OpenBSD/src a8ZYb6K — sys/net bsd-comp.c

   Fix an off-by-one in bsd_decompress()

   An incorrect bounds check for the LZW KwKwK case allows the creation of a
   self-refential dictionary entry, resulting in an infinite expansion loop
   that writes backward from the output mbuf, corrupting kernel memory.

   This is an ancient buffer overflow that is also present in the version of
   the code in RFC 1977.

   From Acts1631

   ok deraadt
VersionDeltaFile
1.19+2-2sys/net/bsd-comp.c
+2-21 files

OpenBSD/src oggoA91 — share/mk bsd.prog.mk

   An restriction on setuid/setgid binaries linked against libc will arrive
   soon, and this is another prep step.
   The libc startup code is aware of the executable file's setuid/setgid
   bits (via new AUX_openbsd_execmode), and will compare these bits
   against a global (weak) variable "mode_t _permit_setugid" in the main
   program dso -- which must indicate similar abilities.
   If the binary does not contain that variable, it picks up the weak libc
   version which is 0.  If the corresponding bits are not set right, it means
   this binary was not intended to be setuid/setgid.
   The file has become setuid/setgid accidentally, unintentionally, or
   due to attacker control, and libc will log the event and abort (the
   abort is disabled until we complete more steps of this transition).
   This change in bsd.prog.mk automatically (based upon BINMODE) creates
   an additional .c file with the correct variable definition to compile
   and link into the program, so that we don't need any additional changes
   in userland base.
VersionDeltaFile
1.86+15-1share/mk/bsd.prog.mk
+15-11 files

OpenBSD/src JxaRogB — libexec/ld.so ld.so.1

   The list of ignored environment variables and the conditions under
   which they are ignored or removed from downstream environment has
   become too complicated to list at every specific variable, so replace
   all of them a single note at the end which also mentions the new
   restriction for binary readability.
VersionDeltaFile
1.27+5-6libexec/ld.so/ld.so.1
+5-61 files

OpenBSD/src yetICTj — libexec/ld.so loader.c

   If AUX_openbsd_execmode lacks S_IRUSR, disable a plethora of LD_*
   environment variables which emit information about the binary at
   startup.  Some of these are minor info leaks, like the exec address of
   the binary and shared library locations. For binaries which are unreadable,
   we should respect the wishes of whoever set the mode restrictively.
   I made a few more relinked binaries non-readable, and dgl pointed out
   that ld.so was leaking too much information so this is the fix.
VersionDeltaFile
1.226+18-7libexec/ld.so/loader.c
+18-71 files

OpenBSD/src w6o50le — gnu/usr.bin/binutils/gdb auxv.c, gnu/usr.bin/binutils/include/elf common.h

   make binutils aware of the AUX_openbsd_execmode variable
   ok kettenis
VersionDeltaFile
1.5+5-1gnu/usr.bin/binutils/gdb/auxv.c
1.15+1-0gnu/usr.bin/binutils/include/elf/common.h
+6-12 files

OpenBSD/src cFUj38H — sys/kern exec_elf.c kern_exec.c, sys/sys exec.h

   store the S_ISUID and S_ISGID bits via AUX_openbsd_execmode.
   The S_IRUSR bit determined using VOP_ACCESS VREAD at the same time.
   ok kettenis
VersionDeltaFile
1.276+6-1sys/kern/kern_exec.c
1.207+5-1sys/kern/exec_elf.c
1.62+2-1sys/sys/exec.h
+13-33 files

OpenBSD/src m2l2DjV — sys/sys exec_elf.h

   AUX_openbsd_execmode's au_v provides a mode_t containing S_ISUID and
   S_ISGUID from the executable file's mode_t, and S_IRUSR which says
   whether the executable file was openable for read-access (with the
   process' uid/gids and the file's mode_t permissions).
   ok kettenis and others
VersionDeltaFile
1.113+3-2sys/sys/exec_elf.h
+3-21 files

OpenBSD/src mmbpUiA — sys/netinet ip_spd.c

   Remove orphaned ipsp_delete_acquire().
   ok bluhm@
VersionDeltaFile
1.123+1-10sys/netinet/ip_spd.c
+1-101 files

OpenBSD/src FkUawsf — sys/netinet6 in6.c in6.h

   Remove no longer used in6mask0 and in6mask96.
   ok florian@
VersionDeltaFile
1.126+1-6sys/netinet6/in6.h
1.280+1-3sys/netinet6/in6.c
+2-92 files

OpenBSD/src izc6gEs — sys/arch/macppc/dev pm_direct.h pm_direct.c

   ADB macppc systems as well as macppc laptops store the time in their
   nonvolatile clock, as a 32-bit unsigned integer value for the number of seconds
   since 1904, and that number happens to wrap around in february 2040.

   When reading a possibly truncated value which is below 1970, assume this is
   actually a truncated value from after 2040.

   ok deraadt@
VersionDeltaFile
1.53+15-6sys/arch/macppc/dev/adb.c
1.36+6-9sys/arch/macppc/dev/pm_direct.c
1.18+3-3sys/arch/macppc/dev/pm_direct.h
+24-183 files

OpenBSD/src FEpcHQs — etc/rc.d rc.subr

   _allowed_keys should be a local variable.
VersionDeltaFile
1.181+3-3etc/rc.d/rc.subr
+3-31 files

OpenBSD/src xKQxOHw — etc/rc.d rc.subr

   Make sure we can cope with super small daemon_timeout.
VersionDeltaFile
1.180+10-7etc/rc.d/rc.subr
+10-71 files

OpenBSD/src 86T55pW — sys/dev/usb if_uncm.c

   knf cleanup; from jan schreiber the author
VersionDeltaFile
1.2+44-23sys/dev/usb/if_uncm.c
+44-231 files

OpenBSD/src 5QEBDLh — usr.bin/ipcs ipcs.c

   the kvm method can use pledge("stdio")
VersionDeltaFile
1.30+4-1usr.bin/ipcs/ipcs.c
+4-11 files

OpenBSD/src fYzzqSe — etc/rc.d rc.subr

   Simplify _rc_check_name.
VersionDeltaFile
1.179+2-2etc/rc.d/rc.subr
+2-21 files

OpenBSD/src Y3kkB8F — usr.sbin/syslogd privsep.c

   whitespace
VersionDeltaFile
1.81+2-2usr.sbin/syslogd/privsep.c
+2-21 files

OpenBSD/src 59Akx0L — etc/rc.d rc.subr

   Make a couple of variables local.
VersionDeltaFile
1.178+3-3etc/rc.d/rc.subr
+3-31 files

OpenBSD/src VTDoxBg — etc/rc.d rc.subr

   No need to sleep for non rc_bg daemons.
VersionDeltaFile
1.177+2-4etc/rc.d/rc.subr
+2-41 files

OpenBSD/src 59fTj4g — etc/rc.d rc.subr

   Useless use of grep.
VersionDeltaFile
1.176+3-2etc/rc.d/rc.subr
+3-21 files

OpenBSD/src rmigsxD — etc/rc.d rc.subr

   Do what the comment says and redirect the alarm clock to /dev/null.
VersionDeltaFile
1.175+3-3etc/rc.d/rc.subr
+3-31 files

OpenBSD/src N6PJ3rF — etc/rc.d rc.subr

   Add a few comments so that I don't need to spend hours understanding what
   I did 2 years ago.
VersionDeltaFile
1.174+5-3etc/rc.d/rc.subr
+5-31 files

OpenBSD/src CmlgPgN — etc/rc.d rc.subr

   In rc_exec() make sure we join all the arguments with spaces into a single
   string. None of our rc.d scripts are affected (they all quote rc_exec commands)
   but better safe than sorry for future scripts.
   No behavior change.
VersionDeltaFile
1.173+1-1etc/rc.d/rc.subr
+1-11 files

OpenBSD/src JAdLrCN — etc/rc.d rc.subr

   In _rc_parse_conf, key is eval'ed, so don't just check if it's empty but pass it
   through _rc_check_name for a more complete sanity check.
VersionDeltaFile
1.172+3-2etc/rc.d/rc.subr
+3-21 files

OpenBSD/src urHIxA1 — etc/rc.d rc.subr

   Add a comment about rc_stop=NO
VersionDeltaFile
1.171+4-2etc/rc.d/rc.subr
+4-21 files

OpenBSD/src setyCUS — etc/rc.d rc.subr

   When a daemon is running, ensure that rc_reload rc_reload_signal rc_stop_signal
   and rc_usercheck are read from the rc.d run script. We want to use values
   compatible with what the script was started with because the original script
   might have been updated since (ex. by using pkg_add -u).
VersionDeltaFile
1.170+7-2etc/rc.d/rc.subr
+7-21 files

OpenBSD/src Cji0H4t — sys/arch/riscv64/riscv64 vector.c fpu.c

   Unify whitespace used in asm statements

   No functional change.  Pointed out by jsing@, ok jsing@
VersionDeltaFile
1.13+4-4sys/arch/riscv64/riscv64/fpu.c
1.3+3-3sys/arch/riscv64/riscv64/vector.c
+7-72 files

OpenBSD/src lyacyMy — usr.bin/ssh PROTOCOL.sshsig

   Correct language. From viktorashi via github PR#713.
VersionDeltaFile
1.5+2-2usr.bin/ssh/PROTOCOL.sshsig
+2-21 files

OpenBSD/src kEhfqBZ — share/man/man4 pci.4

   Mediatek -> MediaTek
VersionDeltaFile
1.419+2-2share/man/man4/pci.4
+2-21 files

OpenBSD/src rAVaviJ — sys/dev/ic i82596.c

   Fix operator priority in promisc setting expression. Reported by modern gcc.
VersionDeltaFile
1.57+2-2sys/dev/ic/i82596.c
+2-21 files

OpenBSD/src jvC7xz2 — usr.bin/ypmatch ypmatch.c, usr.bin/ypwhich ypwhich.c

   I strongly suspect these tools will work with unveil "/etc" "r" and
   pledge "stdio rpath getpw inet dns".  might even be able to
   remove something after some observation.
VersionDeltaFile
1.18+6-1usr.sbin/yppoll/yppoll.c
1.27+6-1usr.bin/ypwhich/ypwhich.c
1.19+6-1usr.bin/ypmatch/ypmatch.c
+18-33 files