* [PATCH] core205: Ship curl
@ 2026-09-13 17:12 Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship iana-etc Adolf Belka
` (29 more replies)
0 siblings, 30 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/core/205/filelists/curl | 1 +
1 file changed, 1 insertion(+)
create mode 120000 config/rootfiles/core/205/filelists/curl
diff --git a/config/rootfiles/core/205/filelists/curl b/config/rootfiles/core/205/filelists/curl
new file mode 120000
index 000000000..4b84bef53
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/curl
@@ -0,0 +1 @@
+../../../common/curl
\ No newline at end of file
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] core205: Ship iana-etc
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship jansson Adolf Belka
` (28 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/core/205/filelists/iana-etc | 1 +
1 file changed, 1 insertion(+)
create mode 120000 config/rootfiles/core/205/filelists/iana-etc
diff --git a/config/rootfiles/core/205/filelists/iana-etc b/config/rootfiles/core/205/filelists/iana-etc
new file mode 120000
index 000000000..1f3d54dbd
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/iana-etc
@@ -0,0 +1 @@
+../../../common/iana-etc
\ No newline at end of file
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] core205: Ship jansson
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship iana-etc Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship libksba Adolf Belka
` (27 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/core/205/filelists/jansson | 1 +
1 file changed, 1 insertion(+)
create mode 120000 config/rootfiles/core/205/filelists/jansson
diff --git a/config/rootfiles/core/205/filelists/jansson b/config/rootfiles/core/205/filelists/jansson
new file mode 120000
index 000000000..21f73bd0c
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/jansson
@@ -0,0 +1 @@
+../../../common/jansson
\ No newline at end of file
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] core205: Ship libksba
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship iana-etc Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship jansson Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship libpcap Adolf Belka
` (26 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/core/205/filelists/libksba | 1 +
1 file changed, 1 insertion(+)
create mode 120000 config/rootfiles/core/205/filelists/libksba
diff --git a/config/rootfiles/core/205/filelists/libksba b/config/rootfiles/core/205/filelists/libksba
new file mode 120000
index 000000000..8d01f8224
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/libksba
@@ -0,0 +1 @@
+../../../common/libksba
\ No newline at end of file
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] core205: Ship libpcap
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (2 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] core205: Ship libksba Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship liburcu Adolf Belka
` (25 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/core/205/filelists/libpcap | 1 +
1 file changed, 1 insertion(+)
create mode 120000 config/rootfiles/core/205/filelists/libpcap
diff --git a/config/rootfiles/core/205/filelists/libpcap b/config/rootfiles/core/205/filelists/libpcap
new file mode 120000
index 000000000..c7f9f52a8
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/libpcap
@@ -0,0 +1 @@
+../../../common/libpcap
\ No newline at end of file
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] core205: Ship liburcu
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (3 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] core205: Ship libpcap Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship libxml2 Adolf Belka
` (24 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/core/205/filelists/liburcu | 1 +
1 file changed, 1 insertion(+)
create mode 120000 config/rootfiles/core/205/filelists/liburcu
diff --git a/config/rootfiles/core/205/filelists/liburcu b/config/rootfiles/core/205/filelists/liburcu
new file mode 120000
index 000000000..d19012e04
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/liburcu
@@ -0,0 +1 @@
+../../../common/liburcu
\ No newline at end of file
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] core205: Ship libxml2
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (4 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] core205: Ship liburcu Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship pcre2 Adolf Belka
` (23 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/core/205/filelists/libxml2 | 1 +
1 file changed, 1 insertion(+)
create mode 120000 config/rootfiles/core/205/filelists/libxml2
diff --git a/config/rootfiles/core/205/filelists/libxml2 b/config/rootfiles/core/205/filelists/libxml2
new file mode 120000
index 000000000..242e69fa3
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/libxml2
@@ -0,0 +1 @@
+../../../common/libxml2
\ No newline at end of file
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] core205: Ship pcre2
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (5 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] core205: Ship libxml2 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship tzdata Adolf Belka
` (22 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/core/205/filelists/pcre2 | 1 +
1 file changed, 1 insertion(+)
create mode 120000 config/rootfiles/core/205/filelists/pcre2
diff --git a/config/rootfiles/core/205/filelists/pcre2 b/config/rootfiles/core/205/filelists/pcre2
new file mode 120000
index 000000000..4482caeae
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/pcre2
@@ -0,0 +1 @@
+../../../common/pcre2
\ No newline at end of file
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] core205: Ship tzdata
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (6 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] core205: Ship pcre2 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship util-linux Adolf Belka
` (21 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/core/205/filelists/tzdata | 1 +
1 file changed, 1 insertion(+)
create mode 120000 config/rootfiles/core/205/filelists/tzdata
diff --git a/config/rootfiles/core/205/filelists/tzdata b/config/rootfiles/core/205/filelists/tzdata
new file mode 120000
index 000000000..5a6e3252f
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/tzdata
@@ -0,0 +1 @@
+../../../common/tzdata
\ No newline at end of file
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] core205: Ship util-linux
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (7 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] core205: Ship tzdata Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship vim Adolf Belka
` (20 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/core/205/filelists/aarch64/util-linux | 1 +
config/rootfiles/core/205/filelists/riscv64/util-linux | 1 +
config/rootfiles/core/205/filelists/x86_64/util-linux | 1 +
3 files changed, 3 insertions(+)
create mode 120000 config/rootfiles/core/205/filelists/aarch64/util-linux
create mode 120000 config/rootfiles/core/205/filelists/riscv64/util-linux
create mode 120000 config/rootfiles/core/205/filelists/x86_64/util-linux
diff --git a/config/rootfiles/core/205/filelists/aarch64/util-linux b/config/rootfiles/core/205/filelists/aarch64/util-linux
new file mode 120000
index 000000000..9c253c689
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/aarch64/util-linux
@@ -0,0 +1 @@
+../../../../common/aarch64/util-linux
\ No newline at end of file
diff --git a/config/rootfiles/core/205/filelists/riscv64/util-linux b/config/rootfiles/core/205/filelists/riscv64/util-linux
new file mode 120000
index 000000000..f8e680205
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/riscv64/util-linux
@@ -0,0 +1 @@
+../../../../common/riscv64/util-linux
\ No newline at end of file
diff --git a/config/rootfiles/core/205/filelists/x86_64/util-linux b/config/rootfiles/core/205/filelists/x86_64/util-linux
new file mode 120000
index 000000000..7b5558d2c
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/x86_64/util-linux
@@ -0,0 +1 @@
+../../../../common/x86_64/util-linux
\ No newline at end of file
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] core205: Ship vim
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (8 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] core205: Ship util-linux Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship xz Adolf Belka
` (19 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/core/205/filelists/vim | 1 +
1 file changed, 1 insertion(+)
create mode 120000 config/rootfiles/core/205/filelists/vim
diff --git a/config/rootfiles/core/205/filelists/vim b/config/rootfiles/core/205/filelists/vim
new file mode 120000
index 000000000..98613172e
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/vim
@@ -0,0 +1 @@
+../../../common/vim
\ No newline at end of file
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] core205: Ship xz
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (9 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] core205: Ship vim Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] curl: Update to version 8.22.0 Adolf Belka
` (18 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/core/205/filelists/xz | 1 +
1 file changed, 1 insertion(+)
create mode 120000 config/rootfiles/core/205/filelists/xz
diff --git a/config/rootfiles/core/205/filelists/xz b/config/rootfiles/core/205/filelists/xz
new file mode 120000
index 000000000..734e926c7
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/xz
@@ -0,0 +1 @@
+../../../common/xz
\ No newline at end of file
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] curl: Update to version 8.22.0
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (10 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] core205: Ship xz Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] fetchmail: Update to version 6.6.7 Adolf Belka
` (17 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 8.21.0 to 8.22.0
- Update of rootfile
- Changelog
8.22.0
Changes:
gssapi: add support for Apple GSS Framework
hardening: add API guards
RFC 9421 HTTP Message Signatures support
spnego: block NTLM fallback in SPNEGO negotiation
TLS: drop support for TLS-SRP
vquic: add option to use Apple fast UDP
Bugfixes:
altsvc: continue after unknown parameters
asyn-thrdd: retry link-local ipv6 if missing scope id
autotools: minor fixes and improvements
build: always use local `inet_pton()`/`inet_ntop()` implementations
build: assume POSIX `select()` is available
build: clear `Require.private` for static-only builds in `libcurl.pc`
build: drop `dirent.h` and `opendir()` detections on Windows
build: drop detecting `gettimeofday()` on Windows
build: drop superfluous `STDC_HEADERS` macro
build: enable thread-safe `getaddrinfo()` for OpenBSD
build: minor debug option message fixes/improvements
build: require `!NDEBUG` for debug-enabled (aka development) builds
build: strip duplicate spaces after `Libs.private:` in `libcurl.pc`
build: strip trailing spaces from `libcurl.pc`
cd2nroff: fix backslashes for 4-space indent lines
cd2nroff: stricter checks for asterisks for italics
cf-ngtcp2-cmn: de-duplicate `ngtcp2_conn_client_new()` call code
cf-ngtcp2-cmn: initialize new callback ptr for ngtcp2 1.24.0+
cf-socket: avoid broken NetBSD SOCK_NONBLOCK
cf-socket: disable TCP SYN retransmissions for localhost on Windows
cfilters: fix event-based connection shutdown
clock: save one call
cmake/FindLibgsasl: fix to set `LIBGSASL_VERSION` with pkg-config detection
cmake: check libgsasl version at configure time
cmake: dedupe expressions into local vars in `cmake_uninstall.in.cmake`
cmake: fix not to build `tunits` when `BUILD_CURL_EXE=OFF`
cmake: flatten build tree, tidy up base dir variables
cmake: minor improvements to `cmake_uninstall.in.cmake`
cmake: optimize OpenSSL fork detection
cmake: replace `remove` command with `rm` and pass arg safely
cmake: robustify base path in local file reference
cmake: stop probing unused `float.h` for `STDC_HEADERS`
cmake: use built-in variable and target property dump functions with CMake 4.5+
config-riscos.h: delete handcrafted RISC OS config header, in favor of autotools
config-win32.h: drop UWP, c-ares, simplify more
config-win32.h: limit use to MSVC IDE Project builds
configure: clarify --enable-debug option
configure: fix misleading error messages
configure: link `-lcrypt32` instead of `-lm` for wolfSSL on Windows
configure: only check in the watt library if WATT_ROOT is set
configure: remove double check for GnuTLS
configure: set ldap lib to no by default for non-finds
conncache: apply multi limits to transfers using a shared pool
conncache: conn upkeep/alive: move and enhance
conncache: connection alive checks intervals
conncache: don't assume curl_off_t increment wrap-around
conncache: guess maxconnects different
connect: connection close tweaks
connect: only set connect timer on first socket
connection reuse: age check
connection reuse: check SSL configs when doing a scheme upgrade
connections: use admin handles only for maintenance
content_encoding: exact-match the identity transfer-coding token
content_encoding: give a clear error on multi-member gzip
cookie: cookies set for an exact PSL domain is host-only
cookie: improve TAB handling
cookie: refuse to load cookies set against a PSL domain
CREDENTIALS.md: remove comment about empty user/pass
ctype: exclude control bytes from ISPRINT and ISGRAPH
curl: help category cleanups
curl_gssapi: document/update feature availability
curl_threads: always use native threads/mutex on Windows
curl_trc: remove unused expire timers
curl_url_set.md: expand the CURLU_NO_AUTHORITY description
curl_ws_meta.md: polish and better vocabulary
CURLOPT_HEADERFUNCTION.md: document folded header unfolding
CURLOPT_SOCKOPTFUNCTION.md: ALREADY_CONNECTED does not work for HTTP/3
CURLOPT_SSH_*_KEYFILE: used for setting up, then no more
CURLOPT_UNRESTRICTED_AUTH.md: 'Authorization', not 'Authentication'
CURLOPT_USERNAME.md: ambient username caveats
CURLSHOPT_(UN)SHARE.md: do not modify shares while in use
curlx_inet_ntop: return `CURLcode`, drop setting `errno`
curlx_inet_pton: drop setting `errno` on error
DEPRECATE.md: HTTP/2 Server Push gets removed in March 2027
dict: avoid busy-loop in sendf() when the socket is not writable
dist: fix to drop test bundle .c files from the source tarball
dnsd: fix bounds check in `read_https_alpn_part()`
docs/INTERNALS.md -> docs/DEPENDENCIES.md
docs: clarify that cookies need domain set to match
docs: connection reuse behavior for socket callbacks
docs: make 5 example snippets compile cleanly with clang
docs: mention possible auth option conflicts
docs: remove doubled word in SECURITY-ADVISORY.md
DoH: improvements
easy: fix unused global on non-Windows
easy_lock: silence `portability-no-assembler` with clang-tidy 23.1.0+
FAQ: correct an option typo
file: support directory listing on Windows
filter: change time reporting
FTP: fix TLS session reuse on the data connection
ftp: reject control bytes in ACCT and alternative-to-user
gitignore: maintenance updates
gopher: fix partial sends of CRLF
gopher: reject CR and LF in the selector
h2 push: use squeaky clean easy handle
h2: bootstrap max streams from multi handle if in use
h3-proxy: fix NULL deref when non-:status header arrives before :status
Happy Eyeballing v3: resolution delay of 25ms
header api: add guards
headers: name the arguments the way the definitions name them
HISTORY.md: PSL support in 2015
HISTORY: add when c-ares support was introduced (2004)
HISTORY: September 1999: started using CVS
hostip: only cache negative resolves for authoritative answers
hsts: only match the exact strings
http digest: tie peer/credentials on input
http2: make server push transfers inherit share from parent
http2: remove assert in ingress processing
http: avoid length underflow in Curl_compareheader
http: custom Authorization: header overrides Negotiate
http: fix non-tunneling proxy hostname use
http: stop dropping large custom headers
http: trim custom header name before the Authorization drop
httpsrr: DoH with HTTPS, fix response handling
idn: restore `MultiByteToWideChar()` `MB_ERR_INVALID_CHARS` flag
imap: APPEND CRLF fix
include: include <sys/select.h> when building for modern Linux.
INSTALL.md: add building-from-source overview section
INTERNALS.md: require quiche 0.20.0+
ipv6 scope_id: set from first peer
keylog: add a random size argument to Curl_tls_keylog_write()
ldap: base64-encode LDIF values beginning with colon or less-than
ldap: reject control characters in URL-decoded filter values
ldap: support empty username and password
ldap: support insecure mode for Windows native LDAP
lib1587: fix gcc `-Wconversion` with LibreSSL on Windows, test in CI
lib2405: adjust for non-threaded builds
lib: add "Curl_" prefix to two global functions
lib: add multi_wakeup_internal
lib: drop unused `system_win32.h` includes
lib: fix 'ns' -> 'us' in trace messages
lib: new easy option string storage
lib: optimize struct layouts for reduced memory usage
lib: ratelimit timestamps
lib: silence gcc-16 compiler warnings `-Wmaybe-uninitialized`
lib: update mentions of the legacy "sessionhandle"
libcurl.md: emphasize that the output needs checking
libcurl.pc: add `License` tag
libcurl.pc: add Copyright tag to the pkgconf file
libcurl.pc: add the Link.ABI and Source tags
macos sectrust: fail ocsp verify when not builtin
Makefile.am: improve etags
mbedtls: enforce verifyhost when verifypeer is disabled
mbedtls: replace `memset()` with `psa_hash_operation_init()`
md5: replace magic numbers with `MD5_DIGEST_LEN`
mime.c: avoid integer overflow in base64 size calculation
mime: reject CR and LF in mail part name and filename
mod_curltest: fix compiler warnings
mprintf: acknowledge %F
mprintf: avoid never-ending loop for positive-infinite
mprintf: fix long double output
mqtt: reject control bytes in the topic
multi: cap expire times to INT_MAX internally
multi: forbid curl_easy_pause from within multi socket callback
multi: hold timeout values in 'int' instead of 'long'
multi: remove #if 0'ed code that uses old struct
multi: shrink expire timer indices
multi: timeout improvements
multi: use index list for expire timeouts
multi: xfer table initial size and growth
multihandle: move two struct fields
ngtcp2+openssL: fix early data
ngtcp2: avoid NULL deref in cf_ngtcp2_send
ngtcp2: clean up after ngtcp2 in `curl_global_cleanup`
ngtcp2: let verify failures win over expiry processing errors
openldap: handle Curl_sasl_continue() returns better
openssl+sectrust: fix session reuse
openssl+sectrust: move session verified set into result check
openssl: avoid conn reuse if provider is used
openssl: avoid strlen() on the data from OpenSSL
openssl: aws-lc ocsp workaround
openssl: drop unused pre-OpenSSL3 `ctx_option_t` typedef
openssl: fix DER buffer leak in Apple SecTrust verification
openssl: no server cert is only okay if also not pinned
openssl: prefer modern API flavors for `EVP_MD_CTX` new/free
openssl: replace stray legacy API variant with `EVP_DigestInit_ex()`
os400: port latest header files changes to ILE/RPG interface
os400: rewrite upper ebcdic wrappers using dynbuf
progress: cleanup, less memory
protocol: simpler Curl_getn_scheme runs faster
proxy: CONNECT trailers handling
psl: update a comment to understandable English
pytest: update two H3 tests for nghttp3 1.18.0+
quic: upload improvements
quiche: set the max field section size
rtsp: refactor method handling and improve error checks
runtests: allow comments in `setenv` section, merge sections in test433
runtests: fix `mode="warn"` tests passing unconditionally, fix test 1752
runtests: flush cached test parts when (re)loading a file
runtests: restore `-k` option and actively process as no-op
sasl: fix zero-length response encoding
schannel: add ALPN support for mingw-w64 <9 and <VS2015
schannel: clear PFX password before free
schannel: fix ALPN erroneously disabled
schannel: fix error check logic in `get_client_cert()` file reader
schannel: refresh stream sizes after renegotiation
schannel: reuse the send buffer
schannel: shut off experimental TLS 1.3 support for Win 10
scorecard: fix `max_upload` init value in `ul_parallel()`
scripts/badwords.txt: do not recommend using 'will' in rewrites
scripts: replace/extend `--` with `--end-of-options` in git commands
scripts: use end-of-options marker in `cd`, `mkdir`, `mv`, `sha256sum` commands
servers: fix HANDLE leak in UWP builds
servers: fix to reverse `SA_RESTART` option for `sigaction()` on modern codepath
setopt: allow setting a referer from CURLINFO_REFERER
setopt: error for CURLOPT_SHARE when easy handle is used
setopt: make NULL `CURLOPT_AWS_SIGV4` disable aws-sigv4 auth
setopt: return OK earlier for the deprecated h2 dep options
share unlink: forget connection
smtp: reject CR and LF in the envelope address
spacecheck: cap number of lines per file
spnego_sspi: drop redundant UNICODE branch
spnego_sspi: pass channel bindings on initial context
src: safely clear certain buffers
sshserver.pl: bump an sshd config to use its modern name
ssls: fix potential memory leak on import
sspi: add local helper macro to avoid UNICODE branching
sspi: enable channel-binding in mingw-w64 <9 builds
strcase: inline the raw case conversions
sws: allow connection-monitor to log all disconnects
sws: log the exact closing reason better, to help debugging tests
terminal: Enhance terminal size detection for multiple outputs
test 1560: test RFC4291 style IPv6 IPv4-mapped addresses
test1560: allow to build and run without LDAP support
test798: force IPv4 to avoid cross-runner port aliasing
test: adjust test_06_13 for 0100::/64 being blackholed
tests: address mutable class vars and naive datetime in Python code
tests: change whitespace and comments in Python test code
tests: convert unit test 1396 and 1398 into libtests
tests: enable and fix some new Python ruff warnings
tests: fix Content-Length mismatch in test 2064
tests: fix the FTP check for unexpected RST
tests: fix type promotion on 32-bit arches in http test code
tests: fix typo in assert message in http test
tests: improve exception handling in Python test code
tests: remove test1701
tests: simplify by removing unneeded Python code
tests: skip test 311 for wolfSSL 5.9.2
tests: target Python 3.8 as the minimum Python version
tests: use simpler constructions in Python code
thrdpool: retry failed thread starts while items wait
thrdqueue: drop name strdups from Curl_thrdq_create
tidy-up: `TEXT()` vs `_TEXT()` vs `_T()` use (Windows)
tidy-up: comments, messages, formatting
tidy-up: drop redundant includes
tidy-up: fix Perl syntax and formatting nits
tidy-up: fix typos in docs and comments
tidy-up: formatting, messages and comments
tidy-up: minor code fixes and improvements
tidy-up: typos, comment nits
timeval: make `Curl_freq` variable static (Windows)
tool: checkfds, open on null device
tool: do not flush on out-null
tool: fix memory use in parallel mode
tool: init progress bar on demand
tool: remove duplicate setopts
tool_cb_hdr: de-duplicate filename setter
tool_cb_hdr: do not truncate etags output to stdout
tool_cb_prg: avoid integer overflows
tool_doswin: add stdin relay auth
tool_doswin: don't use `TerminateThread` in stdin relay
tool_doswin: fix stdin data truncation
tool_msgs: make notef() respect --silent
tool_operate: limit `is_using_schannel()` call to Windows
tool_operate: only check for schannel if on windows
tool_operate: remove call to abort()
tool_paramhlp: --proto only supports one modifier
tool_xattr: add support for Windows alternate data stream
transfer: DID handling
typecheck-gcc: allow passing `char[]` as callback data
uint-spbset: reused empty chunks
unit3214: fix to pass on systems with >=128-bit pointers
url: fix handling of empty user in NTLM matching
url: fix negotiate/ntlm connection reuse
url: reject control codes in credentials set via CURLOPT
urlapi: allow URLs to not have userauth (hostname)
urlapi: avoid dedotdotify() if possible
urlapi: clear password buffer on error path
urlapi: do not keep an internal port string
urlapi: improved return codes
urlapi: preserve empty markers in relative URLs
urldata: cleanups
urldata: drop four strings from the aptr struct
urldata: sort the connectdata struct fields by size
VERSIONS.md: document Rock-solid curl releases
vms: fix symbol typo and missing closing quotes in `config_h.com`
vquic: add Curl_ prefix to some global functions
vquic: initialize new callback slot for nghttp3 v1.18.0+
vquic: silence `-Wmissing-field-initializers` for nghttp3/ngtcp2 callback tables
vquic: use ngtcp2 v1.25.0 new close2 callback
vssh: keyfile use cleanups
vssh: silence gcc-11 `-Wnull-dereference`, dedupe `CURL_EASY_STR()` calls
vtls: move 'native_ca_store' ssl_config_data => ssl_primary_config
vtls_scache: use case sensitive path match
VULN-DISCLOSURE-POLICY.md: issues that should be found by tests are LOW
wcurl: import v2026.08.30
websocket: pause writing and meta data fix
winsock: drop redundant version checks at initialization
wolfssl: do not run Curl_wssl_setup_x509_store() twice
wolfssl: fix build for wolfssl without bio chain support
ws: fix write callback error handling
ws: pause/unpause write handling
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/common/curl | 4 ++++
lfs/curl | 4 ++--
2 files changed, 6 insertions(+), 2 deletions(-)
diff --git a/config/rootfiles/common/curl b/config/rootfiles/common/curl
index 96daee9e6..27b79e8c5 100644
--- a/config/rootfiles/common/curl
+++ b/config/rootfiles/common/curl
@@ -223,6 +223,10 @@ usr/lib/libcurl.so.4.8.0
#usr/share/man/man3/CURLOPT_HTTPHEADER.3
#usr/share/man/man3/CURLOPT_HTTPPOST.3
#usr/share/man/man3/CURLOPT_HTTPPROXYTUNNEL.3
+#usr/share/man/man3/CURLOPT_HTTPSIG_ALGORITHM.3
+#usr/share/man/man3/CURLOPT_HTTPSIG_HEADERS.3
+#usr/share/man/man3/CURLOPT_HTTPSIG_KEY.3
+#usr/share/man/man3/CURLOPT_HTTPSIG_KEYID.3
#usr/share/man/man3/CURLOPT_HTTP_CONTENT_DECODING.3
#usr/share/man/man3/CURLOPT_HTTP_TRANSFER_DECODING.3
#usr/share/man/man3/CURLOPT_HTTP_VERSION.3
diff --git a/lfs/curl b/lfs/curl
index b41766a07..2dd3e804d 100644
--- a/lfs/curl
+++ b/lfs/curl
@@ -24,7 +24,7 @@
include Config
-VER = 8.21.0
+VER = 8.22.0
THISAPP = curl-$(VER)
DL_FILE = $(THISAPP).tar.xz
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 230989e586a592b2aee768a1a6d48f1c8247e4d26afd0787a94f45faa9fbebcda5c9a8e2b739fb5a2ada151c13b09a8e2319825e9314fcc894377f24e92d338f
+$(DL_FILE)_BLAKE2 = 1efe036ae4ba6bc1e2bcf7bae2229e2c3be8e9d72a0f32f6c1f192d277f625f77786cf538593ad59a7873b477ff3566412d3404d6ccd202c0f7055b6d3a45d25
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] fetchmail: Update to version 6.6.7
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (11 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] curl: Update to version 8.22.0 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] frr: Update to version 10.7.1 Adolf Belka
` (16 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 6.6.6 to 6.6.7
- No change in rootfile
- Changelog
6.6.7
Fetchmail 6.6.7 is the eighth fetchmail 6.6 release, it fixes a NTLM stack buffer
overflow bug that can lead to remote code execution if NTLM is enabled at configure
time. There has been some confusion as to the exploitability, but because the C
standard does not guarantee a particular layout of stack variables, the security
announcement fetchmail-SA-2006-01.txt is being re-issued. The NEWS file in the 6.6.7
release (contents used for changelog below) claims the release were non-vulnerable,
which is no longer believed to be correct, and NTLM-enabled fetchmail 6.6.6 and
older must be considered vulnerable. This version fixes various other NTLM
authenticator protocol bugs, makes IMAP protocol exchange a bit stricter to avoid
desynch, and fixes build issues of the test suite on Cygwin's updated GCC 14.
BUGFIXES:
* Safeguard internal NTLM buffer handling to avoid overrun if server
sends extremely long fields in the challenge, to avoid stack corruption.
Reported by "Tristan".
The code will report the buffer sizing issue and abort the NTLM authentication
flow properly so that it's clear that message sizes are the issue.
Fetchmail 6.6.7 currently supports 1 kByte of NTLM payload for each of the
three messages, plus header.
Earlier reports of this bug overestimated the impact. While the bug
indeed can write beyond the end of a stack-based buffer, it is reaching
into another stack-based buffer that is at least 2048 bytes large, whereas
the overflow is a few dozen bytes at most. The worst impact is that the
NegotiateFlags value in the final Authenticate Message step of the NTLM
authentication protocol gets messed up and the authentication fails.
It COULD previously happen, depending on hardening, stack protection and
other compiler flags that these _protections_ terminated fetchmail because
one write to a data structure crosses into an other variable that is
adjacent, on normal stack layouts that "victim" would be the challenge
message, which was already read except for its "flags" value. The
termination can happen, for instance, with the Address Sanitizer feature,
or other features that separate variables into pages of their own or
put "canary"/sentinel values between them in the memory layout.
NOTE: NTLM is based on obsolete cryptographic mechanisms
and should not be used without TLS or SSL security for the transport.
NOTE: fetchmail 7 will remove support for NTLM and MSN authentication.
Microsoft (which owns the specification) generally advises that applications
should not use NTLM, and is replacing with with Kerberos, see
[MS-NLMP]: NT LAN Manager (NTLM) Authentication Protocol,
https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-nlmp/
See Introduction and Security Considerations for Implements
(In Version 37.0 of the spec, sections 1 and 5.1 on page 84)
Since this _was_ initially reported as a stack smashing vulnerability,
a security announcement fetchmail-SA-2026-01 has been issued to reduce
the severity of the impact in public reporting.
* The IMAP protocol exchange was made stricter,
(1) it will validate tagged responses that we received the right
response to make sure fetchmail and the IMAP server are still in synch,
(2) it will no longer accept the response words OK, NO, BAD, BYE if
there is trailing garbage, and will now reject "OKAY" or "NONE", which
would previously be accepted as aliases for OK or NO.
* For NTLM: Made protocol exchange more robust and make it track errors
and SASL cancellation better to avoid hangs if NTLM does not work but other
authentication schemes do or NTLM gets rejected by the server.
* Handling of escape sequences in the rcfile has been bugfixed to handle
all ISO C escape sequences and handle octal escapes more strictly.
* The AC_LIBOBJ extensions have been moved to a lib/ subdirectory
in an attempt to fix build issues on Cygwin, see #96 reported by Achim.
TRANSLATION UPDATES were contributed by these fine people - thank you!
* eo: Keith Bowes [Esperanto]
* ja: Takeshi Hamasaki [Japanese]
* ro: Remus-Gabriel Chelu [Romanian]
* cs: Petr Pisar [Czech]
* es: Cristian Othón Martínez Vera [Spanish]
* sv: Göran Uddeborg [Swedish]
* fr: Frédéric Marchal [French]
* pl: Jakub Bogusz [Polish]
* it: Luca Vercelli [Italian]
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
lfs/fetchmail | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/lfs/fetchmail b/lfs/fetchmail
index 4b5fc42d7..6d9c4c2d5 100644
--- a/lfs/fetchmail
+++ b/lfs/fetchmail
@@ -26,7 +26,7 @@ include Config
SUMMARY = Full-Featured POP and IMAP Mail Retrieval Daemon
-VER = 6.6.6
+VER = 6.6.7
THISAPP = fetchmail-$(VER)
DL_FILE = $(THISAPP).tar.xz
@@ -34,7 +34,7 @@ DL_FROM = $(URL_IPFIRE)
DIR_APP = $(DIR_SRC)/$(THISAPP)
TARGET = $(DIR_INFO)/$(THISAPP)
PROG = fetchmail
-PAK_VER = 26
+PAK_VER = 27
DEPS =
@@ -48,7 +48,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 0f7a26a2f34d902d30801d5016e67697877f7c3f41dc9d9c4a1b44420c9e08f6acd94853c298b2938b9ddf08b3aa3115a14917f42d680f3ada8daba0e5f50953
+$(DL_FILE)_BLAKE2 = 5c0a974b67e4c3392ab4de2b14eb5e34a0bff8eac48d2a5f412bfb500333df601e563d41dc26b897534a705c253222d13eb16e23dbefd0f82e945ae94cbf66ba
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] frr: Update to version 10.7.1
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (12 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] fetchmail: Update to version 6.6.7 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] hwdata: Update to version 0.411 Adolf Belka
` (15 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 10.7.0 to 10.7.1
- No change in rootfile
- Changelog
10.7.1
What's Changed
bgpd: Discard malformed BGP-LS attribute instead of withdrawing (backport #22674) by @mergify[bot] in #22675
Pim crash and use after free (backport #22684) by @mergify[bot] in #22688
bgpd: Reject malformed NHC attribute with a trailing partial TLV (backport #22673) by @mergify[bot] in #22698
pimd: fix null-check and stream read issues (backport #22680) by @mergify[bot] in #22702
pimd: sanitize IGMPv3 and mtrace packet-derived lengths (backport #22679) by @mergify[bot] in #22700
lib: fix wrong nexthop comparision for SRv6 (backport #22710) by @mergify[bot] in #22713
ospf6d: avoid route use after unlock in best route iterator (backport #22549) by @mergify[bot] in #22711
Improve pim autorp test stability in CI (backport #22730) by @mergify[bot] in #22736
bgpd: Preserve disable_ieee_floating on link-bandwidth extended communities (backport #22682) by @mergify[bot] in #22738
lib: fix wrong nexthop comparision for SRv6 by @ton31337 in #22759
lib: Fix ZAPI SRv6 nexthop comparison (backport #22772) by @mergify[bot] in #22786
bgpd: Ignore duplicate Prefix-SID SRv6 L3 Service TLVs (backport #22602) by @mergify[bot] in #22769
bgpd: Fix crash for no neighbor X path-attribute discard ... (backport #22785) by @mergify[bot] in #22793
lib: Clear seg6local context when deleting seg6local state (backport #22790) by @mergify[bot] in #22799
bgpd: Fix link-bandwidth extended community handling above ~34 Gbps (backport #22681) by @mergify[bot] in #22845
A couple minor bgpd fixes (backport #22512) by @mergify[bot] in #22853
bgpd: fix BAD_COPY_PASTE in bgp_path_info_cmp() (backport #22838) by @mergify[bot] in #22859
bgpd: fix link-bandwidth AS truncation in route-map for extended encoding (backport #22867) by @mergify[bot] in #22868
zebra: Fix SRv6 source-address config output (backport #22879) by @mergify[bot] in #22902
zebra: Fix SRv6 locator delete after no prefix (backport #22882) by @mergify[bot] in #22899
bgpd: fix RD route_node refcount leak in bgp_safi_node_lookup() (backport #22938) by @mergify[bot] in #22940
zebra: backport stale ifp cleanup PRs to 10.7 by @mjstapp in #22969
bgpd: Fix route-map use count for EVPN no advertise (backport #22945) by @mergify[bot] in #22954
isisd: Fix Router Capability subTLV parsing (backport #22873) by @mergify[bot] in #22976
bgpd: Withdraw routes with malformed SRv6 Service TLVs (backport #22980) by @mergify[bot] in #22997
isisd: backport #22234 (per-AF adjacency usability / SPF nexthop gating) to stable/10.7 by @gdmiller-za in #22999
*: fix some mem leaks in error paths (backport #23031) by @mergify[bot] in #23033
lib: bound the locator name skip in zapi_srv6_sid_notify_decode (backport #23035) by @mergify[bot] in #23045
bgpd: fix self nexthop overwrite in unnumbered interfaces setup (backport #23054) by @mergify[bot] in #23080
zebra: add TUNNEL_CSUM to netlink EVPN DVNI encode (backport #23058) by @mjstapp in #23084
watchfrr: don't admit to systemd that we restart (backport #23088) by @mergify[bot] in #23091
bgpd: allow GR-helper stale paths through the evaluate_paths peer-down skip (backport #23067) by @mergify[bot] in #23111
zebra: notify the client when an SRv6 SID allocation fails (backport #23051) by @mergify[bot] in #23128
bgpd: Do not print advertise-pip if it has a default value (backport #23110) by @ton31337 in #23127
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
lfs/frr | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/lfs/frr b/lfs/frr
index 0188d5e8f..0c89d19cc 100644
--- a/lfs/frr
+++ b/lfs/frr
@@ -26,7 +26,7 @@ include Config
SUMMARY = FRRouting Routing daemon
-VER = 10.7.0
+VER = 10.7.1
THISAPP = frr-frr-$(VER)
DL_FILE = $(THISAPP).tar.gz
@@ -34,7 +34,7 @@ DL_FROM = $(URL_IPFIRE)
DIR_APP = $(DIR_SRC)/$(THISAPP)
TARGET = $(DIR_INFO)/$(THISAPP)
PROG = frr
-PAK_VER = 18
+PAK_VER = 19
DEPS =
@@ -50,7 +50,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 4adc266bb68788d084986ec5ada3aff2f8cee29203556340932930f8232b217ca649d126b982e03f8c7f82144ef6efed29eea2055d32d08cde242c52c6acca89
+$(DL_FILE)_BLAKE2 = 7f7e703a5d2a2615c5061e57aed6dbd36baa796592cc03d2c1c8bb306e183957eeb331c586953bfd87e16f39947988a74c00f76b79a8284d07967f05ec1362e5
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] hwdata: Update to version 0.411
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (13 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] frr: Update to version 10.7.1 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] iana-etc: Update to version 20260911 Adolf Belka
` (14 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 0.410 to 0.411
- No change in rootfile
- Changelog
0.411
Update usb and vendor ids
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
lfs/hwdata | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/lfs/hwdata b/lfs/hwdata
index 3e050e2c3..f2185ecda 100644
--- a/lfs/hwdata
+++ b/lfs/hwdata
@@ -24,7 +24,7 @@
include Config
-VER = 0.410
+VER = 0.411
THISAPP = hwdata-$(VER)
DL_FILE = $(THISAPP).tar.gz
@@ -42,7 +42,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 5e02947999341b2e249097f76cf318a2aaca64aeca7620f3e510021c204d489f68f64c8dcefd830f4be9ad96fc3b602b78c76443396bbf53770d5315e89a5c5c
+$(DL_FILE)_BLAKE2 = fd1b0deae85e017d2e7615ac68007f0b0394ae01cb5cb7258f5a005e969006f1e5d39e1946c42a6d7c4be9d85c029266893eae0e3df498d6c0673ffda70ec456
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] iana-etc: Update to version 20260911
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (14 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] hwdata: Update to version 0.411 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] jansson: Update to version 2.15.1 Adolf Belka
` (13 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 20260511 to 20260911
- No change in rootfile
- No changelog provided
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
lfs/iana-etc | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/lfs/iana-etc b/lfs/iana-etc
index ab28469f0..d5554835f 100644
--- a/lfs/iana-etc
+++ b/lfs/iana-etc
@@ -24,7 +24,7 @@
include Config
-VER = 20260511
+VER = 20260911
# https://github.com/Mic92/iana-etc
THISAPP = iana-etc-$(VER)
@@ -41,7 +41,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 7d0e759b01f60a604ca37f4c7e0b981d88b8091b17efee37e79e54f05fde9c349d5f3ec8a93256b9bddb55726a03a01b194f492003ed9a39f08d5ff8a1411280
+$(DL_FILE)_BLAKE2 = 8e06ea19c77bb7bcbb8c0e8b2faadd10c6415b85efbaff24271daa00edb6db842313957d7809956128caccdac55437eb9f5dc37847a1760fa61eae2a7638382b
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] jansson: Update to version 2.15.1
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (15 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] iana-etc: Update to version 20260911 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] libcap-ng: Update to version 0.9.6 Adolf Belka
` (12 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 2.15.0 to 2.15.1
- Update of rootfile
- Changelog
2.15.1
* Fixes:
- Include the object key or array index in unpack type mismatch error
messages (@cwalther in #731)
- Reject negative string length in the `json_pack` `s#` and `+#` formats
(@akheron in #740)
- Limit recursion depth in dump, equal and deep copy to prevent stack
overflow (@akheron in #741)
* Build:
- Only export symbols starting with `json_` and `jansson_` from the CMake
build (@shyjun in #705)
- Include `jansson_private_config.h` only if `HAVE_CONFIG_H` is enabled
(@jaeyoonjung in #704)
- Add a configurable pkg-config install path to the CMake build
(@akallabeth in #721)
- Only use `--default-symver` when the linker supports it (@kraj in #744)
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/common/jansson | 2 +-
lfs/jansson | 7 ++++---
2 files changed, 5 insertions(+), 4 deletions(-)
diff --git a/config/rootfiles/common/jansson b/config/rootfiles/common/jansson
index b8877564d..aa20dcf2c 100644
--- a/config/rootfiles/common/jansson
+++ b/config/rootfiles/common/jansson
@@ -4,5 +4,5 @@
#usr/lib/libjansson.la
#usr/lib/libjansson.so
usr/lib/libjansson.so.4
-usr/lib/libjansson.so.4.15.0
+usr/lib/libjansson.so.4.15.1
#usr/lib/pkgconfig/jansson.pc
diff --git a/lfs/jansson b/lfs/jansson
index 1d7a0fca2..3ddf3e1e5 100644
--- a/lfs/jansson
+++ b/lfs/jansson
@@ -24,7 +24,7 @@
include Config
-VER = 2.15.0
+VER = 2.15.1
THISAPP = jansson-$(VER)
DL_FILE = $(THISAPP).tar.bz2
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = d83046024949fd9dda9ae74f78595d11522cb9be12ab585c95d211dc750afa0d06458dad5f1e18307209fbdeebdf27ed5f3ae2ab9d10aa82e2dfacc1113e6341
+$(DL_FILE)_BLAKE2 = d5c2cae07425d01f51ce6f73d703c011683f934bde206c9137753bc61c32932fe1fe7c670df3215f65fab5b9db9c96b668aff3b6635fb383d6bd9acea1076bb4
install : $(TARGET)
@@ -73,7 +73,8 @@ $(subst %,%_BLAKE2,$(objects)) :
$(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
@$(PREBUILD)
@rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar axf $(DIR_DL)/$(DL_FILE)
- cd $(DIR_APP) && ./configure --prefix=/usr
+ cd $(DIR_APP) && ./configure \
+ --prefix=/usr
cd $(DIR_APP) && make $(MAKETUNING)
cd $(DIR_APP) && make install
@rm -rf $(DIR_APP)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] libcap-ng: Update to version 0.9.6
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (16 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] jansson: Update to version 2.15.1 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] libksba: Update to version 1.8.1 Adolf Belka
` (11 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 0.9.5 to 0.9.6
- No change in rootfile
- Changelog
0.9.6
- Fix supplementary group changes in capng_change_id
- Reduce cap-audit size and memory use; builds now require llvm-strip
- Preserve capability evidence during cap-audit shutdown
- In cap-audit, fix optional SETPCAP false positives w/o hiding required caps
- Fix ambient capabilities and capability list handling in cap-audit --service
- In cap-audit, reject unsupported systemd unit syntax
- Fix tree branch drawing for repeated socket owners in netcap --advanced
- Fix utility builds with musl libc
- Ensure capng_change_id is multi-thread safe
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
lfs/libcap-ng | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/lfs/libcap-ng b/lfs/libcap-ng
index f08ad5ab9..98630b5c8 100644
--- a/lfs/libcap-ng
+++ b/lfs/libcap-ng
@@ -24,7 +24,7 @@
include Config
-VER = 0.9.5
+VER = 0.9.6
THISAPP = libcap-ng-$(VER)
DL_FILE = $(THISAPP).tar.gz
@@ -40,7 +40,8 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = ddfe7b6975747963a2eb53485481c55f5638a06f119260e34619336445321d41b1531e4b78593aab9267a463e08641eb666f58ca6dc19fabf776995a4579e072
+$(DL_FILE)_BLAKE2 = 64599a9405895e4b2ec3275cbc58c137be025d6dd11ff51219254495d1370e3dc92a97017fa8651c59426ac81a16660d6194ce0a17b02c502cd85bf44adb7e90
+
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] libksba: Update to version 1.8.1
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (17 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] libcap-ng: Update to version 0.9.6 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] libpcap: Update to version 1.10.7 Adolf Belka
` (10 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 1.8.0 to 1.8.1
- Update of rootfile
- Changelog
1.8.1
* Fix CMS parser to avoid possible infinite loop. [T8361]
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/common/libksba | 2 +-
lfs/libksba | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/config/rootfiles/common/libksba b/config/rootfiles/common/libksba
index 792dd7744..86a444bb3 100644
--- a/config/rootfiles/common/libksba
+++ b/config/rootfiles/common/libksba
@@ -2,6 +2,6 @@
#usr/lib/libksba.la
#usr/lib/libksba.so
usr/lib/libksba.so.8
-usr/lib/libksba.so.8.16.0
+usr/lib/libksba.so.8.16.1
#usr/lib/pkgconfig/ksba.pc
#usr/share/aclocal/ksba.m4
diff --git a/lfs/libksba b/lfs/libksba
index 766f0f933..1c06e7c7d 100644
--- a/lfs/libksba
+++ b/lfs/libksba
@@ -24,7 +24,7 @@
include Config
-VER = 1.8.0
+VER = 1.8.1
THISAPP = libksba-$(VER)
DL_FILE = $(THISAPP).tar.bz2
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = ce1ceaf4b2542c2ac391fe944e81d0a05d73abf6abbc2637ef2c6c93d0a110a9fd352ae1586eb486148244ec68b0974348f440560991ca96196ab57549ab2cd3
+$(DL_FILE)_BLAKE2 = d100a709ed16f1ccd19e78d788dc6e929941647029aa539172c1bcdf1312b47183722d2c90b6d438906e977b79fa0219c8289373625eddc40eb77162222a535c
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] libpcap: Update to version 1.10.7
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (18 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] libksba: Update to version 1.8.1 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] liburcu: Update to version 0.15.7 Adolf Belka
` (9 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 1.10.6 to 1.10.7
- Update of rootfile
- 7 CVE fixes
- Changelog
1.10.7
General:
Free p->opt.device on close, not on cleanup (issue #1615). Issue
reported by Harrison Green.
Source code:
Deprecate bpf_filter().
Packet filtering:
Initialize the scratch memory store to 0.
In "net <n> mask <m>" catch ENOMEM for the "m" too.
CVE-2026-0799: Access M[] safely in the BPF interpreter.
CVE-2026-31912: Mind the program bounds in pcap_offline_filter().
CVE-2026-31911: Fail opcodes safely in the BPF interpreter.
CVE-2026-6244: Avoid division by zero via pcap_offline_filter().
CVE-2026-6554: Limit "ja L" looping in pcap_offline_filter().
Validate BPF opcodes stricter.
For "lsh" and "rsh" guard "#k" as well.
Windows:
Fix error return from memory allocation error.
rpcap:
CVE-2026-18313: Fix a memory leak in rpcapd.
CVE-2026-18238: Fix RPCAP_MSG_PACKET validation.
Documentation:
Remove list of OSes that support "ipv6-icmp"; all the ones we
support appear to do so.
Fix pcap_next_ex(3PCAP) man page to clarify the PCAP_ERROR_BREAK
return value.
Building and testing:
CMake: Disable remote capture support on Windows by default.
RDMA: Avoid valgrind errors when calling rdmasniff_findalldevs().
Autoconf: Add QNX support to AC_LBL_LIBRARY_NET().
capturetest: Treat SA_RESTART as optional.
QNX:
Disable zero-copy BPF to work around portability issues.
DAG:
Fix packet filtering with low snaplen.
SNF:
Fix packet filtering with low snaplen.
Netmap:
Set packet captured length based on the snapshot length and return
value of the capture filter.
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/common/libpcap | 2 +-
lfs/libpcap | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/config/rootfiles/common/libpcap b/config/rootfiles/common/libpcap
index 4b74eda39..e76e8bc3a 100644
--- a/config/rootfiles/common/libpcap
+++ b/config/rootfiles/common/libpcap
@@ -21,7 +21,7 @@
#usr/lib/libpcap.a
usr/lib/libpcap.so
usr/lib/libpcap.so.1
-usr/lib/libpcap.so.1.10.6
+usr/lib/libpcap.so.1.10.7
#usr/lib/pkgconfig/libpcap.pc
#usr/share/man/man1/pcap-config.1
#usr/share/man/man3/pcap.3pcap
diff --git a/lfs/libpcap b/lfs/libpcap
index 08e10aa0b..259c66eb2 100644
--- a/lfs/libpcap
+++ b/lfs/libpcap
@@ -24,7 +24,7 @@
include Config
-VER = 1.10.6
+VER = 1.10.7
THISAPP = libpcap-$(VER)
DL_FILE = $(THISAPP).tar.xz
@@ -42,7 +42,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 392bee5b22cd4664ee4f2f110c27ee677c2e3ab25d4427e8d72c7f3347ba1b45acf987d661fc024f8a71e0e2d2b90d53352ad63796ae3836a41561816adf341d
+$(DL_FILE)_BLAKE2 = 5cec38e048446c7837e95a4c51fb3b5cc3a7d8e459f7599d918e9304d6c39725c3e22a9563fdbb0e2bd318f484872b2516856a43928884834403411391859e20
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] liburcu: Update to version 0.15.7
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (19 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] libpcap: Update to version 1.10.7 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] libxml2: Update to version 2.15.4 Adolf Belka
` (8 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 0.15.6 to 0.15.7
- Update of rootfile
- Changelog
0.15.7
* call-rcu worker: set CPU affinity on first non-empty dequeue
* Fix: leaky wfcq tests
* Fix: test_build.c: Test output mismatch
* Fix: workqueue leaks mutexes on FreeBSD
* Fix: call-rcu leaks mutexes on FreeBSD
* call_rcu: pin per-CPU worker at thread startup
* urcu-pointer: Add rcu_dereference_sym2() taking the pointer address
* urcu-pointer: Fix missing memory ordering in rcu_dereference_sym()
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/common/liburcu | 14 +++++++-------
lfs/liburcu | 4 ++--
2 files changed, 9 insertions(+), 9 deletions(-)
diff --git a/config/rootfiles/common/liburcu b/config/rootfiles/common/liburcu
index e3d0352c3..004f90432 100644
--- a/config/rootfiles/common/liburcu
+++ b/config/rootfiles/common/liburcu
@@ -108,31 +108,31 @@
#usr/lib/liburcu-bp.la
#usr/lib/liburcu-bp.so
usr/lib/liburcu-bp.so.8
-usr/lib/liburcu-bp.so.8.1.0
+usr/lib/liburcu-bp.so.8.2.0
#usr/lib/liburcu-cds.la
#usr/lib/liburcu-cds.so
usr/lib/liburcu-cds.so.8
-usr/lib/liburcu-cds.so.8.1.0
+usr/lib/liburcu-cds.so.8.2.0
#usr/lib/liburcu-common.la
#usr/lib/liburcu-common.so
usr/lib/liburcu-common.so.8
-usr/lib/liburcu-common.so.8.1.0
+usr/lib/liburcu-common.so.8.2.0
#usr/lib/liburcu-mb.la
#usr/lib/liburcu-mb.so
usr/lib/liburcu-mb.so.8
-usr/lib/liburcu-mb.so.8.1.0
+usr/lib/liburcu-mb.so.8.2.0
#usr/lib/liburcu-memb.la
#usr/lib/liburcu-memb.so
usr/lib/liburcu-memb.so.8
-usr/lib/liburcu-memb.so.8.1.0
+usr/lib/liburcu-memb.so.8.2.0
#usr/lib/liburcu-qsbr.la
#usr/lib/liburcu-qsbr.so
usr/lib/liburcu-qsbr.so.8
-usr/lib/liburcu-qsbr.so.8.1.0
+usr/lib/liburcu-qsbr.so.8.2.0
#usr/lib/liburcu.la
#usr/lib/liburcu.so
usr/lib/liburcu.so.8
-usr/lib/liburcu.so.8.1.0
+usr/lib/liburcu.so.8.2.0
#usr/lib/pkgconfig/liburcu-bp.pc
#usr/lib/pkgconfig/liburcu-cds.pc
#usr/lib/pkgconfig/liburcu-mb.pc
diff --git a/lfs/liburcu b/lfs/liburcu
index 15f0ac602..af930c5d2 100644
--- a/lfs/liburcu
+++ b/lfs/liburcu
@@ -24,7 +24,7 @@
include Config
-VER = 0.15.6
+VER = 0.15.7
THISAPP = userspace-rcu-$(VER)
DL_FILE = $(THISAPP).tar.bz2
@@ -41,7 +41,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 7bc4892f7a322051a1326e7857a14ebdde5867dbccd6a7ceaf1ce0e74668e5ff5f829f6b9d5b6be2163ae000fe2a07bf937fb62b67e7959d7ed8021f67f6ce04
+$(DL_FILE)_BLAKE2 = 4efebf23aabe729294c128e80cbce4f88f0c2cdc030a551c2a6aeddd1c108028737e452b1f6d65325524794777bb04b383cfa93f2300b2d2931d042adfbd5026
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] libxml2: Update to version 2.15.4
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (20 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] liburcu: Update to version 0.15.7 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] openvpn: Update to version 2.7.7 Adolf Belka
` (7 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 2.15.3 to 2.15.4
- Update of rootfile
- Changelog
2.15.4
Security
- xmlregexp: Prevent out-of-bounds read in NXT macro
- fix: add missing overflow checks in dict.c, uri.c, and valid.c
- xmlregexp: Calc string length after null checking
- xpointer: Check overflow in xmlXPtrEvalXPtrPart
- xmlIO: Check for int overflow before calling writecallback
- fix(xinclude): propagate parseFlags in xmlXIncludeProcess and xmlXIncludeProcessTree
Improvements
- Improve bound checks for xmlcatalog and xmllint arguments (out-of-bound)
- Fix memory leak in static Windows library (memory-leak)
- xmlreader: Copy DTD in xmlTextReaderDumpCopy
- parser: Fix double free in xmlIOParseDTD (double-free)
- parser: fix division-by-zero when maxAmpl is set to 0
- parser: Fix memory leak in xmlCtxtSetSaxHandler (memory-leak)
- catalog: Make sure to reset catalog resolve cache
- xmlAddChild: unlink node before free for text nodes (memory-leak)
- Normalize entity values in attr in xmlNodeGetContent
- Handle whitespace for date/time/duration types
- catalog: Fix NULL deref for nextCatalog without 'catalog' attribute (null-deref)
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/common/libxml2 | 2 +-
lfs/libxml2 | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/config/rootfiles/common/libxml2 b/config/rootfiles/common/libxml2
index 5a4f85793..4dcef88dc 100644
--- a/config/rootfiles/common/libxml2
+++ b/config/rootfiles/common/libxml2
@@ -54,5 +54,5 @@
#usr/lib/libxml2.la
#usr/lib/libxml2.so
usr/lib/libxml2.so.16
-usr/lib/libxml2.so.16.1.3
+usr/lib/libxml2.so.16.1.4
#usr/lib/pkgconfig/libxml-2.0.pc
diff --git a/lfs/libxml2 b/lfs/libxml2
index 84ebb0a0a..18ac7808a 100644
--- a/lfs/libxml2
+++ b/lfs/libxml2
@@ -24,7 +24,7 @@
include Config
-VER = 2.15.3
+VER = 2.15.4
# https://download.gnome.org/sources/libxml2/
THISAPP = libxml2-$(VER)
@@ -43,7 +43,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 2ff478b46a40957386cd1ed0627bfc0f2433f47e786f20db3942304c90289adaeb1d9c3f12665df312b86cfac42f8e4dbc18e965bf90018f93c230b9b862df66
+$(DL_FILE)_BLAKE2 = 92a4fc5179527968b9ac7043669a77d54c85143883749aa497005797bbf8b3d08514f62191437bfd079e0bb965859e456308b90e0ff1da738cc3dbd945c0f0bf
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] openvpn: Update to version 2.7.7
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (21 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] libxml2: Update to version 2.15.4 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] pcre2: Update to version 10.48 Adolf Belka
` (6 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 2.7.6 to 2.7.7
- No change in rootfile
- 10 CVE fixes
- Changelog
2.7.7
Security fixes
reliability layer: Avoid unbounded reliable TLS timeout (CVE-2026-84732)
reliability layer: Ignore acks for packets that cannot be outstanding
(CVE-2026-84732)
(both reliability layer bugs found by Mark Bregman <mark.bregman@fox-it.com>,
tracked in Github: OpenVPN/openvpn-private-issues#161)
Windows: fix CreateProcess() command line quoting for characters that are special
to cmd.exe and where a combination of validation script plus rogue CA could
lead to misbehavior (CVE-2026-84256)
(Bug found by Clouditera Security <security@clouditera.com>, tracked
in Github: OpenVPN/openvpn-private-issues#159)
Windows: fix tapctl to always call netsh.exe with full path (as we do elsewhere)
(CVE-2026-84226)
(Bug found by BreachX Zero Day Labs, using Typhon AI Mil v2, tracked
in Github: OpenVPN/openvpn-private-issues#164)
Windows: don't use NULL DACL with system objects, namely the --service exit event
and the netsh.exe guard semaphore. The old approach was prone to a local DoS
where one user could interfere with other users' openvpn processes by
blocking the netsh semaphore or sending events. This only affects setups not
using the iservice, or using the automatic service to start/stop openvpn
(CVE-2026-82312).
(Bug found by DEBRAJ BASAK <https://in.linkedin.com/in/debrajbasak>,
tracked in Github: OpenVPN/openvpn-private-issues#167)
Linux Netlink: validate netlink replies against the request
(Suggested by Joshua Rogers <contact@joshua.hu> as a security improvement,
tracked in Github: OpenVPN/openvpn-private-issues#9)
Windows: fix off-by-one on input validation in openvpnserv (discovered while
fixing CVE-2026-78221)
Windows: openvpnserv: pass correct NRPT domains size - when IDN domains with
UTF8 encoding were involved, a buffer overread could be achieved (CVE-2026-78221).
(Bug found by BreachX Zero Day Labs, using Typhon AI Mil v2,
in Github: OpenVPN/openvpn-private-issues#162)
Windows: harden CheckConfigPath() a bit more (another improvement while working
on CVE-2026-78043)
Windows: openvpnserv: don't allow '/' in config paths (the APIs windows uses for
path validation do not handle '/' as path
separator, while the file open APIs do, so this could be used to circumvent
our config path validation, leading to openvpn.exe starting a user-controlled
config file even if administatively not allowed. CVE-2026-78043)
(Bug found by BreachX Zero Day Labs, using Typhon AI Mil v2,
in Github: OpenVPN/openvpn-private-issues#162)
Windows: dhcp: Fix off-by-one in write_dhcp_search_str() temp buffer guard
(suitable DHCP options could lead to a single-byte overflow of a temp
buffer, CVE-2026-81738)
(Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked
in Github: OpenVPN/openvpn-private-issues#165)
Bugfixes
work around a pubkey-handling bug in mbedTLS 4.1.0 and 4.2.0 (supposedly fixed
in 4.3.0)
multi: don't let stale-routes-check delete permanent routes (the
--stale-routes-check did not delete dynamic cached routes,
but also routes installed by --iroute and --ifconfig-push - fix by
introducing route flags and restraining the check on them)
(Github: #1063)
Windows: openvpnserv: fix log lines format string interface names with
international characters printed in some error messages need to be converted
from UTF8 to UCS16 first.
clinat: do not adjust UDP checksum if zero (as per RFC768) (Github: #1037)
OpenSSL: avoid resetting the HMAC key on every packet (Github: #1088)
fix format string specifier for size_t (%zu)
ssl: Do not queue control ciphertext while a packet is still queued (fixes
problems in TCP p2p handshake when both sides try to handshake
at the same time)
(Github: #1089)
Reenable xmit_hold when using p2p tcp-server and tls-server (in TCP server mode,
the server is not expected to initiate the TLS
handshake - bug introduced by the multisocket code, checking the wrong
variable for socket protocol)
(Github: #1089)
fix test_misc compile issues with -Werror
User-visible Changes
when using EPOCH data channel format, reduce number of future keys from 16 to 4
(calculation was wrong, 4 spare keys are sufficient for 100+ Gbit/s links,
less log spam in userland and less resources used in in-kernel implementations)
Building/Testing improvements
clang-format: Convert deprecated setting KeepEmptyLinesAtTheStartOfBlocks
t_client.sh: various improvements
Documentation improvements
doc: Update doxygen references to removed tunnel_server_{udp, tcp}() (those
functions do not exist in 2.7+ anymore)
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
lfs/openvpn | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/lfs/openvpn b/lfs/openvpn
index 010c3a375..266dc7140 100644
--- a/lfs/openvpn
+++ b/lfs/openvpn
@@ -24,7 +24,7 @@
include Config
-VER = 2.7.6
+VER = 2.7.7
THISAPP = openvpn-$(VER)
DL_FILE = $(THISAPP).tar.gz
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 0cf4f6c7337ef3e31cb6f261423863b86fedcaaa69272d26811f4066afcece873ccebca167cb5e9f37bc474ccbbad7f71effc0678b98ed52864a96351a8cc3f0
+$(DL_FILE)_BLAKE2 = 6f4230df1f238f0b0e1bdcc978850cf3f49c8c61dcebcdc819861399bf68016d14800140a2fb69bfc7fdc8fa4987cde531d59249f3f91533d7c9244080d557fc
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] pcre2: Update to version 10.48
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (22 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] openvpn: Update to version 2.7.7 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] postfix: Update to version 3.11.7 Adolf Belka
` (5 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 10.47 to 10.48
- Update of rootfile
- 6 GHSA security fixes
- Changelog
10.48
This is a regular release, incorporating security fixes along with small
improvements and fixes to library behaviour.
Only changes to behaviour, changes to the API, and other significant changes
are described here. Please see the ChangeLog and Git log for further details.
As well as the tarball and Git tag for this release, there are detailed
instructions for backporting security and correctness fixes, for the last
five years of releases.
* (Git change) Renamed the default development branch from master to main.
* (Maintenance change) Added a five-year support lifecycle policy and
publication of backport patches for security and high-severity fixes in older
releases.
* (Security fix for very specific API usage, GHSA-2p8c-ff85-vh9x) If
pcre2_jit_compile() is called with options for some match modes, and then
pcre2_match() is used to perform a match for a different match mode, an
out-of-bounds read can occur if the match is attempted against invalid UTF input.
* (Security fix for pattern conversion, GHSA-q8g2-wprr-34m9) If pcre2_convert()
is called on untrusted input on platforms with 32-bit size_t, an out-of-bounds
heap write can occur.
* (Security fix, GHSA-3r4p-g7gg-ppmf) Fixed an out-of-bounds write in DFA
matching when using a heap limit; also fixed possible integer overflows which
could cause under-allocation of the workspace.
* (Security fix, GHSA-fmgr-6ggq-9859) Added bounds checks for several integer
overflows while compiling patterns on 32-bit CPUs, which could cause
under-allocation followed by out-of-bounds writes.
* (Security fix, GHSA-9qww-pwc4-77qq) Applied lower buffer bound to prevent
two out-of-bounds reads while scanning backwards through invalid UTF data with
PCRE2_MATCH_INVALID_UTF.
* (Matching correctness) Fixed several matching issues:
- A JIT-specific matching bug affecting prefix scanning on patterns with
repeats (#875).
- A JIT-specific matching bug in variable-length lookbehinds (#912).
- Miscompiled Unicode character classes combining characters at or below
U+00FF with characters at U+0100 and U+8000 or above (#841).
- Incorrect JIT character advancement with PCRE2_MATCH_INVALID_UTF in UTF-8
and UTF-16 modes, which could skip adjacent characters (#945).
* (Behaviour change) Updated Unicode support to Unicode 17.0.
* (Small behaviour changes) Many small fixes, including pcre2_substitute()
improvements, optimisation of possessive backreference matching, and
pcre2_compile() fixes.
* (Small build changes) Many small adjustments to the CMake and Zig builds.
* (Security fix for very specific API usage, #937) Fixed a leak and later
invalid free when calling the fast-path pcre2_jit_match() function with a match
data object previously used with pcre2_match() and
PCRE2_COPY_MATCHED_SUBJECT.
* (Low-severity security fix, GHSA-q7rw-r7qq-2hx6) Fixed exposure of two
uninitialised bytes from malloc() via pcre2_serialize_encode().
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/common/pcre2 | 241 +++++++++++++++++-----------------
lfs/pcre2 | 6 +-
2 files changed, 124 insertions(+), 123 deletions(-)
diff --git a/config/rootfiles/common/pcre2 b/config/rootfiles/common/pcre2
index bb6366fb0..152524867 100644
--- a/config/rootfiles/common/pcre2
+++ b/config/rootfiles/common/pcre2
@@ -6,139 +6,140 @@
#usr/lib/libpcre2-16.la
#usr/lib/libpcre2-16.so
usr/lib/libpcre2-16.so.0
-usr/lib/libpcre2-16.so.0.15.0
+usr/lib/libpcre2-16.so.0.16.0
#usr/lib/libpcre2-32.la
#usr/lib/libpcre2-32.so
usr/lib/libpcre2-32.so.0
-usr/lib/libpcre2-32.so.0.15.0
+usr/lib/libpcre2-32.so.0.16.0
#usr/lib/libpcre2-8.la
#usr/lib/libpcre2-8.so
usr/lib/libpcre2-8.so.0
-usr/lib/libpcre2-8.so.0.15.0
+usr/lib/libpcre2-8.so.0.16.0
#usr/lib/libpcre2-posix.la
#usr/lib/libpcre2-posix.so
usr/lib/libpcre2-posix.so.3
-usr/lib/libpcre2-posix.so.3.0.7
+usr/lib/libpcre2-posix.so.3.0.8
#usr/lib/pkgconfig/libpcre2-16.pc
#usr/lib/pkgconfig/libpcre2-32.pc
#usr/lib/pkgconfig/libpcre2-8.pc
#usr/lib/pkgconfig/libpcre2-posix.pc
-#usr/share/doc/pcre-pcre2-10.47
-#usr/share/doc/pcre-pcre2-10.47/AUTHORS.md
-#usr/share/doc/pcre-pcre2-10.47/COPYING
-#usr/share/doc/pcre-pcre2-10.47/ChangeLog
-#usr/share/doc/pcre-pcre2-10.47/LICENCE.md
-#usr/share/doc/pcre-pcre2-10.47/NEWS
-#usr/share/doc/pcre-pcre2-10.47/README
-#usr/share/doc/pcre-pcre2-10.47/SECURITY.md
-#usr/share/doc/pcre-pcre2-10.47/html
-#usr/share/doc/pcre-pcre2-10.47/html/NON-AUTOTOOLS-BUILD.txt
-#usr/share/doc/pcre-pcre2-10.47/html/README.txt
-#usr/share/doc/pcre-pcre2-10.47/html/index.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2-config.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_callout_enumerate.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_code_copy.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_code_copy_with_tables.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_code_free.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_compile.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_compile_context_copy.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_compile_context_create.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_compile_context_free.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_config.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_convert_context_copy.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_convert_context_create.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_convert_context_free.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_converted_pattern_free.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_dfa_match.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_general_context_copy.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_general_context_create.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_general_context_free.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_get_error_message.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_get_mark.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_get_match_data_heapframes_size.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_get_match_data_size.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_get_ovector_count.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_get_ovector_pointer.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_get_startchar.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_jit_compile.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_jit_free_unused_memory.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_jit_match.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_jit_stack_assign.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_jit_stack_create.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_jit_stack_free.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_maketables.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_maketables_free.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_match.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_match_context_copy.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_match_context_create.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_match_context_free.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_match_data_create.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_match_data_create_from_pattern.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_match_data_free.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_next_match.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_pattern_convert.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_pattern_info.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_serialize_decode.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_serialize_encode.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_serialize_free.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_serialize_get_number_of_codes.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_bsr.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_callout.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_character_tables.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_compile_extra_options.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_compile_recursion_guard.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_depth_limit.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_glob_escape.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_glob_separator.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_heap_limit.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_match_limit.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_max_pattern_compiled_length.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_max_pattern_length.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_max_varlookbehind.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_newline.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_offset_limit.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_optimize.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_parens_nest_limit.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_recursion_limit.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_recursion_memory_management.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_substitute_callout.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_set_substitute_case_callout.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_substitute.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_substring_copy_byname.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_substring_copy_bynumber.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_substring_free.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_substring_get_byname.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_substring_get_bynumber.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_substring_length_byname.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_substring_length_bynumber.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_substring_list_free.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_substring_list_get.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_substring_nametable_scan.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2_substring_number_from_name.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2api.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2build.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2callout.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2compat.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2convert.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2demo.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2grep.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2jit.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2limits.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2matching.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2partial.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2pattern.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2perform.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2posix.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2sample.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2serialize.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2syntax.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2test.html
-#usr/share/doc/pcre-pcre2-10.47/html/pcre2unicode.html
-#usr/share/doc/pcre-pcre2-10.47/pcre2-config.txt
-#usr/share/doc/pcre-pcre2-10.47/pcre2.txt
-#usr/share/doc/pcre-pcre2-10.47/pcre2grep.txt
-#usr/share/doc/pcre-pcre2-10.47/pcre2test.txt
+#usr/share/doc/pcre-pcre2-10.48
+#usr/share/doc/pcre-pcre2-10.48/AUTHORS.md
+#usr/share/doc/pcre-pcre2-10.48/COPYING
+#usr/share/doc/pcre-pcre2-10.48/ChangeLog
+#usr/share/doc/pcre-pcre2-10.48/LICENCE.md
+#usr/share/doc/pcre-pcre2-10.48/NEWS
+#usr/share/doc/pcre-pcre2-10.48/README
+#usr/share/doc/pcre-pcre2-10.48/SECURITY.md
+#usr/share/doc/pcre-pcre2-10.48/SUPPORT-LIFECYCLE.md
+#usr/share/doc/pcre-pcre2-10.48/html
+#usr/share/doc/pcre-pcre2-10.48/html/NON-AUTOTOOLS-BUILD.txt
+#usr/share/doc/pcre-pcre2-10.48/html/README.txt
+#usr/share/doc/pcre-pcre2-10.48/html/index.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2-config.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_callout_enumerate.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_code_copy.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_code_copy_with_tables.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_code_free.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_compile.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_compile_context_copy.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_compile_context_create.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_compile_context_free.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_config.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_convert_context_copy.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_convert_context_create.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_convert_context_free.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_converted_pattern_free.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_dfa_match.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_general_context_copy.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_general_context_create.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_general_context_free.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_get_error_message.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_get_mark.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_get_match_data_heapframes_size.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_get_match_data_size.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_get_ovector_count.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_get_ovector_pointer.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_get_startchar.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_jit_compile.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_jit_free_unused_memory.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_jit_match.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_jit_stack_assign.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_jit_stack_create.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_jit_stack_free.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_maketables.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_maketables_free.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_match.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_match_context_copy.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_match_context_create.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_match_context_free.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_match_data_create.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_match_data_create_from_pattern.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_match_data_free.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_next_match.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_pattern_convert.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_pattern_info.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_serialize_decode.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_serialize_encode.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_serialize_free.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_serialize_get_number_of_codes.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_bsr.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_callout.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_character_tables.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_compile_extra_options.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_compile_recursion_guard.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_depth_limit.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_glob_escape.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_glob_separator.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_heap_limit.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_match_limit.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_max_pattern_compiled_length.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_max_pattern_length.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_max_varlookbehind.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_newline.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_offset_limit.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_optimize.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_parens_nest_limit.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_recursion_limit.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_recursion_memory_management.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_substitute_callout.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_set_substitute_case_callout.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substitute.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_copy_byname.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_copy_bynumber.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_free.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_get_byname.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_get_bynumber.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_length_byname.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_length_bynumber.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_list_free.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_list_get.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_nametable_scan.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2_substring_number_from_name.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2api.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2build.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2callout.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2compat.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2convert.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2demo.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2grep.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2jit.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2limits.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2matching.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2partial.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2pattern.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2perform.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2posix.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2sample.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2serialize.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2syntax.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2test.html
+#usr/share/doc/pcre-pcre2-10.48/html/pcre2unicode.html
+#usr/share/doc/pcre-pcre2-10.48/pcre2-config.txt
+#usr/share/doc/pcre-pcre2-10.48/pcre2.txt
+#usr/share/doc/pcre-pcre2-10.48/pcre2grep.txt
+#usr/share/doc/pcre-pcre2-10.48/pcre2test.txt
#usr/share/man/man1/pcre2-config.1
#usr/share/man/man1/pcre2grep.1
#usr/share/man/man1/pcre2test.1
diff --git a/lfs/pcre2 b/lfs/pcre2
index 9686bf750..9a47dfb43 100644
--- a/lfs/pcre2
+++ b/lfs/pcre2
@@ -1,7 +1,7 @@
###############################################################################
# #
# IPFire.org - A linux based firewall #
-# Copyright (C) 2007-2025 IPFire Team <info@ipfire.org> #
+# Copyright (C) 2007-2026 IPFire Team <info@ipfire.org> #
# #
# This program is free software: you can redistribute it and/or modify #
# it under the terms of the GNU General Public License as published by #
@@ -24,7 +24,7 @@
include Config
-VER = 10.47
+VER = 10.48
THISAPP = pcre2-$(VER)
DL_FILE = $(THISAPP).tar.bz2
@@ -54,7 +54,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 9b56eddbc8b6fd6ce925575c337891c4f7790215c77325c1f0ad4a72be07e2a2a6a6b6638a5a2c49d1da6f4715320f240fd17c4ffcb77d1bb00875b990d6ee13
+$(DL_FILE)_BLAKE2 = 7c500b4271e13c8a965a85c2aac4a72d5f29b7a3318b6077fa9de391512669ad26a5a774eee322c966ed38127ca9dfc139e4dacc1c1b23578d0674d882b3d84c
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] postfix: Update to version 3.11.7
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (23 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] pcre2: Update to version 10.48 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] systemd: Update to version 261.3 Adolf Belka
` (4 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 3.11.6 to 3.11.7
- No change in rootfile
- Changelog
3.11.7
Major changes - database
[Incompat 20260220] The alias_maps and alias_database parameter
default values have changed from hash:/path/to/aliases (or
dbm:/path/to/aliases) to $default_database_type:/path/to/aliases.
This simplifies the migration away from Berkeley DB.
[Infrastructure 20260219] Support to migrate a Postfix configuration
that uses Berkeley DB hash: or btree: tables, to a configuration
that uses lmdb: or a combination of cdb: and lmdb:. This is needed
for (Linux) OS distributions that have removed Berkeley DB support.
See NON_BERKELEYDB_README for manual and automatic migration support.
Postfix already supports CDB and LMDB for more than 10 years. It
may be a good idea to do the migration before you need to upgrade
to an OS distribution that no longer supports Berkeley DB.
[Infrastructure 20251226] Tooling to help with the migration away
from Berkeley DB.
The new parameter default_cache_db_type controls the default database
type for address_verify_map, postscreen_cache_map, and
smtp_sasl_auth_cache_name, previously hard-coded as 'btree'.
[Feature 20250321] Safety: the SQLite client now logs a warning
when a query uses double quotes instead of the Postfix-recommended
single quotes. Only the recommended form is protected against SQL
injection.
[Feature 20250509] Support to run all memcache lookup keys through
an OpenSSL digest function. This prevents a database access error
when lookup keys may exceed the memcache server's key length limit
(usually, 250 bytes).
[Feature 20250624] Support for a new "debug:" pseudo lookup table.
Specify debug:maptype:mapname to encapsulate a maptype:mapname
lookup table and log all access. This builds on existing but unused
code to log table access. Contributed by Richard Hansen.
[Infrastructure 20250626] Overhauled in-memory lookup table life-cycle
management; overhauled sharing/isolation for proxied lookup tables.
Major changes - deprecation
[Feature 20250609] smtp_tls_enforce_peername and lmtp_tls_enforce_peername
are now officially deprecated. Postfix will log a warning until the
features are deleted. See DEPRECATION_README for a summary of
deprecated and deleted features.
[Feature 20251027] This adds 12 more deprecation warnings for
parameters that have been renamed in the past, and that still provide
a backwards-compatible default value for their replacement. The
parameters deprecated by this change are: authorized_verp_clients,
fallback_relay, lmtp_per_record_deadline, postscreen_blacklist_action,
postscreen_dnsbl_ttl, postscreen_dnsbl_whitelist_threshold,
postscreen_whitelist_interfaces, smtpd_client_connection_limit_exceptions,
smtp_per_record_deadline, tlsproxy_client_level, tlsproxy_client_policy,
virtual_maps.
[Feature 20251028] Deprecate the smtp_cname_overrides_servername
and lmtp_cname_overrides_servername parameters, and delete documentation
that has been obsolete since Postfix 2.11.
Major changes - logging
[Feature 20250910] TLS feature policy status summary in delivery
status logging. This shows the desired and actual TLS security level
enforcement status and, if a message requests REQUIRETLS, the
REQUIRETLS policy enforcement status. For a list of examples see
https://www.postfix.org/postconf.5.html#smtp_log_tls_feature_status
[Feature 20251216] After a delivery failure, the bounce daemon
logged "<old-queue-id>: sender non-delivery notification: <new-queue-id>"
only if the notification was queued successfully. The bounce daemon
now always logs this, making Postfix behavior easier to understand.
Visible changes for logfile analyzers:
- The bounce daemon now logs "<old-queue-id>: sender non-delivery
notification: <new-queue-id>" BEFORE the cleanup daemon logs activity
with "<new-queue-id>". Previously, the bounce daemon logged the
old<=>new queue ID connection later, which made logfile analysis
more difficult.
- The bounce daemon now logs a logfile record "<old-queue-id>:
sender notification failed to <address>: <reason>" when the
notification was not queued. In some cases it will log "<old-queue-id>:
sender notification failed to <address>" (without the reason). In
those cases the failure reason was already logged by lower-level
code, but without the queue ID.
Major changes - management tool integration
[Feature 20251124] Basic JSON output support with "postconf
-j|-jM|-jF|-jP", "postalias -jq|-js", "postmap -jq|-js", and
"postmulti -jl". No support is planned for JSON input support.
Major changes - milter support
[Feature 20251208] Improved Milter error handling for messages that
arrive over a long-lived SMTP connection, by changing the default
milter_default_action from "tempfail" to the new "shutdown" action
(i.e. disconnect the remote SMTP client).
This avoids a worst-case scenario where after a single Milter error,
Postfix would tempfail all messages that the client sends over a
long-lived connection, even if the Milter error was only temporary.
Major changes - mime support
[Feature 20251104] New non_empty_end_of_header_action parameter
with the cleanup(8) server action when a primary message header is
terminated with a non-empty line:
1) fix_quietly: Insert an empty line before the offending text (the
backwards-compatible default),
2) add_header: Insert a MIME-Error: header before inserting an empty
line, or
3) reject: Log a "mime-error" and reject the message.
Note that the 'empty line' separator is not used for DKIM signature
checks. Therefore, adding a missing separator does not break DKIM.
Major changes - mta-sts
[Feature 20250906] Workaround for an interface mis-match between
the Postfix SMTP client and MTA-STS policy plugins. This introduces
a new parameter "smtp_tls_enforce_sts_mx_patterns" (default: "yes").
The MTA-STS plugin configuration needs to enable TLSRPT support,
so that it forwards STS policy attributes to Postfix. This works
even if Postfix TLSRPT support is disabled at build time or at
runtime.
With the above two configurations, the Postfix SMTP client will
connect to an MX host only if its name matches any STS policy MX
host pattern, and will match a server certificate against the MX
hostname. Otherwise, the old behavior stays in effect: connect to
any MX host listed in DNS, and match a server certificate against
any STS policy MX host pattern.
This code was published first in Postfix 3.11, and later back-ported
to Postfix 3.10.5.
Major changes - portability
[Feature 20241201] Support for the C23 built-in bool type. Older
Postfix releases have been updated with a makedefs script that
disables C23 built-in bool support.
Major changes - postqueue
[Feature 20251218] the postqueue (and mailq) command now also lists
recipients in bounce logfiles (in JSON output, this uses a new
object member 'bounce_reason' instead of the existing 'delay_reason').
Such recipients have already been deleted from the message queue
file, but they are still pending the creation of a non-delivery
status notification message that will be returned to the sender.
Major changes - relocated_maps
[Feature 20250608] Specify "relocated_prefix_enable = no" to disable
the hard-coded prefix "5.1.6 User has moved to " that is by default
prepended to all relocated_maps lookup results. This setting requires
that the table contains responses with both custom enhanced status
code (X.Y.Z) and text. For details, see "man 5 relocated" or
https://www.postfix.org/relocated.5.html .
Major changes - requiretls
[Feature 20241111] Support for the REQUIRETLS verb in SMTP. This,
and everything that was added later through 2025, is described in
REQUIRETLS_README.
[Feature 20250120] After a certificate check fails, or a remote
SMTP server does not announce REQUIRETLS support, the Postfix SMTP
client will override the RFC 8689 5.x.x. status and treat it as a
soft error, until there are no more alternate MX servers to try.
[Feature 20250827] New parameter requiretls_redact_dsn (default:
yes) to redact bounce messages as described in RFC 8689 section 5,
so that they don't need REQUIRETLS support on every hop in the
return path.
[Feature 20250827] smtp_requiretls_policy and lmtp_requiretls_policy
for responsible REQUIRETLS policy enforcement. REQUIRETLS must be
enforced with care, because at this time most domains do not publish
DANE or MTA-STS policies, and most MTAs and content filters do not
support REQUIRETLS.
[Feature 20250916] support for a "Require-TLS-ESMTP: yes" header
to propagate an ESMTP REQUIRETLS request through a FILTER_README
or SMTPD_PROXY_README style content filter. This header is detected
or added by the cleanup daemon and by the before-proxy-filter Postfix
SMTP server. This feature is enabled by default with
"requiretls_esmtp_header = yes". The Require-TLS-ESMTP header will
be visible to local and remote recipients. This feature can safely
be disabled when a configuration does not use REQUIRETLS, or does
not use FILTER_README or SMTPD_PROXY_README style content filters.
Major changes - smtp server
[Feature 20250801] smtpd_reject_filter_maps support to selectively
replace a reject response from the Postfix SMTP server, or from a
program that replies through the Postfix SMTP server.
Major changes - smtputf8
[Feature 20250122] New Postfix sendmail command option "-O smtputf8"
to request that deliveries over SMTP use the SMTPUTF8 extension.
This reuses logic that was introduced for REQUIRETLS.
[Feature 20250824] When a message needs to be delivered with SMTPUTF8,
but a remote server does not support it, the Postfix SMTP client
may now try alternate servers instead of returning the message
immediately. This reuses code that was implemented for REQUIRETLS.
Major changes - tls support
[Feature 20250623] This changes the Postfix SMTP client
smtp_tls_security_level default value to "may" if Postfix was built
with TLS support, and the compatibility_level is 3.11 or higher.
There is no change to the default lmtp_tls_security_level value.
It remains empty, because there is no default TLS security level
that makes sense for connections over UNIX-domain and loopback TCP
and non-loopback TCP sockets.
There also is no equivalent change for Postfix SMTP server TLS
security levels, because changing smtpd_tls_security_level is not
sufficient. Server-side TLS requires that at least one private key
and corresponding public-key certificate chain are configured.
[Feature 20251029] Debugging: depending on OpenSSL build options,
"posttls-finger -L ssl-debug" will decode TLS handshake messages.
[Feature 20251102] Post-quantum cryptography support: with OpenSSL
3.5 and later, change the tls_eecdh_auto_curves default value to
avoid problems with network infrastructure that mis-handles TLS
hello messages larger than one (Ethernet) TCP segment. This problem
is more generally known as "protocol ossification".
Major changes - tlsrpt
[Incompat 20250601] the default smtp_tlsrpt_skip_reused_handshakes
setting was changed from "yes" to "no". The new default is enabled
with compatibility level >= 3.11.
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
lfs/postfix | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/lfs/postfix b/lfs/postfix
index 4ab686707..836075e52 100644
--- a/lfs/postfix
+++ b/lfs/postfix
@@ -26,7 +26,7 @@ include Config
SUMMARY = A fast, secure, and flexible mailer
-VER = 3.11.6
+VER = 3.11.7
THISAPP = postfix-$(VER)
DL_FILE = $(THISAPP).tar.gz
@@ -34,7 +34,7 @@ DL_FROM = $(URL_IPFIRE)
DIR_APP = $(DIR_SRC)/$(THISAPP)
TARGET = $(DIR_INFO)/$(THISAPP)
PROG = postfix
-PAK_VER = 56
+PAK_VER = 57
DEPS =
@@ -72,7 +72,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = e4a1194fa3f718212413bcee4f61f3c7fe3bd6b0bc6e96a714ca4093e3827350c2eda0e68c5826d865fc9c657e6bcebb0724b99c282c7a85dd877f2207de5075
+$(DL_FILE)_BLAKE2 = 4f3d9f92320336a80770593800d026aa41dc628dfd9db5e5d3b6fad667fe700bdd4bddcc16fce17f47fdba9cd58419946dc5f14b0e9d7dc5569c45b1226ffae4
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] systemd: Update to version 261.3
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (24 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] postfix: Update to version 3.11.7 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] tzdata: Update to version 2026d Adolf Belka
` (3 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 261.2 to 261.3
- No change in rootfile
- Changelog is for whole systemd. Searching for commits including the word udev gave
4 entries for 261.3 compared to 261.2
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
lfs/systemd | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/lfs/systemd b/lfs/systemd
index cba1b7620..7af3e5f6e 100644
--- a/lfs/systemd
+++ b/lfs/systemd
@@ -24,7 +24,7 @@
include Config
-VER = 261.2
+VER = 261.3
THISAPP = systemd-$(VER)
DL_FILE = $(THISAPP).tar.gz
@@ -50,7 +50,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = f8f57c5e78ff31727ecfd18b61d3a3a95b764e5a049c0cc974be567273db2f771ab2f50df1ebf06b0c3a659c7e02db309dee4844217e3a91ae1169877971a34e
+$(DL_FILE)_BLAKE2 = d0809439fea1f8c8b00a597ea5a09ff0455009c07f13976ed7663978bb8cafbd22ce0f49386087fec3553b376251cc8c82ca05adb6188c6ec43e580b336dc7de
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] tzdata: Update to version 2026d
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (25 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] systemd: Update to version 261.3 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] util-linux: Update to version 2.42.3 Adolf Belka
` (2 subsequent siblings)
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 2026c to 2026d
- No change in rootfile
- Changelog
2026d
Briefly:
Canada’s Northwest Territories moved to permanent -06 on 2026-08-21.
Obsolescent settings like TZ="EST5EDT" now conform better to POSIX.
Fix security, performance and porting bugs in zic and localtime.
Changes to future timestamps
Canada’s Northwest Territories will not fall back on 2026-11-01
and will stay on -06 year-round, matching Alberta’s recent change.
Model this with its traditional abbreviation CST. Although the
change to permanent -06 legally took place on 2026-08-21,
temporarily model the change to occur on 2026-11-01 at 02:00
for the same reason as other recent temporary hacks. (Caution:
see “NOTE FOR 2026b TEMPORARY HACK FOR CLDR AND CANADA” below.)
This affects only America/Inuvik as the rest of the territory is
covered by America/Edmonton, for which the equivalent change was
released in 2026c.
NOTE FOR 2026b TEMPORARY HACK FOR CLDR AND CANADA:
This zic fix is needed for the temporary hack (mentioned above)
that works around the Canadian timekeeping bug in Unicode CLDR.
Without the fix, the temporary hack causes zic versions 2023d
through 2026a, in their default mode that generates slim output,
to generate a TZif file that violates Internet RFC 9636 §3.3.
The buggy file in turn causes some TZif readers, including tzcode
itself, to ignore America/Vancouver’s 2026-11-01 02:00 transition
from PDT (tm_isdst=1) to MST (tm_isdst=0). Although the buggy
file does not cause any known TZif reader to mishandle UT offsets,
caution is advised when using zic 2023d through 2026a to compile
data from more-recent tz releases. To work around this problem
when using these older zic versions, use ‘zic -b fat’.
Changes to past timestamps
Colombia’s 1992-05-02 spring forward was at 00:00, not 24:00.
Iran’s 1979-05-26 spring forward was at 00:00, not 24:00.
(Thanks to N.F. Hase.)
The backward-compatibility names EST5EDT, CST6CDT, MST7MDT, and
PST8PDT now conform better to POSIX. For example, EST5EDT now
always uses the abbreviation "EST" for standard time (now always 5
hours behind UT) and "EDT" for daylight saving time, whereas it
formerly had different UT offsets before standard time was
introduced and sometimes used abbreviations like "LMT", "EWT" and
"EPT", all contrary to POSIX. Also, though not required by POSIX
these names now use US federal rules rather than rules of places
like New York, reverting to 2024a behavior. This change affects
only timestamps before 1966-10-30 at 01:00 standard time.
Other data changes
The temporary hacks used for North American timekeeping changes
now work around a libstdc++ std::chrono bug in GCC 14.1-14.4,
15.1-15.2, and 16.1; see GCC bug 124851. This data change does
not affect TZif files or timestamps. The change does not work
around the related but less serious GCC bugs 116110 and 124513.
These GCC bugs are all fixed in GCC 16.2.
Changes to code
zic now rejects Link targets that would have invalid names, and
more efficiently processes Expires, Leap and Rule lines with years
far in the past or future. (Thanks to Darren Carreras.)
zic now ports to systems that report lack of link support via
EINVAL, ENOSYS or EPERM errno values. (Thanks to Tom Lane.)
When tzset and related functions encounter a TZif file that is too
large for them, they now consistently fail instead of sometimes
silently ignoring excess parts of the file.
localtime-related functions no longer mishandle extreme timestamps
when given TZif files holding some unlikely timezone histories.
(Problem reported by David Sarkisyan.)
localtime-related functions no longer check the values of TZif
files’ standard/wall and UT/local indicators, which these
functions have not used since 2026a’s removal of the old
posixrules feature.
tzcode has been ported to Haiku.
localtime.c now works again by default on AIX and DragonFly BSD.
zic now rejects ‘:’ and ‘\’ in Zone and Link names when running on
Microsoft Windows. (Problem reported by David Diaz.)
Changes to documentation
URLs for release tarballs in tz-link.html have been updated to
reflect their new canonical URLs on data.iana.org.
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
lfs/tzdata | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/lfs/tzdata b/lfs/tzdata
index 42b916af0..04856bca8 100644
--- a/lfs/tzdata
+++ b/lfs/tzdata
@@ -24,7 +24,7 @@
include Config
-VER = 2026c
+VER = 2026d
# https://data.iana.org/time-zones/releases/.tar.gx & .asc
TZDATA_VER = $(VER)
@@ -47,8 +47,8 @@ objects = tzdata$(TZDATA_VER).tar.gz tzcode$(TZCODE_VER).tar.gz
tzdata$(TZDATA_VER).tar.gz = $(DL_FROM)/tzdata$(TZDATA_VER).tar.gz
tzcode$(TZCODE_VER).tar.gz = $(DL_FROM)/tzcode$(TZCODE_VER).tar.gz
-tzdata$(TZDATA_VER).tar.gz_BLAKE2 = 53a759b9081736b5daba8574b2f6a6852fcd0fbb85237d90e5c589f4126a445a9fbbf338383fc14cee09fa4bb38b546a8285adcbdd944d93eb7e1242cae8feda
-tzcode$(TZCODE_VER).tar.gz_BLAKE2 = 09939593ad33e894d7ad62f8a7e1ee09a4490143a4c744551f81e836eb1b63f96926d362e415d1e254d2fe2d52378017c190b027e1d99a00b94014a413e329dd
+tzdata$(TZDATA_VER).tar.gz_BLAKE2 = a9ed7437306e582e2b6791ca02de44c0bf7ec0e52d303532a972aaa2610820c1c16c3b959e5222398bc5101d2061a00b417d815bd5de730ad1f57b98471b901a
+tzcode$(TZCODE_VER).tar.gz_BLAKE2 = 7a042efe57b2e319ce96a38b7ec28335fed1713eeeed799cbc7d7164cbd596601718a5ec2847daa3ac5f5051f7957779455b637c6b49d45eae7eb7429c393c07
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] util-linux: Update to version 2.42.3
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (26 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] tzdata: Update to version 2026d Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] vim: Update to version 9.2.1091 Adolf Belka
2026-09-13 17:12 ` [PATCH] xz: Update to version 5.8.4 Adolf Belka
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 2.42 to 2.42.3
- No change in any rootfiles
- 5 CVE fixes in 2.42.3
- Changelog
2.42.3
Security fixes:
CVE-2026-53613 - mount(8) TOCTOU race on target path.
The SUID mount does not pin the mount target directory, allowing a
race between path resolution and the actual mount syscall. A local
attacker can swap an ancestor directory component between these
steps to redirect a mount to an arbitrary location.
Reported-by: Xinyao Hu
CVE-2026-53612 - mount(8) TOCTOU race on post-mount owner/mode change.
The X-mount.owner, X-mount.group, and X-mount.mode options use
path-based lchown()/chmod() after mounting. An attacker can swap
the target between mount and the ownership/mode change to gain
control of arbitrary files.
Reported-by: Xinyao Hu
CVE-2026-53614 - mount(8) SUID bypass via LIBMOUNT_FORCE_MOUNT2.
The environment variable LIBMOUNT_FORCE_MOUNT2 is not filtered
via safe_getenv() in SUID context. A local attacker can force
the legacy mount(2) code path, which uses a two-step bind+remount
or propagation sequence with a window where security flags (nosuid,
noexec, ...) are not yet applied.
Reported-by: Xinyao Hu
CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device (follow-up).
The v2.42.1 fix used O_NOFOLLOW which only rejects symlinks at the
last path component. This update uses openat2(RESOLVE_NO_SYMLINKS)
to reject symlinks at any component of the backing file path.
CVE-2026-13595 - libblkid: use-after-free in nested partition probing.
The partitions list stores partitions in a contiguous array grown by
reallocarray(). When the array is reallocated, all existing
blkid_partition pointers become dangling.
Reported-by: Thai Duong
Backward incompatible changes:
The security fixes above harden the SUID mount(8) against TOCTOU
attacks. As a side effect, the following features are restricted
for non-root users:
X-mount.subdir=
Restricted to Linux >= 6.15 for non-root users. The old-kernel
implementation uses namespace unsharing and string-based
move_mount() which is unsafe (TOCTOU). The safe detached subdir
open is available only on Linux >= 6.15.
X-mount.nocanonicalize
Ignored for non-root users. Paths must always be canonicalized
in restricted mode to ensure safe target resolution before
fd pinning.
LIBMOUNT_FORCE_MOUNT2=
Ignored in SUID context (filtered via safe_getenv()).
Additionally, multi-step mount(2) sequences (bind+remount and
propagation changes) are refused for non-root users in the
legacy mount path because the two-step approach has a window
where security flags (nosuid, noexec, ...) are not yet applied.
The new mount API (fsopen/fsconfig/fsmount) handles this
atomically and is not affected.
Changes:
asciidoctor:
- fix encoding error for non-ASCII translations (by Karel Zak)
docs:
- setpriv improve EXAMPLES section (by Karel Zak)
fdisk-list:
- fix memory leak when partition returns empty string (by Leefancy)
- fix memory leak in partition listing (by Leefancy)
fsck.minix:
- bound namelen guessed in get_dirsize (by aizu-m)
hexdump:
- fix buffer overflow in color_cond() (by Karel Zak)
include/mountutils.h:
- fix LSMT_ROOT definition (by Shubham Chakraborty)
lib:
- (pidutils.c) allow zero and negative numbers for PIDs (by Christian Goeschel Ndjomouo)
libblkid:
- fix use-after-free in nested partition probing (by Karel Zak)
libfdisk:
- fix use of on-disk sizeof_partition_entry in GPT (by Karel Zak)
lib/fileutils:
- add ul_open_no_symlinks() (by Karel Zak)
libmount:
- add mount ID verification and man page TOCTOU note (by Karel Zak)
- use fd_target in hook_idmap for move_mount() (by Karel Zak)
- restrict X-mount.subdir for non-root to Linux >= 6.15 (by Karel Zak)
- use fd-based fchownat/chmod in hook_owner (by Karel Zak)
- ignore X-mount.nocanonicalize for restricted users (by Karel Zak)
- add fd_target to context for TOCTOU prevention (by Karel Zak)
- fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (by Karel Zak)
- detect fanotify queue overflow in monitor (by Karel Zak)
- fix subvolid buffer overflow in get_btrfs_fs_root (by aizu-m)
loopdev:
- use openat2(RESOLVE_NO_SYMLINKS) for backing file (by Karel Zak)
lscpu:
- free cputype ISA string (by Zephyr Li)
lslogins:
- bound lastlog2 tty/host copy to destination size (by aizu-m)
nsenter:
- Fix invalid fd check in enter_namespaces (by Vladimir Riabchun)
pam_lastlog2:
- fix libpam linking in autotools build (by Karel Zak)
readprofile:
- replace popen() with fork/exec for .gz map files (by Karel Zak)
tests:
- (hexdump) use arrays for OPTS and ADDRFMT (by Karel Zak)
- mkswap file-existing subtest add explicit page size (by Karel Zak)
2.42.1
getty:
- Always call chdir after chroot (by Tobias Stoeckmann)
autotools:
- Fix setpriv build with econf (by Tobias Stoeckmann)
bits:
- use getline() to avoid stdin input truncation (by WanBingjiang)
- prevent unsigned integer underflow and long-lived loop (by Christian Goeschel Ndjomouo)
build:
- (copyfilerange) include syscall header check for fallback (by Christian Goeschel Ndjomouo)
- Fix --disable-copyfilerange (by Tobias Stoeckmann)
build-sys:
- drop libcommon_shells from binaries that only need ul_default_shell (by Karel Zak)
cfdisk:
- fix memory leak of original_layout table (by Karel Zak)
chrt:
- Fix confusing error messages when priority argument is required (by Rong Zhang)
- Only show current scheduling policy when pid is given (by Rong Zhang)
- pass correct integer types to printf (by Thomas Weißschuh)
- (man) explain which kernel config options are needed for SCHED_EXT (by Christian Goeschel Ndjomouo)
ci:
- use GCC 15 (by Thomas Weißschuh)
- run 'make checkusage' only for autotools build (by Thomas Weißschuh)
CI:
- replace ntp with ntpsec (by Karel Zak)
column:
- fix missing out-of-bounds check in table reordering (by Christian Goeschel Ndjomouo)
copyfilerange:
- (man) fix swapped offsets in command example (by Štěpán Němec)
dmesg:
- fix out-of-bounds read when parsing malformed kmsg file (by WanBingjiang)
docs:
- clarify wipefs --force description for partition-table signatures (by AndyLau-SOC)
eject:
- tolerate ILLEGAL REQUEST on ALLOW_MEDIUM_REMOVAL (by Alessandro Ratti)
fallocate:
- (man) mention supported file systems for --insert-range (by Christian Goeschel Ndjomouo)
fdisk:
- fix trailing whitespace in user reply from readline completion (by Leonid Znamenok)
fincore:
- (tests) fix tmpfs detection for out-of-tree builds (by Leonid Znamenok)
flock:
- re-enable the initial shell selection logic (by Christian Goeschel Ndjomouo)
fsck.minix(man):
- Fix asciidoctor table (by Tobias Stoeckmann)
hardlink:
- avoid format string error for dev_t (by Thomas Weißschuh)
include:
- (fileutils.h) add fallback for the copy_file_range syscall (by Christian Goeschel Ndjomouo)
ipcutils:
- use memset explicitly to fill bpf_attr with zero (by Masatake YAMATO)
irqtop:
- add vw_printw() fallback for slang builds (by Karel Zak)
irqtop/lsirq:
- Handle EOF in get_irqinfo (by Tobias Stoeckmann)
last:
- fix phantom detection for unset loginuid and X11 sessions (by Karel Zak)
lib:
- split ul_default_shell() from shells.c into default_shell.c (by Karel Zak)
- (cpuset.c) dont calculate allocation size for 0 ncpus (by Christian Goeschel Ndjomouo)
libblkid:
- Fix typo in probe_zfs (by Tobias Stoeckmann)
- Fix type access in zfs_extract_guid_name (by Tobias Stoeckmann)
- Fix debug OOB read in zfs_process_value (by Tobias Stoeckmann)
- Fix parse_dev debug output (by Tobias Stoeckmann)
- Ignore secondary LUKS2 header in blkid_do_safeprobe() (by silentcreek)
- reiserfs add block size validation for reiser4 (by Karel Zak)
- erofs validate blkszbits before checksum calculation (by Karel Zak)
- exfs avoid 32-bit overflow in rextsize validation (by Karel Zak)
- solaris use 64-bit for partition offset calculations (by Karel Zak)
- bsd use 64-bit for partition offset calculations (by Karel Zak)
- mac use 64-bit for partition offset calculations (by Karel Zak)
- dos use 64-bit for partition offset calculations (by Karel Zak)
- udf avoid 32-bit overflow in offset calculations (by Karel Zak)
- vfat avoid 32-bit overflow in offset calculations (by Karel Zak)
- ubi fix probe return values (by Karel Zak)
- f2fs tighten log_blocksize validation (by Karel Zak)
- nilfs fix byte order and block size validation (by Karel Zak)
- gpt fix wiper offset to use sector size (by Karel Zak)
- udf cap descriptor sequence iteration count (by Karel Zak)
- bcache add missing NULL check (by Karel Zak)
- bsd read enough data to cover disklabel struct (by Karel Zak)
- befs improve bounds checking in B+ tree search (by Karel Zak)
- ntfs improve integer overflow checks (by Karel Zak)
- introduce sysfs_devno_is_dm_hidden() for pre-open check (by Zdenek Kabelac)
libcommon:
- move pidfd-utils.c to Linux-only sources (by Karel Zak)
liblastlog2:
- (tests) avoid log spam (by Thomas Weißschuh)
- wait on busy SQLite connections (by WanBingjiang)
libmount:
- return btrfs rootfs from get_btrfs_fs_root() (by Karel Zak)
- use match_source for mountinfo comparison (by Karel Zak)
lib/pidutils, lib/pidfd-utils:
- use _() instead of N_() in err() calls (by Karel Zak)
lib/pwdutils:
- fix compiler warning [-Werror=maybe-uninitialized] (by Karel Zak)
libsmartcols:
- drop superfluous call yo yylex_init() (by Thomas Weißschuh)
- (tests) fix failure reporting in filter test (by Thomas Weißschuh)
- (tests) fix filter test name (by Thomas Weißschuh)
- Ignore -Wsign-compare in filter-scanner.l (by Thomas Weißschuh)
libuser:
- fix misleading error message (by Christian Goeschel Ndjomouo)
login:
- Clean up PAM resources on error path (by Tobias Stoeckmann)
login-utils/auth:
- Drop pam_setcred (by Tobias Stoeckmann)
lsblk(man):
- Add COLORS section (by Tobias Stoeckmann)
lsclocks:
- add missing newline character in option description (by Christian Goeschel Ndjomouo)
lscpu(man):
- Move options into correct section (by Tobias Stoeckmann)
lsfd:
- use memset explicitly to fill bpf_attr with zero (by Masatake YAMATO)
meson:
- check slang headers only when slang library is found (by Karel Zak)
- rename logindefs_c to lib_common_logindefs (by Karel Zak)
- split shells.c out of lib_common into lib_common_shells (by Karel Zak)
- respect build-dmesg for test_dmesg (by Thomas Weißschuh)
- test for statx::stx_mnt_id in sys/stat.h (by Thomas Weißschuh)
mkfs.cramfs:
- Consider -i only once (by Tobias Stoeckmann)
- Add -p padding only once (by Tobias Stoeckmann)
- Improve file size check (by Tobias Stoeckmann)
mkswap:
- Fix --file chmod(2) check when file exists (by Johannes Wüller)
more:
- align MORE_SHELL_LINES semantics with less(1) (by Karel Zak, Christian Goeschel Ndjomouo)
newgrp:
- Correctly handle getline error (by Tobias Stoeckmann)
nsenter:
- Fix AT_HANDLE_FID on musl (by Aleksi Hannula)
pidfd-utils:
- Fix pidfd_get_inode declaration (by Tobias Stoeckmann)
po:
- merge changes (by Karel Zak)
- update ro.po (from translationproject.org) (by Remus-Gabriel Chelu)
- update pt.po (from translationproject.org) (by Pedro Albuquerque)
- update pl.po (from translationproject.org) (by Jakub Bogusz)
- update ja.po (from translationproject.org) (by YOSHIDA Hideki)
- update et.po (from translationproject.org) (by Toomas Soome)
- update cs.po (from translationproject.org) (by Petr Písař)
po-man:
- merge changes (by Karel Zak)
- update ro.po (from translationproject.org) (by Remus-Gabriel Chelu)
po-man/po4a:
- Add missing manual pages (by Tobias Stoeckmann)
readprofile:
- (man) clarify not designed for privilege-elevation use (by Karel Zak)
script:
- fix "--" separator when used as option argument (by Karel Zak)
- fix command and command_norm memory leaks (by Karel Zak)
- fix backward compatibility for options after non-option args (by Karel Zak)
scriptreplay(man):
- Add right arrow documentation (by koraynilay)
strutils:
- fix printf formats (by Thomas Weißschuh)
su:
- Clean up PAM resources on all error paths (by Tobias Stoeckmann)
- fix grammar on man page (by Christian Goeschel Ndjomouo)
su-common:
- revert "su pass arguments after <user> to shell" (by Christian Goeschel Ndjomouo)
terminal-colors.d:
- (man) re-apply improvements lost in merge (by Benno Schulenberg)
tests:
- (lsfd/mkfds-udp*) make UDPLite related test cases skippable (by Masatake YAMATO)
- (lsfd/option-inet{,-udp}) make UDPLite related test case skippable (by Masatake YAMATO)
- (lsfd) add a function checking the availability of UDPLite socket (by Masatake YAMATO)
- (lsfd::mkfds-udp) fix confusion between UDP and UDPLite (by Masatake YAMATO)
- (test_mkfds) use memset explicitly to fill bpf_attr with zero (by Masatake YAMATO)
- (ipcs/limits) skip when /proc/sys/kernel is read-only (by Karel Zak)
- (bits) add --width tests for invalid values (by Christian Goeschel Ndjomouo)
- add btrfs RAID is-mounted test for libmount (by Karel Zak)
tests/functions.sh:
- consider '+' for metadata in kernel version parsing (by Christian Goeschel Ndjomouo)
tools:
- (compare-buildsys) suppress common lines in diff output (by Karel Zak)
tools/git-tp-sync:
- update po4a.cfg language list on sync (by Karel Zak)
write:
- cleanup indentation and whitespace (by Karel Zak)
- use mem2strcpy() for utmp strings (by Karel Zak)
- always use utmp as fallback (by Karel Zak)
write, mesg:
- add S_ISCHR() check for terminal device paths (by Karel Zak)
Misc:
- Remove obsolete comment since 2015 (by Julien Nabet)
- Link against libcommon_logindefs.la and libcommon_shells.la (by Stanislav Brabec)
- Fix build with libeconf (by Stanislav Brabec)
- [po-man] Add missing languages to po4a.cfg (by Mario Blättermann)
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
lfs/util-linux | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/lfs/util-linux b/lfs/util-linux
index cf551f9c2..6b1ac6f67 100644
--- a/lfs/util-linux
+++ b/lfs/util-linux
@@ -24,7 +24,7 @@
include Config
-VER = 2.42
+VER = 2.42.3
# https://www.kernel.org/pub/linux/utils/util-linux/
THISAPP = util-linux-$(VER)
@@ -43,7 +43,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 531b79bbec272cf1007c55ff4042b5e1b14bcc0dc098e54e4b76ea2e70c785fc763f96686ad8cea5ea9c0f7190794f4d828b7742e3aa18a0c3ef506d34e9d465
+$(DL_FILE)_BLAKE2 = fcb9fb7f522cabebb4813c78d56115d4516371922f9a4c8e2036d3622ed427d6c0897bca7a60b2176297ff08b6a4f28b85d09509462d3aac4cd73b863402eed6
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] vim: Update to version 9.2.1091
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (27 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] util-linux: Update to version 2.42.3 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
2026-09-13 17:12 ` [PATCH] xz: Update to version 5.8.4 Adolf Belka
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 9.2.0769 to 9.2.1091
- Update of rootfile
- Changelog is not available. Generally each patch version number update is related to
a commit entry in the git repository. The details for all the commit changes can be
found at https://github.com/vim/vim/commits/master/
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/common/vim | 22 ++++++++++++++++++++++
lfs/vim | 4 ++--
2 files changed, 24 insertions(+), 2 deletions(-)
diff --git a/config/rootfiles/common/vim b/config/rootfiles/common/vim
index 322aa52d8..67c6cffa7 100644
--- a/config/rootfiles/common/vim
+++ b/config/rootfiles/common/vim
@@ -133,6 +133,7 @@ usr/share/vim
#usr/share/vim/vim92/colors/lunaperche.vim
#usr/share/vim/vim92/colors/morning.vim
#usr/share/vim/vim92/colors/murphy.vim
+#usr/share/vim/vim92/colors/novum.vim
#usr/share/vim/vim92/colors/pablo.vim
#usr/share/vim/vim92/colors/peachpuff.vim
#usr/share/vim/vim92/colors/quiet.vim
@@ -199,6 +200,7 @@ usr/share/vim
#usr/share/vim/vim92/compiler/haml.vim
#usr/share/vim/vim92/compiler/hare.vim
#usr/share/vim/vim92/compiler/hp_acc.vim
+#usr/share/vim/vim92/compiler/iar.vim
#usr/share/vim/vim92/compiler/icc.vim
#usr/share/vim/vim92/compiler/icon.vim
#usr/share/vim/vim92/compiler/ifort.vim
@@ -478,6 +480,7 @@ usr/share/vim
#usr/share/vim/vim92/ftplugin/awk.vim
#usr/share/vim/vim92/ftplugin/bash.vim
#usr/share/vim/vim92/ftplugin/basic.vim
+#usr/share/vim/vim92/ftplugin/bazelrc.vim
#usr/share/vim/vim92/ftplugin/bdf.vim
#usr/share/vim/vim92/ftplugin/beancount.vim
#usr/share/vim/vim92/ftplugin/bicep-params.vim
@@ -581,6 +584,7 @@ usr/share/vim
#usr/share/vim/vim92/ftplugin/gitconfig.vim
#usr/share/vim/vim92/ftplugin/gitignore.vim
#usr/share/vim/vim92/ftplugin/gitrebase.vim
+#usr/share/vim/vim92/ftplugin/gitrevlist.vim
#usr/share/vim/vim92/ftplugin/gitsendemail.vim
#usr/share/vim/vim92/ftplugin/gleam.vim
#usr/share/vim/vim92/ftplugin/go.vim
@@ -603,6 +607,8 @@ usr/share/vim
#usr/share/vim/vim92/ftplugin/heex.vim
#usr/share/vim/vim92/ftplugin/help.vim
#usr/share/vim/vim92/ftplugin/hgcommit.vim
+#usr/share/vim/vim92/ftplugin/hip.vim
+#usr/share/vim/vim92/ftplugin/hlsl.vim
#usr/share/vim/vim92/ftplugin/hlsplaylist.vim
#usr/share/vim/vim92/ftplugin/hog.vim
#usr/share/vim/vim92/ftplugin/hostconf.vim
@@ -625,12 +631,14 @@ usr/share/vim
#usr/share/vim/vim92/ftplugin/javacc.vim
#usr/share/vim/vim92/ftplugin/javascript.vim
#usr/share/vim/vim92/ftplugin/javascriptreact.vim
+#usr/share/vim/vim92/ftplugin/jinja.vim
#usr/share/vim/vim92/ftplugin/jjdescription.vim
#usr/share/vim/vim92/ftplugin/jproperties.vim
#usr/share/vim/vim92/ftplugin/jq.vim
#usr/share/vim/vim92/ftplugin/json.vim
#usr/share/vim/vim92/ftplugin/json5.vim
#usr/share/vim/vim92/ftplugin/jsonc.vim
+#usr/share/vim/vim92/ftplugin/jsonld.vim
#usr/share/vim/vim92/ftplugin/jsonnet.vim
#usr/share/vim/vim92/ftplugin/jsp.vim
#usr/share/vim/vim92/ftplugin/julia.vim
@@ -759,6 +767,7 @@ usr/share/vim
#usr/share/vim/vim92/ftplugin/r.vim
#usr/share/vim/vim92/ftplugin/racc.vim
#usr/share/vim/vim92/ftplugin/racket.vim
+#usr/share/vim/vim92/ftplugin/radvd.vim
#usr/share/vim/vim92/ftplugin/raku.vim
#usr/share/vim/vim92/ftplugin/rasi.vim
#usr/share/vim/vim92/ftplugin/readline.vim
@@ -771,6 +780,7 @@ usr/share/vim
#usr/share/vim/vim92/ftplugin/rmd.vim
#usr/share/vim/vim92/ftplugin/rnc.vim
#usr/share/vim/vim92/ftplugin/rnoweb.vim
+#usr/share/vim/vim92/ftplugin/robot.vim
#usr/share/vim/vim92/ftplugin/roc.vim
#usr/share/vim/vim92/ftplugin/routeros.vim
#usr/share/vim/vim92/ftplugin/rpl.vim
@@ -961,6 +971,8 @@ usr/share/vim
#usr/share/vim/vim92/indent/handlebars.vim
#usr/share/vim/vim92/indent/hare.vim
#usr/share/vim/vim92/indent/hcl.vim
+#usr/share/vim/vim92/indent/hip.vim
+#usr/share/vim/vim92/indent/hlsl.vim
#usr/share/vim/vim92/indent/hog.vim
#usr/share/vim/vim92/indent/html.vim
#usr/share/vim/vim92/indent/htmldjango.vim
@@ -974,6 +986,7 @@ usr/share/vim
#usr/share/vim/vim92/indent/json.vim
#usr/share/vim/vim92/indent/json5.vim
#usr/share/vim/vim92/indent/jsonc.vim
+#usr/share/vim/vim92/indent/jsonld.vim
#usr/share/vim/vim92/indent/jsp.vim
#usr/share/vim/vim92/indent/julia.vim
#usr/share/vim/vim92/indent/just.vim
@@ -1347,6 +1360,7 @@ usr/share/vim
#usr/share/vim/vim92/syntax/baan.vim
#usr/share/vim/vim92/syntax/bash.vim
#usr/share/vim/vim92/syntax/basic.vim
+#usr/share/vim/vim92/syntax/bazelrc.vim
#usr/share/vim/vim92/syntax/bc.vim
#usr/share/vim/vim92/syntax/bdf.vim
#usr/share/vim/vim92/syntax/beancount.vim
@@ -1467,6 +1481,7 @@ usr/share/vim
#usr/share/vim/vim92/syntax/dylanintr.vim
#usr/share/vim/vim92/syntax/dylanlid.vim
#usr/share/vim/vim92/syntax/ecd.vim
+#usr/share/vim/vim92/syntax/ed.vim
#usr/share/vim/vim92/syntax/edif.vim
#usr/share/vim/vim92/syntax/editorconfig.vim
#usr/share/vim/vim92/syntax/eiffel.vim
@@ -1522,6 +1537,7 @@ usr/share/vim
#usr/share/vim/vim92/syntax/gitignore.vim
#usr/share/vim/vim92/syntax/gitolite.vim
#usr/share/vim/vim92/syntax/gitrebase.vim
+#usr/share/vim/vim92/syntax/gitrevlist.vim
#usr/share/vim/vim92/syntax/gitsendemail.vim
#usr/share/vim/vim92/syntax/gkrellmrc.vim
#usr/share/vim/vim92/syntax/gleam.vim
@@ -1562,7 +1578,9 @@ usr/share/vim
#usr/share/vim/vim92/syntax/hercules.vim
#usr/share/vim/vim92/syntax/hex.vim
#usr/share/vim/vim92/syntax/hgcommit.vim
+#usr/share/vim/vim92/syntax/hip.vim
#usr/share/vim/vim92/syntax/hitest.vim
+#usr/share/vim/vim92/syntax/hlsl.vim
#usr/share/vim/vim92/syntax/hlsplaylist.vim
#usr/share/vim/vim92/syntax/hog.vim
#usr/share/vim/vim92/syntax/hollywood.vim
@@ -1611,6 +1629,7 @@ usr/share/vim
#usr/share/vim/vim92/syntax/json.vim
#usr/share/vim/vim92/syntax/json5.vim
#usr/share/vim/vim92/syntax/jsonc.vim
+#usr/share/vim/vim92/syntax/jsonld.vim
#usr/share/vim/vim92/syntax/jsp.vim
#usr/share/vim/vim92/syntax/julia.vim
#usr/share/vim/vim92/syntax/just.vim
@@ -1677,6 +1696,7 @@ usr/share/vim
#usr/share/vim/vim92/syntax/manual.vim
#usr/share/vim/vim92/syntax/maple.vim
#usr/share/vim/vim92/syntax/markdown.vim
+#usr/share/vim/vim92/syntax/marko.vim
#usr/share/vim/vim92/syntax/masm.vim
#usr/share/vim/vim92/syntax/mason.vim
#usr/share/vim/vim92/syntax/master.vim
@@ -1822,6 +1842,7 @@ usr/share/vim
#usr/share/vim/vim92/syntax/racc.vim
#usr/share/vim/vim92/syntax/racket.vim
#usr/share/vim/vim92/syntax/radiance.vim
+#usr/share/vim/vim92/syntax/radvd.vim
#usr/share/vim/vim92/syntax/raku.vim
#usr/share/vim/vim92/syntax/raml.vim
#usr/share/vim/vim92/syntax/rapid.vim
@@ -1950,6 +1971,7 @@ usr/share/vim
#usr/share/vim/vim92/syntax/structurizr.vim
#usr/share/vim/vim92/syntax/stylus.vim
#usr/share/vim/vim92/syntax/sudoers.vim
+#usr/share/vim/vim92/syntax/svelte.vim
#usr/share/vim/vim92/syntax/svg.vim
#usr/share/vim/vim92/syntax/svn.vim
#usr/share/vim/vim92/syntax/swayconfig.vim
diff --git a/lfs/vim b/lfs/vim
index a389c3995..622148df6 100644
--- a/lfs/vim
+++ b/lfs/vim
@@ -24,7 +24,7 @@
include Config
-VER = 9.2.0769
+VER = 9.2.1091
THISAPP = vim-$(VER)
DL_FILE = $(THISAPP).tar.gz
@@ -44,7 +44,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 99a2221fd39bab66365980a76f2c0fc14e2d1c7518e6b03806f11a5da55cceaaadbc2291ce5a9e67be2913d2f9f5937961d87dfb61c1d77559e57c9e51464017
+$(DL_FILE)_BLAKE2 = 7201f502d092d1c20a94eb0990251f4889bc32f8a2059c04b4881bb68ac3ab5e22ab0a156b8fdbcace8bb6dbe2e7a5f3c3b093d2a73f94c3dd002f92214fbb81
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
* [PATCH] xz: Update to version 5.8.4
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
` (28 preceding siblings ...)
2026-09-13 17:12 ` [PATCH] vim: Update to version 9.2.1091 Adolf Belka
@ 2026-09-13 17:12 ` Adolf Belka
29 siblings, 0 replies; 31+ messages in thread
From: Adolf Belka @ 2026-09-13 17:12 UTC (permalink / raw)
To: development; +Cc: Adolf Belka
- Update from version 5.8.3 to 5.8.4
- Update of rootfile
- 1 GHSA security fix
- Changelog
5.8.4
IMPORTANT: This includes a fix for a security issue that affects all
XZ Utils versions since 5.0.0. This and a few other fixes have also
been committed to the old stable branches (v5.2, v5.4, and v5.6) in
the xz Git repository. Those fixes are marked below. No new 5.2.x,
5.4.x, or 5.6.x releases will be made.
* liblzma:
- lzma_alone_decoder(), lzma_lzip_decoder(),
lzma_auto_decoder(), and lzma_microlzma_decoder(): Fix an
invalid memory access after memory allocation has failed and
the application reinitializes the existing decoder to decode
a different file. This bug could at least result in a crash.
This is tracked as GHSA-5qpq-xqfv-j9pg. CVE number is pending.
(Also in v5.2, v5.4, and v5.6.)
- lzma_stream_buffer_decode(): Fix wrong error code and,
in debug builds, assertion failure. LZMA_BUF_ERROR could
be returned with truncated inputs while LZMA_DATA_ERROR
is the correct one in this function.
(Also in v5.2, v5.4, and v5.6.)
- Fix a performance issue in the typical use case of
lzma_index_cat(). Internally liblzma calls it from
lzma_file_info_decoder(), so that was affected too. The
problem occurred if the input .xz file was created by
concatenating a large number of .xz files. A crafted file
could make "xz --list" very slow or effectively hang.
Normal decompression doesn't use these functions and
thus wasn't affected.
(Also in v5.2, v5.4, and v5.6.)
- Fix a theoretical integer overflow in lzma_index_cat().
(Also in v5.2, v5.4, and v5.6.)
- Fix bogus memory usage report in lzma_index_decoder() when
the .xz Index is obviously invalid. A huge bogus value could
cause an integer overflow in lzma_file_info_decoder()'s
memory usage reporting due to a missing overflow check,
making lzma_memused() report an incorrect tiny value. This
bug didn't affect the memory usage limiter in these two
decoders; only the reporting via lzma_memused() was affected.
(Also in v5.2, v5.4, and v5.6.)
- Fix a too low memory usage report in lzma_index_decoder()
if lzma_memused() is called after a part of the Index has
already been decoded. The typical use case is to call
lzma_memused() immediately after LZMA_MEMLIMIT_ERROR,
which did work correctly.
- Fix copying of check type in lzma_index_dup(). Calling
lzma_index_checks() on the duplicated lzma_index returned
return garbage a result. lzma_index_dup() is rarely used;
liblzma doesn't use it internally and xz itself doesn't use
it either.
(Also in v5.2, v5.4, and v5.6.)
- lzma_file_info_decoder() and lzma_index_decoder(): Reject
an obviously-invalid Number of Records field earlier.
(Partially also in v5.2, v5.4, and v5.6.)
- Fix a missing synchronization in the threaded .xz decoder. It
could make lzma_get_progress() return incorrect progress info.
(Also in v5.4 and v5.6.)
- Detect certain kinds of corrupt inputs slightly earlier in
the LZMA2 decoder.
- ARM64 and LoongArch: Don't use aligned reads on unaligned
buffers. This makes the code work on strict-align processors
and fixes a sanitizer error in other cases. (Since 5.7.1alpha)
* xz:
- Fix a use-after-free when showing an error message if --files
or --files0 was specified in the environment variables XZ_OPT
or XZ_DEFAULTS.
(Also in v5.2, v5.4, and v5.6.)
- Fix a use-after-free bug when --verbose is used and
standard error isn't a terminal. (Since 5.7.1alpha)
- Make it an error if the totals in "xz --list" exceed the range
of 64-bit integers.
(Also in v5.2, v5.4, and v5.6.)
* xz and xzdec on Linux:
- Add support for Landlock ABI version 9.
- Use fallback macros for Landlock ABI version 2, 3, and 5
(but not 4) if <linux/landlock.h> is older than ABI version 5.
This makes the binary slightly more protected if it is run on
a kernel that supports newer ABIs than <linux/landlock.h>.
* Scripts:
- xzgrep: Fix handling of the ' char at the end of a command
line option. For example, the following tricked xzgrep to
run "id": xzgrep "-e'" "-e;id;'" somefile
(Also in v5.2, v5.4, and v5.6.)
- xzdiff: Use the C locale (LC_ALL=C) with "sed" and "expr"
to ensure safe behavior with invalid multibyte sequences.
An equivalent improvement was made in xzgrep in 5.2.6
(2022-08-12), but it was forgotten from xzdiff.
(Also in v5.2, v5.4, and v5.6.)
* Tests:
- Improve a few tests and fuzz targets.
- Add new test files:
* bad-0-index-1.xz (32 bytes)
* bad-1-index-huge-uncomp.xz (72 bytes)
* Man pages:
- Improve the rendering with OpenBSD's mandoc(1).
- Reduce indentation of the tables to avoid overlong lines
in translated versions of the xz man page.
* Translations:
- In translated man pages, workaround an issue with non-ASCII
characters in tables.
- Fix syntax errors in a few man page translations.
- Update Arabic and German man page translations.
- Update Brazilian Portuguese, Croatian, Dutch, German, Italian,
Korean, Polish, Portuguese, Romanian, and Ukrainian message
translations.
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/common/xz | 2 +-
lfs/xz | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/config/rootfiles/common/xz b/config/rootfiles/common/xz
index 5debdf404..d7af0fa4d 100644
--- a/config/rootfiles/common/xz
+++ b/config/rootfiles/common/xz
@@ -41,7 +41,7 @@ usr/bin/xzmore
#usr/lib/liblzma.la
#usr/lib/liblzma.so
usr/lib/liblzma.so.5
-usr/lib/liblzma.so.5.8.3
+usr/lib/liblzma.so.5.8.4
#usr/lib/pkgconfig/liblzma.pc
#usr/share/doc/xz
#usr/share/doc/xz/AUTHORS
diff --git a/lfs/xz b/lfs/xz
index a8de6c5d7..b0c90d790 100644
--- a/lfs/xz
+++ b/lfs/xz
@@ -24,7 +24,7 @@
include Config
-VER = 5.8.3
+VER = 5.8.4
THISAPP = xz-$(VER)
DL_FILE = $(THISAPP).tar.xz
@@ -45,7 +45,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 36d6ae3ce1ee70f1d18d10107f7d6b4dfb43c34e11d8ec4504feeaa50b43cfa8d80de2b8ac2a1b66478723a83b4ebacf4179b69fb4d746f08b120b2e804fc2ce
+$(DL_FILE)_BLAKE2 = 917cd5c0b8bf296d15b6d868a6be3910f73e06f96eb2e17a2064902c3635268a4b0aca9f8c617a402cffc10e06e4e12d998bacf8db81f084cf62e46f3485fb51
install : $(TARGET)
--
2.55.0
^ permalink raw reply [flat|nested] 31+ messages in thread
end of thread, other threads:[~2026-09-13 17:12 UTC | newest]
Thread overview: 31+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-13 17:12 [PATCH] core205: Ship curl Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship iana-etc Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship jansson Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship libksba Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship libpcap Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship liburcu Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship libxml2 Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship pcre2 Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship tzdata Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship util-linux Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship vim Adolf Belka
2026-09-13 17:12 ` [PATCH] core205: Ship xz Adolf Belka
2026-09-13 17:12 ` [PATCH] curl: Update to version 8.22.0 Adolf Belka
2026-09-13 17:12 ` [PATCH] fetchmail: Update to version 6.6.7 Adolf Belka
2026-09-13 17:12 ` [PATCH] frr: Update to version 10.7.1 Adolf Belka
2026-09-13 17:12 ` [PATCH] hwdata: Update to version 0.411 Adolf Belka
2026-09-13 17:12 ` [PATCH] iana-etc: Update to version 20260911 Adolf Belka
2026-09-13 17:12 ` [PATCH] jansson: Update to version 2.15.1 Adolf Belka
2026-09-13 17:12 ` [PATCH] libcap-ng: Update to version 0.9.6 Adolf Belka
2026-09-13 17:12 ` [PATCH] libksba: Update to version 1.8.1 Adolf Belka
2026-09-13 17:12 ` [PATCH] libpcap: Update to version 1.10.7 Adolf Belka
2026-09-13 17:12 ` [PATCH] liburcu: Update to version 0.15.7 Adolf Belka
2026-09-13 17:12 ` [PATCH] libxml2: Update to version 2.15.4 Adolf Belka
2026-09-13 17:12 ` [PATCH] openvpn: Update to version 2.7.7 Adolf Belka
2026-09-13 17:12 ` [PATCH] pcre2: Update to version 10.48 Adolf Belka
2026-09-13 17:12 ` [PATCH] postfix: Update to version 3.11.7 Adolf Belka
2026-09-13 17:12 ` [PATCH] systemd: Update to version 261.3 Adolf Belka
2026-09-13 17:12 ` [PATCH] tzdata: Update to version 2026d Adolf Belka
2026-09-13 17:12 ` [PATCH] util-linux: Update to version 2.42.3 Adolf Belka
2026-09-13 17:12 ` [PATCH] vim: Update to version 9.2.1091 Adolf Belka
2026-09-13 17:12 ` [PATCH] xz: Update to version 5.8.4 Adolf Belka
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox