OpenBSD/src O86tLyN — usr.bin/ssh readconf.c

   Further restrict the characters allowed in a command-line supplied user
   name, disallowing '$' and '\'.
   Reported by SecBuddyF KeenLab Tencent (CodeBuddy Security).
VersionDeltaFile
1.419+2-5usr.bin/ssh/readconf.c
+2-51 files

OpenBSD/src KqHmz6K — lib/libc/sys open.2

   the 1.57 chunk mentioning O_CREAT and O_DIRECTORY failed to use .Dv
VersionDeltaFile
1.64+6-3lib/libc/sys/open.2
+6-31 files

OpenBSD/src fgMAufJ — sbin/isakmpd isakmpd.8

   remove comma after final SEE ALSO reference
VersionDeltaFile
1.125+3-3sbin/isakmpd/isakmpd.8
+3-31 files

OpenBSD/src S5H3bCD — sys/dev/pci/drm/amd/amdgpu amdgpu_dma_buf.c

   drm/amdgpu: hold a runtime PM reference for P2P dma-buf attachments

   From Mike Lothian
   aeaa7bdc0ea2c725331a423575bb7f93c040f8fb in linux-6.18.y/6.18.54
   636139603b99d2e3a18a46cf3f8d39313ce8042e in mainline linux
VersionDeltaFile
1.14+44-2sys/dev/pci/drm/amd/amdgpu/amdgpu_dma_buf.c
+44-21 files

OpenBSD/src SPz3YDR — sys/kern vfs_syscalls.c

   remove very unneccessary temporary variable
VersionDeltaFile
1.389+2-5sys/kern/vfs_syscalls.c
+2-51 files

OpenBSD/src rR8N5ng — sys/dev/pci/drm/amd/amdgpu amdgpu_dma_buf.c

   drm/amdgpu: lock bo before calling amdgpu_vm_bo_update_shared

   From Pierre-Eric Pelloux-Prayer
   801d8647dcb0d34f0654b11f932e4ed365092c5e in linux-6.18.y/6.18.54
   36ffc58b8a8704e690a0ce679db26baa5759256f in mainline linux
VersionDeltaFile
1.13+8-0sys/dev/pci/drm/amd/amdgpu/amdgpu_dma_buf.c
+8-01 files

OpenBSD/src 6gqHmRn — usr.sbin/rarpd rarpd.c

   NULL not 0
VersionDeltaFile
1.82+2-2usr.sbin/rarpd/rarpd.c
+2-21 files

OpenBSD/src IXMoQYq — sys/dev/pci/drm/amd/amdgpu amdgpu_device.c

   drm/amdgpu: fix rmmio iounmap skipped on device removal

   From Chengjun Yao
   cd55dde2b63789a3dafe982c89844f537501d096 in linux-6.18.y/6.18.54
   5155002b03b24ba3ef91c5c313b8cf0171b24904 in mainline linux
VersionDeltaFile
1.110+7-7sys/dev/pci/drm/amd/amdgpu/amdgpu_device.c
+7-71 files

OpenBSD/src MHaBE5n — sys/dev/pci/drm/amd/amdgpu nbio_v7_9.c

   drm/amdgpu: check ras and obj before dereference

   From Dmitriy Chumachenko
   37583946d8751f8e285c467d770ac0b609b82a23 in linux-6.18.y/6.18.54
   723d4dc628d764b19cf9efca14b82cca5ff020c9 in mainline linux
VersionDeltaFile
1.7+1-1sys/dev/pci/drm/amd/amdgpu/nbio_v7_9.c
+1-11 files

OpenBSD/src kyojmcb — sys/dev/pci/drm drm_atomic_uapi.c

   drm: Fix drm_pending_vblank_event leak in error path for out_fence_ptr

   From Thadeu Lima de Souza Cascardo
   daefd7ff159b0d1fb8c9e64430dcbe2aca1bdd09 in linux-6.18.y/6.18.54
   9eb1a393c89a79c4210230d23e7d88d239c61d7b in mainline linux
VersionDeltaFile
1.12+11-4sys/dev/pci/drm/drm_atomic_uapi.c
+11-41 files

OpenBSD/src D2SGAi2 — sys/uvm uvm_swap.c

   Reserve a 16K-byte gap at the start of a swap partition.

   Swap currently reserves PAGE_SIZE (4K, 8K or 16K depending on arch) bytes
   as potential space for a disklabel and boot code.

   A disklabel can be placed in the first or second DEV_BSIZE bytes of swap, with
   some arch's needing up to 6 * DEV_BSIZE additional bytes for boot code and arch
   dependent disklabel info.

   New disklabel code will need to store a bigger disklabel structure
   in 3 * DEV_BSIZE bytes of the *FIRST VIABLE PARTITION WITH A GAP*.

   VIABLE PARTITIONS are filesystems (ffs and swap in particular) which have a
   sufficiently large gap.

   Increasing the swap partition gap makes it much more likely that those bytes
   will be available.

   Suggested by & ok deraadt@
VersionDeltaFile
1.184+6-7sys/uvm/uvm_swap.c
+6-71 files

OpenBSD/src VdHhd3K — usr.bin/ypwhich ypwhich.c

   remove accidental test code from 1994 which neutered parts of the
   intended behaviour.
   ok miod
VersionDeltaFile
1.25+1-2usr.bin/ypwhich/ypwhich.c
+1-21 files

OpenBSD/src vrQsoDT — libexec/ld.so library_subr.c

   Oops, this proposal isn't ready yet.
   accidental commit spotted by by caspar
VersionDeltaFile
1.57+1-11libexec/ld.so/library_subr.c
+1-111 files

OpenBSD/src eabIbK0 — libexec/ld.so ld.so.1 library_subr.c

   surprised this page did not Xr ldd 1
VersionDeltaFile
1.56+12-2libexec/ld.so/library_subr.c
1.26+3-2libexec/ld.so/ld.so.1
+15-42 files

OpenBSD/src 2ynya8Y — sbin/isakmpd udp.c

   using sizeof is recommended practice
VersionDeltaFile
1.97+3-3sbin/isakmpd/udp.c
+3-31 files

OpenBSD/src gtrwOTs — usr.sbin/rpc.statd statd.c

   O_NONBLOCK is the modern name (with 2 legacy userland defines and 2 legacy
   kernel defines, not sure when all of that will collapse)
VersionDeltaFile
1.7+2-2usr.sbin/rpc.statd/statd.c
+2-21 files

OpenBSD/src ZtRZoWY — usr.sbin/rtrd hash.c commands.c

   more knf
VersionDeltaFile
1.6+4-24usr.sbin/rtrd/cache.c
1.5+5-15usr.sbin/rtrd/commands.c
1.4+1-2usr.sbin/rtrd/hash.c
+10-413 files

OpenBSD/src PTVPsju — regress/lib/libcrypto/objects objectstest.c

   objectstest: succeded -> succeeded
VersionDeltaFile
1.9+2-2regress/lib/libcrypto/objects/objectstest.c
+2-21 files

OpenBSD/src RI5eRcb — regress/usr.sbin/rpki-client Makefile.inc

   rpki-client regress: link bytestring API to the build
VersionDeltaFile
1.51+2-2regress/usr.sbin/rpki-client/Makefile.inc
+2-21 files

OpenBSD/src 4arpZzi — usr.sbin/rpki-client Makefile

   rpki-client: link bytestring API to the build

   ok beck
VersionDeltaFile
1.43+4-1usr.sbin/rpki-client/Makefile
+4-11 files

OpenBSD/src 4WI3rIb — usr.sbin/rpki-client bs_ber.c bs_cbb.c

   rpki-client: add a copy of libcrypto's bytestring API

   This will be used to replace the terrible CMS API from libcrypto. Longer
   term this might also be used to implement better parsers for certs, CRLs
   and the signed objects' eContent.

   discussed with claudio and job
   ok beck
VersionDeltaFile
1.1+616-0usr.sbin/rpki-client/bs_cbs.c
1.1+573-0usr.sbin/rpki-client/bytestring.h
1.1+490-0usr.sbin/rpki-client/bs_cbb.c
1.1+270-0usr.sbin/rpki-client/bs_ber.c
+1,949-04 files

OpenBSD/src WtI5fVl — lib/libcrypto/bytestring bytestring.h, lib/libssl bytestring.h

   libcrypto/bytestring.h: make parentheses line up again

   whitespace-only change
VersionDeltaFile
1.30+11-11lib/libssl/bytestring.h
1.10+11-11lib/libcrypto/bytestring/bytestring.h
+22-222 files

OpenBSD/src eihZpxP — lib/libcrypto/bytestring bytestring.h, lib/libssl bytestring.h

   libcrypto/bytestring: add some missing tag classes

   This adds tags for NULL, PrintableString, UTCTime, and GeneralizedTime with
   names matching BoringSSL.

   ok kenjiro
VersionDeltaFile
1.29+5-1lib/libssl/bytestring.h
1.9+5-1lib/libcrypto/bytestring/bytestring.h
+10-22 files

OpenBSD/src swx6bAd — lib/libcrypto/bytestring bytestring.h, lib/libssl bytestring.h

   libcrypto/bytestring: remove LIBRESSL_INTERNAL from bytestring.h

   This currently marks the LibreSSL-specific additions to this API. It has
   no effect other than getting in the way of other projects wanting to use
   this since it is always compiled with LIBRESSL_INTERNAL.

   ok kenjiro
VersionDeltaFile
1.28+1-3lib/libssl/bytestring.h
1.8+1-3lib/libcrypto/bytestring/bytestring.h
+2-62 files

OpenBSD/src huuBdUT — sys/kern sysv_shm.c

   sysv_shm: claim the vm_shm slot after uvm_map(), not before

   sys_shmat() chose a free slot in the per-vmspace vm_shm array, then slept
   in uvm_map(), then published into the slot it had chosen.  Nothing marked
   the slot taken across the sleep, so a sibling thread entering sys_shmat()
   scanned the same array, found the same slot still reading -1, and took it
   too.  Both uvm_map() calls succeed at different addresses and the thread
   that stores last wins; the other mapping is left with no vm_shm entry, so
   shmdt() returns EINVAL for it and shmexit() cannot drop its shm_nattch.
   The permanently raised count keeps IPC_RMID from deallocating the segment,
   which then sits in shmsegs[] reachable by nobody; 128 of those and
   shmget() returns ENOSPC system-wide.

   uvm_map() is the only sleep between choosing the slot and filling it in,
   so moving the scan below the map closes the window without a reserved
   state that shmdt(), shmexit() and shmfork() would each have to learn
   about.  EMFILE is now discovered after the mapping exists, so that path
   undoes it.


    [9 lines not shown]
VersionDeltaFile
1.92+26-17sys/kern/sysv_shm.c
+26-171 files

OpenBSD/src C1f1tNZ — regress/usr.sbin/rpki-client/openssl unistd.h

   rpki-client regress: this unistd.h hack needs to include x509.h
VersionDeltaFile
1.7+2-1regress/usr.sbin/rpki-client/openssl/unistd.h
+2-11 files

OpenBSD/src ydGmbba — lib/libexpat/lib xmltok.h xmltok_impl.c, lib/libexpat/tests basic_tests.c

   Backport fixes from libexpat version 2.8.5.

   Relevant for OpenBSD are security fixes #1282, bug fixes #1346
   #1371, other changes #1354 #1357 #1349 #1360 #1378.  Library bump
   is not necessary.
   CVE-2026-93990

   OK deraadt@

   this is errata/7.9/033_expat.patch.sig
VersionDeltaFile
1.9.4.3+342-0lib/libexpat/tests/basic_tests.c
1.20.4.2+138-64lib/libexpat/lib/xmltok.c
1.47.2.3+89-92lib/libexpat/lib/xmlparse.c
1.15.4.2+55-56lib/libexpat/lib/xmlrole.c
1.18.12.2+28-32lib/libexpat/lib/xmltok_impl.c
1.9.6.3+25-26lib/libexpat/lib/xmltok.h
+677-2706 files not shown
+716-31912 files

OpenBSD/src dGRHt22 — lib/libexpat/lib xmltok.h xmltok_impl.c, lib/libexpat/tests basic_tests.c

   Backport fixes from libexpat version 2.8.5.

   Relevant for OpenBSD are security fixes #1282, bug fixes #1346
   #1371, other changes #1354 #1357 #1349 #1360 #1378.  Library bump
   is not necessary.
   CVE-2026-93990

   OK deraadt@

   this is errata/7.8/069_expat.patch.sig
VersionDeltaFile
1.7.2.5+342-0lib/libexpat/tests/basic_tests.c
1.18.2.2+138-64lib/libexpat/lib/xmltok.c
1.44.2.6+89-92lib/libexpat/lib/xmlparse.c
1.13.6.2+55-56lib/libexpat/lib/xmlrole.c
1.18.6.2+28-32lib/libexpat/lib/xmltok_impl.c
1.9.2.3+25-26lib/libexpat/lib/xmltok.h
+677-2706 files not shown
+716-31912 files

OpenBSD/src hAu9Erc — sbin/isakmpd isakmpd.c message.c

   incorrect object being freed
   from Franz Bettag / Bettag Systems
   from deraadt@; OK markus@ hshoexer@ sthen@ mvs@

   IKEv1 short-HASH heap overflow; second approach for fix
   from Franz Bettag / Bettag Systems
   from deraadt@; OK sthen@ mvs@

   Franz Bettag sent a report & diff repairing the privsep monitor's
   dangerous file behavior in /var/run, and I was shocked at what it
   does.  isakmpd never had a proper diagnosis and control program like
   other daemons do, and instead accepts weird commands on a fifo and
   splats files dangerously.  Some path names can be manipulated.  This
   2600 line diff removes all of this session debugging mechanism which
   is the main cause of that unsafe design.  There are no reuseable parts
   in that code (it cannot be reconstructed into a proper control program
   interface).  As a result, the privsep monitor now has unveil to the
   config directory, and the network speaking process is "stdio sendfd
   route recvfd inet".  There is some loss of functionality, since some

    [22 lines not shown]
VersionDeltaFile
1.125.18.1+2-342sbin/isakmpd/sa.c
1.65.8.1+1-341sbin/isakmpd/log.c
1.83.14.1+64-187sbin/isakmpd/monitor.c
1.22.36.1+1-133sbin/isakmpd/field.c
1.129.40.1+4-120sbin/isakmpd/message.c
1.109.14.1+7-116sbin/isakmpd/isakmpd.c
+79-1,23928 files not shown
+166-1,81334 files

OpenBSD/src 3ns2n6b — sbin/isakmpd isakmpd.c message.c

   incorrect object being freed
   from Franz Bettag / Bettag Systems
   from deraadt@; OK markus@ hshoexer@ sthen@ mvs@

   IKEv1 short-HASH heap overflow; second approach for fix
   from Franz Bettag / Bettag Systems
   from deraadt@; OK sthen@ mvs@

   Franz Bettag sent a report & diff repairing the privsep monitor's
   dangerous file behavior in /var/run, and I was shocked at what it
   does.  isakmpd never had a proper diagnosis and control program like
   other daemons do, and instead accepts weird commands on a fifo and
   splats files dangerously.  Some path names can be manipulated.  This
   2600 line diff removes all of this session debugging mechanism which
   is the main cause of that unsafe design.  There are no reuseable parts
   in that code (it cannot be reconstructed into a proper control program
   interface).  As a result, the privsep monitor now has unveil to the
   config directory, and the network speaking process is "stdio sendfd
   route recvfd inet".  There is some loss of functionality, since some

    [22 lines not shown]
VersionDeltaFile
1.125.14.1+2-342sbin/isakmpd/sa.c
1.65.4.1+1-341sbin/isakmpd/log.c
1.83.10.1+64-187sbin/isakmpd/monitor.c
1.22.32.1+1-133sbin/isakmpd/field.c
1.129.36.1+4-120sbin/isakmpd/message.c
1.109.10.1+7-116sbin/isakmpd/isakmpd.c
+79-1,23928 files not shown
+166-1,81334 files