Build date: 1784584803 - Mon Jul 20 22:00:03 UTC 2026 Build cvs date: 1784570222 - Mon Jul 20 17:57:02 UTC 2026 Build id: 2026-07-21.1 Build tags: amd64-regress ports sysupgrade Applied the following diff(s): /home/anton/tmp/robsd/src-sys-em.diff /home/anton/tmp/robsd/src-sys-uhidev-sispm.diff /home/anton/tmp/robsd/src-sysupgrade.diff P lib/libc/sys/pledge.2 P lib/libc/sys/unveil.2 P regress/usr.sbin/relayd/Makefile U regress/usr.sbin/relayd/args-ssl-ec.pl P sys/dev/fdt/dwpcie.c P sys/dev/fdt/xhci_fdt.c M sys/dev/usb/uhidev.c P usr.bin/tmux/cmd-capture-pane.c P usr.bin/tmux/format.c P usr.bin/tmux/grid.c P usr.bin/tmux/input.c P usr.bin/tmux/screen-write.c P usr.bin/tmux/tmux.h P usr.bin/tmux/window-copy.c P usr.sbin/authpf/authpf.c P usr.sbin/bgpd/rde.h P usr.sbin/bgpd/rde_rib.c P usr.sbin/bgpd/rde_update.c M usr.sbin/bgpd/session.c P usr.sbin/fw_update/fw_update.sh P usr.sbin/relayd/ca.c P usr.sbin/relayd/relay.c P usr.sbin/relayd/relayd.h P usr.sbin/relayd/ssl.c P usr.sbin/rpki-client/ccr.c P usr.sbin/vmd/vmd.c commit 1RZ6ml972MybMtTT Author: kettenis Date: 2026/07/20 17:57:02 Enable on Spacemit K3. sys/dev/fdt/xhci_fdt.c commit 1qNIgZLxdhKWiF46 Author: rsadowski Date: 2026/07/20 17:44:04 Add add ECDSA tests (based on the RSA tests) regress/usr.sbin/relayd/Makefile regress/usr.sbin/relayd/args-ssl-ec.pl commit f8xlPVqvHshFB2RH Author: rsadowski Date: 2026/07/20 17:41:07 relayd: add ECDSA support to the CA privsep engine Add an EC_KEY_METHOD that forwards the sign operation to the CA process, clone the existing RSA engine. ssl_load_pkey() now handles both RSA and EC keys and attaches the cert hash accordingly. The engine and signing code was migrated from smtpd from (op@) with some tweaks by me. OK op@ usr.sbin/relayd/ca.c usr.sbin/relayd/relay.c usr.sbin/relayd/relayd.h usr.sbin/relayd/ssl.c commit USyrzGKMLVTFhPBr Author: dv Date: 2026/07/20 17:37:10 vmd(8): validate memory ranges in vmd before vmm(4). While vmm(4) does its own check on the number of memory ranges, do the check in vmd(8) to fail fast and provide feedback to the user. Report and diff by Andrew Griffiths. ok @hshoexer usr.sbin/vmd/vmd.c commit CBjHZ8P1dqTITDXS Author: sashan Date: 2026/07/20 16:00:35 authpf(8) read_config() should chop off trailing white space if administrator mistakenly types into configuration file anchor=authpf_test where 'authpf_test' is followed by white space, the authpf(8) is going to use anchor 'authpf_test ' instead of the 'authpf_test' which is defined in pf.conf(5) as 'anchor authpf_test/*' issue kindly reported and patch submitted by Avinash Duduskar OK sashan@ usr.sbin/authpf/authpf.c commit QDh7bggSwPPpFQZR Author: claudio Date: 2026/07/20 13:25:49 Bring back up_generate_addpath_all() using the rib entry queue add-path send all can take a fair amount of shortcuts compared to the other add-path send modes. The rib entry queue (struct pq_entry) holds all the information to update the adj-rib-out. For general updates just walk the pq list and insert / withdraw all paths. A path can only be once on the list so the code just needs to walk it and call up_process_prefix for updates. If up_process_prefix() returns UP_FILTERED or UP_EXCLUDED then try to withdraw the prefix. This uses the same codepath as for any withdraw in the queue. Tested on the NLNOG ring looking glass server. OK tb@ usr.sbin/bgpd/rde.h usr.sbin/bgpd/rde_rib.c usr.sbin/bgpd/rde_update.c commit giri6XEZ6FqzDzhw Author: nicm Date: 2026/07/20 11:16:33 Change cellused/size to 16 bits and time to 32 bits in grid_line and add the OSC 133 positions (size stays the same). usr.bin/tmux/cmd-capture-pane.c usr.bin/tmux/grid.c usr.bin/tmux/input.c usr.bin/tmux/screen-write.c usr.bin/tmux/tmux.h usr.bin/tmux/window-copy.c commit SzXR7GcvKnL7uewq Author: job Date: 2026/07/20 10:02:55 Disambigulate all warnings about CCR corruption OK tb@ usr.sbin/rpki-client/ccr.c commit fI7GNj6Eluev1MFW Author: nicm Date: 2026/07/20 07:42:13 Correctly include status line in pane height. usr.bin/tmux/format.c commit pRMfjn8pCfkoOU5w Author: dgl Date: 2026/07/20 01:26:11 Document how unveil(2) permissions correspond to various pledge(2) promises. unveil considers the operation that happens at namei(9) time, but pledge has a deeper integration into subsystems, therefore pledge can be more precise. This change is the result of various experiments. For example the "unix" promise allows creating files when calling bind(2) on an AF_UNIX socket, we found requiring the "cpath" promise along with "unix" either required extensive changes or made the promise set too broad. Similiar applies to connect(2) and "wpath". Instead document that the unveil permissions "c", "w" and "r" correspond to a larger set of pledge promises. ok deraadt lib/libc/sys/pledge.2 lib/libc/sys/unveil.2 commit 9mXhlg5qgSXyYHMh Author: afresh1 Date: 2026/07/19 23:33:16 Clean trailing slashes from FWURL job@ noticed sysupgrade passes urls with trailing slashes that aren't valid on firmware.openbsd.org. usr.sbin/fw_update/fw_update.sh commit zxcMNeFbG8rNbL8I Author: dlg Date: 2026/07/19 22:00:50 make dwpcie_rk3568_link_up less pedantic about what it considers "up". ie, only report whether the pcie link is up, don't look at the state of the up link too. this matches linux behaviour fwiw. after a warm boot (ie, reboot), the re(4) in my rk3528 based radxa e20c didnt attach because the pcie link was in a power saving state instead of the ready state this code was expecting. jmatthew@ and i have also tested this on a bunch of rk356x boards too. ok jmatthew@ kettenis@ sys/dev/fdt/dwpcie.c