OpenBSD/src HCgyNG1 — lib/libc/sys send.2

   Describe what sendmmsg(2) actually does and fix prototype.

   ok deraadt@
VersionDeltaFile
1.36+18-5lib/libc/sys/send.2
+18-51 files

OpenBSD/src hpncMba — usr.bin/ssh scp.c

   start process of deprecating the -R flag. This was the old way of
   performing a remote-to-remote copy that was basically executed scp on
   the remote host. It barely worked (needing agent forwarding enabled or
   usable credentials on the remote host) and has largely been replaced
   by a better SFTP-protocol remote-to-remote copy that runs through the
   host performing the copy.

   We'll disable this option in a release or two; ok dtucker@
VersionDeltaFile
1.278+3-1usr.bin/ssh/scp.c
+3-11 files

OpenBSD/src AhkY8jG — usr.bin/ssh ssh-keygen.1

   mention default KDF rounds is now 32
VersionDeltaFile
1.242+3-3usr.bin/ssh/ssh-keygen.1
+3-31 files

OpenBSD/src g826yro — usr.bin/ssh sshkey.c

   Implement a maximum number of KDF rounds that will be accepted when
   writing an OpenSSH-format private key or when loading one. This limit
   is set pretty high (1<<20), but ensures that a service that is passed a
   bad key with an ridiculously high number of rounds will _eventually_
   complete parsing it.

   Also bump the default number of KDF rounds from 24 to 32 (this is a
   linear increase, not like bcrypt(3) which is exponential).

   Pointed out by Aris Adamantiadis
VersionDeltaFile
1.165+11-2usr.bin/ssh/sshkey.c
+11-21 files

OpenBSD/ports eo4oRVn — lang/python/3 Makefile, lang/python/3/patches patch-Modules__ssl_c

   cherrypick fix for CPython CVE-2026-19445: Use-after-free of a
   server-side SSLContext when sni_callback switches contexts. ok tb kmos
VersionDeltaFile
1.6.2.1+56-25lang/python/3/patches/patch-Modules__ssl_c
1.25.2.3+1-0lang/python/3/Makefile
+57-252 files

OpenBSD/ports QTrl6WC — lang/python/3 Makefile, lang/python/3/patches patch-Modules__ssl_c

   cherrypick fix for CPython CVE-2026-19445: Use-after-free of a
   server-side SSLContext when sni_callback switches contexts. ok tb kmos

   A remote, unauthenticated TLS client can make a server crash or call
   through a freed pointer if its sni_callback assigns a different context
   to SSLSocket.context (the documented way to select a certificate per
   server name) and nothing else keeps the original ssl.SSLContext alive.
   Typical cases are servers that create an SSLContext per connection or
   replace it while connections are open.
VersionDeltaFile
1.6+84-6lang/python/3/patches/patch-Modules__ssl_c
1.35+1-0lang/python/3/Makefile
+85-62 files

OpenBSD/src b2OCjYc — usr.bin/ssh ssh-mldsa-eddsa.c

   fix the bit length of ML-DSA 44/Ed25519 keys that was being
   incorrectly reported as 256. The private key length for these
   composite keys is 512 bits. This value is only used for display.

   Spotted by Yiyue Wang
VersionDeltaFile
1.7+3-3usr.bin/ssh/ssh-mldsa-eddsa.c
+3-31 files

OpenBSD/src qXJOc94 — usr.bin/ssh sftp-client.c sftp.c

   sftp: be stricter in accepting paths returned by the server for
   SSH_FXP_REALPATH or SSH2_FXP_READDIR replies, as these can be
   used in some situations to decide the destination path for recursive
   transfers.

   Report and patch from Junghoon Cho
VersionDeltaFile
1.260+10-4usr.bin/ssh/sftp.c
1.188+3-2usr.bin/ssh/sftp-client.c
+13-62 files

OpenBSD/src oYrJoa3 — usr.bin/ssh auth2-pubkey.c

   handle max-pk-ok path identically when the incoming user is invalid;
   avoids max-pk-ok feature presenting a username validity oracle

   analysis and patch from Chris Rohlf in collaboration with Claude and
   Anthropic Research
VersionDeltaFile
1.131+8-6usr.bin/ssh/auth2-pubkey.c
+8-61 files

OpenBSD/src 7XkA8Nt — usr.sbin/rpki-client main.c

   Now that we open early we can remove unix pledge
   OK deraadt@
VersionDeltaFile
1.316+2-2usr.sbin/rpki-client/main.c
+2-21 files

OpenBSD/src LQIgayk — sys/conf newvers.sh

   8.0 -current development
VersionDeltaFile
1.219+3-3sys/conf/newvers.sh
+3-31 files

OpenBSD/ports JCxKe70 — net/libtorrent distinfo Makefile, net/libtorrent/patches patch-test_Makefile_in

   update net/libtorrent 0.16.24

   - major bump due to removed symbols
   - unbreaks tests by linking using static archive (from tj@)

   approved by sthen@ and tested by and OK tj@
VersionDeltaFile
1.9+25-9net/libtorrent/patches/patch-test_Makefile_in
1.75+2-3net/libtorrent/Makefile
1.25+2-2net/libtorrent/distinfo
+29-143 files

OpenBSD/ports xwTjQsY — net/rtorrent Makefile distinfo, net/rtorrent/patches patch-test_Makefile_in

   update net/rtorrent 0.16.24

   - various security fixes (e.g., overflow, heap overflow and use-after-free)
   - regen test/Makefile.in patch to remove a new, third instance of -ldl

   approved by sthen@ and tested by and OK tj@
VersionDeltaFile
1.11+4-1net/rtorrent/patches/patch-test_Makefile_in
1.25+2-2net/rtorrent/distinfo
1.81+1-2net/rtorrent/Makefile
+7-53 files

OpenBSD/src SCtaIn4 — sys/dev/ic qwz.c

   sys/qwz: avoid peer access after key waits

   Do not retain a pointer into peer cipher state across key installation.
   Installation can sleep while the peer is removed; dropping the failure
   rollback avoids accessing freed peer memory.

   OK: stsp@
VersionDeltaFile
1.74+3-7sys/dev/ic/qwz.c
+3-71 files

OpenBSD/src gvBpFDP — sys/dev/ic qwzvar.h qwz.c

   sys/qwz: track pairwise and group RX ciphers

   Backport of sys/dev/ic/qwx.c,v 1.88 and sys/dev/ic/qwxvar.h,v 1.30

   OK: stsp@
VersionDeltaFile
1.73+40-22sys/dev/ic/qwz.c
1.25+6-4sys/dev/ic/qwzvar.h
+46-262 files

OpenBSD/src QJmdrJB — sys/dev/ic qwz.c

   sys/qwz: report HT transmit rates

   Backport missed pieces from sys/dev/ic/qwx.c,v 1.85

   OK: stsp@
VersionDeltaFile
1.72+8-4sys/dev/ic/qwz.c
+8-41 files

OpenBSD/src ThwFgyS — sys/dev/ic qwz.c

   sys/qwz: discard stale foreground scan results

   Backport of sys/dev/ic/qwx.c,v 1.79

   OK: stsp@
VersionDeltaFile
1.71+6-1sys/dev/ic/qwz.c
+6-11 files

OpenBSD/src Zuje2Tc — sys/dev/ic qwz.c

   sys/qwz: handle scan events during cancellation

   Ignore late scan started events while cancellation is pending;
   finish an aborting scan when firmware reports that startup failed.

   OK: stsp@
VersionDeltaFile
1.70+4-3sys/dev/ic/qwz.c
+4-31 files

OpenBSD/src KQqPflN — sys/dev/ic qwz.c

   sys/qwz: stop firmware scans on interface down

   Based on sys/dev/ic/qwx.c,v 1.72

   Abort firmware scans during interface stop, including scans still
   starting; taer down started vdevs and remaining peers even when net80211
   has not reached AUTH.

   OK: stsp@
VersionDeltaFile
1.69+7-3sys/dev/ic/qwz.c
+7-31 files

OpenBSD/src yZZglXf — sys/dev/ic qwz.c

   sys/qwz: respect the configured scan PHY mode

   Backport of sys/dev/ic/qwx.c,v 1.68

   OK: stsp@
VersionDeltaFile
1.68+17-2sys/dev/ic/qwz.c
+17-21 files

OpenBSD/src 9cIHpsW — sys/dev/ic qwzvar.h qwz.c, sys/dev/pci if_qwz_pci.c

   sys/qwz: use the standard media callback

   Backport of sys/dev/ic/qwx.c,v 1.133 and sys/dev/pci/if_qwx_pci.c,v 1.37

   OK: stsp@
VersionDeltaFile
1.67+2-19sys/dev/ic/qwz.c
1.19+2-2sys/dev/pci/if_qwz_pci.c
1.24+1-2sys/dev/ic/qwzvar.h
+5-233 files

OpenBSD/src XmDe1Si — sys/arch/amd64/amd64 vmm_machdep.c

   vmm(4): handle proper injection during mov ss/sti shadow on vmx

   arm the interrupt window when we have something to inject but are in a mov ss
   or sti interrupt shadow

   ok dv
VersionDeltaFile
1.92+40-19sys/arch/amd64/amd64/vmm_machdep.c
+40-191 files

OpenBSD/src almxoZX — usr.sbin/rpki-client main.c

   re-arrange rtrd 660 AF_UNIX connect(), setgroups/setresuid/setresgid
   privdrop, and first pledge() above the innocuous getopt() block.
   ok tb
VersionDeltaFile
1.315+23-21usr.sbin/rpki-client/main.c
+23-211 files

OpenBSD/src 7OkRLD8 — usr.sbin/rtrd sched.c packets.c

   use err() and warn(), and various knf and include reduction
   (-portable will revisit this in the next round, and then we're good)
VersionDeltaFile
1.9+27-60usr.sbin/rtrd/rtrd.c
1.6+22-37usr.sbin/rtrd/sockets.c
1.5+1-11usr.sbin/rtrd/ip_utils.c
1.5+1-10usr.sbin/rtrd/packets.c
1.3+1-10usr.sbin/rtrd/hash.c
1.6+2-8usr.sbin/rtrd/sched.c
+54-1367 files not shown
+65-16713 files

OpenBSD/src 9mMI0LS — usr.sbin/rpki-client ccr.c

   rpki-client: don't treat a duplicate CCR MFT as fatal

   It is possible to concoct situations where two PPs serve byte identical
   manifests. Then CCR generation errors with "CCR MFT tree corrupted".

   Handle this situation gracefully and only warn about the weird situation.
   There are more problems in the vicinity that need fixing but that's for
   after the release.

   Reported by eur1ka qq com. Diff is a tweaked version of the suggested fix.

   ok job
VersionDeltaFile
1.46+5-3usr.sbin/rpki-client/ccr.c
+5-31 files

OpenBSD/src uaRHfx3 — usr.sbin/rpki-client ccr.c

   rpki-client: hoist ccr_mft_free() next to ccr_mft_new()

   part of a larger diff that was ok job
VersionDeltaFile
1.45+20-20usr.sbin/rpki-client/ccr.c
+20-201 files

OpenBSD/ports fdSivOC — databases/p5-DBI Makefile distinfo, databases/p5-DBI/patches patch-DBI_xs

   Update p5-DBI to 1.654

   1.654 - 2026-09-25, H.Merijn Brand & Robert Rothenberg
       * Fix DBI::sql_type_cast on IV/NV (CVE-2026-88815) (reported by Raj)
       * Fix FetchHashKeyName   on IV/NV (CVE-2026-88816) (reported by Raj)
       * Fix provided in META

   With upstream patch for compilation under gcc.

   ok sthen@
VersionDeltaFile
1.3+18-23databases/p5-DBI/patches/patch-DBI_xs
1.36+2-2databases/p5-DBI/distinfo
1.78+1-1databases/p5-DBI/Makefile
+21-263 files

OpenBSD/ports Fr9aOuY — net/knot Makefile

   There is a hidden dep on databases/libhiredis that can cause a build
   failure when junking between configure and build.  Since enabling this
   feature changes PLIST, disable for now and we can re-evaluate after
   unlock.

   OK lucas@ naddy@
VersionDeltaFile
1.90+2-0net/knot/Makefile
+2-01 files

OpenBSD/ports u24A4Bd — mail/mozilla-thunderbird Makefile distinfo

   mail/mozilla-thunderbird: update to 140.17.0.

   see https://www.thunderbird.net/en-US/thunderbird/140.17.0esr/releasenotes/
VersionDeltaFile
1.312.2.10+2-2mail/mozilla-thunderbird/distinfo
1.525.2.10+1-1mail/mozilla-thunderbird/Makefile
+3-32 files

OpenBSD/ports Ta2EUnK — mail/mozilla-thunderbird Makefile distinfo, mail/thunderbird-i18n Makefile.inc distinfo

   mail/mozilla-thunderbird: update to 153.4.0.

   see https://www.thunderbird.net/en-US/thunderbird/153.4.0esr/releasenotes/
   fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-101/ (404)
VersionDeltaFile
1.311+132-132mail/thunderbird-i18n/distinfo
1.328+2-2mail/mozilla-thunderbird/distinfo
1.285+1-1mail/thunderbird-i18n/Makefile.inc
1.543+1-1mail/mozilla-thunderbird/Makefile
+136-1364 files