OpenBSD/src zl9bFfK — sys/dev/ic qwzvar.h qwz.c, sys/dev/pci if_qwz_pci.c

   sys/qwz: unwind cold startup failures

   Based on sys/dev/ic/qwx.c,v 1.134

   Track powerup and completed core initialization so failed cold starts
   reset hardware before reclaiming initialized DMA resources. Release
   partial TX allocations and RX rings; ordinary interface down and up
   continues to retain firmware.

   OK: stsp@
VersionDeltaFile
1.66+100-26sys/dev/ic/qwz.c
1.18+4-2sys/dev/pci/if_qwz_pci.c
1.23+2-1sys/dev/ic/qwzvar.h
+106-293 files

OpenBSD/src VQn7YMy — sys/dev/ic qwzvar.h qwz.c

   sys/qwz: skip uninitialized CE polling

   Based on sys/dev/ic/qwx.c,v 1.135

   Track successful CE initialization to decide whether completion
   polling is valid; provide dircet TX buffer reclamation for cold
   cleanup after hardware reset, when ring polling is no longer safe.

   OK: stsp@
VersionDeltaFile
1.65+22-3sys/dev/ic/qwz.c
1.22+2-1sys/dev/ic/qwzvar.h
+24-42 files

OpenBSD/src TsEHEXf — sys/dev/ic qwzvar.h qwz.c, sys/dev/pci if_qwz_pci.c

   sys/qwz: allocate management maps at attach

   Backport of sys/dev/ic/qwx.c,v 1.139 , sys/dev/ic/qwxvar.h,v 1.39
   and sys/dev/pci/if_qwx_pci.c,v 1.40

   OK: stsp@
VersionDeltaFile
1.17+17-2sys/dev/pci/if_qwz_pci.c
1.64+4-10sys/dev/ic/qwz.c
1.21+5-2sys/dev/ic/qwzvar.h
+26-143 files

OpenBSD/src wkszEze — sys/dev/ic qwzvar.h qwz.c

   sys/qwz: retain the host VIF

   Backport of sys/dev/ic/qwx.c,v 1.138 and sys/dev/ic/qwxvar.h,v 1.38

   OK: stsp@
VersionDeltaFile
1.63+69-101sys/dev/ic/qwz.c
1.20+2-7sys/dev/ic/qwzvar.h
+71-1082 files

OpenBSD/src lonXqon — sys/dev/ic qwz.c

   sys/qwz: initialize QRTR before power-up

   Backport of sys/dev/ic/qwx.c,v 1.132

   OK: stsp@
VersionDeltaFile
1.62+4-4sys/dev/ic/qwz.c
+4-41 files

OpenBSD/src mDl2mmD — sys/dev/ic qwz.c

   sys/qwz: propagate firmware startup errors

   Backport of sys/dev/ic/qwx.c,v 1.128

   OK: stsp@
VersionDeltaFile
1.61+4-5sys/dev/ic/qwz.c
+4-51 files

OpenBSD/src acSCJ5q — sys/dev/ic qwz.c

   sys/qwz: mark running after MAC startup

   Backport of sys/dev/ic/qwx.c,v 1.122 and sys/dev/ic/qwx.c,v 1.134

   OK: stsp@
VersionDeltaFile
1.60+5-6sys/dev/ic/qwz.c
+5-61 files

OpenBSD/src SFcdrSJ — sys/dev/ic qwz.c

   sys/qwz: retain HAL allocations on resume

   Based on sys/dev/ic/qwx.c,v 1.97 and sys/dev/ic/qwx.c,v 1.136

   Preserve HAL allocation pointers across reinitialization: reuse qwz
   allocated ring configuration and claer retained pointer memory. On
   failure, free only allocations made by the current attempt.

   OK: stsp@
VersionDeltaFile
1.59+18-11sys/dev/ic/qwz.c
+18-111 files

OpenBSD/src 11kMeqb — sys/dev/ic qwz.c

   sys/qwz: wait for cookie pool allocations

   Backport of sys/dev/ic/qwx.c,v 1.127

   OK: stsp@
VersionDeltaFile
1.58+8-29sys/dev/ic/qwz.c
+8-291 files

OpenBSD/src o9WHC8v — sys/dev/ic qwz.c

   sys/qwz: wait for startup allocations

   Backport of sys/dev/ic/qwx.c,v 1.127

   OK: stsp@
VersionDeltaFile
1.57+17-29sys/dev/ic/qwz.c
+17-291 files

OpenBSD/ports T0mnlFj — graphics/png distinfo Makefile, graphics/png/patches patch-Makefile_in

   update to png-1.6.59
   https://github.com/pnggroup/libpng/security/advisories/GHSA-qvg3-h654-xq3j
VersionDeltaFile
1.150.2.1+6-3graphics/png/Makefile
1.6.4.1+3-3graphics/png/patches/patch-Makefile_in
1.79.2.1+2-2graphics/png/distinfo
+11-83 files

OpenBSD/ports BKXvJP0 — graphics/png distinfo Makefile, graphics/png/patches patch-Makefile_in

   update to png-1.6.59, fixing use-after-free of zlib input in
   png_read_end() after incomplete zTXt, iTXt or iCCP decompression
   https://github.com/pnggroup/libpng/security/advisories/GHSA-qvg3-h654-xq3j

   ok matthieu who has verified that this is not reachable from xenocara's
   use of the static-linked copy
VersionDeltaFile
1.151+6-3graphics/png/Makefile
1.7+3-3graphics/png/patches/patch-Makefile_in
1.80+2-2graphics/png/distinfo
+11-83 files

OpenBSD/ports tzUvWuF — sysutils/telegraf Makefile, sysutils/telegraf/patches patch-plugins_inputs_unbound_unbound_go patch-plugins_inputs_nsd_nsd_go

   set -u _nsd / _unbound as appropriate when running nsd-control /
   unbound-control through doas, to match the existing pkg-readme.
   from Atanas Vladimirov.
VersionDeltaFile
1.3+6-3sysutils/telegraf/pkg/README
1.6+4-2sysutils/telegraf/patches/patch-plugins_inputs_unbound_unbound_go
1.4+4-2sysutils/telegraf/patches/patch-plugins_inputs_nsd_nsd_go
1.48+2-0sysutils/telegraf/Makefile
+16-74 files

OpenBSD/ports ytOzOeq — meta/tor-browser Makefile, www/tor-browser Makefile.inc

   Tor Browser: update to 15.0.24
VersionDeltaFile
1.118.2.9+6-6www/tor-browser/browser/distinfo
1.67.2.8+2-2www/tor-browser/noscript/distinfo
1.124.2.9+2-2meta/tor-browser/Makefile
1.74.2.8+1-1www/tor-browser/noscript/Makefile
1.197.2.9+1-1www/tor-browser/browser/Makefile
1.121.2.9+1-1www/tor-browser/Makefile.inc
+13-136 files

OpenBSD/ports eQ1CBAh — meta/tor-browser Makefile, www/tor-browser Makefile.inc

   Tor Browser: update to 15.0.24

   OK naddy@
VersionDeltaFile
1.133+6-6www/tor-browser/browser/distinfo
1.77+2-2www/tor-browser/noscript/distinfo
1.138+2-2meta/tor-browser/Makefile
1.84+1-1www/tor-browser/noscript/Makefile
1.216+1-1www/tor-browser/browser/Makefile
1.135+1-1www/tor-browser/Makefile.inc
+13-136 files

OpenBSD/src MU2k9qv — lib/libc/stdlib malloc.c

   For allocations between half a page and a page (which are moved
   towards the end) we don't clear the proper region with freezero().
   Instead, the clearing is done from the start of the page. So fix that.
   Reported by Acts1631

   ok deraadt@
VersionDeltaFile
1.301+5-1lib/libc/stdlib/malloc.c
+5-11 files

OpenBSD/src n0jC4ZF — share/man/man4 qwz.4 qwx.4

   differentiate the two qualcomm wifi drivers by well-understood names
   Wi-Fi 6 and Wi-Fi 7, even if it looks a bit like puke
   discussed with kettenis
VersionDeltaFile
1.11+3-3share/man/man4/qwx.4
1.3+2-2share/man/man4/qwz.4
+5-52 files

OpenBSD/src v29Sly0 — usr.sbin/rpki-client output-rtrx.c

   handle EINPROGRESS and carry errno through.
   OK deraadt@
VersionDeltaFile
1.4+20-5usr.sbin/rpki-client/output-rtrx.c
+20-51 files

OpenBSD/src YJ0ZGH3 — sys/dev softraid.c

   Fix softraid rebuild on disks with 4096-byte sectors.

   Problem found, suggested diffs, and testing by Dariusz Swiderski.

   ok claudio@ "makes release" deraadt@
VersionDeltaFile
1.440+9-6sys/dev/softraid.c
+9-61 files

OpenBSD/src hdBBbzy — usr.sbin/rpki-client output-rtrx.c

   correct include order
VersionDeltaFile
1.3+2-2usr.sbin/rpki-client/output-rtrx.c
+2-21 files

OpenBSD/src znFsEwI — usr.sbin/rpki-client output-rtrx.c

   use __packed; ok rcovelli
VersionDeltaFile
1.2+11-13usr.sbin/rpki-client/output-rtrx.c
+11-131 files

OpenBSD/src Mf8hmAy — usr.sbin/rpki-client Makefile extern.h

   Add option -r to output tables directly to the rtrd(8) controller socket.
   OK deraadt@
VersionDeltaFile
1.1+541-0usr.sbin/rpki-client/output-rtrx.c
1.314+11-4usr.sbin/rpki-client/main.c
1.48+12-1usr.sbin/rpki-client/output.c
1.144+7-3usr.sbin/rpki-client/rpki-client.8
1.300+7-1usr.sbin/rpki-client/extern.h
1.42+2-1usr.sbin/rpki-client/Makefile
+580-106 files

OpenBSD/ports TcDrRW9 — games/devilutionx Makefile, games/devilutionx/patches patch-Source_dvlnet_tcp_server_cpp

   missed cvs add to go with devilutiomx/Makefile r1.21, unbreaking
   newer asio. from Brad.
VersionDeltaFile
1.1+15-0games/devilutionx/patches/patch-Source_dvlnet_tcp_server_cpp
1.23+1-1games/devilutionx/Makefile
+16-12 files

OpenBSD/ports rtreQij — textproc/groff Makefile, textproc/groff/patches patch-contrib_mm_mmroff_pl patch-src_preproc_html_pre-html_cpp

   Backport three security fixes from the groff-1.24.2 release.
   OK naddy@ on a previous, minimally different version of this patch.

   From the groff-1.24.2 release announcement (September 28, 2026):
   "This release corrects command injection security vulnerabilities
   (CWE-78) in the mmroff, pdfmom, and pre-grohtml programs.  The last of
   these is a preprocessor that is run when groff or troff is run with the
   -T html or -T xhtml options.  The vulnerabilities are variously
   14-26 years old.  Malicious input can escape groff's default "safer"
   mode, running commands embedded in that input at the user's privilege
   level.  The groff development team recommends this release to any users
   who employ the named tools or GNU troff output formats with untrusted
   inputs.
   Man page rendering is not vulnerable unless rendering (X)HTML."
VersionDeltaFile
1.1+82-0textproc/groff/patches/patch-src_devices_gropdf_pdfmom_pl
1.3+35-12textproc/groff/patches/patch-src_roff_troff_input_cpp
1.1+39-0textproc/groff/patches/patch-src_preproc_html_pre-html_cpp
1.1+24-0textproc/groff/patches/patch-contrib_mm_mmroff_pl
1.53+1-1textproc/groff/Makefile
+181-135 files

OpenBSD/ports ZIx0pWO — mail/postfix/stable Makefile, security/sslscan Makefile

   bump ports with static links against security/openssl/3.5 in -stable
VersionDeltaFile
1.56.2.3+1-1sysutils/borgbackup/2.0/Makefile
1.86.2.3+1-1security/sslscan/Makefile
1.281.2.8+1-0mail/postfix/stable/Makefile
+3-23 files

OpenBSD/ports mJSFADA — security/openssl/3.5 Makefile distinfo, security/openssl/3.5/pkg PLIST

   MFC: Update to OpenSSL 3.5.9

   https://github.com/openssl/openssl/releases/tag/openssl-3.5.9
VersionDeltaFile
1.7.2.3+2-2security/openssl/3.5/distinfo
1.16.2.3+1-1security/openssl/3.5/Makefile
1.7.2.3+2-0security/openssl/3.5/pkg/PLIST
+5-33 files

OpenBSD/ports Pd8bpzp — mail/postfix/stable Makefile, security/sslscan Makefile

   bump ports with static link against security/openssl/3.5
VersionDeltaFile
1.64+2-0sysutils/borgbackup/2.0/Makefile
1.90+1-0security/sslscan/Makefile
1.289+1-0mail/postfix/stable/Makefile
+4-03 files

OpenBSD/ports Qu9OKte — security/openssl/3.5 Makefile distinfo, security/openssl/3.5/pkg PLIST

   Update to OpenSSL 3.5.9, ok naddy

   https://github.com/openssl/openssl/releases/tag/openssl-3.5.9
VersionDeltaFile
1.10+2-2security/openssl/3.5/distinfo
1.19+1-1security/openssl/3.5/Makefile
1.10+2-0security/openssl/3.5/pkg/PLIST
+5-33 files

OpenBSD/ports f8r12LY — security/openssl/4.0 Makefile distinfo, security/openssl/4.0/pkg PLIST

   Update to openssl 4.0.3, ok naddy

   https://github.com/openssl/openssl/releases/tag/openssl-4.0.3
VersionDeltaFile
1.5+2-2security/openssl/4.0/distinfo
1.8+1-1security/openssl/4.0/Makefile
1.5+2-0security/openssl/4.0/pkg/PLIST
+5-33 files

OpenBSD/src AMEral4 — lib/libcrypto/x509 x509_crld.c

   set_dist_point_name(): tiny tweak to restore previous behavior

   Allocate fnm before allocating *pdp. This way a second call to to
   set_dist_point_name() has a tiny little chance of succeeding.

   ok beck ("I strongly suspect this will never matter anywhere.")
VersionDeltaFile
1.13+4-4lib/libcrypto/x509/x509_crld.c
+4-41 files