On 30/09/2026 15:48, Sven F. wrote: > https://man.openbsd.org/syspatch
Thanks. I'm already using syspatch(8), so I know how an errata is applied. My question is about the timing: why the nsd security releases 4.14.3 (Jun 25) and 4.15.1 (Aug 26) did not become errata for 7.9 earlier, and what triggered errata 022 now. G > On Wed, Sep 30, 2026 at 8:25 AM Kapetanakis Giannis > <[email protected]> wrote: >> Hi, >> >> We rely on nsd and unbound from base for our DNS infrastructure, so I'd like >> to understand how updates to them are handled for -stable. >> >> Errata 022 for 7.9 updates nsd to 4.15.2, from 4.14.2 as shipped with 7.9, >> if I read it correctly. >> Upstream, in the meantime, there were: >> >> - NSD 4.14.3 security release (Jun 25) >> - NSD 4.15.0 release (Jul 7) >> - NSD 4.15.1 security release (Aug 26) >> - NSD 4.15.2 release (Sep 2) >> >> I'm asking because OpenBSD usually gets security fixes out very quickly, so >> the gap here surprised me. >> >> I'm not complaining or demanding anything, I'd just like to understand the >> process: how does the project decide when nsd/unbound security releases >> become an errata, and what led to doing it now rather than with 4.14.3 or >> 4.15.1? >> Or was it something in 4.15.2, rather than the earlier CVEs, that triggered >> it? >> >> Knowing this would help us plan (e.g. whether to track upstream ourselves >> for these daemons). >> >> regards, >> >> Giannis >> >> ps: Stuart, none of this is aimed at you. My question is about the process, >> not the people doing the work. Much respect for everything you do for >> OpenBSD, not only nsd and unbound. >> >> >>

