untrusted comment: verify with openbsd-78-base.pub RWS3/nvFmk4SWUGY2lZg4I4WLKgv1Jp6K/oX610XUU0/FpHS48L9B4LxWtpuINICRPV36dYPysGlCeCsl9C1ZkxPfmcnHO2Xzg0= OpenBSD 7.8 errata 066, September 30, 2026: Incorrect upper bound for uid and gid can result in -1 being used. Apply by doing: signify -Vep /etc/signify/openbsd-78-base.pub -x 066_uidrange.patch.sig \ -m - | (cd /usr/src && patch -p0) And then rebuild and install libc, libutil, smtpd, ypldap, init, mountd, and chroot: cd /usr/src/lib/libc make obj make make install cd /usr/src/lib/libutil make obj make make install cd /usr/src/usr.sbin/smtpd make obj make make install cd /usr/src/usr.sbin/ypldap make obj make make install cd /usr/src/sbin/init make obj make make install cd /usr/src/sbin/mountd make obj make make install cd /usr/src/usr.sbin/chroot make obj make make install Index: lib/libc/gen/getgrouplist.c =================================================================== RCS file: /cvs/src/lib/libc/gen/getgrouplist.c,v diff -u -p -u -r1.31 getgrouplist.c --- lib/libc/gen/getgrouplist.c 4 Nov 2024 21:49:26 -0000 1.31 +++ lib/libc/gen/getgrouplist.c 23 Sep 2026 00:45:16 -0000 @@ -73,7 +73,7 @@ _parse_netid(char *netid, uid_t uid, gid if (!p) return (0); *p++ = '\0'; - tuid = (uid_t)strtonum(netid, 0, UID_MAX, &errstr); + tuid = (uid_t)strtonum(netid, 0, UID_MAX - 1, &errstr); if (errstr || tuid != uid) return (0); @@ -83,7 +83,7 @@ _parse_netid(char *netid, uid_t uid, gid p = strchr(start, ','); if (p) *p++ = '\0'; - gid = (gid_t)strtonum(start, 0, GID_MAX, &errstr); + gid = (gid_t)strtonum(start, 0, GID_MAX - 1, &errstr); if (errstr) continue; Index: lib/libutil/passwd.c =================================================================== RCS file: /cvs/src/lib/libutil/passwd.c,v diff -u -p -u -r1.56 passwd.c --- lib/libutil/passwd.c 28 Jun 2019 13:32:43 -0000 1.56 +++ lib/libutil/passwd.c 23 Sep 2026 00:45:16 -0000 @@ -394,7 +394,7 @@ pw_scan(char *bp, struct passwd *pw, int if (!(p = strsep(&bp, ":"))) /* uid */ goto fmt; - pw->pw_uid = strtonum(p, -1, UID_MAX, &errstr); + pw->pw_uid = strtonum(p, -1, UID_MAX - 1, &errstr); if (errstr != NULL) { if (*p != '\0') { warnx("uid is %s", errstr); @@ -410,7 +410,7 @@ pw_scan(char *bp, struct passwd *pw, int if (!(p = strsep(&bp, ":"))) /* gid */ goto fmt; - pw->pw_gid = strtonum(p, -1, GID_MAX, &errstr); + pw->pw_gid = strtonum(p, -1, GID_MAX - 1, &errstr); if (errstr != NULL) { if (*p != '\0') { warnx("gid is %s", errstr); Index: usr.sbin/smtpd/smtpd.c =================================================================== RCS file: /cvs/src/usr.sbin/smtpd/smtpd.c,v diff -u -p -u -r1.357.2.1 smtpd.c --- usr.sbin/smtpd/smtpd.c 27 Feb 2026 20:31:13 -0000 1.357.2.1 +++ usr.sbin/smtpd/smtpd.c 23 Sep 2026 00:45:16 -0000 @@ -1448,7 +1448,8 @@ forkmda(struct mproc *p, uint64_t id, st pw_dir = deliver->userinfo.directory; } - if (pw_uid == 0 && (!dsp->u.local.is_mbox || deliver->mda_exec[0])) { + if (pw_uid == UID_MAX || pw_gid == GID_MAX || + (pw_uid == 0 && (!dsp->u.local.is_mbox || deliver->mda_exec[0]))) { (void)snprintf(ebuf, sizeof ebuf, "MDA not allowed to deliver to: %s", deliver->userinfo.username); m_create(p_dispatcher, IMSG_MDA_DONE, 0, 0, -1); Index: usr.sbin/smtpd/to.c =================================================================== RCS file: /cvs/src/usr.sbin/smtpd/to.c,v diff -u -p -u -r1.50 to.c --- usr.sbin/smtpd/to.c 31 May 2023 16:51:46 -0000 1.50 +++ usr.sbin/smtpd/to.c 23 Sep 2026 00:45:16 -0000 @@ -526,7 +526,7 @@ text_to_userinfo(struct userinfo *userin *p++ = *s++; if (*s++ != ':') goto error; - userinfo->uid = strtonum(buf, 0, UID_MAX, &errstr); + userinfo->uid = strtonum(buf, 0, UID_MAX - 1, &errstr); if (errstr) goto error; @@ -536,7 +536,7 @@ text_to_userinfo(struct userinfo *userin *p++ = *s++; if (*s++ != ':') goto error; - userinfo->gid = strtonum(buf, 0, GID_MAX, &errstr); + userinfo->gid = strtonum(buf, 0, GID_MAX - 1, &errstr); if (errstr) goto error; Index: usr.sbin/ypldap/ldapclient.c =================================================================== RCS file: /cvs/src/usr.sbin/ypldap/ldapclient.c,v diff -u -p -u -r1.55 ldapclient.c --- usr.sbin/ypldap/ldapclient.c 21 Nov 2024 13:38:15 -0000 1.55 +++ usr.sbin/ypldap/ldapclient.c 23 Sep 2026 00:45:16 -0000 @@ -437,11 +437,11 @@ client_build_req(struct idm *idm, struct if (i == ATTR_UID) { ir->ir_key.ik_uid = strtonum( idm->idm_attrs[i], 0, - UID_MAX, NULL); + UID_MAX - 1, NULL); } else if (i == ATTR_GR_GID) { ir->ir_key.ik_gid = strtonum( idm->idm_attrs[i], 0, - GID_MAX, NULL); + GID_MAX - 1, NULL); } } else if (idm->idm_list & F_LIST(i)) { aldap_match_attr(m, idm->idm_attrs[i], &ldap_attrs); @@ -470,11 +470,11 @@ client_build_req(struct idm *idm, struct } if (i == ATTR_UID) { ir->ir_key.ik_uid = strtonum( - ldap_attrs->str[0].ostr_val, 0, UID_MAX, + ldap_attrs->str[0].ostr_val, 0, UID_MAX - 1, NULL); } else if (i == ATTR_GR_GID) { ir->ir_key.ik_uid = strtonum( - ldap_attrs->str[0].ostr_val, 0, GID_MAX, + ldap_attrs->str[0].ostr_val, 0, GID_MAX - 1, NULL); } aldap_free_attr(ldap_attrs); Index: usr.sbin/ypldap/yp.c =================================================================== RCS file: /cvs/src/usr.sbin/ypldap/yp.c,v diff -u -p -u -r1.22 yp.c --- usr.sbin/ypldap/yp.c 18 Jul 2023 13:06:33 -0000 1.22 +++ usr.sbin/ypldap/yp.c 23 Sep 2026 00:45:16 -0000 @@ -468,7 +468,7 @@ ypproc_match_2_svc(ypreq_key *arg, struc return (&res); } else if (strcmp(arg->map, "passwd.byuid") == 0 || strcmp(arg->map, "master.passwd.byuid") == 0) { - ukey.ue_uid = strtonum(key, 0, UID_MAX, &estr); + ukey.ue_uid = strtonum(key, 0, UID_MAX - 1, &estr); if (estr) { res.stat = YP_BADARGS; return (&res); @@ -483,7 +483,7 @@ ypproc_match_2_svc(ypreq_key *arg, struc yp_make_val(&res, ue->ue_line, 1); return (&res); } else if (strcmp(arg->map, "group.bygid") == 0) { - gkey.ge_gid = strtonum(key, 0, GID_MAX, &estr); + gkey.ge_gid = strtonum(key, 0, GID_MAX - 1, &estr); if (estr) { res.stat = YP_BADARGS; return (&res); @@ -531,7 +531,7 @@ ypproc_match_2_svc(ypreq_key *arg, struc return (&res); } - ukey.ue_uid = strtonum(cp, 0, UID_MAX, &estr); + ukey.ue_uid = strtonum(cp, 0, UID_MAX - 1, &estr); if (estr) { res.stat = YP_BADARGS; return (&res); Index: usr.sbin/ypldap/ypldap.c =================================================================== RCS file: /cvs/src/usr.sbin/ypldap/ypldap.c,v diff -u -p -u -r1.31 ypldap.c --- usr.sbin/ypldap/ypldap.c 21 Nov 2024 13:38:15 -0000 1.31 +++ usr.sbin/ypldap/ypldap.c 23 Sep 2026 00:45:16 -0000 @@ -199,7 +199,7 @@ main_create_user_groups(struct env *env) /* gid */ bp[strcspn(bp, ":")] = '\0'; - pw_gid = (gid_t)strtonum(bp, 0, GID_MAX, &errstr); + pw_gid = (gid_t)strtonum(bp, 0, GID_MAX - 1, &errstr); if (errstr) { log_warnx("main: failed to parse gid for uid: %d", ue->ue_uid);