rpki-client: don't treat a duplicate CCR MFT as fatal
It is possible to concoct situations where two PPs serve byte identical
manifests. Then CCR generation errors with "CCR MFT tree corrupted".
Handle this situation gracefully and only warn about the weird situation.
There are more problems in the vicinity that need fixing but that's for
after the release.
Reported by eur1ka qq com. Diff is a tweaked version of the suggested fix.
ok job
Update p5-DBI to 1.654
1.654 - 2026-09-25, H.Merijn Brand & Robert Rothenberg
* Fix DBI::sql_type_cast on IV/NV (CVE-2026-88815) (reported by Raj)
* Fix FetchHashKeyName on IV/NV (CVE-2026-88816) (reported by Raj)
* Fix provided in META
With upstream patch for compilation under gcc.
ok sthen@
There is a hidden dep on databases/libhiredis that can cause a build
failure when junking between configure and build. Since enabling this
feature changes PLIST, disable for now and we can re-evaluate after
unlock.
OK lucas@ naddy@
sys/qwz: unwind cold startup failures
Based on sys/dev/ic/qwx.c,v 1.134
Track powerup and completed core initialization so failed cold starts
reset hardware before reclaiming initialized DMA resources. Release
partial TX allocations and RX rings; ordinary interface down and up
continues to retain firmware.
OK: stsp@
sys/qwz: skip uninitialized CE polling
Based on sys/dev/ic/qwx.c,v 1.135
Track successful CE initialization to decide whether completion
polling is valid; provide dircet TX buffer reclamation for cold
cleanup after hardware reset, when ring polling is no longer safe.
OK: stsp@
sys/qwz: retain HAL allocations on resume
Based on sys/dev/ic/qwx.c,v 1.97 and sys/dev/ic/qwx.c,v 1.136
Preserve HAL allocation pointers across reinitialization: reuse qwz
allocated ring configuration and claer retained pointer memory. On
failure, free only allocations made by the current attempt.
OK: stsp@
update to png-1.6.59, fixing use-after-free of zlib input in
png_read_end() after incomplete zTXt, iTXt or iCCP decompression
https://github.com/pnggroup/libpng/security/advisories/GHSA-qvg3-h654-xq3j
ok matthieu who has verified that this is not reachable from xenocara's
use of the static-linked copy
set -u _nsd / _unbound as appropriate when running nsd-control /
unbound-control through doas, to match the existing pkg-readme.
from Atanas Vladimirov.
For allocations between half a page and a page (which are moved
towards the end) we don't clear the proper region with freezero().
Instead, the clearing is done from the start of the page. So fix that.
Reported by Acts1631
ok deraadt@
Fix softraid rebuild on disks with 4096-byte sectors.
Problem found, suggested diffs, and testing by Dariusz Swiderski.
ok claudio@ "makes release" deraadt@