CVSROOT: /cvs Module name: ports Changes by: namn@cvs.openbsd.org 2026/09/30 14:22:30 Modified files: net/rtorrent : Makefile distinfo net/rtorrent/patches: patch-test_Makefile_in Log message: update net/rtorrent 0.16.24 - various security fixes (e.g., overflow, heap overflow and use-after-free) - regen test/Makefile.in patch to remove a new, third instance of -ldl approved by sthen@ and tested by and OK tj@ CVSROOT: /cvs Module name: ports Changes by: namn@cvs.openbsd.org 2026/09/30 14:27:21 Modified files: net/libtorrent : Makefile distinfo Added files: net/libtorrent/patches: patch-test_Makefile_in Log message: update net/libtorrent 0.16.24 - major bump due to removed symbols - unbreaks tests by linking using static archive (from tj@) approved by sthen@ and tested by and OK tj@ CVSROOT: /cvs Module name: src Changes by: deraadt@cvs.openbsd.org 2026/09/30 14:44:06 Modified files: sys/conf : newvers.sh Log message: 8.0 -current development CVSROOT: /cvs Module name: www Changes by: sthen@cvs.openbsd.org 2026/09/30 14:47:47 Modified files: faq : current.html Log message: mention geolite->dbip change in ports CVSROOT: /cvs Module name: src Changes by: rcovelli@cvs.openbsd.org 2026/09/30 14:48:11 Modified files: usr.sbin/rpki-client: main.c Log message: Now that we open early we can remove unix pledge OK deraadt@ CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/09/30 20:01:51 Modified files: usr.bin/ssh : auth2-pubkey.c Log message: handle max-pk-ok path identically when the incoming user is invalid; avoids max-pk-ok feature presenting a username validity oracle analysis and patch from Chris Rohlf in collaboration with Claude and Anthropic Research CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/09/30 20:18:26 Modified files: . : 80.html Log message: spelling CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/09/30 20:47:41 Modified files: . : 80.html Log message: update base and xenocara component versions CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/09/30 21:11:49 Modified files: usr.bin/ssh : sftp-client.c sftp.c Log message: sftp: be stricter in accepting paths returned by the server for SSH_FXP_REALPATH or SSH2_FXP_READDIR replies, as these can be used in some situations to decide the destination path for recursive transfers. Report and patch from Junghoon Cho CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/09/30 21:40:35 Modified files: . : 80.html Log message: update ports versions CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/09/30 21:54:19 Modified files: . : 80.html Log message: no loongson for 8.0 CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/09/30 22:17:39 Modified files: usr.bin/ssh : ssh-mldsa-eddsa.c Log message: fix the bit length of ML-DSA 44/Ed25519 keys that was being incorrectly reported as 256. The private key length for these composite keys is 512 bits. This value is only used for display. Spotted by Yiyue Wang CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/09/30 23:53:25 Modified files: lang/python/3 : Makefile Added files: lang/python/3/patches: patch-Modules__ssl_c Log message: cherrypick fix for CPython CVE-2026-19445: Use-after-free of a server-side SSLContext when sni_callback switches contexts. ok tb kmos A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open. CVSROOT: /cvs Module name: ports Changes by: sthen@cvs.openbsd.org 2026/09/30 23:54:02 Modified files: lang/python/3 : Tag: OPENBSD_7_9 Makefile Added files: lang/python/3/patches: Tag: OPENBSD_7_9 patch-Modules__ssl_c Log message: cherrypick fix for CPython CVE-2026-19445: Use-after-free of a server-side SSLContext when sni_callback switches contexts. ok tb kmos CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/01 00:30:05 Modified files: . : 80.html Log message: Thunderbird 153.4.0 CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/01 01:07:49 Modified files: usr.bin/ssh : sshkey.c Log message: Implement a maximum number of KDF rounds that will be accepted when writing an OpenSSH-format private key or when loading one. This limit is set pretty high (1<<20), but ensures that a service that is passed a bad key with an ridiculously high number of rounds will _eventually_ complete parsing it. Also bump the default number of KDF rounds from 24 to 32 (this is a linear increase, not like bcrypt(3) which is exponential). Pointed out by Aris Adamantiadis CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/01 01:08:05 Modified files: usr.bin/ssh : ssh-keygen.1 Log message: mention default KDF rounds is now 32 CVSROOT: /cvs Module name: src Changes by: djm@cvs.openbsd.org 2026/10/01 01:10:56 Modified files: usr.bin/ssh : scp.c Log message: start process of deprecating the -R flag. This was the old way of performing a remote-to-remote copy that was basically executed scp on the remote host. It barely worked (needing agent forwarding enabled or usable credentials on the remote host) and has largely been replaced by a better SFTP-protocol remote-to-remote copy that runs through the host performing the copy. We'll disable this option in a release or two; ok dtucker@ CVSROOT: /cvs Module name: src Changes by: otto@cvs.openbsd.org 2026/10/01 01:16:45 Modified files: lib/libc/sys : send.2 Log message: Describe what sendmmsg(2) actually does and fix prototype. ok deraadt@ CVSROOT: /cvs Module name: www Changes by: claudio@cvs.openbsd.org 2026/10/01 03:13:56 Modified files: . : mail.html openbgpd : index.html mail.html build/mirrors : openbgpd-ftp.html.head Log message: The openbgpd github organization was moved from "openbgpd-portable" to "openbgpd". Adjust various links. Diff provided by Clara Engler (cve (at) cve cx) CVSROOT: /cvs Module name: www Changes by: claudio@cvs.openbsd.org 2026/10/01 03:15:05 Modified files: openbgpd : ftp.html Log message: Regen after github url change CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:11:41 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: report hardware RX aggregation Based on sys/dev/ic/qwx.c,v 1.85 and sys/dev/ic/qwx.c,v 1.90 Report hardware deaggregation and reordering after successful RX reconstruction; allow repaeted sequence numbers for later A-MSDU subframes and clear the AMSDU QoS bit. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:13:03 Modified files: sys/dev/ic : qwz.c qwzreg.h qwzvar.h Log message: sys/qwz: handle WBM RX errors Based on sys/dev/ic/qwx.c,v 1.35 and sys/dev/ic/qwxvar.h,v 1.18 , sys/dev/ic/qwx.c,v 1.89 , sys/dev/ic/qwx.c,v 1.121 and sys/dev/ic/qwxvar.h,v 1.36 Process WBM RX releases using WCN7850 descriptor and cookie formats. Deliver valid null queue frames through existing RX processing, clear mbuf pointers after delivery, and then replenish descriptors OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:13:53 Modified files: sys/dev/ic : qwz.c qwzvar.h Log message: sys/qwz: read RX metadata from MPDU TLVs Read sequence numbers and TIDs from WCN7850 MPDU descriptors. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:14:55 Modified files: sys/dev/ic : qwz.c qwzreg.h Log message: sys/qwz: drain REO RX exceptions Based on sys/dev/ic/qwx.c,v 1.33 Drain REO RX exceptions using descriptor layouts and qwz cookie. Reclaim packet buffers, return link descriptors and replenish RX, checking bank bounds and release ring space. OK: stsp@ CVSROOT: /cvs Module name: ports Changes by: robert@cvs.openbsd.org 2026/10/01 04:15:01 Modified files: www/chromium : Makefile distinfo www/chromium/patches: patch-chrome_browser_picture_in_picture_picture_in_picture_window_manager_cc patch-content_browser_web_contents_web_contents_impl_cc patch-gpu_command_buffer_service_gles2_cmd_decoder_cc patch-gpu_command_buffer_service_shared_image_external_vk_image_backing_factory_cc patch-third_party_fontconfig_include_meson-config_h patch-third_party_test_fonts_fontconfig_BUILD_gn Removed files: www/chromium/patches: patch-third_party_test_fonts_fontconfig_generate_fontconfig_caches_cc Log message: update to 154.0.8037.92; ok naddy@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:15:51 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: count discarded RX packets Backport of sys/dev/ic/qwx.c,v 1.91 and sys/dev/ic/qwx.c,v 1.95 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:16:43 Modified files: sys/dev/ic : qwz.c qwzvar.h Log message: sys/qwz: report radiotap channels and rates Based on sys/dev/ic/qwx.c,v 1.93 and sys/dev/ic/qwxvar.h,v 1.31 Populate radiotap channel and rate fields with WCN7850 RX rate decoding. Use QWZ presence masks and omit unavailable timestamps, noise and signal strength for data frames. Correct 54 Mb/s encoding from 104 to 108 in 500 kb/s. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:17:30 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: preserve decoded radiotap frequency Management RX parameters already contain a hostorder chanel frequency. Avoid decoding it again before writing the little endian radiotap field. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 04:18:14 Modified files: sys/dev/pci : if_qwz_pci.c Log message: sys/qwz: retain cached firmware filenames Backport of sys/dev/pci/if_qwx_pci.c,v 1.29 OK: stsp@ CVSROOT: /cvs Module name: ports Changes by: jca@cvs.openbsd.org 2026/10/01 06:04:07 Modified files: security/gnupg : Makefile distinfo Added files: security/gnupg/patches: patch-g10_import_c Log message: Reattempt the upgrade to gnupg-2.5.24 Upstream published a fix for regression that broke mail/notmuch configure. Updating now means smaller steps if we need an update for a security issue in the next 8.0 OpenBSD release. ok sthen@ naddy@ CVSROOT: /cvs Module name: src Changes by: claudio@cvs.openbsd.org 2026/10/01 07:06:56 Modified files: usr.sbin/rpki-client: repo.c Log message: Track the nofetch variable by TAL. This matches better with the MAX_REPO_PER_TAL limit which is already tracked by TAL and with that a TAL hitting the limit will not affect the other TALs. Reported by eur1ka OK tb@ CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/01 07:12:16 Modified files: . : errata.html errata20.html errata21.html errata22.html errata23.html errata24.html errata25.html errata26.html errata27.html errata28.html errata29.html errata30.html errata31.html errata32.html errata33.html errata34.html errata35.html errata36.html errata37.html errata38.html errata39.html errata40.html errata41.html errata42.html errata43.html errata44.html errata45.html errata46.html errata47.html errata48.html errata49.html errata50.html errata51.html errata52.html errata53.html errata54.html errata55.html errata56.html errata57.html errata58.html errata59.html errata60.html errata61.html errata62.html errata63.html errata64.html errata65.html errata66.html errata67.html errata68.html errata69.html errata70.html errata71.html errata72.html errata73.html errata74.html errata75.html errata76.html errata77.html errata78.html errata79.html Added files: . : errata80.html Log message: add errata80 CVSROOT: /cvs Module name: www Changes by: tj@cvs.openbsd.org 2026/10/01 07:12:42 Modified files: . : plus.html plus20.html plus21.html plus22.html plus23.html plus24.html plus25.html plus26.html plus27.html plus28.html plus29.html plus30.html plus31.html plus32.html plus33.html plus34.html plus35.html plus36.html plus37.html plus38.html plus39.html plus40.html plus41.html plus42.html plus43.html plus44.html plus45.html plus46.html plus47.html plus48.html plus49.html plus50.html plus51.html plus52.html plus53.html plus54.html plus55.html plus56.html plus57.html plus58.html plus59.html plus60.html plus61.html plus62.html plus63.html plus64.html plus65.html plus66.html plus67.html plus68.html plus69.html plus70.html plus71.html plus72.html plus73.html plus74.html plus75.html plus76.html plus77.html plus78.html plus79.html Added files: . : plus80.html Log message: add plus80 CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/01 07:25:54 Modified files: usr.sbin/rpki-client: nca.c Log message: rpki-client: factor a nonfunc_ca_free() out of nca_tree_remove_cert() ok claudio CVSROOT: /cvs Module name: src Changes by: tb@cvs.openbsd.org 2026/10/01 07:31:14 Modified files: usr.sbin/rpki-client: nca.c Log message: rpki-client: do not fatal after RB_INSERT() into the NCA trees rpki-client is generally a bit too quick to error out and a repeated source of problems has been errx after RB_INSERT() (one fixed just yesterday). The first of these is probably not reachable but do that for good measure. The other one was shown to be reachable in somewhat contrived setups by eur1ka, which means rpki-client would refuse to start. ok claudio CVSROOT: /cvs Module name: src Changes by: stsp@cvs.openbsd.org 2026/10/01 07:39:35 Modified files: sys/dev/ic : qwx.c Log message: Don't use negative errno values in qwx(4). Spotted by kirill@ CVSROOT: /cvs Module name: src Changes by: millert@cvs.openbsd.org 2026/10/01 10:33:26 Modified files: share/zoneinfo/datfiles: europe northamerica zone.tab zone1970.tab zonenow.tab Log message: Update to 2026egtz from https://github.com/JodaOrg/global-tz o Manitoba moves to permanent -05 on 2026-10-31. o In 1925 Ireland fell back on 09-20 not 10-04. CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:26:07 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: update RSSI from TX acknowledgments Backport of sys/dev/ic/qwx.c,v 1.98 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:26:51 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: clear node flags during deauthentication Backport of sys/dev/ic/qwx.c,v 1.113 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:27:39 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: keep data interrupts through association Backport of sys/dev/ic/qwx.c,v 1.125 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:28:42 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: prepare peers before association requests Backport of sys/dev/ic/qwx.c,v 1.94, sys/dev/ic/qwx.c,v 1.118 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:29:43 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: configure negotiated HT SMPS Backport of sys/dev/ic/qwx.c,v 1.92 OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:30:30 Modified files: sys/dev/ic : qwz.c qwzreg.h Log message: sys/qwz: fix WCN7850 REO layout Use WCN7850 REO tags and 64-bit TLV headers so commands and completions use the correct offsets. Correct the status ring size and clear command payloads before reuse. The layout follows Linux ath12k's WCN7850 definitions. OK: stsp@ CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 11:37:59 Modified files: sys/dev/ic : qwz.c qwzvar.h Log message: sys/qwz: fix REO queue lifetime Track REO completions before publication and wait for peer unmap, deletion, and cache flushes before reusing queue DMA. Submission errors and timeouts retain ownership; hardware failures block reuse until cold cleanup. HAL error conventions and flush semantics follow ath12k; tracking and the reuse barrier adapt qwz's retained pool. CVSROOT: /cvs Module name: src Changes by: mlarkin@cvs.openbsd.org 2026/10/01 15:49:49 Modified files: usr.sbin/vmd : i8259.c Log message: vmd(8): change a log_warnx to a log_debug no functional change, just quieting a chatty log message. CVSROOT: /cvs Module name: src Changes by: kirill@cvs.openbsd.org 2026/10/01 16:35:08 Modified files: sys/dev/ic : qwz.c Log message: sys/qwz: spoted one more negative errno CVSROOT: /cvs Module name: src Changes by: jsg@cvs.openbsd.org 2026/10/01 17:51:29 Modified files: sys/arch/i386/i386: machdep.c sys/arch/amd64/amd64: cpu.c Log message: don't access the DE_CFG MSR when running on a hypervisor Sebastian Albert encountered a KVM hosting provider where trying to access the MSR resulted in a protection fault. DE_CFG is not documented in AMD's 'AMD64 Architecture Programmer's Manual'. ok brynet@ mlarkin@ CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/01 19:29:30 Modified files: . : 80.html Log message: add rkotp(4) and sambat(4) CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/01 19:44:47 Modified files: . : 80.html Log message: arm64 hibernate support is new for 8.0, don't mention fixes CVSROOT: /cvs Module name: www Changes by: jsg@cvs.openbsd.org 2026/10/01 19:49:19 Modified files: . : 80.html Log message: don't mention pkgconf version twice CVSROOT: /cvs Module name: src Changes by: rsadowski@cvs.openbsd.org 2026/10/01 22:03:47 Modified files: usr.sbin/relayd: relay_http.c Log message: relayd: apply the header length limit to unterminated lines The limit was only checked for complete lines, so a header line without line ending could be buffered without bound. Reject such lines with 413 as soon as they exceed the limit. Spotted by Acts1631 (with diff), OK kirill@ CVSROOT: /cvs Module name: src Changes by: rsadowski@cvs.openbsd.org 2026/10/01 22:18:48 Modified files: usr.sbin/relayd: relay_http.c Log message: relayd: apply the header length limit to chunk size and trailer lines Chunk size and trailer lines were not limited, so a line without line ending could be buffered without bound. Limit each chunk size line and the whole trailer to the configured header length and close the session if they exceed it. Spotted by Acts1631 (with diff), OK kirill@ CVSROOT: /cvs Module name: src Changes by: rsadowski@cvs.openbsd.org 2026/10/01 22:34:27 Added files: regress/usr.sbin/relayd: args-http-chunked-trailer-unterminated.pl Log message: Test unterminated chunk trailer lines against the header length limit CVSROOT: /cvs Module name: src Changes by: rsadowski@cvs.openbsd.org 2026/10/01 22:47:07 Modified files: usr.sbin/httpd : config.c httpd.c httpd.conf.5 httpd.h parse.y server.c server_http.c Log message: httpd: add header block/drop rules for request filtering With this incoming requests can also be rejected based on the value of a request header. Valid options are: header block name value code [arg] Close the connection with an error response when a request header matches. Both name and value are shell- style patterns and are matched case-insensitively against the header name and value. code must be a valid HTTP status code. For codes in the 3xx range, arg is required and sent as the "Location" header. It must start with "http://" or "https://". For all other codes, arg is optional and used as the log message identifying the rule. header drop name value Silently close the connection without sending a response when a request header matches, using the same pattern rules as block. Based on a diff from Purple Rain from SecBSD, who wrote a initial version to block Ai- and other Scraper. Also requested and tested by Mischa. Tested by Purple Rain, Mischa and others, thanks Feedback by Lloyd, Christian Schulte, thanks OK kirill@