OpenBSD/ports hkjgL9rnet/kdeconnect-kde/patches patch-plugins_mousepad_waylandremoteinput_cpp

   I forgot to remove the patch it in my last KDE Gear commit
VersionDeltaFile
1.8+0-0net/kdeconnect-kde/patches/patch-plugins_mousepad_waylandremoteinput_cpp
+0-01 files

OpenBSD/src 3ca4uERetc/root root.mail

   correct date
VersionDeltaFile
1.182+2-2etc/root/root.mail
+2-21 files

OpenBSD/ports mMlci3tsysutils/fzf Makefile distinfo

   sysutils/fzf: Update to 0.74.4

   From Maintainer Laurent Cheylus, thanks
VersionDeltaFile
1.55+2-2sysutils/fzf/distinfo
1.64+1-1sysutils/fzf/Makefile
+3-32 files

OpenBSD/src mmlrjiJusr.sbin/smtpd mda_variables.c

   indent
VersionDeltaFile
1.13+2-2usr.sbin/smtpd/mda_variables.c
+2-21 files

OpenBSD/ports X60GC1Rgraphics/stable-diffusion.cpp Makefile distinfo, graphics/stable-diffusion.cpp/patches patch-ggml_src_ggml-backend-reg_cpp patch-CMakeLists_txt

   graphics/stable-diffusion.cpp: Update to 0.0.850
VersionDeltaFile
1.10+4-4graphics/stable-diffusion.cpp/distinfo
1.13+2-3graphics/stable-diffusion.cpp/Makefile
1.5+1-1graphics/stable-diffusion.cpp/patches/patch-ggml_src_ggml-backend-reg_cpp
1.7+1-1graphics/stable-diffusion.cpp/patches/patch-CMakeLists_txt
+8-94 files

OpenBSD/ports aeL9iu7wayland/foot distinfo Makefile, wayland/foot/patches patch-main_c

   wayland/foot: Update to 1.28.0
VersionDeltaFile
1.18+1-5wayland/foot/Makefile
1.13+2-2wayland/foot/distinfo
1.7+1-1wayland/foot/patches/patch-main_c
1.9+2-0wayland/foot/pkg/PLIST
+6-84 files

OpenBSD/ports pAxbTsowayland/mango Makefile distinfo, wayland/mango/patches patch-src_mango_c patch-src_dispatch_bind_define_h

   wayland/mango: Update to 0.17.0
VersionDeltaFile
1.1+59-0wayland/mango/patches/patch-src_dispatch_bind_c
1.1+11-0wayland/mango/patches/patch-src_main_c
1.17+2-2wayland/mango/distinfo
1.18+1-1wayland/mango/Makefile
1.9+0-0wayland/mango/patches/patch-src_mango_c
1.13+0-0wayland/mango/patches/patch-src_dispatch_bind_define_h
+73-36 files

OpenBSD/ports EHPH2zvgames/scummvm Makefile distinfo, games/scummvm/patches patch-configure

   update to scummvm 2026.3.0
VersionDeltaFile
1.33+2-2games/scummvm/patches/patch-configure
1.51+2-2games/scummvm/distinfo
1.110+1-1games/scummvm/Makefile
+5-53 files

OpenBSD/ports EZr5nkCwww/chromium/patches patch-chrome_browser_chrome_content_browser_client_cc patch-base_process_process_handle_openbsd_cc

   update to 153.0.8010.36
VersionDeltaFile
1.163+79-70www/chromium/patches/patch-chrome_browser_about_flags_cc
1.80+37-82www/chromium/patches/patch-media_base_media_switches_cc
1.17+15-86www/chromium/patches/patch-base_base_paths_posix_cc
1.1+101-0www/chromium/patches/patch-third_party_blink_renderer_platform_fonts_opentype_format_check_rs
1.12+18-66www/chromium/patches/patch-base_process_process_handle_openbsd_cc
1.141+48-30www/chromium/patches/patch-chrome_browser_chrome_content_browser_client_cc
+298-334415 files not shown
+2,289-1,754421 files

OpenBSD/ports UgFXYXmmeta/kde Makefile

   Forgotten to remove x11/kde-applications/kmines in the last KDE update

   Spotted by naddy@
VersionDeltaFile
1.59+0-1meta/kde/Makefile
+0-11 files

OpenBSD/src u1k2OyDdistrib/notes/octeon prep

   Add note about ogx(4) and non-free firmware

   Suggested by jj@
VersionDeltaFile
1.13+14-1distrib/notes/octeon/prep
+14-11 files

OpenBSD/src NvLgJ41usr.sbin/rpki-client crl.c extern.h

   Check alignment of certificate CRLDPs with the CRLDP of the referring Manifest

   RFC 6480, section 4.2, figure 2 illustrates how all valid products in
   the same CA repository (i.e., from the same issuer, listed on the same
   manifest) will point to the same CRL. For CRLDPs in manifest EE certs
   alignment was already checked against the CRL location derived from
   the fileList in a given manifest's eContent. Add a check to explicitly
   confirm internally consistent CRLDPs in certificates as well.

   OK tb@
VersionDeltaFile
1.185+9-1usr.sbin/rpki-client/parser.c
1.144+4-1usr.sbin/rpki-client/mft.c
1.296+3-1usr.sbin/rpki-client/extern.h
1.53+2-1usr.sbin/rpki-client/crl.c
+18-44 files

OpenBSD/ports EDqaRi4net/telemt Makefile crates.inc

   update to telemt 3.5.7
VersionDeltaFile
1.13+256-282net/telemt/distinfo
1.10+127-140net/telemt/crates.inc
1.14+1-1net/telemt/Makefile
+384-4233 files

OpenBSD/ports 4Oxr0flx11/qt6/qtspeech Makefile

   x11/qt6/qtspeech: fix Makefile syntax error
VersionDeltaFile
1.7+1-1x11/qt6/qtspeech/Makefile
+1-11 files

OpenBSD/ports QtyDaz2x11/kde-plasma/kdeplasma-addons distinfo, x11/kde-plasma/kscreenlocker Makefile

   Update KDE Plasma 6.7.5

   https://kde.org/announcements/plasma/6/6.7.5/
VersionDeltaFile
1.7+19-17x11/kde-plasma/spectacle/Makefile
1.16+8-8x11/kde-plasma/plasma-sdk/Makefile
1.19+6-4x11/kde-plasma/kscreenlocker/Makefile
1.38+4-4x11/kde-plasma/kdeplasma-addons/distinfo
1.21+4-3x11/kde-plasma/plasma-pa/Makefile
1.9+4-2x11/kde-plasma/ksystemstats/Makefile
+45-3861 files not shown
+159-14367 files

OpenBSD/ports MCwfHjsmail/postfix Makefile.inc, mail/postfix/stable Makefile distinfo

   MFC update to postfix-3.5.28 and 3.11.7
VersionDeltaFile
1.4.10.4+2-2mail/postfix/stable35/distinfo
1.164.2.5+2-2mail/postfix/stable/distinfo
1.281.2.7+1-2mail/postfix/stable/Makefile
1.115.2.3+0-2mail/postfix/Makefile.inc
1.11.2.4+1-1mail/postfix/stable35/Makefile
+6-95 files

OpenBSD/ports B8y2POHmail/postfix Makefile.inc, mail/postfix/stable Makefile distinfo

   update to postfix-3.5.28 and 3.11.7, from Brad (maintainer)
VersionDeltaFile
1.8+2-2mail/postfix/stable35/distinfo
1.169+2-2mail/postfix/stable/distinfo
1.16+1-2mail/postfix/stable35/Makefile
1.288+1-2mail/postfix/stable/Makefile
1.118+0-2mail/postfix/Makefile.inc
+6-105 files

OpenBSD/ports q10ja8hdevel/meson-python Makefile distinfo

   Update to meson-python-0.21.1.
VersionDeltaFile
1.9+2-2devel/meson-python/distinfo
1.14+1-1devel/meson-python/Makefile
+3-32 files

OpenBSD/ports rtY8G2Jx11/gnome/gvfs Makefile distinfo

   Update to gvfs-1.60.3.
VersionDeltaFile
1.100+2-2x11/gnome/gvfs/distinfo
1.231+1-1x11/gnome/gvfs/Makefile
+3-32 files

OpenBSD/ports Woa0B2ix11/gnome/papers distinfo Makefile

   Update to papers-50.3.
VersionDeltaFile
1.12+1-4x11/gnome/papers/Makefile
1.9+2-2x11/gnome/papers/distinfo
+3-62 files

OpenBSD/ports KA92J2Nx11/gnome/maps Makefile distinfo

   Update to gnome-maps-50.5.
VersionDeltaFile
1.95+2-2x11/gnome/maps/distinfo
1.130+1-2x11/gnome/maps/Makefile
+3-42 files

OpenBSD/ports 12kpiCQx11/gnome/libshumate distinfo Makefile, x11/gnome/libshumate/pkg PLIST

   Update to libshumate-1.7.0.
VersionDeltaFile
1.34+3-3x11/gnome/libshumate/Makefile
1.15+6-0x11/gnome/libshumate/pkg/PLIST
1.28+2-2x11/gnome/libshumate/distinfo
+11-53 files

OpenBSD/ports WmSOXXgx11/gnome/ghex Makefile distinfo

   Update to ghex-50.4.
VersionDeltaFile
1.46+2-2x11/gnome/ghex/distinfo
1.112+1-1x11/gnome/ghex/Makefile
+3-32 files

OpenBSD/ports ycWKxDLwww/webkitgtk4 Makefile, www/webkitgtk4/patches patch-Source_WebKit_UIProcess_gtk_AcceleratedBackingStore_cpp patch-Source_WebKit_WebProcess_WebPage_CoordinatedGraphics_AcceleratedSurface_cpp

   Add a workaround to enable accelerated graphics (so support for dma-buf in gtk4).
VersionDeltaFile
1.1+36-0www/webkitgtk4/patches/patch-Source_WebKit_WebProcess_WebPage_CoordinatedGraphics_AcceleratedSurface_cpp
1.2+20-12www/webkitgtk4/patches/patch-Source_WebKit_UIProcess_gtk_AcceleratedBackingStore_cpp
1.264+1-1www/webkitgtk4/Makefile
+57-133 files

OpenBSD/ports qJ2ay0Rsecurity/openssl/libretls Makefile, security/openssl/libretls/patches patch-tls_verify_c

   libretls: sync with libretls4
VersionDeltaFile
1.2+61-1security/openssl/libretls/patches/patch-tls_verify_c
1.18+1-1security/openssl/libretls/Makefile
+62-22 files

OpenBSD/ports 20E2kU2security/openssl/libretls4 Makefile, security/openssl/libretls4/patches patch-tls_verify_c

   libretls4: port ASN1_STRING compat from tls_verify.c r1.35 to libretls4

   This makes libretls work with OpenSSL 4.1.
VersionDeltaFile
1.2+61-1security/openssl/libretls4/patches/patch-tls_verify_c
1.2+1-0security/openssl/libretls4/Makefile
+62-12 files

OpenBSD/src nD0xW8plib/libtls tls_verify.c

   tls_verify: add empty line I forgot to add before commit
VersionDeltaFile
1.36+2-1lib/libtls/tls_verify.c
+2-11 files

OpenBSD/src 43I9Vkqlib/libtls tls_verify.c

   tls_verify: do not assume ASN1_STRINGs are strings

   OpenSSL 4.1 no longer NUL terminates ASN.1 strings. This is fine per se,
   but the fact that they don't mention this major breaking change in their
   overlong CHANGES.md is crazy. Who reads the migration guide for an update
   that's supposedly backward compatible? This will cause buffer overreads
   left and right.

   To wit, strlen(data) is a buffer overread, so use strnlen() instead.

   While it is probably possible to rewrite tls_match_name() to cope with a
   bag of bytes, it gets really hairy (I think it is already hairier than
   all the yaks in Tibet combined). So use the lazy way and strndup(), then
   we have a string and do not need to mess with this horrible byte bashing.
   The other caller of tls_match_name() already passes a string.

   As jsing points out, CBS_strndup() would be the right way to fix this.

   ok kenjiro jsing
VersionDeltaFile
1.35+16-4lib/libtls/tls_verify.c
+16-41 files

OpenBSD/src Dn4sRXkusr.sbin/rpki-client rfc3779.c extern.h

   rpki-client: do not provide IPAddrBlocks_{new,free}() unconditionally

   After sitting on the issue for over four years, a last-minute addition to
   OpenSSL 4.1 provided a somewhat incorrect version of IPAddrBlocks_new(),
   and versions of IPAddrBlocks_free() ith i2d and d2i and the ASN.1 item.
   Until LibreSSL provides the corresponding functions, we need this compat
   code in base. After that the rfc3779.c file can move to portable where it
   really belongs.

   With this the rpki-client code is ready for OpenSSL 4.1, provided it uses
   a fixed version of lib(re)tls.

   ok claudio
VersionDeltaFile
1.295+5-5usr.sbin/rpki-client/extern.h
1.3+5-1usr.sbin/rpki-client/rfc3779.c
+10-62 files

OpenBSD/src NmIEjfmusr.sbin/rpki-client validate.c

   rpki-client: fix valid_uri() to work with non-strings

   valid_uri() takes a length parameter and should honor that. Most uris
   passed are NUL terminated, but the ones coming from an ASN1_STRING are
   not guaranteed to be. Calling strstr() on a non-terminated string with
   no match is a buffer overread. So use memmem() instead.

   This is needed for rpki-client to work with OpenSSL 4.1, who, in their
   infinite disregard for downstreams chose to stop NUL-terminating ASN.1
   strings. A massive breaking change in a minor release that will surely
   cause lots of buffer overreads. It's also not mentioned in CHANGES.md,
   only in their terrible migration guide. Of course it's been documented
   since forever, but who reads OpenSSL's crappy documentation anyway?

   ok claudio
VersionDeltaFile
1.86+2-2usr.sbin/rpki-client/validate.c
+2-21 files