OpenBSD/src PZhcIFN — sys/conf newvers.sh

   leave -beta
VersionDeltaFile
1.218+3-3sys/conf/newvers.sh
+3-31 files

OpenBSD/src K1hQ5wq — distrib/special/doas doas.c

   Stop using non-standard UID_MAX and GID_MAX because a variety of code
   uses inclusive comparisons such that the UINT_MAX value aliases on top
   of -1 and causes issues.  First instance of this reported by Acts1631.
   joint work with millert
VersionDeltaFile
1.5+3-3distrib/special/doas/doas.c
+3-31 files

OpenBSD/src qc19ESN — lib/libc/gen getpwent.c getgrouplist.c, lib/libutil passwd.c

   Stop using non-standard UID_MAX and GID_MAX because a variety of code
   uses inclusive comparisons such that the UINT_MAX value aliases on top
   of -1 and causes issues.  First instance of this reported by Acts1631.
   joint work with millert
VersionDeltaFile
1.58+3-3lib/libutil/passwd.c
1.75+3-3lib/libc/gen/getpwent.c
1.33+3-3lib/libc/gen/getgrouplist.c
1.53+3-3lib/libc/gen/getgrent.c
+12-124 files

OpenBSD/src SyAzYeS — sys/kern kern_acct.c

   use UNVEIL_WRITE for acct; from Acts1631
VersionDeltaFile
1.51+2-2sys/kern/kern_acct.c
+2-21 files

OpenBSD/src PLwcd22 — sys/sys limits.h

   remove UID_MAX and GID_MAX defines.  base no longer uses them.  The
   few cases in ports will be purged sometime today.
VersionDeltaFile
1.11+1-6sys/sys/limits.h
+1-61 files

OpenBSD/src zYJzEZ4 — usr.bin/doas doas.c, usr.sbin/cron atrun.c

   Stop using non-standard UID_MAX and GID_MAX because a variety of code
   uses inclusive comparisons such that the UINT_MAX value aliases on top
   of -1 and causes issues.  First instance of this reported by Acts1631.
   joint work with millert
VersionDeltaFile
1.133+7-7usr.sbin/user/user.c
1.93+6-6usr.sbin/snmpd/parse.y
1.57+5-5usr.sbin/ypldap/ldapclient.c
1.100+5-5usr.bin/doas/doas.c
1.23+4-4usr.sbin/ypldap/yp.c
1.56+3-3usr.sbin/cron/atrun.c
+30-3018 files not shown
+77-7724 files

OpenBSD/src 4EgUJyh — sys/arch/m88k/m88k m8820x_machdep.c

   Do not write multiple assignment of the same value to multiple cmmu registers
   as nested assignment in a single statement.

   This used to work in the gcc 2 days, but from gcc 3 onwards, because these
   registers are declared volatile, this caused register reloads to propagate
   the assignment value.

   This had been noticed and fixed in arch/luna88k/luna88k/machdep.c 1.135, but
   the similar constructs in this file were missed.

   Noticed by tsutsuii at netbsd
VersionDeltaFile
1.69+16-9sys/arch/m88k/m88k/m8820x_machdep.c
+16-91 files

OpenBSD/src GAoWNKG — sys/arch/m88k/m88k trap.c

   Do not limit kernel-mode cmmu fault handling to segment and page faults,
   there could be write protection faults as well.

   The CMU Mach code did not have such a restriction, it had been added by
   Nivas while doing the original mvme88k port.

   The logic is now the same for kernel and userland.

   Noticed by tsutsui at netbsd.
VersionDeltaFile
1.142+4-3sys/arch/m88k/m88k/trap.c
+4-31 files

OpenBSD/src rcNg3QL — usr.sbin/bgpd bgpd.h session.c

   Adjust graceful restart timer handling for multi-AFI/SAFI sessions

   The timer is global for all AFI/SAFI but the first EoR would clear the timer
   which then can result in stale routes. Instead stop clearing the timer and
   use a new flag CAPA_GR_FINISHED. The code no longer clears CAPA_GR_RESTARTING
   on EoR but instead sets CAPA_GR_FINISHED and so when the timer fires the
   loop over all AFI/SAFI pairs will will skip all the ones that only have
   CAPA_GR_RESTARTING set (but no CAPA_GR_FINISHED).

   On top of this improve parse_capabilities() by respecting that only the last
   instance of the capability matters. Also make sure capa_neg_calc() does not
   write anything to capa.neg.grestart if the capability is disabled on our
   end.

   Reported by N0zoM1z0
   OK tb@
VersionDeltaFile
1.14+29-23usr.sbin/bgpd/session_bgp.c
1.542+12-9usr.sbin/bgpd/session.c
1.550+2-1usr.sbin/bgpd/bgpd.h
+43-333 files

OpenBSD/src pKF1G21 — usr.bin/tmux tmux.1 tmux.c

   Tighten up TMUX_TMPDIR - do not allow relative paths or .. or if
   realpath fails. From Alexandre Fiori.
VersionDeltaFile
1.225+50-8usr.bin/tmux/tmux.c
1.1174+5-2usr.bin/tmux/tmux.1
+55-102 files

OpenBSD/src tvEcRXs — sys/dev/pci/drm/include/linux delay.h

   change some busy wait delays to tsleep

   Previously tsleep was avoided in usleep_range(), drm_msleep() and
   fsleep() on precision grounds.  That shouldn't be a problem after
   kern_synch.c rev 1.225.

   This change prevents inteldrm GuC initialisation errors seen on
   Alder Lake by daniel@ and rsadowski@

   Problem found by and initial patch from daniel@
VersionDeltaFile
1.9+10-3sys/dev/pci/drm/include/linux/delay.h
+10-31 files

OpenBSD/src oqkTMve — usr.bin/tmux tty-keys.c

   Discard keys if there is no session, fixes crash reported by Artyom
   Pertsovsky.
VersionDeltaFile
1.215+11-1usr.bin/tmux/tty-keys.c
+11-11 files

OpenBSD/src xawQkTg — usr.bin/tmux tmux.c

   Fix some indentation.
VersionDeltaFile
1.224+3-3usr.bin/tmux/tmux.c
+3-31 files

OpenBSD/src fQC9DNV — usr.bin/tmux window.c session.c

   Do not overflow window indexes at INT_MAX in new-window -a and
   renumber-windows. GitHub issue 5637 from Alexandre Fiori.
VersionDeltaFile
1.109+12-4usr.bin/tmux/session.c
1.379+2-2usr.bin/tmux/window.c
+14-62 files

OpenBSD/src m5qJKcr — lib/libcrypto/bytestring bytestring.h, lib/libssl bytestring.h

   bytestring.h: add missing 1 to CBB_add_asn1 doc comment
VersionDeltaFile
1.27+2-2lib/libssl/bytestring.h
1.7+2-2lib/libcrypto/bytestring/bytestring.h
+4-42 files

OpenBSD/src uSx9I9K — sys/kern subr_prof.c

   profil(2): release the dirfd reference, and publish pr_cdir once

   Fixes both leaks reported by Acts1631, plus the race that fixing the
   first one exposes.

   - Take the vnode reference while the file reference is still held, then
     FRELE() it.
   - Acquire pr_ucred together with pr_cdir, after validation, so an
     EBADF/ENOTDIR return cannot leave a cred held with pr_cdir still NULL
   - Re-test pr_cdir before publishing to and release the loser's resource

   deraadt@ Looks good
VersionDeltaFile
1.44+16-5sys/kern/subr_prof.c
+16-51 files

OpenBSD/src N9ocvc9 — usr.bin/tmux mode-tree.c

   Keep the scroll position in tree mode when the list is rebuilt, GitHub
   issue 5631 from Kim A Brandt.
VersionDeltaFile
1.103+18-13usr.bin/tmux/mode-tree.c
+18-131 files

OpenBSD/src qOH0NZR — usr.sbin/bgpd rde_rib.c

   Do a prefix re-evaluation if the validation state of a route changes.

   The validation state of a route does not change the route evaluation
   but if the state changes the result of the outbound filters may change.
   Because of this do the same dance we do for the filtered flag and
   re-evaluate the prefix.

   Move the validation state also into the middle of the re-evaluation dance
   even though it is not strictly needed. At least that way it is more
   consistent with the rest of the code.

   Reported by N0zoM1z0
   OK tb@
VersionDeltaFile
1.306+12-6usr.sbin/bgpd/rde_rib.c
+12-61 files

OpenBSD/src UUSAq66 — sys/arch/arm/arm pmap7.c

   sys/arm: avoid cache faults on untranslated aliases

   An executable PV entry does not establish a usable hardware translation;
   for an unreferenced prefaulted page, pmap_enter() can install an L2 PTE
   with its access flag clear while leaving the L1 descriptor invalid.
   pmap_clean_page() nevertheless uses such aliases for cache maintenance;
   during address space teardown, a translation abort can reenter
   uvm_fault() while the current thread owns the map write lock, provoking
   recursive acquisition of vmmaplk.

   Inspect each executable alias's L1 descriptor before issuing cache
   maintenance by virtual address; if it is invalid, use
   cpu_idcache_wbinv_all() and return, since the operation covers the
   remaining aliases. This preserves data cache cleaning and instruction
   cache invalidation without translating the unusable address; aliases
   with valid L1 descriptors retain the existing per page operation.

   This idea follow discovered discussion in linux-arm-kernel:
   https://lists.infradead.org/pipermail/linux-arm-kernel/2018-January/556458.html

    [4 lines not shown]
VersionDeltaFile
1.70+10-2sys/arch/arm/arm/pmap7.c
+10-21 files

OpenBSD/src BGR4kga — sys/dev/ic qwx.c

   properly handle potential case of empty packets returned from qwx hardware

   tested by Jean-Michel Bessot, phessler@, and myself
   ok phessler@
VersionDeltaFile
1.141+5-8sys/dev/ic/qwx.c
+5-81 files

OpenBSD/src trFdNNZ — sys/dev/ic qwx.c

   add missing DMA syncs for qwx(4) SRNG DMA descriptor memory

   tested by Jean-Michel Bessot, phessler@, and myself
   ok phessler@
VersionDeltaFile
1.140+7-2sys/dev/ic/qwx.c
+7-21 files

OpenBSD/src 0gmE39d — sbin/iked ikev2.c

   iked: Remove invalid SPI size 8 in delete path

   DELETE does not provide the SPI of the IKE SA to be deleted.  It
   is the IKE SA that is used to send the DELETE notify.  Therefore,
   SPI size 8 is not valid.  With the previous change, such DELETE
   notifies will be dropped.  Therefore remove the now dead code.

   See https://www.rfc-editor.org/rfc/rfc7296.html#section-3.11

   ok markus@
VersionDeltaFile
1.404+9-27sbin/iked/ikev2.c
+9-271 files

OpenBSD/src 71t6VnP — sys/arch/amd64/amd64 vmm_machdep.c

   vmm(4): Do not access raw PSL_I

   With SEV-ES enabled we can not directly access PSL_I in RFLAGS.
   Instead we have to use the GUEST_INTR_MASK bit in vmcb->v_intr_shadow
   which indicates the actual PSL_I state.

   ok dv@ mlarkin@
VersionDeltaFile
1.91+3-2sys/arch/amd64/amd64/vmm_machdep.c
+3-21 files

OpenBSD/src dXsb1Rz — usr.sbin/rpki-client validate.c extern.h

   rpki-client: rename valid_x509() to valid_cert()

   x509 usually indicates an X509 * argument and cert a struct cert *.
   This got changed in the surgery today and valid_cert() is now free,
   so we can fix this.

   ok claudio
VersionDeltaFile
1.189+7-7usr.sbin/rpki-client/parser.c
1.91+3-3usr.sbin/rpki-client/filemode.c
1.90+2-2usr.sbin/rpki-client/validate.c
1.299+2-2usr.sbin/rpki-client/extern.h
+14-144 files

OpenBSD/src dy0DwQA — usr.sbin/rpki-client extern.h parser.c

   rpki-client: check all !TA certs for resource coverage

   For historic reasons, EE certs did not have their resources checked for
   coverage in the parent. Since we have the exception of EE certs that need
   special casing for inheritance (MFT/TAK/GBR), this can be done at the end
   of valid_x509(). The check is not expensive since this only goes up as
   many issuers as needed to hit explicit resources.

   Rename the misnamed valid_cert() to valid_resources() for lack of a better
   idea and call it from the end of valid_x509(). Remove the remaining calls
   since they're now redundant, and make valid_resources() static.

   ok job
VersionDeltaFile
1.89+6-4usr.sbin/rpki-client/validate.c
1.188+2-3usr.sbin/rpki-client/parser.c
1.90+2-3usr.sbin/rpki-client/filemode.c
1.298+1-2usr.sbin/rpki-client/extern.h
+11-124 files

OpenBSD/src MmTfaNA — sys/dev/usb uaudio.c

   uaudio: Make sure the reported format and channels are usable

   A bogus device may trigger a division by zero if the number of
   channels or sample size are 0. Similarly, memory corruption may occur
   if the reported sample size is larger than four bytes.

   Found by Acts1631 <acts1631kjv at proton.me>, who proposed a diff that
   inspired this fix. Thanks!
VersionDeltaFile
1.189+16-1sys/dev/usb/uaudio.c
+16-11 files

OpenBSD/src aMHWeHh — sys/arch/arm64/dev apldc.c

   The MTP firmware needs to stay around after "loading" it; the comprocessor
   that runs the firmware seems to reference the firmware image that we pass
   it directly instead of making its own copy.  This fixes a regression on
   laptops with a dockchannel touchpad after the recent changes to apldart(4).

   ok tobhe@
VersionDeltaFile
1.13+23-20sys/arch/arm64/dev/apldc.c
+23-201 files

OpenBSD/src GxNksT5 — usr.sbin/bgpctl bgpctl.c parser.c, usr.sbin/bgpd bgpd.conf.5 bgpd.h

   Add shorthand for well-known BGP community "DOWNGRADE"

   From https://datatracker.ietf.org/doc/html/draft-ietf-grow-downgrade-bgp-community

   OK claudio@
VersionDeltaFile
1.506+5-1usr.sbin/bgpd/parse.y
1.141+5-1usr.sbin/bgpctl/parser.c
1.549+3-2usr.sbin/bgpd/bgpd.h
1.325+3-1usr.sbin/bgpctl/bgpctl.c
1.259+2-1usr.sbin/bgpd/bgpd.conf.5
+18-65 files

OpenBSD/src J4xED6Y — usr.bin/tmux window.c screen-redraw.c

   As well as tracking modified (dirty) lines during a synchronized update,
   also track scrolled lines. This means they can be scrolled as one
   instead of forcing each line to be redrawn - much less expensive for a
   very common operation. From Ben Maurer in GitHub issue 5611.
VersionDeltaFile
1.293+153-30usr.bin/tmux/screen-write.c
1.1448+6-2usr.bin/tmux/tmux.h
1.162+3-3usr.bin/tmux/screen-redraw.c
1.378+2-2usr.bin/tmux/window.c
+164-374 files

OpenBSD/src qXYO9wC — usr.sbin/rpki-client parser.c validate.c

   rpki-client: match CRLDP and referring Manifest for all !TA certs

   Now that crl->mftcrldp is always set, we can move the comparison of
   cert->crl with crl->mftdp into valid_x509() so that all certs which
   come through here must satisfy this requirement. While TA certs are
   not validated here, add a check for cert->purpose to avoid potential
   NULL accesses.

   ok job
VersionDeltaFile
1.88+13-8usr.sbin/rpki-client/validate.c
1.187+1-6usr.sbin/rpki-client/parser.c
+14-142 files