diff --git a/pkgs/applications/graphics/sane/backends/default.nix b/pkgs/applications/graphics/sane/backends/default.nix index 02dd36e23d7e..05f67e51cd2a 100644 --- a/pkgs/applications/graphics/sane/backends/default.nix +++ b/pkgs/applications/graphics/sane/backends/default.nix @@ -66,6 +66,16 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-9KKTr7p1vCgvGr6hFY83K5gbL7Ilm4Uzc86JIxv+ahI="; revert = true; }) + + # Fix gphoto2 backend build with glibc 2.43 C23 const-preserving strchr + (fetchpatch { + url = "https://gitlab.com/sane-project/backends/-/commit/d04d17b456d9847021b6df6eb08a3419a75172cf.patch"; + hash = "sha256-4iAzwA+uh8W+xSpUkZgvShQ71kq/OVJ26pKsD1NwiXs="; + }) + (fetchpatch { + url = "https://gitlab.com/sane-project/backends/-/commit/ebd4d82bd7a6b8c57870dbfb492e4c186cf584d8.patch"; + hash = "sha256-vHtv+OMA0f9JR1ReshTg8IOgcZf7cnV7chitRBBCAg4="; + }) ]; postPatch = '' diff --git a/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix b/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix index 3750111eba50..766225ea1da7 100644 --- a/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix +++ b/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix @@ -37,6 +37,7 @@ buildMozillaMach rec { spec = "firefox@${lib.removeSuffix "esr" version}"; }; }; + broken = true; # doesn't build on glibc 2.44 }; tests = { inherit (nixosTests) firefox-esr-140; diff --git a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix index 5febcfeee1e3..d685dda597d3 100644 --- a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix +++ b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix @@ -15,6 +15,7 @@ let sha512, updateScript, applicationName ? "Thunderbird", + broken ? stdenv.buildPlatform.is32bit, }: (buildMozillaMach rec { pname = "thunderbird"; @@ -49,6 +50,7 @@ let ''; meta = { + inherit broken; changelog = "https://www.thunderbird.net/en-US/thunderbird/${version}/releasenotes/"; description = "Full-featured e-mail client"; homepage = "https://www.thunderbird.net/"; @@ -61,7 +63,6 @@ let vcunat ]; platforms = lib.platforms.unix; - broken = stdenv.buildPlatform.is32bit; # since Firefox 60, build on 32-bit platforms fails with "out of memory". # not in `badPlatforms` because cross-compilation on 64-bit machine might work. license = lib.licenses.mpl20; @@ -120,6 +121,8 @@ rec { versionPrefix = "140"; versionSuffix = "esr"; }; + + broken = true; }; } // lib.optionalAttrs config.allowAliases { diff --git a/pkgs/by-name/ae/aerospike/package.nix b/pkgs/by-name/ae/aerospike/package.nix index b90753491800..1818ad0f0e60 100644 --- a/pkgs/by-name/ae/aerospike/package.nix +++ b/pkgs/by-name/ae/aerospike/package.nix @@ -33,6 +33,9 @@ stdenv.mkDerivation (finalAttrs: { zlib ]; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + dontUseCmakeConfigure = true; preBuild = '' diff --git a/pkgs/by-name/al/alsa-scarlett-gui/package.nix b/pkgs/by-name/al/alsa-scarlett-gui/package.nix index e96089a715c6..2215e090c31a 100644 --- a/pkgs/by-name/al/alsa-scarlett-gui/package.nix +++ b/pkgs/by-name/al/alsa-scarlett-gui/package.nix @@ -22,7 +22,10 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-DkfpMK0T67B4mnriignf4hx6Ifddls0rN0SxyfEsPZg="; }; - env.NIX_CFLAGS_COMPILE = toString [ "-Wno-error=deprecated-declarations" ]; + env.NIX_CFLAGS_COMPILE = toString [ + "-Wno-error=deprecated-declarations" + "-Wno-error=discarded-qualifiers" + ]; makeFlags = [ "DESTDIR=\${out}" diff --git a/pkgs/by-name/at/ats2/fix-build-glibc-2.44.patch b/pkgs/by-name/at/ats2/fix-build-glibc-2.44.patch new file mode 100644 index 000000000000..5cc48100c380 --- /dev/null +++ b/pkgs/by-name/at/ats2/fix-build-glibc-2.44.patch @@ -0,0 +1,20 @@ +diff --git a/prelude/CATS/array.cats b/prelude/CATS/array.cats +index 70c7e3e..cec3b1d 100644 +--- a/prelude/CATS/array.cats ++++ b/prelude/CATS/array.cats +@@ -56,6 +56,7 @@ void qsort + void *base, size_t nmemb, size_t size + , int(*compar)(const void *, const void *) + ) ; // end of [qsort] ++#ifndef bsearch + extern + void *bsearch + ( +@@ -64,6 +65,7 @@ void *bsearch + , size_t nmemb, size_t size + , int (*compar)(const void *, const void *) + ) ; // end of [bsearch] ++#endif + // + #define atspre_array_qsort qsort + #define atspre_array_bsearch bsearch diff --git a/pkgs/by-name/at/ats2/package.nix b/pkgs/by-name/at/ats2/package.nix index ea804a173894..4f1e7287ec16 100644 --- a/pkgs/by-name/at/ats2/package.nix +++ b/pkgs/by-name/at/ats2/package.nix @@ -49,6 +49,10 @@ stdenv.mkDerivation rec { sed -i 's/gcc/clang/g' utils/*/DATS/atscc_util.dats ''; + patches = [ + ./fix-build-glibc-2.44.patch + ]; + buildInputs = [ gmp ]; # Disable parallel build, errors: diff --git a/pkgs/by-name/be/beanstalkd/package.nix b/pkgs/by-name/be/beanstalkd/package.nix index bca64619cf03..45228640a9ee 100644 --- a/pkgs/by-name/be/beanstalkd/package.nix +++ b/pkgs/by-name/be/beanstalkd/package.nix @@ -28,6 +28,9 @@ stdenv.mkDerivation (finalAttrs: { hardeningDisable = [ "fortify" ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + makeFlags = [ "PREFIX=${placeholder "out"}" ]; nativeBuildInputs = [ installShellFiles ]; diff --git a/pkgs/by-name/be/bees/package.nix b/pkgs/by-name/be/bees/package.nix index c29b5c0545fa..88c237730baf 100644 --- a/pkgs/by-name/be/bees/package.nix +++ b/pkgs/by-name/be/bees/package.nix @@ -3,6 +3,7 @@ fetchFromGitHub, makeWrapper, nixosTests, + fetchpatch, stdenv, # Build inputs @@ -25,6 +26,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-qaiRWRd9+ElJ40QGOS3AxT2NvF3phQCyPnVz6RfTt8c="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/Zygo/bees/commit/14c82dce8a7e9714d6f9cd03229e0fb55460aa25.patch"; + hash = "sha256-bAYacaS3u01XdlM/8+baD+sMuCOyYDtSis4NvTkx8jk="; + }) + ]; + buildInputs = [ btrfs-progs # for btrfs/ioctl.h util-linux # for uuid.h diff --git a/pkgs/by-name/cd/cdecl/package.nix b/pkgs/by-name/cd/cdecl/package.nix index 8295f1653575..494604a65625 100644 --- a/pkgs/by-name/cd/cdecl/package.nix +++ b/pkgs/by-name/cd/cdecl/package.nix @@ -73,5 +73,6 @@ stdenv.mkDerivation (finalAttrs: { maintainers = with lib.maintainers; [ sigmanificient ]; platforms = lib.platforms.unix; mainProgram = "cdecl"; + broken = true; }; }) diff --git a/pkgs/by-name/cl/clickhouse/generic.nix b/pkgs/by-name/cl/clickhouse/generic.nix index 4616222f3363..ec64d528972a 100644 --- a/pkgs/by-name/cl/clickhouse/generic.nix +++ b/pkgs/by-name/cl/clickhouse/generic.nix @@ -130,6 +130,9 @@ llvmStdenv.mkDerivation (finalAttrs: { postPatch = '' patchShebangs src/ utils/ + + substituteInPlace contrib/liburing-cmake/CMakeLists.txt \ + --replace-fail "set (LIBURING_CONFIG_HAS_OPEN_HOW FALSE)" "set (LIBURING_CONFIG_HAS_OPEN_HOW TRUE)" '' + lib.optionalString stdenv.hostPlatform.isDarwin '' substituteInPlace cmake/tools.cmake \ diff --git a/pkgs/by-name/co/convimg/package.nix b/pkgs/by-name/co/convimg/package.nix index 505ac4ff7dc7..f148bfc9d3d0 100644 --- a/pkgs/by-name/co/convimg/package.nix +++ b/pkgs/by-name/co/convimg/package.nix @@ -42,5 +42,6 @@ stdenv.mkDerivation (finalAttrs: { maintainers = [ ]; platforms = lib.platforms.linux; mainProgram = "convimg"; + broken = true; }; }) diff --git a/pkgs/by-name/co/cowsql/package.nix b/pkgs/by-name/co/cowsql/package.nix index d672b987265c..d524cd0a16db 100644 --- a/pkgs/by-name/co/cowsql/package.nix +++ b/pkgs/by-name/co/cowsql/package.nix @@ -9,6 +9,7 @@ sqlite, incus, nix-update-script, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -22,6 +23,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-7djVcozWklI/0KhDC20df+H3YQbodUZaXBnQT4Ug8oI="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/cowsql/cowsql/commit/7c4d73151969ead4f81077ae243d81396ce67988.patch"; + hash = "sha256-aJkf3egKbF23KNC0feDkxh8gIEupsyDBY3PTKuT6lcQ="; + }) + ]; + nativeBuildInputs = [ autoreconfHook pkg-config diff --git a/pkgs/by-name/cr/criu/package.nix b/pkgs/by-name/cr/criu/package.nix index f96504b19735..f4e0b527fd66 100644 --- a/pkgs/by-name/cr/criu/package.nix +++ b/pkgs/by-name/cr/criu/package.nix @@ -45,6 +45,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/checkpoint-restore/criu/commit/3f3acc3200a23140abaa32a2017ae159d3c2d02c.patch?full_index=1"; hash = "sha256-J8n4TjqjzJLLULnpJdR/6YWa/8moFQMn+wNo4a0otgE="; }) + + # fix build w/ glibc-2.44 + (fetchpatch2 { + url = "https://github.com/checkpoint-restore/criu/commit/a810faba33f43d61372741ed196eafd485546f83.patch?full_index=1"; + hash = "sha256-UHSSC3qI6dvtUAiXNnKXTtuXZYGE0SXpUnQ917SXFaU="; + }) ]; enableParallelBuilding = true; diff --git a/pkgs/by-name/ct/ctx/0001-fix-detections.diff b/pkgs/by-name/ct/ctx/0001-fix-detections.diff deleted file mode 100644 index d2580d0fde1d..000000000000 --- a/pkgs/by-name/ct/ctx/0001-fix-detections.diff +++ /dev/null @@ -1,67 +0,0 @@ -diff -Naur --no-dereference ctx-source-old/configure.sh ctx-source-new/configure.sh ---- ctx-source-old/configure.sh 1969-12-31 21:00:01.000000000 -0300 -+++ ctx-source-new/configure.sh 2023-09-27 19:26:05.403569888 -0300 -@@ -42,15 +42,18 @@ - ENABLE_SWITCH_DISPATCH=1 - - pkg-config sdl2 && HAVE_SDL=1 --pkg-config babl && HAVE_BABL=1 -+ -+pkg-config babl-0.1 && { HAVE_BABL=1; BABL_NAME=babl-0.1; } -+if [ $HAVE_BABL != 1 ]; then -+ pkg-config babl && { HAVE_BABL=1; BABL_NAME=babl; } -+fi -+ - pkg-config libcurl && HAVE_LIBCURL=1 - pkg-config alsa && HAVE_ALSA=1 - pkg-config libdrm && HAVE_KMS=1 - #pkg-config harfbuzz && HAVE_HARFBUZZ=1 - -- -- --ARCH=`uname -m` -+: "${ARCH:="$(uname -m)"}" - - case "$ARCH" in - "x86_64") HAVE_SIMD=1 ;; -@@ -224,8 +227,8 @@ - if [ $HAVE_BABL = 1 ];then - echo "#define CTX_BABL 1 " >> local.conf - echo "#define CTX_ENABLE_CM 1 " >> local.conf -- echo "CTX_CFLAGS+= `pkg-config babl --cflags`" >> build.conf -- echo "CTX_LIBS+= `pkg-config babl --libs` " >> build.conf -+ echo "CTX_CFLAGS+= `pkg-config "${BABL_NAME}" --cflags`" >> build.conf -+ echo "CTX_LIBS+= `pkg-config "${BABL_NAME}" --libs` " >> build.conf - else - echo "#define CTX_BABL 0 " >> local.conf - echo "#define CTX_ENABLE_CM 0 " >> local.conf -@@ -335,7 +338,7 @@ - #echo "Generating build.deps" - #make build.deps 2>/dev/null - --echo -n "configuration summary, architecture $(arch)" -+echo -n "configuration summary, architecture $ARCH" - [ $HAVE_SIMD = 1 ] && echo " SIMD multi-pass" - echo "" - echo "Backends:" -diff -Naur --no-dereference ctx-source-old/Makefile ctx-source-new/Makefile ---- ctx-source-old/Makefile 1969-12-31 21:00:01.000000000 -0300 -+++ ctx-source-new/Makefile 2023-09-27 19:37:23.779830320 -0300 -@@ -206,8 +206,8 @@ - libctx.a: itk.o deps.o $(CTX_OBJS) build.conf Makefile - $(AR) rcs $@ $(CTX_OBJS) deps.o itk.o - libctx.so: $(CTX_OBJS) deps.o itk.o build.conf Makefile -- $(LD) -shared $(LIBS) $(CTX_OBJS) deps.o itk.o $(CTX_LIBS) -o $@ -- #$(LD) --retain-symbols-file=symbols -shared $(LIBS) $? $(CTX_LIBS) -o $@ -+ $(CCC) -shared $(LIBS) $(CTX_OBJS) deps.o itk.o $(CTX_LIBS) -o $@ -+ #$(CCC) --retain-symbols-file=symbols -shared $(LIBS) $? $(CTX_LIBS) -o $@ - - ctx: main.c ctx.h build.conf Makefile $(TERMINAL_OBJS) $(MEDIA_HANDLERS_OBJS) libctx.a - $(CCC) main.c $(TERMINAL_OBJS) $(MEDIA_HANDLERS_OBJS) -o $@ $(CFLAGS) libctx.a $(LIBS) $(CTX_CFLAGS) $(OFLAGS_LIGHT) -lpthread $(CTX_LIBS) -@@ -277,5 +277,5 @@ - for a in `cat itk/css.h | tr ';' ' ' | tr ',' ' ' | tr ')' ' '|tr ':' ' ' | tr '{' ' ' | tr ' ' '\n' | grep 'SQZ_[a-z][0-9a-zA-Z_]*'| sort | uniq`;do b=`echo $$a|tail -c+5|tr '_' '-'`;echo "#define $$a `./squoze/squoze -33 $$b`u // \"$$b\"";done \ - >> $@ - echo '#endif' >> $@ --static.inc: static/* static/*/* tools/gen_fs.sh -+static.inc: static/* tools/gen_fs.sh - ./tools/gen_fs.sh static > $@ diff --git a/pkgs/by-name/ct/ctx/package.nix b/pkgs/by-name/ct/ctx/package.nix deleted file mode 100644 index 37e3ac1582db..000000000000 --- a/pkgs/by-name/ct/ctx/package.nix +++ /dev/null @@ -1,83 +0,0 @@ -{ - lib, - stdenv, - fetchgit, - SDL2, - alsa-lib, - babl, - bash, - curl, - libdrm, # Not documented - pkg-config, - xxd, - enableFb ? false, - nixosTests, -}: - -stdenv.mkDerivation (finalAttrs: { - pname = "ctx"; - version = "0-unstable-2023-09-03"; - - src = fetchgit { - name = "ctx-source"; # because of a dash starting the directory - url = "https://ctx.graphics/.git/"; - rev = "1bac18c152eace3ca995b3c2b829a452085d46fb"; - hash = "sha256-fOcQJ2XCeomdtAUmy0A+vU7Vt325OSwrb1+ccW+gZ38="; - }; - - patches = [ - # Many problematic things fixed - it should be upstreamed somehow: - # - babl changed its name in pkg-config files - # - arch detection made optional - # - LD changed to CCC - # - remove inexistent reference to static/*/* - ./0001-fix-detections.diff - ]; - - postPatch = '' - patchShebangs ./tools/gen_fs.sh - ''; - - nativeBuildInputs = [ - pkg-config - xxd - ]; - - buildInputs = [ - SDL2 - alsa-lib - babl - bash # for ctx-audioplayer - curl - libdrm - ]; - - strictDeps = true; - - env.ARCH = stdenv.hostPlatform.parsed.cpu.arch or stdenv.hostPlatform.parsed.cpu.name; - - configureScript = "./configure.sh"; - configureFlags = lib.optional enableFb "--enable-fb"; - configurePlatforms = [ ]; - dontAddPrefix = true; - dontDisableStatic = true; - - installFlags = [ - "PREFIX=${placeholder "out"}" - ]; - - passthru.tests.test = nixosTests.terminal-emulators.ctx; - - meta = { - homepage = "https://ctx.graphics/"; - description = "Vector graphics terminal"; - longDescription = '' - ctx is an interactive 2D vector graphics, audio, text- canvas and - terminal, with escape sequences that enable a 2D vector drawing API using - a vector graphics protocol. - ''; - license = lib.licenses.gpl3Plus; - maintainers = [ ]; - platforms = lib.platforms.unix; - }; -}) diff --git a/pkgs/by-name/di/diod/package.nix b/pkgs/by-name/di/diod/package.nix index 32b3748bed52..a3127d32ab80 100644 --- a/pkgs/by-name/di/diod/package.nix +++ b/pkgs/by-name/di/diod/package.nix @@ -9,6 +9,7 @@ libcap, perl, ncurses, + fetchpatch, }: let lua = lua5_1; @@ -24,6 +25,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-Fz+qvgw5ipyAcZlWBGkmSHuGrZ95i5OorLN3dkdsYKU="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/chaos/diod/commit/d56db0c55012c8a9ea2d3c72749022292c0f65b8.patch"; + hash = "sha256-wuPok3D3VKiao9NmHYLcccsL+91xVbhUeSDExw17X/E="; + }) + ]; + postPatch = '' sed -i configure.ac -e '/git describe/c ${finalAttrs.version})' ''; diff --git a/pkgs/by-name/dr/dragmap/boost-iterator-range.patch b/pkgs/by-name/dr/dragmap/boost-iterator-range.patch deleted file mode 100644 index bd70eab43f49..000000000000 --- a/pkgs/by-name/dr/dragmap/boost-iterator-range.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff --git a/src/lib/map/Mapper.cpp b/src/lib/map/Mapper.cpp -index 6eaa2c5..781988c 100644 ---- a/src/lib/map/Mapper.cpp -+++ b/src/lib/map/Mapper.cpp -@@ -22,6 +22,7 @@ - //#include "common/Crc32Hw.hpp" - #include "common/DragenLogger.hpp" - #include "map/Mapper.hpp" -+#include - - namespace dragenos { - namespace map { diff --git a/pkgs/by-name/dr/dragmap/cstdint.patch b/pkgs/by-name/dr/dragmap/cstdint.patch deleted file mode 100644 index 6004510d2999..000000000000 --- a/pkgs/by-name/dr/dragmap/cstdint.patch +++ /dev/null @@ -1,73 +0,0 @@ -diff --git a/src/include/map/SeedPosition.hpp b/src/include/map/SeedPosition.hpp -index 30a7d47..c05af16 100644 ---- a/src/include/map/SeedPosition.hpp -+++ b/src/include/map/SeedPosition.hpp -@@ -16,6 +16,7 @@ - #define MAP_SEED_POSITION_HPP - - #include -+#include - - #include "sequences/Seed.hpp" - -diff --git a/src/include/sequences/Read.hpp b/src/include/sequences/Read.hpp -index 460c1cb..c7ff619 100644 ---- a/src/include/sequences/Read.hpp -+++ b/src/include/sequences/Read.hpp -@@ -16,6 +16,7 @@ - #define SEQUENCES_READ_HPP - - #include -+#include - #include - #include - -diff --git a/src/include/sequences/Seed.hpp b/src/include/sequences/Seed.hpp -index a242153..dd4d23b 100644 ---- a/src/include/sequences/Seed.hpp -+++ b/src/include/sequences/Seed.hpp -@@ -16,6 +16,7 @@ - #define SEQUENCES_SEED_HPP - - #include -+#include - #include - - #include "sequences/Read.hpp" -diff --git a/src/lib/sequences/tests/unit/CrcHasherMocks.hpp b/src/lib/sequences/tests/unit/CrcHasherMocks.hpp -index 1866be7..5d9b7d7 100644 ---- a/src/lib/sequences/tests/unit/CrcHasherMocks.hpp -+++ b/src/lib/sequences/tests/unit/CrcHasherMocks.hpp -@@ -2,6 +2,7 @@ - - #include - #include -+#include - #include - #include - -diff --git a/stubs/dragen/src/host/dragen_api/read_group_list.hpp b/stubs/dragen/src/host/dragen_api/read_group_list.hpp -index eefb9ae..623a77f 100644 ---- a/stubs/dragen/src/host/dragen_api/read_group_list.hpp -+++ b/stubs/dragen/src/host/dragen_api/read_group_list.hpp -@@ -14,6 +14,7 @@ - #define __READ_GROUP_LIST_HPP__ - - #include "dragen_exception.hpp" -+#include - class ReadGroupList { - public: - const std::string &getReadGroupName(const uint16_t idx) const { - -diff --git a/stubs/dragen/src/host/metrics/public/run_stats.hpp b/stubs/dragen/src/host/metrics/public/run_stats.hpp -index 998fe4e..9561b0b 100644 ---- a/stubs/dragen/src/host/metrics/public/run_stats.hpp -+++ b/stubs/dragen/src/host/metrics/public/run_stats.hpp -@@ -10,6 +10,7 @@ - #include - #include - #include -+#include - // - // RP: HA! HA! HA! That's what you get when you write code logging to cout all - // over the place! diff --git a/pkgs/by-name/dr/dragmap/getHostVersion.patch b/pkgs/by-name/dr/dragmap/getHostVersion.patch deleted file mode 100644 index ba769c9b09a3..000000000000 --- a/pkgs/by-name/dr/dragmap/getHostVersion.patch +++ /dev/null @@ -1,11 +0,0 @@ -diff --git a/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c b/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c -index cdca3df..5a55699 100644 ---- a/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c -+++ b/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c -@@ -249,7 +249,7 @@ void setDefaultHashParams(hashTableConfig_t* defConfig, const char* destDir, Has - free(dir); - } - -- defConfig->hostVersion = (char*)getHostVersion(0); -+ defConfig->hostVersion = (char*)getHostVersion(); - } diff --git a/pkgs/by-name/dr/dragmap/package.nix b/pkgs/by-name/dr/dragmap/package.nix deleted file mode 100644 index 8f554102db65..000000000000 --- a/pkgs/by-name/dr/dragmap/package.nix +++ /dev/null @@ -1,82 +0,0 @@ -{ - lib, - stdenv, - fetchFromGitHub, - boost, - gtest, - zlib, -}: - -stdenv.mkDerivation (finalAttrs: { - pname = "dragmap"; - version = "1.3.0"; - - src = fetchFromGitHub { - owner = "Illumina"; - repo = "DRAGMAP"; - tag = finalAttrs.version; - fetchSubmodules = true; - hash = "sha256-f1jsOErriS1I/iUS4CzJ3+Dz8SMUve/ccb3KaE+L7U8="; - }; - - nativeBuildInputs = [ boost ]; - buildInputs = [ - gtest - zlib - ]; - - # Latest boost do not need system as a linking flag - postPatch = '' - sed -i 's/system filesystem/filesystem/' config.mk - ''; - - patches = [ - # getHostVersion use an empty parameter list. This is now an error for GC - ./getHostVersion.patch - - # pclose is called on a NULL value. This is no longer allowed since - # https://github.com/bminor/glibc/commit/64b1a44183a3094672ed304532bedb9acc707554 - ./stdio-pclose.patch - - # Add missing include cstdint. Upstream does not accept PR. Issue opened at - # https://github.com/Illumina/DRAGMAP/issues/63 - ./cstdint.patch - - # Missing import in Mapper.cpp - # Issue opened upstream https://github.com/Illumina/DRAGMAP/pull/66 - ./boost-iterator-range.patch - ]; - - env = { - GTEST_INCLUDEDIR = "${gtest.dev}/include"; - CPPFLAGS = "-I ${boost.dev}/include"; - LDFLAGS = "-L ${boost.out}/lib"; - }; - - installPhase = '' - runHook preInstall - - mkdir -p $out/bin - cp build/release/dragen-os $out/bin/ - - runHook postInstall - ''; - - # Tests are launched by default from makefile - doCheck = false; - - meta = { - description = "Open Source version of Dragen mapper for genomics"; - mainProgram = "dragen-os"; - longDescription = '' - DRAGMAP is an open-source software implementation of the DRAGEN mapper, - which the Illumina team created to produce the same results as their - proprietary DRAGEN hardware. - ''; - homepage = "https://github.com/Illumina/DRAGMAP"; - changelog = "https://github.com/Illumina/DRAGMAP/releases/tag/${finalAttrs.version}"; - license = lib.licenses.gpl3; - platforms = [ "x86_64-linux" ]; - maintainers = with lib.maintainers; [ apraga ]; - }; -}) diff --git a/pkgs/by-name/dr/dragmap/stdio-pclose.patch b/pkgs/by-name/dr/dragmap/stdio-pclose.patch deleted file mode 100644 index 74e8d57e9fa5..000000000000 --- a/pkgs/by-name/dr/dragmap/stdio-pclose.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff --git a/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp b/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp -index cd02cd4..c26e9cf 100644 ---- a/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp -+++ b/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp -@@ -57,7 +57,6 @@ int GetDmiValue(const std::string& label, std::string& value) - FILE* dmiOutput = popen("sudo /usr/sbin/dmidecode -t 2", "r"); - if (dmiOutput == NULL) { - perror("dmidecode popen"); -- pclose(dmiOutput); - return -1; - } - diff --git a/pkgs/by-name/dt/dtc/package.nix b/pkgs/by-name/dt/dtc/package.nix index c05cd70b2b4a..c6b4cf138b00 100644 --- a/pkgs/by-name/dt/dtc/package.nix +++ b/pkgs/by-name/dt/dtc/package.nix @@ -73,6 +73,8 @@ stdenv.mkDerivation (finalAttrs: { # Required for installation of Python library and is innocuous otherwise. env.DESTDIR = "/"; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; mesonAutoFeatures = "auto"; mesonFlags = [ diff --git a/pkgs/by-name/ef/efivar/package.nix b/pkgs/by-name/ef/efivar/package.nix index bdc7a06b9503..12ebaf4a7500 100644 --- a/pkgs/by-name/ef/efivar/package.nix +++ b/pkgs/by-name/ef/efivar/package.nix @@ -6,6 +6,7 @@ pkg-config, popt, mandoc, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -33,6 +34,14 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ popt ]; depsBuildBuild = [ buildPackages.stdenv.cc ]; + patches = [ + # fix build with glibc-2.44 + (fetchpatch { + url = "https://github.com/rhboot/efivar/commit/f521cd7f584c95d8308659ab9d89d750e2bd76da.patch"; + hash = "sha256-I19UIS0tNTsEipuoMQPlTEwih1RrYPz9Q4Wy98u1z0Q="; + }) + ]; + makeFlags = [ "prefix=$(out)" "libdir=$(out)/lib" diff --git a/pkgs/by-name/fn/fnc/package.nix b/pkgs/by-name/fn/fnc/package.nix index 2e6b2abcde37..20fcea12bbca 100644 --- a/pkgs/by-name/fn/fnc/package.nix +++ b/pkgs/by-name/fn/fnc/package.nix @@ -28,6 +28,8 @@ stdenv.mkDerivation (finalAttrs: { lib.optionals stdenv.cc.isGNU [ # Needed with GCC 12 "-Wno-error=maybe-uninitialized" + # Fix build w/ glibc-2.44 + "-Wno-error=discarded-qualifiers" ] ); diff --git a/pkgs/by-name/fu/futility/package.nix b/pkgs/by-name/fu/futility/package.nix index 41416f226c2d..061c0ac54249 100644 --- a/pkgs/by-name/fu/futility/package.nix +++ b/pkgs/by-name/fu/futility/package.nix @@ -27,6 +27,8 @@ stdenv.mkDerivation { nss ]; + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + postPatch = '' patchShebangs ./scripts substituteInPlace ./scripts/getversion.sh \ diff --git a/pkgs/by-name/fy/fyi/package.nix b/pkgs/by-name/fy/fyi/package.nix index e1ea4eaed3e9..f30b86444430 100644 --- a/pkgs/by-name/fy/fyi/package.nix +++ b/pkgs/by-name/fy/fyi/package.nix @@ -7,6 +7,7 @@ ninja, dbus, scdoc, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -19,6 +20,15 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-UGkShHziREQTkQUlbFXT1144BiBApFVbCvu5A1DuoMI="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://codeberg.org/dnkl/fyi/commit/0a663c5230f756d1161a11080d1a113664e79c21.patch"; + hash = "sha256-B4RkenK4pDAl0jYCgoZH27yUDt3evAHaYnassLaFvB4="; + excludes = [ "CHANGELOG.md" ]; + }) + ]; + depsBuildBuild = [ pkg-config ]; nativeBuildInputs = [ diff --git a/pkgs/by-name/gr/grub2/package.nix b/pkgs/by-name/gr/grub2/package.nix index 392a6ed6e794..6ab78b82c4eb 100644 --- a/pkgs/by-name/gr/grub2/package.nix +++ b/pkgs/by-name/gr/grub2/package.nix @@ -223,6 +223,9 @@ stdenv.mkDerivation rec { strictDeps = true; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + hardeningDisable = [ "all" ]; separateDebugInfo = !xenSupport; diff --git a/pkgs/by-name/gu/guacamole-server/package.nix b/pkgs/by-name/gu/guacamole-server/package.nix index c79a68bdc5f7..89634c3bc25a 100644 --- a/pkgs/by-name/gu/guacamole-server/package.nix +++ b/pkgs/by-name/gu/guacamole-server/package.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchFromGitHub, - fetchpatch2, pkg-config, autoPatchelfHook, autoreconfHook, @@ -28,13 +27,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "guacamole-server"; - version = "1.6.0-unstable-2025-06-29"; + version = "1.6.0-unstable-2026-08-16"; src = fetchFromGitHub { owner = "apache"; repo = "guacamole-server"; - rev = "f3f5b9d76649ccc24f551cb166c81078f4b5e236"; - hash = "sha256-OjTwAQzKUuXfwZXLsL9XjrJc/0be38CmAGG+CoCeNwk="; + rev = "d3b7828977c63a5b197158d6cbbdaf1846b579fb"; + hash = "sha256-sxZLzF6m35EtfLRHb1+aqR3RF+piOuvPT9w9Hs3cor0="; }; env.NIX_CFLAGS_COMPILE = toString [ diff --git a/pkgs/by-name/he/helix/package.nix b/pkgs/by-name/he/helix/package.nix index e301693489f6..dd0f7662cab0 100644 --- a/pkgs/by-name/he/helix/package.nix +++ b/pkgs/by-name/he/helix/package.nix @@ -68,7 +68,23 @@ let helixTreeSitterGrammars = lib.filterAttrs (drvName: _: lib.hasAttr (lib.removePrefix "tree-sitter-" drvName) lockedGrammars) - (tree-sitter-grammars.overrideScope (lib.composeExtensions lockedVersionsOverlay grammarsOverlay)); + ( + tree-sitter-grammars.overrideScope ( + lib.composeManyExtensions [ + lockedVersionsOverlay + grammarsOverlay + (self: super: { + tree-sitter-perl = super.tree-sitter-perl.overrideAttrs { + postPatch = '' + rm src/bsearch.c + substituteInPlace src/tsp_unicode.h \ + --replace-fail '#include "bsearch.c"' "" + ''; + }; + }) + ] + ) + ); # Dynamic libraries for the grammars always use the `.so` extension, also on Darwin (should use `.dylib`) # See here: https://github.com/helix-editor/helix/pull/14982 diff --git a/pkgs/by-name/he/hexcurse/package.nix b/pkgs/by-name/he/hexcurse/package.nix index b8863337e7bf..7c72389a47e2 100644 --- a/pkgs/by-name/he/hexcurse/package.nix +++ b/pkgs/by-name/he/hexcurse/package.nix @@ -21,6 +21,7 @@ stdenv.mkDerivation (finalAttrs: { env.NIX_CFLAGS_COMPILE = toString [ "-Wno-error=stringop-overflow" "-Wno-error=stringop-truncation" + "-Wno-error=discarded-qualifiers" ]; patches = [ # gcc7 compat diff --git a/pkgs/by-name/ip/ipv6calc/package.nix b/pkgs/by-name/ip/ipv6calc/package.nix index fa460738f960..533ca9257a5d 100644 --- a/pkgs/by-name/ip/ipv6calc/package.nix +++ b/pkgs/by-name/ip/ipv6calc/package.nix @@ -6,6 +6,7 @@ ip2location-c, openssl, perl, + fetchpatch, libmaxminddb ? null, geolite-legacy ? null, }: @@ -30,6 +31,14 @@ stdenv.mkDerivation (finalAttrs: { perl ]; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/pbiering/ipv6calc/commit/9b6aebd3690d93b6c2f9efa9346ec72540b1a718.patch"; + hash = "sha256-Y/XBMWdG2/Pfr/vZ2+RGYGj2JS3mWJwQGkXnKvXHArg="; + }) + ]; + postPatch = '' patchShebangs *.sh */*.sh for i in {,databases/}lib/Makefile.in; do diff --git a/pkgs/by-name/j/j/package.nix b/pkgs/by-name/j/j/package.nix index dd4ed59c1fe4..72b5523589ba 100644 --- a/pkgs/by-name/j/j/package.nix +++ b/pkgs/by-name/j/j/package.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-fW6Tc0UEPYFTgEFMUxZaVm2NU5LNFqszifqOqfdFJZY="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ which ]; buildInputs = [ gmp ]; diff --git a/pkgs/by-name/kr/krb5/package.nix b/pkgs/by-name/kr/krb5/package.nix index 4e97e9867190..9b5b2cc2d628 100644 --- a/pkgs/by-name/kr/krb5/package.nix +++ b/pkgs/by-name/kr/krb5/package.nix @@ -75,7 +75,9 @@ stdenv.mkDerivation (finalAttrs: { # void foo(); # # declaration. - NIX_CFLAGS_COMPILE = "-std=gnu17" + lib.optionalString stdenv.hostPlatform.isStatic " -fcommon"; + NIX_CFLAGS_COMPILE = + "-std=gnu17 -Wno-error=discarded-qualifiers" + + lib.optionalString stdenv.hostPlatform.isStatic " -fcommon"; }; configureFlags = [ diff --git a/pkgs/by-name/kv/kvmtool/package.nix b/pkgs/by-name/kv/kvmtool/package.nix index adfbd884d0e0..f89324a5909d 100644 --- a/pkgs/by-name/kv/kvmtool/package.nix +++ b/pkgs/by-name/kv/kvmtool/package.nix @@ -19,6 +19,9 @@ stdenv.mkDerivation { buildInputs = lib.optionals stdenv.hostPlatform.isAarch64 [ dtc ]; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + enableParallelBuilding = true; makeFlags = [ diff --git a/pkgs/by-name/ld/ldb/package.nix b/pkgs/by-name/ld/ldb/package.nix index 04d9e7d645bd..45e3f142befb 100644 --- a/pkgs/by-name/ld/ldb/package.nix +++ b/pkgs/by-name/ld/ldb/package.nix @@ -17,6 +17,7 @@ buildPackages, libxcrypt, testers, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -33,6 +34,16 @@ stdenv.mkDerivation (finalAttrs: { "dev" ]; + patches = [ + # Fix rep_memset_s calling C23 memset_explicit with wrong arg count (4 instead of 3). + # Upstream samba commit 04e0fb9b2d; later reworked more broadly in ef08be24e9 and 3e81b73a05 + # which replace memset_s with memset_explicit entirely, but those don't apply to ldb 2.9.2. + (fetchpatch { + url = "https://gitlab.com/samba-team/samba/-/commit/04e0fb9b2d1d87516f1331096c78e8355b4fa9f3.patch"; + hash = "sha256-sBqtVwGBXseCAMlv3QaiSYQmOw7H4cAJwc0Ey5yD6Os="; + }) + ]; + nativeBuildInputs = [ pkg-config python3 diff --git a/pkgs/by-name/li/libbladeRF/package.nix b/pkgs/by-name/li/libbladeRF/package.nix index cb340b8bad73..c022cc7b3a34 100644 --- a/pkgs/by-name/li/libbladeRF/package.nix +++ b/pkgs/by-name/li/libbladeRF/package.nix @@ -12,6 +12,7 @@ libusb1, curl, udev, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -29,6 +30,12 @@ stdenv.mkDerivation (finalAttrs: { patches = [ # fix clang build: https://github.com/Nuand/bladeRF/pull/1045 ./clang-fix.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/Nuand/bladeRF/commit/87bdb1a4bbbc45b749bb90db504fe9cf8fe7a595.patch"; + hash = "sha256-/sB18hwBSIqMkjaC7J0rb4STUrq4BWlJKnyy0Szac9c="; + }) ]; nativeBuildInputs = [ diff --git a/pkgs/by-name/li/libfaketime/package.nix b/pkgs/by-name/li/libfaketime/package.nix index 1e9667b83fba..7bc9995e09d8 100644 --- a/pkgs/by-name/li/libfaketime/package.nix +++ b/pkgs/by-name/li/libfaketime/package.nix @@ -34,6 +34,11 @@ stdenv.mkDerivation (finalAttrs: { patches = [ ./nix-store-date.patch + # Fixes build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/wolfcw/libfaketime/commit/dbe865dfdba0145d993d70b7fd4ec88b2f47554b.patch"; + hash = "sha256-pn9MInefa4ZKuOorGEpi/sDQOQamCakjdYOkFSNA2VQ="; + }) ] ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ # GCC 16's unused variable analysis is more advanced than previous diff --git a/pkgs/by-name/li/libmongocrypt/package.nix b/pkgs/by-name/li/libmongocrypt/package.nix index 98efd633bdee..808c8b4d97e7 100644 --- a/pkgs/by-name/li/libmongocrypt/package.nix +++ b/pkgs/by-name/li/libmongocrypt/package.nix @@ -29,6 +29,9 @@ stdenv.mkDerivation (finalAttrs: { }) ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ cmake pkg-config diff --git a/pkgs/by-name/li/librist/package.nix b/pkgs/by-name/li/librist/package.nix index 606b5f6a5acb..21d163f974d5 100644 --- a/pkgs/by-name/li/librist/package.nix +++ b/pkgs/by-name/li/librist/package.nix @@ -34,6 +34,9 @@ stdenv.mkDerivation (finalAttrs: { pkg-config ]; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + buildInputs = [ cjson cmocka diff --git a/pkgs/by-name/li/links2/package.nix b/pkgs/by-name/li/links2/package.nix index d63aab7bc04b..885bfb3c1158 100644 --- a/pkgs/by-name/li/links2/package.nix +++ b/pkgs/by-name/li/links2/package.nix @@ -76,5 +76,6 @@ stdenv.mkDerivation (finalAttrs: { mainProgram = "links"; license = lib.licenses.gpl2Plus; platforms = lib.platforms.unix; + broken = true; }; }) diff --git a/pkgs/by-name/li/liquidwar/package.nix b/pkgs/by-name/li/liquidwar/package.nix index 8da0022a3421..35761a6e8d8d 100644 --- a/pkgs/by-name/li/liquidwar/package.nix +++ b/pkgs/by-name/li/liquidwar/package.nix @@ -96,6 +96,8 @@ stdenv.mkDerivation (finalAttrs: { "-Wno-error=address" "-Wno-error=use-after-free" "-std=gnu17" + # Fix build w/ glibc-2.44 + "-Wno-error=discarded-qualifiers" ] ++ [ "-Wno-error=deprecated-declarations" diff --git a/pkgs/by-name/li/livegrep/package.nix b/pkgs/by-name/li/livegrep/package.nix index f2b8d4a47463..3fc784850bae 100644 --- a/pkgs/by-name/li/livegrep/package.nix +++ b/pkgs/by-name/li/livegrep/package.nix @@ -94,7 +94,10 @@ buildBazelPackage { "file://${registry}" ]; - env = lib.optionalAttrs stdenv.hostPlatform.isDarwin { + env = { + NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + } + // lib.optionalAttrs stdenv.hostPlatform.isDarwin { LIBTOOL = "${cctools}/bin/libtool"; }; diff --git a/pkgs/by-name/lo/loudmouth/package.nix b/pkgs/by-name/lo/loudmouth/package.nix index 91155e474d41..a64d6e61f16a 100644 --- a/pkgs/by-name/lo/loudmouth/package.nix +++ b/pkgs/by-name/lo/loudmouth/package.nix @@ -20,7 +20,10 @@ stdenv.mkDerivation (finalAttrs: { configureFlags = [ "--with-ssl=openssl" ]; - env.NIX_CFLAGS_COMPILE = "-Wno-error=deprecated-declarations"; + env.NIX_CFLAGS_COMPILE = toString [ + "-Wno-error=deprecated-declarations" + "-Wno-error=discarded-qualifiers" + ]; propagatedBuildInputs = [ openssl diff --git a/pkgs/by-name/mi/mimic/package.nix b/pkgs/by-name/mi/mimic/package.nix index 931460357fb8..5b158b89ee77 100644 --- a/pkgs/by-name/mi/mimic/package.nix +++ b/pkgs/by-name/mi/mimic/package.nix @@ -55,6 +55,8 @@ stdenv.mkDerivation (finalAttrs: { env.NIX_CFLAGS_COMPILE = toString [ # Needed with GCC 12 "-Wno-error=free-nonheap-object" + # Fix build w/ glibc-2.44 + "-Wno-error=discarded-qualifiers" ]; postInstall = '' diff --git a/pkgs/by-name/mi/mitscheme/package.nix b/pkgs/by-name/mi/mitscheme/package.nix index 8f311d6c15ce..b0be6a25077b 100644 --- a/pkgs/by-name/mi/mitscheme/package.nix +++ b/pkgs/by-name/mi/mitscheme/package.nix @@ -44,6 +44,11 @@ stdenv.mkDerivation { sha256 = "035f92vni0vqmgj9hq2i7vwasz7crx52wll4823vhfkm1qdv5ywc"; }; + postPatch = '' + substituteInPlace "src/microcode/chacha.i" \ + --replace-fail "#define _POSIX_C_SOURCE 200809L" "" + ''; + patches = [ (fetchDebianPatch { pname = "mit-scheme"; diff --git a/pkgs/by-name/ng/ngn-k/package.nix b/pkgs/by-name/ng/ngn-k/package.nix deleted file mode 100644 index 92ab2e867624..000000000000 --- a/pkgs/by-name/ng/ngn-k/package.nix +++ /dev/null @@ -1,64 +0,0 @@ -{ - lib, - stdenv, - fetchFromCodeberg, - runtimeShell, -}: - -stdenv.mkDerivation { - pname = "ngn-k"; - version = "0-unstable-2025-11-17"; - - src = fetchFromCodeberg { - owner = "ngn"; - repo = "k"; - rev = "717063f24921d5aff405a39cf7643efedb5bb365"; - hash = "sha256-rUMi+VetQc139PjbFJXlSkmYEuK5wtM6LpQ/f1tcB1s="; - }; - - patches = [ - ./repl-license-path.patch - ./repl-argv-1.patch - ]; - - postPatch = '' - # don't use hardcoded /bin/sh - for f in repl.k m.c;do - substituteInPlace "$f" --replace-fail "/bin/sh" "${runtimeShell}" - done - ''; - - makeFlags = [ "-e" ]; - buildFlags = [ - "k" - "libk.so" - ]; - checkTarget = "t"; - doCheck = true; - - outputs = [ - "out" - "dev" - "lib" - ]; - - # TODO(@sternenseemann): package bulgarian translation - installPhase = '' - runHook preInstall - install -Dm755 k "$out/bin/k" - install -Dm755 repl.k "$out/bin/k-repl" - install -Dm755 libk.so "$lib/lib/libk.so" - install -Dm644 k.h "$dev/include/k.h" - install -Dm644 LICENSE -t "$out/share/ngn-k" - substituteInPlace "$out/bin/k-repl" --replace-fail "#!k" "#!$out/bin/k" - runHook postInstall - ''; - - meta = { - description = "Simple fast vector programming language"; - homepage = "https://codeberg.org/ngn/k"; - license = lib.licenses.agpl3Only; - maintainers = [ lib.maintainers.sternenseemann ]; - platforms = lib.platforms.linux ++ lib.platforms.freebsd; - }; -} diff --git a/pkgs/by-name/ng/ngn-k/repl-argv-1.patch b/pkgs/by-name/ng/ngn-k/repl-argv-1.patch deleted file mode 100644 index 0e54a0845e4a..000000000000 --- a/pkgs/by-name/ng/ngn-k/repl-argv-1.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/repl.k b/repl.k -index dc89832c..33780850 100755 ---- a/repl.k -+++ b/repl.k -@@ -28,7 +28,7 @@ joinpath:{$[x~,".";y;"/"~*|x;x,y;x,"/",y]} - line0:{c:{0x07~*-2#*x}{(l;r):x;(1:1;r,,(-2_l))}/(x;());"\n"/(*|c),,*c} - line1:{$[#x;;:0];x:-1_x;$[(3>#x)&("\\"=*x)&~^(!cmds)?x 1;cmds[x 1]x 1;.[`1:(fmt;fmtx)[" "~*x]@.:;,x;{`0:`err[]}]];`1:prompt;1} - line:line1@line0@ --$["repl.k"~basename`argv 1;{cmds::@[cmds;x[1]1;:;{y;`0:x}2_x]}'{(&x~\:80#"-")_x:(1+*&x~\:,"/")_-1_x}@0:`argv 1;]; -+$["k-repl"~basename`argv 1;{cmds::@[cmds;x[1]1;:;{y;`0:x}2_x]}'{(&x~\:80#"-")_x:(1+*&x~\:,"/")_-1_x}@0:`argv 1;]; - run:{`1:banner,prompt;{line@1:`}::/`;} - \d . - diff --git a/pkgs/by-name/ng/ngn-k/repl-license-path.patch b/pkgs/by-name/ng/ngn-k/repl-license-path.patch deleted file mode 100644 index d3cd8c781b6b..000000000000 --- a/pkgs/by-name/ng/ngn-k/repl-license-path.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/repl.k b/repl.k -index dc89832c..7a6e0dcf 100755 ---- a/repl.k -+++ b/repl.k -@@ -21,7 +21,7 @@ tbl:{[w;u;x]h:`k'!x;d:`k''.x;W:(#'h)|/'#''d - r,par'dd[w-2]'sem/'+@[W;&~^`i`d?_@'.x;-:]$'d} - cell:{$[|/`i`d=@y;-x;x]$z} - par:{opn,x,cls} --cmds:(,"a")!{`1:1:joinpath[dirname`argv 0]"LICENSE";} -+cmds:(,"a")!{`1:1:joinpath[dirname`argv 0]"../share/ngn-k/LICENSE";} - basename:{*|"/"\x} - dirname:{$[#x:"/"/-1_"/"\x;x;,"."]} - joinpath:{$[x~,".";y;"/"~*|x;x,y;x,"/",y]} diff --git a/pkgs/by-name/nt/ntp/package.nix b/pkgs/by-name/nt/ntp/package.nix index e36dad33bf80..a5ec68840827 100644 --- a/pkgs/by-name/nt/ntp/package.nix +++ b/pkgs/by-name/nt/ntp/package.nix @@ -7,6 +7,7 @@ perl, pps-tools, libcap, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -18,6 +19,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-z4TF8/saKVKElCYk2CP/+mNBROCWz8T5lprJjvX0aOU="; }; + patches = [ + # Fix build w/ glibc-2.44 + (fetchpatch { + url = "https://gitlab.archlinux.org/archlinux/packaging/packages/ntp/-/raw/8513bf75be3c0425318475e30f5725a03d8fb067/ntp-4.2.8.p18-glib-2.43.patch"; + hash = "sha256-20ztNAnirijKt8rgaMz6FGoHubBOskNL5ynXte3NTvM="; + }) + ]; + # fix for gcc-14 compile failure postPatch = '' substituteInPlace sntp/m4/openldap-thread-check.m4 \ diff --git a/pkgs/by-name/oc/ocf-resource-agents/package.nix b/pkgs/by-name/oc/ocf-resource-agents/package.nix index 0807b266aafb..f86d1bb1e9d5 100644 --- a/pkgs/by-name/oc/ocf-resource-agents/package.nix +++ b/pkgs/by-name/oc/ocf-resource-agents/package.nix @@ -63,6 +63,9 @@ let # Needed with GCC 12 but breaks on darwin (with clang) or older gcc "-Wno-error=maybe-uninitialized" ] + ++ [ + "-Wno-error=discarded-qualifiers" + ] ); meta = { diff --git a/pkgs/by-name/od/odhcp6c/package.nix b/pkgs/by-name/od/odhcp6c/package.nix index 2ddedb629ebb..a149d7597435 100644 --- a/pkgs/by-name/od/odhcp6c/package.nix +++ b/pkgs/by-name/od/odhcp6c/package.nix @@ -18,6 +18,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-IDBbVWs017JcrApJ3s8fjEQghWCwrK1d+E6Wp5eHNX4="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ cmake ]; buildInputs = [ libubox ]; diff --git a/pkgs/by-name/od/odp-dpdk/package.nix b/pkgs/by-name/od/odp-dpdk/package.nix index 76b5a869b4e4..c11143fa6c1f 100644 --- a/pkgs/by-name/od/odp-dpdk/package.nix +++ b/pkgs/by-name/od/odp-dpdk/package.nix @@ -34,6 +34,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-L6lF8VaycAz7PcFArAgLhI8+sc0jnAHY3gum/uDIYz4="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ autoreconfHook pkg-config diff --git a/pkgs/by-name/od/odyssey/package.nix b/pkgs/by-name/od/odyssey/package.nix index f776d973e23f..69cfacd289d9 100644 --- a/pkgs/by-name/od/odyssey/package.nix +++ b/pkgs/by-name/od/odyssey/package.nix @@ -25,6 +25,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/yandex/odyssey/commit/51c0e777aa45157f4f03fbd036113ce6d11ca41f.patch?full_index=1"; hash = "sha256-yytyA2K62v7XwJQ+WJnBGh87AVyeOv0cuzlQ7oYnhFg="; }) + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/yandex/odyssey/commit/1edf6bfd05dc34324162fda1b4ca4bc38b1b581c.patch"; + hash = "sha256-Rd/dqmvpY2gJMqg3hX5rXMu3vRjOG5V3QXV/S1M625Q="; + }) ]; nativeBuildInputs = [ cmake ]; diff --git a/pkgs/by-name/op/open-vm-tools/package.nix b/pkgs/by-name/op/open-vm-tools/package.nix index 5835333ae557..06e87eeeb82c 100644 --- a/pkgs/by-name/op/open-vm-tools/package.nix +++ b/pkgs/by-name/op/open-vm-tools/package.nix @@ -150,6 +150,9 @@ stdenv.mkDerivation (finalAttrs: { substituteInPlace udev/99-vmware-scsi-udev.rules \ --replace-fail "/bin/sh" "${bash}/bin/sh" + + substituteInPlace lib/rpcChannel/glib_stubs.c \ + --replace-fail "void g_free(void *p) { free(p); }" "" ''; configureFlags = [ diff --git a/pkgs/by-name/op/openvas-scanner/package.nix b/pkgs/by-name/op/openvas-scanner/package.nix index 8868ea132e0d..72637f8f05f4 100644 --- a/pkgs/by-name/op/openvas-scanner/package.nix +++ b/pkgs/by-name/op/openvas-scanner/package.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-ggmex/BmAVgdE1JNM3kybEmr/uKqrIl8JdSoBnsg+40="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ cmake git diff --git a/pkgs/by-name/or/orbuculum/package.nix b/pkgs/by-name/or/orbuculum/package.nix index 80ce39a2c83f..055a5051937e 100644 --- a/pkgs/by-name/or/orbuculum/package.nix +++ b/pkgs/by-name/or/orbuculum/package.nix @@ -39,6 +39,9 @@ stdenv.mkDerivation (finalAttrs: { popd ''; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ meson ninja diff --git a/pkgs/by-name/or/orcania/package.nix b/pkgs/by-name/or/orcania/package.nix index e034e574341f..be2bc176a70b 100644 --- a/pkgs/by-name/or/orcania/package.nix +++ b/pkgs/by-name/or/orcania/package.nix @@ -5,6 +5,7 @@ cmake, check, subunit, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { pname = "orcania"; @@ -17,6 +18,18 @@ stdenv.mkDerivation (finalAttrs: { sha256 = "sha256-Cz3IE5UrfoWjMxQ/+iR1bLsYxf5DVN+7aJqLBcPjduA="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/babelouest/orcania/commit/ee2f45b5da8b7fb2c747419c17880ccdca14521d.patch"; + hash = "sha256-BNGL2Q5STrrAO8/OKMS4S5GqlikGnvg4hgBwKTMulgU="; + }) + (fetchpatch { + url = "https://github.com/babelouest/orcania/commit/f261393b4dd1b4f50aca389916407e0dfa5f2e55.patch"; + hash = "sha256-KyRedPj5gBFPZmefmjLL49OY8eJNmMyd5jsFsQByTUE="; + }) + ]; + nativeBuildInputs = [ cmake ]; nativeCheckInputs = [ diff --git a/pkgs/by-name/pa/pacemaker/package.nix b/pkgs/by-name/pa/pacemaker/package.nix index 7d670749fe05..ff6d8fc48a7b 100644 --- a/pkgs/by-name/pa/pacemaker/package.nix +++ b/pkgs/by-name/pa/pacemaker/package.nix @@ -111,6 +111,9 @@ stdenv.mkDerivation (finalAttrs: { "-Wno-error=strict-prototypes" "-Wno-error=deprecated-declarations" ] + ++ [ + "-Wno-error=discarded-qualifiers" + ] ); enableParallelBuilding = true; diff --git a/pkgs/by-name/pa/papi/package.nix b/pkgs/by-name/pa/papi/package.nix index 96c0ee99f1ab..164a7b46104a 100644 --- a/pkgs/by-name/pa/papi/package.nix +++ b/pkgs/by-name/pa/papi/package.nix @@ -13,6 +13,9 @@ stdenv.mkDerivation (finalAttrs: { sha256 = "sha256-qb/4nM85kV1yngiuCgxqcc4Ou+mEEemi6zyDyNsK85w="; }; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + setSourceRoot = '' sourceRoot=$(echo */src) ''; diff --git a/pkgs/by-name/pe/pesign/package.nix b/pkgs/by-name/pe/pesign/package.nix index 7fd597e164a8..989062b68f41 100644 --- a/pkgs/by-name/pe/pesign/package.nix +++ b/pkgs/by-name/pe/pesign/package.nix @@ -30,6 +30,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/rhboot/pesign/commit/1f9e2fa0b4d872fdd01ca3ba81b04dfb1211a187.patch?full_index=1"; hash = "sha256-viVM4Z0jAEAWC3EdJVHcWe21aQskH5XE85lOd6Xd/qU="; }) + + # fix build w/ glibc-2.44 + (fetchpatch2 { + url = "https://github.com/rhboot/pesign/commit/419d63a8b6434f94b57730bb8a58a32a0bb199aa.patch?full_index=1"; + hash = "sha256-/o0QknZ1IDFwmsQAt1IENx7tr8WRNJS3wl84cHzprzA="; + }) ]; # nss-util is missing because it is already contained in nss diff --git a/pkgs/by-name/pi/picolibc/package.nix b/pkgs/by-name/pi/picolibc/package.nix index 0bffb8ddd2e9..d9bf1a174531 100644 --- a/pkgs/by-name/pi/picolibc/package.nix +++ b/pkgs/by-name/pi/picolibc/package.nix @@ -1,5 +1,6 @@ { stdenvNoLibc, + fetchpatch, buildPackages, fetchFromGitHub, lib, @@ -34,6 +35,14 @@ stdenvNoLibc.mkDerivation (finalAttrs: { hash = "sha256-FhTNgffsnHbzIXOOwCMe6O1FGkEtqWfw+e30RW+Y4K4="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/picolibc/picolibc/commit/11a46b6ed03c4dca64e0534435da9841e837b160.patch"; + hash = "sha256-i1dKW1L5si0gf0/Sn4sU/BuIof778tvHgCCCY1TxMME="; + }) + ]; + depsBuildBuild = lib.optionals canExecute [ buildPackages.stdenv.cc ]; diff --git a/pkgs/by-name/ps/pspp/fix-glibc-2.42.patch b/pkgs/by-name/ps/pspp/fix-glibc-2.42.patch new file mode 100644 index 000000000000..8bf84cc53a94 --- /dev/null +++ b/pkgs/by-name/ps/pspp/fix-glibc-2.42.patch @@ -0,0 +1,29 @@ +diff --git a/gl/stdlib.in.h b/gl/stdlib.in.h +index bef0aaa..b2e19c3 100644 +--- a/gl/stdlib.in.h ++++ b/gl/stdlib.in.h +@@ -223,7 +223,7 @@ _GL_INLINE_HEADER_BEGIN + + + /* Declarations for ISO C N3322. */ +-#if defined __GNUC__ && __GNUC__ >= 15 && !defined __clang__ ++#if defined __GNUC__ && __GNUC__ >= 15 && !defined __clang__ && !defined(bsearch) + _GL_EXTERN_C void *bsearch (const void *__key, + const void *__base, size_t __nmemb, size_t __size, + int (*__compare) (const void *, const void *)) +diff --git a/gl/wchar.in.h b/gl/wchar.in.h +index ab602a2..a2aa597 100644 +--- a/gl/wchar.in.h ++++ b/gl/wchar.in.h +@@ -301,9 +301,11 @@ _GL_EXTERN_C int wcsncmp (const wchar_t *__s1, const wchar_t *__s2, size_t __n) + _GL_ATTRIBUTE_NONNULL_IF_NONZERO (1, 3) + _GL_ATTRIBUTE_NONNULL_IF_NONZERO (2, 3); + # ifndef __cplusplus ++# if !defined(wmemchr) + _GL_EXTERN_C wchar_t *wmemchr (const wchar_t *__s, wchar_t __wc, size_t __n) + _GL_ATTRIBUTE_NONNULL_IF_NONZERO (1, 3); + # endif ++# endif + _GL_EXTERN_C wchar_t *wmemset (wchar_t *__s, wchar_t __wc, size_t __n) + # if __GLIBC__ + (__GLIBC_MINOR__ >= 2) > 2 + _GL_ATTRIBUTE_NOTHROW diff --git a/pkgs/by-name/ps/pspp/package.nix b/pkgs/by-name/ps/pspp/package.nix index 7585269dc3d5..0cfad65068fd 100644 --- a/pkgs/by-name/ps/pspp/package.nix +++ b/pkgs/by-name/ps/pspp/package.nix @@ -55,10 +55,17 @@ stdenv.mkDerivation rec { iconv ]; + patches = [ + ./fix-glibc-2.42.patch + ]; + env = { C_INCLUDE_PATH = "${libxml2.dev}/include/libxml2/:" + lib.makeSearchPathOutput "dev" "include" buildInputs; LIBRARY_PATH = lib.makeLibraryPath buildInputs; + + # fix build w/ glibc-2.44 + NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; }; doCheck = false; diff --git a/pkgs/by-name/sp/spice-vdagent/package.nix b/pkgs/by-name/sp/spice-vdagent/package.nix index 7c7633f86f2c..48ca54f12f46 100644 --- a/pkgs/by-name/sp/spice-vdagent/package.nix +++ b/pkgs/by-name/sp/spice-vdagent/package.nix @@ -56,6 +56,9 @@ stdenv.mkDerivation (finalAttrs: { systemd ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + meta = { description = "Enhanced SPICE integration for linux QEMU guest"; longDescription = '' diff --git a/pkgs/by-name/su/surge-xt/package.nix b/pkgs/by-name/su/surge-xt/package.nix index bad3fc26ea66..f31724aed58d 100644 --- a/pkgs/by-name/su/surge-xt/package.nix +++ b/pkgs/by-name/su/surge-xt/package.nix @@ -39,6 +39,9 @@ stdenv.mkDerivation (finalAttrs: { ./clap-option.diff ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + postPatch = '' # see https://github.com/NixOS/nixpkgs/pull/149487#issuecomment-991747333 export XDG_DOCUMENTS_DIR=$(mktemp -d) diff --git a/pkgs/by-name/su/suricata/package.nix b/pkgs/by-name/su/suricata/package.nix index b4c2782e8eb2..5dac04bb6ed9 100644 --- a/pkgs/by-name/su/suricata/package.nix +++ b/pkgs/by-name/su/suricata/package.nix @@ -8,7 +8,7 @@ elfutils, file, jansson, - libbpf_0, + libbpf, libcap_ng, libevent, libmaxminddb, @@ -67,7 +67,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ elfutils jansson - libbpf_0 + libbpf libcap_ng libevent libmagic diff --git a/pkgs/by-name/ta/target-isns/package.nix b/pkgs/by-name/ta/target-isns/package.nix index b7c9d8f9eba1..cedaf1f35604 100644 --- a/pkgs/by-name/ta/target-isns/package.nix +++ b/pkgs/by-name/ta/target-isns/package.nix @@ -32,6 +32,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/open-iscsi/target-isns/commit/e209821423f936d1cc9b946fb8f7a8979b8e751b.patch?full_index=1"; hash = "sha256-86nl8wTiI9WSZ+Hhw/a9VtgS8OLqoFwiot5iU5IK0f8="; }) + + # Fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/open-iscsi/target-isns/commit/d3645f0c357b2b14fb682fa2cd4ba3621efc4cea.patch"; + hash = "sha256-/ew+B4WDF2s5bjfPLZ7glHW+o/pRTI7zPHLTDh+n4lY="; + }) ]; cmakeFlags = [ "-DSUPPORT_SYSTEMD=ON" ]; diff --git a/pkgs/by-name/ta/tayga/package.nix b/pkgs/by-name/ta/tayga/package.nix index c153319c1677..5efecdef4648 100644 --- a/pkgs/by-name/ta/tayga/package.nix +++ b/pkgs/by-name/ta/tayga/package.nix @@ -24,6 +24,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/apalrd/tayga/commit/b41bd030846451d72b277854678b58370b1d5c8f.patch?full_index=1"; hash = "sha256-vFQTlZs9ghxdx4k/iODDOUBAglyll1OxUdTjzDtcwB0="; }) + + # Fix build w/ glibc-2.44 + (fetchpatch2 { + url = "https://github.com/apalrd/tayga/commit/807fe4e4510e697fef6916cd76d393a8ab8e495e.patch?full_index=1"; + hash = "sha256-JqRKv5ZAlypQxYvhctBKPdWgC6Opxo1IV1niS5v2CfY="; + }) ]; makeFlags = [ diff --git a/pkgs/by-name/te/termpaint/package.nix b/pkgs/by-name/te/termpaint/package.nix index b9cc6217119d..9656eb68d8e9 100644 --- a/pkgs/by-name/te/termpaint/package.nix +++ b/pkgs/by-name/te/termpaint/package.nix @@ -6,6 +6,7 @@ ninja, pkg-config, python3, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { pname = "termpaint"; @@ -18,7 +19,15 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-7mfGTC5vJ4806bDbrPMSVthtW05a+M3vgUlHGbtaI4Q="; }; - patches = [ ./0001-meson.build-use-prefix.patch ]; + patches = [ + ./0001-meson.build-use-prefix.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/termpaint/termpaint/commit/6164fb5ff17fd3d05bf44e942539082aa71a2ff3.patch"; + hash = "sha256-rTI0ZdJ6Q/a7M73igihd+4EZT9l6l+7oHGUnKmB5n0o="; + }) + ]; nativeBuildInputs = [ meson diff --git a/pkgs/by-name/tr/trurl/0001-build-constify-strchr-memchr-results.patch b/pkgs/by-name/tr/trurl/0001-build-constify-strchr-memchr-results.patch new file mode 100644 index 000000000000..eb43174b2f28 --- /dev/null +++ b/pkgs/by-name/tr/trurl/0001-build-constify-strchr-memchr-results.patch @@ -0,0 +1,146 @@ +From f081fc506e0e53f671f02ebac8b324f3fd421ee8 Mon Sep 17 00:00:00 2001 +From: Viktor Szakats +Date: Sun, 1 Mar 2026 11:39:41 +0100 +Subject: [PATCH] build: constify `strchr()`/`memchr()` results + +To fix building with glibc-2.43. +(also seen with gcc 16 on Fedora rawhide/f44) + +Also: +- scope a variable while there. +- fix altering the const format buffer on bad syntax. + +Reported-by: Gustavo Costa +Fixes #430 +Reported-by: Michael Ablassmeier +Fixes #431 + +Closes #432 +--- + trurl.c | 37 +++++++++++++++++++------------------ + 1 file changed, 19 insertions(+), 18 deletions(-) + +diff --git a/trurl.c b/trurl.c +index b5a716c..d150a93 100644 +--- a/trurl.c ++++ b/trurl.c +@@ -483,7 +483,7 @@ static void pathadd(struct option *o, const char *path) + + static char *encodeassign(const char *query) + { +- char *p = strchr(query, '='); ++ const char *p = strchr(query, '='); + char *urle; + if(p) { + /* URL encode the left and the right side of the '=' separately */ +@@ -600,7 +600,7 @@ static int getarg(struct option *o, + gap = false; + } + else if((flag[0] == '-') && (flag[1] == '-')) { +- char *equals = strchr(&flag[2], '='); ++ const char *equals = strchr(&flag[2], '='); + if(equals) { + arg = (char *)&equals[1]; + gap = false; +@@ -861,9 +861,10 @@ static void get(struct option *o, CURLU *uh) + else { + /* this is meant as a variable to output */ + const char *start = ptr; +- char *end; +- char *cl; ++ const char *end; ++ const char *cl; + size_t vlen; ++ size_t badlen = 0; + bool isquery = false; + bool queryall = false; + bool strict = false; /* strict mode, fail on URL decode problems */ +@@ -923,7 +924,7 @@ static void get(struct option *o, CURLU *uh) + else { + /* syntax error */ + vlen = 0; +- end[1] = '\0'; ++ badlen = end - start + 1; + } + break; + } +@@ -938,7 +939,7 @@ static void get(struct option *o, CURLU *uh) + queryall); + } + else if(!vlen) +- errorf(o, ERROR_GET, "Bad --get syntax: %s", start); ++ errorf(o, ERROR_GET, "Bad --get syntax: %.*s", (int)badlen, start); + else if(!strncmp(ptr, "url", vlen)) + showurl(stream, o, mods, uh); + else { +@@ -1022,7 +1023,7 @@ static void get(struct option *o, CURLU *uh) + static const struct var *setone(CURLU *uh, const char *setline, + struct option *o) + { +- char *ptr = strchr(setline, '='); ++ const char *ptr = strchr(setline, '='); + const struct var *v = NULL; + if(ptr && (ptr > setline)) { + size_t vlen = ptr - setline; +@@ -1269,9 +1270,9 @@ static bool trim(struct option *o) + inslen--; + } + +- for(i = 0 ; i < nqpairs; i++) { +- char *q = qpairs[i].str; +- char *sep = strchr(q, '='); ++ for(i = 0; i < nqpairs; i++) { ++ const char *q = qpairs[i].str; ++ const char *sep = strchr(q, '='); + size_t qlen; + if(sep) + qlen = sep - q; +@@ -1546,10 +1547,9 @@ static bool extractqpairs(CURLU *uh, struct option *o) + /* extract the query */ + if(!curl_url_get(uh, CURLUPART_QUERY, &q, 0)) { + char *p = q; +- char *amp; + while(*p) { + size_t len; +- amp = strchr(p, o->qsep[0]); ++ char *amp = strchr(p, o->qsep[0]); + if(!amp) + len = strlen(p); + else +@@ -1684,7 +1684,7 @@ static char *canonical_path(const char *path) + { + /* split the path per slash, URL decode + encode, then put together again */ + size_t len = strlen(path); +- char *sl; ++ const char *sl; + char *dupe = NULL; + + do { +@@ -1810,7 +1810,8 @@ static void singleurl(struct option *o, + size_t plen; + const char *w; + size_t wlen; +- char *sep; ++ const char *sep; ++ char *sepw; + bool urlencode = true; + const struct var *v; + +@@ -1852,10 +1853,10 @@ static void singleurl(struct option *o, + w = iinfo->ptr; + } + +- sep = strchr(w, ' '); +- if(sep) { +- wlen = sep - w; +- iinfo->ptr = sep + 1; /* next word is here */ ++ sepw = strchr(w, ' '); ++ if(sepw) { ++ wlen = sepw - w; ++ iinfo->ptr = sepw + 1; /* next word is here */ + } + else { + /* last word */ +-- +2.54.0 + diff --git a/pkgs/by-name/tr/trurl/package.nix b/pkgs/by-name/tr/trurl/package.nix index 5cddcd00a35e..bd2e932fd697 100644 --- a/pkgs/by-name/tr/trurl/package.nix +++ b/pkgs/by-name/tr/trurl/package.nix @@ -6,7 +6,6 @@ curl, python3, perl, - trurl, versionCheckHook, }: @@ -22,6 +21,14 @@ stdenv.mkDerivation rec { }; patches = [ + # fix build w/ glibc-2.44 + # https://github.com/curl/trurl/commit/6e1479cc3bdece8d9a7602e6f8f799305d5a5b7d, but rebased + ./0001-build-constify-strchr-memchr-results.patch + (fetchpatch { + url = "https://github.com/curl/trurl/commit/b3c2faf7ee519e4686248957ee079a2452741d61.patch"; + hash = "sha256-khA77XHPVF+2Vn492UuPrhVAEUijRBA2P8lvPlKYSQM="; + }) + (fetchpatch { url = "https://github.com/curl/trurl/commit/f22a2c45956f35702e437fb83ac05376f1956ec5.patch"; hash = "sha256-7CkUs5tMk77WKc7SlgE2NslHtU5cViKSGhHj3IBlpWo="; diff --git a/pkgs/by-name/tu/tuxpaint/package.nix b/pkgs/by-name/tu/tuxpaint/package.nix index 3152be909715..5e81c3583ef4 100644 --- a/pkgs/by-name/tu/tuxpaint/package.nix +++ b/pkgs/by-name/tu/tuxpaint/package.nix @@ -23,6 +23,7 @@ SDL2_Pango, SDL2_ttf, netpbm, + fetchpatch, }: let @@ -50,6 +51,15 @@ stdenv.mkDerivation (finalAttrs: { strictDeps = true; + patches = [ + # Fix build w/ glibc-2.44 + # https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=51c28b814990551897631be7a222af2d922030a9 + (fetchpatch { + url = "https://gitweb.gentoo.org/repo/gentoo.git/plain/media-gfx/tuxpaint/files/tuxpaint-0.9.35-glibc-2.43.patch?id=51c28b814990551897631be7a222af2d922030a9"; + hash = "sha256-xkV73GoCd/epeyWfLHq2MNmRNfKaledoFsukwVKiZSI="; + }) + ]; + nativeBuildInputs = [ gettext gperf diff --git a/pkgs/by-name/uc/ucode/package.nix b/pkgs/by-name/uc/ucode/package.nix index a8309fbc4e26..ed014133c91d 100644 --- a/pkgs/by-name/uc/ucode/package.nix +++ b/pkgs/by-name/uc/ucode/package.nix @@ -5,6 +5,7 @@ cmake, pkg-config, json_c, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -18,6 +19,22 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-V8WGd4rSuCtGIA5oTfnagp0Dmh5FNG87/MJSeILtbM4="; }; + patches = [ + (fetchpatch { + url = "https://github.com/jow-/ucode/commit/4d81e6c13506599261208786cfe4ee068f346dcd.patch"; + hash = "sha256-RZhD422ue00bqam4n7jAynPDJdOzOFJnf34YbT2wH/s="; + }) + (fetchpatch { + url = "https://github.com/jow-/ucode/commit/a7ead3169ebf355e66b399aca1dd3a5ce29e1e5b.patch"; + hash = "sha256-sc+jSAlix1jE9Cb4MMuqI7VHG6h+zpCL7UZ84awOL6M="; + }) + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/jow-/ucode/commit/beafcff845fcdbb46308ee54422661e80300079d.patch"; + hash = "sha256-JcBk8kJHDlHLRuVR2fmsSfWqVmbFZMPF16+nPp6QFf4="; + }) + ]; + buildInputs = [ json_c ]; diff --git a/pkgs/by-name/ul/ulfius/package.nix b/pkgs/by-name/ul/ulfius/package.nix index 21542df0d6ad..6db5cbc75f7d 100644 --- a/pkgs/by-name/ul/ulfius/package.nix +++ b/pkgs/by-name/ul/ulfius/package.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation (finalAttrs: { cmake ]; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + propagatedBuildInputs = [ libmicrohttpd orcania diff --git a/pkgs/by-name/ur/urweb/package.nix b/pkgs/by-name/ur/urweb/package.nix index 445c01cec8f0..e79a09bfda7a 100644 --- a/pkgs/by-name/ur/urweb/package.nix +++ b/pkgs/by-name/ur/urweb/package.nix @@ -64,6 +64,7 @@ stdenv.mkDerivation rec { env.NIX_CFLAGS_COMPILE = toString [ # Needed with GCC 12 "-Wno-error=use-after-free" + "-Wno-error=discarded-qualifiers" ]; # Be sure to keep the statically linked libraries diff --git a/pkgs/by-name/vb/vboot-utils/package.nix b/pkgs/by-name/vb/vboot-utils/package.nix index 981202ea1fa0..d04f8a109aaf 100644 --- a/pkgs/by-name/vb/vboot-utils/package.nix +++ b/pkgs/by-name/vb/vboot-utils/package.nix @@ -36,6 +36,9 @@ stdenv.mkDerivation (finalAttrs: { ] ++ lib.optional withFlashrom finalAttrs.passthru.flashromChromeos; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + enableParallelBuilding = true; postPatch = '' diff --git a/pkgs/by-name/vg/vg/package.nix b/pkgs/by-name/vg/vg/package.nix index b0c38d6c3cd5..5cc0fb425efb 100644 --- a/pkgs/by-name/vg/vg/package.nix +++ b/pkgs/by-name/vg/vg/package.nix @@ -133,6 +133,7 @@ stdenv.mkDerivation (finalAttrs: { NIX_CFLAGS_COMPILE = toString [ "-Wno-error=stringop-overflow" "-Wno-error=unterminated-string-initialization" + "-Wno-error=discarded-qualifiers" ]; }; diff --git a/pkgs/by-name/vi/virt-viewer/package.nix b/pkgs/by-name/vi/virt-viewer/package.nix index 56a1962294ab..c599d66504ed 100644 --- a/pkgs/by-name/vi/virt-viewer/package.nix +++ b/pkgs/by-name/vi/virt-viewer/package.nix @@ -49,6 +49,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://gitlab.com/virt-viewer/virt-viewer/-/commit/98d9f202ef768f22ae21b5c43a080a1aa64a7107.patch"; sha256 = "sha256-3AbnkbhWOh0aNjUkmVoSV/9jFQtvTllOr7plnkntb2o="; }) + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://gitlab.com/virt-viewer/virt-viewer/-/commit/a634fa8d9fbc59b093f2f07110b2c867f622599d.patch"; + hash = "sha256-xNwpuVwYajlfQUbT6aDrTBqwa61Je8EhD0C9+PL/qx0="; + }) ]; nativeBuildInputs = [ diff --git a/pkgs/by-name/x1/x16/package.nix b/pkgs/by-name/x1/x16/package.nix index b1114d51b5fe..f1226c2f2bc9 100644 --- a/pkgs/by-name/x1/x16/package.nix +++ b/pkgs/by-name/x1/x16/package.nix @@ -7,6 +7,7 @@ callPackage, zlib, nix-update-script, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -30,6 +31,9 @@ stdenv.mkDerivation (finalAttrs: { }) ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + postPatch = '' substituteInPlace Makefile \ --replace-fail '/bin/echo' 'echo' diff --git a/pkgs/by-name/xb/xbps/package.nix b/pkgs/by-name/xb/xbps/package.nix index 6f3e1ef231ea..b343f27c4909 100644 --- a/pkgs/by-name/xb/xbps/package.nix +++ b/pkgs/by-name/xb/xbps/package.nix @@ -7,6 +7,7 @@ zlib, openssl, libarchive, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -33,6 +34,23 @@ stdenv.mkDerivation (finalAttrs: { patches = [ ./cert-paths.patch + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/7d02b79d3d7e0bf644adf8b412e76dba1b1fdce1.patch"; + hash = "sha256-iUNBmkkfR02/EFDkax/ZpE7oM+5IVDMmD0FYz7p0dQ4="; + }) + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/9a8002c5688c3cdda700b022bf432b4426d64042.patch"; + hash = "sha256-/94HKeyv9LaQv6QHE0CqmM1ajBOSNt9Sfh0XKV0RLMQ="; + }) + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/7f2f10300f235639c5880bea1e4b14245fd5fbda.patch"; + hash = "sha256-iZXiNYrSFaP55qyzefc3hqJ+SoIOsFILqnra6u5iGpM="; + }) + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/84f6a1be26348c265afedebe9cea958424b0aabf.patch"; + hash = "sha256-WDsGkI+3JnJskM+UKjI/UZP6ypMCd5+3rYtlQgQEr40="; + }) ]; env.NIX_CFLAGS_COMPILE = "-Wno-error=unused-result -Wno-error=deprecated-declarations"; diff --git a/pkgs/by-name/xf/xfstests/package.nix b/pkgs/by-name/xf/xfstests/package.nix index 97cc46233cd9..b3aeb33f7fc9 100644 --- a/pkgs/by-name/xf/xfstests/package.nix +++ b/pkgs/by-name/xf/xfstests/package.nix @@ -10,6 +10,7 @@ coreutils, e2fsprogs, fetchzip, + fetchpatch, fio, gawk, keyutils, @@ -45,6 +46,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-jnwEcGUSkKW9afGQTUsWR7CNQECWz/sYdSaDx0hY1Uo="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://lore.kernel.org/fstests/20260813150846.280498-1-zlang@kernel.org/raw"; + hash = "sha256-NOPMo0cdKKoPMwG53BdTe+G+vDXb+2ICGYFRs4g+edQ="; + }) + ]; + nativeBuildInputs = [ autoconf automake @@ -65,7 +74,7 @@ stdenv.mkDerivation (finalAttrs: { hardeningDisable = [ "format" ]; enableParallelBuilding = true; - patchPhase = '' + postPatch = '' substituteInPlace Makefile \ --replace-fail "cp include/install-sh ." "cp -f include/install-sh ." diff --git a/pkgs/by-name/zo/zookeeper_mt/package.nix b/pkgs/by-name/zo/zookeeper_mt/package.nix index 44dc1fdf8cd8..4d7d4eaf5986 100644 --- a/pkgs/by-name/zo/zookeeper_mt/package.nix +++ b/pkgs/by-name/zo/zookeeper_mt/package.nix @@ -21,6 +21,9 @@ stdenv.mkDerivation rec { sourceRoot = "apache-${zookeeper.pname}-${version}/zookeeper-client/zookeeper-client-c"; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ autoreconfHook pkg-config diff --git a/pkgs/by-name/zu/zutty/package.nix b/pkgs/by-name/zu/zutty/package.nix index 06f975b68420..5a6f7ebfb87d 100644 --- a/pkgs/by-name/zu/zutty/package.nix +++ b/pkgs/by-name/zu/zutty/package.nix @@ -57,5 +57,6 @@ stdenv.mkDerivation (finalAttrs: { license = lib.licenses.gpl3Plus; maintainers = [ lib.maintainers.rolfschr ]; platforms = lib.platforms.linux; + broken = true; # Added 2026-09-19, fails with latest glibc }; }) diff --git a/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch b/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch index 25cb329e086e..d1ea3ad0cdd2 100644 --- a/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch +++ b/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch @@ -1,4 +1,4 @@ -From c1c36f73aa3085a856c7cf36d69c21d18d3ef5ac Mon Sep 17 00:00:00 2001 +From 0ea28d2f38500559734cb0fe99eae40c04783730 Mon Sep 17 00:00:00 2001 From: Bernardo Meurer Date: Fri, 22 Jul 2022 22:11:07 -0700 Subject: [PATCH] Revert "Remove all usage of @BASH@ or ${BASH} in installed @@ -22,10 +22,10 @@ Co-authored-by: Maximilian Bosch 8 files changed, 15 insertions(+), 10 deletions(-) diff --git a/debug/Makefile b/debug/Makefile -index 6a05205ce6..dd63b16ae8 100644 +index c6c1069b40..ccecf6b70b 100644 --- a/debug/Makefile +++ b/debug/Makefile -@@ -345,8 +345,9 @@ $(objpfx)pcprofiledump: $(objpfx)pcprofiledump.o +@@ -407,8 +407,9 @@ $(objpfx)pcprofiledump: $(objpfx)pcprofiledump.o $(objpfx)xtrace: xtrace.sh rm -f $@.new @@ -38,17 +38,17 @@ index 6a05205ce6..dd63b16ae8 100644 && rm -f $@ && mv $@.new $@ && chmod +x $@ diff --git a/debug/xtrace.sh b/debug/xtrace.sh -index 00bafd33db..d0f9fca9a9 100755 +index a1bb50eeaf..01383c7c79 100755 --- a/debug/xtrace.sh +++ b/debug/xtrace.sh @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 1999-2025 Free Software Foundation, Inc. + # Copyright (C) 1999-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/elf/Makefile b/elf/Makefile -index 4b1d0d8741..bbcf688c99 100644 +index d279a5135c..dc39ccea60 100644 --- a/elf/Makefile +++ b/elf/Makefile @@ -250,7 +250,8 @@ $(objpfx)sotruss-lib.so: $(common-objpfx)libc.so $(objpfx)ld.so \ @@ -61,7 +61,7 @@ index 4b1d0d8741..bbcf688c99 100644 -e 's%@TEXTDOMAINDIR@%$(localedir)%g' \ -e 's%@PREFIX@%$(prefix)%g' \ -e 's|@PKGVERSION@|$(PKGVERSION)|g' \ -@@ -1556,6 +1557,7 @@ ldd-rewrite = -e 's%@RTLD@%$(rtlddir)/$(rtld-installed-name)%g' \ +@@ -1720,6 +1721,7 @@ ldd-rewrite = -e 's%@RTLD@%$(rtlddir)/$(rtld-installed-name)%g' \ -e 's%@VERSION@%$(version)%g' \ -e 's|@PKGVERSION@|$(PKGVERSION)|g' \ -e 's|@REPORT_BUGS_TO@|$(REPORT_BUGS_TO)|g' \ @@ -70,30 +70,30 @@ index 4b1d0d8741..bbcf688c99 100644 ifeq ($(ldd-rewrite-script),no) diff --git a/elf/ldd.bash.in b/elf/ldd.bash.in -index 2d3df6e57e..0faf83dc86 100644 +index bfc40f6505..59ca54e2d9 100644 --- a/elf/ldd.bash.in +++ b/elf/ldd.bash.in @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 1996-2025 Free Software Foundation, Inc. + # Copyright (C) 1996-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/elf/sotruss.sh b/elf/sotruss.sh -index 8944645df9..1c36981b22 100755 +index c90abaaed9..03cb25bc57 100755 --- a/elf/sotruss.sh +++ b/elf/sotruss.sh @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 2011-2025 Free Software Foundation, Inc. + # Copyright (C) 2011-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/malloc/Makefile b/malloc/Makefile -index e2b2c1ae1b..67a399f1dd 100644 +index 72aa77af20..e148b6480a 100644 --- a/malloc/Makefile +++ b/malloc/Makefile -@@ -359,8 +359,9 @@ $(objpfx)mtrace: mtrace.pl +@@ -484,8 +484,9 @@ $(objpfx)mtrace: mtrace.pl $(objpfx)memusage: memusage.sh rm -f $@.new @@ -106,20 +106,20 @@ index e2b2c1ae1b..67a399f1dd 100644 && rm -f $@ && mv $@.new $@ && chmod +x $@ diff --git a/malloc/memusage.sh b/malloc/memusage.sh -index 8ae435d2f8..c929d16af7 100755 +index 309991a7c9..28117c4561 100755 --- a/malloc/memusage.sh +++ b/malloc/memusage.sh @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 1999-2025 Free Software Foundation, Inc. + # Copyright (C) 1999-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/timezone/Makefile b/timezone/Makefile -index ebe5cf73a1..e9cf92861c 100644 +index ce9abe6cb2..3ee1eed54a 100644 --- a/timezone/Makefile +++ b/timezone/Makefile -@@ -139,7 +139,8 @@ $(testdata)/XT5: testdata/gen-XT5.sh +@@ -136,7 +136,8 @@ $(testdata)/XT5: testdata/gen-XT5.sh mv $@.tmp $@ $(objpfx)tzselect: tzselect.ksh $(common-objpfx)config.make @@ -130,5 +130,5 @@ index ebe5cf73a1..e9cf92861c 100644 -e '/PKGVERSION=/s|=.*|="$(PKGVERSION)"|' \ -e '/REPORT_BUGS_TO=/s|=.*|="$(REPORT_BUGS_TO)"|' \ -- -2.47.2 +2.54.0 diff --git a/pkgs/development/libraries/glibc/2.42-master.patch b/pkgs/development/libraries/glibc/2.42-master.patch deleted file mode 100644 index 8abd567ee32b..000000000000 --- a/pkgs/development/libraries/glibc/2.42-master.patch +++ /dev/null @@ -1,11174 +0,0 @@ -commit bdea6c37197a3c9bd976911cce5f580dea1c28dd -Author: Andreas K. Hüttel -Date: Mon Jul 28 20:35:38 2025 +0200 - - Replace advisories directory with pointer file - - Signed-off-by: Andreas K. Hüttel - -diff --git a/advisories/GLIBC-SA-2023-0001 b/advisories/GLIBC-SA-2023-0001 -deleted file mode 100644 -index 3d19c91b6a..0000000000 ---- a/advisories/GLIBC-SA-2023-0001 -+++ /dev/null -@@ -1,14 +0,0 @@ --printf: incorrect output for integers with thousands separator and width field -- --When the printf family of functions is called with a format specifier --that uses an (enable grouping) and a minimum width --specifier, the resulting output could be larger than reasonably expected --by a caller that computed a tight bound on the buffer size. The --resulting larger than expected output could result in a buffer overflow --in the printf family of functions. -- --CVE-Id: CVE-2023-25139 --Public-Date: 2023-02-02 --Vulnerable-Commit: e88b9f0e5cc50cab57a299dc7efe1a4eb385161d (2.37) --Fix-Commit: c980549cc6a1c03c23cc2fe3e7b0fe626a0364b0 (2.38) --Fix-Commit: 07b9521fc6369d000216b96562ff7c0ed32a16c4 (2.37-4) -diff --git a/advisories/GLIBC-SA-2023-0002 b/advisories/GLIBC-SA-2023-0002 -deleted file mode 100644 -index 5122669a64..0000000000 ---- a/advisories/GLIBC-SA-2023-0002 -+++ /dev/null -@@ -1,15 +0,0 @@ --getaddrinfo: Stack read overflow in no-aaaa mode -- --If the system is configured in no-aaaa mode via /etc/resolv.conf, --getaddrinfo is called for the AF_UNSPEC address family, and a DNS --response is received over TCP that is larger than 2048 bytes, --getaddrinfo may potentially disclose stack contents via the returned --address data, or crash. -- --CVE-Id: CVE-2023-4527 --Public-Date: 2023-09-12 --Vulnerable-Commit: f282cdbe7f436c75864e5640a409a10485e9abb2 (2.36) --Fix-Commit: bd77dd7e73e3530203be1c52c8a29d08270cb25d (2.39) --Fix-Commit: 4ea972b7edd7e36610e8cde18bf7a8149d7bac4f (2.36-113) --Fix-Commit: b7529346025a130fee483d42178b5c118da971bb (2.37-38) --Fix-Commit: b25508dd774b617f99419bdc3cf2ace4560cd2d6 (2.38-19) -diff --git a/advisories/GLIBC-SA-2023-0003 b/advisories/GLIBC-SA-2023-0003 -deleted file mode 100644 -index d3aef80348..0000000000 ---- a/advisories/GLIBC-SA-2023-0003 -+++ /dev/null -@@ -1,15 +0,0 @@ --getaddrinfo: Potential use-after-free -- --When an NSS plugin only implements the _gethostbyname2_r and --_getcanonname_r callbacks, getaddrinfo could use memory that was freed --during buffer resizing, potentially causing a crash or read or write to --arbitrary memory. -- --CVE-Id: CVE-2023-4806 --Public-Date: 2023-09-12 --Fix-Commit: 973fe93a5675c42798b2161c6f29c01b0e243994 (2.39) --Fix-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) --Fix-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) --Fix-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) --Fix-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) --Fix-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) -diff --git a/advisories/GLIBC-SA-2023-0004 b/advisories/GLIBC-SA-2023-0004 -deleted file mode 100644 -index 5286a7aa54..0000000000 ---- a/advisories/GLIBC-SA-2023-0004 -+++ /dev/null -@@ -1,16 +0,0 @@ --tunables: local privilege escalation through buffer overflow -- --If a tunable of the form NAME=NAME=VAL is passed in the environment of a --setuid program and NAME is valid, it may result in a buffer overflow, --which could be exploited to achieve escalated privileges. This flaw was --introduced in glibc 2.34. -- --CVE-Id: CVE-2023-4911 --Public-Date: 2023-10-03 --Vulnerable-Commit: 2ed18c5b534d9e92fc006202a5af0df6b72e7aca (2.34) --Fix-Commit: 1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa (2.39) --Fix-Commit: dcc367f148bc92e7f3778a125f7a416b093964d9 (2.34-423) --Fix-Commit: c84018a05aec80f5ee6f682db0da1130b0196aef (2.35-274) --Fix-Commit: 22955ad85186ee05834e47e665056148ca07699c (2.36-118) --Fix-Commit: b4e23c75aea756b4bddc4abcf27a1c6dca8b6bd3 (2.37-45) --Fix-Commit: 750a45a783906a19591fb8ff6b7841470f1f5701 (2.38-27) -diff --git a/advisories/GLIBC-SA-2023-0005 b/advisories/GLIBC-SA-2023-0005 -deleted file mode 100644 -index cc4eb90b82..0000000000 ---- a/advisories/GLIBC-SA-2023-0005 -+++ /dev/null -@@ -1,18 +0,0 @@ --getaddrinfo: DoS due to memory leak -- --The fix for CVE-2023-4806 introduced a memory leak when an application --calls getaddrinfo for AF_INET6 with AI_CANONNAME, AI_ALL and AI_V4MAPPED --flags set. -- --CVE-Id: CVE-2023-5156 --Public-Date: 2023-09-25 --Vulnerable-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) --Vulnerable-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) --Vulnerable-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) --Vulnerable-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) --Vulnerable-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) --Fix-Commit: 8006457ab7e1cd556b919f477348a96fe88f2e49 (2.34-421) --Fix-Commit: 17092c0311f954e6f3c010f73ce3a78c24ac279a (2.35-272) --Fix-Commit: 856bac55f98dc840e7c27cfa82262b933385de90 (2.36-116) --Fix-Commit: 4473d1b87d04b25cdd0e0354814eeaa421328268 (2.37-42) --Fix-Commit: 5ee59ca371b99984232d7584fe2b1a758b4421d3 (2.38-24) -diff --git a/advisories/GLIBC-SA-2024-0001 b/advisories/GLIBC-SA-2024-0001 -deleted file mode 100644 -index 28931c75ae..0000000000 ---- a/advisories/GLIBC-SA-2024-0001 -+++ /dev/null -@@ -1,15 +0,0 @@ --syslog: Heap buffer overflow in __vsyslog_internal -- --__vsyslog_internal did not handle a case where printing a SYSLOG_HEADER --containing a long program name failed to update the required buffer --size, leading to the allocation and overflow of a too-small buffer on --the heap. -- --CVE-Id: CVE-2023-6246 --Public-Date: 2024-01-30 --Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) --Fix-Commit: 6bd0e4efcc78f3c0115e5ea9739a1642807450da (2.39) --Fix-Commit: 23514c72b780f3da097ecf33a793b7ba9c2070d2 (2.38-42) --Fix-Commit: 97a4292aa4a2642e251472b878d0ec4c46a0e59a (2.37-57) --Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) --Fix-Commit: d1a83b6767f68b3cb5b4b4ea2617254acd040c82 (2.36-126) -diff --git a/advisories/GLIBC-SA-2024-0002 b/advisories/GLIBC-SA-2024-0002 -deleted file mode 100644 -index 940bfcf2fc..0000000000 ---- a/advisories/GLIBC-SA-2024-0002 -+++ /dev/null -@@ -1,15 +0,0 @@ --syslog: Heap buffer overflow in __vsyslog_internal -- --__vsyslog_internal used the return value of snprintf/vsnprintf to --calculate buffer sizes for memory allocation. If these functions (for --any reason) failed and returned -1, the resulting buffer would be too --small to hold output. -- --CVE-Id: CVE-2023-6779 --Public-Date: 2024-01-30 --Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) --Fix-Commit: 7e5a0c286da33159d47d0122007aac016f3e02cd (2.39) --Fix-Commit: d0338312aace5bbfef85e03055e1212dd0e49578 (2.38-43) --Fix-Commit: 67062eccd9a65d7fda9976a56aeaaf6c25a80214 (2.37-58) --Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) --Fix-Commit: 2bc9d7c002bdac38b5c2a3f11b78e309d7765b83 (2.36-127) -diff --git a/advisories/GLIBC-SA-2024-0003 b/advisories/GLIBC-SA-2024-0003 -deleted file mode 100644 -index b43a5150ab..0000000000 ---- a/advisories/GLIBC-SA-2024-0003 -+++ /dev/null -@@ -1,13 +0,0 @@ --syslog: Integer overflow in __vsyslog_internal -- --__vsyslog_internal calculated a buffer size by adding two integers, but --did not first check if the addition would overflow. -- --CVE-Id: CVE-2023-6780 --Public-Date: 2024-01-30 --Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) --Fix-Commit: ddf542da94caf97ff43cc2875c88749880b7259b (2.39) --Fix-Commit: d37c2b20a4787463d192b32041c3406c2bd91de0 (2.38-44) --Fix-Commit: 2b58cba076e912961ceaa5fa58588e4b10f791c0 (2.37-59) --Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) --Fix-Commit: b9b7d6a27aa0632f334352fa400771115b3c69b7 (2.36-128) -diff --git a/advisories/GLIBC-SA-2024-0004 b/advisories/GLIBC-SA-2024-0004 -deleted file mode 100644 -index 08df2b3118..0000000000 ---- a/advisories/GLIBC-SA-2024-0004 -+++ /dev/null -@@ -1,28 +0,0 @@ --ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence -- --The iconv() function in the GNU C Library versions 2.39 and older may --overflow the output buffer passed to it by up to 4 bytes when converting --strings to the ISO-2022-CN-EXT character set, which may be used to --crash an application or overwrite a neighbouring variable. -- --ISO-2022-CN-EXT uses escape sequences to indicate character set changes --(as specified by RFC 1922). While the SOdesignation has the expected --bounds checks, neither SS2designation nor SS3designation have its; --allowing a write overflow of 1, 2, or 3 bytes with fixed values: --'$+I', '$+J', '$+K', '$+L', '$+M', or '$*H'. -- --CVE-Id: CVE-2024-2961 --Public-Date: 2024-04-17 --Vulnerable-Commit: 755104edc75c53f4a0e7440334e944ad3c6b32fc (2.1.93-169) --Fix-Commit: f9dc609e06b1136bb0408be9605ce7973a767ada (2.40) --Fix-Commit: 31da30f23cddd36db29d5b6a1c7619361b271fb4 (2.39-31) --Fix-Commit: e1135387deded5d73924f6ca20c72a35dc8e1bda (2.38-66) --Fix-Commit: 89ce64b269a897a7780e4c73a7412016381c6ecf (2.37-89) --Fix-Commit: 4ed98540a7fd19f458287e783ae59c41e64df7b5 (2.36-164) --Fix-Commit: 36280d1ce5e245aabefb877fe4d3c6cff95dabfa (2.35-315) --Fix-Commit: a8b0561db4b9847ebfbfec20075697d5492a363c (2.34-459) --Fix-Commit: ed4f16ff6bed3037266f1fa682ebd32a18fce29c (2.33-263) --Fix-Commit: 682ad4c8623e611a971839990ceef00346289cc9 (2.32-140) --Fix-Commit: 3703c32a8d304c1ee12126134ce69be965f38000 (2.31-154) -- --Reported-By: Charles Fol -diff --git a/advisories/GLIBC-SA-2024-0005 b/advisories/GLIBC-SA-2024-0005 -deleted file mode 100644 -index a59596610a..0000000000 ---- a/advisories/GLIBC-SA-2024-0005 -+++ /dev/null -@@ -1,22 +0,0 @@ --nscd: Stack-based buffer overflow in netgroup cache -- --If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted --by client requests then a subsequent client request for netgroup data --may result in a stack-based buffer overflow. This flaw was introduced --in glibc 2.15 when the cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --CVE-Id: CVE-2024-33599 --Public-Date: 2024-04-23 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: 69c58d5ef9f584ea198bd00f7964d364d0e6b921 (2.31-155) --Fix-Commit: a77064893bfe8a701770e2f53a4d33805bc47a5a (2.32-141) --Fix-Commit: 5c75001a96abcd50cbdb74df24c3f013188d076e (2.33-264) --Fix-Commit: 52f73e5c4e29b14e79167272297977f360ae1e97 (2.34-460) --Fix-Commit: 7a95873543ce225376faf13bb71c43dea6d24f86 (2.35-316) --Fix-Commit: caa3151ca460bdd9330adeedd68c3112d97bffe4 (2.36-165) --Fix-Commit: f75c298e747b2b8b41b1c2f551c011a52c41bfd1 (2.37-91) --Fix-Commit: 5968aebb86164034b8f8421b4abab2f837a5bdaf (2.38-72) --Fix-Commit: 1263d583d2e28afb8be53f8d6922f0842036f35d (2.39-35) --Fix-Commit: 87801a8fd06db1d654eea3e4f7626ff476a9bdaa (2.40) -diff --git a/advisories/GLIBC-SA-2024-0006 b/advisories/GLIBC-SA-2024-0006 -deleted file mode 100644 -index d44148d3d9..0000000000 ---- a/advisories/GLIBC-SA-2024-0006 -+++ /dev/null -@@ -1,32 +0,0 @@ --nscd: Null pointer crash after notfound response -- --If the Name Service Cache Daemon's (nscd) cache fails to add a not-found --netgroup response to the cache, the client request can result in a null --pointer dereference. This flaw was introduced in glibc 2.15 when the --cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --CVE-Id: CVE-2024-33600 --Public-Date: 2024-04-24 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: b048a482f088e53144d26a61c390bed0210f49f2 (2.40) --Fix-Commit: 7835b00dbce53c3c87bbbb1754a95fb5e58187aa (2.40) --Fix-Commit: c99f886de54446cd4447db6b44be93dabbdc2f8b (2.39-37) --Fix-Commit: 5a508e0b508c8ad53bd0d2fb48fd71b242626341 (2.39-36) --Fix-Commit: 2ae9446c1b7a3064743b4a51c0bbae668ee43e4c (2.38-74) --Fix-Commit: 541ea5172aa658c4bd5c6c6d6fd13903c3d5bb0a (2.38-73) --Fix-Commit: a8070b31043c7585c36ba68a74298c4f7af075c3 (2.37-93) --Fix-Commit: 5eea50c4402e39588de98aa1d4469a79774703d4 (2.37-92) --Fix-Commit: f205b3af56740e3b014915b1bd3b162afe3407ef (2.36-167) --Fix-Commit: c34f470a615b136170abd16142da5dd0c024f7d1 (2.36-166) --Fix-Commit: bafadc589fbe21ae330e8c2af74db9da44a17660 (2.35-318) --Fix-Commit: 4370bef52b0f3f3652c6aa13d7a9bb3ac079746d (2.35-317) --Fix-Commit: 1f94122289a9bf7dba573f5d60327aaa2b85cf2e (2.34-462) --Fix-Commit: 966d6ac9e40222b84bb21674cc4f83c8d72a5a26 (2.34-461) --Fix-Commit: e3eef1b8fbdd3a7917af466ca9c4b7477251ca79 (2.33-266) --Fix-Commit: f20a8d696b13c6261b52a6434899121f8b19d5a7 (2.33-265) --Fix-Commit: be602180146de37582a3da3a0caa4b719645de9c (2.32-143) --Fix-Commit: 394eae338199078b7961b051c191539870742d7b (2.32-142) --Fix-Commit: 8d7949183760170c61e55def723c1d8050187874 (2.31-157) --Fix-Commit: 304ce5fe466c4762b21b36c26926a4657b59b53e (2.31-156) -diff --git a/advisories/GLIBC-SA-2024-0007 b/advisories/GLIBC-SA-2024-0007 -deleted file mode 100644 -index b6928fa27a..0000000000 ---- a/advisories/GLIBC-SA-2024-0007 -+++ /dev/null -@@ -1,28 +0,0 @@ --nscd: netgroup cache may terminate daemon on memory allocation failure -- --The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or --xrealloc and these functions may terminate the process due to a memory --allocation failure resulting in a denial of service to the clients. The --flaw was introduced in glibc 2.15 when the cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --Subsequent refactoring of the netgroup cache only added more uses of --xmalloc and xrealloc. Uses of xmalloc and xrealloc in other parts of --nscd only occur during startup of the daemon and so are not affected by --client requests that could trigger an out of memory followed by --termination. -- --CVE-Id: CVE-2024-33601 --Public-Date: 2024-04-24 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) --Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) --Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) --Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) --Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) --Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) --Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) --Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) --Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) --Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) -diff --git a/advisories/GLIBC-SA-2024-0008 b/advisories/GLIBC-SA-2024-0008 -deleted file mode 100644 -index d93e2a6f0b..0000000000 ---- a/advisories/GLIBC-SA-2024-0008 -+++ /dev/null -@@ -1,26 +0,0 @@ --nscd: netgroup cache assumes NSS callback uses in-buffer strings -- --The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory --when the NSS callback does not store all strings in the provided buffer. --The flaw was introduced in glibc 2.15 when the cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --There is no guarantee from the NSS callback API that the returned --strings are all within the buffer. However, the netgroup cache code --assumes that the NSS callback uses in-buffer strings and if it doesn't --the buffer resizing logic could lead to potential memory corruption. -- --CVE-Id: CVE-2024-33602 --Public-Date: 2024-04-24 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) --Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) --Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) --Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) --Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) --Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) --Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) --Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) --Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) --Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) -diff --git a/advisories/GLIBC-SA-2025-0001 b/advisories/GLIBC-SA-2025-0001 -deleted file mode 100644 -index b053d32e91..0000000000 ---- a/advisories/GLIBC-SA-2025-0001 -+++ /dev/null -@@ -1,40 +0,0 @@ --assert: Buffer overflow when printing assertion failure message -- --When the assert() function fails, it does not allocate enough space for the --assertion failure message string and size information, which may lead to a --buffer overflow if the message string size aligns to page size. -- --This bug can be triggered when an assertion in a program fails. The assertion --failure message is allocated to allow developers to see this failure in core --dumps and it typically includes, in addition to the invariant assertion --string and function name, the name of the program. If the name of the failing --program is user controlled, for example on a local system, this could allow an --attacker to control the assertion failure to trigger this buffer overflow. -- --The only viable vector for exploitation of this bug is local, if a setuid --program exists that has an existing bug that results in an assertion failure. --No such program has been discovered at the time of publishing this advisory, --but the presence of custom setuid programs, although strongly discouraged as a --security practice, cannot be discounted. -- --CVE-Id: CVE-2025-0395 --Public-Date: 2025-01-22 --Vulnerable-Commit: f8a3b5bf8fa1d0c43d2458e03cc109a04fdef194 (2.13-175) --Fix-Commit: 68ee0f704cb81e9ad0a78c644a83e1e9cd2ee578 (2.41) --Fix-Commit: cdb9ba84191ce72e86346fb8b1d906e7cd930ea2 (2.42) --Fix-Commit: 69fda28279b497bd405fdd442a6d8e4d3d5f681b (2.41-7) --Fix-Commit: 7d4b6bcae91f29d7b4daf15bab06b66cf1d2217c (2.40-66) --Fix-Commit: d6c156c326999f144cb5b73d29982108d549ad8a (2.40-71) --Fix-Commit: 808a84a8b81468b517a4d721fdc62069cb8c211f (2.39-146) --Fix-Commit: f6d48470aef9264d2d56f4c4533eb76db7f9c2e4 (2.39-150) --Fix-Commit: c32fd59314c343db88c3ea4a203870481d33c3d2 (2.38-122) --Fix-Commit: f984e2d7e8299726891a1a497a3c36cd5542a0bf (2.38-124) --Fix-Commit: a3d7865b098a3a67c44f7812208d9ce4718873ba (2.37-143) --Fix-Commit: b989519fe1683c204ac24ec92830e3fe3bfaccad (2.37-146) --Fix-Commit: 7971add7ee4171fdd8dfd17e7c04c4ed77a18845 (2.36-216) --Fix-Commit: 0487893d5c5bc6710d83d7c3152d888a0339559e (2.36-219) --Fix-Commit: 8b5d4be762419c4f6176261c6fea40ac559b88dc (2.35-370) --Fix-Commit: 8b3d09dc0d350191985f9d291cc30ce96f034b49 (2.35-373) --Fix-Commit: df4e1f4a5096b385c9bcc94424cf2eaa227b3761 (2.34-500) --Fix-Commit: 31eb872cb21449832ab47ad5db83281d240e1d03 (2.34-503) --Reported-By: Qualys Security Advisory -diff --git a/advisories/GLIBC-SA-2025-0002 b/advisories/GLIBC-SA-2025-0002 -deleted file mode 100644 -index 161da13dd4..0000000000 ---- a/advisories/GLIBC-SA-2025-0002 -+++ /dev/null -@@ -1,23 +0,0 @@ --elf: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH -- --A statically linked setuid binary that calls dlopen (including internal --dlopen calls after setlocale or calls to NSS functions such as getaddrinfo) --may incorrectly search LD_LIBRARY_PATH to determine which library to load, --leading to the execution of library code that is attacker controlled. -- --The only viable vector for exploitation of this bug is local, if a static --setuid program exists, and that program calls dlopen, then it may search --LD_LIBRARY_PATH to locate the SONAME to load. No such program has been --discovered at the time of publishing this advisory, but the presence of --custom setuid programs, although strongly discouraged as a security --practice, cannot be discounted. -- --CVE-Id: CVE-2025-4802 --Public-Date: 2025-05-16 --Vulnerable-Commit: 10e93d968716ab82931d593bada121c17c0a4b93 (2.27) --Fix-Commit: 5451fa962cd0a90a0e2ec1d8910a559ace02bba0 (2.39) --Fix-Commit: 3be3728df2f1912c80abd3288bc6e3a25ad679e4 (2.38-132) --Fix-Commit: 7403ede2d7752e59e0c47d5d33d73c2bf850e7be (2.37-154) --Fix-Commit: 2ef7850279b2931caf6d6d6743ebaa91839e1cf7 (2.36-227) --Fix-Commit: 621c65ccf12ddd415ceeb2234423bd1acd0fabb3 (2.35-387) --Fix-Commit: 35018c0fd20eac9ceaf60060fed2745b3177359d (2.34-517) -diff --git a/advisories/GLIBC-SA-2025-0003 b/advisories/GLIBC-SA-2025-0003 -deleted file mode 100644 -index 2adeb3ce00..0000000000 ---- a/advisories/GLIBC-SA-2025-0003 -+++ /dev/null -@@ -1,30 +0,0 @@ --power10: strcmp fails to save and restore nonvolatile vector registers -- --The Power 10 implementation of strcmp in --sysdeps/powerpc/powerpc64/le/power10/strcmp.S failed to save/restore --nonvolatile vector registers in the 32-byte aligned loop path. This --results in callers reading content from those registers in a different --context, potentially altering program logic. -- --There could be a program context where a user controlled string could --leak through strcmp into program code, thus altering its logic. There --is also a potential for sensitive strings passed into strcmp leaking --through the clobbered registers into parts of the calling program that --should otherwise not have had access to those strings. -- --The impact of this flaw is limited to applications running on Power 10 --hardware that use the nonvolatile vector registers, i.e. v20 to v31 --assuming that they have been treated in accordance with the OpenPower --psABI. It is possible to work around the issue for those specific --applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like --so: -- -- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 -- --CVE-Id: CVE-2025-5702 --Public-Date: 2025-06-04 --Vulnerable-Commit: 3367d8e180848030d1646f088759f02b8dfe0d6f (2.39) --Fix-Commit: 15808c77b35319e67ee0dc8f984a9a1a434701bc (2.42) --Fix-Commit: 0c76c951620f9e12df2a89b2c684878b55bb6795 (2.41-60) --Fix-Commit: 7e12550b8e3a11764a4a9090ce6bd3fc23fc8a8e (2.40-139) --Fix-Commit: 06a70769fd0b2e1f2a3085ad50ab620282bd77b3 (2.39-209) -diff --git a/advisories/GLIBC-SA-2025-0004 b/advisories/GLIBC-SA-2025-0004 -deleted file mode 100644 -index 9409ca27c4..0000000000 ---- a/advisories/GLIBC-SA-2025-0004 -+++ /dev/null -@@ -1,29 +0,0 @@ --power10: strncmp fails to save and restore nonvolatile vector registers -- --The Power 10 implementation of strncmp in --sysdeps/powerpc/powerpc64/le/power10/strncmp.S failed to save/restore --nonvolatile vector registers in the 32-byte aligned loop path. This --results in callers reading content from those registers in a different --context, potentially altering program logic. -- --There could be a program context where a user controlled string could --leak through strncmp into program code, thus altering its logic. There --is also a potential for sensitive strings passed into strncmp leaking --through the clobbered registers into parts of the calling program that --should otherwise not have had access to those strings. -- --The impact of this flaw is limited to applications running on Power 10 --hardware that use the nonvolatile vector registers, i.e. v20 to v31 --assuming that they have been treated in accordance with the OpenPower --psABI. It is possible to work around the issue for those specific --applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like --so: -- -- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 -- --CVE-Id: CVE-2025-5745 --Public-Date: 2025-06-05 --Vulnerable-Commit: 23f0d81608d0ca6379894ef81670cf30af7fd081 (2.40) --Fix-Commit: 63c60101ce7c5eac42be90f698ba02099b41b965 (2.42) --Fix-Commit: 84bdbf8a6f2fdafd3661489dbb7f79835a52da82 (2.41-57) --Fix-Commit: 42a5a940c974d02540c8da26d6374c744d148cb9 (2.40-136) -diff --git a/advisories/GLIBC-SA-2025-0005 b/advisories/GLIBC-SA-2025-0005 -deleted file mode 100644 -index 8bcccc59a5..0000000000 ---- a/advisories/GLIBC-SA-2025-0005 -+++ /dev/null -@@ -1,14 +0,0 @@ --posix: Fix double-free after allocation failure in regcomp -- --The regcomp function in the GNU C library version from 2.4 to 2.41 is --subject to a double free if some previous allocation fails. It can be --accomplished either by a malloc failure or by using an interposed --malloc that injects random malloc failures. The double free can allow --buffer manipulation depending of how the regex is constructed. --This issue affects all architectures and ABIs supported by the GNU C --library. -- --CVE-Id: CVE-2025-8058 --Public-Date: 2025-07-22 --Vulnerable-Commit: 963d8d782fc98fb6dc3a66f0068795f9920c269d (2.3.3-1596) --Fix-Commit: 7ea06e994093fa0bcca0d0ee2c1db271d8d7885d (2.42) -diff --git a/advisories/README b/advisories/README -deleted file mode 100644 -index b8f8a829ca..0000000000 ---- a/advisories/README -+++ /dev/null -@@ -1,77 +0,0 @@ --GNU C Library Security Advisory Format --====================================== -- --Security advisories in this directory follow a simple git commit log --format, with a heading and free-format description augmented with tags --to allow parsing key information. References to code changes are --specific to the glibc repository and follow a specific format: -- -- Tag-name: (release-version) -- --The indicates a specific commit in the repository. The --release-version indicates the publicly consumable release in which this --commit is known to exist. The release-version is derived from the --git-describe format, (i.e. stripped out from glibc-2.34.NNN-gxxxx) and --is of the form 2.34-NNN. If the -NNN suffix is absent, it means that --the change is in that release tarball, otherwise the change is on the --release/2.YY/master branch and not in any released tarball. -- --The following tags are currently being used: -- --CVE-Id: --This is the CVE-Id assigned under the CVE Program --(https://www.cve.org/). -- --Public-Date: --The date this issue became publicly known. -- --Vulnerable-Commit: --The commit that introduced this vulnerability. There could be multiple --entries, one for each release branch in the glibc repository; the --release-version portion of this tag should tell you which branch this is --on. -- --Fix-Commit: --The commit that fixed this vulnerability. There could be multiple --entries for each release branch in the glibc repository, indicating that --all of those commits contributed to fixing that issue in each of those --branches. -- --Reported-By: --The entity that reported this issue. There could be multiple entries, one for --each reporter. -- --Adding an Advisory -------------------- -- --An advisory for a CVE needs to be added on the master branch in two steps: -- --1. Add the text of the advisory without any Fix-Commit tags along with -- the fix for the CVE. Add the Vulnerable-Commit tag, if applicable. -- The advisories directory does not exist in release branches, so keep -- the advisory text commit distinct from the code changes, to ease -- backports. Ask for the GLIBC-SA advisory number from the security -- team. -- --2. Finish all backports on release branches and then back on the msater -- branch, add all commit refs to the advisory using the Fix-Commit -- tags. Don't bother adding the release-version subscript since the -- next step will overwrite it. -- --3. Run the process-advisories.sh script in the scripts directory on the -- advisory: -- -- scripts/process-advisories.sh update GLIBC-SA-YYYY-NNNN -- -- (replace YYYY-NNNN with the actual advisory number). -- --4. Verify the updated advisory and push the result. -- --Getting a NEWS snippet from advisories ---------------------------------------- -- --Run: -- -- scripts/process-advisories.sh news -- --and copy the content into the NEWS file. - -commit 3ec4dd77f648da031bba4d3fa14825e057b5a40d -Author: Andreas K. Hüttel -Date: Mon Jul 28 23:39:48 2025 +0200 - - NEWS: add new section - - Signed-off-by: Andreas K. Hüttel - -diff --git a/NEWS b/NEWS -index f0b0e924a4..9cb8de11f9 100644 ---- a/NEWS -+++ b/NEWS -@@ -5,6 +5,12 @@ See the end for copying conditions. - Please send GNU C library bug reports via - using `glibc' in the "product" field. - -+Version 2.42.1 -+ -+The following bugs were resolved with this release: -+ -+ [insert bugs here] -+ - Version 2.42 - - Major new features: - -commit bc13db73937730401d592b33092db6df806d193e -Author: Sam James -Date: Mon Jul 28 21:55:30 2025 +0100 - - inet-fortified: fix namespace violation (bug 33227) - - We need to use __sz, not sz, as we do elsewhere. - - Reviewed-by: Florian Weimer - (cherry picked from commit 87afbd7a1ad9c1dd116921817fa97198171045db) - -diff --git a/inet/bits/inet-fortified.h b/inet/bits/inet-fortified.h -index 6738221a54..cc476ebcfd 100644 ---- a/inet/bits/inet-fortified.h -+++ b/inet/bits/inet-fortified.h -@@ -45,15 +45,15 @@ __NTH (inet_pton (int __af, - __fortify_clang_warning_only_if_bos0_lt - (4, __dst, "inet_pton called with destination buffer size less than 4") - { -- size_t sz = 0; -+ size_t __sz = 0; - if (__af == AF_INET) -- sz = sizeof (struct in_addr); -+ __sz = sizeof (struct in_addr); - else if (__af == AF_INET6) -- sz = sizeof (struct in6_addr); -+ __sz = sizeof (struct in6_addr); - else - return __inet_pton_alias (__af, __src, __dst); - -- return __glibc_fortify (inet_pton, sz, sizeof (char), -+ return __glibc_fortify (inet_pton, __sz, sizeof (char), - __glibc_objsize (__dst), - __af, __src, __dst); - }; - -commit fd18059c0fcf5568db3688da47403b663cf91c5e -Author: Davide Cavalca -Date: Thu Jul 31 17:32:58 2025 +0200 - - stdlib: resolve a double lock init issue after fork [BZ #32994] - - The __abort_fork_reset_child (introduced in - d40ac01cbbc66e6d9dbd8e3485605c63b2178251) call resets the lock after the - fork. This causes a DRD regression in valgrind - (https://bugs.kde.org/show_bug.cgi?id=503668), as it's effectively a - double initialization, despite it being actually ok in this case. As - suggested in https://sourceware.org/bugzilla/show_bug.cgi?id=32994#c2 - we replace it here with a memcpy of another initialized lock instead, - which makes valgrind happy. - - Reviewed-by: Florian Weimer - (cherry picked from commit d9a348d0927c7a1aec5caf3df3fcd36956b3eb23) - -diff --git a/NEWS b/NEWS -index 9cb8de11f9..4610b8bbc6 100644 ---- a/NEWS -+++ b/NEWS -@@ -9,7 +9,7 @@ Version 2.42.1 - - The following bugs were resolved with this release: - -- [insert bugs here] -+ [32994] stdlib: resolve a double lock init issue after fork - - Version 2.42 - -diff --git a/stdlib/abort.c b/stdlib/abort.c -index caa9e6dc04..904244a2fb 100644 ---- a/stdlib/abort.c -+++ b/stdlib/abort.c -@@ -19,6 +19,7 @@ - #include - #include - #include -+#include - #include - - /* Try to get a machine dependent instruction which will make the -@@ -42,7 +43,10 @@ __libc_rwlock_define_initialized (static, lock); - void - __abort_fork_reset_child (void) - { -- __libc_rwlock_init (lock); -+ /* Reinitialize lock without calling pthread_rwlock_init, to -+ avoid a valgrind DRD false positive. */ -+ __libc_rwlock_define_initialized (, reset_lock); -+ memcpy (&lock, &reset_lock, sizeof (lock)); - } - - void - -commit 2fadee530155bae6682ab2965d6ff3a2fc9eced6 -Author: Florian Weimer -Date: Fri Aug 1 19:27:04 2025 +0200 - - elf: Extract rtld_setup_phdr function from dl_main - - Remove historic binutils reference from comment and update - how this data is used by applications. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 2cac9559e06044ba520e785c151fbbd25011865f) - -diff --git a/elf/rtld.c b/elf/rtld.c -index 493f9696ea..6fb900fb31 100644 ---- a/elf/rtld.c -+++ b/elf/rtld.c -@@ -1239,6 +1239,37 @@ rtld_setup_main_map (struct link_map *main_map) - return has_interp; - } - -+/* Set up the program header information for the dynamic linker -+ itself. It can be accessed via _r_debug and dl_iterate_phdr -+ callbacks. */ -+static void -+rtld_setup_phdr (void) -+{ -+ /* Starting from binutils-2.23, the linker will define the magic -+ symbol __ehdr_start to point to our own ELF header if it is -+ visible in a segment that also includes the phdrs. */ -+ -+ const ElfW(Ehdr) *rtld_ehdr = &__ehdr_start; -+ assert (rtld_ehdr->e_ehsize == sizeof *rtld_ehdr); -+ assert (rtld_ehdr->e_phentsize == sizeof (ElfW(Phdr))); -+ -+ const ElfW(Phdr) *rtld_phdr = (const void *) rtld_ehdr + rtld_ehdr->e_phoff; -+ -+ _dl_rtld_map.l_phdr = rtld_phdr; -+ _dl_rtld_map.l_phnum = rtld_ehdr->e_phnum; -+ -+ -+ /* PT_GNU_RELRO is usually the last phdr. */ -+ size_t cnt = rtld_ehdr->e_phnum; -+ while (cnt-- > 0) -+ if (rtld_phdr[cnt].p_type == PT_GNU_RELRO) -+ { -+ _dl_rtld_map.l_relro_addr = rtld_phdr[cnt].p_vaddr; -+ _dl_rtld_map.l_relro_size = rtld_phdr[cnt].p_memsz; -+ break; -+ } -+} -+ - /* Adjusts the contents of the stack and related globals for the user - entry point. The ld.so processed skip_args arguments and bumped - _dl_argv and _dl_argc accordingly. Those arguments are removed from -@@ -1705,33 +1736,7 @@ dl_main (const ElfW(Phdr) *phdr, - ++GL(dl_ns)[LM_ID_BASE]._ns_nloaded; - ++GL(dl_load_adds); - -- /* Starting from binutils-2.23, the linker will define the magic symbol -- __ehdr_start to point to our own ELF header if it is visible in a -- segment that also includes the phdrs. If that's not available, we use -- the old method that assumes the beginning of the file is part of the -- lowest-addressed PT_LOAD segment. */ -- -- /* Set up the program header information for the dynamic linker -- itself. It is needed in the dl_iterate_phdr callbacks. */ -- const ElfW(Ehdr) *rtld_ehdr = &__ehdr_start; -- assert (rtld_ehdr->e_ehsize == sizeof *rtld_ehdr); -- assert (rtld_ehdr->e_phentsize == sizeof (ElfW(Phdr))); -- -- const ElfW(Phdr) *rtld_phdr = (const void *) rtld_ehdr + rtld_ehdr->e_phoff; -- -- _dl_rtld_map.l_phdr = rtld_phdr; -- _dl_rtld_map.l_phnum = rtld_ehdr->e_phnum; -- -- -- /* PT_GNU_RELRO is usually the last phdr. */ -- size_t cnt = rtld_ehdr->e_phnum; -- while (cnt-- > 0) -- if (rtld_phdr[cnt].p_type == PT_GNU_RELRO) -- { -- _dl_rtld_map.l_relro_addr = rtld_phdr[cnt].p_vaddr; -- _dl_rtld_map.l_relro_size = rtld_phdr[cnt].p_memsz; -- break; -- } -+ rtld_setup_phdr (); - - /* Add the dynamic linker to the TLS list if it also uses TLS. */ - if (_dl_rtld_map.l_tls_blocksize != 0) - -commit 5e298d2d937b6da06500478be956abeb24357e05 -Author: Florian Weimer -Date: Fri Aug 1 19:27:35 2025 +0200 - - elf: Handle ld.so with LOAD segment gaps in _dl_find_object (bug 31943) - - Detect if ld.so not contiguous and handle that case in _dl_find_object. - Set l_find_object_processed even for initially loaded link maps, - otherwise dlopen of an initially loaded object adds it to - _dlfo_loaded_mappings (where maps are expected to be contiguous), - in addition to _dlfo_nodelete_mappings. - - Test elf/tst-link-map-contiguous-ldso iterates over the loader - image, reading every word to make sure memory is actually mapped. - It only does that if the l_contiguous flag is set for the link map. - Otherwise, it finds gaps with mmap and checks that _dl_find_object - does not return the ld.so mapping for them. - - The test elf/tst-link-map-contiguous-main does the same thing for - the libc.so shared object. This only works if the kernel loaded - the main program because the glibc dynamic loader may fill - the gaps with PROT_NONE mappings in some cases, making it contiguous, - but accesses to individual words may still fault. - - Test elf/tst-link-map-contiguous-libc is again slightly different - because the dynamic loader always fills the gaps with PROT_NONE - mappings, so a different form of probing has to be used. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 20681be149b9eb1b6c1f4246bf4bd801221c86cd) - -diff --git a/NEWS b/NEWS -index 4610b8bbc6..cbe11ac95b 100644 ---- a/NEWS -+++ b/NEWS -@@ -9,6 +9,7 @@ Version 2.42.1 - - The following bugs were resolved with this release: - -+ [31943] _dl_find_object can fail if ld.so contains gaps between load segments - [32994] stdlib: resolve a double lock init issue after fork - - Version 2.42 -diff --git a/elf/Makefile b/elf/Makefile -index 48aa0b57e5..3a5596e2bb 100644 ---- a/elf/Makefile -+++ b/elf/Makefile -@@ -543,6 +543,8 @@ tests-internal += \ - tst-dl_find_object-threads \ - tst-dlmopen2 \ - tst-hash-collision3 \ -+ tst-link-map-contiguous-ldso \ -+ tst-link-map-contiguous-libc \ - tst-ptrguard1 \ - tst-stackguard1 \ - tst-tls-surplus \ -@@ -554,6 +556,10 @@ tests-internal += \ - unload2 \ - # tests-internal - -+ifeq ($(build-hardcoded-path-in-tests),yes) -+tests-internal += tst-link-map-contiguous-main -+endif -+ - tests-container += \ - tst-dlopen-self-container \ - tst-dlopen-tlsmodid-container \ -diff --git a/elf/dl-find_object.c b/elf/dl-find_object.c -index 1e76373292..c9f4c1c8d1 100644 ---- a/elf/dl-find_object.c -+++ b/elf/dl-find_object.c -@@ -465,6 +465,37 @@ _dl_find_object (void *pc1, struct dl_find_object *result) - } - rtld_hidden_def (_dl_find_object) - -+/* Subroutine of _dlfo_process_initial to split out noncontigous link -+ maps. NODELETE is the number of used _dlfo_nodelete_mappings -+ elements. It is incremented as needed, and the new NODELETE value -+ is returned. */ -+static size_t -+_dlfo_process_initial_noncontiguous_map (struct link_map *map, -+ size_t nodelete) -+{ -+ struct dl_find_object_internal dlfo; -+ _dl_find_object_from_map (map, &dlfo); -+ -+ /* PT_LOAD segments for a non-contiguous link map are added to the -+ non-closeable mappings. */ -+ const ElfW(Phdr) *ph = map->l_phdr; -+ const ElfW(Phdr) *ph_end = map->l_phdr + map->l_phnum; -+ for (; ph < ph_end; ++ph) -+ if (ph->p_type == PT_LOAD) -+ { -+ if (_dlfo_nodelete_mappings != NULL) -+ { -+ /* Second pass only. */ -+ _dlfo_nodelete_mappings[nodelete] = dlfo; -+ ElfW(Addr) start = ph->p_vaddr + map->l_addr; -+ _dlfo_nodelete_mappings[nodelete].map_start = start; -+ _dlfo_nodelete_mappings[nodelete].map_end = start + ph->p_memsz; -+ } -+ ++nodelete; -+ } -+ return nodelete; -+} -+ - /* _dlfo_process_initial is called twice. First to compute the array - sizes from the initial loaded mappings. Second to fill in the - bases and infos arrays with the (still unsorted) data. Returns the -@@ -476,29 +507,8 @@ _dlfo_process_initial (void) - - size_t nodelete = 0; - if (!main_map->l_contiguous) -- { -- struct dl_find_object_internal dlfo; -- _dl_find_object_from_map (main_map, &dlfo); -- -- /* PT_LOAD segments for a non-contiguous are added to the -- non-closeable mappings. */ -- for (const ElfW(Phdr) *ph = main_map->l_phdr, -- *ph_end = main_map->l_phdr + main_map->l_phnum; -- ph < ph_end; ++ph) -- if (ph->p_type == PT_LOAD) -- { -- if (_dlfo_nodelete_mappings != NULL) -- { -- /* Second pass only. */ -- _dlfo_nodelete_mappings[nodelete] = dlfo; -- _dlfo_nodelete_mappings[nodelete].map_start -- = ph->p_vaddr + main_map->l_addr; -- _dlfo_nodelete_mappings[nodelete].map_end -- = _dlfo_nodelete_mappings[nodelete].map_start + ph->p_memsz; -- } -- ++nodelete; -- } -- } -+ /* Contiguous case already handled in _dl_find_object_init. */ -+ nodelete = _dlfo_process_initial_noncontiguous_map (main_map, nodelete); - - size_t loaded = 0; - for (Lmid_t ns = 0; ns < GL(dl_nns); ++ns) -@@ -510,11 +520,18 @@ _dlfo_process_initial (void) - /* lt_library link maps are implicitly NODELETE. */ - if (l->l_type == lt_library || l->l_nodelete_active) - { -- if (_dlfo_nodelete_mappings != NULL) -- /* Second pass only. */ -- _dl_find_object_from_map -- (l, _dlfo_nodelete_mappings + nodelete); -- ++nodelete; -+ /* The kernel may have loaded ld.so with gaps. */ -+ if (!l->l_contiguous && is_rtld_link_map (l)) -+ nodelete -+ = _dlfo_process_initial_noncontiguous_map (l, nodelete); -+ else -+ { -+ if (_dlfo_nodelete_mappings != NULL) -+ /* Second pass only. */ -+ _dl_find_object_from_map -+ (l, _dlfo_nodelete_mappings + nodelete); -+ ++nodelete; -+ } - } - else if (l->l_type == lt_loaded) - { -@@ -764,7 +781,6 @@ _dl_find_object_update_1 (struct link_map **loaded, size_t count) - /* Prefer newly loaded link map. */ - assert (loaded_index1 > 0); - _dl_find_object_from_map (loaded[loaded_index1 - 1], dlfo); -- loaded[loaded_index1 - 1]->l_find_object_processed = 1; - --loaded_index1; - } - -diff --git a/elf/dl-find_object.h b/elf/dl-find_object.h -index 9aa2439eaa..d9d75c4ad9 100644 ---- a/elf/dl-find_object.h -+++ b/elf/dl-find_object.h -@@ -94,7 +94,7 @@ _dl_find_object_to_external (struct dl_find_object_internal *internal, - } - - /* Extract the object location data from a link map and writes it to -- *RESULT using relaxed MO stores. */ -+ *RESULT using relaxed MO stores. Set L->l_find_object_processed. */ - static void __attribute__ ((unused)) - _dl_find_object_from_map (struct link_map *l, - struct dl_find_object_internal *result) -@@ -141,8 +141,11 @@ _dl_find_object_from_map (struct link_map *l, - break; - } - if (read_seg == 3) -- return; -+ goto done; - } -+ -+ done: -+ l->l_find_object_processed = 1; - } - - /* Called by the dynamic linker to set up the data structures for the -diff --git a/elf/rtld.c b/elf/rtld.c -index 6fb900fb31..ef4d96c053 100644 ---- a/elf/rtld.c -+++ b/elf/rtld.c -@@ -1241,7 +1241,7 @@ rtld_setup_main_map (struct link_map *main_map) - - /* Set up the program header information for the dynamic linker - itself. It can be accessed via _r_debug and dl_iterate_phdr -- callbacks. */ -+ callbacks, and it is used by _dl_find_object. */ - static void - rtld_setup_phdr (void) - { -@@ -1259,6 +1259,29 @@ rtld_setup_phdr (void) - _dl_rtld_map.l_phnum = rtld_ehdr->e_phnum; - - -+ _dl_rtld_map.l_contiguous = 1; -+ /* The linker may not have produced a contiguous object. The kernel -+ will load the object with actual gaps (unlike the glibc loader -+ for shared objects, which always produces a contiguous mapping). -+ See similar logic in rtld_setup_main_map above. */ -+ { -+ ElfW(Addr) expected_load_address = 0; -+ for (const ElfW(Phdr) *ph = rtld_phdr; ph < &rtld_phdr[rtld_ehdr->e_phnum]; -+ ++ph) -+ if (ph->p_type == PT_LOAD) -+ { -+ ElfW(Addr) mapstart = ph->p_vaddr & ~(GLRO(dl_pagesize) - 1); -+ if (_dl_rtld_map.l_contiguous && expected_load_address != 0 -+ && expected_load_address != mapstart) -+ _dl_rtld_map.l_contiguous = 0; -+ ElfW(Addr) allocend = ph->p_vaddr + ph->p_memsz; -+ /* The next expected address is the page following this load -+ segment. */ -+ expected_load_address = ((allocend + GLRO(dl_pagesize) - 1) -+ & ~(GLRO(dl_pagesize) - 1)); -+ } -+ } -+ - /* PT_GNU_RELRO is usually the last phdr. */ - size_t cnt = rtld_ehdr->e_phnum; - while (cnt-- > 0) -diff --git a/elf/tst-link-map-contiguous-ldso.c b/elf/tst-link-map-contiguous-ldso.c -new file mode 100644 -index 0000000000..04de808bb2 ---- /dev/null -+++ b/elf/tst-link-map-contiguous-ldso.c -@@ -0,0 +1,98 @@ -+/* Check that _dl_find_object behavior matches up with gaps. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ struct link_map *l = xdlopen (LD_SO, RTLD_NOW); -+ if (!l->l_contiguous) -+ { -+ puts ("info: ld.so link map is not contiguous"); -+ -+ /* Try to find holes by probing with mmap. */ -+ int pagesize = getpagesize (); -+ bool gap_found = false; -+ ElfW(Addr) addr = l->l_map_start; -+ TEST_COMPARE (addr % pagesize, 0); -+ while (addr < l->l_map_end) -+ { -+ void *expected = (void *) addr; -+ void *ptr = xmmap (expected, 1, PROT_READ | PROT_WRITE, -+ MAP_PRIVATE | MAP_ANONYMOUS, -1); -+ struct dl_find_object dlfo; -+ int dlfo_ret = _dl_find_object (expected, &dlfo); -+ if (ptr == expected) -+ { -+ if (dlfo_ret < 0) -+ { -+ TEST_COMPARE (dlfo_ret, -1); -+ printf ("info: hole without mapping data found at %p\n", ptr); -+ } -+ else -+ FAIL ("object \"%s\" found in gap at %p", -+ dlfo.dlfo_link_map->l_name, ptr); -+ gap_found = true; -+ } -+ else if (dlfo_ret == 0) -+ { -+ if ((void *) dlfo.dlfo_link_map != (void *) l) -+ { -+ printf ("info: object \"%s\" found at %p\n", -+ dlfo.dlfo_link_map->l_name, ptr); -+ gap_found = true; -+ } -+ } -+ else -+ TEST_COMPARE (dlfo_ret, -1); -+ xmunmap (ptr, 1); -+ addr += pagesize; -+ } -+ if (!gap_found) -+ FAIL ("no ld.so gap found"); -+ } -+ else -+ { -+ puts ("info: ld.so link map is contiguous"); -+ -+ /* Assert that ld.so is truly contiguous in memory. */ -+ volatile long int *p = (volatile long int *) l->l_map_start; -+ volatile long int *end = (volatile long int *) l->l_map_end; -+ while (p < end) -+ { -+ *p; -+ ++p; -+ } -+ } -+ -+ xdlclose (l); -+ -+ return 0; -+} -+ -+#include -diff --git a/elf/tst-link-map-contiguous-libc.c b/elf/tst-link-map-contiguous-libc.c -new file mode 100644 -index 0000000000..eb5728c765 ---- /dev/null -+++ b/elf/tst-link-map-contiguous-libc.c -@@ -0,0 +1,57 @@ -+/* Check that the entire libc.so program image is readable if contiguous. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ struct link_map *l = xdlopen (LIBC_SO, RTLD_NOW); -+ -+ /* The dynamic loader fills holes with PROT_NONE mappings. */ -+ if (!l->l_contiguous) -+ FAIL_EXIT1 ("libc.so link map is not contiguous"); -+ -+ /* Direct probing does not work because not everything is readable -+ due to PROT_NONE mappings. */ -+ int pagesize = getpagesize (); -+ ElfW(Addr) addr = l->l_map_start; -+ TEST_COMPARE (addr % pagesize, 0); -+ while (addr < l->l_map_end) -+ { -+ void *expected = (void *) addr; -+ void *ptr = xmmap (expected, 1, PROT_READ | PROT_WRITE, -+ MAP_PRIVATE | MAP_ANONYMOUS, -1); -+ if (ptr == expected) -+ FAIL ("hole in libc.so memory image after %lu bytes", -+ (unsigned long int) (addr - l->l_map_start)); -+ xmunmap (ptr, 1); -+ addr += pagesize; -+ } -+ -+ xdlclose (l); -+ -+ return 0; -+} -+#include -diff --git a/elf/tst-link-map-contiguous-main.c b/elf/tst-link-map-contiguous-main.c -new file mode 100644 -index 0000000000..2d1a054f0f ---- /dev/null -+++ b/elf/tst-link-map-contiguous-main.c -@@ -0,0 +1,45 @@ -+/* Check that the entire main program image is readable if contiguous. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ struct link_map *l = xdlopen ("", RTLD_NOW); -+ if (!l->l_contiguous) -+ FAIL_UNSUPPORTED ("main link map is not contiguous"); -+ -+ /* This check only works if the kernel loaded the main program. The -+ dynamic loader replaces gaps with PROT_NONE mappings, resulting -+ in faults. */ -+ volatile long int *p = (volatile long int *) l->l_map_start; -+ volatile long int *end = (volatile long int *) l->l_map_end; -+ while (p < end) -+ { -+ *p; -+ ++p; -+ } -+ -+ xdlclose (l); -+ -+ return 0; -+} -+#include - -commit b38f3f60d5b157edcf4d8bd1fd3ed02d417889e0 -Author: Adhemerval Zanella -Date: Fri Aug 1 15:00:25 2025 -0300 - - nptl: Fix SYSCALL_CANCEL for return values larger than INT_MAX (BZ 33245) - - The SYSCALL_CANCEL calls __syscall_cancel, which in turn - calls __internal_syscall_cancel with an 'int' return instead of the - expected 'long int'. This causes issues with syscalls that return - values larger than INT_MAX, such as copy_file_range [1]. - - Checked on x86_64-linux-gnu. - - [1] https://debbugs.gnu.org/cgi/bugreport.cgi?bug=79139 - - Reviewed-by: Andreas K. Huettel - (cherry picked from commit 7107bebf19286f42dcb0a97581137a5893c16206) - -diff --git a/NEWS b/NEWS -index cbe11ac95b..1d04bdfef8 100644 ---- a/NEWS -+++ b/NEWS -@@ -11,6 +11,7 @@ The following bugs were resolved with this release: - - [31943] _dl_find_object can fail if ld.so contains gaps between load segments - [32994] stdlib: resolve a double lock init issue after fork -+ [33245] nptl: nptl: error in internal cancellation syscall handling - - Version 2.42 - -diff --git a/nptl/cancellation.c b/nptl/cancellation.c -index 156e63dcf0..bed0383a23 100644 ---- a/nptl/cancellation.c -+++ b/nptl/cancellation.c -@@ -72,8 +72,8 @@ __syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, - __syscall_arg_t a5, __syscall_arg_t a6, - __SYSCALL_CANCEL7_ARG_DEF __syscall_arg_t nr) - { -- int r = __internal_syscall_cancel (a1, a2, a3, a4, a5, a6, -- __SYSCALL_CANCEL7_ARG nr); -+ long int r = __internal_syscall_cancel (a1, a2, a3, a4, a5, a6, -+ __SYSCALL_CANCEL7_ARG nr); - return __glibc_unlikely (INTERNAL_SYSCALL_ERROR_P (r)) - ? SYSCALL_ERROR_LABEL (INTERNAL_SYSCALL_ERRNO (r)) - : r; - -commit 9d5bf9c17db0f35268cd798660c8bbeea1f4071d -Author: H.J. Lu -Date: Sat Jul 19 07:43:26 2025 -0700 - - Delete temporary files in support_subprocess - - Call support_delete_temp_files to delete temporary files before exit in - support_subprocess. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit d27b1a71cd424710813bd3d81afb32a36470d643) - -diff --git a/support/support_subprocess.c b/support/support_subprocess.c -index be00dde3a7..8bf9a33ea2 100644 ---- a/support/support_subprocess.c -+++ b/support/support_subprocess.c -@@ -25,6 +25,7 @@ - #include - #include - #include -+#include - - static struct support_subprocess - support_subprocess_init (void) -@@ -60,6 +61,8 @@ support_subprocess (void (*callback) (void *), void *closure) - xclose (result.stdout_pipe[1]); - xclose (result.stderr_pipe[1]); - callback (closure); -+ /* Make sure that temporary files are deleted. */ -+ support_delete_temp_files (); - _exit (0); - } - xclose (result.stdout_pipe[1]); - -commit 9ec7a532ffdb9a6e0a4b220d7a694d6120701035 -Author: H.J. Lu -Date: Sat Jul 19 07:43:27 2025 -0700 - - tst-fopen-threaded.c: Delete temporary file - - Update tst-fopen-threaded.c to call support_create_temp_directory to - create a temporary directory and open "file" in the temporary directory, - instead of using /tmp/openclosetest and leaving it behind. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit e7db5150603bb2224a2bfd9628cae04ddcbe49e3) - -diff --git a/sysdeps/pthread/tst-fopen-threaded.c b/sysdeps/pthread/tst-fopen-threaded.c -index ade58ad19e..c17f1eaa13 100644 ---- a/sysdeps/pthread/tst-fopen-threaded.c -+++ b/sysdeps/pthread/tst-fopen-threaded.c -@@ -34,11 +34,13 @@ - #include - #include - #include -+#include - - #include - #include - #include - #include -+#include - - #define NUM_THREADS 100 - #define ITERS 10 -@@ -111,7 +113,8 @@ threadOpenCloseRoutine (void *argv) - /* Wait for all threads to be ready to call fopen and fclose. */ - xpthread_barrier_wait (&barrier); - -- FILE *fd = xfopen ("/tmp/openclosetest", "w+"); -+ char *file = (char *) argv; -+ FILE *fd = xfopen (file, "w+"); - xfclose (fd); - return NULL; - } -@@ -235,6 +238,10 @@ do_test (void) - xfclose (fd_file); - } - -+ char *tempdir = support_create_temp_directory ("openclosetest-"); -+ char *file = xasprintf ("%s/file", tempdir); -+ add_temp_file (file); -+ - /* Test 3: Concurrent open/close. */ - for (int reps = 1; reps <= ITERS; reps++) - { -@@ -243,7 +250,7 @@ do_test (void) - { - threads[i] = - xpthread_create (support_small_stack_thread_attribute (), -- threadOpenCloseRoutine, NULL); -+ threadOpenCloseRoutine, file); - } - for (int i = 0; i < NUM_THREADS; i++) - { -@@ -252,6 +259,9 @@ do_test (void) - xpthread_barrier_destroy (&barrier); - } - -+ free (file); -+ free (tempdir); -+ - return 0; - } - - -commit 41a77b78cff821007e3dd874619ebec7ce708c3d -Author: H.J. Lu -Date: Sat Jul 19 07:43:28 2025 -0700 - - tst-freopen4-main.c: Call support_capture_subprocess with chroot - - Update tst-freopen4-main.c to call support_capture_subprocess with chroot, - which makes temporary files inaccessible, so that temporary files can be - deleted. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 6463d4a7b28e5ee3891c34a8a1f0a59c24dfa9de) - -diff --git a/stdio-common/tst-freopen4-main.c b/stdio-common/tst-freopen4-main.c -index 3336f5327d..436da4d203 100644 ---- a/stdio-common/tst-freopen4-main.c -+++ b/stdio-common/tst-freopen4-main.c -@@ -28,25 +28,15 @@ - #include - #include - #include -+#include - --int --do_test (void) -+static void -+do_test_chroot (void *data) - { -- mtrace (); -- char *temp_dir; -+ char *temp_dir = (char *) data; - FILE *fp; - int ret; - -- /* These chroot tests verify that either reopening a renamed or -- deleted file works even in the absence of /proc, or that it fails -- (without memory leaks); thus, for example, such reopening does -- not crash in the absence of /proc. */ -- -- support_become_root (); -- if (!support_can_chroot ()) -- return EXIT_UNSUPPORTED; -- -- temp_dir = support_create_temp_directory ("tst-freopen4"); - xchroot (temp_dir); - - /* Test freopen with NULL, renamed file. This verifies that -@@ -96,6 +86,32 @@ do_test (void) - puts ("freopen of deleted file failed (OK)"); - - free (temp_dir); -+} -+ -+int -+do_test (void) -+{ -+ mtrace (); -+ char *temp_dir; -+ -+ /* These chroot tests verify that either reopening a renamed or -+ deleted file works even in the absence of /proc, or that it fails -+ (without memory leaks); thus, for example, such reopening does -+ not crash in the absence of /proc. */ -+ -+ support_become_root (); -+ if (!support_can_chroot ()) -+ return EXIT_UNSUPPORTED; -+ -+ temp_dir = support_create_temp_directory ("tst-freopen4"); -+ -+ struct support_capture_subprocess result; -+ result = support_capture_subprocess (do_test_chroot, temp_dir); -+ support_capture_subprocess_check (&result, "freopen4", 0, -+ sc_allow_stdout); -+ fputs (result.out.buffer, stdout); -+ support_capture_subprocess_free (&result); -+ - return 0; - } - - -commit c090b0cb1cde74aaeec01663dd55d6681dc92075 -Author: H.J. Lu -Date: Sat Jul 19 07:43:29 2025 -0700 - - tst-env-setuid: Delete LD_DEBUG_OUTPUT output - - Update tst-env-setuid.c to delete LD_DEBUG_OUTPUT output, instead of - leaving it behind. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 5d23dfb289174d73b8907b86d2bef7a3ca889840) - -diff --git a/elf/tst-env-setuid.c b/elf/tst-env-setuid.c -index 7209acd616..ff3eda7f91 100644 ---- a/elf/tst-env-setuid.c -+++ b/elf/tst-env-setuid.c -@@ -40,6 +40,8 @@ static char SETGID_CHILD[] = "setgid-child"; - # define PROFILE_LIB "tst-sonamemove-runmod2.so" - #endif - -+#define LD_DEBUG_OUTPUT "/tmp/some-file" -+ - struct envvar_t - { - const char *env; -@@ -61,7 +63,7 @@ static const struct envvar_t filtered_envvars[] = - { "MALLOC_TRIM_THRESHOLD_", FILTERED_VALUE }, - { "RES_OPTIONS", FILTERED_VALUE }, - { "LD_DEBUG", "all" }, -- { "LD_DEBUG_OUTPUT", "/tmp/some-file" }, -+ { "LD_DEBUG_OUTPUT", LD_DEBUG_OUTPUT }, - { "LD_WARN", FILTERED_VALUE }, - { "LD_VERBOSE", FILTERED_VALUE }, - { "LD_BIND_NOW", "0" }, -@@ -74,6 +76,14 @@ static const struct envvar_t unfiltered_envvars[] = - { "LD_ASSUME_KERNEL", UNFILTERED_VALUE }, - }; - -+static void -+unlink_ld_debug_output (pid_t pid) -+{ -+ char *output = xasprintf ("%s.%d", LD_DEBUG_OUTPUT, pid); -+ unlink (output); -+ free (output); -+} -+ - static int - test_child (void) - { -@@ -138,13 +148,21 @@ do_test (int argc, char **argv) - /* Setgid child process. */ - if (argc == 2 && strcmp (argv[1], SETGID_CHILD) == 0) - { -+ pid_t ppid = getppid (); -+ - if (getgid () == getegid ()) -- /* This can happen if the file system is mounted nosuid. */ -- FAIL_UNSUPPORTED ("SGID failed: GID and EGID match (%jd)\n", -- (intmax_t) getgid ()); -+ { -+ /* This can happen if the file system is mounted nosuid. */ -+ unlink_ld_debug_output (ppid); -+ -+ FAIL_UNSUPPORTED ("SGID failed: GID and EGID match (%jd)\n", -+ (intmax_t) getgid ()); -+ } - - int ret = test_child (); - -+ unlink_ld_debug_output (ppid); -+ - if (ret != 0) - exit (1); - return 0; - -commit e5754399b542640f3f69c5e2513c57a307656032 -Author: H.J. Lu -Date: Tue Aug 5 09:16:14 2025 -0700 - - Revert "tst-freopen4-main.c: Call support_capture_subprocess with chroot" - - Revert commit 6463d4a7b28e5ee3891c34a8a1f0a59c24dfa9de to fix - - FAIL: stdio-common/tst-freopen4-mem - FAIL: stdio-common/tst-freopen64-4-mem - - This fixes BZ #33254. - - Reviewed-by: Sam James - (cherry picked from commit adec0bf05bc23ec35573c7a5b96440089b69265e) - -diff --git a/stdio-common/tst-freopen4-main.c b/stdio-common/tst-freopen4-main.c -index 436da4d203..3336f5327d 100644 ---- a/stdio-common/tst-freopen4-main.c -+++ b/stdio-common/tst-freopen4-main.c -@@ -28,15 +28,25 @@ - #include - #include - #include --#include - --static void --do_test_chroot (void *data) -+int -+do_test (void) - { -- char *temp_dir = (char *) data; -+ mtrace (); -+ char *temp_dir; - FILE *fp; - int ret; - -+ /* These chroot tests verify that either reopening a renamed or -+ deleted file works even in the absence of /proc, or that it fails -+ (without memory leaks); thus, for example, such reopening does -+ not crash in the absence of /proc. */ -+ -+ support_become_root (); -+ if (!support_can_chroot ()) -+ return EXIT_UNSUPPORTED; -+ -+ temp_dir = support_create_temp_directory ("tst-freopen4"); - xchroot (temp_dir); - - /* Test freopen with NULL, renamed file. This verifies that -@@ -86,32 +96,6 @@ do_test_chroot (void *data) - puts ("freopen of deleted file failed (OK)"); - - free (temp_dir); --} -- --int --do_test (void) --{ -- mtrace (); -- char *temp_dir; -- -- /* These chroot tests verify that either reopening a renamed or -- deleted file works even in the absence of /proc, or that it fails -- (without memory leaks); thus, for example, such reopening does -- not crash in the absence of /proc. */ -- -- support_become_root (); -- if (!support_can_chroot ()) -- return EXIT_UNSUPPORTED; -- -- temp_dir = support_create_temp_directory ("tst-freopen4"); -- -- struct support_capture_subprocess result; -- result = support_capture_subprocess (do_test_chroot, temp_dir); -- support_capture_subprocess_check (&result, "freopen4", 0, -- sc_allow_stdout); -- fputs (result.out.buffer, stdout); -- support_capture_subprocess_free (&result); -- - return 0; - } - - -commit c5476b7907d01207ede6bf57b26cef151b601f35 -Author: Samuel Thibault -Date: Fri Jul 18 23:14:40 2025 +0200 - - hurd: support: Fix running SGID tests - - Secure mode is enabled only if SGID actually provides a new privilege, - so we have to drop it before gaining it again. - - Fixes commit 3a3fb2ed83f79100c116c824454095ecfb335ad7 - ("Fix error reporting (false negatives) in SGID tests") - - (cherry picked from commit ad4589e2d834c80a042a8c354fb00cf33e06802c) - -diff --git a/support/support_capture_subprocess.c b/support/support_capture_subprocess.c -index b4e4bf9502..c89e65b534 100644 ---- a/support/support_capture_subprocess.c -+++ b/support/support_capture_subprocess.c -@@ -133,6 +133,27 @@ copy_and_spawn_sgid (const char *child_id, gid_t gid) - if (chmod (execname, 02750) != 0) - FAIL_UNSUPPORTED ("cannot make \"%s\" SGID: %m ", execname); - -+ /* Now we can drop the privilege of that group. */ -+ const int count = 64; -+ gid_t groups[count]; -+ int ngroups = getgroups(count, groups); -+ -+ if (ngroups < 0) -+ FAIL_UNSUPPORTED ("Could not get group list again for user %jd\n", -+ (intmax_t) getuid ()); -+ -+ int n = 0; -+ for (int i = 0; i < ngroups; i++) -+ { -+ if (groups[i] != gid) -+ { -+ if (n != i) -+ groups[n] = groups[i]; -+ n++; -+ } -+ } -+ setgroups (n, groups); -+ - /* We have the binary, now spawn the subprocess. Avoid using - support_subprogram because we only want the program exit status, not the - contents. */ - -commit 8a726b63047241c6dd4b55bf85eacd02244362a2 -Author: Wilco Dijkstra -Date: Thu Jul 10 15:49:14 2025 +0000 - - malloc: Remove redundant NULL check - - Remove a redundant NULL check from tcache_get_n. - - Reviewed-by: Cupertino Miranda - (cherry picked from commit 089b4fb90fac8ed53039bc4c465c4d333c6b4048) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index 5ca390cc22..cf5c02ff64 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -3208,11 +3208,10 @@ tcache_get_n (size_t tc_idx, tcache_entry **ep, bool mangled) - if (__glibc_unlikely (misaligned_mem (e))) - malloc_printerr ("malloc(): unaligned tcache chunk detected"); - -- void *ne = e == NULL ? NULL : REVEAL_PTR (e->next); - if (!mangled) -- *ep = ne; -+ *ep = REVEAL_PTR (e->next); - else -- *ep = PROTECT_PTR (ep, ne); -+ *ep = PROTECT_PTR (ep, REVEAL_PTR (e->next)); - - ++(tcache->num_slots[tc_idx]); - e->key = 0; -@@ -3229,7 +3228,7 @@ tcache_put (mchunkptr chunk, size_t tc_idx) - static __always_inline void * - tcache_get (size_t tc_idx) - { -- return tcache_get_n (tc_idx, & tcache->entries[tc_idx], false); -+ return tcache_get_n (tc_idx, &tcache->entries[tc_idx], false); - } - - static __always_inline tcache_entry ** - -commit c491dabd8a3de090d1ccb4589421a44e79c5b185 -Author: Wilco Dijkstra -Date: Thu Jul 17 14:31:06 2025 +0000 - - malloc: Fix MAX_TCACHE_SMALL_SIZE - - MAX_TCACHE_SMALL_SIZE should use chunk size since it is used after - checked_request2size. Increase limit of tcache_max_bytes by 1 since all - comparisons use '<'. As a result, the last tcache entry is now used as - expected. - - Reviewed-by: DJ Delorie - (cherry picked from commit ad4caba4146583fc543cd434221dec7113c03e09) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index cf5c02ff64..b89b654f17 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -294,9 +294,9 @@ - # define TCACHE_SMALL_BINS 64 - # define TCACHE_LARGE_BINS 12 /* Up to 4M chunks */ - # define TCACHE_MAX_BINS (TCACHE_SMALL_BINS + TCACHE_LARGE_BINS) --# define MAX_TCACHE_SMALL_SIZE tidx2usize (TCACHE_SMALL_BINS-1) -+# define MAX_TCACHE_SMALL_SIZE tidx2csize (TCACHE_SMALL_BINS-1) - --/* Only used to pre-fill the tunables. */ -+# define tidx2csize(idx) (((size_t) idx) * MALLOC_ALIGNMENT + MINSIZE) - # define tidx2usize(idx) (((size_t) idx) * MALLOC_ALIGNMENT + MINSIZE - SIZE_SZ) - - /* When "x" is from chunksize(). */ -@@ -1932,7 +1932,7 @@ static struct malloc_par mp_ = - , - .tcache_count = TCACHE_FILL_COUNT, - .tcache_small_bins = TCACHE_SMALL_BINS, -- .tcache_max_bytes = MAX_TCACHE_SMALL_SIZE, -+ .tcache_max_bytes = MAX_TCACHE_SMALL_SIZE + 1, - .tcache_unsorted_limit = 0 /* No limit. */ - #endif - }; -@@ -5586,15 +5586,13 @@ do_set_arena_max (size_t value) - static __always_inline int - do_set_tcache_max (size_t value) - { -+ if (value > PTRDIFF_MAX) -+ return 0; -+ - size_t nb = request2size (value); - size_t tc_idx = csize2tidx (nb); - -- /* To check that value is not too big and request2size does not return an -- overflown value. */ -- if (value > nb) -- return 0; -- -- if (nb > MAX_TCACHE_SMALL_SIZE) -+ if (tc_idx >= TCACHE_SMALL_BINS) - tc_idx = large_csize2tidx (nb); - - LIBC_PROBE (memory_tunable_tcache_max_bytes, 2, value, mp_.tcache_max_bytes); -@@ -5603,7 +5601,7 @@ do_set_tcache_max (size_t value) - { - if (tc_idx < TCACHE_SMALL_BINS) - mp_.tcache_small_bins = tc_idx + 1; -- mp_.tcache_max_bytes = nb; -+ mp_.tcache_max_bytes = nb + 1; - return 1; - } - - -commit a96a82c4a5efd3139e75cd11fd2a5554164dd5a0 -Author: Samuel Thibault -Date: Wed Jul 30 01:55:22 2025 +0200 - - malloc: Make sure tcache_key is odd enough - - We want tcache_key not to be a commonly-occurring value in memory, so ensure - a minimum amount of one and zero bits. - - And we need it non-zero, otherwise even if tcache_double_free_verify sets - e->key to 0 before calling __libc_free, it gets called again by __libc_free, - thus looping indefinitely. - - Fixes: c968fe50628db74b52124d863cd828225a1d305c ("malloc: Use tailcalls in __libc_free") - (cherry picked from commit 2536c4f8584082a1ac4c5e0a2a6222e290d43983) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index b89b654f17..e4e2f03600 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -230,6 +230,9 @@ - /* For uintptr_t. */ - #include - -+/* For stdc_count_ones. */ -+#include -+ - /* For va_arg, va_start, va_end. */ - #include - -@@ -3152,6 +3155,19 @@ tcache_key_initialize (void) - if (__getrandom_nocancel_nostatus_direct (&tcache_key, sizeof(tcache_key), - GRND_NONBLOCK) - != sizeof (tcache_key)) -+ tcache_key = 0; -+ -+ /* We need tcache_key to be non-zero (otherwise tcache_double_free_verify's -+ clearing of e->key would go unnoticed and it would loop getting called -+ through __libc_free), and we want tcache_key not to be a -+ commonly-occurring value in memory, so ensure a minimum amount of one and -+ zero bits. */ -+ int minimum_bits = __WORDSIZE / 4; -+ int maximum_bits = __WORDSIZE - minimum_bits; -+ -+ while (labs (tcache_key) <= 0x1000000 -+ || stdc_count_ones (tcache_key) < minimum_bits -+ || stdc_count_ones (tcache_key) > maximum_bits) - { - tcache_key = random_bits (); - #if __WORDSIZE == 64 - -commit d7274d718e6f3655eabe311d4eb70fabb5ffa7ef -Author: Samuel Thibault -Date: Sun Aug 10 23:43:37 2025 +0200 - - malloc: Fix checking for small negative values of tcache_key - - tcache_key is unsigned so we should turn it explicitly to signed before - taking its absolute value. - - (cherry picked from commit 8543577b04ded6d979ffcc5a818930e4d74d0645) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index e4e2f03600..5f3e701fd1 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -3165,7 +3165,7 @@ tcache_key_initialize (void) - int minimum_bits = __WORDSIZE / 4; - int maximum_bits = __WORDSIZE - minimum_bits; - -- while (labs (tcache_key) <= 0x1000000 -+ while (labs ((intptr_t) tcache_key) <= 0x1000000 - || stdc_count_ones (tcache_key) < minimum_bits - || stdc_count_ones (tcache_key) > maximum_bits) - { - -commit 8dbaecbe92ac7ab73b7d0aae84626af59131e41b -Author: Jens Remus -Date: Fri Jul 25 15:40:03 2025 +0200 - - Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables [BZ #33234] - - Commit 10a66a8e421b ("Remove ") removed the TLS initial-exec - (IE) model attribute from the __libc_tsd_CTYPE_* thread variable declarations - and definitions. Commit a894f04d8776 ("Optimize __libc_tsd_* thread - variable access") restored it on declarations. - - Restore the TLS initial-exec model attribute on __libc_tsd_CTYPE_* thread - variable definitions. - - This resolves test tst-locale1 failure on s390 32-bit, when using a - GNU linker without the fix from GNU binutils commit aefebe82dc89 - ("IBM zSystems: Fix offset relative to static TLS"). - - Reviewed-by: Florian Weimer - (cherry picked from commit e5363e6f460c2d58809bf10fc96d70fd1ef8b5b2) - -diff --git a/NEWS b/NEWS -index 1d04bdfef8..69aa600c6d 100644 ---- a/NEWS -+++ b/NEWS -@@ -11,6 +11,7 @@ The following bugs were resolved with this release: - - [31943] _dl_find_object can fail if ld.so contains gaps between load segments - [32994] stdlib: resolve a double lock init issue after fork -+ [33234] Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables - [33245] nptl: nptl: error in internal cancellation syscall handling - - Version 2.42 -diff --git a/ctype/ctype-info.c b/ctype/ctype-info.c -index b7d3422726..fb5acf9419 100644 ---- a/ctype/ctype-info.c -+++ b/ctype/ctype-info.c -@@ -24,11 +24,11 @@ - __ctype_init before user code runs, but this does not happen for - threads in secondary namespaces. With the initializers, secondary - namespaces at least get locale data from the C locale. */ --__thread const uint16_t * __libc_tsd_CTYPE_B -+__thread const uint16_t * __libc_tsd_CTYPE_B attribute_tls_model_ie - = (const uint16_t *) _nl_C_LC_CTYPE_class + 128; --__thread const int32_t * __libc_tsd_CTYPE_TOLOWER -+__thread const int32_t * __libc_tsd_CTYPE_TOLOWER attribute_tls_model_ie - = (const int32_t *) _nl_C_LC_CTYPE_tolower + 128; --__thread const int32_t * __libc_tsd_CTYPE_TOUPPER -+__thread const int32_t * __libc_tsd_CTYPE_TOUPPER attribute_tls_model_ie - = (const int32_t *) _nl_C_LC_CTYPE_toupper + 128; - - - -commit d0f72b96f2e91e1aa93f7e826c71f74078ada7d0 -Author: H.J. Lu -Date: Mon Jul 28 12:16:11 2025 -0700 - - i386: Add GLIBC_ABI_GNU_TLS version [BZ #33221] - - On i386, programs and shared libraries with __thread usage may fail - silently at run-time against glibc without the TLS run-time fix for: - - https://sourceware.org/bugzilla/show_bug.cgi?id=32996 - - Add GLIBC_ABI_GNU_TLS version to indicate that glibc has the working - GNU TLS run-time. Linker can add the GLIBC_ABI_GNU_TLS version to - binaries which depend on the working TLS run-time so that such programs - and shared libraries will fail to load and run at run-time against - libc.so without the GLIBC_ABI_GNU_TLS version, instead of fail silently - at random. - - This fixes BZ #33221. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit ed1b7a5a489ab555a27fad9c101ebe2e1c1ba881) - -diff --git a/sysdeps/i386/Makefile b/sysdeps/i386/Makefile -index ee6470d78e..c0c017b899 100644 ---- a/sysdeps/i386/Makefile -+++ b/sysdeps/i386/Makefile -@@ -60,6 +60,15 @@ $(objpfx)tst-ld-sse-use.out: ../sysdeps/i386/tst-ld-sse-use.sh $(objpfx)ld.so - @echo "Checking ld.so for SSE register use. This will take a few seconds..." - $(BASH) $< $(objpfx) '$(NM)' '$(OBJDUMP)' '$(READELF)' > $@; \ - $(evaluate-test) -+ -+tests-special += $(objpfx)check-gnu-tls.out -+ -+$(objpfx)check-gnu-tls.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_GNU_TLS > $@; \ -+ $(evaluate-test) -+generated += check-gnu-tls.out - else - CFLAGS-.os += $(if $(filter rtld-%.os,$(@F)), $(rtld-CFLAGS)) - endif -diff --git a/sysdeps/i386/Versions b/sysdeps/i386/Versions -index 36e23b466a..9c84c8ef04 100644 ---- a/sysdeps/i386/Versions -+++ b/sysdeps/i386/Versions -@@ -28,6 +28,11 @@ libc { - GLIBC_2.13 { - __fentry__; - } -+ GLIBC_ABI_GNU_TLS { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } - libm { - GLIBC_2.1 { - -commit 3970785bebcc3f1de4460072f3a041d178f64846 -Author: H.J. Lu -Date: Mon Jul 28 12:18:22 2025 -0700 - - x86-64: Add GLIBC_ABI_GNU2_TLS version [BZ #33129] - - Programs and shared libraries compiled with -mtls-dialect=gnu2 may fail - silently at run-time against glibc without the GNU2 TLS run-time fix - for: - - https://sourceware.org/bugzilla/show_bug.cgi?id=31372 - - Add GLIBC_ABI_GNU2_TLS version to indicate that glibc has the working - GNU2 TLS run-time. Linker can add the GLIBC_ABI_GNU2_TLS version to - binaries which depend on the working GNU2 TLS run-time: - - https://sourceware.org/bugzilla/show_bug.cgi?id=33130 - - so that such programs and shared libraries will fail to load and run at - run-time against libc.so without the GLIBC_ABI_GNU2_TLS version, instead - of fail silently at random. - - This fixes BZ #33129. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit 9df8fa397d515dc86ff5565f6c45625e672d539e) - -diff --git a/sysdeps/x86_64/Makefile b/sysdeps/x86_64/Makefile -index c3e1065c81..3ab8c1ed0f 100644 ---- a/sysdeps/x86_64/Makefile -+++ b/sysdeps/x86_64/Makefile -@@ -212,6 +212,15 @@ LDFLAGS-tst-plt-rewrite2 = -Wl,-z,now - LDFLAGS-tst-plt-rewritemod2.so = -Wl,-z,now,-z,undefs - tst-plt-rewrite2-ENV = GLIBC_TUNABLES=glibc.cpu.plt_rewrite=2 - $(objpfx)tst-plt-rewrite2: $(objpfx)tst-plt-rewritemod2.so -+ -+tests-special += $(objpfx)check-gnu2-tls.out -+ -+$(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_GNU2_TLS > $@; \ -+ $(evaluate-test) -+generated += check-gnu2-tls.out - endif - - test-internal-extras += tst-gnu2-tls2mod1 -diff --git a/sysdeps/x86_64/Versions b/sysdeps/x86_64/Versions -index e94758b236..a63c11bcb2 100644 ---- a/sysdeps/x86_64/Versions -+++ b/sysdeps/x86_64/Versions -@@ -5,6 +5,11 @@ libc { - GLIBC_2.13 { - __fentry__; - } -+ GLIBC_ABI_GNU2_TLS { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } - libm { - GLIBC_2.1 { - -commit 7a8f3c6ee4b565a02da4ba0dad9aaeaeed4639ce -Author: H.J. Lu -Date: Thu Aug 14 07:03:20 2025 -0700 - - x86-64: Add GLIBC_ABI_DT_X86_64_PLT [BZ #33212] - - When the linker -z mark-plt option is used to add DT_X86_64_PLT, - DT_X86_64_PLTSZ and DT_X86_64_PLTENT, the r_addend field of the - R_X86_64_JUMP_SLOT relocation stores the offset of the indirect - branch instruction. However, glibc versions without the commit: - - commit f8587a61892cbafd98ce599131bf4f103466f084 - Author: H.J. Lu - Date: Fri May 20 19:21:48 2022 -0700 - - x86-64: Ignore r_addend for R_X86_64_GLOB_DAT/R_X86_64_JUMP_SLOT - - According to x86-64 psABI, r_addend should be ignored for R_X86_64_GLOB_DAT - and R_X86_64_JUMP_SLOT. Since linkers always set their r_addends to 0, we - can ignore their r_addends. - - Reviewed-by: Fangrui Song - - won't ignore the r_addend value in the R_X86_64_JUMP_SLOT relocation. - Such programs and shared libraries will fail at run-time randomly. - - Add GLIBC_ABI_DT_X86_64_PLT version to indicate that glibc is compatible - with DT_X86_64_PLT. - - The linker can add the glibc GLIBC_ABI_DT_X86_64_PLT version dependency - whenever -z mark-plt is passed to the linker. The resulting programs and - shared libraries will fail to load at run-time against libc.so without the - GLIBC_ABI_DT_X86_64_PLT version, instead of fail randomly. - - This fixes BZ #33212. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit 399384e0c8193e31aea014220ccfa24300ae5938) - -diff --git a/sysdeps/x86_64/Makefile b/sysdeps/x86_64/Makefile -index 3ab8c1ed0f..01100597a8 100644 ---- a/sysdeps/x86_64/Makefile -+++ b/sysdeps/x86_64/Makefile -@@ -213,6 +213,15 @@ LDFLAGS-tst-plt-rewritemod2.so = -Wl,-z,now,-z,undefs - tst-plt-rewrite2-ENV = GLIBC_TUNABLES=glibc.cpu.plt_rewrite=2 - $(objpfx)tst-plt-rewrite2: $(objpfx)tst-plt-rewritemod2.so - -+tests-special += $(objpfx)check-dt-x86-64-plt.out -+ -+$(objpfx)check-dt-x86-64-plt.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_DT_X86_64_PLT > $@; \ -+ $(evaluate-test) -+generated += check-dt-x86-64-plt.out -+ - tests-special += $(objpfx)check-gnu2-tls.out - - $(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -diff --git a/sysdeps/x86_64/Versions b/sysdeps/x86_64/Versions -index a63c11bcb2..0a759029e5 100644 ---- a/sysdeps/x86_64/Versions -+++ b/sysdeps/x86_64/Versions -@@ -10,6 +10,11 @@ libc { - # by scripts/versions.awk. - __placeholder_only_for_empty_version_map; - } -+ GLIBC_ABI_DT_X86_64_PLT { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } - libm { - GLIBC_2.1 { - -commit e87844ec42b77363a499ea4da6c4a6ab85eba310 -Author: H.J. Lu -Date: Mon Aug 18 09:06:48 2025 -0700 - - i386: Also add GLIBC_ABI_GNU2_TLS version [BZ #33129] - - Since the GNU2 TLS run-time bug: - - https://sourceware.org/bugzilla/show_bug.cgi?id=31372 - - affects both i386 and x86-64, also add GLIBC_ABI_GNU2_TLS version to i386 - to indicate the working GNU2 TLS run-time. For x86-64, the additional - GNU2 TLS run-time bug fix is needed for - - https://sourceware.org/bugzilla/show_bug.cgi?id=31501 - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit bd4628f3f18ac312408782eea450429c6f044860) - -diff --git a/sysdeps/x86/Makefile b/sysdeps/x86/Makefile -index 4fbd48e1c8..9e1c8cce85 100644 ---- a/sysdeps/x86/Makefile -+++ b/sysdeps/x86/Makefile -@@ -135,6 +135,15 @@ LDFLAGS-tst-tls23 += -rdynamic - tst-tls23-mod.so-no-z-defs = yes - - $(objpfx)tst-tls23-mod.so: $(libsupport) -+ -+tests-special += $(objpfx)check-gnu2-tls.out -+ -+$(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_GNU2_TLS > $@; \ -+ $(evaluate-test) -+generated += check-gnu2-tls.out - endif - - ifeq ($(subdir),gmon) -diff --git a/sysdeps/x86/Versions b/sysdeps/x86/Versions -index 4b10c4b5d7..e8dcfccbe4 100644 ---- a/sysdeps/x86/Versions -+++ b/sysdeps/x86/Versions -@@ -7,4 +7,9 @@ libc { - GLIBC_2.33 { - __x86_get_cpuid_feature_leaf; - } -+ GLIBC_ABI_GNU2_TLS { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } -diff --git a/sysdeps/x86_64/Makefile b/sysdeps/x86_64/Makefile -index 01100597a8..fe9f1cdddb 100644 ---- a/sysdeps/x86_64/Makefile -+++ b/sysdeps/x86_64/Makefile -@@ -221,15 +221,6 @@ $(objpfx)check-dt-x86-64-plt.out: $(common-objpfx)libc.so - | grep GLIBC_ABI_DT_X86_64_PLT > $@; \ - $(evaluate-test) - generated += check-dt-x86-64-plt.out -- --tests-special += $(objpfx)check-gnu2-tls.out -- --$(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -- LC_ALL=C $(READELF) -V -W $< \ -- | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -- | grep GLIBC_ABI_GNU2_TLS > $@; \ -- $(evaluate-test) --generated += check-gnu2-tls.out - endif - - test-internal-extras += tst-gnu2-tls2mod1 -diff --git a/sysdeps/x86_64/Versions b/sysdeps/x86_64/Versions -index 0a759029e5..6a989ad3b3 100644 ---- a/sysdeps/x86_64/Versions -+++ b/sysdeps/x86_64/Versions -@@ -5,11 +5,6 @@ libc { - GLIBC_2.13 { - __fentry__; - } -- GLIBC_ABI_GNU2_TLS { -- # This symbol is used only for empty version map and will be removed -- # by scripts/versions.awk. -- __placeholder_only_for_empty_version_map; -- } - GLIBC_ABI_DT_X86_64_PLT { - # This symbol is used only for empty version map and will be removed - # by scripts/versions.awk. - -commit e34453cd6a8c592c325756ff3c7ac0afd3975cb4 -Author: Pierre Blanchard -Date: Wed Aug 20 17:41:50 2025 +0000 - - AArch64: Fix SVE powf routine [BZ #33299] - - Fix a bug in predicate logic introduced in last change. - A slight performance improvement from relying on all true - predicates during conversion from single to double. - This fixes BZ #33299. - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit aac077645a645bba0d67f3250e82017c539d0f4b) - -diff --git a/sysdeps/aarch64/fpu/powf_sve.c b/sysdeps/aarch64/fpu/powf_sve.c -index 7046990aa1..65e9bd29d9 100644 ---- a/sysdeps/aarch64/fpu/powf_sve.c -+++ b/sysdeps/aarch64/fpu/powf_sve.c -@@ -223,15 +223,15 @@ sv_powf_core (const svbool_t pg, svuint32_t i, svuint32_t iz, svint32_t k, - const svbool_t ptrue = svptrue_b64 (); - - /* Unpack and promote input vectors (pg, y, z, i, k and sign_bias) into two -- * in order to perform core computation in double precision. */ -+ in order to perform core computation in double precision. */ - const svbool_t pg_lo = svunpklo (pg); - const svbool_t pg_hi = svunpkhi (pg); -- svfloat64_t y_lo -- = svcvt_f64_x (pg, svreinterpret_f32 (svunpklo (svreinterpret_u32 (y)))); -- svfloat64_t y_hi -- = svcvt_f64_x (pg, svreinterpret_f32 (svunpkhi (svreinterpret_u32 (y)))); -- svfloat64_t z_lo = svcvt_f64_x (pg, svreinterpret_f32 (svunpklo (iz))); -- svfloat64_t z_hi = svcvt_f64_x (pg, svreinterpret_f32 (svunpkhi (iz))); -+ svfloat64_t y_lo = svcvt_f64_x ( -+ ptrue, svreinterpret_f32 (svunpklo (svreinterpret_u32 (y)))); -+ svfloat64_t y_hi = svcvt_f64_x ( -+ ptrue, svreinterpret_f32 (svunpkhi (svreinterpret_u32 (y)))); -+ svfloat64_t z_lo = svcvt_f64_x (ptrue, svreinterpret_f32 (svunpklo (iz))); -+ svfloat64_t z_hi = svcvt_f64_x (ptrue, svreinterpret_f32 (svunpkhi (iz))); - svuint64_t i_lo = svunpklo (i); - svuint64_t i_hi = svunpkhi (i); - svint64_t k_lo = svunpklo (k); -@@ -312,7 +312,7 @@ svfloat32_t SV_NAME_F2 (pow) (svfloat32_t x, svfloat32_t y, const svbool_t pg) - (23 - V_POWF_EXP2_TABLE_BITS)); - - /* Compute core in extended precision and return intermediate ylogx results -- * to handle cases of underflow and underflow in exp. */ -+ to handle cases of underflow and overflow in exp. */ - svfloat32_t ylogx; - svfloat32_t ret - = sv_powf_core (yint_or_xpos, i, iz, k, y, sign_bias, &ylogx, d); - -commit 1166170d95863e5a6f8121a5ca9d97713f524f49 -Author: Florian Weimer -Date: Fri Sep 5 19:02:57 2025 +0200 - - libio: Define AT_RENAME_* with the same tokens as Linux - - Linux uses different expressions for the RENAME_* and AT_RENAME_* - constants. Mirror that in , so that the macro redefinitions - do not result in preprocessor warnings. - - Reviewed-by: Collin Funk - (cherry picked from commit b173557da978a04ac3bdfc0bd3b0e7ac583b44d5) - -diff --git a/libio/stdio.h b/libio/stdio.h -index d042b36618..e0e70945fa 100644 ---- a/libio/stdio.h -+++ b/libio/stdio.h -@@ -168,11 +168,11 @@ extern int renameat (int __oldfd, const char *__old, int __newfd, - #ifdef __USE_GNU - /* Flags for renameat2. */ - # define RENAME_NOREPLACE (1 << 0) --# define AT_RENAME_NOREPLACE RENAME_NOREPLACE -+# define AT_RENAME_NOREPLACE 0x0001 - # define RENAME_EXCHANGE (1 << 1) --# define AT_RENAME_EXCHANGE RENAME_EXCHANGE -+# define AT_RENAME_EXCHANGE 0x0002 - # define RENAME_WHITEOUT (1 << 2) --# define AT_RENAME_WHITEOUT RENAME_WHITEOUT -+# define AT_RENAME_WHITEOUT 0x0004 - - /* Rename file OLD relative to OLDFD to NEW relative to NEWFD, with - additional flags. */ -diff --git a/stdio-common/tst-renameat2.c b/stdio-common/tst-renameat2.c -index 12aa0f8b0f..6213e1376d 100644 ---- a/stdio-common/tst-renameat2.c -+++ b/stdio-common/tst-renameat2.c -@@ -28,6 +28,12 @@ - #include - #include - -+/* These constants are defined with different token sequences, -+ matching the Linux definitions, to avoid preprocessor warnings. */ -+_Static_assert (RENAME_NOREPLACE == AT_RENAME_NOREPLACE, "RENAME_NOREPLACE"); -+_Static_assert (RENAME_EXCHANGE == AT_RENAME_EXCHANGE, "RENAME_EXCHANGE"); -+_Static_assert (RENAME_WHITEOUT == AT_RENAME_WHITEOUT, "RENAME_WHITEOUT"); -+ - /* Directory with the temporary files. */ - static char *directory; - static int directory_fd; - -commit 46b4e37c9e0619d0cf065ba207c29996b326a06f -Author: Florian Weimer -Date: Fri Sep 12 21:33:34 2025 +0200 - - nss: Group merge does not react to ERANGE during merge (bug 33361) - - The break statement in CHECK_MERGE is expected to exit the surrounding - while loop, not the do-while loop with in the macro. Remove the - do-while loop from the macro. It is not needed to turn the macro - expansion into a single statement due to the way CHECK_MERGE is used - (and the statement expression would cover this anyway). - - Reviewed-by: Collin Funk - (cherry picked from commit 0fceed254559836b57ee05188deac649bc505d05) - -diff --git a/NEWS b/NEWS -index 69aa600c6d..06c27a8e17 100644 ---- a/NEWS -+++ b/NEWS -@@ -13,6 +13,7 @@ The following bugs were resolved with this release: - [32994] stdlib: resolve a double lock init issue after fork - [33234] Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables - [33245] nptl: nptl: error in internal cancellation syscall handling -+ [33361] nss: Group merge does not react to ERANGE during merge - - Version 2.42 - -diff --git a/nss/getXXbyYY_r.c b/nss/getXXbyYY_r.c -index eae6c3480e..2b0735fb6a 100644 ---- a/nss/getXXbyYY_r.c -+++ b/nss/getXXbyYY_r.c -@@ -157,19 +157,15 @@ __merge_einval (LOOKUP_TYPE *a, - - #define CHECK_MERGE(err, status) \ - ({ \ -- do \ -+ if (err) \ - { \ -- if (err) \ -- { \ -- __set_errno (err); \ -- if (err == ERANGE) \ -- status = NSS_STATUS_TRYAGAIN; \ -- else \ -- status = NSS_STATUS_UNAVAIL; \ -- break; \ -- } \ -+ __set_errno (err); \ -+ if (err == ERANGE) \ -+ status = NSS_STATUS_TRYAGAIN; \ -+ else \ -+ status = NSS_STATUS_UNAVAIL; \ -+ break; \ - } \ -- while (0); \ - }) - - /* Type of the lookup function we need here. */ - -commit 18fd689cdced8348e42991964557cddea0ba2dc5 -Author: Adhemerval Zanella -Date: Mon Sep 8 13:06:13 2025 -0300 - - nptl: Fix MADV_GUARD_INSTALL logic for thread without guard page (BZ 33356) - - The main issue is that setup_stack_prot fails to account for cases where - the cached thread stack lacks a guard page, which can cause madvise to - fail. Update the logic to also handle whether MADV_GUARD_INSTALL is - supported when resizing the guard page. - - Checked on x86_64-linux-gnu with 6.8.0 and 6.15 kernels. - - Reviewed-by: Florian Weimer - (cherry picked from commit 855bfa2566bbefefa27c516b344df58a75824a5c) - -diff --git a/NEWS b/NEWS -index 06c27a8e17..ed3c114c7a 100644 ---- a/NEWS -+++ b/NEWS -@@ -13,6 +13,8 @@ The following bugs were resolved with this release: - [32994] stdlib: resolve a double lock init issue after fork - [33234] Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables - [33245] nptl: nptl: error in internal cancellation syscall handling -+ [33356] nptl: creating thread stack with guardsize 0 can erroneously -+ conclude MADV_GUARD_INSTALL is available - [33361] nss: Group merge does not react to ERANGE during merge - - Version 2.42 -diff --git a/nptl/allocatestack.c b/nptl/allocatestack.c -index 800ca89720..fb8a60a21d 100644 ---- a/nptl/allocatestack.c -+++ b/nptl/allocatestack.c -@@ -240,7 +240,7 @@ setup_stack_prot (char *mem, size_t size, struct pthread *pd, - /* Update the guard area of the thread stack MEM of size SIZE with the new - GUARDISZE. It uses the method defined by PD stack_mode. */ - static inline bool --adjust_stack_prot (char *mem, size_t size, const struct pthread *pd, -+adjust_stack_prot (char *mem, size_t size, struct pthread *pd, - size_t guardsize, size_t pagesize_m1) - { - /* The required guard area is larger than the current one. For -@@ -258,11 +258,23 @@ adjust_stack_prot (char *mem, size_t size, const struct pthread *pd, - so use the new guard placement with the new size. */ - if (guardsize > pd->guardsize) - { -+ /* There was no need to previously setup a guard page, so we need -+ to check whether the kernel supports guard advise. */ - char *guard = guard_position (mem, size, guardsize, pd, pagesize_m1); -- if (pd->stack_mode == ALLOCATE_GUARD_MADV_GUARD) -- return __madvise (guard, guardsize, MADV_GUARD_INSTALL) == 0; -- else if (pd->stack_mode == ALLOCATE_GUARD_PROT_NONE) -- return __mprotect (guard, guardsize, PROT_NONE) == 0; -+ if (atomic_load_relaxed (&allocate_stack_mode) -+ == ALLOCATE_GUARD_MADV_GUARD) -+ { -+ if (__madvise (guard, guardsize, MADV_GUARD_INSTALL) == 0) -+ { -+ pd->stack_mode = ALLOCATE_GUARD_MADV_GUARD; -+ return true; -+ } -+ atomic_store_relaxed (&allocate_stack_mode, -+ ALLOCATE_GUARD_PROT_NONE); -+ } -+ -+ pd->stack_mode = ALLOCATE_GUARD_PROT_NONE; -+ return __mprotect (guard, guardsize, PROT_NONE) == 0; - } - /* The current guard area is larger than the required one. For - _STACK_GROWS_DOWN is means change the guard as: -diff --git a/nptl/tst-guard1.c b/nptl/tst-guard1.c -index e3e06df0fc..1c73d3fc93 100644 ---- a/nptl/tst-guard1.c -+++ b/nptl/tst-guard1.c -@@ -21,6 +21,7 @@ - #include - #include - #include -+#include - #include - #include - #include -@@ -202,7 +203,7 @@ tf (void *closure) - - /* Test 1: caller provided stack without guard. */ - static void --do_test1 (void) -+do_test1 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -227,7 +228,7 @@ do_test1 (void) - - /* Test 2: same as 1., but with a guard area. */ - static void --do_test2 (void) -+do_test2 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -250,18 +251,9 @@ do_test2 (void) - xmunmap (stack, stacksize); - } - --/* Test 3: pthread_create with default values. */ -+/* Test 3: pthread_create without a guard area. */ - static void --do_test3 (void) --{ -- pthread_t t = xpthread_create (NULL, tf, NULL); -- void *status = xpthread_join (t); -- TEST_VERIFY (status == 0); --} -- --/* Test 4: pthread_create without a guard area. */ --static void --do_test4 (void) -+do_test3 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -277,9 +269,18 @@ do_test4 (void) - xpthread_attr_destroy (&attr); - } - -+/* Test 4: pthread_create with default values. */ -+static void -+do_test4 (void *closure) -+{ -+ pthread_t t = xpthread_create (NULL, tf, NULL); -+ void *status = xpthread_join (t); -+ TEST_VERIFY (status == 0); -+} -+ - /* Test 5: pthread_create with non default stack and guard size value. */ - static void --do_test5 (void) -+do_test5 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -299,7 +300,7 @@ do_test5 (void) - test 3, but with a larger guard area. The pthread_create will need to - increase the guard area. */ - static void --do_test6 (void) -+do_test6 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -320,7 +321,7 @@ do_test6 (void) - pthread_create should use the cached stack from previous tests, but it - would require to reduce the guard area. */ - static void --do_test7 (void) -+do_test7 (void *closure) - { - pthread_t t = xpthread_create (NULL, tf, NULL); - void *status = xpthread_join (t); -@@ -346,21 +347,40 @@ do_test (void) - - static const struct { - const char *descr; -- void (*test)(void); -+ void (*test) (void *); - } tests[] = { - { "user provided stack without guard", do_test1 }, - { "user provided stack with guard", do_test2 }, -- { "default attribute", do_test3 }, -- { "default attribute without guard", do_test4 }, -+ /* N.B: do_test3 should be before do_test4 to check if a new thread -+ that uses the thread stack previously allocated without a guard -+ page correctly sets up the guard pages even on a kernel without -+ MADV_GUARD_INSTALL support (BZ 33356). */ -+ { "default attribute without guard", do_test3 }, -+ { "default attribute", do_test4 }, -+ /* Also checks if the guard is correctly removed from the cache thread -+ stack. */ -+ { "default attribute without guard", do_test3 }, - { "non default stack and guard sizes", do_test5 }, - { "reused stack with larger guard", do_test6 }, - { "reused stack with smaller guard", do_test7 }, - }; - -+ /* Run each test with a clean state. */ -+ for (int i = 0; i < array_length (tests); i++) -+ { -+ printf ("debug: fork: test%01d: %s\n", i, tests[i].descr); -+ struct support_capture_subprocess result = -+ support_capture_subprocess (tests[i].test, NULL); -+ support_capture_subprocess_check (&result, tests[i].descr, 0, -+ sc_allow_none); -+ support_capture_subprocess_free (&result); -+ } -+ -+ /* And now run the same tests along with the thread stack cache. */ - for (int i = 0; i < array_length (tests); i++) - { - printf ("debug: test%01d: %s\n", i, tests[i].descr); -- tests[i].test(); -+ tests[i].test ( NULL); - } - - return 0; - -commit bf48b17a28066a54f172e0d63da9fc5dc60c6355 -Author: Sunil K Pandey -Date: Mon Oct 6 18:13:04 2025 -0700 - - x86: Detect Intel Wildcat Lake Processor - - Detect Intel Wildcat Lake Processor and tune it similar to Intel Panther - Lake. https://cdrdv2.intel.com/v1/dl/getContent/671368 Section 1.2. - - Reviewed-by: H.J. Lu - (cherry picked from commit f8dd52901b72805a831d5a4cb7d971e4a3c9970b) - -diff --git a/sysdeps/x86/cpu-features.c b/sysdeps/x86/cpu-features.c -index b7d1506135..4bdade883e 100644 ---- a/sysdeps/x86/cpu-features.c -+++ b/sysdeps/x86/cpu-features.c -@@ -543,6 +543,7 @@ enum intel_microarch - INTEL_BIGCORE_PANTHERLAKE, - INTEL_BIGCORE_GRANITERAPIDS, - INTEL_BIGCORE_DIAMONDRAPIDS, -+ INTEL_BIGCORE_WILDCATLAKE, - - /* Mixed (bigcore + atom SOC). */ - INTEL_MIXED_LAKEFIELD, -@@ -702,6 +703,8 @@ intel_get_fam6_microarch (unsigned int model, - return INTEL_BIGCORE_ARROWLAKE; - case 0xCC: - return INTEL_BIGCORE_PANTHERLAKE; -+ case 0xD5: -+ return INTEL_BIGCORE_WILDCATLAKE; - case 0xAD: - case 0xAE: - return INTEL_BIGCORE_GRANITERAPIDS; -@@ -934,6 +937,7 @@ disable_tsx: - case INTEL_BIGCORE_LUNARLAKE: - case INTEL_BIGCORE_ARROWLAKE: - case INTEL_BIGCORE_PANTHERLAKE: -+ case INTEL_BIGCORE_WILDCATLAKE: - case INTEL_BIGCORE_SAPPHIRERAPIDS: - case INTEL_BIGCORE_EMERALDRAPIDS: - case INTEL_BIGCORE_GRANITERAPIDS: - -commit ab8c1b5d62d7be2c3c23f535bea3d7fff19c53ae -Author: Sunil K Pandey -Date: Wed Sep 24 09:38:17 2025 -0700 - - x86: Detect Intel Nova Lake Processor - - Detect Intel Nova Lake Processor and tune it similar to Intel Panther - Lake. https://cdrdv2.intel.com/v1/dl/getContent/671368 Section 1.2. - - Reviewed-by: H.J. Lu - (cherry picked from commit a114e29ddd530962d2b44aa9d89f1f6075abe7fa) - -diff --git a/sysdeps/x86/cpu-features.c b/sysdeps/x86/cpu-features.c -index 4bdade883e..b67ef541dd 100644 ---- a/sysdeps/x86/cpu-features.c -+++ b/sysdeps/x86/cpu-features.c -@@ -544,6 +544,7 @@ enum intel_microarch - INTEL_BIGCORE_GRANITERAPIDS, - INTEL_BIGCORE_DIAMONDRAPIDS, - INTEL_BIGCORE_WILDCATLAKE, -+ INTEL_BIGCORE_NOVALAKE, - - /* Mixed (bigcore + atom SOC). */ - INTEL_MIXED_LAKEFIELD, -@@ -821,6 +822,17 @@ disable_tsx: - break; - } - } -+ else if (family == 18) -+ switch (model) -+ { -+ case 0x01: -+ case 0x03: -+ microarch = INTEL_BIGCORE_NOVALAKE; -+ break; -+ -+ default: -+ break; -+ } - else if (family == 19) - switch (model) - { -@@ -938,6 +950,7 @@ disable_tsx: - case INTEL_BIGCORE_ARROWLAKE: - case INTEL_BIGCORE_PANTHERLAKE: - case INTEL_BIGCORE_WILDCATLAKE: -+ case INTEL_BIGCORE_NOVALAKE: - case INTEL_BIGCORE_SAPPHIRERAPIDS: - case INTEL_BIGCORE_EMERALDRAPIDS: - case INTEL_BIGCORE_GRANITERAPIDS: - -commit 6de12fc9ad56bc19fa6fcbd8ee502f29b5170d47 -Author: Yury Khrustalev -Date: Thu Sep 25 15:51:30 2025 +0100 - - aarch64: define macro for calling __libc_arm_za_disable - - A common sequence of instructions is used in several places - in assembly files, so define it in one place as an assembly - macro. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit b4b713bd8921aff04773557da94fabb5fb9dd705) - -diff --git a/sysdeps/aarch64/__longjmp.S b/sysdeps/aarch64/__longjmp.S -index 70ac02c44b..53b42e1bdc 100644 ---- a/sysdeps/aarch64/__longjmp.S -+++ b/sysdeps/aarch64/__longjmp.S -@@ -26,16 +26,8 @@ - ENTRY (__longjmp) - - #if IS_IN(libc) -- /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. -- The calling convention of __libc_arm_za_disable allows to do -- this thus allowing to avoid saving to and reading from stack. -- As a result we also don't need to sign the return address and -- check it after returning because it is not stored to stack. */ -- mov x13, x30 -- cfi_register (x30, x13) -- bl __libc_arm_za_disable -- mov x30, x13 -- cfi_register (x13, x30) -+ /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. */ -+ CALL_LIBC_ARM_ZA_DISABLE - #endif - - cfi_def_cfa (x0, 0) -diff --git a/sysdeps/aarch64/setjmp.S b/sysdeps/aarch64/setjmp.S -index 53c5e7d8cc..92cedfad83 100644 ---- a/sysdeps/aarch64/setjmp.S -+++ b/sysdeps/aarch64/setjmp.S -@@ -37,16 +37,8 @@ ENTRY_ALIGN (__sigsetjmp, 2) - 1: - - #if IS_IN(libc) -- /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. -- The calling convention of __libc_arm_za_disable allows to do -- this thus allowing to avoid saving to and reading from stack. -- As a result we also don't need to sign the return address and -- check it after returning because it is not stored to stack. */ -- mov x13, x30 -- cfi_register (x30, x13) -- bl __libc_arm_za_disable -- mov x30, x13 -- cfi_register (x13, x30) -+ /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. */ -+ CALL_LIBC_ARM_ZA_DISABLE - #endif - - stp x19, x20, [x0, #JB_X19<<3] -diff --git a/sysdeps/unix/sysv/linux/aarch64/setcontext.S b/sysdeps/unix/sysv/linux/aarch64/setcontext.S -index d9716f012e..8e98594663 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/setcontext.S -+++ b/sysdeps/unix/sysv/linux/aarch64/setcontext.S -@@ -49,15 +49,7 @@ ENTRY (__setcontext) - b C_SYMBOL_NAME (__syscall_error) - 1: - /* Clear ZA state of SME. */ -- /* The calling convention of __libc_arm_za_disable allows to do -- this thus allowing to avoid saving to and reading from stack. -- As a result we also don't need to sign the return address and -- check it after returning because it is not stored to stack. */ -- mov x13, x30 -- cfi_register (x30, x13) -- bl __libc_arm_za_disable -- mov x30, x13 -- cfi_register (x13, x30) -+ CALL_LIBC_ARM_ZA_DISABLE - /* Restore the general purpose registers. */ - mov x0, x9 - cfi_def_cfa (x0, 0) -diff --git a/sysdeps/unix/sysv/linux/aarch64/sysdep.h b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -index f0e8d64eef..fa01386b25 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/sysdep.h -+++ b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -@@ -150,6 +150,18 @@ - mov x8, SYS_ify (syscall_name); \ - svc 0 - -+/* Clear ZA state of SME (ASM version). */ -+/* The __libc_arm_za_disable function has special calling convention -+ that allows to call it without stack manipulation and preserving -+ most of the registers. */ -+ .macro CALL_LIBC_ARM_ZA_DISABLE -+ mov x13, x30 -+ .cfi_register x30, x13 -+ bl __libc_arm_za_disable -+ mov x30, x13 -+ .cfi_register x13, x30 -+ .endm -+ - #else /* not __ASSEMBLER__ */ - - # define VDSO_NAME "LINUX_2.6.39" - -commit 256030b9842a10b1f22851b1de0c119761417544 -Author: Yury Khrustalev -Date: Thu Sep 25 15:54:36 2025 +0100 - - aarch64: clear ZA state of SME before clone and clone3 syscalls - - This change adds a call to the __arm_za_disable() function immediately - before the SVC instruction inside clone() and clone3() wrappers. It also - adds a macro for inline clone() used in fork() and adds the same call to - the vfork implementation. This sets the ZA state of SME to "off" on return - from these functions (for both the child and the parent). - - The __arm_za_disable() function is described in [1] (8.1.3). Note that - the internal Glibc name for this function is __libc_arm_za_disable(). - - When this change was originally proposed [2,3], it generated a long - discussion where several questions and concerns were raised. Here we - will address these concerns and explain why this change is useful and, - in fact, necessary. - - In a nutshell, a C library that conforms to the AAPCS64 spec [1] (pertinent - to this change, mainly, the chapters 6.2 and 6.6), should have a call to the - __arm_za_disable() function in clone() and clone3() wrappers. The following - explains in detail why this is the case. - - When we consider using the __arm_za_disable() function inside the clone() - and clone3() libc wrappers, we talk about the C library subroutines clone() - and clone3() rather than the syscalls with similar names. In the current - version of Glibc, clone() is public and clone3() is private, but it being - private is not pertinent to this discussion. - - We will begin with stating that this change is NOT a bug fix for something - in the kernel. The requirement to call __arm_za_disable() does NOT come from - the kernel. It also is NOT needed to satisfy a contract between the kernel - and userspace. This is why it is not for the kernel documentation to describe - this requirement. This requirement is instead needed to satisfy a pure userspace - scheme outlined in [1] and to make sure that software that uses Glibc (or any - other C library that has correct handling of SME states (see below)) conforms - to [1] without having to unnecessarily become SME-aware thus losing portability. - - To recap (see [1] (6.2)), SME extension defines SME state which is part of - processor state. Part of this SME state is ZA state that is necessary to - manage ZA storage register in the context of the ZA lazy saving scheme [1] - (6.6). This scheme exists because it would be challenging to handle ZA - storage of SME in either callee-saved or caller-saved manner. - - There are 3 kinds of ZA state that are defined in terms of the PSTATE.ZA - bit and the TPIDR2_EL0 register (see [1] (6.6.3)): - - - "off":       PSTATE.ZA == 0 - - "active":    PSTATE.ZA == 1 TPIDR2_EL0 == null - - "dormant":   PSTATE.ZA == 1 TPIDR2_EL0 != null - - As [1] (6.7.2) outlines, every subroutine has exactly one SME-interface - depending on the permitted ZA-states on entry and on normal return from - a call to this subroutine. Callers of a subroutine must know and respect - the ZA-interface of the subroutines they are using. Using a subroutine - in a way that is not permitted by its ZA-interface is undefined behaviour. - - In particular, clone() and clone3() (the C library functions) have the - ZA-private interface. This means that the permitted ZA-states on entry - are "off" and "dormant" and that the permitted states on return are "off" - or "dormant" (but if and only if it was "dormant" on entry). - - This means that both functions in question should correctly handle both - "off" and "dormant" ZA-states on entry. The conforming states on return - are "off" and "dormant" (if inbound state was already "dormant"). - - This change ensures that the ZA-state on return is always "off". Note, - that, in the context of clone() and clone3(), "on return" means a point - when execution resumes at certain address after transferring from clone() - or clone3(). For the caller (we may refer to it as "parent") this is the - return address in the link register where the RET instruction jumps. For - the "child", this is the target branch address. - - So, the "off" state on return is permitted and conformant. Why can't we - retain the "dormant" state? In theory, we can, but we shouldn't, here is - why. - - Every subroutine with a private-ZA interface, including clone() and clone3(), - must comply with the lazy saving scheme [1] (6.7.2). This puts additional - responsibility on a subroutine if ZA-state on return is "dormant" because - this state has special meaning. The "caller" (that is the place in code - where execution is transferred to, so this include both "parent" and "child") - may check the ZA-state and use it as per the spec of the "dormant" state that - is outlined in [1] (6.6.6 and 6.6.7). - - Conforming to this would require more code inside of clone() and clone3() - which hardly is desirable. - - For the return to "parent" this could be achieved in theory, but given that - neither clone() nor clone3() are supposed to be used in the middle of an - SME operation, if wouldn't be useful. For the "return" to "child" this - would be particularly difficult to achieve given the complexity of these - functions and their interfaces. Most importantly, it would be illegal - and somewhat meaningless to allow a "child" to start execution in the - "dormant" ZA-state because the very essence of the "dormant" state implies - that there is a place to return and that there is some outer context that - we are allowed to interact with. - - To sum up, calling __arm_za_disable() to ensure the "off" ZA-state when the - execution resumes after a call to clone() or clone3() is correct and also - the most simple way to conform to [1]. - - Can there be situations when we can avoid calling __arm_za_disable()? - - Calling __arm_za_disable() implies certain (sufficiently small) overhead, - so one might rightly ponder avoiding making a call to this function when - we can afford not to. The most trivial cases like this (e.g. when the - calling thread doesn't have access to SME or to the TPIDR2_EL0 register) - are already handled by this function (see [1] (8.1.3 and 8.1.2)). Reasoning - about other possible use cases would require making code inside clone() and - clone3() more complicated and it would defeat the point of trying to make - an optimisation of not calling __arm_za_disable(). - - Why can't the kernel do this instead? - - The handling of SME state by the kernel is described in [4]. In short, - kernel must not impose a specific ZA-interface onto a userspace function. - Interaction with the kernel happens (among other thing) via system calls. - In Glibc many of the system calls (notably, including SYS_clone and - SYS_clone3) are used via wrappers, and the kernel has no control of them - and, moreover, it cannot dictate how these wrappers should behave because - it is simply outside of the kernel's remit. - - However, in certain cases, the kernel may ensure that a "child" doesn't - start in an incorrect state. This is what is done by the recent change - included in 6.16 kernel [5]. This is not enough to ensure that code that - uses clone() and clone3() function conforms to [1] when it runs on a - system that provides SME, hence this change. - - [1]: https://github.com/ARM-software/abi-aa/blob/main/aapcs64/aapcs64.rst - [2]: https://inbox.sourceware.org/libc-alpha/20250522114828.2291047-1-yury.khrustalev@arm.com - [3]: https://inbox.sourceware.org/libc-alpha/20250609121407.3316070-1-yury.khrustalev@arm.com - [4]: https://www.kernel.org/doc/html/v6.16/arch/arm64/sme.html - [5]: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cde5c32db55740659fca6d56c09b88800d88fd29 - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 27effb3d50424fb9634be77a2acd614b0386ff25) - -diff --git a/sysdeps/unix/sysv/linux/aarch64/clone.S b/sysdeps/unix/sysv/linux/aarch64/clone.S -index 40015c6933..53f1efd728 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/clone.S -+++ b/sysdeps/unix/sysv/linux/aarch64/clone.S -@@ -45,6 +45,9 @@ ENTRY(__clone) - and x1, x1, -16 - cbz x1, .Lsyscall_error - -+ /* Clear ZA state of SME. */ -+ CALL_LIBC_ARM_ZA_DISABLE -+ - /* Do the system call. */ - /* X0:flags, x1:newsp, x2:parenttidptr, x3:newtls, x4:childtid. */ - mov x0, x2 /* flags */ -diff --git a/sysdeps/unix/sysv/linux/aarch64/clone3.S b/sysdeps/unix/sysv/linux/aarch64/clone3.S -index c9ca845ef2..bc978b7e10 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/clone3.S -+++ b/sysdeps/unix/sysv/linux/aarch64/clone3.S -@@ -46,6 +46,9 @@ ENTRY(__clone3) - cbz x10, .Lsyscall_error /* No NULL cl_args pointer. */ - cbz x2, .Lsyscall_error /* No NULL function pointer. */ - -+ /* Clear ZA state of SME. */ -+ CALL_LIBC_ARM_ZA_DISABLE -+ - /* Do the system call, the kernel expects: - x8: system call number - x0: cl_args -diff --git a/sysdeps/unix/sysv/linux/aarch64/sysdep.h b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -index fa01386b25..30003c0145 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/sysdep.h -+++ b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -@@ -242,6 +242,31 @@ - #undef HAVE_INTERNAL_BRK_ADDR_SYMBOL - #define HAVE_INTERNAL_BRK_ADDR_SYMBOL 1 - -+/* Clear ZA state of SME (C version). */ -+/* The __libc_arm_za_disable function has special calling convention -+ that allows to call it without stack manipulation and preserving -+ most of the registers. */ -+#define CALL_LIBC_ARM_ZA_DISABLE() \ -+({ \ -+ unsigned long int __tmp; \ -+ asm volatile ( \ -+ " mov %0, x30\n" \ -+ " .cfi_register x30, %0\n" \ -+ " bl __libc_arm_za_disable\n" \ -+ " mov x30, %0\n" \ -+ " .cfi_register %0, x30\n" \ -+ : "=r" (__tmp) \ -+ : \ -+ : "x14", "x15", "x16", "x17", "x18", "memory" ); \ -+}) -+ -+/* Do clear ZA state of SME before making normal clone syscall. */ -+#define INLINE_CLONE_SYSCALL(a0, a1, a2, a3, a4) \ -+({ \ -+ CALL_LIBC_ARM_ZA_DISABLE (); \ -+ INLINE_SYSCALL_CALL (clone, a0, a1, a2, a3, a4); \ -+}) -+ - #endif /* __ASSEMBLER__ */ - - #endif /* linux/aarch64/sysdep.h */ -diff --git a/sysdeps/unix/sysv/linux/aarch64/vfork.S b/sysdeps/unix/sysv/linux/aarch64/vfork.S -index d5943a7485..2600bc9be3 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/vfork.S -+++ b/sysdeps/unix/sysv/linux/aarch64/vfork.S -@@ -27,6 +27,9 @@ - - ENTRY (__vfork) - -+ /* Clear ZA state of SME. */ -+ CALL_LIBC_ARM_ZA_DISABLE -+ - mov x0, #0x4111 /* CLONE_VM | CLONE_VFORK | SIGCHLD */ - mov x1, sp - DO_CALL (clone, 2) - -commit 71874f167aa5bb1538ff7e394beaacee28ebe65f -Author: Yury Khrustalev -Date: Fri Sep 26 10:03:45 2025 +0100 - - aarch64: tests for SME - - This commit adds tests for the following use cases relevant to handing of - the SME state: - - - fork() and vfork() - - clone() and clone3() - - signal handler - - While most cases are trivial, the case of clone3() is more complicated since - the clone3() symbol is not public in Glibc. - - To avoid having to check all possible ways clone3() may be called via other - public functions (e.g. vfork() or pthread_create()), we put together a test - that links directly with clone3.o. All the existing functions that have calls - to clone3() may not actually use it, in which case the outcome of such tests - would be unexpected. Having a direct call to the clone3() symbol in the test - allows to check precisely what we need to test: that the __arm_za_disable() - function is indeed called and has the desired effect. - - Linking to clone3.o also requires linking to __arm_za_disable.o that in - turn requires the _dl_hwcap2 hidden symbol which to provide in the test - and initialise it before using. - - Co-authored-by: Adhemerval Zanella Netto - Reviewed-by: Adhemerval Zanella - (cherry picked from commit ecb0fc2f0f839f36cd2a106283142c9df8ea8214) - -diff --git a/sysdeps/aarch64/Makefile b/sysdeps/aarch64/Makefile -index bb97d31355..9479fb9679 100644 ---- a/sysdeps/aarch64/Makefile -+++ b/sysdeps/aarch64/Makefile -@@ -79,8 +79,18 @@ sysdep_routines += \ - - tests += \ - tst-sme-jmp \ -+ tst-sme-signal \ - tst-sme-za-state \ - # tests -+tests-internal += \ -+ tst-sme-clone \ -+ tst-sme-clone3 \ -+ tst-sme-fork \ -+ tst-sme-vfork \ -+ # tests-internal -+ -+$(objpfx)tst-sme-clone3: $(objpfx)clone3.o $(objpfx)__arm_za_disable.o -+ - endif - - ifeq ($(subdir),malloc) -diff --git a/sysdeps/aarch64/tst-sme-clone.c b/sysdeps/aarch64/tst-sme-clone.c -new file mode 100644 -index 0000000000..7106ec7926 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-clone.c -@@ -0,0 +1,53 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when clone() syscall is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+#include -+ -+static int -+fun (void * const arg) -+{ -+ printf ("in child: %s\n", (const char *)arg); -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after clone in child", /* Clear. */ true); -+ return 0; -+} -+ -+static char __attribute__((aligned(16))) -+stack[1024 * 1024]; -+ -+static void -+run (struct blk *ptr) -+{ -+ char *syscall_name = (char *)"clone"; -+ printf ("in parent: before %s\n", syscall_name); -+ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (ptr); -+ check_sme_za_state ("before clone", /* Clear. */ false); -+ -+ pid_t pid = xclone (fun, syscall_name, stack, sizeof (stack), -+ CLONE_NEWUSER | CLONE_NEWNS | SIGCHLD); -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after clone in parent", /* Clear. */ true); -+ -+ TEST_VERIFY (xwaitpid (pid, NULL, 0) == pid); -+} -diff --git a/sysdeps/aarch64/tst-sme-clone3.c b/sysdeps/aarch64/tst-sme-clone3.c -new file mode 100644 -index 0000000000..402b040cfd ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-clone3.c -@@ -0,0 +1,84 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when clone3() syscall is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+#include -+ -+#include -+#include -+#include -+ -+/* Since clone3 is not a public symbol, we link this test explicitly -+ with clone3.o and have to provide this declaration. */ -+int __clone3 (struct clone_args *cl_args, size_t size, -+ int (*func)(void *arg), void *arg); -+ -+static int -+fun (void * const arg) -+{ -+ printf ("in child: %s\n", (const char *)arg); -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after clone3 in child", /* Clear. */ true); -+ return 0; -+} -+ -+static char __attribute__((aligned(16))) -+stack[1024 * 1024]; -+ -+/* Required by __arm_za_disable.o and provided by the startup code -+ as a hidden symbol. */ -+uint64_t _dl_hwcap2; -+ -+static void -+run (struct blk *ptr) -+{ -+ _dl_hwcap2 = getauxval (AT_HWCAP2); -+ -+ char *syscall_name = (char *)"clone3"; -+ struct clone_args args = { -+ .flags = CLONE_VM | CLONE_VFORK, -+ .exit_signal = SIGCHLD, -+ .stack = (uintptr_t) stack, -+ .stack_size = sizeof (stack), -+ }; -+ printf ("in parent: before %s\n", syscall_name); -+ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (ptr); -+ check_sme_za_state ("before clone3", /* Clear. */ false); -+ -+ pid_t pid = __clone3 (&args, sizeof (args), fun, syscall_name); -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after clone3 in parent", /* Clear. */ true); -+ -+ printf ("%s child pid: %d\n", syscall_name, pid); -+ -+ xwaitpid (pid, NULL, 0); -+ printf ("in parent: after %s\n", syscall_name); -+} -+ -+/* Workaround to simplify linking with clone3.o. */ -+void __syscall_error(int code) -+{ -+ int err = -code; -+ fprintf (stderr, "syscall error %d (%s)\n", err, strerror (err)); -+ exit (err); -+} -diff --git a/sysdeps/aarch64/tst-sme-fork.c b/sysdeps/aarch64/tst-sme-fork.c -new file mode 100644 -index 0000000000..b003b08884 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-fork.c -@@ -0,0 +1,43 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when fork() function is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+static void -+run (struct blk *blk) -+{ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (blk); -+ check_sme_za_state ("before fork", /* Clear. */ false); -+ fflush (stdout); -+ -+ pid_t pid = xfork (); -+ -+ if (pid == 0) -+ { -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after fork in child", /* Clear. */ true); -+ exit (0); -+ } -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after fork in parent", /* Clear. */ true); -+ -+ TEST_VERIFY (xwaitpid (pid, NULL, 0) == pid); -+} -diff --git a/sysdeps/aarch64/tst-sme-helper.h b/sysdeps/aarch64/tst-sme-helper.h -index f049416c2b..ab9c503e45 100644 ---- a/sysdeps/aarch64/tst-sme-helper.h -+++ b/sysdeps/aarch64/tst-sme-helper.h -@@ -16,9 +16,6 @@ - License along with the GNU C Library; if not, see - . */ - --/* Streaming SVE vector register size. */ --static unsigned long svl; -- - struct blk { - void *za_save_buffer; - uint16_t num_za_save_slices; -@@ -68,10 +65,10 @@ start_za (void) - - /* Load data into ZA byte by byte from p. */ - static void __attribute__ ((noinline)) --load_za (const void *p) -+load_za (const void *buf, unsigned long svl) - { - register unsigned long x15 asm ("x15") = 0; -- register unsigned long x16 asm ("x16") = (unsigned long)p; -+ register unsigned long x16 asm ("x16") = (unsigned long)buf; - register unsigned long x17 asm ("x17") = svl; - - asm volatile ( -diff --git a/sysdeps/aarch64/tst-sme-jmp.c b/sysdeps/aarch64/tst-sme-jmp.c -index 103897ad36..b2d21c6e1a 100644 ---- a/sysdeps/aarch64/tst-sme-jmp.c -+++ b/sysdeps/aarch64/tst-sme-jmp.c -@@ -29,6 +29,9 @@ - - #include "tst-sme-helper.h" - -+/* Streaming SVE vector register size. */ -+static unsigned long svl; -+ - static uint8_t *za_orig; - static uint8_t *za_dump; - static uint8_t *za_save; -@@ -82,7 +85,7 @@ longjmp_test (void) - FAIL_EXIT1 ("svcr != 0: %lu", svcr); - set_tpidr2 (&blk); - start_za (); -- load_za (za_orig); -+ load_za (za_orig, svl); - - print_data ("za save space", za_save); - p = get_tpidr2 (); -@@ -131,7 +134,7 @@ setcontext_test (void) - FAIL_EXIT1 ("svcr != 0: %lu", svcr); - set_tpidr2 (&blk); - start_za (); -- load_za (za_orig); -+ load_za (za_orig, svl); - - print_data ("za save space", za_save); - p = get_tpidr2 (); -diff --git a/sysdeps/aarch64/tst-sme-signal.c b/sysdeps/aarch64/tst-sme-signal.c -new file mode 100644 -index 0000000000..b4b07bcc44 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-signal.c -@@ -0,0 +1,115 @@ -+/* Test handling of SME state in a signal handler. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+#include -+ -+static struct _aarch64_ctx * -+extension (void *p) -+{ -+ return p; -+} -+ -+#ifndef TPIDR2_MAGIC -+#define TPIDR2_MAGIC 0x54504902 -+#endif -+ -+#ifndef ZA_MAGIC -+#define ZA_MAGIC 0x54366345 -+#endif -+ -+#ifndef ZT_MAGIC -+#define ZT_MAGIC 0x5a544e01 -+#endif -+ -+#ifndef EXTRA_MAGIC -+#define EXTRA_MAGIC 0x45585401 -+#endif -+ -+/* We use a pipe to make sure that the final check of the SME state -+ happens after signal handler finished. */ -+static int pipefd[2]; -+ -+#define WRITE(msg) xwrite (1, msg, sizeof (msg)); -+ -+static void -+handler (int signo, siginfo_t *si, void *ctx) -+{ -+ TEST_VERIFY (signo == SIGUSR1); -+ WRITE ("in the handler\n"); -+ check_sme_za_state ("during signal", true /* State is clear. */); -+ ucontext_t *uc = ctx; -+ void *p = uc->uc_mcontext.__reserved; -+ unsigned int found = 0; -+ uint32_t m; -+ while ((m = extension (p)->magic)) -+ { -+ if (m == TPIDR2_MAGIC) -+ { -+ WRITE ("found TPIDR2_MAGIC\n"); -+ found += 1; -+ } -+ if (m == ZA_MAGIC) -+ { -+ WRITE ("found ZA_MAGIC\n"); -+ found += 1; -+ } -+ if (m == ZT_MAGIC) -+ { -+ WRITE ("found ZT_MAGIC\n"); -+ found += 1; -+ } -+ if (m == EXTRA_MAGIC) -+ { -+ WRITE ("found EXTRA_MAGIC\n"); -+ struct { struct _aarch64_ctx h; uint64_t data; } *e = p; -+ p = (char *)e->data; -+ continue; -+ } -+ p = (char *)p + extension (p)->size; -+ } -+ TEST_COMPARE (found, 3); -+ -+ /* Signal that the wait is over (see below). */ -+ char message = '\0'; -+ xwrite (pipefd[1], &message, 1); -+} -+ -+static void -+run (struct blk *blk) -+{ -+ xpipe (pipefd); -+ -+ struct sigaction sigact; -+ sigemptyset (&sigact.sa_mask); -+ sigact.sa_flags = 0; -+ sigact.sa_flags |= SA_SIGINFO; -+ sigact.sa_sigaction = handler; -+ xsigaction (SIGUSR1, &sigact, NULL); -+ -+ enable_sme_za_state (blk); -+ check_sme_za_state ("before signal", false /* State is not clear. */); -+ xraise (SIGUSR1); -+ -+ /* Wait for signal handler to complete. */ -+ char response; -+ xread (pipefd[0], &response, 1); -+ -+ check_sme_za_state ("after signal", false /* State is not clear. */); -+} -diff --git a/sysdeps/aarch64/tst-sme-skeleton.c b/sysdeps/aarch64/tst-sme-skeleton.c -new file mode 100644 -index 0000000000..ba84dda1cb ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-skeleton.c -@@ -0,0 +1,101 @@ -+/* Template for SME tests. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include "tst-sme-helper.h" -+ -+/* Streaming SVE vector register size. */ -+static unsigned long svl; -+ -+static uint8_t *state; -+ -+static void -+enable_sme_za_state (struct blk *blk) -+{ -+ start_za (); -+ set_tpidr2 (blk); -+ load_za (blk, svl); -+} -+ -+/* Check if SME state is disabled (when CLEAR is true) or -+ enabled (when CLEAR is false). */ -+static void -+check_sme_za_state (const char msg[], bool clear) -+{ -+ unsigned long svcr = get_svcr (); -+ void *tpidr2 = get_tpidr2 (); -+ printf ("[%s]\n", msg); -+ printf ("svcr = %016lx\n", svcr); -+ printf ("tpidr2 = %016lx\n", (unsigned long)tpidr2); -+ if (clear) -+ { -+ TEST_VERIFY (svcr == 0); -+ TEST_VERIFY (tpidr2 == NULL); -+ } -+ else -+ { -+ TEST_VERIFY (svcr != 0); -+ TEST_VERIFY (tpidr2 != NULL); -+ } -+} -+ -+/* Should be defined in actual test that includes this -+ skeleton file. */ -+static void -+run (struct blk *ptr); -+ -+static int -+do_test (void) -+{ -+ unsigned long hwcap2 = getauxval (AT_HWCAP2); -+ if ((hwcap2 & HWCAP2_SME) == 0) -+ return EXIT_UNSUPPORTED; -+ -+ /* Get current streaming SVE vector length in bytes. */ -+ svl = get_svl (); -+ printf ("svl: %lu\n", svl); -+ -+ TEST_VERIFY_EXIT (!(svl < 16 || svl % 16 != 0 || svl >= (1 << 16))); -+ -+ /* Initialise buffer for ZA state of SME. */ -+ state = xmalloc (svl * svl); -+ memset (state, 1, svl * svl); -+ struct blk blk = { -+ .za_save_buffer = state, -+ .num_za_save_slices = svl, -+ .__reserved = {0}, -+ }; -+ -+ run (&blk); -+ -+ free (state); -+ return 0; -+} -+ -+#include -diff --git a/sysdeps/aarch64/tst-sme-vfork.c b/sysdeps/aarch64/tst-sme-vfork.c -new file mode 100644 -index 0000000000..3feea065e5 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-vfork.c -@@ -0,0 +1,43 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when vfork() function is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+static void -+run (struct blk *blk) -+{ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (blk); -+ check_sme_za_state ("before vfork", /* Clear. */ false); -+ fflush (stdout); -+ -+ pid_t pid = vfork (); -+ -+ if (pid == 0) -+ { -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after vfork in child", /* Clear. */ true); -+ _exit (0); -+ } -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after vfork in parent", /* Clear. */ true); -+ -+ TEST_VERIFY (xwaitpid (pid, NULL, 0) == pid); -+} -diff --git a/sysdeps/aarch64/tst-sme-za-state.c b/sysdeps/aarch64/tst-sme-za-state.c -index 63f6eebeb4..00118ef506 100644 ---- a/sysdeps/aarch64/tst-sme-za-state.c -+++ b/sysdeps/aarch64/tst-sme-za-state.c -@@ -16,47 +16,9 @@ - License along with the GNU C Library; if not, see - . */ - --#include --#include --#include --#include --#include -- --#include --#include --#include -- --#include "tst-sme-helper.h" -- --static uint8_t *state; -- --static void --enable_sme_za_state (struct blk *ptr) --{ -- set_tpidr2 (ptr); -- start_za (); -- load_za (state); --} -+#include "tst-sme-skeleton.c" - --static void --check_sme_za_state (const char msg[], bool clear) --{ -- unsigned long svcr = get_svcr (); -- void *tpidr2 = get_tpidr2 (); -- printf ("[%s]\n", msg); -- printf ("svcr = %016lx\n", svcr); -- printf ("tpidr2 = %016lx\n", (unsigned long)tpidr2); -- if (clear) -- { -- TEST_VERIFY (svcr == 0); -- TEST_VERIFY (tpidr2 == NULL); -- } -- else -- { -- TEST_VERIFY (svcr != 0); -- TEST_VERIFY (tpidr2 != NULL); -- } --} -+#include - - static void - run (struct blk *ptr) -@@ -88,32 +50,3 @@ run (struct blk *ptr) - TEST_COMPARE (ret, 42); - check_sme_za_state ("after longjmp", /* Clear. */ true); - } -- --static int --do_test (void) --{ -- unsigned long hwcap2 = getauxval (AT_HWCAP2); -- if ((hwcap2 & HWCAP2_SME) == 0) -- return EXIT_UNSUPPORTED; -- -- /* Get current streaming SVE vector register size. */ -- svl = get_svl (); -- printf ("svl: %lu\n", svl); -- TEST_VERIFY_EXIT (!(svl < 16 || svl % 16 != 0 || svl >= (1 << 16))); -- -- /* Initialise buffer for ZA state of SME. */ -- state = xmalloc (svl * svl); -- memset (state, 1, svl * svl); -- struct blk blk = { -- .za_save_buffer = state, -- .num_za_save_slices = svl, -- .__reserved = {0}, -- }; -- -- run (&blk); -- -- free (state); -- return 0; --} -- --#include - -commit bf499c2a4964bddc25a006ec1402f8996d78c6ff -Author: Jiamei Xie -Date: Tue Oct 14 20:14:11 2025 +0800 - - x86: fix wmemset ifunc stray '!' (bug 33542) - - The ifunc selector for wmemset had a stray '!' in the - X86_ISA_CPU_FEATURES_ARCH_P(...) check: - - if (X86_ISA_CPU_FEATURE_USABLE_P (cpu_features, AVX2) - && X86_ISA_CPU_FEATURES_ARCH_P (cpu_features, - AVX_Fast_Unaligned_Load, !)) - - This effectively negated the predicate and caused the AVX2/AVX512 - paths to be skipped, making the dispatcher fall back to the SSE2 - implementation even on CPUs where AVX2/AVX512 are available. The - regression leads to noticeable throughput loss for wmemset. - - Remove the stray '!' so the AVX_Fast_Unaligned_Load capability is - tested as intended and the correct AVX2/EVEX variants are selected. - - Impact: - - On AVX2/AVX512-capable x86_64, wmemset no longer incorrectly - falls back to SSE2; perf now shows __wmemset_evex/avx2 variants. - - Testing: - - benchtests/bench-wmemset shows improved bandwidth across sizes. - - perf confirm the selected symbol is no longer SSE2. - - Signed-off-by: xiejiamei - Signed-off-by: Li jing - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 4d86b6cdd8132e0410347e07262239750f86dfb4) - -diff --git a/sysdeps/x86_64/multiarch/ifunc-wmemset.h b/sysdeps/x86_64/multiarch/ifunc-wmemset.h -index f95cca6ae5..50af138230 100644 ---- a/sysdeps/x86_64/multiarch/ifunc-wmemset.h -+++ b/sysdeps/x86_64/multiarch/ifunc-wmemset.h -@@ -35,7 +35,7 @@ IFUNC_SELECTOR (void) - - if (X86_ISA_CPU_FEATURE_USABLE_P (cpu_features, AVX2) - && X86_ISA_CPU_FEATURES_ARCH_P (cpu_features, -- AVX_Fast_Unaligned_Load, !)) -+ AVX_Fast_Unaligned_Load,)) - { - if (X86_ISA_CPU_FEATURE_USABLE_P (cpu_features, AVX512VL)) - { - -commit de1fe81f471496366580ad728b8986a3424b2fd7 -Author: Yury Khrustalev -Date: Tue Oct 28 11:01:50 2025 +0000 - - aarch64: fix cfi directives around __libc_arm_za_disable - - Incorrect CFI directive corrupted call stack information - and prevented debuggers from correctly displaying call - stack information. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 2f77aec043f61e8533487850b11941a640ae2dea) - -diff --git a/sysdeps/unix/sysv/linux/aarch64/sysdep.h b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -index 30003c0145..8a7690d4a8 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/sysdep.h -+++ b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -@@ -155,11 +155,12 @@ - that allows to call it without stack manipulation and preserving - most of the registers. */ - .macro CALL_LIBC_ARM_ZA_DISABLE -+ cfi_remember_state - mov x13, x30 -- .cfi_register x30, x13 -+ cfi_register(x30, x13) - bl __libc_arm_za_disable - mov x30, x13 -- .cfi_register x13, x30 -+ cfi_restore_state - .endm - - #else /* not __ASSEMBLER__ */ -@@ -250,11 +251,12 @@ - ({ \ - unsigned long int __tmp; \ - asm volatile ( \ -+ " .cfi_remember_state\n" \ - " mov %0, x30\n" \ -- " .cfi_register x30, %0\n" \ -+ " .cfi_register x30, %0\n" \ - " bl __libc_arm_za_disable\n" \ - " mov x30, %0\n" \ -- " .cfi_register %0, x30\n" \ -+ " .cfi_restore_state\n" \ - : "=r" (__tmp) \ - : \ - : "x14", "x15", "x16", "x17", "x18", "memory" ); \ - -commit 17c3eab387c3ceb6972e57888a89b1480793f81a -Author: Yury Khrustalev -Date: Tue Nov 11 11:40:25 2025 +0000 - - aarch64: fix includes in SME tests - - Use the correct include for the SIGCHLD macro: signal.h - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit a9c426bcca59a9e228c4fbe75e75154217ec4ada) - -diff --git a/sysdeps/aarch64/tst-sme-clone.c b/sysdeps/aarch64/tst-sme-clone.c -index 7106ec7926..b6ad54fa37 100644 ---- a/sysdeps/aarch64/tst-sme-clone.c -+++ b/sysdeps/aarch64/tst-sme-clone.c -@@ -19,6 +19,7 @@ - - #include "tst-sme-skeleton.c" - -+#include - #include - - static int -diff --git a/sysdeps/aarch64/tst-sme-clone3.c b/sysdeps/aarch64/tst-sme-clone3.c -index 402b040cfd..f420d5984d 100644 ---- a/sysdeps/aarch64/tst-sme-clone3.c -+++ b/sysdeps/aarch64/tst-sme-clone3.c -@@ -22,7 +22,7 @@ - #include - - #include --#include -+#include - #include - - /* Since clone3 is not a public symbol, we link this test explicitly - -commit 97297120ce04f0edd16ed0357a11ef8731c5bd1e -Author: Joe Ramsay -Date: Thu Nov 6 15:36:03 2025 +0000 - - AArch64: Optimise SVE scalar callbacks - - Instead of using SVE instructions to marshall special results into the - correct lane, just write the entire vector (and the predicate) to - memory, then use cheaper scalar operations. - - Geomean speedup of 16% in special intervals on Neoverse with GCC 14. - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 5b82fb18827e962af9f080fdf3c1a69802783f67) - -diff --git a/sysdeps/aarch64/fpu/sv_math.h b/sysdeps/aarch64/fpu/sv_math.h -index 3d576df4cc..65d7f0ff20 100644 ---- a/sysdeps/aarch64/fpu/sv_math.h -+++ b/sysdeps/aarch64/fpu/sv_math.h -@@ -24,11 +24,29 @@ - - #include "vecmath_config.h" - -+#if !defined(__ARM_FEATURE_SVE_BITS) || __ARM_FEATURE_SVE_BITS == 0 -+/* If not specified by -msve-vector-bits, assume maximum vector length. */ -+# define SVE_VECTOR_BYTES 256 -+#else -+# define SVE_VECTOR_BYTES (__ARM_FEATURE_SVE_BITS / 8) -+#endif -+#define SVE_NUM_FLTS (SVE_VECTOR_BYTES / sizeof (float)) -+#define SVE_NUM_DBLS (SVE_VECTOR_BYTES / sizeof (double)) -+/* Predicate is stored as one bit per byte of VL so requires VL / 64 bytes. */ -+#define SVE_NUM_PG_BYTES (SVE_VECTOR_BYTES / sizeof (uint64_t)) -+ - #define SV_NAME_F1(fun) _ZGVsMxv_##fun##f - #define SV_NAME_D1(fun) _ZGVsMxv_##fun - #define SV_NAME_F2(fun) _ZGVsMxvv_##fun##f - #define SV_NAME_D2(fun) _ZGVsMxvv_##fun - -+static inline void -+svstr_p (uint8_t *dst, svbool_t p) -+{ -+ /* Predicate STR does not currently have an intrinsic. */ -+ __asm__("str %0, [%x1]\n" : : "Upa"(p), "r"(dst) : "memory"); -+} -+ - /* Double precision. */ - static inline svint64_t - sv_s64 (int64_t x) -@@ -51,33 +69,35 @@ sv_f64 (double x) - static inline svfloat64_t - sv_call_f64 (double (*f) (double), svfloat64_t x, svfloat64_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ double tmp[SVE_NUM_DBLS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b64 (), tmp, svsel (cmp, x, y)); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- double elem = svclastb_n_f64 (p, 0, x); -- elem = (*f) (elem); -- svfloat64_t y2 = svdup_n_f64 (elem); -- y = svsel_f64 (p, y2, y); -- p = svpnext_b64 (cmp, p); -+ if (pg_bits[i] & 1) -+ tmp[i] = f (tmp[i]); - } -- return y; -+ return svld1 (svptrue_b64 (), tmp); - } - - static inline svfloat64_t - sv_call2_f64 (double (*f) (double, double), svfloat64_t x1, svfloat64_t x2, - svfloat64_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ double tmp1[SVE_NUM_DBLS], tmp2[SVE_NUM_DBLS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b64 (), tmp1, svsel (cmp, x1, y)); -+ svst1 (cmp, tmp2, x2); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- double elem1 = svclastb_n_f64 (p, 0, x1); -- double elem2 = svclastb_n_f64 (p, 0, x2); -- double ret = (*f) (elem1, elem2); -- svfloat64_t y2 = svdup_n_f64 (ret); -- y = svsel_f64 (p, y2, y); -- p = svpnext_b64 (cmp, p); -+ if (pg_bits[i] & 1) -+ tmp1[i] = f (tmp1[i], tmp2[i]); - } -- return y; -+ return svld1 (svptrue_b64 (), tmp1); - } - - static inline svuint64_t -@@ -109,33 +129,40 @@ sv_f32 (float x) - static inline svfloat32_t - sv_call_f32 (float (*f) (float), svfloat32_t x, svfloat32_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ float tmp[SVE_NUM_FLTS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b32 (), tmp, svsel (cmp, x, y)); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- float elem = svclastb_n_f32 (p, 0, x); -- elem = f (elem); -- svfloat32_t y2 = svdup_n_f32 (elem); -- y = svsel_f32 (p, y2, y); -- p = svpnext_b32 (cmp, p); -+ uint8_t p = pg_bits[i]; -+ if (p & 1) -+ tmp[i * 2] = f (tmp[i * 2]); -+ if (p & (1 << 4)) -+ tmp[i * 2 + 1] = f (tmp[i * 2 + 1]); - } -- return y; -+ return svld1 (svptrue_b32 (), tmp); - } - - static inline svfloat32_t - sv_call2_f32 (float (*f) (float, float), svfloat32_t x1, svfloat32_t x2, - svfloat32_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ float tmp1[SVE_NUM_FLTS], tmp2[SVE_NUM_FLTS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b32 (), tmp1, svsel (cmp, x1, y)); -+ svst1 (cmp, tmp2, x2); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- float elem1 = svclastb_n_f32 (p, 0, x1); -- float elem2 = svclastb_n_f32 (p, 0, x2); -- float ret = f (elem1, elem2); -- svfloat32_t y2 = svdup_n_f32 (ret); -- y = svsel_f32 (p, y2, y); -- p = svpnext_b32 (cmp, p); -+ uint8_t p = pg_bits[i]; -+ if (p & 1) -+ tmp1[i * 2] = f (tmp1[i * 2], tmp2[i * 2]); -+ if (p & (1 << 4)) -+ tmp1[i * 2 + 1] = f (tmp1[i * 2 + 1], tmp2[i * 2 + 1]); - } -- return y; -+ return svld1 (svptrue_b32 (), tmp1); - } -- - #endif - -commit ec041b1f53bf1fd29d94ee147fac69da66437dc6 -Author: Joe Ramsay -Date: Thu Nov 6 18:26:54 2025 +0000 - - AArch64: Fix instability in AdvSIMD tan - - Previously presence of special-cases in one lane could affect the - results in other lanes due to unconditional scalar fallback. The old - WANT_SIMD_EXCEPT option (which has never been enabled in libmvec) has - been removed from AOR, making it easier to spot and fix this. 4% - improvement in throughput with GCC 14 on Neoverse V1. This bug is - present as far back as 2.39 (where tan was first introduced). - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 6c22823da57aa5218f717f569c04c9573c0448c5) - -diff --git a/sysdeps/aarch64/fpu/tan_advsimd.c b/sysdeps/aarch64/fpu/tan_advsimd.c -index 825c9754b3..d391a003d8 100644 ---- a/sysdeps/aarch64/fpu/tan_advsimd.c -+++ b/sysdeps/aarch64/fpu/tan_advsimd.c -@@ -25,9 +25,7 @@ static const struct data - float64x2_t poly[9]; - double half_pi[2]; - float64x2_t two_over_pi, shift; --#if !WANT_SIMD_EXCEPT - float64x2_t range_val; --#endif - } data = { - /* Coefficients generated using FPMinimax. */ - .poly = { V2 (0x1.5555555555556p-2), V2 (0x1.1111111110a63p-3), -@@ -38,20 +36,17 @@ static const struct data - .half_pi = { 0x1.921fb54442d18p0, 0x1.1a62633145c07p-54 }, - .two_over_pi = V2 (0x1.45f306dc9c883p-1), - .shift = V2 (0x1.8p52), --#if !WANT_SIMD_EXCEPT - .range_val = V2 (0x1p23), --#endif - }; - - #define RangeVal 0x4160000000000000 /* asuint64(0x1p23). */ - #define TinyBound 0x3e50000000000000 /* asuint64(2^-26). */ --#define Thresh 0x310000000000000 /* RangeVal - TinyBound. */ - - /* Special cases (fall back to scalar calls). */ - static float64x2_t VPCS_ATTR NOINLINE --special_case (float64x2_t x) -+special_case (float64x2_t x, float64x2_t n, float64x2_t d, uint64x2_t special) - { -- return v_call_f64 (tan, x, x, v_u64 (-1)); -+ return v_call_f64 (tan, x, vdivq_f64 (n, d), special); - } - - /* Vector approximation for double-precision tan. -@@ -65,14 +60,6 @@ float64x2_t VPCS_ATTR V_NAME_D1 (tan) (float64x2_t x) - very large inputs. Fall back to scalar routine for all lanes if any are - too large, or Inf/NaN. If fenv exceptions are expected, also fall back for - tiny input to avoid underflow. */ --#if WANT_SIMD_EXCEPT -- uint64x2_t iax = vreinterpretq_u64_f64 (vabsq_f64 (x)); -- /* iax - tiny_bound > range_val - tiny_bound. */ -- uint64x2_t special -- = vcgtq_u64 (vsubq_u64 (iax, v_u64 (TinyBound)), v_u64 (Thresh)); -- if (__glibc_unlikely (v_any_u64 (special))) -- return special_case (x); --#endif - - /* q = nearest integer to 2 * x / pi. */ - float64x2_t q -@@ -81,9 +68,8 @@ float64x2_t VPCS_ATTR V_NAME_D1 (tan) (float64x2_t x) - - /* Use q to reduce x to r in [-pi/4, pi/4], by: - r = x - q * pi/2, in extended precision. */ -- float64x2_t r = x; - float64x2_t half_pi = vld1q_f64 (dat->half_pi); -- r = vfmsq_laneq_f64 (r, q, half_pi, 0); -+ float64x2_t r = vfmsq_laneq_f64 (x, q, half_pi, 0); - r = vfmsq_laneq_f64 (r, q, half_pi, 1); - /* Further reduce r to [-pi/8, pi/8], to be reconstructed using double angle - formula. */ -@@ -114,12 +100,13 @@ float64x2_t VPCS_ATTR V_NAME_D1 (tan) (float64x2_t x) - - uint64x2_t no_recip = vtstq_u64 (vreinterpretq_u64_s64 (qi), v_u64 (1)); - --#if !WANT_SIMD_EXCEPT - uint64x2_t special = vcageq_f64 (x, dat->range_val); -+ float64x2_t swap = vbslq_f64 (no_recip, n, vnegq_f64 (d)); -+ d = vbslq_f64 (no_recip, d, n); -+ n = swap; -+ - if (__glibc_unlikely (v_any_u64 (special))) -- return special_case (x); --#endif -+ return special_case (x, n, d, special); - -- return vdivq_f64 (vbslq_f64 (no_recip, n, vnegq_f64 (d)), -- vbslq_f64 (no_recip, d, n)); -+ return vdivq_f64 (n, d); - } - -commit 0c9430ed976b961343dd29b752091f3c4771cf30 -Author: Joe Ramsay -Date: Thu Nov 6 18:29:33 2025 +0000 - - AArch64: Fix instability in AdvSIMD sinh - - Previously presence of special-cases in one lane could affect the - results in other lanes due to unconditional scalar fallback. The old - WANT_SIMD_EXCEPT option (which has never been enabled in libmvec) has - been removed from AOR, making it easier to spot and fix - this. No measured change in performance. This patch applies cleanly as - far back as 2.41, however there are conflicts with 2.40 where sinh was - first introduced. - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit e45af510bc816e860c8e2e1d4a652b4fe15c4b34) - -diff --git a/sysdeps/aarch64/fpu/sinh_advsimd.c b/sysdeps/aarch64/fpu/sinh_advsimd.c -index 0d6a4856f8..b6b60262c6 100644 ---- a/sysdeps/aarch64/fpu/sinh_advsimd.c -+++ b/sysdeps/aarch64/fpu/sinh_advsimd.c -@@ -24,36 +24,26 @@ static const struct data - { - struct v_expm1_data d; - uint64x2_t halff; --#if WANT_SIMD_EXCEPT -- uint64x2_t tiny_bound, thresh; --#else - float64x2_t large_bound; --#endif - } data = { - .d = V_EXPM1_DATA, - .halff = V2 (0x3fe0000000000000), --#if WANT_SIMD_EXCEPT -- /* 2^-26, below which sinh(x) rounds to x. */ -- .tiny_bound = V2 (0x3e50000000000000), -- /* asuint(large_bound) - asuint(tiny_bound). */ -- .thresh = V2 (0x0230000000000000), --#else - /* 2^9. expm1 helper overflows for large input. */ - .large_bound = V2 (0x1p+9), --#endif - }; - - static float64x2_t NOINLINE VPCS_ATTR --special_case (float64x2_t x) -+special_case (float64x2_t x, float64x2_t t, float64x2_t halfsign, -+ uint64x2_t special) - { -- return v_call_f64 (sinh, x, x, v_u64 (-1)); -+ return v_call_f64 (sinh, x, vmulq_f64 (t, halfsign), special); - } - - /* Approximation for vector double-precision sinh(x) using expm1. - sinh(x) = (exp(x) - exp(-x)) / 2. - The greatest observed error is 2.52 ULP: -- _ZGVnN2v_sinh(-0x1.a098a2177a2b9p-2) got -0x1.ac2f05bb66fccp-2 -- want -0x1.ac2f05bb66fc9p-2. */ -+ _ZGVnN2v_sinh(0x1.9f6ff2ab6fb19p-2) got 0x1.aaed83a3153ccp-2 -+ want 0x1.aaed83a3153c9p-2. */ - float64x2_t VPCS_ATTR V_NAME_D1 (sinh) (float64x2_t x) - { - const struct data *d = ptr_barrier (&data); -@@ -63,21 +53,16 @@ float64x2_t VPCS_ATTR V_NAME_D1 (sinh) (float64x2_t x) - float64x2_t halfsign = vreinterpretq_f64_u64 ( - vbslq_u64 (v_u64 (0x8000000000000000), ix, d->halff)); - --#if WANT_SIMD_EXCEPT -- uint64x2_t special = vcgeq_u64 ( -- vsubq_u64 (vreinterpretq_u64_f64 (ax), d->tiny_bound), d->thresh); --#else - uint64x2_t special = vcageq_f64 (x, d->large_bound); --#endif -- -- /* Fall back to scalar variant for all lanes if any of them are special. */ -- if (__glibc_unlikely (v_any_u64 (special))) -- return special_case (x); - - /* Up to the point that expm1 overflows, we can use it to calculate sinh - using a slight rearrangement of the definition of sinh. This allows us to - retain acceptable accuracy for very small inputs. */ - float64x2_t t = expm1_inline (ax, &d->d); - t = vaddq_f64 (t, vdivq_f64 (t, vaddq_f64 (t, v_f64 (1.0)))); -+ -+ if (__glibc_unlikely (v_any_u64 (special))) -+ return special_case (x, t, halfsign, special); -+ - return vmulq_f64 (t, halfsign); - } - -commit 710d7a2e8374cf09280a0db170a6c813b70b59e5 -Author: Pierre Blanchard -Date: Tue Nov 18 15:03:10 2025 +0000 - - AArch64: fix SVE tanpi(f) [BZ #33642] - - Fixed svld1rq using incorrect predicates (BZ #33642). - Next to no performance variations (tested on V1). - - Reviewed-by: Wilco Dijkstra  - (cherry picked from commit e889160273a4c2b68870c9adf341955867d76a7d) - -diff --git a/sysdeps/aarch64/fpu/tanpi_sve.c b/sysdeps/aarch64/fpu/tanpi_sve.c -index 57c643ae29..bfe6828e1f 100644 ---- a/sysdeps/aarch64/fpu/tanpi_sve.c -+++ b/sysdeps/aarch64/fpu/tanpi_sve.c -@@ -1,6 +1,6 @@ - /* Double-precision (SVE) tanpi function - -- Copyright (C) 2024 Free Software Foundation, Inc. -+ Copyright (C) 2024-2025 Free Software Foundation, Inc. - This file is part of the GNU C Library. - - The GNU C Library is free software; you can redistribute it and/or -@@ -58,10 +58,10 @@ svfloat64_t SV_NAME_D1 (tanpi) (svfloat64_t x, const svbool_t pg) - svfloat64_t r2 = svmul_x (pg, r, r); - svfloat64_t r4 = svmul_x (pg, r2, r2); - -- svfloat64_t c_1_3 = svld1rq (pg, &d->c1); -- svfloat64_t c_5_7 = svld1rq (pg, &d->c5); -- svfloat64_t c_9_11 = svld1rq (pg, &d->c9); -- svfloat64_t c_13_14 = svld1rq (pg, &d->c13); -+ svfloat64_t c_1_3 = svld1rq (svptrue_b64 (), &d->c1); -+ svfloat64_t c_5_7 = svld1rq (svptrue_b64 (), &d->c5); -+ svfloat64_t c_9_11 = svld1rq (svptrue_b64 (), &d->c9); -+ svfloat64_t c_13_14 = svld1rq (svptrue_b64 (), &d->c13); - svfloat64_t p01 = svmla_lane (sv_f64 (d->c0), r2, c_1_3, 0); - svfloat64_t p23 = svmla_lane (sv_f64 (d->c2), r2, c_1_3, 1); - svfloat64_t p45 = svmla_lane (sv_f64 (d->c4), r2, c_5_7, 0); -diff --git a/sysdeps/aarch64/fpu/tanpif_sve.c b/sysdeps/aarch64/fpu/tanpif_sve.c -index 0285f56f34..6894379564 100644 ---- a/sysdeps/aarch64/fpu/tanpif_sve.c -+++ b/sysdeps/aarch64/fpu/tanpif_sve.c -@@ -1,6 +1,6 @@ - /* Single-precision (SVE) tanpi function - -- Copyright (C) 2024 Free Software Foundation, Inc. -+ Copyright (C) 2024-2025 Free Software Foundation, Inc. - This file is part of the GNU C Library. - - The GNU C Library is free software; you can redistribute it and/or -@@ -37,7 +37,7 @@ const static struct v_tanpif_data - svfloat32_t SV_NAME_F1 (tanpi) (svfloat32_t x, const svbool_t pg) - { - const struct v_tanpif_data *d = ptr_barrier (&tanpif_data); -- svfloat32_t odd_coeffs = svld1rq (pg, &d->c1); -+ svfloat32_t odd_coeffs = svld1rq (svptrue_b32 (), &d->c1); - svfloat32_t n = svrintn_x (pg, x); - - /* inf produces nan that propagates. */ - -commit 828b8d23f3fa05234d35032a61a746918accf91d -Author: Pierre Blanchard -Date: Tue Nov 18 15:09:05 2025 +0000 - - AArch64: Fix and improve SVE pow(f) special cases - - powf: - - Update scalar special case function to best use new interface. - - pow: - - Make specialcase NOINLINE to prevent str/ldr leaking in fast path. - Remove depency in sv_call2, as new callback impl is not a - performance gain. - Replace with vectorised specialcase since structure of scalar - routine is fairly simple. - - Throughput gain of about 5-10% on V1 for large values and 25% for subnormal `x`. - - Reviewed-by: Wilco Dijkstra  - (cherry picked from commit bb6519de1e6fe73d79bc71588ec4e5668907f080) - -diff --git a/sysdeps/aarch64/fpu/pow_sve.c b/sysdeps/aarch64/fpu/pow_sve.c -index b8c1b39dca..becf1a8410 100644 ---- a/sysdeps/aarch64/fpu/pow_sve.c -+++ b/sysdeps/aarch64/fpu/pow_sve.c -@@ -31,8 +31,8 @@ - The SVE algorithm drops the tail in the exp computation at the price of - a lower accuracy, slightly above 1ULP. - The SVE algorithm also drops the special treatement of small (< 2^-65) and -- large (> 2^63) finite values of |y|, as they only affect non-round to nearest -- modes. -+ large (> 2^63) finite values of |y|, as they only affect non-round to -+ nearest modes. - - Maximum measured error is 1.04 ULPs: - SV_NAME_D2 (pow) (0x1.3d2d45bc848acp+63, -0x1.a48a38b40cd43p-12) -@@ -156,42 +156,22 @@ sv_zeroinfnan (svbool_t pg, svuint64_t i) - a double. (int32_t)KI is the k used in the argument reduction and exponent - adjustment of scale, positive k here means the result may overflow and - negative k means the result may underflow. */ --static inline double --specialcase (double tmp, uint64_t sbits, uint64_t ki) --{ -- double scale; -- if ((ki & 0x80000000) == 0) -- { -- /* k > 0, the exponent of scale might have overflowed by <= 460. */ -- sbits -= 1009ull << 52; -- scale = asdouble (sbits); -- return 0x1p1009 * (scale + scale * tmp); -- } -- /* k < 0, need special care in the subnormal range. */ -- sbits += 1022ull << 52; -- /* Note: sbits is signed scale. */ -- scale = asdouble (sbits); -- double y = scale + scale * tmp; -- return 0x1p-1022 * y; --} -- --/* Scalar fallback for special cases of SVE pow's exp. */ - static inline svfloat64_t --sv_call_specialcase (svfloat64_t x1, svuint64_t u1, svuint64_t u2, -- svfloat64_t y, svbool_t cmp) -+specialcase (svfloat64_t tmp, svuint64_t sbits, svuint64_t ki, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -- { -- double sx1 = svclastb (p, 0, x1); -- uint64_t su1 = svclastb (p, 0, u1); -- uint64_t su2 = svclastb (p, 0, u2); -- double elem = specialcase (sx1, su1, su2); -- svfloat64_t y2 = sv_f64 (elem); -- y = svsel (p, y2, y); -- p = svpnext_b64 (cmp, p); -- } -- return y; -+ svbool_t p_pos = svcmpge_n_f64 (cmp, svreinterpret_f64_u64 (ki), 0.0); -+ -+ /* Scale up or down depending on sign of k. */ -+ svint64_t offset -+ = svsel_s64 (p_pos, sv_s64 (1009ull << 52), sv_s64 (-1022ull << 52)); -+ svfloat64_t factor -+ = svsel_f64 (p_pos, sv_f64 (0x1p1009), sv_f64 (0x1p-1022)); -+ -+ svuint64_t offset_sbits -+ = svsub_u64_x (cmp, sbits, svreinterpret_u64_s64 (offset)); -+ svfloat64_t scale = svreinterpret_f64_u64 (offset_sbits); -+ svfloat64_t res = svmad_f64_x (cmp, scale, tmp, scale); -+ return svmul_f64_x (cmp, res, factor); - } - - /* Compute y+TAIL = log(x) where the rounded result is y and TAIL has about -@@ -214,8 +194,8 @@ sv_log_inline (svbool_t pg, svuint64_t ix, svfloat64_t *tail, - - /* log(x) = k*Ln2 + log(c) + log1p(z/c-1). */ - /* SVE lookup requires 3 separate lookup tables, as opposed to scalar version -- that uses array of structures. We also do the lookup earlier in the code to -- make sure it finishes as early as possible. */ -+ that uses array of structures. We also do the lookup earlier in the code -+ to make sure it finishes as early as possible. */ - svfloat64_t invc = svld1_gather_index (pg, __v_pow_log_data.invc, i); - svfloat64_t logc = svld1_gather_index (pg, __v_pow_log_data.logc, i); - svfloat64_t logctail = svld1_gather_index (pg, __v_pow_log_data.logctail, i); -@@ -325,14 +305,14 @@ sv_exp_inline (svbool_t pg, svfloat64_t x, svfloat64_t xtail, - svbool_t oflow = svcmpge (pg, abstop, HugeExp); - oflow = svand_z (pg, uoflow, svbic_z (pg, oflow, uflow)); - -- /* For large |x| values (512 < |x| < 1024) scale * (1 + TMP) can overflow -- or underflow. */ -+ /* Handle underflow and overlow in scale. -+ For large |x| values (512 < |x| < 1024), scale * (1 + TMP) can -+ overflow or underflow. */ - svbool_t special = svbic_z (pg, uoflow, svorr_z (pg, uflow, oflow)); -+ if (__glibc_unlikely (svptest_any (pg, special))) -+ z = svsel (special, specialcase (tmp, sbits, ki, special), z); - -- /* Update result with special and large cases. */ -- z = sv_call_specialcase (tmp, sbits, ki, z, special); -- -- /* Handle underflow and overflow. */ -+ /* Handle underflow and overflow in exp. */ - svbool_t x_is_neg = svcmplt (pg, x, 0); - svuint64_t sign_mask - = svlsl_x (pg, sign_bias, 52 - V_POW_EXP_TABLE_BITS); -@@ -353,7 +333,7 @@ sv_exp_inline (svbool_t pg, svfloat64_t x, svfloat64_t xtail, - } - - static inline double --pow_sc (double x, double y) -+pow_specialcase (double x, double y) - { - uint64_t ix = asuint64 (x); - uint64_t iy = asuint64 (y); -@@ -382,6 +362,14 @@ pow_sc (double x, double y) - return x; - } - -+/* Scalar fallback for special case routines with custom signature. */ -+static svfloat64_t NOINLINE -+sv_pow_specialcase (svfloat64_t x1, svfloat64_t x2, svfloat64_t y, -+ svbool_t cmp) -+{ -+ return sv_call2_f64 (pow_specialcase, x1, x2, y, cmp); -+} -+ - svfloat64_t SV_NAME_D2 (pow) (svfloat64_t x, svfloat64_t y, const svbool_t pg) - { - const struct data *d = ptr_barrier (&data); -@@ -444,7 +432,7 @@ svfloat64_t SV_NAME_D2 (pow) (svfloat64_t x, svfloat64_t y, const svbool_t pg) - - /* Cases of zero/inf/nan x or y. */ - if (__glibc_unlikely (svptest_any (svptrue_b64 (), special))) -- vz = sv_call2_f64 (pow_sc, x, y, vz, special); -+ vz = sv_pow_specialcase (x, y, vz, special); - - return vz; - } -diff --git a/sysdeps/aarch64/fpu/powf_sve.c b/sysdeps/aarch64/fpu/powf_sve.c -index 65e9bd29d9..76f54b3522 100644 ---- a/sysdeps/aarch64/fpu/powf_sve.c -+++ b/sysdeps/aarch64/fpu/powf_sve.c -@@ -116,11 +116,10 @@ zeroinfnan (uint32_t ix) - preamble of scalar powf except that we do not update ix and sign_bias. This - is done in the preamble of the SVE powf. */ - static inline float --powf_specialcase (float x, float y, float z) -+powf_specialcase (float x, float y) - { - uint32_t ix = asuint (x); - uint32_t iy = asuint (y); -- /* Either (x < 0x1p-126 or inf or nan) or (y is 0 or inf or nan). */ - if (__glibc_unlikely (zeroinfnan (iy))) - { - if (2 * iy == 0) -@@ -142,32 +141,15 @@ powf_specialcase (float x, float y, float z) - x2 = -x2; - return iy & 0x80000000 ? 1 / x2 : x2; - } -- /* We need a return here in case x<0 and y is integer, but all other tests -- need to be run. */ -- return z; -+ /* Return x for convenience, but make sure result is never used. */ -+ return x; - } - - /* Scalar fallback for special case routines with custom signature. */ - static svfloat32_t NOINLINE --sv_call_powf_sc (svfloat32_t x1, svfloat32_t x2, svfloat32_t y) -+sv_call_powf_sc (svfloat32_t x1, svfloat32_t x2, svfloat32_t y, svbool_t cmp) - { -- /* Special cases of x or y: zero, inf and nan. */ -- svbool_t xspecial = sv_zeroinfnan (svptrue_b32 (), svreinterpret_u32 (x1)); -- svbool_t yspecial = sv_zeroinfnan (svptrue_b32 (), svreinterpret_u32 (x2)); -- svbool_t cmp = svorr_z (svptrue_b32 (), xspecial, yspecial); -- -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -- { -- float sx1 = svclastb (p, 0, x1); -- float sx2 = svclastb (p, 0, x2); -- float elem = svclastb (p, 0, y); -- elem = powf_specialcase (sx1, sx2, elem); -- svfloat32_t y2 = sv_f32 (elem); -- y = svsel (p, y2, y); -- p = svpnext_b32 (cmp, p); -- } -- return y; -+ return sv_call2_f32 (powf_specialcase, x1, x2, y, cmp); - } - - /* Compute core for half of the lanes in double precision. */ -@@ -330,7 +312,7 @@ svfloat32_t SV_NAME_F2 (pow) (svfloat32_t x, svfloat32_t y, const svbool_t pg) - ret = svsel (yint_or_xpos, ret, sv_f32 (__builtin_nanf (""))); - - if (__glibc_unlikely (svptest_any (cmp, cmp))) -- return sv_call_powf_sc (x, y, ret); -+ return sv_call_powf_sc (x, y, ret, cmp); - - return ret; - } - -commit 6b2957cfe8ad1e02c03a28abfc5a251c05e4005e -Author: Sachin Monga -Date: Fri Nov 21 00:30:04 2025 -0500 - - ppc64le: Restore optimized strcmp for power10 - - This patch addresses the actual cause of CVE-2025-5702 - - The vector non-volatile registers are not used anymore for - 32 byte load and comparison operation - - Additionally, the assembler workaround used earlier for the - instruction lxvp is replaced with actual instruction. - - Signed-off-by: Sachin Monga - Co-authored-by: Paul Murphy - (cherry picked from commit 9a40b1cda519cc4f532acb6d020390829df3d81b) - -diff --git a/sysdeps/powerpc/powerpc64/le/power10/strcmp.S b/sysdeps/powerpc/powerpc64/le/power10/strcmp.S -new file mode 100644 -index 0000000000..0d4a53317c ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/le/power10/strcmp.S -@@ -0,0 +1,185 @@ -+/* Optimized strcmp implementation for PowerPC64/POWER10. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+#include -+ -+#ifndef STRCMP -+# define STRCMP strcmp -+#endif -+ -+/* Implements the function -+ int [r3] strcmp (const char *s1 [r3], const char *s2 [r4]). */ -+ -+ -+#define COMPARE_16(vreg1,vreg2,offset) \ -+ lxv vreg1+32,offset(r3); \ -+ lxv vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(different); \ -+ -+#define COMPARE_32(vreg1,vreg2,offset,label1,label2) \ -+ lxvp vreg1+32,offset(r3); \ -+ lxvp vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1+1,vreg2+1; \ -+ bne cr6,L(label1); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(label2); \ -+ -+#define TAIL(vreg1,vreg2) \ -+ vctzlsbb r6,v7; \ -+ vextubrx r5,r6,vreg1; \ -+ vextubrx r4,r6,vreg2; \ -+ subf r3,r4,r5; \ -+ blr; \ -+ -+#define CHECK_N_BYTES(reg1,reg2,len_reg) \ -+ sldi r0,len_reg,56; \ -+ lxvl 32+v4,reg1,r0; \ -+ lxvl 32+v5,reg2,r0; \ -+ add reg1,reg1,len_reg; \ -+ add reg2,reg2,len_reg; \ -+ vcmpnezb. v7,v4,v5; \ -+ vctzlsbb r6,v7; \ -+ cmpld cr7,r6,len_reg; \ -+ blt cr7,L(different); \ -+ -+ -+ .machine power10 -+ENTRY_TOCLESS (STRCMP, 4) -+ li r11,16 -+ /* eq bit of cr1 used as swap status flag to indicate if -+ source pointers were swapped. */ -+ crclr 4*cr1+eq -+ andi. r7,r3,15 -+ sub r7,r11,r7 /* r7(nalign1) = 16 - (str1 & 15). */ -+ andi. r9,r4,15 -+ sub r5,r11,r9 /* r5(nalign2) = 16 - (str2 & 15). */ -+ cmpld cr7,r7,r5 -+ beq cr7,L(same_aligned) -+ blt cr7,L(nalign1_min) -+ /* Swap r3 and r4, and r7 and r5 such that r3 and r7 hold the -+ pointer which is closer to the next 16B boundary so that only -+ one CHECK_N_BYTES is needed before entering the loop below. */ -+ mr r8,r4 -+ mr r4,r3 -+ mr r3,r8 -+ mr r12,r7 -+ mr r7,r5 -+ mr r5,r12 -+ crset 4*cr1+eq /* Set bit on swapping source pointers. */ -+ -+ .p2align 5 -+L(nalign1_min): -+ CHECK_N_BYTES(r3,r4,r7) -+ -+ .p2align 5 -+L(s1_aligned): -+ /* r9 and r5 is number of bytes to be read after and before -+ page boundary correspondingly. */ -+ sub r5,r5,r7 -+ subfic r9,r5,16 -+ /* Now let r7 hold the count of quadwords which can be -+ checked without crossing a page boundary. quadword offset is -+ (str2>>4)&0xFF. */ -+ rlwinm r7,r4,28,0xFF -+ /* Below check is required only for first iteration. For second -+ iteration and beyond, the new loop counter is always 255. */ -+ cmpldi r7,255 -+ beq L(L3) -+ /* Get the initial loop count by 255-((str2>>4)&0xFF). */ -+ subfic r11,r7,255 -+ -+ .p2align 5 -+L(L1): -+ mtctr r11 -+ -+ .p2align 5 -+L(L2): -+ COMPARE_16(v4,v5,0) /* Load 16B blocks using lxv. */ -+ addi r3,r3,16 -+ addi r4,r4,16 -+ bdnz L(L2) -+ /* Cross the page boundary of s2, carefully. */ -+ -+ .p2align 5 -+L(L3): -+ CHECK_N_BYTES(r3,r4,r5) -+ CHECK_N_BYTES(r3,r4,r9) -+ li r11,255 /* Load the new loop counter. */ -+ b L(L1) -+ -+ .p2align 5 -+L(same_aligned): -+ CHECK_N_BYTES(r3,r4,r7) -+ /* Align s1 to 32B and adjust s2 address. -+ Use lxvp only if both s1 and s2 are 32B aligned. */ -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ -+ clrldi r6,r3,59 -+ subfic r5,r6,32 -+ add r3,r3,r5 -+ add r4,r4,r5 -+ andi. r5,r4,0x1F -+ beq cr0,L(32B_aligned_loop) -+ -+ .p2align 5 -+L(16B_aligned_loop): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ b L(16B_aligned_loop) -+ -+ /* Calculate and return the difference. */ -+L(different): -+ vctzlsbb r6,v7 -+ vextubrx r5,r6,v4 -+ vextubrx r4,r6,v5 -+ bt 4*cr1+eq,L(swapped) -+ subf r3,r4,r5 -+ blr -+ -+ /* If src pointers were swapped, then swap the -+ indices and calculate the return value. */ -+L(swapped): -+ subf r3,r5,r4 -+ blr -+ -+ .p2align 5 -+L(32B_aligned_loop): -+ COMPARE_32(v14,v16,0,tail1,tail2) -+ COMPARE_32(v14,v16,32,tail1,tail2) -+ COMPARE_32(v14,v16,64,tail1,tail2) -+ COMPARE_32(v14,v16,96,tail1,tail2) -+ addi r3,r3,128 -+ addi r4,r4,128 -+ b L(32B_aligned_loop) -+ -+L(tail1): TAIL(v15,v17) -+L(tail2): TAIL(v14,v16) -+ -+END (STRCMP) -+libc_hidden_builtin_def (strcmp) -diff --git a/sysdeps/powerpc/powerpc64/multiarch/Makefile b/sysdeps/powerpc/powerpc64/multiarch/Makefile -index e321ce54e0..818f287925 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/Makefile -+++ b/sysdeps/powerpc/powerpc64/multiarch/Makefile -@@ -32,7 +32,7 @@ sysdep_routines += memcpy-power8-cached memcpy-power7 memcpy-a2 memcpy-power6 \ - ifneq (,$(filter %le,$(config-machine))) - sysdep_routines += memcmp-power10 memcpy-power10 memmove-power10 memset-power10 \ - rawmemchr-power9 rawmemchr-power10 \ -- strcmp-power9 strncmp-power9 \ -+ strcmp-power9 strcmp-power10 strncmp-power9 \ - strcpy-power9 strcat-power10 stpcpy-power9 \ - strlen-power9 strncpy-power9 stpncpy-power9 strlen-power10 - endif -diff --git a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -index 016d05fd16..dde3bec709 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -@@ -366,6 +366,10 @@ __libc_ifunc_impl_list (const char *name, struct libc_ifunc_impl *array, - /* Support sysdeps/powerpc/powerpc64/multiarch/strcmp.c. */ - IFUNC_IMPL (i, name, strcmp, - #ifdef __LITTLE_ENDIAN__ -+ IFUNC_IMPL_ADD (array, i, strcmp, -+ (hwcap2 & PPC_FEATURE2_ARCH_3_1) -+ && (hwcap & PPC_FEATURE_HAS_VSX), -+ __strcmp_power10) - IFUNC_IMPL_ADD (array, i, strcmp, - hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC, -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strcmp-power10.S b/sysdeps/powerpc/powerpc64/multiarch/strcmp-power10.S -new file mode 100644 -index 0000000000..a4ee7fb53c ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/multiarch/strcmp-power10.S -@@ -0,0 +1,26 @@ -+/* Optimized strcmp implementation for POWER10/PPC64. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#if defined __LITTLE_ENDIAN__ && IS_IN (libc) -+#define STRCMP __strcmp_power10 -+ -+#undef libc_hidden_builtin_def -+#define libc_hidden_builtin_def(name) -+ -+#include -+#endif /* __LITTLE_ENDIAN__ && IS_IN (libc) */ -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strcmp.c b/sysdeps/powerpc/powerpc64/multiarch/strcmp.c -index 7c77c084a7..3c636e3bbc 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/strcmp.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/strcmp.c -@@ -29,12 +29,16 @@ extern __typeof (strcmp) __strcmp_power7 attribute_hidden; - extern __typeof (strcmp) __strcmp_power8 attribute_hidden; - # ifdef __LITTLE_ENDIAN__ - extern __typeof (strcmp) __strcmp_power9 attribute_hidden; -+extern __typeof (strcmp) __strcmp_power10 attribute_hidden; - # endif - - # undef strcmp - - libc_ifunc_redirected (__redirect_strcmp, strcmp, - # ifdef __LITTLE_ENDIAN__ -+ (hwcap2 & PPC_FEATURE2_ARCH_3_1 -+ && hwcap & PPC_FEATURE_HAS_VSX) -+ ? __strcmp_power10 : - (hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC) - ? __strcmp_power9 : - -commit 2dbf973fe03f9b8fd5a4740ee0af0d47afdd7bbd -Author: Sachin Monga -Date: Fri Nov 21 00:30:52 2025 -0500 - - ppc64le: Restore optimized strncmp for power10 - - This patch addresses the actual cause of CVE-2025-5745 - - The vector non-volatile registers are not used anymore for - 32 byte load and comparison operation - - Additionally, the assembler workaround used earlier for the - instruction lxvp is replaced with actual instruction. - - Signed-off-by: Sachin Monga - Co-authored-by: Paul Murphy - (cherry picked from commit 2ea943f7d487d6a4166658b32af7c5365889fc34) - -diff --git a/sysdeps/powerpc/powerpc64/le/power10/strncmp.S b/sysdeps/powerpc/powerpc64/le/power10/strncmp.S -new file mode 100644 -index 0000000000..6e09fcb7f2 ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/le/power10/strncmp.S -@@ -0,0 +1,252 @@ -+/* Optimized strncmp implementation for PowerPC64/POWER10. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+/* Implements the function -+ -+ int [r3] strncmp (const char *s1 [r3], const char *s2 [r4], size_t [r5] n) -+ -+ The implementation uses unaligned doubleword access to avoid specialized -+ code paths depending of data alignment for first 32 bytes and uses -+ vectorised loops after that. */ -+ -+#ifndef STRNCMP -+# define STRNCMP strncmp -+#endif -+ -+#define COMPARE_16(vreg1,vreg2,offset) \ -+ lxv vreg1+32,offset(r3); \ -+ lxv vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(different); \ -+ cmpldi cr7,r5,16; \ -+ ble cr7,L(ret0); \ -+ addi r5,r5,-16; -+ -+#define COMPARE_32(vreg1,vreg2,offset,label1,label2) \ -+ lxvp vreg1+32,offset(r3); \ -+ lxvp vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1+1,vreg2+1; \ -+ bne cr6,L(label1); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(label2); \ -+ cmpldi cr7,r5,32; \ -+ ble cr7,L(ret0); \ -+ addi r5,r5,-32; -+ -+#define TAIL_FIRST_16B(vreg1,vreg2) \ -+ vctzlsbb r6,v7; \ -+ cmpld cr7,r5,r6; \ -+ ble cr7,L(ret0); \ -+ vextubrx r5,r6,vreg1; \ -+ vextubrx r4,r6,vreg2; \ -+ subf r3,r4,r5; \ -+ blr; -+ -+#define TAIL_SECOND_16B(vreg1,vreg2) \ -+ vctzlsbb r6,v7; \ -+ addi r0,r6,16; \ -+ cmpld cr7,r5,r0; \ -+ ble cr7,L(ret0); \ -+ vextubrx r5,r6,vreg1; \ -+ vextubrx r4,r6,vreg2; \ -+ subf r3,r4,r5; \ -+ blr; -+ -+#define CHECK_N_BYTES(reg1,reg2,len_reg) \ -+ sldi r6,len_reg,56; \ -+ lxvl 32+v4,reg1,r6; \ -+ lxvl 32+v5,reg2,r6; \ -+ add reg1,reg1,len_reg; \ -+ add reg2,reg2,len_reg; \ -+ vcmpnezb v7,v4,v5; \ -+ vctzlsbb r6,v7; \ -+ cmpld cr7,r6,len_reg; \ -+ blt cr7,L(different); \ -+ cmpld cr7,r5,len_reg; \ -+ ble cr7,L(ret0); \ -+ sub r5,r5,len_reg; \ -+ -+ .machine power10 -+ENTRY_TOCLESS (STRNCMP, 4) -+ /* Check if size is 0. */ -+ cmpdi cr0,r5,0 -+ beq cr0,L(ret0) -+ andi. r7,r3,4095 -+ andi. r8,r4,4095 -+ cmpldi cr0,r7,4096-16 -+ cmpldi cr1,r8,4096-16 -+ bgt cr0,L(crosses) -+ bgt cr1,L(crosses) -+ COMPARE_16(v4,v5,0) -+ addi r3,r3,16 -+ addi r4,r4,16 -+ -+L(crosses): -+ andi. r7,r3,15 -+ subfic r7,r7,16 /* r7(nalign1) = 16 - (str1 & 15). */ -+ andi. r9,r4,15 -+ subfic r8,r9,16 /* r8(nalign2) = 16 - (str2 & 15). */ -+ cmpld cr7,r7,r8 -+ beq cr7,L(same_aligned) -+ blt cr7,L(nalign1_min) -+ -+ /* nalign2 is minimum and s2 pointer is aligned. */ -+ CHECK_N_BYTES(r3,r4,r8) -+ /* Are we on the 64B hunk which crosses a page? */ -+ andi. r10,r3,63 /* Determine offset into 64B hunk. */ -+ andi. r8,r3,15 /* The offset into the 16B hunk. */ -+ neg r7,r3 -+ andi. r9,r7,15 /* Number of bytes after a 16B cross. */ -+ rlwinm. r7,r7,26,0x3F /* ((r4-4096))>>6&63. */ -+ beq L(compare_64_pagecross) -+ mtctr r7 -+ b L(compare_64B_unaligned) -+ -+ /* nalign1 is minimum and s1 pointer is aligned. */ -+L(nalign1_min): -+ CHECK_N_BYTES(r3,r4,r7) -+ /* Are we on the 64B hunk which crosses a page? */ -+ andi. r10,r4,63 /* Determine offset into 64B hunk. */ -+ andi. r8,r4,15 /* The offset into the 16B hunk. */ -+ neg r7,r4 -+ andi. r9,r7,15 /* Number of bytes after a 16B cross. */ -+ rlwinm. r7,r7,26,0x3F /* ((r4-4096))>>6&63. */ -+ beq L(compare_64_pagecross) -+ mtctr r7 -+ -+ .p2align 5 -+L(compare_64B_unaligned): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ bdnz L(compare_64B_unaligned) -+ -+ /* Cross the page boundary of s2, carefully. Only for first -+ iteration we have to get the count of 64B blocks to be checked. -+ From second iteration and beyond, loop counter is always 63. */ -+L(compare_64_pagecross): -+ li r11, 63 -+ mtctr r11 -+ cmpldi r10,16 -+ ble L(cross_4) -+ cmpldi r10,32 -+ ble L(cross_3) -+ cmpldi r10,48 -+ ble L(cross_2) -+L(cross_1): -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ addi r3,r3,48 -+ addi r4,r4,48 -+ b L(compare_64B_unaligned) -+L(cross_2): -+ COMPARE_16(v4,v5,0) -+ addi r3,r3,16 -+ addi r4,r4,16 -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ addi r3,r3,32 -+ addi r4,r4,32 -+ b L(compare_64B_unaligned) -+L(cross_3): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ addi r3,r3,32 -+ addi r4,r4,32 -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ COMPARE_16(v4,v5,0) -+ addi r3,r3,16 -+ addi r4,r4,16 -+ b L(compare_64B_unaligned) -+L(cross_4): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ addi r3,r3,48 -+ addi r4,r4,48 -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ b L(compare_64B_unaligned) -+ -+L(same_aligned): -+ CHECK_N_BYTES(r3,r4,r7) -+ /* Align s1 to 32B and adjust s2 address. -+ Use lxvp only if both s1 and s2 are 32B aligned. */ -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ addi r5,r5,32 -+ -+ clrldi r6,r3,59 -+ subfic r7,r6,32 -+ add r3,r3,r7 -+ add r4,r4,r7 -+ subf r5,r7,r5 -+ andi. r7,r4,0x1F -+ beq cr0,L(32B_aligned_loop) -+ -+ .p2align 5 -+L(16B_aligned_loop): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ b L(16B_aligned_loop) -+ -+ /* Calculate and return the difference. */ -+L(different): -+ TAIL_FIRST_16B(v4,v5) -+ -+ .p2align 5 -+L(32B_aligned_loop): -+ COMPARE_32(v14,v16,0,tail1,tail2) -+ COMPARE_32(v14,v16,32,tail1,tail2) -+ COMPARE_32(v14,v16,64,tail1,tail2) -+ COMPARE_32(v14,v16,96,tail1,tail2) -+ addi r3,r3,128 -+ addi r4,r4,128 -+ b L(32B_aligned_loop) -+ -+L(tail1): TAIL_FIRST_16B(v15,v17) -+L(tail2): TAIL_SECOND_16B(v14,v16) -+ -+ .p2align 5 -+L(ret0): -+ li r3,0 -+ blr -+ -+END(STRNCMP) -+libc_hidden_builtin_def(strncmp) -diff --git a/sysdeps/powerpc/powerpc64/multiarch/Makefile b/sysdeps/powerpc/powerpc64/multiarch/Makefile -index 818f287925..c9178223a8 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/Makefile -+++ b/sysdeps/powerpc/powerpc64/multiarch/Makefile -@@ -32,7 +32,7 @@ sysdep_routines += memcpy-power8-cached memcpy-power7 memcpy-a2 memcpy-power6 \ - ifneq (,$(filter %le,$(config-machine))) - sysdep_routines += memcmp-power10 memcpy-power10 memmove-power10 memset-power10 \ - rawmemchr-power9 rawmemchr-power10 \ -- strcmp-power9 strcmp-power10 strncmp-power9 \ -+ strcmp-power9 strcmp-power10 strncmp-power9 strncmp-power10 \ - strcpy-power9 strcat-power10 stpcpy-power9 \ - strlen-power9 strncpy-power9 stpncpy-power9 strlen-power10 - endif -diff --git a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -index dde3bec709..f2b9cccde3 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -@@ -164,6 +164,9 @@ __libc_ifunc_impl_list (const char *name, struct libc_ifunc_impl *array, - /* Support sysdeps/powerpc/powerpc64/multiarch/strncmp.c. */ - IFUNC_IMPL (i, name, strncmp, - #ifdef __LITTLE_ENDIAN__ -+ IFUNC_IMPL_ADD (array, i, strncmp, hwcap2 & PPC_FEATURE2_ARCH_3_1 -+ && hwcap & PPC_FEATURE_HAS_VSX, -+ __strncmp_power10) - IFUNC_IMPL_ADD (array, i, strncmp, hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC, - __strncmp_power9) -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strncmp-power10.S b/sysdeps/powerpc/powerpc64/multiarch/strncmp-power10.S -new file mode 100644 -index 0000000000..bb25bc75b8 ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/multiarch/strncmp-power10.S -@@ -0,0 +1,25 @@ -+/* Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#if defined __LITTLE_ENDIAN__ && IS_IN (libc) -+#define STRNCMP __strncmp_power10 -+ -+#undef libc_hidden_builtin_def -+#define libc_hidden_builtin_def(name) -+ -+#include -+#endif -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strncmp.c b/sysdeps/powerpc/powerpc64/multiarch/strncmp.c -index 4cfe27fa45..0a664a620d 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/strncmp.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/strncmp.c -@@ -29,6 +29,7 @@ extern __typeof (strncmp) __strncmp_ppc attribute_hidden; - extern __typeof (strncmp) __strncmp_power8 attribute_hidden; - # ifdef __LITTLE_ENDIAN__ - extern __typeof (strncmp) __strncmp_power9 attribute_hidden; -+extern __typeof (strncmp) __strncmp_power10 attribute_hidden; - # endif - # undef strncmp - -@@ -36,6 +37,9 @@ extern __typeof (strncmp) __strncmp_power9 attribute_hidden; - ifunc symbol properly. */ - libc_ifunc_redirected (__redirect_strncmp, strncmp, - # ifdef __LITTLE_ENDIAN__ -+ (hwcap2 & PPC_FEATURE2_ARCH_3_1 -+ && hwcap & PPC_FEATURE_HAS_VSX) -+ ? __strncmp_power10 : - (hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC) - ? __strncmp_power9 : - -commit 8aaf4b732d7650c2db3beb4dc8bb70eab5b022c3 -Author: Sachin Monga -Date: Thu Nov 27 03:28:17 2025 -0500 - - ppc64le: Power 10 rawmemchr clobbers v20 (bug #33091) - - Replace non-volatile(v20) by volatile(v17) - since v20 is not restored - - Reviewed-by: Peter Bergner - (cherry picked from commit b59799f14f97f697c3a36b4380bd4ce2fbe65f11) - -diff --git a/sysdeps/powerpc/powerpc64/le/power10/strlen.S b/sysdeps/powerpc/powerpc64/le/power10/strlen.S -index ec644d5bff..29a5a7d960 100644 ---- a/sysdeps/powerpc/powerpc64/le/power10/strlen.S -+++ b/sysdeps/powerpc/powerpc64/le/power10/strlen.S -@@ -31,7 +31,7 @@ - # define FUNCNAME RAWMEMCHR - # endif - # define MCOUNT_NARGS 2 --# define VREG_ZERO v20 -+# define VREG_ZERO v17 - # define OFF_START_LOOP 256 - # define RAWMEMCHR_SUBTRACT_VECTORS \ - vsububm v4,v4,v18; \ - -commit b11411fe2ee7a8f3c3a2c1ee99c1729adb9a0efe -Author: Yury Khrustalev -Date: Thu Nov 6 12:57:58 2025 +0000 - - posix: Fix invalid flags test for p{write,read}v2 - - Two tests fail from time to time when a new flag is added for the - p{write,read}v2 functions in a new Linux kernel: - - - misc/tst-preadvwritev2 - - misc/tst-preadvwritev64v2 - - This disrupts when testing Glibc on a system with a newer kernel - and it seems we can try improve testing for invalid flags setting - all the bits that are not supposed to be supported (rather than - setting only the next unsupported bit). - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 58a31b4316f1f687184eb147ffa1c676bc6a190e) - -diff --git a/misc/tst-preadvwritev2-common.c b/misc/tst-preadvwritev2-common.c -index ff1007d6d2..5182fcdce0 100644 ---- a/misc/tst-preadvwritev2-common.c -+++ b/misc/tst-preadvwritev2-common.c -@@ -109,9 +109,8 @@ do_test_with_invalid_iov (void) - static void - do_test_with_invalid_flags (void) - { -- /* Set the next bit from the mask of all supported flags. */ -- int invalid_flag = RWF_SUPPORTED != 0 ? __builtin_clz (RWF_SUPPORTED) : 2; -- invalid_flag = 0x1 << ((sizeof (int) * CHAR_BIT) - invalid_flag); -+ /* Set all the bits that are not used by the supported flags. */ -+ int invalid_flag = ~RWF_SUPPORTED; - - char buf[32]; - const struct iovec vec = { .iov_base = buf, .iov_len = sizeof (buf) }; - -commit efdf4c0c879590109778244046f84a80a4bf8fee -Author: DJ Delorie -Date: Wed Oct 15 21:37:56 2025 -0400 - - sprof: check pread size and offset for overflow - - Add a bit of descriptive paranoia to the values we read from - the ELF headers and use to access data. - - Reviewed-by: Collin Funk - (cherry picked from commit 324084649b2da2f6840e3a1b84159a4e9a9e9a74) - -diff --git a/elf/sprof.c b/elf/sprof.c -index c82c7c9db6..e9d2a66a4f 100644 ---- a/elf/sprof.c -+++ b/elf/sprof.c -@@ -38,6 +38,7 @@ - #include - #include - #include -+#include - - /* Get libc version number. */ - #include "../version.h" -@@ -410,6 +411,7 @@ load_shobj (const char *name) - int fd; - ElfW(Shdr) *shdr; - size_t pagesize = getpagesize (); -+ struct stat st; - - /* Since we use dlopen() we must be prepared to work around the sometimes - strange lookup rules for the shared objects. If we have a file foo.so -@@ -550,14 +552,39 @@ load_shobj (const char *name) - error (EXIT_FAILURE, errno, _("Reopening shared object `%s' failed"), - map->l_name); - -+ if (fstat (fd, &st) < 0) -+ error (EXIT_FAILURE, errno, _("stat(%s) failure"), map->l_name); -+ -+ /* We're depending on data that's being read from the file, so be a -+ bit paranoid here and make sure the requests are reasonable - -+ i.e. both size and offset are nonnegative and smaller than the -+ file size, as well as the offset of the end of the data. PREAD -+ would have failed anyway, but this is more robust and explains -+ what happened better. Note that SZ must be unsigned and OFF may -+ be signed or unsigned. */ -+#define PCHECK(sz1,off1) { \ -+ size_t sz = sz1, end_off; \ -+ off_t off = off1; \ -+ if (sz > st.st_size \ -+ || off < 0 || off > st.st_size \ -+ || INT_ADD_WRAPV (sz, off, &end_off) \ -+ || end_off > st.st_size) \ -+ error (EXIT_FAILURE, ERANGE, \ -+ _("read outside of file extents %zu + %zd > %zu"), \ -+ sz, off, st.st_size); \ -+ } -+ - /* Map the section header. */ - size_t size = ehdr->e_shnum * sizeof (ElfW(Shdr)); - shdr = (ElfW(Shdr) *) alloca (size); -+ PCHECK (size, ehdr->e_shoff); - if (pread (fd, shdr, size, ehdr->e_shoff) != size) - error (EXIT_FAILURE, errno, _("reading of section headers failed")); - - /* Get the section header string table. */ - char *shstrtab = (char *) alloca (shdr[ehdr->e_shstrndx].sh_size); -+ PCHECK (shdr[ehdr->e_shstrndx].sh_size, -+ shdr[ehdr->e_shstrndx].sh_offset); - if (pread (fd, shstrtab, shdr[ehdr->e_shstrndx].sh_size, - shdr[ehdr->e_shstrndx].sh_offset) - != shdr[ehdr->e_shstrndx].sh_size) -@@ -585,6 +612,7 @@ load_shobj (const char *name) - size_t size = debuglink_entry->sh_size; - char *debuginfo_fname = (char *) alloca (size + 1); - debuginfo_fname[size] = '\0'; -+ PCHECK (size, debuglink_entry->sh_offset); - if (pread (fd, debuginfo_fname, size, debuglink_entry->sh_offset) - != size) - { -@@ -638,21 +666,32 @@ load_shobj (const char *name) - if (fd2 != -1) - { - ElfW(Ehdr) ehdr2; -+ struct stat st; -+ -+ if (fstat (fd2, &st) < 0) -+ error (EXIT_FAILURE, errno, _("stat(%s) failure"), workbuf); - - /* Read the ELF header. */ -+ PCHECK (sizeof (ehdr2), 0); - if (pread (fd2, &ehdr2, sizeof (ehdr2), 0) != sizeof (ehdr2)) - error (EXIT_FAILURE, errno, - _("reading of ELF header failed")); - - /* Map the section header. */ -- size_t size = ehdr2.e_shnum * sizeof (ElfW(Shdr)); -+ size_t size; -+ if (INT_MULTIPLY_WRAPV (ehdr2.e_shnum, sizeof (ElfW(Shdr)), &size)) -+ error (EXIT_FAILURE, errno, _("too many section headers")); -+ - ElfW(Shdr) *shdr2 = (ElfW(Shdr) *) alloca (size); -+ PCHECK (size, ehdr2.e_shoff); - if (pread (fd2, shdr2, size, ehdr2.e_shoff) != size) - error (EXIT_FAILURE, errno, - _("reading of section headers failed")); - - /* Get the section header string table. */ - shstrtab = (char *) alloca (shdr2[ehdr2.e_shstrndx].sh_size); -+ PCHECK (shdr2[ehdr2.e_shstrndx].sh_size, -+ shdr2[ehdr2.e_shstrndx].sh_offset); - if (pread (fd2, shstrtab, shdr2[ehdr2.e_shstrndx].sh_size, - shdr2[ehdr2.e_shstrndx].sh_offset) - != shdr2[ehdr2.e_shstrndx].sh_size) - -commit 2a0873aa81446149c6065237e1dc2511201bef88 -Author: Collin Funk -Date: Wed Oct 22 01:51:09 2025 -0700 - - sprof: fix -Wformat warnings on 32-bit hosts - - Reviewed-by: H.J. Lu - (cherry picked from commit 9681f645ba20fc3c18eb12ffebf94e3df1f888e3) - -diff --git a/elf/sprof.c b/elf/sprof.c -index e9d2a66a4f..513e0470b2 100644 ---- a/elf/sprof.c -+++ b/elf/sprof.c -@@ -570,8 +570,8 @@ load_shobj (const char *name) - || INT_ADD_WRAPV (sz, off, &end_off) \ - || end_off > st.st_size) \ - error (EXIT_FAILURE, ERANGE, \ -- _("read outside of file extents %zu + %zd > %zu"), \ -- sz, off, st.st_size); \ -+ _("read outside of file extents %zu + %jd > %jd"), \ -+ sz, (intmax_t) off, (intmax_t) st.st_size); \ - } - - /* Map the section header. */ - -commit 8dfb84ad4efbc39c7a7d9efdff6f6ac9017e0a53 -Author: Florian Weimer -Date: Thu Nov 6 14:33:22 2025 +0100 - - support: Fix FILE * leak in check_for_unshare_hints in test-container - - The file opened via fopen is never closed. - - (cherry picked from commit 20a2a756089eacd7e7f4c02e381e82b5d0e40a2c) - -diff --git a/support/test-container.c b/support/test-container.c -index 1c40ab377f..d78139622f 100644 ---- a/support/test-container.c -+++ b/support/test-container.c -@@ -705,6 +705,7 @@ check_for_unshare_hints (int require_pidns) - - val = -1; /* Sentinel. */ - int cnt = fscanf (f, "%d", &val); -+ fclose (f); - if (cnt == 1 && val != files[i].bad_value) - continue; - - -commit a1d3294a5bed821aece03994ab4e72c8b822a962 -Author: Florian Weimer -Date: Thu Nov 6 14:49:21 2025 +0100 - - support: Exit on consistency check failure in resolv_response_add_name - - Using TEST_VERIFY (crname_target != crname) instructs some analysis - tools that crname_target == crname might hold. Under this assumption, - they report a use-after-free for crname_target->offset below, caused - by the previous free (crname). - - Reviewed-by: Collin Funk - (cherry picked from commit b64335ff111c071fde61aec1c1a8460afb3d16d4) - -diff --git a/support/resolv_test.c b/support/resolv_test.c -index ab37d3d58c..29e59da958 100644 ---- a/support/resolv_test.c -+++ b/support/resolv_test.c -@@ -326,7 +326,7 @@ resolv_response_add_name (struct resolv_response_builder *b, - crname_target = *ptr; - else - crname_target = NULL; -- TEST_VERIFY (crname_target != crname); -+ TEST_VERIFY_EXIT (crname_target != crname); - /* Not added to the tree. */ - free (crname); - } - -commit f122d0b4d145814869bf10c56db1d971bcba55c5 -Author: Sunil K Pandey -Date: Tue Dec 9 08:57:44 2025 -0800 - - nptl: Optimize trylock for high cache contention workloads (BZ #33704) - - Check lock availability before acquisition to reduce cache line - bouncing. Significantly improves trylock throughput on multi-core - systems under heavy contention. - - Tested on x86_64. - - Fixes BZ #33704. - - Co-authored-by: Alex M Wells - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 63716823dbad9482e09972907ae98e9cb00f9b86) - -diff --git a/nptl/pthread_mutex_trylock.c b/nptl/pthread_mutex_trylock.c -index dbb8fcc754..392619021b 100644 ---- a/nptl/pthread_mutex_trylock.c -+++ b/nptl/pthread_mutex_trylock.c -@@ -48,7 +48,8 @@ ___pthread_mutex_trylock (pthread_mutex_t *mutex) - return 0; - } - -- if (lll_trylock (mutex->__data.__lock) == 0) -+ if (atomic_load_relaxed (&(mutex->__data.__lock)) == 0 -+ && lll_trylock (mutex->__data.__lock) == 0) - { - /* Record the ownership. */ - mutex->__data.__owner = id; -@@ -71,7 +72,10 @@ ___pthread_mutex_trylock (pthread_mutex_t *mutex) - /*FALL THROUGH*/ - case PTHREAD_MUTEX_ADAPTIVE_NP: - case PTHREAD_MUTEX_ERRORCHECK_NP: -- if (lll_trylock (mutex->__data.__lock) != 0) -+ /* Mutex type is already loaded, lock check overhead should -+ be minimal. */ -+ if (atomic_load_relaxed (&(mutex->__data.__lock)) != 0 -+ || lll_trylock (mutex->__data.__lock) != 0) - break; - - /* Record the ownership. */ - -commit b0ec8fb689df862171f0f78994a3bdeb51313545 -Author: Siddhesh Poyarekar -Date: Thu Jan 15 06:06:40 2026 -0500 - - memalign: reinstate alignment overflow check (CVE-2026-0861) - - The change to cap valid sizes to PTRDIFF_MAX inadvertently dropped the - overflow check for alignment in memalign functions, _mid_memalign and - _int_memalign. Reinstate the overflow check in _int_memalign, aligned - with the PTRDIFF_MAX change since that is directly responsible for the - CVE. The missing _mid_memalign check is not relevant (and does not have - a security impact) and may need a different approach to fully resolve, - so it has been omitted. - - CVE-Id: CVE-2026-0861 - Vulnerable-Commit: 9bf8e29ca136094f73f69f725f15c51facc97206 - Reported-by: Igor Morgenstern, Aisle Research - Fixes: BZ #33796 - Reviewed-by: Wilco Dijkstra - Signed-off-by: Siddhesh Poyarekar - (cherry picked from commit c9188d333717d3ceb7e3020011651f424f749f93) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index 5f3e701fd1..1d5aa304d3 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -5167,7 +5167,7 @@ _int_memalign (mstate av, size_t alignment, size_t bytes) - INTERNAL_SIZE_T size; - - nb = checked_request2size (bytes); -- if (nb == 0) -+ if (nb == 0 || alignment > PTRDIFF_MAX) - { - __set_errno (ENOMEM); - return NULL; -@@ -5183,7 +5183,10 @@ _int_memalign (mstate av, size_t alignment, size_t bytes) - we don't find anything in those bins, the common malloc code will - scan starting at 2x. */ - -- /* Call malloc with worst case padding to hit alignment. */ -+ /* Call malloc with worst case padding to hit alignment. ALIGNMENT is a -+ power of 2, so it tops out at (PTRDIFF_MAX >> 1) + 1, leaving plenty of -+ space to add MINSIZE and whatever checked_request2size adds to BYTES to -+ get NB. Consequently, total below also does not overflow. */ - m = (char *) (_int_malloc (av, nb + alignment + MINSIZE)); - - if (m == NULL) -diff --git a/malloc/tst-malloc-too-large.c b/malloc/tst-malloc-too-large.c -index a548a37b46..a1bda673a3 100644 ---- a/malloc/tst-malloc-too-large.c -+++ b/malloc/tst-malloc-too-large.c -@@ -152,7 +152,6 @@ test_large_allocations (size_t size) - } - - --static long pagesize; - - /* This function tests the following aligned memory allocation functions - using several valid alignments and precedes each allocation test with a -@@ -171,8 +170,8 @@ test_large_aligned_allocations (size_t size) - - /* All aligned memory allocation functions expect an alignment that is a - power of 2. Given this, we test each of them with every valid -- alignment from 1 thru PAGESIZE. */ -- for (align = 1; align <= pagesize; align *= 2) -+ alignment for the type of ALIGN, i.e. until it wraps to 0. */ -+ for (align = 1; align > 0; align <<= 1) - { - test_setup (); - #if __GNUC_PREREQ (7, 0) -@@ -265,11 +264,6 @@ do_test (void) - DIAG_IGNORE_NEEDS_COMMENT (7, "-Walloc-size-larger-than="); - #endif - -- /* Aligned memory allocation functions need to be tested up to alignment -- size equivalent to page size, which should be a power of 2. */ -- pagesize = sysconf (_SC_PAGESIZE); -- TEST_VERIFY_EXIT (powerof2 (pagesize)); -- - /* Loop 1: Ensure that all allocations with SIZE close to SIZE_MAX, i.e. - in the range (SIZE_MAX - 2^14, SIZE_MAX], fail. - - -commit 453e6b8dbab935257eb0802b0c97bca6b67ba30e -Author: Carlos O'Donell -Date: Thu Jan 15 15:09:38 2026 -0500 - - resolv: Fix NSS DNS backend for getnetbyaddr (CVE-2026-0915) - - The default network value of zero for net was never tested for and - results in a DNS query constructed from uninitialized stack bytes. - The solution is to provide a default query for the case where net - is zero. - - Adding a test case for this was straight forward given the existence of - tst-resolv-network and if the test is added without the fix you observe - this failure: - - FAIL: resolv/tst-resolv-network - original exit status 1 - error: tst-resolv-network.c:174: invalid QNAME: \146\218\129\128 - error: 1 test failures - - With a random QNAME resulting from the use of uninitialized stack bytes. - - After the fix the test passes. - - Additionally verified using wireshark before and after to ensure - on-the-wire bytes for the DNS query were as expected. - - No regressions on x86_64. - - Reviewed-by: Florian Weimer - (cherry picked from commit e56ff82d5034ec66c6a78f517af6faa427f65b0b) - -diff --git a/resolv/nss_dns/dns-network.c b/resolv/nss_dns/dns-network.c -index 519f8422ca..e14e959d7c 100644 ---- a/resolv/nss_dns/dns-network.c -+++ b/resolv/nss_dns/dns-network.c -@@ -207,6 +207,10 @@ _nss_dns_getnetbyaddr_r (uint32_t net, int type, struct netent *result, - sprintf (qbuf, "%u.%u.%u.%u.in-addr.arpa", net_bytes[3], net_bytes[2], - net_bytes[1], net_bytes[0]); - break; -+ default: -+ /* Default network (net is originally zero). */ -+ strcpy (qbuf, "0.0.0.0.in-addr.arpa"); -+ break; - } - - net_buffer.buf = orig_net_buffer = (querybuf *) alloca (1024); -diff --git a/resolv/tst-resolv-network.c b/resolv/tst-resolv-network.c -index d9f69649d0..181be80835 100644 ---- a/resolv/tst-resolv-network.c -+++ b/resolv/tst-resolv-network.c -@@ -46,6 +46,9 @@ handle_code (const struct resolv_response_context *ctx, - { - switch (code) - { -+ case 0: -+ send_ptr (b, qname, qclass, qtype, "0.in-addr.arpa"); -+ break; - case 1: - send_ptr (b, qname, qclass, qtype, "1.in-addr.arpa"); - break; -@@ -265,6 +268,9 @@ do_test (void) - "error: TRY_AGAIN\n"); - - /* Lookup by address, success cases. */ -+ check_reverse (0, -+ "name: 0.in-addr.arpa\n" -+ "net: 0x00000000\n"); - check_reverse (1, - "name: 1.in-addr.arpa\n" - "net: 0x00000001\n"); - -commit cbf39c26b25801e9bc88499b4fd361ac172d4125 -Author: Adhemerval Zanella -Date: Thu Jan 15 10:32:19 2026 -0300 - - posix: Reset wordexp_t fields with WRDE_REUSE (CVE-2025-15281 / BZ 33814) - - The wordexp fails to properly initialize the input wordexp_t when - WRDE_REUSE is used. The wordexp_t struct is properly freed, but - reuses the old wc_wordc value and updates the we_wordv in the - wrong position. A later wordfree will then call free with an - invalid pointer. - - Checked on x86_64-linux-gnu and i686-linux-gnu. - - Reviewed-by: Carlos O'Donell - (cherry picked from commit 80cc58ea2de214f85b0a1d902a3b668ad2ecb302) - -diff --git a/NEWS b/NEWS -index ed3c114c7a..7e7e1930dd 100644 ---- a/NEWS -+++ b/NEWS -@@ -16,6 +16,8 @@ The following bugs were resolved with this release: - [33356] nptl: creating thread stack with guardsize 0 can erroneously - conclude MADV_GUARD_INSTALL is available - [33361] nss: Group merge does not react to ERANGE during merge -+ [33814] glob: wordexp with WRDE_REUSE and WRDE_APPEND may return -+ uninitialized memory - - Version 2.42 - -diff --git a/posix/Makefile b/posix/Makefile -index a36e5decd3..1ea86efcc1 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -327,6 +327,7 @@ tests := \ - tst-wait4 \ - tst-waitid \ - tst-wordexp-nocmd \ -+ tst-wordexp-reuse \ - tstgetopt \ - # tests - -@@ -457,6 +458,8 @@ generated += \ - tst-rxspencer-no-utf8.mtrace \ - tst-vfork3-mem.out \ - tst-vfork3.mtrace \ -+ tst-wordexp-reuse-mem.out \ -+ tst-wordexp-reuse.mtrace \ - # generated - endif - endif -@@ -492,6 +495,7 @@ tests-special += \ - $(objpfx)tst-pcre-mem.out \ - $(objpfx)tst-rxspencer-no-utf8-mem.out \ - $(objpfx)tst-vfork3-mem.out \ -+ $(objpfx)tst-wordexp-reuse.out \ - # tests-special - endif - endif -@@ -775,3 +779,10 @@ $(objpfx)posix-conf-vars-def.h: $(..)scripts/gen-posix-conf-vars.awk \ - $(make-target-directory) - $(AWK) -f $(filter-out Makefile, $^) > $@.tmp - mv -f $@.tmp $@ -+ -+tst-wordexp-reuse-ENV += MALLOC_TRACE=$(objpfx)tst-wordexp-reuse.mtrace \ -+ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so -+ -+$(objpfx)tst-wordexp-reuse-mem.out: $(objpfx)tst-wordexp-reuse.out -+ $(common-objpfx)malloc/mtrace $(objpfx)tst-wordexp-reuse.mtrace > $@; \ -+ $(evaluate-test) -diff --git a/posix/tst-wordexp-reuse.c b/posix/tst-wordexp-reuse.c -new file mode 100644 -index 0000000000..3926b9f557 ---- /dev/null -+++ b/posix/tst-wordexp-reuse.c -@@ -0,0 +1,89 @@ -+/* Test for wordexp with WRDE_REUSE flag. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+ -+#include -+ -+static int -+do_test (void) -+{ -+ mtrace (); -+ -+ { -+ wordexp_t p = { 0 }; -+ TEST_COMPARE (wordexp ("one", &p, 0), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { .we_offs = 2 }; -+ TEST_COMPARE (wordexp ("one", &p, 0), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE | WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { 0 }; -+ TEST_COMPARE (wordexp ("one", &p, 0), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE | WRDE_APPEND), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { .we_offs = 2 }; -+ TEST_COMPARE (wordexp ("one", &p, WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE -+ | WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { .we_offs = 2 }; -+ TEST_COMPARE (wordexp ("one", &p, WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE -+ | WRDE_DOOFFS | WRDE_APPEND), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "two"); -+ wordfree (&p); -+ } -+ -+ return 0; -+} -+ -+#include -diff --git a/posix/wordexp.c b/posix/wordexp.c -index a69b732801..9df4bb7424 100644 ---- a/posix/wordexp.c -+++ b/posix/wordexp.c -@@ -2216,7 +2216,9 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - { - /* Minimal implementation of WRDE_REUSE for now */ - wordfree (pwordexp); -+ old_word.we_wordc = 0; - old_word.we_wordv = NULL; -+ pwordexp->we_wordc = 0; - } - - if ((flags & WRDE_APPEND) == 0) - -commit 912d89a766847649a3857985a3b5e6065c51bfd4 -Author: Florian Weimer -Date: Thu Jan 8 12:35:08 2026 +0100 - - Switch currency symbol for the bg_BG locale to euro - - Bulgaria joined the eurozone on 2026-01-01. - - Suggested-by: Йордан Гигов - Reviewed-by: Collin Funk - (cherry picked from commit 78fdb2d6b1c34ea8e779fd48f9436dfbd50b6387) - -diff --git a/localedata/locales/bg_BG b/localedata/locales/bg_BG -index 159a6c3334..eda2a8d01b 100644 ---- a/localedata/locales/bg_BG -+++ b/localedata/locales/bg_BG -@@ -248,8 +248,8 @@ reorder-end - END LC_COLLATE - - LC_MONETARY --int_curr_symbol "BGN " --currency_symbol "лв." -+int_curr_symbol "EUR " -+currency_symbol "€" - mon_decimal_point "," - mon_thousands_sep " " - mon_grouping 3 - -commit 39897805917ab1c44dbf4452b9c4c2bbafc7117b -Author: Florian Weimer -Date: Fri Feb 13 09:02:07 2026 +0100 - - nss: Introduce dedicated struct nss_database_for_fork type - - The initialized field in struct nss_database_data is rather confusing - because it is not used by the regular NSS code, only by the fork - state synchronization code. Introduce a separate type and place - the initialized field there. - - Reviewed-by: Sam James - (cherry picked from commit 7bb859f4198d0be19c31a9937eae4f6c2c9a079e) - -diff --git a/nss/nss_database.c b/nss/nss_database.c -index a7ac32beb9..a6b7d5c956 100644 ---- a/nss/nss_database.c -+++ b/nss/nss_database.c -@@ -56,7 +56,6 @@ global_state_allocate (void *closure) - { - result->data.nsswitch_conf.size = -1; /* Force reload. */ - memset (result->data.services, 0, sizeof (result->data.services)); -- result->data.initialized = true; - result->data.reload_disabled = false; - __libc_lock_init (result->lock); - result->root_ino = 0; -@@ -451,8 +450,8 @@ nss_database_check_reload_and_get (struct nss_database_state *local, - /* Avoid overwriting the global configuration until we have loaded - everything successfully. Otherwise, if the file change - information changes back to what is in the global configuration, -- the lookups would use the partially-written configuration. */ -- struct nss_database_data staging = { .initialized = true, }; -+ the lookups would use the partially-written configuration. */ -+ struct nss_database_data staging = { }; - - bool ok = nss_database_reload (&staging, &initial); - -@@ -503,7 +502,7 @@ __nss_database_freeres (void) - } - - void --__nss_database_fork_prepare_parent (struct nss_database_data *data) -+__nss_database_fork_prepare_parent (struct nss_database_for_fork *data) - { - /* Do not use allocate_once to trigger loading unnecessarily. */ - struct nss_database_state *local = atomic_load_acquire (&global_database_state); -@@ -515,20 +514,21 @@ __nss_database_fork_prepare_parent (struct nss_database_data *data) - because it avoids acquiring the lock during the actual - fork. */ - __libc_lock_lock (local->lock); -- *data = local->data; -+ data->data = local->data; - __libc_lock_unlock (local->lock); -+ data->initialized = true; - } - } - - void --__nss_database_fork_subprocess (struct nss_database_data *data) -+__nss_database_fork_subprocess (struct nss_database_for_fork *data) - { - struct nss_database_state *local = atomic_load_acquire (&global_database_state); - if (data->initialized) - { - /* Restore the state at the point of the fork. */ - assert (local != NULL); -- local->data = *data; -+ local->data = data->data; - __libc_lock_init (local->lock); - } - else if (local != NULL) -diff --git a/nss/nss_database.h b/nss/nss_database.h -index 0eaea49685..c170da03f6 100644 ---- a/nss/nss_database.h -+++ b/nss/nss_database.h -@@ -70,15 +70,21 @@ struct nss_database_data - struct file_change_detection nsswitch_conf; - nss_action_list services[NSS_DATABASE_COUNT]; - int reload_disabled; /* Actually bool; int for atomic access. */ -- bool initialized; -+}; -+ -+/* Use to store a consistent state snapshot across fork. */ -+struct nss_database_for_fork -+{ -+ bool initialized; /* Set to true if the data field below is initialized. */ -+ struct nss_database_data data; - }; - - /* Called by fork in the parent process, before forking. */ --void __nss_database_fork_prepare_parent (struct nss_database_data *data) -+void __nss_database_fork_prepare_parent (struct nss_database_for_fork *) - attribute_hidden; - - /* Called by fork in the new subprocess, after forking. */ --void __nss_database_fork_subprocess (struct nss_database_data *data) -+void __nss_database_fork_subprocess (struct nss_database_for_fork *) - attribute_hidden; - - #endif /* _NSS_DATABASE_H */ -diff --git a/posix/fork.c b/posix/fork.c -index 011e92fc1d..7f2370f2eb 100644 ---- a/posix/fork.c -+++ b/posix/fork.c -@@ -50,7 +50,7 @@ __libc_fork (void) - - lastrun = __run_prefork_handlers (multiple_threads); - -- struct nss_database_data nss_database_data; -+ struct nss_database_for_fork nss_database_data; - - /* If we are not running multiple threads, we do not have to - preserve lock state. If fork runs from a signal handler, only - -commit 937ef7aaf3ce41038b3e12675a6298b86b389af2 -Author: Florian Weimer -Date: Fri Feb 13 09:02:07 2026 +0100 - - Linux: In getlogin_r, use utmp fallback only for specific errors - - Most importantly, if getwpuid_r fails, it does not make sense to retry - via utmp because the user ID obtained from there is less reliable than - the one from /proc/self/loginuid. - - Reviewed-by: Sam James - (cherry picked from commit 28660f4b45afa8921c2faebaec2846f95f670ba0) - -diff --git a/sysdeps/unix/sysv/linux/getlogin_r.c b/sysdeps/unix/sysv/linux/getlogin_r.c -index f03ecd4da9..0e66944570 100644 ---- a/sysdeps/unix/sysv/linux/getlogin_r.c -+++ b/sysdeps/unix/sysv/linux/getlogin_r.c -@@ -37,7 +37,12 @@ __getlogin_r_loginuid (char *name, size_t namesize) - { - int fd = __open_nocancel ("/proc/self/loginuid", O_RDONLY); - if (fd == -1) -- return -1; -+ { -+ if (errno == ENOENT) -+ /* Trigger utmp fallback. */ -+ return -1; -+ return errno; -+ } - - /* We are reading a 32-bit number. 12 bytes are enough for the text - representation. If not, something is wrong. */ -@@ -45,6 +50,8 @@ __getlogin_r_loginuid (char *name, size_t namesize) - ssize_t n = TEMP_FAILURE_RETRY (__read_nocancel (fd, uidbuf, - sizeof (uidbuf))); - __close_nocancel_nostatus (fd); -+ if (n < 0) -+ return errno; - - uid_t uid; - char *endp; -@@ -53,12 +60,13 @@ __getlogin_r_loginuid (char *name, size_t namesize) - || (uidbuf[n] = '\0', - uid = strtoul (uidbuf, &endp, 10), - endp == uidbuf || *endp != '\0')) -- return -1; -+ return EINVAL; - - /* If there is no login uid, linux sets /proc/self/loginid to the sentinel - value of, (uid_t) -1, so check if that value is set and return early to - avoid making unneeded nss lookups. */ - if (uid == (uid_t) -1) -+ /* Trigger utmp fallback. */ - return -1; - - struct passwd pwd; -@@ -78,9 +86,14 @@ __getlogin_r_loginuid (char *name, size_t namesize) - } - } - -- if (res != 0 || tpwd == NULL) -+ if (res != 0) -+ { -+ result = res; -+ goto out; -+ } -+ if (tpwd == NULL) - { -- result = -1; -+ result = ENOENT; - goto out; - } - - -commit ebd45473f5421e0fced5ba2cde0f1aaa36e79b61 -Author: Florian Weimer -Date: Fri Feb 13 09:02:07 2026 +0100 - - nss: Missing checks in __nss_configure_lookup, __nss_database_get (bug 28940) - - This avoids a null pointer dereference in the - nss_database_check_reload_and_get function, and assertion failures. - - Reviewed-by: Sam James - (cherry picked from commit 5b713b49443eb6a4e54e50e2f0147105f86dab02) - -diff --git a/nss/Makefile b/nss/Makefile -index 1991b7482a..f690c29b94 100644 ---- a/nss/Makefile -+++ b/nss/Makefile -@@ -326,6 +326,7 @@ tests := \ - tst-gshadow \ - tst-nss-getpwent \ - tst-nss-hash \ -+ tst-nss-malloc-failure-getlogin_r \ - tst-nss-test1 \ - tst-nss-test2 \ - tst-nss-test4 \ -diff --git a/nss/nss_database.c b/nss/nss_database.c -index a6b7d5c956..7aa460c7df 100644 ---- a/nss/nss_database.c -+++ b/nss/nss_database.c -@@ -250,9 +250,12 @@ __nss_configure_lookup (const char *dbname, const char *service_line) - - /* Force any load/cache/read whatever to happen, so we can override - it. */ -- __nss_database_get (db, &result); -+ if (!__nss_database_get (db, &result)) -+ return -1; - - local = nss_database_state_get (); -+ if (local == NULL) -+ return -1; - - result = __nss_action_parse (service_line); - if (result == NULL) -@@ -477,6 +480,8 @@ bool - __nss_database_get (enum nss_database db, nss_action_list *actions) - { - struct nss_database_state *local = nss_database_state_get (); -+ if (local == NULL) -+ return false; - return nss_database_check_reload_and_get (local, actions, db); - } - libc_hidden_def (__nss_database_get) -diff --git a/nss/tst-nss-malloc-failure-getlogin_r.c b/nss/tst-nss-malloc-failure-getlogin_r.c -new file mode 100644 -index 0000000000..0e2985ad57 ---- /dev/null -+++ b/nss/tst-nss-malloc-failure-getlogin_r.c -@@ -0,0 +1,345 @@ -+/* Test NSS/getlogin_r with injected allocation failures (bug 28940). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+/* This test calls getpwuid_r via getlogin_r (on Linux). -+ -+ This test uses the NSS system configuration to exercise that code -+ path. It means that it can fail (crash) if malloc failure is not -+ handled by NSS modules for the passwd database. */ -+ -+/* Data structure allocated via MAP_SHARED, so that writes from the -+ subprocess are visible. */ -+struct shared_data -+{ -+ /* Number of tracked allocations performed so far. */ -+ volatile unsigned int allocation_count; -+ -+ /* If this number is reached, one allocation fails. */ -+ volatile unsigned int failing_allocation; -+ -+ /* The number of allocations performed during initialization -+ (before the actual getlogin_r call). */ -+ volatile unsigned int init_allocation_count; -+ -+ /* Error code of an expected getlogin_r failure. */ -+ volatile int expected_failure; -+ -+ /* The subprocess stores the expected name here. */ -+ char name[100]; -+}; -+ -+/* Allocation count in shared mapping. */ -+static struct shared_data *shared; -+ -+/* Returns true if a failure should be injected for this allocation. */ -+static bool -+fail_this_allocation (void) -+{ -+ if (shared != NULL) -+ { -+ unsigned int count = shared->allocation_count; -+ shared->allocation_count = count + 1; -+ return count == shared->failing_allocation; -+ } -+ else -+ return false; -+} -+ -+/* Failure-injecting wrappers for allocation functions used by glibc. */ -+ -+void * -+malloc (size_t size) -+{ -+ if (fail_this_allocation ()) -+ { -+ errno = ENOMEM; -+ return NULL; -+ } -+ extern __typeof (malloc) __libc_malloc; -+ return __libc_malloc (size); -+} -+ -+void * -+calloc (size_t a, size_t b) -+{ -+ if (fail_this_allocation ()) -+ { -+ errno = ENOMEM; -+ return NULL; -+ } -+ extern __typeof (calloc) __libc_calloc; -+ return __libc_calloc (a, b); -+} -+ -+void * -+realloc (void *ptr, size_t size) -+{ -+ if (fail_this_allocation ()) -+ { -+ errno = ENOMEM; -+ return NULL; -+ } -+ extern __typeof (realloc) __libc_realloc; -+ return __libc_realloc (ptr, size); -+} -+ -+/* No-op subprocess to verify that support_isolate_in_subprocess does -+ not perform any heap allocations. */ -+static void -+no_op (void *ignored) -+{ -+} -+ -+/* Perform a getlogin_r call in a subprocess, to obtain the number of -+ allocations used and the expected result of a successful call. */ -+static void -+initialize (void *configure_lookup) -+{ -+ shared->init_allocation_count = 0; -+ if (configure_lookup != NULL) -+ { -+ TEST_COMPARE (__nss_configure_lookup ("passwd", configure_lookup), 0); -+ shared->init_allocation_count = shared->allocation_count; -+ } -+ -+ shared->name[0] = '\0'; -+ int ret = getlogin_r (shared->name, sizeof (shared->name)); -+ if (ret != 0) -+ { -+ printf ("info: getlogin_r failed: %s (%d)\n", -+ strerrorname_np (ret), ret); -+ shared->expected_failure = ret; -+ } -+ else -+ { -+ shared->expected_failure = 0; -+ if (shared->name[0] == '\0') -+ FAIL ("error: getlogin_r succeeded without result\n"); -+ else -+ printf ("info: getlogin_r: \"%s\"\n", shared->name); -+ } -+} -+ -+/* Perform getlogin_r in a subprocess with fault injection. */ -+static void -+test_in_subprocess (void *configure_lookup) -+{ -+ if (configure_lookup != NULL -+ && __nss_configure_lookup ("passwd", configure_lookup) < 0) -+ { -+ printf ("info: __nss_configure_lookup failed: %s (%d)\n", -+ strerrorname_np (errno), errno); -+ TEST_COMPARE (errno, ENOMEM); -+ TEST_VERIFY (shared->allocation_count <= shared->init_allocation_count); -+ return; -+ } -+ -+ unsigned int inject_at = shared->failing_allocation; -+ char name[sizeof (shared->name)] = "name not set"; -+ int ret = getlogin_r (name, sizeof (name)); -+ shared->failing_allocation = ~0U; -+ -+ if (ret == 0) -+ { -+ TEST_COMPARE (shared->expected_failure, 0); -+ TEST_COMPARE_STRING (name, shared->name); -+ } -+ else -+ { -+ printf ("info: allocation %u failure results in error %s (%d)\n", -+ inject_at, strerrorname_np (ret), ret); -+ -+ if (ret != ENOMEM) -+ { -+ if (shared->expected_failure != 0) -+ TEST_COMPARE (ret, shared->expected_failure); -+ else if (configure_lookup == NULL) -+ /* The ENOENT failure can happen due to an issue related -+ to bug 22041: dlopen failure does not result in ENOMEM. */ -+ TEST_COMPARE (ret, ENOENT); -+ else -+ FAIL ("unexpected getlogin_r error"); -+ } -+ } -+ -+ if (shared->expected_failure == 0) -+ { -+ /* The second call should succeed. */ -+ puts ("info: about to perform second getlogin_r call"); -+ ret = getlogin_r (name, sizeof (name)); -+ if (configure_lookup == NULL) -+ { -+ /* This check can fail due to bug 22041 if the malloc error -+ injection causes a failure internally in dlopen. */ -+ if (ret != 0) -+ { -+ printf ("warning: second getlogin_r call failed with %s (%d)\n", -+ strerrorname_np (ret), ret); -+ TEST_COMPARE (ret, ENOENT); -+ } -+ } -+ else -+ /* If __nss_configure_lookup has been called, the error caching -+ bug does not happen because nss_files is built-in, and the -+ second getlogin_r is expected to succeed. */ -+ TEST_COMPARE (ret, 0); -+ if (ret == 0) -+ TEST_COMPARE_STRING (name, shared->name); -+ } -+} -+ -+/* Set by the --failing-allocation command line option. Together with -+ --direct, this can be used to trigger an allocation failure in the -+ original process, which may help with debugging. */ -+static int option_failing_allocation = -1; -+ -+/* Set by --override, to be used with --failing-allocation. Turns on -+ the __nss_configure_lookup call for passwd/files, which is disabled -+ by default. */ -+static int option_override = 0; -+ -+static int -+do_test (void) -+{ -+ char files[] = "files"; -+ -+ if (option_failing_allocation >= 0) -+ { -+ /* The test was invoked with --failing-allocation. Perform just -+ one test, using the original nsswitch.conf. This is a -+ condensed version of the probing/testing loop below. */ -+ printf ("info: testing with failing allocation %d\n", -+ option_failing_allocation); -+ shared = support_shared_allocate (sizeof (*shared)); -+ shared->failing_allocation = ~0U; -+ char *configure_lookup = option_override ? files : NULL; -+ support_isolate_in_subprocess (initialize, configure_lookup); -+ shared->allocation_count = 0; -+ shared->failing_allocation = option_failing_allocation; -+ test_in_subprocess (configure_lookup); /* No subprocess. */ -+ support_shared_free (shared); -+ shared = NULL; -+ return 0; -+ } -+ -+ bool any_success = false; -+ -+ for (int do_configure_lookup = 0; do_configure_lookup < 2; -+ ++do_configure_lookup) -+ { -+ if (do_configure_lookup) -+ puts ("info: testing with nsswitch.conf override"); -+ else -+ puts ("info: testing with original nsswitch.conf"); -+ -+ char *configure_lookup = do_configure_lookup ? files : NULL; -+ -+ shared = support_shared_allocate (sizeof (*shared)); -+ -+ /* Disable fault injection. */ -+ shared->failing_allocation = ~0U; -+ -+ support_isolate_in_subprocess (no_op, NULL); -+ TEST_COMPARE (shared->allocation_count, 0); -+ -+ support_isolate_in_subprocess (initialize, configure_lookup); -+ -+ if (shared->name[0] != '\0') -+ any_success = true; -+ -+ /* The number of allocations in the successful case. Once the -+ number of expected allocations is exceeded, injecting further -+ failures does not make a difference (assuming that the number -+ of malloc calls is deterministic). */ -+ unsigned int maximum_allocation_count = shared->allocation_count; -+ printf ("info: initial getlogin_r performed %u allocations\n", -+ maximum_allocation_count); -+ -+ for (unsigned int inject_at = 0; inject_at <= maximum_allocation_count; -+ ++inject_at) -+ { -+ printf ("info: running fault injection at allocation %u\n", -+ inject_at); -+ shared->allocation_count = 0; -+ shared->failing_allocation = inject_at; -+ support_isolate_in_subprocess (test_in_subprocess, configure_lookup); -+ } -+ -+ support_shared_free (shared); -+ shared = NULL; -+ } -+ -+ { -+ FILE *fp = fopen (_PATH_NSSWITCH_CONF, "r"); -+ if (fp == NULL) -+ printf ("info: no %s file\n", _PATH_NSSWITCH_CONF); -+ else -+ { -+ printf ("info: %s contents follows\n", _PATH_NSSWITCH_CONF); -+ int last_ch = '\n'; -+ while (true) -+ { -+ int ch = fgetc (fp); -+ if (ch == EOF) -+ break; -+ putchar (ch); -+ last_ch = ch; -+ } -+ if (last_ch != '\n') -+ putchar ('\n'); -+ printf ("(end of %s contents)\n", _PATH_NSSWITCH_CONF); -+ xfclose (fp); -+ } -+ } -+ -+ support_record_failure_barrier (); -+ -+ if (!any_success) -+ FAIL_UNSUPPORTED ("no successful getlogin_r calls"); -+ -+ return 0; -+} -+ -+static void -+cmdline_process (int c) -+{ -+ if (c == 'F') -+ option_failing_allocation = atoi (optarg); -+} -+ -+#define CMDLINE_OPTIONS \ -+ { "failing-allocation", required_argument, NULL, 'F' }, \ -+ { "override", no_argument, &option_override, 1 }, -+ -+#define CMDLINE_PROCESS cmdline_process -+ -+#include - -commit 9cd9c9054409d192aab06bfea32624af9ffa8121 -Author: Florian Weimer -Date: Fri Nov 28 11:46:09 2025 +0100 - - iconvdata: Fix invalid pointer arithmetic in ANSI_X3.110 module - - The expression inptr + 1 can technically be invalid: if inptr == inend, - inptr may point one element past the end of an array. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit e98bd0c54d5e296ad1be91b6fe35260c6b87e733) - -diff --git a/iconvdata/ansi_x3.110.c b/iconvdata/ansi_x3.110.c -index c5506b13b8..94e6e6b745 100644 ---- a/iconvdata/ansi_x3.110.c -+++ b/iconvdata/ansi_x3.110.c -@@ -407,7 +407,7 @@ static const char from_ucs4[][2] = - is also available. */ \ - uint32_t ch2; \ - \ -- if (inptr + 1 >= inend) \ -+ if (inend - inptr <= 1) \ - { \ - /* The second character is not available. */ \ - result = __GCONV_INCOMPLETE_INPUT; \ - -commit 1a19d5a507eb82a2cf1cf8bd1c14ca1758fb8a82 -Author: Florian Weimer -Date: Mon Jan 26 17:12:37 2026 +0100 - - posix: Run tst-wordexp-reuse-mem test - - The test was not properly scheduled for execution with a Makefile - dependency. - - Fixes commit 80cc58ea2de214f85b0a1d902a3b668ad2ecb302 ("posix: Reset - wordexp_t fields with WRDE_REUSE (CVE-2025-15281 / BZ 33814"). - - (cherry picked from commit bed2db02f3183e93f21d506786c5f884a1dec9e7) - -diff --git a/posix/Makefile b/posix/Makefile -index 1ea86efcc1..0b29c9aa4e 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -495,7 +495,7 @@ tests-special += \ - $(objpfx)tst-pcre-mem.out \ - $(objpfx)tst-rxspencer-no-utf8-mem.out \ - $(objpfx)tst-vfork3-mem.out \ -- $(objpfx)tst-wordexp-reuse.out \ -+ $(objpfx)tst-wordexp-reuse-mem.out \ - # tests-special - endif - endif - -commit 8e863fb1c92360520704a69dc948be6bb4a17cb3 -Author: Carlos O'Donell -Date: Fri Mar 20 16:43:33 2026 -0400 - - resolv: Count records correctly (CVE-2026-4437) - - The answer section boundary was previously ignored, and the code in - getanswer_ptr would iterate past the last resource record, but not - beyond the end of the returned data. This could lead to subsequent data - being interpreted as answer records, thus violating the DNS - specification. Such resource records could be maliciously crafted and - hidden from other tooling, but processed by the glibc stub resolver and - acted upon by the application. While we trust the data returned by the - configured recursive resolvers, we should not trust its format and - should validate it as required. It is a security issue to incorrectly - process the DNS protocol. - - A regression test is added for response section crossing. - - No regressions on x86_64-linux-gnu. - - Reviewed-by: Collin Funk - (cherry picked from commit 9f5f18aab40ec6b61fa49a007615e6077e9a979b) - -diff --git a/resolv/Makefile b/resolv/Makefile -index 8fa3398d76..0ba5fba710 100644 ---- a/resolv/Makefile -+++ b/resolv/Makefile -@@ -104,6 +104,7 @@ tests += \ - tst-resolv-basic \ - tst-resolv-binary \ - tst-resolv-byaddr \ -+ tst-resolv-dns-section \ - tst-resolv-edns \ - tst-resolv-invalid-cname \ - tst-resolv-network \ -@@ -115,6 +116,7 @@ tests += \ - tst-resolv-semi-failure \ - tst-resolv-short-response \ - tst-resolv-trailing \ -+ # tests - - # This test calls __res_context_send directly, which is not exported - # from libresolv. -@@ -293,6 +295,8 @@ $(objpfx)tst-resolv-aliases: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-basic: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-binary: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-byaddr: $(objpfx)libresolv.so $(shared-thread-library) -+$(objpfx)tst-resolv-dns-section: $(objpfx)libresolv.so \ -+ $(shared-thread-library) - $(objpfx)tst-resolv-edns: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-network: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-res_init: $(objpfx)libresolv.so -diff --git a/resolv/nss_dns/dns-host.c b/resolv/nss_dns/dns-host.c -index 14da73ee1d..27096edad2 100644 ---- a/resolv/nss_dns/dns-host.c -+++ b/resolv/nss_dns/dns-host.c -@@ -820,7 +820,7 @@ getanswer_ptr (unsigned char *packet, size_t packetlen, - /* expected_name may be updated to point into this buffer. */ - unsigned char name_buffer[NS_MAXCDNAME]; - -- while (ancount > 0) -+ for (; ancount > 0; --ancount) - { - struct ns_rr_wire rr; - if (!__ns_rr_cursor_next (&c, &rr)) -diff --git a/resolv/tst-resolv-dns-section.c b/resolv/tst-resolv-dns-section.c -new file mode 100644 -index 0000000000..1171baef51 ---- /dev/null -+++ b/resolv/tst-resolv-dns-section.c -@@ -0,0 +1,162 @@ -+/* Test handling of invalid section transitions (bug 34014). -+ Copyright (C) 2022-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+/* Name of test, and the second section type. */ -+struct item { -+ const char *test; -+ int ns_section; -+}; -+ -+static const struct item test_items[] = -+ { -+ { "Test crossing from ns_s_an to ns_s_ar.", ns_s_ar }, -+ { "Test crossing from ns_s_an to ns_s_an.", ns_s_ns }, -+ -+ { NULL, 0 }, -+ }; -+ -+/* The response is designed to contain the following: -+ - An Answer section with one T_PTR record that is skipped. -+ - A second section with a semantically invalid T_PTR record. -+ The original defect is that the response parsing would cross -+ section boundaries and handle the additional section T_PTR -+ as if it were an answer. A conforming implementation would -+ stop as soon as it reaches the end of the section. */ -+static void -+response (const struct resolv_response_context *ctx, -+ struct resolv_response_builder *b, -+ const char *qname, uint16_t qclass, uint16_t qtype) -+{ -+ TEST_COMPARE (qclass, C_IN); -+ -+ /* We only test PTR. */ -+ TEST_COMPARE (qtype, T_PTR); -+ -+ unsigned int count; -+ char *tail = NULL; -+ -+ if (strstr (qname, "in-addr.arpa") != NULL -+ && sscanf (qname, "%u.%ms", &count, &tail) == 2) -+ TEST_COMPARE_STRING (tail, "0.168.192.in-addr.arpa"); -+ else if (sscanf (qname, "%x.%ms", &count, &tail) == 2) -+ { -+ TEST_COMPARE_STRING (tail, "\ -+0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa"); -+ } -+ else -+ FAIL_EXIT1 ("invalid QNAME: %s\n", qname); -+ free (tail); -+ -+ /* We have a bounded number of possible tests. */ -+ TEST_VERIFY (count >= 0); -+ TEST_VERIFY (count <= 15); -+ -+ struct resolv_response_flags flags = {}; -+ resolv_response_init (b, flags); -+ resolv_response_add_question (b, qname, qclass, qtype); -+ resolv_response_section (b, ns_s_an); -+ -+ /* Actual answer record, but the wrong name (skipped). */ -+ resolv_response_open_record (b, "1.0.0.10.in-addr.arpa", qclass, qtype, 60); -+ -+ /* Record the answer. */ -+ resolv_response_add_name (b, "test.ptr.example.net"); -+ resolv_response_close_record (b); -+ -+ /* Add a second section to test section boundary crossing. */ -+ resolv_response_section (b, test_items[count].ns_section); -+ /* Semantically incorrect, but hide a T_PTR entry. */ -+ resolv_response_open_record (b, qname, qclass, qtype, 60); -+ resolv_response_add_name (b, "wrong.ptr.example.net"); -+ resolv_response_close_record (b); -+} -+ -+ -+/* Perform one check using a reverse lookup. */ -+static void -+check_reverse (int af, int count) -+{ -+ TEST_VERIFY (af == AF_INET || af == AF_INET6); -+ TEST_VERIFY (count < array_length (test_items)); -+ -+ char addr[sizeof (struct in6_addr)] = { 0 }; -+ socklen_t addrlen; -+ if (af == AF_INET) -+ { -+ addr[0] = (char) 192; -+ addr[1] = (char) 168; -+ addr[2] = (char) 0; -+ addr[3] = (char) count; -+ addrlen = 4; -+ } -+ else -+ { -+ addr[0] = 0x20; -+ addr[1] = 0x01; -+ addr[2] = 0x0d; -+ addr[3] = 0xb8; -+ addr[4] = addr[5] = addr[6] = addr[7] = 0x0; -+ addr[8] = addr[9] = addr[10] = addr[11] = 0x0; -+ addr[12] = 0x0; -+ addr[13] = 0x0; -+ addr[14] = 0x0; -+ addr[15] = count; -+ addrlen = 16; -+ } -+ -+ h_errno = 0; -+ struct hostent *answer = gethostbyaddr (addr, addrlen, af); -+ TEST_VERIFY (answer == NULL); -+ TEST_VERIFY (h_errno == NO_RECOVERY); -+ if (answer != NULL) -+ printf ("error: unexpected success: %s\n", -+ support_format_hostent (answer)); -+} -+ -+static int -+do_test (void) -+{ -+ struct resolv_test *obj = resolv_test_start -+ ((struct resolv_redirect_config) -+ { -+ .response_callback = response -+ }); -+ -+ for (int i = 0; test_items[i].test != NULL; i++) -+ { -+ check_reverse (AF_INET, i); -+ check_reverse (AF_INET6, i); -+ } -+ -+ resolv_test_end (obj); -+ -+ return 0; -+} -+ -+#include - -commit 426378547e6ddead92f28f5558a124eb0821d2f9 -Author: Carlos O'Donell -Date: Fri Mar 20 17:14:33 2026 -0400 - - resolv: Check hostname for validity (CVE-2026-4438) - - The processed hostname in getanswer_ptr should be correctly checked to - avoid invalid characters from being allowed, including shell - metacharacters. It is a security issue to fail to check the returned - hostname for validity. - - A regression test is added for invalid metacharacters and other cases - of invalid or valid characters. - - No regressions on x86_64-linux-gnu. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit e10977481f4db4b2a3ce34fa4c3a1e26651ae312) - -diff --git a/resolv/Makefile b/resolv/Makefile -index 0ba5fba710..088a22ea18 100644 ---- a/resolv/Makefile -+++ b/resolv/Makefile -@@ -107,6 +107,7 @@ tests += \ - tst-resolv-dns-section \ - tst-resolv-edns \ - tst-resolv-invalid-cname \ -+ tst-resolv-invalid-ptr \ - tst-resolv-network \ - tst-resolv-noaaaa \ - tst-resolv-noaaaa-vc \ -@@ -306,6 +307,8 @@ $(objpfx)tst-resolv-res_init-thread: $(objpfx)libresolv.so \ - $(shared-thread-library) - $(objpfx)tst-resolv-invalid-cname: $(objpfx)libresolv.so \ - $(shared-thread-library) -+$(objpfx)tst-resolv-invalid-ptr: $(objpfx)libresolv.so \ -+ $(shared-thread-library) - $(objpfx)tst-resolv-noaaaa: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-noaaaa-vc: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-nondecimal: $(objpfx)libresolv.so $(shared-thread-library) -diff --git a/resolv/nss_dns/dns-host.c b/resolv/nss_dns/dns-host.c -index 27096edad2..1bc2e1df95 100644 ---- a/resolv/nss_dns/dns-host.c -+++ b/resolv/nss_dns/dns-host.c -@@ -866,7 +866,7 @@ getanswer_ptr (unsigned char *packet, size_t packetlen, - char hname[MAXHOSTNAMELEN + 1]; - if (__ns_name_unpack (c.begin, c.end, rr.rdata, - name_buffer, sizeof (name_buffer)) < 0 -- || !__res_binary_hnok (expected_name) -+ || !__res_binary_hnok (name_buffer) - || __ns_name_ntop (name_buffer, hname, sizeof (hname)) < 0) - { - *h_errnop = NO_RECOVERY; -diff --git a/resolv/tst-resolv-invalid-ptr.c b/resolv/tst-resolv-invalid-ptr.c -new file mode 100644 -index 0000000000..0c802ab967 ---- /dev/null -+++ b/resolv/tst-resolv-invalid-ptr.c -@@ -0,0 +1,255 @@ -+/* Test handling of invalid T_PTR results (bug 34015). -+ Copyright (C) 2022-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+/* Name of test, the answer, the expected error return, and if we -+ expect the call to fail. */ -+struct item { -+ const char *test; -+ const char *answer; -+ int expected; -+ bool fail; -+}; -+ -+static const struct item test_items[] = -+ { -+ /* Test for invalid characters. */ -+ { "Invalid use of \"|\"", -+ "test.|.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"&\"", -+ "test.&.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \";\"", -+ "test.;.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"<\"", -+ "test.<.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \">\"", -+ "test.>.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"(\"", -+ "test.(.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \")\"", -+ "test.).ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"$\"", -+ "test.$.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"`\"", -+ "test.`.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\\"", -+ "test.\\.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\'\"", -+ "test.'.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\"\"", -+ "test.\".ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \" \"", -+ "test. .ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\t\"", -+ "test.\t.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\n\"", -+ "test.\n.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\r\"", -+ "test.\r.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"*\"", -+ "test.*.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"?\"", -+ "test.?.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"[\"", -+ "test.[.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"]\"", -+ "test.].ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \",\"", -+ "test.,.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"~\"", -+ "test.~.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \":\"", -+ "test.:.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"!\"", -+ "test.!.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"@\"", -+ "test.@.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"#\"", -+ "test.#.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"%\"", -+ "test.%%.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"^\"", -+ "test.^.ptr.example", NO_RECOVERY, true }, -+ -+ /* Test for invalid UTF-8 characters (2-byte, 4-byte, 6-byte). */ -+ { "Invalid use of UTF-8 (2-byte, U+00C0-U+00C2)", -+ "ÁÂÃ.test.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of UTF-8 (4-byte, U+0750-U+0752)", -+ "ݐݑݒ.test.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of UTF-8 (6-byte, U+0904-U+0906)", -+ "ऄअआ.test.ptr.example", NO_RECOVERY, true }, -+ -+ /* Test for "-" which may be valid depending on position. */ -+ { "Invalid leading \"-\"", -+ "-test.ptr.example", NO_RECOVERY, true }, -+ { "Valid trailing \"-\"", -+ "test-.ptr.example", 0, false }, -+ { "Valid mid-label use of \"-\"", -+ "te-st.ptr.example", 0, false }, -+ -+ /* Test for "_" which is always valid in any position. */ -+ { "Valid leading use of \"_\"", -+ "_test.ptr.example", 0, false }, -+ { "Valid mid-label use of \"_\"", -+ "te_st.ptr.example", 0, false }, -+ { "Valid trailing use of \"_\"", -+ "test_.ptr.example", 0, false }, -+ -+ /* Sanity test the broader set [A-Za-z0-9_-] of valid characters. */ -+ { "Valid \"[A-Z]\"", -+ "test.ABCDEFGHIJKLMNOPQRSTUVWXYZ.ptr.example", 0, false }, -+ { "Valid \"[a-z]\"", -+ "test.abcdefghijklmnopqrstuvwxyz.ptr.example", 0, false }, -+ { "Valid \"[0-9]\"", -+ "test.0123456789.ptr.example", 0, false }, -+ { "Valid mixed use of \"[A-Za-z0-9_-]\"", -+ "test.012abcABZ_-.ptr.example", 0, false }, -+ }; -+ -+static void -+response (const struct resolv_response_context *ctx, -+ struct resolv_response_builder *b, -+ const char *qname, uint16_t qclass, uint16_t qtype) -+{ -+ TEST_COMPARE (qclass, C_IN); -+ -+ /* We only test PTR. */ -+ TEST_COMPARE (qtype, T_PTR); -+ -+ unsigned int count, count1; -+ char *tail = NULL; -+ -+ /* The test implementation can handle up to 255 tests. */ -+ if (strstr (qname, "in-addr.arpa") != NULL -+ && sscanf (qname, "%u.%ms", &count, &tail) == 2) -+ TEST_COMPARE_STRING (tail, "0.168.192.in-addr.arpa"); -+ else if (sscanf (qname, "%x.%x.%ms", &count, &count1, &tail) == 3) -+ { -+ TEST_COMPARE_STRING (tail, "\ -+0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa"); -+ count |= count1 << 4; -+ } -+ else -+ FAIL_EXIT1 ("invalid QNAME: %s\n", qname); -+ free (tail); -+ -+ /* Cross check. Count has a fixed bound (soft limit). */ -+ TEST_VERIFY (count >= 0 && count <= 255); -+ -+ /* We have a fixed number of tests (hard limit). */ -+ TEST_VERIFY_EXIT (count < array_length (test_items)); -+ -+ struct resolv_response_flags flags = {}; -+ resolv_response_init (b, flags); -+ resolv_response_add_question (b, qname, qclass, qtype); -+ resolv_response_section (b, ns_s_an); -+ -+ /* Actual answer record. */ -+ resolv_response_open_record (b, qname, qclass, qtype, 60); -+ -+ /* Record the answer. */ -+ resolv_response_add_name (b, test_items[count].answer); -+ resolv_response_close_record (b); -+} -+ -+/* Perform one check using a reverse lookup. */ -+static void -+check_reverse (int af, int count) -+{ -+ TEST_VERIFY (af == AF_INET || af == AF_INET6); -+ TEST_VERIFY_EXIT (count < array_length (test_items)); -+ -+ /* Generate an address to query for each test. */ -+ char addr[sizeof (struct in6_addr)] = { 0 }; -+ socklen_t addrlen; -+ if (af == AF_INET) -+ { -+ addr[0] = (char) 192; -+ addr[1] = (char) 168; -+ addr[2] = (char) 0; -+ addr[3] = (char) count; -+ addrlen = 4; -+ } -+ else -+ { -+ addr[0] = 0x20; -+ addr[1] = 0x01; -+ addr[2] = 0x0d; -+ addr[3] = 0xb8; -+ addr[4] = addr[5] = addr[6] = addr[7] = 0x0; -+ addr[8] = addr[9] = addr[10] = addr[11] = 0x0; -+ addr[12] = 0x0; -+ addr[13] = 0x0; -+ addr[14] = 0x0; -+ addr[15] = (char) count; -+ addrlen = 16; -+ } -+ -+ h_errno = 0; -+ struct hostent *answer = gethostbyaddr (addr, addrlen, af); -+ -+ /* Verify h_errno is as expected. */ -+ TEST_COMPARE (h_errno, test_items[count].expected); -+ if (h_errno != test_items[count].expected) -+ /* And print more information if it's not. */ -+ printf ("INFO: %s\n", test_items[count].test); -+ -+ if (test_items[count].fail) -+ { -+ /* We expected a failure so verify answer is NULL. */ -+ TEST_VERIFY (answer == NULL); -+ /* If it's not NULL we should print out what we received. */ -+ if (answer != NULL) -+ printf ("error: unexpected success: %s\n", -+ support_format_hostent (answer)); -+ } -+ else -+ /* We don't expect a failure so answer must be valid. */ -+ TEST_COMPARE_STRING (answer->h_name, test_items[count].answer); -+} -+ -+static int -+do_test (void) -+{ -+ struct resolv_test *obj = resolv_test_start -+ ((struct resolv_redirect_config) -+ { -+ .response_callback = response -+ }); -+ -+ for (int i = 0; i < array_length (test_items); i++) -+ { -+ check_reverse (AF_INET, i); -+ check_reverse (AF_INET6, i); -+ } -+ resolv_test_end (obj); -+ -+ return 0; -+} -+ -+#include - -commit 68099ccc941664481386c62cba40bbc5dac8b00e -Author: Xi Ruoyao -Date: Tue Feb 3 16:20:12 2026 +0800 - - elf: parse /proc/self/maps as the last resort to find the gap for tst-link-map-contiguous-ldso - - The initialization process of libc.so calls mmap() several times and the - kernel may lay the maps into the gap. If all pages in the gap are - occupied, the test would not be able to find the gap with mmap() and the - test would fail. - - The failure reproduces most frequently on LoongArch because with the - commonly used page size (16 KiB) the gap only contains 4 pages and the - probability they are all occupied is not near to zero. - - With the changes in the patch, a test run may output: - - info: ld.so link map is not contiguous - info: object "/dev/zero" found at 0x7ffff1fe0000 - 0x7ffff1fe4000 - info: anonymous mapping found at 0x7ffff1fe4000 - 0x7ffff1fec000 - - Also take the chance to fix a mistake in the "object found at" message - which has puzzled me during the initial debug session. - - Signed-off-by: Xi Ruoyao - Reviewed-by: Adhemerval Zanella - (cherry picked from commit aed8390a6a22e5751fc12704c0c5f2a8271fc286) - -diff --git a/elf/tst-link-map-contiguous-ldso.c b/elf/tst-link-map-contiguous-ldso.c -index 04de808bb2..f0e26682f2 100644 ---- a/elf/tst-link-map-contiguous-ldso.c -+++ b/elf/tst-link-map-contiguous-ldso.c -@@ -18,15 +18,73 @@ - - #include - #include -+#include - #include - #include - #include - #include -+#include - #include - #include -+#include - #include - #include - -+/* Slow path in case we cannot find a gap with mmap (when the runtime has -+ mapped all the pages in the gap for some reason). */ -+static bool -+find_gap_with_proc_self_map (const struct link_map *l) -+{ -+ int pagesize = getpagesize (); -+ -+ support_need_proc ("Reads /proc/self/maps to find gap in ld.so mapping"); -+ -+ /* Parse /proc/self/maps and find all the mappings in the ld.so range -+ but not from ld.so. */ -+ FILE *f = xfopen ("/proc/self/maps", "r"); -+ char *line = NULL, *path_ldso = NULL; -+ size_t len; -+ bool found = false; -+ while (xgetline (&line, &len, f)) -+ { -+ uintptr_t from, to; -+ char *path = NULL; -+ int r = sscanf (line, "%" SCNxPTR "-%" SCNxPTR "%*s%*s%*s%*s%ms", -+ &from, &to, &path); -+ -+ TEST_VERIFY (r == 2 || r == 3); -+ TEST_COMPARE (from % pagesize, 0); -+ TEST_COMPARE (to % pagesize, 0); -+ -+ if (path_ldso == NULL && l->l_map_start == from) -+ { -+ TEST_COMPARE (r, 3); -+ path_ldso = path; -+ continue; -+ } -+ -+ if (from > l->l_map_start && to < l->l_map_end -+ && (r == 2 || (path_ldso != NULL && strcmp (path, path_ldso)))) -+ { -+ if (r == 2) -+ printf ("info: anonymous mapping found at 0x%" PRIxPTR " - 0x%" -+ PRIxPTR "\n", from, to); -+ else -+ printf ("info: object \"%s\" found at 0x%" PRIxPTR " - 0x%" -+ PRIxPTR "\n", path, from, to); -+ -+ found = true; -+ } -+ -+ free (path); -+ } -+ -+ free (path_ldso); -+ free (line); -+ xfclose (f); -+ return found; -+} -+ - static int - do_test (void) - { -@@ -64,16 +122,18 @@ do_test (void) - if ((void *) dlfo.dlfo_link_map != (void *) l) - { - printf ("info: object \"%s\" found at %p\n", -- dlfo.dlfo_link_map->l_name, ptr); -+ dlfo.dlfo_link_map->l_name, expected); - gap_found = true; - } - } - else - TEST_COMPARE (dlfo_ret, -1); -+ - xmunmap (ptr, 1); - addr += pagesize; - } -- if (!gap_found) -+ -+ if (!gap_found && !find_gap_with_proc_self_map (l)) - FAIL ("no ld.so gap found"); - } - else - -commit a56a2943d2ce541102c630142c2eae0fbfc5886b -Author: Michael Jeanson -Date: Fri Feb 20 11:01:00 2026 -0500 - - tests: fix tst-rseq with Linux 7.0 - - A sub-test of tst-rseq is to validate the return code and errno of the - rseq syscall when attempting to register the exact same rseq area as was - done in the dynamic loader. - - This involves finding the rseq area address by adding the - '__rseq_offset' to the thread pointer and calculating the area size from - the AT_RSEQ_FEATURE_SIZE auxiliary vector. However the test currently - calculates the size of the rseq area allocation in the TLS block which - must be a multiple of AT_RSEQ_ALIGN. - - Up until now that happened to be the same value since the feature size - and alignment exposed by the kernel were below the minimum ABI size of - 32. Starting with Linux 7.0 the feature size has reached 33 while the - alignment is now 64. - - This results in the test trying to re-register the rseq area with a - different size and thus not getting the expected errno value. - - Signed-off-by: Michael Jeanson - Reviewed-by: Mathieu Desnoyers - (cherry picked from commit 67f303b47dc584f204e3f2441b9832082415eebc) - -diff --git a/sysdeps/unix/sysv/linux/tst-rseq.c b/sysdeps/unix/sysv/linux/tst-rseq.c -index 00181cfefb..e83ea2b939 100644 ---- a/sysdeps/unix/sysv/linux/tst-rseq.c -+++ b/sysdeps/unix/sysv/linux/tst-rseq.c -@@ -48,8 +48,7 @@ do_rseq_main_test (void) - size_t rseq_align = MAX (getauxval (AT_RSEQ_ALIGN), RSEQ_MIN_ALIGN); - size_t rseq_feature_size = MAX (getauxval (AT_RSEQ_FEATURE_SIZE), - RSEQ_AREA_SIZE_INITIAL_USED); -- size_t rseq_alloc_size = roundup (MAX (rseq_feature_size, -- RSEQ_AREA_SIZE_INITIAL_USED), rseq_align); -+ size_t rseq_reg_size = MAX (rseq_feature_size, RSEQ_AREA_SIZE_INITIAL); - struct rseq *rseq_abi = __thread_pointer () + __rseq_offset; - - TEST_VERIFY_EXIT (rseq_thread_registered ()); -@@ -89,8 +88,8 @@ do_rseq_main_test (void) - /* Test a rseq registration with the same arguments as the internal - registration which should fail with errno == EBUSY. */ - TEST_VERIFY (((unsigned long) rseq_abi % rseq_align) == 0); -- TEST_VERIFY (__rseq_size <= rseq_alloc_size); -- int ret = syscall (__NR_rseq, rseq_abi, rseq_alloc_size, 0, RSEQ_SIG); -+ TEST_VERIFY (__rseq_size <= rseq_reg_size); -+ int ret = syscall (__NR_rseq, rseq_abi, rseq_reg_size, 0, RSEQ_SIG); - TEST_VERIFY (ret != 0); - TEST_COMPARE (errno, EBUSY); - } - -commit f13c1bb0f97fbc12a6ba1ab5669ce561ea32b80a -Author: Florian Weimer -Date: Thu Apr 16 19:13:43 2026 +0200 - - Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046) - - Follow the example in iso-2022-jp-3.c and use the __count state - variable to store the pending character. This avoids restarting - the conversion if the output buffer ends between two 4-byte UCS-4 - code points, so that the assert reported in the bug can no longer - happen. - - Even though the fix is applied to ibm1364.c, the change is only - effective for the two HAS_COMBINED codecs for IBM1390, IBM1399. - - The test case was mostly auto-generated using - claude-4.6-opus-high-thinking, and composer-2-fast shows up in the - log as well. During review, gpt-5.4-xhigh flagged that the original - version of the test case was not exercising the new character - flush logic. - - This fixes bug 33980. - - Assisted-by: LLM - Reviewed-by: Carlos O'Donell - (cherry picked from commit d6f08d1cf027f4eb2ba289a6cc66853722d4badc) - -diff --git a/iconvdata/Makefile b/iconvdata/Makefile -index 5a2abeea24..cc689f63e9 100644 ---- a/iconvdata/Makefile -+++ b/iconvdata/Makefile -@@ -76,7 +76,7 @@ tests = bug-iconv1 bug-iconv2 tst-loading tst-e2big tst-iconv4 bug-iconv4 \ - tst-iconv6 bug-iconv5 bug-iconv6 tst-iconv7 bug-iconv8 bug-iconv9 \ - bug-iconv10 bug-iconv11 bug-iconv12 tst-iconv-big5-hkscs-to-2ucs4 \ - bug-iconv13 bug-iconv14 bug-iconv15 \ -- tst-iconv-iso-2022-cn-ext -+ tst-iconv-iso-2022-cn-ext tst-bug33980 - ifeq ($(have-thread-library),yes) - tests += bug-iconv3 - endif -@@ -333,6 +333,8 @@ $(objpfx)bug-iconv15.out: $(addprefix $(objpfx), $(gconv-modules)) \ - $(addprefix $(objpfx),$(modules.so)) - $(objpfx)tst-iconv-iso-2022-cn-ext.out: $(addprefix $(objpfx), $(gconv-modules)) \ - $(addprefix $(objpfx),$(modules.so)) -+$(objpfx)tst-bug33980.out: $(addprefix $(objpfx), $(gconv-modules)) \ -+ $(addprefix $(objpfx),$(modules.so)) - - $(objpfx)iconv-test.out: run-iconv-test.sh \ - $(addprefix $(objpfx), $(gconv-modules)) \ -diff --git a/iconvdata/ibm1364.c b/iconvdata/ibm1364.c -index 45c62acee5..244c61ad7a 100644 ---- a/iconvdata/ibm1364.c -+++ b/iconvdata/ibm1364.c -@@ -67,12 +67,29 @@ - - /* Since this is a stateful encoding we have to provide code which resets - the output state to the initial state. This has to be done during the -- flushing. */ -+ flushing. For the to-internal direction (FROM_DIRECTION is true), -+ there may be a pending character that needs flushing. */ - #define EMIT_SHIFT_TO_INIT \ - if ((data->__statep->__count & ~7) != sb) \ - { \ - if (FROM_DIRECTION) \ -- data->__statep->__count &= 7; \ -+ { \ -+ uint32_t ch = data->__statep->__count >> 7; \ -+ if (__glibc_unlikely (ch != 0)) \ -+ { \ -+ if (__glibc_unlikely (outend - outbuf < 4)) \ -+ status = __GCONV_FULL_OUTPUT; \ -+ else \ -+ { \ -+ put32 (outbuf, ch); \ -+ outbuf += 4; \ -+ /* Clear character and db bit. */ \ -+ data->__statep->__count &= 7; \ -+ } \ -+ } \ -+ else \ -+ data->__statep->__count &= 7; \ -+ } \ - else \ - { \ - /* We are not in the initial state. To switch back we have \ -@@ -99,11 +116,13 @@ - *curcsp = save_curcs - - --/* Current codeset type. */ -+/* Current codeset type. The bit is stored in the __count variable of -+ the conversion state. If the db bit is set, bit 7 and above store -+ a pending UCS-4 code point if non-zero. */ - enum - { -- sb = 0, -- db = 64 -+ sb = 0, /* Single byte mode. */ -+ db = 64 /* Double byte mode. */ - }; - - -@@ -119,21 +138,29 @@ enum - } \ - else \ - { \ -- /* This is a combined character. Make sure we have room. */ \ -- if (__glibc_unlikely (outptr + 8 > outend)) \ -- { \ -- result = __GCONV_FULL_OUTPUT; \ -- break; \ -- } \ -- \ - const struct divide *cmbp \ - = &DB_TO_UCS4_COMB[ch - __TO_UCS4_COMBINED_MIN]; \ - assert (cmbp->res1 != 0 && cmbp->res2 != 0); \ - \ - put32 (outptr, cmbp->res1); \ - outptr += 4; \ -- put32 (outptr, cmbp->res2); \ -- outptr += 4; \ -+ \ -+ /* See whether we have room for the second character. */ \ -+ if (outend - outptr >= 4) \ -+ { \ -+ put32 (outptr, cmbp->res2); \ -+ outptr += 4; \ -+ } \ -+ else \ -+ { \ -+ /* Otherwise store only the first character now, and \ -+ put the second one into the queue. */ \ -+ curcs |= cmbp->res2 << 7; \ -+ inptr += 2; \ -+ /* Tell the caller why we terminate the loop. */ \ -+ result = __GCONV_FULL_OUTPUT; \ -+ break; \ -+ } \ - } \ - } - #else -@@ -153,7 +180,20 @@ enum - #define LOOPFCT FROM_LOOP - #define BODY \ - { \ -- uint32_t ch = *inptr; \ -+ uint32_t ch; \ -+ \ -+ ch = curcs >> 7; \ -+ if (__glibc_unlikely (ch != 0)) \ -+ { \ -+ put32 (outptr, ch); \ -+ outptr += 4; \ -+ /* Remove the pending character, but preserve state bits. */ \ -+ curcs &= (1 << 7) - 1; \ -+ continue; \ -+ } \ -+ \ -+ /* Otherwise read the next input byte. */ \ -+ ch = *inptr; \ - \ - if (__builtin_expect (ch, 0) == SO) \ - { \ -diff --git a/iconvdata/tst-bug33980.c b/iconvdata/tst-bug33980.c -new file mode 100644 -index 0000000000..c9693e0efe ---- /dev/null -+++ b/iconvdata/tst-bug33980.c -@@ -0,0 +1,153 @@ -+/* Test for bug 33980: combining characters in IBM1390/IBM1399. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+ -+/* Run iconv in a loop with a small output buffer of OUTBUFSIZE bytes -+ starting at OUTBUF. OUTBUF should be right before an unmapped page -+ so that writing past the end will fault. Skip SHIFT bytes at the -+ start of the input and output, to exercise different buffer -+ alignment. TRUNCATE indicates skipped bytes at the end of -+ input (0 and 1 a valid). */ -+static void -+test_one (const char *encoding, unsigned int shift, unsigned int truncate, -+ char *outbuf, size_t outbufsize) -+{ -+ /* In IBM1390 and IBM1399, the DBCS code 0xECB5 expands to two -+ Unicode code points when translated. */ -+ static char input[] = -+ { -+ /* 8 letters X. */ -+ 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, -+ /* SO, 0xECB5, SI: shift to DBCS, special character, shift back. */ -+ 0x0e, 0xec, 0xb5, 0x0f -+ }; -+ -+ /* Expected output after UTF-8 conversion. */ -+ static char expected[] = -+ { -+ 'X', 'X', 'X', 'X', 'X', 'X', 'X', 'X', -+ /* U+304B (HIRAGANA LETTER KA). */ -+ 0xe3, 0x81, 0x8b, -+ /* U+309A (COMBINING KATAKANA-HIRAGANA SEMI-VOICED SOUND MARK). */ -+ 0xe3, 0x82, 0x9a -+ }; -+ -+ iconv_t cd = iconv_open ("UTF-8", encoding); -+ TEST_VERIFY_EXIT (cd != (iconv_t) -1); -+ -+ char result_storage[64]; -+ struct alloc_buffer result_buf -+ = alloc_buffer_create (result_storage, sizeof (result_storage)); -+ -+ char *inptr = &input[shift]; -+ size_t inleft = sizeof (input) - shift - truncate; -+ -+ while (inleft > 0) -+ { -+ char *outptr = outbuf; -+ size_t outleft = outbufsize; -+ size_t inleft_before = inleft; -+ -+ size_t ret = iconv (cd, &inptr, &inleft, &outptr, &outleft); -+ size_t produced = outptr - outbuf; -+ alloc_buffer_copy_bytes (&result_buf, outbuf, produced); -+ -+ if (ret == (size_t) -1 && errno == E2BIG) -+ { -+ if (produced == 0 && inleft == inleft_before) -+ { -+ /* Output buffer too small to make progress. This is -+ expected for very small output buffer sizes. */ -+ TEST_VERIFY_EXIT (outbufsize < 3); -+ break; -+ } -+ continue; -+ } -+ if (ret == (size_t) -1) -+ FAIL_EXIT1 ("%s (outbufsize %zu): iconv: %m", encoding, outbufsize); -+ break; -+ } -+ -+ /* Flush any pending state (e.g. a buffered combined character). -+ With outbufsize < 3, we could not store the first character, so -+ the second character did not become pending, and there is nothing -+ to flush. */ -+ { -+ char *outptr = outbuf; -+ size_t outleft = outbufsize; -+ -+ size_t ret = iconv (cd, NULL, NULL, &outptr, &outleft); -+ TEST_VERIFY_EXIT (ret == 0); -+ size_t produced = outptr - outbuf; -+ alloc_buffer_copy_bytes (&result_buf, outbuf, produced); -+ -+ /* Second flush does not provide more data. */ -+ outptr = outbuf; -+ outleft = outbufsize; -+ ret = iconv (cd, NULL, NULL, &outptr, &outleft); -+ TEST_VERIFY_EXIT (ret == 0); -+ TEST_VERIFY (outptr == outbuf); -+ } -+ -+ TEST_VERIFY_EXIT (!alloc_buffer_has_failed (&result_buf)); -+ size_t result_used -+ = sizeof (result_storage) - alloc_buffer_size (&result_buf); -+ -+ if (outbufsize >= 3) -+ { -+ TEST_COMPARE (inleft, 0); -+ TEST_COMPARE (result_used, sizeof (expected) - shift); -+ TEST_COMPARE_BLOB (result_storage, result_used, -+ &expected[shift], sizeof (expected) - shift); -+ } -+ else -+ /* If the buffer is too small, only the leading X could be converted. */ -+ TEST_COMPARE (result_used, 8 - shift); -+ -+ TEST_VERIFY_EXIT (iconv_close (cd) == 0); -+} -+ -+static int -+do_test (void) -+{ -+ struct support_next_to_fault ntf -+ = support_next_to_fault_allocate (8); -+ -+ for (int shift = 0; shift <= 8; ++shift) -+ for (int truncate = 0; truncate < 2; ++truncate) -+ for (size_t outbufsize = 1; outbufsize <= 8; outbufsize++) -+ { -+ char *outbuf = ntf.buffer + ntf.length - outbufsize; -+ test_one ("IBM1390", shift, truncate, outbuf, outbufsize); -+ test_one ("IBM1399", shift, truncate, outbuf, outbufsize); -+ } -+ -+ support_next_to_fault_free (&ntf); -+ return 0; -+} -+ -+#include - -commit 12feedaf67e11c4618dc50c6aab4dbfd1e6d9531 -Author: DJ Delorie -Date: Mon Jan 26 22:24:42 2026 -0500 - - include: isolate __O_CLOEXEC flag for sys/mount.h and fcntl.h - - Including sys/mount.h should not implicitly include fcntl.h - as that causes namespace pollution and conflicts with kernel - headers. It only needs O_CLOEXEC for OPEN_TREE_CLOEXEC - (although it shouldn't need that, but it's defined that way) - so we provide that define (via a private version) separately. - - Reviewed-by: Adhemerval Zanella - Tested-by: Florian Weimer - (cherry picked from commit 419245719ccbc7dad6a97f24465e7f09c090327a) - -diff --git a/io/fcntl.c b/io/fcntl.c -index e88e28664c..b7dab1bb39 100644 ---- a/io/fcntl.c -+++ b/io/fcntl.c -@@ -18,6 +18,10 @@ - #include - #include - -+#ifndef __O_CLOEXEC -+# error __O_CLOEXEC not defined by fcntl.h/cloexec.h -+#endif -+ - /* Perform file control operations on FD. */ - int - __fcntl (int fd, int cmd, ...) -diff --git a/sysdeps/unix/sysv/linux/Makefile b/sysdeps/unix/sysv/linux/Makefile -index c47cbdf428..053041f256 100644 ---- a/sysdeps/unix/sysv/linux/Makefile -+++ b/sysdeps/unix/sysv/linux/Makefile -@@ -129,6 +129,7 @@ CFLAGS-test-errno-linux.c += $(no-fortify-source) - - sysdep_headers += \ - bits/a.out.h \ -+ bits/cloexec.h \ - bits/epoll.h \ - bits/eventfd.h \ - bits/inotify.h \ -diff --git a/sysdeps/unix/sysv/linux/alpha/bits/cloexec.h b/sysdeps/unix/sysv/linux/alpha/bits/cloexec.h -new file mode 100644 -index 0000000000..f381f28a53 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/alpha/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 010000000 -diff --git a/sysdeps/unix/sysv/linux/bits/cloexec.h b/sysdeps/unix/sysv/linux/bits/cloexec.h -new file mode 100644 -index 0000000000..3059fb6473 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 02000000 -diff --git a/sysdeps/unix/sysv/linux/bits/fcntl-linux.h b/sysdeps/unix/sysv/linux/bits/fcntl-linux.h -index f425a4bf22..98954feaca 100644 ---- a/sysdeps/unix/sysv/linux/bits/fcntl-linux.h -+++ b/sysdeps/unix/sysv/linux/bits/fcntl-linux.h -@@ -81,9 +81,7 @@ - #ifndef __O_NOFOLLOW - # define __O_NOFOLLOW 0400000 - #endif --#ifndef __O_CLOEXEC --# define __O_CLOEXEC 02000000 --#endif -+#include - #ifndef __O_DIRECT - # define __O_DIRECT 040000 - #endif -diff --git a/sysdeps/unix/sysv/linux/hppa/bits/cloexec.h b/sysdeps/unix/sysv/linux/hppa/bits/cloexec.h -new file mode 100644 -index 0000000000..f381f28a53 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/hppa/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 010000000 -diff --git a/sysdeps/unix/sysv/linux/sparc/bits/cloexec.h b/sysdeps/unix/sysv/linux/sparc/bits/cloexec.h -new file mode 100644 -index 0000000000..6706eaa7d5 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/sparc/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 0x400000 -diff --git a/sysdeps/unix/sysv/linux/sys/mount.h b/sysdeps/unix/sysv/linux/sys/mount.h -index b549e75148..365da1c296 100644 ---- a/sysdeps/unix/sysv/linux/sys/mount.h -+++ b/sysdeps/unix/sysv/linux/sys/mount.h -@@ -21,7 +21,6 @@ - #ifndef _SYS_MOUNT_H - #define _SYS_MOUNT_H 1 - --#include - #include - #include - #include -@@ -266,6 +265,11 @@ enum fsconfig_command - - /* open_tree flags. */ - #define OPEN_TREE_CLONE 1 /* Clone the target tree and attach the clone */ -+#ifndef O_CLOEXEC -+# include -+# define O_CLOEXEC __O_CLOEXEC -+#endif -+#undef OPEN_TREE_CLOEXEC - #define OPEN_TREE_CLOEXEC O_CLOEXEC /* Close the file on execve() */ - - -diff --git a/sysdeps/unix/sysv/linux/tst-mount.c b/sysdeps/unix/sysv/linux/tst-mount.c -index 40913c7082..78a2772b2f 100644 ---- a/sysdeps/unix/sysv/linux/tst-mount.c -+++ b/sysdeps/unix/sysv/linux/tst-mount.c -@@ -20,6 +20,7 @@ - #include - #include - #include -+#include /* For AT_ constants. */ - #include - - _Static_assert (sizeof (struct mount_attr) == MOUNT_ATTR_SIZE_VER0, - -commit 3ecfa68561d723564a1fb565366182eb4acb3e8f -Author: Florian Weimer -Date: Wed Mar 4 18:32:36 2026 +0100 - - Linux: Only define OPEN_TREE_* macros in if undefined (bug 33921) - - There is a conditional inclusion of earlier in the file. - If that defines the macros, do not redefine them. This addresses build - problems as the token sequence used by the UAPI macro definitions - changes between Linux versions. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit d12b017cddfeb9fe9920ba054ae3dfcb8e9238b8) - -diff --git a/sysdeps/unix/sysv/linux/sys/mount.h b/sysdeps/unix/sysv/linux/sys/mount.h -index 365da1c296..30ba56c1e8 100644 ---- a/sysdeps/unix/sysv/linux/sys/mount.h -+++ b/sysdeps/unix/sysv/linux/sys/mount.h -@@ -264,14 +264,16 @@ enum fsconfig_command - #define FSOPEN_CLOEXEC 0x00000001 - - /* open_tree flags. */ --#define OPEN_TREE_CLONE 1 /* Clone the target tree and attach the clone */ -+#ifndef OPEN_TREE_CLONE -+# define OPEN_TREE_CLONE 1 /* Clone the target tree and attach the clone */ -+#endif - #ifndef O_CLOEXEC - # include - # define O_CLOEXEC __O_CLOEXEC - #endif --#undef OPEN_TREE_CLOEXEC --#define OPEN_TREE_CLOEXEC O_CLOEXEC /* Close the file on execve() */ -- -+#ifndef OPEN_TREE_CLOEXEC -+# define OPEN_TREE_CLOEXEC O_CLOEXEC /* Close the file on execve() */ -+#endif - - __BEGIN_DECLS - - -commit 3e87cf9be93acf19d685e8003fc649cdb052a891 -Author: H.J. Lu -Date: Mon Apr 13 10:46:42 2026 +0800 - - abilist.awk: Handle weak unversioned defined symbols - - After - - commit f685e3953f9a38a41bbd0a597f9882870cee13d5 - Author: H.J. Lu - Date: Wed Oct 29 09:49:57 2025 +0800 - - elf: Don't set its DT_VERSYM entry for unversioned symbol - - ld no longer assigns version index 1 to unversioned defined symbol. - For libmachuser.so, "objdump --dynamic-syms" reports: - - 0000dd30 w DF .text 000000f8 processor_start - - instead of - - 0000dd30 w DF .text 000000f8 (Base) processor_start - - Also allow NF == 6 for weak unversioned dynamic symbols. This fixes BZ - 33650. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit ee5d1db2a81468413fbf7c82779ffa782f429d1a) - -diff --git a/scripts/abilist.awk b/scripts/abilist.awk -index 6cc7af6ac8..7ea1edf8c0 100644 ---- a/scripts/abilist.awk -+++ b/scripts/abilist.awk -@@ -38,7 +38,7 @@ $4 == "*UND*" { next } - $2 == "l" { next } - - # If the target uses ST_OTHER, it will be output before the symbol name. --$2 == "g" || $2 == "w" && (NF == 7 || NF == 8) { -+$2 == "g" || $2 == "w" && (NF == 6 || NF == 7 || NF == 8) { - type = $3; - size = $5; - sub(/^0*/, "", size); - -commit b4bca35ab9e76890504c4dbdd5eaf15a93514580 -Author: Rocket Ma -Date: Fri May 1 20:39:07 2026 -0700 - - libio: Fix ungetwc operating on byte stream [BZ #33998] - - * libio/wgenops.c: When _IO_wdefault_pbackfail attempts to push back one - character, it accidently compare the wchar to push back with the last - char from byte stream, instead of wide stream. Under specific coding, - attacker may exploit this to leak information. This commit fix bug - 33998, or CVE-2026-5928. - - Signed-off-by: Rocket Ma - Reviewed-by: Carlos O'Donell - (cherry picked from commit ef3bfb5f910011f3780cb06aa47e730035f53285) - -diff --git a/libio/Makefile b/libio/Makefile -index f020f8ec4d..fa2b8ae791 100644 ---- a/libio/Makefile -+++ b/libio/Makefile -@@ -83,6 +83,7 @@ tests = \ - bug-ungetwc1 \ - bug-ungetwc2 \ - bug-wfflush \ -+ bug-wgenops-bz33998 \ - bug-wmemstream1 \ - bug-wsetpos \ - test-fmemopen \ -diff --git a/libio/bug-wgenops-bz33998.c b/libio/bug-wgenops-bz33998.c -new file mode 100644 -index 0000000000..cc4067da99 ---- /dev/null -+++ b/libio/bug-wgenops-bz33998.c -@@ -0,0 +1,54 @@ -+/* Regression test for ungetwc operating on byte stream (BZ #33998) -+ Copyright (C) 2026 The GNU Toolchain Authors. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "support/temp_file.h" -+#include "support/xstdio.h" -+#include "support/xunistd.h" -+#include -+#include -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ char *filename; -+ int fd = create_temp_file ("tst-bz33998-", &filename); -+ TEST_VERIFY (fd != -1); -+ xwrite (fd, "A", sizeof ("A")); // write "A\0" by design -+ xclose (fd); -+ -+ FILE *fp = xfopen (filename, "r+"); -+ TEST_COMPARE (getwc (fp), L'A'); -+ /* If the bug is fixed, then ungetwc should not touch byte stream. -+ If the bug is not fixed, ungetwc firstly match last read char, L'A', -+ failed, then the pbackfail branch, matching last read char in byte -+ stream, that is, '\0' (initialized when setup wide stream). */ -+ char *old_read_ptr = fp->_IO_read_ptr; -+ TEST_COMPARE (ungetwc (L'\0', fp), L'\0'); -+ TEST_VERIFY (fp->_IO_read_ptr == old_read_ptr); -+ -+ xfclose (fp); -+ free (filename); -+ -+ return 0; -+} -+ -+#include -diff --git a/libio/wgenops.c b/libio/wgenops.c -index 0a11d1b1de..9e0b2c00ea 100644 ---- a/libio/wgenops.c -+++ b/libio/wgenops.c -@@ -108,8 +108,8 @@ _IO_wdefault_pbackfail (FILE *fp, wint_t c) - { - if (fp->_wide_data->_IO_read_ptr > fp->_wide_data->_IO_read_base - && !_IO_in_backup (fp) -- && (wint_t) fp->_IO_read_ptr[-1] == c) -- --fp->_IO_read_ptr; -+ && (wint_t) fp->_wide_data->_IO_read_ptr[-1] == c) -+ --fp->_wide_data->_IO_read_ptr; - else - { - /* Need to handle a filebuf in write mode (switch to read mode). FIXME!*/ - -commit 4ebd33dd77eabe8d4c45232bed4b42a31d2f9edc -Author: Rocket Ma -Date: Fri Apr 17 23:48:41 2026 -0700 - - stdio-common: Fix buffer overflow in scanf %mc [BZ #34008] - - * stdio-common/vfscanf-internal.c: When enlarging allocated buffer with - format %mc or %mC, glibc allocates one byte less, leading to - user-controlled one byte overflow. This commit fixes BZ #34008, or - CVE-2026-5450. - - Reviewed-by: Carlos O'Donell - Signed-off-by: Rocket Ma - Reviewed-by: H.J. Lu - (cherry picked from commit 839898777226a3ed88c0859f25ffe712519b4ead) - -diff --git a/stdio-common/Makefile b/stdio-common/Makefile -index 64b3575acb..e52c333808 100644 ---- a/stdio-common/Makefile -+++ b/stdio-common/Makefile -@@ -347,6 +347,7 @@ tests := \ - tst-vfprintf-user-type \ - tst-vfprintf-width-i18n \ - tst-vfprintf-width-prec-alloc \ -+ tst-vfscanf-bz34008 \ - tst-wc-printf \ - tstdiomisc \ - tstgetln \ -@@ -562,6 +563,9 @@ tst-printf-bz18872-ENV = MALLOC_TRACE=$(objpfx)tst-printf-bz18872.mtrace \ - tst-vfprintf-width-prec-ENV = \ - MALLOC_TRACE=$(objpfx)tst-vfprintf-width-prec.mtrace \ - LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so -+tst-vfscanf-bz34008-ENV = \ -+ MALLOC_CHECK_=3 \ -+ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so - tst-printf-bz25691-ENV = \ - MALLOC_TRACE=$(objpfx)tst-printf-bz25691.mtrace \ - LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so -diff --git a/stdio-common/tst-vfscanf-bz34008.c b/stdio-common/tst-vfscanf-bz34008.c -new file mode 100644 -index 0000000000..48371c8a3d ---- /dev/null -+++ b/stdio-common/tst-vfscanf-bz34008.c -@@ -0,0 +1,48 @@ -+/* Regression test for vfscanf %Nmc out-of-bound write (BZ #34008) -+ Copyright (C) 2026 The GNU Toolchain Authors. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "malloc/mcheck.h" -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+#define WIDTH 0x410 -+#define SCANFSTR "%1040mc" -+static int -+do_test (void) -+{ -+ mcheck_pedantic (NULL); -+ char *input = malloc (WIDTH + 1); -+ TEST_VERIFY (input != NULL); -+ memset (input, 'A', WIDTH); -+ input[WIDTH] = '\0'; -+ -+ char *buf = NULL; -+ TEST_VERIFY (sscanf (input, SCANFSTR, &buf) != -1); -+ TEST_VERIFY (buf != NULL); -+ -+ free (buf); -+ free (input); -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/vfscanf-internal.c b/stdio-common/vfscanf-internal.c -index 86ae5019a6..17b5565d0f 100644 ---- a/stdio-common/vfscanf-internal.c -+++ b/stdio-common/vfscanf-internal.c -@@ -853,8 +853,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - { - /* Enlarge the buffer. */ - size_t newsize -- = strsize -- + (strsize >= width ? width - 1 : strsize); -+ = strsize + (strsize >= width ? width : strsize); - - str = (char *) realloc (*strptr, newsize); - if (str == NULL) -@@ -925,7 +924,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - && wstr == (wchar_t *) *strptr + strsize) - { - size_t newsize -- = strsize + (strsize > width ? width - 1 : strsize); -+ = strsize + (strsize >= width ? width : strsize); - /* Enlarge the buffer. */ - wstr = (wchar_t *) realloc (*strptr, - newsize * sizeof (wchar_t)); -@@ -980,7 +979,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - && wstr == (wchar_t *) *strptr + strsize) - { - size_t newsize -- = strsize + (strsize > width ? width - 1 : strsize); -+ = strsize + (strsize >= width ? width : strsize); - /* Enlarge the buffer. */ - wstr = (wchar_t *) realloc (*strptr, - newsize * sizeof (wchar_t)); - -commit b866ef29773b22a1343ff9084374775114350b78 -Author: Maciej W. Rozycki -Date: Wed May 27 12:57:10 2026 -0400 - - support: Implement 'xfmemopen' for seamless 'fmemopen' use - - Add 'xfmemopen' wrapper for seamless 'fmemopen' use in tests, following - 'xfopen', 'xfclose', etc., and providing a standardized error reporting - facility. - - Reviewed-by: Florian Weimer - (cherry picked from commit fe709cc24578ecfd2ff5b07e10e3829fcb55075b) - - Reviewed-by: Carlos O'Donell - -diff --git a/support/Makefile b/support/Makefile -index d41278eeab..f67f38130a 100644 ---- a/support/Makefile -+++ b/support/Makefile -@@ -134,6 +134,7 @@ libsupport-routines = \ - xfclose \ - xfdopendir \ - xfgets \ -+ xfmemopen \ - xfopen \ - xfork \ - xfread \ -diff --git a/support/xfmemopen.c b/support/xfmemopen.c -new file mode 100644 -index 0000000000..f1dbc72c67 ---- /dev/null -+++ b/support/xfmemopen.c -@@ -0,0 +1,31 @@ -+/* fmemopen with error checking. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+#include -+#include -+ -+FILE * -+xfmemopen (void *mem, size_t len, const char *mode) -+{ -+ FILE *fp = fmemopen (mem, len, mode); -+ if (fp == NULL) -+ FAIL_EXIT1 ("fmemopen (mode \"%s\"): %m", mode); -+ return fp; -+} -diff --git a/support/xstdio.h b/support/xstdio.h -index c3fdf9496f..70b83f11da 100644 ---- a/support/xstdio.h -+++ b/support/xstdio.h -@@ -27,6 +27,7 @@ __BEGIN_DECLS - FILE *xfopen (const char *path, const char *mode); - void xfclose (FILE *); - FILE *xfreopen (const char *path, const char *mode, FILE *stream); -+FILE *xfmemopen (void *mem, size_t len, const char *mode); - void xfread (void *ptr, size_t size, size_t nmemb, FILE *stream); - char *xfgets (char *s, int size, FILE *stream); - - -commit 97926e9017f3faeaacce9337f1288460f5e6ec7d -Author: Maciej W. Rozycki -Date: Wed May 27 12:57:10 2026 -0400 - - stdio-common: Reject insufficient character data in scanf [BZ #12701] - - Reject invalid formatted scanf character data with the 'c' conversion - where there is not enough input available to satisfy the field width - requested. It is required by ISO C that this conversion matches a - sequence of characters of exactly the number specified by the field - width and it is also already documented as such in our own manual: - - "It reads precisely the next N characters, and fails if it cannot get - that many." - - Currently a matching success is instead incorrectly produced where the - EOF condition is encountered before the required number of characters - has been retrieved, and the characters actually obtained are stored in - the buffer provided. - - Add test cases accordingly and remove placeholders from 'c' conversion - input data for the existing scanf tests. - - Reviewed-by: Adhemerval Zanella - - [This is a modified version of commit 2b16c76609, which tests for the - old behavior and only includes the test cases, for older branches - and downstream backports - DJ] - - Reviewed-by: Carlos O'Donell - -diff --git a/localedata/Makefile b/localedata/Makefile -index 4a23593cca..bff5c0bc71 100644 ---- a/localedata/Makefile -+++ b/localedata/Makefile -@@ -236,6 +236,7 @@ tests = \ - bug-iconv-trans \ - bug-setlocale1 \ - bug-usesetlocale \ -+ tst-bz12701-lc \ - tst-bz13988 \ - tst-c-utf8-consistency \ - tst-digits \ -diff --git a/localedata/tst-bz12701-lc.c b/localedata/tst-bz12701-lc.c -new file mode 100644 -index 0000000000..23c2ab7d2a ---- /dev/null -+++ b/localedata/tst-bz12701-lc.c -@@ -0,0 +1,218 @@ -+/* Verify scanf field width handling with the 'lc' conversion (BZ #12701). -+ Copyright (C) 2025-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+/* Compare character-wise the initial part of the wide character object -+ pointed to by WS corresponding to wide characters obtained by the -+ conversion of first N bytes of the multibyte character object pointed -+ to by S. */ -+ -+static int -+tst_bz12701_lc_memcmp (const wchar_t *ds, const char *s, size_t n) -+{ -+ size_t nc = mbsnrtowcs (NULL, &s, n, 0, NULL); -+ -+ struct support_next_to_fault ntf; -+ ntf = support_next_to_fault_allocate (nc * sizeof (wchar_t)); -+ wchar_t *ss = (wchar_t *) ntf.buffer; -+ -+ mbsnrtowcs (ss, &s, n, nc, NULL); -+ int r = wmemcmp (ds, ss, nc); -+ -+ support_next_to_fault_free (&ntf); -+ -+ return r; -+} -+ -+/* Verify various aspects of field width handling, including the data -+ obtained, the number of bytes consumed, and the stream position. */ -+ -+static int -+do_test (void) -+{ -+ if (setlocale (LC_ALL, "pl_PL.UTF-8") == NULL) -+ FAIL_EXIT1 ("setlocale (LC_ALL, \"pl_PL.UTF-8\")"); -+ -+ /* Part of a tongue-twister in Polish, which says: -+ "On a rainy morning cuckoos and warblers, rather than starting -+ on earthworms, stuffed themselves fasted with the flesh of cress." */ -+ static const char s[126] = "Dżdżystym rankiem gżegżółki i piegże, " -+ "zamiast wziąć się za dżdżownice, " -+ "nażarły się na czczo miąższu rzeżuchy"; -+ -+ const char *sp = s; -+ size_t nc; -+ TEST_VERIFY_EXIT ((nc = mbsnrtowcs (NULL, &sp, sizeof (s), 0, NULL)) == 108); -+ -+ struct support_next_to_fault ntfo, ntfi; -+ ntfo = support_next_to_fault_allocate (nc * sizeof (wchar_t)); -+ ntfi = support_next_to_fault_allocate (sizeof (s)); -+ wchar_t *e = (wchar_t *) ntfo.buffer + nc; -+ char *b = ntfi.buffer; -+ -+ wchar_t *c; -+ FILE *f; -+ int ic; -+ int n; -+ int i; -+ -+ memcpy (ntfi.buffer, s, sizeof (s)); -+ -+ ic = i = 0; -+ f = xfmemopen (b, sizeof (s), "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ /* Avoid: "warning: zero width in gnu_scanf format [-Werror=format=]". */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wformat"); -+ TEST_VERIFY_EXIT (fscanf (f, "%0lc%n", c, &n) == 1); -+ DIAG_POP_NEEDS_COMMENT; -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%1lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 3); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 2; -+ i += n; -+ -+ c = e - 4; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%4lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 4); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 4; -+ i += n; -+ -+ c = e - 8; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%8lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 8); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 8; -+ i += n; -+ -+ c = e - 16; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%16lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 20); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 16; -+ i += n; -+ -+ c = e - 32; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%32lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 38); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 32; -+ i += n; -+ -+ c = e - (nc - ic); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_COMPARE (fscanf (f, "%64lc%n", c, &n), 1); -+ TEST_COMPARE (n , 49); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, sizeof (s) - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == sizeof (s)); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ ic = i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 3); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 2; -+ i += n; -+ -+ c = e - (nc - ic); -+ TEST_VERIFY_EXIT (feof (f) == 0); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == EOF); -+ TEST_VERIFY_EXIT (n == 3); -+ -+ TEST_VERIFY_EXIT (ftell (f) == 3); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ ic = i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - (nc - ic); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, 3 - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == 3); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ support_next_to_fault_free (&ntfi); -+ support_next_to_fault_free (&ntfo); -+ -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/Makefile b/stdio-common/Makefile -index e52c333808..fdb545242e 100644 ---- a/stdio-common/Makefile -+++ b/stdio-common/Makefile -@@ -260,6 +260,7 @@ tests := \ - tllformat \ - tst-bz11319 \ - tst-bz11319-fortify2 \ -+ tst-bz12701-c \ - tst-cookie \ - tst-dprintf-length \ - tst-fclose-devzero \ -diff --git a/stdio-common/tst-bz12701-c.c b/stdio-common/tst-bz12701-c.c -new file mode 100644 -index 0000000000..4f3616fbfd ---- /dev/null -+++ b/stdio-common/tst-bz12701-c.c -@@ -0,0 +1,169 @@ -+/* Verify scanf field width handling with the 'c' conversion (BZ #12701). -+ Copyright (C) 2025-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+/* Verify various aspects of field width handling, including the data -+ obtained, the number of bytes consumed, and the stream position. */ -+ -+static int -+do_test (void) -+{ -+ static const char s[43] = "The quick brown fox jumps over the lazy dog"; -+ struct support_next_to_fault ntfo, ntfi; -+ ntfo = support_next_to_fault_allocate (sizeof (s)); -+ ntfi = support_next_to_fault_allocate (sizeof (s)); -+ char *e = ntfo.buffer + sizeof (s); -+ char *b = ntfi.buffer; -+ -+ char *c; -+ FILE *f; -+ int n; -+ int i; -+ -+ memcpy (ntfi.buffer, s, sizeof (s)); -+ -+ i = 0; -+ f = xfmemopen (b, sizeof (s), "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ /* Avoid: "warning: zero width in gnu_scanf format [-Werror=format=]". */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wformat"); -+ TEST_VERIFY_EXIT (fscanf (f, "%0c%n", c, &n) == 1); -+ DIAG_POP_NEEDS_COMMENT; -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%1c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 4; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%4c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 4); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 8; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%8c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 8); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 16; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%16c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 16); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - (sizeof (s) - i); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%32c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 10); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, sizeof (s) - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == sizeof (s)); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - (3 - i); -+ TEST_VERIFY_EXIT (feof (f) == 0); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == EOF); -+ TEST_VERIFY_EXIT (n == 2); -+ -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - (3 - i); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, 3 - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == 3); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ support_next_to_fault_free (&ntfi); -+ support_next_to_fault_free (&ntfo); -+ -+ return 0; -+} -+ -+#include - -commit 6cebb0b80fd783e442a8ad27c3f52cde52a9cac7 -Author: DJ Delorie -Date: Wed May 27 12:57:10 2026 -0400 - - stdio-common: Allow partially-filled %mc buffers [BZ #12701] - - This is a backwards-compatible alternative to the main solution to - the %mc part of 12701. The allocated buffer is expanded to the - requested size and NUL padded, but truncated reads are allowed. - - Reviewed-by: Carlos O'Donell - -diff --git a/localedata/Makefile b/localedata/Makefile -index bff5c0bc71..e212facef0 100644 ---- a/localedata/Makefile -+++ b/localedata/Makefile -@@ -237,6 +237,7 @@ tests = \ - bug-setlocale1 \ - bug-usesetlocale \ - tst-bz12701-lc \ -+ tst-bz12701-lc2 \ - tst-bz13988 \ - tst-c-utf8-consistency \ - tst-digits \ -diff --git a/localedata/tst-bz12701-lc2.c b/localedata/tst-bz12701-lc2.c -new file mode 100644 -index 0000000000..b24e86df0b ---- /dev/null -+++ b/localedata/tst-bz12701-lc2.c -@@ -0,0 +1,47 @@ -+/* Verify scanf memory handling with the 'c' conversion (BZ #12701). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ wchar_t *c = NULL; -+ int i; -+ -+ TEST_VERIFY (sscanf ("1234", "%30mlc", &c) == 1); -+ -+ TEST_VERIFY (c != NULL); -+ TEST_COMPARE_BLOB (c, 5 * sizeof (wchar_t), -+ L"1234\0", 5 * sizeof (wchar_t)); -+ for (i = 5; i < 30; i ++) -+ TEST_VERIFY (c[i] == L'\0'); -+ -+ TEST_VERIFY (malloc_usable_size (c) >= 30 * sizeof(wchar_t)); -+ -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/Makefile b/stdio-common/Makefile -index fdb545242e..27e7ea20f0 100644 ---- a/stdio-common/Makefile -+++ b/stdio-common/Makefile -@@ -261,6 +261,7 @@ tests := \ - tst-bz11319 \ - tst-bz11319-fortify2 \ - tst-bz12701-c \ -+ tst-bz12701-c2 \ - tst-cookie \ - tst-dprintf-length \ - tst-fclose-devzero \ -diff --git a/stdio-common/tst-bz12701-c2.c b/stdio-common/tst-bz12701-c2.c -new file mode 100644 -index 0000000000..5f9ca7c592 ---- /dev/null -+++ b/stdio-common/tst-bz12701-c2.c -@@ -0,0 +1,46 @@ -+/* Verify scanf memory handling with the 'c' conversion (BZ #12701). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ char *c = NULL; -+ int i; -+ -+ TEST_VERIFY (sscanf ("1234", "%30mc", &c) == 1); -+ -+ TEST_VERIFY (c != NULL); -+ TEST_COMPARE_BLOB (c, 5, "1234\0", 5); -+ for (i = 5; i < 30; i ++) -+ TEST_VERIFY (c[i] == '\0'); -+ -+ TEST_VERIFY (malloc_usable_size (c) >= 30); -+ -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/vfscanf-internal.c b/stdio-common/vfscanf-internal.c -index 17b5565d0f..90a1886951 100644 ---- a/stdio-common/vfscanf-internal.c -+++ b/stdio-common/vfscanf-internal.c -@@ -780,9 +780,9 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - conv_error (); \ - } while (0) - #ifdef COMPILE_WSCANF -- STRING_ARG (str, char, 100); -+ STRING_ARG (str, char, (width > 0 ? width : 1)); - #else -- STRING_ARG (str, char, (width > 1024 ? 1024 : width)); -+ STRING_ARG (str, char, (width > 0 ? width : 1)); - #endif - - c = inchar (); -@@ -891,6 +891,11 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - - if (!(flags & SUPPRESS)) - { -+ /* If the buffer isn't completely filled, pad it with NULs. */ -+ if (flags & MALLOC) -+ while (width-- > 0) -+ *str++ = '\0'; -+ - if ((flags & MALLOC) && str - *strptr != strsize) - { - char *cp = (char *) realloc (*strptr, str - *strptr); -@@ -908,7 +913,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - if (width == -1) - width = 1; - -- STRING_ARG (wstr, wchar_t, (width > 1024 ? 1024 : width)); -+ STRING_ARG (wstr, wchar_t, (width > 0 ? width : 1)); - - c = inchar (); - if (__glibc_unlikely (c == EOF)) -@@ -1044,6 +1049,11 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - - if (!(flags & SUPPRESS)) - { -+ /* If the buffer isn't completely filled, pad it with NULs. */ -+ if (flags & MALLOC) -+ while (width-- > 0) -+ *wstr++ = L'\0'; -+ - if ((flags & MALLOC) && wstr - (wchar_t *) *strptr != strsize) - { - wchar_t *cp = (wchar_t *) realloc (*strptr, - -commit 748699d9385fc298f7d3369af0a015a6d88b7e64 -Author: Sam James -Date: Sat Jun 6 20:32:27 2026 +0100 - - elf: don't clobber ld.so.conf in tst-glibc-hwcaps-prepend-cache [BZ #34210] - - dbe5065f2166be20e57a24f246a40d50e001a05d and ae589cb84df10825fc545a45c7007a5f79409bf1 - cater for setups where ld.so.conf{,.d} is required to find runtime support - libraries, but tst-glibc-hwcaps-prepend-cache clobbers the created ld.so.conf - with its own entry. - - Fix it to instead use the ld.so.conf.d created in ae589cb84df10825fc545a45c7007a5f79409bf1 - to co-exist with existing entries. - - Bug: https://bugs.gentoo.org/976773 - Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=31901 - Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=34210 - Tested-by: Andreas K. Hüttel - Reported-by: Eli Schwartz - Reviewed-by: Andreas K. Hüttel - (cherry picked from commit d0cc9bf859d0434e397530d75a6507f13db79fba) - -diff --git a/elf/tst-glibc-hwcaps-prepend-cache.c b/elf/tst-glibc-hwcaps-prepend-cache.c -index b7df3962b5..2d51c22328 100644 ---- a/elf/tst-glibc-hwcaps-prepend-cache.c -+++ b/elf/tst-glibc-hwcaps-prepend-cache.c -@@ -46,7 +46,7 @@ do_test (void) - - { - /* Install the default implementation of libmarkermod1.so. */ -- char *conf_path = xasprintf ("%s/ld.so.conf", support_sysconfdir_prefix); -+ char *conf_path = xasprintf ("%s/ld.so.conf.d/hwcaps.conf", support_sysconfdir_prefix); - xmkdirp (support_sysconfdir_prefix, 0777); - support_write_file_string (conf_path, "/glibc-test/lib\n"); - free (conf_path); - -commit f671746f6c3ae511432b5666953be668267159f8 -Author: Florian Weimer -Date: Tue Jun 9 07:28:02 2026 +0200 - - iconv: Suppress intermediate errors with //TRANSLIT (bug 34236) - - When tentatively converting characters on behalf of - __gconv_transliterate, do not create a persistent error. Just - produce a local error, and rely on __gconv_transliterate to - produce the error if all transliteration options are exhausted. - - This fixes transliteration of “½” to ASCII, which cannot use the - “ 1⁄2 ” alternative. Eventually, the “ 1/2 ” alternative is chosen, - but the error sticks. Therefore, iconv exited with status 1 before - this change. - - Adjust iconv/tst-iconv_prog.sh to test both C and en_US.UTF-8 locales. - This requires changing the way the ICONV template is defined, so that - run_program_env is evaluated multiple times. - - Fixes commit 9a4b0eaf726f5404c6683d5c7c5e86f61c3f3fbc ("iconv: do not - report error exit with transliteration [BZ #32448]"), - commit 6cbf845fcdc76131d0e674cee454fe738b69c69d ("iconv: Preserve - iconv -c error exit on invalid inputs (bug 32046)"), and bug 34236. - - Reviewed-by: Aurelien Jarno - (cherry picked from commit e9325bd7d04aacc45cf39505e279b1ca9de22c08) - -diff --git a/iconv/Makefile b/iconv/Makefile -index 9a94a41ba4..028d24ffc3 100644 ---- a/iconv/Makefile -+++ b/iconv/Makefile -@@ -138,7 +138,8 @@ $(objpfx)test-iconvconfig.out: $(objpfx)iconvconfig - rm -f $$tmp) > $@; \ - $(evaluate-test) - --$(objpfx)tst-iconv_prog.out: tst-iconv_prog.sh $(objpfx)iconv_prog -+$(objpfx)tst-iconv_prog.out: tst-iconv_prog.sh $(objpfx)iconv_prog \ -+ $(gen-locales) - $(BASH) $< $(common-objdir) '$(test-wrapper-env)' \ - '$(run-program-env)' > $@; \ - $(evaluate-test) -diff --git a/iconv/loop.c b/iconv/loop.c -index 1378d23147..74b2a3e26d 100644 ---- a/iconv/loop.c -+++ b/iconv/loop.c -@@ -144,8 +144,10 @@ - if (irreversible == NULL) \ - { \ - /* This means we are in call from __gconv_transliterate. In this \ -- case we are not doing any error recovery ourselves. */ \ -- result = __gconv_mark_illegal_input (step_data); \ -+ case we are not doing any error recovery ourselves. Do not create \ -+ a persistent error state. If __gconv_transliterate exhausts all \ -+ alternatives, it will call __gconv_mark_illegal_input itself. */ \ -+ result = __GCONV_ILLEGAL_INPUT; \ - break; \ - } \ - \ -diff --git a/iconv/tst-iconv_prog.sh b/iconv/tst-iconv_prog.sh -index e2a43280d2..7d7948b7aa 100644 ---- a/iconv/tst-iconv_prog.sh -+++ b/iconv/tst-iconv_prog.sh -@@ -27,10 +27,10 @@ LIBPATH=$codir:$codir/iconvdata - - # How the start the iconv(1) program. $from is not defined/expanded yet. - ICONV=' -+$test_wrapper_env $run_program_env - $codir/elf/ld.so --library-path $LIBPATH --inhibit-rpath ${from}.so - $codir/iconv/iconv_prog - ' --ICONV="$test_wrapper_env $run_program_env $ICONV" - - TIMEOUTFACTOR=${TIMEOUTFACTOR:-1} - -@@ -218,6 +218,7 @@ testarray=( - "\x00\x00;;INVALID;UTF-8;1" - "\x00\x00;;UTF-8;INVALID;1" - "\xc3\xa9;;UTF-8;ASCII//TRANSLIT;0" -+"X\xc2\xbdY;;UTF-8;ASCII//TRANSLIT;0" - ) - - # Requires $twobyte input, $c flag, $from, and $to to be set; sets $ret -@@ -278,12 +279,21 @@ check_errtest_result () - fi - } - --for testcommand in "${testarray[@]}"; do -- twobyte="$(echo "$testcommand" | cut -d";" -f 1)" -- c="$(echo "$testcommand" | cut -d";" -f 2)" -- from="$(echo "$testcommand" | cut -d";" -f 3)" -- to="$(echo "$testcommand" | cut -d";" -f 4)" -- eret="$(echo "$testcommand" | cut -d";" -f 5)" -- execute_test -- check_errtest_result --done -+run_test_array () -+{ -+ for testcommand in "${testarray[@]}"; do -+ twobyte="$(echo "$testcommand" | cut -d";" -f 1)" -+ c="$(echo "$testcommand" | cut -d";" -f 2)" -+ from="$(echo "$testcommand" | cut -d";" -f 3)" -+ to="$(echo "$testcommand" | cut -d";" -f 4)" -+ eret="$(echo "$testcommand" | cut -d";" -f 5)" -+ execute_test -+ check_errtest_result -+ done -+} -+ -+echo "info: testing C locale" -+run_test_array -+echo "info: testing en_US.UTF-8 locale" -+run_program_env="$run_program_env LC_ALL=en_US.UTF-8" -+run_test_array - -commit f6713070c6accac5c93d96c1d580833afacde3f5 -Author: Adhemerval Zanella -Date: Wed May 13 08:32:24 2026 -0300 - - arm: Save/restore VFP registers in PLT trampolines (BZ 34144, BZ 15792) - - _dl_runtime_resolve and _dl_runtime_profile only preserved the integer - argument registers (r0-r3) across the inner call to _dl_fixup / - _dl_profile_fixup. Two related ABI requirements demand more: - - * Under AAPCS-VFP, d0-d7 hold the caller's double arguments to the - function being resolved. Recent GCC emits VFP instructions inside - the fixup routines, clobbering them, so the resolved function sees - corrupted arguments (BZ 34144). - - * Per RTABI32, the __aeabi_mem* helpers (and similar runtime helpers - reachable through the dynamic linker) must only corrupt integer - core registers. IFUNC resolvers, audit modules, and interposed - malloc invoked during symbol resolution may also use VFP, even on - softfp ABI builds (BZ 15792). - - Save all call-clobbered VFP state -- d0-d15 unconditionally, d16-d31 - when HWCAP_ARM_VFPD32 is set, and fpscr -- around the inner fixup - call. Whether VFP is usable is a property of the hardware, not of - the ABI glibc was built with, so the decision is gated on AT_HWCAP at - runtime in both hardfp and softfp builds; hardfp builds will always - find HWCAP_ARM_VFP set, while softfp builds running on a non-VFP CPU - correctly skip the save. - - For _dl_runtime_profile the save area is slipped in just before the - bl to _dl_profile_fixup; the outgoing framesizep argument is - recomputed to account for the extra frame, and both the fast path - (no audit framesize) and the slow path (audit wraps with - pltenter/pltexit) traverse the restore before splitting. - - Checked on arm-linux-gnueabihf. - - Tested-by: Aurelien Jarno - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 1111fbdd3e7ebed402800bc23e67055eaae0d972) - -diff --git a/sysdeps/arm/Makefile b/sysdeps/arm/Makefile -index 9c4fd6b236..be9e46aeeb 100644 ---- a/sysdeps/arm/Makefile -+++ b/sysdeps/arm/Makefile -@@ -30,6 +30,25 @@ $(objpfx)tst-armtlsdescloc: $(objpfx)tst-armtlsdesclocmod.so - $(objpfx)tst-armtlsdescextnow: $(objpfx)tst-armtlsdescextnowmod.so - $(objpfx)tst-armtlsdescextlazy: $(objpfx)tst-armtlsdescextlazymod.so - endif -+ -+tests += \ -+ tst-bz34144 \ -+ tst-bz34144-audit \ -+ # tests -+modules-names += \ -+ tst-bz34144-auditmod \ -+ tst-bz34144-mod \ -+ # modules-names -+$(objpfx)tst-bz34144: $(objpfx)tst-bz34144-mod.so -+$(objpfx)tst-bz34144-audit: $(objpfx)tst-bz34144-mod.so -+$(objpfx)tst-bz34144-audit.out: $(objpfx)tst-bz34144-auditmod.so -+# Use lazy binding to check if _dl_runtime_resolve correctly save/restore -+# the VFP state. -+LDFLAGS-tst-bz34144 = -Wl,-z,lazy -+# With LD_AUDIT, lazy resolution goes through _dl_runtime_profile, which -+# must also save/restore VFP state (BZ 34144). -+LDFLAGS-tst-bz34144-audit = -Wl,-z,lazy -+tst-bz34144-audit-ENV = LD_AUDIT=$(objpfx)tst-bz34144-auditmod.so - endif - endif - -diff --git a/sysdeps/arm/dl-trampoline.S b/sysdeps/arm/dl-trampoline.S -index fffac55050..ef358d48bc 100644 ---- a/sysdeps/arm/dl-trampoline.S -+++ b/sysdeps/arm/dl-trampoline.S -@@ -20,6 +20,7 @@ - #define NO_THUMB - #include - #include -+#include - - .text - .globl _dl_runtime_resolve -@@ -36,13 +37,40 @@ _dl_runtime_resolve: - @ ip contains &GOT[n+3] (pointer to function) - @ lr points to &GOT[2] - -- @ Save arguments. We save r4 to realign the stack. -+ @ Save arguments. We save r4 to realign the stack and to hold -+ @ the hwcap value used to decide whether to save VFP registers. - push {r0-r4} - cfi_adjust_cfa_offset (20) - cfi_rel_offset (r0, 0) - cfi_rel_offset (r1, 4) - cfi_rel_offset (r2, 8) - cfi_rel_offset (r3, 12) -+ cfi_rel_offset (r4, 16) -+ -+#ifdef SHARED -+ @ Preserve all call-clobbered VFP registers across _dl_fixup. -+ @ VFP may be used by IFUNC resolvers, audit modules, interposed -+ @ malloc, and the __aeabi_mem* helpers required by RTABI32, -+ @ which mandates that those helpers only corrupt integer core -+ @ registers. -+ LDR_GLOBAL (r4, r3, C_SYMBOL_NAME(_rtld_global_ro), \ -+ RTLD_GLOBAL_RO_DL_HWCAP_OFFSET) -+ -+ tst r4, #HWCAP_ARM_VFP -+ beq .Lno_vfp_save -+ -+# define VFP_STACK_REQ (32*8 + 8) -+ sub sp, sp, VFP_STACK_REQ -+ cfi_adjust_cfa_offset (VFP_STACK_REQ) -+ mov r3, sp -+ .inst 0xeca30b20 @ vstmia r3!, {d0-d15} -+ tst r4, #HWCAP_ARM_VFPD32 -+ beq 1f -+ .inst 0xece30b20 @ vstmia r3!, {d16-d31} -+1: .inst 0xeef12a10 @ vmrs r2, fpscr -+ str r2, [r3] -+.Lno_vfp_save: -+#endif /* SHARED */ - - @ get pointer to linker struct - ldr r0, [lr, #-4] -@@ -59,8 +87,23 @@ _dl_runtime_resolve: - @ save the return - mov ip, r0 - -- @ get arguments and return address back. We restore r4 -- @ only to realign the stack. -+#ifdef SHARED -+ tst r4, #HWCAP_ARM_VFP -+ beq .Lno_vfp_restore -+ mov r3, sp -+ .inst 0xecb30b20 @ vldmia r3!, {d0-d15} -+ tst r4, #HWCAP_ARM_VFPD32 -+ beq 2f -+ .inst 0xecf30b20 @ vldmia r3!, {d16-d31} -+2: ldr r2, [r3] -+ .inst 0xeee12a10 @ vmsr fpscr, r2 -+ add sp, sp, VFP_STACK_REQ -+ cfi_adjust_cfa_offset (-VFP_STACK_REQ) -+.Lno_vfp_restore: -+#endif /* SHARED */ -+ -+ @ get arguments and return address back. We restore r4 to -+ @ its original value as well. - pop {r0-r4,lr} - cfi_adjust_cfa_offset (-24) - -@@ -124,14 +167,71 @@ _dl_runtime_profile: - add r3, sp, #8 - stmia r3!, {r0,r1} - -+ @ Preserve all call-clobbered VFP registers across -+ @ _dl_profile_fixup. See the matching comment in -+ @ _dl_runtime_resolve above for the rationale (BZ 34144, -+ @ BZ 15792). -+ @ -+ @ Stack layout below the current sp (which becomes the new sp -+ @ after the sub): -+ @ sp + 0 .. 3: outgoing arg (framesizep) for _dl_profile_fixup -+ @ sp + 4 .. 7: saved hwcap (so we can test it after the call) -+ @ sp + 8 .. 11: saved r2 (used as scratch for LDR_GLOBAL) -+ @ sp + 12 .. 15: padding (for 8-byte alignment of the VFP area) -+ @ sp + 16 .. 16+VFP_STACK_REQ-1: VFP regs + fpscr -+#define VFP_PROFILE_STACK (16 + VFP_STACK_REQ) -+ sub sp, sp, #VFP_PROFILE_STACK -+ cfi_adjust_cfa_offset (VFP_PROFILE_STACK) -+ -+ @ r2 holds the retaddr (3rd arg to _dl_profile_fixup); spill -+ @ it so we can use it as the LDR_GLOBAL destination. -+ str r2, [sp, #8] -+ -+ LDR_GLOBAL (r2, ip, C_SYMBOL_NAME(_rtld_global_ro), \ -+ RTLD_GLOBAL_RO_DL_HWCAP_OFFSET) -+ str r2, [sp, #4] -+ -+ tst r2, #HWCAP_ARM_VFP -+ beq .Lprofile_no_vfp_save -+ add ip, sp, #16 -+ .inst 0xecac0b20 @ vstmia ip!, {d0-d15} -+ tst r2, #HWCAP_ARM_VFPD32 -+ beq 7f -+ .inst 0xecec0b20 @ vstmia ip!, {d16-d31} -+7: .inst 0xeef12a10 @ vmrs r2, fpscr -+ str r2, [ip] -+.Lprofile_no_vfp_save: -+ -+ @ Restore r2 (retaddr) for _dl_profile_fixup. -+ ldr r2, [sp, #8] -+ - @ Set up extra args for _dl_profile_fixup. -- @ r2 and r3 are already loaded. -- add ip, sp, #208 -+ @ The framesize slot is at the old sp+208, which is the new -+ @ sp + VFP_PROFILE_STACK + 208 -- compute in two steps because -+ @ the combined offset is not encodable as an ARM immediate. -+ add ip, sp, #VFP_PROFILE_STACK -+ add ip, ip, #208 - str ip, [sp, #0] - - @ call profiling fixup routine - bl _dl_profile_fixup - -+ @ Restore VFP registers. r0 holds the resolved function -+ @ address; r1/r2/ip are caller-saved by the call. -+ ldr r1, [sp, #4] -+ tst r1, #HWCAP_ARM_VFP -+ beq .Lprofile_no_vfp_restore -+ add ip, sp, #16 -+ .inst 0xecbc0b20 @ vldmia ip!, {d0-d15} -+ tst r1, #HWCAP_ARM_VFPD32 -+ beq 8f -+ .inst 0xecfc0b20 @ vldmia ip!, {d16-d31} -+8: ldr r2, [ip] -+ .inst 0xeee12a10 @ vmsr fpscr, r2 -+.Lprofile_no_vfp_restore: -+ add sp, sp, #VFP_PROFILE_STACK -+ cfi_adjust_cfa_offset (-VFP_PROFILE_STACK) -+ - @ The address to call is now in r0. - - @ Check whether we're wrapping this function. -diff --git a/sysdeps/arm/tst-bz34144-audit.c b/sysdeps/arm/tst-bz34144-audit.c -new file mode 100644 -index 0000000000..8f1084fa0a ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144-audit.c -@@ -0,0 +1,32 @@ -+/* Test that lazy PLT resolution via _dl_runtime_profile preserves -+ caller-saved VFP registers used to pass double arguments (BZ 34144). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+extern void test_float_args (double a, double b, double c, double d, -+ double e, double f, double g, double h); -+ -+static int -+do_test (void) -+{ -+ test_float_args (2.0, 3.0, 4.0, 5.0, 6.0, 7.0, 8.0, 9.0); -+ return 0; -+} -+ -+#include -diff --git a/sysdeps/arm/tst-bz34144-auditmod.c b/sysdeps/arm/tst-bz34144-auditmod.c -new file mode 100644 -index 0000000000..ada9f126c2 ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144-auditmod.c -@@ -0,0 +1,50 @@ -+/* Minimal audit module used by tst-bz34144-audit to force PLT calls -+ to go through _dl_runtime_profile instead of _dl_runtime_resolve. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+unsigned int -+la_version (unsigned int v) -+{ -+ return v; -+} -+ -+unsigned int -+la_objopen (struct link_map *l, Lmid_t lmid, uintptr_t *cookie) -+{ -+ return LA_FLG_BINDFROM | LA_FLG_BINDTO; -+} -+ -+uintptr_t -+la_symbind32 (Elf32_Sym *sym, unsigned int ndx, uintptr_t *refcook, -+ uintptr_t *defcook, unsigned int *flags, const char *symname) -+{ -+ return sym->st_value; -+} -+ -+Elf32_Addr -+la_arm_gnu_pltenter (Elf32_Sym *sym, unsigned int ndx, uintptr_t *refcook, -+ uintptr_t *defcook, La_arm_regs *regs, -+ unsigned int *flags, const char *symname, -+ long int *framesizep) -+{ -+ return sym->st_value; -+} -diff --git a/sysdeps/arm/tst-bz34144-mod.c b/sysdeps/arm/tst-bz34144-mod.c -new file mode 100644 -index 0000000000..be6b54bf91 ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144-mod.c -@@ -0,0 +1,28 @@ -+/* DSO used by tst-bz34144. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+void -+test_float_args (double a, double b, double c, double d, -+ double e, double f, double g, double h) -+{ -+ if (a != 2.0 || b != 3.0 || c != 4.0 || d != 5.0 -+ || e != 6.0 || f != 7.0 || g != 8.0 || h != 9.0) -+ abort (); -+} -diff --git a/sysdeps/arm/tst-bz34144.c b/sysdeps/arm/tst-bz34144.c -new file mode 100644 -index 0000000000..61e41b3945 ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144.c -@@ -0,0 +1,32 @@ -+/* Test that lazy PLT resolution preserves caller-saved VFP registers -+ used to pass double arguments (BZ 34144). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+extern void test_float_args (double a, double b, double c, double d, -+ double e, double f, double g, double h); -+ -+static int -+do_test (void) -+{ -+ test_float_args (2.0, 3.0, 4.0, 5.0, 6.0, 7.0, 8.0, 9.0); -+ return 0; -+} -+ -+#include - -commit 0be5a6a72a4a3132bc211720d2b6949a84f54dc3 -Author: John David Anglin -Date: Tue Jun 23 13:41:10 2026 -0400 - - hppa: Fix missing call to __feraiseexcept (BZ 34306) - - The feupdateenv function is supposed to raise exceptions after - installing the environment represented by its envp argument. - This was accidentally missed on hppa. - - The failure to raise exceptions was noticed by the failure of - the math/test-narrowing-trap test. - - Signed-off-by: John David Anglin - -diff --git a/sysdeps/hppa/fpu/feupdateenv.c b/sysdeps/hppa/fpu/feupdateenv.c -index 46b83cc7a0..a3d3de33e4 100644 ---- a/sysdeps/hppa/fpu/feupdateenv.c -+++ b/sysdeps/hppa/fpu/feupdateenv.c -@@ -24,6 +24,7 @@ __feupdateenv (const fenv_t *envp) - { - union { unsigned long long l; unsigned int sw[2]; } s; - fenv_t temp; -+ - /* Get the current exception status */ - __asm__ ("fstd %%fr0,0(%1) \n\t" - "fldd 0(%1),%%fr0 \n\t" -@@ -46,6 +47,10 @@ __feupdateenv (const fenv_t *envp) - - /* Install new environment. */ - __fesetenv (&temp); -+ -+ /* Raise exceptions. */ -+ __feraiseexcept (temp.__status_word >> 27); -+ - /* Success. */ - return 0; - } - -commit 54929540335ef339ac66a8c28e3f4c22ebae2630 -Author: Fabian Rast -Date: Thu Jun 11 14:30:37 2026 +0200 - - rtld: cache cpuid results on the stack for intel - - dl_init_cacheinfo retrieves various information about cache - sizes, using the cpuid instruction on x86. - Previously, the same cpuid leaves were queried multiple times. - This behavior caused intel_check_word to prominently show up in - profiles of dynamic loader startup on the Intel(R) Xeon(R) Gold 6430. - The big performance impact could not be reproduced on other Intel cpus. - - This patch reduces the number of cpuid queries on startup - by caching their results on the stack for reuse when searching for a - different cache size value. - This approach does not change the overall design of - the cache enumeration code (repeated calls to handle_* functions). - The values are cached on the stack instead of globally (e.g. - in the cpu_features global) because they are never needed after - early initialization. - - The cache is only active for Intel cpus, because it has not yet - been shown through benchmarks that it meaningfully improves performance - for other processors. - - Signed-off-by: Fabian Rast - Reviewed-by: Sunil K Pandey - (cherry picked from commit df83fa8813eb53dcb232462a4f6dd00c873115f0) - -diff --git a/sysdeps/x86/dl-cacheinfo.h b/sysdeps/x86/dl-cacheinfo.h -index 6f9bb08a19..201d3ad278 100644 ---- a/sysdeps/x86/dl-cacheinfo.h -+++ b/sysdeps/x86/dl-cacheinfo.h -@@ -98,6 +98,15 @@ static const struct intel_02_cache_info - - #define nintel_02_known (sizeof (intel_02_known) / sizeof (intel_02_known [0])) - -+/* Cache for redundant cpuid queries in handle_intel, intel_check_word and -+ get_common_cache_info. Currently, this has only been shown to significantly -+ improve performance on a specific Intel CPU (Xeon 6430). */ -+struct intel_cpuid_cache -+{ -+ unsigned char leaf2_valid, leaf4_valid; /* Number of cached (sub)leaves. */ -+ unsigned int leaf2[4], leaf4[0x10][4]; -+}; -+ - static int - intel_02_known_compare (const void *p1, const void *p2) - { -@@ -118,7 +127,8 @@ static long int - __attribute__ ((noinline)) - intel_check_word (int name, unsigned int value, bool *has_level_2, - bool *no_level_2_or_3, -- const struct cpu_features *cpu_features) -+ const struct cpu_features *cpu_features, -+ struct intel_cpuid_cache *cache) - { - if ((value & 0x80000000) != 0) - /* The register value is reserved. */ -@@ -152,7 +162,21 @@ intel_check_word (int name, unsigned int value, bool *has_level_2, - unsigned int round = 0; - while (1) - { -- __cpuid_count (4, round, eax, ebx, ecx, edx); -+ if (round < cache->leaf4_valid) -+ /* Subleaf was queried before. Do not execute cpuid again. */ -+ eax = cache->leaf4[round][0], ebx = cache->leaf4[round][1], -+ ecx = cache->leaf4[round][2], edx = cache->leaf4[round][3]; -+ else if (round == cache->leaf4_valid -+ && round < sizeof(cache->leaf4)/sizeof(*cache->leaf4)) -+ { -+ /* Cache the cpuid result if we have space. */ -+ __cpuid_count (4, round, eax, ebx, ecx, edx); -+ cache->leaf4[round][0] = eax, cache->leaf4[round][1] = ebx; -+ cache->leaf4[round][2] = ecx, cache->leaf4[round][3] = edx; -+ cache->leaf4_valid++; -+ } -+ else -+ __cpuid_count (4, round, eax, ebx, ecx, edx); - - enum { null = 0, data = 1, inst = 2, uni = 3 } type = eax & 0x1f; - if (type == null) -@@ -247,7 +271,8 @@ intel_check_word (int name, unsigned int value, bool *has_level_2, - - - static long int __attribute__ ((noinline)) --handle_intel (int name, const struct cpu_features *cpu_features) -+handle_intel (int name, const struct cpu_features *cpu_features, -+ struct intel_cpuid_cache *cache) - { - unsigned int maxidx = cpu_features->basic.max_cpuid; - -@@ -260,41 +285,33 @@ handle_intel (int name, const struct cpu_features *cpu_features) - long int result = 0; - bool no_level_2_or_3 = false; - bool has_level_2 = false; -- unsigned int eax; -- unsigned int ebx; -- unsigned int ecx; -- unsigned int edx; -- __cpuid (2, eax, ebx, ecx, edx); -+ int i; -+ -+ if (!cache->leaf2_valid) -+ { -+ __cpuid (2, cache->leaf2[0], cache->leaf2[1], -+ cache->leaf2[2], cache->leaf2[3]); -+ cache->leaf2_valid = 1; -+ } - - /* The low byte of EAX of CPUID leaf 2 should always return 1 and it - should be ignored. If it isn't 1, use CPUID leaf 4 instead. */ -- if ((eax & 0xff) != 1) -+ if ((cache->leaf2[0] & 0xff) != 1) - return intel_check_word (name, 0xff, &has_level_2, &no_level_2_or_3, -- cpu_features); -- else -- { -- eax &= 0xffffff00; -- -- /* Process the individual registers' value. */ -- result = intel_check_word (name, eax, &has_level_2, -- &no_level_2_or_3, cpu_features); -- if (result != 0) -- return result; -+ cpu_features, cache); - -- result = intel_check_word (name, ebx, &has_level_2, -- &no_level_2_or_3, cpu_features); -- if (result != 0) -- return result; -- -- result = intel_check_word (name, ecx, &has_level_2, -- &no_level_2_or_3, cpu_features); -- if (result != 0) -- return result; -+ /* Process all descriptors in leaf 2. */ -+ result = intel_check_word (name, cache->leaf2[0]&0xffffff00, &has_level_2, -+ &no_level_2_or_3, cpu_features, cache); -+ if (result != 0) -+ return result; - -- result = intel_check_word (name, edx, &has_level_2, -- &no_level_2_or_3, cpu_features); -+ for (i = 1; i < 4; i++) -+ { -+ result = intel_check_word (name, cache->leaf2[i], &has_level_2, -+ &no_level_2_or_3, cpu_features, cache); - if (result != 0) -- return result; -+ return result; - } - - if (name >= _SC_LEVEL2_CACHE_SIZE && name <= _SC_LEVEL3_CACHE_LINESIZE -@@ -611,7 +628,7 @@ handle_hygon (int name) - - static void - get_common_cache_info (long int *shared_ptr, long int * shared_per_thread_ptr, unsigned int *threads_ptr, -- long int core) -+ long int core, struct intel_cpuid_cache *cache) - { - unsigned int eax; - unsigned int ebx; -@@ -669,7 +686,14 @@ get_common_cache_info (long int *shared_ptr, long int * shared_per_thread_ptr, u - int check = 0x1 | (threads_l3 == 0) << 1; - do - { -- __cpuid_count (4, i++, eax, ebx, ecx, edx); -+ if (cache != NULL && i < cache->leaf4_valid) -+ eax = cache->leaf4[i][0], ebx = cache->leaf4[i][1], -+ ecx = cache->leaf4[i][2], edx = cache->leaf4[i][3]; -+ else -+ /* Do not attempt to cache queries at this point, -+ because get_common_cache_info is called last. */ -+ __cpuid_count (4, i, eax, ebx, ecx, edx); -+ i++; - - /* There seems to be a bug in at least some Pentium Ds - which sometimes fail to iterate all cache parameters. -@@ -849,35 +873,38 @@ dl_init_cacheinfo (struct cpu_features *cpu_features) - - if (cpu_features->basic.kind == arch_kind_intel) - { -- data = handle_intel (_SC_LEVEL1_DCACHE_SIZE, cpu_features); -- shared = handle_intel (_SC_LEVEL3_CACHE_SIZE, cpu_features); -+ struct intel_cpuid_cache cache; -+ cache.leaf2_valid = cache.leaf4_valid = 0; -+ -+ data = handle_intel (_SC_LEVEL1_DCACHE_SIZE, cpu_features, &cache); -+ shared = handle_intel (_SC_LEVEL3_CACHE_SIZE, cpu_features, &cache); - shared_per_thread = shared; - - level1_icache_size -- = handle_intel (_SC_LEVEL1_ICACHE_SIZE, cpu_features); -+ = handle_intel (_SC_LEVEL1_ICACHE_SIZE, cpu_features, &cache); - level1_icache_linesize -- = handle_intel (_SC_LEVEL1_ICACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL1_ICACHE_LINESIZE, cpu_features, &cache); - level1_dcache_size = data; - level1_dcache_assoc -- = handle_intel (_SC_LEVEL1_DCACHE_ASSOC, cpu_features); -+ = handle_intel (_SC_LEVEL1_DCACHE_ASSOC, cpu_features, &cache); - level1_dcache_linesize -- = handle_intel (_SC_LEVEL1_DCACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL1_DCACHE_LINESIZE, cpu_features, &cache); - level2_cache_size -- = handle_intel (_SC_LEVEL2_CACHE_SIZE, cpu_features); -+ = handle_intel (_SC_LEVEL2_CACHE_SIZE, cpu_features, &cache); - level2_cache_assoc -- = handle_intel (_SC_LEVEL2_CACHE_ASSOC, cpu_features); -+ = handle_intel (_SC_LEVEL2_CACHE_ASSOC, cpu_features, &cache); - level2_cache_linesize -- = handle_intel (_SC_LEVEL2_CACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL2_CACHE_LINESIZE, cpu_features, &cache); - level3_cache_size = shared; - level3_cache_assoc -- = handle_intel (_SC_LEVEL3_CACHE_ASSOC, cpu_features); -+ = handle_intel (_SC_LEVEL3_CACHE_ASSOC, cpu_features, &cache); - level3_cache_linesize -- = handle_intel (_SC_LEVEL3_CACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL3_CACHE_LINESIZE, cpu_features, &cache); - level4_cache_size -- = handle_intel (_SC_LEVEL4_CACHE_SIZE, cpu_features); -+ = handle_intel (_SC_LEVEL4_CACHE_SIZE, cpu_features, &cache); - - get_common_cache_info (&shared, &shared_per_thread, &threads, -- level2_cache_size); -+ level2_cache_size, &cache); - } - else if (cpu_features->basic.kind == arch_kind_zhaoxin) - { -@@ -898,7 +925,7 @@ dl_init_cacheinfo (struct cpu_features *cpu_features) - level3_cache_linesize = handle_zhaoxin (_SC_LEVEL3_CACHE_LINESIZE); - - get_common_cache_info (&shared, &shared_per_thread, &threads, -- level2_cache_size); -+ level2_cache_size, NULL); - } - else if (cpu_features->basic.kind == arch_kind_amd) - { - -commit f2f55eac9e6f1167486f2694dea88adf87c77fdd -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Declare __p_class_syms, __p_type_syms for internal use - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 360f352c9a6da545d798ef3015e73ca114f0d230) - -diff --git a/include/resolv.h b/include/resolv.h -index 4dbbac3800..d5ad9994b9 100644 ---- a/include/resolv.h -+++ b/include/resolv.h -@@ -70,6 +70,11 @@ libc_hidden_proto (__libc_res_nameinquery) - extern __typeof (__res_queriesmatch) __libc_res_queriesmatch; - libc_hidden_proto (__libc_res_queriesmatch) - -+extern const struct res_sym __p_class_syms[]; -+libresolv_hidden_proto (__p_class_syms) -+extern const struct res_sym __p_type_syms[]; -+libresolv_hidden_proto (__p_type_syms) -+ - /* Variant of res_hnok which operates on binary (but uncompressed) names. */ - bool __res_binary_hnok (const unsigned char *dn) attribute_hidden; - -diff --git a/resolv/res_debug.c b/resolv/res_debug.c -index 73af0c72fe..6bf9962916 100644 ---- a/resolv/res_debug.c -+++ b/resolv/res_debug.c -@@ -390,8 +390,6 @@ p_fqname(const u_char *cp, const u_char *msg, FILE *file) { - * that C_ANY is a qclass but not a class. (You can ask for records of class - * C_ANY, but you can't have any records of that class in the database.) - */ --extern const struct res_sym __p_class_syms[]; --libresolv_hidden_proto (__p_class_syms) - const struct res_sym __p_class_syms[] = { - {C_IN, (char *) "IN"}, - {C_CHAOS, (char *) "CHAOS"}, -@@ -426,8 +424,6 @@ const struct res_sym __p_update_section_syms[] attribute_hidden = { - * Names of RR types and qtypes. The list is incomplete because its - * size is part of the ABI. - */ --extern const struct res_sym __p_type_syms[]; --libresolv_hidden_proto (__p_type_syms) - const struct res_sym __p_type_syms[] = { - {ns_t_a, (char *) "A", (char *) "address"}, - {ns_t_ns, (char *) "NS", (char *) "name server"}, - -commit 3c27e5170c456a69807348de8586c123f62a51f6 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Fix ns_sprintrrf formatting of class, type values (bug 34289) - - The p_class and p_type results could overwrite each other if both - were unknown. Format unknown values with CLASS and TYPE prefixes, - as in RFC 3597. Handle A6 separately because it cannot be added - to __p_type_syms for ABI reasons. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit f69b7f95e3694177546faec25d88bb266885c3b8) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index cef2212fd2..e75c39eaa8 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -78,6 +78,24 @@ ns_sprintrr(const ns_msg *handle, const ns_rr *rr, - } - libresolv_hidden_def (ns_sprintrr) - -+/* Writes the class/type symbol NUMBER to *BUF, using the name from -+ *SYMS if possible. If NUMBER is not found in *SYMS, print the -+ number with PREFIX. */ -+static int -+addsym (const struct res_sym *syms, int number, const char *prefix, -+ char **buf, size_t *buflen) -+{ -+ for (; syms->name != NULL; syms++) -+ if (number == syms->number) -+ { -+ T (addstr (" ", 1, buf, buflen)); -+ return addstr (syms->name, strlen (syms->name), buf, buflen); -+ } -+ char tmp[20]; -+ int len = snprintf (tmp, sizeof (tmp), " %s%d", prefix, number); -+ return addstr (tmp, len, buf, buflen); -+} -+ - /*% - * Convert the fields of an RR into presentation format. - * -@@ -128,11 +146,21 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - /* - * TTL, Class, Type. - */ -- T(x = ns_format_ttl(ttl, buf, buflen)); -- addlen(x, &buf, &buflen); -- len = SPRINTF((tmp, " %s %s", p_class(class), p_type(type))); -- T(addstr(tmp, len, &buf, &buflen)); -- T(spaced = addtab(x + len, 16, spaced, &buf, &buflen)); -+ { -+ char *start = buf; -+ -+ T (x = ns_format_ttl (ttl, buf, buflen)); -+ addlen (x, &buf, &buflen); -+ T (addsym (__p_class_syms, class, "CLASS", &buf, &buflen)); -+ if (type == ns_t_a6) -+ /* A6 is not part of __p_type_syms, which is exported. -+ Adding A6 there would change its size. Handle it here. */ -+ T (addstr (" A6", 3, &buf, &buflen)); -+ else -+ T (addsym (__p_type_syms, type, "TYPE", &buf, &buflen)); -+ -+ T (spaced = addtab(buf - start, 16, spaced, &buf, &buflen)); -+ } - - /* - * RData. - -commit 509d819cea20f5d6c615eed1f869cc930effd9d2 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Improve formatting of unknown records in ns_sprintrrf - - Do not add the "unknown RR type" comment. After adding the TYPE - prefix, the number is largely redundant. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit d58415eb17d457a160af99f9e8ab164404ca151b) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index e75c39eaa8..3d38876483 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -115,7 +115,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - - const char *comment; - char tmp[100]; -- char errbuf[40]; - int len, x; - - /* -@@ -590,20 +589,18 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - T(addstr(tmp, len, &buf, &buflen)); - break; - } -- - default: -- snprintf (errbuf, sizeof (errbuf), "unknown RR type %d", type); -- comment = errbuf; -+ comment = ""; - goto hexify; - } - return (buf - obuf); - formerr: -- comment = "RR format error"; -+ comment = " ; RR format error"; - hexify: { - int n, m; - char *p; - -- len = SPRINTF((tmp, "\\# %u%s\t; %s", (unsigned)(edata - rdata), -+ len = SPRINTF((tmp, "\\# %u%s%s", (unsigned)(edata - rdata), - rdlen != 0U ? " (" : "", comment)); - T(addstr(tmp, len, &buf, &buflen)); - while (rdata < edata) { - -commit 05dc6da0b4e12dbc60d3705e4961b823d3f7026d -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Check for inet_ntop failure in ns_sprintrrf - - This makes the output more consistent (either failure or complete - output) and helps with systematic testing with varying buffer - sizes. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit cd0db208d56a2cecd528b8ae96df752ba5344d9a) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index 3d38876483..e58df5f35a 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -167,8 +167,9 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - switch (type) { - case ns_t_a: - if (rdlen != (size_t)NS_INADDRSZ) -- goto formerr; -- (void) inet_ntop(AF_INET, rdata, buf, buflen); -+ goto formerr; -+ if (inet_ntop (AF_INET, rdata, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - break; - -@@ -334,9 +335,10 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - } - - case ns_t_aaaa: -- if (rdlen != (size_t)NS_IN6ADDRSZ) -- goto formerr; -- (void) inet_ntop(AF_INET6, rdata, buf, buflen); -+ if (rdlen != (size_t)NS_IN6ADDRSZ) -+ goto formerr; -+ if (inet_ntop (AF_INET6, rdata, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - break; - -@@ -427,7 +429,8 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - goto formerr; - - /* Address. */ -- (void) inet_ntop(AF_INET, rdata, buf, buflen); -+ if (inet_ntop (AF_INET, rdata, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - rdata += NS_INADDRSZ; - -@@ -569,7 +572,8 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - if (rdata + pbyte >= edata) goto formerr; - memset(&a, 0, sizeof(a)); - memcpy(&a.s6_addr[pbyte], rdata, sizeof(a) - pbyte); -- (void) inet_ntop(AF_INET6, &a, buf, buflen); -+ if (inet_ntop (AF_INET6, &a, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - rdata += sizeof(a) - pbyte; - } - -commit 299e1d25c32c5f9ef78ddd6cbfd0c6a09a1f4227 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435) - - Specifically, CERT, TKEY, TSIG, OPT. This removes the buggy - implementations of TSIG, fixing bug 34033, and partially - fixing bug 34069. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit ca44a6609c29a683b03575fa035c6d17aa591e72) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index e58df5f35a..ab68bf2cb7 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -464,96 +464,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - break; - } - -- case ns_t_cert: { -- u_int c_type, key_tag, alg; -- int n; -- unsigned int siz; -- char base64_cert[8192], tmp[40]; -- const char *leader; -- -- c_type = ns_get16(rdata); rdata += NS_INT16SZ; -- key_tag = ns_get16(rdata); rdata += NS_INT16SZ; -- alg = (u_int) *rdata++; -- -- len = SPRINTF((tmp, "%d %d %d ", c_type, key_tag, alg)); -- T(addstr(tmp, len, &buf, &buflen)); -- siz = (edata-rdata)*4/3 + 4; /* "+4" accounts for trailing \0 */ -- if (siz > sizeof(base64_cert) * 3/4) { -- const char *str = "record too long to print"; -- T(addstr(str, strlen(str), &buf, &buflen)); -- } -- else { -- len = b64_ntop(rdata, edata-rdata, base64_cert, siz); -- -- if (len < 0) -- goto formerr; -- else if (len > 15) { -- T(addstr(" (", 2, &buf, &buflen)); -- leader = "\n\t\t"; -- spaced = 0; -- } -- else -- leader = " "; -- -- for (n = 0; n < len; n += 48) { -- T(addstr(leader, strlen(leader), -- &buf, &buflen)); -- T(addstr(base64_cert + n, MIN(len - n, 48), -- &buf, &buflen)); -- } -- if (len > 15) -- T(addstr(" )", 2, &buf, &buflen)); -- } -- break; -- } -- -- case ns_t_tkey: { -- /* KJD - need to complete this */ -- u_long t; -- int mode, err, keysize; -- -- /* Algorithm name. */ -- T(addname(msg, msglen, &rdata, origin, &buf, &buflen)); -- T(addstr(" ", 1, &buf, &buflen)); -- -- /* Inception. */ -- t = ns_get32(rdata); rdata += NS_INT32SZ; -- len = SPRINTF((tmp, "%lu ", t)); -- T(addstr(tmp, len, &buf, &buflen)); -- -- /* Expiration. */ -- t = ns_get32(rdata); rdata += NS_INT32SZ; -- len = SPRINTF((tmp, "%lu ", t)); -- T(addstr(tmp, len, &buf, &buflen)); -- -- /* Mode , Error, Key Size. */ -- /* Priority, Weight, Port. */ -- mode = ns_get16(rdata); rdata += NS_INT16SZ; -- err = ns_get16(rdata); rdata += NS_INT16SZ; -- keysize = ns_get16(rdata); rdata += NS_INT16SZ; -- len = SPRINTF((tmp, "%u %u %u ", mode, err, keysize)); -- T(addstr(tmp, len, &buf, &buflen)); -- -- /* XXX need to dump key, print otherdata length & other data */ -- break; -- } -- -- case ns_t_tsig: { -- /* BEW - need to complete this */ -- int n; -- -- T(len = addname(msg, msglen, &rdata, origin, &buf, &buflen)); -- T(addstr(" ", 1, &buf, &buflen)); -- rdata += 8; /*%< time */ -- n = ns_get16(rdata); rdata += INT16SZ; -- rdata += n; /*%< sig */ -- n = ns_get16(rdata); rdata += INT16SZ; /*%< original id */ -- sprintf(buf, "%d", ns_get16(rdata)); -- rdata += INT16SZ; -- addlen(strlen(buf), &buf, &buflen); -- break; -- } -- - case ns_t_a6: { - struct in6_addr a; - int pbyte, pbit; -@@ -588,11 +498,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - break; - } - -- case ns_t_opt: { -- len = SPRINTF((tmp, "%u bytes", class)); -- T(addstr(tmp, len, &buf, &buflen)); -- break; -- } - default: - comment = ""; - goto hexify; - -commit cb4c62448047c043981deea84e5e01eccf8b36d4 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Fix buffer overreads in ns_sprintrrf (CVE-2026-6238) - - Check that the RDATA payload does not require more than RDATALEN - bytes while processing it. The fixes cover A6, LOC records. - (CERT, TKEY, TSIG were fixed before, by switching to the generic - formatter.) - - The vulnerable LOC record handling was first introduced before - glibc 2.0, in commit ee188d555b8c32ad9704a7440cab400af967292f. - - CERT, TSIG, TKEY handling came with commit - b43b13ac2544b11f35be301d1589b51a8473e32b, released with glibc 2.2. - - A6 record handling was introduced in commit - 91633816430e7ec5a19fe3ff510a7c4822a9557e ("* resolv/ns_print.c - (ns_sprintrrf): Handle ns_t_a6 and ns_t_opt."), which went into glibc - 2.7. - - This fixes bug 34069. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit a7b60d23bbb56eaef59f4962e4140062e552600a) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index ab68bf2cb7..f9dd086804 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -345,7 +345,8 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - case ns_t_loc: { - char t[255]; - -- /* XXX protocol format checking? */ -+ if (rdlen != 16) -+ goto formerr; - (void) loc_ntoa(rdata, t); - T(addstr(t, strlen(t), &buf, &buflen)); - break; -@@ -479,13 +480,14 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - - /* address suffix: provided only when prefix len != 128 */ - if (pbit < 128) { -- if (rdata + pbyte >= edata) goto formerr; -+ unsigned int bytelen = sizeof(a) - pbyte; -+ if (edata - rdata < bytelen) goto formerr; - memset(&a, 0, sizeof(a)); -- memcpy(&a.s6_addr[pbyte], rdata, sizeof(a) - pbyte); -+ memcpy(&a.s6_addr[pbyte], rdata, bytelen); - if (inet_ntop (AF_INET6, &a, buf, buflen) == NULL) - return -1; - addlen(strlen(buf), &buf, &buflen); -- rdata += sizeof(a) - pbyte; -+ rdata += bytelen; - } - - /* prefix name: provided only when prefix len > 0 */ - -commit 296fb7f4a2b35db13efef52609f8efc00291b2a8 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Add test case tst-ns_sprintrr (bug 34033, bug 34069) - - This test case covers both input buffer overreads and output buffer - overflows. It should systematically cover these issues. - - I used code auto-generation for updating the test expectations for - truncated RDATA in TXT, ISDN records, after writing the rest - of the test by hand. - - Assisted-by: LLM - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 4ba0b79b9596e5a4951cc9eaa1546a55e543e083) - -diff --git a/resolv/Makefile b/resolv/Makefile -index 088a22ea18..c6d73b411c 100644 ---- a/resolv/Makefile -+++ b/resolv/Makefile -@@ -98,6 +98,7 @@ tests += \ - tst-ns_name \ - tst-ns_name_compress \ - tst-ns_name_pton \ -+ tst-ns_sprintrr \ - tst-res_hconf_reorder \ - tst-res_hnok \ - tst-resolv-aliases \ -@@ -331,5 +332,6 @@ $(objpfx)tst-ns_name: $(objpfx)libresolv.so - $(objpfx)tst-ns_name.out: tst-ns_name.data - $(objpfx)tst-ns_name_compress: $(objpfx)libresolv.so - $(objpfx)tst-ns_name_pton: $(objpfx)libresolv.so -+$(objpfx)tst-ns_sprintrr: $(objpfx)libresolv.so - $(objpfx)tst-res_hnok: $(objpfx)libresolv.so - $(objpfx)tst-p_secstodate: $(objpfx)libresolv.so -diff --git a/resolv/tst-ns_sprintrr.c b/resolv/tst-ns_sprintrr.c -new file mode 100644 -index 0000000000..34739b5924 ---- /dev/null -+++ b/resolv/tst-ns_sprintrr.c -@@ -0,0 +1,329 @@ -+/* Tests for the ns_sprintrr function. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+#include -+ -+/* Regions that test_one_record uses for input and output. */ -+static struct support_next_to_fault ntf_in; -+static struct support_next_to_fault ntf_out; -+ -+/* This is used by test_one_record to construct the packet. */ -+static const char packet_prefix[] = -+ /* DNS response with one question, one answer record. */ -+ "AA\x81\x80\0\1\0\1\0\0\0\0" -+ /* Question: www.example.org/IN/ANY. */ -+ "\3www\7example\3org\0\0\xff\0\1" -+ /* Response: compression reference. */ -+ "\xc0\x0c"; -+ -+/* Use ns_sprintrr to format a DNS record (starting with -+ packet_prefix) of type RTYPE, with a record payload of RDATALEN -+ bytes starting at RDATA. Check successful formatting against -+ EXPECTED. Try various truncated input and output buffers to catch -+ overreads and buffer overflows, using ntf_in and ntf_out above. */ -+static void -+test_one_record (uint16_t rtype, const char *rdata, size_t rdatalen, -+ const char *expected) -+{ -+ struct rr_header -+ { -+ uint16_t typ; -+ uint16_t cls; -+ uint32_t ttl; -+ uint16_t rdatalen; -+ uint16_t pad; -+ } hdr = -+ { -+ .typ = htons (rtype), -+ .cls = htons (ns_c_in), -+ .ttl = htonl (86400), /* One day. */ -+ .rdatalen = htons (rdatalen), -+ }; -+ enum { hdrlen = offsetof (struct rr_header, pad) }; -+ TEST_COMPARE (hdrlen, 10); -+ -+ /* Construct the packet from packet_prefix, hdr, and rdata. */ -+ unsigned char packet[512]; -+ size_t packetlen; -+ { -+ struct alloc_buffer buf = alloc_buffer_create (packet, sizeof (packet)); -+ alloc_buffer_copy_bytes (&buf, packet_prefix, sizeof (packet_prefix) - 1); -+ alloc_buffer_copy_bytes (&buf, &hdr, hdrlen); -+ alloc_buffer_copy_bytes (&buf, rdata, rdatalen); -+ packetlen = sizeof (packet) - alloc_buffer_size (&buf); -+ } -+ -+ /* Parse the record. */ -+ ns_msg msg; -+ TEST_COMPARE (ns_initparse (packet, packetlen, &msg), 0); -+ ns_rr rr; -+ TEST_COMPARE (ns_parserr (&msg, ns_s_an, 0, &rr), 0); -+ -+ /* Try sizes up to this limit. Go a bit beyond the expected size to -+ check for errors. */ -+ size_t max_result_size = strlen (expected) + 16; -+ -+ bool success = false; -+ for (size_t result_size = 1; result_size <= max_result_size; ++result_size) -+ { -+ char *result_start = ntf_out.buffer + ntf_out.length - result_size; -+ memset (result_start, 'X', result_size); -+ -+ /* ns_sprintrr was deprecated in 2.34. */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wdeprecated-declarations"); -+ int ret = ns_sprintrr (&msg, &rr, NULL, NULL, result_start, result_size); -+ DIAG_POP_NEEDS_COMMENT; -+ -+ if (ret > 0) -+ { -+ TEST_COMPARE_STRING (result_start, expected); -+ TEST_COMPARE (ret, strlen (expected)); -+ success = true; -+ } -+ else -+ { -+ TEST_VERIFY (!success); -+ TEST_COMPARE (ret, -1); -+ } -+ } -+ TEST_VERIFY (success); -+ -+ /* Test with truncated RDATA. */ -+ for (size_t rdata_size = 0; rdata_size <= rdatalen; ++rdata_size) -+ { -+ size_t truncated_packet_size = packetlen - rdatalen + rdata_size; -+ unsigned char *packet_start -+ = ((unsigned char *) ntf_in.buffer + ntf_in.length -+ - truncated_packet_size); -+ memcpy (packet_start, packet, truncated_packet_size); -+ /* Patch in the updated RDATA length field. */ -+ uint16_t new_rdatalen = htons (rdata_size); -+ memcpy (packet_start + truncated_packet_size - rdata_size - 2, -+ &new_rdatalen, 2); -+ -+ ns_msg msg; -+ TEST_COMPARE (ns_initparse (packet_start, truncated_packet_size, &msg), -+ 0); -+ ns_rr rr; -+ TEST_COMPARE (ns_parserr (&msg, ns_s_an, 0, &rr), 0); -+ -+ size_t result_size = strlen (expected) + 1; -+ char *result_start = ntf_out.buffer + ntf_out.length - result_size; -+ memset (result_start, 'X', result_size); -+ -+ /* ns_sprintrr was deprecated in 2.34. */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wdeprecated-declarations"); -+ int ret = ns_sprintrr (&msg, &rr, NULL, NULL, result_start, result_size); -+ DIAG_POP_NEEDS_COMMENT; -+ -+ /* This flag indicates whether the output is syntactically -+ correct. In some cases, truncation may still yield a valid -+ payload. */ -+ bool broken = rdata_size < rdatalen; -+ switch (rtype) -+ { -+ case ns_t_wks: -+ /* WKS records use all trailing bytes for the port bitmap. */ -+ broken = rdata_size < 5; -+ break; -+ case ns_t_nsap: -+ /* Uses all bytes that are available. */ -+ broken = false; -+ break; -+ case ns_t_txt: -+ /* Truncation produces a valid payload if it occurs right -+ after a complete string in the TXT payload. */ -+ broken = false; -+ for (size_t pos = 0; pos < rdata_size; ) -+ { -+ unsigned int slen = rdata[pos] & 0xff; -+ if (pos + 1 + slen > rdata_size) -+ { -+ broken = true; -+ break; -+ } -+ pos += 1 + slen; -+ } -+ break; -+ case ns_t_isdn: -+ /* The second field is optional. If it is present, it must -+ not be truncated. */ -+ broken = rdata_size < 6 || (rdata_size > 6 && rdata_size < rdatalen); -+ break; -+ case ns_t_a6: -+ /* The first A6 subtest contains a trailing domain name, -+ which is ignored and not formatted. */ -+ if (rdata_size > 0 && rdata[0] == 0) -+ broken = rdata_size < 17; -+ break; -+ case ns_t_cert: -+ case ns_t_tkey: -+ case ns_t_tsig: -+ /* Only generic printing, which does not validate anything. */ -+ broken = false; -+ break; -+ } -+ -+ if (broken) -+ { -+ if (strstr (result_start, "RR format error") != NULL) -+ /* No further checks if an error indicator has been added -+ to the output. */ -+ ; -+ else -+ TEST_COMPARE (ret, -1); -+ } -+ else -+ TEST_VERIFY (ret > 0); -+ } -+} -+ -+static int -+do_test (void) -+{ -+ ntf_in = support_next_to_fault_allocate (512); -+ ntf_out = support_next_to_fault_allocate (256); -+ -+#define T(rtype, rdata, expected) \ -+ test_one_record (rtype, rdata, sizeof (rdata) - 1, expected) -+ T (ns_t_a, "\xc0\0\2\1", "www.example.org.\t1D IN A\t\t192.0.2.1"); -+ T (ns_t_cname, "\4www1\4prod\xc0\x10", -+ "www.example.org.\t1D IN CNAME\twww1.prod.example.org."); -+ T (ns_t_hinfo, "\5first\6second", -+ "www.example.org.\t1D IN HINFO\t\"first\" \"second\""); -+ T (ns_t_isdn, "\5first\6second", -+ "www.example.org.\t1D IN ISDN\t\"first\" \"second\""); -+ /* Bug: Extra space at the end in the text representation of ISDN RRs. */ -+ T (ns_t_isdn, "\5first", "www.example.org.\t1D IN ISDN\t\"first\" "); -+ T (ns_t_soa, -+ "\2ns\xc0\x10\12hostmaster\xc0\x10" -+ "\0\0\0\1\0\0\0\2\0\0\0\3\0\0\0\4\0\0\0\5", -+ "www.example.org.\t1D IN SOA\tns.example.org. hostmaster.example.org. (\n" -+ "\t\t\t\t\t1\t\t; serial\n" -+ "\t\t\t\t\t2S\t\t; refresh\n" -+ "\t\t\t\t\t3S\t\t; retry\n" -+ "\t\t\t\t\t4S\t\t; expiry\n" -+ "\t\t\t\t\t5S )\t\t; minimum\n"); -+ T (ns_t_mx, "\0\xa\2mx\xc0\x10", -+ "www.example.org.\t1D IN MX\t10 mx.example.org."); -+ T (ns_t_px, "\0\xa\3px1\xc0\x10\3px2\xc0\x10", -+ "www.example.org.\t1D IN PX\t10 px1.example.org. px2.example.org."); -+ T (ns_t_x25, "\4X.25", -+ "www.example.org.\t1D IN X25\t\"X.25\""); -+ T (ns_t_txt, "\1A\2BC\3DEF", -+ "www.example.org.\t1D IN TXT\t\"A\" \"BC\" \"DEF\""); -+ T (ns_t_nsap, "", -+ "www.example.org.\t1D IN NSAP\t"); -+ T (ns_t_nsap, "\1", -+ "www.example.org.\t1D IN NSAP\t01"); -+ T (ns_t_nsap, "\1\2", -+ "www.example.org.\t1D IN NSAP\t01.02"); -+ T (ns_t_nsap, "\1\2\3", -+ "www.example.org.\t1D IN NSAP\t01.0203"); -+ T (ns_t_nsap, "\1\2\3\4", -+ "www.example.org.\t1D IN NSAP\t01.0203.04"); -+ T (ns_t_nsap, -+ "\1\2\3\4\5\6\7\10\11\12\13\14\15\16\17\20\21\22\23\24\25\26\27\30\31\32" -+ "\33\34\35\36\37\40\41\42\43\44\45\46\47\50\51\52\53\54\55\56\57\60\61" -+ "\62\63\64\65\66\67\70\71\72\73\74\75\76\77\100\101\102\103\104\105\106" -+ "\107\110\111\112\113\114\115\116\117\120\121\122\123\124\125\126\127" -+ "\130\131\132\133\134\135\136\137\140\141\142\143\144\145\146\147\150" -+ "\151\152\153\154\155\156\157\160\161\162\163\164\165\166\167\170\171" -+ "\172\173\174\175\176\177\200\201\202\203\204\205\206\207\210\211\212" -+ "\213\214\215\216\217\220\221\222\223\224\225\226\227\230\231\232\233" -+ "\234\235\236\237\240\241\242\243\244\245\246\247\250\251\252\253\254" -+ "\255\256\257\260\261\262\263\264\265\266\267\270\271\272\273\274\275" -+ "\276\277\300\301\302\303\304\305\306\307\310\311\312\313\314\315\316" -+ "\317\320\321\322\323\324\325\326\327\330\331\332\333\334\335\336\337" -+ "\340\341\342\343\344\345\346\347\350\351\352\353\354\355\356\357\360" -+ "\361\362\363\364\365\366\367\370\371\372\373\374\375\376\377", -+ "www.example.org.\t1D IN NSAP\t" -+ "01.0203.0405.0607.0809.0A0B.0C0D.0E0F.1011.1213.1415.1617.1819.1A1B" -+ ".1C1D.1E1F.2021.2223.2425.2627.2829.2A2B.2C2D.2E2F.3031.3233.3435.3637" -+ ".3839.3A3B.3C3D.3E3F.4041.4243.4445.4647.4849.4A4B.4C4D.4E4F.5051.5253" -+ ".5455.5657.5859.5A5B.5C5D.5E5F.6061.6263.6465.6667.6869.6A6B.6C6D.6E6F" -+ ".7071.7273.7475.7677.7879.7A7B.7C7D.7E7F.8081.8283.8485.8687.8889.8A8B" -+ ".8C8D.8E8F.9091.9293.9495.9697.9899.9A9B.9C9D.9E9F.A0A1.A2A3.A4A5.A6A7" -+ ".A8A9.AAAB.ACAD.AEAF.B0B1.B2B3.B4B5.B6B7.B8B9.BABB.BCBD.BEBF.C0C1.C2C3" -+ ".C4C5.C6C7.C8C9.CACB.CCCD.CECF.D0D1.D2D3.D4D5.D6D7.D8D9.DADB.DCDD.DEDF" -+ ".E0E1.E2E3.E4E5.E6E7.E8E9.EAEB.ECED.EEEF.F0F1.F2F3.F4F5.F6F7.F8F9.FAFB" -+ ".FCFD.FEFF"); -+ T (ns_t_aaaa, "\x20\x01\x0d\xb8\0\0\0\0\0\0\0\0\0\0\x12\x34", -+ "www.example.org.\t1D IN AAAA\t2001:db8::1234"); -+ /* Example from RFC 1876. The loc_ntoa format is different from the -+ official text representation. */ -+ T (ns_t_loc, -+ "\000\063\026\023\211\027\055\320\160\276\025\360\000\230\215\040", -+ "www.example.org.\t1D IN LOC" -+ "\t42 21 54.000 N 71 06 18.000 W -24.00m 30.00m 10000.00m 10.00m"); -+ T (ns_t_naptr, -+ "\0\1\0\2\5flags\7service\2.*\5naptr\xc0\x10", -+ "www.example.org.\t1D IN NAPTR\t1 2 \"flags\" \"service\" \".*\"" -+ " naptr.example.org."); -+ T (ns_t_srv, -+ "\0\1\0\2\0\x50\4www1\xc0\x10", -+ "www.example.org.\t1D IN SRV\t1 2 80 www1.example.org."); -+ T (ns_t_rp, "\3rp1\xc0\x10\3rp2\xc0\x10", -+ "www.example.org.\t1D IN RP\trp1.example.org. rp2.example.org."); -+ T (ns_t_wks, "\xc0\0\2\1\6\0\0\0\0\0\0\0\0\0\0\200", -+ "www.example.org.\t1D IN WKS\t192.0.2.1 6 ( \n\t\t\t\t80 )"); -+ T (ns_t_cert, "\0\1\x04\xd2\0blob", -+ "www.example.org.\t1D IN CERT\t\\# 9 (\n" -+ "\t00 01 04 d2 00 62 6c 6f 62 )\t\t\t; .....blob"); -+ T (ns_t_tkey, "\4algo\0\0\0\0\1\0\0\0\2\0\3\0\4" -+ "\0\5\xa1\xa2\xa3\xa4\xa5\0\3\xb1\xb2\xb3", -+ "www.example.org.\t1D IN TYPE249\t\\# 30 (\n" -+ "\t04 61 6c 67 6f 00 00 00 00 01 00 00 00 02 00 03 ; .algo...........\n" -+ "\t00 04 00 05 a1 a2 a3 a4 a5 00 03 b1 b2 b3 )\t; .............."); -+ T (ns_t_tsig, "\4algo\0" -+ "\0\20\xdd\xcd\x64\x10\xe9\x21\x34\x1a\x8e\xe0\xa1\x9a\x30\xfc\x3b\xd1" -+ "\0\2\0\3\0\5other", -+ "www.example.org.\t1D IN TSIG\t\\# 35 (\n" -+ "\t04 61 6c 67 6f 00 00 10 dd cd 64 10 e9 21 34 1a ; .algo.....d..!4.\n" -+ "\t8e e0 a1 9a 30 fc 3b d1 00 02 00 03 00 05 6f 74 ; ....0.;.......ot\n" -+ "\t68 65 72 )\t\t\t\t\t; her"); -+ T (ns_t_a6, -+ "\0\x20\x01\x0d\xb8\0\0\0\0\0\0\0\0\0\0\x12\x34\6prefix\xc0\x10", -+ "www.example.org.\t1D IN A6\t0 2001:db8::1234"); -+ T (ns_t_a6, -+ "\0\x20\x01\x0d\xb8\0\0\0\0\0\0\0\0\0\0\x12\x35", -+ "www.example.org.\t1D IN A6\t0 2001:db8::1235"); -+ T (ns_t_a6, "\200\6prefix\xc0\x10", -+ "www.example.org.\t1D IN A6\t128 prefix.example.org."); -+ T (ns_t_a6, "\x20\0\0\0\0\0\0\0\0\0\0\x12\x36\6prefix\xc0\x10", -+ "www.example.org.\t1D IN A6\t32 ::1236 prefix.example.org."); -+#undef T -+ -+ support_next_to_fault_free (&ntf_in); -+ support_next_to_fault_free (&ntf_out); -+ return 0; -+} -+ -+#include - -commit 7414631f8aec8b9cee1a8311506e1fdcd9b94c0d -Author: Adhemerval Zanella -Date: Tue Apr 14 10:50:37 2026 -0300 - - posix: Fix stack overflow in wordexp tilde expansion (BZ 34091, CVE-2026-6791) - - The parse_tilde function previously used strndupa to allocate memory - for the parsed username on the stack, and since the input is - user-defined, this can lead to a stack overflow. - - This patch fixes the issue by replacing strndupa with scratch_buffer, - by reusing the buffer used in the __getpwnam_r call. - - The new “tst-wordexp-tilde.c” test is a test-container to avoid using - system-defined NSS modules. - - Checked on x86_64-linux-gnu and i686-linux-gnu. - - (cherry picked from commit 07c24f35392b727e6100d33edfdf811a6c68c218) - -diff --git a/posix/Makefile b/posix/Makefile -index 0b29c9aa4e..595c6b3ec2 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -356,6 +356,7 @@ tests-internal := \ - tests-container := \ - bug-ga2 \ - tst-vfork3 \ -+ tst-wordexp-tilde \ - # tests-container - - tests-time64 := \ -diff --git a/posix/tst-wordexp-tilde.c b/posix/tst-wordexp-tilde.c -new file mode 100644 -index 0000000000..1661603681 ---- /dev/null -+++ b/posix/tst-wordexp-tilde.c -@@ -0,0 +1,244 @@ -+/* Test wordexp tilde expansion with large usernames (BZ 34091). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+typedef void (*func_callback_t)(void); -+ -+static void -+subprocess_small_stack (void *closure) -+{ -+ struct rlimit rl; -+ TEST_COMPARE (getrlimit (RLIMIT_STACK, &rl), 0); -+ rl.rlim_cur = 512 * 1024; -+ TEST_COMPARE (setrlimit (RLIMIT_STACK, &rl), 0); -+ -+ func_callback_t func_test = closure; -+ func_test (); -+} -+ -+/* Build a string "~/tail" where is LEN bytes of the -+ character CH. The caller must free the result. */ -+static char * -+make_tilde_input (char ch, size_t len, const char *tail) -+{ -+ /* ~ + len + / + tail + \0 */ -+ size_t taillen = tail != NULL ? strlen (tail) : 0; -+ size_t total = 1 + len + 1 + taillen + 1; -+ char *buf = xmalloc (total); -+ buf[0] = '~'; -+ memset (buf + 1, ch, len); -+ buf[1 + len] = '/'; -+ if (tail != NULL) -+ memcpy (buf + 1 + len + 1, tail, taillen); -+ buf[total - 1] = '\0'; -+ return buf; -+} -+ -+/* Test 1: A very long username must not crash. The username will not match -+ any real user, so wordexp returns ~/rest. */ -+static void -+test_long_username (void) -+{ -+ printf ("info: test_long_username_no_crash\n"); -+ -+ static const char REST[] = "rest"; -+ -+ /* 1 MiB username — well beyond any reasonable stack frame. */ -+ const size_t long_len = 1024 * 1024; -+ char *input = make_tilde_input ('A', long_len, REST); -+ -+ wordexp_t we = { 0 }; -+ int ret = wordexp (input, &we, 0); -+ /* The (non-existent) username is invalid, so wordexp falls back to -+ literal output: ~AAA…/rest. */ -+ TEST_COMPARE (ret, 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ -+ /* Verify prefix: '~' followed by long_len 'A's. */ -+ const char *result = we.we_wordv[0]; -+ TEST_COMPARE (result[0], '~'); -+ TEST_COMPARE (strlen (result), -+ 1 /* ~ */ + long_len + sizeof (REST)); -+ for (size_t j = 1; j <= long_len; j++) -+ if (result[j] != 'A') -+ { -+ printf (" mismatch at position %zu: expected 'A', got '%c'\n", -+ j, result[j]); -+ support_record_failure (); -+ break; -+ } -+ /* Verify the tail after the username. */ -+ TEST_COMPARE_STRING (result + 1 + long_len, "/rest"); -+ -+ wordfree (&we); -+ free (input); -+} -+ -+/* Test 2: A username that just exceeds the default scratch_buffer inline -+ size (1024 bytes) exercises the scratch_buffer_set_array_size growth path -+ without being excessively large. */ -+static void -+test_scratch_buffer_growth (void) -+{ -+ printf ("info: test_scratch_buffer_growth\n"); -+ -+ const size_t len = 2048; -+ char *input = make_tilde_input ('x', len, NULL); -+ -+ wordexp_t we = { 0 }; -+ int ret = wordexp (input, &we, 0); -+ TEST_COMPARE (ret, 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ -+ /* ~xxx…/ — the trailing slash makes a separate empty component, but -+ wordexp merges it into the single token ~xxx…/. */ -+ const char *result = we.we_wordv[0]; -+ TEST_COMPARE (result[0], '~'); -+ for (size_t j = 1; j <= len; j++) -+ if (result[j] != 'x') -+ { -+ printf (" mismatch at position %zu\n", j); -+ support_record_failure (); -+ break; -+ } -+ TEST_COMPARE (result[1 + len], '/'); -+ -+ wordfree (&we); -+ free (input); -+} -+ -+/* Test 3: ~root still resolves to the correct home directory through the -+ __getpwnam_r path. */ -+static void -+test_known_user (void) -+{ -+ printf ("info: test_known_user\n"); -+ -+ /* Look up root's home directory for comparison. */ -+ struct passwd *pw = getpwnam ("root"); -+ if (pw == NULL || pw->pw_dir == NULL) -+ { -+ printf (" SKIP: cannot look up root\n"); -+ return; -+ } -+ -+ char *expected = xasprintf ("%s/file", pw->pw_dir); -+ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("~root/file", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ TEST_COMPARE_STRING (we.we_wordv[0], expected); -+ -+ wordfree (&we); -+ free (expected); -+} -+ -+/* Test 4: Bare tilde expands to $HOME. */ -+static void -+test_bare_tilde (void) -+{ -+ printf ("info: test_bare_tilde\n"); -+ -+ const char *home = getenv ("HOME"); -+ if (home == NULL) -+ { -+ printf (" SKIP: HOME is not set\n"); -+ return; -+ } -+ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("~", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ TEST_COMPARE_STRING (we.we_wordv[0], home); -+ -+ wordfree (&we); -+} -+ -+/* Test 5: Short non-existent username falls back to literal ~username output, -+ exercising the invalid-login-name path. */ -+static void -+test_unknown_user (void) -+{ -+ printf ("info: test_unknown_user\n"); -+ -+ /* Pick a username that is extremely unlikely to exist. */ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("~no_such_user_xyzzy42", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ TEST_COMPARE_STRING (we.we_wordv[0], "~no_such_user_xyzzy42"); -+ -+ wordfree (&we); -+} -+ -+/* Test 6: Tilde with username and WRDE_APPEND — exercises parse_tilde's -+ interaction with the WRDE_APPEND word list. */ -+static void -+test_tilde_with_append (void) -+{ -+ printf ("info: test_tilde_with_append\n"); -+ -+ const char *home = getenv ("HOME"); -+ if (home == NULL) -+ { -+ printf (" SKIP: HOME is not set\n"); -+ return; -+ } -+ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("first", &we, 0), 0); -+ -+ TEST_COMPARE (wordexp ("~/path", &we, WRDE_APPEND), 0); -+ TEST_COMPARE (we.we_wordc, 2); -+ TEST_COMPARE_STRING (we.we_wordv[0], "first"); -+ -+ char *expected = xasprintf ("%s/path", home); -+ TEST_COMPARE_STRING (we.we_wordv[1], expected); -+ -+ wordfree (&we); -+ free (expected); -+} -+ -+static int -+do_test (void) -+{ -+ test_known_user (); -+ test_bare_tilde (); -+ test_unknown_user (); -+ test_tilde_with_append (); -+ -+ support_isolate_in_subprocess (subprocess_small_stack, -+ test_long_username); -+ -+ support_isolate_in_subprocess (subprocess_small_stack, -+ test_scratch_buffer_growth); -+ -+ return 0; -+} -+ -+#include -diff --git a/posix/tst-wordexp-tilde.root/etc/group b/posix/tst-wordexp-tilde.root/etc/group -new file mode 100644 -index 0000000000..1dbf9013ee ---- /dev/null -+++ b/posix/tst-wordexp-tilde.root/etc/group -@@ -0,0 +1 @@ -+root:x:0: -diff --git a/posix/tst-wordexp-tilde.root/etc/nsswitch.conf b/posix/tst-wordexp-tilde.root/etc/nsswitch.conf -new file mode 100644 -index 0000000000..098a8d5938 ---- /dev/null -+++ b/posix/tst-wordexp-tilde.root/etc/nsswitch.conf -@@ -0,0 +1,3 @@ -+passwd: files -+group: files -+shadow: files -diff --git a/posix/tst-wordexp-tilde.root/etc/passwd b/posix/tst-wordexp-tilde.root/etc/passwd -new file mode 100644 -index 0000000000..eb85a552ad ---- /dev/null -+++ b/posix/tst-wordexp-tilde.root/etc/passwd -@@ -0,0 +1 @@ -+root:x:0:0:root:/root:/bin/sh -diff --git a/posix/wordexp.c b/posix/wordexp.c -index 9df4bb7424..731d1650e9 100644 ---- a/posix/wordexp.c -+++ b/posix/wordexp.c -@@ -335,17 +335,29 @@ parse_tilde (char **word, size_t *word_length, size_t *max_length, - else - { - /* Look up user name in database to get home directory */ -- char *user = strndupa (&words[1 + *offset], i - (1 + *offset)); -- struct passwd pwd, *tpwd; -- int result; -+ size_t userlen = i - (1 + *offset); -+ /* tmpbuf contains both the user and the __getpwnam_r working area. */ - struct scratch_buffer tmpbuf; - scratch_buffer_init (&tmpbuf); -+ if (!scratch_buffer_set_array_size (&tmpbuf, userlen + 1, 1)) -+ return WRDE_NOSPACE; -+ char *user = tmpbuf.data; -+ memcpy (user, &words[1 + *offset], userlen); -+ user[userlen] = '\0'; - -- while ((result = __getpwnam_r (user, &pwd, tmpbuf.data, tmpbuf.length, -+ struct passwd pwd, *tpwd; -+ int result; -+ while ((result = __getpwnam_r (user, -+ &pwd, -+ tmpbuf.data + userlen + 1, -+ tmpbuf.length - userlen - 1, - &tpwd)) != 0 - && errno == ERANGE) -- if (!scratch_buffer_grow (&tmpbuf)) -- return WRDE_NOSPACE; -+ { -+ if (!scratch_buffer_grow_preserve (&tmpbuf)) -+ return WRDE_NOSPACE; -+ user = tmpbuf.data; -+ } - - if (result == 0 && tpwd != NULL && pwd.pw_dir) - *word = w_addstr (*word, word_length, max_length, pwd.pw_dir); - -commit 8be3551ccb4e17e93ad82152de56d2c90de21f97 -Author: Adhemerval Zanella -Date: Mon Apr 13 16:33:30 2026 -0300 - - posix: Fix wordexp WRDE_APPEND to preserve state on non-NOSPACE errors (BZ 34090, CVE-2026-6368) - - The previous implementation saved a copy of the wordexp_t struct at - entry and blindly restored it on error via (*pwordexp = old_word). - This is incorrect when WRDE_APPEND is set because w_addword may have - called realloc on we_wordv during partial processing before the error - was detected. If realloc relocated the buffer, the saved we_wordv - pointer is dangling; restoring it causes a use-after-free in the - caller (e.g. via wordfree), and the relocated buffer is leaked. - - Fix this by duplicating the we_wordv pointer array at entry when - WRDE_APPEND is set, so that all subsequent realloc calls inside - w_addword operate on the copy. - - This change also fixes a POSIX conformance issue: if the WRDE_APPEND - flag is specified, pwordexp->we_wordc and pwordexp->we_wordv shall - not be modified. - - Also fix two pre-existing error return paths in the '"' and '\'' cases - that returned directly from w_addword failures instead of going through - do_error, which would leak the saved array (and previously would also - skip the word cleanup). - - Checked on x86_64-linux-gnu and i686-linux-gnu. - - Reviewed-by: DJ Delorie - (cherry picked from commit e2cefe16c37a617df9f11407cb00a272a6098823) - -diff --git a/posix/Makefile b/posix/Makefile -index 595c6b3ec2..a12c49c0ed 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -326,6 +326,7 @@ tests := \ - tst-wait3 \ - tst-wait4 \ - tst-waitid \ -+ tst-wordexp-append \ - tst-wordexp-nocmd \ - tst-wordexp-reuse \ - tstgetopt \ -diff --git a/posix/tst-wordexp-append.c b/posix/tst-wordexp-append.c -new file mode 100644 -index 0000000000..87f388f0a7 ---- /dev/null -+++ b/posix/tst-wordexp-append.c -@@ -0,0 +1,393 @@ -+/* Test for wordexp with WRDE_APPEND flag. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+ -+static unsigned int relocating_reallocs; -+ -+/* w_addword grows we_wordv with realloc, make every call guaranteed to -+ relocate the block. This makes BZ 34090 regression more deterministic. */ -+void * -+realloc (void *ptr, size_t size) -+{ -+ if (ptr == NULL) -+ return malloc (size); -+ if (size == 0) -+ { -+ free (ptr); -+ return NULL; -+ } -+ -+ void *new = malloc (size); -+ if (new == NULL) -+ return NULL; -+ -+ /* Copy only what is valid in the old block to avoid reading past it. */ -+ size_t old = malloc_usable_size (ptr); -+ memcpy (new, ptr, old < size ? old : size); -+ /* Clobber the old block so that a stale we_wordv pointer restored on the -+ error path reads garbage instead of the old contents, which might -+ otherwise survive intact and mask the bug. */ -+ memset (ptr, 0x5a, old); -+ free (ptr); -+ relocating_reallocs++; -+ return new; -+} -+ -+/* Verify that all words in we match the expected NULL-terminated -+ array. */ -+static void -+check_words (const wordexp_t *we, const char *const *expected) -+{ -+ size_t i; -+ for (i = 0; expected[i] != NULL; i++) -+ { -+ TEST_VERIFY (i < we->we_wordc); -+ TEST_COMPARE_STRING (we->we_wordv[we->we_offs + i], expected[i]); -+ } -+ TEST_COMPARE (we->we_wordc, i); -+} -+ -+#define CHECK_WORDS(we, ...) \ -+ do { \ -+ const char *const expected_[] = { __VA_ARGS__, NULL }; \ -+ check_words (we, expected_); \ -+ } while (0) -+ -+/* Test 1: WRDE_APPEND + WRDE_BADCHAR preserves we_wordc. */ -+static void -+test_append_badchar_preserves_count (void) -+{ -+ printf ("info: test_append_badchar_preserves_count\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("one two three", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 3); -+ -+ size_t saved_count = we.we_wordc; -+ -+ /* ')' triggers WRDE_BADCHAR and "extra" would be a new word if the -+ expansion succeeded, exercising the w_addword path before the error -+ is detected. */ -+ TEST_COMPARE (wordexp ("extra )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ -+ wordfree (&we); -+} -+ -+/* Test 2: WRDE_APPEND + WRDE_BADCHAR preserves the we_wordv pointer even -+ when internal realloc would move the buffer. */ -+static void -+test_append_badchar_preserves_pointer (void) -+{ -+ printf ("info: test_append_badchar_preserves_pointer\n"); -+ wordexp_t we = { 0 }; -+ -+ /* Use many words so that the initial we_wordv allocation is -+ non-trivial and a later realloc is more likely to move it. */ -+ TEST_COMPARE (wordexp ("a b c d e f g h", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 8); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ unsigned int saved_reallocs = relocating_reallocs; -+ -+ /* The interposed realloc guarantees the internal we_wordv buffer moves -+ during parsing, so the pointer-stability check below is meaningful. */ -+ TEST_COMPARE (wordexp ("append )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ /* Verify that a relocating realloc actually happened during the failed -+ call, otherwise the pointer-stability check is vacuous. */ -+ TEST_VERIFY (relocating_reallocs > saved_reallocs); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ -+ wordfree (&we); -+} -+ -+/* Test 3: After a failed WRDE_APPEND the original words are still accessible -+ and correct. */ -+static void -+test_append_badchar_words_intact (void) -+{ -+ printf ("info: test_append_badchar_words_intact\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("alpha beta gamma", &we, 0), 0); -+ CHECK_WORDS (&we, "alpha", "beta", "gamma"); -+ -+ TEST_COMPARE (wordexp ("delta )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ -+ /* Words must still be intact. */ -+ CHECK_WORDS (&we, "alpha", "beta", "gamma"); -+ /* The NULL terminator must still be present. */ -+ TEST_VERIFY (we.we_wordv[we.we_offs + we.we_wordc] == NULL); -+ -+ wordfree (&we); -+} -+ -+/* Test 4: Successful WRDE_APPEND still works (regression test). */ -+static void -+test_append_success (void) -+{ -+ printf ("info: test_append_success\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("hello", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ -+ char **saved_wordv = we.we_wordv; -+ -+ TEST_COMPARE (wordexp ("world", &we, WRDE_APPEND), 0); -+ TEST_COMPARE (we.we_wordc, 2); -+ /* A successful append works on a fresh copy of the array, so the -+ caller-visible pointer must have changed. */ -+ TEST_VERIFY (we.we_wordv != saved_wordv); -+ CHECK_WORDS (&we, "hello", "world"); -+ -+ wordfree (&we); -+} -+ -+/* Test 5: Successful append after a failed append — the implementation must -+ recover and allow further use of the wordexp_t. */ -+static void -+test_append_success_after_failure (void) -+{ -+ printf ("info: test_append_success_after_failure\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("first", &we, 0), 0); -+ CHECK_WORDS (&we, "first"); -+ -+ TEST_COMPARE (wordexp ("bad |", &we, WRDE_APPEND), WRDE_BADCHAR); -+ -+ /* State must be exactly as before the failed call. */ -+ CHECK_WORDS (&we, "first"); -+ -+ /* A subsequent successful append must work. */ -+ TEST_COMPARE (wordexp ("second third", &we, WRDE_APPEND), 0); -+ CHECK_WORDS (&we, "first", "second", "third"); -+ -+ wordfree (&we); -+} -+ -+/* Test 6: Multiple consecutive failed appends do not corrupt state. */ -+static void -+test_append_multiple_failures (void) -+{ -+ printf ("info: test_append_multiple_failures\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("keep this", &we, 0), 0); -+ CHECK_WORDS (&we, "keep", "this"); -+ -+ size_t saved_count = we.we_wordc; -+ char **saved_wordv = we.we_wordv; -+ -+ /* Each of these bad characters must leave the state unchanged. */ -+ TEST_COMPARE (wordexp ("x )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x |", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x ;", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x &", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x <", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x >", &we, WRDE_APPEND), WRDE_BADCHAR); -+ -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ CHECK_WORDS (&we, "keep", "this"); -+ -+ wordfree (&we); -+} -+ -+/* Test 7: WRDE_APPEND with WRDE_SYNTAX error (unterminated quote) also -+ preserves state. */ -+static void -+test_append_syntax_error (void) -+{ -+ printf ("info: test_append_syntax_error\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("original", &we, 0), 0); -+ CHECK_WORDS (&we, "original"); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ -+ /* Unterminated double quote triggers WRDE_SYNTAX. */ -+ TEST_COMPARE (wordexp ("\"unterminated", &we, WRDE_APPEND), WRDE_SYNTAX); -+ -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ CHECK_WORDS (&we, "original"); -+ -+ wordfree (&we); -+} -+ -+/* Test 8: Error without WRDE_APPEND still works (regression test for the -+ non-APPEND code path in do_error). */ -+static void -+test_no_append_error (void) -+{ -+ printf ("info: test_no_append_error\n"); -+ wordexp_t we = { 0 }; -+ -+ /* Simple failure without WRDE_APPEND. */ -+ TEST_COMPARE (wordexp ("bad |", &we, 0), WRDE_BADCHAR); -+ -+ /* After failure without WRDE_APPEND the struct should be safe to -+ reuse — start fresh. */ -+ TEST_COMPARE (wordexp ("ok", &we, 0), 0); -+ CHECK_WORDS (&we, "ok"); -+ -+ wordfree (&we); -+} -+ -+/* Test 9: WRDE_BADCHAR on the very first character (no partial words added -+ before the error). */ -+static void -+test_append_badchar_immediate (void) -+{ -+ printf ("info: test_append_badchar_immediate\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("hello world", &we, 0), 0); -+ CHECK_WORDS (&we, "hello", "world"); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ -+ /* The bad character is the very first byte — no w_addword call happens -+ before the error. */ -+ TEST_COMPARE (wordexp ("|", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ -+ wordfree (&we); -+} -+ -+/* Test 10: WRDE_APPEND into an empty wordexp_t (initial call uses WRDE_APPEND -+ with a zeroed struct — unusual but allowed). */ -+static void -+test_append_into_empty (void) -+{ -+ printf ("info: test_append_into_empty\n"); -+ wordexp_t we = { 0 }; -+ -+ /* First call with WRDE_APPEND on a zeroed struct. The implementation -+ must handle we_wordv == NULL gracefully. */ -+ TEST_COMPARE (wordexp ("solo", &we, WRDE_APPEND), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ CHECK_WORDS (&we, "solo"); -+ -+ wordfree (&we); -+} -+ -+/* Verify that the leading we_offs slots are all NULL. */ -+static void -+check_offs_null (const wordexp_t *we) -+{ -+ for (size_t i = 0; i < we->we_offs; i++) -+ TEST_VERIFY (we->we_wordv[i] == NULL); -+} -+ -+/* Test 11: successful WRDE_APPEND with WRDE_DOOFFS and a non-zero we_offs. -+ The leading offset slots must stay NULL and words must land at -+ we_wordv[we_offs + i] across both the initial and the appended call. */ -+static void -+test_dooffs_append_success (void) -+{ -+ printf ("info: test_dooffs_append_success\n"); -+ wordexp_t we = { 0 }; -+ we.we_offs = 2; -+ -+ TEST_COMPARE (wordexp ("one two", &we, WRDE_DOOFFS), 0); -+ TEST_COMPARE (we.we_offs, 2); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "one", "two"); -+ -+ TEST_COMPARE (wordexp ("three", &we, WRDE_APPEND | WRDE_DOOFFS), 0); -+ TEST_COMPARE (we.we_offs, 2); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "one", "two", "three"); -+ /* The NULL terminator must sit right after the last word. */ -+ TEST_VERIFY (we.we_wordv[we.we_offs + we.we_wordc] == NULL); -+ -+ wordfree (&we); -+} -+ -+/* Test 12: failed WRDE_APPEND with WRDE_DOOFFS preserves we_wordc, the -+ we_wordv pointer, the words and the leading NULL offset slots. This -+ exercises the we_offs arithmetic in the array duplication and in the -+ error-path cleanup (we_wordv[we_offs + --we_wordc]). */ -+static void -+test_dooffs_append_error_preserves_state (void) -+{ -+ printf ("info: test_dooffs_append_error_preserves_state\n"); -+ wordexp_t we = { 0 }; -+ we.we_offs = 3; -+ -+ TEST_COMPARE (wordexp ("alpha beta", &we, WRDE_DOOFFS), 0); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "alpha", "beta"); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ unsigned int saved_reallocs = relocating_reallocs; -+ -+ /* "gamma" is a partial word added via w_addword (forcing a relocating -+ realloc of we_wordv) before ')' triggers WRDE_BADCHAR. */ -+ TEST_COMPARE (wordexp ("gamma )", &we, WRDE_APPEND | WRDE_DOOFFS), -+ WRDE_BADCHAR); -+ TEST_VERIFY (relocating_reallocs > saved_reallocs); -+ -+ TEST_COMPARE (we.we_offs, 3); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "alpha", "beta"); -+ TEST_VERIFY (we.we_wordv[we.we_offs + we.we_wordc] == NULL); -+ -+ wordfree (&we); -+} -+ -+static int -+do_test (void) -+{ -+ test_append_badchar_preserves_count (); -+ test_append_badchar_preserves_pointer (); -+ test_append_badchar_words_intact (); -+ test_append_success (); -+ test_append_success_after_failure (); -+ test_append_multiple_failures (); -+ test_append_syntax_error (); -+ test_no_append_error (); -+ test_append_badchar_immediate (); -+ test_append_into_empty (); -+ test_dooffs_append_success (); -+ test_dooffs_append_error_preserves_state (); -+ -+ return 0; -+} -+ -+#include -diff --git a/posix/wordexp.c b/posix/wordexp.c -index 731d1650e9..50b0d7a256 100644 ---- a/posix/wordexp.c -+++ b/posix/wordexp.c -@@ -35,6 +35,7 @@ - #include - #include <_itoa.h> - #include -+#include - - /* - * This is a recursive-descent-style word expansion routine. -@@ -2224,6 +2225,12 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - char ifs_white[4]; - wordexp_t old_word = *pwordexp; - -+ /* When WRDE_APPEND is set we work on a copy of the we_wordv array so that -+ the caller's original pointer is never invalidated by realloc inside -+ w_addword. The saved_wordv keeps the original; on success we free it, -+ on non-NOSPACE error we free the working copy and restore the original. */ -+ char **saved_wordv = NULL; -+ - if (flags & WRDE_REUSE) - { - /* Minimal implementation of WRDE_REUSE for now */ -@@ -2258,6 +2265,23 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - pwordexp->we_offs = 0; - } - } -+ else if (pwordexp->we_wordv != NULL) -+ { -+ /* WRDE_APPEND with an existing word list: duplicate the array so that -+ realloc during parsing does not invalidate the caller's pointer. The -+ strings themselves are shared. */ -+ size_t num_p; -+ char **dup; -+ if (INT_ADD_WRAPV (pwordexp->we_offs, pwordexp->we_wordc, &num_p) -+ || INT_ADD_WRAPV (num_p, 1, &num_p)) -+ return WRDE_NOSPACE; -+ dup = __libc_reallocarray (NULL, num_p, sizeof *dup); -+ if (dup == NULL) -+ return WRDE_NOSPACE; -+ memcpy (dup, pwordexp->we_wordv, num_p * sizeof *dup); -+ saved_wordv = pwordexp->we_wordv; -+ pwordexp->we_wordv = dup; -+ } - - /* Find out what the field separators are. - * There are two types: whitespace and non-whitespace. -@@ -2338,7 +2362,7 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - error = w_addword (pwordexp, NULL); - - if (error) -- return error; -+ goto do_error; - } - - break; -@@ -2356,7 +2380,7 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - error = w_addword (pwordexp, NULL); - - if (error) -- return error; -+ goto do_error; - } - - break; -@@ -2422,10 +2446,18 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - - /* There was a word separator at the end */ - if (word == NULL) /* i.e. w_newword */ -- return 0; -+ { -+ free (saved_wordv); -+ return 0; -+ } - -- /* There was no field separator at the end */ -- return w_addword (pwordexp, word); -+ /* There was no field separator at the end. The only possible error -+ from w_addword is WRDE_NOSPACE. */ -+ error = w_addword (pwordexp, word); -+ if (error != 0) -+ goto do_error; -+ free (saved_wordv); -+ return 0; - - do_error: - /* Error: -@@ -2436,11 +2468,30 @@ do_error: - free (word); - - if (error == WRDE_NOSPACE) -- return WRDE_NOSPACE; -+ { -+ /* we_wordc and we_wordv are updated to reflect any words that were -+ successfully expanded. The old array is obsolete. */ -+ free (saved_wordv); -+ return WRDE_NOSPACE; -+ } - -- if ((flags & WRDE_APPEND) == 0) -- wordfree (pwordexp); -+ if (flags & WRDE_APPEND) -+ { -+ /* POSIX 2024 states that for in other error cases, if the WRDE_APPEND -+ flag was specified, we_wordc and we_wordv shall not be modified. -+ -+ Free strings appended during this call, discard the working copy of -+ we_wordv, and restore the caller's original pointer. */ -+ while (pwordexp->we_wordc > old_word.we_wordc) -+ free (pwordexp->we_wordv[pwordexp->we_offs + --pwordexp->we_wordc]); -+ free (pwordexp->we_wordv); -+ pwordexp->we_wordv = saved_wordv; -+ } -+ else -+ { -+ wordfree (pwordexp); -+ *pwordexp = old_word; -+ } - -- *pwordexp = old_word; - return error; - } diff --git a/pkgs/development/libraries/glibc/2.44-master.patch b/pkgs/development/libraries/glibc/2.44-master.patch new file mode 100644 index 000000000000..08c0e1da3143 --- /dev/null +++ b/pkgs/development/libraries/glibc/2.44-master.patch @@ -0,0 +1,4138 @@ +commit 5e5ddf57987ae4b37da5ca2fa039c8803b0be735 +Author: Andreas K. Hüttel +Date: Sat Jul 25 09:20:26 2026 +0900 + + advisories: replace with ADVISORIES text file + + Signed-off-by: Andreas K. Hüttel + +diff --git a/advisories/GLIBC-SA-2023-0001 b/advisories/GLIBC-SA-2023-0001 +deleted file mode 100644 +index 3d19c91b6a..0000000000 +--- a/advisories/GLIBC-SA-2023-0001 ++++ /dev/null +@@ -1,14 +0,0 @@ +-printf: incorrect output for integers with thousands separator and width field +- +-When the printf family of functions is called with a format specifier +-that uses an (enable grouping) and a minimum width +-specifier, the resulting output could be larger than reasonably expected +-by a caller that computed a tight bound on the buffer size. The +-resulting larger than expected output could result in a buffer overflow +-in the printf family of functions. +- +-CVE-Id: CVE-2023-25139 +-Public-Date: 2023-02-02 +-Vulnerable-Commit: e88b9f0e5cc50cab57a299dc7efe1a4eb385161d (2.37) +-Fix-Commit: c980549cc6a1c03c23cc2fe3e7b0fe626a0364b0 (2.38) +-Fix-Commit: 07b9521fc6369d000216b96562ff7c0ed32a16c4 (2.37-4) +diff --git a/advisories/GLIBC-SA-2023-0002 b/advisories/GLIBC-SA-2023-0002 +deleted file mode 100644 +index 5122669a64..0000000000 +--- a/advisories/GLIBC-SA-2023-0002 ++++ /dev/null +@@ -1,15 +0,0 @@ +-getaddrinfo: Stack read overflow in no-aaaa mode +- +-If the system is configured in no-aaaa mode via /etc/resolv.conf, +-getaddrinfo is called for the AF_UNSPEC address family, and a DNS +-response is received over TCP that is larger than 2048 bytes, +-getaddrinfo may potentially disclose stack contents via the returned +-address data, or crash. +- +-CVE-Id: CVE-2023-4527 +-Public-Date: 2023-09-12 +-Vulnerable-Commit: f282cdbe7f436c75864e5640a409a10485e9abb2 (2.36) +-Fix-Commit: bd77dd7e73e3530203be1c52c8a29d08270cb25d (2.39) +-Fix-Commit: 4ea972b7edd7e36610e8cde18bf7a8149d7bac4f (2.36-113) +-Fix-Commit: b7529346025a130fee483d42178b5c118da971bb (2.37-38) +-Fix-Commit: b25508dd774b617f99419bdc3cf2ace4560cd2d6 (2.38-19) +diff --git a/advisories/GLIBC-SA-2023-0003 b/advisories/GLIBC-SA-2023-0003 +deleted file mode 100644 +index d3aef80348..0000000000 +--- a/advisories/GLIBC-SA-2023-0003 ++++ /dev/null +@@ -1,15 +0,0 @@ +-getaddrinfo: Potential use-after-free +- +-When an NSS plugin only implements the _gethostbyname2_r and +-_getcanonname_r callbacks, getaddrinfo could use memory that was freed +-during buffer resizing, potentially causing a crash or read or write to +-arbitrary memory. +- +-CVE-Id: CVE-2023-4806 +-Public-Date: 2023-09-12 +-Fix-Commit: 973fe93a5675c42798b2161c6f29c01b0e243994 (2.39) +-Fix-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) +-Fix-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) +-Fix-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) +-Fix-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) +-Fix-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) +diff --git a/advisories/GLIBC-SA-2023-0004 b/advisories/GLIBC-SA-2023-0004 +deleted file mode 100644 +index 5286a7aa54..0000000000 +--- a/advisories/GLIBC-SA-2023-0004 ++++ /dev/null +@@ -1,16 +0,0 @@ +-tunables: local privilege escalation through buffer overflow +- +-If a tunable of the form NAME=NAME=VAL is passed in the environment of a +-setuid program and NAME is valid, it may result in a buffer overflow, +-which could be exploited to achieve escalated privileges. This flaw was +-introduced in glibc 2.34. +- +-CVE-Id: CVE-2023-4911 +-Public-Date: 2023-10-03 +-Vulnerable-Commit: 2ed18c5b534d9e92fc006202a5af0df6b72e7aca (2.34) +-Fix-Commit: 1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa (2.39) +-Fix-Commit: dcc367f148bc92e7f3778a125f7a416b093964d9 (2.34-423) +-Fix-Commit: c84018a05aec80f5ee6f682db0da1130b0196aef (2.35-274) +-Fix-Commit: 22955ad85186ee05834e47e665056148ca07699c (2.36-118) +-Fix-Commit: b4e23c75aea756b4bddc4abcf27a1c6dca8b6bd3 (2.37-45) +-Fix-Commit: 750a45a783906a19591fb8ff6b7841470f1f5701 (2.38-27) +diff --git a/advisories/GLIBC-SA-2023-0005 b/advisories/GLIBC-SA-2023-0005 +deleted file mode 100644 +index cc4eb90b82..0000000000 +--- a/advisories/GLIBC-SA-2023-0005 ++++ /dev/null +@@ -1,18 +0,0 @@ +-getaddrinfo: DoS due to memory leak +- +-The fix for CVE-2023-4806 introduced a memory leak when an application +-calls getaddrinfo for AF_INET6 with AI_CANONNAME, AI_ALL and AI_V4MAPPED +-flags set. +- +-CVE-Id: CVE-2023-5156 +-Public-Date: 2023-09-25 +-Vulnerable-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) +-Vulnerable-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) +-Vulnerable-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) +-Vulnerable-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) +-Vulnerable-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) +-Fix-Commit: 8006457ab7e1cd556b919f477348a96fe88f2e49 (2.34-421) +-Fix-Commit: 17092c0311f954e6f3c010f73ce3a78c24ac279a (2.35-272) +-Fix-Commit: 856bac55f98dc840e7c27cfa82262b933385de90 (2.36-116) +-Fix-Commit: 4473d1b87d04b25cdd0e0354814eeaa421328268 (2.37-42) +-Fix-Commit: 5ee59ca371b99984232d7584fe2b1a758b4421d3 (2.38-24) +diff --git a/advisories/GLIBC-SA-2024-0001 b/advisories/GLIBC-SA-2024-0001 +deleted file mode 100644 +index 28931c75ae..0000000000 +--- a/advisories/GLIBC-SA-2024-0001 ++++ /dev/null +@@ -1,15 +0,0 @@ +-syslog: Heap buffer overflow in __vsyslog_internal +- +-__vsyslog_internal did not handle a case where printing a SYSLOG_HEADER +-containing a long program name failed to update the required buffer +-size, leading to the allocation and overflow of a too-small buffer on +-the heap. +- +-CVE-Id: CVE-2023-6246 +-Public-Date: 2024-01-30 +-Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) +-Fix-Commit: 6bd0e4efcc78f3c0115e5ea9739a1642807450da (2.39) +-Fix-Commit: 23514c72b780f3da097ecf33a793b7ba9c2070d2 (2.38-42) +-Fix-Commit: 97a4292aa4a2642e251472b878d0ec4c46a0e59a (2.37-57) +-Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) +-Fix-Commit: d1a83b6767f68b3cb5b4b4ea2617254acd040c82 (2.36-126) +diff --git a/advisories/GLIBC-SA-2024-0002 b/advisories/GLIBC-SA-2024-0002 +deleted file mode 100644 +index 940bfcf2fc..0000000000 +--- a/advisories/GLIBC-SA-2024-0002 ++++ /dev/null +@@ -1,15 +0,0 @@ +-syslog: Heap buffer overflow in __vsyslog_internal +- +-__vsyslog_internal used the return value of snprintf/vsnprintf to +-calculate buffer sizes for memory allocation. If these functions (for +-any reason) failed and returned -1, the resulting buffer would be too +-small to hold output. +- +-CVE-Id: CVE-2023-6779 +-Public-Date: 2024-01-30 +-Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) +-Fix-Commit: 7e5a0c286da33159d47d0122007aac016f3e02cd (2.39) +-Fix-Commit: d0338312aace5bbfef85e03055e1212dd0e49578 (2.38-43) +-Fix-Commit: 67062eccd9a65d7fda9976a56aeaaf6c25a80214 (2.37-58) +-Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) +-Fix-Commit: 2bc9d7c002bdac38b5c2a3f11b78e309d7765b83 (2.36-127) +diff --git a/advisories/GLIBC-SA-2024-0003 b/advisories/GLIBC-SA-2024-0003 +deleted file mode 100644 +index b43a5150ab..0000000000 +--- a/advisories/GLIBC-SA-2024-0003 ++++ /dev/null +@@ -1,13 +0,0 @@ +-syslog: Integer overflow in __vsyslog_internal +- +-__vsyslog_internal calculated a buffer size by adding two integers, but +-did not first check if the addition would overflow. +- +-CVE-Id: CVE-2023-6780 +-Public-Date: 2024-01-30 +-Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) +-Fix-Commit: ddf542da94caf97ff43cc2875c88749880b7259b (2.39) +-Fix-Commit: d37c2b20a4787463d192b32041c3406c2bd91de0 (2.38-44) +-Fix-Commit: 2b58cba076e912961ceaa5fa58588e4b10f791c0 (2.37-59) +-Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) +-Fix-Commit: b9b7d6a27aa0632f334352fa400771115b3c69b7 (2.36-128) +diff --git a/advisories/GLIBC-SA-2024-0004 b/advisories/GLIBC-SA-2024-0004 +deleted file mode 100644 +index 08df2b3118..0000000000 +--- a/advisories/GLIBC-SA-2024-0004 ++++ /dev/null +@@ -1,28 +0,0 @@ +-ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence +- +-The iconv() function in the GNU C Library versions 2.39 and older may +-overflow the output buffer passed to it by up to 4 bytes when converting +-strings to the ISO-2022-CN-EXT character set, which may be used to +-crash an application or overwrite a neighbouring variable. +- +-ISO-2022-CN-EXT uses escape sequences to indicate character set changes +-(as specified by RFC 1922). While the SOdesignation has the expected +-bounds checks, neither SS2designation nor SS3designation have its; +-allowing a write overflow of 1, 2, or 3 bytes with fixed values: +-'$+I', '$+J', '$+K', '$+L', '$+M', or '$*H'. +- +-CVE-Id: CVE-2024-2961 +-Public-Date: 2024-04-17 +-Vulnerable-Commit: 755104edc75c53f4a0e7440334e944ad3c6b32fc (2.1.93-169) +-Fix-Commit: f9dc609e06b1136bb0408be9605ce7973a767ada (2.40) +-Fix-Commit: 31da30f23cddd36db29d5b6a1c7619361b271fb4 (2.39-31) +-Fix-Commit: e1135387deded5d73924f6ca20c72a35dc8e1bda (2.38-66) +-Fix-Commit: 89ce64b269a897a7780e4c73a7412016381c6ecf (2.37-89) +-Fix-Commit: 4ed98540a7fd19f458287e783ae59c41e64df7b5 (2.36-164) +-Fix-Commit: 36280d1ce5e245aabefb877fe4d3c6cff95dabfa (2.35-315) +-Fix-Commit: a8b0561db4b9847ebfbfec20075697d5492a363c (2.34-459) +-Fix-Commit: ed4f16ff6bed3037266f1fa682ebd32a18fce29c (2.33-263) +-Fix-Commit: 682ad4c8623e611a971839990ceef00346289cc9 (2.32-140) +-Fix-Commit: 3703c32a8d304c1ee12126134ce69be965f38000 (2.31-154) +- +-Reported-By: Charles Fol +diff --git a/advisories/GLIBC-SA-2024-0005 b/advisories/GLIBC-SA-2024-0005 +deleted file mode 100644 +index a59596610a..0000000000 +--- a/advisories/GLIBC-SA-2024-0005 ++++ /dev/null +@@ -1,22 +0,0 @@ +-nscd: Stack-based buffer overflow in netgroup cache +- +-If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted +-by client requests then a subsequent client request for netgroup data +-may result in a stack-based buffer overflow. This flaw was introduced +-in glibc 2.15 when the cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-CVE-Id: CVE-2024-33599 +-Public-Date: 2024-04-23 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: 69c58d5ef9f584ea198bd00f7964d364d0e6b921 (2.31-155) +-Fix-Commit: a77064893bfe8a701770e2f53a4d33805bc47a5a (2.32-141) +-Fix-Commit: 5c75001a96abcd50cbdb74df24c3f013188d076e (2.33-264) +-Fix-Commit: 52f73e5c4e29b14e79167272297977f360ae1e97 (2.34-460) +-Fix-Commit: 7a95873543ce225376faf13bb71c43dea6d24f86 (2.35-316) +-Fix-Commit: caa3151ca460bdd9330adeedd68c3112d97bffe4 (2.36-165) +-Fix-Commit: f75c298e747b2b8b41b1c2f551c011a52c41bfd1 (2.37-91) +-Fix-Commit: 5968aebb86164034b8f8421b4abab2f837a5bdaf (2.38-72) +-Fix-Commit: 1263d583d2e28afb8be53f8d6922f0842036f35d (2.39-35) +-Fix-Commit: 87801a8fd06db1d654eea3e4f7626ff476a9bdaa (2.40) +diff --git a/advisories/GLIBC-SA-2024-0006 b/advisories/GLIBC-SA-2024-0006 +deleted file mode 100644 +index d44148d3d9..0000000000 +--- a/advisories/GLIBC-SA-2024-0006 ++++ /dev/null +@@ -1,32 +0,0 @@ +-nscd: Null pointer crash after notfound response +- +-If the Name Service Cache Daemon's (nscd) cache fails to add a not-found +-netgroup response to the cache, the client request can result in a null +-pointer dereference. This flaw was introduced in glibc 2.15 when the +-cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-CVE-Id: CVE-2024-33600 +-Public-Date: 2024-04-24 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: b048a482f088e53144d26a61c390bed0210f49f2 (2.40) +-Fix-Commit: 7835b00dbce53c3c87bbbb1754a95fb5e58187aa (2.40) +-Fix-Commit: c99f886de54446cd4447db6b44be93dabbdc2f8b (2.39-37) +-Fix-Commit: 5a508e0b508c8ad53bd0d2fb48fd71b242626341 (2.39-36) +-Fix-Commit: 2ae9446c1b7a3064743b4a51c0bbae668ee43e4c (2.38-74) +-Fix-Commit: 541ea5172aa658c4bd5c6c6d6fd13903c3d5bb0a (2.38-73) +-Fix-Commit: a8070b31043c7585c36ba68a74298c4f7af075c3 (2.37-93) +-Fix-Commit: 5eea50c4402e39588de98aa1d4469a79774703d4 (2.37-92) +-Fix-Commit: f205b3af56740e3b014915b1bd3b162afe3407ef (2.36-167) +-Fix-Commit: c34f470a615b136170abd16142da5dd0c024f7d1 (2.36-166) +-Fix-Commit: bafadc589fbe21ae330e8c2af74db9da44a17660 (2.35-318) +-Fix-Commit: 4370bef52b0f3f3652c6aa13d7a9bb3ac079746d (2.35-317) +-Fix-Commit: 1f94122289a9bf7dba573f5d60327aaa2b85cf2e (2.34-462) +-Fix-Commit: 966d6ac9e40222b84bb21674cc4f83c8d72a5a26 (2.34-461) +-Fix-Commit: e3eef1b8fbdd3a7917af466ca9c4b7477251ca79 (2.33-266) +-Fix-Commit: f20a8d696b13c6261b52a6434899121f8b19d5a7 (2.33-265) +-Fix-Commit: be602180146de37582a3da3a0caa4b719645de9c (2.32-143) +-Fix-Commit: 394eae338199078b7961b051c191539870742d7b (2.32-142) +-Fix-Commit: 8d7949183760170c61e55def723c1d8050187874 (2.31-157) +-Fix-Commit: 304ce5fe466c4762b21b36c26926a4657b59b53e (2.31-156) +diff --git a/advisories/GLIBC-SA-2024-0007 b/advisories/GLIBC-SA-2024-0007 +deleted file mode 100644 +index b6928fa27a..0000000000 +--- a/advisories/GLIBC-SA-2024-0007 ++++ /dev/null +@@ -1,28 +0,0 @@ +-nscd: netgroup cache may terminate daemon on memory allocation failure +- +-The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or +-xrealloc and these functions may terminate the process due to a memory +-allocation failure resulting in a denial of service to the clients. The +-flaw was introduced in glibc 2.15 when the cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-Subsequent refactoring of the netgroup cache only added more uses of +-xmalloc and xrealloc. Uses of xmalloc and xrealloc in other parts of +-nscd only occur during startup of the daemon and so are not affected by +-client requests that could trigger an out of memory followed by +-termination. +- +-CVE-Id: CVE-2024-33601 +-Public-Date: 2024-04-24 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) +-Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) +-Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) +-Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) +-Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) +-Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) +-Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) +-Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) +-Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) +-Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) +diff --git a/advisories/GLIBC-SA-2024-0008 b/advisories/GLIBC-SA-2024-0008 +deleted file mode 100644 +index d93e2a6f0b..0000000000 +--- a/advisories/GLIBC-SA-2024-0008 ++++ /dev/null +@@ -1,26 +0,0 @@ +-nscd: netgroup cache assumes NSS callback uses in-buffer strings +- +-The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory +-when the NSS callback does not store all strings in the provided buffer. +-The flaw was introduced in glibc 2.15 when the cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-There is no guarantee from the NSS callback API that the returned +-strings are all within the buffer. However, the netgroup cache code +-assumes that the NSS callback uses in-buffer strings and if it doesn't +-the buffer resizing logic could lead to potential memory corruption. +- +-CVE-Id: CVE-2024-33602 +-Public-Date: 2024-04-24 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) +-Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) +-Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) +-Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) +-Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) +-Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) +-Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) +-Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) +-Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) +-Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) +diff --git a/advisories/GLIBC-SA-2025-0001 b/advisories/GLIBC-SA-2025-0001 +deleted file mode 100644 +index b053d32e91..0000000000 +--- a/advisories/GLIBC-SA-2025-0001 ++++ /dev/null +@@ -1,40 +0,0 @@ +-assert: Buffer overflow when printing assertion failure message +- +-When the assert() function fails, it does not allocate enough space for the +-assertion failure message string and size information, which may lead to a +-buffer overflow if the message string size aligns to page size. +- +-This bug can be triggered when an assertion in a program fails. The assertion +-failure message is allocated to allow developers to see this failure in core +-dumps and it typically includes, in addition to the invariant assertion +-string and function name, the name of the program. If the name of the failing +-program is user controlled, for example on a local system, this could allow an +-attacker to control the assertion failure to trigger this buffer overflow. +- +-The only viable vector for exploitation of this bug is local, if a setuid +-program exists that has an existing bug that results in an assertion failure. +-No such program has been discovered at the time of publishing this advisory, +-but the presence of custom setuid programs, although strongly discouraged as a +-security practice, cannot be discounted. +- +-CVE-Id: CVE-2025-0395 +-Public-Date: 2025-01-22 +-Vulnerable-Commit: f8a3b5bf8fa1d0c43d2458e03cc109a04fdef194 (2.13-175) +-Fix-Commit: 68ee0f704cb81e9ad0a78c644a83e1e9cd2ee578 (2.41) +-Fix-Commit: cdb9ba84191ce72e86346fb8b1d906e7cd930ea2 (2.42) +-Fix-Commit: 69fda28279b497bd405fdd442a6d8e4d3d5f681b (2.41-7) +-Fix-Commit: 7d4b6bcae91f29d7b4daf15bab06b66cf1d2217c (2.40-66) +-Fix-Commit: d6c156c326999f144cb5b73d29982108d549ad8a (2.40-71) +-Fix-Commit: 808a84a8b81468b517a4d721fdc62069cb8c211f (2.39-146) +-Fix-Commit: f6d48470aef9264d2d56f4c4533eb76db7f9c2e4 (2.39-150) +-Fix-Commit: c32fd59314c343db88c3ea4a203870481d33c3d2 (2.38-122) +-Fix-Commit: f984e2d7e8299726891a1a497a3c36cd5542a0bf (2.38-124) +-Fix-Commit: a3d7865b098a3a67c44f7812208d9ce4718873ba (2.37-143) +-Fix-Commit: b989519fe1683c204ac24ec92830e3fe3bfaccad (2.37-146) +-Fix-Commit: 7971add7ee4171fdd8dfd17e7c04c4ed77a18845 (2.36-216) +-Fix-Commit: 0487893d5c5bc6710d83d7c3152d888a0339559e (2.36-219) +-Fix-Commit: 8b5d4be762419c4f6176261c6fea40ac559b88dc (2.35-370) +-Fix-Commit: 8b3d09dc0d350191985f9d291cc30ce96f034b49 (2.35-373) +-Fix-Commit: df4e1f4a5096b385c9bcc94424cf2eaa227b3761 (2.34-500) +-Fix-Commit: 31eb872cb21449832ab47ad5db83281d240e1d03 (2.34-503) +-Reported-By: Qualys Security Advisory +diff --git a/advisories/GLIBC-SA-2025-0002 b/advisories/GLIBC-SA-2025-0002 +deleted file mode 100644 +index 161da13dd4..0000000000 +--- a/advisories/GLIBC-SA-2025-0002 ++++ /dev/null +@@ -1,23 +0,0 @@ +-elf: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH +- +-A statically linked setuid binary that calls dlopen (including internal +-dlopen calls after setlocale or calls to NSS functions such as getaddrinfo) +-may incorrectly search LD_LIBRARY_PATH to determine which library to load, +-leading to the execution of library code that is attacker controlled. +- +-The only viable vector for exploitation of this bug is local, if a static +-setuid program exists, and that program calls dlopen, then it may search +-LD_LIBRARY_PATH to locate the SONAME to load. No such program has been +-discovered at the time of publishing this advisory, but the presence of +-custom setuid programs, although strongly discouraged as a security +-practice, cannot be discounted. +- +-CVE-Id: CVE-2025-4802 +-Public-Date: 2025-05-16 +-Vulnerable-Commit: 10e93d968716ab82931d593bada121c17c0a4b93 (2.27) +-Fix-Commit: 5451fa962cd0a90a0e2ec1d8910a559ace02bba0 (2.39) +-Fix-Commit: 3be3728df2f1912c80abd3288bc6e3a25ad679e4 (2.38-132) +-Fix-Commit: 7403ede2d7752e59e0c47d5d33d73c2bf850e7be (2.37-154) +-Fix-Commit: 2ef7850279b2931caf6d6d6743ebaa91839e1cf7 (2.36-227) +-Fix-Commit: 621c65ccf12ddd415ceeb2234423bd1acd0fabb3 (2.35-387) +-Fix-Commit: 35018c0fd20eac9ceaf60060fed2745b3177359d (2.34-517) +diff --git a/advisories/GLIBC-SA-2025-0003 b/advisories/GLIBC-SA-2025-0003 +deleted file mode 100644 +index 2adeb3ce00..0000000000 +--- a/advisories/GLIBC-SA-2025-0003 ++++ /dev/null +@@ -1,30 +0,0 @@ +-power10: strcmp fails to save and restore nonvolatile vector registers +- +-The Power 10 implementation of strcmp in +-sysdeps/powerpc/powerpc64/le/power10/strcmp.S failed to save/restore +-nonvolatile vector registers in the 32-byte aligned loop path. This +-results in callers reading content from those registers in a different +-context, potentially altering program logic. +- +-There could be a program context where a user controlled string could +-leak through strcmp into program code, thus altering its logic. There +-is also a potential for sensitive strings passed into strcmp leaking +-through the clobbered registers into parts of the calling program that +-should otherwise not have had access to those strings. +- +-The impact of this flaw is limited to applications running on Power 10 +-hardware that use the nonvolatile vector registers, i.e. v20 to v31 +-assuming that they have been treated in accordance with the OpenPower +-psABI. It is possible to work around the issue for those specific +-applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like +-so: +- +- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 +- +-CVE-Id: CVE-2025-5702 +-Public-Date: 2025-06-04 +-Vulnerable-Commit: 3367d8e180848030d1646f088759f02b8dfe0d6f (2.39) +-Fix-Commit: 15808c77b35319e67ee0dc8f984a9a1a434701bc (2.42) +-Fix-Commit: 0c76c951620f9e12df2a89b2c684878b55bb6795 (2.41-60) +-Fix-Commit: 7e12550b8e3a11764a4a9090ce6bd3fc23fc8a8e (2.40-139) +-Fix-Commit: 06a70769fd0b2e1f2a3085ad50ab620282bd77b3 (2.39-209) +diff --git a/advisories/GLIBC-SA-2025-0004 b/advisories/GLIBC-SA-2025-0004 +deleted file mode 100644 +index 9409ca27c4..0000000000 +--- a/advisories/GLIBC-SA-2025-0004 ++++ /dev/null +@@ -1,29 +0,0 @@ +-power10: strncmp fails to save and restore nonvolatile vector registers +- +-The Power 10 implementation of strncmp in +-sysdeps/powerpc/powerpc64/le/power10/strncmp.S failed to save/restore +-nonvolatile vector registers in the 32-byte aligned loop path. This +-results in callers reading content from those registers in a different +-context, potentially altering program logic. +- +-There could be a program context where a user controlled string could +-leak through strncmp into program code, thus altering its logic. There +-is also a potential for sensitive strings passed into strncmp leaking +-through the clobbered registers into parts of the calling program that +-should otherwise not have had access to those strings. +- +-The impact of this flaw is limited to applications running on Power 10 +-hardware that use the nonvolatile vector registers, i.e. v20 to v31 +-assuming that they have been treated in accordance with the OpenPower +-psABI. It is possible to work around the issue for those specific +-applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like +-so: +- +- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 +- +-CVE-Id: CVE-2025-5745 +-Public-Date: 2025-06-05 +-Vulnerable-Commit: 23f0d81608d0ca6379894ef81670cf30af7fd081 (2.40) +-Fix-Commit: 63c60101ce7c5eac42be90f698ba02099b41b965 (2.42) +-Fix-Commit: 84bdbf8a6f2fdafd3661489dbb7f79835a52da82 (2.41-57) +-Fix-Commit: 42a5a940c974d02540c8da26d6374c744d148cb9 (2.40-136) +diff --git a/advisories/GLIBC-SA-2025-0005 b/advisories/GLIBC-SA-2025-0005 +deleted file mode 100644 +index 8bcccc59a5..0000000000 +--- a/advisories/GLIBC-SA-2025-0005 ++++ /dev/null +@@ -1,14 +0,0 @@ +-posix: Fix double-free after allocation failure in regcomp +- +-The regcomp function in the GNU C library version from 2.4 to 2.41 is +-subject to a double free if some previous allocation fails. It can be +-accomplished either by a malloc failure or by using an interposed +-malloc that injects random malloc failures. The double free can allow +-buffer manipulation depending of how the regex is constructed. +-This issue affects all architectures and ABIs supported by the GNU C +-library. +- +-CVE-Id: CVE-2025-8058 +-Public-Date: 2025-07-22 +-Vulnerable-Commit: 963d8d782fc98fb6dc3a66f0068795f9920c269d (2.3.3-1596) +-Fix-Commit: 7ea06e994093fa0bcca0d0ee2c1db271d8d7885d (2.42) +diff --git a/advisories/GLIBC-SA-2026-0001 b/advisories/GLIBC-SA-2026-0001 +deleted file mode 100644 +index 3e0ee3b3f4..0000000000 +--- a/advisories/GLIBC-SA-2026-0001 ++++ /dev/null +@@ -1,41 +0,0 @@ +-Integer overflow in memalign leads to heap corruption +- +-Passing too large an alignment to the memalign suite of functions +-(memalign, posix_memalign, aligned_alloc) in the GNU C Library version +-2.30 to 2.42 may result in an integer overflow, which could consequently +-result in a heap corruption. +- +-Note that the attacker must have control over both, the size as well as +-the alignment arguments of the memalign function to be able to exploit +-this. The size parameter must be close enough to PTRDIFF_MAX so as to +-overflow size_t along with the large alignment argument. This limits +-the malicious inputs for the alignment for memalign to the range [1<<62 +-+ 1, 1<<63] and exactly 1<<63 for posix_memalign and aligned_alloc. +- +-Typically the alignment argument passed to such functions is a known +-constrained quantity (e.g. page size, block size, struct sizes) and is +-not attacker controlled, because of which this may not be easily +-exploitable in practice. An application bug could potentially result in +-the input alignment being too large, e.g. due to a different buffer +-overflow or integer overflow in the application or its dependent +-libraries, but that is again an uncommon usage pattern given typical +-sources of alignments. +- +-CVE-Id: CVE-2026-0861 +-Public-Date: 2026-01-14 +-Vulnerable-Commit: 9bf8e29ca136094f73f69f725f15c51facc97206 (2.30) +-Fix-Commit: c9188d333717d3ceb7e3020011651f424f749f93 (2.43) +-Fix-Commit: 7f19ef14fbce095d4c77395e258320cad2ea2b28 (2.30-153) +-Fix-Commit: f18446d7b4a423090ee5e328c36b3c2a0f26041c (2.31-166) +-Fix-Commit: 8aef9e7a7af9565c0324b4ecb38b30dfa3782fd8 (2.32-151) +-Fix-Commit: 011293b4fd748cdd6f95874ba2b6aba9a3df8bff (2.33-275) +-Fix-Commit: 2c77e52108a58956c9f674b36e1f59a4e3fdcf4d (2.34-525) +-Fix-Commit: 499d1ccafccfe64df1b88deea2fa84d8180e8e8f (2.35-399) +-Fix-Commit: fb6b8822175769b5794fb6ea04f2895483a29b61 (2.36-244) +-Fix-Commit: 7b913d41a07836def826f2164c52541a9835f324 (2.37-172) +-Fix-Commit: 744b63026a29f7eedbbc8e3a01a7f48a6eb0a085 (2.38-212) +-Fix-Commit: fb22fd3f5b415dd4cd6f7b5741c2f0412374e242 (2.39-286) +-Fix-Commit: bfc4dd9e526eacf3017dd8864ba0848e9d045dd4 (2.40-216) +-Fix-Commit: 1e2c1ea4307197ccece0cda574bcfebf9080894c (2.41-121) +-Fix-Commit: b0ec8fb689df862171f0f78994a3bdeb51313545 (2.42-49) +-Reported-by: Igor Morgenstern, Aisle Research +diff --git a/advisories/GLIBC-SA-2026-0002 b/advisories/GLIBC-SA-2026-0002 +deleted file mode 100644 +index f10d8362f6..0000000000 +--- a/advisories/GLIBC-SA-2026-0002 ++++ /dev/null +@@ -1,36 +0,0 @@ +-getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler +- +-Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf +-that specifies the library's DNS backend for networks and queries for a +-zero-valued network in the GNU C Library version 2.0 to version 2.42 +-can leak stack contents to the configured DNS resolver. +- +-A defect in the _nss_dns_getnetbyaddr_r function which implements +-getnetbyaddr and getnetbyaddr_r in the dns-based network database can +-pass stack contents unmodified to the configured DNS resolver as part of +-the network DNS query when the network queried is the default network +-i.e. net == 0x0. This stack contents leaking in the query is considered +-a loss of confidentiality for the host making the query. Typically it +-is rare to call these APIs with a net value of zero, and if an attacker +-can control the net value it can only leak adjacent stack, and so loss +-of confidentiality is spatially limited. The leak might be used to +-accelerate an ASLR bypass by knowing pointer values, but also requires +-network adjacent access to snoop between the application and the +-DNS server; making the attack complexity higher. +- +-CVE-Id: CVE-2026-0915 +-Public-Date: 2026-01-15 +-Vulnerable-Commit: 5f0e6fc702296840d2daa39f83f6cb1e40073d58 (1.92-1) +-Fix-Commit: e56ff82d5034ec66c6a78f517af6faa427f65b0b (2.43) +-Fix-Commit: 453e6b8dbab935257eb0802b0c97bca6b67ba30e (2.42-50) +-Fix-Commit: 15c9839a0b853f552b4ed9047841b6223f3c104d (2.41-122) +-Fix-Commit: 329c775788b2c9ff3da774ccf59fba7b6b8ff08e (2.40-217) +-Fix-Commit: 831f63b94ceb92fb14c0d1a7ddad35a0d1404c71 (2.39-287) +-Fix-Commit: 49125ffc8e1674dc2a100dfdc5b78796f22e16f2 (2.38-213) +-Fix-Commit: ddcaed5dfb05b2c1a6ea842fd6b643501365450a (2.37-173) +-Fix-Commit: a6bf47887f24b2b394acb301a3189fda04bd4d4d (2.36-245) +-Fix-Commit: 66f0cb057c9b4fb1249a5fec6ef4a63511a37899 (2.35-400) +-Fix-Commit: 96863dee262225cfb79f9fe45e06fd188319c7b8 (2.34-526) +-Fix-Commit: d210011f1536c8322157cbb4fe4229b35c834c08 (2.33-276) +-Fix-Commit: 1bc1832cfc74c2a601220969f36e789a5e9f0ebe (2.32-152) +-Reported-by: Igor Morgenstern, Aisle Research +diff --git a/advisories/GLIBC-SA-2026-0003 b/advisories/GLIBC-SA-2026-0003 +deleted file mode 100644 +index b7a6e83a10..0000000000 +--- a/advisories/GLIBC-SA-2026-0003 ++++ /dev/null +@@ -1,36 +0,0 @@ +-wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory +- +-Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the +-GNU C Library version 2.0 to version 2.42 may cause the interface to +-return uninitialized memory in the we_wordv member, which on subsequent +-calls to wordfree may abort the process. +- +-The implementation of WRDE_REUSE in conjunction with WRDE_APPEND fails +-to clear the we_wordc member of the structure, and as such, when new +-words are added internally, a leading we_wordc count number of entries +-are skipped since they are assumed initialized. These skipped entries +-are not initialized, but are the contents of a realloc-expanded array of +-pointers. If the caller inspects the we_wordv array, it will +-dereference invalid pointers and crash. If the caller calls wordfree, +-the malloc implementation may detect the invalid pointers and abort the +-process. Calls to wordexp using WRDE_REUSE and WRDE_APPEND have never +-worked correctly and thus the existence of applications that make use of +-this feature is unlikely. +- +-CVE-Id: CVE-2025-15281 +-Public-Date: 2026-01-20 +-Vulnerable-Commit: 8f2ece695d8822e9ecc63ecd157e90bf17a6fe65 (1.93-260) +-Fix-Commit: 80cc58ea2de214f85b0a1d902a3b668ad2ecb302 (2.43) +-Fix-Commit: cbf39c26b25801e9bc88499b4fd361ac172d4125 (2.42-51) +-Fix-Commit: fb4db64a04ad6c96cd1fbb7e02eb59323b1f2ac2 (2.41-123) +-Fix-Commit: 9fe8576664d43b87ca19401fb6a975e217e47623 (2.40-218) +-Fix-Commit: ce65d944e38a20cb70af2a48a4b8aa5d8fabe1cc (2.39-288) +-Fix-Commit: d5409a1be010699794264162c551ba60f05ee6c3 (2.38-214) +-Fix-Commit: ff2b172803f6bbd897755d2ce83ec4323a1a15b3 (2.37-174) +-Fix-Commit: e97cfe2293ed097eb3d0b4c18274d22855e65130 (2.36-246) +-Fix-Commit: bb59339d02faebac534a87eea50c83c948f35b77 (2.35-401) +-Fix-Commit: 2b656ff94d72f93c84d8da2e7c76456c1994f02e (2.34-527) +-Fix-Commit: 1d8ed2067a8a5d162a07670d0d063429679f17a0 (2.33-277) +-Fix-Commit: 3a56c4ee4ea49b8f2391a2d8d6220013c4160a79 (2.32-153) +-Fix-Commit: 28eb5caf895ced5d895cb02757e109004a2d33e5 (2.31-167) +-Reported-by: Vitaly Simonovich +diff --git a/advisories/GLIBC-SA-2026-0004 b/advisories/GLIBC-SA-2026-0004 +deleted file mode 100644 +index fd630dc591..0000000000 +--- a/advisories/GLIBC-SA-2026-0004 ++++ /dev/null +@@ -1,30 +0,0 @@ +-nscd client crash on x86_64 under high nscd load +- +-Calling NSS-backed functions that support caching via nscd may call the +-nscd client side code and in the GNU C Library version 2.36 under high +-load on x86_64 systems, the client may call memcmp on inputs that are +-concurrently modified by other processes or threads and crash. +- +-The nscd client in the GNU C Library uses the memcmp function with +-inputs that may be concurrently modified by another thread, potentially +-resulting in spurious cache misses, which in itself is not a security +-issue. However in the GNU C Library version 2.36 an optimized +-implementation of memcmp was introduced for x86_64 which could crash +-when invoked with such undefined behaviour, turning this into a +-potential crash of the nscd client and the application that uses it. +-This implementation was backported to the 2.35 branch, making the nscd +-client in that branch vulnerable as well. Subsequently, the fix for +-this issue was backported to all vulnerable branches in the GNU C +-Library repository. +- +-It is advised that distributions that may have cherry-picked the memcpy +-SSE2 optimization in their copy of the GNU C Library, also apply the fix +-to avoid the potential crash in the nscd client. +- +-CVE-Id: CVE-2026-3904 +-Public-Date: 2026-03-11 +-Vulnerable-Commit: 8804157ad9da39631703b92315460808eac86b0c (2.36) +-Vulnerable-Commit: 5a8df6485c584e2b0e957ec6b9070437a724911a (2.35-89) +-Fix-Commit: b712be52645282c706a5faa038242504feb06db5 (2.37) +-Fix-Commit: 93967a2a7bbdcedb73e0b246713580c7c84d001e (2.36-84) +-Fix-Commit: 6bcd5d8e3668d52388a6e0580611749f93e6871f (2.35-230) +diff --git a/advisories/GLIBC-SA-2026-0005 b/advisories/GLIBC-SA-2026-0005 +deleted file mode 100644 +index 7a50a43263..0000000000 +--- a/advisories/GLIBC-SA-2026-0005 ++++ /dev/null +@@ -1,37 +0,0 @@ +-gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response +- +-Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf +-that specifies the library's DNS backend in the GNU C Library version +-2.34 to version 2.43 could, with a crafted response from the configured +-DNS server, result in a violation of the DNS specification that causes +-the application to treat a non-answer section of the DNS response as a +-valid answer. +- +-A defect in the getanswer_ptr function, which implements the iteration +-and extraction of the answer from the DNS response, can cause it to +-incorrectly transition from the answer section to the next section while +-still treating it as an answer to the question. This can happen when +-the answer contains only skipped records, and the subsequent section +-contains a semantically invalid T_PTR record. This is considered a +-security issue because it is a violation of the DNS specification that +-leads to incorrect behaviour that could result in the wrong hostname +-being returned to the caller. At the time of publication, no known +-affected DNS server returns results that would be incorrectly +-interpreted by the library. An attacker would either need to be network +-adjacent or have compromised the DNS server to use this defect to hide +-returned reverse DNS results from intrusion detection systems. Even +-then, the inbound connection from the attacker, or the outbound +-connection from the application, would be visible to the intrusion +-detection system. At best, the defect can be used to obfuscate and +-delay analysis of the evolving threat. +- +-CVE-Id: CVE-2026-4437 +-Public-Date: 2026-03-20 +-Vulnerable-Commit: 32e5db37684ffcbc6ae34fcc6cdcf28670506baa (2.34-323) +-Vulnerable-Commit: def97e7f71a07517810f7263213d607e08ad21f1 (2.35-188) +-Vulnerable-Commit: 77f523c473878ec0051582ef15161c6982879095 (2.36-30) +-Vulnerable-Commit: e32547d661a43da63368e488b6cfa9c53b4dcf92 (2.37) +-Fix-Commit: 5c6fca0c62ce5bd6e68e259f138097756cbafd4d (2.43-16) +-Fix-Commit: 9f5f18aab40ec6b61fa49a007615e6077e9a979b (2.44) +-Reported-by: Antonio Maini (0rbitingZer0) - 0rbitingZer0@proton.me +-Reported-by: Kevin Farrell +diff --git a/advisories/GLIBC-SA-2026-0006 b/advisories/GLIBC-SA-2026-0006 +deleted file mode 100644 +index 1ac70de4d9..0000000000 +--- a/advisories/GLIBC-SA-2026-0006 ++++ /dev/null +@@ -1,27 +0,0 @@ +-gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames +- +-Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf +-that specifies the library's DNS backend in the GNU C library version +-2.34 to version 2.43 could result in an invalid DNS hostname being +-returned to the caller in violation of the DNS specification. +- +-A defect in the getanswer_ptr function, which implements the iteration +-and extraction of the answer from a DNS response, can cause it to accept +-an invalid DNS hostname that can contain shell metacharacters. An +-application that uses the returned hostname in a shell, without guarding +-for shell expansion, may be subject to shell injection attacks. At the +-time of publication, no known affected DNS server returns results with +-shell metacharacters in the results. An attacker would either need to +-be network adjacent or have compromised the DNS server to use this +-defect for shell injection. No known vulnerable application has been +-identified. +- +-CVE-Id: CVE-2026-4438 +-Public-Date: 2026-03-20 +-Vulnerable-Commit: 32e5db37684ffcbc6ae34fcc6cdcf28670506baa (2.34-323) +-Vulnerable-Commit: def97e7f71a07517810f7263213d607e08ad21f1 (2.35-188) +-Vulnerable-Commit: 77f523c473878ec0051582ef15161c6982879095 (2.36-30) +-Vulnerable-Commit: e32547d661a43da63368e488b6cfa9c53b4dcf92 (2.37) +-Fix-Commit: dd9945c0ba40d2dbc9eb7c99291ba6b69bd66718 (2.43-17) +-Fix-Commit: e10977481f4db4b2a3ce34fa4c3a1e26651ae312 (2.44) +-Reported-by: Antonio Maini (0rbitingZer0) - 0rbitingZer0@proton.me +diff --git a/advisories/GLIBC-SA-2026-0007 b/advisories/GLIBC-SA-2026-0007 +deleted file mode 100644 +index b880fb5544..0000000000 +--- a/advisories/GLIBC-SA-2026-0007 ++++ /dev/null +@@ -1,15 +0,0 @@ +-iconv crash due to assertion failure with untrusted input +- +-The iconv() function in the GNU C Library versions 2.43 and earlier may +-crash due to an assertion failure when converting inputs from the +-IBM1390 or IBM1399 character sets, which may be used to remotely crash +-an application. +- +-This vulnerability can be trivially mitigated by removing the IBM1390 +-and IBM1399 character sets from systems that do not need them. +- +-CVE-Id: CVE-2026-4046 +-Public-Date: 2026-03-12 +-Vulnerable-Commit: 0ecb606cb6cf65de1d9fc8a919bceb4be476c602 (2.3.3-1501) +-Fix-Commit: d6f08d1cf027f4eb2ba289a6cc66853722d4badc (2.44) +-Reported-by: Rocket Ma +diff --git a/advisories/GLIBC-SA-2026-0008 b/advisories/GLIBC-SA-2026-0008 +deleted file mode 100644 +index 43b38ce38a..0000000000 +--- a/advisories/GLIBC-SA-2026-0008 ++++ /dev/null +@@ -1,22 +0,0 @@ +-REJECTED: Static buffer overflow in deprecated nis_local_principal +- +-REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been +-discovered that no NIS+ client or server was ever released for any +-Linux-based OS distributions and as such this makes the API provisional +-and unused. Secondly it has been discovered that the NIS+ cold start +-cache (/var/nis/NIS_COLD_START) cannot be bypassed and as such the API +-can only be called with a trusted server from the pre-populated cache. +-The use of a trusted server means no trust boundary is crossed and this +-is therefore considered a normal bug. +- +-NIS+ support in the GNU C Library was never officially supported even +-though an incomplete implementation of the APIs was made pulibc. To the +-best knowledge of the glibc security team no open-source NIS+ server +-implementations were ever released for use with this API. Applications +-should not use any of the NIS+ APIs and should move to modern identity +-and access management services. +- +-CVE-Id: CVE-2026-5358 +-Public-Date: 2026-04-10 +-Rejected-Date: 2026-04-33 +-Reported-by: Rahul Hoysala +diff --git a/advisories/GLIBC-SA-2026-0009 b/advisories/GLIBC-SA-2026-0009 +deleted file mode 100644 +index 3c297fdc80..0000000000 +--- a/advisories/GLIBC-SA-2026-0009 ++++ /dev/null +@@ -1,23 +0,0 @@ +-scanf %mc off-by-one heap buffer overflow +- +-Calling the scanf family of functions with a %mc (malloc'd character +-match) in the GNU C Library version 2.7 to version 2.43 with a format +-width specifier with an explicit width greater than 1024 could result in +-a one byte heap buffer overflow. +- +-The bug is in the buffer growth formula in __vfscanf_internal, which +-under-allocates by one byte during realloc expansion, allowing a +-controlled single-byte overwrite past the end of the heap buffer. +- +-The impact is limited by the fact that to execute the overwrite you need +-both user controlled input data and a specific choice of maximum width +-that yields a smaller than needed allocation. The latter point has to +-take into account malloc's particular chunk size rounding process. The +-"%[width]mc" format specifier does not appear to have notable use in +-major Linux-based OS distributions, due to which the real world impact +-may be limited to bespoke use cases. +- +-CVE-Id: CVE-2026-5450 +-Public-Date: 2026-03-19 +-Vulnerable-Commit: 874aa52349cc111d1f6ea5dff24bb14c306714e0 (2.7) +-Reported-by: Rocket Ma +diff --git a/advisories/GLIBC-SA-2026-0010 b/advisories/GLIBC-SA-2026-0010 +deleted file mode 100644 +index ae9953fb71..0000000000 +--- a/advisories/GLIBC-SA-2026-0010 ++++ /dev/null +@@ -1,24 +0,0 @@ +-Potential buffer under-read in ungetwc +- +-Calling the ungetwc function on a FILE stream with wide characters +-encoded in a character set that has overlaps between its single byte and +-multi-byte character encodings, in the GNU C Library version 2.43 or +-earlier, may result in an attempt to read bytes before an allocated +-buffer, potentially resulting in unintentional disclosure of neighboring +-data in the heap, or a program crash. +- +-A bug in the wide character pushback implementation +-(_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate +-on the regular character buffer (fp->_IO_read_ptr) instead of the actual +-wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program +-crash may happen in cases where fp->_IO_read_ptr is not initialized and +-hence points to NULL. The buffer under-read requires a special situation +-where the input character encoding is such that there are overlaps +-between single byte representations and multibyte representations in +-that encoding, resulting in spurious matches. The spurious match case +-is not possible in the standard Unicode character sets. +- +-CVE-Id: CVE-2026-5928 +-Public-Date: 2026-03-17 +-Reported-by: Rocket Ma +-Vulnerable-Commit: d64b6ad07585b8a37e5fecc9a47fcee766d52ede (2.1.1-89) +diff --git a/advisories/GLIBC-SA-2026-0011 b/advisories/GLIBC-SA-2026-0011 +deleted file mode 100644 +index e492fa5507..0000000000 +--- a/advisories/GLIBC-SA-2026-0011 ++++ /dev/null +@@ -1,24 +0,0 @@ +-Potential buffer overflow in ns_sprintrrf TSIG handling path +- +-The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the +-GNU C Library version 2.2 and newer fail to enforce the caller-supplied +-buffer length, and can result in an out-of-bounds write when printing +-TSIG records. +- +-A defect in the TSIG case handling within ns_sprintrrf performs a +-formatted write using sprintf without checking the remaining buffer +-length, and may write up to 6 bytes past the end of the buffer. If the +-library is compiled with assertions, and the out-of-bounds write doesn't +-terminate the process, then a subsequent check for "len <= *buflen" will +-trigger an assertion failure. +- +-These functions are for application debugging only and hence not in the +-path of code executed by the DNS resolver. Further, they have been +-deprecated since version 2.34 (2021-08-02) and should not be used by any +-new applications. Applications should consider porting away from these +-interfaces since they may be removed in future versions. +- +-CVE-Id: CVE-2026-5435 +-Public-Date: 2026-04-02 +-Vulnerable-Commit: b43b13ac2544b11f35be301d1589b51a8473e32b (2.2) +-Reported-by: shinobu +diff --git a/advisories/GLIBC-SA-2026-0012 b/advisories/GLIBC-SA-2026-0012 +deleted file mode 100644 +index 22071d97a6..0000000000 +--- a/advisories/GLIBC-SA-2026-0012 ++++ /dev/null +@@ -1,18 +0,0 @@ +-Buffer overread in ns_printrrf with corrupted RDATA field +- +-The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the +-GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA +-content against the RDATA length in a DNS response when processing A6, +-CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a +-DNS response, causing a target application to crash or read +-uninitialized memory. +- +-These functions are for application debugging only and hence not in the +-path of code executed by the DNS resolver. Further, they have been +-deprecated since version 2.34 and should not be used by any new +-applications. Applications should consider porting away from these +-interfaces since they may be removed in future versions. +- +-CVE-Id: CVE-2026-6238 +-Public-Date: 2026-04-11 +-Vulnerable-Commit: ee188d555b8c32ad9704a7440cab400af967292f (1.90) +diff --git a/advisories/GLIBC-SA-2026-0013 b/advisories/GLIBC-SA-2026-0013 +deleted file mode 100644 +index 085a853434..0000000000 +--- a/advisories/GLIBC-SA-2026-0013 ++++ /dev/null +@@ -1,20 +0,0 @@ +-Potential stack-based buffer clash during tilde expansion in wordexp +- +-Calling wordexp with a tilde (~) followed by an overly long username +-in the GNU C Library version 2.2.3 to 2.43 may lead to a stack buffer +-clash. +- +-When expanding paths that begin with a tilde (~) followed by a username, the +-internal parse_tilde function extracts the username to determine the user's +-home directory. The implementation allocates memory for this username directly +-on the stack using the strndupa macro. Because the size of this allocation +-was determined by the length of the user-supplied input without any bounds +-checks, passing an excessively long username e.g. thousands of characters, +-forces the thread to exhaust its stack space. Thus if an application passes +-untrusted, attacker-controlled input to the wordexp function, an attacker +-can trigger a stack clash. +- +-CVE-Id: CVE-2026-6791 +-Public-Date: 2026-06-22 +-Vulnerable-Commit: 344af000e1d6e9c7882b9bc48e71cb3f1b5fc03c (2.2.3-114) +-Reported-by: storm +diff --git a/advisories/GLIBC-SA-2026-0014 b/advisories/GLIBC-SA-2026-0014 +deleted file mode 100644 +index 1e9a0039f0..0000000000 +--- a/advisories/GLIBC-SA-2026-0014 ++++ /dev/null +@@ -1,19 +0,0 @@ +-wordexp with WRDE_APPEND may result in an invalid call to free() +- +-Calling wordexp with WRDE_APPEND in conjunction with an invalid expansion +-(where an error like WRDE_BADCHAR would be returned) can create a stale +-address in the wordexp_t that can cause an invalid free from wordfree. +-This affects the GNU C Library version 2.0 to version 2.43. +- +-In WRDE_APPEND mode, wordexp saves the caller-visible wordexp_t state +-before appending the processing input. If the word expansion grows +-we_wordv via realloc, and realloc requires moving we_wordv to a new memory +-location (instead of expanding in-place), and the expansion later fails, +-the rollback fails to properly restore all previous we_wordv values and +-may add stale pointers into the caller-visible state. A subsequent +-wordfree may then issue an invalid call to free(). +- +-CVE-Id: CVE-2026-6368 +-Public-Date: 2026-07-14 +-Vulnerable-Commit: 8f2ece695d8822e9ecc63ecd157e90bf17a6fe65 (1.93-260) +-Reported-by: shinobu +diff --git a/advisories/README b/advisories/README +deleted file mode 100644 +index 330a31dff3..0000000000 +--- a/advisories/README ++++ /dev/null +@@ -1,92 +0,0 @@ +-GNU C Library Security Advisory Format +-====================================== +- +-Security advisories in this directory follow a simple git commit log +-format, with a heading and free-format description augmented with tags +-to allow parsing key information. References to code changes are +-specific to the glibc repository and follow a specific format: +- +- Tag-name: (release-version) +- +-The indicates a specific commit in the repository. The +-release-version indicates the publicly consumable release in which this +-commit is known to exist. The release-version is derived from the +-git-describe format, (i.e. stripped out from glibc-2.34.NNN-gxxxx) and +-is of the form 2.34-NNN. If the -NNN suffix is absent, it means that +-the change is in that release tarball, otherwise the change is on the +-release/2.YY/master branch and not in any released tarball. +- +-The following tags are currently being used: +- +-CVE-Id: +-This is the CVE-Id assigned under the CVE Program +-(https://www.cve.org/). +- +-Public-Date: +-The date this issue became publicly known. +- +-Rejected-Date: +-The most recent date the assigned advisory was rejected. If the advisory +-is ever published again the Rejected-Date tag should be removed. +- +-Vulnerable-Commit: +-The commit that introduced this vulnerability. There could be multiple +-entries, one for each release branch in the glibc repository; the +-release-version portion of this tag should tell you which branch this is +-on. +- +-Fix-Commit: +-The commit that fixed this vulnerability. There could be multiple +-entries for each release branch in the glibc repository, indicating that +-all of those commits contributed to fixing that issue in each of those +-branches. +- +-Reported-By: +-The entity that reported this issue. There could be multiple entries, one for +-each reporter. +- +-Adding an Advisory +------------------- +- +-An advisory for a CVE needs to be added on the master branch in two steps: +- +-1. Add the text of the advisory without any Fix-Commit tags along with +- the fix for the CVE. Add the Vulnerable-Commit tag, if applicable. +- The advisories directory does not exist in release branches, so keep +- the advisory text commit distinct from the code changes, to ease +- backports. Ask for the GLIBC-SA advisory number from the security +- team. +- +-2. Finish all backports on release branches and then back on the msater +- branch, add all commit refs to the advisory using the Fix-Commit +- tags. Don't bother adding the release-version subscript since the +- next step will overwrite it. +- +-3. Run the process-advisories.sh script in the scripts directory on the +- advisory: +- +- scripts/process-advisories.sh update GLIBC-SA-YYYY-NNNN +- +- (replace YYYY-NNNN with the actual advisory number). +- +-4. Verify the updated advisory and push the result. +- +-Rejecting an Advisory +---------------------- +- +-Rejecting an advisory on the master branch can be done in one step: +- +-1. Mark the advisory as rejected. Add the text "REJECTED: " as a prefix +- to any short-form description. Add a new paragraph that starts with +- "REJECTED: " and explains the reason for the rejection including +- justification for why it no longer has security impact. Lastly add +- a Rejected-Date tag to the advisory. +- +-Getting a NEWS snippet from advisories +--------------------------------------- +- +-Run: +- +- scripts/process-advisories.sh news +- +-and copy the content into the NEWS file. + +commit 1bd79651065b27c02c6502b9423124e54882058d +Author: Andreas K. Hüttel +Date: Sat Jul 25 09:21:33 2026 +0900 + + NEWS: start 2.44.1 section + + Signed-off-by: Andreas K. Hüttel + +diff --git a/NEWS b/NEWS +index ee28fadf49..1043343d70 100644 +--- a/NEWS ++++ b/NEWS +@@ -5,6 +5,10 @@ See the end for copying conditions. + Please send GNU C library bug reports via + using `glibc' in the "product" field. + ++Version 2.44.1 ++ ++The following bugs are resolved with this release: ++ + Version 2.44 + + Major new features: + +commit 0b05bc142249ac47e72be5cad5c37f33f4bb68d4 +Author: Samuel Thibault +Date: Fri Jul 24 23:10:02 2026 +0200 + + hurd: Make the readlink __fstatat64 references optional + + They may show up or not depending on the toolchain in use. + +diff --git a/sysdeps/mach/hurd/i386/localplt.data b/sysdeps/mach/hurd/i386/localplt.data +index 2befcd3748..5b9413422d 100644 +--- a/sysdeps/mach/hurd/i386/localplt.data ++++ b/sysdeps/mach/hurd/i386/localplt.data +@@ -25,14 +25,14 @@ ld.so: __writev + ld.so: __libc_lseek64 + ld.so: __mmap + ld.so: __fstat64 +-ld.so: __fstatat64 ++ld.so: __fstatat64 ? + ld.so: __stat64 + ld.so: __access + ld.so: __getpid + ld.so: __getcwd + ld.so: _exit ? + ld.so: abort +-ld.so: readlink ++ld.so: readlink ? + ld.so: _hurd_intr_rpc_mach_msg + ld.so: __errno_location + ld.so: _dl_init_first +diff --git a/sysdeps/mach/hurd/x86_64/localplt.data b/sysdeps/mach/hurd/x86_64/localplt.data +index fda28cd983..cc39118d12 100644 +--- a/sysdeps/mach/hurd/x86_64/localplt.data ++++ b/sysdeps/mach/hurd/x86_64/localplt.data +@@ -24,14 +24,14 @@ ld.so: __writev + ld.so: __libc_lseek64 + ld.so: __mmap + ld.so: __fstat64 +-ld.so: __fstatat64 ++ld.so: __fstatat64 ? + ld.so: __stat64 + ld.so: __access + ld.so: __getpid + ld.so: __getcwd + ld.so: _exit ? + ld.so: abort +-ld.so: readlink ++ld.so: readlink ? + ld.so: _hurd_intr_rpc_mach_msg + ld.so: __errno_location + ld.so: _dl_init_first + +commit c045fc61e8435c103ebfe06d01fec7f56503e2b4 +Author: Samuel Thibault +Date: Mon Jul 27 00:59:36 2026 +0200 + + hurd: fix fork's longjmp demangling on i386 + + i386's setjmp does not actually mangle ebp. + +diff --git a/sysdeps/mach/hurd/i386/longjmp-ts.c b/sysdeps/mach/hurd/i386/longjmp-ts.c +index 93450e86b4..340104b832 100644 +--- a/sysdeps/mach/hurd/i386/longjmp-ts.c ++++ b/sysdeps/mach/hurd/i386/longjmp-ts.c +@@ -38,7 +38,6 @@ _hurd_longjmp_thread_state (void *state, jmp_buf env, int val) + ts->eip = env[0].__jmpbuf[JB_PC]; + ts->eax = val ?: 1; + +- PTR_DEMANGLE (ts->ebp); + PTR_DEMANGLE (ts->uesp); + PTR_DEMANGLE (ts->eip); + } + +commit 7cba77790f3279bec3ac20e9c7632b021cd53f95 +Author: Adhemerval Zanella +Date: Mon Jul 27 13:37:19 2026 -0300 + + math: Fix sinh worst-case results for |x| > 36.736801 [BZ 34441] + + The CORE-MATH import mistranslated the accurate path result scaling + 'th *= sp.f' as 'th *= asuint64 (sp)' (commit 106f8c2ed68), and two of + the 51 exceptional-case table entries were dropped when the table was + moved to e_sinh_data.c (commit f05c4907a27). + + Checked on x86_64-linux-gnu and aarch64-linux-gnu. + + (cherry picked from commit fdc90dbb52b092f68cd5a4fac7a4cbd854c91bc3) + +diff --git a/NEWS b/NEWS +index 1043343d70..fe2b1d7f79 100644 +--- a/NEWS ++++ b/NEWS +@@ -8,6 +8,9 @@ using `glibc' in the "product" field. + Version 2.44.1 + + The following bugs are resolved with this release: ++ ++ [34441] math: math: sinh() returns wrong results for some inputs with ++ |x| > 36.736801 + + Version 2.44 + +diff --git a/math/auto-libm-test-in b/math/auto-libm-test-in +index ca670768a2..5c4d486af4 100644 +--- a/math/auto-libm-test-in ++++ b/math/auto-libm-test-in +@@ -9661,6 +9661,14 @@ sinh 0x2.c5d37700c6bb03a6c24b6c9b494cp+12 + sinh 0x2.c5d37700c6bb03a6c24b6c9b494ep+12 + # the next value generates larger error bounds on x86_64 (binary64) + sinh -0x1.633c62890fa14p+9 ++sinh 0x1.2b4f4e0bb49c9p+5 ++sinh -0x1.2b4f4e0bb49c9p+5 ++sinh 0x1.2ac43fb6d3abap+5 ++sinh -0x1.2ac43fb6d3abap+5 ++sinh 0x1.b7efa91915c95p-2 ++sinh -0x1.b7efa91915c95p-2 ++sinh 0x1.92a5c27afbe82p+4 ++sinh -0x1.92a5c27afbe82p+4 + + sinpi 0 + sinpi -0 +diff --git a/math/auto-libm-test-out-sinh b/math/auto-libm-test-out-sinh +index f96252b91c..91ab5c19fa 100644 +--- a/math/auto-libm-test-out-sinh ++++ b/math/auto-libm-test-out-sinh +@@ -6466,3 +6466,555 @@ sinh -0x1.633c62890fa14p+9 + = sinh tonearest ibm128 -0x2.c678c5121f428p+8 : -0xf.ef3a7e711d2c75a66ea3ca1c4p+1020 : inexact-ok + = sinh towardzero ibm128 -0x2.c678c5121f428p+8 : -0xf.ef3a7e711d2c75a66ea3ca1c4p+1020 : inexact-ok + = sinh upward ibm128 -0x2.c678c5121f428p+8 : -0xf.ef3a7e711d2c75a66ea3ca1c4p+1020 : inexact-ok ++sinh 0x1.2b4f4e0bb49c9p+5 ++= sinh downward binary32 0x2.569eap+4 : 0x1.f7c30ap+52 : inexact-ok ++= sinh tonearest binary32 0x2.569eap+4 : 0x1.f7c30ap+52 : inexact-ok ++= sinh towardzero binary32 0x2.569eap+4 : 0x1.f7c30ap+52 : inexact-ok ++= sinh upward binary32 0x2.569eap+4 : 0x1.f7c30cp+52 : inexact-ok ++= sinh downward binary64 0x2.569eap+4 : 0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh tonearest binary64 0x2.569eap+4 : 0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh towardzero binary64 0x2.569eap+4 : 0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh upward binary64 0x2.569eap+4 : 0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh downward intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh tonearest intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh downward m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh tonearest m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh downward binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh tonearest binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh towardzero binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh upward binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f53p+52 : inexact-ok ++= sinh downward ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh tonearest ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh upward ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh downward binary32 0x2.569e9cp+4 : 0x1.f7c28cp+52 : inexact-ok ++= sinh tonearest binary32 0x2.569e9cp+4 : 0x1.f7c28cp+52 : inexact-ok ++= sinh towardzero binary32 0x2.569e9cp+4 : 0x1.f7c28cp+52 : inexact-ok ++= sinh upward binary32 0x2.569e9cp+4 : 0x1.f7c28ep+52 : inexact-ok ++= sinh downward binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh tonearest binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh towardzero binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh upward binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh downward intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh tonearest intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh downward m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh tonearest m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh downward binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh tonearest binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh towardzero binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh upward binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ecp+52 : inexact-ok ++= sinh downward ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh upward ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh downward binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh tonearest binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh towardzero binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh upward binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh downward intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh tonearest intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh downward m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh tonearest m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh downward binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh tonearest binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh towardzero binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh upward binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh downward ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh upward ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000009p+52 : inexact-ok ++sinh -0x1.2b4f4e0bb49c9p+5 ++= sinh downward binary32 -0x2.569e9cp+4 : -0x1.f7c28ep+52 : inexact-ok ++= sinh tonearest binary32 -0x2.569e9cp+4 : -0x1.f7c28cp+52 : inexact-ok ++= sinh towardzero binary32 -0x2.569e9cp+4 : -0x1.f7c28cp+52 : inexact-ok ++= sinh upward binary32 -0x2.569e9cp+4 : -0x1.f7c28cp+52 : inexact-ok ++= sinh downward binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh upward binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh downward intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh tonearest intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh downward m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh downward binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ecp+52 : inexact-ok ++= sinh tonearest binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh towardzero binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh upward binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh downward ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh upward ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh downward binary32 -0x2.569eap+4 : -0x1.f7c30cp+52 : inexact-ok ++= sinh tonearest binary32 -0x2.569eap+4 : -0x1.f7c30ap+52 : inexact-ok ++= sinh towardzero binary32 -0x2.569eap+4 : -0x1.f7c30ap+52 : inexact-ok ++= sinh upward binary32 -0x2.569eap+4 : -0x1.f7c30ap+52 : inexact-ok ++= sinh downward binary64 -0x2.569eap+4 : -0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.569eap+4 : -0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.569eap+4 : -0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh upward binary64 -0x2.569eap+4 : -0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh downward intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh downward m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh downward binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f53p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh upward binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh downward ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh upward ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh downward binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh tonearest binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh towardzero binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh upward binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh downward intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh downward m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh downward binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh upward binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh downward ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000009p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh upward ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++sinh 0x1.2ac43fb6d3abap+5 ++= sinh downward binary32 0x2.55888p+4 : 0x1.d6b0ecp+52 : inexact-ok ++= sinh tonearest binary32 0x2.55888p+4 : 0x1.d6b0ecp+52 : inexact-ok ++= sinh towardzero binary32 0x2.55888p+4 : 0x1.d6b0ecp+52 : inexact-ok ++= sinh upward binary32 0x2.55888p+4 : 0x1.d6b0eep+52 : inexact-ok ++= sinh downward binary64 0x2.55888p+4 : 0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh tonearest binary64 0x2.55888p+4 : 0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh towardzero binary64 0x2.55888p+4 : 0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh upward binary64 0x2.55888p+4 : 0x1.d6b0ecda100c3p+52 : inexact-ok ++= sinh downward intel96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh tonearest intel96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero intel96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward intel96 0x2.55888p+4 : 0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh downward m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh tonearest m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh downward binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh tonearest binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh towardzero binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh upward binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d9p+52 : inexact-ok ++= sinh downward ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh upward ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh downward binary32 0x2.55887cp+4 : 0x1.d6b076p+52 : inexact-ok ++= sinh tonearest binary32 0x2.55887cp+4 : 0x1.d6b078p+52 : inexact-ok ++= sinh towardzero binary32 0x2.55887cp+4 : 0x1.d6b076p+52 : inexact-ok ++= sinh upward binary32 0x2.55887cp+4 : 0x1.d6b078p+52 : inexact-ok ++= sinh downward binary64 0x2.55887cp+4 : 0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh tonearest binary64 0x2.55887cp+4 : 0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh towardzero binary64 0x2.55887cp+4 : 0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh upward binary64 0x2.55887cp+4 : 0x1.d6b0772de38b3p+52 : inexact-ok ++= sinh downward intel96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh tonearest intel96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero intel96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward intel96 0x2.55887cp+4 : 0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh downward m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh tonearest m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh downward binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh tonearest binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh towardzero binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh upward binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c262p+52 : inexact-ok ++= sinh downward ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh upward ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh downward binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh tonearest binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh upward binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh downward intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh tonearest intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh downward m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh tonearest m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh downward binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh tonearest binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh towardzero binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh upward binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289fp+52 : inexact-ok ++= sinh downward ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh upward ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff29p+52 : inexact-ok ++sinh -0x1.2ac43fb6d3abap+5 ++= sinh downward binary32 -0x2.55887cp+4 : -0x1.d6b078p+52 : inexact-ok ++= sinh tonearest binary32 -0x2.55887cp+4 : -0x1.d6b078p+52 : inexact-ok ++= sinh towardzero binary32 -0x2.55887cp+4 : -0x1.d6b076p+52 : inexact-ok ++= sinh upward binary32 -0x2.55887cp+4 : -0x1.d6b076p+52 : inexact-ok ++= sinh downward binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b3p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh upward binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh downward intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh tonearest intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh downward m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh downward binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c262p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh upward binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh downward ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh upward ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh downward binary32 -0x2.55888p+4 : -0x1.d6b0eep+52 : inexact-ok ++= sinh tonearest binary32 -0x2.55888p+4 : -0x1.d6b0ecp+52 : inexact-ok ++= sinh towardzero binary32 -0x2.55888p+4 : -0x1.d6b0ecp+52 : inexact-ok ++= sinh upward binary32 -0x2.55888p+4 : -0x1.d6b0ecp+52 : inexact-ok ++= sinh downward binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c3p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh upward binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh downward intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh downward m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh downward binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d9p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh upward binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh downward ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh upward ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh downward binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh upward binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh downward intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh downward m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh downward binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289fp+52 : inexact-ok ++= sinh tonearest binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh towardzero binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh upward binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh downward ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff29p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh upward ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++sinh 0x1.b7efa91915c95p-2 ++= sinh downward binary32 0x6.dfbea8p-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh tonearest binary32 0x6.dfbea8p-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh towardzero binary32 0x6.dfbea8p-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh upward binary32 0x6.dfbea8p-4 : 0x7.1661bp-4 : inexact-ok ++= sinh downward binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e4p-4 : inexact-ok ++= sinh tonearest binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e8p-4 : inexact-ok ++= sinh towardzero binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e4p-4 : inexact-ok ++= sinh upward binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e8p-4 : inexact-ok ++= sinh downward intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh tonearest intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh downward m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh tonearest m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh downward binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh tonearest binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh towardzero binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh upward binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh downward ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh tonearest ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh towardzero ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh upward ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ecp-4 : inexact-ok ++= sinh downward binary32 0x6.dfbeap-4 : 0x7.1661ap-4 : inexact-ok ++= sinh tonearest binary32 0x6.dfbeap-4 : 0x7.1661ap-4 : inexact-ok ++= sinh towardzero binary32 0x6.dfbeap-4 : 0x7.1661ap-4 : inexact-ok ++= sinh upward binary32 0x6.dfbeap-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh downward binary64 0x6.dfbeap-4 : 0x7.1661a2f837414p-4 : inexact-ok ++= sinh tonearest binary64 0x6.dfbeap-4 : 0x7.1661a2f837418p-4 : inexact-ok ++= sinh towardzero binary64 0x6.dfbeap-4 : 0x7.1661a2f837414p-4 : inexact-ok ++= sinh upward binary64 0x6.dfbeap-4 : 0x7.1661a2f837418p-4 : inexact-ok ++= sinh downward intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh tonearest intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh downward m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh tonearest m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh downward binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh tonearest binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh towardzero binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh upward binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4ccp-4 : inexact-ok ++= sinh downward ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh tonearest ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh towardzero ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh upward ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d6p-4 : inexact-ok ++= sinh downward binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh tonearest binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh upward binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh downward intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh tonearest intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh downward m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh tonearest m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh downward binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh tonearest binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh towardzero binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh upward binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh downward ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++= sinh tonearest ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++= sinh towardzero ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++= sinh upward ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++sinh -0x1.b7efa91915c95p-2 ++= sinh downward binary32 -0x6.dfbeap-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh tonearest binary32 -0x6.dfbeap-4 : -0x7.1661ap-4 : inexact-ok ++= sinh towardzero binary32 -0x6.dfbeap-4 : -0x7.1661ap-4 : inexact-ok ++= sinh upward binary32 -0x6.dfbeap-4 : -0x7.1661ap-4 : inexact-ok ++= sinh downward binary64 -0x6.dfbeap-4 : -0x7.1661a2f837418p-4 : inexact-ok ++= sinh tonearest binary64 -0x6.dfbeap-4 : -0x7.1661a2f837418p-4 : inexact-ok ++= sinh towardzero binary64 -0x6.dfbeap-4 : -0x7.1661a2f837414p-4 : inexact-ok ++= sinh upward binary64 -0x6.dfbeap-4 : -0x7.1661a2f837414p-4 : inexact-ok ++= sinh downward intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh tonearest intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh downward m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh tonearest m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh downward binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4ccp-4 : inexact-ok ++= sinh tonearest binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh towardzero binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh upward binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh downward ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d6p-4 : inexact-ok ++= sinh tonearest ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh towardzero ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh upward ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh downward binary32 -0x6.dfbea8p-4 : -0x7.1661bp-4 : inexact-ok ++= sinh tonearest binary32 -0x6.dfbea8p-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh towardzero binary32 -0x6.dfbea8p-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh upward binary32 -0x6.dfbea8p-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh downward binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e8p-4 : inexact-ok ++= sinh tonearest binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e8p-4 : inexact-ok ++= sinh towardzero binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e4p-4 : inexact-ok ++= sinh upward binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e4p-4 : inexact-ok ++= sinh downward intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh tonearest intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh downward m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh tonearest m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh downward binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh tonearest binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh towardzero binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh upward binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh downward ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ecp-4 : inexact-ok ++= sinh tonearest ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh towardzero ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh upward ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh downward binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh tonearest binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh upward binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh downward intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh tonearest intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh downward m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh tonearest m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh downward binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh tonearest binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh towardzero binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh upward binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh downward ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++= sinh tonearest ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++= sinh towardzero ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++= sinh upward ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++sinh 0x1.92a5c27afbe82p+4 ++= sinh downward binary32 0x1.92a5c4p+4 : 0x9.e410bp+32 : inexact-ok ++= sinh tonearest binary32 0x1.92a5c4p+4 : 0x9.e410cp+32 : inexact-ok ++= sinh towardzero binary32 0x1.92a5c4p+4 : 0x9.e410bp+32 : inexact-ok ++= sinh upward binary32 0x1.92a5c4p+4 : 0x9.e410cp+32 : inexact-ok ++= sinh downward binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh tonearest binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh towardzero binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh upward binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c858p+32 : inexact-ok ++= sinh downward intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh tonearest intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh downward m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh tonearest m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh downward binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh tonearest binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh towardzero binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh upward binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh downward ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh tonearest ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh towardzero ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh upward ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60ecp+32 : inexact-ok ++= sinh downward binary32 0x1.92a5c2p+4 : 0x9.e40f8p+32 : inexact-ok ++= sinh tonearest binary32 0x1.92a5c2p+4 : 0x9.e40f8p+32 : inexact-ok ++= sinh towardzero binary32 0x1.92a5c2p+4 : 0x9.e40f8p+32 : inexact-ok ++= sinh upward binary32 0x1.92a5c2p+4 : 0x9.e40f9p+32 : inexact-ok ++= sinh downward binary64 0x1.92a5c2p+4 : 0x9.e40f810b889bp+32 : inexact-ok ++= sinh tonearest binary64 0x1.92a5c2p+4 : 0x9.e40f810b889b8p+32 : inexact-ok ++= sinh towardzero binary64 0x1.92a5c2p+4 : 0x9.e40f810b889bp+32 : inexact-ok ++= sinh upward binary64 0x1.92a5c2p+4 : 0x9.e40f810b889b8p+32 : inexact-ok ++= sinh downward intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh tonearest intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh downward m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh tonearest m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh downward binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh tonearest binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh towardzero binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh upward binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa468p+32 : inexact-ok ++= sinh downward ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh tonearest ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh towardzero ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh upward ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa8p+32 : inexact-ok ++= sinh downward binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh tonearest binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd12392ap+32 : inexact-ok ++= sinh downward intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh tonearest intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929801p+32 : inexact-ok ++= sinh downward m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh tonearest m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929801p+32 : inexact-ok ++= sinh downward binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh tonearest binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh towardzero binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh upward binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh downward ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh tonearest ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh towardzero ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh upward ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd12392980000000000024p+32 : inexact-ok ++sinh -0x1.92a5c27afbe82p+4 ++= sinh downward binary32 -0x1.92a5c2p+4 : -0x9.e40f9p+32 : inexact-ok ++= sinh tonearest binary32 -0x1.92a5c2p+4 : -0x9.e40f8p+32 : inexact-ok ++= sinh towardzero binary32 -0x1.92a5c2p+4 : -0x9.e40f8p+32 : inexact-ok ++= sinh upward binary32 -0x1.92a5c2p+4 : -0x9.e40f8p+32 : inexact-ok ++= sinh downward binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889b8p+32 : inexact-ok ++= sinh tonearest binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889b8p+32 : inexact-ok ++= sinh towardzero binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889bp+32 : inexact-ok ++= sinh upward binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889bp+32 : inexact-ok ++= sinh downward intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh tonearest intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh downward m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh tonearest m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh downward binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa468p+32 : inexact-ok ++= sinh tonearest binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh towardzero binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh upward binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh downward ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa8p+32 : inexact-ok ++= sinh tonearest ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh towardzero ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh upward ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh downward binary32 -0x1.92a5c4p+4 : -0x9.e410cp+32 : inexact-ok ++= sinh tonearest binary32 -0x1.92a5c4p+4 : -0x9.e410cp+32 : inexact-ok ++= sinh towardzero binary32 -0x1.92a5c4p+4 : -0x9.e410bp+32 : inexact-ok ++= sinh upward binary32 -0x1.92a5c4p+4 : -0x9.e410bp+32 : inexact-ok ++= sinh downward binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c858p+32 : inexact-ok ++= sinh tonearest binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh towardzero binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh upward binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh downward intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh tonearest intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh downward m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh tonearest m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh downward binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh tonearest binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh towardzero binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh upward binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh downward ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60ecp+32 : inexact-ok ++= sinh tonearest ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh towardzero ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh upward ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh downward binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd12392ap+32 : inexact-ok ++= sinh tonearest binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh downward intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929801p+32 : inexact-ok ++= sinh tonearest intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh downward m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929801p+32 : inexact-ok ++= sinh tonearest m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh downward binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh tonearest binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh towardzero binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh upward binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh downward ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd12392980000000000024p+32 : inexact-ok ++= sinh tonearest ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh towardzero ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh upward ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002p+32 : inexact-ok +diff --git a/sysdeps/ieee754/dbl-64/e_sinh.c b/sysdeps/ieee754/dbl-64/e_sinh.c +index 1643f3f504..638e3d6a6d 100644 +--- a/sysdeps/ieee754/dbl-64/e_sinh.c ++++ b/sysdeps/ieee754/dbl-64/e_sinh.c +@@ -213,7 +213,7 @@ __sinh (double x) + ml = (ul + 8) & MANTISSA_MASK; + th += tl; + th *= 2; +- th *= asuint64 (sp); ++ th *= sp; + if (ml <= 16 || eh - el > 103) + return as_sinh_database (x, th); + return th; +diff --git a/sysdeps/ieee754/dbl-64/e_sinh_data.c b/sysdeps/ieee754/dbl-64/e_sinh_data.c +index ca61e311f1..d4fd41d934 100644 +--- a/sysdeps/ieee754/dbl-64/e_sinh_data.c ++++ b/sysdeps/ieee754/dbl-64/e_sinh_data.c +@@ -35,12 +35,13 @@ const double __sinh_data_ch[][2] = + { 0x1.ae64567f54482p-26, -0x1.defcf17a6ab79p-81 } + }; + +-const double __sinh_data_db[49][3] = ++const double __sinh_data_db[51][3] = + { + { 0x1.364303e1ad8f6p-2, 0x1.3b07e0c779ddap-2, -0x1.bcp-106 }, + { 0x1.4169f234f23b9p-2, 0x1.46b7b3b358f99p-2, -0x1p-56 }, + { 0x1.616cc75d49226p-2, 0x1.687bd068c1c1ep-2, 0x1.ap-111 }, + { 0x1.ae3773250e7d2p-2, 0x1.bafc3479fc9ccp-2, -0x1p-105 }, ++ { 0x1.b7efa91915c95p-2, 0x1.c59869f17b483p-2, -0x1p-104 }, + { 0x1.d68039861ab53p-2, 0x1.e73b46abb01e1p-2, -0x1.2p-109 }, + { 0x1.e90f16eb88c09p-2, 0x1.fbdd4a37760b7p-2, -0x1.f8p-108 }, + { 0x1.a3fc7e4dd47d1p-1, 0x1.d4b21ebf542fp-1, 0x1.ep-107 }, +@@ -62,6 +63,7 @@ const double __sinh_data_db[49][3] = + { 0x1.43a81752eabe7p+3, 0x1.81d364845ecfap+13, -0x1p-90 }, + { 0x1.16369cd53bb69p+4, 0x1.0fbc6c02b1c9p+24, -0x1.9p-81 }, + { 0x1.20e29ea8b51e2p+4, 0x1.08b8abba28abcp+25, 0x1.9bp-79 }, ++ { 0x1.92a5c27afbe82p+4, 0x1.3c81f9a247253p+35, 0x1p-67 }, + { 0x1.a1e4f11b513d7p+4, 0x1.9a65b6c2e2185p+36, -0x1.bcp-70 }, + { 0x1.c089fcf166171p+4, 0x1.5c452e0e37569p+39, 0x1.4p-69 }, + { 0x1.e42a98b3a0be5p+4, 0x1.938768ca4f8aap+42, 0x1.6dp-62 }, +diff --git a/sysdeps/ieee754/dbl-64/e_sinh_data.h b/sysdeps/ieee754/dbl-64/e_sinh_data.h +index 16f7e0da5a..c34848fd54 100644 +--- a/sysdeps/ieee754/dbl-64/e_sinh_data.h ++++ b/sysdeps/ieee754/dbl-64/e_sinh_data.h +@@ -29,7 +29,7 @@ SOFTWARE. + + extern const double __sinh_data_ch[][2] attribute_hidden; + #define CH __sinh_data_ch +-extern const double __sinh_data_db[49][3] attribute_hidden; ++extern const double __sinh_data_db[51][3] attribute_hidden; + #define DB __sinh_data_db + + #endif + +commit 0b58f5d80d24cf83cfde9d8381aafb11fef0e152 +Author: Adhemerval Zanella +Date: Thu Jul 30 08:55:54 2026 -0300 + + math: Fix x86_64 tanh _FloatN aliases binding to the FMA variant [BZ 34465] + + The generic implementation emits libm_alias_double unconditionally, so + tanhf32x and tanhf64 bind directly to __tanh_fma. + + Guard the alias with '#ifndef __tanh' and emit it from the dispatcher, + as sin. Also remove the stale __expm1 defines, unused since tanh moved + to CORE-MATH. + + Checked on x86_64-linux-gnu, and with 'qemu-x86_64 -cpu Nehalem'. + + Reported-by: Michael Brunnbauer + + (cherry picked from commit b01abba04a954cbd6b2834c0643a08685a915fe5) + +diff --git a/NEWS b/NEWS +index fe2b1d7f79..43667c1963 100644 +--- a/NEWS ++++ b/NEWS +@@ -11,6 +11,7 @@ The following bugs are resolved with this release: + + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 ++ [34465] math: math: x86_64 tanh ifunc selection wrong + + Version 2.44 + +diff --git a/sysdeps/ieee754/dbl-64/s_tanh.c b/sysdeps/ieee754/dbl-64/s_tanh.c +index 2029de8fa5..ef80b9edb6 100644 +--- a/sysdeps/ieee754/dbl-64/s_tanh.c ++++ b/sysdeps/ieee754/dbl-64/s_tanh.c +@@ -283,4 +283,6 @@ __tanh (double x) + return as_tanh_database (x, res); + return res; + } ++#ifndef __tanh + libm_alias_double (__tanh, tanh) ++#endif +diff --git a/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c b/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c +index 1b808b1227..1e6b33740a 100644 +--- a/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c ++++ b/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c +@@ -1,10 +1,4 @@ + #define __tanh __tanh_fma +-#define __expm1 __expm1_fma +- +-/* NB: __expm1 may be expanded to __expm1_fma in the following +- prototypes. */ +-extern long double __expm1l (long double); +-extern long double __expm1f128 (long double); + + #define SECTION __attribute__ ((section (".text.fma"))) + +diff --git a/sysdeps/x86_64/fpu/multiarch/s_tanh.c b/sysdeps/x86_64/fpu/multiarch/s_tanh.c +index ec8826f634..9048c977c1 100644 +--- a/sysdeps/x86_64/fpu/multiarch/s_tanh.c ++++ b/sysdeps/x86_64/fpu/multiarch/s_tanh.c +@@ -25,10 +25,9 @@ extern double __redirect_tanh (double); + # define SYMBOL_NAME tanh + # include "ifunc-fma.h" + +-libc_ifunc_redirected (__redirect_tanh, tanh, IFUNC_SELECTOR ()); ++libc_ifunc_redirected (__redirect_tanh, __tanh, IFUNC_SELECTOR ()); ++libm_alias_double (__tanh, tanh) + + # define __tanh __tanh_sse2 +-# undef libm_alias_double +-# define libm_alias_double(a, b) + #endif + #include + +commit 9bcb85688e58847191deb42bfc68d60802078df4 +Author: Xi Ruoyao +Date: Wed Jul 22 19:26:10 2026 +0800 + + io: fix ftw ABI on MIPS n64 + + On MIPS n64 off_t is same as off64_t, but struct stat is not same as + struct stat64 (very peculiar but see the "as tempting as it..." comment + in linux/mips/kernel_stat.h). As the ftw/ftw64 callback accepts a + pointer to a function who accepts struct stat/stat64, for MIPS n64 we + must use different implementations for ftw and ftw64. + + Thus for testing if ftw64 can be aliased to ftw, we should check + XSTAT_IS_XSTAT64 instead of __OFF_T_MATCHES_OFF64_T. + + This resolves the io/tst-ftw-lnk failure observed on MIPS n64. + + Link: https://sourceware.org/glibc/wiki/Testing/Tests/io/tst-ftw-lnk + Signed-off-by: Xi Ruoyao + Reviewed-by: Adhemerval Zanella + + (cherry picked from commit 6758def717175e679cb49b5051b6b5ec54ddfb2c) + +diff --git a/io/ftw.c b/io/ftw.c +index ed0eeb3904..a9368a706e 100644 +--- a/io/ftw.c ++++ b/io/ftw.c +@@ -18,7 +18,9 @@ + + #include + +-#ifndef __OFF_T_MATCHES_OFF64_T ++#include ++ ++#if !XSTAT_IS_XSTAT64 + # include "ftw-common.c" + + versioned_symbol (libc, __new_nftw, nftw, GLIBC_2_3_3); +diff --git a/io/ftw64.c b/io/ftw64.c +index d3cd14c21a..fa7b05df22 100644 +--- a/io/ftw64.c ++++ b/io/ftw64.c +@@ -31,6 +31,9 @@ + #define ftw __rename_ftw + #define nftw __rename_nftw + ++#include ++ ++#include + #include + #include "ftw-common.c" + +@@ -44,7 +47,7 @@ versioned_symbol (libc, __new_nftw64, nftw64, GLIBC_2_3_3); + compat_symbol (libc, __old_nftw64, nftw64, GLIBC_2_1); + #endif + +-#ifdef __OFF_T_MATCHES_OFF64_T ++#if XSTAT_IS_XSTAT64 + weak_alias (__ftw64, ftw) + versioned_symbol (libc, __new_nftw64, nftw, GLIBC_2_3_3); + # if SHLIB_COMPAT(libc, GLIBC_2_1, GLIBC_2_3_3) + +commit 58da792d8a2d8f2fe711318836e853fcddfd7cd8 +Author: Adhemerval Zanella +Date: Tue Aug 4 14:25:48 2026 +0000 + + hurd: Fix build after the ftw kernel_stat.h inclusion + + Commit 6758def7171 changed the generic ftw{64}.c to include + kernel_stat.h, which is Linux specific. + + Add a Hurd version of kernel_stat.h defining XSTAT_IS_XSTAT64 to 0, + since struct stat and struct stat64 never share a layout on Hurd: on + 32-bit ABIs st_ino, st_size, and st_blocks are narrower in struct stat, + and on 64-bit ABIs the two structures still differ in size because + _SPARE_SIZE in bits/stat.h reserves three more ints of spare space in + struct stat than in struct stat64. + + This keeps the ftw/ftw64 symbols exactly as before the change, where + the aliasing check on __OFF_T_MATCHES_OFF64_T was always false because + the Hurd bits/typesizes.h does not define it. + + Checked with a full build for i686-gnu and x86_64-gnu. + + (cherry picked from commit d6031665c3a59faf75cf6bc55e041611da21d0e6) + +diff --git a/sysdeps/mach/hurd/kernel_stat.h b/sysdeps/mach/hurd/kernel_stat.h +new file mode 100644 +index 0000000000..aa8c26b1d9 +--- /dev/null ++++ b/sysdeps/mach/hurd/kernel_stat.h +@@ -0,0 +1,23 @@ ++/* Internal definitions for stat functions. Hurd version. ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++/* struct stat and struct stat64 never have the same layout: on 32-bit ++ ABIs st_ino, st_size, and st_blocks are narrower in struct stat, and ++ on 64-bit ABIs the two structures still differ in the amount of ++ trailing spare space (see _SPARE_SIZE in bits/stat.h). */ ++#define XSTAT_IS_XSTAT64 0 + +commit fec2a9c6765b548f9d738e3a1c63a63ad7061d40 +Author: Adhemerval Zanella +Date: Fri Mar 21 14:03:00 2025 +0000 + + linux: Inline syscall cancellation to keep wrapper frames observable (BZ 34338) + + The cancellable syscall wrappers end with a tail call to __syscall_cancel, + the wrapper frame is then elided, so when the syscall executes the wrapper + is no longer present on the stack. Tools that unwind from CFI alone, such + as valgrind, perf and sampling profilers, cannot observe it. On gdb, it + only recovers it from DWARF call site information, which reduced-debuginfo + libc builds usually omit. + + The behaviour is target dependent: for a shared (PIC) the tail call is + emitted on aarch64, arc, loongarch and riscv. It is not emitted on i386, + x86_64, arm, s390x, sparc and alpha, where the seventh argument is passed + on the stack or fewer argument registers are available, nor on powerpc + and mips, where the TOC/GOT pointer must be restored after the call. + This is why the problem was originally reported as aarch64 specific while + x86_64 was unaffected. + + Rather than only inhibiting the tail call [1] (which keeps the wrapper frame + but still leaves the __syscall_cancel and __internal_syscall_cancel + frames), move the cancellation logic back into the wrappers. In the + single-threaded case the syscall is now issued directly from the wrapper; + only the multi-threaded path still calls the out-of-line __syscall_cancel_arch. + + This keeps the wrapper observable and removes the extra frames, mimicking + how cancellation was handled before 89b53077d2a58f00e7debdfe58afabe953dac60d. + + The result is a small libc.so .text increase (size, first column): + + ABI master patched diff increase + aarch64 1635880 1647424 11544 0.71% + x86_64 1981081 1992257 11176 0.56% + powerpc64le 2364336 2376964 12628 0.53% + riscv64 1368386 1376704 8318 0.61% + loongarch64 1741385 1755601 14216 0.82% + + The tst-backtrace5 was suppose to track this issue, but due wrong + loop variable check it does not take this in account. This patch also fixes + it. + + Checked on aarch64-linux-gnu, x86_64-linux-gnu, i686-linux-gnu, + arm-linux-gnueabihf, and powerpc64le-linux-gnu. + + [1] https://sourceware.org/pipermail/libc-alpha/2025-March/165395.html + + (cherry picked from commit 1b5ff009fa5bf01ad26e6cc330a1df5a0c84135e) + +diff --git a/NEWS b/NEWS +index 43667c1963..28fbd9bcd8 100644 +--- a/NEWS ++++ b/NEWS +@@ -9,6 +9,8 @@ Version 2.44.1 + + The following bugs are resolved with this release: + ++ [34338] libc: Cancellable syscall wrappers are missing from backtraces ++ because they tail-call __syscall_cancel + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong +diff --git a/debug/tst-backtrace5.c b/debug/tst-backtrace5.c +index 4c5784c060..6538da9ab5 100644 +--- a/debug/tst-backtrace5.c ++++ b/debug/tst-backtrace5.c +@@ -36,10 +36,15 @@ + trampoline, read, 3 * fn, and do_test. */ + #define NUM_FUNCTIONS 7 + ++/* Avoid the read wrapper frame truncation on targets that add extra frames ++ between it and handle_signal (the cancellable syscall wrappers ++ __syscall_cancel*, or the i686 __kernel_vsyscall entry). */ ++#define MAX_FUNCTIONS 64 ++ + void + handle_signal (int signum) + { +- void *addresses[NUM_FUNCTIONS]; ++ void *addresses[MAX_FUNCTIONS]; + char **symbols; + int n; + int i; +@@ -70,23 +75,28 @@ handle_signal (int signum) + return; + } + +- /* Do not check name for signal trampoline or cancellable syscall +- wrappers (__syscall_cancel*). */ +- for (; i < n - 1; i++) ++ /* Skip the signal trampoline and any cancellable syscall wrapper frames ++ (__syscall_cancel*) and require the read syscall wrapper to be ++ present. */ ++ for (i = 1; i < n; i++) + if (match (symbols[i], "read")) + break; +- if (i == n - 1) ++ if (i == n) + { + FAIL (); + return; + } + +- for (; i < n - 1; i++) +- if (!match (symbols[i], "fn")) +- { +- FAIL (); +- return; +- } ++ /* The read wrapper must be followed by the three fn recursion frames. */ ++ for (int j = 0; j < 3; j++) ++ { ++ i++; ++ if (i == n || !match (symbols[i], "fn")) ++ { ++ FAIL (); ++ return; ++ } ++ } + /* Symbol names are not available for static functions, so we do not + check do_test. */ + +diff --git a/elf/Makefile b/elf/Makefile +index 94c5b7e6ed..8b063e1bba 100644 +--- a/elf/Makefile ++++ b/elf/Makefile +@@ -1574,7 +1574,9 @@ $(objpfx)dl-allobjs.os: $(all-rtld-routines:%=$(objpfx)%.os) + # when compiled for libc. + rtld-stubbed-symbols = \ + __libc_assert_fail \ +- __syscall_cancel \ ++ __libc_single_threaded_internal \ ++ __syscall_cancel_arch \ ++ __syscall_do_cancel \ + calloc \ + free \ + malloc \ +diff --git a/nptl/cancellation.c b/nptl/cancellation.c +index 4368cb7231..63f09840ff 100644 +--- a/nptl/cancellation.c ++++ b/nptl/cancellation.c +@@ -19,66 +19,6 @@ + #include + #include "pthreadP.h" + +-/* Called by the INTERNAL_SYSCALL_CANCEL macro, check for cancellation and +- returns the syscall value or its negative error code. */ +-long int +-__internal_syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, +- __syscall_arg_t a3, __syscall_arg_t a4, +- __syscall_arg_t a5, __syscall_arg_t a6, +- __SYSCALL_CANCEL7_ARG_DEF +- __syscall_arg_t nr) +-{ +- long int result; +- struct pthread *pd = THREAD_SELF; +- +- /* If cancellation is not enabled, call the syscall directly and also +- for thread terminatation to avoid call __syscall_do_cancel while +- executing cleanup handlers. */ +- int ch = atomic_load_relaxed (&pd->cancelhandling); +- if (SINGLE_THREAD_P || !cancel_enabled (ch) || cancel_exiting (ch)) +- { +- result = INTERNAL_SYSCALL_NCS_CALL (nr, a1, a2, a3, a4, a5, a6 +- __SYSCALL_CANCEL7_ARCH_ARG7); +- if (INTERNAL_SYSCALL_ERROR_P (result)) +- return -INTERNAL_SYSCALL_ERRNO (result); +- return result; +- } +- +- /* Call the arch-specific entry points that contains the globals markers +- to be checked by SIGCANCEL handler. */ +- result = __syscall_cancel_arch (&pd->cancelhandling, nr, a1, a2, a3, a4, a5, +- a6 __SYSCALL_CANCEL7_ARCH_ARG7); +- +- /* If the cancellable syscall was interrupted by SIGCANCEL and it has no +- side-effect, cancel the thread if cancellation is enabled. */ +- ch = atomic_load_relaxed (&pd->cancelhandling); +- /* The behaviour here assumes that EINTR is returned only if there are no +- visible side effects. POSIX Issue 7 has not yet provided any stronger +- language for close, and in theory the close syscall could return EINTR +- and leave the file descriptor open (conforming and leaks). It expects +- that no such kernel is used with glibc. */ +- if (result == -EINTR && cancel_enabled_and_canceled (ch)) +- __syscall_do_cancel (); +- +- return result; +-} +- +-/* Called by the SYSCALL_CANCEL macro, check for cancellation and return the +- syscall expected success value (usually 0) or, in case of failure, -1 and +- sets errno to syscall return value. */ +-long int +-__syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, +- __syscall_arg_t a3, __syscall_arg_t a4, +- __syscall_arg_t a5, __syscall_arg_t a6, +- __SYSCALL_CANCEL7_ARG_DEF __syscall_arg_t nr) +-{ +- long int r = __internal_syscall_cancel (a1, a2, a3, a4, a5, a6, +- __SYSCALL_CANCEL7_ARG nr); +- return __glibc_unlikely (INTERNAL_SYSCALL_ERROR_P (r)) +- ? SYSCALL_ERROR_LABEL (INTERNAL_SYSCALL_ERRNO (r)) +- : r; +-} +- + /* Called by __syscall_cancel_arch or function above start the thread + cancellation. */ + _Noreturn void +diff --git a/nptl/futex-internal.c b/nptl/futex-internal.c +index fc6b11c8ad..07f1462abe 100644 +--- a/nptl/futex-internal.c ++++ b/nptl/futex-internal.c +@@ -17,7 +17,7 @@ + . */ + + #include +-#include ++#include + #include + #include + #include +diff --git a/nptl/sem_waitcommon.c b/nptl/sem_waitcommon.c +index b0cbe5cebf..82c686f020 100644 +--- a/nptl/sem_waitcommon.c ++++ b/nptl/sem_waitcommon.c +@@ -18,7 +18,7 @@ + + #include + #include +-#include ++#include + #include + #include + #include +diff --git a/sysdeps/unix/sysdep.h b/sysdeps/unix/sysdep.h +index a6ce5348ec..f0f271ec02 100644 +--- a/sysdeps/unix/sysdep.h ++++ b/sysdeps/unix/sysdep.h +@@ -154,42 +154,31 @@ + # define __SYSCALL_CANCEL7_ARG7 + # define __SYSCALL_CANCEL7_ARCH_ARG7 + #endif +-long int __internal_syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, +- __syscall_arg_t a3, __syscall_arg_t a4, +- __syscall_arg_t a5, __syscall_arg_t a6, +- __SYSCALL_CANCEL7_ARG_DEF +- __syscall_arg_t nr) attribute_hidden; +- +-long int __syscall_cancel (__syscall_arg_t arg1, __syscall_arg_t arg2, +- __syscall_arg_t arg3, __syscall_arg_t arg4, +- __syscall_arg_t arg5, __syscall_arg_t arg6, +- __SYSCALL_CANCEL7_ARG_DEF +- __syscall_arg_t nr) attribute_hidden; + + #define __SYSCALL_CANCEL0(name) \ +- __syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL1(name, a1) \ +- __syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL2(name, a1, a2) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL3(name, a1, a2, a3) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL4(name, a1, a2, a3, a4) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC(a4), 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC(a4), 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL5(name, a1, a2, a3, a4, a5) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC(a4), \ +- __SSC (a5), 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC(a4), \ ++ __SSC (a5), 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL6(name, a1, a2, a3, a4, a5, a6) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ +- __SSC (a5), __SSC (a6), __SYSCALL_CANCEL7_ARG \ +- __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ ++ __SSC (a5), __SSC (a6), __SYSCALL_CANCEL7_ARG \ ++ __NR_##name) + #define __SYSCALL_CANCEL7(name, a1, a2, a3, a4, a5, a6, a7) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ +- __SSC (a5), __SSC (a6), __SSC (a7), __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ ++ __SSC (a5), __SSC (a6), __SSC (a7), __NR_##name) + + #define __SYSCALL_CANCEL_NARGS_X(a,b,c,d,e,f,g,h,n,...) n + #define __SYSCALL_CANCEL_NARGS(...) \ +@@ -206,33 +195,33 @@ long int __syscall_cancel (__syscall_arg_t arg1, __syscall_arg_t arg2, + __SYSCALL_CANCEL_DISP (__SYSCALL_CANCEL, __VA_ARGS__) + + #define __INTERNAL_SYSCALL_CANCEL0(name) \ +- __internal_syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG \ ++ internal_syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG \ + __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL1(name, a1) \ +- __internal_syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL2(name, a1, a2) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL3(name, a1, a2, a3) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, \ +- 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, \ ++ 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL4(name, a1, a2, a3, a4) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC(a4), 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC(a4), 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL5(name, a1, a2, a3, a4, a5) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC(a4), __SSC (a5), 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC(a4), __SSC (a5), 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL6(name, a1, a2, a3, a4, a5, a6) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC (a4), __SSC (a5), __SSC (a6), \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC (a4), __SSC (a5), __SSC (a6), \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL7(name, a1, a2, a3, a4, a5, a6, a7) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC (a4), __SSC (a5), __SSC (a6), \ +- __SSC (a7), __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC (a4), __SSC (a5), __SSC (a6), \ ++ __SSC (a7), __NR_##name) + + /* Issue a cancellable syscall defined by syscall number NAME plus any other + argument required. If an error occurs its value is returned as an negative +diff --git a/sysdeps/unix/sysv/linux/epoll_pwait2.c b/sysdeps/unix/sysv/linux/epoll_pwait2.c +index 4da03e3e69..76ec1f8a71 100644 +--- a/sysdeps/unix/sysv/linux/epoll_pwait2.c ++++ b/sysdeps/unix/sysv/linux/epoll_pwait2.c +@@ -17,7 +17,7 @@ + . */ + + #include +-#include ++#include + + int + __epoll_pwait2_time64 (int fd, struct epoll_event *ev, int maxev, +diff --git a/sysdeps/unix/sysv/linux/recvmmsg.c b/sysdeps/unix/sysv/linux/recvmmsg.c +index 6fbe4b80aa..6a89f914c2 100644 +--- a/sysdeps/unix/sysv/linux/recvmmsg.c ++++ b/sysdeps/unix/sysv/linux/recvmmsg.c +@@ -16,7 +16,7 @@ + . */ + + #include +-#include ++#include + #include + + static int +diff --git a/sysdeps/unix/sysv/linux/sigtimedwait.c b/sysdeps/unix/sysv/linux/sigtimedwait.c +index a4fa8e9e8e..c2c5e2c0f2 100644 +--- a/sysdeps/unix/sysv/linux/sigtimedwait.c ++++ b/sysdeps/unix/sysv/linux/sigtimedwait.c +@@ -16,7 +16,7 @@ + . */ + + #include +-#include ++#include + + int + __sigtimedwait64 (const sigset_t *set, siginfo_t *info, +diff --git a/sysdeps/unix/sysv/linux/sysdep-cancel.h b/sysdeps/unix/sysv/linux/sysdep-cancel.h +index 7fd8258ba5..4b7278915a 100644 +--- a/sysdeps/unix/sysv/linux/sysdep-cancel.h ++++ b/sysdeps/unix/sysv/linux/sysdep-cancel.h +@@ -21,5 +21,66 @@ + #define _SYSDEP_CANCEL_H + + #include ++#include "pthreadP.h" ++ ++/* Called by the INTERNAL_SYSCALL_CANCEL macro, check for cancellation and ++ returns the syscall value or its negative error code. */ ++static __always_inline long int ++internal_syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, ++ __syscall_arg_t a3, __syscall_arg_t a4, ++ __syscall_arg_t a5, __syscall_arg_t a6, ++ __SYSCALL_CANCEL7_ARG_DEF ++ __syscall_arg_t nr) ++{ ++ long int result; ++ struct pthread *pd = THREAD_SELF; ++ ++ /* If cancellation is not enabled, call the syscall directly and also ++ for thread terminatation to avoid call __syscall_do_cancel while ++ executing cleanup handlers. */ ++ int ch = atomic_load_relaxed (&pd->cancelhandling); ++ if (SINGLE_THREAD_P || !cancel_enabled (ch) || cancel_exiting (ch)) ++ { ++ result = INTERNAL_SYSCALL_NCS_CALL (nr, a1, a2, a3, a4, a5, a6 ++ __SYSCALL_CANCEL7_ARCH_ARG7); ++ if (INTERNAL_SYSCALL_ERROR_P (result)) ++ return -INTERNAL_SYSCALL_ERRNO (result); ++ return result; ++ } ++ ++ /* Call the arch-specific entry points that contains the globals markers ++ to be checked by SIGCANCEL handler. */ ++ result = __syscall_cancel_arch (&pd->cancelhandling, nr, a1, a2, a3, a4, a5, ++ a6 __SYSCALL_CANCEL7_ARCH_ARG7); ++ ++ /* If the cancellable syscall was interrupted by SIGCANCEL and it has no ++ side-effect, cancel the thread if cancellation is enabled. */ ++ ch = atomic_load_relaxed (&pd->cancelhandling); ++ /* The behaviour here assumes that EINTR is returned only if there are no ++ visible side effects. POSIX Issue 7 has not yet provided any stronger ++ language for close, and in theory the close syscall could return EINTR ++ and leave the file descriptor open (conforming and leaks). It expects ++ that no such kernel is used with glibc. */ ++ if (result == -EINTR && cancel_enabled_and_canceled (ch)) ++ __syscall_do_cancel (); ++ ++ return result; ++} ++ ++/* Called by the SYSCALL_CANCEL macro, check for cancellation and return the ++ syscall expected success value (usually 0) or, in case of failure, -1 and ++ sets errno to syscall return value. */ ++static __always_inline long int ++syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, ++ __syscall_arg_t a3, __syscall_arg_t a4, ++ __syscall_arg_t a5, __syscall_arg_t a6, ++ __SYSCALL_CANCEL7_ARG_DEF __syscall_arg_t nr) ++{ ++ long int r = internal_syscall_cancel (a1, a2, a3, a4, a5, a6, ++ __SYSCALL_CANCEL7_ARG nr); ++ return __glibc_unlikely (INTERNAL_SYSCALL_ERROR_P (r)) ++ ? SYSCALL_ERROR_LABEL (INTERNAL_SYSCALL_ERRNO (r)) ++ : r; ++} + + #endif + +commit 5d1e923ed79185668ac62d19fc37e7e23a3642b6 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:55 2026 -0300 + + Fix gen-as-const-headers races with the parallel subdir recursion (BZ 34438) + + The parallel subdirectory recursion (commit 7cac99621e96) only orders + csu (and mach/hurd on Hurd) before the parallel fan-out plus the edges + the Depend files request. A header generated from gen-as-const-headers + is only ordered before the compilations of the subdirectory that + adds the .sym (through before-compile), so a header consumed by a + different subdirectory may not exist yet when its consumer is + compiled. + + That is the case for : it is generated when + building misc, while its only consumer, ____longjmp_chk.S (x86_64 and + sh), is built in debug. The serial recursion always ran misc before + debug in the sorted order, hiding the missing dependency. + + Move the generate the header to 'debug' instead. + + The same class of problem exists on Hurd: jmp_buf-ssp.h that is used + by ____longjmp_chk.S in debug, and signal-defines.h that is sued + by debug and setjmp. + + Deterministically reproduced with 'make debug/subdir_lib' from a clean + build tree (which orders only csu before debug), and verified with + builds for x86_64-linux-gnu, sh4-linux-gnu, i686-gnu, and x86_64-gnu. + Reviewed-by: Sam James + + (cherry picked from commit 60c9ed0e6b9cce07e85ee56fc39b9afe36919e45) + +diff --git a/Makerules b/Makerules +index 6bef57ece9..cef30974f1 100644 +--- a/Makerules ++++ b/Makerules +@@ -259,7 +259,17 @@ endif # gen-py-const-headers + ifdef gen-as-const-headers + # Generating headers for assembly constants. + # We need this defined early to get into before-compile before +-# it's used in sysd-rules, below. ++# it's used in sysd-rules, below. The gen-as-const-headers is evaluated ++# per subdirectory, so the before-compile dependency below only orders ++# the generated header before the compiles of the subdirectory whose ++# Makefile adds the .sym directive. ++# The parallel subdirectory recursion does not order sibling subdirectories, ++# so a .sym must be added in the subdirectory that compiles its consumers, ++# or in csu (which runs before the parallel) when it has consumers in ++# several subdirectories. ++# It must not add the same .sym in several subdirectories though: their ++# concurrent sub-makes would race generating the header through the fixed ++# temporary files below. + # Define GEN_AS_CONST_HEADERS to avoid circular dependency [BZ #22792]. + # NB: is generated from tcb-offsets.sym to define + # offsets and sizes of types in and maybe which +diff --git a/NEWS b/NEWS +index 28fbd9bcd8..ee292ff6c9 100644 +--- a/NEWS ++++ b/NEWS +@@ -11,6 +11,8 @@ The following bugs are resolved with this release: + + [34338] libc: Cancellable syscall wrappers are missing from backtraces + because they tail-call __syscall_cancel ++ [34438] build: non reproducible build failure: sigaltstack-offsets.h: ++ No such file or directory + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong +diff --git a/sysdeps/mach/hurd/x86/Makefile b/sysdeps/mach/hurd/x86/Makefile +index 97e3287c87..1d94f3a1c1 100644 +--- a/sysdeps/mach/hurd/x86/Makefile ++++ b/sysdeps/mach/hurd/x86/Makefile +@@ -3,11 +3,7 @@ sysdep_routines += ioperm + sysdep_headers += sys/io.h + endif + +-ifeq ($(subdir),debug) +-gen-as-const-headers += signal-defines.sym +-endif +- +-ifeq ($(subdir),setjmp) ++ifeq ($(subdir),csu) + gen-as-const-headers += signal-defines.sym + endif + +diff --git a/sysdeps/unix/sysv/linux/sh/Makefile b/sysdeps/unix/sysv/linux/sh/Makefile +index dd3b382ac1..8c4cb73824 100644 +--- a/sysdeps/unix/sysv/linux/sh/Makefile ++++ b/sysdeps/unix/sysv/linux/sh/Makefile +@@ -6,7 +6,9 @@ ifeq ($(subdir),stdlib) + gen-as-const-headers += ucontext_i.sym + endif + +-ifeq ($(subdir),misc) ++# is only used by ____longjmp_chk.S, which is ++# built in the debug subdirectory. ++ifeq ($(subdir),debug) + gen-as-const-headers += sigaltstack-offsets.sym + endif + +diff --git a/sysdeps/unix/sysv/linux/x86_64/Makefile b/sysdeps/unix/sysv/linux/x86_64/Makefile +index 6938382801..528fd951b2 100644 +--- a/sysdeps/unix/sysv/linux/x86_64/Makefile ++++ b/sysdeps/unix/sysv/linux/x86_64/Makefile +@@ -10,7 +10,9 @@ ifeq ($(subdir),csu) + gen-as-const-headers += ucontext_i.sym + endif + +-ifeq ($(subdir),misc) ++# is only used by ____longjmp_chk.S, which is ++# built in the debug subdirectory. ++ifeq ($(subdir),debug) + gen-as-const-headers += sigaltstack-offsets.sym + endif + +diff --git a/sysdeps/x86/Makefile b/sysdeps/x86/Makefile +index 232e388d32..b4434deb0c 100644 +--- a/sysdeps/x86/Makefile ++++ b/sysdeps/x86/Makefile +@@ -1,5 +1,12 @@ + ifeq ($(subdir),csu) +-gen-as-const-headers += cpu-features-offsets.sym features-offsets.sym ++# is used by the setjmp/longjmp implementations in the ++# setjmp subdirectory and also by ____longjmp_chk.S in the debug ++# subdirectory. ++gen-as-const-headers += \ ++ cpu-features-offsets.sym \ ++ features-offsets.sym \ ++ jmp_buf-ssp.sym \ ++ # gen-as-const-headers + endif + + ifeq ($(subdir),elf) +@@ -171,7 +178,6 @@ tests += \ + endif # $(subdir) == math + + ifeq ($(subdir),setjmp) +-gen-as-const-headers += jmp_buf-ssp.sym + sysdep_routines += __longjmp_cancel + endif + + +commit 45b8a13c48da92bc5dd6fe102011391dd6847862 +Author: Rudi Heitbaum +Date: Thu Aug 6 14:07:56 2026 -0300 + + Makerules: Only install the ABI lib-names header from the top level (BZ 34439) + + The $(inst_includedir)/%.h install rules exist only where $(headers) is + non-empty, so in a subdir without headers (e.g. csu) the prerequisite + added on install-others-nosubdir has no rule. + + It only worked because .NOTPARALLEL made the top level install the header + first, which the parallel subdir recursion no longer guarantees. + Reviewed-by: Sam James + + (cherry picked from commit 82c0a96b8e63005a49ba52ddb21993811030613f) + +diff --git a/Makerules b/Makerules +index cef30974f1..dfe66b7fa6 100644 +--- a/Makerules ++++ b/Makerules +@@ -312,7 +312,12 @@ lib-names-h-abi = gnu/lib-names-$(default-abi).h + lib-names-stmp-abi = gnu/lib-names-$(default-abi).stmp + before-compile += $(common-objpfx)$(lib-names-h-abi) + common-generated += gnu/lib-names.h ++# The $(inst_includedir)/%.h install rules are defined only where $(headers) ++# is non-empty, and with parallel subdir recursion a subdir without headers ++# (e.g. csu) may run before the top level has installed the header. ++ifndef subdir + install-others-nosubdir: $(inst_includedir)/$(lib-names-h-abi) ++endif + $(common-objpfx)gnu/lib-names.h: + $(make-target-directory) + { \ +diff --git a/NEWS b/NEWS +index ee292ff6c9..d0ef2d3e9a 100644 +--- a/NEWS ++++ b/NEWS +@@ -13,6 +13,8 @@ The following bugs are resolved with this release: + because they tail-call __syscall_cancel + [34438] build: non reproducible build failure: sigaltstack-offsets.h: + No such file or directory ++ [34439] build: parallel make install fails on multi-ABI targets: no ++ rule to make $(inst_includedir)/gnu/lib-names-$(abi).h in csu + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong + +commit f7beb24f3ad5dbf8e84a5b75d5b2428a262e9ab9 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:57 2026 -0300 + + Makefile: Only print the test summary in the second pass of 'make check' + + The build-only first pass of the two-pass 'make check' still runs the + static checks (abi, conformtest, installed headers, etc.), and the + top-level tests recipe merged and summarized their results. + + An unexpected FAIL there (e.g. check-abi) aborted 'check' before the + second pass ran any built test, and even a clean run printed a misleading + partial summary. + + Pass tests-summary=no in the first pass to skip the merge and summary; + the .test-result files persist, so the second pass folds those results + into the one complete summary at the end, restoring the single-pass + reporting behavior. + Reviewed-by: Sam James + + (cherry picked from commit 96a9a09d7d5527462a823c247569e65feeca8ddb) + +diff --git a/Makefile b/Makefile +index a6aabca691..b9fac6f47c 100644 +--- a/Makefile ++++ b/Makefile +@@ -869,7 +869,11 @@ endif + touch $(objpfx)testroot.pristine/install.stamp + + tests-special-notdir = $(patsubst $(objpfx)%, %, $(tests-special)) ++# The build-only first pass of the two-pass 'make check' (see Makerules) ++# passes tests-summary=no: the merge and summary are left to the second ++# pass, which folds in this pass's $(tests-special) results. + tests: $(tests-special) ++ifneq ($(tests-summary),no) + $(..)scripts/merge-test-results.sh -s $(objpfx) "" \ + $(sort $(tests-special-notdir:.out=)) \ + > $(objpfx)subdir-tests.sum +@@ -877,11 +881,14 @@ tests: $(tests-special) + $(sort $(subdirs) .) \ + > $(objpfx)tests.sum + $(call summarize-tests,tests.sum) ++endif + xtests: ++ifneq ($(tests-summary),no) + $(..)scripts/merge-test-results.sh -t $(objpfx) subdir-xtests.sum \ + $(sort $(subdirs)) \ + > $(objpfx)xtests.sum + $(call summarize-tests,xtests.sum, for extra tests) ++endif + + # The realclean target is just like distclean for the parent, but we want + # the subdirs to know the difference in case they care. +diff --git a/Makerules b/Makerules +index dfe66b7fa6..5f65f3ab9e 100644 +--- a/Makerules ++++ b/Makerules +@@ -1211,6 +1211,13 @@ ALL_BUILD_CFLAGS = $(BUILD_CFLAGS) $(BUILD_CPPFLAGS) -D_GNU_SOURCE \ + # therefore builds the test programs (run-built-tests=no, recursion fully + # parallel) and then runs them (run-built-tests=yes). 'make tests' and a + # subdirectory's own 'check' stay single-pass. ++# The first pass still runs the static checks ($(tests-special): abi, ++# conformtest, installed headers, ...), so tests-summary=no makes it skip ++# the results merge and summary: an unexpected FAIL there would otherwise ++# abort 'check' before the second pass runs any built test, and even a ++# clean run would print a misleading partial summary. The .test-result ++# files persist, so the second pass folds those results into the one ++# complete summary at the end. + check-twopass := + ifndef subdir + ifeq (yes,$(run-built-tests)) +@@ -1219,10 +1226,10 @@ endif + endif + ifeq (yes,$(check-twopass)) + check: +- $(MAKE) run-built-tests=no tests ++ $(MAKE) run-built-tests=no tests-summary=no tests + $(MAKE) run-built-tests=yes tests + xcheck: +- $(MAKE) run-built-tests=no xtests ++ $(MAKE) run-built-tests=no tests-summary=no xtests + $(MAKE) run-built-tests=yes xtests + else + check: tests + +commit fc3641194619c7c327ef398c88c07b3069878ed3 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:58 2026 -0300 + + Makerules: Make the .dt to .d conversion safe against concurrent sub-makes + + The %.d: %.dt rule seds its input into a fixed temporary name, renames + it into place and removes the input. Two makes converting the same + file trip over each other: + + mv: cannot stat '.../test-double-libmvec-sincos-avx512f.o.T': No such file or directory + sed: can't read .../test-float-libmvec-acosf-avx512f.o.dt: No such file or directory + + That happens because the elf rtld-Rules recursion runs a sub-make over + every $(rtld-subdirs) directory, which converts that directory's .dt + files, and the parallel subdirectory recursion (commit 7cac99621e96) + runs it concurrently with those subdirectories' own sub-makes. + + Add the PID of the shell to the temporary name and claim the input with + a rename: only the run that wins converts and installs the target. + Reviewed-by: Sam James + + (cherry picked from commit ba8c8801be7674cc12406914184516a811ac22a8) + +diff --git a/Makerules b/Makerules +index 5f65f3ab9e..be51154bae 100644 +--- a/Makerules ++++ b/Makerules +@@ -758,10 +758,20 @@ all-dt-files := $(foreach o,$(object-suffixes-for-libc),$(+depfiles:.d=$o.dt)) + $(wildcard $(all-dt-files:.dt=.d)) + + # This is a funny rule in that it removes its input file. ++# ++# More than one make can convert the .dt files of a single object ++# directory: the elf rtld-Rules recursion runs a sub-make over every ++# $(rtld-subdirs) directory, concurrently with that directory's own ++# sub-make under the parallel subdir recursion. Add the PID of the ++# shell to the temporary name and claim the input with a rename: only ++# the run that wins converts and installs the target. + %.d: %.dt +- @sed $(sed-remove-objpfx) $< > $(@:.d=.T) && \ +- mv -f $(@:.d=.T) $@ && \ +- rm -f $< ++ @dt=$(@:.d=.T)$$$$; \ ++ if mv -f $< $$dt 2>/dev/null; then \ ++ sed $(sed-remove-objpfx) $$dt > $$dt.new && \ ++ mv -f $$dt.new $@ && \ ++ rm -f $$dt; \ ++ fi + + # Avoid the .h.d files for any .sym files whose .h files don't exist yet. + # They will be generated when they're needed, and trying too early won't work. +@@ -1433,7 +1443,7 @@ endef + # Also remove the dependencies and generated source files. + common-clean: common-mostlyclean + -rm -f $(addprefix $(objpfx),$(generated)) +- -rm -f $(objpfx)*.d $(objpfx)*.dt ++ -rm -f $(objpfx)*.d $(objpfx)*.dt $(objpfx)*.T[0-9]* + -rm -fr $(addprefix $(objpfx),$(generated-dirs)) + -rm -f $(addprefix $(common-objpfx),$(common-generated)) + -rm -f $(gen-as-const-headers:%.sym=$(common-objpfx)%.h) + +commit f34027b27fefbc94aab04bff613ba5c24fb909b1 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:59 2026 -0300 + + Makefile: Order the top-level stamp files before the subdirectory fan-out + + The archive rules in Makerules list every stamp file as a prerequisite, + including the top level's own, and the elf sub-make evaluates them to + build libc_pic.a for the librtld.map link. A sub-make can only create + the stamp files of its own directory, so when the top-level ones do not + exist yet it fails with: + + make[2]: *** No rule to make target '.../stamp.os', needed by + '.../libc_pic.a'. Stop. + + The serial recursion created them before the subdirectories through the + prerequisite order of subdir_lib; the parallel recursion (commit + 7cac99621e96) does not. Add them as prerequisites of the object-building + per-subdirectory targets. + Reviewed-by: Sam James + + (cherry picked from commit 25c42d04c45fc5fdb1481a7f968782791b21fd3e) + +diff --git a/Makefile b/Makefile +index b9fac6f47c..d559c42873 100644 +--- a/Makefile ++++ b/Makefile +@@ -575,6 +575,14 @@ $(foreach t,$(+elf_last_subdir_targets),$(eval \ + elf/$(t): $(addsuffix /$(t),$(filter-out elf,$(subdirs))))) + endif + ++# The archive rules in Makerules list every stamp file as a ++# prerequisite of libc_pic.a, which the elf sub-make evaluates for the ++# librtld.map link, but a sub-make can only create its own directory's ++# stamps. Create the top-level ones before the fan-out. ++$(foreach t,$(+elf_last_subdir_targets),$(eval \ ++ $(addsuffix /$(t),$(subdirs)): \ ++ $(foreach o,$(object-suffixes-for-libc),$(common-objpfx)stamp$(o)))) ++ + # Pass barriers: a subdirectory 'others' build links programs against + # the libraries, so the 'lib' pass (including the top-level libc.so + # link) must have completed. + +commit 10e3ce8a57e134c13dd28772de68542b0e3d4e86 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:08:00 2026 -0300 + + arm: Order the rtld link after libgcc-stubs.a + + The librtld.map and librtld.os link recipes use $(gnulib), which on arm + contains libgcc-stubs.a through gnulib-arch. But the archive is only a + prerequisite of lib-noranlib so the rtld link can run before the archive + exists: + + ld.bfd: cannot find .../elf/libgcc-stubs.a: No such file or directory + + The race seems to predates the parallel subdirectory recursion, which + only made it observable. + + Add the order-only dependency in sysdeps/arm/Makefile rather than in + elf/Makefile. Theprerequisite lists expand when the rule is parsed, + and gnulib-arch is only defined once Makerules includes the sysdeps + makefiles. + + Verified with a build for arm-linux-gnueabihf. + Reviewed-by: Sam James + + (cherry picked from commit a33ceb6e96dc8de8d36de1b1f3ec06ceb524d012) + +diff --git a/sysdeps/arm/Makefile b/sysdeps/arm/Makefile +index 0bb1b6e05b..9042315492 100644 +--- a/sysdeps/arm/Makefile ++++ b/sysdeps/arm/Makefile +@@ -10,6 +10,11 @@ shared-only-routines += aeabi_unwind_cpp_pr1 + $(objpfx)libgcc-stubs.a: $(objpfx)aeabi_unwind_cpp_pr1.os + $(build-extra-lib) + ++# The rtld link recipes in elf/Makefile use $(gnulib), which here ++# includes libgcc-stubs.a, but they cannot name it as a prerequisite: ++# gnulib-arch is only defined once this file is included from Makerules. ++$(objpfx)librtld.map $(objpfx)librtld.os: | $(objpfx)libgcc-stubs.a ++ + lib-noranlib: $(objpfx)libgcc-stubs.a + + ifeq ($(build-shared),yes) + +commit 26b9cc42a051f78233fcecd2a3b83f98ec9862b9 +Author: Adhemerval Zanella +Date: Tue Jul 28 11:27:33 2026 -0300 + + benchtests: Create objdir in the bench-%.c generation rule + + The $(objpfx)bench-%.c rule writes its output into $(objpfx) without + ensuring that directory exists. Serial builds happened to satisfy + that ordering, with parallel builds the generation recipe can + run before the directory is created, failing with: + + cannot create .../benchtests/bench-xxx.c-tmp: Directory nonexistent + + Add the standard $(make-target-directory). + + Reviewed-by: Florian Weimer + (cherry picked from commit 26f0f2aa7d6ea63f85b5186349c41de2c91b4dd7) + +diff --git a/benchtests/Makefile b/benchtests/Makefile +index f407e492cb..16cc951d19 100644 +--- a/benchtests/Makefile ++++ b/benchtests/Makefile +@@ -622,6 +622,7 @@ $(bench-link-targets): %: %.o $(objpfx)json-lib.o \ + $(bench-link-targets): LDFLAGS += $(link-bench-bind-now) + + $(objpfx)bench-%.c: %-inputs $(bench-deps) ++ $(make-target-directory) + { if [ -n "$($*-INCLUDE)" ]; then \ + cat $($*-INCLUDE); \ + fi; \ + +commit 4662c4675d7f3ba87637c61730f06071f305c5cb +Author: Xi Ruoyao +Date: Sun Jul 26 00:11:44 2026 +0800 + + elf: test: handle different rootsbindir in tst-ldconfig-cache + + When compiling a glibc for a merged-/usr distro people may set + rootsbindir=/usr/sbin. But tst-ldconfig-cache has hard-coded + /sbin/ldconfig path and so it fails with a different rootsbindir. + + Fix it by using support_install_rootsbindir like run_ldconfig in + test-container.c. + + Signed-off-by: Xi Ruoyao + Reviewed-by: Florian Weimer + (cherry picked from commit 02ea17b5add83a205d8b204dce28f38fe0498ea3) + +diff --git a/elf/tst-ldconfig-cache.c b/elf/tst-ldconfig-cache.c +index 9f71418b3a..f4820a1822 100644 +--- a/elf/tst-ldconfig-cache.c ++++ b/elf/tst-ldconfig-cache.c +@@ -85,7 +85,10 @@ corrupt (void) + static void + ldconfig (void) + { +- xsystem ("/sbin/ldconfig -X"); ++ char *cmd = xasprintf("%s/ldconfig -X", support_install_rootsbindir); ++ xsystem (cmd); ++ ++ free(cmd); + } + + /* Change ld.so.conf to refer to the new directory, and generate a new + +commit 9e1b1ef77c7b1cc58f625500e9ea74fb3cafdf12 +Author: Matt Turner +Date: Sun Jul 26 00:27:37 2026 -0400 + + ldbl-opt: Fix -mlong-double-128 configure test for Clang + + The check for -mlong-double-128 support wrapped its test code in + AC_LANG_PROGRAM, which places the body inside main(). The body defines + a function, so it became a nested function definition -- a GCC extension + that Clang does not implement, making the test fail (and thus the whole + build error out) with Clang even though it supports -mlong-double-128. + + Use AC_LANG_SOURCE so the function is defined at file scope, matching the + pattern already used by the powerpc64le compiler checks, and regenerate + configure. + + Reviewed-by: Sam James + (cherry picked from commit e7a14f03b8d5e34e8ac46db6c377da5c66a3ec2a) + +diff --git a/sysdeps/ieee754/ldbl-opt/configure b/sysdeps/ieee754/ldbl-opt/configure +old mode 100644 +new mode 100755 +index bc6552da0b..7769cc9781 +--- a/sysdeps/ieee754/ldbl-opt/configure ++++ b/sysdeps/ieee754/ldbl-opt/configure +@@ -13,17 +13,10 @@ CFLAGS="$CFLAGS -mlong-double-128" + cat confdefs.h - <<_ACEOF >conftest.$ac_ext + /* end confdefs.h. */ + +-int +-main (void) +-{ +- + #ifndef __LONG_DOUBLE_128__ + # error "compiler did not predefine __LONG_DOUBLE_128__ as expected" + #endif + long double foobar (long double x) { return x; } +- ; +- return 0; +-} + _ACEOF + if ac_fn_c_try_compile "$LINENO" + then : +diff --git a/sysdeps/ieee754/ldbl-opt/configure.ac b/sysdeps/ieee754/ldbl-opt/configure.ac +index 70e3b32dc6..1c500ad581 100644 +--- a/sysdeps/ieee754/ldbl-opt/configure.ac ++++ b/sysdeps/ieee754/ldbl-opt/configure.ac +@@ -6,7 +6,7 @@ AC_CACHE_CHECK(whether $CC $CFLAGS supports -mlong-double-128, + libc_cv_mlong_double_128, [dnl + save_CFLAGS="$CFLAGS" + CFLAGS="$CFLAGS -mlong-double-128" +-AC_COMPILE_IFELSE([AC_LANG_PROGRAM([[]], [[ ++AC_COMPILE_IFELSE([AC_LANG_SOURCE([[ + #ifndef __LONG_DOUBLE_128__ + # error "compiler did not predefine __LONG_DOUBLE_128__ as expected" + #endif + +commit eacd9cced93498e671c7e7f758aaf52593847e01 +Author: Matt Turner +Date: Sun Jul 26 14:43:11 2026 -0400 + + powerpc: Fix -mlong-double-128 IBM format configure test for Clang + + The check for -mlong-double-128 IBM extended format support wrapped its + test code in AC_LANG_PROGRAM, which places the body inside main(). The + body defines a function, so it became a nested function definition -- a + GCC extension that Clang does not implement, making the test fail with + Clang. + + Use AC_LANG_SOURCE so the function is defined at file scope, and + regenerate configure. + + Reviewed-by: Sam James + (cherry picked from commit 559d0f77f3ee1000cf8a2d0baba7a59a1ec45f50) + +diff --git a/sysdeps/unix/sysv/linux/powerpc/configure b/sysdeps/unix/sysv/linux/powerpc/configure +index ef2055db92..eb8578404f 100644 +--- a/sysdeps/unix/sysv/linux/powerpc/configure ++++ b/sysdeps/unix/sysv/linux/powerpc/configure +@@ -12,18 +12,12 @@ else case e in #( + CFLAGS="$CFLAGS -mlong-double-128" + cat confdefs.h - <<_ACEOF >conftest.$ac_ext + /* end confdefs.h. */ +-#include +-int +-main (void) +-{ + ++#include + #if LDBL_MANT_DIG != 106 + # error "compiler doesn't implement IBM extended format of long double" + #endif + long double foobar (long double x) { return x; } +- ; +- return 0; +-} + _ACEOF + if ac_fn_c_try_compile "$LINENO" + then : +diff --git a/sysdeps/unix/sysv/linux/powerpc/configure.ac b/sysdeps/unix/sysv/linux/powerpc/configure.ac +index 42347a66fc..ca0f82da08 100644 +--- a/sysdeps/unix/sysv/linux/powerpc/configure.ac ++++ b/sysdeps/unix/sysv/linux/powerpc/configure.ac +@@ -6,7 +6,8 @@ AC_CACHE_CHECK(whether $CC $CFLAGS -mlong-double-128 uses IBM extended format, + libc_cv_mlong_double_128ibm, [dnl + save_CFLAGS="$CFLAGS" + CFLAGS="$CFLAGS -mlong-double-128" +-AC_COMPILE_IFELSE([AC_LANG_PROGRAM([[#include ]], [[ ++AC_COMPILE_IFELSE([AC_LANG_SOURCE([[ ++#include + #if LDBL_MANT_DIG != 106 + # error "compiler doesn't implement IBM extended format of long double" + #endif + +commit 89da37bb6e4a631f375b5fe48783e5c023441b0c +Author: Matt Turner +Date: Tue Aug 4 10:17:20 2026 -0400 + + stdio-common: run AWK in the C locale in the printf format tests + + The program under test runs in the C locale, through the test program + prefix, but AWK inherits whatever locale the build was started in. They + agree today only because the locale in use shares its decimal point with + the C locale. + + It is also faster. gawk takes a single byte path in its regular + expression engine when MB_CUR_MAX is 1, and the script matches several + expressions against every line. For the %f conversion for double, the + largest of these tests, as the median of five runs: + + x86_64, gawk 5.4.1 1.482s -> 1.248s + x86_64, gawk 5.3.2 0.911s -> 0.703s + alpha, gawk 5.4.60 30.9s -> 26.6s + + Worth noting that gawk 5.4 is a good deal slower here than 5.3 was, at + 1.248s against 0.703s for the same input in the C locale, so these tests + have become more expensive than they used to be. + + Reviewed-by: Adhemerval Zanella + (cherry picked from commit 866a70167b85903a02d4ccacb91afb8922702c14) + +diff --git a/stdio-common/tst-printf-format-c.sh b/stdio-common/tst-printf-format-c.sh +index 825c50ec42..73d28c5607 100644 +--- a/stdio-common/tst-printf-format-c.sh ++++ b/stdio-common/tst-printf-format-c.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + echo Verifying c + (set -o pipefail +diff --git a/stdio-common/tst-printf-format-char.sh b/stdio-common/tst-printf-format-char.sh +index 7867bdd62f..aa4d211126 100644 +--- a/stdio-common/tst-printf-format-char.sh ++++ b/stdio-common/tst-printf-format-char.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + +diff --git a/stdio-common/tst-printf-format-double.sh b/stdio-common/tst-printf-format-double.sh +index 8157092dc4..051e4716c5 100644 +--- a/stdio-common/tst-printf-format-double.sh ++++ b/stdio-common/tst-printf-format-double.sh +@@ -29,7 +29,7 @@ test_program_prefix=$1; shift + # internally to process the conversion requested, so any bug in our code + # would then be verified against itself, defeating the objective of doing + # the verification against an independent implementation. +-AWK="${AWK:-awk} -M" ++AWK="env LC_ALL=C ${AWK:-awk} -M" + + status=77 + +diff --git a/stdio-common/tst-printf-format-int.sh b/stdio-common/tst-printf-format-int.sh +index 8542ff4150..e9dcbedc04 100644 +--- a/stdio-common/tst-printf-format-int.sh ++++ b/stdio-common/tst-printf-format-int.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ldouble.sh b/stdio-common/tst-printf-format-ldouble.sh +index dbf78a98c6..7ee097ac0a 100644 +--- a/stdio-common/tst-printf-format-ldouble.sh ++++ b/stdio-common/tst-printf-format-ldouble.sh +@@ -29,7 +29,7 @@ test_program_prefix=$1; shift + # internally to process the conversion requested, so any bug in our code + # would then be verified against itself, defeating the objective of doing + # the verification against an independent implementation. +-AWK="${AWK:-awk} -M" ++AWK="env LC_ALL=C ${AWK:-awk} -M" + + status=77 + +diff --git a/stdio-common/tst-printf-format-llong.sh b/stdio-common/tst-printf-format-llong.sh +index e1f5252c9a..98a79660cc 100644 +--- a/stdio-common/tst-printf-format-llong.sh ++++ b/stdio-common/tst-printf-format-llong.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-long.sh b/stdio-common/tst-printf-format-long.sh +index 4b68ab1e04..89ac3302b8 100644 +--- a/stdio-common/tst-printf-format-long.sh ++++ b/stdio-common/tst-printf-format-long.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-s.sh b/stdio-common/tst-printf-format-s.sh +index 65aa0cb675..015c730609 100644 +--- a/stdio-common/tst-printf-format-s.sh ++++ b/stdio-common/tst-printf-format-s.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + echo Verifying s + (set -o pipefail +diff --git a/stdio-common/tst-printf-format-short.sh b/stdio-common/tst-printf-format-short.sh +index 30357baa02..a7df8b8e6d 100644 +--- a/stdio-common/tst-printf-format-short.sh ++++ b/stdio-common/tst-printf-format-short.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + +diff --git a/stdio-common/tst-printf-format-uchar.sh b/stdio-common/tst-printf-format-uchar.sh +index 08a6914b88..356de4217d 100644 +--- a/stdio-common/tst-printf-format-uchar.sh ++++ b/stdio-common/tst-printf-format-uchar.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + +diff --git a/stdio-common/tst-printf-format-uint.sh b/stdio-common/tst-printf-format-uint.sh +index 0ba203ccda..b496047a49 100644 +--- a/stdio-common/tst-printf-format-uint.sh ++++ b/stdio-common/tst-printf-format-uint.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ullong.sh b/stdio-common/tst-printf-format-ullong.sh +index 5b881ab924..f030f66a24 100644 +--- a/stdio-common/tst-printf-format-ullong.sh ++++ b/stdio-common/tst-printf-format-ullong.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ulong.sh b/stdio-common/tst-printf-format-ulong.sh +index f6aeb8e3c0..7102575ed2 100644 +--- a/stdio-common/tst-printf-format-ulong.sh ++++ b/stdio-common/tst-printf-format-ulong.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ushort.sh b/stdio-common/tst-printf-format-ushort.sh +index 07609128ab..5f612b5398 100644 +--- a/stdio-common/tst-printf-format-ushort.sh ++++ b/stdio-common/tst-printf-format-ushort.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + + +commit 7cc7a3a4fbf15c8a7d61a69452f754f9c352cd62 +Author: Matt Turner +Date: Mon Aug 3 21:59:44 2026 -0400 + + stdio-common: avoid repeated regexp matches in tst-printf-format.awk + + Whether the value is an infinity, a NaN or zero does not change between + the conversions applied to it, but was determined again for each one. + Determine it where the value is read. + + Also look for the '#' flag with index() before matching the expressions + that need it, and test the value first where both have to hold. + + For the %f conversion for double, in the C locale, as the median of five + runs: + + x86_64, gawk 5.4.1 1.248s -> 1.184s + x86_64, gawk 5.3.2 0.703s -> 0.708s + alpha, gawk 5.4.60 26.6s -> 25.8s + + So this only helps with the regular expression engine that gawk 5.4 + brought in; under 5.3.2 it is lost in the noise. Output and exit status + are unchanged for the e, f and g conversions for double under both + gawk versions and both locales. + + Reviewed-by: Adhemerval Zanella + (cherry picked from commit 0cc3f9b3f3f2950844bd41cc8923215cd5d97269) + +diff --git a/stdio-common/tst-printf-format.awk b/stdio-common/tst-printf-format.awk +index 5d0324c551..57bea12621 100644 +--- a/stdio-common/tst-printf-format.awk ++++ b/stdio-common/tst-printf-format.awk +@@ -32,6 +32,9 @@ BEGIN { + # non-bignum mode unless a sign has been explicitly given. Keep + # original 'val' for reporting. + value = gensub(/^(INF|NAN|inf|nan)/, "+\\1", 1, val) ++ # Neither changes between the conversions applied to this value. ++ value_infnan = value ~ /(INF|NAN|inf|nan)/ ++ value_zero = value == 0 + next + } + +@@ -52,7 +55,7 @@ BEGIN { + # Discard the '#' flag with the octal conversion if output starts with + # 0 in the absence of this flag. In that case no extra 0 is supposed + # to be produced, but gawk prepends it anyway. +- if (format ~ /#.*o/) ++ if (index(format, "#") && format ~ /#.*o/) + { + tmpfmt = gensub(/#/, "", "g", format) + tmpout = sprintf(tmpfmt, value) +@@ -62,7 +65,7 @@ BEGIN { + # Likewise with the hexadecimal conversion where zero value with the + # precision of zero is supposed to produce no characters, but gawk + # outputs 0 instead. +- else if (format ~ /#.*[Xx]/) ++ else if (index(format, "#") && format ~ /#.*[Xx]/) + { + tmpfmt = gensub(/#/, "", "g", format) + tmpout = sprintf(tmpfmt, value) +@@ -78,7 +81,7 @@ BEGIN { + # values and reprint the output produced using the string conversion, + # with the field width carried over and the relevant flags handled by + # hand. +- if (format ~ /[EFGefg]/ && value ~ /(INF|NAN|inf|nan)/) ++ if (value_infnan && format ~ /[EFGefg]/) + { + minus = format ~ /-/ ? "-" : "" + sign = value ~ /-/ ? "-" : format ~ /\+/ ? "+" : format ~ / / ? " " : "" +@@ -94,7 +97,7 @@ BEGIN { + # In that case "+" is always supposed to be produced, but with the + # precision of zero gawk in the non-bignum mode produces any padding + # requested only. +- else if (format ~ /\+.*[di]/ && value == 0) ++ else if (value_zero && format ~ /\+.*[di]/) + { + output = gensub(/^( *) $/, format ~ /-/ ? "+\\1" : "\\1+", 1, output) + output = gensub(/^$/, "+", 1, output) +@@ -103,7 +106,7 @@ BEGIN { + # conversion for zero value. In that case at least one " " is + # supposed to be produced, but with the precision of zero gawk in the + # non-bignum mode produces nothing. +- else if (format ~ / .*[di]/ && value == 0) ++ else if (value_zero && format ~ / .*[di]/) + { + output = gensub(/^$/, " ", 1, output) + } + +commit 65d35639a9d055e423345c8748908c8aa48b19b9 +Author: Magnus Lindholm +Date: Wed Aug 5 23:14:58 2026 +0200 + + string: Speed up strcmp test data initialization + + The strcmp and strncmp tests repeatedly initialize large buffers for + many combinations of lengths and alignments. The existing loops + perform a remainder operation and two individual stores for every + element. + + Generate at most max_char elements using an additive recurrence. The + recurrence produces the same sequence as the existing multiplication + and remainder expression. Expand this initial pattern using bulk + copies, and then copy the completed first buffer to the second buffer. + + This preserves the generated test data while substantially reducing + the initialization cost on slower systems. + + The change also applies to the wcscmp and wcsncmp tests, which include + the same test sources. + + Signed-off-by: Magnus Lindholm + Reviewed-by: Adhemerval Zanella + (cherry picked from commit 9b323b95567dff46b34157ac4455734633921abb) + +diff --git a/string/test-strcmp.c b/string/test-strcmp.c +index 76ccff46e2..ca52827b11 100644 +--- a/string/test-strcmp.c ++++ b/string/test-strcmp.c +@@ -156,6 +156,10 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + int exp_result) + { + size_t i; ++ size_t value = 0; ++ size_t pattern_len; ++ size_t step ++ = (23U << ((CHARBYTES - 1) * 8)) % (size_t) max_char; + + CHAR *s1, *s2; + +@@ -179,8 +183,28 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + i = align2 + CHARBYTES * (len + 2); + s2 = (CHAR *)(buf2 + ((page_size - i) / 16 * 16) + align2); + +- for (i = 0; i < len; i++) +- s1[i] = s2[i] = 1 + (23 << ((CHARBYTES - 1) * 8)) * i % max_char; ++ /* The generated sequence repeats after at most max_char elements. */ ++ pattern_len ++ = len < (size_t) max_char ? len : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) ++ { ++ s1[i] = 1 + value; ++ ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < len) ++ { ++ size_t copy = i < len - i ? i : len - i; ++ ++ MEMCPY (s1 + i, s1, copy); ++ i += copy; ++ } ++ ++ MEMCPY (s2, s1, len); + + s1[len] = s2[len] = 0; + s1[len + 1] = 23; +diff --git a/string/test-strncmp.c b/string/test-strncmp.c +index 54ada39eb2..9da0f21f60 100644 +--- a/string/test-strncmp.c ++++ b/string/test-strncmp.c +@@ -190,6 +190,9 @@ do_test_n (size_t align1, size_t align2, size_t len, size_t n, int n_in_bounds, + { + size_t i, buf_bound; + CHAR *s1, *s2, *s1_end, *s2_end; ++ size_t value = 0; ++ size_t pattern_len; ++ size_t step = (23U << ((CHARBYTES - 1) * 8)) % (size_t) max_char; + + align1 &= ~(CHARBYTES - 1); + align2 &= ~(CHARBYTES - 1); +@@ -216,8 +219,29 @@ do_test_n (size_t align1, size_t align2, size_t len, size_t n, int n_in_bounds, + s2[n] = 23; + } + +- for (i = 0; i < buf_bound; i++) +- s1[i] = s2[i] = 1 + (23 << ((CHARBYTES - 1) * 8)) * i % max_char; ++ /* The generated sequence repeats after at most max_char elements. */ ++ pattern_len ++ = buf_bound < (size_t) max_char ++ ? buf_bound : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) ++ { ++ s1[i] = 1 + value; ++ ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < buf_bound) ++ { ++ size_t copy = i < buf_bound - i ? i : buf_bound - i; ++ ++ MEMCPY (s1 + i, s1, copy); ++ i += copy; ++ } ++ ++ MEMCPY (s2, s1, buf_bound); + + s1[len] = 0; + s2[len] = 0; + +commit 11ac3d78fc5e4f7f2846002e099f773ad8ff82fc +Author: Magnus Lindholm +Date: Wed Aug 5 23:14:59 2026 +0200 + + string: Speed up strcasecmp test data initialization + + The strcasecmp and strncasecmp tests repeatedly initialize large + buffers for many combinations of lengths and alignments. The existing + loops perform a remainder operation and call toupper and tolower for + every element. + + Generate at most max_char elements using an additive recurrence and + apply the case conversions while creating this initial pattern. The + recurrence produces the same sequence as the existing multiplication + and remainder expression. Expand the completed pattern using bulk + copies. + + This preserves the generated test data and locale-dependent case + conversion while substantially reducing the initialization cost on + slower systems. + + Signed-off-by: Magnus Lindholm + Reviewed-by: Adhemerval Zanella + (cherry picked from commit c1fb5d0e6b8d292ac526974d05c5adb4c3827fb0) + +diff --git a/string/test-strcasecmp.c b/string/test-strcasecmp.c +index a5235fa1bb..d090dcbf36 100644 +--- a/string/test-strcasecmp.c ++++ b/string/test-strcasecmp.c +@@ -63,6 +63,9 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + int exp_result) + { + size_t i; ++ size_t value = 0; ++ size_t step = 23U % (size_t) max_char; ++ size_t pattern_len; + char *s1, *s2; + + if (len == 0) +@@ -80,10 +83,25 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + s1 = (char *) (buf1 + align1); + s2 = (char *) (buf2 + align2); + +- for (i = 0; i < len; i++) ++ pattern_len ++ = len < (size_t) max_char ? len : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) + { +- s1[i] = toupper (1 + 23 * i % max_char); ++ s1[i] = toupper (1 + value); + s2[i] = tolower (s1[i]); ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < len) ++ { ++ size_t copy = i < len - i ? i : len - i; ++ ++ memcpy (s1 + i, s1, copy); ++ memcpy (s2 + i, s2, copy); ++ i += copy; + } + + s1[len] = s2[len] = 0; +diff --git a/string/test-strncasecmp.c b/string/test-strncasecmp.c +index 035c680532..6b00113e66 100644 +--- a/string/test-strncasecmp.c ++++ b/string/test-strncasecmp.c +@@ -83,6 +83,9 @@ do_test (size_t align1, size_t align2, size_t n, size_t len, int max_char, + int exp_result) + { + size_t i; ++ size_t value = 0; ++ size_t step = 23U % (size_t) max_char; ++ size_t pattern_len; + char *s1, *s2; + + if (len == 0) +@@ -100,10 +103,26 @@ do_test (size_t align1, size_t align2, size_t n, size_t len, int max_char, + s1 = (char *) (buf1 + align1); + s2 = (char *) (buf2 + align2); + +- for (i = 0; i < len; i++) ++ pattern_len ++ = len < (size_t) max_char ? len : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) + { +- s1[i] = toupper (1 + 23 * i % max_char); ++ s1[i] = toupper (1 + value); + s2[i] = tolower (s1[i]); ++ ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < len) ++ { ++ size_t copy = i < len - i ? i : len - i; ++ ++ memcpy (s1 + i, s1, copy); ++ memcpy (s2 + i, s2, copy); ++ i += copy; + } + + s1[len] = s2[len] = 0; + +commit 16be1518495f1fa05481b0182c4e4c24927c62df +Author: Adhemerval Zanella +Date: Mon Aug 3 11:02:53 2026 -0300 + + elf: Honour skip_ifunc for cross-object IFUNC relocations [BZ #34428] + + Commit 63b31c05a8a ("elf: Defer all IRELATIVE relocations until after PLT + setup") dropped the skip_ifunc argument from elf_dynamic_do_Rel, assuming + the new deferred elf_dynamic_do_Rel_irelative pass handles every relocation + that may run an IFUNC resolver. That only holds for IFUNC symbols defined + in the object being relocated: a reference to an IFUNC in another object is + an ordinary JMP_SLOT or GLOB_DAT against an undefined symbol, and its IFUNC + nature is only known after symbol resolution inside elf_machine_rel. Those + relocations stay in the regular pass, which no longer propagated + skip_ifunc, so __RTLD_NOIFUNC was ignored for them. + + ldd -u forces non-lazy binding (GLRO(dl_lazy) = 0 for DL_DEBUG_UNUSED), so + the resolver was called and the diagnostic emitted: + + $ ldd -u /bin/ls + /bin/ls: Relink `' with `/usr/lib64/libc.so.6' for IFUNC symbol `__mempcpy_chk' + + ldd -r with LD_BIND_NOW is affected in the same way. + + Restore the skip_ifunc parameter and thread it through _ELF_DYNAMIC_DO_RELOC. + + This new semantic shows that ELF_DYNAMIC_RELOCATE_NOIFUNC naming is misleading + (it reads as "do not process IFUNC", yet it takes a skip_ifunc + argument). Replace it to: + + DL_RELOC_BOTH -> DL_RELOC_ALL + DL_RELOC_NOIFUNC -> DL_RELOC_NORMAL + DL_RELOC_IFUNC -> DL_RELOC_IRELATIVE + + ELF_DYNAMIC_RELOCATE_NOIFUNC and ELF_DYNAMIC_RELOCATE_IFUNC become a single + ELF_DYNAMIC_RELOCATE_PASS taking the pass as its first argument, and + ELF_DYNAMIC_DO_REL/ELF_DYNAMIC_DO_RELA take the pass instead of having three + near-identical variants each. + + Checked on x86_64-linux-gnu, and built for all supported architectures. + + Reviewed-by: Sam James + + (cherry picked from commit 2f2e9bae4093e1c3ba61250e340d3c3b99788f68) + +diff --git a/elf/Makefile b/elf/Makefile +index 8b063e1bba..d279a5135c 100644 +--- a/elf/Makefile ++++ b/elf/Makefile +@@ -1396,6 +1396,13 @@ modules-names += \ + tst-ifunc-tls-write-lib \ + tst-tls-tdata-reloc-lib \ + # modules-names ++ifeq (yes,$(have-gcc-ifunc)) ++tests += \ ++ tst-ifunc-fault-dep-bindnow \ ++ tst-ifunc-fault-dep-lazy \ ++ # tests ++modules-names += tst-ifunc-fault-mod ++endif + ifneq (no,$(have-test-mtls-descriptor)) + tests += tst-ifunc-tls-init-tlsdesc + modules-names += tst-ifunc-tls-init-tlsdesc-lib +@@ -2547,6 +2554,27 @@ $(objpfx)tst-ifunc-fault-bindnow.out: $(objpfx)tst-ifunc-fault-bindnow \ + $(objpfx)ld.so + $(tst-ifunc-fault-script) + ++LDFLAGS-tst-ifunc-fault-dep-lazy = -Wl,-z,lazy ++LDFLAGS-tst-ifunc-fault-dep-bindnow = -Wl,-z,now ++define tst-ifunc-fault-dep-script ++( $(test-wrapper) $(rtld-prefix) --verify $< \ ++ && $(test-wrapper-env) LD_TRACE_LOADED_OBJECTS=1 $(rtld-prefix) $< \ ++ && $(test-wrapper-env) LD_TRACE_LOADED_OBJECTS=1 LD_DEBUG=unused \ ++ $(rtld-prefix) $< \ ++ && $(test-wrapper-env) LD_TRACE_LOADED_OBJECTS=1 LD_WARN=yes LD_BIND_NOW=1 \ ++ $(rtld-prefix) $< \ ++) > $@; $(evaluate-test) ++endef ++$(objpfx)tst-ifunc-fault-dep-lazy: $(objpfx)tst-ifunc-fault-mod.so ++$(objpfx)tst-ifunc-fault-dep-bindnow: $(objpfx)tst-ifunc-fault-mod.so ++$(objpfx)tst-ifunc-fault-dep-lazy.out: $(objpfx)tst-ifunc-fault-dep-lazy \ ++ $(objpfx)tst-ifunc-fault-mod.so $(objpfx)ld.so ++ $(tst-ifunc-fault-dep-script) ++$(objpfx)tst-ifunc-fault-dep-bindnow.out: \ ++ $(objpfx)tst-ifunc-fault-dep-bindnow \ ++ $(objpfx)tst-ifunc-fault-mod.so $(objpfx)ld.so ++ $(tst-ifunc-fault-dep-script) ++ + LDFLAGS-tst-ifunc-plt-lib.so = -Wl,-z,lazy + + tst-ifunc-plt-bindnow-ENV = LD_BIND_NOW=1 +diff --git a/elf/dl-reloc-static-pie.c b/elf/dl-reloc-static-pie.c +index 8463e46147..5dc5a545a8 100644 +--- a/elf/dl-reloc-static-pie.c ++++ b/elf/dl-reloc-static-pie.c +@@ -80,7 +80,7 @@ _dl_relocate_static_pie (void) + + /* Relocate ourselves so we can do normal function calls and data access + using the global offset table. IRELATIVE entries are deferred. */ +- ELF_DYNAMIC_RELOCATE_NOIFUNC (main_map, NULL, 0, 0); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_NORMAL, main_map, NULL, 0, 0, 0); + + /* Initialize _r_debug_extended. */ + struct r_debug *r = _dl_debug_initialize (0, LM_ID_BASE); +@@ -98,7 +98,7 @@ void + _dl_relocate_static_pie_ifunc (void) + { + struct link_map *main_map = _dl_get_dl_main_map (); +- ELF_DYNAMIC_RELOCATE_IFUNC (main_map, NULL, 0, 0); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_IRELATIVE, main_map, NULL, 0, 0, 0); + main_map->l_relocated = 1; + } + #endif +diff --git a/elf/dl-reloc.c b/elf/dl-reloc.c +index 15a6a4cffe..fa2f41ac44 100644 +--- a/elf/dl-reloc.c ++++ b/elf/dl-reloc.c +@@ -278,7 +278,8 @@ _dl_relocate_object_no_relro (struct link_map *l, struct r_scope_elem *scope[], + IFUNC resolvers. Without this, a resolver would see the unrelocated + initialiser bytes that were placed into the slot by the early + _dl_allocate_tls_init. */ +- ELF_DYNAMIC_RELOCATE_NOIFUNC (l, scope, lazy, consider_profiling); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_NORMAL, l, scope, lazy, ++ consider_profiling, skip_ifunc); + + #ifdef SHARED + /* Re-initialise the static TLS slot with the .tdata so the IRELATIVE +@@ -291,7 +292,8 @@ _dl_relocate_object_no_relro (struct link_map *l, struct r_scope_elem *scope[], + _dl_init_static_tls (l); + #endif + +- ELF_DYNAMIC_RELOCATE_IFUNC (l, scope, lazy, skip_ifunc); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_IRELATIVE, l, scope, lazy, ++ 0, skip_ifunc); + + if ((consider_profiling || consider_symbind) + && l->l_info[DT_PLTRELSZ] != NULL) +diff --git a/elf/do-rel.h b/elf/do-rel.h +index 7702244734..c610d12dbe 100644 +--- a/elf/do-rel.h ++++ b/elf/do-rel.h +@@ -79,17 +79,23 @@ elf_dynamic_Rel_audit_symbind (struct link_map *map, + /* Perform the relocations in MAP on the running program image as specified + by RELTAG, SZTAG. If LAZY is nonzero, this is the first pass on PLT + relocations; they should be set up to call _dl_runtime_resolve, rather +- than fully resolved now. ++ than fully resolved now. If SKIP_IFUNC is nonzero no IFUNC resolver is ++ called; this is required for the trace modes (ldd -u / ldd -r), which ++ relocate objects. + +- IRELATIVE entries are always skipped (non-bootstrap); they are handled ++ IRELATIVE entries and relocations against an STT_GNU_IFUNC symbol defined ++ in MAP itself are always skipped (non-bootstrap); they are handled + separately by elf_dynamic_do_Rel_irelative after all other relocations +- for both .rel.dyn and .rel.plt have been processed. */ ++ for both .rel.dyn and .rel.plt have been processed. Relocations against ++ an IFUNC symbol defined in *another* object are not deferred, since the ++ IFUNC symbol is only known after symbol resolution, and the defining object ++ has already been relocated at this point. */ + + static inline void __attribute__ ((always_inline)) + elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + ElfW(Addr) reladdr, ElfW(Addr) relsize, + __typeof (((ElfW(Dyn) *) 0)->d_un.d_val) nrelative, +- int lazy) ++ int lazy, int skip_ifunc) + { + const ElfW(Rel) *relative = (const void *) reladdr; + const ElfW(Rel) *r = relative + nrelative; +@@ -111,7 +117,7 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + void *const r_addr_arg = (void *) (l_addr + r->r_offset); + const struct r_found_version *rversion = &map->l_versions[ndx]; + +- elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, 0); ++ elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, skip_ifunc); + } + #else /* !RTLD_BOOTSTRAP */ + #if !defined DO_RELA || !defined ELF_MACHINE_PLT_REL +@@ -126,7 +132,7 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + const ElfW (Sym) *sym = &symtab[ELFW (R_SYM) (r->r_info)]; + if (elf_dynamic_is_Rel_irelative (r, sym)) + continue; +- elf_machine_lazy_rel (map, scope, l_addr, r, 0); ++ elf_machine_lazy_rel (map, scope, l_addr, r, skip_ifunc); + } + } + else +@@ -158,7 +164,8 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + + if (elf_dynamic_is_Rel_irelative (r, sym)) + continue; +- elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, 0); ++ elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, ++ skip_ifunc); + elf_dynamic_Rel_audit_symbind (map, scope, r, sym, rversion, + r_addr_arg); + } +@@ -172,7 +179,8 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + + if (elf_dynamic_is_Rel_irelative (r, sym)) + continue; +- elf_machine_rel (map, scope, r, sym, NULL, r_addr_arg, 0); ++ elf_machine_rel (map, scope, r, sym, NULL, r_addr_arg, ++ skip_ifunc); + elf_dynamic_Rel_audit_symbind (map, scope, r, sym, NULL, + r_addr_arg); + } +diff --git a/elf/dynamic-link.h b/elf/dynamic-link.h +index 35141acec4..0130c63feb 100644 +--- a/elf/dynamic-link.h ++++ b/elf/dynamic-link.h +@@ -78,18 +78,23 @@ elf_machine_lazy_rel (struct link_map *map, struct r_scope_elem *scope[], + consumes precisely the very end of the DT_REL*, or DT_JMPREL and DT_REL* + are completely separate and there is a gap between them. */ + +-/* This controls which sub-passes _ELF_DYNAMIC_DO_RELOC runs. Used to +- interleave TLS / stack-protector setup between the two passes so IFUNC +- resolvers see a fully-initialised TCB. */ +-enum elf_dynamic_reloc_phase ++/* Selects which relocations a pass processes. Splitting them allows the ++ caller to interleave TLS / stack-protector setup between the two passes, ++ so IFUNC resolvers see a fully-initialised TCB. ++ ++ This is orthogonal to the skip_ifunc argument, which says whether an IFUNC ++ resolver may be run at all and is honoured by every pass. In particular ++ DL_RELOC_NORMAL also runs IFUNC resolvers, for relocations against an ++ IFUNC symbol defined in another object. */ ++enum elf_dynamic_reloc_pass + { +- DL_RELOC_BOTH = 0, /* Non-IRELATIVE pass then IRELATIVE pass. */ +- DL_RELOC_NOIFUNC = 1, /* Non-IRELATIVE pass only. */ +- DL_RELOC_IFUNC = 2, /* IRELATIVE pass only. */ ++ DL_RELOC_ALL = 0, /* Non-IRELATIVE relocations, then IRELATIVE. */ ++ DL_RELOC_NORMAL = 1, /* Non-IRELATIVE relocations only. */ ++ DL_RELOC_IRELATIVE = 2, /* IRELATIVE relocations only. */ + }; + + # define _ELF_DYNAMIC_DO_RELOC(RELOC, reloc, map, scope, do_lazy, skip_ifunc, \ +- test_rel, phase) \ ++ test_rel, pass) \ + do { \ + struct { ElfW(Addr) start, size; \ + __typeof (((ElfW(Dyn) *) 0)->d_un.d_val) nrelative; int lazy; } \ +@@ -136,14 +141,15 @@ enum elf_dynamic_reloc_phase + by the linker. */ \ + if (!DO_RTLD_BOOTSTRAP) \ + { \ +- if ((phase) != DL_RELOC_IFUNC) \ ++ if ((pass) != DL_RELOC_IRELATIVE) \ + for (int ranges_index = 0; ranges_index < 2; ++ranges_index) \ + elf_dynamic_do_##reloc ((map), scope, \ + ranges[ranges_index].start, \ + ranges[ranges_index].size, \ + ranges[ranges_index].nrelative, \ +- ranges[ranges_index].lazy); \ +- if ((phase) != DL_RELOC_NOIFUNC) \ ++ ranges[ranges_index].lazy, \ ++ skip_ifunc); \ ++ if ((pass) != DL_RELOC_NORMAL) \ + for (int ranges_index = 0; ranges_index < 2; ++ranges_index) \ + elf_dynamic_do_##reloc##_irelative ((map), scope, \ + ranges[ranges_index].start, \ +@@ -158,7 +164,8 @@ enum elf_dynamic_reloc_phase + ranges[ranges_index].start, \ + ranges[ranges_index].size, \ + ranges[ranges_index].nrelative, \ +- ranges[ranges_index].lazy); \ ++ ranges[ranges_index].lazy, \ ++ skip_ifunc); \ + } while (0) + + # if ELF_MACHINE_NO_REL || ELF_MACHINE_NO_RELA +@@ -169,37 +176,21 @@ enum elf_dynamic_reloc_phase + + # if ! ELF_MACHINE_NO_REL + # include "do-rel.h" +-# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc) \ +- _ELF_DYNAMIC_DO_RELOC (REL, Rel, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_BOTH) +-# define ELF_DYNAMIC_DO_REL_NOIFUNC(map, scope, lazy) \ +- _ELF_DYNAMIC_DO_RELOC (REL, Rel, map, scope, lazy, 0, \ +- _ELF_CHECK_REL, DL_RELOC_NOIFUNC) +-# define ELF_DYNAMIC_DO_REL_IFUNCONLY(map, scope, lazy, skip_ifunc) \ ++# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc, pass) \ + _ELF_DYNAMIC_DO_RELOC (REL, Rel, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_IFUNC) ++ _ELF_CHECK_REL, pass) + # else +-# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_REL_NOIFUNC(map, scope, lazy) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_REL_IFUNCONLY(map, scope, lazy, skip_ifunc) /* Nothing. */ ++# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc, pass) /* Nothing. */ + # endif + + # if ! ELF_MACHINE_NO_RELA + # define DO_RELA + # include "do-rel.h" +-# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc) \ +- _ELF_DYNAMIC_DO_RELOC (RELA, Rela, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_BOTH) +-# define ELF_DYNAMIC_DO_RELA_NOIFUNC(map, scope, lazy) \ +- _ELF_DYNAMIC_DO_RELOC (RELA, Rela, map, scope, lazy, 0, \ +- _ELF_CHECK_REL, DL_RELOC_NOIFUNC) +-# define ELF_DYNAMIC_DO_RELA_IFUNCONLY(map, scope, lazy, skip_ifunc) \ ++# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc, pass) \ + _ELF_DYNAMIC_DO_RELOC (RELA, Rela, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_IFUNC) ++ _ELF_CHECK_REL, pass) + # else +-# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_RELA_NOIFUNC(map, scope, lazy) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_RELA_IFUNCONLY(map, scope, lazy, skip_ifunc) /* Nothing. */ ++# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc, pass) /* Nothing. */ + # endif + + # define ELF_DYNAMIC_DO_RELR(map) \ +@@ -240,37 +231,33 @@ enum elf_dynamic_reloc_phase + # else + # define DO_RTLD_BOOTSTRAP 0 + # endif +-# define ELF_DYNAMIC_RELOCATE(map, scope, lazy, consider_profile, skip_ifunc) \ +- do { \ +- int edr_lazy = elf_machine_runtime_setup ((map), (scope), (lazy), \ +- (consider_profile)); \ +- if (!is_rtld_link_map (map) || DO_RTLD_BOOTSTRAP) \ +- ELF_DYNAMIC_DO_RELR (map); \ +- ELF_DYNAMIC_DO_REL ((map), (scope), edr_lazy, skip_ifunc); \ +- ELF_DYNAMIC_DO_RELA ((map), (scope), edr_lazy, skip_ifunc); \ +- ELF_DYNAMIC_AFTER_RELOC ((map), (edr_lazy)); \ +- } while (0) ++/* Perform one relocation pass over MAP. PASS selects which relocations are ++ processed. It is orthogonal to SKIP_IFUNC, which suppresses running IFUNC ++ resolvers in whichever pass is selected. + +-/* Like ELF_DYNAMIC_RELOCATE but only processes the non-IRELATIVE pass. +- The IRELATIVE pass must be completed later via ELF_DYNAMIC_RELOCATE_IFUNC. +- Used by the static-pie startup so the TCB and stack-protector canary can +- be initialised between the two passes. */ +-# define ELF_DYNAMIC_RELOCATE_NOIFUNC(map, scope, lazy, consider_profile) \ ++ Unless PASS is DL_RELOC_IRELATIVE, this also performs the machine-specific ++ PLT/GOT setup, the DT_RELR relocations, and the ELF_DYNAMIC_AFTER_RELOC ++ hook. */ ++# define ELF_DYNAMIC_RELOCATE_PASS(pass, map, scope, lazy, consider_profile, \ ++ skip_ifunc) \ + do { \ +- int edr_lazy = elf_machine_runtime_setup ((map), (scope), (lazy), \ ++ int edr_lazy = (lazy); \ ++ if ((pass) != DL_RELOC_IRELATIVE) \ ++ { \ ++ edr_lazy = elf_machine_runtime_setup ((map), (scope), (lazy), \ + (consider_profile)); \ +- if (!is_rtld_link_map (map) || DO_RTLD_BOOTSTRAP) \ +- ELF_DYNAMIC_DO_RELR (map); \ +- ELF_DYNAMIC_DO_REL_NOIFUNC ((map), (scope), edr_lazy); \ +- ELF_DYNAMIC_DO_RELA_NOIFUNC ((map), (scope), edr_lazy); \ +- ELF_DYNAMIC_AFTER_RELOC ((map), (edr_lazy)); \ ++ if (!is_rtld_link_map (map) || DO_RTLD_BOOTSTRAP) \ ++ ELF_DYNAMIC_DO_RELR (map); \ ++ } \ ++ ELF_DYNAMIC_DO_REL ((map), (scope), edr_lazy, skip_ifunc, (pass)); \ ++ ELF_DYNAMIC_DO_RELA ((map), (scope), edr_lazy, skip_ifunc, (pass)); \ ++ if ((pass) != DL_RELOC_IRELATIVE) \ ++ ELF_DYNAMIC_AFTER_RELOC ((map), edr_lazy); \ + } while (0) + +-/* IRELATIVE-only companion to ELF_DYNAMIC_RELOCATE_NOIFUNC. */ +-# define ELF_DYNAMIC_RELOCATE_IFUNC(map, scope, lazy, skip_ifunc) \ +- do { \ +- ELF_DYNAMIC_DO_REL_IFUNCONLY ((map), (scope), (lazy), skip_ifunc); \ +- ELF_DYNAMIC_DO_RELA_IFUNCONLY ((map), (scope), (lazy), skip_ifunc); \ +- } while (0) ++/* Run both passes back to back, for callers with nothing to interleave. */ ++# define ELF_DYNAMIC_RELOCATE(map, scope, lazy, consider_profile, skip_ifunc) \ ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_ALL, (map), (scope), (lazy), \ ++ (consider_profile), skip_ifunc) + + #endif +diff --git a/elf/tst-ifunc-fault-dep-bindnow.c b/elf/tst-ifunc-fault-dep-bindnow.c +new file mode 100644 +index 0000000000..60d97dcaa4 +--- /dev/null ++++ b/elf/tst-ifunc-fault-dep-bindnow.c +@@ -0,0 +1,19 @@ ++/* Program calling an IFUNC defined in a dependency. BIND_NOW variant. ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++#include "tst-ifunc-fault-dep-lazy.c" +diff --git a/elf/tst-ifunc-fault-dep-lazy.c b/elf/tst-ifunc-fault-dep-lazy.c +new file mode 100644 +index 0000000000..122d33f391 +--- /dev/null ++++ b/elf/tst-ifunc-fault-dep-lazy.c +@@ -0,0 +1,27 @@ ++/* Program calling an IFUNC defined in a dependency (BZ 34428). ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++extern void magic (void); ++ ++int ++main (void) ++{ ++ /* JMP_SLOT relocation against an undefined symbol. */ ++ magic (); ++ return 1; ++} +diff --git a/elf/tst-ifunc-fault-mod.c b/elf/tst-ifunc-fault-mod.c +new file mode 100644 +index 0000000000..11c21b48ac +--- /dev/null ++++ b/elf/tst-ifunc-fault-mod.c +@@ -0,0 +1,38 @@ ++/* Shared object exporting an IFUNC symbol with a resolver which crashes. ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++#include ++ ++static void ++implementation (void) ++{ ++ /* Produce a crash, without depending on any relocations. */ ++ volatile char *volatile p = NULL; ++ *p = 0; ++} ++ ++static __typeof__ (implementation) * ++resolver (void) ++{ ++ /* Produce a crash, without depending on any relocations. */ ++ volatile char *volatile p = NULL; ++ *p = 0; ++ return implementation; ++} ++ ++void magic (void) __attribute__ ((ifunc ("resolver"))); + +commit afd131806b25715a7617ab757db43f0bb610acbf +Author: Adhemerval Zanella +Date: Wed Aug 12 09:03:17 2026 -0300 + + m68k: Fix fmod/fmodf infinite recursion (BZ 34508) + + Commits 6deadd4eb6a and ade9f30ce27 changed m68k fmod to call + __m81_u(fmod), instead of the mathimpl.h inline + __m81_u(__ieee754_fmod) (that wraps the m68k fmod instruction). + This leads to infinite recursion. + + Tested-by: John Paul Adrian Glaubitz + + (cherry picked from commit bb213471bedc177b8efd3178584137fb81cc976a) + +diff --git a/NEWS b/NEWS +index d0ef2d3e9a..697049efd1 100644 +--- a/NEWS ++++ b/NEWS +@@ -18,6 +18,8 @@ The following bugs are resolved with this release: + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong ++ [34509] libc: [m68k] Regression: Perl locks up after upgrading glibc ++ to 2.43 + + Version 2.44 + +diff --git a/sysdeps/m68k/m680x0/fpu/e_fmod.c b/sysdeps/m68k/m680x0/fpu/e_fmod.c +index 9ad6924422..faac7c79e3 100644 +--- a/sysdeps/m68k/m680x0/fpu/e_fmod.c ++++ b/sysdeps/m68k/m680x0/fpu/e_fmod.c +@@ -33,7 +33,7 @@ __fmod (double x, double y) + && !is_nan (hx))) + return __math_invalid (x); + +- return __m81_u(fmod)(x, y); ++ return __m81_u(__ieee754_fmod)(x, y); + } + strong_alias (__fmod, __ieee754_fmod) + libm_alias_finite (__ieee754_fmod, __fmod) +diff --git a/sysdeps/m68k/m680x0/fpu/e_fmodf.c b/sysdeps/m68k/m680x0/fpu/e_fmodf.c +index a3bd24b71f..98797e0887 100644 +--- a/sysdeps/m68k/m680x0/fpu/e_fmodf.c ++++ b/sysdeps/m68k/m680x0/fpu/e_fmodf.c +@@ -34,7 +34,7 @@ __fmodf (float x, float y) + && !is_nan (hx))) + return __math_invalidf (x); + +- return __m81_u(fmodf)(x, y); ++ return __m81_u(__ieee754_fmodf)(x, y); + } + strong_alias (__fmodf, __ieee754_fmodf) + versioned_symbol (libm, __fmodf, fmodf, GLIBC_2_43); diff --git a/pkgs/development/libraries/glibc/common.nix b/pkgs/development/libraries/glibc/common.nix index 4db1dac187ed..ab415d5b932f 100644 --- a/pkgs/development/libraries/glibc/common.nix +++ b/pkgs/development/libraries/glibc/common.nix @@ -50,9 +50,9 @@ }@args: let - version = "2.42"; - patchSuffix = "-84"; - sha256 = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; + version = "2.44"; + patchSuffix = "-25"; + sha256 = "sha256-N/YA8r7zxegwAUcFlWiyouQKetbMxlzpQlVtSUKcxmc="; in assert withLinuxHeaders -> linuxHeaders != null; @@ -69,17 +69,17 @@ stdenv.mkDerivation ( /* No tarballs for stable upstream branch, only https://sourceware.org/git/glibc.git and using git would complicate bootstrapping. $ git fetch --all -p && git checkout origin/release/2.42/master && git describe - glibc-2.42-67-g4ebd33dd77 - $ git show --minimal --reverse glibc-2.42.. ':!ADVISORIES' > 2.42-master.patch + glibc-2.44-25-gafd131806b + $ git show --minimal --reverse glibc-2.44.. ':!ADVISORIES' > 2.44-master.patch To compare the archive contents zdiff can be used. - $ diff -u 2.42-master.patch ../nixpkgs/pkgs/development/libraries/glibc/2.42-master.patch + $ diff -u 2.44-master.patch ../nixpkgs/pkgs/development/libraries/glibc/2.44-master.patch Please note that each commit has changes to the file ADVISORIES excluded since that conflicts with the directory advisories/ making cross-builds from hosts with case-insensitive file-systems impossible. */ - ./2.42-master.patch + ./2.44-master.patch # Allow NixOS and Nix to handle the locale-archive. ./nix-locale-archive.patch diff --git a/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch b/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch index 0e0315aca270..f9f3f815bbad 100644 --- a/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch +++ b/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch @@ -1,8 +1,8 @@ diff --git a/elf/Makefile b/elf/Makefile -index 5d666b1b..a5017e9c 100644 +index dc39ccea60..3230939376 100644 --- a/elf/Makefile +++ b/elf/Makefile -@@ -669,14 +669,14 @@ $(objpfx)sln: $(sln-modules:%=$(objpfx)%.o) +@@ -1745,14 +1745,14 @@ $(objpfx)sln: $(sln-modules:%=$(objpfx)%.o) $(objpfx)ldconfig: $(ldconfig-modules:%=$(objpfx)%.o) @@ -21,36 +21,41 @@ index 5d666b1b..a5017e9c 100644 +CFLAGS-rtld.c += $(PREFIX-FLAGS) +CFLAGS-dl-usage.c += $(PREFIX-FLAGS) \ -D'RTLD="$(rtlddir)/$(rtld-installed-name)"' - - cpp-srcs-left := $(all-rtld-routines:=.os) + CFLAGS-dl-diagnostics.c += $(SYSCONF-FLAGS) \ + -D'PREFIX="$(prefix)"' \ diff --git a/elf/dl-diagnostics.c b/elf/dl-diagnostics.c -index bef224b3..8e166b12 100644 +index 21311178c7..719e02f8e6 100644 --- a/elf/dl-diagnostics.c +++ b/elf/dl-diagnostics.c -@@ -205,7 +205,7 @@ print_paths (void) +@@ -204,7 +204,7 @@ print_paths (void) { _dl_diagnostics_print_labeled_string ("path.prefix", PREFIX); _dl_diagnostics_print_labeled_string ("path.rtld", RTLD); - _dl_diagnostics_print_labeled_string ("path.sysconfdir", SYSCONFDIR); + _dl_diagnostics_print_labeled_string ("path.sysconfdir", PREFIX "/etc"); - + unsigned int index = 0; static const char *system_dirs = SYSTEM_DIRS "\0"; diff --git a/elf/ldconfig.c b/elf/ldconfig.c -index 28ed637a..6f07b79a 100644 +index a39f3ecfcd..b5f12d0760 100644 --- a/elf/ldconfig.c +++ b/elf/ldconfig.c -@@ -57,7 +57,7 @@ - #define TLS_HWCAP_BIT 63 +@@ -48,11 +48,11 @@ + #ifndef LD_SO_CONF -# define LD_SO_CONF SYSCONFDIR "/ld.so.conf" +# define LD_SO_CONF PREFIX "/etc/ld.so.conf" #endif + #ifndef TUNABLES_CONF +-# define TUNABLES_CONF SYSCONFDIR "/tunables.conf" ++# define TUNABLES_CONF PREFIX "/etc/tunables.conf" + #endif + /* Get libc version number. */ diff --git a/sysdeps/generic/dl-cache.h b/sysdeps/generic/dl-cache.h -index 964d50a4..2224d651 100644 +index 972ab32b86..a0e0775506 100644 --- a/sysdeps/generic/dl-cache.h +++ b/sysdeps/generic/dl-cache.h @@ -35,7 +35,7 @@ diff --git a/pkgs/development/python-modules/mypy/default.nix b/pkgs/development/python-modules/mypy/default.nix index 68587c7c345f..a50eb9c32761 100644 --- a/pkgs/development/python-modules/mypy/default.nix +++ b/pkgs/development/python-modules/mypy/default.nix @@ -6,6 +6,7 @@ gitUpdater, pythonAtLeast, isPyPy, + fetchpatch, # build-system pathspec, @@ -49,6 +50,15 @@ buildPythonPackage rec { hash = "sha256-sm/pxQGxH5XuPH7B8i3fpp30KaFU9aSp6BT67UcDPvU="; }; + patches = [ + # fix build w/ glibc-2.44 + # If Python.h isn't included first, a const redefinition error now occurs otherwise. + (fetchpatch { + url = "https://github.com/python/mypy/commit/46acbe85c0e1703ebf2e6d4c699772edcdcf4652.patch"; + hash = "sha256-KslHiKqinvvXZoxvCnZXOhCm7i8577PbSdNGudCsjZE="; + }) + ]; + passthru.updateScript = gitUpdater { rev-prefix = "v"; }; diff --git a/pkgs/development/tools/electron/common.nix b/pkgs/development/tools/electron/common.nix index 9a114ae5974e..99946bc1901a 100644 --- a/pkgs/development/tools/electron/common.nix +++ b/pkgs/development/tools/electron/common.nix @@ -119,7 +119,8 @@ in ++ # Restore fake libGLESv2.so which is patchelf'd by the chromium derivation lib.optional (lib.versionAtLeast info.version "44") - ./0001-Revert-build-stop-shipping-dummy-ANGLE-libs-in-Linux.patch; + ./0001-Revert-build-stop-shipping-dummy-ANGLE-libs-in-Linux.patch + ++ lib.optional (lib.versionOlder info.version "43") ./fix-electron42-glibc-2.43.patch; postPatch = '' mkdir -p third_party/jdk/current/bin diff --git a/pkgs/development/tools/electron/fix-electron42-glibc-2.43.patch b/pkgs/development/tools/electron/fix-electron42-glibc-2.43.patch new file mode 100644 index 000000000000..27ca436c2b52 --- /dev/null +++ b/pkgs/development/tools/electron/fix-electron42-glibc-2.43.patch @@ -0,0 +1,67 @@ +From 83a9ccb1265dcdeeb8bf17205e00b751f86641d3 Mon Sep 17 00:00:00 2001 +From: Ho Cheung +Date: Tue, 21 Apr 2026 08:19:53 -0700 +Subject: [PATCH] [sandbox] Fix SYS_SECCOMP conflict with newer glibc + +glibc now exposes SYS_SECCOMP in signal headers, which conflicts with +Chromium's fallback macro in linux_seccomp.h. + +Stop defining SYS_SECCOMP in the public compat header and use a local +fallback in trap.cc instead. + +Test: Tested on an Ubuntu 26.04 container using use_sysroot = false. +Bug: 456218403 +Change-Id: I73ddfa85453dd9d524b64b4c1bca4f95b82c9f2b +Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7781604 +Reviewed-by: Elly +Commit-Queue: Aaron Teo +Cr-Commit-Position: refs/heads/main@{#1618207} +--- + +diff --git a/sandbox/linux/seccomp-bpf/trap.cc b/sandbox/linux/seccomp-bpf/trap.cc +index 1316786d..212e80e 100644 +--- a/sandbox/linux/seccomp-bpf/trap.cc ++++ b/sandbox/linux/seccomp-bpf/trap.cc +@@ -29,6 +29,12 @@ + + namespace { + ++#if defined(SYS_SECCOMP) ++constexpr int kSigsysSeccompCode = SYS_SECCOMP; ++#else ++constexpr int kSigsysSeccompCode = 1; ++#endif ++ + struct arch_sigsys { + // RAW_PTR_EXCLUSION: Points to a code address given to us by the kernel. + RAW_PTR_EXCLUSION void* ip; +@@ -151,7 +157,7 @@ + // Various sanity checks to make sure we actually received a signal + // triggered by a BPF filter. If something else triggered SIGSYS + // (e.g. kill()), there is really nothing we can do with this signal. +- if (nr != LINUX_SIGSYS || info->si_code != SYS_SECCOMP || !ctx || ++ if (nr != LINUX_SIGSYS || info->si_code != kSigsysSeccompCode || !ctx || + info->si_errno <= 0 || + static_cast(info->si_errno) > trap_array_size_) { + // ATI drivers seem to send SIGSYS, so this cannot be FATAL. +@@ -162,7 +168,6 @@ + return; + } + +- + // Obtain the siginfo information that is specific to SIGSYS. + struct arch_sigsys sigsys; + #if defined(si_call_addr) +diff --git a/sandbox/linux/system_headers/linux_seccomp.h b/sandbox/linux/system_headers/linux_seccomp.h +index 8690a96..8ebf4045 100644 +--- a/sandbox/linux/system_headers/linux_seccomp.h ++++ b/sandbox/linux/system_headers/linux_seccomp.h +@@ -214,8 +214,4 @@ + #define SECCOMP_RET_INVALID 0x00010000U // Illegal return value + #endif + +-#ifndef SYS_SECCOMP +-#define SYS_SECCOMP 1 +-#endif +- + #endif // SANDBOX_LINUX_SYSTEM_HEADERS_LINUX_SECCOMP_H_ diff --git a/pkgs/development/tools/mysql-shell/8.nix b/pkgs/development/tools/mysql-shell/8.nix index 238742bd3ebf..7c6b7680e282 100644 --- a/pkgs/development/tools/mysql-shell/8.nix +++ b/pkgs/development/tools/mysql-shell/8.nix @@ -29,6 +29,7 @@ cyrus_sasl, openldap, antlr, + fetchpatch, }: let @@ -66,6 +67,12 @@ stdenv.mkDerivation (finalAttrs: { # No openssl bundling on macOS. It's not working. # See https://github.com/mysql/mysql-shell/blob/5b84e0be59fc0e027ef3f4920df15f7be97624c1/cmake/ssl.cmake#L53 ./no-openssl-bundling.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/mysql/mysql-shell/commit/4ce8746d8a7eecf9ae66d4d500c84d57cc4fbdbb.patch"; + hash = "sha256-LUGC7gnNQ3zhmWUm2xogsOAmx8QSngQBHVJMWHFtWz0="; + }) ]; postPatch = '' diff --git a/pkgs/development/tools/mysql-shell/9.nix b/pkgs/development/tools/mysql-shell/9.nix index 14843a23f189..5f68b885640e 100644 --- a/pkgs/development/tools/mysql-shell/9.nix +++ b/pkgs/development/tools/mysql-shell/9.nix @@ -29,6 +29,7 @@ cyrus_sasl, openldap, antlr, + fetchpatch, }: let @@ -66,6 +67,12 @@ stdenv.mkDerivation (finalAttrs: { # No openssl bundling on macOS. It's not working. # See https://github.com/mysql/mysql-shell/blob/5b84e0be59fc0e027ef3f4920df15f7be97624c1/cmake/ssl.cmake#L53 ./no-openssl-bundling.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/mysql/mysql-shell/commit/4ce8746d8a7eecf9ae66d4d500c84d57cc4fbdbb.patch"; + hash = "sha256-LUGC7gnNQ3zhmWUm2xogsOAmx8QSngQBHVJMWHFtWz0="; + }) ]; postPatch = '' diff --git a/pkgs/os-specific/linux/kernel/C23-compat-6.1.patch b/pkgs/os-specific/linux/kernel/C23-compat-6.1.patch new file mode 100644 index 000000000000..73c268b8b615 --- /dev/null +++ b/pkgs/os-specific/linux/kernel/C23-compat-6.1.patch @@ -0,0 +1,13 @@ +diff --git a/tools/lib/bpf/libbpf.c b/tools/lib/bpf/libbpf.c +index 7bd6aff6e260..33b214a91338 100644 +--- a/tools/lib/bpf/libbpf.c ++++ b/tools/lib/bpf/libbpf.c +@@ -10748,7 +10748,7 @@ static int resolve_full_path(const char *file, char *result, size_t result_sz) + if (!search_paths[i]) + continue; + for (s = search_paths[i]; s != NULL; s = strchr(s, ':')) { +- char *next_path; ++ const char *next_path; + int seg_len; + + if (s[0] == ':') diff --git a/pkgs/os-specific/linux/kernel/patches.nix b/pkgs/os-specific/linux/kernel/patches.nix index db617c867064..12cf001b6503 100644 --- a/pkgs/os-specific/linux/kernel/patches.nix +++ b/pkgs/os-specific/linux/kernel/patches.nix @@ -27,4 +27,9 @@ name = "request-key-helper"; patch = ./request-key-helper.patch; }; + + libbpf_C23_compat = { + name = "c23-compat-libbpf"; + patch = ./C23-compat-6.1.patch; + }; } diff --git a/pkgs/os-specific/linux/libbpf/0.x.nix b/pkgs/os-specific/linux/libbpf/0.x.nix deleted file mode 100644 index 7d5676be8c0a..000000000000 --- a/pkgs/os-specific/linux/libbpf/0.x.nix +++ /dev/null @@ -1,70 +0,0 @@ -{ - fetchFromGitHub, - elfutils, - pkg-config, - stdenv, - zlib, - lib, - nixosTests, -}: - -# update bot does not seem to limit updates here to 0.8.x despite -# the all-packages derivation being libbpf_0 as the libbpf base alias -# is still present: just disable it for 0.x: -# nixpkgs-update: no auto update - -stdenv.mkDerivation rec { - pname = "libbpf"; - version = "0.8.3"; - - src = fetchFromGitHub { - owner = "libbpf"; - repo = "libbpf"; - rev = "v${version}"; - sha256 = "sha256-J5cUvfUYc+uLdkFa2jx/2bqBoZg/eSzc6SWlgKqcfIc="; - }; - - nativeBuildInputs = [ pkg-config ]; - buildInputs = [ - elfutils - zlib - ]; - - enableParallelBuilding = true; - makeFlags = [ - "PREFIX=$(out)" - "-C src" - ]; - - passthru.tests = { - bpf = nixosTests.bpf; - }; - - postInstall = '' - # install linux's libbpf-compatible linux/btf.h - install -Dm444 include/uapi/linux/*.h -t $out/include/linux - ''; - - # FIXME: Multi-output requires some fixes to the way the pkg-config file is - # constructed (it gets put in $out instead of $dev for some reason, with - # improper paths embedded). Don't enable it for now. - - # outputs = [ "out" "dev" ]; - - meta = { - description = "Upstream mirror of libbpf"; - homepage = "https://github.com/libbpf/libbpf"; - license = with lib.licenses; [ - lgpl21 # or - bsd2 - ]; - maintainers = with lib.maintainers; [ - thoughtpolice - vcunat - saschagrunert - martinetd - ]; - platforms = lib.platforms.linux; - identifiers.cpeParts = lib.meta.cpeFullVersionWithVendor "libbpf_project" version; - }; -} diff --git a/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix b/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix index f156f862ecc0..cf71f17513f1 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix @@ -20,11 +20,11 @@ }: let pname = "glibc"; - version = "2.42"; + version = "2.44"; src = fetchurl { url = "mirror://gnu/libc/glibc-${version}.tar.xz"; - hash = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; + hash = "sha256-N/YA8r7zxegwAUcFlWiyouQKetbMxlzpQlVtSUKcxmc="; }; linkerFile = diff --git a/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix b/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix index 2a4676231f2f..b636629bff8d 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix @@ -21,11 +21,11 @@ }: let pname = "glibc-headers"; - version = "2.42"; + version = "2.44"; src = fetchurl { url = "mirror://gnu/libc/glibc-${version}.tar.xz"; - hash = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; + hash = "sha256-N/YA8r7zxegwAUcFlWiyouQKetbMxlzpQlVtSUKcxmc="; }; in bash.runCommand "${pname}-${version}" diff --git a/pkgs/servers/mir/common.nix b/pkgs/servers/mir/common.nix index 28a2d5f566bf..8693a3027011 100644 --- a/pkgs/servers/mir/common.nix +++ b/pkgs/servers/mir/common.nix @@ -53,6 +53,7 @@ { version, pinned ? false, + broken ? false, hash, cargoHash ? null, patches ? [ ], @@ -298,6 +299,7 @@ stdenv.mkDerivation ( }; meta = { + inherit broken; description = "Display server and Wayland compositor developed by Canonical"; homepage = "https://mir-server.io"; changelog = "https://github.com/canonical/mir/releases/tag/v${finalAttrs.version}"; diff --git a/pkgs/servers/mir/default.nix b/pkgs/servers/mir/default.nix index 873dca525581..e3044d42d221 100644 --- a/pkgs/servers/mir/default.nix +++ b/pkgs/servers/mir/default.nix @@ -11,6 +11,7 @@ in }; mir_2_15 = common { + broken = true; # doesn't build with glibc 2.44 version = "2.15.0"; pinned = true; hash = "sha256-c1+gxzLEtNCjR/mx76O5QElQ8+AO4WsfcG7Wy1+nC6E="; diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index 6435b7d85879..394caf7b563f 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -641,6 +641,7 @@ mapAliases { csslint = throw "'csslint' has been removed as upstream considers it abandoned."; # Added 2025-11-07 cstore_fdw = throw "'cstore_fdw' has been removed. Use 'postgresqlPackages.cstore_fdw' instead."; # Added 2025-07-19 ctpp2 = throw "'ctpp2' has been removed due to lack of maintenance."; # Added 2025-12-31 + ctx = throw "'ctx' was unmaintained and not updated for three years"; # Added 2026-09-08 cudaPackages_11 = throw "CUDA 11 has been removed from Nixpkgs, as it is unmaintained upstream and depends on unsupported compilers"; # Added 2025-08-08 cudaPackages_11_0 = throw "CUDA 11.0 has been removed from Nixpkgs, as it is unmaintained upstream and depends on unsupported compilers"; # Added 2025-08-08 cudaPackages_11_1 = throw "CUDA 11.1 has been removed from Nixpkgs, as it is unmaintained upstream and depends on unsupported compilers"; # Added 2025-08-08 @@ -724,6 +725,7 @@ mapAliases { dotnetfx40 = throw "'dotnetfx40' has been removed because it was unmaintained in Nixpkgs"; # Added 2026-01-27 dotty = throw "'dotty' has been renamed to/replaced by 'scala_3'"; # Converted to throw 2025-10-27 dovecot_fts_xapian = throw "'dovecot_fts_xapian' has been removed because it was unmaintained in Nixpkgs. Consider using dovecot-fts-flatcurve instead"; # Added 2025-08-16 + dragmap = throw "'dragmap' doesn't build with latest glibc anymore and upstream repo is archived"; # Added 2026-09-03 drone-runner-exec = throw "'drone-runner-exec' has been removed as it was deprecated and archived upstream."; # Added 2026-07-20 dsd = throw "dsd has been removed, as it was broken and lack of upstream maintenance"; # Added 2025-08-25 dtv-scan-tables_linuxtv = throw "'dtv-scan-tables_linuxtv' has been renamed to/replaced by 'dtv-scan-tables'"; # Converted to throw 2025-10-27 @@ -1338,6 +1340,7 @@ mapAliases { libayatana-indicator-gtk3 = throw "'libayatana-indicator-gtk3' has been renamed to/replaced by 'libayatana-indicator'"; # Converted to throw 2025-10-27 libbaseencode = throw "'libbaseencode' has been removed because it was deprecated and archived upstream. Consider using 'libcotp' instead"; # Added 2026-01-15 libbencodetools = throw "'libbencodetools' has been renamed to/replaced by 'bencodetools'"; # Converted to throw 2025-10-27 + libbpf_0 = throw "'libbpf_0' has been removed since it's EOL for four years"; # Added 2026-09-03 libbpf_1 = throw "'libbpf_1' has been renamed to/replaced by 'libbpf'"; # Converted to throw 2025-10-27 libbson = throw "'libbson' has been renamed to/replaced by 'mongoc'"; # Converted to throw 2025-10-27 libcanberra-gtk2 = throw "'libcanberra-gtk2' has been removed as it depended on the deprecated GTK 2 engine. Consider using 'libcanberra-gtk3' instead."; # Added 2026-08-10 @@ -1838,6 +1841,7 @@ mapAliases { nextcloud32Packages = throw "Nextcloud 32 is EOL!"; # Added 2026-09-19 nfstrace = throw "nfstrace has been removed, as it was broken"; # Added 2025-08-25 nginxQuic = throw "'nginxQuic' has been removed. QUIC support is now available in the default nginx builds."; + ngn-k = throw "'ngn-k' doesn't build with glibc 2.44 and upstream claims that the implementation is no longer supported"; # Added 2026-09-03 ngrid = throw "'ngrid' has been removed as it has been unmaintained upstream and broken"; # Added 2025-11-15 nightfox-gtk-theme = throw "'nightfox-gtk-theme' has been removed because it depended on 'gtk-engine-murrine', which was removed because it was unmaintained upstream and depended on GTK 2."; # Added 2026-07-22 nim1 = throw "'nim1' has reached EOL, please use 'nim'"; # Added 2026-03-06 diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 447dcf518cf2..e6823acab098 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -4884,7 +4884,6 @@ with pkgs; }; libbpf = callPackage ../os-specific/linux/libbpf { }; - libbpf_0 = callPackage ../os-specific/linux/libbpf/0.x.nix { }; bundlewrap = with python3.pkgs; toPythonApplication bundlewrap; diff --git a/pkgs/top-level/linux-kernels.nix b/pkgs/top-level/linux-kernels.nix index d3fa965d9516..3baabf4a14b5 100644 --- a/pkgs/top-level/linux-kernels.nix +++ b/pkgs/top-level/linux-kernels.nix @@ -65,6 +65,7 @@ in kernelPatches = [ kernelPatches.bridge_stp_helper kernelPatches.request_key_helper + kernelPatches.libbpf_C23_compat ]; };