc-9980 secret keys.

   gpg-agent now appears unable to export the "session key" used by notmuch
   tests, so gpg has no key to pass back to gpgme/gmime. The code in
   notmuch/configure mimics the code in notmuch/util/crypto.c so we can
   expect this to be an actual regression. Revert to the previous gnupg
   release to unbreak bulk builds and avoid regressions.

   Reported by sthen@
VersionDeltaFile
1.57+2-2security/gnupg/distinfo
1.153+2-1security/gnupg/Makefile
+4-32 files

OpenBSD/src b667MI5 — lib/libc/gen getgrouplist.c, lib/libutil passwd.c

   Incorrect upper bound for uid and gid can result in -1 being used.
   smtpd and YP/ldap situations are the most worrying.
   Different fix from -current, because -stable avoids API/ABI changes.
   from deraadt@

   this is errata/7.9/030_uidrange.patch.sig
VersionDeltaFile
1.55.6.1+5-5usr.sbin/ypldap/ldapclient.c
1.22.12.1+4-4usr.sbin/ypldap/yp.c
1.51.2.1+3-3usr.sbin/smtpd/to.c
1.57.2.1+3-3lib/libutil/passwd.c
1.32.2.1+3-3lib/libc/gen/getgrouplist.c
1.359.2.1+3-2usr.sbin/smtpd/smtpd.c
+21-201 files not shown
+23-227 files

OpenBSD/src FOyI6na — lib/libc/gen getgrouplist.c, lib/libutil passwd.c

   Incorrect upper bound for uid and gid can result in -1 being used.
   smtpd and YP/ldap situations are the most worrying.
   Different fix from -current, because -stable avoids API/ABI changes.
   from deraadt@

   this is errata/7.8/066_uidrange.patch.sig
VersionDeltaFile
1.55.2.1+5-5usr.sbin/ypldap/ldapclient.c
1.22.8.1+4-4usr.sbin/ypldap/yp.c
1.50.8.1+3-3usr.sbin/smtpd/to.c
1.56.24.1+3-3lib/libutil/passwd.c
1.31.2.1+3-3lib/libc/gen/getgrouplist.c
1.357.2.2+3-2usr.sbin/smtpd/smtpd.c
+21-201 files not shown
+23-227 files

OpenBSD/src XcRJRYt — lib/libcrypto/x509 x509_verify.c, lib/libssl d1_pkt.c d1_both.c

   Don't drop X509_V_ERR_HOSTNAME_MISMATCH when verify callback returns 1

   While not the advised way of using the verify callback (either by OpenSSL
   or by us) in production, sometimes folks like to return 1 from everything
   in the callback and then check the error return and make decicions about
   things.

   This fix ensures that such callbacks will see the hostname mismatch and
   be able to act upon them.

   Reported by Alexander Aleksandrovic Klimov
   from beck, ok tb@

   Correct botched size check in dtls1_preprocess_fragment().

   Check message length against max, rather than fragment offset and length.
   Due to a various questionable code, this allows for a crafted messsage
   to be sent that results in a 21MB allocation, which then promptly results
   in an error. Providing that the SSL context is cleared or freed, the

    [136 lines not shown]
VersionDeltaFile
1.85.2.1+18-8lib/libssl/d1_both.c
1.73.2.1+14-6lib/libcrypto/x509/x509_verify.c
1.26.4.1+2-10lib/libtls/tls_ocsp.c
1.130.2.1+3-3lib/libssl/d1_pkt.c
1.34.2.1+2-3usr.sbin/ocspcheck/ocspcheck.c
+39-305 files

OpenBSD/src NTH4cJG — lib/libcrypto/x509 x509_verify.c, lib/libssl d1_pkt.c d1_both.c

   Don't drop X509_V_ERR_HOSTNAME_MISMATCH when verify callback returns 1

   While not the advised way of using the verify callback (either by OpenSSL
   or by us) in production, sometimes folks like to return 1 from everything
   in the callback and then check the error return and make decicions about
   things.

   This fix ensures that such callbacks will see the hostname mismatch and
   be able to act upon them.

   Reported by Alexander Aleksandrovic Klimov
   from beck, ok tb@

   Correct botched size check in dtls1_preprocess_fragment().

   Check message length against max, rather than fragment offset and length.
   Due to a various questionable code, this allows for a crafted messsage
   to be sent that results in a 21MB allocation, which then promptly results
   in an error. Providing that the SSL context is cleared or freed, the

    [77 lines not shown]
VersionDeltaFile
1.85.6.1+18-8lib/libssl/d1_both.c
1.29.2.1+2-10lib/libtls/tls_ocsp.c
1.76.2.1+5-2lib/libcrypto/x509/x509_verify.c
1.130.6.1+3-3lib/libssl/d1_pkt.c
1.34.6.1+2-3usr.sbin/ocspcheck/ocspcheck.c
+30-265 files

OpenBSD/ports cbCc9Kg — geo/cdo distinfo Makefile

   Update cdo to 2.6.4. From maintainer Marco van Hulten, thanks.
   Improve WANTLIB while there.
VersionDeltaFile
1.4+5-5geo/cdo/Makefile
1.4+2-2geo/cdo/distinfo
+7-72 files

OpenBSD/ports n7cAQAY — productivity/baikal Makefile distinfo, productivity/baikal/pkg PLIST

   Update baikal to 0.12.1.
VersionDeltaFile
1.21+82-79productivity/baikal/pkg/PLIST
1.17+2-2productivity/baikal/distinfo
1.44+1-2productivity/baikal/Makefile
+85-833 files

OpenBSD/ports QsNd2pn — mail/p5-MIME-tools Makefile distinfo

   bugfix update to 5.519
VersionDeltaFile
1.23+2-2mail/p5-MIME-tools/distinfo
1.47+1-1mail/p5-MIME-tools/Makefile
+3-32 files

OpenBSD/ports m2vXUzk — telephony/resiprocate Makefile

   BDEP on sox, reported by naddy
VersionDeltaFile
1.16+2-1telephony/resiprocate/Makefile
+2-11 files

OpenBSD/ports W85mFp2 — math/py-scipy/patches patch-pyproject_toml

   Relax meson-python version check.
VersionDeltaFile
1.7+6-2math/py-scipy/patches/patch-pyproject_toml
+6-21 files

OpenBSD/ports zGWQglh — devel/meson-python Makefile

   Missing RDEP on sysutils/patchelf.
VersionDeltaFile
1.16+3-1devel/meson-python/Makefile
+3-11 files

OpenBSD/ports UDeqvuF — net/knot distinfo

   distinfo for libknot fell in here, use distinfo for knot instead
VersionDeltaFile
1.55+2-2net/knot/distinfo
+2-21 files

OpenBSD/src xp6DSxi — sys/kern sysv_sem.c

   Avoid sleeping while recording SEM_UNDO information

   sys_semop(), by way of semundo_adjust() and semu_alloc(), could sleep in
   pool_get(PR_WAITOK) after it had already applied the semaphore operations.
   Another process can remove the set with IPC_RMID while we sleep; we then write
   sempid and sem_otime through the freed semid_ds_kern and sem_base, and record
   an undo entry for a set semundo_clear() has already swept, which panics
   semexit() when the process exits.

   This was introduced as a fallback in rev 1.14, after moving the
   structures from a static array to a pool made the allocation able to
   fail at all.  semop(2) documents ENOSPC, so drop the fallback with the
   extra complexity to work around the sleep.

   semundo_adjust() must then stop freeing an emptied structure in the middle of
   an operation: sys_semop()'s rollback can need it again, and re-creating it
   there is allowed to fail, which is a panic.  Keep it until done2.  That also
   takes a second sleeping pool_put() out of the done: region.


    [8 lines not shown]
VersionDeltaFile
1.66.2.2+41-44sys/kern/sysv_sem.c
+41-441 files

OpenBSD/src niZpBUM — sys/kern sysv_sem.c

   Avoid sleeping while recording SEM_UNDO information

   sys_semop(), by way of semundo_adjust() and semu_alloc(), could sleep in
   pool_get(PR_WAITOK) after it had already applied the semaphore operations.
   Another process can remove the set with IPC_RMID while we sleep; we then write
   sempid and sem_otime through the freed semid_ds_kern and sem_base, and record
   an undo entry for a set semundo_clear() has already swept, which panics
   semexit() when the process exits.

   This was introduced as a fallback in rev 1.14, after moving the
   structures from a static array to a pool made the allocation able to
   fail at all.  semop(2) documents ENOSPC, so drop the fallback with the
   extra complexity to work around the sleep.

   semundo_adjust() must then stop freeing an emptied structure in the middle of
   an operation: sys_semop()'s rollback can need it again, and re-creating it
   there is allowed to fail, which is a panic.  Keep it until done2.  That also
   takes a second sleeping pool_put() out of the done: region.


    [8 lines not shown]
VersionDeltaFile
1.65.2.2+41-44sys/kern/sysv_sem.c
+41-441 files

OpenBSD/src Nts9fb4 — sys/net if_wg.c

   In wg_bind() close IPv4 socket while failed to bind IPv6 socket with
   automatic port selection.
   from mvs@; From Acts1631.

   this is errata/7.9/028_wgbind.patch.sig
VersionDeltaFile
1.48.2.1+6-4sys/net/if_wg.c
+6-41 files

OpenBSD/src 7lfKyF5 — sys/net if_wg.c

   In wg_bind() close IPv4 socket while failed to bind IPv6 socket with
   automatic port selection.
   from mvs@; From Acts1631.

   this is errata/7.8/064_wgbind.patch.sig
VersionDeltaFile
1.47.2.1+6-4sys/net/if_wg.c
+6-41 files

OpenBSD/src IEV73EJ — sbin/iked iked.h ca.c

   iked: Reject malformed and out-of-state IKEv2 messages

   A malicious or malformed IKEv2 peer could crash iked, or cause a
   certificate validation verdict to be applied to the wrong peer
   identity. Reject malformed DELETE payloads and EAP responses for
   which no matching server state exists, and bind CA and OCSP verdicts
   to the identity they were computed for.

   Reported by Stefan Rinkes and acts1631kjv at proton me.
   from hshoexer@; OK markus@

   this is errata/7.9/027_iked.patch.sig
VersionDeltaFile
1.398.2.1+52-1sbin/iked/ikev2.c
1.138.4.1+24-9sbin/iked/ikev2_pld.c
1.14.6.1+26-2sbin/iked/radius.c
1.105.6.2+8-6sbin/iked/ca.c
1.25.12.1+10-4sbin/iked/ocsp.c
1.233.8.1+2-2sbin/iked/iked.h
+122-246 files

OpenBSD/src xV7ehPG — sbin/iked iked.h ca.c

   iked: Reject malformed and out-of-state IKEv2 messages

   A malicious or malformed IKEv2 peer could crash iked, or cause a
   certificate validation verdict to be applied to the wrong peer
   identity. Reject malformed DELETE payloads and EAP responses for
   which no matching server state exists, and bind CA and OCSP verdicts
   to the identity they were computed for.

   Reported by Stefan Rinkes and acts1631kjv at proton me.
   from hshoexer@; OK markus@

   this is errata/7.8/063_iked.patch.sig
VersionDeltaFile
1.394.2.3+52-1sbin/iked/ikev2.c
1.136.4.2+24-9sbin/iked/ikev2_pld.c
1.14.2.1+26-2sbin/iked/radius.c
1.105.2.2+8-6sbin/iked/ca.c
1.25.6.1+10-4sbin/iked/ocsp.c
1.233.2.1+2-2sbin/iked/iked.h
+122-246 files