From 55b4fee88a78a85d7168e4766049b0149f708f67 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:15:40 +0200 Subject: [PATCH 01/82] minimal-bootstrap: glibc 2.42 -> 2.44 --- pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix b/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix index f156f862ecc0..cf71f17513f1 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix @@ -20,11 +20,11 @@ }: let pname = "glibc"; - version = "2.42"; + version = "2.44"; src = fetchurl { url = "mirror://gnu/libc/glibc-${version}.tar.xz"; - hash = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; + hash = "sha256-N/YA8r7zxegwAUcFlWiyouQKetbMxlzpQlVtSUKcxmc="; }; linkerFile = From 9149e326c565f95aa2cc0ddc027064ae11dd9830 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sat, 19 Sep 2026 16:43:13 +0200 Subject: [PATCH 02/82] minimal-bootstrap.glibc-headers: 2.42 -> 2.44 --- pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix b/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix index 2a4676231f2f..b636629bff8d 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix @@ -21,11 +21,11 @@ }: let pname = "glibc-headers"; - version = "2.42"; + version = "2.44"; src = fetchurl { url = "mirror://gnu/libc/glibc-${version}.tar.xz"; - hash = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; + hash = "sha256-N/YA8r7zxegwAUcFlWiyouQKetbMxlzpQlVtSUKcxmc="; }; in bash.runCommand "${pname}-${version}" From 03290f63705e155c994e8e6dadcf501f59b0e343 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:18:58 +0200 Subject: [PATCH 03/82] grub2: fix build w/ glibc-2.44 Co-authored-by: Philip Taron --- pkgs/by-name/gr/grub2/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/gr/grub2/package.nix b/pkgs/by-name/gr/grub2/package.nix index 392a6ed6e794..6ab78b82c4eb 100644 --- a/pkgs/by-name/gr/grub2/package.nix +++ b/pkgs/by-name/gr/grub2/package.nix @@ -223,6 +223,9 @@ stdenv.mkDerivation rec { strictDeps = true; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + hardeningDisable = [ "all" ]; separateDebugInfo = !xenSupport; From 00b73f98545dd811cffb259767de46b09478339c Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:19:36 +0200 Subject: [PATCH 04/82] dtc: fix build w/ glibc-2.44 Co-authored-by: Philip Taron --- pkgs/by-name/dt/dtc/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/dt/dtc/package.nix b/pkgs/by-name/dt/dtc/package.nix index 17fe8f5653e3..a65192ee8daa 100644 --- a/pkgs/by-name/dt/dtc/package.nix +++ b/pkgs/by-name/dt/dtc/package.nix @@ -74,6 +74,8 @@ stdenv.mkDerivation (finalAttrs: { # Required for installation of Python library and is innocuous otherwise. env.DESTDIR = "/"; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; mesonAutoFeatures = "auto"; mesonFlags = [ From db8336f9f1335fef75c570f1408655d1511941ef Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:19:55 +0200 Subject: [PATCH 05/82] librist: fix build w/ glibc-2.44 Co-authored-by: Philip Taron --- pkgs/by-name/li/librist/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/li/librist/package.nix b/pkgs/by-name/li/librist/package.nix index 606b5f6a5acb..21d163f974d5 100644 --- a/pkgs/by-name/li/librist/package.nix +++ b/pkgs/by-name/li/librist/package.nix @@ -34,6 +34,9 @@ stdenv.mkDerivation (finalAttrs: { pkg-config ]; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + buildInputs = [ cjson cmocka From 1a0a983791e26f2ee69a42373f88ca65fb7417f8 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:20:13 +0200 Subject: [PATCH 06/82] krb5: fix build w/ glibc-2.44 Co-authored-by: Philip Taron --- pkgs/by-name/kr/krb5/package.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/kr/krb5/package.nix b/pkgs/by-name/kr/krb5/package.nix index 4e97e9867190..9b5b2cc2d628 100644 --- a/pkgs/by-name/kr/krb5/package.nix +++ b/pkgs/by-name/kr/krb5/package.nix @@ -75,7 +75,9 @@ stdenv.mkDerivation (finalAttrs: { # void foo(); # # declaration. - NIX_CFLAGS_COMPILE = "-std=gnu17" + lib.optionalString stdenv.hostPlatform.isStatic " -fcommon"; + NIX_CFLAGS_COMPILE = + "-std=gnu17 -Wno-error=discarded-qualifiers" + + lib.optionalString stdenv.hostPlatform.isStatic " -fcommon"; }; configureFlags = [ From efa476934e14f8ad69fce1f76e61a5c790d7ce88 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:20:25 +0200 Subject: [PATCH 07/82] kvmtool: fix build w/ glibc-2.44 --- pkgs/by-name/kv/kvmtool/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/kv/kvmtool/package.nix b/pkgs/by-name/kv/kvmtool/package.nix index adfbd884d0e0..f89324a5909d 100644 --- a/pkgs/by-name/kv/kvmtool/package.nix +++ b/pkgs/by-name/kv/kvmtool/package.nix @@ -19,6 +19,9 @@ stdenv.mkDerivation { buildInputs = lib.optionals stdenv.hostPlatform.isAarch64 [ dtc ]; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + enableParallelBuilding = true; makeFlags = [ From abc74b463f2ac4bd0e1870c2c5b368a228437be6 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:22:03 +0200 Subject: [PATCH 08/82] efivar: fix build w/ glibc-2.44 --- pkgs/by-name/ef/efivar/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/ef/efivar/package.nix b/pkgs/by-name/ef/efivar/package.nix index bdc7a06b9503..12ebaf4a7500 100644 --- a/pkgs/by-name/ef/efivar/package.nix +++ b/pkgs/by-name/ef/efivar/package.nix @@ -6,6 +6,7 @@ pkg-config, popt, mandoc, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -33,6 +34,14 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ popt ]; depsBuildBuild = [ buildPackages.stdenv.cc ]; + patches = [ + # fix build with glibc-2.44 + (fetchpatch { + url = "https://github.com/rhboot/efivar/commit/f521cd7f584c95d8308659ab9d89d750e2bd76da.patch"; + hash = "sha256-I19UIS0tNTsEipuoMQPlTEwih1RrYPz9Q4Wy98u1z0Q="; + }) + ]; + makeFlags = [ "prefix=$(out)" "libdir=$(out)/lib" From 53c393eb115c6f5db389bf033ee134b92c17e288 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:22:59 +0200 Subject: [PATCH 09/82] ldb: fix build w/ glibc-2.44 Co-authored-by: Philip Taron --- pkgs/by-name/ld/ldb/package.nix | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/pkgs/by-name/ld/ldb/package.nix b/pkgs/by-name/ld/ldb/package.nix index 04d9e7d645bd..45e3f142befb 100644 --- a/pkgs/by-name/ld/ldb/package.nix +++ b/pkgs/by-name/ld/ldb/package.nix @@ -17,6 +17,7 @@ buildPackages, libxcrypt, testers, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -33,6 +34,16 @@ stdenv.mkDerivation (finalAttrs: { "dev" ]; + patches = [ + # Fix rep_memset_s calling C23 memset_explicit with wrong arg count (4 instead of 3). + # Upstream samba commit 04e0fb9b2d; later reworked more broadly in ef08be24e9 and 3e81b73a05 + # which replace memset_s with memset_explicit entirely, but those don't apply to ldb 2.9.2. + (fetchpatch { + url = "https://gitlab.com/samba-team/samba/-/commit/04e0fb9b2d1d87516f1331096c78e8355b4fa9f3.patch"; + hash = "sha256-sBqtVwGBXseCAMlv3QaiSYQmOw7H4cAJwc0Ey5yD6Os="; + }) + ]; + nativeBuildInputs = [ pkg-config python3 From 9c912cb79757cc1a0f0723589e36e68780596056 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:23:25 +0200 Subject: [PATCH 10/82] sane-backends: fix build w/ glibc-2.44 Co-authored-by: Philip Taron --- pkgs/applications/graphics/sane/backends/default.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/applications/graphics/sane/backends/default.nix b/pkgs/applications/graphics/sane/backends/default.nix index 02dd36e23d7e..05f67e51cd2a 100644 --- a/pkgs/applications/graphics/sane/backends/default.nix +++ b/pkgs/applications/graphics/sane/backends/default.nix @@ -66,6 +66,16 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-9KKTr7p1vCgvGr6hFY83K5gbL7Ilm4Uzc86JIxv+ahI="; revert = true; }) + + # Fix gphoto2 backend build with glibc 2.43 C23 const-preserving strchr + (fetchpatch { + url = "https://gitlab.com/sane-project/backends/-/commit/d04d17b456d9847021b6df6eb08a3419a75172cf.patch"; + hash = "sha256-4iAzwA+uh8W+xSpUkZgvShQ71kq/OVJ26pKsD1NwiXs="; + }) + (fetchpatch { + url = "https://gitlab.com/sane-project/backends/-/commit/ebd4d82bd7a6b8c57870dbfb492e4c186cf584d8.patch"; + hash = "sha256-vHtv+OMA0f9JR1ReshTg8IOgcZf7cnV7chitRBBCAg4="; + }) ]; postPatch = '' From 31bb833ca2b358a8d557e1a8cfae13f2214e4b60 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:24:00 +0200 Subject: [PATCH 11/82] python3Packages.mypy: fix build w/ glibc-2.44 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Otherwiwse a bunch of tests break with "warning: ‘_POSIX_C_SOURCE’ redefined". Apparently this now happens, if software doesn't adhere to the rule of `Python.h` having to be included first[1]. The applied patch focuses on Python 3.15 support, but also happens to fix that. [1] https://bugzilla.redhat.com/show_bug.cgi?id=2416110 --- pkgs/development/python-modules/mypy/default.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/development/python-modules/mypy/default.nix b/pkgs/development/python-modules/mypy/default.nix index 68587c7c345f..a50eb9c32761 100644 --- a/pkgs/development/python-modules/mypy/default.nix +++ b/pkgs/development/python-modules/mypy/default.nix @@ -6,6 +6,7 @@ gitUpdater, pythonAtLeast, isPyPy, + fetchpatch, # build-system pathspec, @@ -49,6 +50,15 @@ buildPythonPackage rec { hash = "sha256-sm/pxQGxH5XuPH7B8i3fpp30KaFU9aSp6BT67UcDPvU="; }; + patches = [ + # fix build w/ glibc-2.44 + # If Python.h isn't included first, a const redefinition error now occurs otherwise. + (fetchpatch { + url = "https://github.com/python/mypy/commit/46acbe85c0e1703ebf2e6d4c699772edcdcf4652.patch"; + hash = "sha256-KslHiKqinvvXZoxvCnZXOhCm7i8577PbSdNGudCsjZE="; + }) + ]; + passthru.updateScript = gitUpdater { rev-prefix = "v"; }; From 1e23b1be785ea5d625c65aff6de3333831a842fb Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:28:45 +0200 Subject: [PATCH 12/82] glibc: 2.42-84 -> 2.44-25 Announcements: * https://inbox.sourceware.org/libc-announce/13932477.uLZWGnKmhe@pinacolada/T/#u * https://inbox.sourceware.org/libc-announce/teaVXxrfQH2qv0xBul7sXg@gentoo.org/T/#u Closes #502924 --- ...l-usage-of-BASH-or-BASH-in-installed.patch | 36 +- .../libraries/glibc/2.42-master.patch | 11174 ---------------- .../libraries/glibc/2.44-master.patch | 4138 ++++++ pkgs/development/libraries/glibc/common.nix | 14 +- .../glibc/dont-use-system-ld-so-cache.patch | 27 +- 5 files changed, 4179 insertions(+), 11210 deletions(-) delete mode 100644 pkgs/development/libraries/glibc/2.42-master.patch create mode 100644 pkgs/development/libraries/glibc/2.44-master.patch diff --git a/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch b/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch index 25cb329e086e..d1ea3ad0cdd2 100644 --- a/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch +++ b/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch @@ -1,4 +1,4 @@ -From c1c36f73aa3085a856c7cf36d69c21d18d3ef5ac Mon Sep 17 00:00:00 2001 +From 0ea28d2f38500559734cb0fe99eae40c04783730 Mon Sep 17 00:00:00 2001 From: Bernardo Meurer Date: Fri, 22 Jul 2022 22:11:07 -0700 Subject: [PATCH] Revert "Remove all usage of @BASH@ or ${BASH} in installed @@ -22,10 +22,10 @@ Co-authored-by: Maximilian Bosch 8 files changed, 15 insertions(+), 10 deletions(-) diff --git a/debug/Makefile b/debug/Makefile -index 6a05205ce6..dd63b16ae8 100644 +index c6c1069b40..ccecf6b70b 100644 --- a/debug/Makefile +++ b/debug/Makefile -@@ -345,8 +345,9 @@ $(objpfx)pcprofiledump: $(objpfx)pcprofiledump.o +@@ -407,8 +407,9 @@ $(objpfx)pcprofiledump: $(objpfx)pcprofiledump.o $(objpfx)xtrace: xtrace.sh rm -f $@.new @@ -38,17 +38,17 @@ index 6a05205ce6..dd63b16ae8 100644 && rm -f $@ && mv $@.new $@ && chmod +x $@ diff --git a/debug/xtrace.sh b/debug/xtrace.sh -index 00bafd33db..d0f9fca9a9 100755 +index a1bb50eeaf..01383c7c79 100755 --- a/debug/xtrace.sh +++ b/debug/xtrace.sh @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 1999-2025 Free Software Foundation, Inc. + # Copyright (C) 1999-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/elf/Makefile b/elf/Makefile -index 4b1d0d8741..bbcf688c99 100644 +index d279a5135c..dc39ccea60 100644 --- a/elf/Makefile +++ b/elf/Makefile @@ -250,7 +250,8 @@ $(objpfx)sotruss-lib.so: $(common-objpfx)libc.so $(objpfx)ld.so \ @@ -61,7 +61,7 @@ index 4b1d0d8741..bbcf688c99 100644 -e 's%@TEXTDOMAINDIR@%$(localedir)%g' \ -e 's%@PREFIX@%$(prefix)%g' \ -e 's|@PKGVERSION@|$(PKGVERSION)|g' \ -@@ -1556,6 +1557,7 @@ ldd-rewrite = -e 's%@RTLD@%$(rtlddir)/$(rtld-installed-name)%g' \ +@@ -1720,6 +1721,7 @@ ldd-rewrite = -e 's%@RTLD@%$(rtlddir)/$(rtld-installed-name)%g' \ -e 's%@VERSION@%$(version)%g' \ -e 's|@PKGVERSION@|$(PKGVERSION)|g' \ -e 's|@REPORT_BUGS_TO@|$(REPORT_BUGS_TO)|g' \ @@ -70,30 +70,30 @@ index 4b1d0d8741..bbcf688c99 100644 ifeq ($(ldd-rewrite-script),no) diff --git a/elf/ldd.bash.in b/elf/ldd.bash.in -index 2d3df6e57e..0faf83dc86 100644 +index bfc40f6505..59ca54e2d9 100644 --- a/elf/ldd.bash.in +++ b/elf/ldd.bash.in @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 1996-2025 Free Software Foundation, Inc. + # Copyright (C) 1996-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/elf/sotruss.sh b/elf/sotruss.sh -index 8944645df9..1c36981b22 100755 +index c90abaaed9..03cb25bc57 100755 --- a/elf/sotruss.sh +++ b/elf/sotruss.sh @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 2011-2025 Free Software Foundation, Inc. + # Copyright (C) 2011-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/malloc/Makefile b/malloc/Makefile -index e2b2c1ae1b..67a399f1dd 100644 +index 72aa77af20..e148b6480a 100644 --- a/malloc/Makefile +++ b/malloc/Makefile -@@ -359,8 +359,9 @@ $(objpfx)mtrace: mtrace.pl +@@ -484,8 +484,9 @@ $(objpfx)mtrace: mtrace.pl $(objpfx)memusage: memusage.sh rm -f $@.new @@ -106,20 +106,20 @@ index e2b2c1ae1b..67a399f1dd 100644 && rm -f $@ && mv $@.new $@ && chmod +x $@ diff --git a/malloc/memusage.sh b/malloc/memusage.sh -index 8ae435d2f8..c929d16af7 100755 +index 309991a7c9..28117c4561 100755 --- a/malloc/memusage.sh +++ b/malloc/memusage.sh @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 1999-2025 Free Software Foundation, Inc. + # Copyright (C) 1999-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/timezone/Makefile b/timezone/Makefile -index ebe5cf73a1..e9cf92861c 100644 +index ce9abe6cb2..3ee1eed54a 100644 --- a/timezone/Makefile +++ b/timezone/Makefile -@@ -139,7 +139,8 @@ $(testdata)/XT5: testdata/gen-XT5.sh +@@ -136,7 +136,8 @@ $(testdata)/XT5: testdata/gen-XT5.sh mv $@.tmp $@ $(objpfx)tzselect: tzselect.ksh $(common-objpfx)config.make @@ -130,5 +130,5 @@ index ebe5cf73a1..e9cf92861c 100644 -e '/PKGVERSION=/s|=.*|="$(PKGVERSION)"|' \ -e '/REPORT_BUGS_TO=/s|=.*|="$(REPORT_BUGS_TO)"|' \ -- -2.47.2 +2.54.0 diff --git a/pkgs/development/libraries/glibc/2.42-master.patch b/pkgs/development/libraries/glibc/2.42-master.patch deleted file mode 100644 index 8abd567ee32b..000000000000 --- a/pkgs/development/libraries/glibc/2.42-master.patch +++ /dev/null @@ -1,11174 +0,0 @@ -commit bdea6c37197a3c9bd976911cce5f580dea1c28dd -Author: Andreas K. Hüttel -Date: Mon Jul 28 20:35:38 2025 +0200 - - Replace advisories directory with pointer file - - Signed-off-by: Andreas K. Hüttel - -diff --git a/advisories/GLIBC-SA-2023-0001 b/advisories/GLIBC-SA-2023-0001 -deleted file mode 100644 -index 3d19c91b6a..0000000000 ---- a/advisories/GLIBC-SA-2023-0001 -+++ /dev/null -@@ -1,14 +0,0 @@ --printf: incorrect output for integers with thousands separator and width field -- --When the printf family of functions is called with a format specifier --that uses an (enable grouping) and a minimum width --specifier, the resulting output could be larger than reasonably expected --by a caller that computed a tight bound on the buffer size. The --resulting larger than expected output could result in a buffer overflow --in the printf family of functions. -- --CVE-Id: CVE-2023-25139 --Public-Date: 2023-02-02 --Vulnerable-Commit: e88b9f0e5cc50cab57a299dc7efe1a4eb385161d (2.37) --Fix-Commit: c980549cc6a1c03c23cc2fe3e7b0fe626a0364b0 (2.38) --Fix-Commit: 07b9521fc6369d000216b96562ff7c0ed32a16c4 (2.37-4) -diff --git a/advisories/GLIBC-SA-2023-0002 b/advisories/GLIBC-SA-2023-0002 -deleted file mode 100644 -index 5122669a64..0000000000 ---- a/advisories/GLIBC-SA-2023-0002 -+++ /dev/null -@@ -1,15 +0,0 @@ --getaddrinfo: Stack read overflow in no-aaaa mode -- --If the system is configured in no-aaaa mode via /etc/resolv.conf, --getaddrinfo is called for the AF_UNSPEC address family, and a DNS --response is received over TCP that is larger than 2048 bytes, --getaddrinfo may potentially disclose stack contents via the returned --address data, or crash. -- --CVE-Id: CVE-2023-4527 --Public-Date: 2023-09-12 --Vulnerable-Commit: f282cdbe7f436c75864e5640a409a10485e9abb2 (2.36) --Fix-Commit: bd77dd7e73e3530203be1c52c8a29d08270cb25d (2.39) --Fix-Commit: 4ea972b7edd7e36610e8cde18bf7a8149d7bac4f (2.36-113) --Fix-Commit: b7529346025a130fee483d42178b5c118da971bb (2.37-38) --Fix-Commit: b25508dd774b617f99419bdc3cf2ace4560cd2d6 (2.38-19) -diff --git a/advisories/GLIBC-SA-2023-0003 b/advisories/GLIBC-SA-2023-0003 -deleted file mode 100644 -index d3aef80348..0000000000 ---- a/advisories/GLIBC-SA-2023-0003 -+++ /dev/null -@@ -1,15 +0,0 @@ --getaddrinfo: Potential use-after-free -- --When an NSS plugin only implements the _gethostbyname2_r and --_getcanonname_r callbacks, getaddrinfo could use memory that was freed --during buffer resizing, potentially causing a crash or read or write to --arbitrary memory. -- --CVE-Id: CVE-2023-4806 --Public-Date: 2023-09-12 --Fix-Commit: 973fe93a5675c42798b2161c6f29c01b0e243994 (2.39) --Fix-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) --Fix-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) --Fix-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) --Fix-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) --Fix-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) -diff --git a/advisories/GLIBC-SA-2023-0004 b/advisories/GLIBC-SA-2023-0004 -deleted file mode 100644 -index 5286a7aa54..0000000000 ---- a/advisories/GLIBC-SA-2023-0004 -+++ /dev/null -@@ -1,16 +0,0 @@ --tunables: local privilege escalation through buffer overflow -- --If a tunable of the form NAME=NAME=VAL is passed in the environment of a --setuid program and NAME is valid, it may result in a buffer overflow, --which could be exploited to achieve escalated privileges. This flaw was --introduced in glibc 2.34. -- --CVE-Id: CVE-2023-4911 --Public-Date: 2023-10-03 --Vulnerable-Commit: 2ed18c5b534d9e92fc006202a5af0df6b72e7aca (2.34) --Fix-Commit: 1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa (2.39) --Fix-Commit: dcc367f148bc92e7f3778a125f7a416b093964d9 (2.34-423) --Fix-Commit: c84018a05aec80f5ee6f682db0da1130b0196aef (2.35-274) --Fix-Commit: 22955ad85186ee05834e47e665056148ca07699c (2.36-118) --Fix-Commit: b4e23c75aea756b4bddc4abcf27a1c6dca8b6bd3 (2.37-45) --Fix-Commit: 750a45a783906a19591fb8ff6b7841470f1f5701 (2.38-27) -diff --git a/advisories/GLIBC-SA-2023-0005 b/advisories/GLIBC-SA-2023-0005 -deleted file mode 100644 -index cc4eb90b82..0000000000 ---- a/advisories/GLIBC-SA-2023-0005 -+++ /dev/null -@@ -1,18 +0,0 @@ --getaddrinfo: DoS due to memory leak -- --The fix for CVE-2023-4806 introduced a memory leak when an application --calls getaddrinfo for AF_INET6 with AI_CANONNAME, AI_ALL and AI_V4MAPPED --flags set. -- --CVE-Id: CVE-2023-5156 --Public-Date: 2023-09-25 --Vulnerable-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) --Vulnerable-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) --Vulnerable-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) --Vulnerable-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) --Vulnerable-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) --Fix-Commit: 8006457ab7e1cd556b919f477348a96fe88f2e49 (2.34-421) --Fix-Commit: 17092c0311f954e6f3c010f73ce3a78c24ac279a (2.35-272) --Fix-Commit: 856bac55f98dc840e7c27cfa82262b933385de90 (2.36-116) --Fix-Commit: 4473d1b87d04b25cdd0e0354814eeaa421328268 (2.37-42) --Fix-Commit: 5ee59ca371b99984232d7584fe2b1a758b4421d3 (2.38-24) -diff --git a/advisories/GLIBC-SA-2024-0001 b/advisories/GLIBC-SA-2024-0001 -deleted file mode 100644 -index 28931c75ae..0000000000 ---- a/advisories/GLIBC-SA-2024-0001 -+++ /dev/null -@@ -1,15 +0,0 @@ --syslog: Heap buffer overflow in __vsyslog_internal -- --__vsyslog_internal did not handle a case where printing a SYSLOG_HEADER --containing a long program name failed to update the required buffer --size, leading to the allocation and overflow of a too-small buffer on --the heap. -- --CVE-Id: CVE-2023-6246 --Public-Date: 2024-01-30 --Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) --Fix-Commit: 6bd0e4efcc78f3c0115e5ea9739a1642807450da (2.39) --Fix-Commit: 23514c72b780f3da097ecf33a793b7ba9c2070d2 (2.38-42) --Fix-Commit: 97a4292aa4a2642e251472b878d0ec4c46a0e59a (2.37-57) --Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) --Fix-Commit: d1a83b6767f68b3cb5b4b4ea2617254acd040c82 (2.36-126) -diff --git a/advisories/GLIBC-SA-2024-0002 b/advisories/GLIBC-SA-2024-0002 -deleted file mode 100644 -index 940bfcf2fc..0000000000 ---- a/advisories/GLIBC-SA-2024-0002 -+++ /dev/null -@@ -1,15 +0,0 @@ --syslog: Heap buffer overflow in __vsyslog_internal -- --__vsyslog_internal used the return value of snprintf/vsnprintf to --calculate buffer sizes for memory allocation. If these functions (for --any reason) failed and returned -1, the resulting buffer would be too --small to hold output. -- --CVE-Id: CVE-2023-6779 --Public-Date: 2024-01-30 --Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) --Fix-Commit: 7e5a0c286da33159d47d0122007aac016f3e02cd (2.39) --Fix-Commit: d0338312aace5bbfef85e03055e1212dd0e49578 (2.38-43) --Fix-Commit: 67062eccd9a65d7fda9976a56aeaaf6c25a80214 (2.37-58) --Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) --Fix-Commit: 2bc9d7c002bdac38b5c2a3f11b78e309d7765b83 (2.36-127) -diff --git a/advisories/GLIBC-SA-2024-0003 b/advisories/GLIBC-SA-2024-0003 -deleted file mode 100644 -index b43a5150ab..0000000000 ---- a/advisories/GLIBC-SA-2024-0003 -+++ /dev/null -@@ -1,13 +0,0 @@ --syslog: Integer overflow in __vsyslog_internal -- --__vsyslog_internal calculated a buffer size by adding two integers, but --did not first check if the addition would overflow. -- --CVE-Id: CVE-2023-6780 --Public-Date: 2024-01-30 --Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) --Fix-Commit: ddf542da94caf97ff43cc2875c88749880b7259b (2.39) --Fix-Commit: d37c2b20a4787463d192b32041c3406c2bd91de0 (2.38-44) --Fix-Commit: 2b58cba076e912961ceaa5fa58588e4b10f791c0 (2.37-59) --Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) --Fix-Commit: b9b7d6a27aa0632f334352fa400771115b3c69b7 (2.36-128) -diff --git a/advisories/GLIBC-SA-2024-0004 b/advisories/GLIBC-SA-2024-0004 -deleted file mode 100644 -index 08df2b3118..0000000000 ---- a/advisories/GLIBC-SA-2024-0004 -+++ /dev/null -@@ -1,28 +0,0 @@ --ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence -- --The iconv() function in the GNU C Library versions 2.39 and older may --overflow the output buffer passed to it by up to 4 bytes when converting --strings to the ISO-2022-CN-EXT character set, which may be used to --crash an application or overwrite a neighbouring variable. -- --ISO-2022-CN-EXT uses escape sequences to indicate character set changes --(as specified by RFC 1922). While the SOdesignation has the expected --bounds checks, neither SS2designation nor SS3designation have its; --allowing a write overflow of 1, 2, or 3 bytes with fixed values: --'$+I', '$+J', '$+K', '$+L', '$+M', or '$*H'. -- --CVE-Id: CVE-2024-2961 --Public-Date: 2024-04-17 --Vulnerable-Commit: 755104edc75c53f4a0e7440334e944ad3c6b32fc (2.1.93-169) --Fix-Commit: f9dc609e06b1136bb0408be9605ce7973a767ada (2.40) --Fix-Commit: 31da30f23cddd36db29d5b6a1c7619361b271fb4 (2.39-31) --Fix-Commit: e1135387deded5d73924f6ca20c72a35dc8e1bda (2.38-66) --Fix-Commit: 89ce64b269a897a7780e4c73a7412016381c6ecf (2.37-89) --Fix-Commit: 4ed98540a7fd19f458287e783ae59c41e64df7b5 (2.36-164) --Fix-Commit: 36280d1ce5e245aabefb877fe4d3c6cff95dabfa (2.35-315) --Fix-Commit: a8b0561db4b9847ebfbfec20075697d5492a363c (2.34-459) --Fix-Commit: ed4f16ff6bed3037266f1fa682ebd32a18fce29c (2.33-263) --Fix-Commit: 682ad4c8623e611a971839990ceef00346289cc9 (2.32-140) --Fix-Commit: 3703c32a8d304c1ee12126134ce69be965f38000 (2.31-154) -- --Reported-By: Charles Fol -diff --git a/advisories/GLIBC-SA-2024-0005 b/advisories/GLIBC-SA-2024-0005 -deleted file mode 100644 -index a59596610a..0000000000 ---- a/advisories/GLIBC-SA-2024-0005 -+++ /dev/null -@@ -1,22 +0,0 @@ --nscd: Stack-based buffer overflow in netgroup cache -- --If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted --by client requests then a subsequent client request for netgroup data --may result in a stack-based buffer overflow. This flaw was introduced --in glibc 2.15 when the cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --CVE-Id: CVE-2024-33599 --Public-Date: 2024-04-23 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: 69c58d5ef9f584ea198bd00f7964d364d0e6b921 (2.31-155) --Fix-Commit: a77064893bfe8a701770e2f53a4d33805bc47a5a (2.32-141) --Fix-Commit: 5c75001a96abcd50cbdb74df24c3f013188d076e (2.33-264) --Fix-Commit: 52f73e5c4e29b14e79167272297977f360ae1e97 (2.34-460) --Fix-Commit: 7a95873543ce225376faf13bb71c43dea6d24f86 (2.35-316) --Fix-Commit: caa3151ca460bdd9330adeedd68c3112d97bffe4 (2.36-165) --Fix-Commit: f75c298e747b2b8b41b1c2f551c011a52c41bfd1 (2.37-91) --Fix-Commit: 5968aebb86164034b8f8421b4abab2f837a5bdaf (2.38-72) --Fix-Commit: 1263d583d2e28afb8be53f8d6922f0842036f35d (2.39-35) --Fix-Commit: 87801a8fd06db1d654eea3e4f7626ff476a9bdaa (2.40) -diff --git a/advisories/GLIBC-SA-2024-0006 b/advisories/GLIBC-SA-2024-0006 -deleted file mode 100644 -index d44148d3d9..0000000000 ---- a/advisories/GLIBC-SA-2024-0006 -+++ /dev/null -@@ -1,32 +0,0 @@ --nscd: Null pointer crash after notfound response -- --If the Name Service Cache Daemon's (nscd) cache fails to add a not-found --netgroup response to the cache, the client request can result in a null --pointer dereference. This flaw was introduced in glibc 2.15 when the --cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --CVE-Id: CVE-2024-33600 --Public-Date: 2024-04-24 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: b048a482f088e53144d26a61c390bed0210f49f2 (2.40) --Fix-Commit: 7835b00dbce53c3c87bbbb1754a95fb5e58187aa (2.40) --Fix-Commit: c99f886de54446cd4447db6b44be93dabbdc2f8b (2.39-37) --Fix-Commit: 5a508e0b508c8ad53bd0d2fb48fd71b242626341 (2.39-36) --Fix-Commit: 2ae9446c1b7a3064743b4a51c0bbae668ee43e4c (2.38-74) --Fix-Commit: 541ea5172aa658c4bd5c6c6d6fd13903c3d5bb0a (2.38-73) --Fix-Commit: a8070b31043c7585c36ba68a74298c4f7af075c3 (2.37-93) --Fix-Commit: 5eea50c4402e39588de98aa1d4469a79774703d4 (2.37-92) --Fix-Commit: f205b3af56740e3b014915b1bd3b162afe3407ef (2.36-167) --Fix-Commit: c34f470a615b136170abd16142da5dd0c024f7d1 (2.36-166) --Fix-Commit: bafadc589fbe21ae330e8c2af74db9da44a17660 (2.35-318) --Fix-Commit: 4370bef52b0f3f3652c6aa13d7a9bb3ac079746d (2.35-317) --Fix-Commit: 1f94122289a9bf7dba573f5d60327aaa2b85cf2e (2.34-462) --Fix-Commit: 966d6ac9e40222b84bb21674cc4f83c8d72a5a26 (2.34-461) --Fix-Commit: e3eef1b8fbdd3a7917af466ca9c4b7477251ca79 (2.33-266) --Fix-Commit: f20a8d696b13c6261b52a6434899121f8b19d5a7 (2.33-265) --Fix-Commit: be602180146de37582a3da3a0caa4b719645de9c (2.32-143) --Fix-Commit: 394eae338199078b7961b051c191539870742d7b (2.32-142) --Fix-Commit: 8d7949183760170c61e55def723c1d8050187874 (2.31-157) --Fix-Commit: 304ce5fe466c4762b21b36c26926a4657b59b53e (2.31-156) -diff --git a/advisories/GLIBC-SA-2024-0007 b/advisories/GLIBC-SA-2024-0007 -deleted file mode 100644 -index b6928fa27a..0000000000 ---- a/advisories/GLIBC-SA-2024-0007 -+++ /dev/null -@@ -1,28 +0,0 @@ --nscd: netgroup cache may terminate daemon on memory allocation failure -- --The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or --xrealloc and these functions may terminate the process due to a memory --allocation failure resulting in a denial of service to the clients. The --flaw was introduced in glibc 2.15 when the cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --Subsequent refactoring of the netgroup cache only added more uses of --xmalloc and xrealloc. Uses of xmalloc and xrealloc in other parts of --nscd only occur during startup of the daemon and so are not affected by --client requests that could trigger an out of memory followed by --termination. -- --CVE-Id: CVE-2024-33601 --Public-Date: 2024-04-24 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) --Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) --Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) --Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) --Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) --Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) --Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) --Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) --Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) --Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) -diff --git a/advisories/GLIBC-SA-2024-0008 b/advisories/GLIBC-SA-2024-0008 -deleted file mode 100644 -index d93e2a6f0b..0000000000 ---- a/advisories/GLIBC-SA-2024-0008 -+++ /dev/null -@@ -1,26 +0,0 @@ --nscd: netgroup cache assumes NSS callback uses in-buffer strings -- --The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory --when the NSS callback does not store all strings in the provided buffer. --The flaw was introduced in glibc 2.15 when the cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --There is no guarantee from the NSS callback API that the returned --strings are all within the buffer. However, the netgroup cache code --assumes that the NSS callback uses in-buffer strings and if it doesn't --the buffer resizing logic could lead to potential memory corruption. -- --CVE-Id: CVE-2024-33602 --Public-Date: 2024-04-24 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) --Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) --Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) --Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) --Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) --Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) --Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) --Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) --Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) --Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) -diff --git a/advisories/GLIBC-SA-2025-0001 b/advisories/GLIBC-SA-2025-0001 -deleted file mode 100644 -index b053d32e91..0000000000 ---- a/advisories/GLIBC-SA-2025-0001 -+++ /dev/null -@@ -1,40 +0,0 @@ --assert: Buffer overflow when printing assertion failure message -- --When the assert() function fails, it does not allocate enough space for the --assertion failure message string and size information, which may lead to a --buffer overflow if the message string size aligns to page size. -- --This bug can be triggered when an assertion in a program fails. The assertion --failure message is allocated to allow developers to see this failure in core --dumps and it typically includes, in addition to the invariant assertion --string and function name, the name of the program. If the name of the failing --program is user controlled, for example on a local system, this could allow an --attacker to control the assertion failure to trigger this buffer overflow. -- --The only viable vector for exploitation of this bug is local, if a setuid --program exists that has an existing bug that results in an assertion failure. --No such program has been discovered at the time of publishing this advisory, --but the presence of custom setuid programs, although strongly discouraged as a --security practice, cannot be discounted. -- --CVE-Id: CVE-2025-0395 --Public-Date: 2025-01-22 --Vulnerable-Commit: f8a3b5bf8fa1d0c43d2458e03cc109a04fdef194 (2.13-175) --Fix-Commit: 68ee0f704cb81e9ad0a78c644a83e1e9cd2ee578 (2.41) --Fix-Commit: cdb9ba84191ce72e86346fb8b1d906e7cd930ea2 (2.42) --Fix-Commit: 69fda28279b497bd405fdd442a6d8e4d3d5f681b (2.41-7) --Fix-Commit: 7d4b6bcae91f29d7b4daf15bab06b66cf1d2217c (2.40-66) --Fix-Commit: d6c156c326999f144cb5b73d29982108d549ad8a (2.40-71) --Fix-Commit: 808a84a8b81468b517a4d721fdc62069cb8c211f (2.39-146) --Fix-Commit: f6d48470aef9264d2d56f4c4533eb76db7f9c2e4 (2.39-150) --Fix-Commit: c32fd59314c343db88c3ea4a203870481d33c3d2 (2.38-122) --Fix-Commit: f984e2d7e8299726891a1a497a3c36cd5542a0bf (2.38-124) --Fix-Commit: a3d7865b098a3a67c44f7812208d9ce4718873ba (2.37-143) --Fix-Commit: b989519fe1683c204ac24ec92830e3fe3bfaccad (2.37-146) --Fix-Commit: 7971add7ee4171fdd8dfd17e7c04c4ed77a18845 (2.36-216) --Fix-Commit: 0487893d5c5bc6710d83d7c3152d888a0339559e (2.36-219) --Fix-Commit: 8b5d4be762419c4f6176261c6fea40ac559b88dc (2.35-370) --Fix-Commit: 8b3d09dc0d350191985f9d291cc30ce96f034b49 (2.35-373) --Fix-Commit: df4e1f4a5096b385c9bcc94424cf2eaa227b3761 (2.34-500) --Fix-Commit: 31eb872cb21449832ab47ad5db83281d240e1d03 (2.34-503) --Reported-By: Qualys Security Advisory -diff --git a/advisories/GLIBC-SA-2025-0002 b/advisories/GLIBC-SA-2025-0002 -deleted file mode 100644 -index 161da13dd4..0000000000 ---- a/advisories/GLIBC-SA-2025-0002 -+++ /dev/null -@@ -1,23 +0,0 @@ --elf: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH -- --A statically linked setuid binary that calls dlopen (including internal --dlopen calls after setlocale or calls to NSS functions such as getaddrinfo) --may incorrectly search LD_LIBRARY_PATH to determine which library to load, --leading to the execution of library code that is attacker controlled. -- --The only viable vector for exploitation of this bug is local, if a static --setuid program exists, and that program calls dlopen, then it may search --LD_LIBRARY_PATH to locate the SONAME to load. No such program has been --discovered at the time of publishing this advisory, but the presence of --custom setuid programs, although strongly discouraged as a security --practice, cannot be discounted. -- --CVE-Id: CVE-2025-4802 --Public-Date: 2025-05-16 --Vulnerable-Commit: 10e93d968716ab82931d593bada121c17c0a4b93 (2.27) --Fix-Commit: 5451fa962cd0a90a0e2ec1d8910a559ace02bba0 (2.39) --Fix-Commit: 3be3728df2f1912c80abd3288bc6e3a25ad679e4 (2.38-132) --Fix-Commit: 7403ede2d7752e59e0c47d5d33d73c2bf850e7be (2.37-154) --Fix-Commit: 2ef7850279b2931caf6d6d6743ebaa91839e1cf7 (2.36-227) --Fix-Commit: 621c65ccf12ddd415ceeb2234423bd1acd0fabb3 (2.35-387) --Fix-Commit: 35018c0fd20eac9ceaf60060fed2745b3177359d (2.34-517) -diff --git a/advisories/GLIBC-SA-2025-0003 b/advisories/GLIBC-SA-2025-0003 -deleted file mode 100644 -index 2adeb3ce00..0000000000 ---- a/advisories/GLIBC-SA-2025-0003 -+++ /dev/null -@@ -1,30 +0,0 @@ --power10: strcmp fails to save and restore nonvolatile vector registers -- --The Power 10 implementation of strcmp in --sysdeps/powerpc/powerpc64/le/power10/strcmp.S failed to save/restore --nonvolatile vector registers in the 32-byte aligned loop path. This --results in callers reading content from those registers in a different --context, potentially altering program logic. -- --There could be a program context where a user controlled string could --leak through strcmp into program code, thus altering its logic. There --is also a potential for sensitive strings passed into strcmp leaking --through the clobbered registers into parts of the calling program that --should otherwise not have had access to those strings. -- --The impact of this flaw is limited to applications running on Power 10 --hardware that use the nonvolatile vector registers, i.e. v20 to v31 --assuming that they have been treated in accordance with the OpenPower --psABI. It is possible to work around the issue for those specific --applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like --so: -- -- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 -- --CVE-Id: CVE-2025-5702 --Public-Date: 2025-06-04 --Vulnerable-Commit: 3367d8e180848030d1646f088759f02b8dfe0d6f (2.39) --Fix-Commit: 15808c77b35319e67ee0dc8f984a9a1a434701bc (2.42) --Fix-Commit: 0c76c951620f9e12df2a89b2c684878b55bb6795 (2.41-60) --Fix-Commit: 7e12550b8e3a11764a4a9090ce6bd3fc23fc8a8e (2.40-139) --Fix-Commit: 06a70769fd0b2e1f2a3085ad50ab620282bd77b3 (2.39-209) -diff --git a/advisories/GLIBC-SA-2025-0004 b/advisories/GLIBC-SA-2025-0004 -deleted file mode 100644 -index 9409ca27c4..0000000000 ---- a/advisories/GLIBC-SA-2025-0004 -+++ /dev/null -@@ -1,29 +0,0 @@ --power10: strncmp fails to save and restore nonvolatile vector registers -- --The Power 10 implementation of strncmp in --sysdeps/powerpc/powerpc64/le/power10/strncmp.S failed to save/restore --nonvolatile vector registers in the 32-byte aligned loop path. This --results in callers reading content from those registers in a different --context, potentially altering program logic. -- --There could be a program context where a user controlled string could --leak through strncmp into program code, thus altering its logic. There --is also a potential for sensitive strings passed into strncmp leaking --through the clobbered registers into parts of the calling program that --should otherwise not have had access to those strings. -- --The impact of this flaw is limited to applications running on Power 10 --hardware that use the nonvolatile vector registers, i.e. v20 to v31 --assuming that they have been treated in accordance with the OpenPower --psABI. It is possible to work around the issue for those specific --applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like --so: -- -- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 -- --CVE-Id: CVE-2025-5745 --Public-Date: 2025-06-05 --Vulnerable-Commit: 23f0d81608d0ca6379894ef81670cf30af7fd081 (2.40) --Fix-Commit: 63c60101ce7c5eac42be90f698ba02099b41b965 (2.42) --Fix-Commit: 84bdbf8a6f2fdafd3661489dbb7f79835a52da82 (2.41-57) --Fix-Commit: 42a5a940c974d02540c8da26d6374c744d148cb9 (2.40-136) -diff --git a/advisories/GLIBC-SA-2025-0005 b/advisories/GLIBC-SA-2025-0005 -deleted file mode 100644 -index 8bcccc59a5..0000000000 ---- a/advisories/GLIBC-SA-2025-0005 -+++ /dev/null -@@ -1,14 +0,0 @@ --posix: Fix double-free after allocation failure in regcomp -- --The regcomp function in the GNU C library version from 2.4 to 2.41 is --subject to a double free if some previous allocation fails. It can be --accomplished either by a malloc failure or by using an interposed --malloc that injects random malloc failures. The double free can allow --buffer manipulation depending of how the regex is constructed. --This issue affects all architectures and ABIs supported by the GNU C --library. -- --CVE-Id: CVE-2025-8058 --Public-Date: 2025-07-22 --Vulnerable-Commit: 963d8d782fc98fb6dc3a66f0068795f9920c269d (2.3.3-1596) --Fix-Commit: 7ea06e994093fa0bcca0d0ee2c1db271d8d7885d (2.42) -diff --git a/advisories/README b/advisories/README -deleted file mode 100644 -index b8f8a829ca..0000000000 ---- a/advisories/README -+++ /dev/null -@@ -1,77 +0,0 @@ --GNU C Library Security Advisory Format --====================================== -- --Security advisories in this directory follow a simple git commit log --format, with a heading and free-format description augmented with tags --to allow parsing key information. References to code changes are --specific to the glibc repository and follow a specific format: -- -- Tag-name: (release-version) -- --The indicates a specific commit in the repository. The --release-version indicates the publicly consumable release in which this --commit is known to exist. The release-version is derived from the --git-describe format, (i.e. stripped out from glibc-2.34.NNN-gxxxx) and --is of the form 2.34-NNN. If the -NNN suffix is absent, it means that --the change is in that release tarball, otherwise the change is on the --release/2.YY/master branch and not in any released tarball. -- --The following tags are currently being used: -- --CVE-Id: --This is the CVE-Id assigned under the CVE Program --(https://www.cve.org/). -- --Public-Date: --The date this issue became publicly known. -- --Vulnerable-Commit: --The commit that introduced this vulnerability. There could be multiple --entries, one for each release branch in the glibc repository; the --release-version portion of this tag should tell you which branch this is --on. -- --Fix-Commit: --The commit that fixed this vulnerability. There could be multiple --entries for each release branch in the glibc repository, indicating that --all of those commits contributed to fixing that issue in each of those --branches. -- --Reported-By: --The entity that reported this issue. There could be multiple entries, one for --each reporter. -- --Adding an Advisory -------------------- -- --An advisory for a CVE needs to be added on the master branch in two steps: -- --1. Add the text of the advisory without any Fix-Commit tags along with -- the fix for the CVE. Add the Vulnerable-Commit tag, if applicable. -- The advisories directory does not exist in release branches, so keep -- the advisory text commit distinct from the code changes, to ease -- backports. Ask for the GLIBC-SA advisory number from the security -- team. -- --2. Finish all backports on release branches and then back on the msater -- branch, add all commit refs to the advisory using the Fix-Commit -- tags. Don't bother adding the release-version subscript since the -- next step will overwrite it. -- --3. Run the process-advisories.sh script in the scripts directory on the -- advisory: -- -- scripts/process-advisories.sh update GLIBC-SA-YYYY-NNNN -- -- (replace YYYY-NNNN with the actual advisory number). -- --4. Verify the updated advisory and push the result. -- --Getting a NEWS snippet from advisories ---------------------------------------- -- --Run: -- -- scripts/process-advisories.sh news -- --and copy the content into the NEWS file. - -commit 3ec4dd77f648da031bba4d3fa14825e057b5a40d -Author: Andreas K. Hüttel -Date: Mon Jul 28 23:39:48 2025 +0200 - - NEWS: add new section - - Signed-off-by: Andreas K. Hüttel - -diff --git a/NEWS b/NEWS -index f0b0e924a4..9cb8de11f9 100644 ---- a/NEWS -+++ b/NEWS -@@ -5,6 +5,12 @@ See the end for copying conditions. - Please send GNU C library bug reports via - using `glibc' in the "product" field. - -+Version 2.42.1 -+ -+The following bugs were resolved with this release: -+ -+ [insert bugs here] -+ - Version 2.42 - - Major new features: - -commit bc13db73937730401d592b33092db6df806d193e -Author: Sam James -Date: Mon Jul 28 21:55:30 2025 +0100 - - inet-fortified: fix namespace violation (bug 33227) - - We need to use __sz, not sz, as we do elsewhere. - - Reviewed-by: Florian Weimer - (cherry picked from commit 87afbd7a1ad9c1dd116921817fa97198171045db) - -diff --git a/inet/bits/inet-fortified.h b/inet/bits/inet-fortified.h -index 6738221a54..cc476ebcfd 100644 ---- a/inet/bits/inet-fortified.h -+++ b/inet/bits/inet-fortified.h -@@ -45,15 +45,15 @@ __NTH (inet_pton (int __af, - __fortify_clang_warning_only_if_bos0_lt - (4, __dst, "inet_pton called with destination buffer size less than 4") - { -- size_t sz = 0; -+ size_t __sz = 0; - if (__af == AF_INET) -- sz = sizeof (struct in_addr); -+ __sz = sizeof (struct in_addr); - else if (__af == AF_INET6) -- sz = sizeof (struct in6_addr); -+ __sz = sizeof (struct in6_addr); - else - return __inet_pton_alias (__af, __src, __dst); - -- return __glibc_fortify (inet_pton, sz, sizeof (char), -+ return __glibc_fortify (inet_pton, __sz, sizeof (char), - __glibc_objsize (__dst), - __af, __src, __dst); - }; - -commit fd18059c0fcf5568db3688da47403b663cf91c5e -Author: Davide Cavalca -Date: Thu Jul 31 17:32:58 2025 +0200 - - stdlib: resolve a double lock init issue after fork [BZ #32994] - - The __abort_fork_reset_child (introduced in - d40ac01cbbc66e6d9dbd8e3485605c63b2178251) call resets the lock after the - fork. This causes a DRD regression in valgrind - (https://bugs.kde.org/show_bug.cgi?id=503668), as it's effectively a - double initialization, despite it being actually ok in this case. As - suggested in https://sourceware.org/bugzilla/show_bug.cgi?id=32994#c2 - we replace it here with a memcpy of another initialized lock instead, - which makes valgrind happy. - - Reviewed-by: Florian Weimer - (cherry picked from commit d9a348d0927c7a1aec5caf3df3fcd36956b3eb23) - -diff --git a/NEWS b/NEWS -index 9cb8de11f9..4610b8bbc6 100644 ---- a/NEWS -+++ b/NEWS -@@ -9,7 +9,7 @@ Version 2.42.1 - - The following bugs were resolved with this release: - -- [insert bugs here] -+ [32994] stdlib: resolve a double lock init issue after fork - - Version 2.42 - -diff --git a/stdlib/abort.c b/stdlib/abort.c -index caa9e6dc04..904244a2fb 100644 ---- a/stdlib/abort.c -+++ b/stdlib/abort.c -@@ -19,6 +19,7 @@ - #include - #include - #include -+#include - #include - - /* Try to get a machine dependent instruction which will make the -@@ -42,7 +43,10 @@ __libc_rwlock_define_initialized (static, lock); - void - __abort_fork_reset_child (void) - { -- __libc_rwlock_init (lock); -+ /* Reinitialize lock without calling pthread_rwlock_init, to -+ avoid a valgrind DRD false positive. */ -+ __libc_rwlock_define_initialized (, reset_lock); -+ memcpy (&lock, &reset_lock, sizeof (lock)); - } - - void - -commit 2fadee530155bae6682ab2965d6ff3a2fc9eced6 -Author: Florian Weimer -Date: Fri Aug 1 19:27:04 2025 +0200 - - elf: Extract rtld_setup_phdr function from dl_main - - Remove historic binutils reference from comment and update - how this data is used by applications. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 2cac9559e06044ba520e785c151fbbd25011865f) - -diff --git a/elf/rtld.c b/elf/rtld.c -index 493f9696ea..6fb900fb31 100644 ---- a/elf/rtld.c -+++ b/elf/rtld.c -@@ -1239,6 +1239,37 @@ rtld_setup_main_map (struct link_map *main_map) - return has_interp; - } - -+/* Set up the program header information for the dynamic linker -+ itself. It can be accessed via _r_debug and dl_iterate_phdr -+ callbacks. */ -+static void -+rtld_setup_phdr (void) -+{ -+ /* Starting from binutils-2.23, the linker will define the magic -+ symbol __ehdr_start to point to our own ELF header if it is -+ visible in a segment that also includes the phdrs. */ -+ -+ const ElfW(Ehdr) *rtld_ehdr = &__ehdr_start; -+ assert (rtld_ehdr->e_ehsize == sizeof *rtld_ehdr); -+ assert (rtld_ehdr->e_phentsize == sizeof (ElfW(Phdr))); -+ -+ const ElfW(Phdr) *rtld_phdr = (const void *) rtld_ehdr + rtld_ehdr->e_phoff; -+ -+ _dl_rtld_map.l_phdr = rtld_phdr; -+ _dl_rtld_map.l_phnum = rtld_ehdr->e_phnum; -+ -+ -+ /* PT_GNU_RELRO is usually the last phdr. */ -+ size_t cnt = rtld_ehdr->e_phnum; -+ while (cnt-- > 0) -+ if (rtld_phdr[cnt].p_type == PT_GNU_RELRO) -+ { -+ _dl_rtld_map.l_relro_addr = rtld_phdr[cnt].p_vaddr; -+ _dl_rtld_map.l_relro_size = rtld_phdr[cnt].p_memsz; -+ break; -+ } -+} -+ - /* Adjusts the contents of the stack and related globals for the user - entry point. The ld.so processed skip_args arguments and bumped - _dl_argv and _dl_argc accordingly. Those arguments are removed from -@@ -1705,33 +1736,7 @@ dl_main (const ElfW(Phdr) *phdr, - ++GL(dl_ns)[LM_ID_BASE]._ns_nloaded; - ++GL(dl_load_adds); - -- /* Starting from binutils-2.23, the linker will define the magic symbol -- __ehdr_start to point to our own ELF header if it is visible in a -- segment that also includes the phdrs. If that's not available, we use -- the old method that assumes the beginning of the file is part of the -- lowest-addressed PT_LOAD segment. */ -- -- /* Set up the program header information for the dynamic linker -- itself. It is needed in the dl_iterate_phdr callbacks. */ -- const ElfW(Ehdr) *rtld_ehdr = &__ehdr_start; -- assert (rtld_ehdr->e_ehsize == sizeof *rtld_ehdr); -- assert (rtld_ehdr->e_phentsize == sizeof (ElfW(Phdr))); -- -- const ElfW(Phdr) *rtld_phdr = (const void *) rtld_ehdr + rtld_ehdr->e_phoff; -- -- _dl_rtld_map.l_phdr = rtld_phdr; -- _dl_rtld_map.l_phnum = rtld_ehdr->e_phnum; -- -- -- /* PT_GNU_RELRO is usually the last phdr. */ -- size_t cnt = rtld_ehdr->e_phnum; -- while (cnt-- > 0) -- if (rtld_phdr[cnt].p_type == PT_GNU_RELRO) -- { -- _dl_rtld_map.l_relro_addr = rtld_phdr[cnt].p_vaddr; -- _dl_rtld_map.l_relro_size = rtld_phdr[cnt].p_memsz; -- break; -- } -+ rtld_setup_phdr (); - - /* Add the dynamic linker to the TLS list if it also uses TLS. */ - if (_dl_rtld_map.l_tls_blocksize != 0) - -commit 5e298d2d937b6da06500478be956abeb24357e05 -Author: Florian Weimer -Date: Fri Aug 1 19:27:35 2025 +0200 - - elf: Handle ld.so with LOAD segment gaps in _dl_find_object (bug 31943) - - Detect if ld.so not contiguous and handle that case in _dl_find_object. - Set l_find_object_processed even for initially loaded link maps, - otherwise dlopen of an initially loaded object adds it to - _dlfo_loaded_mappings (where maps are expected to be contiguous), - in addition to _dlfo_nodelete_mappings. - - Test elf/tst-link-map-contiguous-ldso iterates over the loader - image, reading every word to make sure memory is actually mapped. - It only does that if the l_contiguous flag is set for the link map. - Otherwise, it finds gaps with mmap and checks that _dl_find_object - does not return the ld.so mapping for them. - - The test elf/tst-link-map-contiguous-main does the same thing for - the libc.so shared object. This only works if the kernel loaded - the main program because the glibc dynamic loader may fill - the gaps with PROT_NONE mappings in some cases, making it contiguous, - but accesses to individual words may still fault. - - Test elf/tst-link-map-contiguous-libc is again slightly different - because the dynamic loader always fills the gaps with PROT_NONE - mappings, so a different form of probing has to be used. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 20681be149b9eb1b6c1f4246bf4bd801221c86cd) - -diff --git a/NEWS b/NEWS -index 4610b8bbc6..cbe11ac95b 100644 ---- a/NEWS -+++ b/NEWS -@@ -9,6 +9,7 @@ Version 2.42.1 - - The following bugs were resolved with this release: - -+ [31943] _dl_find_object can fail if ld.so contains gaps between load segments - [32994] stdlib: resolve a double lock init issue after fork - - Version 2.42 -diff --git a/elf/Makefile b/elf/Makefile -index 48aa0b57e5..3a5596e2bb 100644 ---- a/elf/Makefile -+++ b/elf/Makefile -@@ -543,6 +543,8 @@ tests-internal += \ - tst-dl_find_object-threads \ - tst-dlmopen2 \ - tst-hash-collision3 \ -+ tst-link-map-contiguous-ldso \ -+ tst-link-map-contiguous-libc \ - tst-ptrguard1 \ - tst-stackguard1 \ - tst-tls-surplus \ -@@ -554,6 +556,10 @@ tests-internal += \ - unload2 \ - # tests-internal - -+ifeq ($(build-hardcoded-path-in-tests),yes) -+tests-internal += tst-link-map-contiguous-main -+endif -+ - tests-container += \ - tst-dlopen-self-container \ - tst-dlopen-tlsmodid-container \ -diff --git a/elf/dl-find_object.c b/elf/dl-find_object.c -index 1e76373292..c9f4c1c8d1 100644 ---- a/elf/dl-find_object.c -+++ b/elf/dl-find_object.c -@@ -465,6 +465,37 @@ _dl_find_object (void *pc1, struct dl_find_object *result) - } - rtld_hidden_def (_dl_find_object) - -+/* Subroutine of _dlfo_process_initial to split out noncontigous link -+ maps. NODELETE is the number of used _dlfo_nodelete_mappings -+ elements. It is incremented as needed, and the new NODELETE value -+ is returned. */ -+static size_t -+_dlfo_process_initial_noncontiguous_map (struct link_map *map, -+ size_t nodelete) -+{ -+ struct dl_find_object_internal dlfo; -+ _dl_find_object_from_map (map, &dlfo); -+ -+ /* PT_LOAD segments for a non-contiguous link map are added to the -+ non-closeable mappings. */ -+ const ElfW(Phdr) *ph = map->l_phdr; -+ const ElfW(Phdr) *ph_end = map->l_phdr + map->l_phnum; -+ for (; ph < ph_end; ++ph) -+ if (ph->p_type == PT_LOAD) -+ { -+ if (_dlfo_nodelete_mappings != NULL) -+ { -+ /* Second pass only. */ -+ _dlfo_nodelete_mappings[nodelete] = dlfo; -+ ElfW(Addr) start = ph->p_vaddr + map->l_addr; -+ _dlfo_nodelete_mappings[nodelete].map_start = start; -+ _dlfo_nodelete_mappings[nodelete].map_end = start + ph->p_memsz; -+ } -+ ++nodelete; -+ } -+ return nodelete; -+} -+ - /* _dlfo_process_initial is called twice. First to compute the array - sizes from the initial loaded mappings. Second to fill in the - bases and infos arrays with the (still unsorted) data. Returns the -@@ -476,29 +507,8 @@ _dlfo_process_initial (void) - - size_t nodelete = 0; - if (!main_map->l_contiguous) -- { -- struct dl_find_object_internal dlfo; -- _dl_find_object_from_map (main_map, &dlfo); -- -- /* PT_LOAD segments for a non-contiguous are added to the -- non-closeable mappings. */ -- for (const ElfW(Phdr) *ph = main_map->l_phdr, -- *ph_end = main_map->l_phdr + main_map->l_phnum; -- ph < ph_end; ++ph) -- if (ph->p_type == PT_LOAD) -- { -- if (_dlfo_nodelete_mappings != NULL) -- { -- /* Second pass only. */ -- _dlfo_nodelete_mappings[nodelete] = dlfo; -- _dlfo_nodelete_mappings[nodelete].map_start -- = ph->p_vaddr + main_map->l_addr; -- _dlfo_nodelete_mappings[nodelete].map_end -- = _dlfo_nodelete_mappings[nodelete].map_start + ph->p_memsz; -- } -- ++nodelete; -- } -- } -+ /* Contiguous case already handled in _dl_find_object_init. */ -+ nodelete = _dlfo_process_initial_noncontiguous_map (main_map, nodelete); - - size_t loaded = 0; - for (Lmid_t ns = 0; ns < GL(dl_nns); ++ns) -@@ -510,11 +520,18 @@ _dlfo_process_initial (void) - /* lt_library link maps are implicitly NODELETE. */ - if (l->l_type == lt_library || l->l_nodelete_active) - { -- if (_dlfo_nodelete_mappings != NULL) -- /* Second pass only. */ -- _dl_find_object_from_map -- (l, _dlfo_nodelete_mappings + nodelete); -- ++nodelete; -+ /* The kernel may have loaded ld.so with gaps. */ -+ if (!l->l_contiguous && is_rtld_link_map (l)) -+ nodelete -+ = _dlfo_process_initial_noncontiguous_map (l, nodelete); -+ else -+ { -+ if (_dlfo_nodelete_mappings != NULL) -+ /* Second pass only. */ -+ _dl_find_object_from_map -+ (l, _dlfo_nodelete_mappings + nodelete); -+ ++nodelete; -+ } - } - else if (l->l_type == lt_loaded) - { -@@ -764,7 +781,6 @@ _dl_find_object_update_1 (struct link_map **loaded, size_t count) - /* Prefer newly loaded link map. */ - assert (loaded_index1 > 0); - _dl_find_object_from_map (loaded[loaded_index1 - 1], dlfo); -- loaded[loaded_index1 - 1]->l_find_object_processed = 1; - --loaded_index1; - } - -diff --git a/elf/dl-find_object.h b/elf/dl-find_object.h -index 9aa2439eaa..d9d75c4ad9 100644 ---- a/elf/dl-find_object.h -+++ b/elf/dl-find_object.h -@@ -94,7 +94,7 @@ _dl_find_object_to_external (struct dl_find_object_internal *internal, - } - - /* Extract the object location data from a link map and writes it to -- *RESULT using relaxed MO stores. */ -+ *RESULT using relaxed MO stores. Set L->l_find_object_processed. */ - static void __attribute__ ((unused)) - _dl_find_object_from_map (struct link_map *l, - struct dl_find_object_internal *result) -@@ -141,8 +141,11 @@ _dl_find_object_from_map (struct link_map *l, - break; - } - if (read_seg == 3) -- return; -+ goto done; - } -+ -+ done: -+ l->l_find_object_processed = 1; - } - - /* Called by the dynamic linker to set up the data structures for the -diff --git a/elf/rtld.c b/elf/rtld.c -index 6fb900fb31..ef4d96c053 100644 ---- a/elf/rtld.c -+++ b/elf/rtld.c -@@ -1241,7 +1241,7 @@ rtld_setup_main_map (struct link_map *main_map) - - /* Set up the program header information for the dynamic linker - itself. It can be accessed via _r_debug and dl_iterate_phdr -- callbacks. */ -+ callbacks, and it is used by _dl_find_object. */ - static void - rtld_setup_phdr (void) - { -@@ -1259,6 +1259,29 @@ rtld_setup_phdr (void) - _dl_rtld_map.l_phnum = rtld_ehdr->e_phnum; - - -+ _dl_rtld_map.l_contiguous = 1; -+ /* The linker may not have produced a contiguous object. The kernel -+ will load the object with actual gaps (unlike the glibc loader -+ for shared objects, which always produces a contiguous mapping). -+ See similar logic in rtld_setup_main_map above. */ -+ { -+ ElfW(Addr) expected_load_address = 0; -+ for (const ElfW(Phdr) *ph = rtld_phdr; ph < &rtld_phdr[rtld_ehdr->e_phnum]; -+ ++ph) -+ if (ph->p_type == PT_LOAD) -+ { -+ ElfW(Addr) mapstart = ph->p_vaddr & ~(GLRO(dl_pagesize) - 1); -+ if (_dl_rtld_map.l_contiguous && expected_load_address != 0 -+ && expected_load_address != mapstart) -+ _dl_rtld_map.l_contiguous = 0; -+ ElfW(Addr) allocend = ph->p_vaddr + ph->p_memsz; -+ /* The next expected address is the page following this load -+ segment. */ -+ expected_load_address = ((allocend + GLRO(dl_pagesize) - 1) -+ & ~(GLRO(dl_pagesize) - 1)); -+ } -+ } -+ - /* PT_GNU_RELRO is usually the last phdr. */ - size_t cnt = rtld_ehdr->e_phnum; - while (cnt-- > 0) -diff --git a/elf/tst-link-map-contiguous-ldso.c b/elf/tst-link-map-contiguous-ldso.c -new file mode 100644 -index 0000000000..04de808bb2 ---- /dev/null -+++ b/elf/tst-link-map-contiguous-ldso.c -@@ -0,0 +1,98 @@ -+/* Check that _dl_find_object behavior matches up with gaps. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ struct link_map *l = xdlopen (LD_SO, RTLD_NOW); -+ if (!l->l_contiguous) -+ { -+ puts ("info: ld.so link map is not contiguous"); -+ -+ /* Try to find holes by probing with mmap. */ -+ int pagesize = getpagesize (); -+ bool gap_found = false; -+ ElfW(Addr) addr = l->l_map_start; -+ TEST_COMPARE (addr % pagesize, 0); -+ while (addr < l->l_map_end) -+ { -+ void *expected = (void *) addr; -+ void *ptr = xmmap (expected, 1, PROT_READ | PROT_WRITE, -+ MAP_PRIVATE | MAP_ANONYMOUS, -1); -+ struct dl_find_object dlfo; -+ int dlfo_ret = _dl_find_object (expected, &dlfo); -+ if (ptr == expected) -+ { -+ if (dlfo_ret < 0) -+ { -+ TEST_COMPARE (dlfo_ret, -1); -+ printf ("info: hole without mapping data found at %p\n", ptr); -+ } -+ else -+ FAIL ("object \"%s\" found in gap at %p", -+ dlfo.dlfo_link_map->l_name, ptr); -+ gap_found = true; -+ } -+ else if (dlfo_ret == 0) -+ { -+ if ((void *) dlfo.dlfo_link_map != (void *) l) -+ { -+ printf ("info: object \"%s\" found at %p\n", -+ dlfo.dlfo_link_map->l_name, ptr); -+ gap_found = true; -+ } -+ } -+ else -+ TEST_COMPARE (dlfo_ret, -1); -+ xmunmap (ptr, 1); -+ addr += pagesize; -+ } -+ if (!gap_found) -+ FAIL ("no ld.so gap found"); -+ } -+ else -+ { -+ puts ("info: ld.so link map is contiguous"); -+ -+ /* Assert that ld.so is truly contiguous in memory. */ -+ volatile long int *p = (volatile long int *) l->l_map_start; -+ volatile long int *end = (volatile long int *) l->l_map_end; -+ while (p < end) -+ { -+ *p; -+ ++p; -+ } -+ } -+ -+ xdlclose (l); -+ -+ return 0; -+} -+ -+#include -diff --git a/elf/tst-link-map-contiguous-libc.c b/elf/tst-link-map-contiguous-libc.c -new file mode 100644 -index 0000000000..eb5728c765 ---- /dev/null -+++ b/elf/tst-link-map-contiguous-libc.c -@@ -0,0 +1,57 @@ -+/* Check that the entire libc.so program image is readable if contiguous. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ struct link_map *l = xdlopen (LIBC_SO, RTLD_NOW); -+ -+ /* The dynamic loader fills holes with PROT_NONE mappings. */ -+ if (!l->l_contiguous) -+ FAIL_EXIT1 ("libc.so link map is not contiguous"); -+ -+ /* Direct probing does not work because not everything is readable -+ due to PROT_NONE mappings. */ -+ int pagesize = getpagesize (); -+ ElfW(Addr) addr = l->l_map_start; -+ TEST_COMPARE (addr % pagesize, 0); -+ while (addr < l->l_map_end) -+ { -+ void *expected = (void *) addr; -+ void *ptr = xmmap (expected, 1, PROT_READ | PROT_WRITE, -+ MAP_PRIVATE | MAP_ANONYMOUS, -1); -+ if (ptr == expected) -+ FAIL ("hole in libc.so memory image after %lu bytes", -+ (unsigned long int) (addr - l->l_map_start)); -+ xmunmap (ptr, 1); -+ addr += pagesize; -+ } -+ -+ xdlclose (l); -+ -+ return 0; -+} -+#include -diff --git a/elf/tst-link-map-contiguous-main.c b/elf/tst-link-map-contiguous-main.c -new file mode 100644 -index 0000000000..2d1a054f0f ---- /dev/null -+++ b/elf/tst-link-map-contiguous-main.c -@@ -0,0 +1,45 @@ -+/* Check that the entire main program image is readable if contiguous. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ struct link_map *l = xdlopen ("", RTLD_NOW); -+ if (!l->l_contiguous) -+ FAIL_UNSUPPORTED ("main link map is not contiguous"); -+ -+ /* This check only works if the kernel loaded the main program. The -+ dynamic loader replaces gaps with PROT_NONE mappings, resulting -+ in faults. */ -+ volatile long int *p = (volatile long int *) l->l_map_start; -+ volatile long int *end = (volatile long int *) l->l_map_end; -+ while (p < end) -+ { -+ *p; -+ ++p; -+ } -+ -+ xdlclose (l); -+ -+ return 0; -+} -+#include - -commit b38f3f60d5b157edcf4d8bd1fd3ed02d417889e0 -Author: Adhemerval Zanella -Date: Fri Aug 1 15:00:25 2025 -0300 - - nptl: Fix SYSCALL_CANCEL for return values larger than INT_MAX (BZ 33245) - - The SYSCALL_CANCEL calls __syscall_cancel, which in turn - calls __internal_syscall_cancel with an 'int' return instead of the - expected 'long int'. This causes issues with syscalls that return - values larger than INT_MAX, such as copy_file_range [1]. - - Checked on x86_64-linux-gnu. - - [1] https://debbugs.gnu.org/cgi/bugreport.cgi?bug=79139 - - Reviewed-by: Andreas K. Huettel - (cherry picked from commit 7107bebf19286f42dcb0a97581137a5893c16206) - -diff --git a/NEWS b/NEWS -index cbe11ac95b..1d04bdfef8 100644 ---- a/NEWS -+++ b/NEWS -@@ -11,6 +11,7 @@ The following bugs were resolved with this release: - - [31943] _dl_find_object can fail if ld.so contains gaps between load segments - [32994] stdlib: resolve a double lock init issue after fork -+ [33245] nptl: nptl: error in internal cancellation syscall handling - - Version 2.42 - -diff --git a/nptl/cancellation.c b/nptl/cancellation.c -index 156e63dcf0..bed0383a23 100644 ---- a/nptl/cancellation.c -+++ b/nptl/cancellation.c -@@ -72,8 +72,8 @@ __syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, - __syscall_arg_t a5, __syscall_arg_t a6, - __SYSCALL_CANCEL7_ARG_DEF __syscall_arg_t nr) - { -- int r = __internal_syscall_cancel (a1, a2, a3, a4, a5, a6, -- __SYSCALL_CANCEL7_ARG nr); -+ long int r = __internal_syscall_cancel (a1, a2, a3, a4, a5, a6, -+ __SYSCALL_CANCEL7_ARG nr); - return __glibc_unlikely (INTERNAL_SYSCALL_ERROR_P (r)) - ? SYSCALL_ERROR_LABEL (INTERNAL_SYSCALL_ERRNO (r)) - : r; - -commit 9d5bf9c17db0f35268cd798660c8bbeea1f4071d -Author: H.J. Lu -Date: Sat Jul 19 07:43:26 2025 -0700 - - Delete temporary files in support_subprocess - - Call support_delete_temp_files to delete temporary files before exit in - support_subprocess. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit d27b1a71cd424710813bd3d81afb32a36470d643) - -diff --git a/support/support_subprocess.c b/support/support_subprocess.c -index be00dde3a7..8bf9a33ea2 100644 ---- a/support/support_subprocess.c -+++ b/support/support_subprocess.c -@@ -25,6 +25,7 @@ - #include - #include - #include -+#include - - static struct support_subprocess - support_subprocess_init (void) -@@ -60,6 +61,8 @@ support_subprocess (void (*callback) (void *), void *closure) - xclose (result.stdout_pipe[1]); - xclose (result.stderr_pipe[1]); - callback (closure); -+ /* Make sure that temporary files are deleted. */ -+ support_delete_temp_files (); - _exit (0); - } - xclose (result.stdout_pipe[1]); - -commit 9ec7a532ffdb9a6e0a4b220d7a694d6120701035 -Author: H.J. Lu -Date: Sat Jul 19 07:43:27 2025 -0700 - - tst-fopen-threaded.c: Delete temporary file - - Update tst-fopen-threaded.c to call support_create_temp_directory to - create a temporary directory and open "file" in the temporary directory, - instead of using /tmp/openclosetest and leaving it behind. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit e7db5150603bb2224a2bfd9628cae04ddcbe49e3) - -diff --git a/sysdeps/pthread/tst-fopen-threaded.c b/sysdeps/pthread/tst-fopen-threaded.c -index ade58ad19e..c17f1eaa13 100644 ---- a/sysdeps/pthread/tst-fopen-threaded.c -+++ b/sysdeps/pthread/tst-fopen-threaded.c -@@ -34,11 +34,13 @@ - #include - #include - #include -+#include - - #include - #include - #include - #include -+#include - - #define NUM_THREADS 100 - #define ITERS 10 -@@ -111,7 +113,8 @@ threadOpenCloseRoutine (void *argv) - /* Wait for all threads to be ready to call fopen and fclose. */ - xpthread_barrier_wait (&barrier); - -- FILE *fd = xfopen ("/tmp/openclosetest", "w+"); -+ char *file = (char *) argv; -+ FILE *fd = xfopen (file, "w+"); - xfclose (fd); - return NULL; - } -@@ -235,6 +238,10 @@ do_test (void) - xfclose (fd_file); - } - -+ char *tempdir = support_create_temp_directory ("openclosetest-"); -+ char *file = xasprintf ("%s/file", tempdir); -+ add_temp_file (file); -+ - /* Test 3: Concurrent open/close. */ - for (int reps = 1; reps <= ITERS; reps++) - { -@@ -243,7 +250,7 @@ do_test (void) - { - threads[i] = - xpthread_create (support_small_stack_thread_attribute (), -- threadOpenCloseRoutine, NULL); -+ threadOpenCloseRoutine, file); - } - for (int i = 0; i < NUM_THREADS; i++) - { -@@ -252,6 +259,9 @@ do_test (void) - xpthread_barrier_destroy (&barrier); - } - -+ free (file); -+ free (tempdir); -+ - return 0; - } - - -commit 41a77b78cff821007e3dd874619ebec7ce708c3d -Author: H.J. Lu -Date: Sat Jul 19 07:43:28 2025 -0700 - - tst-freopen4-main.c: Call support_capture_subprocess with chroot - - Update tst-freopen4-main.c to call support_capture_subprocess with chroot, - which makes temporary files inaccessible, so that temporary files can be - deleted. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 6463d4a7b28e5ee3891c34a8a1f0a59c24dfa9de) - -diff --git a/stdio-common/tst-freopen4-main.c b/stdio-common/tst-freopen4-main.c -index 3336f5327d..436da4d203 100644 ---- a/stdio-common/tst-freopen4-main.c -+++ b/stdio-common/tst-freopen4-main.c -@@ -28,25 +28,15 @@ - #include - #include - #include -+#include - --int --do_test (void) -+static void -+do_test_chroot (void *data) - { -- mtrace (); -- char *temp_dir; -+ char *temp_dir = (char *) data; - FILE *fp; - int ret; - -- /* These chroot tests verify that either reopening a renamed or -- deleted file works even in the absence of /proc, or that it fails -- (without memory leaks); thus, for example, such reopening does -- not crash in the absence of /proc. */ -- -- support_become_root (); -- if (!support_can_chroot ()) -- return EXIT_UNSUPPORTED; -- -- temp_dir = support_create_temp_directory ("tst-freopen4"); - xchroot (temp_dir); - - /* Test freopen with NULL, renamed file. This verifies that -@@ -96,6 +86,32 @@ do_test (void) - puts ("freopen of deleted file failed (OK)"); - - free (temp_dir); -+} -+ -+int -+do_test (void) -+{ -+ mtrace (); -+ char *temp_dir; -+ -+ /* These chroot tests verify that either reopening a renamed or -+ deleted file works even in the absence of /proc, or that it fails -+ (without memory leaks); thus, for example, such reopening does -+ not crash in the absence of /proc. */ -+ -+ support_become_root (); -+ if (!support_can_chroot ()) -+ return EXIT_UNSUPPORTED; -+ -+ temp_dir = support_create_temp_directory ("tst-freopen4"); -+ -+ struct support_capture_subprocess result; -+ result = support_capture_subprocess (do_test_chroot, temp_dir); -+ support_capture_subprocess_check (&result, "freopen4", 0, -+ sc_allow_stdout); -+ fputs (result.out.buffer, stdout); -+ support_capture_subprocess_free (&result); -+ - return 0; - } - - -commit c090b0cb1cde74aaeec01663dd55d6681dc92075 -Author: H.J. Lu -Date: Sat Jul 19 07:43:29 2025 -0700 - - tst-env-setuid: Delete LD_DEBUG_OUTPUT output - - Update tst-env-setuid.c to delete LD_DEBUG_OUTPUT output, instead of - leaving it behind. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 5d23dfb289174d73b8907b86d2bef7a3ca889840) - -diff --git a/elf/tst-env-setuid.c b/elf/tst-env-setuid.c -index 7209acd616..ff3eda7f91 100644 ---- a/elf/tst-env-setuid.c -+++ b/elf/tst-env-setuid.c -@@ -40,6 +40,8 @@ static char SETGID_CHILD[] = "setgid-child"; - # define PROFILE_LIB "tst-sonamemove-runmod2.so" - #endif - -+#define LD_DEBUG_OUTPUT "/tmp/some-file" -+ - struct envvar_t - { - const char *env; -@@ -61,7 +63,7 @@ static const struct envvar_t filtered_envvars[] = - { "MALLOC_TRIM_THRESHOLD_", FILTERED_VALUE }, - { "RES_OPTIONS", FILTERED_VALUE }, - { "LD_DEBUG", "all" }, -- { "LD_DEBUG_OUTPUT", "/tmp/some-file" }, -+ { "LD_DEBUG_OUTPUT", LD_DEBUG_OUTPUT }, - { "LD_WARN", FILTERED_VALUE }, - { "LD_VERBOSE", FILTERED_VALUE }, - { "LD_BIND_NOW", "0" }, -@@ -74,6 +76,14 @@ static const struct envvar_t unfiltered_envvars[] = - { "LD_ASSUME_KERNEL", UNFILTERED_VALUE }, - }; - -+static void -+unlink_ld_debug_output (pid_t pid) -+{ -+ char *output = xasprintf ("%s.%d", LD_DEBUG_OUTPUT, pid); -+ unlink (output); -+ free (output); -+} -+ - static int - test_child (void) - { -@@ -138,13 +148,21 @@ do_test (int argc, char **argv) - /* Setgid child process. */ - if (argc == 2 && strcmp (argv[1], SETGID_CHILD) == 0) - { -+ pid_t ppid = getppid (); -+ - if (getgid () == getegid ()) -- /* This can happen if the file system is mounted nosuid. */ -- FAIL_UNSUPPORTED ("SGID failed: GID and EGID match (%jd)\n", -- (intmax_t) getgid ()); -+ { -+ /* This can happen if the file system is mounted nosuid. */ -+ unlink_ld_debug_output (ppid); -+ -+ FAIL_UNSUPPORTED ("SGID failed: GID and EGID match (%jd)\n", -+ (intmax_t) getgid ()); -+ } - - int ret = test_child (); - -+ unlink_ld_debug_output (ppid); -+ - if (ret != 0) - exit (1); - return 0; - -commit e5754399b542640f3f69c5e2513c57a307656032 -Author: H.J. Lu -Date: Tue Aug 5 09:16:14 2025 -0700 - - Revert "tst-freopen4-main.c: Call support_capture_subprocess with chroot" - - Revert commit 6463d4a7b28e5ee3891c34a8a1f0a59c24dfa9de to fix - - FAIL: stdio-common/tst-freopen4-mem - FAIL: stdio-common/tst-freopen64-4-mem - - This fixes BZ #33254. - - Reviewed-by: Sam James - (cherry picked from commit adec0bf05bc23ec35573c7a5b96440089b69265e) - -diff --git a/stdio-common/tst-freopen4-main.c b/stdio-common/tst-freopen4-main.c -index 436da4d203..3336f5327d 100644 ---- a/stdio-common/tst-freopen4-main.c -+++ b/stdio-common/tst-freopen4-main.c -@@ -28,15 +28,25 @@ - #include - #include - #include --#include - --static void --do_test_chroot (void *data) -+int -+do_test (void) - { -- char *temp_dir = (char *) data; -+ mtrace (); -+ char *temp_dir; - FILE *fp; - int ret; - -+ /* These chroot tests verify that either reopening a renamed or -+ deleted file works even in the absence of /proc, or that it fails -+ (without memory leaks); thus, for example, such reopening does -+ not crash in the absence of /proc. */ -+ -+ support_become_root (); -+ if (!support_can_chroot ()) -+ return EXIT_UNSUPPORTED; -+ -+ temp_dir = support_create_temp_directory ("tst-freopen4"); - xchroot (temp_dir); - - /* Test freopen with NULL, renamed file. This verifies that -@@ -86,32 +96,6 @@ do_test_chroot (void *data) - puts ("freopen of deleted file failed (OK)"); - - free (temp_dir); --} -- --int --do_test (void) --{ -- mtrace (); -- char *temp_dir; -- -- /* These chroot tests verify that either reopening a renamed or -- deleted file works even in the absence of /proc, or that it fails -- (without memory leaks); thus, for example, such reopening does -- not crash in the absence of /proc. */ -- -- support_become_root (); -- if (!support_can_chroot ()) -- return EXIT_UNSUPPORTED; -- -- temp_dir = support_create_temp_directory ("tst-freopen4"); -- -- struct support_capture_subprocess result; -- result = support_capture_subprocess (do_test_chroot, temp_dir); -- support_capture_subprocess_check (&result, "freopen4", 0, -- sc_allow_stdout); -- fputs (result.out.buffer, stdout); -- support_capture_subprocess_free (&result); -- - return 0; - } - - -commit c5476b7907d01207ede6bf57b26cef151b601f35 -Author: Samuel Thibault -Date: Fri Jul 18 23:14:40 2025 +0200 - - hurd: support: Fix running SGID tests - - Secure mode is enabled only if SGID actually provides a new privilege, - so we have to drop it before gaining it again. - - Fixes commit 3a3fb2ed83f79100c116c824454095ecfb335ad7 - ("Fix error reporting (false negatives) in SGID tests") - - (cherry picked from commit ad4589e2d834c80a042a8c354fb00cf33e06802c) - -diff --git a/support/support_capture_subprocess.c b/support/support_capture_subprocess.c -index b4e4bf9502..c89e65b534 100644 ---- a/support/support_capture_subprocess.c -+++ b/support/support_capture_subprocess.c -@@ -133,6 +133,27 @@ copy_and_spawn_sgid (const char *child_id, gid_t gid) - if (chmod (execname, 02750) != 0) - FAIL_UNSUPPORTED ("cannot make \"%s\" SGID: %m ", execname); - -+ /* Now we can drop the privilege of that group. */ -+ const int count = 64; -+ gid_t groups[count]; -+ int ngroups = getgroups(count, groups); -+ -+ if (ngroups < 0) -+ FAIL_UNSUPPORTED ("Could not get group list again for user %jd\n", -+ (intmax_t) getuid ()); -+ -+ int n = 0; -+ for (int i = 0; i < ngroups; i++) -+ { -+ if (groups[i] != gid) -+ { -+ if (n != i) -+ groups[n] = groups[i]; -+ n++; -+ } -+ } -+ setgroups (n, groups); -+ - /* We have the binary, now spawn the subprocess. Avoid using - support_subprogram because we only want the program exit status, not the - contents. */ - -commit 8a726b63047241c6dd4b55bf85eacd02244362a2 -Author: Wilco Dijkstra -Date: Thu Jul 10 15:49:14 2025 +0000 - - malloc: Remove redundant NULL check - - Remove a redundant NULL check from tcache_get_n. - - Reviewed-by: Cupertino Miranda - (cherry picked from commit 089b4fb90fac8ed53039bc4c465c4d333c6b4048) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index 5ca390cc22..cf5c02ff64 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -3208,11 +3208,10 @@ tcache_get_n (size_t tc_idx, tcache_entry **ep, bool mangled) - if (__glibc_unlikely (misaligned_mem (e))) - malloc_printerr ("malloc(): unaligned tcache chunk detected"); - -- void *ne = e == NULL ? NULL : REVEAL_PTR (e->next); - if (!mangled) -- *ep = ne; -+ *ep = REVEAL_PTR (e->next); - else -- *ep = PROTECT_PTR (ep, ne); -+ *ep = PROTECT_PTR (ep, REVEAL_PTR (e->next)); - - ++(tcache->num_slots[tc_idx]); - e->key = 0; -@@ -3229,7 +3228,7 @@ tcache_put (mchunkptr chunk, size_t tc_idx) - static __always_inline void * - tcache_get (size_t tc_idx) - { -- return tcache_get_n (tc_idx, & tcache->entries[tc_idx], false); -+ return tcache_get_n (tc_idx, &tcache->entries[tc_idx], false); - } - - static __always_inline tcache_entry ** - -commit c491dabd8a3de090d1ccb4589421a44e79c5b185 -Author: Wilco Dijkstra -Date: Thu Jul 17 14:31:06 2025 +0000 - - malloc: Fix MAX_TCACHE_SMALL_SIZE - - MAX_TCACHE_SMALL_SIZE should use chunk size since it is used after - checked_request2size. Increase limit of tcache_max_bytes by 1 since all - comparisons use '<'. As a result, the last tcache entry is now used as - expected. - - Reviewed-by: DJ Delorie - (cherry picked from commit ad4caba4146583fc543cd434221dec7113c03e09) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index cf5c02ff64..b89b654f17 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -294,9 +294,9 @@ - # define TCACHE_SMALL_BINS 64 - # define TCACHE_LARGE_BINS 12 /* Up to 4M chunks */ - # define TCACHE_MAX_BINS (TCACHE_SMALL_BINS + TCACHE_LARGE_BINS) --# define MAX_TCACHE_SMALL_SIZE tidx2usize (TCACHE_SMALL_BINS-1) -+# define MAX_TCACHE_SMALL_SIZE tidx2csize (TCACHE_SMALL_BINS-1) - --/* Only used to pre-fill the tunables. */ -+# define tidx2csize(idx) (((size_t) idx) * MALLOC_ALIGNMENT + MINSIZE) - # define tidx2usize(idx) (((size_t) idx) * MALLOC_ALIGNMENT + MINSIZE - SIZE_SZ) - - /* When "x" is from chunksize(). */ -@@ -1932,7 +1932,7 @@ static struct malloc_par mp_ = - , - .tcache_count = TCACHE_FILL_COUNT, - .tcache_small_bins = TCACHE_SMALL_BINS, -- .tcache_max_bytes = MAX_TCACHE_SMALL_SIZE, -+ .tcache_max_bytes = MAX_TCACHE_SMALL_SIZE + 1, - .tcache_unsorted_limit = 0 /* No limit. */ - #endif - }; -@@ -5586,15 +5586,13 @@ do_set_arena_max (size_t value) - static __always_inline int - do_set_tcache_max (size_t value) - { -+ if (value > PTRDIFF_MAX) -+ return 0; -+ - size_t nb = request2size (value); - size_t tc_idx = csize2tidx (nb); - -- /* To check that value is not too big and request2size does not return an -- overflown value. */ -- if (value > nb) -- return 0; -- -- if (nb > MAX_TCACHE_SMALL_SIZE) -+ if (tc_idx >= TCACHE_SMALL_BINS) - tc_idx = large_csize2tidx (nb); - - LIBC_PROBE (memory_tunable_tcache_max_bytes, 2, value, mp_.tcache_max_bytes); -@@ -5603,7 +5601,7 @@ do_set_tcache_max (size_t value) - { - if (tc_idx < TCACHE_SMALL_BINS) - mp_.tcache_small_bins = tc_idx + 1; -- mp_.tcache_max_bytes = nb; -+ mp_.tcache_max_bytes = nb + 1; - return 1; - } - - -commit a96a82c4a5efd3139e75cd11fd2a5554164dd5a0 -Author: Samuel Thibault -Date: Wed Jul 30 01:55:22 2025 +0200 - - malloc: Make sure tcache_key is odd enough - - We want tcache_key not to be a commonly-occurring value in memory, so ensure - a minimum amount of one and zero bits. - - And we need it non-zero, otherwise even if tcache_double_free_verify sets - e->key to 0 before calling __libc_free, it gets called again by __libc_free, - thus looping indefinitely. - - Fixes: c968fe50628db74b52124d863cd828225a1d305c ("malloc: Use tailcalls in __libc_free") - (cherry picked from commit 2536c4f8584082a1ac4c5e0a2a6222e290d43983) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index b89b654f17..e4e2f03600 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -230,6 +230,9 @@ - /* For uintptr_t. */ - #include - -+/* For stdc_count_ones. */ -+#include -+ - /* For va_arg, va_start, va_end. */ - #include - -@@ -3152,6 +3155,19 @@ tcache_key_initialize (void) - if (__getrandom_nocancel_nostatus_direct (&tcache_key, sizeof(tcache_key), - GRND_NONBLOCK) - != sizeof (tcache_key)) -+ tcache_key = 0; -+ -+ /* We need tcache_key to be non-zero (otherwise tcache_double_free_verify's -+ clearing of e->key would go unnoticed and it would loop getting called -+ through __libc_free), and we want tcache_key not to be a -+ commonly-occurring value in memory, so ensure a minimum amount of one and -+ zero bits. */ -+ int minimum_bits = __WORDSIZE / 4; -+ int maximum_bits = __WORDSIZE - minimum_bits; -+ -+ while (labs (tcache_key) <= 0x1000000 -+ || stdc_count_ones (tcache_key) < minimum_bits -+ || stdc_count_ones (tcache_key) > maximum_bits) - { - tcache_key = random_bits (); - #if __WORDSIZE == 64 - -commit d7274d718e6f3655eabe311d4eb70fabb5ffa7ef -Author: Samuel Thibault -Date: Sun Aug 10 23:43:37 2025 +0200 - - malloc: Fix checking for small negative values of tcache_key - - tcache_key is unsigned so we should turn it explicitly to signed before - taking its absolute value. - - (cherry picked from commit 8543577b04ded6d979ffcc5a818930e4d74d0645) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index e4e2f03600..5f3e701fd1 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -3165,7 +3165,7 @@ tcache_key_initialize (void) - int minimum_bits = __WORDSIZE / 4; - int maximum_bits = __WORDSIZE - minimum_bits; - -- while (labs (tcache_key) <= 0x1000000 -+ while (labs ((intptr_t) tcache_key) <= 0x1000000 - || stdc_count_ones (tcache_key) < minimum_bits - || stdc_count_ones (tcache_key) > maximum_bits) - { - -commit 8dbaecbe92ac7ab73b7d0aae84626af59131e41b -Author: Jens Remus -Date: Fri Jul 25 15:40:03 2025 +0200 - - Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables [BZ #33234] - - Commit 10a66a8e421b ("Remove ") removed the TLS initial-exec - (IE) model attribute from the __libc_tsd_CTYPE_* thread variable declarations - and definitions. Commit a894f04d8776 ("Optimize __libc_tsd_* thread - variable access") restored it on declarations. - - Restore the TLS initial-exec model attribute on __libc_tsd_CTYPE_* thread - variable definitions. - - This resolves test tst-locale1 failure on s390 32-bit, when using a - GNU linker without the fix from GNU binutils commit aefebe82dc89 - ("IBM zSystems: Fix offset relative to static TLS"). - - Reviewed-by: Florian Weimer - (cherry picked from commit e5363e6f460c2d58809bf10fc96d70fd1ef8b5b2) - -diff --git a/NEWS b/NEWS -index 1d04bdfef8..69aa600c6d 100644 ---- a/NEWS -+++ b/NEWS -@@ -11,6 +11,7 @@ The following bugs were resolved with this release: - - [31943] _dl_find_object can fail if ld.so contains gaps between load segments - [32994] stdlib: resolve a double lock init issue after fork -+ [33234] Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables - [33245] nptl: nptl: error in internal cancellation syscall handling - - Version 2.42 -diff --git a/ctype/ctype-info.c b/ctype/ctype-info.c -index b7d3422726..fb5acf9419 100644 ---- a/ctype/ctype-info.c -+++ b/ctype/ctype-info.c -@@ -24,11 +24,11 @@ - __ctype_init before user code runs, but this does not happen for - threads in secondary namespaces. With the initializers, secondary - namespaces at least get locale data from the C locale. */ --__thread const uint16_t * __libc_tsd_CTYPE_B -+__thread const uint16_t * __libc_tsd_CTYPE_B attribute_tls_model_ie - = (const uint16_t *) _nl_C_LC_CTYPE_class + 128; --__thread const int32_t * __libc_tsd_CTYPE_TOLOWER -+__thread const int32_t * __libc_tsd_CTYPE_TOLOWER attribute_tls_model_ie - = (const int32_t *) _nl_C_LC_CTYPE_tolower + 128; --__thread const int32_t * __libc_tsd_CTYPE_TOUPPER -+__thread const int32_t * __libc_tsd_CTYPE_TOUPPER attribute_tls_model_ie - = (const int32_t *) _nl_C_LC_CTYPE_toupper + 128; - - - -commit d0f72b96f2e91e1aa93f7e826c71f74078ada7d0 -Author: H.J. Lu -Date: Mon Jul 28 12:16:11 2025 -0700 - - i386: Add GLIBC_ABI_GNU_TLS version [BZ #33221] - - On i386, programs and shared libraries with __thread usage may fail - silently at run-time against glibc without the TLS run-time fix for: - - https://sourceware.org/bugzilla/show_bug.cgi?id=32996 - - Add GLIBC_ABI_GNU_TLS version to indicate that glibc has the working - GNU TLS run-time. Linker can add the GLIBC_ABI_GNU_TLS version to - binaries which depend on the working TLS run-time so that such programs - and shared libraries will fail to load and run at run-time against - libc.so without the GLIBC_ABI_GNU_TLS version, instead of fail silently - at random. - - This fixes BZ #33221. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit ed1b7a5a489ab555a27fad9c101ebe2e1c1ba881) - -diff --git a/sysdeps/i386/Makefile b/sysdeps/i386/Makefile -index ee6470d78e..c0c017b899 100644 ---- a/sysdeps/i386/Makefile -+++ b/sysdeps/i386/Makefile -@@ -60,6 +60,15 @@ $(objpfx)tst-ld-sse-use.out: ../sysdeps/i386/tst-ld-sse-use.sh $(objpfx)ld.so - @echo "Checking ld.so for SSE register use. This will take a few seconds..." - $(BASH) $< $(objpfx) '$(NM)' '$(OBJDUMP)' '$(READELF)' > $@; \ - $(evaluate-test) -+ -+tests-special += $(objpfx)check-gnu-tls.out -+ -+$(objpfx)check-gnu-tls.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_GNU_TLS > $@; \ -+ $(evaluate-test) -+generated += check-gnu-tls.out - else - CFLAGS-.os += $(if $(filter rtld-%.os,$(@F)), $(rtld-CFLAGS)) - endif -diff --git a/sysdeps/i386/Versions b/sysdeps/i386/Versions -index 36e23b466a..9c84c8ef04 100644 ---- a/sysdeps/i386/Versions -+++ b/sysdeps/i386/Versions -@@ -28,6 +28,11 @@ libc { - GLIBC_2.13 { - __fentry__; - } -+ GLIBC_ABI_GNU_TLS { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } - libm { - GLIBC_2.1 { - -commit 3970785bebcc3f1de4460072f3a041d178f64846 -Author: H.J. Lu -Date: Mon Jul 28 12:18:22 2025 -0700 - - x86-64: Add GLIBC_ABI_GNU2_TLS version [BZ #33129] - - Programs and shared libraries compiled with -mtls-dialect=gnu2 may fail - silently at run-time against glibc without the GNU2 TLS run-time fix - for: - - https://sourceware.org/bugzilla/show_bug.cgi?id=31372 - - Add GLIBC_ABI_GNU2_TLS version to indicate that glibc has the working - GNU2 TLS run-time. Linker can add the GLIBC_ABI_GNU2_TLS version to - binaries which depend on the working GNU2 TLS run-time: - - https://sourceware.org/bugzilla/show_bug.cgi?id=33130 - - so that such programs and shared libraries will fail to load and run at - run-time against libc.so without the GLIBC_ABI_GNU2_TLS version, instead - of fail silently at random. - - This fixes BZ #33129. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit 9df8fa397d515dc86ff5565f6c45625e672d539e) - -diff --git a/sysdeps/x86_64/Makefile b/sysdeps/x86_64/Makefile -index c3e1065c81..3ab8c1ed0f 100644 ---- a/sysdeps/x86_64/Makefile -+++ b/sysdeps/x86_64/Makefile -@@ -212,6 +212,15 @@ LDFLAGS-tst-plt-rewrite2 = -Wl,-z,now - LDFLAGS-tst-plt-rewritemod2.so = -Wl,-z,now,-z,undefs - tst-plt-rewrite2-ENV = GLIBC_TUNABLES=glibc.cpu.plt_rewrite=2 - $(objpfx)tst-plt-rewrite2: $(objpfx)tst-plt-rewritemod2.so -+ -+tests-special += $(objpfx)check-gnu2-tls.out -+ -+$(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_GNU2_TLS > $@; \ -+ $(evaluate-test) -+generated += check-gnu2-tls.out - endif - - test-internal-extras += tst-gnu2-tls2mod1 -diff --git a/sysdeps/x86_64/Versions b/sysdeps/x86_64/Versions -index e94758b236..a63c11bcb2 100644 ---- a/sysdeps/x86_64/Versions -+++ b/sysdeps/x86_64/Versions -@@ -5,6 +5,11 @@ libc { - GLIBC_2.13 { - __fentry__; - } -+ GLIBC_ABI_GNU2_TLS { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } - libm { - GLIBC_2.1 { - -commit 7a8f3c6ee4b565a02da4ba0dad9aaeaeed4639ce -Author: H.J. Lu -Date: Thu Aug 14 07:03:20 2025 -0700 - - x86-64: Add GLIBC_ABI_DT_X86_64_PLT [BZ #33212] - - When the linker -z mark-plt option is used to add DT_X86_64_PLT, - DT_X86_64_PLTSZ and DT_X86_64_PLTENT, the r_addend field of the - R_X86_64_JUMP_SLOT relocation stores the offset of the indirect - branch instruction. However, glibc versions without the commit: - - commit f8587a61892cbafd98ce599131bf4f103466f084 - Author: H.J. Lu - Date: Fri May 20 19:21:48 2022 -0700 - - x86-64: Ignore r_addend for R_X86_64_GLOB_DAT/R_X86_64_JUMP_SLOT - - According to x86-64 psABI, r_addend should be ignored for R_X86_64_GLOB_DAT - and R_X86_64_JUMP_SLOT. Since linkers always set their r_addends to 0, we - can ignore their r_addends. - - Reviewed-by: Fangrui Song - - won't ignore the r_addend value in the R_X86_64_JUMP_SLOT relocation. - Such programs and shared libraries will fail at run-time randomly. - - Add GLIBC_ABI_DT_X86_64_PLT version to indicate that glibc is compatible - with DT_X86_64_PLT. - - The linker can add the glibc GLIBC_ABI_DT_X86_64_PLT version dependency - whenever -z mark-plt is passed to the linker. The resulting programs and - shared libraries will fail to load at run-time against libc.so without the - GLIBC_ABI_DT_X86_64_PLT version, instead of fail randomly. - - This fixes BZ #33212. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit 399384e0c8193e31aea014220ccfa24300ae5938) - -diff --git a/sysdeps/x86_64/Makefile b/sysdeps/x86_64/Makefile -index 3ab8c1ed0f..01100597a8 100644 ---- a/sysdeps/x86_64/Makefile -+++ b/sysdeps/x86_64/Makefile -@@ -213,6 +213,15 @@ LDFLAGS-tst-plt-rewritemod2.so = -Wl,-z,now,-z,undefs - tst-plt-rewrite2-ENV = GLIBC_TUNABLES=glibc.cpu.plt_rewrite=2 - $(objpfx)tst-plt-rewrite2: $(objpfx)tst-plt-rewritemod2.so - -+tests-special += $(objpfx)check-dt-x86-64-plt.out -+ -+$(objpfx)check-dt-x86-64-plt.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_DT_X86_64_PLT > $@; \ -+ $(evaluate-test) -+generated += check-dt-x86-64-plt.out -+ - tests-special += $(objpfx)check-gnu2-tls.out - - $(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -diff --git a/sysdeps/x86_64/Versions b/sysdeps/x86_64/Versions -index a63c11bcb2..0a759029e5 100644 ---- a/sysdeps/x86_64/Versions -+++ b/sysdeps/x86_64/Versions -@@ -10,6 +10,11 @@ libc { - # by scripts/versions.awk. - __placeholder_only_for_empty_version_map; - } -+ GLIBC_ABI_DT_X86_64_PLT { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } - libm { - GLIBC_2.1 { - -commit e87844ec42b77363a499ea4da6c4a6ab85eba310 -Author: H.J. Lu -Date: Mon Aug 18 09:06:48 2025 -0700 - - i386: Also add GLIBC_ABI_GNU2_TLS version [BZ #33129] - - Since the GNU2 TLS run-time bug: - - https://sourceware.org/bugzilla/show_bug.cgi?id=31372 - - affects both i386 and x86-64, also add GLIBC_ABI_GNU2_TLS version to i386 - to indicate the working GNU2 TLS run-time. For x86-64, the additional - GNU2 TLS run-time bug fix is needed for - - https://sourceware.org/bugzilla/show_bug.cgi?id=31501 - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit bd4628f3f18ac312408782eea450429c6f044860) - -diff --git a/sysdeps/x86/Makefile b/sysdeps/x86/Makefile -index 4fbd48e1c8..9e1c8cce85 100644 ---- a/sysdeps/x86/Makefile -+++ b/sysdeps/x86/Makefile -@@ -135,6 +135,15 @@ LDFLAGS-tst-tls23 += -rdynamic - tst-tls23-mod.so-no-z-defs = yes - - $(objpfx)tst-tls23-mod.so: $(libsupport) -+ -+tests-special += $(objpfx)check-gnu2-tls.out -+ -+$(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_GNU2_TLS > $@; \ -+ $(evaluate-test) -+generated += check-gnu2-tls.out - endif - - ifeq ($(subdir),gmon) -diff --git a/sysdeps/x86/Versions b/sysdeps/x86/Versions -index 4b10c4b5d7..e8dcfccbe4 100644 ---- a/sysdeps/x86/Versions -+++ b/sysdeps/x86/Versions -@@ -7,4 +7,9 @@ libc { - GLIBC_2.33 { - __x86_get_cpuid_feature_leaf; - } -+ GLIBC_ABI_GNU2_TLS { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } -diff --git a/sysdeps/x86_64/Makefile b/sysdeps/x86_64/Makefile -index 01100597a8..fe9f1cdddb 100644 ---- a/sysdeps/x86_64/Makefile -+++ b/sysdeps/x86_64/Makefile -@@ -221,15 +221,6 @@ $(objpfx)check-dt-x86-64-plt.out: $(common-objpfx)libc.so - | grep GLIBC_ABI_DT_X86_64_PLT > $@; \ - $(evaluate-test) - generated += check-dt-x86-64-plt.out -- --tests-special += $(objpfx)check-gnu2-tls.out -- --$(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -- LC_ALL=C $(READELF) -V -W $< \ -- | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -- | grep GLIBC_ABI_GNU2_TLS > $@; \ -- $(evaluate-test) --generated += check-gnu2-tls.out - endif - - test-internal-extras += tst-gnu2-tls2mod1 -diff --git a/sysdeps/x86_64/Versions b/sysdeps/x86_64/Versions -index 0a759029e5..6a989ad3b3 100644 ---- a/sysdeps/x86_64/Versions -+++ b/sysdeps/x86_64/Versions -@@ -5,11 +5,6 @@ libc { - GLIBC_2.13 { - __fentry__; - } -- GLIBC_ABI_GNU2_TLS { -- # This symbol is used only for empty version map and will be removed -- # by scripts/versions.awk. -- __placeholder_only_for_empty_version_map; -- } - GLIBC_ABI_DT_X86_64_PLT { - # This symbol is used only for empty version map and will be removed - # by scripts/versions.awk. - -commit e34453cd6a8c592c325756ff3c7ac0afd3975cb4 -Author: Pierre Blanchard -Date: Wed Aug 20 17:41:50 2025 +0000 - - AArch64: Fix SVE powf routine [BZ #33299] - - Fix a bug in predicate logic introduced in last change. - A slight performance improvement from relying on all true - predicates during conversion from single to double. - This fixes BZ #33299. - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit aac077645a645bba0d67f3250e82017c539d0f4b) - -diff --git a/sysdeps/aarch64/fpu/powf_sve.c b/sysdeps/aarch64/fpu/powf_sve.c -index 7046990aa1..65e9bd29d9 100644 ---- a/sysdeps/aarch64/fpu/powf_sve.c -+++ b/sysdeps/aarch64/fpu/powf_sve.c -@@ -223,15 +223,15 @@ sv_powf_core (const svbool_t pg, svuint32_t i, svuint32_t iz, svint32_t k, - const svbool_t ptrue = svptrue_b64 (); - - /* Unpack and promote input vectors (pg, y, z, i, k and sign_bias) into two -- * in order to perform core computation in double precision. */ -+ in order to perform core computation in double precision. */ - const svbool_t pg_lo = svunpklo (pg); - const svbool_t pg_hi = svunpkhi (pg); -- svfloat64_t y_lo -- = svcvt_f64_x (pg, svreinterpret_f32 (svunpklo (svreinterpret_u32 (y)))); -- svfloat64_t y_hi -- = svcvt_f64_x (pg, svreinterpret_f32 (svunpkhi (svreinterpret_u32 (y)))); -- svfloat64_t z_lo = svcvt_f64_x (pg, svreinterpret_f32 (svunpklo (iz))); -- svfloat64_t z_hi = svcvt_f64_x (pg, svreinterpret_f32 (svunpkhi (iz))); -+ svfloat64_t y_lo = svcvt_f64_x ( -+ ptrue, svreinterpret_f32 (svunpklo (svreinterpret_u32 (y)))); -+ svfloat64_t y_hi = svcvt_f64_x ( -+ ptrue, svreinterpret_f32 (svunpkhi (svreinterpret_u32 (y)))); -+ svfloat64_t z_lo = svcvt_f64_x (ptrue, svreinterpret_f32 (svunpklo (iz))); -+ svfloat64_t z_hi = svcvt_f64_x (ptrue, svreinterpret_f32 (svunpkhi (iz))); - svuint64_t i_lo = svunpklo (i); - svuint64_t i_hi = svunpkhi (i); - svint64_t k_lo = svunpklo (k); -@@ -312,7 +312,7 @@ svfloat32_t SV_NAME_F2 (pow) (svfloat32_t x, svfloat32_t y, const svbool_t pg) - (23 - V_POWF_EXP2_TABLE_BITS)); - - /* Compute core in extended precision and return intermediate ylogx results -- * to handle cases of underflow and underflow in exp. */ -+ to handle cases of underflow and overflow in exp. */ - svfloat32_t ylogx; - svfloat32_t ret - = sv_powf_core (yint_or_xpos, i, iz, k, y, sign_bias, &ylogx, d); - -commit 1166170d95863e5a6f8121a5ca9d97713f524f49 -Author: Florian Weimer -Date: Fri Sep 5 19:02:57 2025 +0200 - - libio: Define AT_RENAME_* with the same tokens as Linux - - Linux uses different expressions for the RENAME_* and AT_RENAME_* - constants. Mirror that in , so that the macro redefinitions - do not result in preprocessor warnings. - - Reviewed-by: Collin Funk - (cherry picked from commit b173557da978a04ac3bdfc0bd3b0e7ac583b44d5) - -diff --git a/libio/stdio.h b/libio/stdio.h -index d042b36618..e0e70945fa 100644 ---- a/libio/stdio.h -+++ b/libio/stdio.h -@@ -168,11 +168,11 @@ extern int renameat (int __oldfd, const char *__old, int __newfd, - #ifdef __USE_GNU - /* Flags for renameat2. */ - # define RENAME_NOREPLACE (1 << 0) --# define AT_RENAME_NOREPLACE RENAME_NOREPLACE -+# define AT_RENAME_NOREPLACE 0x0001 - # define RENAME_EXCHANGE (1 << 1) --# define AT_RENAME_EXCHANGE RENAME_EXCHANGE -+# define AT_RENAME_EXCHANGE 0x0002 - # define RENAME_WHITEOUT (1 << 2) --# define AT_RENAME_WHITEOUT RENAME_WHITEOUT -+# define AT_RENAME_WHITEOUT 0x0004 - - /* Rename file OLD relative to OLDFD to NEW relative to NEWFD, with - additional flags. */ -diff --git a/stdio-common/tst-renameat2.c b/stdio-common/tst-renameat2.c -index 12aa0f8b0f..6213e1376d 100644 ---- a/stdio-common/tst-renameat2.c -+++ b/stdio-common/tst-renameat2.c -@@ -28,6 +28,12 @@ - #include - #include - -+/* These constants are defined with different token sequences, -+ matching the Linux definitions, to avoid preprocessor warnings. */ -+_Static_assert (RENAME_NOREPLACE == AT_RENAME_NOREPLACE, "RENAME_NOREPLACE"); -+_Static_assert (RENAME_EXCHANGE == AT_RENAME_EXCHANGE, "RENAME_EXCHANGE"); -+_Static_assert (RENAME_WHITEOUT == AT_RENAME_WHITEOUT, "RENAME_WHITEOUT"); -+ - /* Directory with the temporary files. */ - static char *directory; - static int directory_fd; - -commit 46b4e37c9e0619d0cf065ba207c29996b326a06f -Author: Florian Weimer -Date: Fri Sep 12 21:33:34 2025 +0200 - - nss: Group merge does not react to ERANGE during merge (bug 33361) - - The break statement in CHECK_MERGE is expected to exit the surrounding - while loop, not the do-while loop with in the macro. Remove the - do-while loop from the macro. It is not needed to turn the macro - expansion into a single statement due to the way CHECK_MERGE is used - (and the statement expression would cover this anyway). - - Reviewed-by: Collin Funk - (cherry picked from commit 0fceed254559836b57ee05188deac649bc505d05) - -diff --git a/NEWS b/NEWS -index 69aa600c6d..06c27a8e17 100644 ---- a/NEWS -+++ b/NEWS -@@ -13,6 +13,7 @@ The following bugs were resolved with this release: - [32994] stdlib: resolve a double lock init issue after fork - [33234] Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables - [33245] nptl: nptl: error in internal cancellation syscall handling -+ [33361] nss: Group merge does not react to ERANGE during merge - - Version 2.42 - -diff --git a/nss/getXXbyYY_r.c b/nss/getXXbyYY_r.c -index eae6c3480e..2b0735fb6a 100644 ---- a/nss/getXXbyYY_r.c -+++ b/nss/getXXbyYY_r.c -@@ -157,19 +157,15 @@ __merge_einval (LOOKUP_TYPE *a, - - #define CHECK_MERGE(err, status) \ - ({ \ -- do \ -+ if (err) \ - { \ -- if (err) \ -- { \ -- __set_errno (err); \ -- if (err == ERANGE) \ -- status = NSS_STATUS_TRYAGAIN; \ -- else \ -- status = NSS_STATUS_UNAVAIL; \ -- break; \ -- } \ -+ __set_errno (err); \ -+ if (err == ERANGE) \ -+ status = NSS_STATUS_TRYAGAIN; \ -+ else \ -+ status = NSS_STATUS_UNAVAIL; \ -+ break; \ - } \ -- while (0); \ - }) - - /* Type of the lookup function we need here. */ - -commit 18fd689cdced8348e42991964557cddea0ba2dc5 -Author: Adhemerval Zanella -Date: Mon Sep 8 13:06:13 2025 -0300 - - nptl: Fix MADV_GUARD_INSTALL logic for thread without guard page (BZ 33356) - - The main issue is that setup_stack_prot fails to account for cases where - the cached thread stack lacks a guard page, which can cause madvise to - fail. Update the logic to also handle whether MADV_GUARD_INSTALL is - supported when resizing the guard page. - - Checked on x86_64-linux-gnu with 6.8.0 and 6.15 kernels. - - Reviewed-by: Florian Weimer - (cherry picked from commit 855bfa2566bbefefa27c516b344df58a75824a5c) - -diff --git a/NEWS b/NEWS -index 06c27a8e17..ed3c114c7a 100644 ---- a/NEWS -+++ b/NEWS -@@ -13,6 +13,8 @@ The following bugs were resolved with this release: - [32994] stdlib: resolve a double lock init issue after fork - [33234] Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables - [33245] nptl: nptl: error in internal cancellation syscall handling -+ [33356] nptl: creating thread stack with guardsize 0 can erroneously -+ conclude MADV_GUARD_INSTALL is available - [33361] nss: Group merge does not react to ERANGE during merge - - Version 2.42 -diff --git a/nptl/allocatestack.c b/nptl/allocatestack.c -index 800ca89720..fb8a60a21d 100644 ---- a/nptl/allocatestack.c -+++ b/nptl/allocatestack.c -@@ -240,7 +240,7 @@ setup_stack_prot (char *mem, size_t size, struct pthread *pd, - /* Update the guard area of the thread stack MEM of size SIZE with the new - GUARDISZE. It uses the method defined by PD stack_mode. */ - static inline bool --adjust_stack_prot (char *mem, size_t size, const struct pthread *pd, -+adjust_stack_prot (char *mem, size_t size, struct pthread *pd, - size_t guardsize, size_t pagesize_m1) - { - /* The required guard area is larger than the current one. For -@@ -258,11 +258,23 @@ adjust_stack_prot (char *mem, size_t size, const struct pthread *pd, - so use the new guard placement with the new size. */ - if (guardsize > pd->guardsize) - { -+ /* There was no need to previously setup a guard page, so we need -+ to check whether the kernel supports guard advise. */ - char *guard = guard_position (mem, size, guardsize, pd, pagesize_m1); -- if (pd->stack_mode == ALLOCATE_GUARD_MADV_GUARD) -- return __madvise (guard, guardsize, MADV_GUARD_INSTALL) == 0; -- else if (pd->stack_mode == ALLOCATE_GUARD_PROT_NONE) -- return __mprotect (guard, guardsize, PROT_NONE) == 0; -+ if (atomic_load_relaxed (&allocate_stack_mode) -+ == ALLOCATE_GUARD_MADV_GUARD) -+ { -+ if (__madvise (guard, guardsize, MADV_GUARD_INSTALL) == 0) -+ { -+ pd->stack_mode = ALLOCATE_GUARD_MADV_GUARD; -+ return true; -+ } -+ atomic_store_relaxed (&allocate_stack_mode, -+ ALLOCATE_GUARD_PROT_NONE); -+ } -+ -+ pd->stack_mode = ALLOCATE_GUARD_PROT_NONE; -+ return __mprotect (guard, guardsize, PROT_NONE) == 0; - } - /* The current guard area is larger than the required one. For - _STACK_GROWS_DOWN is means change the guard as: -diff --git a/nptl/tst-guard1.c b/nptl/tst-guard1.c -index e3e06df0fc..1c73d3fc93 100644 ---- a/nptl/tst-guard1.c -+++ b/nptl/tst-guard1.c -@@ -21,6 +21,7 @@ - #include - #include - #include -+#include - #include - #include - #include -@@ -202,7 +203,7 @@ tf (void *closure) - - /* Test 1: caller provided stack without guard. */ - static void --do_test1 (void) -+do_test1 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -227,7 +228,7 @@ do_test1 (void) - - /* Test 2: same as 1., but with a guard area. */ - static void --do_test2 (void) -+do_test2 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -250,18 +251,9 @@ do_test2 (void) - xmunmap (stack, stacksize); - } - --/* Test 3: pthread_create with default values. */ -+/* Test 3: pthread_create without a guard area. */ - static void --do_test3 (void) --{ -- pthread_t t = xpthread_create (NULL, tf, NULL); -- void *status = xpthread_join (t); -- TEST_VERIFY (status == 0); --} -- --/* Test 4: pthread_create without a guard area. */ --static void --do_test4 (void) -+do_test3 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -277,9 +269,18 @@ do_test4 (void) - xpthread_attr_destroy (&attr); - } - -+/* Test 4: pthread_create with default values. */ -+static void -+do_test4 (void *closure) -+{ -+ pthread_t t = xpthread_create (NULL, tf, NULL); -+ void *status = xpthread_join (t); -+ TEST_VERIFY (status == 0); -+} -+ - /* Test 5: pthread_create with non default stack and guard size value. */ - static void --do_test5 (void) -+do_test5 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -299,7 +300,7 @@ do_test5 (void) - test 3, but with a larger guard area. The pthread_create will need to - increase the guard area. */ - static void --do_test6 (void) -+do_test6 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -320,7 +321,7 @@ do_test6 (void) - pthread_create should use the cached stack from previous tests, but it - would require to reduce the guard area. */ - static void --do_test7 (void) -+do_test7 (void *closure) - { - pthread_t t = xpthread_create (NULL, tf, NULL); - void *status = xpthread_join (t); -@@ -346,21 +347,40 @@ do_test (void) - - static const struct { - const char *descr; -- void (*test)(void); -+ void (*test) (void *); - } tests[] = { - { "user provided stack without guard", do_test1 }, - { "user provided stack with guard", do_test2 }, -- { "default attribute", do_test3 }, -- { "default attribute without guard", do_test4 }, -+ /* N.B: do_test3 should be before do_test4 to check if a new thread -+ that uses the thread stack previously allocated without a guard -+ page correctly sets up the guard pages even on a kernel without -+ MADV_GUARD_INSTALL support (BZ 33356). */ -+ { "default attribute without guard", do_test3 }, -+ { "default attribute", do_test4 }, -+ /* Also checks if the guard is correctly removed from the cache thread -+ stack. */ -+ { "default attribute without guard", do_test3 }, - { "non default stack and guard sizes", do_test5 }, - { "reused stack with larger guard", do_test6 }, - { "reused stack with smaller guard", do_test7 }, - }; - -+ /* Run each test with a clean state. */ -+ for (int i = 0; i < array_length (tests); i++) -+ { -+ printf ("debug: fork: test%01d: %s\n", i, tests[i].descr); -+ struct support_capture_subprocess result = -+ support_capture_subprocess (tests[i].test, NULL); -+ support_capture_subprocess_check (&result, tests[i].descr, 0, -+ sc_allow_none); -+ support_capture_subprocess_free (&result); -+ } -+ -+ /* And now run the same tests along with the thread stack cache. */ - for (int i = 0; i < array_length (tests); i++) - { - printf ("debug: test%01d: %s\n", i, tests[i].descr); -- tests[i].test(); -+ tests[i].test ( NULL); - } - - return 0; - -commit bf48b17a28066a54f172e0d63da9fc5dc60c6355 -Author: Sunil K Pandey -Date: Mon Oct 6 18:13:04 2025 -0700 - - x86: Detect Intel Wildcat Lake Processor - - Detect Intel Wildcat Lake Processor and tune it similar to Intel Panther - Lake. https://cdrdv2.intel.com/v1/dl/getContent/671368 Section 1.2. - - Reviewed-by: H.J. Lu - (cherry picked from commit f8dd52901b72805a831d5a4cb7d971e4a3c9970b) - -diff --git a/sysdeps/x86/cpu-features.c b/sysdeps/x86/cpu-features.c -index b7d1506135..4bdade883e 100644 ---- a/sysdeps/x86/cpu-features.c -+++ b/sysdeps/x86/cpu-features.c -@@ -543,6 +543,7 @@ enum intel_microarch - INTEL_BIGCORE_PANTHERLAKE, - INTEL_BIGCORE_GRANITERAPIDS, - INTEL_BIGCORE_DIAMONDRAPIDS, -+ INTEL_BIGCORE_WILDCATLAKE, - - /* Mixed (bigcore + atom SOC). */ - INTEL_MIXED_LAKEFIELD, -@@ -702,6 +703,8 @@ intel_get_fam6_microarch (unsigned int model, - return INTEL_BIGCORE_ARROWLAKE; - case 0xCC: - return INTEL_BIGCORE_PANTHERLAKE; -+ case 0xD5: -+ return INTEL_BIGCORE_WILDCATLAKE; - case 0xAD: - case 0xAE: - return INTEL_BIGCORE_GRANITERAPIDS; -@@ -934,6 +937,7 @@ disable_tsx: - case INTEL_BIGCORE_LUNARLAKE: - case INTEL_BIGCORE_ARROWLAKE: - case INTEL_BIGCORE_PANTHERLAKE: -+ case INTEL_BIGCORE_WILDCATLAKE: - case INTEL_BIGCORE_SAPPHIRERAPIDS: - case INTEL_BIGCORE_EMERALDRAPIDS: - case INTEL_BIGCORE_GRANITERAPIDS: - -commit ab8c1b5d62d7be2c3c23f535bea3d7fff19c53ae -Author: Sunil K Pandey -Date: Wed Sep 24 09:38:17 2025 -0700 - - x86: Detect Intel Nova Lake Processor - - Detect Intel Nova Lake Processor and tune it similar to Intel Panther - Lake. https://cdrdv2.intel.com/v1/dl/getContent/671368 Section 1.2. - - Reviewed-by: H.J. Lu - (cherry picked from commit a114e29ddd530962d2b44aa9d89f1f6075abe7fa) - -diff --git a/sysdeps/x86/cpu-features.c b/sysdeps/x86/cpu-features.c -index 4bdade883e..b67ef541dd 100644 ---- a/sysdeps/x86/cpu-features.c -+++ b/sysdeps/x86/cpu-features.c -@@ -544,6 +544,7 @@ enum intel_microarch - INTEL_BIGCORE_GRANITERAPIDS, - INTEL_BIGCORE_DIAMONDRAPIDS, - INTEL_BIGCORE_WILDCATLAKE, -+ INTEL_BIGCORE_NOVALAKE, - - /* Mixed (bigcore + atom SOC). */ - INTEL_MIXED_LAKEFIELD, -@@ -821,6 +822,17 @@ disable_tsx: - break; - } - } -+ else if (family == 18) -+ switch (model) -+ { -+ case 0x01: -+ case 0x03: -+ microarch = INTEL_BIGCORE_NOVALAKE; -+ break; -+ -+ default: -+ break; -+ } - else if (family == 19) - switch (model) - { -@@ -938,6 +950,7 @@ disable_tsx: - case INTEL_BIGCORE_ARROWLAKE: - case INTEL_BIGCORE_PANTHERLAKE: - case INTEL_BIGCORE_WILDCATLAKE: -+ case INTEL_BIGCORE_NOVALAKE: - case INTEL_BIGCORE_SAPPHIRERAPIDS: - case INTEL_BIGCORE_EMERALDRAPIDS: - case INTEL_BIGCORE_GRANITERAPIDS: - -commit 6de12fc9ad56bc19fa6fcbd8ee502f29b5170d47 -Author: Yury Khrustalev -Date: Thu Sep 25 15:51:30 2025 +0100 - - aarch64: define macro for calling __libc_arm_za_disable - - A common sequence of instructions is used in several places - in assembly files, so define it in one place as an assembly - macro. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit b4b713bd8921aff04773557da94fabb5fb9dd705) - -diff --git a/sysdeps/aarch64/__longjmp.S b/sysdeps/aarch64/__longjmp.S -index 70ac02c44b..53b42e1bdc 100644 ---- a/sysdeps/aarch64/__longjmp.S -+++ b/sysdeps/aarch64/__longjmp.S -@@ -26,16 +26,8 @@ - ENTRY (__longjmp) - - #if IS_IN(libc) -- /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. -- The calling convention of __libc_arm_za_disable allows to do -- this thus allowing to avoid saving to and reading from stack. -- As a result we also don't need to sign the return address and -- check it after returning because it is not stored to stack. */ -- mov x13, x30 -- cfi_register (x30, x13) -- bl __libc_arm_za_disable -- mov x30, x13 -- cfi_register (x13, x30) -+ /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. */ -+ CALL_LIBC_ARM_ZA_DISABLE - #endif - - cfi_def_cfa (x0, 0) -diff --git a/sysdeps/aarch64/setjmp.S b/sysdeps/aarch64/setjmp.S -index 53c5e7d8cc..92cedfad83 100644 ---- a/sysdeps/aarch64/setjmp.S -+++ b/sysdeps/aarch64/setjmp.S -@@ -37,16 +37,8 @@ ENTRY_ALIGN (__sigsetjmp, 2) - 1: - - #if IS_IN(libc) -- /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. -- The calling convention of __libc_arm_za_disable allows to do -- this thus allowing to avoid saving to and reading from stack. -- As a result we also don't need to sign the return address and -- check it after returning because it is not stored to stack. */ -- mov x13, x30 -- cfi_register (x30, x13) -- bl __libc_arm_za_disable -- mov x30, x13 -- cfi_register (x13, x30) -+ /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. */ -+ CALL_LIBC_ARM_ZA_DISABLE - #endif - - stp x19, x20, [x0, #JB_X19<<3] -diff --git a/sysdeps/unix/sysv/linux/aarch64/setcontext.S b/sysdeps/unix/sysv/linux/aarch64/setcontext.S -index d9716f012e..8e98594663 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/setcontext.S -+++ b/sysdeps/unix/sysv/linux/aarch64/setcontext.S -@@ -49,15 +49,7 @@ ENTRY (__setcontext) - b C_SYMBOL_NAME (__syscall_error) - 1: - /* Clear ZA state of SME. */ -- /* The calling convention of __libc_arm_za_disable allows to do -- this thus allowing to avoid saving to and reading from stack. -- As a result we also don't need to sign the return address and -- check it after returning because it is not stored to stack. */ -- mov x13, x30 -- cfi_register (x30, x13) -- bl __libc_arm_za_disable -- mov x30, x13 -- cfi_register (x13, x30) -+ CALL_LIBC_ARM_ZA_DISABLE - /* Restore the general purpose registers. */ - mov x0, x9 - cfi_def_cfa (x0, 0) -diff --git a/sysdeps/unix/sysv/linux/aarch64/sysdep.h b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -index f0e8d64eef..fa01386b25 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/sysdep.h -+++ b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -@@ -150,6 +150,18 @@ - mov x8, SYS_ify (syscall_name); \ - svc 0 - -+/* Clear ZA state of SME (ASM version). */ -+/* The __libc_arm_za_disable function has special calling convention -+ that allows to call it without stack manipulation and preserving -+ most of the registers. */ -+ .macro CALL_LIBC_ARM_ZA_DISABLE -+ mov x13, x30 -+ .cfi_register x30, x13 -+ bl __libc_arm_za_disable -+ mov x30, x13 -+ .cfi_register x13, x30 -+ .endm -+ - #else /* not __ASSEMBLER__ */ - - # define VDSO_NAME "LINUX_2.6.39" - -commit 256030b9842a10b1f22851b1de0c119761417544 -Author: Yury Khrustalev -Date: Thu Sep 25 15:54:36 2025 +0100 - - aarch64: clear ZA state of SME before clone and clone3 syscalls - - This change adds a call to the __arm_za_disable() function immediately - before the SVC instruction inside clone() and clone3() wrappers. It also - adds a macro for inline clone() used in fork() and adds the same call to - the vfork implementation. This sets the ZA state of SME to "off" on return - from these functions (for both the child and the parent). - - The __arm_za_disable() function is described in [1] (8.1.3). Note that - the internal Glibc name for this function is __libc_arm_za_disable(). - - When this change was originally proposed [2,3], it generated a long - discussion where several questions and concerns were raised. Here we - will address these concerns and explain why this change is useful and, - in fact, necessary. - - In a nutshell, a C library that conforms to the AAPCS64 spec [1] (pertinent - to this change, mainly, the chapters 6.2 and 6.6), should have a call to the - __arm_za_disable() function in clone() and clone3() wrappers. The following - explains in detail why this is the case. - - When we consider using the __arm_za_disable() function inside the clone() - and clone3() libc wrappers, we talk about the C library subroutines clone() - and clone3() rather than the syscalls with similar names. In the current - version of Glibc, clone() is public and clone3() is private, but it being - private is not pertinent to this discussion. - - We will begin with stating that this change is NOT a bug fix for something - in the kernel. The requirement to call __arm_za_disable() does NOT come from - the kernel. It also is NOT needed to satisfy a contract between the kernel - and userspace. This is why it is not for the kernel documentation to describe - this requirement. This requirement is instead needed to satisfy a pure userspace - scheme outlined in [1] and to make sure that software that uses Glibc (or any - other C library that has correct handling of SME states (see below)) conforms - to [1] without having to unnecessarily become SME-aware thus losing portability. - - To recap (see [1] (6.2)), SME extension defines SME state which is part of - processor state. Part of this SME state is ZA state that is necessary to - manage ZA storage register in the context of the ZA lazy saving scheme [1] - (6.6). This scheme exists because it would be challenging to handle ZA - storage of SME in either callee-saved or caller-saved manner. - - There are 3 kinds of ZA state that are defined in terms of the PSTATE.ZA - bit and the TPIDR2_EL0 register (see [1] (6.6.3)): - - - "off":       PSTATE.ZA == 0 - - "active":    PSTATE.ZA == 1 TPIDR2_EL0 == null - - "dormant":   PSTATE.ZA == 1 TPIDR2_EL0 != null - - As [1] (6.7.2) outlines, every subroutine has exactly one SME-interface - depending on the permitted ZA-states on entry and on normal return from - a call to this subroutine. Callers of a subroutine must know and respect - the ZA-interface of the subroutines they are using. Using a subroutine - in a way that is not permitted by its ZA-interface is undefined behaviour. - - In particular, clone() and clone3() (the C library functions) have the - ZA-private interface. This means that the permitted ZA-states on entry - are "off" and "dormant" and that the permitted states on return are "off" - or "dormant" (but if and only if it was "dormant" on entry). - - This means that both functions in question should correctly handle both - "off" and "dormant" ZA-states on entry. The conforming states on return - are "off" and "dormant" (if inbound state was already "dormant"). - - This change ensures that the ZA-state on return is always "off". Note, - that, in the context of clone() and clone3(), "on return" means a point - when execution resumes at certain address after transferring from clone() - or clone3(). For the caller (we may refer to it as "parent") this is the - return address in the link register where the RET instruction jumps. For - the "child", this is the target branch address. - - So, the "off" state on return is permitted and conformant. Why can't we - retain the "dormant" state? In theory, we can, but we shouldn't, here is - why. - - Every subroutine with a private-ZA interface, including clone() and clone3(), - must comply with the lazy saving scheme [1] (6.7.2). This puts additional - responsibility on a subroutine if ZA-state on return is "dormant" because - this state has special meaning. The "caller" (that is the place in code - where execution is transferred to, so this include both "parent" and "child") - may check the ZA-state and use it as per the spec of the "dormant" state that - is outlined in [1] (6.6.6 and 6.6.7). - - Conforming to this would require more code inside of clone() and clone3() - which hardly is desirable. - - For the return to "parent" this could be achieved in theory, but given that - neither clone() nor clone3() are supposed to be used in the middle of an - SME operation, if wouldn't be useful. For the "return" to "child" this - would be particularly difficult to achieve given the complexity of these - functions and their interfaces. Most importantly, it would be illegal - and somewhat meaningless to allow a "child" to start execution in the - "dormant" ZA-state because the very essence of the "dormant" state implies - that there is a place to return and that there is some outer context that - we are allowed to interact with. - - To sum up, calling __arm_za_disable() to ensure the "off" ZA-state when the - execution resumes after a call to clone() or clone3() is correct and also - the most simple way to conform to [1]. - - Can there be situations when we can avoid calling __arm_za_disable()? - - Calling __arm_za_disable() implies certain (sufficiently small) overhead, - so one might rightly ponder avoiding making a call to this function when - we can afford not to. The most trivial cases like this (e.g. when the - calling thread doesn't have access to SME or to the TPIDR2_EL0 register) - are already handled by this function (see [1] (8.1.3 and 8.1.2)). Reasoning - about other possible use cases would require making code inside clone() and - clone3() more complicated and it would defeat the point of trying to make - an optimisation of not calling __arm_za_disable(). - - Why can't the kernel do this instead? - - The handling of SME state by the kernel is described in [4]. In short, - kernel must not impose a specific ZA-interface onto a userspace function. - Interaction with the kernel happens (among other thing) via system calls. - In Glibc many of the system calls (notably, including SYS_clone and - SYS_clone3) are used via wrappers, and the kernel has no control of them - and, moreover, it cannot dictate how these wrappers should behave because - it is simply outside of the kernel's remit. - - However, in certain cases, the kernel may ensure that a "child" doesn't - start in an incorrect state. This is what is done by the recent change - included in 6.16 kernel [5]. This is not enough to ensure that code that - uses clone() and clone3() function conforms to [1] when it runs on a - system that provides SME, hence this change. - - [1]: https://github.com/ARM-software/abi-aa/blob/main/aapcs64/aapcs64.rst - [2]: https://inbox.sourceware.org/libc-alpha/20250522114828.2291047-1-yury.khrustalev@arm.com - [3]: https://inbox.sourceware.org/libc-alpha/20250609121407.3316070-1-yury.khrustalev@arm.com - [4]: https://www.kernel.org/doc/html/v6.16/arch/arm64/sme.html - [5]: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cde5c32db55740659fca6d56c09b88800d88fd29 - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 27effb3d50424fb9634be77a2acd614b0386ff25) - -diff --git a/sysdeps/unix/sysv/linux/aarch64/clone.S b/sysdeps/unix/sysv/linux/aarch64/clone.S -index 40015c6933..53f1efd728 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/clone.S -+++ b/sysdeps/unix/sysv/linux/aarch64/clone.S -@@ -45,6 +45,9 @@ ENTRY(__clone) - and x1, x1, -16 - cbz x1, .Lsyscall_error - -+ /* Clear ZA state of SME. */ -+ CALL_LIBC_ARM_ZA_DISABLE -+ - /* Do the system call. */ - /* X0:flags, x1:newsp, x2:parenttidptr, x3:newtls, x4:childtid. */ - mov x0, x2 /* flags */ -diff --git a/sysdeps/unix/sysv/linux/aarch64/clone3.S b/sysdeps/unix/sysv/linux/aarch64/clone3.S -index c9ca845ef2..bc978b7e10 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/clone3.S -+++ b/sysdeps/unix/sysv/linux/aarch64/clone3.S -@@ -46,6 +46,9 @@ ENTRY(__clone3) - cbz x10, .Lsyscall_error /* No NULL cl_args pointer. */ - cbz x2, .Lsyscall_error /* No NULL function pointer. */ - -+ /* Clear ZA state of SME. */ -+ CALL_LIBC_ARM_ZA_DISABLE -+ - /* Do the system call, the kernel expects: - x8: system call number - x0: cl_args -diff --git a/sysdeps/unix/sysv/linux/aarch64/sysdep.h b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -index fa01386b25..30003c0145 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/sysdep.h -+++ b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -@@ -242,6 +242,31 @@ - #undef HAVE_INTERNAL_BRK_ADDR_SYMBOL - #define HAVE_INTERNAL_BRK_ADDR_SYMBOL 1 - -+/* Clear ZA state of SME (C version). */ -+/* The __libc_arm_za_disable function has special calling convention -+ that allows to call it without stack manipulation and preserving -+ most of the registers. */ -+#define CALL_LIBC_ARM_ZA_DISABLE() \ -+({ \ -+ unsigned long int __tmp; \ -+ asm volatile ( \ -+ " mov %0, x30\n" \ -+ " .cfi_register x30, %0\n" \ -+ " bl __libc_arm_za_disable\n" \ -+ " mov x30, %0\n" \ -+ " .cfi_register %0, x30\n" \ -+ : "=r" (__tmp) \ -+ : \ -+ : "x14", "x15", "x16", "x17", "x18", "memory" ); \ -+}) -+ -+/* Do clear ZA state of SME before making normal clone syscall. */ -+#define INLINE_CLONE_SYSCALL(a0, a1, a2, a3, a4) \ -+({ \ -+ CALL_LIBC_ARM_ZA_DISABLE (); \ -+ INLINE_SYSCALL_CALL (clone, a0, a1, a2, a3, a4); \ -+}) -+ - #endif /* __ASSEMBLER__ */ - - #endif /* linux/aarch64/sysdep.h */ -diff --git a/sysdeps/unix/sysv/linux/aarch64/vfork.S b/sysdeps/unix/sysv/linux/aarch64/vfork.S -index d5943a7485..2600bc9be3 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/vfork.S -+++ b/sysdeps/unix/sysv/linux/aarch64/vfork.S -@@ -27,6 +27,9 @@ - - ENTRY (__vfork) - -+ /* Clear ZA state of SME. */ -+ CALL_LIBC_ARM_ZA_DISABLE -+ - mov x0, #0x4111 /* CLONE_VM | CLONE_VFORK | SIGCHLD */ - mov x1, sp - DO_CALL (clone, 2) - -commit 71874f167aa5bb1538ff7e394beaacee28ebe65f -Author: Yury Khrustalev -Date: Fri Sep 26 10:03:45 2025 +0100 - - aarch64: tests for SME - - This commit adds tests for the following use cases relevant to handing of - the SME state: - - - fork() and vfork() - - clone() and clone3() - - signal handler - - While most cases are trivial, the case of clone3() is more complicated since - the clone3() symbol is not public in Glibc. - - To avoid having to check all possible ways clone3() may be called via other - public functions (e.g. vfork() or pthread_create()), we put together a test - that links directly with clone3.o. All the existing functions that have calls - to clone3() may not actually use it, in which case the outcome of such tests - would be unexpected. Having a direct call to the clone3() symbol in the test - allows to check precisely what we need to test: that the __arm_za_disable() - function is indeed called and has the desired effect. - - Linking to clone3.o also requires linking to __arm_za_disable.o that in - turn requires the _dl_hwcap2 hidden symbol which to provide in the test - and initialise it before using. - - Co-authored-by: Adhemerval Zanella Netto - Reviewed-by: Adhemerval Zanella - (cherry picked from commit ecb0fc2f0f839f36cd2a106283142c9df8ea8214) - -diff --git a/sysdeps/aarch64/Makefile b/sysdeps/aarch64/Makefile -index bb97d31355..9479fb9679 100644 ---- a/sysdeps/aarch64/Makefile -+++ b/sysdeps/aarch64/Makefile -@@ -79,8 +79,18 @@ sysdep_routines += \ - - tests += \ - tst-sme-jmp \ -+ tst-sme-signal \ - tst-sme-za-state \ - # tests -+tests-internal += \ -+ tst-sme-clone \ -+ tst-sme-clone3 \ -+ tst-sme-fork \ -+ tst-sme-vfork \ -+ # tests-internal -+ -+$(objpfx)tst-sme-clone3: $(objpfx)clone3.o $(objpfx)__arm_za_disable.o -+ - endif - - ifeq ($(subdir),malloc) -diff --git a/sysdeps/aarch64/tst-sme-clone.c b/sysdeps/aarch64/tst-sme-clone.c -new file mode 100644 -index 0000000000..7106ec7926 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-clone.c -@@ -0,0 +1,53 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when clone() syscall is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+#include -+ -+static int -+fun (void * const arg) -+{ -+ printf ("in child: %s\n", (const char *)arg); -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after clone in child", /* Clear. */ true); -+ return 0; -+} -+ -+static char __attribute__((aligned(16))) -+stack[1024 * 1024]; -+ -+static void -+run (struct blk *ptr) -+{ -+ char *syscall_name = (char *)"clone"; -+ printf ("in parent: before %s\n", syscall_name); -+ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (ptr); -+ check_sme_za_state ("before clone", /* Clear. */ false); -+ -+ pid_t pid = xclone (fun, syscall_name, stack, sizeof (stack), -+ CLONE_NEWUSER | CLONE_NEWNS | SIGCHLD); -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after clone in parent", /* Clear. */ true); -+ -+ TEST_VERIFY (xwaitpid (pid, NULL, 0) == pid); -+} -diff --git a/sysdeps/aarch64/tst-sme-clone3.c b/sysdeps/aarch64/tst-sme-clone3.c -new file mode 100644 -index 0000000000..402b040cfd ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-clone3.c -@@ -0,0 +1,84 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when clone3() syscall is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+#include -+ -+#include -+#include -+#include -+ -+/* Since clone3 is not a public symbol, we link this test explicitly -+ with clone3.o and have to provide this declaration. */ -+int __clone3 (struct clone_args *cl_args, size_t size, -+ int (*func)(void *arg), void *arg); -+ -+static int -+fun (void * const arg) -+{ -+ printf ("in child: %s\n", (const char *)arg); -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after clone3 in child", /* Clear. */ true); -+ return 0; -+} -+ -+static char __attribute__((aligned(16))) -+stack[1024 * 1024]; -+ -+/* Required by __arm_za_disable.o and provided by the startup code -+ as a hidden symbol. */ -+uint64_t _dl_hwcap2; -+ -+static void -+run (struct blk *ptr) -+{ -+ _dl_hwcap2 = getauxval (AT_HWCAP2); -+ -+ char *syscall_name = (char *)"clone3"; -+ struct clone_args args = { -+ .flags = CLONE_VM | CLONE_VFORK, -+ .exit_signal = SIGCHLD, -+ .stack = (uintptr_t) stack, -+ .stack_size = sizeof (stack), -+ }; -+ printf ("in parent: before %s\n", syscall_name); -+ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (ptr); -+ check_sme_za_state ("before clone3", /* Clear. */ false); -+ -+ pid_t pid = __clone3 (&args, sizeof (args), fun, syscall_name); -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after clone3 in parent", /* Clear. */ true); -+ -+ printf ("%s child pid: %d\n", syscall_name, pid); -+ -+ xwaitpid (pid, NULL, 0); -+ printf ("in parent: after %s\n", syscall_name); -+} -+ -+/* Workaround to simplify linking with clone3.o. */ -+void __syscall_error(int code) -+{ -+ int err = -code; -+ fprintf (stderr, "syscall error %d (%s)\n", err, strerror (err)); -+ exit (err); -+} -diff --git a/sysdeps/aarch64/tst-sme-fork.c b/sysdeps/aarch64/tst-sme-fork.c -new file mode 100644 -index 0000000000..b003b08884 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-fork.c -@@ -0,0 +1,43 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when fork() function is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+static void -+run (struct blk *blk) -+{ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (blk); -+ check_sme_za_state ("before fork", /* Clear. */ false); -+ fflush (stdout); -+ -+ pid_t pid = xfork (); -+ -+ if (pid == 0) -+ { -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after fork in child", /* Clear. */ true); -+ exit (0); -+ } -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after fork in parent", /* Clear. */ true); -+ -+ TEST_VERIFY (xwaitpid (pid, NULL, 0) == pid); -+} -diff --git a/sysdeps/aarch64/tst-sme-helper.h b/sysdeps/aarch64/tst-sme-helper.h -index f049416c2b..ab9c503e45 100644 ---- a/sysdeps/aarch64/tst-sme-helper.h -+++ b/sysdeps/aarch64/tst-sme-helper.h -@@ -16,9 +16,6 @@ - License along with the GNU C Library; if not, see - . */ - --/* Streaming SVE vector register size. */ --static unsigned long svl; -- - struct blk { - void *za_save_buffer; - uint16_t num_za_save_slices; -@@ -68,10 +65,10 @@ start_za (void) - - /* Load data into ZA byte by byte from p. */ - static void __attribute__ ((noinline)) --load_za (const void *p) -+load_za (const void *buf, unsigned long svl) - { - register unsigned long x15 asm ("x15") = 0; -- register unsigned long x16 asm ("x16") = (unsigned long)p; -+ register unsigned long x16 asm ("x16") = (unsigned long)buf; - register unsigned long x17 asm ("x17") = svl; - - asm volatile ( -diff --git a/sysdeps/aarch64/tst-sme-jmp.c b/sysdeps/aarch64/tst-sme-jmp.c -index 103897ad36..b2d21c6e1a 100644 ---- a/sysdeps/aarch64/tst-sme-jmp.c -+++ b/sysdeps/aarch64/tst-sme-jmp.c -@@ -29,6 +29,9 @@ - - #include "tst-sme-helper.h" - -+/* Streaming SVE vector register size. */ -+static unsigned long svl; -+ - static uint8_t *za_orig; - static uint8_t *za_dump; - static uint8_t *za_save; -@@ -82,7 +85,7 @@ longjmp_test (void) - FAIL_EXIT1 ("svcr != 0: %lu", svcr); - set_tpidr2 (&blk); - start_za (); -- load_za (za_orig); -+ load_za (za_orig, svl); - - print_data ("za save space", za_save); - p = get_tpidr2 (); -@@ -131,7 +134,7 @@ setcontext_test (void) - FAIL_EXIT1 ("svcr != 0: %lu", svcr); - set_tpidr2 (&blk); - start_za (); -- load_za (za_orig); -+ load_za (za_orig, svl); - - print_data ("za save space", za_save); - p = get_tpidr2 (); -diff --git a/sysdeps/aarch64/tst-sme-signal.c b/sysdeps/aarch64/tst-sme-signal.c -new file mode 100644 -index 0000000000..b4b07bcc44 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-signal.c -@@ -0,0 +1,115 @@ -+/* Test handling of SME state in a signal handler. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+#include -+ -+static struct _aarch64_ctx * -+extension (void *p) -+{ -+ return p; -+} -+ -+#ifndef TPIDR2_MAGIC -+#define TPIDR2_MAGIC 0x54504902 -+#endif -+ -+#ifndef ZA_MAGIC -+#define ZA_MAGIC 0x54366345 -+#endif -+ -+#ifndef ZT_MAGIC -+#define ZT_MAGIC 0x5a544e01 -+#endif -+ -+#ifndef EXTRA_MAGIC -+#define EXTRA_MAGIC 0x45585401 -+#endif -+ -+/* We use a pipe to make sure that the final check of the SME state -+ happens after signal handler finished. */ -+static int pipefd[2]; -+ -+#define WRITE(msg) xwrite (1, msg, sizeof (msg)); -+ -+static void -+handler (int signo, siginfo_t *si, void *ctx) -+{ -+ TEST_VERIFY (signo == SIGUSR1); -+ WRITE ("in the handler\n"); -+ check_sme_za_state ("during signal", true /* State is clear. */); -+ ucontext_t *uc = ctx; -+ void *p = uc->uc_mcontext.__reserved; -+ unsigned int found = 0; -+ uint32_t m; -+ while ((m = extension (p)->magic)) -+ { -+ if (m == TPIDR2_MAGIC) -+ { -+ WRITE ("found TPIDR2_MAGIC\n"); -+ found += 1; -+ } -+ if (m == ZA_MAGIC) -+ { -+ WRITE ("found ZA_MAGIC\n"); -+ found += 1; -+ } -+ if (m == ZT_MAGIC) -+ { -+ WRITE ("found ZT_MAGIC\n"); -+ found += 1; -+ } -+ if (m == EXTRA_MAGIC) -+ { -+ WRITE ("found EXTRA_MAGIC\n"); -+ struct { struct _aarch64_ctx h; uint64_t data; } *e = p; -+ p = (char *)e->data; -+ continue; -+ } -+ p = (char *)p + extension (p)->size; -+ } -+ TEST_COMPARE (found, 3); -+ -+ /* Signal that the wait is over (see below). */ -+ char message = '\0'; -+ xwrite (pipefd[1], &message, 1); -+} -+ -+static void -+run (struct blk *blk) -+{ -+ xpipe (pipefd); -+ -+ struct sigaction sigact; -+ sigemptyset (&sigact.sa_mask); -+ sigact.sa_flags = 0; -+ sigact.sa_flags |= SA_SIGINFO; -+ sigact.sa_sigaction = handler; -+ xsigaction (SIGUSR1, &sigact, NULL); -+ -+ enable_sme_za_state (blk); -+ check_sme_za_state ("before signal", false /* State is not clear. */); -+ xraise (SIGUSR1); -+ -+ /* Wait for signal handler to complete. */ -+ char response; -+ xread (pipefd[0], &response, 1); -+ -+ check_sme_za_state ("after signal", false /* State is not clear. */); -+} -diff --git a/sysdeps/aarch64/tst-sme-skeleton.c b/sysdeps/aarch64/tst-sme-skeleton.c -new file mode 100644 -index 0000000000..ba84dda1cb ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-skeleton.c -@@ -0,0 +1,101 @@ -+/* Template for SME tests. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include "tst-sme-helper.h" -+ -+/* Streaming SVE vector register size. */ -+static unsigned long svl; -+ -+static uint8_t *state; -+ -+static void -+enable_sme_za_state (struct blk *blk) -+{ -+ start_za (); -+ set_tpidr2 (blk); -+ load_za (blk, svl); -+} -+ -+/* Check if SME state is disabled (when CLEAR is true) or -+ enabled (when CLEAR is false). */ -+static void -+check_sme_za_state (const char msg[], bool clear) -+{ -+ unsigned long svcr = get_svcr (); -+ void *tpidr2 = get_tpidr2 (); -+ printf ("[%s]\n", msg); -+ printf ("svcr = %016lx\n", svcr); -+ printf ("tpidr2 = %016lx\n", (unsigned long)tpidr2); -+ if (clear) -+ { -+ TEST_VERIFY (svcr == 0); -+ TEST_VERIFY (tpidr2 == NULL); -+ } -+ else -+ { -+ TEST_VERIFY (svcr != 0); -+ TEST_VERIFY (tpidr2 != NULL); -+ } -+} -+ -+/* Should be defined in actual test that includes this -+ skeleton file. */ -+static void -+run (struct blk *ptr); -+ -+static int -+do_test (void) -+{ -+ unsigned long hwcap2 = getauxval (AT_HWCAP2); -+ if ((hwcap2 & HWCAP2_SME) == 0) -+ return EXIT_UNSUPPORTED; -+ -+ /* Get current streaming SVE vector length in bytes. */ -+ svl = get_svl (); -+ printf ("svl: %lu\n", svl); -+ -+ TEST_VERIFY_EXIT (!(svl < 16 || svl % 16 != 0 || svl >= (1 << 16))); -+ -+ /* Initialise buffer for ZA state of SME. */ -+ state = xmalloc (svl * svl); -+ memset (state, 1, svl * svl); -+ struct blk blk = { -+ .za_save_buffer = state, -+ .num_za_save_slices = svl, -+ .__reserved = {0}, -+ }; -+ -+ run (&blk); -+ -+ free (state); -+ return 0; -+} -+ -+#include -diff --git a/sysdeps/aarch64/tst-sme-vfork.c b/sysdeps/aarch64/tst-sme-vfork.c -new file mode 100644 -index 0000000000..3feea065e5 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-vfork.c -@@ -0,0 +1,43 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when vfork() function is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+static void -+run (struct blk *blk) -+{ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (blk); -+ check_sme_za_state ("before vfork", /* Clear. */ false); -+ fflush (stdout); -+ -+ pid_t pid = vfork (); -+ -+ if (pid == 0) -+ { -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after vfork in child", /* Clear. */ true); -+ _exit (0); -+ } -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after vfork in parent", /* Clear. */ true); -+ -+ TEST_VERIFY (xwaitpid (pid, NULL, 0) == pid); -+} -diff --git a/sysdeps/aarch64/tst-sme-za-state.c b/sysdeps/aarch64/tst-sme-za-state.c -index 63f6eebeb4..00118ef506 100644 ---- a/sysdeps/aarch64/tst-sme-za-state.c -+++ b/sysdeps/aarch64/tst-sme-za-state.c -@@ -16,47 +16,9 @@ - License along with the GNU C Library; if not, see - . */ - --#include --#include --#include --#include --#include -- --#include --#include --#include -- --#include "tst-sme-helper.h" -- --static uint8_t *state; -- --static void --enable_sme_za_state (struct blk *ptr) --{ -- set_tpidr2 (ptr); -- start_za (); -- load_za (state); --} -+#include "tst-sme-skeleton.c" - --static void --check_sme_za_state (const char msg[], bool clear) --{ -- unsigned long svcr = get_svcr (); -- void *tpidr2 = get_tpidr2 (); -- printf ("[%s]\n", msg); -- printf ("svcr = %016lx\n", svcr); -- printf ("tpidr2 = %016lx\n", (unsigned long)tpidr2); -- if (clear) -- { -- TEST_VERIFY (svcr == 0); -- TEST_VERIFY (tpidr2 == NULL); -- } -- else -- { -- TEST_VERIFY (svcr != 0); -- TEST_VERIFY (tpidr2 != NULL); -- } --} -+#include - - static void - run (struct blk *ptr) -@@ -88,32 +50,3 @@ run (struct blk *ptr) - TEST_COMPARE (ret, 42); - check_sme_za_state ("after longjmp", /* Clear. */ true); - } -- --static int --do_test (void) --{ -- unsigned long hwcap2 = getauxval (AT_HWCAP2); -- if ((hwcap2 & HWCAP2_SME) == 0) -- return EXIT_UNSUPPORTED; -- -- /* Get current streaming SVE vector register size. */ -- svl = get_svl (); -- printf ("svl: %lu\n", svl); -- TEST_VERIFY_EXIT (!(svl < 16 || svl % 16 != 0 || svl >= (1 << 16))); -- -- /* Initialise buffer for ZA state of SME. */ -- state = xmalloc (svl * svl); -- memset (state, 1, svl * svl); -- struct blk blk = { -- .za_save_buffer = state, -- .num_za_save_slices = svl, -- .__reserved = {0}, -- }; -- -- run (&blk); -- -- free (state); -- return 0; --} -- --#include - -commit bf499c2a4964bddc25a006ec1402f8996d78c6ff -Author: Jiamei Xie -Date: Tue Oct 14 20:14:11 2025 +0800 - - x86: fix wmemset ifunc stray '!' (bug 33542) - - The ifunc selector for wmemset had a stray '!' in the - X86_ISA_CPU_FEATURES_ARCH_P(...) check: - - if (X86_ISA_CPU_FEATURE_USABLE_P (cpu_features, AVX2) - && X86_ISA_CPU_FEATURES_ARCH_P (cpu_features, - AVX_Fast_Unaligned_Load, !)) - - This effectively negated the predicate and caused the AVX2/AVX512 - paths to be skipped, making the dispatcher fall back to the SSE2 - implementation even on CPUs where AVX2/AVX512 are available. The - regression leads to noticeable throughput loss for wmemset. - - Remove the stray '!' so the AVX_Fast_Unaligned_Load capability is - tested as intended and the correct AVX2/EVEX variants are selected. - - Impact: - - On AVX2/AVX512-capable x86_64, wmemset no longer incorrectly - falls back to SSE2; perf now shows __wmemset_evex/avx2 variants. - - Testing: - - benchtests/bench-wmemset shows improved bandwidth across sizes. - - perf confirm the selected symbol is no longer SSE2. - - Signed-off-by: xiejiamei - Signed-off-by: Li jing - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 4d86b6cdd8132e0410347e07262239750f86dfb4) - -diff --git a/sysdeps/x86_64/multiarch/ifunc-wmemset.h b/sysdeps/x86_64/multiarch/ifunc-wmemset.h -index f95cca6ae5..50af138230 100644 ---- a/sysdeps/x86_64/multiarch/ifunc-wmemset.h -+++ b/sysdeps/x86_64/multiarch/ifunc-wmemset.h -@@ -35,7 +35,7 @@ IFUNC_SELECTOR (void) - - if (X86_ISA_CPU_FEATURE_USABLE_P (cpu_features, AVX2) - && X86_ISA_CPU_FEATURES_ARCH_P (cpu_features, -- AVX_Fast_Unaligned_Load, !)) -+ AVX_Fast_Unaligned_Load,)) - { - if (X86_ISA_CPU_FEATURE_USABLE_P (cpu_features, AVX512VL)) - { - -commit de1fe81f471496366580ad728b8986a3424b2fd7 -Author: Yury Khrustalev -Date: Tue Oct 28 11:01:50 2025 +0000 - - aarch64: fix cfi directives around __libc_arm_za_disable - - Incorrect CFI directive corrupted call stack information - and prevented debuggers from correctly displaying call - stack information. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 2f77aec043f61e8533487850b11941a640ae2dea) - -diff --git a/sysdeps/unix/sysv/linux/aarch64/sysdep.h b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -index 30003c0145..8a7690d4a8 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/sysdep.h -+++ b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -@@ -155,11 +155,12 @@ - that allows to call it without stack manipulation and preserving - most of the registers. */ - .macro CALL_LIBC_ARM_ZA_DISABLE -+ cfi_remember_state - mov x13, x30 -- .cfi_register x30, x13 -+ cfi_register(x30, x13) - bl __libc_arm_za_disable - mov x30, x13 -- .cfi_register x13, x30 -+ cfi_restore_state - .endm - - #else /* not __ASSEMBLER__ */ -@@ -250,11 +251,12 @@ - ({ \ - unsigned long int __tmp; \ - asm volatile ( \ -+ " .cfi_remember_state\n" \ - " mov %0, x30\n" \ -- " .cfi_register x30, %0\n" \ -+ " .cfi_register x30, %0\n" \ - " bl __libc_arm_za_disable\n" \ - " mov x30, %0\n" \ -- " .cfi_register %0, x30\n" \ -+ " .cfi_restore_state\n" \ - : "=r" (__tmp) \ - : \ - : "x14", "x15", "x16", "x17", "x18", "memory" ); \ - -commit 17c3eab387c3ceb6972e57888a89b1480793f81a -Author: Yury Khrustalev -Date: Tue Nov 11 11:40:25 2025 +0000 - - aarch64: fix includes in SME tests - - Use the correct include for the SIGCHLD macro: signal.h - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit a9c426bcca59a9e228c4fbe75e75154217ec4ada) - -diff --git a/sysdeps/aarch64/tst-sme-clone.c b/sysdeps/aarch64/tst-sme-clone.c -index 7106ec7926..b6ad54fa37 100644 ---- a/sysdeps/aarch64/tst-sme-clone.c -+++ b/sysdeps/aarch64/tst-sme-clone.c -@@ -19,6 +19,7 @@ - - #include "tst-sme-skeleton.c" - -+#include - #include - - static int -diff --git a/sysdeps/aarch64/tst-sme-clone3.c b/sysdeps/aarch64/tst-sme-clone3.c -index 402b040cfd..f420d5984d 100644 ---- a/sysdeps/aarch64/tst-sme-clone3.c -+++ b/sysdeps/aarch64/tst-sme-clone3.c -@@ -22,7 +22,7 @@ - #include - - #include --#include -+#include - #include - - /* Since clone3 is not a public symbol, we link this test explicitly - -commit 97297120ce04f0edd16ed0357a11ef8731c5bd1e -Author: Joe Ramsay -Date: Thu Nov 6 15:36:03 2025 +0000 - - AArch64: Optimise SVE scalar callbacks - - Instead of using SVE instructions to marshall special results into the - correct lane, just write the entire vector (and the predicate) to - memory, then use cheaper scalar operations. - - Geomean speedup of 16% in special intervals on Neoverse with GCC 14. - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 5b82fb18827e962af9f080fdf3c1a69802783f67) - -diff --git a/sysdeps/aarch64/fpu/sv_math.h b/sysdeps/aarch64/fpu/sv_math.h -index 3d576df4cc..65d7f0ff20 100644 ---- a/sysdeps/aarch64/fpu/sv_math.h -+++ b/sysdeps/aarch64/fpu/sv_math.h -@@ -24,11 +24,29 @@ - - #include "vecmath_config.h" - -+#if !defined(__ARM_FEATURE_SVE_BITS) || __ARM_FEATURE_SVE_BITS == 0 -+/* If not specified by -msve-vector-bits, assume maximum vector length. */ -+# define SVE_VECTOR_BYTES 256 -+#else -+# define SVE_VECTOR_BYTES (__ARM_FEATURE_SVE_BITS / 8) -+#endif -+#define SVE_NUM_FLTS (SVE_VECTOR_BYTES / sizeof (float)) -+#define SVE_NUM_DBLS (SVE_VECTOR_BYTES / sizeof (double)) -+/* Predicate is stored as one bit per byte of VL so requires VL / 64 bytes. */ -+#define SVE_NUM_PG_BYTES (SVE_VECTOR_BYTES / sizeof (uint64_t)) -+ - #define SV_NAME_F1(fun) _ZGVsMxv_##fun##f - #define SV_NAME_D1(fun) _ZGVsMxv_##fun - #define SV_NAME_F2(fun) _ZGVsMxvv_##fun##f - #define SV_NAME_D2(fun) _ZGVsMxvv_##fun - -+static inline void -+svstr_p (uint8_t *dst, svbool_t p) -+{ -+ /* Predicate STR does not currently have an intrinsic. */ -+ __asm__("str %0, [%x1]\n" : : "Upa"(p), "r"(dst) : "memory"); -+} -+ - /* Double precision. */ - static inline svint64_t - sv_s64 (int64_t x) -@@ -51,33 +69,35 @@ sv_f64 (double x) - static inline svfloat64_t - sv_call_f64 (double (*f) (double), svfloat64_t x, svfloat64_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ double tmp[SVE_NUM_DBLS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b64 (), tmp, svsel (cmp, x, y)); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- double elem = svclastb_n_f64 (p, 0, x); -- elem = (*f) (elem); -- svfloat64_t y2 = svdup_n_f64 (elem); -- y = svsel_f64 (p, y2, y); -- p = svpnext_b64 (cmp, p); -+ if (pg_bits[i] & 1) -+ tmp[i] = f (tmp[i]); - } -- return y; -+ return svld1 (svptrue_b64 (), tmp); - } - - static inline svfloat64_t - sv_call2_f64 (double (*f) (double, double), svfloat64_t x1, svfloat64_t x2, - svfloat64_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ double tmp1[SVE_NUM_DBLS], tmp2[SVE_NUM_DBLS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b64 (), tmp1, svsel (cmp, x1, y)); -+ svst1 (cmp, tmp2, x2); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- double elem1 = svclastb_n_f64 (p, 0, x1); -- double elem2 = svclastb_n_f64 (p, 0, x2); -- double ret = (*f) (elem1, elem2); -- svfloat64_t y2 = svdup_n_f64 (ret); -- y = svsel_f64 (p, y2, y); -- p = svpnext_b64 (cmp, p); -+ if (pg_bits[i] & 1) -+ tmp1[i] = f (tmp1[i], tmp2[i]); - } -- return y; -+ return svld1 (svptrue_b64 (), tmp1); - } - - static inline svuint64_t -@@ -109,33 +129,40 @@ sv_f32 (float x) - static inline svfloat32_t - sv_call_f32 (float (*f) (float), svfloat32_t x, svfloat32_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ float tmp[SVE_NUM_FLTS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b32 (), tmp, svsel (cmp, x, y)); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- float elem = svclastb_n_f32 (p, 0, x); -- elem = f (elem); -- svfloat32_t y2 = svdup_n_f32 (elem); -- y = svsel_f32 (p, y2, y); -- p = svpnext_b32 (cmp, p); -+ uint8_t p = pg_bits[i]; -+ if (p & 1) -+ tmp[i * 2] = f (tmp[i * 2]); -+ if (p & (1 << 4)) -+ tmp[i * 2 + 1] = f (tmp[i * 2 + 1]); - } -- return y; -+ return svld1 (svptrue_b32 (), tmp); - } - - static inline svfloat32_t - sv_call2_f32 (float (*f) (float, float), svfloat32_t x1, svfloat32_t x2, - svfloat32_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ float tmp1[SVE_NUM_FLTS], tmp2[SVE_NUM_FLTS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b32 (), tmp1, svsel (cmp, x1, y)); -+ svst1 (cmp, tmp2, x2); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- float elem1 = svclastb_n_f32 (p, 0, x1); -- float elem2 = svclastb_n_f32 (p, 0, x2); -- float ret = f (elem1, elem2); -- svfloat32_t y2 = svdup_n_f32 (ret); -- y = svsel_f32 (p, y2, y); -- p = svpnext_b32 (cmp, p); -+ uint8_t p = pg_bits[i]; -+ if (p & 1) -+ tmp1[i * 2] = f (tmp1[i * 2], tmp2[i * 2]); -+ if (p & (1 << 4)) -+ tmp1[i * 2 + 1] = f (tmp1[i * 2 + 1], tmp2[i * 2 + 1]); - } -- return y; -+ return svld1 (svptrue_b32 (), tmp1); - } -- - #endif - -commit ec041b1f53bf1fd29d94ee147fac69da66437dc6 -Author: Joe Ramsay -Date: Thu Nov 6 18:26:54 2025 +0000 - - AArch64: Fix instability in AdvSIMD tan - - Previously presence of special-cases in one lane could affect the - results in other lanes due to unconditional scalar fallback. The old - WANT_SIMD_EXCEPT option (which has never been enabled in libmvec) has - been removed from AOR, making it easier to spot and fix this. 4% - improvement in throughput with GCC 14 on Neoverse V1. This bug is - present as far back as 2.39 (where tan was first introduced). - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 6c22823da57aa5218f717f569c04c9573c0448c5) - -diff --git a/sysdeps/aarch64/fpu/tan_advsimd.c b/sysdeps/aarch64/fpu/tan_advsimd.c -index 825c9754b3..d391a003d8 100644 ---- a/sysdeps/aarch64/fpu/tan_advsimd.c -+++ b/sysdeps/aarch64/fpu/tan_advsimd.c -@@ -25,9 +25,7 @@ static const struct data - float64x2_t poly[9]; - double half_pi[2]; - float64x2_t two_over_pi, shift; --#if !WANT_SIMD_EXCEPT - float64x2_t range_val; --#endif - } data = { - /* Coefficients generated using FPMinimax. */ - .poly = { V2 (0x1.5555555555556p-2), V2 (0x1.1111111110a63p-3), -@@ -38,20 +36,17 @@ static const struct data - .half_pi = { 0x1.921fb54442d18p0, 0x1.1a62633145c07p-54 }, - .two_over_pi = V2 (0x1.45f306dc9c883p-1), - .shift = V2 (0x1.8p52), --#if !WANT_SIMD_EXCEPT - .range_val = V2 (0x1p23), --#endif - }; - - #define RangeVal 0x4160000000000000 /* asuint64(0x1p23). */ - #define TinyBound 0x3e50000000000000 /* asuint64(2^-26). */ --#define Thresh 0x310000000000000 /* RangeVal - TinyBound. */ - - /* Special cases (fall back to scalar calls). */ - static float64x2_t VPCS_ATTR NOINLINE --special_case (float64x2_t x) -+special_case (float64x2_t x, float64x2_t n, float64x2_t d, uint64x2_t special) - { -- return v_call_f64 (tan, x, x, v_u64 (-1)); -+ return v_call_f64 (tan, x, vdivq_f64 (n, d), special); - } - - /* Vector approximation for double-precision tan. -@@ -65,14 +60,6 @@ float64x2_t VPCS_ATTR V_NAME_D1 (tan) (float64x2_t x) - very large inputs. Fall back to scalar routine for all lanes if any are - too large, or Inf/NaN. If fenv exceptions are expected, also fall back for - tiny input to avoid underflow. */ --#if WANT_SIMD_EXCEPT -- uint64x2_t iax = vreinterpretq_u64_f64 (vabsq_f64 (x)); -- /* iax - tiny_bound > range_val - tiny_bound. */ -- uint64x2_t special -- = vcgtq_u64 (vsubq_u64 (iax, v_u64 (TinyBound)), v_u64 (Thresh)); -- if (__glibc_unlikely (v_any_u64 (special))) -- return special_case (x); --#endif - - /* q = nearest integer to 2 * x / pi. */ - float64x2_t q -@@ -81,9 +68,8 @@ float64x2_t VPCS_ATTR V_NAME_D1 (tan) (float64x2_t x) - - /* Use q to reduce x to r in [-pi/4, pi/4], by: - r = x - q * pi/2, in extended precision. */ -- float64x2_t r = x; - float64x2_t half_pi = vld1q_f64 (dat->half_pi); -- r = vfmsq_laneq_f64 (r, q, half_pi, 0); -+ float64x2_t r = vfmsq_laneq_f64 (x, q, half_pi, 0); - r = vfmsq_laneq_f64 (r, q, half_pi, 1); - /* Further reduce r to [-pi/8, pi/8], to be reconstructed using double angle - formula. */ -@@ -114,12 +100,13 @@ float64x2_t VPCS_ATTR V_NAME_D1 (tan) (float64x2_t x) - - uint64x2_t no_recip = vtstq_u64 (vreinterpretq_u64_s64 (qi), v_u64 (1)); - --#if !WANT_SIMD_EXCEPT - uint64x2_t special = vcageq_f64 (x, dat->range_val); -+ float64x2_t swap = vbslq_f64 (no_recip, n, vnegq_f64 (d)); -+ d = vbslq_f64 (no_recip, d, n); -+ n = swap; -+ - if (__glibc_unlikely (v_any_u64 (special))) -- return special_case (x); --#endif -+ return special_case (x, n, d, special); - -- return vdivq_f64 (vbslq_f64 (no_recip, n, vnegq_f64 (d)), -- vbslq_f64 (no_recip, d, n)); -+ return vdivq_f64 (n, d); - } - -commit 0c9430ed976b961343dd29b752091f3c4771cf30 -Author: Joe Ramsay -Date: Thu Nov 6 18:29:33 2025 +0000 - - AArch64: Fix instability in AdvSIMD sinh - - Previously presence of special-cases in one lane could affect the - results in other lanes due to unconditional scalar fallback. The old - WANT_SIMD_EXCEPT option (which has never been enabled in libmvec) has - been removed from AOR, making it easier to spot and fix - this. No measured change in performance. This patch applies cleanly as - far back as 2.41, however there are conflicts with 2.40 where sinh was - first introduced. - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit e45af510bc816e860c8e2e1d4a652b4fe15c4b34) - -diff --git a/sysdeps/aarch64/fpu/sinh_advsimd.c b/sysdeps/aarch64/fpu/sinh_advsimd.c -index 0d6a4856f8..b6b60262c6 100644 ---- a/sysdeps/aarch64/fpu/sinh_advsimd.c -+++ b/sysdeps/aarch64/fpu/sinh_advsimd.c -@@ -24,36 +24,26 @@ static const struct data - { - struct v_expm1_data d; - uint64x2_t halff; --#if WANT_SIMD_EXCEPT -- uint64x2_t tiny_bound, thresh; --#else - float64x2_t large_bound; --#endif - } data = { - .d = V_EXPM1_DATA, - .halff = V2 (0x3fe0000000000000), --#if WANT_SIMD_EXCEPT -- /* 2^-26, below which sinh(x) rounds to x. */ -- .tiny_bound = V2 (0x3e50000000000000), -- /* asuint(large_bound) - asuint(tiny_bound). */ -- .thresh = V2 (0x0230000000000000), --#else - /* 2^9. expm1 helper overflows for large input. */ - .large_bound = V2 (0x1p+9), --#endif - }; - - static float64x2_t NOINLINE VPCS_ATTR --special_case (float64x2_t x) -+special_case (float64x2_t x, float64x2_t t, float64x2_t halfsign, -+ uint64x2_t special) - { -- return v_call_f64 (sinh, x, x, v_u64 (-1)); -+ return v_call_f64 (sinh, x, vmulq_f64 (t, halfsign), special); - } - - /* Approximation for vector double-precision sinh(x) using expm1. - sinh(x) = (exp(x) - exp(-x)) / 2. - The greatest observed error is 2.52 ULP: -- _ZGVnN2v_sinh(-0x1.a098a2177a2b9p-2) got -0x1.ac2f05bb66fccp-2 -- want -0x1.ac2f05bb66fc9p-2. */ -+ _ZGVnN2v_sinh(0x1.9f6ff2ab6fb19p-2) got 0x1.aaed83a3153ccp-2 -+ want 0x1.aaed83a3153c9p-2. */ - float64x2_t VPCS_ATTR V_NAME_D1 (sinh) (float64x2_t x) - { - const struct data *d = ptr_barrier (&data); -@@ -63,21 +53,16 @@ float64x2_t VPCS_ATTR V_NAME_D1 (sinh) (float64x2_t x) - float64x2_t halfsign = vreinterpretq_f64_u64 ( - vbslq_u64 (v_u64 (0x8000000000000000), ix, d->halff)); - --#if WANT_SIMD_EXCEPT -- uint64x2_t special = vcgeq_u64 ( -- vsubq_u64 (vreinterpretq_u64_f64 (ax), d->tiny_bound), d->thresh); --#else - uint64x2_t special = vcageq_f64 (x, d->large_bound); --#endif -- -- /* Fall back to scalar variant for all lanes if any of them are special. */ -- if (__glibc_unlikely (v_any_u64 (special))) -- return special_case (x); - - /* Up to the point that expm1 overflows, we can use it to calculate sinh - using a slight rearrangement of the definition of sinh. This allows us to - retain acceptable accuracy for very small inputs. */ - float64x2_t t = expm1_inline (ax, &d->d); - t = vaddq_f64 (t, vdivq_f64 (t, vaddq_f64 (t, v_f64 (1.0)))); -+ -+ if (__glibc_unlikely (v_any_u64 (special))) -+ return special_case (x, t, halfsign, special); -+ - return vmulq_f64 (t, halfsign); - } - -commit 710d7a2e8374cf09280a0db170a6c813b70b59e5 -Author: Pierre Blanchard -Date: Tue Nov 18 15:03:10 2025 +0000 - - AArch64: fix SVE tanpi(f) [BZ #33642] - - Fixed svld1rq using incorrect predicates (BZ #33642). - Next to no performance variations (tested on V1). - - Reviewed-by: Wilco Dijkstra  - (cherry picked from commit e889160273a4c2b68870c9adf341955867d76a7d) - -diff --git a/sysdeps/aarch64/fpu/tanpi_sve.c b/sysdeps/aarch64/fpu/tanpi_sve.c -index 57c643ae29..bfe6828e1f 100644 ---- a/sysdeps/aarch64/fpu/tanpi_sve.c -+++ b/sysdeps/aarch64/fpu/tanpi_sve.c -@@ -1,6 +1,6 @@ - /* Double-precision (SVE) tanpi function - -- Copyright (C) 2024 Free Software Foundation, Inc. -+ Copyright (C) 2024-2025 Free Software Foundation, Inc. - This file is part of the GNU C Library. - - The GNU C Library is free software; you can redistribute it and/or -@@ -58,10 +58,10 @@ svfloat64_t SV_NAME_D1 (tanpi) (svfloat64_t x, const svbool_t pg) - svfloat64_t r2 = svmul_x (pg, r, r); - svfloat64_t r4 = svmul_x (pg, r2, r2); - -- svfloat64_t c_1_3 = svld1rq (pg, &d->c1); -- svfloat64_t c_5_7 = svld1rq (pg, &d->c5); -- svfloat64_t c_9_11 = svld1rq (pg, &d->c9); -- svfloat64_t c_13_14 = svld1rq (pg, &d->c13); -+ svfloat64_t c_1_3 = svld1rq (svptrue_b64 (), &d->c1); -+ svfloat64_t c_5_7 = svld1rq (svptrue_b64 (), &d->c5); -+ svfloat64_t c_9_11 = svld1rq (svptrue_b64 (), &d->c9); -+ svfloat64_t c_13_14 = svld1rq (svptrue_b64 (), &d->c13); - svfloat64_t p01 = svmla_lane (sv_f64 (d->c0), r2, c_1_3, 0); - svfloat64_t p23 = svmla_lane (sv_f64 (d->c2), r2, c_1_3, 1); - svfloat64_t p45 = svmla_lane (sv_f64 (d->c4), r2, c_5_7, 0); -diff --git a/sysdeps/aarch64/fpu/tanpif_sve.c b/sysdeps/aarch64/fpu/tanpif_sve.c -index 0285f56f34..6894379564 100644 ---- a/sysdeps/aarch64/fpu/tanpif_sve.c -+++ b/sysdeps/aarch64/fpu/tanpif_sve.c -@@ -1,6 +1,6 @@ - /* Single-precision (SVE) tanpi function - -- Copyright (C) 2024 Free Software Foundation, Inc. -+ Copyright (C) 2024-2025 Free Software Foundation, Inc. - This file is part of the GNU C Library. - - The GNU C Library is free software; you can redistribute it and/or -@@ -37,7 +37,7 @@ const static struct v_tanpif_data - svfloat32_t SV_NAME_F1 (tanpi) (svfloat32_t x, const svbool_t pg) - { - const struct v_tanpif_data *d = ptr_barrier (&tanpif_data); -- svfloat32_t odd_coeffs = svld1rq (pg, &d->c1); -+ svfloat32_t odd_coeffs = svld1rq (svptrue_b32 (), &d->c1); - svfloat32_t n = svrintn_x (pg, x); - - /* inf produces nan that propagates. */ - -commit 828b8d23f3fa05234d35032a61a746918accf91d -Author: Pierre Blanchard -Date: Tue Nov 18 15:09:05 2025 +0000 - - AArch64: Fix and improve SVE pow(f) special cases - - powf: - - Update scalar special case function to best use new interface. - - pow: - - Make specialcase NOINLINE to prevent str/ldr leaking in fast path. - Remove depency in sv_call2, as new callback impl is not a - performance gain. - Replace with vectorised specialcase since structure of scalar - routine is fairly simple. - - Throughput gain of about 5-10% on V1 for large values and 25% for subnormal `x`. - - Reviewed-by: Wilco Dijkstra  - (cherry picked from commit bb6519de1e6fe73d79bc71588ec4e5668907f080) - -diff --git a/sysdeps/aarch64/fpu/pow_sve.c b/sysdeps/aarch64/fpu/pow_sve.c -index b8c1b39dca..becf1a8410 100644 ---- a/sysdeps/aarch64/fpu/pow_sve.c -+++ b/sysdeps/aarch64/fpu/pow_sve.c -@@ -31,8 +31,8 @@ - The SVE algorithm drops the tail in the exp computation at the price of - a lower accuracy, slightly above 1ULP. - The SVE algorithm also drops the special treatement of small (< 2^-65) and -- large (> 2^63) finite values of |y|, as they only affect non-round to nearest -- modes. -+ large (> 2^63) finite values of |y|, as they only affect non-round to -+ nearest modes. - - Maximum measured error is 1.04 ULPs: - SV_NAME_D2 (pow) (0x1.3d2d45bc848acp+63, -0x1.a48a38b40cd43p-12) -@@ -156,42 +156,22 @@ sv_zeroinfnan (svbool_t pg, svuint64_t i) - a double. (int32_t)KI is the k used in the argument reduction and exponent - adjustment of scale, positive k here means the result may overflow and - negative k means the result may underflow. */ --static inline double --specialcase (double tmp, uint64_t sbits, uint64_t ki) --{ -- double scale; -- if ((ki & 0x80000000) == 0) -- { -- /* k > 0, the exponent of scale might have overflowed by <= 460. */ -- sbits -= 1009ull << 52; -- scale = asdouble (sbits); -- return 0x1p1009 * (scale + scale * tmp); -- } -- /* k < 0, need special care in the subnormal range. */ -- sbits += 1022ull << 52; -- /* Note: sbits is signed scale. */ -- scale = asdouble (sbits); -- double y = scale + scale * tmp; -- return 0x1p-1022 * y; --} -- --/* Scalar fallback for special cases of SVE pow's exp. */ - static inline svfloat64_t --sv_call_specialcase (svfloat64_t x1, svuint64_t u1, svuint64_t u2, -- svfloat64_t y, svbool_t cmp) -+specialcase (svfloat64_t tmp, svuint64_t sbits, svuint64_t ki, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -- { -- double sx1 = svclastb (p, 0, x1); -- uint64_t su1 = svclastb (p, 0, u1); -- uint64_t su2 = svclastb (p, 0, u2); -- double elem = specialcase (sx1, su1, su2); -- svfloat64_t y2 = sv_f64 (elem); -- y = svsel (p, y2, y); -- p = svpnext_b64 (cmp, p); -- } -- return y; -+ svbool_t p_pos = svcmpge_n_f64 (cmp, svreinterpret_f64_u64 (ki), 0.0); -+ -+ /* Scale up or down depending on sign of k. */ -+ svint64_t offset -+ = svsel_s64 (p_pos, sv_s64 (1009ull << 52), sv_s64 (-1022ull << 52)); -+ svfloat64_t factor -+ = svsel_f64 (p_pos, sv_f64 (0x1p1009), sv_f64 (0x1p-1022)); -+ -+ svuint64_t offset_sbits -+ = svsub_u64_x (cmp, sbits, svreinterpret_u64_s64 (offset)); -+ svfloat64_t scale = svreinterpret_f64_u64 (offset_sbits); -+ svfloat64_t res = svmad_f64_x (cmp, scale, tmp, scale); -+ return svmul_f64_x (cmp, res, factor); - } - - /* Compute y+TAIL = log(x) where the rounded result is y and TAIL has about -@@ -214,8 +194,8 @@ sv_log_inline (svbool_t pg, svuint64_t ix, svfloat64_t *tail, - - /* log(x) = k*Ln2 + log(c) + log1p(z/c-1). */ - /* SVE lookup requires 3 separate lookup tables, as opposed to scalar version -- that uses array of structures. We also do the lookup earlier in the code to -- make sure it finishes as early as possible. */ -+ that uses array of structures. We also do the lookup earlier in the code -+ to make sure it finishes as early as possible. */ - svfloat64_t invc = svld1_gather_index (pg, __v_pow_log_data.invc, i); - svfloat64_t logc = svld1_gather_index (pg, __v_pow_log_data.logc, i); - svfloat64_t logctail = svld1_gather_index (pg, __v_pow_log_data.logctail, i); -@@ -325,14 +305,14 @@ sv_exp_inline (svbool_t pg, svfloat64_t x, svfloat64_t xtail, - svbool_t oflow = svcmpge (pg, abstop, HugeExp); - oflow = svand_z (pg, uoflow, svbic_z (pg, oflow, uflow)); - -- /* For large |x| values (512 < |x| < 1024) scale * (1 + TMP) can overflow -- or underflow. */ -+ /* Handle underflow and overlow in scale. -+ For large |x| values (512 < |x| < 1024), scale * (1 + TMP) can -+ overflow or underflow. */ - svbool_t special = svbic_z (pg, uoflow, svorr_z (pg, uflow, oflow)); -+ if (__glibc_unlikely (svptest_any (pg, special))) -+ z = svsel (special, specialcase (tmp, sbits, ki, special), z); - -- /* Update result with special and large cases. */ -- z = sv_call_specialcase (tmp, sbits, ki, z, special); -- -- /* Handle underflow and overflow. */ -+ /* Handle underflow and overflow in exp. */ - svbool_t x_is_neg = svcmplt (pg, x, 0); - svuint64_t sign_mask - = svlsl_x (pg, sign_bias, 52 - V_POW_EXP_TABLE_BITS); -@@ -353,7 +333,7 @@ sv_exp_inline (svbool_t pg, svfloat64_t x, svfloat64_t xtail, - } - - static inline double --pow_sc (double x, double y) -+pow_specialcase (double x, double y) - { - uint64_t ix = asuint64 (x); - uint64_t iy = asuint64 (y); -@@ -382,6 +362,14 @@ pow_sc (double x, double y) - return x; - } - -+/* Scalar fallback for special case routines with custom signature. */ -+static svfloat64_t NOINLINE -+sv_pow_specialcase (svfloat64_t x1, svfloat64_t x2, svfloat64_t y, -+ svbool_t cmp) -+{ -+ return sv_call2_f64 (pow_specialcase, x1, x2, y, cmp); -+} -+ - svfloat64_t SV_NAME_D2 (pow) (svfloat64_t x, svfloat64_t y, const svbool_t pg) - { - const struct data *d = ptr_barrier (&data); -@@ -444,7 +432,7 @@ svfloat64_t SV_NAME_D2 (pow) (svfloat64_t x, svfloat64_t y, const svbool_t pg) - - /* Cases of zero/inf/nan x or y. */ - if (__glibc_unlikely (svptest_any (svptrue_b64 (), special))) -- vz = sv_call2_f64 (pow_sc, x, y, vz, special); -+ vz = sv_pow_specialcase (x, y, vz, special); - - return vz; - } -diff --git a/sysdeps/aarch64/fpu/powf_sve.c b/sysdeps/aarch64/fpu/powf_sve.c -index 65e9bd29d9..76f54b3522 100644 ---- a/sysdeps/aarch64/fpu/powf_sve.c -+++ b/sysdeps/aarch64/fpu/powf_sve.c -@@ -116,11 +116,10 @@ zeroinfnan (uint32_t ix) - preamble of scalar powf except that we do not update ix and sign_bias. This - is done in the preamble of the SVE powf. */ - static inline float --powf_specialcase (float x, float y, float z) -+powf_specialcase (float x, float y) - { - uint32_t ix = asuint (x); - uint32_t iy = asuint (y); -- /* Either (x < 0x1p-126 or inf or nan) or (y is 0 or inf or nan). */ - if (__glibc_unlikely (zeroinfnan (iy))) - { - if (2 * iy == 0) -@@ -142,32 +141,15 @@ powf_specialcase (float x, float y, float z) - x2 = -x2; - return iy & 0x80000000 ? 1 / x2 : x2; - } -- /* We need a return here in case x<0 and y is integer, but all other tests -- need to be run. */ -- return z; -+ /* Return x for convenience, but make sure result is never used. */ -+ return x; - } - - /* Scalar fallback for special case routines with custom signature. */ - static svfloat32_t NOINLINE --sv_call_powf_sc (svfloat32_t x1, svfloat32_t x2, svfloat32_t y) -+sv_call_powf_sc (svfloat32_t x1, svfloat32_t x2, svfloat32_t y, svbool_t cmp) - { -- /* Special cases of x or y: zero, inf and nan. */ -- svbool_t xspecial = sv_zeroinfnan (svptrue_b32 (), svreinterpret_u32 (x1)); -- svbool_t yspecial = sv_zeroinfnan (svptrue_b32 (), svreinterpret_u32 (x2)); -- svbool_t cmp = svorr_z (svptrue_b32 (), xspecial, yspecial); -- -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -- { -- float sx1 = svclastb (p, 0, x1); -- float sx2 = svclastb (p, 0, x2); -- float elem = svclastb (p, 0, y); -- elem = powf_specialcase (sx1, sx2, elem); -- svfloat32_t y2 = sv_f32 (elem); -- y = svsel (p, y2, y); -- p = svpnext_b32 (cmp, p); -- } -- return y; -+ return sv_call2_f32 (powf_specialcase, x1, x2, y, cmp); - } - - /* Compute core for half of the lanes in double precision. */ -@@ -330,7 +312,7 @@ svfloat32_t SV_NAME_F2 (pow) (svfloat32_t x, svfloat32_t y, const svbool_t pg) - ret = svsel (yint_or_xpos, ret, sv_f32 (__builtin_nanf (""))); - - if (__glibc_unlikely (svptest_any (cmp, cmp))) -- return sv_call_powf_sc (x, y, ret); -+ return sv_call_powf_sc (x, y, ret, cmp); - - return ret; - } - -commit 6b2957cfe8ad1e02c03a28abfc5a251c05e4005e -Author: Sachin Monga -Date: Fri Nov 21 00:30:04 2025 -0500 - - ppc64le: Restore optimized strcmp for power10 - - This patch addresses the actual cause of CVE-2025-5702 - - The vector non-volatile registers are not used anymore for - 32 byte load and comparison operation - - Additionally, the assembler workaround used earlier for the - instruction lxvp is replaced with actual instruction. - - Signed-off-by: Sachin Monga - Co-authored-by: Paul Murphy - (cherry picked from commit 9a40b1cda519cc4f532acb6d020390829df3d81b) - -diff --git a/sysdeps/powerpc/powerpc64/le/power10/strcmp.S b/sysdeps/powerpc/powerpc64/le/power10/strcmp.S -new file mode 100644 -index 0000000000..0d4a53317c ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/le/power10/strcmp.S -@@ -0,0 +1,185 @@ -+/* Optimized strcmp implementation for PowerPC64/POWER10. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+#include -+ -+#ifndef STRCMP -+# define STRCMP strcmp -+#endif -+ -+/* Implements the function -+ int [r3] strcmp (const char *s1 [r3], const char *s2 [r4]). */ -+ -+ -+#define COMPARE_16(vreg1,vreg2,offset) \ -+ lxv vreg1+32,offset(r3); \ -+ lxv vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(different); \ -+ -+#define COMPARE_32(vreg1,vreg2,offset,label1,label2) \ -+ lxvp vreg1+32,offset(r3); \ -+ lxvp vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1+1,vreg2+1; \ -+ bne cr6,L(label1); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(label2); \ -+ -+#define TAIL(vreg1,vreg2) \ -+ vctzlsbb r6,v7; \ -+ vextubrx r5,r6,vreg1; \ -+ vextubrx r4,r6,vreg2; \ -+ subf r3,r4,r5; \ -+ blr; \ -+ -+#define CHECK_N_BYTES(reg1,reg2,len_reg) \ -+ sldi r0,len_reg,56; \ -+ lxvl 32+v4,reg1,r0; \ -+ lxvl 32+v5,reg2,r0; \ -+ add reg1,reg1,len_reg; \ -+ add reg2,reg2,len_reg; \ -+ vcmpnezb. v7,v4,v5; \ -+ vctzlsbb r6,v7; \ -+ cmpld cr7,r6,len_reg; \ -+ blt cr7,L(different); \ -+ -+ -+ .machine power10 -+ENTRY_TOCLESS (STRCMP, 4) -+ li r11,16 -+ /* eq bit of cr1 used as swap status flag to indicate if -+ source pointers were swapped. */ -+ crclr 4*cr1+eq -+ andi. r7,r3,15 -+ sub r7,r11,r7 /* r7(nalign1) = 16 - (str1 & 15). */ -+ andi. r9,r4,15 -+ sub r5,r11,r9 /* r5(nalign2) = 16 - (str2 & 15). */ -+ cmpld cr7,r7,r5 -+ beq cr7,L(same_aligned) -+ blt cr7,L(nalign1_min) -+ /* Swap r3 and r4, and r7 and r5 such that r3 and r7 hold the -+ pointer which is closer to the next 16B boundary so that only -+ one CHECK_N_BYTES is needed before entering the loop below. */ -+ mr r8,r4 -+ mr r4,r3 -+ mr r3,r8 -+ mr r12,r7 -+ mr r7,r5 -+ mr r5,r12 -+ crset 4*cr1+eq /* Set bit on swapping source pointers. */ -+ -+ .p2align 5 -+L(nalign1_min): -+ CHECK_N_BYTES(r3,r4,r7) -+ -+ .p2align 5 -+L(s1_aligned): -+ /* r9 and r5 is number of bytes to be read after and before -+ page boundary correspondingly. */ -+ sub r5,r5,r7 -+ subfic r9,r5,16 -+ /* Now let r7 hold the count of quadwords which can be -+ checked without crossing a page boundary. quadword offset is -+ (str2>>4)&0xFF. */ -+ rlwinm r7,r4,28,0xFF -+ /* Below check is required only for first iteration. For second -+ iteration and beyond, the new loop counter is always 255. */ -+ cmpldi r7,255 -+ beq L(L3) -+ /* Get the initial loop count by 255-((str2>>4)&0xFF). */ -+ subfic r11,r7,255 -+ -+ .p2align 5 -+L(L1): -+ mtctr r11 -+ -+ .p2align 5 -+L(L2): -+ COMPARE_16(v4,v5,0) /* Load 16B blocks using lxv. */ -+ addi r3,r3,16 -+ addi r4,r4,16 -+ bdnz L(L2) -+ /* Cross the page boundary of s2, carefully. */ -+ -+ .p2align 5 -+L(L3): -+ CHECK_N_BYTES(r3,r4,r5) -+ CHECK_N_BYTES(r3,r4,r9) -+ li r11,255 /* Load the new loop counter. */ -+ b L(L1) -+ -+ .p2align 5 -+L(same_aligned): -+ CHECK_N_BYTES(r3,r4,r7) -+ /* Align s1 to 32B and adjust s2 address. -+ Use lxvp only if both s1 and s2 are 32B aligned. */ -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ -+ clrldi r6,r3,59 -+ subfic r5,r6,32 -+ add r3,r3,r5 -+ add r4,r4,r5 -+ andi. r5,r4,0x1F -+ beq cr0,L(32B_aligned_loop) -+ -+ .p2align 5 -+L(16B_aligned_loop): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ b L(16B_aligned_loop) -+ -+ /* Calculate and return the difference. */ -+L(different): -+ vctzlsbb r6,v7 -+ vextubrx r5,r6,v4 -+ vextubrx r4,r6,v5 -+ bt 4*cr1+eq,L(swapped) -+ subf r3,r4,r5 -+ blr -+ -+ /* If src pointers were swapped, then swap the -+ indices and calculate the return value. */ -+L(swapped): -+ subf r3,r5,r4 -+ blr -+ -+ .p2align 5 -+L(32B_aligned_loop): -+ COMPARE_32(v14,v16,0,tail1,tail2) -+ COMPARE_32(v14,v16,32,tail1,tail2) -+ COMPARE_32(v14,v16,64,tail1,tail2) -+ COMPARE_32(v14,v16,96,tail1,tail2) -+ addi r3,r3,128 -+ addi r4,r4,128 -+ b L(32B_aligned_loop) -+ -+L(tail1): TAIL(v15,v17) -+L(tail2): TAIL(v14,v16) -+ -+END (STRCMP) -+libc_hidden_builtin_def (strcmp) -diff --git a/sysdeps/powerpc/powerpc64/multiarch/Makefile b/sysdeps/powerpc/powerpc64/multiarch/Makefile -index e321ce54e0..818f287925 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/Makefile -+++ b/sysdeps/powerpc/powerpc64/multiarch/Makefile -@@ -32,7 +32,7 @@ sysdep_routines += memcpy-power8-cached memcpy-power7 memcpy-a2 memcpy-power6 \ - ifneq (,$(filter %le,$(config-machine))) - sysdep_routines += memcmp-power10 memcpy-power10 memmove-power10 memset-power10 \ - rawmemchr-power9 rawmemchr-power10 \ -- strcmp-power9 strncmp-power9 \ -+ strcmp-power9 strcmp-power10 strncmp-power9 \ - strcpy-power9 strcat-power10 stpcpy-power9 \ - strlen-power9 strncpy-power9 stpncpy-power9 strlen-power10 - endif -diff --git a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -index 016d05fd16..dde3bec709 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -@@ -366,6 +366,10 @@ __libc_ifunc_impl_list (const char *name, struct libc_ifunc_impl *array, - /* Support sysdeps/powerpc/powerpc64/multiarch/strcmp.c. */ - IFUNC_IMPL (i, name, strcmp, - #ifdef __LITTLE_ENDIAN__ -+ IFUNC_IMPL_ADD (array, i, strcmp, -+ (hwcap2 & PPC_FEATURE2_ARCH_3_1) -+ && (hwcap & PPC_FEATURE_HAS_VSX), -+ __strcmp_power10) - IFUNC_IMPL_ADD (array, i, strcmp, - hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC, -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strcmp-power10.S b/sysdeps/powerpc/powerpc64/multiarch/strcmp-power10.S -new file mode 100644 -index 0000000000..a4ee7fb53c ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/multiarch/strcmp-power10.S -@@ -0,0 +1,26 @@ -+/* Optimized strcmp implementation for POWER10/PPC64. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#if defined __LITTLE_ENDIAN__ && IS_IN (libc) -+#define STRCMP __strcmp_power10 -+ -+#undef libc_hidden_builtin_def -+#define libc_hidden_builtin_def(name) -+ -+#include -+#endif /* __LITTLE_ENDIAN__ && IS_IN (libc) */ -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strcmp.c b/sysdeps/powerpc/powerpc64/multiarch/strcmp.c -index 7c77c084a7..3c636e3bbc 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/strcmp.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/strcmp.c -@@ -29,12 +29,16 @@ extern __typeof (strcmp) __strcmp_power7 attribute_hidden; - extern __typeof (strcmp) __strcmp_power8 attribute_hidden; - # ifdef __LITTLE_ENDIAN__ - extern __typeof (strcmp) __strcmp_power9 attribute_hidden; -+extern __typeof (strcmp) __strcmp_power10 attribute_hidden; - # endif - - # undef strcmp - - libc_ifunc_redirected (__redirect_strcmp, strcmp, - # ifdef __LITTLE_ENDIAN__ -+ (hwcap2 & PPC_FEATURE2_ARCH_3_1 -+ && hwcap & PPC_FEATURE_HAS_VSX) -+ ? __strcmp_power10 : - (hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC) - ? __strcmp_power9 : - -commit 2dbf973fe03f9b8fd5a4740ee0af0d47afdd7bbd -Author: Sachin Monga -Date: Fri Nov 21 00:30:52 2025 -0500 - - ppc64le: Restore optimized strncmp for power10 - - This patch addresses the actual cause of CVE-2025-5745 - - The vector non-volatile registers are not used anymore for - 32 byte load and comparison operation - - Additionally, the assembler workaround used earlier for the - instruction lxvp is replaced with actual instruction. - - Signed-off-by: Sachin Monga - Co-authored-by: Paul Murphy - (cherry picked from commit 2ea943f7d487d6a4166658b32af7c5365889fc34) - -diff --git a/sysdeps/powerpc/powerpc64/le/power10/strncmp.S b/sysdeps/powerpc/powerpc64/le/power10/strncmp.S -new file mode 100644 -index 0000000000..6e09fcb7f2 ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/le/power10/strncmp.S -@@ -0,0 +1,252 @@ -+/* Optimized strncmp implementation for PowerPC64/POWER10. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+/* Implements the function -+ -+ int [r3] strncmp (const char *s1 [r3], const char *s2 [r4], size_t [r5] n) -+ -+ The implementation uses unaligned doubleword access to avoid specialized -+ code paths depending of data alignment for first 32 bytes and uses -+ vectorised loops after that. */ -+ -+#ifndef STRNCMP -+# define STRNCMP strncmp -+#endif -+ -+#define COMPARE_16(vreg1,vreg2,offset) \ -+ lxv vreg1+32,offset(r3); \ -+ lxv vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(different); \ -+ cmpldi cr7,r5,16; \ -+ ble cr7,L(ret0); \ -+ addi r5,r5,-16; -+ -+#define COMPARE_32(vreg1,vreg2,offset,label1,label2) \ -+ lxvp vreg1+32,offset(r3); \ -+ lxvp vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1+1,vreg2+1; \ -+ bne cr6,L(label1); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(label2); \ -+ cmpldi cr7,r5,32; \ -+ ble cr7,L(ret0); \ -+ addi r5,r5,-32; -+ -+#define TAIL_FIRST_16B(vreg1,vreg2) \ -+ vctzlsbb r6,v7; \ -+ cmpld cr7,r5,r6; \ -+ ble cr7,L(ret0); \ -+ vextubrx r5,r6,vreg1; \ -+ vextubrx r4,r6,vreg2; \ -+ subf r3,r4,r5; \ -+ blr; -+ -+#define TAIL_SECOND_16B(vreg1,vreg2) \ -+ vctzlsbb r6,v7; \ -+ addi r0,r6,16; \ -+ cmpld cr7,r5,r0; \ -+ ble cr7,L(ret0); \ -+ vextubrx r5,r6,vreg1; \ -+ vextubrx r4,r6,vreg2; \ -+ subf r3,r4,r5; \ -+ blr; -+ -+#define CHECK_N_BYTES(reg1,reg2,len_reg) \ -+ sldi r6,len_reg,56; \ -+ lxvl 32+v4,reg1,r6; \ -+ lxvl 32+v5,reg2,r6; \ -+ add reg1,reg1,len_reg; \ -+ add reg2,reg2,len_reg; \ -+ vcmpnezb v7,v4,v5; \ -+ vctzlsbb r6,v7; \ -+ cmpld cr7,r6,len_reg; \ -+ blt cr7,L(different); \ -+ cmpld cr7,r5,len_reg; \ -+ ble cr7,L(ret0); \ -+ sub r5,r5,len_reg; \ -+ -+ .machine power10 -+ENTRY_TOCLESS (STRNCMP, 4) -+ /* Check if size is 0. */ -+ cmpdi cr0,r5,0 -+ beq cr0,L(ret0) -+ andi. r7,r3,4095 -+ andi. r8,r4,4095 -+ cmpldi cr0,r7,4096-16 -+ cmpldi cr1,r8,4096-16 -+ bgt cr0,L(crosses) -+ bgt cr1,L(crosses) -+ COMPARE_16(v4,v5,0) -+ addi r3,r3,16 -+ addi r4,r4,16 -+ -+L(crosses): -+ andi. r7,r3,15 -+ subfic r7,r7,16 /* r7(nalign1) = 16 - (str1 & 15). */ -+ andi. r9,r4,15 -+ subfic r8,r9,16 /* r8(nalign2) = 16 - (str2 & 15). */ -+ cmpld cr7,r7,r8 -+ beq cr7,L(same_aligned) -+ blt cr7,L(nalign1_min) -+ -+ /* nalign2 is minimum and s2 pointer is aligned. */ -+ CHECK_N_BYTES(r3,r4,r8) -+ /* Are we on the 64B hunk which crosses a page? */ -+ andi. r10,r3,63 /* Determine offset into 64B hunk. */ -+ andi. r8,r3,15 /* The offset into the 16B hunk. */ -+ neg r7,r3 -+ andi. r9,r7,15 /* Number of bytes after a 16B cross. */ -+ rlwinm. r7,r7,26,0x3F /* ((r4-4096))>>6&63. */ -+ beq L(compare_64_pagecross) -+ mtctr r7 -+ b L(compare_64B_unaligned) -+ -+ /* nalign1 is minimum and s1 pointer is aligned. */ -+L(nalign1_min): -+ CHECK_N_BYTES(r3,r4,r7) -+ /* Are we on the 64B hunk which crosses a page? */ -+ andi. r10,r4,63 /* Determine offset into 64B hunk. */ -+ andi. r8,r4,15 /* The offset into the 16B hunk. */ -+ neg r7,r4 -+ andi. r9,r7,15 /* Number of bytes after a 16B cross. */ -+ rlwinm. r7,r7,26,0x3F /* ((r4-4096))>>6&63. */ -+ beq L(compare_64_pagecross) -+ mtctr r7 -+ -+ .p2align 5 -+L(compare_64B_unaligned): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ bdnz L(compare_64B_unaligned) -+ -+ /* Cross the page boundary of s2, carefully. Only for first -+ iteration we have to get the count of 64B blocks to be checked. -+ From second iteration and beyond, loop counter is always 63. */ -+L(compare_64_pagecross): -+ li r11, 63 -+ mtctr r11 -+ cmpldi r10,16 -+ ble L(cross_4) -+ cmpldi r10,32 -+ ble L(cross_3) -+ cmpldi r10,48 -+ ble L(cross_2) -+L(cross_1): -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ addi r3,r3,48 -+ addi r4,r4,48 -+ b L(compare_64B_unaligned) -+L(cross_2): -+ COMPARE_16(v4,v5,0) -+ addi r3,r3,16 -+ addi r4,r4,16 -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ addi r3,r3,32 -+ addi r4,r4,32 -+ b L(compare_64B_unaligned) -+L(cross_3): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ addi r3,r3,32 -+ addi r4,r4,32 -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ COMPARE_16(v4,v5,0) -+ addi r3,r3,16 -+ addi r4,r4,16 -+ b L(compare_64B_unaligned) -+L(cross_4): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ addi r3,r3,48 -+ addi r4,r4,48 -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ b L(compare_64B_unaligned) -+ -+L(same_aligned): -+ CHECK_N_BYTES(r3,r4,r7) -+ /* Align s1 to 32B and adjust s2 address. -+ Use lxvp only if both s1 and s2 are 32B aligned. */ -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ addi r5,r5,32 -+ -+ clrldi r6,r3,59 -+ subfic r7,r6,32 -+ add r3,r3,r7 -+ add r4,r4,r7 -+ subf r5,r7,r5 -+ andi. r7,r4,0x1F -+ beq cr0,L(32B_aligned_loop) -+ -+ .p2align 5 -+L(16B_aligned_loop): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ b L(16B_aligned_loop) -+ -+ /* Calculate and return the difference. */ -+L(different): -+ TAIL_FIRST_16B(v4,v5) -+ -+ .p2align 5 -+L(32B_aligned_loop): -+ COMPARE_32(v14,v16,0,tail1,tail2) -+ COMPARE_32(v14,v16,32,tail1,tail2) -+ COMPARE_32(v14,v16,64,tail1,tail2) -+ COMPARE_32(v14,v16,96,tail1,tail2) -+ addi r3,r3,128 -+ addi r4,r4,128 -+ b L(32B_aligned_loop) -+ -+L(tail1): TAIL_FIRST_16B(v15,v17) -+L(tail2): TAIL_SECOND_16B(v14,v16) -+ -+ .p2align 5 -+L(ret0): -+ li r3,0 -+ blr -+ -+END(STRNCMP) -+libc_hidden_builtin_def(strncmp) -diff --git a/sysdeps/powerpc/powerpc64/multiarch/Makefile b/sysdeps/powerpc/powerpc64/multiarch/Makefile -index 818f287925..c9178223a8 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/Makefile -+++ b/sysdeps/powerpc/powerpc64/multiarch/Makefile -@@ -32,7 +32,7 @@ sysdep_routines += memcpy-power8-cached memcpy-power7 memcpy-a2 memcpy-power6 \ - ifneq (,$(filter %le,$(config-machine))) - sysdep_routines += memcmp-power10 memcpy-power10 memmove-power10 memset-power10 \ - rawmemchr-power9 rawmemchr-power10 \ -- strcmp-power9 strcmp-power10 strncmp-power9 \ -+ strcmp-power9 strcmp-power10 strncmp-power9 strncmp-power10 \ - strcpy-power9 strcat-power10 stpcpy-power9 \ - strlen-power9 strncpy-power9 stpncpy-power9 strlen-power10 - endif -diff --git a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -index dde3bec709..f2b9cccde3 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -@@ -164,6 +164,9 @@ __libc_ifunc_impl_list (const char *name, struct libc_ifunc_impl *array, - /* Support sysdeps/powerpc/powerpc64/multiarch/strncmp.c. */ - IFUNC_IMPL (i, name, strncmp, - #ifdef __LITTLE_ENDIAN__ -+ IFUNC_IMPL_ADD (array, i, strncmp, hwcap2 & PPC_FEATURE2_ARCH_3_1 -+ && hwcap & PPC_FEATURE_HAS_VSX, -+ __strncmp_power10) - IFUNC_IMPL_ADD (array, i, strncmp, hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC, - __strncmp_power9) -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strncmp-power10.S b/sysdeps/powerpc/powerpc64/multiarch/strncmp-power10.S -new file mode 100644 -index 0000000000..bb25bc75b8 ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/multiarch/strncmp-power10.S -@@ -0,0 +1,25 @@ -+/* Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#if defined __LITTLE_ENDIAN__ && IS_IN (libc) -+#define STRNCMP __strncmp_power10 -+ -+#undef libc_hidden_builtin_def -+#define libc_hidden_builtin_def(name) -+ -+#include -+#endif -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strncmp.c b/sysdeps/powerpc/powerpc64/multiarch/strncmp.c -index 4cfe27fa45..0a664a620d 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/strncmp.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/strncmp.c -@@ -29,6 +29,7 @@ extern __typeof (strncmp) __strncmp_ppc attribute_hidden; - extern __typeof (strncmp) __strncmp_power8 attribute_hidden; - # ifdef __LITTLE_ENDIAN__ - extern __typeof (strncmp) __strncmp_power9 attribute_hidden; -+extern __typeof (strncmp) __strncmp_power10 attribute_hidden; - # endif - # undef strncmp - -@@ -36,6 +37,9 @@ extern __typeof (strncmp) __strncmp_power9 attribute_hidden; - ifunc symbol properly. */ - libc_ifunc_redirected (__redirect_strncmp, strncmp, - # ifdef __LITTLE_ENDIAN__ -+ (hwcap2 & PPC_FEATURE2_ARCH_3_1 -+ && hwcap & PPC_FEATURE_HAS_VSX) -+ ? __strncmp_power10 : - (hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC) - ? __strncmp_power9 : - -commit 8aaf4b732d7650c2db3beb4dc8bb70eab5b022c3 -Author: Sachin Monga -Date: Thu Nov 27 03:28:17 2025 -0500 - - ppc64le: Power 10 rawmemchr clobbers v20 (bug #33091) - - Replace non-volatile(v20) by volatile(v17) - since v20 is not restored - - Reviewed-by: Peter Bergner - (cherry picked from commit b59799f14f97f697c3a36b4380bd4ce2fbe65f11) - -diff --git a/sysdeps/powerpc/powerpc64/le/power10/strlen.S b/sysdeps/powerpc/powerpc64/le/power10/strlen.S -index ec644d5bff..29a5a7d960 100644 ---- a/sysdeps/powerpc/powerpc64/le/power10/strlen.S -+++ b/sysdeps/powerpc/powerpc64/le/power10/strlen.S -@@ -31,7 +31,7 @@ - # define FUNCNAME RAWMEMCHR - # endif - # define MCOUNT_NARGS 2 --# define VREG_ZERO v20 -+# define VREG_ZERO v17 - # define OFF_START_LOOP 256 - # define RAWMEMCHR_SUBTRACT_VECTORS \ - vsububm v4,v4,v18; \ - -commit b11411fe2ee7a8f3c3a2c1ee99c1729adb9a0efe -Author: Yury Khrustalev -Date: Thu Nov 6 12:57:58 2025 +0000 - - posix: Fix invalid flags test for p{write,read}v2 - - Two tests fail from time to time when a new flag is added for the - p{write,read}v2 functions in a new Linux kernel: - - - misc/tst-preadvwritev2 - - misc/tst-preadvwritev64v2 - - This disrupts when testing Glibc on a system with a newer kernel - and it seems we can try improve testing for invalid flags setting - all the bits that are not supposed to be supported (rather than - setting only the next unsupported bit). - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 58a31b4316f1f687184eb147ffa1c676bc6a190e) - -diff --git a/misc/tst-preadvwritev2-common.c b/misc/tst-preadvwritev2-common.c -index ff1007d6d2..5182fcdce0 100644 ---- a/misc/tst-preadvwritev2-common.c -+++ b/misc/tst-preadvwritev2-common.c -@@ -109,9 +109,8 @@ do_test_with_invalid_iov (void) - static void - do_test_with_invalid_flags (void) - { -- /* Set the next bit from the mask of all supported flags. */ -- int invalid_flag = RWF_SUPPORTED != 0 ? __builtin_clz (RWF_SUPPORTED) : 2; -- invalid_flag = 0x1 << ((sizeof (int) * CHAR_BIT) - invalid_flag); -+ /* Set all the bits that are not used by the supported flags. */ -+ int invalid_flag = ~RWF_SUPPORTED; - - char buf[32]; - const struct iovec vec = { .iov_base = buf, .iov_len = sizeof (buf) }; - -commit efdf4c0c879590109778244046f84a80a4bf8fee -Author: DJ Delorie -Date: Wed Oct 15 21:37:56 2025 -0400 - - sprof: check pread size and offset for overflow - - Add a bit of descriptive paranoia to the values we read from - the ELF headers and use to access data. - - Reviewed-by: Collin Funk - (cherry picked from commit 324084649b2da2f6840e3a1b84159a4e9a9e9a74) - -diff --git a/elf/sprof.c b/elf/sprof.c -index c82c7c9db6..e9d2a66a4f 100644 ---- a/elf/sprof.c -+++ b/elf/sprof.c -@@ -38,6 +38,7 @@ - #include - #include - #include -+#include - - /* Get libc version number. */ - #include "../version.h" -@@ -410,6 +411,7 @@ load_shobj (const char *name) - int fd; - ElfW(Shdr) *shdr; - size_t pagesize = getpagesize (); -+ struct stat st; - - /* Since we use dlopen() we must be prepared to work around the sometimes - strange lookup rules for the shared objects. If we have a file foo.so -@@ -550,14 +552,39 @@ load_shobj (const char *name) - error (EXIT_FAILURE, errno, _("Reopening shared object `%s' failed"), - map->l_name); - -+ if (fstat (fd, &st) < 0) -+ error (EXIT_FAILURE, errno, _("stat(%s) failure"), map->l_name); -+ -+ /* We're depending on data that's being read from the file, so be a -+ bit paranoid here and make sure the requests are reasonable - -+ i.e. both size and offset are nonnegative and smaller than the -+ file size, as well as the offset of the end of the data. PREAD -+ would have failed anyway, but this is more robust and explains -+ what happened better. Note that SZ must be unsigned and OFF may -+ be signed or unsigned. */ -+#define PCHECK(sz1,off1) { \ -+ size_t sz = sz1, end_off; \ -+ off_t off = off1; \ -+ if (sz > st.st_size \ -+ || off < 0 || off > st.st_size \ -+ || INT_ADD_WRAPV (sz, off, &end_off) \ -+ || end_off > st.st_size) \ -+ error (EXIT_FAILURE, ERANGE, \ -+ _("read outside of file extents %zu + %zd > %zu"), \ -+ sz, off, st.st_size); \ -+ } -+ - /* Map the section header. */ - size_t size = ehdr->e_shnum * sizeof (ElfW(Shdr)); - shdr = (ElfW(Shdr) *) alloca (size); -+ PCHECK (size, ehdr->e_shoff); - if (pread (fd, shdr, size, ehdr->e_shoff) != size) - error (EXIT_FAILURE, errno, _("reading of section headers failed")); - - /* Get the section header string table. */ - char *shstrtab = (char *) alloca (shdr[ehdr->e_shstrndx].sh_size); -+ PCHECK (shdr[ehdr->e_shstrndx].sh_size, -+ shdr[ehdr->e_shstrndx].sh_offset); - if (pread (fd, shstrtab, shdr[ehdr->e_shstrndx].sh_size, - shdr[ehdr->e_shstrndx].sh_offset) - != shdr[ehdr->e_shstrndx].sh_size) -@@ -585,6 +612,7 @@ load_shobj (const char *name) - size_t size = debuglink_entry->sh_size; - char *debuginfo_fname = (char *) alloca (size + 1); - debuginfo_fname[size] = '\0'; -+ PCHECK (size, debuglink_entry->sh_offset); - if (pread (fd, debuginfo_fname, size, debuglink_entry->sh_offset) - != size) - { -@@ -638,21 +666,32 @@ load_shobj (const char *name) - if (fd2 != -1) - { - ElfW(Ehdr) ehdr2; -+ struct stat st; -+ -+ if (fstat (fd2, &st) < 0) -+ error (EXIT_FAILURE, errno, _("stat(%s) failure"), workbuf); - - /* Read the ELF header. */ -+ PCHECK (sizeof (ehdr2), 0); - if (pread (fd2, &ehdr2, sizeof (ehdr2), 0) != sizeof (ehdr2)) - error (EXIT_FAILURE, errno, - _("reading of ELF header failed")); - - /* Map the section header. */ -- size_t size = ehdr2.e_shnum * sizeof (ElfW(Shdr)); -+ size_t size; -+ if (INT_MULTIPLY_WRAPV (ehdr2.e_shnum, sizeof (ElfW(Shdr)), &size)) -+ error (EXIT_FAILURE, errno, _("too many section headers")); -+ - ElfW(Shdr) *shdr2 = (ElfW(Shdr) *) alloca (size); -+ PCHECK (size, ehdr2.e_shoff); - if (pread (fd2, shdr2, size, ehdr2.e_shoff) != size) - error (EXIT_FAILURE, errno, - _("reading of section headers failed")); - - /* Get the section header string table. */ - shstrtab = (char *) alloca (shdr2[ehdr2.e_shstrndx].sh_size); -+ PCHECK (shdr2[ehdr2.e_shstrndx].sh_size, -+ shdr2[ehdr2.e_shstrndx].sh_offset); - if (pread (fd2, shstrtab, shdr2[ehdr2.e_shstrndx].sh_size, - shdr2[ehdr2.e_shstrndx].sh_offset) - != shdr2[ehdr2.e_shstrndx].sh_size) - -commit 2a0873aa81446149c6065237e1dc2511201bef88 -Author: Collin Funk -Date: Wed Oct 22 01:51:09 2025 -0700 - - sprof: fix -Wformat warnings on 32-bit hosts - - Reviewed-by: H.J. Lu - (cherry picked from commit 9681f645ba20fc3c18eb12ffebf94e3df1f888e3) - -diff --git a/elf/sprof.c b/elf/sprof.c -index e9d2a66a4f..513e0470b2 100644 ---- a/elf/sprof.c -+++ b/elf/sprof.c -@@ -570,8 +570,8 @@ load_shobj (const char *name) - || INT_ADD_WRAPV (sz, off, &end_off) \ - || end_off > st.st_size) \ - error (EXIT_FAILURE, ERANGE, \ -- _("read outside of file extents %zu + %zd > %zu"), \ -- sz, off, st.st_size); \ -+ _("read outside of file extents %zu + %jd > %jd"), \ -+ sz, (intmax_t) off, (intmax_t) st.st_size); \ - } - - /* Map the section header. */ - -commit 8dfb84ad4efbc39c7a7d9efdff6f6ac9017e0a53 -Author: Florian Weimer -Date: Thu Nov 6 14:33:22 2025 +0100 - - support: Fix FILE * leak in check_for_unshare_hints in test-container - - The file opened via fopen is never closed. - - (cherry picked from commit 20a2a756089eacd7e7f4c02e381e82b5d0e40a2c) - -diff --git a/support/test-container.c b/support/test-container.c -index 1c40ab377f..d78139622f 100644 ---- a/support/test-container.c -+++ b/support/test-container.c -@@ -705,6 +705,7 @@ check_for_unshare_hints (int require_pidns) - - val = -1; /* Sentinel. */ - int cnt = fscanf (f, "%d", &val); -+ fclose (f); - if (cnt == 1 && val != files[i].bad_value) - continue; - - -commit a1d3294a5bed821aece03994ab4e72c8b822a962 -Author: Florian Weimer -Date: Thu Nov 6 14:49:21 2025 +0100 - - support: Exit on consistency check failure in resolv_response_add_name - - Using TEST_VERIFY (crname_target != crname) instructs some analysis - tools that crname_target == crname might hold. Under this assumption, - they report a use-after-free for crname_target->offset below, caused - by the previous free (crname). - - Reviewed-by: Collin Funk - (cherry picked from commit b64335ff111c071fde61aec1c1a8460afb3d16d4) - -diff --git a/support/resolv_test.c b/support/resolv_test.c -index ab37d3d58c..29e59da958 100644 ---- a/support/resolv_test.c -+++ b/support/resolv_test.c -@@ -326,7 +326,7 @@ resolv_response_add_name (struct resolv_response_builder *b, - crname_target = *ptr; - else - crname_target = NULL; -- TEST_VERIFY (crname_target != crname); -+ TEST_VERIFY_EXIT (crname_target != crname); - /* Not added to the tree. */ - free (crname); - } - -commit f122d0b4d145814869bf10c56db1d971bcba55c5 -Author: Sunil K Pandey -Date: Tue Dec 9 08:57:44 2025 -0800 - - nptl: Optimize trylock for high cache contention workloads (BZ #33704) - - Check lock availability before acquisition to reduce cache line - bouncing. Significantly improves trylock throughput on multi-core - systems under heavy contention. - - Tested on x86_64. - - Fixes BZ #33704. - - Co-authored-by: Alex M Wells - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 63716823dbad9482e09972907ae98e9cb00f9b86) - -diff --git a/nptl/pthread_mutex_trylock.c b/nptl/pthread_mutex_trylock.c -index dbb8fcc754..392619021b 100644 ---- a/nptl/pthread_mutex_trylock.c -+++ b/nptl/pthread_mutex_trylock.c -@@ -48,7 +48,8 @@ ___pthread_mutex_trylock (pthread_mutex_t *mutex) - return 0; - } - -- if (lll_trylock (mutex->__data.__lock) == 0) -+ if (atomic_load_relaxed (&(mutex->__data.__lock)) == 0 -+ && lll_trylock (mutex->__data.__lock) == 0) - { - /* Record the ownership. */ - mutex->__data.__owner = id; -@@ -71,7 +72,10 @@ ___pthread_mutex_trylock (pthread_mutex_t *mutex) - /*FALL THROUGH*/ - case PTHREAD_MUTEX_ADAPTIVE_NP: - case PTHREAD_MUTEX_ERRORCHECK_NP: -- if (lll_trylock (mutex->__data.__lock) != 0) -+ /* Mutex type is already loaded, lock check overhead should -+ be minimal. */ -+ if (atomic_load_relaxed (&(mutex->__data.__lock)) != 0 -+ || lll_trylock (mutex->__data.__lock) != 0) - break; - - /* Record the ownership. */ - -commit b0ec8fb689df862171f0f78994a3bdeb51313545 -Author: Siddhesh Poyarekar -Date: Thu Jan 15 06:06:40 2026 -0500 - - memalign: reinstate alignment overflow check (CVE-2026-0861) - - The change to cap valid sizes to PTRDIFF_MAX inadvertently dropped the - overflow check for alignment in memalign functions, _mid_memalign and - _int_memalign. Reinstate the overflow check in _int_memalign, aligned - with the PTRDIFF_MAX change since that is directly responsible for the - CVE. The missing _mid_memalign check is not relevant (and does not have - a security impact) and may need a different approach to fully resolve, - so it has been omitted. - - CVE-Id: CVE-2026-0861 - Vulnerable-Commit: 9bf8e29ca136094f73f69f725f15c51facc97206 - Reported-by: Igor Morgenstern, Aisle Research - Fixes: BZ #33796 - Reviewed-by: Wilco Dijkstra - Signed-off-by: Siddhesh Poyarekar - (cherry picked from commit c9188d333717d3ceb7e3020011651f424f749f93) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index 5f3e701fd1..1d5aa304d3 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -5167,7 +5167,7 @@ _int_memalign (mstate av, size_t alignment, size_t bytes) - INTERNAL_SIZE_T size; - - nb = checked_request2size (bytes); -- if (nb == 0) -+ if (nb == 0 || alignment > PTRDIFF_MAX) - { - __set_errno (ENOMEM); - return NULL; -@@ -5183,7 +5183,10 @@ _int_memalign (mstate av, size_t alignment, size_t bytes) - we don't find anything in those bins, the common malloc code will - scan starting at 2x. */ - -- /* Call malloc with worst case padding to hit alignment. */ -+ /* Call malloc with worst case padding to hit alignment. ALIGNMENT is a -+ power of 2, so it tops out at (PTRDIFF_MAX >> 1) + 1, leaving plenty of -+ space to add MINSIZE and whatever checked_request2size adds to BYTES to -+ get NB. Consequently, total below also does not overflow. */ - m = (char *) (_int_malloc (av, nb + alignment + MINSIZE)); - - if (m == NULL) -diff --git a/malloc/tst-malloc-too-large.c b/malloc/tst-malloc-too-large.c -index a548a37b46..a1bda673a3 100644 ---- a/malloc/tst-malloc-too-large.c -+++ b/malloc/tst-malloc-too-large.c -@@ -152,7 +152,6 @@ test_large_allocations (size_t size) - } - - --static long pagesize; - - /* This function tests the following aligned memory allocation functions - using several valid alignments and precedes each allocation test with a -@@ -171,8 +170,8 @@ test_large_aligned_allocations (size_t size) - - /* All aligned memory allocation functions expect an alignment that is a - power of 2. Given this, we test each of them with every valid -- alignment from 1 thru PAGESIZE. */ -- for (align = 1; align <= pagesize; align *= 2) -+ alignment for the type of ALIGN, i.e. until it wraps to 0. */ -+ for (align = 1; align > 0; align <<= 1) - { - test_setup (); - #if __GNUC_PREREQ (7, 0) -@@ -265,11 +264,6 @@ do_test (void) - DIAG_IGNORE_NEEDS_COMMENT (7, "-Walloc-size-larger-than="); - #endif - -- /* Aligned memory allocation functions need to be tested up to alignment -- size equivalent to page size, which should be a power of 2. */ -- pagesize = sysconf (_SC_PAGESIZE); -- TEST_VERIFY_EXIT (powerof2 (pagesize)); -- - /* Loop 1: Ensure that all allocations with SIZE close to SIZE_MAX, i.e. - in the range (SIZE_MAX - 2^14, SIZE_MAX], fail. - - -commit 453e6b8dbab935257eb0802b0c97bca6b67ba30e -Author: Carlos O'Donell -Date: Thu Jan 15 15:09:38 2026 -0500 - - resolv: Fix NSS DNS backend for getnetbyaddr (CVE-2026-0915) - - The default network value of zero for net was never tested for and - results in a DNS query constructed from uninitialized stack bytes. - The solution is to provide a default query for the case where net - is zero. - - Adding a test case for this was straight forward given the existence of - tst-resolv-network and if the test is added without the fix you observe - this failure: - - FAIL: resolv/tst-resolv-network - original exit status 1 - error: tst-resolv-network.c:174: invalid QNAME: \146\218\129\128 - error: 1 test failures - - With a random QNAME resulting from the use of uninitialized stack bytes. - - After the fix the test passes. - - Additionally verified using wireshark before and after to ensure - on-the-wire bytes for the DNS query were as expected. - - No regressions on x86_64. - - Reviewed-by: Florian Weimer - (cherry picked from commit e56ff82d5034ec66c6a78f517af6faa427f65b0b) - -diff --git a/resolv/nss_dns/dns-network.c b/resolv/nss_dns/dns-network.c -index 519f8422ca..e14e959d7c 100644 ---- a/resolv/nss_dns/dns-network.c -+++ b/resolv/nss_dns/dns-network.c -@@ -207,6 +207,10 @@ _nss_dns_getnetbyaddr_r (uint32_t net, int type, struct netent *result, - sprintf (qbuf, "%u.%u.%u.%u.in-addr.arpa", net_bytes[3], net_bytes[2], - net_bytes[1], net_bytes[0]); - break; -+ default: -+ /* Default network (net is originally zero). */ -+ strcpy (qbuf, "0.0.0.0.in-addr.arpa"); -+ break; - } - - net_buffer.buf = orig_net_buffer = (querybuf *) alloca (1024); -diff --git a/resolv/tst-resolv-network.c b/resolv/tst-resolv-network.c -index d9f69649d0..181be80835 100644 ---- a/resolv/tst-resolv-network.c -+++ b/resolv/tst-resolv-network.c -@@ -46,6 +46,9 @@ handle_code (const struct resolv_response_context *ctx, - { - switch (code) - { -+ case 0: -+ send_ptr (b, qname, qclass, qtype, "0.in-addr.arpa"); -+ break; - case 1: - send_ptr (b, qname, qclass, qtype, "1.in-addr.arpa"); - break; -@@ -265,6 +268,9 @@ do_test (void) - "error: TRY_AGAIN\n"); - - /* Lookup by address, success cases. */ -+ check_reverse (0, -+ "name: 0.in-addr.arpa\n" -+ "net: 0x00000000\n"); - check_reverse (1, - "name: 1.in-addr.arpa\n" - "net: 0x00000001\n"); - -commit cbf39c26b25801e9bc88499b4fd361ac172d4125 -Author: Adhemerval Zanella -Date: Thu Jan 15 10:32:19 2026 -0300 - - posix: Reset wordexp_t fields with WRDE_REUSE (CVE-2025-15281 / BZ 33814) - - The wordexp fails to properly initialize the input wordexp_t when - WRDE_REUSE is used. The wordexp_t struct is properly freed, but - reuses the old wc_wordc value and updates the we_wordv in the - wrong position. A later wordfree will then call free with an - invalid pointer. - - Checked on x86_64-linux-gnu and i686-linux-gnu. - - Reviewed-by: Carlos O'Donell - (cherry picked from commit 80cc58ea2de214f85b0a1d902a3b668ad2ecb302) - -diff --git a/NEWS b/NEWS -index ed3c114c7a..7e7e1930dd 100644 ---- a/NEWS -+++ b/NEWS -@@ -16,6 +16,8 @@ The following bugs were resolved with this release: - [33356] nptl: creating thread stack with guardsize 0 can erroneously - conclude MADV_GUARD_INSTALL is available - [33361] nss: Group merge does not react to ERANGE during merge -+ [33814] glob: wordexp with WRDE_REUSE and WRDE_APPEND may return -+ uninitialized memory - - Version 2.42 - -diff --git a/posix/Makefile b/posix/Makefile -index a36e5decd3..1ea86efcc1 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -327,6 +327,7 @@ tests := \ - tst-wait4 \ - tst-waitid \ - tst-wordexp-nocmd \ -+ tst-wordexp-reuse \ - tstgetopt \ - # tests - -@@ -457,6 +458,8 @@ generated += \ - tst-rxspencer-no-utf8.mtrace \ - tst-vfork3-mem.out \ - tst-vfork3.mtrace \ -+ tst-wordexp-reuse-mem.out \ -+ tst-wordexp-reuse.mtrace \ - # generated - endif - endif -@@ -492,6 +495,7 @@ tests-special += \ - $(objpfx)tst-pcre-mem.out \ - $(objpfx)tst-rxspencer-no-utf8-mem.out \ - $(objpfx)tst-vfork3-mem.out \ -+ $(objpfx)tst-wordexp-reuse.out \ - # tests-special - endif - endif -@@ -775,3 +779,10 @@ $(objpfx)posix-conf-vars-def.h: $(..)scripts/gen-posix-conf-vars.awk \ - $(make-target-directory) - $(AWK) -f $(filter-out Makefile, $^) > $@.tmp - mv -f $@.tmp $@ -+ -+tst-wordexp-reuse-ENV += MALLOC_TRACE=$(objpfx)tst-wordexp-reuse.mtrace \ -+ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so -+ -+$(objpfx)tst-wordexp-reuse-mem.out: $(objpfx)tst-wordexp-reuse.out -+ $(common-objpfx)malloc/mtrace $(objpfx)tst-wordexp-reuse.mtrace > $@; \ -+ $(evaluate-test) -diff --git a/posix/tst-wordexp-reuse.c b/posix/tst-wordexp-reuse.c -new file mode 100644 -index 0000000000..3926b9f557 ---- /dev/null -+++ b/posix/tst-wordexp-reuse.c -@@ -0,0 +1,89 @@ -+/* Test for wordexp with WRDE_REUSE flag. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+ -+#include -+ -+static int -+do_test (void) -+{ -+ mtrace (); -+ -+ { -+ wordexp_t p = { 0 }; -+ TEST_COMPARE (wordexp ("one", &p, 0), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { .we_offs = 2 }; -+ TEST_COMPARE (wordexp ("one", &p, 0), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE | WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { 0 }; -+ TEST_COMPARE (wordexp ("one", &p, 0), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE | WRDE_APPEND), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { .we_offs = 2 }; -+ TEST_COMPARE (wordexp ("one", &p, WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE -+ | WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { .we_offs = 2 }; -+ TEST_COMPARE (wordexp ("one", &p, WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE -+ | WRDE_DOOFFS | WRDE_APPEND), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "two"); -+ wordfree (&p); -+ } -+ -+ return 0; -+} -+ -+#include -diff --git a/posix/wordexp.c b/posix/wordexp.c -index a69b732801..9df4bb7424 100644 ---- a/posix/wordexp.c -+++ b/posix/wordexp.c -@@ -2216,7 +2216,9 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - { - /* Minimal implementation of WRDE_REUSE for now */ - wordfree (pwordexp); -+ old_word.we_wordc = 0; - old_word.we_wordv = NULL; -+ pwordexp->we_wordc = 0; - } - - if ((flags & WRDE_APPEND) == 0) - -commit 912d89a766847649a3857985a3b5e6065c51bfd4 -Author: Florian Weimer -Date: Thu Jan 8 12:35:08 2026 +0100 - - Switch currency symbol for the bg_BG locale to euro - - Bulgaria joined the eurozone on 2026-01-01. - - Suggested-by: Йордан Гигов - Reviewed-by: Collin Funk - (cherry picked from commit 78fdb2d6b1c34ea8e779fd48f9436dfbd50b6387) - -diff --git a/localedata/locales/bg_BG b/localedata/locales/bg_BG -index 159a6c3334..eda2a8d01b 100644 ---- a/localedata/locales/bg_BG -+++ b/localedata/locales/bg_BG -@@ -248,8 +248,8 @@ reorder-end - END LC_COLLATE - - LC_MONETARY --int_curr_symbol "BGN " --currency_symbol "лв." -+int_curr_symbol "EUR " -+currency_symbol "€" - mon_decimal_point "," - mon_thousands_sep " " - mon_grouping 3 - -commit 39897805917ab1c44dbf4452b9c4c2bbafc7117b -Author: Florian Weimer -Date: Fri Feb 13 09:02:07 2026 +0100 - - nss: Introduce dedicated struct nss_database_for_fork type - - The initialized field in struct nss_database_data is rather confusing - because it is not used by the regular NSS code, only by the fork - state synchronization code. Introduce a separate type and place - the initialized field there. - - Reviewed-by: Sam James - (cherry picked from commit 7bb859f4198d0be19c31a9937eae4f6c2c9a079e) - -diff --git a/nss/nss_database.c b/nss/nss_database.c -index a7ac32beb9..a6b7d5c956 100644 ---- a/nss/nss_database.c -+++ b/nss/nss_database.c -@@ -56,7 +56,6 @@ global_state_allocate (void *closure) - { - result->data.nsswitch_conf.size = -1; /* Force reload. */ - memset (result->data.services, 0, sizeof (result->data.services)); -- result->data.initialized = true; - result->data.reload_disabled = false; - __libc_lock_init (result->lock); - result->root_ino = 0; -@@ -451,8 +450,8 @@ nss_database_check_reload_and_get (struct nss_database_state *local, - /* Avoid overwriting the global configuration until we have loaded - everything successfully. Otherwise, if the file change - information changes back to what is in the global configuration, -- the lookups would use the partially-written configuration. */ -- struct nss_database_data staging = { .initialized = true, }; -+ the lookups would use the partially-written configuration. */ -+ struct nss_database_data staging = { }; - - bool ok = nss_database_reload (&staging, &initial); - -@@ -503,7 +502,7 @@ __nss_database_freeres (void) - } - - void --__nss_database_fork_prepare_parent (struct nss_database_data *data) -+__nss_database_fork_prepare_parent (struct nss_database_for_fork *data) - { - /* Do not use allocate_once to trigger loading unnecessarily. */ - struct nss_database_state *local = atomic_load_acquire (&global_database_state); -@@ -515,20 +514,21 @@ __nss_database_fork_prepare_parent (struct nss_database_data *data) - because it avoids acquiring the lock during the actual - fork. */ - __libc_lock_lock (local->lock); -- *data = local->data; -+ data->data = local->data; - __libc_lock_unlock (local->lock); -+ data->initialized = true; - } - } - - void --__nss_database_fork_subprocess (struct nss_database_data *data) -+__nss_database_fork_subprocess (struct nss_database_for_fork *data) - { - struct nss_database_state *local = atomic_load_acquire (&global_database_state); - if (data->initialized) - { - /* Restore the state at the point of the fork. */ - assert (local != NULL); -- local->data = *data; -+ local->data = data->data; - __libc_lock_init (local->lock); - } - else if (local != NULL) -diff --git a/nss/nss_database.h b/nss/nss_database.h -index 0eaea49685..c170da03f6 100644 ---- a/nss/nss_database.h -+++ b/nss/nss_database.h -@@ -70,15 +70,21 @@ struct nss_database_data - struct file_change_detection nsswitch_conf; - nss_action_list services[NSS_DATABASE_COUNT]; - int reload_disabled; /* Actually bool; int for atomic access. */ -- bool initialized; -+}; -+ -+/* Use to store a consistent state snapshot across fork. */ -+struct nss_database_for_fork -+{ -+ bool initialized; /* Set to true if the data field below is initialized. */ -+ struct nss_database_data data; - }; - - /* Called by fork in the parent process, before forking. */ --void __nss_database_fork_prepare_parent (struct nss_database_data *data) -+void __nss_database_fork_prepare_parent (struct nss_database_for_fork *) - attribute_hidden; - - /* Called by fork in the new subprocess, after forking. */ --void __nss_database_fork_subprocess (struct nss_database_data *data) -+void __nss_database_fork_subprocess (struct nss_database_for_fork *) - attribute_hidden; - - #endif /* _NSS_DATABASE_H */ -diff --git a/posix/fork.c b/posix/fork.c -index 011e92fc1d..7f2370f2eb 100644 ---- a/posix/fork.c -+++ b/posix/fork.c -@@ -50,7 +50,7 @@ __libc_fork (void) - - lastrun = __run_prefork_handlers (multiple_threads); - -- struct nss_database_data nss_database_data; -+ struct nss_database_for_fork nss_database_data; - - /* If we are not running multiple threads, we do not have to - preserve lock state. If fork runs from a signal handler, only - -commit 937ef7aaf3ce41038b3e12675a6298b86b389af2 -Author: Florian Weimer -Date: Fri Feb 13 09:02:07 2026 +0100 - - Linux: In getlogin_r, use utmp fallback only for specific errors - - Most importantly, if getwpuid_r fails, it does not make sense to retry - via utmp because the user ID obtained from there is less reliable than - the one from /proc/self/loginuid. - - Reviewed-by: Sam James - (cherry picked from commit 28660f4b45afa8921c2faebaec2846f95f670ba0) - -diff --git a/sysdeps/unix/sysv/linux/getlogin_r.c b/sysdeps/unix/sysv/linux/getlogin_r.c -index f03ecd4da9..0e66944570 100644 ---- a/sysdeps/unix/sysv/linux/getlogin_r.c -+++ b/sysdeps/unix/sysv/linux/getlogin_r.c -@@ -37,7 +37,12 @@ __getlogin_r_loginuid (char *name, size_t namesize) - { - int fd = __open_nocancel ("/proc/self/loginuid", O_RDONLY); - if (fd == -1) -- return -1; -+ { -+ if (errno == ENOENT) -+ /* Trigger utmp fallback. */ -+ return -1; -+ return errno; -+ } - - /* We are reading a 32-bit number. 12 bytes are enough for the text - representation. If not, something is wrong. */ -@@ -45,6 +50,8 @@ __getlogin_r_loginuid (char *name, size_t namesize) - ssize_t n = TEMP_FAILURE_RETRY (__read_nocancel (fd, uidbuf, - sizeof (uidbuf))); - __close_nocancel_nostatus (fd); -+ if (n < 0) -+ return errno; - - uid_t uid; - char *endp; -@@ -53,12 +60,13 @@ __getlogin_r_loginuid (char *name, size_t namesize) - || (uidbuf[n] = '\0', - uid = strtoul (uidbuf, &endp, 10), - endp == uidbuf || *endp != '\0')) -- return -1; -+ return EINVAL; - - /* If there is no login uid, linux sets /proc/self/loginid to the sentinel - value of, (uid_t) -1, so check if that value is set and return early to - avoid making unneeded nss lookups. */ - if (uid == (uid_t) -1) -+ /* Trigger utmp fallback. */ - return -1; - - struct passwd pwd; -@@ -78,9 +86,14 @@ __getlogin_r_loginuid (char *name, size_t namesize) - } - } - -- if (res != 0 || tpwd == NULL) -+ if (res != 0) -+ { -+ result = res; -+ goto out; -+ } -+ if (tpwd == NULL) - { -- result = -1; -+ result = ENOENT; - goto out; - } - - -commit ebd45473f5421e0fced5ba2cde0f1aaa36e79b61 -Author: Florian Weimer -Date: Fri Feb 13 09:02:07 2026 +0100 - - nss: Missing checks in __nss_configure_lookup, __nss_database_get (bug 28940) - - This avoids a null pointer dereference in the - nss_database_check_reload_and_get function, and assertion failures. - - Reviewed-by: Sam James - (cherry picked from commit 5b713b49443eb6a4e54e50e2f0147105f86dab02) - -diff --git a/nss/Makefile b/nss/Makefile -index 1991b7482a..f690c29b94 100644 ---- a/nss/Makefile -+++ b/nss/Makefile -@@ -326,6 +326,7 @@ tests := \ - tst-gshadow \ - tst-nss-getpwent \ - tst-nss-hash \ -+ tst-nss-malloc-failure-getlogin_r \ - tst-nss-test1 \ - tst-nss-test2 \ - tst-nss-test4 \ -diff --git a/nss/nss_database.c b/nss/nss_database.c -index a6b7d5c956..7aa460c7df 100644 ---- a/nss/nss_database.c -+++ b/nss/nss_database.c -@@ -250,9 +250,12 @@ __nss_configure_lookup (const char *dbname, const char *service_line) - - /* Force any load/cache/read whatever to happen, so we can override - it. */ -- __nss_database_get (db, &result); -+ if (!__nss_database_get (db, &result)) -+ return -1; - - local = nss_database_state_get (); -+ if (local == NULL) -+ return -1; - - result = __nss_action_parse (service_line); - if (result == NULL) -@@ -477,6 +480,8 @@ bool - __nss_database_get (enum nss_database db, nss_action_list *actions) - { - struct nss_database_state *local = nss_database_state_get (); -+ if (local == NULL) -+ return false; - return nss_database_check_reload_and_get (local, actions, db); - } - libc_hidden_def (__nss_database_get) -diff --git a/nss/tst-nss-malloc-failure-getlogin_r.c b/nss/tst-nss-malloc-failure-getlogin_r.c -new file mode 100644 -index 0000000000..0e2985ad57 ---- /dev/null -+++ b/nss/tst-nss-malloc-failure-getlogin_r.c -@@ -0,0 +1,345 @@ -+/* Test NSS/getlogin_r with injected allocation failures (bug 28940). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+/* This test calls getpwuid_r via getlogin_r (on Linux). -+ -+ This test uses the NSS system configuration to exercise that code -+ path. It means that it can fail (crash) if malloc failure is not -+ handled by NSS modules for the passwd database. */ -+ -+/* Data structure allocated via MAP_SHARED, so that writes from the -+ subprocess are visible. */ -+struct shared_data -+{ -+ /* Number of tracked allocations performed so far. */ -+ volatile unsigned int allocation_count; -+ -+ /* If this number is reached, one allocation fails. */ -+ volatile unsigned int failing_allocation; -+ -+ /* The number of allocations performed during initialization -+ (before the actual getlogin_r call). */ -+ volatile unsigned int init_allocation_count; -+ -+ /* Error code of an expected getlogin_r failure. */ -+ volatile int expected_failure; -+ -+ /* The subprocess stores the expected name here. */ -+ char name[100]; -+}; -+ -+/* Allocation count in shared mapping. */ -+static struct shared_data *shared; -+ -+/* Returns true if a failure should be injected for this allocation. */ -+static bool -+fail_this_allocation (void) -+{ -+ if (shared != NULL) -+ { -+ unsigned int count = shared->allocation_count; -+ shared->allocation_count = count + 1; -+ return count == shared->failing_allocation; -+ } -+ else -+ return false; -+} -+ -+/* Failure-injecting wrappers for allocation functions used by glibc. */ -+ -+void * -+malloc (size_t size) -+{ -+ if (fail_this_allocation ()) -+ { -+ errno = ENOMEM; -+ return NULL; -+ } -+ extern __typeof (malloc) __libc_malloc; -+ return __libc_malloc (size); -+} -+ -+void * -+calloc (size_t a, size_t b) -+{ -+ if (fail_this_allocation ()) -+ { -+ errno = ENOMEM; -+ return NULL; -+ } -+ extern __typeof (calloc) __libc_calloc; -+ return __libc_calloc (a, b); -+} -+ -+void * -+realloc (void *ptr, size_t size) -+{ -+ if (fail_this_allocation ()) -+ { -+ errno = ENOMEM; -+ return NULL; -+ } -+ extern __typeof (realloc) __libc_realloc; -+ return __libc_realloc (ptr, size); -+} -+ -+/* No-op subprocess to verify that support_isolate_in_subprocess does -+ not perform any heap allocations. */ -+static void -+no_op (void *ignored) -+{ -+} -+ -+/* Perform a getlogin_r call in a subprocess, to obtain the number of -+ allocations used and the expected result of a successful call. */ -+static void -+initialize (void *configure_lookup) -+{ -+ shared->init_allocation_count = 0; -+ if (configure_lookup != NULL) -+ { -+ TEST_COMPARE (__nss_configure_lookup ("passwd", configure_lookup), 0); -+ shared->init_allocation_count = shared->allocation_count; -+ } -+ -+ shared->name[0] = '\0'; -+ int ret = getlogin_r (shared->name, sizeof (shared->name)); -+ if (ret != 0) -+ { -+ printf ("info: getlogin_r failed: %s (%d)\n", -+ strerrorname_np (ret), ret); -+ shared->expected_failure = ret; -+ } -+ else -+ { -+ shared->expected_failure = 0; -+ if (shared->name[0] == '\0') -+ FAIL ("error: getlogin_r succeeded without result\n"); -+ else -+ printf ("info: getlogin_r: \"%s\"\n", shared->name); -+ } -+} -+ -+/* Perform getlogin_r in a subprocess with fault injection. */ -+static void -+test_in_subprocess (void *configure_lookup) -+{ -+ if (configure_lookup != NULL -+ && __nss_configure_lookup ("passwd", configure_lookup) < 0) -+ { -+ printf ("info: __nss_configure_lookup failed: %s (%d)\n", -+ strerrorname_np (errno), errno); -+ TEST_COMPARE (errno, ENOMEM); -+ TEST_VERIFY (shared->allocation_count <= shared->init_allocation_count); -+ return; -+ } -+ -+ unsigned int inject_at = shared->failing_allocation; -+ char name[sizeof (shared->name)] = "name not set"; -+ int ret = getlogin_r (name, sizeof (name)); -+ shared->failing_allocation = ~0U; -+ -+ if (ret == 0) -+ { -+ TEST_COMPARE (shared->expected_failure, 0); -+ TEST_COMPARE_STRING (name, shared->name); -+ } -+ else -+ { -+ printf ("info: allocation %u failure results in error %s (%d)\n", -+ inject_at, strerrorname_np (ret), ret); -+ -+ if (ret != ENOMEM) -+ { -+ if (shared->expected_failure != 0) -+ TEST_COMPARE (ret, shared->expected_failure); -+ else if (configure_lookup == NULL) -+ /* The ENOENT failure can happen due to an issue related -+ to bug 22041: dlopen failure does not result in ENOMEM. */ -+ TEST_COMPARE (ret, ENOENT); -+ else -+ FAIL ("unexpected getlogin_r error"); -+ } -+ } -+ -+ if (shared->expected_failure == 0) -+ { -+ /* The second call should succeed. */ -+ puts ("info: about to perform second getlogin_r call"); -+ ret = getlogin_r (name, sizeof (name)); -+ if (configure_lookup == NULL) -+ { -+ /* This check can fail due to bug 22041 if the malloc error -+ injection causes a failure internally in dlopen. */ -+ if (ret != 0) -+ { -+ printf ("warning: second getlogin_r call failed with %s (%d)\n", -+ strerrorname_np (ret), ret); -+ TEST_COMPARE (ret, ENOENT); -+ } -+ } -+ else -+ /* If __nss_configure_lookup has been called, the error caching -+ bug does not happen because nss_files is built-in, and the -+ second getlogin_r is expected to succeed. */ -+ TEST_COMPARE (ret, 0); -+ if (ret == 0) -+ TEST_COMPARE_STRING (name, shared->name); -+ } -+} -+ -+/* Set by the --failing-allocation command line option. Together with -+ --direct, this can be used to trigger an allocation failure in the -+ original process, which may help with debugging. */ -+static int option_failing_allocation = -1; -+ -+/* Set by --override, to be used with --failing-allocation. Turns on -+ the __nss_configure_lookup call for passwd/files, which is disabled -+ by default. */ -+static int option_override = 0; -+ -+static int -+do_test (void) -+{ -+ char files[] = "files"; -+ -+ if (option_failing_allocation >= 0) -+ { -+ /* The test was invoked with --failing-allocation. Perform just -+ one test, using the original nsswitch.conf. This is a -+ condensed version of the probing/testing loop below. */ -+ printf ("info: testing with failing allocation %d\n", -+ option_failing_allocation); -+ shared = support_shared_allocate (sizeof (*shared)); -+ shared->failing_allocation = ~0U; -+ char *configure_lookup = option_override ? files : NULL; -+ support_isolate_in_subprocess (initialize, configure_lookup); -+ shared->allocation_count = 0; -+ shared->failing_allocation = option_failing_allocation; -+ test_in_subprocess (configure_lookup); /* No subprocess. */ -+ support_shared_free (shared); -+ shared = NULL; -+ return 0; -+ } -+ -+ bool any_success = false; -+ -+ for (int do_configure_lookup = 0; do_configure_lookup < 2; -+ ++do_configure_lookup) -+ { -+ if (do_configure_lookup) -+ puts ("info: testing with nsswitch.conf override"); -+ else -+ puts ("info: testing with original nsswitch.conf"); -+ -+ char *configure_lookup = do_configure_lookup ? files : NULL; -+ -+ shared = support_shared_allocate (sizeof (*shared)); -+ -+ /* Disable fault injection. */ -+ shared->failing_allocation = ~0U; -+ -+ support_isolate_in_subprocess (no_op, NULL); -+ TEST_COMPARE (shared->allocation_count, 0); -+ -+ support_isolate_in_subprocess (initialize, configure_lookup); -+ -+ if (shared->name[0] != '\0') -+ any_success = true; -+ -+ /* The number of allocations in the successful case. Once the -+ number of expected allocations is exceeded, injecting further -+ failures does not make a difference (assuming that the number -+ of malloc calls is deterministic). */ -+ unsigned int maximum_allocation_count = shared->allocation_count; -+ printf ("info: initial getlogin_r performed %u allocations\n", -+ maximum_allocation_count); -+ -+ for (unsigned int inject_at = 0; inject_at <= maximum_allocation_count; -+ ++inject_at) -+ { -+ printf ("info: running fault injection at allocation %u\n", -+ inject_at); -+ shared->allocation_count = 0; -+ shared->failing_allocation = inject_at; -+ support_isolate_in_subprocess (test_in_subprocess, configure_lookup); -+ } -+ -+ support_shared_free (shared); -+ shared = NULL; -+ } -+ -+ { -+ FILE *fp = fopen (_PATH_NSSWITCH_CONF, "r"); -+ if (fp == NULL) -+ printf ("info: no %s file\n", _PATH_NSSWITCH_CONF); -+ else -+ { -+ printf ("info: %s contents follows\n", _PATH_NSSWITCH_CONF); -+ int last_ch = '\n'; -+ while (true) -+ { -+ int ch = fgetc (fp); -+ if (ch == EOF) -+ break; -+ putchar (ch); -+ last_ch = ch; -+ } -+ if (last_ch != '\n') -+ putchar ('\n'); -+ printf ("(end of %s contents)\n", _PATH_NSSWITCH_CONF); -+ xfclose (fp); -+ } -+ } -+ -+ support_record_failure_barrier (); -+ -+ if (!any_success) -+ FAIL_UNSUPPORTED ("no successful getlogin_r calls"); -+ -+ return 0; -+} -+ -+static void -+cmdline_process (int c) -+{ -+ if (c == 'F') -+ option_failing_allocation = atoi (optarg); -+} -+ -+#define CMDLINE_OPTIONS \ -+ { "failing-allocation", required_argument, NULL, 'F' }, \ -+ { "override", no_argument, &option_override, 1 }, -+ -+#define CMDLINE_PROCESS cmdline_process -+ -+#include - -commit 9cd9c9054409d192aab06bfea32624af9ffa8121 -Author: Florian Weimer -Date: Fri Nov 28 11:46:09 2025 +0100 - - iconvdata: Fix invalid pointer arithmetic in ANSI_X3.110 module - - The expression inptr + 1 can technically be invalid: if inptr == inend, - inptr may point one element past the end of an array. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit e98bd0c54d5e296ad1be91b6fe35260c6b87e733) - -diff --git a/iconvdata/ansi_x3.110.c b/iconvdata/ansi_x3.110.c -index c5506b13b8..94e6e6b745 100644 ---- a/iconvdata/ansi_x3.110.c -+++ b/iconvdata/ansi_x3.110.c -@@ -407,7 +407,7 @@ static const char from_ucs4[][2] = - is also available. */ \ - uint32_t ch2; \ - \ -- if (inptr + 1 >= inend) \ -+ if (inend - inptr <= 1) \ - { \ - /* The second character is not available. */ \ - result = __GCONV_INCOMPLETE_INPUT; \ - -commit 1a19d5a507eb82a2cf1cf8bd1c14ca1758fb8a82 -Author: Florian Weimer -Date: Mon Jan 26 17:12:37 2026 +0100 - - posix: Run tst-wordexp-reuse-mem test - - The test was not properly scheduled for execution with a Makefile - dependency. - - Fixes commit 80cc58ea2de214f85b0a1d902a3b668ad2ecb302 ("posix: Reset - wordexp_t fields with WRDE_REUSE (CVE-2025-15281 / BZ 33814"). - - (cherry picked from commit bed2db02f3183e93f21d506786c5f884a1dec9e7) - -diff --git a/posix/Makefile b/posix/Makefile -index 1ea86efcc1..0b29c9aa4e 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -495,7 +495,7 @@ tests-special += \ - $(objpfx)tst-pcre-mem.out \ - $(objpfx)tst-rxspencer-no-utf8-mem.out \ - $(objpfx)tst-vfork3-mem.out \ -- $(objpfx)tst-wordexp-reuse.out \ -+ $(objpfx)tst-wordexp-reuse-mem.out \ - # tests-special - endif - endif - -commit 8e863fb1c92360520704a69dc948be6bb4a17cb3 -Author: Carlos O'Donell -Date: Fri Mar 20 16:43:33 2026 -0400 - - resolv: Count records correctly (CVE-2026-4437) - - The answer section boundary was previously ignored, and the code in - getanswer_ptr would iterate past the last resource record, but not - beyond the end of the returned data. This could lead to subsequent data - being interpreted as answer records, thus violating the DNS - specification. Such resource records could be maliciously crafted and - hidden from other tooling, but processed by the glibc stub resolver and - acted upon by the application. While we trust the data returned by the - configured recursive resolvers, we should not trust its format and - should validate it as required. It is a security issue to incorrectly - process the DNS protocol. - - A regression test is added for response section crossing. - - No regressions on x86_64-linux-gnu. - - Reviewed-by: Collin Funk - (cherry picked from commit 9f5f18aab40ec6b61fa49a007615e6077e9a979b) - -diff --git a/resolv/Makefile b/resolv/Makefile -index 8fa3398d76..0ba5fba710 100644 ---- a/resolv/Makefile -+++ b/resolv/Makefile -@@ -104,6 +104,7 @@ tests += \ - tst-resolv-basic \ - tst-resolv-binary \ - tst-resolv-byaddr \ -+ tst-resolv-dns-section \ - tst-resolv-edns \ - tst-resolv-invalid-cname \ - tst-resolv-network \ -@@ -115,6 +116,7 @@ tests += \ - tst-resolv-semi-failure \ - tst-resolv-short-response \ - tst-resolv-trailing \ -+ # tests - - # This test calls __res_context_send directly, which is not exported - # from libresolv. -@@ -293,6 +295,8 @@ $(objpfx)tst-resolv-aliases: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-basic: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-binary: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-byaddr: $(objpfx)libresolv.so $(shared-thread-library) -+$(objpfx)tst-resolv-dns-section: $(objpfx)libresolv.so \ -+ $(shared-thread-library) - $(objpfx)tst-resolv-edns: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-network: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-res_init: $(objpfx)libresolv.so -diff --git a/resolv/nss_dns/dns-host.c b/resolv/nss_dns/dns-host.c -index 14da73ee1d..27096edad2 100644 ---- a/resolv/nss_dns/dns-host.c -+++ b/resolv/nss_dns/dns-host.c -@@ -820,7 +820,7 @@ getanswer_ptr (unsigned char *packet, size_t packetlen, - /* expected_name may be updated to point into this buffer. */ - unsigned char name_buffer[NS_MAXCDNAME]; - -- while (ancount > 0) -+ for (; ancount > 0; --ancount) - { - struct ns_rr_wire rr; - if (!__ns_rr_cursor_next (&c, &rr)) -diff --git a/resolv/tst-resolv-dns-section.c b/resolv/tst-resolv-dns-section.c -new file mode 100644 -index 0000000000..1171baef51 ---- /dev/null -+++ b/resolv/tst-resolv-dns-section.c -@@ -0,0 +1,162 @@ -+/* Test handling of invalid section transitions (bug 34014). -+ Copyright (C) 2022-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+/* Name of test, and the second section type. */ -+struct item { -+ const char *test; -+ int ns_section; -+}; -+ -+static const struct item test_items[] = -+ { -+ { "Test crossing from ns_s_an to ns_s_ar.", ns_s_ar }, -+ { "Test crossing from ns_s_an to ns_s_an.", ns_s_ns }, -+ -+ { NULL, 0 }, -+ }; -+ -+/* The response is designed to contain the following: -+ - An Answer section with one T_PTR record that is skipped. -+ - A second section with a semantically invalid T_PTR record. -+ The original defect is that the response parsing would cross -+ section boundaries and handle the additional section T_PTR -+ as if it were an answer. A conforming implementation would -+ stop as soon as it reaches the end of the section. */ -+static void -+response (const struct resolv_response_context *ctx, -+ struct resolv_response_builder *b, -+ const char *qname, uint16_t qclass, uint16_t qtype) -+{ -+ TEST_COMPARE (qclass, C_IN); -+ -+ /* We only test PTR. */ -+ TEST_COMPARE (qtype, T_PTR); -+ -+ unsigned int count; -+ char *tail = NULL; -+ -+ if (strstr (qname, "in-addr.arpa") != NULL -+ && sscanf (qname, "%u.%ms", &count, &tail) == 2) -+ TEST_COMPARE_STRING (tail, "0.168.192.in-addr.arpa"); -+ else if (sscanf (qname, "%x.%ms", &count, &tail) == 2) -+ { -+ TEST_COMPARE_STRING (tail, "\ -+0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa"); -+ } -+ else -+ FAIL_EXIT1 ("invalid QNAME: %s\n", qname); -+ free (tail); -+ -+ /* We have a bounded number of possible tests. */ -+ TEST_VERIFY (count >= 0); -+ TEST_VERIFY (count <= 15); -+ -+ struct resolv_response_flags flags = {}; -+ resolv_response_init (b, flags); -+ resolv_response_add_question (b, qname, qclass, qtype); -+ resolv_response_section (b, ns_s_an); -+ -+ /* Actual answer record, but the wrong name (skipped). */ -+ resolv_response_open_record (b, "1.0.0.10.in-addr.arpa", qclass, qtype, 60); -+ -+ /* Record the answer. */ -+ resolv_response_add_name (b, "test.ptr.example.net"); -+ resolv_response_close_record (b); -+ -+ /* Add a second section to test section boundary crossing. */ -+ resolv_response_section (b, test_items[count].ns_section); -+ /* Semantically incorrect, but hide a T_PTR entry. */ -+ resolv_response_open_record (b, qname, qclass, qtype, 60); -+ resolv_response_add_name (b, "wrong.ptr.example.net"); -+ resolv_response_close_record (b); -+} -+ -+ -+/* Perform one check using a reverse lookup. */ -+static void -+check_reverse (int af, int count) -+{ -+ TEST_VERIFY (af == AF_INET || af == AF_INET6); -+ TEST_VERIFY (count < array_length (test_items)); -+ -+ char addr[sizeof (struct in6_addr)] = { 0 }; -+ socklen_t addrlen; -+ if (af == AF_INET) -+ { -+ addr[0] = (char) 192; -+ addr[1] = (char) 168; -+ addr[2] = (char) 0; -+ addr[3] = (char) count; -+ addrlen = 4; -+ } -+ else -+ { -+ addr[0] = 0x20; -+ addr[1] = 0x01; -+ addr[2] = 0x0d; -+ addr[3] = 0xb8; -+ addr[4] = addr[5] = addr[6] = addr[7] = 0x0; -+ addr[8] = addr[9] = addr[10] = addr[11] = 0x0; -+ addr[12] = 0x0; -+ addr[13] = 0x0; -+ addr[14] = 0x0; -+ addr[15] = count; -+ addrlen = 16; -+ } -+ -+ h_errno = 0; -+ struct hostent *answer = gethostbyaddr (addr, addrlen, af); -+ TEST_VERIFY (answer == NULL); -+ TEST_VERIFY (h_errno == NO_RECOVERY); -+ if (answer != NULL) -+ printf ("error: unexpected success: %s\n", -+ support_format_hostent (answer)); -+} -+ -+static int -+do_test (void) -+{ -+ struct resolv_test *obj = resolv_test_start -+ ((struct resolv_redirect_config) -+ { -+ .response_callback = response -+ }); -+ -+ for (int i = 0; test_items[i].test != NULL; i++) -+ { -+ check_reverse (AF_INET, i); -+ check_reverse (AF_INET6, i); -+ } -+ -+ resolv_test_end (obj); -+ -+ return 0; -+} -+ -+#include - -commit 426378547e6ddead92f28f5558a124eb0821d2f9 -Author: Carlos O'Donell -Date: Fri Mar 20 17:14:33 2026 -0400 - - resolv: Check hostname for validity (CVE-2026-4438) - - The processed hostname in getanswer_ptr should be correctly checked to - avoid invalid characters from being allowed, including shell - metacharacters. It is a security issue to fail to check the returned - hostname for validity. - - A regression test is added for invalid metacharacters and other cases - of invalid or valid characters. - - No regressions on x86_64-linux-gnu. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit e10977481f4db4b2a3ce34fa4c3a1e26651ae312) - -diff --git a/resolv/Makefile b/resolv/Makefile -index 0ba5fba710..088a22ea18 100644 ---- a/resolv/Makefile -+++ b/resolv/Makefile -@@ -107,6 +107,7 @@ tests += \ - tst-resolv-dns-section \ - tst-resolv-edns \ - tst-resolv-invalid-cname \ -+ tst-resolv-invalid-ptr \ - tst-resolv-network \ - tst-resolv-noaaaa \ - tst-resolv-noaaaa-vc \ -@@ -306,6 +307,8 @@ $(objpfx)tst-resolv-res_init-thread: $(objpfx)libresolv.so \ - $(shared-thread-library) - $(objpfx)tst-resolv-invalid-cname: $(objpfx)libresolv.so \ - $(shared-thread-library) -+$(objpfx)tst-resolv-invalid-ptr: $(objpfx)libresolv.so \ -+ $(shared-thread-library) - $(objpfx)tst-resolv-noaaaa: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-noaaaa-vc: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-nondecimal: $(objpfx)libresolv.so $(shared-thread-library) -diff --git a/resolv/nss_dns/dns-host.c b/resolv/nss_dns/dns-host.c -index 27096edad2..1bc2e1df95 100644 ---- a/resolv/nss_dns/dns-host.c -+++ b/resolv/nss_dns/dns-host.c -@@ -866,7 +866,7 @@ getanswer_ptr (unsigned char *packet, size_t packetlen, - char hname[MAXHOSTNAMELEN + 1]; - if (__ns_name_unpack (c.begin, c.end, rr.rdata, - name_buffer, sizeof (name_buffer)) < 0 -- || !__res_binary_hnok (expected_name) -+ || !__res_binary_hnok (name_buffer) - || __ns_name_ntop (name_buffer, hname, sizeof (hname)) < 0) - { - *h_errnop = NO_RECOVERY; -diff --git a/resolv/tst-resolv-invalid-ptr.c b/resolv/tst-resolv-invalid-ptr.c -new file mode 100644 -index 0000000000..0c802ab967 ---- /dev/null -+++ b/resolv/tst-resolv-invalid-ptr.c -@@ -0,0 +1,255 @@ -+/* Test handling of invalid T_PTR results (bug 34015). -+ Copyright (C) 2022-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+/* Name of test, the answer, the expected error return, and if we -+ expect the call to fail. */ -+struct item { -+ const char *test; -+ const char *answer; -+ int expected; -+ bool fail; -+}; -+ -+static const struct item test_items[] = -+ { -+ /* Test for invalid characters. */ -+ { "Invalid use of \"|\"", -+ "test.|.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"&\"", -+ "test.&.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \";\"", -+ "test.;.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"<\"", -+ "test.<.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \">\"", -+ "test.>.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"(\"", -+ "test.(.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \")\"", -+ "test.).ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"$\"", -+ "test.$.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"`\"", -+ "test.`.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\\"", -+ "test.\\.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\'\"", -+ "test.'.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\"\"", -+ "test.\".ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \" \"", -+ "test. .ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\t\"", -+ "test.\t.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\n\"", -+ "test.\n.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\r\"", -+ "test.\r.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"*\"", -+ "test.*.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"?\"", -+ "test.?.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"[\"", -+ "test.[.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"]\"", -+ "test.].ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \",\"", -+ "test.,.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"~\"", -+ "test.~.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \":\"", -+ "test.:.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"!\"", -+ "test.!.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"@\"", -+ "test.@.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"#\"", -+ "test.#.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"%\"", -+ "test.%%.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"^\"", -+ "test.^.ptr.example", NO_RECOVERY, true }, -+ -+ /* Test for invalid UTF-8 characters (2-byte, 4-byte, 6-byte). */ -+ { "Invalid use of UTF-8 (2-byte, U+00C0-U+00C2)", -+ "ÁÂÃ.test.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of UTF-8 (4-byte, U+0750-U+0752)", -+ "ݐݑݒ.test.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of UTF-8 (6-byte, U+0904-U+0906)", -+ "ऄअआ.test.ptr.example", NO_RECOVERY, true }, -+ -+ /* Test for "-" which may be valid depending on position. */ -+ { "Invalid leading \"-\"", -+ "-test.ptr.example", NO_RECOVERY, true }, -+ { "Valid trailing \"-\"", -+ "test-.ptr.example", 0, false }, -+ { "Valid mid-label use of \"-\"", -+ "te-st.ptr.example", 0, false }, -+ -+ /* Test for "_" which is always valid in any position. */ -+ { "Valid leading use of \"_\"", -+ "_test.ptr.example", 0, false }, -+ { "Valid mid-label use of \"_\"", -+ "te_st.ptr.example", 0, false }, -+ { "Valid trailing use of \"_\"", -+ "test_.ptr.example", 0, false }, -+ -+ /* Sanity test the broader set [A-Za-z0-9_-] of valid characters. */ -+ { "Valid \"[A-Z]\"", -+ "test.ABCDEFGHIJKLMNOPQRSTUVWXYZ.ptr.example", 0, false }, -+ { "Valid \"[a-z]\"", -+ "test.abcdefghijklmnopqrstuvwxyz.ptr.example", 0, false }, -+ { "Valid \"[0-9]\"", -+ "test.0123456789.ptr.example", 0, false }, -+ { "Valid mixed use of \"[A-Za-z0-9_-]\"", -+ "test.012abcABZ_-.ptr.example", 0, false }, -+ }; -+ -+static void -+response (const struct resolv_response_context *ctx, -+ struct resolv_response_builder *b, -+ const char *qname, uint16_t qclass, uint16_t qtype) -+{ -+ TEST_COMPARE (qclass, C_IN); -+ -+ /* We only test PTR. */ -+ TEST_COMPARE (qtype, T_PTR); -+ -+ unsigned int count, count1; -+ char *tail = NULL; -+ -+ /* The test implementation can handle up to 255 tests. */ -+ if (strstr (qname, "in-addr.arpa") != NULL -+ && sscanf (qname, "%u.%ms", &count, &tail) == 2) -+ TEST_COMPARE_STRING (tail, "0.168.192.in-addr.arpa"); -+ else if (sscanf (qname, "%x.%x.%ms", &count, &count1, &tail) == 3) -+ { -+ TEST_COMPARE_STRING (tail, "\ -+0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa"); -+ count |= count1 << 4; -+ } -+ else -+ FAIL_EXIT1 ("invalid QNAME: %s\n", qname); -+ free (tail); -+ -+ /* Cross check. Count has a fixed bound (soft limit). */ -+ TEST_VERIFY (count >= 0 && count <= 255); -+ -+ /* We have a fixed number of tests (hard limit). */ -+ TEST_VERIFY_EXIT (count < array_length (test_items)); -+ -+ struct resolv_response_flags flags = {}; -+ resolv_response_init (b, flags); -+ resolv_response_add_question (b, qname, qclass, qtype); -+ resolv_response_section (b, ns_s_an); -+ -+ /* Actual answer record. */ -+ resolv_response_open_record (b, qname, qclass, qtype, 60); -+ -+ /* Record the answer. */ -+ resolv_response_add_name (b, test_items[count].answer); -+ resolv_response_close_record (b); -+} -+ -+/* Perform one check using a reverse lookup. */ -+static void -+check_reverse (int af, int count) -+{ -+ TEST_VERIFY (af == AF_INET || af == AF_INET6); -+ TEST_VERIFY_EXIT (count < array_length (test_items)); -+ -+ /* Generate an address to query for each test. */ -+ char addr[sizeof (struct in6_addr)] = { 0 }; -+ socklen_t addrlen; -+ if (af == AF_INET) -+ { -+ addr[0] = (char) 192; -+ addr[1] = (char) 168; -+ addr[2] = (char) 0; -+ addr[3] = (char) count; -+ addrlen = 4; -+ } -+ else -+ { -+ addr[0] = 0x20; -+ addr[1] = 0x01; -+ addr[2] = 0x0d; -+ addr[3] = 0xb8; -+ addr[4] = addr[5] = addr[6] = addr[7] = 0x0; -+ addr[8] = addr[9] = addr[10] = addr[11] = 0x0; -+ addr[12] = 0x0; -+ addr[13] = 0x0; -+ addr[14] = 0x0; -+ addr[15] = (char) count; -+ addrlen = 16; -+ } -+ -+ h_errno = 0; -+ struct hostent *answer = gethostbyaddr (addr, addrlen, af); -+ -+ /* Verify h_errno is as expected. */ -+ TEST_COMPARE (h_errno, test_items[count].expected); -+ if (h_errno != test_items[count].expected) -+ /* And print more information if it's not. */ -+ printf ("INFO: %s\n", test_items[count].test); -+ -+ if (test_items[count].fail) -+ { -+ /* We expected a failure so verify answer is NULL. */ -+ TEST_VERIFY (answer == NULL); -+ /* If it's not NULL we should print out what we received. */ -+ if (answer != NULL) -+ printf ("error: unexpected success: %s\n", -+ support_format_hostent (answer)); -+ } -+ else -+ /* We don't expect a failure so answer must be valid. */ -+ TEST_COMPARE_STRING (answer->h_name, test_items[count].answer); -+} -+ -+static int -+do_test (void) -+{ -+ struct resolv_test *obj = resolv_test_start -+ ((struct resolv_redirect_config) -+ { -+ .response_callback = response -+ }); -+ -+ for (int i = 0; i < array_length (test_items); i++) -+ { -+ check_reverse (AF_INET, i); -+ check_reverse (AF_INET6, i); -+ } -+ resolv_test_end (obj); -+ -+ return 0; -+} -+ -+#include - -commit 68099ccc941664481386c62cba40bbc5dac8b00e -Author: Xi Ruoyao -Date: Tue Feb 3 16:20:12 2026 +0800 - - elf: parse /proc/self/maps as the last resort to find the gap for tst-link-map-contiguous-ldso - - The initialization process of libc.so calls mmap() several times and the - kernel may lay the maps into the gap. If all pages in the gap are - occupied, the test would not be able to find the gap with mmap() and the - test would fail. - - The failure reproduces most frequently on LoongArch because with the - commonly used page size (16 KiB) the gap only contains 4 pages and the - probability they are all occupied is not near to zero. - - With the changes in the patch, a test run may output: - - info: ld.so link map is not contiguous - info: object "/dev/zero" found at 0x7ffff1fe0000 - 0x7ffff1fe4000 - info: anonymous mapping found at 0x7ffff1fe4000 - 0x7ffff1fec000 - - Also take the chance to fix a mistake in the "object found at" message - which has puzzled me during the initial debug session. - - Signed-off-by: Xi Ruoyao - Reviewed-by: Adhemerval Zanella - (cherry picked from commit aed8390a6a22e5751fc12704c0c5f2a8271fc286) - -diff --git a/elf/tst-link-map-contiguous-ldso.c b/elf/tst-link-map-contiguous-ldso.c -index 04de808bb2..f0e26682f2 100644 ---- a/elf/tst-link-map-contiguous-ldso.c -+++ b/elf/tst-link-map-contiguous-ldso.c -@@ -18,15 +18,73 @@ - - #include - #include -+#include - #include - #include - #include - #include -+#include - #include - #include -+#include - #include - #include - -+/* Slow path in case we cannot find a gap with mmap (when the runtime has -+ mapped all the pages in the gap for some reason). */ -+static bool -+find_gap_with_proc_self_map (const struct link_map *l) -+{ -+ int pagesize = getpagesize (); -+ -+ support_need_proc ("Reads /proc/self/maps to find gap in ld.so mapping"); -+ -+ /* Parse /proc/self/maps and find all the mappings in the ld.so range -+ but not from ld.so. */ -+ FILE *f = xfopen ("/proc/self/maps", "r"); -+ char *line = NULL, *path_ldso = NULL; -+ size_t len; -+ bool found = false; -+ while (xgetline (&line, &len, f)) -+ { -+ uintptr_t from, to; -+ char *path = NULL; -+ int r = sscanf (line, "%" SCNxPTR "-%" SCNxPTR "%*s%*s%*s%*s%ms", -+ &from, &to, &path); -+ -+ TEST_VERIFY (r == 2 || r == 3); -+ TEST_COMPARE (from % pagesize, 0); -+ TEST_COMPARE (to % pagesize, 0); -+ -+ if (path_ldso == NULL && l->l_map_start == from) -+ { -+ TEST_COMPARE (r, 3); -+ path_ldso = path; -+ continue; -+ } -+ -+ if (from > l->l_map_start && to < l->l_map_end -+ && (r == 2 || (path_ldso != NULL && strcmp (path, path_ldso)))) -+ { -+ if (r == 2) -+ printf ("info: anonymous mapping found at 0x%" PRIxPTR " - 0x%" -+ PRIxPTR "\n", from, to); -+ else -+ printf ("info: object \"%s\" found at 0x%" PRIxPTR " - 0x%" -+ PRIxPTR "\n", path, from, to); -+ -+ found = true; -+ } -+ -+ free (path); -+ } -+ -+ free (path_ldso); -+ free (line); -+ xfclose (f); -+ return found; -+} -+ - static int - do_test (void) - { -@@ -64,16 +122,18 @@ do_test (void) - if ((void *) dlfo.dlfo_link_map != (void *) l) - { - printf ("info: object \"%s\" found at %p\n", -- dlfo.dlfo_link_map->l_name, ptr); -+ dlfo.dlfo_link_map->l_name, expected); - gap_found = true; - } - } - else - TEST_COMPARE (dlfo_ret, -1); -+ - xmunmap (ptr, 1); - addr += pagesize; - } -- if (!gap_found) -+ -+ if (!gap_found && !find_gap_with_proc_self_map (l)) - FAIL ("no ld.so gap found"); - } - else - -commit a56a2943d2ce541102c630142c2eae0fbfc5886b -Author: Michael Jeanson -Date: Fri Feb 20 11:01:00 2026 -0500 - - tests: fix tst-rseq with Linux 7.0 - - A sub-test of tst-rseq is to validate the return code and errno of the - rseq syscall when attempting to register the exact same rseq area as was - done in the dynamic loader. - - This involves finding the rseq area address by adding the - '__rseq_offset' to the thread pointer and calculating the area size from - the AT_RSEQ_FEATURE_SIZE auxiliary vector. However the test currently - calculates the size of the rseq area allocation in the TLS block which - must be a multiple of AT_RSEQ_ALIGN. - - Up until now that happened to be the same value since the feature size - and alignment exposed by the kernel were below the minimum ABI size of - 32. Starting with Linux 7.0 the feature size has reached 33 while the - alignment is now 64. - - This results in the test trying to re-register the rseq area with a - different size and thus not getting the expected errno value. - - Signed-off-by: Michael Jeanson - Reviewed-by: Mathieu Desnoyers - (cherry picked from commit 67f303b47dc584f204e3f2441b9832082415eebc) - -diff --git a/sysdeps/unix/sysv/linux/tst-rseq.c b/sysdeps/unix/sysv/linux/tst-rseq.c -index 00181cfefb..e83ea2b939 100644 ---- a/sysdeps/unix/sysv/linux/tst-rseq.c -+++ b/sysdeps/unix/sysv/linux/tst-rseq.c -@@ -48,8 +48,7 @@ do_rseq_main_test (void) - size_t rseq_align = MAX (getauxval (AT_RSEQ_ALIGN), RSEQ_MIN_ALIGN); - size_t rseq_feature_size = MAX (getauxval (AT_RSEQ_FEATURE_SIZE), - RSEQ_AREA_SIZE_INITIAL_USED); -- size_t rseq_alloc_size = roundup (MAX (rseq_feature_size, -- RSEQ_AREA_SIZE_INITIAL_USED), rseq_align); -+ size_t rseq_reg_size = MAX (rseq_feature_size, RSEQ_AREA_SIZE_INITIAL); - struct rseq *rseq_abi = __thread_pointer () + __rseq_offset; - - TEST_VERIFY_EXIT (rseq_thread_registered ()); -@@ -89,8 +88,8 @@ do_rseq_main_test (void) - /* Test a rseq registration with the same arguments as the internal - registration which should fail with errno == EBUSY. */ - TEST_VERIFY (((unsigned long) rseq_abi % rseq_align) == 0); -- TEST_VERIFY (__rseq_size <= rseq_alloc_size); -- int ret = syscall (__NR_rseq, rseq_abi, rseq_alloc_size, 0, RSEQ_SIG); -+ TEST_VERIFY (__rseq_size <= rseq_reg_size); -+ int ret = syscall (__NR_rseq, rseq_abi, rseq_reg_size, 0, RSEQ_SIG); - TEST_VERIFY (ret != 0); - TEST_COMPARE (errno, EBUSY); - } - -commit f13c1bb0f97fbc12a6ba1ab5669ce561ea32b80a -Author: Florian Weimer -Date: Thu Apr 16 19:13:43 2026 +0200 - - Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046) - - Follow the example in iso-2022-jp-3.c and use the __count state - variable to store the pending character. This avoids restarting - the conversion if the output buffer ends between two 4-byte UCS-4 - code points, so that the assert reported in the bug can no longer - happen. - - Even though the fix is applied to ibm1364.c, the change is only - effective for the two HAS_COMBINED codecs for IBM1390, IBM1399. - - The test case was mostly auto-generated using - claude-4.6-opus-high-thinking, and composer-2-fast shows up in the - log as well. During review, gpt-5.4-xhigh flagged that the original - version of the test case was not exercising the new character - flush logic. - - This fixes bug 33980. - - Assisted-by: LLM - Reviewed-by: Carlos O'Donell - (cherry picked from commit d6f08d1cf027f4eb2ba289a6cc66853722d4badc) - -diff --git a/iconvdata/Makefile b/iconvdata/Makefile -index 5a2abeea24..cc689f63e9 100644 ---- a/iconvdata/Makefile -+++ b/iconvdata/Makefile -@@ -76,7 +76,7 @@ tests = bug-iconv1 bug-iconv2 tst-loading tst-e2big tst-iconv4 bug-iconv4 \ - tst-iconv6 bug-iconv5 bug-iconv6 tst-iconv7 bug-iconv8 bug-iconv9 \ - bug-iconv10 bug-iconv11 bug-iconv12 tst-iconv-big5-hkscs-to-2ucs4 \ - bug-iconv13 bug-iconv14 bug-iconv15 \ -- tst-iconv-iso-2022-cn-ext -+ tst-iconv-iso-2022-cn-ext tst-bug33980 - ifeq ($(have-thread-library),yes) - tests += bug-iconv3 - endif -@@ -333,6 +333,8 @@ $(objpfx)bug-iconv15.out: $(addprefix $(objpfx), $(gconv-modules)) \ - $(addprefix $(objpfx),$(modules.so)) - $(objpfx)tst-iconv-iso-2022-cn-ext.out: $(addprefix $(objpfx), $(gconv-modules)) \ - $(addprefix $(objpfx),$(modules.so)) -+$(objpfx)tst-bug33980.out: $(addprefix $(objpfx), $(gconv-modules)) \ -+ $(addprefix $(objpfx),$(modules.so)) - - $(objpfx)iconv-test.out: run-iconv-test.sh \ - $(addprefix $(objpfx), $(gconv-modules)) \ -diff --git a/iconvdata/ibm1364.c b/iconvdata/ibm1364.c -index 45c62acee5..244c61ad7a 100644 ---- a/iconvdata/ibm1364.c -+++ b/iconvdata/ibm1364.c -@@ -67,12 +67,29 @@ - - /* Since this is a stateful encoding we have to provide code which resets - the output state to the initial state. This has to be done during the -- flushing. */ -+ flushing. For the to-internal direction (FROM_DIRECTION is true), -+ there may be a pending character that needs flushing. */ - #define EMIT_SHIFT_TO_INIT \ - if ((data->__statep->__count & ~7) != sb) \ - { \ - if (FROM_DIRECTION) \ -- data->__statep->__count &= 7; \ -+ { \ -+ uint32_t ch = data->__statep->__count >> 7; \ -+ if (__glibc_unlikely (ch != 0)) \ -+ { \ -+ if (__glibc_unlikely (outend - outbuf < 4)) \ -+ status = __GCONV_FULL_OUTPUT; \ -+ else \ -+ { \ -+ put32 (outbuf, ch); \ -+ outbuf += 4; \ -+ /* Clear character and db bit. */ \ -+ data->__statep->__count &= 7; \ -+ } \ -+ } \ -+ else \ -+ data->__statep->__count &= 7; \ -+ } \ - else \ - { \ - /* We are not in the initial state. To switch back we have \ -@@ -99,11 +116,13 @@ - *curcsp = save_curcs - - --/* Current codeset type. */ -+/* Current codeset type. The bit is stored in the __count variable of -+ the conversion state. If the db bit is set, bit 7 and above store -+ a pending UCS-4 code point if non-zero. */ - enum - { -- sb = 0, -- db = 64 -+ sb = 0, /* Single byte mode. */ -+ db = 64 /* Double byte mode. */ - }; - - -@@ -119,21 +138,29 @@ enum - } \ - else \ - { \ -- /* This is a combined character. Make sure we have room. */ \ -- if (__glibc_unlikely (outptr + 8 > outend)) \ -- { \ -- result = __GCONV_FULL_OUTPUT; \ -- break; \ -- } \ -- \ - const struct divide *cmbp \ - = &DB_TO_UCS4_COMB[ch - __TO_UCS4_COMBINED_MIN]; \ - assert (cmbp->res1 != 0 && cmbp->res2 != 0); \ - \ - put32 (outptr, cmbp->res1); \ - outptr += 4; \ -- put32 (outptr, cmbp->res2); \ -- outptr += 4; \ -+ \ -+ /* See whether we have room for the second character. */ \ -+ if (outend - outptr >= 4) \ -+ { \ -+ put32 (outptr, cmbp->res2); \ -+ outptr += 4; \ -+ } \ -+ else \ -+ { \ -+ /* Otherwise store only the first character now, and \ -+ put the second one into the queue. */ \ -+ curcs |= cmbp->res2 << 7; \ -+ inptr += 2; \ -+ /* Tell the caller why we terminate the loop. */ \ -+ result = __GCONV_FULL_OUTPUT; \ -+ break; \ -+ } \ - } \ - } - #else -@@ -153,7 +180,20 @@ enum - #define LOOPFCT FROM_LOOP - #define BODY \ - { \ -- uint32_t ch = *inptr; \ -+ uint32_t ch; \ -+ \ -+ ch = curcs >> 7; \ -+ if (__glibc_unlikely (ch != 0)) \ -+ { \ -+ put32 (outptr, ch); \ -+ outptr += 4; \ -+ /* Remove the pending character, but preserve state bits. */ \ -+ curcs &= (1 << 7) - 1; \ -+ continue; \ -+ } \ -+ \ -+ /* Otherwise read the next input byte. */ \ -+ ch = *inptr; \ - \ - if (__builtin_expect (ch, 0) == SO) \ - { \ -diff --git a/iconvdata/tst-bug33980.c b/iconvdata/tst-bug33980.c -new file mode 100644 -index 0000000000..c9693e0efe ---- /dev/null -+++ b/iconvdata/tst-bug33980.c -@@ -0,0 +1,153 @@ -+/* Test for bug 33980: combining characters in IBM1390/IBM1399. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+ -+/* Run iconv in a loop with a small output buffer of OUTBUFSIZE bytes -+ starting at OUTBUF. OUTBUF should be right before an unmapped page -+ so that writing past the end will fault. Skip SHIFT bytes at the -+ start of the input and output, to exercise different buffer -+ alignment. TRUNCATE indicates skipped bytes at the end of -+ input (0 and 1 a valid). */ -+static void -+test_one (const char *encoding, unsigned int shift, unsigned int truncate, -+ char *outbuf, size_t outbufsize) -+{ -+ /* In IBM1390 and IBM1399, the DBCS code 0xECB5 expands to two -+ Unicode code points when translated. */ -+ static char input[] = -+ { -+ /* 8 letters X. */ -+ 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, -+ /* SO, 0xECB5, SI: shift to DBCS, special character, shift back. */ -+ 0x0e, 0xec, 0xb5, 0x0f -+ }; -+ -+ /* Expected output after UTF-8 conversion. */ -+ static char expected[] = -+ { -+ 'X', 'X', 'X', 'X', 'X', 'X', 'X', 'X', -+ /* U+304B (HIRAGANA LETTER KA). */ -+ 0xe3, 0x81, 0x8b, -+ /* U+309A (COMBINING KATAKANA-HIRAGANA SEMI-VOICED SOUND MARK). */ -+ 0xe3, 0x82, 0x9a -+ }; -+ -+ iconv_t cd = iconv_open ("UTF-8", encoding); -+ TEST_VERIFY_EXIT (cd != (iconv_t) -1); -+ -+ char result_storage[64]; -+ struct alloc_buffer result_buf -+ = alloc_buffer_create (result_storage, sizeof (result_storage)); -+ -+ char *inptr = &input[shift]; -+ size_t inleft = sizeof (input) - shift - truncate; -+ -+ while (inleft > 0) -+ { -+ char *outptr = outbuf; -+ size_t outleft = outbufsize; -+ size_t inleft_before = inleft; -+ -+ size_t ret = iconv (cd, &inptr, &inleft, &outptr, &outleft); -+ size_t produced = outptr - outbuf; -+ alloc_buffer_copy_bytes (&result_buf, outbuf, produced); -+ -+ if (ret == (size_t) -1 && errno == E2BIG) -+ { -+ if (produced == 0 && inleft == inleft_before) -+ { -+ /* Output buffer too small to make progress. This is -+ expected for very small output buffer sizes. */ -+ TEST_VERIFY_EXIT (outbufsize < 3); -+ break; -+ } -+ continue; -+ } -+ if (ret == (size_t) -1) -+ FAIL_EXIT1 ("%s (outbufsize %zu): iconv: %m", encoding, outbufsize); -+ break; -+ } -+ -+ /* Flush any pending state (e.g. a buffered combined character). -+ With outbufsize < 3, we could not store the first character, so -+ the second character did not become pending, and there is nothing -+ to flush. */ -+ { -+ char *outptr = outbuf; -+ size_t outleft = outbufsize; -+ -+ size_t ret = iconv (cd, NULL, NULL, &outptr, &outleft); -+ TEST_VERIFY_EXIT (ret == 0); -+ size_t produced = outptr - outbuf; -+ alloc_buffer_copy_bytes (&result_buf, outbuf, produced); -+ -+ /* Second flush does not provide more data. */ -+ outptr = outbuf; -+ outleft = outbufsize; -+ ret = iconv (cd, NULL, NULL, &outptr, &outleft); -+ TEST_VERIFY_EXIT (ret == 0); -+ TEST_VERIFY (outptr == outbuf); -+ } -+ -+ TEST_VERIFY_EXIT (!alloc_buffer_has_failed (&result_buf)); -+ size_t result_used -+ = sizeof (result_storage) - alloc_buffer_size (&result_buf); -+ -+ if (outbufsize >= 3) -+ { -+ TEST_COMPARE (inleft, 0); -+ TEST_COMPARE (result_used, sizeof (expected) - shift); -+ TEST_COMPARE_BLOB (result_storage, result_used, -+ &expected[shift], sizeof (expected) - shift); -+ } -+ else -+ /* If the buffer is too small, only the leading X could be converted. */ -+ TEST_COMPARE (result_used, 8 - shift); -+ -+ TEST_VERIFY_EXIT (iconv_close (cd) == 0); -+} -+ -+static int -+do_test (void) -+{ -+ struct support_next_to_fault ntf -+ = support_next_to_fault_allocate (8); -+ -+ for (int shift = 0; shift <= 8; ++shift) -+ for (int truncate = 0; truncate < 2; ++truncate) -+ for (size_t outbufsize = 1; outbufsize <= 8; outbufsize++) -+ { -+ char *outbuf = ntf.buffer + ntf.length - outbufsize; -+ test_one ("IBM1390", shift, truncate, outbuf, outbufsize); -+ test_one ("IBM1399", shift, truncate, outbuf, outbufsize); -+ } -+ -+ support_next_to_fault_free (&ntf); -+ return 0; -+} -+ -+#include - -commit 12feedaf67e11c4618dc50c6aab4dbfd1e6d9531 -Author: DJ Delorie -Date: Mon Jan 26 22:24:42 2026 -0500 - - include: isolate __O_CLOEXEC flag for sys/mount.h and fcntl.h - - Including sys/mount.h should not implicitly include fcntl.h - as that causes namespace pollution and conflicts with kernel - headers. It only needs O_CLOEXEC for OPEN_TREE_CLOEXEC - (although it shouldn't need that, but it's defined that way) - so we provide that define (via a private version) separately. - - Reviewed-by: Adhemerval Zanella - Tested-by: Florian Weimer - (cherry picked from commit 419245719ccbc7dad6a97f24465e7f09c090327a) - -diff --git a/io/fcntl.c b/io/fcntl.c -index e88e28664c..b7dab1bb39 100644 ---- a/io/fcntl.c -+++ b/io/fcntl.c -@@ -18,6 +18,10 @@ - #include - #include - -+#ifndef __O_CLOEXEC -+# error __O_CLOEXEC not defined by fcntl.h/cloexec.h -+#endif -+ - /* Perform file control operations on FD. */ - int - __fcntl (int fd, int cmd, ...) -diff --git a/sysdeps/unix/sysv/linux/Makefile b/sysdeps/unix/sysv/linux/Makefile -index c47cbdf428..053041f256 100644 ---- a/sysdeps/unix/sysv/linux/Makefile -+++ b/sysdeps/unix/sysv/linux/Makefile -@@ -129,6 +129,7 @@ CFLAGS-test-errno-linux.c += $(no-fortify-source) - - sysdep_headers += \ - bits/a.out.h \ -+ bits/cloexec.h \ - bits/epoll.h \ - bits/eventfd.h \ - bits/inotify.h \ -diff --git a/sysdeps/unix/sysv/linux/alpha/bits/cloexec.h b/sysdeps/unix/sysv/linux/alpha/bits/cloexec.h -new file mode 100644 -index 0000000000..f381f28a53 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/alpha/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 010000000 -diff --git a/sysdeps/unix/sysv/linux/bits/cloexec.h b/sysdeps/unix/sysv/linux/bits/cloexec.h -new file mode 100644 -index 0000000000..3059fb6473 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 02000000 -diff --git a/sysdeps/unix/sysv/linux/bits/fcntl-linux.h b/sysdeps/unix/sysv/linux/bits/fcntl-linux.h -index f425a4bf22..98954feaca 100644 ---- a/sysdeps/unix/sysv/linux/bits/fcntl-linux.h -+++ b/sysdeps/unix/sysv/linux/bits/fcntl-linux.h -@@ -81,9 +81,7 @@ - #ifndef __O_NOFOLLOW - # define __O_NOFOLLOW 0400000 - #endif --#ifndef __O_CLOEXEC --# define __O_CLOEXEC 02000000 --#endif -+#include - #ifndef __O_DIRECT - # define __O_DIRECT 040000 - #endif -diff --git a/sysdeps/unix/sysv/linux/hppa/bits/cloexec.h b/sysdeps/unix/sysv/linux/hppa/bits/cloexec.h -new file mode 100644 -index 0000000000..f381f28a53 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/hppa/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 010000000 -diff --git a/sysdeps/unix/sysv/linux/sparc/bits/cloexec.h b/sysdeps/unix/sysv/linux/sparc/bits/cloexec.h -new file mode 100644 -index 0000000000..6706eaa7d5 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/sparc/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 0x400000 -diff --git a/sysdeps/unix/sysv/linux/sys/mount.h b/sysdeps/unix/sysv/linux/sys/mount.h -index b549e75148..365da1c296 100644 ---- a/sysdeps/unix/sysv/linux/sys/mount.h -+++ b/sysdeps/unix/sysv/linux/sys/mount.h -@@ -21,7 +21,6 @@ - #ifndef _SYS_MOUNT_H - #define _SYS_MOUNT_H 1 - --#include - #include - #include - #include -@@ -266,6 +265,11 @@ enum fsconfig_command - - /* open_tree flags. */ - #define OPEN_TREE_CLONE 1 /* Clone the target tree and attach the clone */ -+#ifndef O_CLOEXEC -+# include -+# define O_CLOEXEC __O_CLOEXEC -+#endif -+#undef OPEN_TREE_CLOEXEC - #define OPEN_TREE_CLOEXEC O_CLOEXEC /* Close the file on execve() */ - - -diff --git a/sysdeps/unix/sysv/linux/tst-mount.c b/sysdeps/unix/sysv/linux/tst-mount.c -index 40913c7082..78a2772b2f 100644 ---- a/sysdeps/unix/sysv/linux/tst-mount.c -+++ b/sysdeps/unix/sysv/linux/tst-mount.c -@@ -20,6 +20,7 @@ - #include - #include - #include -+#include /* For AT_ constants. */ - #include - - _Static_assert (sizeof (struct mount_attr) == MOUNT_ATTR_SIZE_VER0, - -commit 3ecfa68561d723564a1fb565366182eb4acb3e8f -Author: Florian Weimer -Date: Wed Mar 4 18:32:36 2026 +0100 - - Linux: Only define OPEN_TREE_* macros in if undefined (bug 33921) - - There is a conditional inclusion of earlier in the file. - If that defines the macros, do not redefine them. This addresses build - problems as the token sequence used by the UAPI macro definitions - changes between Linux versions. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit d12b017cddfeb9fe9920ba054ae3dfcb8e9238b8) - -diff --git a/sysdeps/unix/sysv/linux/sys/mount.h b/sysdeps/unix/sysv/linux/sys/mount.h -index 365da1c296..30ba56c1e8 100644 ---- a/sysdeps/unix/sysv/linux/sys/mount.h -+++ b/sysdeps/unix/sysv/linux/sys/mount.h -@@ -264,14 +264,16 @@ enum fsconfig_command - #define FSOPEN_CLOEXEC 0x00000001 - - /* open_tree flags. */ --#define OPEN_TREE_CLONE 1 /* Clone the target tree and attach the clone */ -+#ifndef OPEN_TREE_CLONE -+# define OPEN_TREE_CLONE 1 /* Clone the target tree and attach the clone */ -+#endif - #ifndef O_CLOEXEC - # include - # define O_CLOEXEC __O_CLOEXEC - #endif --#undef OPEN_TREE_CLOEXEC --#define OPEN_TREE_CLOEXEC O_CLOEXEC /* Close the file on execve() */ -- -+#ifndef OPEN_TREE_CLOEXEC -+# define OPEN_TREE_CLOEXEC O_CLOEXEC /* Close the file on execve() */ -+#endif - - __BEGIN_DECLS - - -commit 3e87cf9be93acf19d685e8003fc649cdb052a891 -Author: H.J. Lu -Date: Mon Apr 13 10:46:42 2026 +0800 - - abilist.awk: Handle weak unversioned defined symbols - - After - - commit f685e3953f9a38a41bbd0a597f9882870cee13d5 - Author: H.J. Lu - Date: Wed Oct 29 09:49:57 2025 +0800 - - elf: Don't set its DT_VERSYM entry for unversioned symbol - - ld no longer assigns version index 1 to unversioned defined symbol. - For libmachuser.so, "objdump --dynamic-syms" reports: - - 0000dd30 w DF .text 000000f8 processor_start - - instead of - - 0000dd30 w DF .text 000000f8 (Base) processor_start - - Also allow NF == 6 for weak unversioned dynamic symbols. This fixes BZ - 33650. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit ee5d1db2a81468413fbf7c82779ffa782f429d1a) - -diff --git a/scripts/abilist.awk b/scripts/abilist.awk -index 6cc7af6ac8..7ea1edf8c0 100644 ---- a/scripts/abilist.awk -+++ b/scripts/abilist.awk -@@ -38,7 +38,7 @@ $4 == "*UND*" { next } - $2 == "l" { next } - - # If the target uses ST_OTHER, it will be output before the symbol name. --$2 == "g" || $2 == "w" && (NF == 7 || NF == 8) { -+$2 == "g" || $2 == "w" && (NF == 6 || NF == 7 || NF == 8) { - type = $3; - size = $5; - sub(/^0*/, "", size); - -commit b4bca35ab9e76890504c4dbdd5eaf15a93514580 -Author: Rocket Ma -Date: Fri May 1 20:39:07 2026 -0700 - - libio: Fix ungetwc operating on byte stream [BZ #33998] - - * libio/wgenops.c: When _IO_wdefault_pbackfail attempts to push back one - character, it accidently compare the wchar to push back with the last - char from byte stream, instead of wide stream. Under specific coding, - attacker may exploit this to leak information. This commit fix bug - 33998, or CVE-2026-5928. - - Signed-off-by: Rocket Ma - Reviewed-by: Carlos O'Donell - (cherry picked from commit ef3bfb5f910011f3780cb06aa47e730035f53285) - -diff --git a/libio/Makefile b/libio/Makefile -index f020f8ec4d..fa2b8ae791 100644 ---- a/libio/Makefile -+++ b/libio/Makefile -@@ -83,6 +83,7 @@ tests = \ - bug-ungetwc1 \ - bug-ungetwc2 \ - bug-wfflush \ -+ bug-wgenops-bz33998 \ - bug-wmemstream1 \ - bug-wsetpos \ - test-fmemopen \ -diff --git a/libio/bug-wgenops-bz33998.c b/libio/bug-wgenops-bz33998.c -new file mode 100644 -index 0000000000..cc4067da99 ---- /dev/null -+++ b/libio/bug-wgenops-bz33998.c -@@ -0,0 +1,54 @@ -+/* Regression test for ungetwc operating on byte stream (BZ #33998) -+ Copyright (C) 2026 The GNU Toolchain Authors. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "support/temp_file.h" -+#include "support/xstdio.h" -+#include "support/xunistd.h" -+#include -+#include -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ char *filename; -+ int fd = create_temp_file ("tst-bz33998-", &filename); -+ TEST_VERIFY (fd != -1); -+ xwrite (fd, "A", sizeof ("A")); // write "A\0" by design -+ xclose (fd); -+ -+ FILE *fp = xfopen (filename, "r+"); -+ TEST_COMPARE (getwc (fp), L'A'); -+ /* If the bug is fixed, then ungetwc should not touch byte stream. -+ If the bug is not fixed, ungetwc firstly match last read char, L'A', -+ failed, then the pbackfail branch, matching last read char in byte -+ stream, that is, '\0' (initialized when setup wide stream). */ -+ char *old_read_ptr = fp->_IO_read_ptr; -+ TEST_COMPARE (ungetwc (L'\0', fp), L'\0'); -+ TEST_VERIFY (fp->_IO_read_ptr == old_read_ptr); -+ -+ xfclose (fp); -+ free (filename); -+ -+ return 0; -+} -+ -+#include -diff --git a/libio/wgenops.c b/libio/wgenops.c -index 0a11d1b1de..9e0b2c00ea 100644 ---- a/libio/wgenops.c -+++ b/libio/wgenops.c -@@ -108,8 +108,8 @@ _IO_wdefault_pbackfail (FILE *fp, wint_t c) - { - if (fp->_wide_data->_IO_read_ptr > fp->_wide_data->_IO_read_base - && !_IO_in_backup (fp) -- && (wint_t) fp->_IO_read_ptr[-1] == c) -- --fp->_IO_read_ptr; -+ && (wint_t) fp->_wide_data->_IO_read_ptr[-1] == c) -+ --fp->_wide_data->_IO_read_ptr; - else - { - /* Need to handle a filebuf in write mode (switch to read mode). FIXME!*/ - -commit 4ebd33dd77eabe8d4c45232bed4b42a31d2f9edc -Author: Rocket Ma -Date: Fri Apr 17 23:48:41 2026 -0700 - - stdio-common: Fix buffer overflow in scanf %mc [BZ #34008] - - * stdio-common/vfscanf-internal.c: When enlarging allocated buffer with - format %mc or %mC, glibc allocates one byte less, leading to - user-controlled one byte overflow. This commit fixes BZ #34008, or - CVE-2026-5450. - - Reviewed-by: Carlos O'Donell - Signed-off-by: Rocket Ma - Reviewed-by: H.J. Lu - (cherry picked from commit 839898777226a3ed88c0859f25ffe712519b4ead) - -diff --git a/stdio-common/Makefile b/stdio-common/Makefile -index 64b3575acb..e52c333808 100644 ---- a/stdio-common/Makefile -+++ b/stdio-common/Makefile -@@ -347,6 +347,7 @@ tests := \ - tst-vfprintf-user-type \ - tst-vfprintf-width-i18n \ - tst-vfprintf-width-prec-alloc \ -+ tst-vfscanf-bz34008 \ - tst-wc-printf \ - tstdiomisc \ - tstgetln \ -@@ -562,6 +563,9 @@ tst-printf-bz18872-ENV = MALLOC_TRACE=$(objpfx)tst-printf-bz18872.mtrace \ - tst-vfprintf-width-prec-ENV = \ - MALLOC_TRACE=$(objpfx)tst-vfprintf-width-prec.mtrace \ - LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so -+tst-vfscanf-bz34008-ENV = \ -+ MALLOC_CHECK_=3 \ -+ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so - tst-printf-bz25691-ENV = \ - MALLOC_TRACE=$(objpfx)tst-printf-bz25691.mtrace \ - LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so -diff --git a/stdio-common/tst-vfscanf-bz34008.c b/stdio-common/tst-vfscanf-bz34008.c -new file mode 100644 -index 0000000000..48371c8a3d ---- /dev/null -+++ b/stdio-common/tst-vfscanf-bz34008.c -@@ -0,0 +1,48 @@ -+/* Regression test for vfscanf %Nmc out-of-bound write (BZ #34008) -+ Copyright (C) 2026 The GNU Toolchain Authors. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "malloc/mcheck.h" -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+#define WIDTH 0x410 -+#define SCANFSTR "%1040mc" -+static int -+do_test (void) -+{ -+ mcheck_pedantic (NULL); -+ char *input = malloc (WIDTH + 1); -+ TEST_VERIFY (input != NULL); -+ memset (input, 'A', WIDTH); -+ input[WIDTH] = '\0'; -+ -+ char *buf = NULL; -+ TEST_VERIFY (sscanf (input, SCANFSTR, &buf) != -1); -+ TEST_VERIFY (buf != NULL); -+ -+ free (buf); -+ free (input); -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/vfscanf-internal.c b/stdio-common/vfscanf-internal.c -index 86ae5019a6..17b5565d0f 100644 ---- a/stdio-common/vfscanf-internal.c -+++ b/stdio-common/vfscanf-internal.c -@@ -853,8 +853,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - { - /* Enlarge the buffer. */ - size_t newsize -- = strsize -- + (strsize >= width ? width - 1 : strsize); -+ = strsize + (strsize >= width ? width : strsize); - - str = (char *) realloc (*strptr, newsize); - if (str == NULL) -@@ -925,7 +924,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - && wstr == (wchar_t *) *strptr + strsize) - { - size_t newsize -- = strsize + (strsize > width ? width - 1 : strsize); -+ = strsize + (strsize >= width ? width : strsize); - /* Enlarge the buffer. */ - wstr = (wchar_t *) realloc (*strptr, - newsize * sizeof (wchar_t)); -@@ -980,7 +979,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - && wstr == (wchar_t *) *strptr + strsize) - { - size_t newsize -- = strsize + (strsize > width ? width - 1 : strsize); -+ = strsize + (strsize >= width ? width : strsize); - /* Enlarge the buffer. */ - wstr = (wchar_t *) realloc (*strptr, - newsize * sizeof (wchar_t)); - -commit b866ef29773b22a1343ff9084374775114350b78 -Author: Maciej W. Rozycki -Date: Wed May 27 12:57:10 2026 -0400 - - support: Implement 'xfmemopen' for seamless 'fmemopen' use - - Add 'xfmemopen' wrapper for seamless 'fmemopen' use in tests, following - 'xfopen', 'xfclose', etc., and providing a standardized error reporting - facility. - - Reviewed-by: Florian Weimer - (cherry picked from commit fe709cc24578ecfd2ff5b07e10e3829fcb55075b) - - Reviewed-by: Carlos O'Donell - -diff --git a/support/Makefile b/support/Makefile -index d41278eeab..f67f38130a 100644 ---- a/support/Makefile -+++ b/support/Makefile -@@ -134,6 +134,7 @@ libsupport-routines = \ - xfclose \ - xfdopendir \ - xfgets \ -+ xfmemopen \ - xfopen \ - xfork \ - xfread \ -diff --git a/support/xfmemopen.c b/support/xfmemopen.c -new file mode 100644 -index 0000000000..f1dbc72c67 ---- /dev/null -+++ b/support/xfmemopen.c -@@ -0,0 +1,31 @@ -+/* fmemopen with error checking. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+#include -+#include -+ -+FILE * -+xfmemopen (void *mem, size_t len, const char *mode) -+{ -+ FILE *fp = fmemopen (mem, len, mode); -+ if (fp == NULL) -+ FAIL_EXIT1 ("fmemopen (mode \"%s\"): %m", mode); -+ return fp; -+} -diff --git a/support/xstdio.h b/support/xstdio.h -index c3fdf9496f..70b83f11da 100644 ---- a/support/xstdio.h -+++ b/support/xstdio.h -@@ -27,6 +27,7 @@ __BEGIN_DECLS - FILE *xfopen (const char *path, const char *mode); - void xfclose (FILE *); - FILE *xfreopen (const char *path, const char *mode, FILE *stream); -+FILE *xfmemopen (void *mem, size_t len, const char *mode); - void xfread (void *ptr, size_t size, size_t nmemb, FILE *stream); - char *xfgets (char *s, int size, FILE *stream); - - -commit 97926e9017f3faeaacce9337f1288460f5e6ec7d -Author: Maciej W. Rozycki -Date: Wed May 27 12:57:10 2026 -0400 - - stdio-common: Reject insufficient character data in scanf [BZ #12701] - - Reject invalid formatted scanf character data with the 'c' conversion - where there is not enough input available to satisfy the field width - requested. It is required by ISO C that this conversion matches a - sequence of characters of exactly the number specified by the field - width and it is also already documented as such in our own manual: - - "It reads precisely the next N characters, and fails if it cannot get - that many." - - Currently a matching success is instead incorrectly produced where the - EOF condition is encountered before the required number of characters - has been retrieved, and the characters actually obtained are stored in - the buffer provided. - - Add test cases accordingly and remove placeholders from 'c' conversion - input data for the existing scanf tests. - - Reviewed-by: Adhemerval Zanella - - [This is a modified version of commit 2b16c76609, which tests for the - old behavior and only includes the test cases, for older branches - and downstream backports - DJ] - - Reviewed-by: Carlos O'Donell - -diff --git a/localedata/Makefile b/localedata/Makefile -index 4a23593cca..bff5c0bc71 100644 ---- a/localedata/Makefile -+++ b/localedata/Makefile -@@ -236,6 +236,7 @@ tests = \ - bug-iconv-trans \ - bug-setlocale1 \ - bug-usesetlocale \ -+ tst-bz12701-lc \ - tst-bz13988 \ - tst-c-utf8-consistency \ - tst-digits \ -diff --git a/localedata/tst-bz12701-lc.c b/localedata/tst-bz12701-lc.c -new file mode 100644 -index 0000000000..23c2ab7d2a ---- /dev/null -+++ b/localedata/tst-bz12701-lc.c -@@ -0,0 +1,218 @@ -+/* Verify scanf field width handling with the 'lc' conversion (BZ #12701). -+ Copyright (C) 2025-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+/* Compare character-wise the initial part of the wide character object -+ pointed to by WS corresponding to wide characters obtained by the -+ conversion of first N bytes of the multibyte character object pointed -+ to by S. */ -+ -+static int -+tst_bz12701_lc_memcmp (const wchar_t *ds, const char *s, size_t n) -+{ -+ size_t nc = mbsnrtowcs (NULL, &s, n, 0, NULL); -+ -+ struct support_next_to_fault ntf; -+ ntf = support_next_to_fault_allocate (nc * sizeof (wchar_t)); -+ wchar_t *ss = (wchar_t *) ntf.buffer; -+ -+ mbsnrtowcs (ss, &s, n, nc, NULL); -+ int r = wmemcmp (ds, ss, nc); -+ -+ support_next_to_fault_free (&ntf); -+ -+ return r; -+} -+ -+/* Verify various aspects of field width handling, including the data -+ obtained, the number of bytes consumed, and the stream position. */ -+ -+static int -+do_test (void) -+{ -+ if (setlocale (LC_ALL, "pl_PL.UTF-8") == NULL) -+ FAIL_EXIT1 ("setlocale (LC_ALL, \"pl_PL.UTF-8\")"); -+ -+ /* Part of a tongue-twister in Polish, which says: -+ "On a rainy morning cuckoos and warblers, rather than starting -+ on earthworms, stuffed themselves fasted with the flesh of cress." */ -+ static const char s[126] = "Dżdżystym rankiem gżegżółki i piegże, " -+ "zamiast wziąć się za dżdżownice, " -+ "nażarły się na czczo miąższu rzeżuchy"; -+ -+ const char *sp = s; -+ size_t nc; -+ TEST_VERIFY_EXIT ((nc = mbsnrtowcs (NULL, &sp, sizeof (s), 0, NULL)) == 108); -+ -+ struct support_next_to_fault ntfo, ntfi; -+ ntfo = support_next_to_fault_allocate (nc * sizeof (wchar_t)); -+ ntfi = support_next_to_fault_allocate (sizeof (s)); -+ wchar_t *e = (wchar_t *) ntfo.buffer + nc; -+ char *b = ntfi.buffer; -+ -+ wchar_t *c; -+ FILE *f; -+ int ic; -+ int n; -+ int i; -+ -+ memcpy (ntfi.buffer, s, sizeof (s)); -+ -+ ic = i = 0; -+ f = xfmemopen (b, sizeof (s), "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ /* Avoid: "warning: zero width in gnu_scanf format [-Werror=format=]". */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wformat"); -+ TEST_VERIFY_EXIT (fscanf (f, "%0lc%n", c, &n) == 1); -+ DIAG_POP_NEEDS_COMMENT; -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%1lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 3); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 2; -+ i += n; -+ -+ c = e - 4; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%4lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 4); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 4; -+ i += n; -+ -+ c = e - 8; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%8lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 8); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 8; -+ i += n; -+ -+ c = e - 16; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%16lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 20); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 16; -+ i += n; -+ -+ c = e - 32; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%32lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 38); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 32; -+ i += n; -+ -+ c = e - (nc - ic); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_COMPARE (fscanf (f, "%64lc%n", c, &n), 1); -+ TEST_COMPARE (n , 49); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, sizeof (s) - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == sizeof (s)); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ ic = i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 3); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 2; -+ i += n; -+ -+ c = e - (nc - ic); -+ TEST_VERIFY_EXIT (feof (f) == 0); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == EOF); -+ TEST_VERIFY_EXIT (n == 3); -+ -+ TEST_VERIFY_EXIT (ftell (f) == 3); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ ic = i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - (nc - ic); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, 3 - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == 3); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ support_next_to_fault_free (&ntfi); -+ support_next_to_fault_free (&ntfo); -+ -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/Makefile b/stdio-common/Makefile -index e52c333808..fdb545242e 100644 ---- a/stdio-common/Makefile -+++ b/stdio-common/Makefile -@@ -260,6 +260,7 @@ tests := \ - tllformat \ - tst-bz11319 \ - tst-bz11319-fortify2 \ -+ tst-bz12701-c \ - tst-cookie \ - tst-dprintf-length \ - tst-fclose-devzero \ -diff --git a/stdio-common/tst-bz12701-c.c b/stdio-common/tst-bz12701-c.c -new file mode 100644 -index 0000000000..4f3616fbfd ---- /dev/null -+++ b/stdio-common/tst-bz12701-c.c -@@ -0,0 +1,169 @@ -+/* Verify scanf field width handling with the 'c' conversion (BZ #12701). -+ Copyright (C) 2025-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+/* Verify various aspects of field width handling, including the data -+ obtained, the number of bytes consumed, and the stream position. */ -+ -+static int -+do_test (void) -+{ -+ static const char s[43] = "The quick brown fox jumps over the lazy dog"; -+ struct support_next_to_fault ntfo, ntfi; -+ ntfo = support_next_to_fault_allocate (sizeof (s)); -+ ntfi = support_next_to_fault_allocate (sizeof (s)); -+ char *e = ntfo.buffer + sizeof (s); -+ char *b = ntfi.buffer; -+ -+ char *c; -+ FILE *f; -+ int n; -+ int i; -+ -+ memcpy (ntfi.buffer, s, sizeof (s)); -+ -+ i = 0; -+ f = xfmemopen (b, sizeof (s), "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ /* Avoid: "warning: zero width in gnu_scanf format [-Werror=format=]". */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wformat"); -+ TEST_VERIFY_EXIT (fscanf (f, "%0c%n", c, &n) == 1); -+ DIAG_POP_NEEDS_COMMENT; -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%1c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 4; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%4c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 4); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 8; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%8c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 8); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 16; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%16c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 16); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - (sizeof (s) - i); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%32c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 10); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, sizeof (s) - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == sizeof (s)); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - (3 - i); -+ TEST_VERIFY_EXIT (feof (f) == 0); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == EOF); -+ TEST_VERIFY_EXIT (n == 2); -+ -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - (3 - i); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, 3 - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == 3); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ support_next_to_fault_free (&ntfi); -+ support_next_to_fault_free (&ntfo); -+ -+ return 0; -+} -+ -+#include - -commit 6cebb0b80fd783e442a8ad27c3f52cde52a9cac7 -Author: DJ Delorie -Date: Wed May 27 12:57:10 2026 -0400 - - stdio-common: Allow partially-filled %mc buffers [BZ #12701] - - This is a backwards-compatible alternative to the main solution to - the %mc part of 12701. The allocated buffer is expanded to the - requested size and NUL padded, but truncated reads are allowed. - - Reviewed-by: Carlos O'Donell - -diff --git a/localedata/Makefile b/localedata/Makefile -index bff5c0bc71..e212facef0 100644 ---- a/localedata/Makefile -+++ b/localedata/Makefile -@@ -237,6 +237,7 @@ tests = \ - bug-setlocale1 \ - bug-usesetlocale \ - tst-bz12701-lc \ -+ tst-bz12701-lc2 \ - tst-bz13988 \ - tst-c-utf8-consistency \ - tst-digits \ -diff --git a/localedata/tst-bz12701-lc2.c b/localedata/tst-bz12701-lc2.c -new file mode 100644 -index 0000000000..b24e86df0b ---- /dev/null -+++ b/localedata/tst-bz12701-lc2.c -@@ -0,0 +1,47 @@ -+/* Verify scanf memory handling with the 'c' conversion (BZ #12701). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ wchar_t *c = NULL; -+ int i; -+ -+ TEST_VERIFY (sscanf ("1234", "%30mlc", &c) == 1); -+ -+ TEST_VERIFY (c != NULL); -+ TEST_COMPARE_BLOB (c, 5 * sizeof (wchar_t), -+ L"1234\0", 5 * sizeof (wchar_t)); -+ for (i = 5; i < 30; i ++) -+ TEST_VERIFY (c[i] == L'\0'); -+ -+ TEST_VERIFY (malloc_usable_size (c) >= 30 * sizeof(wchar_t)); -+ -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/Makefile b/stdio-common/Makefile -index fdb545242e..27e7ea20f0 100644 ---- a/stdio-common/Makefile -+++ b/stdio-common/Makefile -@@ -261,6 +261,7 @@ tests := \ - tst-bz11319 \ - tst-bz11319-fortify2 \ - tst-bz12701-c \ -+ tst-bz12701-c2 \ - tst-cookie \ - tst-dprintf-length \ - tst-fclose-devzero \ -diff --git a/stdio-common/tst-bz12701-c2.c b/stdio-common/tst-bz12701-c2.c -new file mode 100644 -index 0000000000..5f9ca7c592 ---- /dev/null -+++ b/stdio-common/tst-bz12701-c2.c -@@ -0,0 +1,46 @@ -+/* Verify scanf memory handling with the 'c' conversion (BZ #12701). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ char *c = NULL; -+ int i; -+ -+ TEST_VERIFY (sscanf ("1234", "%30mc", &c) == 1); -+ -+ TEST_VERIFY (c != NULL); -+ TEST_COMPARE_BLOB (c, 5, "1234\0", 5); -+ for (i = 5; i < 30; i ++) -+ TEST_VERIFY (c[i] == '\0'); -+ -+ TEST_VERIFY (malloc_usable_size (c) >= 30); -+ -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/vfscanf-internal.c b/stdio-common/vfscanf-internal.c -index 17b5565d0f..90a1886951 100644 ---- a/stdio-common/vfscanf-internal.c -+++ b/stdio-common/vfscanf-internal.c -@@ -780,9 +780,9 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - conv_error (); \ - } while (0) - #ifdef COMPILE_WSCANF -- STRING_ARG (str, char, 100); -+ STRING_ARG (str, char, (width > 0 ? width : 1)); - #else -- STRING_ARG (str, char, (width > 1024 ? 1024 : width)); -+ STRING_ARG (str, char, (width > 0 ? width : 1)); - #endif - - c = inchar (); -@@ -891,6 +891,11 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - - if (!(flags & SUPPRESS)) - { -+ /* If the buffer isn't completely filled, pad it with NULs. */ -+ if (flags & MALLOC) -+ while (width-- > 0) -+ *str++ = '\0'; -+ - if ((flags & MALLOC) && str - *strptr != strsize) - { - char *cp = (char *) realloc (*strptr, str - *strptr); -@@ -908,7 +913,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - if (width == -1) - width = 1; - -- STRING_ARG (wstr, wchar_t, (width > 1024 ? 1024 : width)); -+ STRING_ARG (wstr, wchar_t, (width > 0 ? width : 1)); - - c = inchar (); - if (__glibc_unlikely (c == EOF)) -@@ -1044,6 +1049,11 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - - if (!(flags & SUPPRESS)) - { -+ /* If the buffer isn't completely filled, pad it with NULs. */ -+ if (flags & MALLOC) -+ while (width-- > 0) -+ *wstr++ = L'\0'; -+ - if ((flags & MALLOC) && wstr - (wchar_t *) *strptr != strsize) - { - wchar_t *cp = (wchar_t *) realloc (*strptr, - -commit 748699d9385fc298f7d3369af0a015a6d88b7e64 -Author: Sam James -Date: Sat Jun 6 20:32:27 2026 +0100 - - elf: don't clobber ld.so.conf in tst-glibc-hwcaps-prepend-cache [BZ #34210] - - dbe5065f2166be20e57a24f246a40d50e001a05d and ae589cb84df10825fc545a45c7007a5f79409bf1 - cater for setups where ld.so.conf{,.d} is required to find runtime support - libraries, but tst-glibc-hwcaps-prepend-cache clobbers the created ld.so.conf - with its own entry. - - Fix it to instead use the ld.so.conf.d created in ae589cb84df10825fc545a45c7007a5f79409bf1 - to co-exist with existing entries. - - Bug: https://bugs.gentoo.org/976773 - Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=31901 - Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=34210 - Tested-by: Andreas K. Hüttel - Reported-by: Eli Schwartz - Reviewed-by: Andreas K. Hüttel - (cherry picked from commit d0cc9bf859d0434e397530d75a6507f13db79fba) - -diff --git a/elf/tst-glibc-hwcaps-prepend-cache.c b/elf/tst-glibc-hwcaps-prepend-cache.c -index b7df3962b5..2d51c22328 100644 ---- a/elf/tst-glibc-hwcaps-prepend-cache.c -+++ b/elf/tst-glibc-hwcaps-prepend-cache.c -@@ -46,7 +46,7 @@ do_test (void) - - { - /* Install the default implementation of libmarkermod1.so. */ -- char *conf_path = xasprintf ("%s/ld.so.conf", support_sysconfdir_prefix); -+ char *conf_path = xasprintf ("%s/ld.so.conf.d/hwcaps.conf", support_sysconfdir_prefix); - xmkdirp (support_sysconfdir_prefix, 0777); - support_write_file_string (conf_path, "/glibc-test/lib\n"); - free (conf_path); - -commit f671746f6c3ae511432b5666953be668267159f8 -Author: Florian Weimer -Date: Tue Jun 9 07:28:02 2026 +0200 - - iconv: Suppress intermediate errors with //TRANSLIT (bug 34236) - - When tentatively converting characters on behalf of - __gconv_transliterate, do not create a persistent error. Just - produce a local error, and rely on __gconv_transliterate to - produce the error if all transliteration options are exhausted. - - This fixes transliteration of “½” to ASCII, which cannot use the - “ 1⁄2 ” alternative. Eventually, the “ 1/2 ” alternative is chosen, - but the error sticks. Therefore, iconv exited with status 1 before - this change. - - Adjust iconv/tst-iconv_prog.sh to test both C and en_US.UTF-8 locales. - This requires changing the way the ICONV template is defined, so that - run_program_env is evaluated multiple times. - - Fixes commit 9a4b0eaf726f5404c6683d5c7c5e86f61c3f3fbc ("iconv: do not - report error exit with transliteration [BZ #32448]"), - commit 6cbf845fcdc76131d0e674cee454fe738b69c69d ("iconv: Preserve - iconv -c error exit on invalid inputs (bug 32046)"), and bug 34236. - - Reviewed-by: Aurelien Jarno - (cherry picked from commit e9325bd7d04aacc45cf39505e279b1ca9de22c08) - -diff --git a/iconv/Makefile b/iconv/Makefile -index 9a94a41ba4..028d24ffc3 100644 ---- a/iconv/Makefile -+++ b/iconv/Makefile -@@ -138,7 +138,8 @@ $(objpfx)test-iconvconfig.out: $(objpfx)iconvconfig - rm -f $$tmp) > $@; \ - $(evaluate-test) - --$(objpfx)tst-iconv_prog.out: tst-iconv_prog.sh $(objpfx)iconv_prog -+$(objpfx)tst-iconv_prog.out: tst-iconv_prog.sh $(objpfx)iconv_prog \ -+ $(gen-locales) - $(BASH) $< $(common-objdir) '$(test-wrapper-env)' \ - '$(run-program-env)' > $@; \ - $(evaluate-test) -diff --git a/iconv/loop.c b/iconv/loop.c -index 1378d23147..74b2a3e26d 100644 ---- a/iconv/loop.c -+++ b/iconv/loop.c -@@ -144,8 +144,10 @@ - if (irreversible == NULL) \ - { \ - /* This means we are in call from __gconv_transliterate. In this \ -- case we are not doing any error recovery ourselves. */ \ -- result = __gconv_mark_illegal_input (step_data); \ -+ case we are not doing any error recovery ourselves. Do not create \ -+ a persistent error state. If __gconv_transliterate exhausts all \ -+ alternatives, it will call __gconv_mark_illegal_input itself. */ \ -+ result = __GCONV_ILLEGAL_INPUT; \ - break; \ - } \ - \ -diff --git a/iconv/tst-iconv_prog.sh b/iconv/tst-iconv_prog.sh -index e2a43280d2..7d7948b7aa 100644 ---- a/iconv/tst-iconv_prog.sh -+++ b/iconv/tst-iconv_prog.sh -@@ -27,10 +27,10 @@ LIBPATH=$codir:$codir/iconvdata - - # How the start the iconv(1) program. $from is not defined/expanded yet. - ICONV=' -+$test_wrapper_env $run_program_env - $codir/elf/ld.so --library-path $LIBPATH --inhibit-rpath ${from}.so - $codir/iconv/iconv_prog - ' --ICONV="$test_wrapper_env $run_program_env $ICONV" - - TIMEOUTFACTOR=${TIMEOUTFACTOR:-1} - -@@ -218,6 +218,7 @@ testarray=( - "\x00\x00;;INVALID;UTF-8;1" - "\x00\x00;;UTF-8;INVALID;1" - "\xc3\xa9;;UTF-8;ASCII//TRANSLIT;0" -+"X\xc2\xbdY;;UTF-8;ASCII//TRANSLIT;0" - ) - - # Requires $twobyte input, $c flag, $from, and $to to be set; sets $ret -@@ -278,12 +279,21 @@ check_errtest_result () - fi - } - --for testcommand in "${testarray[@]}"; do -- twobyte="$(echo "$testcommand" | cut -d";" -f 1)" -- c="$(echo "$testcommand" | cut -d";" -f 2)" -- from="$(echo "$testcommand" | cut -d";" -f 3)" -- to="$(echo "$testcommand" | cut -d";" -f 4)" -- eret="$(echo "$testcommand" | cut -d";" -f 5)" -- execute_test -- check_errtest_result --done -+run_test_array () -+{ -+ for testcommand in "${testarray[@]}"; do -+ twobyte="$(echo "$testcommand" | cut -d";" -f 1)" -+ c="$(echo "$testcommand" | cut -d";" -f 2)" -+ from="$(echo "$testcommand" | cut -d";" -f 3)" -+ to="$(echo "$testcommand" | cut -d";" -f 4)" -+ eret="$(echo "$testcommand" | cut -d";" -f 5)" -+ execute_test -+ check_errtest_result -+ done -+} -+ -+echo "info: testing C locale" -+run_test_array -+echo "info: testing en_US.UTF-8 locale" -+run_program_env="$run_program_env LC_ALL=en_US.UTF-8" -+run_test_array - -commit f6713070c6accac5c93d96c1d580833afacde3f5 -Author: Adhemerval Zanella -Date: Wed May 13 08:32:24 2026 -0300 - - arm: Save/restore VFP registers in PLT trampolines (BZ 34144, BZ 15792) - - _dl_runtime_resolve and _dl_runtime_profile only preserved the integer - argument registers (r0-r3) across the inner call to _dl_fixup / - _dl_profile_fixup. Two related ABI requirements demand more: - - * Under AAPCS-VFP, d0-d7 hold the caller's double arguments to the - function being resolved. Recent GCC emits VFP instructions inside - the fixup routines, clobbering them, so the resolved function sees - corrupted arguments (BZ 34144). - - * Per RTABI32, the __aeabi_mem* helpers (and similar runtime helpers - reachable through the dynamic linker) must only corrupt integer - core registers. IFUNC resolvers, audit modules, and interposed - malloc invoked during symbol resolution may also use VFP, even on - softfp ABI builds (BZ 15792). - - Save all call-clobbered VFP state -- d0-d15 unconditionally, d16-d31 - when HWCAP_ARM_VFPD32 is set, and fpscr -- around the inner fixup - call. Whether VFP is usable is a property of the hardware, not of - the ABI glibc was built with, so the decision is gated on AT_HWCAP at - runtime in both hardfp and softfp builds; hardfp builds will always - find HWCAP_ARM_VFP set, while softfp builds running on a non-VFP CPU - correctly skip the save. - - For _dl_runtime_profile the save area is slipped in just before the - bl to _dl_profile_fixup; the outgoing framesizep argument is - recomputed to account for the extra frame, and both the fast path - (no audit framesize) and the slow path (audit wraps with - pltenter/pltexit) traverse the restore before splitting. - - Checked on arm-linux-gnueabihf. - - Tested-by: Aurelien Jarno - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 1111fbdd3e7ebed402800bc23e67055eaae0d972) - -diff --git a/sysdeps/arm/Makefile b/sysdeps/arm/Makefile -index 9c4fd6b236..be9e46aeeb 100644 ---- a/sysdeps/arm/Makefile -+++ b/sysdeps/arm/Makefile -@@ -30,6 +30,25 @@ $(objpfx)tst-armtlsdescloc: $(objpfx)tst-armtlsdesclocmod.so - $(objpfx)tst-armtlsdescextnow: $(objpfx)tst-armtlsdescextnowmod.so - $(objpfx)tst-armtlsdescextlazy: $(objpfx)tst-armtlsdescextlazymod.so - endif -+ -+tests += \ -+ tst-bz34144 \ -+ tst-bz34144-audit \ -+ # tests -+modules-names += \ -+ tst-bz34144-auditmod \ -+ tst-bz34144-mod \ -+ # modules-names -+$(objpfx)tst-bz34144: $(objpfx)tst-bz34144-mod.so -+$(objpfx)tst-bz34144-audit: $(objpfx)tst-bz34144-mod.so -+$(objpfx)tst-bz34144-audit.out: $(objpfx)tst-bz34144-auditmod.so -+# Use lazy binding to check if _dl_runtime_resolve correctly save/restore -+# the VFP state. -+LDFLAGS-tst-bz34144 = -Wl,-z,lazy -+# With LD_AUDIT, lazy resolution goes through _dl_runtime_profile, which -+# must also save/restore VFP state (BZ 34144). -+LDFLAGS-tst-bz34144-audit = -Wl,-z,lazy -+tst-bz34144-audit-ENV = LD_AUDIT=$(objpfx)tst-bz34144-auditmod.so - endif - endif - -diff --git a/sysdeps/arm/dl-trampoline.S b/sysdeps/arm/dl-trampoline.S -index fffac55050..ef358d48bc 100644 ---- a/sysdeps/arm/dl-trampoline.S -+++ b/sysdeps/arm/dl-trampoline.S -@@ -20,6 +20,7 @@ - #define NO_THUMB - #include - #include -+#include - - .text - .globl _dl_runtime_resolve -@@ -36,13 +37,40 @@ _dl_runtime_resolve: - @ ip contains &GOT[n+3] (pointer to function) - @ lr points to &GOT[2] - -- @ Save arguments. We save r4 to realign the stack. -+ @ Save arguments. We save r4 to realign the stack and to hold -+ @ the hwcap value used to decide whether to save VFP registers. - push {r0-r4} - cfi_adjust_cfa_offset (20) - cfi_rel_offset (r0, 0) - cfi_rel_offset (r1, 4) - cfi_rel_offset (r2, 8) - cfi_rel_offset (r3, 12) -+ cfi_rel_offset (r4, 16) -+ -+#ifdef SHARED -+ @ Preserve all call-clobbered VFP registers across _dl_fixup. -+ @ VFP may be used by IFUNC resolvers, audit modules, interposed -+ @ malloc, and the __aeabi_mem* helpers required by RTABI32, -+ @ which mandates that those helpers only corrupt integer core -+ @ registers. -+ LDR_GLOBAL (r4, r3, C_SYMBOL_NAME(_rtld_global_ro), \ -+ RTLD_GLOBAL_RO_DL_HWCAP_OFFSET) -+ -+ tst r4, #HWCAP_ARM_VFP -+ beq .Lno_vfp_save -+ -+# define VFP_STACK_REQ (32*8 + 8) -+ sub sp, sp, VFP_STACK_REQ -+ cfi_adjust_cfa_offset (VFP_STACK_REQ) -+ mov r3, sp -+ .inst 0xeca30b20 @ vstmia r3!, {d0-d15} -+ tst r4, #HWCAP_ARM_VFPD32 -+ beq 1f -+ .inst 0xece30b20 @ vstmia r3!, {d16-d31} -+1: .inst 0xeef12a10 @ vmrs r2, fpscr -+ str r2, [r3] -+.Lno_vfp_save: -+#endif /* SHARED */ - - @ get pointer to linker struct - ldr r0, [lr, #-4] -@@ -59,8 +87,23 @@ _dl_runtime_resolve: - @ save the return - mov ip, r0 - -- @ get arguments and return address back. We restore r4 -- @ only to realign the stack. -+#ifdef SHARED -+ tst r4, #HWCAP_ARM_VFP -+ beq .Lno_vfp_restore -+ mov r3, sp -+ .inst 0xecb30b20 @ vldmia r3!, {d0-d15} -+ tst r4, #HWCAP_ARM_VFPD32 -+ beq 2f -+ .inst 0xecf30b20 @ vldmia r3!, {d16-d31} -+2: ldr r2, [r3] -+ .inst 0xeee12a10 @ vmsr fpscr, r2 -+ add sp, sp, VFP_STACK_REQ -+ cfi_adjust_cfa_offset (-VFP_STACK_REQ) -+.Lno_vfp_restore: -+#endif /* SHARED */ -+ -+ @ get arguments and return address back. We restore r4 to -+ @ its original value as well. - pop {r0-r4,lr} - cfi_adjust_cfa_offset (-24) - -@@ -124,14 +167,71 @@ _dl_runtime_profile: - add r3, sp, #8 - stmia r3!, {r0,r1} - -+ @ Preserve all call-clobbered VFP registers across -+ @ _dl_profile_fixup. See the matching comment in -+ @ _dl_runtime_resolve above for the rationale (BZ 34144, -+ @ BZ 15792). -+ @ -+ @ Stack layout below the current sp (which becomes the new sp -+ @ after the sub): -+ @ sp + 0 .. 3: outgoing arg (framesizep) for _dl_profile_fixup -+ @ sp + 4 .. 7: saved hwcap (so we can test it after the call) -+ @ sp + 8 .. 11: saved r2 (used as scratch for LDR_GLOBAL) -+ @ sp + 12 .. 15: padding (for 8-byte alignment of the VFP area) -+ @ sp + 16 .. 16+VFP_STACK_REQ-1: VFP regs + fpscr -+#define VFP_PROFILE_STACK (16 + VFP_STACK_REQ) -+ sub sp, sp, #VFP_PROFILE_STACK -+ cfi_adjust_cfa_offset (VFP_PROFILE_STACK) -+ -+ @ r2 holds the retaddr (3rd arg to _dl_profile_fixup); spill -+ @ it so we can use it as the LDR_GLOBAL destination. -+ str r2, [sp, #8] -+ -+ LDR_GLOBAL (r2, ip, C_SYMBOL_NAME(_rtld_global_ro), \ -+ RTLD_GLOBAL_RO_DL_HWCAP_OFFSET) -+ str r2, [sp, #4] -+ -+ tst r2, #HWCAP_ARM_VFP -+ beq .Lprofile_no_vfp_save -+ add ip, sp, #16 -+ .inst 0xecac0b20 @ vstmia ip!, {d0-d15} -+ tst r2, #HWCAP_ARM_VFPD32 -+ beq 7f -+ .inst 0xecec0b20 @ vstmia ip!, {d16-d31} -+7: .inst 0xeef12a10 @ vmrs r2, fpscr -+ str r2, [ip] -+.Lprofile_no_vfp_save: -+ -+ @ Restore r2 (retaddr) for _dl_profile_fixup. -+ ldr r2, [sp, #8] -+ - @ Set up extra args for _dl_profile_fixup. -- @ r2 and r3 are already loaded. -- add ip, sp, #208 -+ @ The framesize slot is at the old sp+208, which is the new -+ @ sp + VFP_PROFILE_STACK + 208 -- compute in two steps because -+ @ the combined offset is not encodable as an ARM immediate. -+ add ip, sp, #VFP_PROFILE_STACK -+ add ip, ip, #208 - str ip, [sp, #0] - - @ call profiling fixup routine - bl _dl_profile_fixup - -+ @ Restore VFP registers. r0 holds the resolved function -+ @ address; r1/r2/ip are caller-saved by the call. -+ ldr r1, [sp, #4] -+ tst r1, #HWCAP_ARM_VFP -+ beq .Lprofile_no_vfp_restore -+ add ip, sp, #16 -+ .inst 0xecbc0b20 @ vldmia ip!, {d0-d15} -+ tst r1, #HWCAP_ARM_VFPD32 -+ beq 8f -+ .inst 0xecfc0b20 @ vldmia ip!, {d16-d31} -+8: ldr r2, [ip] -+ .inst 0xeee12a10 @ vmsr fpscr, r2 -+.Lprofile_no_vfp_restore: -+ add sp, sp, #VFP_PROFILE_STACK -+ cfi_adjust_cfa_offset (-VFP_PROFILE_STACK) -+ - @ The address to call is now in r0. - - @ Check whether we're wrapping this function. -diff --git a/sysdeps/arm/tst-bz34144-audit.c b/sysdeps/arm/tst-bz34144-audit.c -new file mode 100644 -index 0000000000..8f1084fa0a ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144-audit.c -@@ -0,0 +1,32 @@ -+/* Test that lazy PLT resolution via _dl_runtime_profile preserves -+ caller-saved VFP registers used to pass double arguments (BZ 34144). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+extern void test_float_args (double a, double b, double c, double d, -+ double e, double f, double g, double h); -+ -+static int -+do_test (void) -+{ -+ test_float_args (2.0, 3.0, 4.0, 5.0, 6.0, 7.0, 8.0, 9.0); -+ return 0; -+} -+ -+#include -diff --git a/sysdeps/arm/tst-bz34144-auditmod.c b/sysdeps/arm/tst-bz34144-auditmod.c -new file mode 100644 -index 0000000000..ada9f126c2 ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144-auditmod.c -@@ -0,0 +1,50 @@ -+/* Minimal audit module used by tst-bz34144-audit to force PLT calls -+ to go through _dl_runtime_profile instead of _dl_runtime_resolve. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+unsigned int -+la_version (unsigned int v) -+{ -+ return v; -+} -+ -+unsigned int -+la_objopen (struct link_map *l, Lmid_t lmid, uintptr_t *cookie) -+{ -+ return LA_FLG_BINDFROM | LA_FLG_BINDTO; -+} -+ -+uintptr_t -+la_symbind32 (Elf32_Sym *sym, unsigned int ndx, uintptr_t *refcook, -+ uintptr_t *defcook, unsigned int *flags, const char *symname) -+{ -+ return sym->st_value; -+} -+ -+Elf32_Addr -+la_arm_gnu_pltenter (Elf32_Sym *sym, unsigned int ndx, uintptr_t *refcook, -+ uintptr_t *defcook, La_arm_regs *regs, -+ unsigned int *flags, const char *symname, -+ long int *framesizep) -+{ -+ return sym->st_value; -+} -diff --git a/sysdeps/arm/tst-bz34144-mod.c b/sysdeps/arm/tst-bz34144-mod.c -new file mode 100644 -index 0000000000..be6b54bf91 ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144-mod.c -@@ -0,0 +1,28 @@ -+/* DSO used by tst-bz34144. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+void -+test_float_args (double a, double b, double c, double d, -+ double e, double f, double g, double h) -+{ -+ if (a != 2.0 || b != 3.0 || c != 4.0 || d != 5.0 -+ || e != 6.0 || f != 7.0 || g != 8.0 || h != 9.0) -+ abort (); -+} -diff --git a/sysdeps/arm/tst-bz34144.c b/sysdeps/arm/tst-bz34144.c -new file mode 100644 -index 0000000000..61e41b3945 ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144.c -@@ -0,0 +1,32 @@ -+/* Test that lazy PLT resolution preserves caller-saved VFP registers -+ used to pass double arguments (BZ 34144). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+extern void test_float_args (double a, double b, double c, double d, -+ double e, double f, double g, double h); -+ -+static int -+do_test (void) -+{ -+ test_float_args (2.0, 3.0, 4.0, 5.0, 6.0, 7.0, 8.0, 9.0); -+ return 0; -+} -+ -+#include - -commit 0be5a6a72a4a3132bc211720d2b6949a84f54dc3 -Author: John David Anglin -Date: Tue Jun 23 13:41:10 2026 -0400 - - hppa: Fix missing call to __feraiseexcept (BZ 34306) - - The feupdateenv function is supposed to raise exceptions after - installing the environment represented by its envp argument. - This was accidentally missed on hppa. - - The failure to raise exceptions was noticed by the failure of - the math/test-narrowing-trap test. - - Signed-off-by: John David Anglin - -diff --git a/sysdeps/hppa/fpu/feupdateenv.c b/sysdeps/hppa/fpu/feupdateenv.c -index 46b83cc7a0..a3d3de33e4 100644 ---- a/sysdeps/hppa/fpu/feupdateenv.c -+++ b/sysdeps/hppa/fpu/feupdateenv.c -@@ -24,6 +24,7 @@ __feupdateenv (const fenv_t *envp) - { - union { unsigned long long l; unsigned int sw[2]; } s; - fenv_t temp; -+ - /* Get the current exception status */ - __asm__ ("fstd %%fr0,0(%1) \n\t" - "fldd 0(%1),%%fr0 \n\t" -@@ -46,6 +47,10 @@ __feupdateenv (const fenv_t *envp) - - /* Install new environment. */ - __fesetenv (&temp); -+ -+ /* Raise exceptions. */ -+ __feraiseexcept (temp.__status_word >> 27); -+ - /* Success. */ - return 0; - } - -commit 54929540335ef339ac66a8c28e3f4c22ebae2630 -Author: Fabian Rast -Date: Thu Jun 11 14:30:37 2026 +0200 - - rtld: cache cpuid results on the stack for intel - - dl_init_cacheinfo retrieves various information about cache - sizes, using the cpuid instruction on x86. - Previously, the same cpuid leaves were queried multiple times. - This behavior caused intel_check_word to prominently show up in - profiles of dynamic loader startup on the Intel(R) Xeon(R) Gold 6430. - The big performance impact could not be reproduced on other Intel cpus. - - This patch reduces the number of cpuid queries on startup - by caching their results on the stack for reuse when searching for a - different cache size value. - This approach does not change the overall design of - the cache enumeration code (repeated calls to handle_* functions). - The values are cached on the stack instead of globally (e.g. - in the cpu_features global) because they are never needed after - early initialization. - - The cache is only active for Intel cpus, because it has not yet - been shown through benchmarks that it meaningfully improves performance - for other processors. - - Signed-off-by: Fabian Rast - Reviewed-by: Sunil K Pandey - (cherry picked from commit df83fa8813eb53dcb232462a4f6dd00c873115f0) - -diff --git a/sysdeps/x86/dl-cacheinfo.h b/sysdeps/x86/dl-cacheinfo.h -index 6f9bb08a19..201d3ad278 100644 ---- a/sysdeps/x86/dl-cacheinfo.h -+++ b/sysdeps/x86/dl-cacheinfo.h -@@ -98,6 +98,15 @@ static const struct intel_02_cache_info - - #define nintel_02_known (sizeof (intel_02_known) / sizeof (intel_02_known [0])) - -+/* Cache for redundant cpuid queries in handle_intel, intel_check_word and -+ get_common_cache_info. Currently, this has only been shown to significantly -+ improve performance on a specific Intel CPU (Xeon 6430). */ -+struct intel_cpuid_cache -+{ -+ unsigned char leaf2_valid, leaf4_valid; /* Number of cached (sub)leaves. */ -+ unsigned int leaf2[4], leaf4[0x10][4]; -+}; -+ - static int - intel_02_known_compare (const void *p1, const void *p2) - { -@@ -118,7 +127,8 @@ static long int - __attribute__ ((noinline)) - intel_check_word (int name, unsigned int value, bool *has_level_2, - bool *no_level_2_or_3, -- const struct cpu_features *cpu_features) -+ const struct cpu_features *cpu_features, -+ struct intel_cpuid_cache *cache) - { - if ((value & 0x80000000) != 0) - /* The register value is reserved. */ -@@ -152,7 +162,21 @@ intel_check_word (int name, unsigned int value, bool *has_level_2, - unsigned int round = 0; - while (1) - { -- __cpuid_count (4, round, eax, ebx, ecx, edx); -+ if (round < cache->leaf4_valid) -+ /* Subleaf was queried before. Do not execute cpuid again. */ -+ eax = cache->leaf4[round][0], ebx = cache->leaf4[round][1], -+ ecx = cache->leaf4[round][2], edx = cache->leaf4[round][3]; -+ else if (round == cache->leaf4_valid -+ && round < sizeof(cache->leaf4)/sizeof(*cache->leaf4)) -+ { -+ /* Cache the cpuid result if we have space. */ -+ __cpuid_count (4, round, eax, ebx, ecx, edx); -+ cache->leaf4[round][0] = eax, cache->leaf4[round][1] = ebx; -+ cache->leaf4[round][2] = ecx, cache->leaf4[round][3] = edx; -+ cache->leaf4_valid++; -+ } -+ else -+ __cpuid_count (4, round, eax, ebx, ecx, edx); - - enum { null = 0, data = 1, inst = 2, uni = 3 } type = eax & 0x1f; - if (type == null) -@@ -247,7 +271,8 @@ intel_check_word (int name, unsigned int value, bool *has_level_2, - - - static long int __attribute__ ((noinline)) --handle_intel (int name, const struct cpu_features *cpu_features) -+handle_intel (int name, const struct cpu_features *cpu_features, -+ struct intel_cpuid_cache *cache) - { - unsigned int maxidx = cpu_features->basic.max_cpuid; - -@@ -260,41 +285,33 @@ handle_intel (int name, const struct cpu_features *cpu_features) - long int result = 0; - bool no_level_2_or_3 = false; - bool has_level_2 = false; -- unsigned int eax; -- unsigned int ebx; -- unsigned int ecx; -- unsigned int edx; -- __cpuid (2, eax, ebx, ecx, edx); -+ int i; -+ -+ if (!cache->leaf2_valid) -+ { -+ __cpuid (2, cache->leaf2[0], cache->leaf2[1], -+ cache->leaf2[2], cache->leaf2[3]); -+ cache->leaf2_valid = 1; -+ } - - /* The low byte of EAX of CPUID leaf 2 should always return 1 and it - should be ignored. If it isn't 1, use CPUID leaf 4 instead. */ -- if ((eax & 0xff) != 1) -+ if ((cache->leaf2[0] & 0xff) != 1) - return intel_check_word (name, 0xff, &has_level_2, &no_level_2_or_3, -- cpu_features); -- else -- { -- eax &= 0xffffff00; -- -- /* Process the individual registers' value. */ -- result = intel_check_word (name, eax, &has_level_2, -- &no_level_2_or_3, cpu_features); -- if (result != 0) -- return result; -+ cpu_features, cache); - -- result = intel_check_word (name, ebx, &has_level_2, -- &no_level_2_or_3, cpu_features); -- if (result != 0) -- return result; -- -- result = intel_check_word (name, ecx, &has_level_2, -- &no_level_2_or_3, cpu_features); -- if (result != 0) -- return result; -+ /* Process all descriptors in leaf 2. */ -+ result = intel_check_word (name, cache->leaf2[0]&0xffffff00, &has_level_2, -+ &no_level_2_or_3, cpu_features, cache); -+ if (result != 0) -+ return result; - -- result = intel_check_word (name, edx, &has_level_2, -- &no_level_2_or_3, cpu_features); -+ for (i = 1; i < 4; i++) -+ { -+ result = intel_check_word (name, cache->leaf2[i], &has_level_2, -+ &no_level_2_or_3, cpu_features, cache); - if (result != 0) -- return result; -+ return result; - } - - if (name >= _SC_LEVEL2_CACHE_SIZE && name <= _SC_LEVEL3_CACHE_LINESIZE -@@ -611,7 +628,7 @@ handle_hygon (int name) - - static void - get_common_cache_info (long int *shared_ptr, long int * shared_per_thread_ptr, unsigned int *threads_ptr, -- long int core) -+ long int core, struct intel_cpuid_cache *cache) - { - unsigned int eax; - unsigned int ebx; -@@ -669,7 +686,14 @@ get_common_cache_info (long int *shared_ptr, long int * shared_per_thread_ptr, u - int check = 0x1 | (threads_l3 == 0) << 1; - do - { -- __cpuid_count (4, i++, eax, ebx, ecx, edx); -+ if (cache != NULL && i < cache->leaf4_valid) -+ eax = cache->leaf4[i][0], ebx = cache->leaf4[i][1], -+ ecx = cache->leaf4[i][2], edx = cache->leaf4[i][3]; -+ else -+ /* Do not attempt to cache queries at this point, -+ because get_common_cache_info is called last. */ -+ __cpuid_count (4, i, eax, ebx, ecx, edx); -+ i++; - - /* There seems to be a bug in at least some Pentium Ds - which sometimes fail to iterate all cache parameters. -@@ -849,35 +873,38 @@ dl_init_cacheinfo (struct cpu_features *cpu_features) - - if (cpu_features->basic.kind == arch_kind_intel) - { -- data = handle_intel (_SC_LEVEL1_DCACHE_SIZE, cpu_features); -- shared = handle_intel (_SC_LEVEL3_CACHE_SIZE, cpu_features); -+ struct intel_cpuid_cache cache; -+ cache.leaf2_valid = cache.leaf4_valid = 0; -+ -+ data = handle_intel (_SC_LEVEL1_DCACHE_SIZE, cpu_features, &cache); -+ shared = handle_intel (_SC_LEVEL3_CACHE_SIZE, cpu_features, &cache); - shared_per_thread = shared; - - level1_icache_size -- = handle_intel (_SC_LEVEL1_ICACHE_SIZE, cpu_features); -+ = handle_intel (_SC_LEVEL1_ICACHE_SIZE, cpu_features, &cache); - level1_icache_linesize -- = handle_intel (_SC_LEVEL1_ICACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL1_ICACHE_LINESIZE, cpu_features, &cache); - level1_dcache_size = data; - level1_dcache_assoc -- = handle_intel (_SC_LEVEL1_DCACHE_ASSOC, cpu_features); -+ = handle_intel (_SC_LEVEL1_DCACHE_ASSOC, cpu_features, &cache); - level1_dcache_linesize -- = handle_intel (_SC_LEVEL1_DCACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL1_DCACHE_LINESIZE, cpu_features, &cache); - level2_cache_size -- = handle_intel (_SC_LEVEL2_CACHE_SIZE, cpu_features); -+ = handle_intel (_SC_LEVEL2_CACHE_SIZE, cpu_features, &cache); - level2_cache_assoc -- = handle_intel (_SC_LEVEL2_CACHE_ASSOC, cpu_features); -+ = handle_intel (_SC_LEVEL2_CACHE_ASSOC, cpu_features, &cache); - level2_cache_linesize -- = handle_intel (_SC_LEVEL2_CACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL2_CACHE_LINESIZE, cpu_features, &cache); - level3_cache_size = shared; - level3_cache_assoc -- = handle_intel (_SC_LEVEL3_CACHE_ASSOC, cpu_features); -+ = handle_intel (_SC_LEVEL3_CACHE_ASSOC, cpu_features, &cache); - level3_cache_linesize -- = handle_intel (_SC_LEVEL3_CACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL3_CACHE_LINESIZE, cpu_features, &cache); - level4_cache_size -- = handle_intel (_SC_LEVEL4_CACHE_SIZE, cpu_features); -+ = handle_intel (_SC_LEVEL4_CACHE_SIZE, cpu_features, &cache); - - get_common_cache_info (&shared, &shared_per_thread, &threads, -- level2_cache_size); -+ level2_cache_size, &cache); - } - else if (cpu_features->basic.kind == arch_kind_zhaoxin) - { -@@ -898,7 +925,7 @@ dl_init_cacheinfo (struct cpu_features *cpu_features) - level3_cache_linesize = handle_zhaoxin (_SC_LEVEL3_CACHE_LINESIZE); - - get_common_cache_info (&shared, &shared_per_thread, &threads, -- level2_cache_size); -+ level2_cache_size, NULL); - } - else if (cpu_features->basic.kind == arch_kind_amd) - { - -commit f2f55eac9e6f1167486f2694dea88adf87c77fdd -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Declare __p_class_syms, __p_type_syms for internal use - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 360f352c9a6da545d798ef3015e73ca114f0d230) - -diff --git a/include/resolv.h b/include/resolv.h -index 4dbbac3800..d5ad9994b9 100644 ---- a/include/resolv.h -+++ b/include/resolv.h -@@ -70,6 +70,11 @@ libc_hidden_proto (__libc_res_nameinquery) - extern __typeof (__res_queriesmatch) __libc_res_queriesmatch; - libc_hidden_proto (__libc_res_queriesmatch) - -+extern const struct res_sym __p_class_syms[]; -+libresolv_hidden_proto (__p_class_syms) -+extern const struct res_sym __p_type_syms[]; -+libresolv_hidden_proto (__p_type_syms) -+ - /* Variant of res_hnok which operates on binary (but uncompressed) names. */ - bool __res_binary_hnok (const unsigned char *dn) attribute_hidden; - -diff --git a/resolv/res_debug.c b/resolv/res_debug.c -index 73af0c72fe..6bf9962916 100644 ---- a/resolv/res_debug.c -+++ b/resolv/res_debug.c -@@ -390,8 +390,6 @@ p_fqname(const u_char *cp, const u_char *msg, FILE *file) { - * that C_ANY is a qclass but not a class. (You can ask for records of class - * C_ANY, but you can't have any records of that class in the database.) - */ --extern const struct res_sym __p_class_syms[]; --libresolv_hidden_proto (__p_class_syms) - const struct res_sym __p_class_syms[] = { - {C_IN, (char *) "IN"}, - {C_CHAOS, (char *) "CHAOS"}, -@@ -426,8 +424,6 @@ const struct res_sym __p_update_section_syms[] attribute_hidden = { - * Names of RR types and qtypes. The list is incomplete because its - * size is part of the ABI. - */ --extern const struct res_sym __p_type_syms[]; --libresolv_hidden_proto (__p_type_syms) - const struct res_sym __p_type_syms[] = { - {ns_t_a, (char *) "A", (char *) "address"}, - {ns_t_ns, (char *) "NS", (char *) "name server"}, - -commit 3c27e5170c456a69807348de8586c123f62a51f6 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Fix ns_sprintrrf formatting of class, type values (bug 34289) - - The p_class and p_type results could overwrite each other if both - were unknown. Format unknown values with CLASS and TYPE prefixes, - as in RFC 3597. Handle A6 separately because it cannot be added - to __p_type_syms for ABI reasons. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit f69b7f95e3694177546faec25d88bb266885c3b8) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index cef2212fd2..e75c39eaa8 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -78,6 +78,24 @@ ns_sprintrr(const ns_msg *handle, const ns_rr *rr, - } - libresolv_hidden_def (ns_sprintrr) - -+/* Writes the class/type symbol NUMBER to *BUF, using the name from -+ *SYMS if possible. If NUMBER is not found in *SYMS, print the -+ number with PREFIX. */ -+static int -+addsym (const struct res_sym *syms, int number, const char *prefix, -+ char **buf, size_t *buflen) -+{ -+ for (; syms->name != NULL; syms++) -+ if (number == syms->number) -+ { -+ T (addstr (" ", 1, buf, buflen)); -+ return addstr (syms->name, strlen (syms->name), buf, buflen); -+ } -+ char tmp[20]; -+ int len = snprintf (tmp, sizeof (tmp), " %s%d", prefix, number); -+ return addstr (tmp, len, buf, buflen); -+} -+ - /*% - * Convert the fields of an RR into presentation format. - * -@@ -128,11 +146,21 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - /* - * TTL, Class, Type. - */ -- T(x = ns_format_ttl(ttl, buf, buflen)); -- addlen(x, &buf, &buflen); -- len = SPRINTF((tmp, " %s %s", p_class(class), p_type(type))); -- T(addstr(tmp, len, &buf, &buflen)); -- T(spaced = addtab(x + len, 16, spaced, &buf, &buflen)); -+ { -+ char *start = buf; -+ -+ T (x = ns_format_ttl (ttl, buf, buflen)); -+ addlen (x, &buf, &buflen); -+ T (addsym (__p_class_syms, class, "CLASS", &buf, &buflen)); -+ if (type == ns_t_a6) -+ /* A6 is not part of __p_type_syms, which is exported. -+ Adding A6 there would change its size. Handle it here. */ -+ T (addstr (" A6", 3, &buf, &buflen)); -+ else -+ T (addsym (__p_type_syms, type, "TYPE", &buf, &buflen)); -+ -+ T (spaced = addtab(buf - start, 16, spaced, &buf, &buflen)); -+ } - - /* - * RData. - -commit 509d819cea20f5d6c615eed1f869cc930effd9d2 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Improve formatting of unknown records in ns_sprintrrf - - Do not add the "unknown RR type" comment. After adding the TYPE - prefix, the number is largely redundant. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit d58415eb17d457a160af99f9e8ab164404ca151b) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index e75c39eaa8..3d38876483 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -115,7 +115,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - - const char *comment; - char tmp[100]; -- char errbuf[40]; - int len, x; - - /* -@@ -590,20 +589,18 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - T(addstr(tmp, len, &buf, &buflen)); - break; - } -- - default: -- snprintf (errbuf, sizeof (errbuf), "unknown RR type %d", type); -- comment = errbuf; -+ comment = ""; - goto hexify; - } - return (buf - obuf); - formerr: -- comment = "RR format error"; -+ comment = " ; RR format error"; - hexify: { - int n, m; - char *p; - -- len = SPRINTF((tmp, "\\# %u%s\t; %s", (unsigned)(edata - rdata), -+ len = SPRINTF((tmp, "\\# %u%s%s", (unsigned)(edata - rdata), - rdlen != 0U ? " (" : "", comment)); - T(addstr(tmp, len, &buf, &buflen)); - while (rdata < edata) { - -commit 05dc6da0b4e12dbc60d3705e4961b823d3f7026d -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Check for inet_ntop failure in ns_sprintrrf - - This makes the output more consistent (either failure or complete - output) and helps with systematic testing with varying buffer - sizes. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit cd0db208d56a2cecd528b8ae96df752ba5344d9a) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index 3d38876483..e58df5f35a 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -167,8 +167,9 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - switch (type) { - case ns_t_a: - if (rdlen != (size_t)NS_INADDRSZ) -- goto formerr; -- (void) inet_ntop(AF_INET, rdata, buf, buflen); -+ goto formerr; -+ if (inet_ntop (AF_INET, rdata, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - break; - -@@ -334,9 +335,10 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - } - - case ns_t_aaaa: -- if (rdlen != (size_t)NS_IN6ADDRSZ) -- goto formerr; -- (void) inet_ntop(AF_INET6, rdata, buf, buflen); -+ if (rdlen != (size_t)NS_IN6ADDRSZ) -+ goto formerr; -+ if (inet_ntop (AF_INET6, rdata, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - break; - -@@ -427,7 +429,8 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - goto formerr; - - /* Address. */ -- (void) inet_ntop(AF_INET, rdata, buf, buflen); -+ if (inet_ntop (AF_INET, rdata, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - rdata += NS_INADDRSZ; - -@@ -569,7 +572,8 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - if (rdata + pbyte >= edata) goto formerr; - memset(&a, 0, sizeof(a)); - memcpy(&a.s6_addr[pbyte], rdata, sizeof(a) - pbyte); -- (void) inet_ntop(AF_INET6, &a, buf, buflen); -+ if (inet_ntop (AF_INET6, &a, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - rdata += sizeof(a) - pbyte; - } - -commit 299e1d25c32c5f9ef78ddd6cbfd0c6a09a1f4227 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435) - - Specifically, CERT, TKEY, TSIG, OPT. This removes the buggy - implementations of TSIG, fixing bug 34033, and partially - fixing bug 34069. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit ca44a6609c29a683b03575fa035c6d17aa591e72) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index e58df5f35a..ab68bf2cb7 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -464,96 +464,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - break; - } - -- case ns_t_cert: { -- u_int c_type, key_tag, alg; -- int n; -- unsigned int siz; -- char base64_cert[8192], tmp[40]; -- const char *leader; -- -- c_type = ns_get16(rdata); rdata += NS_INT16SZ; -- key_tag = ns_get16(rdata); rdata += NS_INT16SZ; -- alg = (u_int) *rdata++; -- -- len = SPRINTF((tmp, "%d %d %d ", c_type, key_tag, alg)); -- T(addstr(tmp, len, &buf, &buflen)); -- siz = (edata-rdata)*4/3 + 4; /* "+4" accounts for trailing \0 */ -- if (siz > sizeof(base64_cert) * 3/4) { -- const char *str = "record too long to print"; -- T(addstr(str, strlen(str), &buf, &buflen)); -- } -- else { -- len = b64_ntop(rdata, edata-rdata, base64_cert, siz); -- -- if (len < 0) -- goto formerr; -- else if (len > 15) { -- T(addstr(" (", 2, &buf, &buflen)); -- leader = "\n\t\t"; -- spaced = 0; -- } -- else -- leader = " "; -- -- for (n = 0; n < len; n += 48) { -- T(addstr(leader, strlen(leader), -- &buf, &buflen)); -- T(addstr(base64_cert + n, MIN(len - n, 48), -- &buf, &buflen)); -- } -- if (len > 15) -- T(addstr(" )", 2, &buf, &buflen)); -- } -- break; -- } -- -- case ns_t_tkey: { -- /* KJD - need to complete this */ -- u_long t; -- int mode, err, keysize; -- -- /* Algorithm name. */ -- T(addname(msg, msglen, &rdata, origin, &buf, &buflen)); -- T(addstr(" ", 1, &buf, &buflen)); -- -- /* Inception. */ -- t = ns_get32(rdata); rdata += NS_INT32SZ; -- len = SPRINTF((tmp, "%lu ", t)); -- T(addstr(tmp, len, &buf, &buflen)); -- -- /* Expiration. */ -- t = ns_get32(rdata); rdata += NS_INT32SZ; -- len = SPRINTF((tmp, "%lu ", t)); -- T(addstr(tmp, len, &buf, &buflen)); -- -- /* Mode , Error, Key Size. */ -- /* Priority, Weight, Port. */ -- mode = ns_get16(rdata); rdata += NS_INT16SZ; -- err = ns_get16(rdata); rdata += NS_INT16SZ; -- keysize = ns_get16(rdata); rdata += NS_INT16SZ; -- len = SPRINTF((tmp, "%u %u %u ", mode, err, keysize)); -- T(addstr(tmp, len, &buf, &buflen)); -- -- /* XXX need to dump key, print otherdata length & other data */ -- break; -- } -- -- case ns_t_tsig: { -- /* BEW - need to complete this */ -- int n; -- -- T(len = addname(msg, msglen, &rdata, origin, &buf, &buflen)); -- T(addstr(" ", 1, &buf, &buflen)); -- rdata += 8; /*%< time */ -- n = ns_get16(rdata); rdata += INT16SZ; -- rdata += n; /*%< sig */ -- n = ns_get16(rdata); rdata += INT16SZ; /*%< original id */ -- sprintf(buf, "%d", ns_get16(rdata)); -- rdata += INT16SZ; -- addlen(strlen(buf), &buf, &buflen); -- break; -- } -- - case ns_t_a6: { - struct in6_addr a; - int pbyte, pbit; -@@ -588,11 +498,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - break; - } - -- case ns_t_opt: { -- len = SPRINTF((tmp, "%u bytes", class)); -- T(addstr(tmp, len, &buf, &buflen)); -- break; -- } - default: - comment = ""; - goto hexify; - -commit cb4c62448047c043981deea84e5e01eccf8b36d4 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Fix buffer overreads in ns_sprintrrf (CVE-2026-6238) - - Check that the RDATA payload does not require more than RDATALEN - bytes while processing it. The fixes cover A6, LOC records. - (CERT, TKEY, TSIG were fixed before, by switching to the generic - formatter.) - - The vulnerable LOC record handling was first introduced before - glibc 2.0, in commit ee188d555b8c32ad9704a7440cab400af967292f. - - CERT, TSIG, TKEY handling came with commit - b43b13ac2544b11f35be301d1589b51a8473e32b, released with glibc 2.2. - - A6 record handling was introduced in commit - 91633816430e7ec5a19fe3ff510a7c4822a9557e ("* resolv/ns_print.c - (ns_sprintrrf): Handle ns_t_a6 and ns_t_opt."), which went into glibc - 2.7. - - This fixes bug 34069. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit a7b60d23bbb56eaef59f4962e4140062e552600a) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index ab68bf2cb7..f9dd086804 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -345,7 +345,8 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - case ns_t_loc: { - char t[255]; - -- /* XXX protocol format checking? */ -+ if (rdlen != 16) -+ goto formerr; - (void) loc_ntoa(rdata, t); - T(addstr(t, strlen(t), &buf, &buflen)); - break; -@@ -479,13 +480,14 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - - /* address suffix: provided only when prefix len != 128 */ - if (pbit < 128) { -- if (rdata + pbyte >= edata) goto formerr; -+ unsigned int bytelen = sizeof(a) - pbyte; -+ if (edata - rdata < bytelen) goto formerr; - memset(&a, 0, sizeof(a)); -- memcpy(&a.s6_addr[pbyte], rdata, sizeof(a) - pbyte); -+ memcpy(&a.s6_addr[pbyte], rdata, bytelen); - if (inet_ntop (AF_INET6, &a, buf, buflen) == NULL) - return -1; - addlen(strlen(buf), &buf, &buflen); -- rdata += sizeof(a) - pbyte; -+ rdata += bytelen; - } - - /* prefix name: provided only when prefix len > 0 */ - -commit 296fb7f4a2b35db13efef52609f8efc00291b2a8 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Add test case tst-ns_sprintrr (bug 34033, bug 34069) - - This test case covers both input buffer overreads and output buffer - overflows. It should systematically cover these issues. - - I used code auto-generation for updating the test expectations for - truncated RDATA in TXT, ISDN records, after writing the rest - of the test by hand. - - Assisted-by: LLM - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 4ba0b79b9596e5a4951cc9eaa1546a55e543e083) - -diff --git a/resolv/Makefile b/resolv/Makefile -index 088a22ea18..c6d73b411c 100644 ---- a/resolv/Makefile -+++ b/resolv/Makefile -@@ -98,6 +98,7 @@ tests += \ - tst-ns_name \ - tst-ns_name_compress \ - tst-ns_name_pton \ -+ tst-ns_sprintrr \ - tst-res_hconf_reorder \ - tst-res_hnok \ - tst-resolv-aliases \ -@@ -331,5 +332,6 @@ $(objpfx)tst-ns_name: $(objpfx)libresolv.so - $(objpfx)tst-ns_name.out: tst-ns_name.data - $(objpfx)tst-ns_name_compress: $(objpfx)libresolv.so - $(objpfx)tst-ns_name_pton: $(objpfx)libresolv.so -+$(objpfx)tst-ns_sprintrr: $(objpfx)libresolv.so - $(objpfx)tst-res_hnok: $(objpfx)libresolv.so - $(objpfx)tst-p_secstodate: $(objpfx)libresolv.so -diff --git a/resolv/tst-ns_sprintrr.c b/resolv/tst-ns_sprintrr.c -new file mode 100644 -index 0000000000..34739b5924 ---- /dev/null -+++ b/resolv/tst-ns_sprintrr.c -@@ -0,0 +1,329 @@ -+/* Tests for the ns_sprintrr function. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+#include -+ -+/* Regions that test_one_record uses for input and output. */ -+static struct support_next_to_fault ntf_in; -+static struct support_next_to_fault ntf_out; -+ -+/* This is used by test_one_record to construct the packet. */ -+static const char packet_prefix[] = -+ /* DNS response with one question, one answer record. */ -+ "AA\x81\x80\0\1\0\1\0\0\0\0" -+ /* Question: www.example.org/IN/ANY. */ -+ "\3www\7example\3org\0\0\xff\0\1" -+ /* Response: compression reference. */ -+ "\xc0\x0c"; -+ -+/* Use ns_sprintrr to format a DNS record (starting with -+ packet_prefix) of type RTYPE, with a record payload of RDATALEN -+ bytes starting at RDATA. Check successful formatting against -+ EXPECTED. Try various truncated input and output buffers to catch -+ overreads and buffer overflows, using ntf_in and ntf_out above. */ -+static void -+test_one_record (uint16_t rtype, const char *rdata, size_t rdatalen, -+ const char *expected) -+{ -+ struct rr_header -+ { -+ uint16_t typ; -+ uint16_t cls; -+ uint32_t ttl; -+ uint16_t rdatalen; -+ uint16_t pad; -+ } hdr = -+ { -+ .typ = htons (rtype), -+ .cls = htons (ns_c_in), -+ .ttl = htonl (86400), /* One day. */ -+ .rdatalen = htons (rdatalen), -+ }; -+ enum { hdrlen = offsetof (struct rr_header, pad) }; -+ TEST_COMPARE (hdrlen, 10); -+ -+ /* Construct the packet from packet_prefix, hdr, and rdata. */ -+ unsigned char packet[512]; -+ size_t packetlen; -+ { -+ struct alloc_buffer buf = alloc_buffer_create (packet, sizeof (packet)); -+ alloc_buffer_copy_bytes (&buf, packet_prefix, sizeof (packet_prefix) - 1); -+ alloc_buffer_copy_bytes (&buf, &hdr, hdrlen); -+ alloc_buffer_copy_bytes (&buf, rdata, rdatalen); -+ packetlen = sizeof (packet) - alloc_buffer_size (&buf); -+ } -+ -+ /* Parse the record. */ -+ ns_msg msg; -+ TEST_COMPARE (ns_initparse (packet, packetlen, &msg), 0); -+ ns_rr rr; -+ TEST_COMPARE (ns_parserr (&msg, ns_s_an, 0, &rr), 0); -+ -+ /* Try sizes up to this limit. Go a bit beyond the expected size to -+ check for errors. */ -+ size_t max_result_size = strlen (expected) + 16; -+ -+ bool success = false; -+ for (size_t result_size = 1; result_size <= max_result_size; ++result_size) -+ { -+ char *result_start = ntf_out.buffer + ntf_out.length - result_size; -+ memset (result_start, 'X', result_size); -+ -+ /* ns_sprintrr was deprecated in 2.34. */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wdeprecated-declarations"); -+ int ret = ns_sprintrr (&msg, &rr, NULL, NULL, result_start, result_size); -+ DIAG_POP_NEEDS_COMMENT; -+ -+ if (ret > 0) -+ { -+ TEST_COMPARE_STRING (result_start, expected); -+ TEST_COMPARE (ret, strlen (expected)); -+ success = true; -+ } -+ else -+ { -+ TEST_VERIFY (!success); -+ TEST_COMPARE (ret, -1); -+ } -+ } -+ TEST_VERIFY (success); -+ -+ /* Test with truncated RDATA. */ -+ for (size_t rdata_size = 0; rdata_size <= rdatalen; ++rdata_size) -+ { -+ size_t truncated_packet_size = packetlen - rdatalen + rdata_size; -+ unsigned char *packet_start -+ = ((unsigned char *) ntf_in.buffer + ntf_in.length -+ - truncated_packet_size); -+ memcpy (packet_start, packet, truncated_packet_size); -+ /* Patch in the updated RDATA length field. */ -+ uint16_t new_rdatalen = htons (rdata_size); -+ memcpy (packet_start + truncated_packet_size - rdata_size - 2, -+ &new_rdatalen, 2); -+ -+ ns_msg msg; -+ TEST_COMPARE (ns_initparse (packet_start, truncated_packet_size, &msg), -+ 0); -+ ns_rr rr; -+ TEST_COMPARE (ns_parserr (&msg, ns_s_an, 0, &rr), 0); -+ -+ size_t result_size = strlen (expected) + 1; -+ char *result_start = ntf_out.buffer + ntf_out.length - result_size; -+ memset (result_start, 'X', result_size); -+ -+ /* ns_sprintrr was deprecated in 2.34. */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wdeprecated-declarations"); -+ int ret = ns_sprintrr (&msg, &rr, NULL, NULL, result_start, result_size); -+ DIAG_POP_NEEDS_COMMENT; -+ -+ /* This flag indicates whether the output is syntactically -+ correct. In some cases, truncation may still yield a valid -+ payload. */ -+ bool broken = rdata_size < rdatalen; -+ switch (rtype) -+ { -+ case ns_t_wks: -+ /* WKS records use all trailing bytes for the port bitmap. */ -+ broken = rdata_size < 5; -+ break; -+ case ns_t_nsap: -+ /* Uses all bytes that are available. */ -+ broken = false; -+ break; -+ case ns_t_txt: -+ /* Truncation produces a valid payload if it occurs right -+ after a complete string in the TXT payload. */ -+ broken = false; -+ for (size_t pos = 0; pos < rdata_size; ) -+ { -+ unsigned int slen = rdata[pos] & 0xff; -+ if (pos + 1 + slen > rdata_size) -+ { -+ broken = true; -+ break; -+ } -+ pos += 1 + slen; -+ } -+ break; -+ case ns_t_isdn: -+ /* The second field is optional. If it is present, it must -+ not be truncated. */ -+ broken = rdata_size < 6 || (rdata_size > 6 && rdata_size < rdatalen); -+ break; -+ case ns_t_a6: -+ /* The first A6 subtest contains a trailing domain name, -+ which is ignored and not formatted. */ -+ if (rdata_size > 0 && rdata[0] == 0) -+ broken = rdata_size < 17; -+ break; -+ case ns_t_cert: -+ case ns_t_tkey: -+ case ns_t_tsig: -+ /* Only generic printing, which does not validate anything. */ -+ broken = false; -+ break; -+ } -+ -+ if (broken) -+ { -+ if (strstr (result_start, "RR format error") != NULL) -+ /* No further checks if an error indicator has been added -+ to the output. */ -+ ; -+ else -+ TEST_COMPARE (ret, -1); -+ } -+ else -+ TEST_VERIFY (ret > 0); -+ } -+} -+ -+static int -+do_test (void) -+{ -+ ntf_in = support_next_to_fault_allocate (512); -+ ntf_out = support_next_to_fault_allocate (256); -+ -+#define T(rtype, rdata, expected) \ -+ test_one_record (rtype, rdata, sizeof (rdata) - 1, expected) -+ T (ns_t_a, "\xc0\0\2\1", "www.example.org.\t1D IN A\t\t192.0.2.1"); -+ T (ns_t_cname, "\4www1\4prod\xc0\x10", -+ "www.example.org.\t1D IN CNAME\twww1.prod.example.org."); -+ T (ns_t_hinfo, "\5first\6second", -+ "www.example.org.\t1D IN HINFO\t\"first\" \"second\""); -+ T (ns_t_isdn, "\5first\6second", -+ "www.example.org.\t1D IN ISDN\t\"first\" \"second\""); -+ /* Bug: Extra space at the end in the text representation of ISDN RRs. */ -+ T (ns_t_isdn, "\5first", "www.example.org.\t1D IN ISDN\t\"first\" "); -+ T (ns_t_soa, -+ "\2ns\xc0\x10\12hostmaster\xc0\x10" -+ "\0\0\0\1\0\0\0\2\0\0\0\3\0\0\0\4\0\0\0\5", -+ "www.example.org.\t1D IN SOA\tns.example.org. hostmaster.example.org. (\n" -+ "\t\t\t\t\t1\t\t; serial\n" -+ "\t\t\t\t\t2S\t\t; refresh\n" -+ "\t\t\t\t\t3S\t\t; retry\n" -+ "\t\t\t\t\t4S\t\t; expiry\n" -+ "\t\t\t\t\t5S )\t\t; minimum\n"); -+ T (ns_t_mx, "\0\xa\2mx\xc0\x10", -+ "www.example.org.\t1D IN MX\t10 mx.example.org."); -+ T (ns_t_px, "\0\xa\3px1\xc0\x10\3px2\xc0\x10", -+ "www.example.org.\t1D IN PX\t10 px1.example.org. px2.example.org."); -+ T (ns_t_x25, "\4X.25", -+ "www.example.org.\t1D IN X25\t\"X.25\""); -+ T (ns_t_txt, "\1A\2BC\3DEF", -+ "www.example.org.\t1D IN TXT\t\"A\" \"BC\" \"DEF\""); -+ T (ns_t_nsap, "", -+ "www.example.org.\t1D IN NSAP\t"); -+ T (ns_t_nsap, "\1", -+ "www.example.org.\t1D IN NSAP\t01"); -+ T (ns_t_nsap, "\1\2", -+ "www.example.org.\t1D IN NSAP\t01.02"); -+ T (ns_t_nsap, "\1\2\3", -+ "www.example.org.\t1D IN NSAP\t01.0203"); -+ T (ns_t_nsap, "\1\2\3\4", -+ "www.example.org.\t1D IN NSAP\t01.0203.04"); -+ T (ns_t_nsap, -+ "\1\2\3\4\5\6\7\10\11\12\13\14\15\16\17\20\21\22\23\24\25\26\27\30\31\32" -+ "\33\34\35\36\37\40\41\42\43\44\45\46\47\50\51\52\53\54\55\56\57\60\61" -+ "\62\63\64\65\66\67\70\71\72\73\74\75\76\77\100\101\102\103\104\105\106" -+ "\107\110\111\112\113\114\115\116\117\120\121\122\123\124\125\126\127" -+ "\130\131\132\133\134\135\136\137\140\141\142\143\144\145\146\147\150" -+ "\151\152\153\154\155\156\157\160\161\162\163\164\165\166\167\170\171" -+ "\172\173\174\175\176\177\200\201\202\203\204\205\206\207\210\211\212" -+ "\213\214\215\216\217\220\221\222\223\224\225\226\227\230\231\232\233" -+ "\234\235\236\237\240\241\242\243\244\245\246\247\250\251\252\253\254" -+ "\255\256\257\260\261\262\263\264\265\266\267\270\271\272\273\274\275" -+ "\276\277\300\301\302\303\304\305\306\307\310\311\312\313\314\315\316" -+ "\317\320\321\322\323\324\325\326\327\330\331\332\333\334\335\336\337" -+ "\340\341\342\343\344\345\346\347\350\351\352\353\354\355\356\357\360" -+ "\361\362\363\364\365\366\367\370\371\372\373\374\375\376\377", -+ "www.example.org.\t1D IN NSAP\t" -+ "01.0203.0405.0607.0809.0A0B.0C0D.0E0F.1011.1213.1415.1617.1819.1A1B" -+ ".1C1D.1E1F.2021.2223.2425.2627.2829.2A2B.2C2D.2E2F.3031.3233.3435.3637" -+ ".3839.3A3B.3C3D.3E3F.4041.4243.4445.4647.4849.4A4B.4C4D.4E4F.5051.5253" -+ ".5455.5657.5859.5A5B.5C5D.5E5F.6061.6263.6465.6667.6869.6A6B.6C6D.6E6F" -+ ".7071.7273.7475.7677.7879.7A7B.7C7D.7E7F.8081.8283.8485.8687.8889.8A8B" -+ ".8C8D.8E8F.9091.9293.9495.9697.9899.9A9B.9C9D.9E9F.A0A1.A2A3.A4A5.A6A7" -+ ".A8A9.AAAB.ACAD.AEAF.B0B1.B2B3.B4B5.B6B7.B8B9.BABB.BCBD.BEBF.C0C1.C2C3" -+ ".C4C5.C6C7.C8C9.CACB.CCCD.CECF.D0D1.D2D3.D4D5.D6D7.D8D9.DADB.DCDD.DEDF" -+ ".E0E1.E2E3.E4E5.E6E7.E8E9.EAEB.ECED.EEEF.F0F1.F2F3.F4F5.F6F7.F8F9.FAFB" -+ ".FCFD.FEFF"); -+ T (ns_t_aaaa, "\x20\x01\x0d\xb8\0\0\0\0\0\0\0\0\0\0\x12\x34", -+ "www.example.org.\t1D IN AAAA\t2001:db8::1234"); -+ /* Example from RFC 1876. The loc_ntoa format is different from the -+ official text representation. */ -+ T (ns_t_loc, -+ "\000\063\026\023\211\027\055\320\160\276\025\360\000\230\215\040", -+ "www.example.org.\t1D IN LOC" -+ "\t42 21 54.000 N 71 06 18.000 W -24.00m 30.00m 10000.00m 10.00m"); -+ T (ns_t_naptr, -+ "\0\1\0\2\5flags\7service\2.*\5naptr\xc0\x10", -+ "www.example.org.\t1D IN NAPTR\t1 2 \"flags\" \"service\" \".*\"" -+ " naptr.example.org."); -+ T (ns_t_srv, -+ "\0\1\0\2\0\x50\4www1\xc0\x10", -+ "www.example.org.\t1D IN SRV\t1 2 80 www1.example.org."); -+ T (ns_t_rp, "\3rp1\xc0\x10\3rp2\xc0\x10", -+ "www.example.org.\t1D IN RP\trp1.example.org. rp2.example.org."); -+ T (ns_t_wks, "\xc0\0\2\1\6\0\0\0\0\0\0\0\0\0\0\200", -+ "www.example.org.\t1D IN WKS\t192.0.2.1 6 ( \n\t\t\t\t80 )"); -+ T (ns_t_cert, "\0\1\x04\xd2\0blob", -+ "www.example.org.\t1D IN CERT\t\\# 9 (\n" -+ "\t00 01 04 d2 00 62 6c 6f 62 )\t\t\t; .....blob"); -+ T (ns_t_tkey, "\4algo\0\0\0\0\1\0\0\0\2\0\3\0\4" -+ "\0\5\xa1\xa2\xa3\xa4\xa5\0\3\xb1\xb2\xb3", -+ "www.example.org.\t1D IN TYPE249\t\\# 30 (\n" -+ "\t04 61 6c 67 6f 00 00 00 00 01 00 00 00 02 00 03 ; .algo...........\n" -+ "\t00 04 00 05 a1 a2 a3 a4 a5 00 03 b1 b2 b3 )\t; .............."); -+ T (ns_t_tsig, "\4algo\0" -+ "\0\20\xdd\xcd\x64\x10\xe9\x21\x34\x1a\x8e\xe0\xa1\x9a\x30\xfc\x3b\xd1" -+ "\0\2\0\3\0\5other", -+ "www.example.org.\t1D IN TSIG\t\\# 35 (\n" -+ "\t04 61 6c 67 6f 00 00 10 dd cd 64 10 e9 21 34 1a ; .algo.....d..!4.\n" -+ "\t8e e0 a1 9a 30 fc 3b d1 00 02 00 03 00 05 6f 74 ; ....0.;.......ot\n" -+ "\t68 65 72 )\t\t\t\t\t; her"); -+ T (ns_t_a6, -+ "\0\x20\x01\x0d\xb8\0\0\0\0\0\0\0\0\0\0\x12\x34\6prefix\xc0\x10", -+ "www.example.org.\t1D IN A6\t0 2001:db8::1234"); -+ T (ns_t_a6, -+ "\0\x20\x01\x0d\xb8\0\0\0\0\0\0\0\0\0\0\x12\x35", -+ "www.example.org.\t1D IN A6\t0 2001:db8::1235"); -+ T (ns_t_a6, "\200\6prefix\xc0\x10", -+ "www.example.org.\t1D IN A6\t128 prefix.example.org."); -+ T (ns_t_a6, "\x20\0\0\0\0\0\0\0\0\0\0\x12\x36\6prefix\xc0\x10", -+ "www.example.org.\t1D IN A6\t32 ::1236 prefix.example.org."); -+#undef T -+ -+ support_next_to_fault_free (&ntf_in); -+ support_next_to_fault_free (&ntf_out); -+ return 0; -+} -+ -+#include - -commit 7414631f8aec8b9cee1a8311506e1fdcd9b94c0d -Author: Adhemerval Zanella -Date: Tue Apr 14 10:50:37 2026 -0300 - - posix: Fix stack overflow in wordexp tilde expansion (BZ 34091, CVE-2026-6791) - - The parse_tilde function previously used strndupa to allocate memory - for the parsed username on the stack, and since the input is - user-defined, this can lead to a stack overflow. - - This patch fixes the issue by replacing strndupa with scratch_buffer, - by reusing the buffer used in the __getpwnam_r call. - - The new “tst-wordexp-tilde.c” test is a test-container to avoid using - system-defined NSS modules. - - Checked on x86_64-linux-gnu and i686-linux-gnu. - - (cherry picked from commit 07c24f35392b727e6100d33edfdf811a6c68c218) - -diff --git a/posix/Makefile b/posix/Makefile -index 0b29c9aa4e..595c6b3ec2 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -356,6 +356,7 @@ tests-internal := \ - tests-container := \ - bug-ga2 \ - tst-vfork3 \ -+ tst-wordexp-tilde \ - # tests-container - - tests-time64 := \ -diff --git a/posix/tst-wordexp-tilde.c b/posix/tst-wordexp-tilde.c -new file mode 100644 -index 0000000000..1661603681 ---- /dev/null -+++ b/posix/tst-wordexp-tilde.c -@@ -0,0 +1,244 @@ -+/* Test wordexp tilde expansion with large usernames (BZ 34091). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+typedef void (*func_callback_t)(void); -+ -+static void -+subprocess_small_stack (void *closure) -+{ -+ struct rlimit rl; -+ TEST_COMPARE (getrlimit (RLIMIT_STACK, &rl), 0); -+ rl.rlim_cur = 512 * 1024; -+ TEST_COMPARE (setrlimit (RLIMIT_STACK, &rl), 0); -+ -+ func_callback_t func_test = closure; -+ func_test (); -+} -+ -+/* Build a string "~/tail" where is LEN bytes of the -+ character CH. The caller must free the result. */ -+static char * -+make_tilde_input (char ch, size_t len, const char *tail) -+{ -+ /* ~ + len + / + tail + \0 */ -+ size_t taillen = tail != NULL ? strlen (tail) : 0; -+ size_t total = 1 + len + 1 + taillen + 1; -+ char *buf = xmalloc (total); -+ buf[0] = '~'; -+ memset (buf + 1, ch, len); -+ buf[1 + len] = '/'; -+ if (tail != NULL) -+ memcpy (buf + 1 + len + 1, tail, taillen); -+ buf[total - 1] = '\0'; -+ return buf; -+} -+ -+/* Test 1: A very long username must not crash. The username will not match -+ any real user, so wordexp returns ~/rest. */ -+static void -+test_long_username (void) -+{ -+ printf ("info: test_long_username_no_crash\n"); -+ -+ static const char REST[] = "rest"; -+ -+ /* 1 MiB username — well beyond any reasonable stack frame. */ -+ const size_t long_len = 1024 * 1024; -+ char *input = make_tilde_input ('A', long_len, REST); -+ -+ wordexp_t we = { 0 }; -+ int ret = wordexp (input, &we, 0); -+ /* The (non-existent) username is invalid, so wordexp falls back to -+ literal output: ~AAA…/rest. */ -+ TEST_COMPARE (ret, 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ -+ /* Verify prefix: '~' followed by long_len 'A's. */ -+ const char *result = we.we_wordv[0]; -+ TEST_COMPARE (result[0], '~'); -+ TEST_COMPARE (strlen (result), -+ 1 /* ~ */ + long_len + sizeof (REST)); -+ for (size_t j = 1; j <= long_len; j++) -+ if (result[j] != 'A') -+ { -+ printf (" mismatch at position %zu: expected 'A', got '%c'\n", -+ j, result[j]); -+ support_record_failure (); -+ break; -+ } -+ /* Verify the tail after the username. */ -+ TEST_COMPARE_STRING (result + 1 + long_len, "/rest"); -+ -+ wordfree (&we); -+ free (input); -+} -+ -+/* Test 2: A username that just exceeds the default scratch_buffer inline -+ size (1024 bytes) exercises the scratch_buffer_set_array_size growth path -+ without being excessively large. */ -+static void -+test_scratch_buffer_growth (void) -+{ -+ printf ("info: test_scratch_buffer_growth\n"); -+ -+ const size_t len = 2048; -+ char *input = make_tilde_input ('x', len, NULL); -+ -+ wordexp_t we = { 0 }; -+ int ret = wordexp (input, &we, 0); -+ TEST_COMPARE (ret, 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ -+ /* ~xxx…/ — the trailing slash makes a separate empty component, but -+ wordexp merges it into the single token ~xxx…/. */ -+ const char *result = we.we_wordv[0]; -+ TEST_COMPARE (result[0], '~'); -+ for (size_t j = 1; j <= len; j++) -+ if (result[j] != 'x') -+ { -+ printf (" mismatch at position %zu\n", j); -+ support_record_failure (); -+ break; -+ } -+ TEST_COMPARE (result[1 + len], '/'); -+ -+ wordfree (&we); -+ free (input); -+} -+ -+/* Test 3: ~root still resolves to the correct home directory through the -+ __getpwnam_r path. */ -+static void -+test_known_user (void) -+{ -+ printf ("info: test_known_user\n"); -+ -+ /* Look up root's home directory for comparison. */ -+ struct passwd *pw = getpwnam ("root"); -+ if (pw == NULL || pw->pw_dir == NULL) -+ { -+ printf (" SKIP: cannot look up root\n"); -+ return; -+ } -+ -+ char *expected = xasprintf ("%s/file", pw->pw_dir); -+ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("~root/file", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ TEST_COMPARE_STRING (we.we_wordv[0], expected); -+ -+ wordfree (&we); -+ free (expected); -+} -+ -+/* Test 4: Bare tilde expands to $HOME. */ -+static void -+test_bare_tilde (void) -+{ -+ printf ("info: test_bare_tilde\n"); -+ -+ const char *home = getenv ("HOME"); -+ if (home == NULL) -+ { -+ printf (" SKIP: HOME is not set\n"); -+ return; -+ } -+ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("~", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ TEST_COMPARE_STRING (we.we_wordv[0], home); -+ -+ wordfree (&we); -+} -+ -+/* Test 5: Short non-existent username falls back to literal ~username output, -+ exercising the invalid-login-name path. */ -+static void -+test_unknown_user (void) -+{ -+ printf ("info: test_unknown_user\n"); -+ -+ /* Pick a username that is extremely unlikely to exist. */ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("~no_such_user_xyzzy42", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ TEST_COMPARE_STRING (we.we_wordv[0], "~no_such_user_xyzzy42"); -+ -+ wordfree (&we); -+} -+ -+/* Test 6: Tilde with username and WRDE_APPEND — exercises parse_tilde's -+ interaction with the WRDE_APPEND word list. */ -+static void -+test_tilde_with_append (void) -+{ -+ printf ("info: test_tilde_with_append\n"); -+ -+ const char *home = getenv ("HOME"); -+ if (home == NULL) -+ { -+ printf (" SKIP: HOME is not set\n"); -+ return; -+ } -+ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("first", &we, 0), 0); -+ -+ TEST_COMPARE (wordexp ("~/path", &we, WRDE_APPEND), 0); -+ TEST_COMPARE (we.we_wordc, 2); -+ TEST_COMPARE_STRING (we.we_wordv[0], "first"); -+ -+ char *expected = xasprintf ("%s/path", home); -+ TEST_COMPARE_STRING (we.we_wordv[1], expected); -+ -+ wordfree (&we); -+ free (expected); -+} -+ -+static int -+do_test (void) -+{ -+ test_known_user (); -+ test_bare_tilde (); -+ test_unknown_user (); -+ test_tilde_with_append (); -+ -+ support_isolate_in_subprocess (subprocess_small_stack, -+ test_long_username); -+ -+ support_isolate_in_subprocess (subprocess_small_stack, -+ test_scratch_buffer_growth); -+ -+ return 0; -+} -+ -+#include -diff --git a/posix/tst-wordexp-tilde.root/etc/group b/posix/tst-wordexp-tilde.root/etc/group -new file mode 100644 -index 0000000000..1dbf9013ee ---- /dev/null -+++ b/posix/tst-wordexp-tilde.root/etc/group -@@ -0,0 +1 @@ -+root:x:0: -diff --git a/posix/tst-wordexp-tilde.root/etc/nsswitch.conf b/posix/tst-wordexp-tilde.root/etc/nsswitch.conf -new file mode 100644 -index 0000000000..098a8d5938 ---- /dev/null -+++ b/posix/tst-wordexp-tilde.root/etc/nsswitch.conf -@@ -0,0 +1,3 @@ -+passwd: files -+group: files -+shadow: files -diff --git a/posix/tst-wordexp-tilde.root/etc/passwd b/posix/tst-wordexp-tilde.root/etc/passwd -new file mode 100644 -index 0000000000..eb85a552ad ---- /dev/null -+++ b/posix/tst-wordexp-tilde.root/etc/passwd -@@ -0,0 +1 @@ -+root:x:0:0:root:/root:/bin/sh -diff --git a/posix/wordexp.c b/posix/wordexp.c -index 9df4bb7424..731d1650e9 100644 ---- a/posix/wordexp.c -+++ b/posix/wordexp.c -@@ -335,17 +335,29 @@ parse_tilde (char **word, size_t *word_length, size_t *max_length, - else - { - /* Look up user name in database to get home directory */ -- char *user = strndupa (&words[1 + *offset], i - (1 + *offset)); -- struct passwd pwd, *tpwd; -- int result; -+ size_t userlen = i - (1 + *offset); -+ /* tmpbuf contains both the user and the __getpwnam_r working area. */ - struct scratch_buffer tmpbuf; - scratch_buffer_init (&tmpbuf); -+ if (!scratch_buffer_set_array_size (&tmpbuf, userlen + 1, 1)) -+ return WRDE_NOSPACE; -+ char *user = tmpbuf.data; -+ memcpy (user, &words[1 + *offset], userlen); -+ user[userlen] = '\0'; - -- while ((result = __getpwnam_r (user, &pwd, tmpbuf.data, tmpbuf.length, -+ struct passwd pwd, *tpwd; -+ int result; -+ while ((result = __getpwnam_r (user, -+ &pwd, -+ tmpbuf.data + userlen + 1, -+ tmpbuf.length - userlen - 1, - &tpwd)) != 0 - && errno == ERANGE) -- if (!scratch_buffer_grow (&tmpbuf)) -- return WRDE_NOSPACE; -+ { -+ if (!scratch_buffer_grow_preserve (&tmpbuf)) -+ return WRDE_NOSPACE; -+ user = tmpbuf.data; -+ } - - if (result == 0 && tpwd != NULL && pwd.pw_dir) - *word = w_addstr (*word, word_length, max_length, pwd.pw_dir); - -commit 8be3551ccb4e17e93ad82152de56d2c90de21f97 -Author: Adhemerval Zanella -Date: Mon Apr 13 16:33:30 2026 -0300 - - posix: Fix wordexp WRDE_APPEND to preserve state on non-NOSPACE errors (BZ 34090, CVE-2026-6368) - - The previous implementation saved a copy of the wordexp_t struct at - entry and blindly restored it on error via (*pwordexp = old_word). - This is incorrect when WRDE_APPEND is set because w_addword may have - called realloc on we_wordv during partial processing before the error - was detected. If realloc relocated the buffer, the saved we_wordv - pointer is dangling; restoring it causes a use-after-free in the - caller (e.g. via wordfree), and the relocated buffer is leaked. - - Fix this by duplicating the we_wordv pointer array at entry when - WRDE_APPEND is set, so that all subsequent realloc calls inside - w_addword operate on the copy. - - This change also fixes a POSIX conformance issue: if the WRDE_APPEND - flag is specified, pwordexp->we_wordc and pwordexp->we_wordv shall - not be modified. - - Also fix two pre-existing error return paths in the '"' and '\'' cases - that returned directly from w_addword failures instead of going through - do_error, which would leak the saved array (and previously would also - skip the word cleanup). - - Checked on x86_64-linux-gnu and i686-linux-gnu. - - Reviewed-by: DJ Delorie - (cherry picked from commit e2cefe16c37a617df9f11407cb00a272a6098823) - -diff --git a/posix/Makefile b/posix/Makefile -index 595c6b3ec2..a12c49c0ed 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -326,6 +326,7 @@ tests := \ - tst-wait3 \ - tst-wait4 \ - tst-waitid \ -+ tst-wordexp-append \ - tst-wordexp-nocmd \ - tst-wordexp-reuse \ - tstgetopt \ -diff --git a/posix/tst-wordexp-append.c b/posix/tst-wordexp-append.c -new file mode 100644 -index 0000000000..87f388f0a7 ---- /dev/null -+++ b/posix/tst-wordexp-append.c -@@ -0,0 +1,393 @@ -+/* Test for wordexp with WRDE_APPEND flag. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+ -+static unsigned int relocating_reallocs; -+ -+/* w_addword grows we_wordv with realloc, make every call guaranteed to -+ relocate the block. This makes BZ 34090 regression more deterministic. */ -+void * -+realloc (void *ptr, size_t size) -+{ -+ if (ptr == NULL) -+ return malloc (size); -+ if (size == 0) -+ { -+ free (ptr); -+ return NULL; -+ } -+ -+ void *new = malloc (size); -+ if (new == NULL) -+ return NULL; -+ -+ /* Copy only what is valid in the old block to avoid reading past it. */ -+ size_t old = malloc_usable_size (ptr); -+ memcpy (new, ptr, old < size ? old : size); -+ /* Clobber the old block so that a stale we_wordv pointer restored on the -+ error path reads garbage instead of the old contents, which might -+ otherwise survive intact and mask the bug. */ -+ memset (ptr, 0x5a, old); -+ free (ptr); -+ relocating_reallocs++; -+ return new; -+} -+ -+/* Verify that all words in we match the expected NULL-terminated -+ array. */ -+static void -+check_words (const wordexp_t *we, const char *const *expected) -+{ -+ size_t i; -+ for (i = 0; expected[i] != NULL; i++) -+ { -+ TEST_VERIFY (i < we->we_wordc); -+ TEST_COMPARE_STRING (we->we_wordv[we->we_offs + i], expected[i]); -+ } -+ TEST_COMPARE (we->we_wordc, i); -+} -+ -+#define CHECK_WORDS(we, ...) \ -+ do { \ -+ const char *const expected_[] = { __VA_ARGS__, NULL }; \ -+ check_words (we, expected_); \ -+ } while (0) -+ -+/* Test 1: WRDE_APPEND + WRDE_BADCHAR preserves we_wordc. */ -+static void -+test_append_badchar_preserves_count (void) -+{ -+ printf ("info: test_append_badchar_preserves_count\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("one two three", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 3); -+ -+ size_t saved_count = we.we_wordc; -+ -+ /* ')' triggers WRDE_BADCHAR and "extra" would be a new word if the -+ expansion succeeded, exercising the w_addword path before the error -+ is detected. */ -+ TEST_COMPARE (wordexp ("extra )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ -+ wordfree (&we); -+} -+ -+/* Test 2: WRDE_APPEND + WRDE_BADCHAR preserves the we_wordv pointer even -+ when internal realloc would move the buffer. */ -+static void -+test_append_badchar_preserves_pointer (void) -+{ -+ printf ("info: test_append_badchar_preserves_pointer\n"); -+ wordexp_t we = { 0 }; -+ -+ /* Use many words so that the initial we_wordv allocation is -+ non-trivial and a later realloc is more likely to move it. */ -+ TEST_COMPARE (wordexp ("a b c d e f g h", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 8); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ unsigned int saved_reallocs = relocating_reallocs; -+ -+ /* The interposed realloc guarantees the internal we_wordv buffer moves -+ during parsing, so the pointer-stability check below is meaningful. */ -+ TEST_COMPARE (wordexp ("append )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ /* Verify that a relocating realloc actually happened during the failed -+ call, otherwise the pointer-stability check is vacuous. */ -+ TEST_VERIFY (relocating_reallocs > saved_reallocs); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ -+ wordfree (&we); -+} -+ -+/* Test 3: After a failed WRDE_APPEND the original words are still accessible -+ and correct. */ -+static void -+test_append_badchar_words_intact (void) -+{ -+ printf ("info: test_append_badchar_words_intact\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("alpha beta gamma", &we, 0), 0); -+ CHECK_WORDS (&we, "alpha", "beta", "gamma"); -+ -+ TEST_COMPARE (wordexp ("delta )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ -+ /* Words must still be intact. */ -+ CHECK_WORDS (&we, "alpha", "beta", "gamma"); -+ /* The NULL terminator must still be present. */ -+ TEST_VERIFY (we.we_wordv[we.we_offs + we.we_wordc] == NULL); -+ -+ wordfree (&we); -+} -+ -+/* Test 4: Successful WRDE_APPEND still works (regression test). */ -+static void -+test_append_success (void) -+{ -+ printf ("info: test_append_success\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("hello", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ -+ char **saved_wordv = we.we_wordv; -+ -+ TEST_COMPARE (wordexp ("world", &we, WRDE_APPEND), 0); -+ TEST_COMPARE (we.we_wordc, 2); -+ /* A successful append works on a fresh copy of the array, so the -+ caller-visible pointer must have changed. */ -+ TEST_VERIFY (we.we_wordv != saved_wordv); -+ CHECK_WORDS (&we, "hello", "world"); -+ -+ wordfree (&we); -+} -+ -+/* Test 5: Successful append after a failed append — the implementation must -+ recover and allow further use of the wordexp_t. */ -+static void -+test_append_success_after_failure (void) -+{ -+ printf ("info: test_append_success_after_failure\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("first", &we, 0), 0); -+ CHECK_WORDS (&we, "first"); -+ -+ TEST_COMPARE (wordexp ("bad |", &we, WRDE_APPEND), WRDE_BADCHAR); -+ -+ /* State must be exactly as before the failed call. */ -+ CHECK_WORDS (&we, "first"); -+ -+ /* A subsequent successful append must work. */ -+ TEST_COMPARE (wordexp ("second third", &we, WRDE_APPEND), 0); -+ CHECK_WORDS (&we, "first", "second", "third"); -+ -+ wordfree (&we); -+} -+ -+/* Test 6: Multiple consecutive failed appends do not corrupt state. */ -+static void -+test_append_multiple_failures (void) -+{ -+ printf ("info: test_append_multiple_failures\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("keep this", &we, 0), 0); -+ CHECK_WORDS (&we, "keep", "this"); -+ -+ size_t saved_count = we.we_wordc; -+ char **saved_wordv = we.we_wordv; -+ -+ /* Each of these bad characters must leave the state unchanged. */ -+ TEST_COMPARE (wordexp ("x )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x |", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x ;", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x &", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x <", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x >", &we, WRDE_APPEND), WRDE_BADCHAR); -+ -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ CHECK_WORDS (&we, "keep", "this"); -+ -+ wordfree (&we); -+} -+ -+/* Test 7: WRDE_APPEND with WRDE_SYNTAX error (unterminated quote) also -+ preserves state. */ -+static void -+test_append_syntax_error (void) -+{ -+ printf ("info: test_append_syntax_error\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("original", &we, 0), 0); -+ CHECK_WORDS (&we, "original"); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ -+ /* Unterminated double quote triggers WRDE_SYNTAX. */ -+ TEST_COMPARE (wordexp ("\"unterminated", &we, WRDE_APPEND), WRDE_SYNTAX); -+ -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ CHECK_WORDS (&we, "original"); -+ -+ wordfree (&we); -+} -+ -+/* Test 8: Error without WRDE_APPEND still works (regression test for the -+ non-APPEND code path in do_error). */ -+static void -+test_no_append_error (void) -+{ -+ printf ("info: test_no_append_error\n"); -+ wordexp_t we = { 0 }; -+ -+ /* Simple failure without WRDE_APPEND. */ -+ TEST_COMPARE (wordexp ("bad |", &we, 0), WRDE_BADCHAR); -+ -+ /* After failure without WRDE_APPEND the struct should be safe to -+ reuse — start fresh. */ -+ TEST_COMPARE (wordexp ("ok", &we, 0), 0); -+ CHECK_WORDS (&we, "ok"); -+ -+ wordfree (&we); -+} -+ -+/* Test 9: WRDE_BADCHAR on the very first character (no partial words added -+ before the error). */ -+static void -+test_append_badchar_immediate (void) -+{ -+ printf ("info: test_append_badchar_immediate\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("hello world", &we, 0), 0); -+ CHECK_WORDS (&we, "hello", "world"); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ -+ /* The bad character is the very first byte — no w_addword call happens -+ before the error. */ -+ TEST_COMPARE (wordexp ("|", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ -+ wordfree (&we); -+} -+ -+/* Test 10: WRDE_APPEND into an empty wordexp_t (initial call uses WRDE_APPEND -+ with a zeroed struct — unusual but allowed). */ -+static void -+test_append_into_empty (void) -+{ -+ printf ("info: test_append_into_empty\n"); -+ wordexp_t we = { 0 }; -+ -+ /* First call with WRDE_APPEND on a zeroed struct. The implementation -+ must handle we_wordv == NULL gracefully. */ -+ TEST_COMPARE (wordexp ("solo", &we, WRDE_APPEND), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ CHECK_WORDS (&we, "solo"); -+ -+ wordfree (&we); -+} -+ -+/* Verify that the leading we_offs slots are all NULL. */ -+static void -+check_offs_null (const wordexp_t *we) -+{ -+ for (size_t i = 0; i < we->we_offs; i++) -+ TEST_VERIFY (we->we_wordv[i] == NULL); -+} -+ -+/* Test 11: successful WRDE_APPEND with WRDE_DOOFFS and a non-zero we_offs. -+ The leading offset slots must stay NULL and words must land at -+ we_wordv[we_offs + i] across both the initial and the appended call. */ -+static void -+test_dooffs_append_success (void) -+{ -+ printf ("info: test_dooffs_append_success\n"); -+ wordexp_t we = { 0 }; -+ we.we_offs = 2; -+ -+ TEST_COMPARE (wordexp ("one two", &we, WRDE_DOOFFS), 0); -+ TEST_COMPARE (we.we_offs, 2); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "one", "two"); -+ -+ TEST_COMPARE (wordexp ("three", &we, WRDE_APPEND | WRDE_DOOFFS), 0); -+ TEST_COMPARE (we.we_offs, 2); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "one", "two", "three"); -+ /* The NULL terminator must sit right after the last word. */ -+ TEST_VERIFY (we.we_wordv[we.we_offs + we.we_wordc] == NULL); -+ -+ wordfree (&we); -+} -+ -+/* Test 12: failed WRDE_APPEND with WRDE_DOOFFS preserves we_wordc, the -+ we_wordv pointer, the words and the leading NULL offset slots. This -+ exercises the we_offs arithmetic in the array duplication and in the -+ error-path cleanup (we_wordv[we_offs + --we_wordc]). */ -+static void -+test_dooffs_append_error_preserves_state (void) -+{ -+ printf ("info: test_dooffs_append_error_preserves_state\n"); -+ wordexp_t we = { 0 }; -+ we.we_offs = 3; -+ -+ TEST_COMPARE (wordexp ("alpha beta", &we, WRDE_DOOFFS), 0); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "alpha", "beta"); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ unsigned int saved_reallocs = relocating_reallocs; -+ -+ /* "gamma" is a partial word added via w_addword (forcing a relocating -+ realloc of we_wordv) before ')' triggers WRDE_BADCHAR. */ -+ TEST_COMPARE (wordexp ("gamma )", &we, WRDE_APPEND | WRDE_DOOFFS), -+ WRDE_BADCHAR); -+ TEST_VERIFY (relocating_reallocs > saved_reallocs); -+ -+ TEST_COMPARE (we.we_offs, 3); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "alpha", "beta"); -+ TEST_VERIFY (we.we_wordv[we.we_offs + we.we_wordc] == NULL); -+ -+ wordfree (&we); -+} -+ -+static int -+do_test (void) -+{ -+ test_append_badchar_preserves_count (); -+ test_append_badchar_preserves_pointer (); -+ test_append_badchar_words_intact (); -+ test_append_success (); -+ test_append_success_after_failure (); -+ test_append_multiple_failures (); -+ test_append_syntax_error (); -+ test_no_append_error (); -+ test_append_badchar_immediate (); -+ test_append_into_empty (); -+ test_dooffs_append_success (); -+ test_dooffs_append_error_preserves_state (); -+ -+ return 0; -+} -+ -+#include -diff --git a/posix/wordexp.c b/posix/wordexp.c -index 731d1650e9..50b0d7a256 100644 ---- a/posix/wordexp.c -+++ b/posix/wordexp.c -@@ -35,6 +35,7 @@ - #include - #include <_itoa.h> - #include -+#include - - /* - * This is a recursive-descent-style word expansion routine. -@@ -2224,6 +2225,12 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - char ifs_white[4]; - wordexp_t old_word = *pwordexp; - -+ /* When WRDE_APPEND is set we work on a copy of the we_wordv array so that -+ the caller's original pointer is never invalidated by realloc inside -+ w_addword. The saved_wordv keeps the original; on success we free it, -+ on non-NOSPACE error we free the working copy and restore the original. */ -+ char **saved_wordv = NULL; -+ - if (flags & WRDE_REUSE) - { - /* Minimal implementation of WRDE_REUSE for now */ -@@ -2258,6 +2265,23 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - pwordexp->we_offs = 0; - } - } -+ else if (pwordexp->we_wordv != NULL) -+ { -+ /* WRDE_APPEND with an existing word list: duplicate the array so that -+ realloc during parsing does not invalidate the caller's pointer. The -+ strings themselves are shared. */ -+ size_t num_p; -+ char **dup; -+ if (INT_ADD_WRAPV (pwordexp->we_offs, pwordexp->we_wordc, &num_p) -+ || INT_ADD_WRAPV (num_p, 1, &num_p)) -+ return WRDE_NOSPACE; -+ dup = __libc_reallocarray (NULL, num_p, sizeof *dup); -+ if (dup == NULL) -+ return WRDE_NOSPACE; -+ memcpy (dup, pwordexp->we_wordv, num_p * sizeof *dup); -+ saved_wordv = pwordexp->we_wordv; -+ pwordexp->we_wordv = dup; -+ } - - /* Find out what the field separators are. - * There are two types: whitespace and non-whitespace. -@@ -2338,7 +2362,7 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - error = w_addword (pwordexp, NULL); - - if (error) -- return error; -+ goto do_error; - } - - break; -@@ -2356,7 +2380,7 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - error = w_addword (pwordexp, NULL); - - if (error) -- return error; -+ goto do_error; - } - - break; -@@ -2422,10 +2446,18 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - - /* There was a word separator at the end */ - if (word == NULL) /* i.e. w_newword */ -- return 0; -+ { -+ free (saved_wordv); -+ return 0; -+ } - -- /* There was no field separator at the end */ -- return w_addword (pwordexp, word); -+ /* There was no field separator at the end. The only possible error -+ from w_addword is WRDE_NOSPACE. */ -+ error = w_addword (pwordexp, word); -+ if (error != 0) -+ goto do_error; -+ free (saved_wordv); -+ return 0; - - do_error: - /* Error: -@@ -2436,11 +2468,30 @@ do_error: - free (word); - - if (error == WRDE_NOSPACE) -- return WRDE_NOSPACE; -+ { -+ /* we_wordc and we_wordv are updated to reflect any words that were -+ successfully expanded. The old array is obsolete. */ -+ free (saved_wordv); -+ return WRDE_NOSPACE; -+ } - -- if ((flags & WRDE_APPEND) == 0) -- wordfree (pwordexp); -+ if (flags & WRDE_APPEND) -+ { -+ /* POSIX 2024 states that for in other error cases, if the WRDE_APPEND -+ flag was specified, we_wordc and we_wordv shall not be modified. -+ -+ Free strings appended during this call, discard the working copy of -+ we_wordv, and restore the caller's original pointer. */ -+ while (pwordexp->we_wordc > old_word.we_wordc) -+ free (pwordexp->we_wordv[pwordexp->we_offs + --pwordexp->we_wordc]); -+ free (pwordexp->we_wordv); -+ pwordexp->we_wordv = saved_wordv; -+ } -+ else -+ { -+ wordfree (pwordexp); -+ *pwordexp = old_word; -+ } - -- *pwordexp = old_word; - return error; - } diff --git a/pkgs/development/libraries/glibc/2.44-master.patch b/pkgs/development/libraries/glibc/2.44-master.patch new file mode 100644 index 000000000000..08c0e1da3143 --- /dev/null +++ b/pkgs/development/libraries/glibc/2.44-master.patch @@ -0,0 +1,4138 @@ +commit 5e5ddf57987ae4b37da5ca2fa039c8803b0be735 +Author: Andreas K. Hüttel +Date: Sat Jul 25 09:20:26 2026 +0900 + + advisories: replace with ADVISORIES text file + + Signed-off-by: Andreas K. Hüttel + +diff --git a/advisories/GLIBC-SA-2023-0001 b/advisories/GLIBC-SA-2023-0001 +deleted file mode 100644 +index 3d19c91b6a..0000000000 +--- a/advisories/GLIBC-SA-2023-0001 ++++ /dev/null +@@ -1,14 +0,0 @@ +-printf: incorrect output for integers with thousands separator and width field +- +-When the printf family of functions is called with a format specifier +-that uses an (enable grouping) and a minimum width +-specifier, the resulting output could be larger than reasonably expected +-by a caller that computed a tight bound on the buffer size. The +-resulting larger than expected output could result in a buffer overflow +-in the printf family of functions. +- +-CVE-Id: CVE-2023-25139 +-Public-Date: 2023-02-02 +-Vulnerable-Commit: e88b9f0e5cc50cab57a299dc7efe1a4eb385161d (2.37) +-Fix-Commit: c980549cc6a1c03c23cc2fe3e7b0fe626a0364b0 (2.38) +-Fix-Commit: 07b9521fc6369d000216b96562ff7c0ed32a16c4 (2.37-4) +diff --git a/advisories/GLIBC-SA-2023-0002 b/advisories/GLIBC-SA-2023-0002 +deleted file mode 100644 +index 5122669a64..0000000000 +--- a/advisories/GLIBC-SA-2023-0002 ++++ /dev/null +@@ -1,15 +0,0 @@ +-getaddrinfo: Stack read overflow in no-aaaa mode +- +-If the system is configured in no-aaaa mode via /etc/resolv.conf, +-getaddrinfo is called for the AF_UNSPEC address family, and a DNS +-response is received over TCP that is larger than 2048 bytes, +-getaddrinfo may potentially disclose stack contents via the returned +-address data, or crash. +- +-CVE-Id: CVE-2023-4527 +-Public-Date: 2023-09-12 +-Vulnerable-Commit: f282cdbe7f436c75864e5640a409a10485e9abb2 (2.36) +-Fix-Commit: bd77dd7e73e3530203be1c52c8a29d08270cb25d (2.39) +-Fix-Commit: 4ea972b7edd7e36610e8cde18bf7a8149d7bac4f (2.36-113) +-Fix-Commit: b7529346025a130fee483d42178b5c118da971bb (2.37-38) +-Fix-Commit: b25508dd774b617f99419bdc3cf2ace4560cd2d6 (2.38-19) +diff --git a/advisories/GLIBC-SA-2023-0003 b/advisories/GLIBC-SA-2023-0003 +deleted file mode 100644 +index d3aef80348..0000000000 +--- a/advisories/GLIBC-SA-2023-0003 ++++ /dev/null +@@ -1,15 +0,0 @@ +-getaddrinfo: Potential use-after-free +- +-When an NSS plugin only implements the _gethostbyname2_r and +-_getcanonname_r callbacks, getaddrinfo could use memory that was freed +-during buffer resizing, potentially causing a crash or read or write to +-arbitrary memory. +- +-CVE-Id: CVE-2023-4806 +-Public-Date: 2023-09-12 +-Fix-Commit: 973fe93a5675c42798b2161c6f29c01b0e243994 (2.39) +-Fix-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) +-Fix-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) +-Fix-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) +-Fix-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) +-Fix-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) +diff --git a/advisories/GLIBC-SA-2023-0004 b/advisories/GLIBC-SA-2023-0004 +deleted file mode 100644 +index 5286a7aa54..0000000000 +--- a/advisories/GLIBC-SA-2023-0004 ++++ /dev/null +@@ -1,16 +0,0 @@ +-tunables: local privilege escalation through buffer overflow +- +-If a tunable of the form NAME=NAME=VAL is passed in the environment of a +-setuid program and NAME is valid, it may result in a buffer overflow, +-which could be exploited to achieve escalated privileges. This flaw was +-introduced in glibc 2.34. +- +-CVE-Id: CVE-2023-4911 +-Public-Date: 2023-10-03 +-Vulnerable-Commit: 2ed18c5b534d9e92fc006202a5af0df6b72e7aca (2.34) +-Fix-Commit: 1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa (2.39) +-Fix-Commit: dcc367f148bc92e7f3778a125f7a416b093964d9 (2.34-423) +-Fix-Commit: c84018a05aec80f5ee6f682db0da1130b0196aef (2.35-274) +-Fix-Commit: 22955ad85186ee05834e47e665056148ca07699c (2.36-118) +-Fix-Commit: b4e23c75aea756b4bddc4abcf27a1c6dca8b6bd3 (2.37-45) +-Fix-Commit: 750a45a783906a19591fb8ff6b7841470f1f5701 (2.38-27) +diff --git a/advisories/GLIBC-SA-2023-0005 b/advisories/GLIBC-SA-2023-0005 +deleted file mode 100644 +index cc4eb90b82..0000000000 +--- a/advisories/GLIBC-SA-2023-0005 ++++ /dev/null +@@ -1,18 +0,0 @@ +-getaddrinfo: DoS due to memory leak +- +-The fix for CVE-2023-4806 introduced a memory leak when an application +-calls getaddrinfo for AF_INET6 with AI_CANONNAME, AI_ALL and AI_V4MAPPED +-flags set. +- +-CVE-Id: CVE-2023-5156 +-Public-Date: 2023-09-25 +-Vulnerable-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) +-Vulnerable-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) +-Vulnerable-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) +-Vulnerable-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) +-Vulnerable-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) +-Fix-Commit: 8006457ab7e1cd556b919f477348a96fe88f2e49 (2.34-421) +-Fix-Commit: 17092c0311f954e6f3c010f73ce3a78c24ac279a (2.35-272) +-Fix-Commit: 856bac55f98dc840e7c27cfa82262b933385de90 (2.36-116) +-Fix-Commit: 4473d1b87d04b25cdd0e0354814eeaa421328268 (2.37-42) +-Fix-Commit: 5ee59ca371b99984232d7584fe2b1a758b4421d3 (2.38-24) +diff --git a/advisories/GLIBC-SA-2024-0001 b/advisories/GLIBC-SA-2024-0001 +deleted file mode 100644 +index 28931c75ae..0000000000 +--- a/advisories/GLIBC-SA-2024-0001 ++++ /dev/null +@@ -1,15 +0,0 @@ +-syslog: Heap buffer overflow in __vsyslog_internal +- +-__vsyslog_internal did not handle a case where printing a SYSLOG_HEADER +-containing a long program name failed to update the required buffer +-size, leading to the allocation and overflow of a too-small buffer on +-the heap. +- +-CVE-Id: CVE-2023-6246 +-Public-Date: 2024-01-30 +-Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) +-Fix-Commit: 6bd0e4efcc78f3c0115e5ea9739a1642807450da (2.39) +-Fix-Commit: 23514c72b780f3da097ecf33a793b7ba9c2070d2 (2.38-42) +-Fix-Commit: 97a4292aa4a2642e251472b878d0ec4c46a0e59a (2.37-57) +-Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) +-Fix-Commit: d1a83b6767f68b3cb5b4b4ea2617254acd040c82 (2.36-126) +diff --git a/advisories/GLIBC-SA-2024-0002 b/advisories/GLIBC-SA-2024-0002 +deleted file mode 100644 +index 940bfcf2fc..0000000000 +--- a/advisories/GLIBC-SA-2024-0002 ++++ /dev/null +@@ -1,15 +0,0 @@ +-syslog: Heap buffer overflow in __vsyslog_internal +- +-__vsyslog_internal used the return value of snprintf/vsnprintf to +-calculate buffer sizes for memory allocation. If these functions (for +-any reason) failed and returned -1, the resulting buffer would be too +-small to hold output. +- +-CVE-Id: CVE-2023-6779 +-Public-Date: 2024-01-30 +-Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) +-Fix-Commit: 7e5a0c286da33159d47d0122007aac016f3e02cd (2.39) +-Fix-Commit: d0338312aace5bbfef85e03055e1212dd0e49578 (2.38-43) +-Fix-Commit: 67062eccd9a65d7fda9976a56aeaaf6c25a80214 (2.37-58) +-Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) +-Fix-Commit: 2bc9d7c002bdac38b5c2a3f11b78e309d7765b83 (2.36-127) +diff --git a/advisories/GLIBC-SA-2024-0003 b/advisories/GLIBC-SA-2024-0003 +deleted file mode 100644 +index b43a5150ab..0000000000 +--- a/advisories/GLIBC-SA-2024-0003 ++++ /dev/null +@@ -1,13 +0,0 @@ +-syslog: Integer overflow in __vsyslog_internal +- +-__vsyslog_internal calculated a buffer size by adding two integers, but +-did not first check if the addition would overflow. +- +-CVE-Id: CVE-2023-6780 +-Public-Date: 2024-01-30 +-Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) +-Fix-Commit: ddf542da94caf97ff43cc2875c88749880b7259b (2.39) +-Fix-Commit: d37c2b20a4787463d192b32041c3406c2bd91de0 (2.38-44) +-Fix-Commit: 2b58cba076e912961ceaa5fa58588e4b10f791c0 (2.37-59) +-Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) +-Fix-Commit: b9b7d6a27aa0632f334352fa400771115b3c69b7 (2.36-128) +diff --git a/advisories/GLIBC-SA-2024-0004 b/advisories/GLIBC-SA-2024-0004 +deleted file mode 100644 +index 08df2b3118..0000000000 +--- a/advisories/GLIBC-SA-2024-0004 ++++ /dev/null +@@ -1,28 +0,0 @@ +-ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence +- +-The iconv() function in the GNU C Library versions 2.39 and older may +-overflow the output buffer passed to it by up to 4 bytes when converting +-strings to the ISO-2022-CN-EXT character set, which may be used to +-crash an application or overwrite a neighbouring variable. +- +-ISO-2022-CN-EXT uses escape sequences to indicate character set changes +-(as specified by RFC 1922). While the SOdesignation has the expected +-bounds checks, neither SS2designation nor SS3designation have its; +-allowing a write overflow of 1, 2, or 3 bytes with fixed values: +-'$+I', '$+J', '$+K', '$+L', '$+M', or '$*H'. +- +-CVE-Id: CVE-2024-2961 +-Public-Date: 2024-04-17 +-Vulnerable-Commit: 755104edc75c53f4a0e7440334e944ad3c6b32fc (2.1.93-169) +-Fix-Commit: f9dc609e06b1136bb0408be9605ce7973a767ada (2.40) +-Fix-Commit: 31da30f23cddd36db29d5b6a1c7619361b271fb4 (2.39-31) +-Fix-Commit: e1135387deded5d73924f6ca20c72a35dc8e1bda (2.38-66) +-Fix-Commit: 89ce64b269a897a7780e4c73a7412016381c6ecf (2.37-89) +-Fix-Commit: 4ed98540a7fd19f458287e783ae59c41e64df7b5 (2.36-164) +-Fix-Commit: 36280d1ce5e245aabefb877fe4d3c6cff95dabfa (2.35-315) +-Fix-Commit: a8b0561db4b9847ebfbfec20075697d5492a363c (2.34-459) +-Fix-Commit: ed4f16ff6bed3037266f1fa682ebd32a18fce29c (2.33-263) +-Fix-Commit: 682ad4c8623e611a971839990ceef00346289cc9 (2.32-140) +-Fix-Commit: 3703c32a8d304c1ee12126134ce69be965f38000 (2.31-154) +- +-Reported-By: Charles Fol +diff --git a/advisories/GLIBC-SA-2024-0005 b/advisories/GLIBC-SA-2024-0005 +deleted file mode 100644 +index a59596610a..0000000000 +--- a/advisories/GLIBC-SA-2024-0005 ++++ /dev/null +@@ -1,22 +0,0 @@ +-nscd: Stack-based buffer overflow in netgroup cache +- +-If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted +-by client requests then a subsequent client request for netgroup data +-may result in a stack-based buffer overflow. This flaw was introduced +-in glibc 2.15 when the cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-CVE-Id: CVE-2024-33599 +-Public-Date: 2024-04-23 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: 69c58d5ef9f584ea198bd00f7964d364d0e6b921 (2.31-155) +-Fix-Commit: a77064893bfe8a701770e2f53a4d33805bc47a5a (2.32-141) +-Fix-Commit: 5c75001a96abcd50cbdb74df24c3f013188d076e (2.33-264) +-Fix-Commit: 52f73e5c4e29b14e79167272297977f360ae1e97 (2.34-460) +-Fix-Commit: 7a95873543ce225376faf13bb71c43dea6d24f86 (2.35-316) +-Fix-Commit: caa3151ca460bdd9330adeedd68c3112d97bffe4 (2.36-165) +-Fix-Commit: f75c298e747b2b8b41b1c2f551c011a52c41bfd1 (2.37-91) +-Fix-Commit: 5968aebb86164034b8f8421b4abab2f837a5bdaf (2.38-72) +-Fix-Commit: 1263d583d2e28afb8be53f8d6922f0842036f35d (2.39-35) +-Fix-Commit: 87801a8fd06db1d654eea3e4f7626ff476a9bdaa (2.40) +diff --git a/advisories/GLIBC-SA-2024-0006 b/advisories/GLIBC-SA-2024-0006 +deleted file mode 100644 +index d44148d3d9..0000000000 +--- a/advisories/GLIBC-SA-2024-0006 ++++ /dev/null +@@ -1,32 +0,0 @@ +-nscd: Null pointer crash after notfound response +- +-If the Name Service Cache Daemon's (nscd) cache fails to add a not-found +-netgroup response to the cache, the client request can result in a null +-pointer dereference. This flaw was introduced in glibc 2.15 when the +-cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-CVE-Id: CVE-2024-33600 +-Public-Date: 2024-04-24 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: b048a482f088e53144d26a61c390bed0210f49f2 (2.40) +-Fix-Commit: 7835b00dbce53c3c87bbbb1754a95fb5e58187aa (2.40) +-Fix-Commit: c99f886de54446cd4447db6b44be93dabbdc2f8b (2.39-37) +-Fix-Commit: 5a508e0b508c8ad53bd0d2fb48fd71b242626341 (2.39-36) +-Fix-Commit: 2ae9446c1b7a3064743b4a51c0bbae668ee43e4c (2.38-74) +-Fix-Commit: 541ea5172aa658c4bd5c6c6d6fd13903c3d5bb0a (2.38-73) +-Fix-Commit: a8070b31043c7585c36ba68a74298c4f7af075c3 (2.37-93) +-Fix-Commit: 5eea50c4402e39588de98aa1d4469a79774703d4 (2.37-92) +-Fix-Commit: f205b3af56740e3b014915b1bd3b162afe3407ef (2.36-167) +-Fix-Commit: c34f470a615b136170abd16142da5dd0c024f7d1 (2.36-166) +-Fix-Commit: bafadc589fbe21ae330e8c2af74db9da44a17660 (2.35-318) +-Fix-Commit: 4370bef52b0f3f3652c6aa13d7a9bb3ac079746d (2.35-317) +-Fix-Commit: 1f94122289a9bf7dba573f5d60327aaa2b85cf2e (2.34-462) +-Fix-Commit: 966d6ac9e40222b84bb21674cc4f83c8d72a5a26 (2.34-461) +-Fix-Commit: e3eef1b8fbdd3a7917af466ca9c4b7477251ca79 (2.33-266) +-Fix-Commit: f20a8d696b13c6261b52a6434899121f8b19d5a7 (2.33-265) +-Fix-Commit: be602180146de37582a3da3a0caa4b719645de9c (2.32-143) +-Fix-Commit: 394eae338199078b7961b051c191539870742d7b (2.32-142) +-Fix-Commit: 8d7949183760170c61e55def723c1d8050187874 (2.31-157) +-Fix-Commit: 304ce5fe466c4762b21b36c26926a4657b59b53e (2.31-156) +diff --git a/advisories/GLIBC-SA-2024-0007 b/advisories/GLIBC-SA-2024-0007 +deleted file mode 100644 +index b6928fa27a..0000000000 +--- a/advisories/GLIBC-SA-2024-0007 ++++ /dev/null +@@ -1,28 +0,0 @@ +-nscd: netgroup cache may terminate daemon on memory allocation failure +- +-The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or +-xrealloc and these functions may terminate the process due to a memory +-allocation failure resulting in a denial of service to the clients. The +-flaw was introduced in glibc 2.15 when the cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-Subsequent refactoring of the netgroup cache only added more uses of +-xmalloc and xrealloc. Uses of xmalloc and xrealloc in other parts of +-nscd only occur during startup of the daemon and so are not affected by +-client requests that could trigger an out of memory followed by +-termination. +- +-CVE-Id: CVE-2024-33601 +-Public-Date: 2024-04-24 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) +-Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) +-Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) +-Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) +-Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) +-Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) +-Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) +-Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) +-Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) +-Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) +diff --git a/advisories/GLIBC-SA-2024-0008 b/advisories/GLIBC-SA-2024-0008 +deleted file mode 100644 +index d93e2a6f0b..0000000000 +--- a/advisories/GLIBC-SA-2024-0008 ++++ /dev/null +@@ -1,26 +0,0 @@ +-nscd: netgroup cache assumes NSS callback uses in-buffer strings +- +-The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory +-when the NSS callback does not store all strings in the provided buffer. +-The flaw was introduced in glibc 2.15 when the cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-There is no guarantee from the NSS callback API that the returned +-strings are all within the buffer. However, the netgroup cache code +-assumes that the NSS callback uses in-buffer strings and if it doesn't +-the buffer resizing logic could lead to potential memory corruption. +- +-CVE-Id: CVE-2024-33602 +-Public-Date: 2024-04-24 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) +-Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) +-Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) +-Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) +-Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) +-Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) +-Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) +-Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) +-Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) +-Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) +diff --git a/advisories/GLIBC-SA-2025-0001 b/advisories/GLIBC-SA-2025-0001 +deleted file mode 100644 +index b053d32e91..0000000000 +--- a/advisories/GLIBC-SA-2025-0001 ++++ /dev/null +@@ -1,40 +0,0 @@ +-assert: Buffer overflow when printing assertion failure message +- +-When the assert() function fails, it does not allocate enough space for the +-assertion failure message string and size information, which may lead to a +-buffer overflow if the message string size aligns to page size. +- +-This bug can be triggered when an assertion in a program fails. The assertion +-failure message is allocated to allow developers to see this failure in core +-dumps and it typically includes, in addition to the invariant assertion +-string and function name, the name of the program. If the name of the failing +-program is user controlled, for example on a local system, this could allow an +-attacker to control the assertion failure to trigger this buffer overflow. +- +-The only viable vector for exploitation of this bug is local, if a setuid +-program exists that has an existing bug that results in an assertion failure. +-No such program has been discovered at the time of publishing this advisory, +-but the presence of custom setuid programs, although strongly discouraged as a +-security practice, cannot be discounted. +- +-CVE-Id: CVE-2025-0395 +-Public-Date: 2025-01-22 +-Vulnerable-Commit: f8a3b5bf8fa1d0c43d2458e03cc109a04fdef194 (2.13-175) +-Fix-Commit: 68ee0f704cb81e9ad0a78c644a83e1e9cd2ee578 (2.41) +-Fix-Commit: cdb9ba84191ce72e86346fb8b1d906e7cd930ea2 (2.42) +-Fix-Commit: 69fda28279b497bd405fdd442a6d8e4d3d5f681b (2.41-7) +-Fix-Commit: 7d4b6bcae91f29d7b4daf15bab06b66cf1d2217c (2.40-66) +-Fix-Commit: d6c156c326999f144cb5b73d29982108d549ad8a (2.40-71) +-Fix-Commit: 808a84a8b81468b517a4d721fdc62069cb8c211f (2.39-146) +-Fix-Commit: f6d48470aef9264d2d56f4c4533eb76db7f9c2e4 (2.39-150) +-Fix-Commit: c32fd59314c343db88c3ea4a203870481d33c3d2 (2.38-122) +-Fix-Commit: f984e2d7e8299726891a1a497a3c36cd5542a0bf (2.38-124) +-Fix-Commit: a3d7865b098a3a67c44f7812208d9ce4718873ba (2.37-143) +-Fix-Commit: b989519fe1683c204ac24ec92830e3fe3bfaccad (2.37-146) +-Fix-Commit: 7971add7ee4171fdd8dfd17e7c04c4ed77a18845 (2.36-216) +-Fix-Commit: 0487893d5c5bc6710d83d7c3152d888a0339559e (2.36-219) +-Fix-Commit: 8b5d4be762419c4f6176261c6fea40ac559b88dc (2.35-370) +-Fix-Commit: 8b3d09dc0d350191985f9d291cc30ce96f034b49 (2.35-373) +-Fix-Commit: df4e1f4a5096b385c9bcc94424cf2eaa227b3761 (2.34-500) +-Fix-Commit: 31eb872cb21449832ab47ad5db83281d240e1d03 (2.34-503) +-Reported-By: Qualys Security Advisory +diff --git a/advisories/GLIBC-SA-2025-0002 b/advisories/GLIBC-SA-2025-0002 +deleted file mode 100644 +index 161da13dd4..0000000000 +--- a/advisories/GLIBC-SA-2025-0002 ++++ /dev/null +@@ -1,23 +0,0 @@ +-elf: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH +- +-A statically linked setuid binary that calls dlopen (including internal +-dlopen calls after setlocale or calls to NSS functions such as getaddrinfo) +-may incorrectly search LD_LIBRARY_PATH to determine which library to load, +-leading to the execution of library code that is attacker controlled. +- +-The only viable vector for exploitation of this bug is local, if a static +-setuid program exists, and that program calls dlopen, then it may search +-LD_LIBRARY_PATH to locate the SONAME to load. No such program has been +-discovered at the time of publishing this advisory, but the presence of +-custom setuid programs, although strongly discouraged as a security +-practice, cannot be discounted. +- +-CVE-Id: CVE-2025-4802 +-Public-Date: 2025-05-16 +-Vulnerable-Commit: 10e93d968716ab82931d593bada121c17c0a4b93 (2.27) +-Fix-Commit: 5451fa962cd0a90a0e2ec1d8910a559ace02bba0 (2.39) +-Fix-Commit: 3be3728df2f1912c80abd3288bc6e3a25ad679e4 (2.38-132) +-Fix-Commit: 7403ede2d7752e59e0c47d5d33d73c2bf850e7be (2.37-154) +-Fix-Commit: 2ef7850279b2931caf6d6d6743ebaa91839e1cf7 (2.36-227) +-Fix-Commit: 621c65ccf12ddd415ceeb2234423bd1acd0fabb3 (2.35-387) +-Fix-Commit: 35018c0fd20eac9ceaf60060fed2745b3177359d (2.34-517) +diff --git a/advisories/GLIBC-SA-2025-0003 b/advisories/GLIBC-SA-2025-0003 +deleted file mode 100644 +index 2adeb3ce00..0000000000 +--- a/advisories/GLIBC-SA-2025-0003 ++++ /dev/null +@@ -1,30 +0,0 @@ +-power10: strcmp fails to save and restore nonvolatile vector registers +- +-The Power 10 implementation of strcmp in +-sysdeps/powerpc/powerpc64/le/power10/strcmp.S failed to save/restore +-nonvolatile vector registers in the 32-byte aligned loop path. This +-results in callers reading content from those registers in a different +-context, potentially altering program logic. +- +-There could be a program context where a user controlled string could +-leak through strcmp into program code, thus altering its logic. There +-is also a potential for sensitive strings passed into strcmp leaking +-through the clobbered registers into parts of the calling program that +-should otherwise not have had access to those strings. +- +-The impact of this flaw is limited to applications running on Power 10 +-hardware that use the nonvolatile vector registers, i.e. v20 to v31 +-assuming that they have been treated in accordance with the OpenPower +-psABI. It is possible to work around the issue for those specific +-applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like +-so: +- +- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 +- +-CVE-Id: CVE-2025-5702 +-Public-Date: 2025-06-04 +-Vulnerable-Commit: 3367d8e180848030d1646f088759f02b8dfe0d6f (2.39) +-Fix-Commit: 15808c77b35319e67ee0dc8f984a9a1a434701bc (2.42) +-Fix-Commit: 0c76c951620f9e12df2a89b2c684878b55bb6795 (2.41-60) +-Fix-Commit: 7e12550b8e3a11764a4a9090ce6bd3fc23fc8a8e (2.40-139) +-Fix-Commit: 06a70769fd0b2e1f2a3085ad50ab620282bd77b3 (2.39-209) +diff --git a/advisories/GLIBC-SA-2025-0004 b/advisories/GLIBC-SA-2025-0004 +deleted file mode 100644 +index 9409ca27c4..0000000000 +--- a/advisories/GLIBC-SA-2025-0004 ++++ /dev/null +@@ -1,29 +0,0 @@ +-power10: strncmp fails to save and restore nonvolatile vector registers +- +-The Power 10 implementation of strncmp in +-sysdeps/powerpc/powerpc64/le/power10/strncmp.S failed to save/restore +-nonvolatile vector registers in the 32-byte aligned loop path. This +-results in callers reading content from those registers in a different +-context, potentially altering program logic. +- +-There could be a program context where a user controlled string could +-leak through strncmp into program code, thus altering its logic. There +-is also a potential for sensitive strings passed into strncmp leaking +-through the clobbered registers into parts of the calling program that +-should otherwise not have had access to those strings. +- +-The impact of this flaw is limited to applications running on Power 10 +-hardware that use the nonvolatile vector registers, i.e. v20 to v31 +-assuming that they have been treated in accordance with the OpenPower +-psABI. It is possible to work around the issue for those specific +-applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like +-so: +- +- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 +- +-CVE-Id: CVE-2025-5745 +-Public-Date: 2025-06-05 +-Vulnerable-Commit: 23f0d81608d0ca6379894ef81670cf30af7fd081 (2.40) +-Fix-Commit: 63c60101ce7c5eac42be90f698ba02099b41b965 (2.42) +-Fix-Commit: 84bdbf8a6f2fdafd3661489dbb7f79835a52da82 (2.41-57) +-Fix-Commit: 42a5a940c974d02540c8da26d6374c744d148cb9 (2.40-136) +diff --git a/advisories/GLIBC-SA-2025-0005 b/advisories/GLIBC-SA-2025-0005 +deleted file mode 100644 +index 8bcccc59a5..0000000000 +--- a/advisories/GLIBC-SA-2025-0005 ++++ /dev/null +@@ -1,14 +0,0 @@ +-posix: Fix double-free after allocation failure in regcomp +- +-The regcomp function in the GNU C library version from 2.4 to 2.41 is +-subject to a double free if some previous allocation fails. It can be +-accomplished either by a malloc failure or by using an interposed +-malloc that injects random malloc failures. The double free can allow +-buffer manipulation depending of how the regex is constructed. +-This issue affects all architectures and ABIs supported by the GNU C +-library. +- +-CVE-Id: CVE-2025-8058 +-Public-Date: 2025-07-22 +-Vulnerable-Commit: 963d8d782fc98fb6dc3a66f0068795f9920c269d (2.3.3-1596) +-Fix-Commit: 7ea06e994093fa0bcca0d0ee2c1db271d8d7885d (2.42) +diff --git a/advisories/GLIBC-SA-2026-0001 b/advisories/GLIBC-SA-2026-0001 +deleted file mode 100644 +index 3e0ee3b3f4..0000000000 +--- a/advisories/GLIBC-SA-2026-0001 ++++ /dev/null +@@ -1,41 +0,0 @@ +-Integer overflow in memalign leads to heap corruption +- +-Passing too large an alignment to the memalign suite of functions +-(memalign, posix_memalign, aligned_alloc) in the GNU C Library version +-2.30 to 2.42 may result in an integer overflow, which could consequently +-result in a heap corruption. +- +-Note that the attacker must have control over both, the size as well as +-the alignment arguments of the memalign function to be able to exploit +-this. The size parameter must be close enough to PTRDIFF_MAX so as to +-overflow size_t along with the large alignment argument. This limits +-the malicious inputs for the alignment for memalign to the range [1<<62 +-+ 1, 1<<63] and exactly 1<<63 for posix_memalign and aligned_alloc. +- +-Typically the alignment argument passed to such functions is a known +-constrained quantity (e.g. page size, block size, struct sizes) and is +-not attacker controlled, because of which this may not be easily +-exploitable in practice. An application bug could potentially result in +-the input alignment being too large, e.g. due to a different buffer +-overflow or integer overflow in the application or its dependent +-libraries, but that is again an uncommon usage pattern given typical +-sources of alignments. +- +-CVE-Id: CVE-2026-0861 +-Public-Date: 2026-01-14 +-Vulnerable-Commit: 9bf8e29ca136094f73f69f725f15c51facc97206 (2.30) +-Fix-Commit: c9188d333717d3ceb7e3020011651f424f749f93 (2.43) +-Fix-Commit: 7f19ef14fbce095d4c77395e258320cad2ea2b28 (2.30-153) +-Fix-Commit: f18446d7b4a423090ee5e328c36b3c2a0f26041c (2.31-166) +-Fix-Commit: 8aef9e7a7af9565c0324b4ecb38b30dfa3782fd8 (2.32-151) +-Fix-Commit: 011293b4fd748cdd6f95874ba2b6aba9a3df8bff (2.33-275) +-Fix-Commit: 2c77e52108a58956c9f674b36e1f59a4e3fdcf4d (2.34-525) +-Fix-Commit: 499d1ccafccfe64df1b88deea2fa84d8180e8e8f (2.35-399) +-Fix-Commit: fb6b8822175769b5794fb6ea04f2895483a29b61 (2.36-244) +-Fix-Commit: 7b913d41a07836def826f2164c52541a9835f324 (2.37-172) +-Fix-Commit: 744b63026a29f7eedbbc8e3a01a7f48a6eb0a085 (2.38-212) +-Fix-Commit: fb22fd3f5b415dd4cd6f7b5741c2f0412374e242 (2.39-286) +-Fix-Commit: bfc4dd9e526eacf3017dd8864ba0848e9d045dd4 (2.40-216) +-Fix-Commit: 1e2c1ea4307197ccece0cda574bcfebf9080894c (2.41-121) +-Fix-Commit: b0ec8fb689df862171f0f78994a3bdeb51313545 (2.42-49) +-Reported-by: Igor Morgenstern, Aisle Research +diff --git a/advisories/GLIBC-SA-2026-0002 b/advisories/GLIBC-SA-2026-0002 +deleted file mode 100644 +index f10d8362f6..0000000000 +--- a/advisories/GLIBC-SA-2026-0002 ++++ /dev/null +@@ -1,36 +0,0 @@ +-getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler +- +-Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf +-that specifies the library's DNS backend for networks and queries for a +-zero-valued network in the GNU C Library version 2.0 to version 2.42 +-can leak stack contents to the configured DNS resolver. +- +-A defect in the _nss_dns_getnetbyaddr_r function which implements +-getnetbyaddr and getnetbyaddr_r in the dns-based network database can +-pass stack contents unmodified to the configured DNS resolver as part of +-the network DNS query when the network queried is the default network +-i.e. net == 0x0. This stack contents leaking in the query is considered +-a loss of confidentiality for the host making the query. Typically it +-is rare to call these APIs with a net value of zero, and if an attacker +-can control the net value it can only leak adjacent stack, and so loss +-of confidentiality is spatially limited. The leak might be used to +-accelerate an ASLR bypass by knowing pointer values, but also requires +-network adjacent access to snoop between the application and the +-DNS server; making the attack complexity higher. +- +-CVE-Id: CVE-2026-0915 +-Public-Date: 2026-01-15 +-Vulnerable-Commit: 5f0e6fc702296840d2daa39f83f6cb1e40073d58 (1.92-1) +-Fix-Commit: e56ff82d5034ec66c6a78f517af6faa427f65b0b (2.43) +-Fix-Commit: 453e6b8dbab935257eb0802b0c97bca6b67ba30e (2.42-50) +-Fix-Commit: 15c9839a0b853f552b4ed9047841b6223f3c104d (2.41-122) +-Fix-Commit: 329c775788b2c9ff3da774ccf59fba7b6b8ff08e (2.40-217) +-Fix-Commit: 831f63b94ceb92fb14c0d1a7ddad35a0d1404c71 (2.39-287) +-Fix-Commit: 49125ffc8e1674dc2a100dfdc5b78796f22e16f2 (2.38-213) +-Fix-Commit: ddcaed5dfb05b2c1a6ea842fd6b643501365450a (2.37-173) +-Fix-Commit: a6bf47887f24b2b394acb301a3189fda04bd4d4d (2.36-245) +-Fix-Commit: 66f0cb057c9b4fb1249a5fec6ef4a63511a37899 (2.35-400) +-Fix-Commit: 96863dee262225cfb79f9fe45e06fd188319c7b8 (2.34-526) +-Fix-Commit: d210011f1536c8322157cbb4fe4229b35c834c08 (2.33-276) +-Fix-Commit: 1bc1832cfc74c2a601220969f36e789a5e9f0ebe (2.32-152) +-Reported-by: Igor Morgenstern, Aisle Research +diff --git a/advisories/GLIBC-SA-2026-0003 b/advisories/GLIBC-SA-2026-0003 +deleted file mode 100644 +index b7a6e83a10..0000000000 +--- a/advisories/GLIBC-SA-2026-0003 ++++ /dev/null +@@ -1,36 +0,0 @@ +-wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory +- +-Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the +-GNU C Library version 2.0 to version 2.42 may cause the interface to +-return uninitialized memory in the we_wordv member, which on subsequent +-calls to wordfree may abort the process. +- +-The implementation of WRDE_REUSE in conjunction with WRDE_APPEND fails +-to clear the we_wordc member of the structure, and as such, when new +-words are added internally, a leading we_wordc count number of entries +-are skipped since they are assumed initialized. These skipped entries +-are not initialized, but are the contents of a realloc-expanded array of +-pointers. If the caller inspects the we_wordv array, it will +-dereference invalid pointers and crash. If the caller calls wordfree, +-the malloc implementation may detect the invalid pointers and abort the +-process. Calls to wordexp using WRDE_REUSE and WRDE_APPEND have never +-worked correctly and thus the existence of applications that make use of +-this feature is unlikely. +- +-CVE-Id: CVE-2025-15281 +-Public-Date: 2026-01-20 +-Vulnerable-Commit: 8f2ece695d8822e9ecc63ecd157e90bf17a6fe65 (1.93-260) +-Fix-Commit: 80cc58ea2de214f85b0a1d902a3b668ad2ecb302 (2.43) +-Fix-Commit: cbf39c26b25801e9bc88499b4fd361ac172d4125 (2.42-51) +-Fix-Commit: fb4db64a04ad6c96cd1fbb7e02eb59323b1f2ac2 (2.41-123) +-Fix-Commit: 9fe8576664d43b87ca19401fb6a975e217e47623 (2.40-218) +-Fix-Commit: ce65d944e38a20cb70af2a48a4b8aa5d8fabe1cc (2.39-288) +-Fix-Commit: d5409a1be010699794264162c551ba60f05ee6c3 (2.38-214) +-Fix-Commit: ff2b172803f6bbd897755d2ce83ec4323a1a15b3 (2.37-174) +-Fix-Commit: e97cfe2293ed097eb3d0b4c18274d22855e65130 (2.36-246) +-Fix-Commit: bb59339d02faebac534a87eea50c83c948f35b77 (2.35-401) +-Fix-Commit: 2b656ff94d72f93c84d8da2e7c76456c1994f02e (2.34-527) +-Fix-Commit: 1d8ed2067a8a5d162a07670d0d063429679f17a0 (2.33-277) +-Fix-Commit: 3a56c4ee4ea49b8f2391a2d8d6220013c4160a79 (2.32-153) +-Fix-Commit: 28eb5caf895ced5d895cb02757e109004a2d33e5 (2.31-167) +-Reported-by: Vitaly Simonovich +diff --git a/advisories/GLIBC-SA-2026-0004 b/advisories/GLIBC-SA-2026-0004 +deleted file mode 100644 +index fd630dc591..0000000000 +--- a/advisories/GLIBC-SA-2026-0004 ++++ /dev/null +@@ -1,30 +0,0 @@ +-nscd client crash on x86_64 under high nscd load +- +-Calling NSS-backed functions that support caching via nscd may call the +-nscd client side code and in the GNU C Library version 2.36 under high +-load on x86_64 systems, the client may call memcmp on inputs that are +-concurrently modified by other processes or threads and crash. +- +-The nscd client in the GNU C Library uses the memcmp function with +-inputs that may be concurrently modified by another thread, potentially +-resulting in spurious cache misses, which in itself is not a security +-issue. However in the GNU C Library version 2.36 an optimized +-implementation of memcmp was introduced for x86_64 which could crash +-when invoked with such undefined behaviour, turning this into a +-potential crash of the nscd client and the application that uses it. +-This implementation was backported to the 2.35 branch, making the nscd +-client in that branch vulnerable as well. Subsequently, the fix for +-this issue was backported to all vulnerable branches in the GNU C +-Library repository. +- +-It is advised that distributions that may have cherry-picked the memcpy +-SSE2 optimization in their copy of the GNU C Library, also apply the fix +-to avoid the potential crash in the nscd client. +- +-CVE-Id: CVE-2026-3904 +-Public-Date: 2026-03-11 +-Vulnerable-Commit: 8804157ad9da39631703b92315460808eac86b0c (2.36) +-Vulnerable-Commit: 5a8df6485c584e2b0e957ec6b9070437a724911a (2.35-89) +-Fix-Commit: b712be52645282c706a5faa038242504feb06db5 (2.37) +-Fix-Commit: 93967a2a7bbdcedb73e0b246713580c7c84d001e (2.36-84) +-Fix-Commit: 6bcd5d8e3668d52388a6e0580611749f93e6871f (2.35-230) +diff --git a/advisories/GLIBC-SA-2026-0005 b/advisories/GLIBC-SA-2026-0005 +deleted file mode 100644 +index 7a50a43263..0000000000 +--- a/advisories/GLIBC-SA-2026-0005 ++++ /dev/null +@@ -1,37 +0,0 @@ +-gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response +- +-Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf +-that specifies the library's DNS backend in the GNU C Library version +-2.34 to version 2.43 could, with a crafted response from the configured +-DNS server, result in a violation of the DNS specification that causes +-the application to treat a non-answer section of the DNS response as a +-valid answer. +- +-A defect in the getanswer_ptr function, which implements the iteration +-and extraction of the answer from the DNS response, can cause it to +-incorrectly transition from the answer section to the next section while +-still treating it as an answer to the question. This can happen when +-the answer contains only skipped records, and the subsequent section +-contains a semantically invalid T_PTR record. This is considered a +-security issue because it is a violation of the DNS specification that +-leads to incorrect behaviour that could result in the wrong hostname +-being returned to the caller. At the time of publication, no known +-affected DNS server returns results that would be incorrectly +-interpreted by the library. An attacker would either need to be network +-adjacent or have compromised the DNS server to use this defect to hide +-returned reverse DNS results from intrusion detection systems. Even +-then, the inbound connection from the attacker, or the outbound +-connection from the application, would be visible to the intrusion +-detection system. At best, the defect can be used to obfuscate and +-delay analysis of the evolving threat. +- +-CVE-Id: CVE-2026-4437 +-Public-Date: 2026-03-20 +-Vulnerable-Commit: 32e5db37684ffcbc6ae34fcc6cdcf28670506baa (2.34-323) +-Vulnerable-Commit: def97e7f71a07517810f7263213d607e08ad21f1 (2.35-188) +-Vulnerable-Commit: 77f523c473878ec0051582ef15161c6982879095 (2.36-30) +-Vulnerable-Commit: e32547d661a43da63368e488b6cfa9c53b4dcf92 (2.37) +-Fix-Commit: 5c6fca0c62ce5bd6e68e259f138097756cbafd4d (2.43-16) +-Fix-Commit: 9f5f18aab40ec6b61fa49a007615e6077e9a979b (2.44) +-Reported-by: Antonio Maini (0rbitingZer0) - 0rbitingZer0@proton.me +-Reported-by: Kevin Farrell +diff --git a/advisories/GLIBC-SA-2026-0006 b/advisories/GLIBC-SA-2026-0006 +deleted file mode 100644 +index 1ac70de4d9..0000000000 +--- a/advisories/GLIBC-SA-2026-0006 ++++ /dev/null +@@ -1,27 +0,0 @@ +-gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames +- +-Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf +-that specifies the library's DNS backend in the GNU C library version +-2.34 to version 2.43 could result in an invalid DNS hostname being +-returned to the caller in violation of the DNS specification. +- +-A defect in the getanswer_ptr function, which implements the iteration +-and extraction of the answer from a DNS response, can cause it to accept +-an invalid DNS hostname that can contain shell metacharacters. An +-application that uses the returned hostname in a shell, without guarding +-for shell expansion, may be subject to shell injection attacks. At the +-time of publication, no known affected DNS server returns results with +-shell metacharacters in the results. An attacker would either need to +-be network adjacent or have compromised the DNS server to use this +-defect for shell injection. No known vulnerable application has been +-identified. +- +-CVE-Id: CVE-2026-4438 +-Public-Date: 2026-03-20 +-Vulnerable-Commit: 32e5db37684ffcbc6ae34fcc6cdcf28670506baa (2.34-323) +-Vulnerable-Commit: def97e7f71a07517810f7263213d607e08ad21f1 (2.35-188) +-Vulnerable-Commit: 77f523c473878ec0051582ef15161c6982879095 (2.36-30) +-Vulnerable-Commit: e32547d661a43da63368e488b6cfa9c53b4dcf92 (2.37) +-Fix-Commit: dd9945c0ba40d2dbc9eb7c99291ba6b69bd66718 (2.43-17) +-Fix-Commit: e10977481f4db4b2a3ce34fa4c3a1e26651ae312 (2.44) +-Reported-by: Antonio Maini (0rbitingZer0) - 0rbitingZer0@proton.me +diff --git a/advisories/GLIBC-SA-2026-0007 b/advisories/GLIBC-SA-2026-0007 +deleted file mode 100644 +index b880fb5544..0000000000 +--- a/advisories/GLIBC-SA-2026-0007 ++++ /dev/null +@@ -1,15 +0,0 @@ +-iconv crash due to assertion failure with untrusted input +- +-The iconv() function in the GNU C Library versions 2.43 and earlier may +-crash due to an assertion failure when converting inputs from the +-IBM1390 or IBM1399 character sets, which may be used to remotely crash +-an application. +- +-This vulnerability can be trivially mitigated by removing the IBM1390 +-and IBM1399 character sets from systems that do not need them. +- +-CVE-Id: CVE-2026-4046 +-Public-Date: 2026-03-12 +-Vulnerable-Commit: 0ecb606cb6cf65de1d9fc8a919bceb4be476c602 (2.3.3-1501) +-Fix-Commit: d6f08d1cf027f4eb2ba289a6cc66853722d4badc (2.44) +-Reported-by: Rocket Ma +diff --git a/advisories/GLIBC-SA-2026-0008 b/advisories/GLIBC-SA-2026-0008 +deleted file mode 100644 +index 43b38ce38a..0000000000 +--- a/advisories/GLIBC-SA-2026-0008 ++++ /dev/null +@@ -1,22 +0,0 @@ +-REJECTED: Static buffer overflow in deprecated nis_local_principal +- +-REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been +-discovered that no NIS+ client or server was ever released for any +-Linux-based OS distributions and as such this makes the API provisional +-and unused. Secondly it has been discovered that the NIS+ cold start +-cache (/var/nis/NIS_COLD_START) cannot be bypassed and as such the API +-can only be called with a trusted server from the pre-populated cache. +-The use of a trusted server means no trust boundary is crossed and this +-is therefore considered a normal bug. +- +-NIS+ support in the GNU C Library was never officially supported even +-though an incomplete implementation of the APIs was made pulibc. To the +-best knowledge of the glibc security team no open-source NIS+ server +-implementations were ever released for use with this API. Applications +-should not use any of the NIS+ APIs and should move to modern identity +-and access management services. +- +-CVE-Id: CVE-2026-5358 +-Public-Date: 2026-04-10 +-Rejected-Date: 2026-04-33 +-Reported-by: Rahul Hoysala +diff --git a/advisories/GLIBC-SA-2026-0009 b/advisories/GLIBC-SA-2026-0009 +deleted file mode 100644 +index 3c297fdc80..0000000000 +--- a/advisories/GLIBC-SA-2026-0009 ++++ /dev/null +@@ -1,23 +0,0 @@ +-scanf %mc off-by-one heap buffer overflow +- +-Calling the scanf family of functions with a %mc (malloc'd character +-match) in the GNU C Library version 2.7 to version 2.43 with a format +-width specifier with an explicit width greater than 1024 could result in +-a one byte heap buffer overflow. +- +-The bug is in the buffer growth formula in __vfscanf_internal, which +-under-allocates by one byte during realloc expansion, allowing a +-controlled single-byte overwrite past the end of the heap buffer. +- +-The impact is limited by the fact that to execute the overwrite you need +-both user controlled input data and a specific choice of maximum width +-that yields a smaller than needed allocation. The latter point has to +-take into account malloc's particular chunk size rounding process. The +-"%[width]mc" format specifier does not appear to have notable use in +-major Linux-based OS distributions, due to which the real world impact +-may be limited to bespoke use cases. +- +-CVE-Id: CVE-2026-5450 +-Public-Date: 2026-03-19 +-Vulnerable-Commit: 874aa52349cc111d1f6ea5dff24bb14c306714e0 (2.7) +-Reported-by: Rocket Ma +diff --git a/advisories/GLIBC-SA-2026-0010 b/advisories/GLIBC-SA-2026-0010 +deleted file mode 100644 +index ae9953fb71..0000000000 +--- a/advisories/GLIBC-SA-2026-0010 ++++ /dev/null +@@ -1,24 +0,0 @@ +-Potential buffer under-read in ungetwc +- +-Calling the ungetwc function on a FILE stream with wide characters +-encoded in a character set that has overlaps between its single byte and +-multi-byte character encodings, in the GNU C Library version 2.43 or +-earlier, may result in an attempt to read bytes before an allocated +-buffer, potentially resulting in unintentional disclosure of neighboring +-data in the heap, or a program crash. +- +-A bug in the wide character pushback implementation +-(_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate +-on the regular character buffer (fp->_IO_read_ptr) instead of the actual +-wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program +-crash may happen in cases where fp->_IO_read_ptr is not initialized and +-hence points to NULL. The buffer under-read requires a special situation +-where the input character encoding is such that there are overlaps +-between single byte representations and multibyte representations in +-that encoding, resulting in spurious matches. The spurious match case +-is not possible in the standard Unicode character sets. +- +-CVE-Id: CVE-2026-5928 +-Public-Date: 2026-03-17 +-Reported-by: Rocket Ma +-Vulnerable-Commit: d64b6ad07585b8a37e5fecc9a47fcee766d52ede (2.1.1-89) +diff --git a/advisories/GLIBC-SA-2026-0011 b/advisories/GLIBC-SA-2026-0011 +deleted file mode 100644 +index e492fa5507..0000000000 +--- a/advisories/GLIBC-SA-2026-0011 ++++ /dev/null +@@ -1,24 +0,0 @@ +-Potential buffer overflow in ns_sprintrrf TSIG handling path +- +-The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the +-GNU C Library version 2.2 and newer fail to enforce the caller-supplied +-buffer length, and can result in an out-of-bounds write when printing +-TSIG records. +- +-A defect in the TSIG case handling within ns_sprintrrf performs a +-formatted write using sprintf without checking the remaining buffer +-length, and may write up to 6 bytes past the end of the buffer. If the +-library is compiled with assertions, and the out-of-bounds write doesn't +-terminate the process, then a subsequent check for "len <= *buflen" will +-trigger an assertion failure. +- +-These functions are for application debugging only and hence not in the +-path of code executed by the DNS resolver. Further, they have been +-deprecated since version 2.34 (2021-08-02) and should not be used by any +-new applications. Applications should consider porting away from these +-interfaces since they may be removed in future versions. +- +-CVE-Id: CVE-2026-5435 +-Public-Date: 2026-04-02 +-Vulnerable-Commit: b43b13ac2544b11f35be301d1589b51a8473e32b (2.2) +-Reported-by: shinobu +diff --git a/advisories/GLIBC-SA-2026-0012 b/advisories/GLIBC-SA-2026-0012 +deleted file mode 100644 +index 22071d97a6..0000000000 +--- a/advisories/GLIBC-SA-2026-0012 ++++ /dev/null +@@ -1,18 +0,0 @@ +-Buffer overread in ns_printrrf with corrupted RDATA field +- +-The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the +-GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA +-content against the RDATA length in a DNS response when processing A6, +-CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a +-DNS response, causing a target application to crash or read +-uninitialized memory. +- +-These functions are for application debugging only and hence not in the +-path of code executed by the DNS resolver. Further, they have been +-deprecated since version 2.34 and should not be used by any new +-applications. Applications should consider porting away from these +-interfaces since they may be removed in future versions. +- +-CVE-Id: CVE-2026-6238 +-Public-Date: 2026-04-11 +-Vulnerable-Commit: ee188d555b8c32ad9704a7440cab400af967292f (1.90) +diff --git a/advisories/GLIBC-SA-2026-0013 b/advisories/GLIBC-SA-2026-0013 +deleted file mode 100644 +index 085a853434..0000000000 +--- a/advisories/GLIBC-SA-2026-0013 ++++ /dev/null +@@ -1,20 +0,0 @@ +-Potential stack-based buffer clash during tilde expansion in wordexp +- +-Calling wordexp with a tilde (~) followed by an overly long username +-in the GNU C Library version 2.2.3 to 2.43 may lead to a stack buffer +-clash. +- +-When expanding paths that begin with a tilde (~) followed by a username, the +-internal parse_tilde function extracts the username to determine the user's +-home directory. The implementation allocates memory for this username directly +-on the stack using the strndupa macro. Because the size of this allocation +-was determined by the length of the user-supplied input without any bounds +-checks, passing an excessively long username e.g. thousands of characters, +-forces the thread to exhaust its stack space. Thus if an application passes +-untrusted, attacker-controlled input to the wordexp function, an attacker +-can trigger a stack clash. +- +-CVE-Id: CVE-2026-6791 +-Public-Date: 2026-06-22 +-Vulnerable-Commit: 344af000e1d6e9c7882b9bc48e71cb3f1b5fc03c (2.2.3-114) +-Reported-by: storm +diff --git a/advisories/GLIBC-SA-2026-0014 b/advisories/GLIBC-SA-2026-0014 +deleted file mode 100644 +index 1e9a0039f0..0000000000 +--- a/advisories/GLIBC-SA-2026-0014 ++++ /dev/null +@@ -1,19 +0,0 @@ +-wordexp with WRDE_APPEND may result in an invalid call to free() +- +-Calling wordexp with WRDE_APPEND in conjunction with an invalid expansion +-(where an error like WRDE_BADCHAR would be returned) can create a stale +-address in the wordexp_t that can cause an invalid free from wordfree. +-This affects the GNU C Library version 2.0 to version 2.43. +- +-In WRDE_APPEND mode, wordexp saves the caller-visible wordexp_t state +-before appending the processing input. If the word expansion grows +-we_wordv via realloc, and realloc requires moving we_wordv to a new memory +-location (instead of expanding in-place), and the expansion later fails, +-the rollback fails to properly restore all previous we_wordv values and +-may add stale pointers into the caller-visible state. A subsequent +-wordfree may then issue an invalid call to free(). +- +-CVE-Id: CVE-2026-6368 +-Public-Date: 2026-07-14 +-Vulnerable-Commit: 8f2ece695d8822e9ecc63ecd157e90bf17a6fe65 (1.93-260) +-Reported-by: shinobu +diff --git a/advisories/README b/advisories/README +deleted file mode 100644 +index 330a31dff3..0000000000 +--- a/advisories/README ++++ /dev/null +@@ -1,92 +0,0 @@ +-GNU C Library Security Advisory Format +-====================================== +- +-Security advisories in this directory follow a simple git commit log +-format, with a heading and free-format description augmented with tags +-to allow parsing key information. References to code changes are +-specific to the glibc repository and follow a specific format: +- +- Tag-name: (release-version) +- +-The indicates a specific commit in the repository. The +-release-version indicates the publicly consumable release in which this +-commit is known to exist. The release-version is derived from the +-git-describe format, (i.e. stripped out from glibc-2.34.NNN-gxxxx) and +-is of the form 2.34-NNN. If the -NNN suffix is absent, it means that +-the change is in that release tarball, otherwise the change is on the +-release/2.YY/master branch and not in any released tarball. +- +-The following tags are currently being used: +- +-CVE-Id: +-This is the CVE-Id assigned under the CVE Program +-(https://www.cve.org/). +- +-Public-Date: +-The date this issue became publicly known. +- +-Rejected-Date: +-The most recent date the assigned advisory was rejected. If the advisory +-is ever published again the Rejected-Date tag should be removed. +- +-Vulnerable-Commit: +-The commit that introduced this vulnerability. There could be multiple +-entries, one for each release branch in the glibc repository; the +-release-version portion of this tag should tell you which branch this is +-on. +- +-Fix-Commit: +-The commit that fixed this vulnerability. There could be multiple +-entries for each release branch in the glibc repository, indicating that +-all of those commits contributed to fixing that issue in each of those +-branches. +- +-Reported-By: +-The entity that reported this issue. There could be multiple entries, one for +-each reporter. +- +-Adding an Advisory +------------------- +- +-An advisory for a CVE needs to be added on the master branch in two steps: +- +-1. Add the text of the advisory without any Fix-Commit tags along with +- the fix for the CVE. Add the Vulnerable-Commit tag, if applicable. +- The advisories directory does not exist in release branches, so keep +- the advisory text commit distinct from the code changes, to ease +- backports. Ask for the GLIBC-SA advisory number from the security +- team. +- +-2. Finish all backports on release branches and then back on the msater +- branch, add all commit refs to the advisory using the Fix-Commit +- tags. Don't bother adding the release-version subscript since the +- next step will overwrite it. +- +-3. Run the process-advisories.sh script in the scripts directory on the +- advisory: +- +- scripts/process-advisories.sh update GLIBC-SA-YYYY-NNNN +- +- (replace YYYY-NNNN with the actual advisory number). +- +-4. Verify the updated advisory and push the result. +- +-Rejecting an Advisory +---------------------- +- +-Rejecting an advisory on the master branch can be done in one step: +- +-1. Mark the advisory as rejected. Add the text "REJECTED: " as a prefix +- to any short-form description. Add a new paragraph that starts with +- "REJECTED: " and explains the reason for the rejection including +- justification for why it no longer has security impact. Lastly add +- a Rejected-Date tag to the advisory. +- +-Getting a NEWS snippet from advisories +--------------------------------------- +- +-Run: +- +- scripts/process-advisories.sh news +- +-and copy the content into the NEWS file. + +commit 1bd79651065b27c02c6502b9423124e54882058d +Author: Andreas K. Hüttel +Date: Sat Jul 25 09:21:33 2026 +0900 + + NEWS: start 2.44.1 section + + Signed-off-by: Andreas K. Hüttel + +diff --git a/NEWS b/NEWS +index ee28fadf49..1043343d70 100644 +--- a/NEWS ++++ b/NEWS +@@ -5,6 +5,10 @@ See the end for copying conditions. + Please send GNU C library bug reports via + using `glibc' in the "product" field. + ++Version 2.44.1 ++ ++The following bugs are resolved with this release: ++ + Version 2.44 + + Major new features: + +commit 0b05bc142249ac47e72be5cad5c37f33f4bb68d4 +Author: Samuel Thibault +Date: Fri Jul 24 23:10:02 2026 +0200 + + hurd: Make the readlink __fstatat64 references optional + + They may show up or not depending on the toolchain in use. + +diff --git a/sysdeps/mach/hurd/i386/localplt.data b/sysdeps/mach/hurd/i386/localplt.data +index 2befcd3748..5b9413422d 100644 +--- a/sysdeps/mach/hurd/i386/localplt.data ++++ b/sysdeps/mach/hurd/i386/localplt.data +@@ -25,14 +25,14 @@ ld.so: __writev + ld.so: __libc_lseek64 + ld.so: __mmap + ld.so: __fstat64 +-ld.so: __fstatat64 ++ld.so: __fstatat64 ? + ld.so: __stat64 + ld.so: __access + ld.so: __getpid + ld.so: __getcwd + ld.so: _exit ? + ld.so: abort +-ld.so: readlink ++ld.so: readlink ? + ld.so: _hurd_intr_rpc_mach_msg + ld.so: __errno_location + ld.so: _dl_init_first +diff --git a/sysdeps/mach/hurd/x86_64/localplt.data b/sysdeps/mach/hurd/x86_64/localplt.data +index fda28cd983..cc39118d12 100644 +--- a/sysdeps/mach/hurd/x86_64/localplt.data ++++ b/sysdeps/mach/hurd/x86_64/localplt.data +@@ -24,14 +24,14 @@ ld.so: __writev + ld.so: __libc_lseek64 + ld.so: __mmap + ld.so: __fstat64 +-ld.so: __fstatat64 ++ld.so: __fstatat64 ? + ld.so: __stat64 + ld.so: __access + ld.so: __getpid + ld.so: __getcwd + ld.so: _exit ? + ld.so: abort +-ld.so: readlink ++ld.so: readlink ? + ld.so: _hurd_intr_rpc_mach_msg + ld.so: __errno_location + ld.so: _dl_init_first + +commit c045fc61e8435c103ebfe06d01fec7f56503e2b4 +Author: Samuel Thibault +Date: Mon Jul 27 00:59:36 2026 +0200 + + hurd: fix fork's longjmp demangling on i386 + + i386's setjmp does not actually mangle ebp. + +diff --git a/sysdeps/mach/hurd/i386/longjmp-ts.c b/sysdeps/mach/hurd/i386/longjmp-ts.c +index 93450e86b4..340104b832 100644 +--- a/sysdeps/mach/hurd/i386/longjmp-ts.c ++++ b/sysdeps/mach/hurd/i386/longjmp-ts.c +@@ -38,7 +38,6 @@ _hurd_longjmp_thread_state (void *state, jmp_buf env, int val) + ts->eip = env[0].__jmpbuf[JB_PC]; + ts->eax = val ?: 1; + +- PTR_DEMANGLE (ts->ebp); + PTR_DEMANGLE (ts->uesp); + PTR_DEMANGLE (ts->eip); + } + +commit 7cba77790f3279bec3ac20e9c7632b021cd53f95 +Author: Adhemerval Zanella +Date: Mon Jul 27 13:37:19 2026 -0300 + + math: Fix sinh worst-case results for |x| > 36.736801 [BZ 34441] + + The CORE-MATH import mistranslated the accurate path result scaling + 'th *= sp.f' as 'th *= asuint64 (sp)' (commit 106f8c2ed68), and two of + the 51 exceptional-case table entries were dropped when the table was + moved to e_sinh_data.c (commit f05c4907a27). + + Checked on x86_64-linux-gnu and aarch64-linux-gnu. + + (cherry picked from commit fdc90dbb52b092f68cd5a4fac7a4cbd854c91bc3) + +diff --git a/NEWS b/NEWS +index 1043343d70..fe2b1d7f79 100644 +--- a/NEWS ++++ b/NEWS +@@ -8,6 +8,9 @@ using `glibc' in the "product" field. + Version 2.44.1 + + The following bugs are resolved with this release: ++ ++ [34441] math: math: sinh() returns wrong results for some inputs with ++ |x| > 36.736801 + + Version 2.44 + +diff --git a/math/auto-libm-test-in b/math/auto-libm-test-in +index ca670768a2..5c4d486af4 100644 +--- a/math/auto-libm-test-in ++++ b/math/auto-libm-test-in +@@ -9661,6 +9661,14 @@ sinh 0x2.c5d37700c6bb03a6c24b6c9b494cp+12 + sinh 0x2.c5d37700c6bb03a6c24b6c9b494ep+12 + # the next value generates larger error bounds on x86_64 (binary64) + sinh -0x1.633c62890fa14p+9 ++sinh 0x1.2b4f4e0bb49c9p+5 ++sinh -0x1.2b4f4e0bb49c9p+5 ++sinh 0x1.2ac43fb6d3abap+5 ++sinh -0x1.2ac43fb6d3abap+5 ++sinh 0x1.b7efa91915c95p-2 ++sinh -0x1.b7efa91915c95p-2 ++sinh 0x1.92a5c27afbe82p+4 ++sinh -0x1.92a5c27afbe82p+4 + + sinpi 0 + sinpi -0 +diff --git a/math/auto-libm-test-out-sinh b/math/auto-libm-test-out-sinh +index f96252b91c..91ab5c19fa 100644 +--- a/math/auto-libm-test-out-sinh ++++ b/math/auto-libm-test-out-sinh +@@ -6466,3 +6466,555 @@ sinh -0x1.633c62890fa14p+9 + = sinh tonearest ibm128 -0x2.c678c5121f428p+8 : -0xf.ef3a7e711d2c75a66ea3ca1c4p+1020 : inexact-ok + = sinh towardzero ibm128 -0x2.c678c5121f428p+8 : -0xf.ef3a7e711d2c75a66ea3ca1c4p+1020 : inexact-ok + = sinh upward ibm128 -0x2.c678c5121f428p+8 : -0xf.ef3a7e711d2c75a66ea3ca1c4p+1020 : inexact-ok ++sinh 0x1.2b4f4e0bb49c9p+5 ++= sinh downward binary32 0x2.569eap+4 : 0x1.f7c30ap+52 : inexact-ok ++= sinh tonearest binary32 0x2.569eap+4 : 0x1.f7c30ap+52 : inexact-ok ++= sinh towardzero binary32 0x2.569eap+4 : 0x1.f7c30ap+52 : inexact-ok ++= sinh upward binary32 0x2.569eap+4 : 0x1.f7c30cp+52 : inexact-ok ++= sinh downward binary64 0x2.569eap+4 : 0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh tonearest binary64 0x2.569eap+4 : 0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh towardzero binary64 0x2.569eap+4 : 0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh upward binary64 0x2.569eap+4 : 0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh downward intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh tonearest intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh downward m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh tonearest m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh downward binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh tonearest binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh towardzero binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh upward binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f53p+52 : inexact-ok ++= sinh downward ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh tonearest ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh upward ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh downward binary32 0x2.569e9cp+4 : 0x1.f7c28cp+52 : inexact-ok ++= sinh tonearest binary32 0x2.569e9cp+4 : 0x1.f7c28cp+52 : inexact-ok ++= sinh towardzero binary32 0x2.569e9cp+4 : 0x1.f7c28cp+52 : inexact-ok ++= sinh upward binary32 0x2.569e9cp+4 : 0x1.f7c28ep+52 : inexact-ok ++= sinh downward binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh tonearest binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh towardzero binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh upward binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh downward intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh tonearest intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh downward m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh tonearest m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh downward binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh tonearest binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh towardzero binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh upward binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ecp+52 : inexact-ok ++= sinh downward ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh upward ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh downward binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh tonearest binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh towardzero binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh upward binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh downward intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh tonearest intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh downward m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh tonearest m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh downward binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh tonearest binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh towardzero binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh upward binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh downward ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh upward ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000009p+52 : inexact-ok ++sinh -0x1.2b4f4e0bb49c9p+5 ++= sinh downward binary32 -0x2.569e9cp+4 : -0x1.f7c28ep+52 : inexact-ok ++= sinh tonearest binary32 -0x2.569e9cp+4 : -0x1.f7c28cp+52 : inexact-ok ++= sinh towardzero binary32 -0x2.569e9cp+4 : -0x1.f7c28cp+52 : inexact-ok ++= sinh upward binary32 -0x2.569e9cp+4 : -0x1.f7c28cp+52 : inexact-ok ++= sinh downward binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh upward binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh downward intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh tonearest intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh downward m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh downward binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ecp+52 : inexact-ok ++= sinh tonearest binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh towardzero binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh upward binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh downward ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh upward ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh downward binary32 -0x2.569eap+4 : -0x1.f7c30cp+52 : inexact-ok ++= sinh tonearest binary32 -0x2.569eap+4 : -0x1.f7c30ap+52 : inexact-ok ++= sinh towardzero binary32 -0x2.569eap+4 : -0x1.f7c30ap+52 : inexact-ok ++= sinh upward binary32 -0x2.569eap+4 : -0x1.f7c30ap+52 : inexact-ok ++= sinh downward binary64 -0x2.569eap+4 : -0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.569eap+4 : -0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.569eap+4 : -0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh upward binary64 -0x2.569eap+4 : -0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh downward intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh downward m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh downward binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f53p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh upward binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh downward ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh upward ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh downward binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh tonearest binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh towardzero binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh upward binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh downward intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh downward m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh downward binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh upward binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh downward ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000009p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh upward ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++sinh 0x1.2ac43fb6d3abap+5 ++= sinh downward binary32 0x2.55888p+4 : 0x1.d6b0ecp+52 : inexact-ok ++= sinh tonearest binary32 0x2.55888p+4 : 0x1.d6b0ecp+52 : inexact-ok ++= sinh towardzero binary32 0x2.55888p+4 : 0x1.d6b0ecp+52 : inexact-ok ++= sinh upward binary32 0x2.55888p+4 : 0x1.d6b0eep+52 : inexact-ok ++= sinh downward binary64 0x2.55888p+4 : 0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh tonearest binary64 0x2.55888p+4 : 0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh towardzero binary64 0x2.55888p+4 : 0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh upward binary64 0x2.55888p+4 : 0x1.d6b0ecda100c3p+52 : inexact-ok ++= sinh downward intel96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh tonearest intel96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero intel96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward intel96 0x2.55888p+4 : 0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh downward m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh tonearest m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh downward binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh tonearest binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh towardzero binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh upward binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d9p+52 : inexact-ok ++= sinh downward ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh upward ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh downward binary32 0x2.55887cp+4 : 0x1.d6b076p+52 : inexact-ok ++= sinh tonearest binary32 0x2.55887cp+4 : 0x1.d6b078p+52 : inexact-ok ++= sinh towardzero binary32 0x2.55887cp+4 : 0x1.d6b076p+52 : inexact-ok ++= sinh upward binary32 0x2.55887cp+4 : 0x1.d6b078p+52 : inexact-ok ++= sinh downward binary64 0x2.55887cp+4 : 0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh tonearest binary64 0x2.55887cp+4 : 0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh towardzero binary64 0x2.55887cp+4 : 0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh upward binary64 0x2.55887cp+4 : 0x1.d6b0772de38b3p+52 : inexact-ok ++= sinh downward intel96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh tonearest intel96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero intel96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward intel96 0x2.55887cp+4 : 0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh downward m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh tonearest m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh downward binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh tonearest binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh towardzero binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh upward binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c262p+52 : inexact-ok ++= sinh downward ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh upward ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh downward binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh tonearest binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh upward binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh downward intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh tonearest intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh downward m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh tonearest m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh downward binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh tonearest binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh towardzero binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh upward binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289fp+52 : inexact-ok ++= sinh downward ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh upward ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff29p+52 : inexact-ok ++sinh -0x1.2ac43fb6d3abap+5 ++= sinh downward binary32 -0x2.55887cp+4 : -0x1.d6b078p+52 : inexact-ok ++= sinh tonearest binary32 -0x2.55887cp+4 : -0x1.d6b078p+52 : inexact-ok ++= sinh towardzero binary32 -0x2.55887cp+4 : -0x1.d6b076p+52 : inexact-ok ++= sinh upward binary32 -0x2.55887cp+4 : -0x1.d6b076p+52 : inexact-ok ++= sinh downward binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b3p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh upward binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh downward intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh tonearest intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh downward m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh downward binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c262p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh upward binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh downward ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh upward ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh downward binary32 -0x2.55888p+4 : -0x1.d6b0eep+52 : inexact-ok ++= sinh tonearest binary32 -0x2.55888p+4 : -0x1.d6b0ecp+52 : inexact-ok ++= sinh towardzero binary32 -0x2.55888p+4 : -0x1.d6b0ecp+52 : inexact-ok ++= sinh upward binary32 -0x2.55888p+4 : -0x1.d6b0ecp+52 : inexact-ok ++= sinh downward binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c3p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh upward binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh downward intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh downward m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh downward binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d9p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh upward binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh downward ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh upward ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh downward binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh upward binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh downward intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh downward m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh downward binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289fp+52 : inexact-ok ++= sinh tonearest binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh towardzero binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh upward binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh downward ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff29p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh upward ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++sinh 0x1.b7efa91915c95p-2 ++= sinh downward binary32 0x6.dfbea8p-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh tonearest binary32 0x6.dfbea8p-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh towardzero binary32 0x6.dfbea8p-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh upward binary32 0x6.dfbea8p-4 : 0x7.1661bp-4 : inexact-ok ++= sinh downward binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e4p-4 : inexact-ok ++= sinh tonearest binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e8p-4 : inexact-ok ++= sinh towardzero binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e4p-4 : inexact-ok ++= sinh upward binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e8p-4 : inexact-ok ++= sinh downward intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh tonearest intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh downward m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh tonearest m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh downward binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh tonearest binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh towardzero binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh upward binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh downward ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh tonearest ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh towardzero ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh upward ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ecp-4 : inexact-ok ++= sinh downward binary32 0x6.dfbeap-4 : 0x7.1661ap-4 : inexact-ok ++= sinh tonearest binary32 0x6.dfbeap-4 : 0x7.1661ap-4 : inexact-ok ++= sinh towardzero binary32 0x6.dfbeap-4 : 0x7.1661ap-4 : inexact-ok ++= sinh upward binary32 0x6.dfbeap-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh downward binary64 0x6.dfbeap-4 : 0x7.1661a2f837414p-4 : inexact-ok ++= sinh tonearest binary64 0x6.dfbeap-4 : 0x7.1661a2f837418p-4 : inexact-ok ++= sinh towardzero binary64 0x6.dfbeap-4 : 0x7.1661a2f837414p-4 : inexact-ok ++= sinh upward binary64 0x6.dfbeap-4 : 0x7.1661a2f837418p-4 : inexact-ok ++= sinh downward intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh tonearest intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh downward m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh tonearest m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh downward binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh tonearest binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh towardzero binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh upward binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4ccp-4 : inexact-ok ++= sinh downward ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh tonearest ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh towardzero ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh upward ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d6p-4 : inexact-ok ++= sinh downward binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh tonearest binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh upward binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh downward intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh tonearest intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh downward m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh tonearest m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh downward binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh tonearest binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh towardzero binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh upward binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh downward ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++= sinh tonearest ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++= sinh towardzero ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++= sinh upward ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++sinh -0x1.b7efa91915c95p-2 ++= sinh downward binary32 -0x6.dfbeap-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh tonearest binary32 -0x6.dfbeap-4 : -0x7.1661ap-4 : inexact-ok ++= sinh towardzero binary32 -0x6.dfbeap-4 : -0x7.1661ap-4 : inexact-ok ++= sinh upward binary32 -0x6.dfbeap-4 : -0x7.1661ap-4 : inexact-ok ++= sinh downward binary64 -0x6.dfbeap-4 : -0x7.1661a2f837418p-4 : inexact-ok ++= sinh tonearest binary64 -0x6.dfbeap-4 : -0x7.1661a2f837418p-4 : inexact-ok ++= sinh towardzero binary64 -0x6.dfbeap-4 : -0x7.1661a2f837414p-4 : inexact-ok ++= sinh upward binary64 -0x6.dfbeap-4 : -0x7.1661a2f837414p-4 : inexact-ok ++= sinh downward intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh tonearest intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh downward m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh tonearest m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh downward binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4ccp-4 : inexact-ok ++= sinh tonearest binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh towardzero binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh upward binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh downward ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d6p-4 : inexact-ok ++= sinh tonearest ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh towardzero ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh upward ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh downward binary32 -0x6.dfbea8p-4 : -0x7.1661bp-4 : inexact-ok ++= sinh tonearest binary32 -0x6.dfbea8p-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh towardzero binary32 -0x6.dfbea8p-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh upward binary32 -0x6.dfbea8p-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh downward binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e8p-4 : inexact-ok ++= sinh tonearest binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e8p-4 : inexact-ok ++= sinh towardzero binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e4p-4 : inexact-ok ++= sinh upward binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e4p-4 : inexact-ok ++= sinh downward intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh tonearest intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh downward m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh tonearest m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh downward binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh tonearest binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh towardzero binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh upward binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh downward ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ecp-4 : inexact-ok ++= sinh tonearest ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh towardzero ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh upward ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh downward binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh tonearest binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh upward binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh downward intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh tonearest intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh downward m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh tonearest m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh downward binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh tonearest binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh towardzero binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh upward binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh downward ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++= sinh tonearest ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++= sinh towardzero ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++= sinh upward ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++sinh 0x1.92a5c27afbe82p+4 ++= sinh downward binary32 0x1.92a5c4p+4 : 0x9.e410bp+32 : inexact-ok ++= sinh tonearest binary32 0x1.92a5c4p+4 : 0x9.e410cp+32 : inexact-ok ++= sinh towardzero binary32 0x1.92a5c4p+4 : 0x9.e410bp+32 : inexact-ok ++= sinh upward binary32 0x1.92a5c4p+4 : 0x9.e410cp+32 : inexact-ok ++= sinh downward binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh tonearest binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh towardzero binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh upward binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c858p+32 : inexact-ok ++= sinh downward intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh tonearest intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh downward m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh tonearest m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh downward binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh tonearest binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh towardzero binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh upward binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh downward ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh tonearest ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh towardzero ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh upward ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60ecp+32 : inexact-ok ++= sinh downward binary32 0x1.92a5c2p+4 : 0x9.e40f8p+32 : inexact-ok ++= sinh tonearest binary32 0x1.92a5c2p+4 : 0x9.e40f8p+32 : inexact-ok ++= sinh towardzero binary32 0x1.92a5c2p+4 : 0x9.e40f8p+32 : inexact-ok ++= sinh upward binary32 0x1.92a5c2p+4 : 0x9.e40f9p+32 : inexact-ok ++= sinh downward binary64 0x1.92a5c2p+4 : 0x9.e40f810b889bp+32 : inexact-ok ++= sinh tonearest binary64 0x1.92a5c2p+4 : 0x9.e40f810b889b8p+32 : inexact-ok ++= sinh towardzero binary64 0x1.92a5c2p+4 : 0x9.e40f810b889bp+32 : inexact-ok ++= sinh upward binary64 0x1.92a5c2p+4 : 0x9.e40f810b889b8p+32 : inexact-ok ++= sinh downward intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh tonearest intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh downward m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh tonearest m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh downward binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh tonearest binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh towardzero binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh upward binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa468p+32 : inexact-ok ++= sinh downward ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh tonearest ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh towardzero ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh upward ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa8p+32 : inexact-ok ++= sinh downward binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh tonearest binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd12392ap+32 : inexact-ok ++= sinh downward intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh tonearest intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929801p+32 : inexact-ok ++= sinh downward m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh tonearest m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929801p+32 : inexact-ok ++= sinh downward binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh tonearest binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh towardzero binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh upward binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh downward ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh tonearest ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh towardzero ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh upward ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd12392980000000000024p+32 : inexact-ok ++sinh -0x1.92a5c27afbe82p+4 ++= sinh downward binary32 -0x1.92a5c2p+4 : -0x9.e40f9p+32 : inexact-ok ++= sinh tonearest binary32 -0x1.92a5c2p+4 : -0x9.e40f8p+32 : inexact-ok ++= sinh towardzero binary32 -0x1.92a5c2p+4 : -0x9.e40f8p+32 : inexact-ok ++= sinh upward binary32 -0x1.92a5c2p+4 : -0x9.e40f8p+32 : inexact-ok ++= sinh downward binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889b8p+32 : inexact-ok ++= sinh tonearest binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889b8p+32 : inexact-ok ++= sinh towardzero binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889bp+32 : inexact-ok ++= sinh upward binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889bp+32 : inexact-ok ++= sinh downward intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh tonearest intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh downward m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh tonearest m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh downward binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa468p+32 : inexact-ok ++= sinh tonearest binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh towardzero binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh upward binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh downward ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa8p+32 : inexact-ok ++= sinh tonearest ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh towardzero ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh upward ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh downward binary32 -0x1.92a5c4p+4 : -0x9.e410cp+32 : inexact-ok ++= sinh tonearest binary32 -0x1.92a5c4p+4 : -0x9.e410cp+32 : inexact-ok ++= sinh towardzero binary32 -0x1.92a5c4p+4 : -0x9.e410bp+32 : inexact-ok ++= sinh upward binary32 -0x1.92a5c4p+4 : -0x9.e410bp+32 : inexact-ok ++= sinh downward binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c858p+32 : inexact-ok ++= sinh tonearest binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh towardzero binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh upward binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh downward intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh tonearest intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh downward m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh tonearest m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh downward binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh tonearest binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh towardzero binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh upward binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh downward ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60ecp+32 : inexact-ok ++= sinh tonearest ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh towardzero ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh upward ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh downward binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd12392ap+32 : inexact-ok ++= sinh tonearest binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh downward intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929801p+32 : inexact-ok ++= sinh tonearest intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh downward m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929801p+32 : inexact-ok ++= sinh tonearest m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh downward binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh tonearest binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh towardzero binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh upward binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh downward ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd12392980000000000024p+32 : inexact-ok ++= sinh tonearest ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh towardzero ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh upward ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002p+32 : inexact-ok +diff --git a/sysdeps/ieee754/dbl-64/e_sinh.c b/sysdeps/ieee754/dbl-64/e_sinh.c +index 1643f3f504..638e3d6a6d 100644 +--- a/sysdeps/ieee754/dbl-64/e_sinh.c ++++ b/sysdeps/ieee754/dbl-64/e_sinh.c +@@ -213,7 +213,7 @@ __sinh (double x) + ml = (ul + 8) & MANTISSA_MASK; + th += tl; + th *= 2; +- th *= asuint64 (sp); ++ th *= sp; + if (ml <= 16 || eh - el > 103) + return as_sinh_database (x, th); + return th; +diff --git a/sysdeps/ieee754/dbl-64/e_sinh_data.c b/sysdeps/ieee754/dbl-64/e_sinh_data.c +index ca61e311f1..d4fd41d934 100644 +--- a/sysdeps/ieee754/dbl-64/e_sinh_data.c ++++ b/sysdeps/ieee754/dbl-64/e_sinh_data.c +@@ -35,12 +35,13 @@ const double __sinh_data_ch[][2] = + { 0x1.ae64567f54482p-26, -0x1.defcf17a6ab79p-81 } + }; + +-const double __sinh_data_db[49][3] = ++const double __sinh_data_db[51][3] = + { + { 0x1.364303e1ad8f6p-2, 0x1.3b07e0c779ddap-2, -0x1.bcp-106 }, + { 0x1.4169f234f23b9p-2, 0x1.46b7b3b358f99p-2, -0x1p-56 }, + { 0x1.616cc75d49226p-2, 0x1.687bd068c1c1ep-2, 0x1.ap-111 }, + { 0x1.ae3773250e7d2p-2, 0x1.bafc3479fc9ccp-2, -0x1p-105 }, ++ { 0x1.b7efa91915c95p-2, 0x1.c59869f17b483p-2, -0x1p-104 }, + { 0x1.d68039861ab53p-2, 0x1.e73b46abb01e1p-2, -0x1.2p-109 }, + { 0x1.e90f16eb88c09p-2, 0x1.fbdd4a37760b7p-2, -0x1.f8p-108 }, + { 0x1.a3fc7e4dd47d1p-1, 0x1.d4b21ebf542fp-1, 0x1.ep-107 }, +@@ -62,6 +63,7 @@ const double __sinh_data_db[49][3] = + { 0x1.43a81752eabe7p+3, 0x1.81d364845ecfap+13, -0x1p-90 }, + { 0x1.16369cd53bb69p+4, 0x1.0fbc6c02b1c9p+24, -0x1.9p-81 }, + { 0x1.20e29ea8b51e2p+4, 0x1.08b8abba28abcp+25, 0x1.9bp-79 }, ++ { 0x1.92a5c27afbe82p+4, 0x1.3c81f9a247253p+35, 0x1p-67 }, + { 0x1.a1e4f11b513d7p+4, 0x1.9a65b6c2e2185p+36, -0x1.bcp-70 }, + { 0x1.c089fcf166171p+4, 0x1.5c452e0e37569p+39, 0x1.4p-69 }, + { 0x1.e42a98b3a0be5p+4, 0x1.938768ca4f8aap+42, 0x1.6dp-62 }, +diff --git a/sysdeps/ieee754/dbl-64/e_sinh_data.h b/sysdeps/ieee754/dbl-64/e_sinh_data.h +index 16f7e0da5a..c34848fd54 100644 +--- a/sysdeps/ieee754/dbl-64/e_sinh_data.h ++++ b/sysdeps/ieee754/dbl-64/e_sinh_data.h +@@ -29,7 +29,7 @@ SOFTWARE. + + extern const double __sinh_data_ch[][2] attribute_hidden; + #define CH __sinh_data_ch +-extern const double __sinh_data_db[49][3] attribute_hidden; ++extern const double __sinh_data_db[51][3] attribute_hidden; + #define DB __sinh_data_db + + #endif + +commit 0b58f5d80d24cf83cfde9d8381aafb11fef0e152 +Author: Adhemerval Zanella +Date: Thu Jul 30 08:55:54 2026 -0300 + + math: Fix x86_64 tanh _FloatN aliases binding to the FMA variant [BZ 34465] + + The generic implementation emits libm_alias_double unconditionally, so + tanhf32x and tanhf64 bind directly to __tanh_fma. + + Guard the alias with '#ifndef __tanh' and emit it from the dispatcher, + as sin. Also remove the stale __expm1 defines, unused since tanh moved + to CORE-MATH. + + Checked on x86_64-linux-gnu, and with 'qemu-x86_64 -cpu Nehalem'. + + Reported-by: Michael Brunnbauer + + (cherry picked from commit b01abba04a954cbd6b2834c0643a08685a915fe5) + +diff --git a/NEWS b/NEWS +index fe2b1d7f79..43667c1963 100644 +--- a/NEWS ++++ b/NEWS +@@ -11,6 +11,7 @@ The following bugs are resolved with this release: + + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 ++ [34465] math: math: x86_64 tanh ifunc selection wrong + + Version 2.44 + +diff --git a/sysdeps/ieee754/dbl-64/s_tanh.c b/sysdeps/ieee754/dbl-64/s_tanh.c +index 2029de8fa5..ef80b9edb6 100644 +--- a/sysdeps/ieee754/dbl-64/s_tanh.c ++++ b/sysdeps/ieee754/dbl-64/s_tanh.c +@@ -283,4 +283,6 @@ __tanh (double x) + return as_tanh_database (x, res); + return res; + } ++#ifndef __tanh + libm_alias_double (__tanh, tanh) ++#endif +diff --git a/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c b/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c +index 1b808b1227..1e6b33740a 100644 +--- a/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c ++++ b/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c +@@ -1,10 +1,4 @@ + #define __tanh __tanh_fma +-#define __expm1 __expm1_fma +- +-/* NB: __expm1 may be expanded to __expm1_fma in the following +- prototypes. */ +-extern long double __expm1l (long double); +-extern long double __expm1f128 (long double); + + #define SECTION __attribute__ ((section (".text.fma"))) + +diff --git a/sysdeps/x86_64/fpu/multiarch/s_tanh.c b/sysdeps/x86_64/fpu/multiarch/s_tanh.c +index ec8826f634..9048c977c1 100644 +--- a/sysdeps/x86_64/fpu/multiarch/s_tanh.c ++++ b/sysdeps/x86_64/fpu/multiarch/s_tanh.c +@@ -25,10 +25,9 @@ extern double __redirect_tanh (double); + # define SYMBOL_NAME tanh + # include "ifunc-fma.h" + +-libc_ifunc_redirected (__redirect_tanh, tanh, IFUNC_SELECTOR ()); ++libc_ifunc_redirected (__redirect_tanh, __tanh, IFUNC_SELECTOR ()); ++libm_alias_double (__tanh, tanh) + + # define __tanh __tanh_sse2 +-# undef libm_alias_double +-# define libm_alias_double(a, b) + #endif + #include + +commit 9bcb85688e58847191deb42bfc68d60802078df4 +Author: Xi Ruoyao +Date: Wed Jul 22 19:26:10 2026 +0800 + + io: fix ftw ABI on MIPS n64 + + On MIPS n64 off_t is same as off64_t, but struct stat is not same as + struct stat64 (very peculiar but see the "as tempting as it..." comment + in linux/mips/kernel_stat.h). As the ftw/ftw64 callback accepts a + pointer to a function who accepts struct stat/stat64, for MIPS n64 we + must use different implementations for ftw and ftw64. + + Thus for testing if ftw64 can be aliased to ftw, we should check + XSTAT_IS_XSTAT64 instead of __OFF_T_MATCHES_OFF64_T. + + This resolves the io/tst-ftw-lnk failure observed on MIPS n64. + + Link: https://sourceware.org/glibc/wiki/Testing/Tests/io/tst-ftw-lnk + Signed-off-by: Xi Ruoyao + Reviewed-by: Adhemerval Zanella + + (cherry picked from commit 6758def717175e679cb49b5051b6b5ec54ddfb2c) + +diff --git a/io/ftw.c b/io/ftw.c +index ed0eeb3904..a9368a706e 100644 +--- a/io/ftw.c ++++ b/io/ftw.c +@@ -18,7 +18,9 @@ + + #include + +-#ifndef __OFF_T_MATCHES_OFF64_T ++#include ++ ++#if !XSTAT_IS_XSTAT64 + # include "ftw-common.c" + + versioned_symbol (libc, __new_nftw, nftw, GLIBC_2_3_3); +diff --git a/io/ftw64.c b/io/ftw64.c +index d3cd14c21a..fa7b05df22 100644 +--- a/io/ftw64.c ++++ b/io/ftw64.c +@@ -31,6 +31,9 @@ + #define ftw __rename_ftw + #define nftw __rename_nftw + ++#include ++ ++#include + #include + #include "ftw-common.c" + +@@ -44,7 +47,7 @@ versioned_symbol (libc, __new_nftw64, nftw64, GLIBC_2_3_3); + compat_symbol (libc, __old_nftw64, nftw64, GLIBC_2_1); + #endif + +-#ifdef __OFF_T_MATCHES_OFF64_T ++#if XSTAT_IS_XSTAT64 + weak_alias (__ftw64, ftw) + versioned_symbol (libc, __new_nftw64, nftw, GLIBC_2_3_3); + # if SHLIB_COMPAT(libc, GLIBC_2_1, GLIBC_2_3_3) + +commit 58da792d8a2d8f2fe711318836e853fcddfd7cd8 +Author: Adhemerval Zanella +Date: Tue Aug 4 14:25:48 2026 +0000 + + hurd: Fix build after the ftw kernel_stat.h inclusion + + Commit 6758def7171 changed the generic ftw{64}.c to include + kernel_stat.h, which is Linux specific. + + Add a Hurd version of kernel_stat.h defining XSTAT_IS_XSTAT64 to 0, + since struct stat and struct stat64 never share a layout on Hurd: on + 32-bit ABIs st_ino, st_size, and st_blocks are narrower in struct stat, + and on 64-bit ABIs the two structures still differ in size because + _SPARE_SIZE in bits/stat.h reserves three more ints of spare space in + struct stat than in struct stat64. + + This keeps the ftw/ftw64 symbols exactly as before the change, where + the aliasing check on __OFF_T_MATCHES_OFF64_T was always false because + the Hurd bits/typesizes.h does not define it. + + Checked with a full build for i686-gnu and x86_64-gnu. + + (cherry picked from commit d6031665c3a59faf75cf6bc55e041611da21d0e6) + +diff --git a/sysdeps/mach/hurd/kernel_stat.h b/sysdeps/mach/hurd/kernel_stat.h +new file mode 100644 +index 0000000000..aa8c26b1d9 +--- /dev/null ++++ b/sysdeps/mach/hurd/kernel_stat.h +@@ -0,0 +1,23 @@ ++/* Internal definitions for stat functions. Hurd version. ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++/* struct stat and struct stat64 never have the same layout: on 32-bit ++ ABIs st_ino, st_size, and st_blocks are narrower in struct stat, and ++ on 64-bit ABIs the two structures still differ in the amount of ++ trailing spare space (see _SPARE_SIZE in bits/stat.h). */ ++#define XSTAT_IS_XSTAT64 0 + +commit fec2a9c6765b548f9d738e3a1c63a63ad7061d40 +Author: Adhemerval Zanella +Date: Fri Mar 21 14:03:00 2025 +0000 + + linux: Inline syscall cancellation to keep wrapper frames observable (BZ 34338) + + The cancellable syscall wrappers end with a tail call to __syscall_cancel, + the wrapper frame is then elided, so when the syscall executes the wrapper + is no longer present on the stack. Tools that unwind from CFI alone, such + as valgrind, perf and sampling profilers, cannot observe it. On gdb, it + only recovers it from DWARF call site information, which reduced-debuginfo + libc builds usually omit. + + The behaviour is target dependent: for a shared (PIC) the tail call is + emitted on aarch64, arc, loongarch and riscv. It is not emitted on i386, + x86_64, arm, s390x, sparc and alpha, where the seventh argument is passed + on the stack or fewer argument registers are available, nor on powerpc + and mips, where the TOC/GOT pointer must be restored after the call. + This is why the problem was originally reported as aarch64 specific while + x86_64 was unaffected. + + Rather than only inhibiting the tail call [1] (which keeps the wrapper frame + but still leaves the __syscall_cancel and __internal_syscall_cancel + frames), move the cancellation logic back into the wrappers. In the + single-threaded case the syscall is now issued directly from the wrapper; + only the multi-threaded path still calls the out-of-line __syscall_cancel_arch. + + This keeps the wrapper observable and removes the extra frames, mimicking + how cancellation was handled before 89b53077d2a58f00e7debdfe58afabe953dac60d. + + The result is a small libc.so .text increase (size, first column): + + ABI master patched diff increase + aarch64 1635880 1647424 11544 0.71% + x86_64 1981081 1992257 11176 0.56% + powerpc64le 2364336 2376964 12628 0.53% + riscv64 1368386 1376704 8318 0.61% + loongarch64 1741385 1755601 14216 0.82% + + The tst-backtrace5 was suppose to track this issue, but due wrong + loop variable check it does not take this in account. This patch also fixes + it. + + Checked on aarch64-linux-gnu, x86_64-linux-gnu, i686-linux-gnu, + arm-linux-gnueabihf, and powerpc64le-linux-gnu. + + [1] https://sourceware.org/pipermail/libc-alpha/2025-March/165395.html + + (cherry picked from commit 1b5ff009fa5bf01ad26e6cc330a1df5a0c84135e) + +diff --git a/NEWS b/NEWS +index 43667c1963..28fbd9bcd8 100644 +--- a/NEWS ++++ b/NEWS +@@ -9,6 +9,8 @@ Version 2.44.1 + + The following bugs are resolved with this release: + ++ [34338] libc: Cancellable syscall wrappers are missing from backtraces ++ because they tail-call __syscall_cancel + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong +diff --git a/debug/tst-backtrace5.c b/debug/tst-backtrace5.c +index 4c5784c060..6538da9ab5 100644 +--- a/debug/tst-backtrace5.c ++++ b/debug/tst-backtrace5.c +@@ -36,10 +36,15 @@ + trampoline, read, 3 * fn, and do_test. */ + #define NUM_FUNCTIONS 7 + ++/* Avoid the read wrapper frame truncation on targets that add extra frames ++ between it and handle_signal (the cancellable syscall wrappers ++ __syscall_cancel*, or the i686 __kernel_vsyscall entry). */ ++#define MAX_FUNCTIONS 64 ++ + void + handle_signal (int signum) + { +- void *addresses[NUM_FUNCTIONS]; ++ void *addresses[MAX_FUNCTIONS]; + char **symbols; + int n; + int i; +@@ -70,23 +75,28 @@ handle_signal (int signum) + return; + } + +- /* Do not check name for signal trampoline or cancellable syscall +- wrappers (__syscall_cancel*). */ +- for (; i < n - 1; i++) ++ /* Skip the signal trampoline and any cancellable syscall wrapper frames ++ (__syscall_cancel*) and require the read syscall wrapper to be ++ present. */ ++ for (i = 1; i < n; i++) + if (match (symbols[i], "read")) + break; +- if (i == n - 1) ++ if (i == n) + { + FAIL (); + return; + } + +- for (; i < n - 1; i++) +- if (!match (symbols[i], "fn")) +- { +- FAIL (); +- return; +- } ++ /* The read wrapper must be followed by the three fn recursion frames. */ ++ for (int j = 0; j < 3; j++) ++ { ++ i++; ++ if (i == n || !match (symbols[i], "fn")) ++ { ++ FAIL (); ++ return; ++ } ++ } + /* Symbol names are not available for static functions, so we do not + check do_test. */ + +diff --git a/elf/Makefile b/elf/Makefile +index 94c5b7e6ed..8b063e1bba 100644 +--- a/elf/Makefile ++++ b/elf/Makefile +@@ -1574,7 +1574,9 @@ $(objpfx)dl-allobjs.os: $(all-rtld-routines:%=$(objpfx)%.os) + # when compiled for libc. + rtld-stubbed-symbols = \ + __libc_assert_fail \ +- __syscall_cancel \ ++ __libc_single_threaded_internal \ ++ __syscall_cancel_arch \ ++ __syscall_do_cancel \ + calloc \ + free \ + malloc \ +diff --git a/nptl/cancellation.c b/nptl/cancellation.c +index 4368cb7231..63f09840ff 100644 +--- a/nptl/cancellation.c ++++ b/nptl/cancellation.c +@@ -19,66 +19,6 @@ + #include + #include "pthreadP.h" + +-/* Called by the INTERNAL_SYSCALL_CANCEL macro, check for cancellation and +- returns the syscall value or its negative error code. */ +-long int +-__internal_syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, +- __syscall_arg_t a3, __syscall_arg_t a4, +- __syscall_arg_t a5, __syscall_arg_t a6, +- __SYSCALL_CANCEL7_ARG_DEF +- __syscall_arg_t nr) +-{ +- long int result; +- struct pthread *pd = THREAD_SELF; +- +- /* If cancellation is not enabled, call the syscall directly and also +- for thread terminatation to avoid call __syscall_do_cancel while +- executing cleanup handlers. */ +- int ch = atomic_load_relaxed (&pd->cancelhandling); +- if (SINGLE_THREAD_P || !cancel_enabled (ch) || cancel_exiting (ch)) +- { +- result = INTERNAL_SYSCALL_NCS_CALL (nr, a1, a2, a3, a4, a5, a6 +- __SYSCALL_CANCEL7_ARCH_ARG7); +- if (INTERNAL_SYSCALL_ERROR_P (result)) +- return -INTERNAL_SYSCALL_ERRNO (result); +- return result; +- } +- +- /* Call the arch-specific entry points that contains the globals markers +- to be checked by SIGCANCEL handler. */ +- result = __syscall_cancel_arch (&pd->cancelhandling, nr, a1, a2, a3, a4, a5, +- a6 __SYSCALL_CANCEL7_ARCH_ARG7); +- +- /* If the cancellable syscall was interrupted by SIGCANCEL and it has no +- side-effect, cancel the thread if cancellation is enabled. */ +- ch = atomic_load_relaxed (&pd->cancelhandling); +- /* The behaviour here assumes that EINTR is returned only if there are no +- visible side effects. POSIX Issue 7 has not yet provided any stronger +- language for close, and in theory the close syscall could return EINTR +- and leave the file descriptor open (conforming and leaks). It expects +- that no such kernel is used with glibc. */ +- if (result == -EINTR && cancel_enabled_and_canceled (ch)) +- __syscall_do_cancel (); +- +- return result; +-} +- +-/* Called by the SYSCALL_CANCEL macro, check for cancellation and return the +- syscall expected success value (usually 0) or, in case of failure, -1 and +- sets errno to syscall return value. */ +-long int +-__syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, +- __syscall_arg_t a3, __syscall_arg_t a4, +- __syscall_arg_t a5, __syscall_arg_t a6, +- __SYSCALL_CANCEL7_ARG_DEF __syscall_arg_t nr) +-{ +- long int r = __internal_syscall_cancel (a1, a2, a3, a4, a5, a6, +- __SYSCALL_CANCEL7_ARG nr); +- return __glibc_unlikely (INTERNAL_SYSCALL_ERROR_P (r)) +- ? SYSCALL_ERROR_LABEL (INTERNAL_SYSCALL_ERRNO (r)) +- : r; +-} +- + /* Called by __syscall_cancel_arch or function above start the thread + cancellation. */ + _Noreturn void +diff --git a/nptl/futex-internal.c b/nptl/futex-internal.c +index fc6b11c8ad..07f1462abe 100644 +--- a/nptl/futex-internal.c ++++ b/nptl/futex-internal.c +@@ -17,7 +17,7 @@ + . */ + + #include +-#include ++#include + #include + #include + #include +diff --git a/nptl/sem_waitcommon.c b/nptl/sem_waitcommon.c +index b0cbe5cebf..82c686f020 100644 +--- a/nptl/sem_waitcommon.c ++++ b/nptl/sem_waitcommon.c +@@ -18,7 +18,7 @@ + + #include + #include +-#include ++#include + #include + #include + #include +diff --git a/sysdeps/unix/sysdep.h b/sysdeps/unix/sysdep.h +index a6ce5348ec..f0f271ec02 100644 +--- a/sysdeps/unix/sysdep.h ++++ b/sysdeps/unix/sysdep.h +@@ -154,42 +154,31 @@ + # define __SYSCALL_CANCEL7_ARG7 + # define __SYSCALL_CANCEL7_ARCH_ARG7 + #endif +-long int __internal_syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, +- __syscall_arg_t a3, __syscall_arg_t a4, +- __syscall_arg_t a5, __syscall_arg_t a6, +- __SYSCALL_CANCEL7_ARG_DEF +- __syscall_arg_t nr) attribute_hidden; +- +-long int __syscall_cancel (__syscall_arg_t arg1, __syscall_arg_t arg2, +- __syscall_arg_t arg3, __syscall_arg_t arg4, +- __syscall_arg_t arg5, __syscall_arg_t arg6, +- __SYSCALL_CANCEL7_ARG_DEF +- __syscall_arg_t nr) attribute_hidden; + + #define __SYSCALL_CANCEL0(name) \ +- __syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL1(name, a1) \ +- __syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL2(name, a1, a2) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL3(name, a1, a2, a3) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL4(name, a1, a2, a3, a4) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC(a4), 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC(a4), 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL5(name, a1, a2, a3, a4, a5) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC(a4), \ +- __SSC (a5), 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC(a4), \ ++ __SSC (a5), 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL6(name, a1, a2, a3, a4, a5, a6) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ +- __SSC (a5), __SSC (a6), __SYSCALL_CANCEL7_ARG \ +- __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ ++ __SSC (a5), __SSC (a6), __SYSCALL_CANCEL7_ARG \ ++ __NR_##name) + #define __SYSCALL_CANCEL7(name, a1, a2, a3, a4, a5, a6, a7) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ +- __SSC (a5), __SSC (a6), __SSC (a7), __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ ++ __SSC (a5), __SSC (a6), __SSC (a7), __NR_##name) + + #define __SYSCALL_CANCEL_NARGS_X(a,b,c,d,e,f,g,h,n,...) n + #define __SYSCALL_CANCEL_NARGS(...) \ +@@ -206,33 +195,33 @@ long int __syscall_cancel (__syscall_arg_t arg1, __syscall_arg_t arg2, + __SYSCALL_CANCEL_DISP (__SYSCALL_CANCEL, __VA_ARGS__) + + #define __INTERNAL_SYSCALL_CANCEL0(name) \ +- __internal_syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG \ ++ internal_syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG \ + __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL1(name, a1) \ +- __internal_syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL2(name, a1, a2) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL3(name, a1, a2, a3) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, \ +- 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, \ ++ 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL4(name, a1, a2, a3, a4) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC(a4), 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC(a4), 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL5(name, a1, a2, a3, a4, a5) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC(a4), __SSC (a5), 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC(a4), __SSC (a5), 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL6(name, a1, a2, a3, a4, a5, a6) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC (a4), __SSC (a5), __SSC (a6), \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC (a4), __SSC (a5), __SSC (a6), \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL7(name, a1, a2, a3, a4, a5, a6, a7) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC (a4), __SSC (a5), __SSC (a6), \ +- __SSC (a7), __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC (a4), __SSC (a5), __SSC (a6), \ ++ __SSC (a7), __NR_##name) + + /* Issue a cancellable syscall defined by syscall number NAME plus any other + argument required. If an error occurs its value is returned as an negative +diff --git a/sysdeps/unix/sysv/linux/epoll_pwait2.c b/sysdeps/unix/sysv/linux/epoll_pwait2.c +index 4da03e3e69..76ec1f8a71 100644 +--- a/sysdeps/unix/sysv/linux/epoll_pwait2.c ++++ b/sysdeps/unix/sysv/linux/epoll_pwait2.c +@@ -17,7 +17,7 @@ + . */ + + #include +-#include ++#include + + int + __epoll_pwait2_time64 (int fd, struct epoll_event *ev, int maxev, +diff --git a/sysdeps/unix/sysv/linux/recvmmsg.c b/sysdeps/unix/sysv/linux/recvmmsg.c +index 6fbe4b80aa..6a89f914c2 100644 +--- a/sysdeps/unix/sysv/linux/recvmmsg.c ++++ b/sysdeps/unix/sysv/linux/recvmmsg.c +@@ -16,7 +16,7 @@ + . */ + + #include +-#include ++#include + #include + + static int +diff --git a/sysdeps/unix/sysv/linux/sigtimedwait.c b/sysdeps/unix/sysv/linux/sigtimedwait.c +index a4fa8e9e8e..c2c5e2c0f2 100644 +--- a/sysdeps/unix/sysv/linux/sigtimedwait.c ++++ b/sysdeps/unix/sysv/linux/sigtimedwait.c +@@ -16,7 +16,7 @@ + . */ + + #include +-#include ++#include + + int + __sigtimedwait64 (const sigset_t *set, siginfo_t *info, +diff --git a/sysdeps/unix/sysv/linux/sysdep-cancel.h b/sysdeps/unix/sysv/linux/sysdep-cancel.h +index 7fd8258ba5..4b7278915a 100644 +--- a/sysdeps/unix/sysv/linux/sysdep-cancel.h ++++ b/sysdeps/unix/sysv/linux/sysdep-cancel.h +@@ -21,5 +21,66 @@ + #define _SYSDEP_CANCEL_H + + #include ++#include "pthreadP.h" ++ ++/* Called by the INTERNAL_SYSCALL_CANCEL macro, check for cancellation and ++ returns the syscall value or its negative error code. */ ++static __always_inline long int ++internal_syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, ++ __syscall_arg_t a3, __syscall_arg_t a4, ++ __syscall_arg_t a5, __syscall_arg_t a6, ++ __SYSCALL_CANCEL7_ARG_DEF ++ __syscall_arg_t nr) ++{ ++ long int result; ++ struct pthread *pd = THREAD_SELF; ++ ++ /* If cancellation is not enabled, call the syscall directly and also ++ for thread terminatation to avoid call __syscall_do_cancel while ++ executing cleanup handlers. */ ++ int ch = atomic_load_relaxed (&pd->cancelhandling); ++ if (SINGLE_THREAD_P || !cancel_enabled (ch) || cancel_exiting (ch)) ++ { ++ result = INTERNAL_SYSCALL_NCS_CALL (nr, a1, a2, a3, a4, a5, a6 ++ __SYSCALL_CANCEL7_ARCH_ARG7); ++ if (INTERNAL_SYSCALL_ERROR_P (result)) ++ return -INTERNAL_SYSCALL_ERRNO (result); ++ return result; ++ } ++ ++ /* Call the arch-specific entry points that contains the globals markers ++ to be checked by SIGCANCEL handler. */ ++ result = __syscall_cancel_arch (&pd->cancelhandling, nr, a1, a2, a3, a4, a5, ++ a6 __SYSCALL_CANCEL7_ARCH_ARG7); ++ ++ /* If the cancellable syscall was interrupted by SIGCANCEL and it has no ++ side-effect, cancel the thread if cancellation is enabled. */ ++ ch = atomic_load_relaxed (&pd->cancelhandling); ++ /* The behaviour here assumes that EINTR is returned only if there are no ++ visible side effects. POSIX Issue 7 has not yet provided any stronger ++ language for close, and in theory the close syscall could return EINTR ++ and leave the file descriptor open (conforming and leaks). It expects ++ that no such kernel is used with glibc. */ ++ if (result == -EINTR && cancel_enabled_and_canceled (ch)) ++ __syscall_do_cancel (); ++ ++ return result; ++} ++ ++/* Called by the SYSCALL_CANCEL macro, check for cancellation and return the ++ syscall expected success value (usually 0) or, in case of failure, -1 and ++ sets errno to syscall return value. */ ++static __always_inline long int ++syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, ++ __syscall_arg_t a3, __syscall_arg_t a4, ++ __syscall_arg_t a5, __syscall_arg_t a6, ++ __SYSCALL_CANCEL7_ARG_DEF __syscall_arg_t nr) ++{ ++ long int r = internal_syscall_cancel (a1, a2, a3, a4, a5, a6, ++ __SYSCALL_CANCEL7_ARG nr); ++ return __glibc_unlikely (INTERNAL_SYSCALL_ERROR_P (r)) ++ ? SYSCALL_ERROR_LABEL (INTERNAL_SYSCALL_ERRNO (r)) ++ : r; ++} + + #endif + +commit 5d1e923ed79185668ac62d19fc37e7e23a3642b6 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:55 2026 -0300 + + Fix gen-as-const-headers races with the parallel subdir recursion (BZ 34438) + + The parallel subdirectory recursion (commit 7cac99621e96) only orders + csu (and mach/hurd on Hurd) before the parallel fan-out plus the edges + the Depend files request. A header generated from gen-as-const-headers + is only ordered before the compilations of the subdirectory that + adds the .sym (through before-compile), so a header consumed by a + different subdirectory may not exist yet when its consumer is + compiled. + + That is the case for : it is generated when + building misc, while its only consumer, ____longjmp_chk.S (x86_64 and + sh), is built in debug. The serial recursion always ran misc before + debug in the sorted order, hiding the missing dependency. + + Move the generate the header to 'debug' instead. + + The same class of problem exists on Hurd: jmp_buf-ssp.h that is used + by ____longjmp_chk.S in debug, and signal-defines.h that is sued + by debug and setjmp. + + Deterministically reproduced with 'make debug/subdir_lib' from a clean + build tree (which orders only csu before debug), and verified with + builds for x86_64-linux-gnu, sh4-linux-gnu, i686-gnu, and x86_64-gnu. + Reviewed-by: Sam James + + (cherry picked from commit 60c9ed0e6b9cce07e85ee56fc39b9afe36919e45) + +diff --git a/Makerules b/Makerules +index 6bef57ece9..cef30974f1 100644 +--- a/Makerules ++++ b/Makerules +@@ -259,7 +259,17 @@ endif # gen-py-const-headers + ifdef gen-as-const-headers + # Generating headers for assembly constants. + # We need this defined early to get into before-compile before +-# it's used in sysd-rules, below. ++# it's used in sysd-rules, below. The gen-as-const-headers is evaluated ++# per subdirectory, so the before-compile dependency below only orders ++# the generated header before the compiles of the subdirectory whose ++# Makefile adds the .sym directive. ++# The parallel subdirectory recursion does not order sibling subdirectories, ++# so a .sym must be added in the subdirectory that compiles its consumers, ++# or in csu (which runs before the parallel) when it has consumers in ++# several subdirectories. ++# It must not add the same .sym in several subdirectories though: their ++# concurrent sub-makes would race generating the header through the fixed ++# temporary files below. + # Define GEN_AS_CONST_HEADERS to avoid circular dependency [BZ #22792]. + # NB: is generated from tcb-offsets.sym to define + # offsets and sizes of types in and maybe which +diff --git a/NEWS b/NEWS +index 28fbd9bcd8..ee292ff6c9 100644 +--- a/NEWS ++++ b/NEWS +@@ -11,6 +11,8 @@ The following bugs are resolved with this release: + + [34338] libc: Cancellable syscall wrappers are missing from backtraces + because they tail-call __syscall_cancel ++ [34438] build: non reproducible build failure: sigaltstack-offsets.h: ++ No such file or directory + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong +diff --git a/sysdeps/mach/hurd/x86/Makefile b/sysdeps/mach/hurd/x86/Makefile +index 97e3287c87..1d94f3a1c1 100644 +--- a/sysdeps/mach/hurd/x86/Makefile ++++ b/sysdeps/mach/hurd/x86/Makefile +@@ -3,11 +3,7 @@ sysdep_routines += ioperm + sysdep_headers += sys/io.h + endif + +-ifeq ($(subdir),debug) +-gen-as-const-headers += signal-defines.sym +-endif +- +-ifeq ($(subdir),setjmp) ++ifeq ($(subdir),csu) + gen-as-const-headers += signal-defines.sym + endif + +diff --git a/sysdeps/unix/sysv/linux/sh/Makefile b/sysdeps/unix/sysv/linux/sh/Makefile +index dd3b382ac1..8c4cb73824 100644 +--- a/sysdeps/unix/sysv/linux/sh/Makefile ++++ b/sysdeps/unix/sysv/linux/sh/Makefile +@@ -6,7 +6,9 @@ ifeq ($(subdir),stdlib) + gen-as-const-headers += ucontext_i.sym + endif + +-ifeq ($(subdir),misc) ++# is only used by ____longjmp_chk.S, which is ++# built in the debug subdirectory. ++ifeq ($(subdir),debug) + gen-as-const-headers += sigaltstack-offsets.sym + endif + +diff --git a/sysdeps/unix/sysv/linux/x86_64/Makefile b/sysdeps/unix/sysv/linux/x86_64/Makefile +index 6938382801..528fd951b2 100644 +--- a/sysdeps/unix/sysv/linux/x86_64/Makefile ++++ b/sysdeps/unix/sysv/linux/x86_64/Makefile +@@ -10,7 +10,9 @@ ifeq ($(subdir),csu) + gen-as-const-headers += ucontext_i.sym + endif + +-ifeq ($(subdir),misc) ++# is only used by ____longjmp_chk.S, which is ++# built in the debug subdirectory. ++ifeq ($(subdir),debug) + gen-as-const-headers += sigaltstack-offsets.sym + endif + +diff --git a/sysdeps/x86/Makefile b/sysdeps/x86/Makefile +index 232e388d32..b4434deb0c 100644 +--- a/sysdeps/x86/Makefile ++++ b/sysdeps/x86/Makefile +@@ -1,5 +1,12 @@ + ifeq ($(subdir),csu) +-gen-as-const-headers += cpu-features-offsets.sym features-offsets.sym ++# is used by the setjmp/longjmp implementations in the ++# setjmp subdirectory and also by ____longjmp_chk.S in the debug ++# subdirectory. ++gen-as-const-headers += \ ++ cpu-features-offsets.sym \ ++ features-offsets.sym \ ++ jmp_buf-ssp.sym \ ++ # gen-as-const-headers + endif + + ifeq ($(subdir),elf) +@@ -171,7 +178,6 @@ tests += \ + endif # $(subdir) == math + + ifeq ($(subdir),setjmp) +-gen-as-const-headers += jmp_buf-ssp.sym + sysdep_routines += __longjmp_cancel + endif + + +commit 45b8a13c48da92bc5dd6fe102011391dd6847862 +Author: Rudi Heitbaum +Date: Thu Aug 6 14:07:56 2026 -0300 + + Makerules: Only install the ABI lib-names header from the top level (BZ 34439) + + The $(inst_includedir)/%.h install rules exist only where $(headers) is + non-empty, so in a subdir without headers (e.g. csu) the prerequisite + added on install-others-nosubdir has no rule. + + It only worked because .NOTPARALLEL made the top level install the header + first, which the parallel subdir recursion no longer guarantees. + Reviewed-by: Sam James + + (cherry picked from commit 82c0a96b8e63005a49ba52ddb21993811030613f) + +diff --git a/Makerules b/Makerules +index cef30974f1..dfe66b7fa6 100644 +--- a/Makerules ++++ b/Makerules +@@ -312,7 +312,12 @@ lib-names-h-abi = gnu/lib-names-$(default-abi).h + lib-names-stmp-abi = gnu/lib-names-$(default-abi).stmp + before-compile += $(common-objpfx)$(lib-names-h-abi) + common-generated += gnu/lib-names.h ++# The $(inst_includedir)/%.h install rules are defined only where $(headers) ++# is non-empty, and with parallel subdir recursion a subdir without headers ++# (e.g. csu) may run before the top level has installed the header. ++ifndef subdir + install-others-nosubdir: $(inst_includedir)/$(lib-names-h-abi) ++endif + $(common-objpfx)gnu/lib-names.h: + $(make-target-directory) + { \ +diff --git a/NEWS b/NEWS +index ee292ff6c9..d0ef2d3e9a 100644 +--- a/NEWS ++++ b/NEWS +@@ -13,6 +13,8 @@ The following bugs are resolved with this release: + because they tail-call __syscall_cancel + [34438] build: non reproducible build failure: sigaltstack-offsets.h: + No such file or directory ++ [34439] build: parallel make install fails on multi-ABI targets: no ++ rule to make $(inst_includedir)/gnu/lib-names-$(abi).h in csu + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong + +commit f7beb24f3ad5dbf8e84a5b75d5b2428a262e9ab9 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:57 2026 -0300 + + Makefile: Only print the test summary in the second pass of 'make check' + + The build-only first pass of the two-pass 'make check' still runs the + static checks (abi, conformtest, installed headers, etc.), and the + top-level tests recipe merged and summarized their results. + + An unexpected FAIL there (e.g. check-abi) aborted 'check' before the + second pass ran any built test, and even a clean run printed a misleading + partial summary. + + Pass tests-summary=no in the first pass to skip the merge and summary; + the .test-result files persist, so the second pass folds those results + into the one complete summary at the end, restoring the single-pass + reporting behavior. + Reviewed-by: Sam James + + (cherry picked from commit 96a9a09d7d5527462a823c247569e65feeca8ddb) + +diff --git a/Makefile b/Makefile +index a6aabca691..b9fac6f47c 100644 +--- a/Makefile ++++ b/Makefile +@@ -869,7 +869,11 @@ endif + touch $(objpfx)testroot.pristine/install.stamp + + tests-special-notdir = $(patsubst $(objpfx)%, %, $(tests-special)) ++# The build-only first pass of the two-pass 'make check' (see Makerules) ++# passes tests-summary=no: the merge and summary are left to the second ++# pass, which folds in this pass's $(tests-special) results. + tests: $(tests-special) ++ifneq ($(tests-summary),no) + $(..)scripts/merge-test-results.sh -s $(objpfx) "" \ + $(sort $(tests-special-notdir:.out=)) \ + > $(objpfx)subdir-tests.sum +@@ -877,11 +881,14 @@ tests: $(tests-special) + $(sort $(subdirs) .) \ + > $(objpfx)tests.sum + $(call summarize-tests,tests.sum) ++endif + xtests: ++ifneq ($(tests-summary),no) + $(..)scripts/merge-test-results.sh -t $(objpfx) subdir-xtests.sum \ + $(sort $(subdirs)) \ + > $(objpfx)xtests.sum + $(call summarize-tests,xtests.sum, for extra tests) ++endif + + # The realclean target is just like distclean for the parent, but we want + # the subdirs to know the difference in case they care. +diff --git a/Makerules b/Makerules +index dfe66b7fa6..5f65f3ab9e 100644 +--- a/Makerules ++++ b/Makerules +@@ -1211,6 +1211,13 @@ ALL_BUILD_CFLAGS = $(BUILD_CFLAGS) $(BUILD_CPPFLAGS) -D_GNU_SOURCE \ + # therefore builds the test programs (run-built-tests=no, recursion fully + # parallel) and then runs them (run-built-tests=yes). 'make tests' and a + # subdirectory's own 'check' stay single-pass. ++# The first pass still runs the static checks ($(tests-special): abi, ++# conformtest, installed headers, ...), so tests-summary=no makes it skip ++# the results merge and summary: an unexpected FAIL there would otherwise ++# abort 'check' before the second pass runs any built test, and even a ++# clean run would print a misleading partial summary. The .test-result ++# files persist, so the second pass folds those results into the one ++# complete summary at the end. + check-twopass := + ifndef subdir + ifeq (yes,$(run-built-tests)) +@@ -1219,10 +1226,10 @@ endif + endif + ifeq (yes,$(check-twopass)) + check: +- $(MAKE) run-built-tests=no tests ++ $(MAKE) run-built-tests=no tests-summary=no tests + $(MAKE) run-built-tests=yes tests + xcheck: +- $(MAKE) run-built-tests=no xtests ++ $(MAKE) run-built-tests=no tests-summary=no xtests + $(MAKE) run-built-tests=yes xtests + else + check: tests + +commit fc3641194619c7c327ef398c88c07b3069878ed3 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:58 2026 -0300 + + Makerules: Make the .dt to .d conversion safe against concurrent sub-makes + + The %.d: %.dt rule seds its input into a fixed temporary name, renames + it into place and removes the input. Two makes converting the same + file trip over each other: + + mv: cannot stat '.../test-double-libmvec-sincos-avx512f.o.T': No such file or directory + sed: can't read .../test-float-libmvec-acosf-avx512f.o.dt: No such file or directory + + That happens because the elf rtld-Rules recursion runs a sub-make over + every $(rtld-subdirs) directory, which converts that directory's .dt + files, and the parallel subdirectory recursion (commit 7cac99621e96) + runs it concurrently with those subdirectories' own sub-makes. + + Add the PID of the shell to the temporary name and claim the input with + a rename: only the run that wins converts and installs the target. + Reviewed-by: Sam James + + (cherry picked from commit ba8c8801be7674cc12406914184516a811ac22a8) + +diff --git a/Makerules b/Makerules +index 5f65f3ab9e..be51154bae 100644 +--- a/Makerules ++++ b/Makerules +@@ -758,10 +758,20 @@ all-dt-files := $(foreach o,$(object-suffixes-for-libc),$(+depfiles:.d=$o.dt)) + $(wildcard $(all-dt-files:.dt=.d)) + + # This is a funny rule in that it removes its input file. ++# ++# More than one make can convert the .dt files of a single object ++# directory: the elf rtld-Rules recursion runs a sub-make over every ++# $(rtld-subdirs) directory, concurrently with that directory's own ++# sub-make under the parallel subdir recursion. Add the PID of the ++# shell to the temporary name and claim the input with a rename: only ++# the run that wins converts and installs the target. + %.d: %.dt +- @sed $(sed-remove-objpfx) $< > $(@:.d=.T) && \ +- mv -f $(@:.d=.T) $@ && \ +- rm -f $< ++ @dt=$(@:.d=.T)$$$$; \ ++ if mv -f $< $$dt 2>/dev/null; then \ ++ sed $(sed-remove-objpfx) $$dt > $$dt.new && \ ++ mv -f $$dt.new $@ && \ ++ rm -f $$dt; \ ++ fi + + # Avoid the .h.d files for any .sym files whose .h files don't exist yet. + # They will be generated when they're needed, and trying too early won't work. +@@ -1433,7 +1443,7 @@ endef + # Also remove the dependencies and generated source files. + common-clean: common-mostlyclean + -rm -f $(addprefix $(objpfx),$(generated)) +- -rm -f $(objpfx)*.d $(objpfx)*.dt ++ -rm -f $(objpfx)*.d $(objpfx)*.dt $(objpfx)*.T[0-9]* + -rm -fr $(addprefix $(objpfx),$(generated-dirs)) + -rm -f $(addprefix $(common-objpfx),$(common-generated)) + -rm -f $(gen-as-const-headers:%.sym=$(common-objpfx)%.h) + +commit f34027b27fefbc94aab04bff613ba5c24fb909b1 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:59 2026 -0300 + + Makefile: Order the top-level stamp files before the subdirectory fan-out + + The archive rules in Makerules list every stamp file as a prerequisite, + including the top level's own, and the elf sub-make evaluates them to + build libc_pic.a for the librtld.map link. A sub-make can only create + the stamp files of its own directory, so when the top-level ones do not + exist yet it fails with: + + make[2]: *** No rule to make target '.../stamp.os', needed by + '.../libc_pic.a'. Stop. + + The serial recursion created them before the subdirectories through the + prerequisite order of subdir_lib; the parallel recursion (commit + 7cac99621e96) does not. Add them as prerequisites of the object-building + per-subdirectory targets. + Reviewed-by: Sam James + + (cherry picked from commit 25c42d04c45fc5fdb1481a7f968782791b21fd3e) + +diff --git a/Makefile b/Makefile +index b9fac6f47c..d559c42873 100644 +--- a/Makefile ++++ b/Makefile +@@ -575,6 +575,14 @@ $(foreach t,$(+elf_last_subdir_targets),$(eval \ + elf/$(t): $(addsuffix /$(t),$(filter-out elf,$(subdirs))))) + endif + ++# The archive rules in Makerules list every stamp file as a ++# prerequisite of libc_pic.a, which the elf sub-make evaluates for the ++# librtld.map link, but a sub-make can only create its own directory's ++# stamps. Create the top-level ones before the fan-out. ++$(foreach t,$(+elf_last_subdir_targets),$(eval \ ++ $(addsuffix /$(t),$(subdirs)): \ ++ $(foreach o,$(object-suffixes-for-libc),$(common-objpfx)stamp$(o)))) ++ + # Pass barriers: a subdirectory 'others' build links programs against + # the libraries, so the 'lib' pass (including the top-level libc.so + # link) must have completed. + +commit 10e3ce8a57e134c13dd28772de68542b0e3d4e86 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:08:00 2026 -0300 + + arm: Order the rtld link after libgcc-stubs.a + + The librtld.map and librtld.os link recipes use $(gnulib), which on arm + contains libgcc-stubs.a through gnulib-arch. But the archive is only a + prerequisite of lib-noranlib so the rtld link can run before the archive + exists: + + ld.bfd: cannot find .../elf/libgcc-stubs.a: No such file or directory + + The race seems to predates the parallel subdirectory recursion, which + only made it observable. + + Add the order-only dependency in sysdeps/arm/Makefile rather than in + elf/Makefile. Theprerequisite lists expand when the rule is parsed, + and gnulib-arch is only defined once Makerules includes the sysdeps + makefiles. + + Verified with a build for arm-linux-gnueabihf. + Reviewed-by: Sam James + + (cherry picked from commit a33ceb6e96dc8de8d36de1b1f3ec06ceb524d012) + +diff --git a/sysdeps/arm/Makefile b/sysdeps/arm/Makefile +index 0bb1b6e05b..9042315492 100644 +--- a/sysdeps/arm/Makefile ++++ b/sysdeps/arm/Makefile +@@ -10,6 +10,11 @@ shared-only-routines += aeabi_unwind_cpp_pr1 + $(objpfx)libgcc-stubs.a: $(objpfx)aeabi_unwind_cpp_pr1.os + $(build-extra-lib) + ++# The rtld link recipes in elf/Makefile use $(gnulib), which here ++# includes libgcc-stubs.a, but they cannot name it as a prerequisite: ++# gnulib-arch is only defined once this file is included from Makerules. ++$(objpfx)librtld.map $(objpfx)librtld.os: | $(objpfx)libgcc-stubs.a ++ + lib-noranlib: $(objpfx)libgcc-stubs.a + + ifeq ($(build-shared),yes) + +commit 26b9cc42a051f78233fcecd2a3b83f98ec9862b9 +Author: Adhemerval Zanella +Date: Tue Jul 28 11:27:33 2026 -0300 + + benchtests: Create objdir in the bench-%.c generation rule + + The $(objpfx)bench-%.c rule writes its output into $(objpfx) without + ensuring that directory exists. Serial builds happened to satisfy + that ordering, with parallel builds the generation recipe can + run before the directory is created, failing with: + + cannot create .../benchtests/bench-xxx.c-tmp: Directory nonexistent + + Add the standard $(make-target-directory). + + Reviewed-by: Florian Weimer + (cherry picked from commit 26f0f2aa7d6ea63f85b5186349c41de2c91b4dd7) + +diff --git a/benchtests/Makefile b/benchtests/Makefile +index f407e492cb..16cc951d19 100644 +--- a/benchtests/Makefile ++++ b/benchtests/Makefile +@@ -622,6 +622,7 @@ $(bench-link-targets): %: %.o $(objpfx)json-lib.o \ + $(bench-link-targets): LDFLAGS += $(link-bench-bind-now) + + $(objpfx)bench-%.c: %-inputs $(bench-deps) ++ $(make-target-directory) + { if [ -n "$($*-INCLUDE)" ]; then \ + cat $($*-INCLUDE); \ + fi; \ + +commit 4662c4675d7f3ba87637c61730f06071f305c5cb +Author: Xi Ruoyao +Date: Sun Jul 26 00:11:44 2026 +0800 + + elf: test: handle different rootsbindir in tst-ldconfig-cache + + When compiling a glibc for a merged-/usr distro people may set + rootsbindir=/usr/sbin. But tst-ldconfig-cache has hard-coded + /sbin/ldconfig path and so it fails with a different rootsbindir. + + Fix it by using support_install_rootsbindir like run_ldconfig in + test-container.c. + + Signed-off-by: Xi Ruoyao + Reviewed-by: Florian Weimer + (cherry picked from commit 02ea17b5add83a205d8b204dce28f38fe0498ea3) + +diff --git a/elf/tst-ldconfig-cache.c b/elf/tst-ldconfig-cache.c +index 9f71418b3a..f4820a1822 100644 +--- a/elf/tst-ldconfig-cache.c ++++ b/elf/tst-ldconfig-cache.c +@@ -85,7 +85,10 @@ corrupt (void) + static void + ldconfig (void) + { +- xsystem ("/sbin/ldconfig -X"); ++ char *cmd = xasprintf("%s/ldconfig -X", support_install_rootsbindir); ++ xsystem (cmd); ++ ++ free(cmd); + } + + /* Change ld.so.conf to refer to the new directory, and generate a new + +commit 9e1b1ef77c7b1cc58f625500e9ea74fb3cafdf12 +Author: Matt Turner +Date: Sun Jul 26 00:27:37 2026 -0400 + + ldbl-opt: Fix -mlong-double-128 configure test for Clang + + The check for -mlong-double-128 support wrapped its test code in + AC_LANG_PROGRAM, which places the body inside main(). The body defines + a function, so it became a nested function definition -- a GCC extension + that Clang does not implement, making the test fail (and thus the whole + build error out) with Clang even though it supports -mlong-double-128. + + Use AC_LANG_SOURCE so the function is defined at file scope, matching the + pattern already used by the powerpc64le compiler checks, and regenerate + configure. + + Reviewed-by: Sam James + (cherry picked from commit e7a14f03b8d5e34e8ac46db6c377da5c66a3ec2a) + +diff --git a/sysdeps/ieee754/ldbl-opt/configure b/sysdeps/ieee754/ldbl-opt/configure +old mode 100644 +new mode 100755 +index bc6552da0b..7769cc9781 +--- a/sysdeps/ieee754/ldbl-opt/configure ++++ b/sysdeps/ieee754/ldbl-opt/configure +@@ -13,17 +13,10 @@ CFLAGS="$CFLAGS -mlong-double-128" + cat confdefs.h - <<_ACEOF >conftest.$ac_ext + /* end confdefs.h. */ + +-int +-main (void) +-{ +- + #ifndef __LONG_DOUBLE_128__ + # error "compiler did not predefine __LONG_DOUBLE_128__ as expected" + #endif + long double foobar (long double x) { return x; } +- ; +- return 0; +-} + _ACEOF + if ac_fn_c_try_compile "$LINENO" + then : +diff --git a/sysdeps/ieee754/ldbl-opt/configure.ac b/sysdeps/ieee754/ldbl-opt/configure.ac +index 70e3b32dc6..1c500ad581 100644 +--- a/sysdeps/ieee754/ldbl-opt/configure.ac ++++ b/sysdeps/ieee754/ldbl-opt/configure.ac +@@ -6,7 +6,7 @@ AC_CACHE_CHECK(whether $CC $CFLAGS supports -mlong-double-128, + libc_cv_mlong_double_128, [dnl + save_CFLAGS="$CFLAGS" + CFLAGS="$CFLAGS -mlong-double-128" +-AC_COMPILE_IFELSE([AC_LANG_PROGRAM([[]], [[ ++AC_COMPILE_IFELSE([AC_LANG_SOURCE([[ + #ifndef __LONG_DOUBLE_128__ + # error "compiler did not predefine __LONG_DOUBLE_128__ as expected" + #endif + +commit eacd9cced93498e671c7e7f758aaf52593847e01 +Author: Matt Turner +Date: Sun Jul 26 14:43:11 2026 -0400 + + powerpc: Fix -mlong-double-128 IBM format configure test for Clang + + The check for -mlong-double-128 IBM extended format support wrapped its + test code in AC_LANG_PROGRAM, which places the body inside main(). The + body defines a function, so it became a nested function definition -- a + GCC extension that Clang does not implement, making the test fail with + Clang. + + Use AC_LANG_SOURCE so the function is defined at file scope, and + regenerate configure. + + Reviewed-by: Sam James + (cherry picked from commit 559d0f77f3ee1000cf8a2d0baba7a59a1ec45f50) + +diff --git a/sysdeps/unix/sysv/linux/powerpc/configure b/sysdeps/unix/sysv/linux/powerpc/configure +index ef2055db92..eb8578404f 100644 +--- a/sysdeps/unix/sysv/linux/powerpc/configure ++++ b/sysdeps/unix/sysv/linux/powerpc/configure +@@ -12,18 +12,12 @@ else case e in #( + CFLAGS="$CFLAGS -mlong-double-128" + cat confdefs.h - <<_ACEOF >conftest.$ac_ext + /* end confdefs.h. */ +-#include +-int +-main (void) +-{ + ++#include + #if LDBL_MANT_DIG != 106 + # error "compiler doesn't implement IBM extended format of long double" + #endif + long double foobar (long double x) { return x; } +- ; +- return 0; +-} + _ACEOF + if ac_fn_c_try_compile "$LINENO" + then : +diff --git a/sysdeps/unix/sysv/linux/powerpc/configure.ac b/sysdeps/unix/sysv/linux/powerpc/configure.ac +index 42347a66fc..ca0f82da08 100644 +--- a/sysdeps/unix/sysv/linux/powerpc/configure.ac ++++ b/sysdeps/unix/sysv/linux/powerpc/configure.ac +@@ -6,7 +6,8 @@ AC_CACHE_CHECK(whether $CC $CFLAGS -mlong-double-128 uses IBM extended format, + libc_cv_mlong_double_128ibm, [dnl + save_CFLAGS="$CFLAGS" + CFLAGS="$CFLAGS -mlong-double-128" +-AC_COMPILE_IFELSE([AC_LANG_PROGRAM([[#include ]], [[ ++AC_COMPILE_IFELSE([AC_LANG_SOURCE([[ ++#include + #if LDBL_MANT_DIG != 106 + # error "compiler doesn't implement IBM extended format of long double" + #endif + +commit 89da37bb6e4a631f375b5fe48783e5c023441b0c +Author: Matt Turner +Date: Tue Aug 4 10:17:20 2026 -0400 + + stdio-common: run AWK in the C locale in the printf format tests + + The program under test runs in the C locale, through the test program + prefix, but AWK inherits whatever locale the build was started in. They + agree today only because the locale in use shares its decimal point with + the C locale. + + It is also faster. gawk takes a single byte path in its regular + expression engine when MB_CUR_MAX is 1, and the script matches several + expressions against every line. For the %f conversion for double, the + largest of these tests, as the median of five runs: + + x86_64, gawk 5.4.1 1.482s -> 1.248s + x86_64, gawk 5.3.2 0.911s -> 0.703s + alpha, gawk 5.4.60 30.9s -> 26.6s + + Worth noting that gawk 5.4 is a good deal slower here than 5.3 was, at + 1.248s against 0.703s for the same input in the C locale, so these tests + have become more expensive than they used to be. + + Reviewed-by: Adhemerval Zanella + (cherry picked from commit 866a70167b85903a02d4ccacb91afb8922702c14) + +diff --git a/stdio-common/tst-printf-format-c.sh b/stdio-common/tst-printf-format-c.sh +index 825c50ec42..73d28c5607 100644 +--- a/stdio-common/tst-printf-format-c.sh ++++ b/stdio-common/tst-printf-format-c.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + echo Verifying c + (set -o pipefail +diff --git a/stdio-common/tst-printf-format-char.sh b/stdio-common/tst-printf-format-char.sh +index 7867bdd62f..aa4d211126 100644 +--- a/stdio-common/tst-printf-format-char.sh ++++ b/stdio-common/tst-printf-format-char.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + +diff --git a/stdio-common/tst-printf-format-double.sh b/stdio-common/tst-printf-format-double.sh +index 8157092dc4..051e4716c5 100644 +--- a/stdio-common/tst-printf-format-double.sh ++++ b/stdio-common/tst-printf-format-double.sh +@@ -29,7 +29,7 @@ test_program_prefix=$1; shift + # internally to process the conversion requested, so any bug in our code + # would then be verified against itself, defeating the objective of doing + # the verification against an independent implementation. +-AWK="${AWK:-awk} -M" ++AWK="env LC_ALL=C ${AWK:-awk} -M" + + status=77 + +diff --git a/stdio-common/tst-printf-format-int.sh b/stdio-common/tst-printf-format-int.sh +index 8542ff4150..e9dcbedc04 100644 +--- a/stdio-common/tst-printf-format-int.sh ++++ b/stdio-common/tst-printf-format-int.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ldouble.sh b/stdio-common/tst-printf-format-ldouble.sh +index dbf78a98c6..7ee097ac0a 100644 +--- a/stdio-common/tst-printf-format-ldouble.sh ++++ b/stdio-common/tst-printf-format-ldouble.sh +@@ -29,7 +29,7 @@ test_program_prefix=$1; shift + # internally to process the conversion requested, so any bug in our code + # would then be verified against itself, defeating the objective of doing + # the verification against an independent implementation. +-AWK="${AWK:-awk} -M" ++AWK="env LC_ALL=C ${AWK:-awk} -M" + + status=77 + +diff --git a/stdio-common/tst-printf-format-llong.sh b/stdio-common/tst-printf-format-llong.sh +index e1f5252c9a..98a79660cc 100644 +--- a/stdio-common/tst-printf-format-llong.sh ++++ b/stdio-common/tst-printf-format-llong.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-long.sh b/stdio-common/tst-printf-format-long.sh +index 4b68ab1e04..89ac3302b8 100644 +--- a/stdio-common/tst-printf-format-long.sh ++++ b/stdio-common/tst-printf-format-long.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-s.sh b/stdio-common/tst-printf-format-s.sh +index 65aa0cb675..015c730609 100644 +--- a/stdio-common/tst-printf-format-s.sh ++++ b/stdio-common/tst-printf-format-s.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + echo Verifying s + (set -o pipefail +diff --git a/stdio-common/tst-printf-format-short.sh b/stdio-common/tst-printf-format-short.sh +index 30357baa02..a7df8b8e6d 100644 +--- a/stdio-common/tst-printf-format-short.sh ++++ b/stdio-common/tst-printf-format-short.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + +diff --git a/stdio-common/tst-printf-format-uchar.sh b/stdio-common/tst-printf-format-uchar.sh +index 08a6914b88..356de4217d 100644 +--- a/stdio-common/tst-printf-format-uchar.sh ++++ b/stdio-common/tst-printf-format-uchar.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + +diff --git a/stdio-common/tst-printf-format-uint.sh b/stdio-common/tst-printf-format-uint.sh +index 0ba203ccda..b496047a49 100644 +--- a/stdio-common/tst-printf-format-uint.sh ++++ b/stdio-common/tst-printf-format-uint.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ullong.sh b/stdio-common/tst-printf-format-ullong.sh +index 5b881ab924..f030f66a24 100644 +--- a/stdio-common/tst-printf-format-ullong.sh ++++ b/stdio-common/tst-printf-format-ullong.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ulong.sh b/stdio-common/tst-printf-format-ulong.sh +index f6aeb8e3c0..7102575ed2 100644 +--- a/stdio-common/tst-printf-format-ulong.sh ++++ b/stdio-common/tst-printf-format-ulong.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ushort.sh b/stdio-common/tst-printf-format-ushort.sh +index 07609128ab..5f612b5398 100644 +--- a/stdio-common/tst-printf-format-ushort.sh ++++ b/stdio-common/tst-printf-format-ushort.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + + +commit 7cc7a3a4fbf15c8a7d61a69452f754f9c352cd62 +Author: Matt Turner +Date: Mon Aug 3 21:59:44 2026 -0400 + + stdio-common: avoid repeated regexp matches in tst-printf-format.awk + + Whether the value is an infinity, a NaN or zero does not change between + the conversions applied to it, but was determined again for each one. + Determine it where the value is read. + + Also look for the '#' flag with index() before matching the expressions + that need it, and test the value first where both have to hold. + + For the %f conversion for double, in the C locale, as the median of five + runs: + + x86_64, gawk 5.4.1 1.248s -> 1.184s + x86_64, gawk 5.3.2 0.703s -> 0.708s + alpha, gawk 5.4.60 26.6s -> 25.8s + + So this only helps with the regular expression engine that gawk 5.4 + brought in; under 5.3.2 it is lost in the noise. Output and exit status + are unchanged for the e, f and g conversions for double under both + gawk versions and both locales. + + Reviewed-by: Adhemerval Zanella + (cherry picked from commit 0cc3f9b3f3f2950844bd41cc8923215cd5d97269) + +diff --git a/stdio-common/tst-printf-format.awk b/stdio-common/tst-printf-format.awk +index 5d0324c551..57bea12621 100644 +--- a/stdio-common/tst-printf-format.awk ++++ b/stdio-common/tst-printf-format.awk +@@ -32,6 +32,9 @@ BEGIN { + # non-bignum mode unless a sign has been explicitly given. Keep + # original 'val' for reporting. + value = gensub(/^(INF|NAN|inf|nan)/, "+\\1", 1, val) ++ # Neither changes between the conversions applied to this value. ++ value_infnan = value ~ /(INF|NAN|inf|nan)/ ++ value_zero = value == 0 + next + } + +@@ -52,7 +55,7 @@ BEGIN { + # Discard the '#' flag with the octal conversion if output starts with + # 0 in the absence of this flag. In that case no extra 0 is supposed + # to be produced, but gawk prepends it anyway. +- if (format ~ /#.*o/) ++ if (index(format, "#") && format ~ /#.*o/) + { + tmpfmt = gensub(/#/, "", "g", format) + tmpout = sprintf(tmpfmt, value) +@@ -62,7 +65,7 @@ BEGIN { + # Likewise with the hexadecimal conversion where zero value with the + # precision of zero is supposed to produce no characters, but gawk + # outputs 0 instead. +- else if (format ~ /#.*[Xx]/) ++ else if (index(format, "#") && format ~ /#.*[Xx]/) + { + tmpfmt = gensub(/#/, "", "g", format) + tmpout = sprintf(tmpfmt, value) +@@ -78,7 +81,7 @@ BEGIN { + # values and reprint the output produced using the string conversion, + # with the field width carried over and the relevant flags handled by + # hand. +- if (format ~ /[EFGefg]/ && value ~ /(INF|NAN|inf|nan)/) ++ if (value_infnan && format ~ /[EFGefg]/) + { + minus = format ~ /-/ ? "-" : "" + sign = value ~ /-/ ? "-" : format ~ /\+/ ? "+" : format ~ / / ? " " : "" +@@ -94,7 +97,7 @@ BEGIN { + # In that case "+" is always supposed to be produced, but with the + # precision of zero gawk in the non-bignum mode produces any padding + # requested only. +- else if (format ~ /\+.*[di]/ && value == 0) ++ else if (value_zero && format ~ /\+.*[di]/) + { + output = gensub(/^( *) $/, format ~ /-/ ? "+\\1" : "\\1+", 1, output) + output = gensub(/^$/, "+", 1, output) +@@ -103,7 +106,7 @@ BEGIN { + # conversion for zero value. In that case at least one " " is + # supposed to be produced, but with the precision of zero gawk in the + # non-bignum mode produces nothing. +- else if (format ~ / .*[di]/ && value == 0) ++ else if (value_zero && format ~ / .*[di]/) + { + output = gensub(/^$/, " ", 1, output) + } + +commit 65d35639a9d055e423345c8748908c8aa48b19b9 +Author: Magnus Lindholm +Date: Wed Aug 5 23:14:58 2026 +0200 + + string: Speed up strcmp test data initialization + + The strcmp and strncmp tests repeatedly initialize large buffers for + many combinations of lengths and alignments. The existing loops + perform a remainder operation and two individual stores for every + element. + + Generate at most max_char elements using an additive recurrence. The + recurrence produces the same sequence as the existing multiplication + and remainder expression. Expand this initial pattern using bulk + copies, and then copy the completed first buffer to the second buffer. + + This preserves the generated test data while substantially reducing + the initialization cost on slower systems. + + The change also applies to the wcscmp and wcsncmp tests, which include + the same test sources. + + Signed-off-by: Magnus Lindholm + Reviewed-by: Adhemerval Zanella + (cherry picked from commit 9b323b95567dff46b34157ac4455734633921abb) + +diff --git a/string/test-strcmp.c b/string/test-strcmp.c +index 76ccff46e2..ca52827b11 100644 +--- a/string/test-strcmp.c ++++ b/string/test-strcmp.c +@@ -156,6 +156,10 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + int exp_result) + { + size_t i; ++ size_t value = 0; ++ size_t pattern_len; ++ size_t step ++ = (23U << ((CHARBYTES - 1) * 8)) % (size_t) max_char; + + CHAR *s1, *s2; + +@@ -179,8 +183,28 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + i = align2 + CHARBYTES * (len + 2); + s2 = (CHAR *)(buf2 + ((page_size - i) / 16 * 16) + align2); + +- for (i = 0; i < len; i++) +- s1[i] = s2[i] = 1 + (23 << ((CHARBYTES - 1) * 8)) * i % max_char; ++ /* The generated sequence repeats after at most max_char elements. */ ++ pattern_len ++ = len < (size_t) max_char ? len : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) ++ { ++ s1[i] = 1 + value; ++ ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < len) ++ { ++ size_t copy = i < len - i ? i : len - i; ++ ++ MEMCPY (s1 + i, s1, copy); ++ i += copy; ++ } ++ ++ MEMCPY (s2, s1, len); + + s1[len] = s2[len] = 0; + s1[len + 1] = 23; +diff --git a/string/test-strncmp.c b/string/test-strncmp.c +index 54ada39eb2..9da0f21f60 100644 +--- a/string/test-strncmp.c ++++ b/string/test-strncmp.c +@@ -190,6 +190,9 @@ do_test_n (size_t align1, size_t align2, size_t len, size_t n, int n_in_bounds, + { + size_t i, buf_bound; + CHAR *s1, *s2, *s1_end, *s2_end; ++ size_t value = 0; ++ size_t pattern_len; ++ size_t step = (23U << ((CHARBYTES - 1) * 8)) % (size_t) max_char; + + align1 &= ~(CHARBYTES - 1); + align2 &= ~(CHARBYTES - 1); +@@ -216,8 +219,29 @@ do_test_n (size_t align1, size_t align2, size_t len, size_t n, int n_in_bounds, + s2[n] = 23; + } + +- for (i = 0; i < buf_bound; i++) +- s1[i] = s2[i] = 1 + (23 << ((CHARBYTES - 1) * 8)) * i % max_char; ++ /* The generated sequence repeats after at most max_char elements. */ ++ pattern_len ++ = buf_bound < (size_t) max_char ++ ? buf_bound : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) ++ { ++ s1[i] = 1 + value; ++ ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < buf_bound) ++ { ++ size_t copy = i < buf_bound - i ? i : buf_bound - i; ++ ++ MEMCPY (s1 + i, s1, copy); ++ i += copy; ++ } ++ ++ MEMCPY (s2, s1, buf_bound); + + s1[len] = 0; + s2[len] = 0; + +commit 11ac3d78fc5e4f7f2846002e099f773ad8ff82fc +Author: Magnus Lindholm +Date: Wed Aug 5 23:14:59 2026 +0200 + + string: Speed up strcasecmp test data initialization + + The strcasecmp and strncasecmp tests repeatedly initialize large + buffers for many combinations of lengths and alignments. The existing + loops perform a remainder operation and call toupper and tolower for + every element. + + Generate at most max_char elements using an additive recurrence and + apply the case conversions while creating this initial pattern. The + recurrence produces the same sequence as the existing multiplication + and remainder expression. Expand the completed pattern using bulk + copies. + + This preserves the generated test data and locale-dependent case + conversion while substantially reducing the initialization cost on + slower systems. + + Signed-off-by: Magnus Lindholm + Reviewed-by: Adhemerval Zanella + (cherry picked from commit c1fb5d0e6b8d292ac526974d05c5adb4c3827fb0) + +diff --git a/string/test-strcasecmp.c b/string/test-strcasecmp.c +index a5235fa1bb..d090dcbf36 100644 +--- a/string/test-strcasecmp.c ++++ b/string/test-strcasecmp.c +@@ -63,6 +63,9 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + int exp_result) + { + size_t i; ++ size_t value = 0; ++ size_t step = 23U % (size_t) max_char; ++ size_t pattern_len; + char *s1, *s2; + + if (len == 0) +@@ -80,10 +83,25 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + s1 = (char *) (buf1 + align1); + s2 = (char *) (buf2 + align2); + +- for (i = 0; i < len; i++) ++ pattern_len ++ = len < (size_t) max_char ? len : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) + { +- s1[i] = toupper (1 + 23 * i % max_char); ++ s1[i] = toupper (1 + value); + s2[i] = tolower (s1[i]); ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < len) ++ { ++ size_t copy = i < len - i ? i : len - i; ++ ++ memcpy (s1 + i, s1, copy); ++ memcpy (s2 + i, s2, copy); ++ i += copy; + } + + s1[len] = s2[len] = 0; +diff --git a/string/test-strncasecmp.c b/string/test-strncasecmp.c +index 035c680532..6b00113e66 100644 +--- a/string/test-strncasecmp.c ++++ b/string/test-strncasecmp.c +@@ -83,6 +83,9 @@ do_test (size_t align1, size_t align2, size_t n, size_t len, int max_char, + int exp_result) + { + size_t i; ++ size_t value = 0; ++ size_t step = 23U % (size_t) max_char; ++ size_t pattern_len; + char *s1, *s2; + + if (len == 0) +@@ -100,10 +103,26 @@ do_test (size_t align1, size_t align2, size_t n, size_t len, int max_char, + s1 = (char *) (buf1 + align1); + s2 = (char *) (buf2 + align2); + +- for (i = 0; i < len; i++) ++ pattern_len ++ = len < (size_t) max_char ? len : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) + { +- s1[i] = toupper (1 + 23 * i % max_char); ++ s1[i] = toupper (1 + value); + s2[i] = tolower (s1[i]); ++ ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < len) ++ { ++ size_t copy = i < len - i ? i : len - i; ++ ++ memcpy (s1 + i, s1, copy); ++ memcpy (s2 + i, s2, copy); ++ i += copy; + } + + s1[len] = s2[len] = 0; + +commit 16be1518495f1fa05481b0182c4e4c24927c62df +Author: Adhemerval Zanella +Date: Mon Aug 3 11:02:53 2026 -0300 + + elf: Honour skip_ifunc for cross-object IFUNC relocations [BZ #34428] + + Commit 63b31c05a8a ("elf: Defer all IRELATIVE relocations until after PLT + setup") dropped the skip_ifunc argument from elf_dynamic_do_Rel, assuming + the new deferred elf_dynamic_do_Rel_irelative pass handles every relocation + that may run an IFUNC resolver. That only holds for IFUNC symbols defined + in the object being relocated: a reference to an IFUNC in another object is + an ordinary JMP_SLOT or GLOB_DAT against an undefined symbol, and its IFUNC + nature is only known after symbol resolution inside elf_machine_rel. Those + relocations stay in the regular pass, which no longer propagated + skip_ifunc, so __RTLD_NOIFUNC was ignored for them. + + ldd -u forces non-lazy binding (GLRO(dl_lazy) = 0 for DL_DEBUG_UNUSED), so + the resolver was called and the diagnostic emitted: + + $ ldd -u /bin/ls + /bin/ls: Relink `' with `/usr/lib64/libc.so.6' for IFUNC symbol `__mempcpy_chk' + + ldd -r with LD_BIND_NOW is affected in the same way. + + Restore the skip_ifunc parameter and thread it through _ELF_DYNAMIC_DO_RELOC. + + This new semantic shows that ELF_DYNAMIC_RELOCATE_NOIFUNC naming is misleading + (it reads as "do not process IFUNC", yet it takes a skip_ifunc + argument). Replace it to: + + DL_RELOC_BOTH -> DL_RELOC_ALL + DL_RELOC_NOIFUNC -> DL_RELOC_NORMAL + DL_RELOC_IFUNC -> DL_RELOC_IRELATIVE + + ELF_DYNAMIC_RELOCATE_NOIFUNC and ELF_DYNAMIC_RELOCATE_IFUNC become a single + ELF_DYNAMIC_RELOCATE_PASS taking the pass as its first argument, and + ELF_DYNAMIC_DO_REL/ELF_DYNAMIC_DO_RELA take the pass instead of having three + near-identical variants each. + + Checked on x86_64-linux-gnu, and built for all supported architectures. + + Reviewed-by: Sam James + + (cherry picked from commit 2f2e9bae4093e1c3ba61250e340d3c3b99788f68) + +diff --git a/elf/Makefile b/elf/Makefile +index 8b063e1bba..d279a5135c 100644 +--- a/elf/Makefile ++++ b/elf/Makefile +@@ -1396,6 +1396,13 @@ modules-names += \ + tst-ifunc-tls-write-lib \ + tst-tls-tdata-reloc-lib \ + # modules-names ++ifeq (yes,$(have-gcc-ifunc)) ++tests += \ ++ tst-ifunc-fault-dep-bindnow \ ++ tst-ifunc-fault-dep-lazy \ ++ # tests ++modules-names += tst-ifunc-fault-mod ++endif + ifneq (no,$(have-test-mtls-descriptor)) + tests += tst-ifunc-tls-init-tlsdesc + modules-names += tst-ifunc-tls-init-tlsdesc-lib +@@ -2547,6 +2554,27 @@ $(objpfx)tst-ifunc-fault-bindnow.out: $(objpfx)tst-ifunc-fault-bindnow \ + $(objpfx)ld.so + $(tst-ifunc-fault-script) + ++LDFLAGS-tst-ifunc-fault-dep-lazy = -Wl,-z,lazy ++LDFLAGS-tst-ifunc-fault-dep-bindnow = -Wl,-z,now ++define tst-ifunc-fault-dep-script ++( $(test-wrapper) $(rtld-prefix) --verify $< \ ++ && $(test-wrapper-env) LD_TRACE_LOADED_OBJECTS=1 $(rtld-prefix) $< \ ++ && $(test-wrapper-env) LD_TRACE_LOADED_OBJECTS=1 LD_DEBUG=unused \ ++ $(rtld-prefix) $< \ ++ && $(test-wrapper-env) LD_TRACE_LOADED_OBJECTS=1 LD_WARN=yes LD_BIND_NOW=1 \ ++ $(rtld-prefix) $< \ ++) > $@; $(evaluate-test) ++endef ++$(objpfx)tst-ifunc-fault-dep-lazy: $(objpfx)tst-ifunc-fault-mod.so ++$(objpfx)tst-ifunc-fault-dep-bindnow: $(objpfx)tst-ifunc-fault-mod.so ++$(objpfx)tst-ifunc-fault-dep-lazy.out: $(objpfx)tst-ifunc-fault-dep-lazy \ ++ $(objpfx)tst-ifunc-fault-mod.so $(objpfx)ld.so ++ $(tst-ifunc-fault-dep-script) ++$(objpfx)tst-ifunc-fault-dep-bindnow.out: \ ++ $(objpfx)tst-ifunc-fault-dep-bindnow \ ++ $(objpfx)tst-ifunc-fault-mod.so $(objpfx)ld.so ++ $(tst-ifunc-fault-dep-script) ++ + LDFLAGS-tst-ifunc-plt-lib.so = -Wl,-z,lazy + + tst-ifunc-plt-bindnow-ENV = LD_BIND_NOW=1 +diff --git a/elf/dl-reloc-static-pie.c b/elf/dl-reloc-static-pie.c +index 8463e46147..5dc5a545a8 100644 +--- a/elf/dl-reloc-static-pie.c ++++ b/elf/dl-reloc-static-pie.c +@@ -80,7 +80,7 @@ _dl_relocate_static_pie (void) + + /* Relocate ourselves so we can do normal function calls and data access + using the global offset table. IRELATIVE entries are deferred. */ +- ELF_DYNAMIC_RELOCATE_NOIFUNC (main_map, NULL, 0, 0); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_NORMAL, main_map, NULL, 0, 0, 0); + + /* Initialize _r_debug_extended. */ + struct r_debug *r = _dl_debug_initialize (0, LM_ID_BASE); +@@ -98,7 +98,7 @@ void + _dl_relocate_static_pie_ifunc (void) + { + struct link_map *main_map = _dl_get_dl_main_map (); +- ELF_DYNAMIC_RELOCATE_IFUNC (main_map, NULL, 0, 0); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_IRELATIVE, main_map, NULL, 0, 0, 0); + main_map->l_relocated = 1; + } + #endif +diff --git a/elf/dl-reloc.c b/elf/dl-reloc.c +index 15a6a4cffe..fa2f41ac44 100644 +--- a/elf/dl-reloc.c ++++ b/elf/dl-reloc.c +@@ -278,7 +278,8 @@ _dl_relocate_object_no_relro (struct link_map *l, struct r_scope_elem *scope[], + IFUNC resolvers. Without this, a resolver would see the unrelocated + initialiser bytes that were placed into the slot by the early + _dl_allocate_tls_init. */ +- ELF_DYNAMIC_RELOCATE_NOIFUNC (l, scope, lazy, consider_profiling); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_NORMAL, l, scope, lazy, ++ consider_profiling, skip_ifunc); + + #ifdef SHARED + /* Re-initialise the static TLS slot with the .tdata so the IRELATIVE +@@ -291,7 +292,8 @@ _dl_relocate_object_no_relro (struct link_map *l, struct r_scope_elem *scope[], + _dl_init_static_tls (l); + #endif + +- ELF_DYNAMIC_RELOCATE_IFUNC (l, scope, lazy, skip_ifunc); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_IRELATIVE, l, scope, lazy, ++ 0, skip_ifunc); + + if ((consider_profiling || consider_symbind) + && l->l_info[DT_PLTRELSZ] != NULL) +diff --git a/elf/do-rel.h b/elf/do-rel.h +index 7702244734..c610d12dbe 100644 +--- a/elf/do-rel.h ++++ b/elf/do-rel.h +@@ -79,17 +79,23 @@ elf_dynamic_Rel_audit_symbind (struct link_map *map, + /* Perform the relocations in MAP on the running program image as specified + by RELTAG, SZTAG. If LAZY is nonzero, this is the first pass on PLT + relocations; they should be set up to call _dl_runtime_resolve, rather +- than fully resolved now. ++ than fully resolved now. If SKIP_IFUNC is nonzero no IFUNC resolver is ++ called; this is required for the trace modes (ldd -u / ldd -r), which ++ relocate objects. + +- IRELATIVE entries are always skipped (non-bootstrap); they are handled ++ IRELATIVE entries and relocations against an STT_GNU_IFUNC symbol defined ++ in MAP itself are always skipped (non-bootstrap); they are handled + separately by elf_dynamic_do_Rel_irelative after all other relocations +- for both .rel.dyn and .rel.plt have been processed. */ ++ for both .rel.dyn and .rel.plt have been processed. Relocations against ++ an IFUNC symbol defined in *another* object are not deferred, since the ++ IFUNC symbol is only known after symbol resolution, and the defining object ++ has already been relocated at this point. */ + + static inline void __attribute__ ((always_inline)) + elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + ElfW(Addr) reladdr, ElfW(Addr) relsize, + __typeof (((ElfW(Dyn) *) 0)->d_un.d_val) nrelative, +- int lazy) ++ int lazy, int skip_ifunc) + { + const ElfW(Rel) *relative = (const void *) reladdr; + const ElfW(Rel) *r = relative + nrelative; +@@ -111,7 +117,7 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + void *const r_addr_arg = (void *) (l_addr + r->r_offset); + const struct r_found_version *rversion = &map->l_versions[ndx]; + +- elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, 0); ++ elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, skip_ifunc); + } + #else /* !RTLD_BOOTSTRAP */ + #if !defined DO_RELA || !defined ELF_MACHINE_PLT_REL +@@ -126,7 +132,7 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + const ElfW (Sym) *sym = &symtab[ELFW (R_SYM) (r->r_info)]; + if (elf_dynamic_is_Rel_irelative (r, sym)) + continue; +- elf_machine_lazy_rel (map, scope, l_addr, r, 0); ++ elf_machine_lazy_rel (map, scope, l_addr, r, skip_ifunc); + } + } + else +@@ -158,7 +164,8 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + + if (elf_dynamic_is_Rel_irelative (r, sym)) + continue; +- elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, 0); ++ elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, ++ skip_ifunc); + elf_dynamic_Rel_audit_symbind (map, scope, r, sym, rversion, + r_addr_arg); + } +@@ -172,7 +179,8 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + + if (elf_dynamic_is_Rel_irelative (r, sym)) + continue; +- elf_machine_rel (map, scope, r, sym, NULL, r_addr_arg, 0); ++ elf_machine_rel (map, scope, r, sym, NULL, r_addr_arg, ++ skip_ifunc); + elf_dynamic_Rel_audit_symbind (map, scope, r, sym, NULL, + r_addr_arg); + } +diff --git a/elf/dynamic-link.h b/elf/dynamic-link.h +index 35141acec4..0130c63feb 100644 +--- a/elf/dynamic-link.h ++++ b/elf/dynamic-link.h +@@ -78,18 +78,23 @@ elf_machine_lazy_rel (struct link_map *map, struct r_scope_elem *scope[], + consumes precisely the very end of the DT_REL*, or DT_JMPREL and DT_REL* + are completely separate and there is a gap between them. */ + +-/* This controls which sub-passes _ELF_DYNAMIC_DO_RELOC runs. Used to +- interleave TLS / stack-protector setup between the two passes so IFUNC +- resolvers see a fully-initialised TCB. */ +-enum elf_dynamic_reloc_phase ++/* Selects which relocations a pass processes. Splitting them allows the ++ caller to interleave TLS / stack-protector setup between the two passes, ++ so IFUNC resolvers see a fully-initialised TCB. ++ ++ This is orthogonal to the skip_ifunc argument, which says whether an IFUNC ++ resolver may be run at all and is honoured by every pass. In particular ++ DL_RELOC_NORMAL also runs IFUNC resolvers, for relocations against an ++ IFUNC symbol defined in another object. */ ++enum elf_dynamic_reloc_pass + { +- DL_RELOC_BOTH = 0, /* Non-IRELATIVE pass then IRELATIVE pass. */ +- DL_RELOC_NOIFUNC = 1, /* Non-IRELATIVE pass only. */ +- DL_RELOC_IFUNC = 2, /* IRELATIVE pass only. */ ++ DL_RELOC_ALL = 0, /* Non-IRELATIVE relocations, then IRELATIVE. */ ++ DL_RELOC_NORMAL = 1, /* Non-IRELATIVE relocations only. */ ++ DL_RELOC_IRELATIVE = 2, /* IRELATIVE relocations only. */ + }; + + # define _ELF_DYNAMIC_DO_RELOC(RELOC, reloc, map, scope, do_lazy, skip_ifunc, \ +- test_rel, phase) \ ++ test_rel, pass) \ + do { \ + struct { ElfW(Addr) start, size; \ + __typeof (((ElfW(Dyn) *) 0)->d_un.d_val) nrelative; int lazy; } \ +@@ -136,14 +141,15 @@ enum elf_dynamic_reloc_phase + by the linker. */ \ + if (!DO_RTLD_BOOTSTRAP) \ + { \ +- if ((phase) != DL_RELOC_IFUNC) \ ++ if ((pass) != DL_RELOC_IRELATIVE) \ + for (int ranges_index = 0; ranges_index < 2; ++ranges_index) \ + elf_dynamic_do_##reloc ((map), scope, \ + ranges[ranges_index].start, \ + ranges[ranges_index].size, \ + ranges[ranges_index].nrelative, \ +- ranges[ranges_index].lazy); \ +- if ((phase) != DL_RELOC_NOIFUNC) \ ++ ranges[ranges_index].lazy, \ ++ skip_ifunc); \ ++ if ((pass) != DL_RELOC_NORMAL) \ + for (int ranges_index = 0; ranges_index < 2; ++ranges_index) \ + elf_dynamic_do_##reloc##_irelative ((map), scope, \ + ranges[ranges_index].start, \ +@@ -158,7 +164,8 @@ enum elf_dynamic_reloc_phase + ranges[ranges_index].start, \ + ranges[ranges_index].size, \ + ranges[ranges_index].nrelative, \ +- ranges[ranges_index].lazy); \ ++ ranges[ranges_index].lazy, \ ++ skip_ifunc); \ + } while (0) + + # if ELF_MACHINE_NO_REL || ELF_MACHINE_NO_RELA +@@ -169,37 +176,21 @@ enum elf_dynamic_reloc_phase + + # if ! ELF_MACHINE_NO_REL + # include "do-rel.h" +-# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc) \ +- _ELF_DYNAMIC_DO_RELOC (REL, Rel, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_BOTH) +-# define ELF_DYNAMIC_DO_REL_NOIFUNC(map, scope, lazy) \ +- _ELF_DYNAMIC_DO_RELOC (REL, Rel, map, scope, lazy, 0, \ +- _ELF_CHECK_REL, DL_RELOC_NOIFUNC) +-# define ELF_DYNAMIC_DO_REL_IFUNCONLY(map, scope, lazy, skip_ifunc) \ ++# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc, pass) \ + _ELF_DYNAMIC_DO_RELOC (REL, Rel, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_IFUNC) ++ _ELF_CHECK_REL, pass) + # else +-# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_REL_NOIFUNC(map, scope, lazy) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_REL_IFUNCONLY(map, scope, lazy, skip_ifunc) /* Nothing. */ ++# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc, pass) /* Nothing. */ + # endif + + # if ! ELF_MACHINE_NO_RELA + # define DO_RELA + # include "do-rel.h" +-# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc) \ +- _ELF_DYNAMIC_DO_RELOC (RELA, Rela, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_BOTH) +-# define ELF_DYNAMIC_DO_RELA_NOIFUNC(map, scope, lazy) \ +- _ELF_DYNAMIC_DO_RELOC (RELA, Rela, map, scope, lazy, 0, \ +- _ELF_CHECK_REL, DL_RELOC_NOIFUNC) +-# define ELF_DYNAMIC_DO_RELA_IFUNCONLY(map, scope, lazy, skip_ifunc) \ ++# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc, pass) \ + _ELF_DYNAMIC_DO_RELOC (RELA, Rela, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_IFUNC) ++ _ELF_CHECK_REL, pass) + # else +-# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_RELA_NOIFUNC(map, scope, lazy) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_RELA_IFUNCONLY(map, scope, lazy, skip_ifunc) /* Nothing. */ ++# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc, pass) /* Nothing. */ + # endif + + # define ELF_DYNAMIC_DO_RELR(map) \ +@@ -240,37 +231,33 @@ enum elf_dynamic_reloc_phase + # else + # define DO_RTLD_BOOTSTRAP 0 + # endif +-# define ELF_DYNAMIC_RELOCATE(map, scope, lazy, consider_profile, skip_ifunc) \ +- do { \ +- int edr_lazy = elf_machine_runtime_setup ((map), (scope), (lazy), \ +- (consider_profile)); \ +- if (!is_rtld_link_map (map) || DO_RTLD_BOOTSTRAP) \ +- ELF_DYNAMIC_DO_RELR (map); \ +- ELF_DYNAMIC_DO_REL ((map), (scope), edr_lazy, skip_ifunc); \ +- ELF_DYNAMIC_DO_RELA ((map), (scope), edr_lazy, skip_ifunc); \ +- ELF_DYNAMIC_AFTER_RELOC ((map), (edr_lazy)); \ +- } while (0) ++/* Perform one relocation pass over MAP. PASS selects which relocations are ++ processed. It is orthogonal to SKIP_IFUNC, which suppresses running IFUNC ++ resolvers in whichever pass is selected. + +-/* Like ELF_DYNAMIC_RELOCATE but only processes the non-IRELATIVE pass. +- The IRELATIVE pass must be completed later via ELF_DYNAMIC_RELOCATE_IFUNC. +- Used by the static-pie startup so the TCB and stack-protector canary can +- be initialised between the two passes. */ +-# define ELF_DYNAMIC_RELOCATE_NOIFUNC(map, scope, lazy, consider_profile) \ ++ Unless PASS is DL_RELOC_IRELATIVE, this also performs the machine-specific ++ PLT/GOT setup, the DT_RELR relocations, and the ELF_DYNAMIC_AFTER_RELOC ++ hook. */ ++# define ELF_DYNAMIC_RELOCATE_PASS(pass, map, scope, lazy, consider_profile, \ ++ skip_ifunc) \ + do { \ +- int edr_lazy = elf_machine_runtime_setup ((map), (scope), (lazy), \ ++ int edr_lazy = (lazy); \ ++ if ((pass) != DL_RELOC_IRELATIVE) \ ++ { \ ++ edr_lazy = elf_machine_runtime_setup ((map), (scope), (lazy), \ + (consider_profile)); \ +- if (!is_rtld_link_map (map) || DO_RTLD_BOOTSTRAP) \ +- ELF_DYNAMIC_DO_RELR (map); \ +- ELF_DYNAMIC_DO_REL_NOIFUNC ((map), (scope), edr_lazy); \ +- ELF_DYNAMIC_DO_RELA_NOIFUNC ((map), (scope), edr_lazy); \ +- ELF_DYNAMIC_AFTER_RELOC ((map), (edr_lazy)); \ ++ if (!is_rtld_link_map (map) || DO_RTLD_BOOTSTRAP) \ ++ ELF_DYNAMIC_DO_RELR (map); \ ++ } \ ++ ELF_DYNAMIC_DO_REL ((map), (scope), edr_lazy, skip_ifunc, (pass)); \ ++ ELF_DYNAMIC_DO_RELA ((map), (scope), edr_lazy, skip_ifunc, (pass)); \ ++ if ((pass) != DL_RELOC_IRELATIVE) \ ++ ELF_DYNAMIC_AFTER_RELOC ((map), edr_lazy); \ + } while (0) + +-/* IRELATIVE-only companion to ELF_DYNAMIC_RELOCATE_NOIFUNC. */ +-# define ELF_DYNAMIC_RELOCATE_IFUNC(map, scope, lazy, skip_ifunc) \ +- do { \ +- ELF_DYNAMIC_DO_REL_IFUNCONLY ((map), (scope), (lazy), skip_ifunc); \ +- ELF_DYNAMIC_DO_RELA_IFUNCONLY ((map), (scope), (lazy), skip_ifunc); \ +- } while (0) ++/* Run both passes back to back, for callers with nothing to interleave. */ ++# define ELF_DYNAMIC_RELOCATE(map, scope, lazy, consider_profile, skip_ifunc) \ ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_ALL, (map), (scope), (lazy), \ ++ (consider_profile), skip_ifunc) + + #endif +diff --git a/elf/tst-ifunc-fault-dep-bindnow.c b/elf/tst-ifunc-fault-dep-bindnow.c +new file mode 100644 +index 0000000000..60d97dcaa4 +--- /dev/null ++++ b/elf/tst-ifunc-fault-dep-bindnow.c +@@ -0,0 +1,19 @@ ++/* Program calling an IFUNC defined in a dependency. BIND_NOW variant. ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++#include "tst-ifunc-fault-dep-lazy.c" +diff --git a/elf/tst-ifunc-fault-dep-lazy.c b/elf/tst-ifunc-fault-dep-lazy.c +new file mode 100644 +index 0000000000..122d33f391 +--- /dev/null ++++ b/elf/tst-ifunc-fault-dep-lazy.c +@@ -0,0 +1,27 @@ ++/* Program calling an IFUNC defined in a dependency (BZ 34428). ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++extern void magic (void); ++ ++int ++main (void) ++{ ++ /* JMP_SLOT relocation against an undefined symbol. */ ++ magic (); ++ return 1; ++} +diff --git a/elf/tst-ifunc-fault-mod.c b/elf/tst-ifunc-fault-mod.c +new file mode 100644 +index 0000000000..11c21b48ac +--- /dev/null ++++ b/elf/tst-ifunc-fault-mod.c +@@ -0,0 +1,38 @@ ++/* Shared object exporting an IFUNC symbol with a resolver which crashes. ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++#include ++ ++static void ++implementation (void) ++{ ++ /* Produce a crash, without depending on any relocations. */ ++ volatile char *volatile p = NULL; ++ *p = 0; ++} ++ ++static __typeof__ (implementation) * ++resolver (void) ++{ ++ /* Produce a crash, without depending on any relocations. */ ++ volatile char *volatile p = NULL; ++ *p = 0; ++ return implementation; ++} ++ ++void magic (void) __attribute__ ((ifunc ("resolver"))); + +commit afd131806b25715a7617ab757db43f0bb610acbf +Author: Adhemerval Zanella +Date: Wed Aug 12 09:03:17 2026 -0300 + + m68k: Fix fmod/fmodf infinite recursion (BZ 34508) + + Commits 6deadd4eb6a and ade9f30ce27 changed m68k fmod to call + __m81_u(fmod), instead of the mathimpl.h inline + __m81_u(__ieee754_fmod) (that wraps the m68k fmod instruction). + This leads to infinite recursion. + + Tested-by: John Paul Adrian Glaubitz + + (cherry picked from commit bb213471bedc177b8efd3178584137fb81cc976a) + +diff --git a/NEWS b/NEWS +index d0ef2d3e9a..697049efd1 100644 +--- a/NEWS ++++ b/NEWS +@@ -18,6 +18,8 @@ The following bugs are resolved with this release: + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong ++ [34509] libc: [m68k] Regression: Perl locks up after upgrading glibc ++ to 2.43 + + Version 2.44 + +diff --git a/sysdeps/m68k/m680x0/fpu/e_fmod.c b/sysdeps/m68k/m680x0/fpu/e_fmod.c +index 9ad6924422..faac7c79e3 100644 +--- a/sysdeps/m68k/m680x0/fpu/e_fmod.c ++++ b/sysdeps/m68k/m680x0/fpu/e_fmod.c +@@ -33,7 +33,7 @@ __fmod (double x, double y) + && !is_nan (hx))) + return __math_invalid (x); + +- return __m81_u(fmod)(x, y); ++ return __m81_u(__ieee754_fmod)(x, y); + } + strong_alias (__fmod, __ieee754_fmod) + libm_alias_finite (__ieee754_fmod, __fmod) +diff --git a/sysdeps/m68k/m680x0/fpu/e_fmodf.c b/sysdeps/m68k/m680x0/fpu/e_fmodf.c +index a3bd24b71f..98797e0887 100644 +--- a/sysdeps/m68k/m680x0/fpu/e_fmodf.c ++++ b/sysdeps/m68k/m680x0/fpu/e_fmodf.c +@@ -34,7 +34,7 @@ __fmodf (float x, float y) + && !is_nan (hx))) + return __math_invalidf (x); + +- return __m81_u(fmodf)(x, y); ++ return __m81_u(__ieee754_fmodf)(x, y); + } + strong_alias (__fmodf, __ieee754_fmodf) + versioned_symbol (libm, __fmodf, fmodf, GLIBC_2_43); diff --git a/pkgs/development/libraries/glibc/common.nix b/pkgs/development/libraries/glibc/common.nix index 4db1dac187ed..ab415d5b932f 100644 --- a/pkgs/development/libraries/glibc/common.nix +++ b/pkgs/development/libraries/glibc/common.nix @@ -50,9 +50,9 @@ }@args: let - version = "2.42"; - patchSuffix = "-84"; - sha256 = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; + version = "2.44"; + patchSuffix = "-25"; + sha256 = "sha256-N/YA8r7zxegwAUcFlWiyouQKetbMxlzpQlVtSUKcxmc="; in assert withLinuxHeaders -> linuxHeaders != null; @@ -69,17 +69,17 @@ stdenv.mkDerivation ( /* No tarballs for stable upstream branch, only https://sourceware.org/git/glibc.git and using git would complicate bootstrapping. $ git fetch --all -p && git checkout origin/release/2.42/master && git describe - glibc-2.42-67-g4ebd33dd77 - $ git show --minimal --reverse glibc-2.42.. ':!ADVISORIES' > 2.42-master.patch + glibc-2.44-25-gafd131806b + $ git show --minimal --reverse glibc-2.44.. ':!ADVISORIES' > 2.44-master.patch To compare the archive contents zdiff can be used. - $ diff -u 2.42-master.patch ../nixpkgs/pkgs/development/libraries/glibc/2.42-master.patch + $ diff -u 2.44-master.patch ../nixpkgs/pkgs/development/libraries/glibc/2.44-master.patch Please note that each commit has changes to the file ADVISORIES excluded since that conflicts with the directory advisories/ making cross-builds from hosts with case-insensitive file-systems impossible. */ - ./2.42-master.patch + ./2.44-master.patch # Allow NixOS and Nix to handle the locale-archive. ./nix-locale-archive.patch diff --git a/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch b/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch index 0e0315aca270..f9f3f815bbad 100644 --- a/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch +++ b/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch @@ -1,8 +1,8 @@ diff --git a/elf/Makefile b/elf/Makefile -index 5d666b1b..a5017e9c 100644 +index dc39ccea60..3230939376 100644 --- a/elf/Makefile +++ b/elf/Makefile -@@ -669,14 +669,14 @@ $(objpfx)sln: $(sln-modules:%=$(objpfx)%.o) +@@ -1745,14 +1745,14 @@ $(objpfx)sln: $(sln-modules:%=$(objpfx)%.o) $(objpfx)ldconfig: $(ldconfig-modules:%=$(objpfx)%.o) @@ -21,36 +21,41 @@ index 5d666b1b..a5017e9c 100644 +CFLAGS-rtld.c += $(PREFIX-FLAGS) +CFLAGS-dl-usage.c += $(PREFIX-FLAGS) \ -D'RTLD="$(rtlddir)/$(rtld-installed-name)"' - - cpp-srcs-left := $(all-rtld-routines:=.os) + CFLAGS-dl-diagnostics.c += $(SYSCONF-FLAGS) \ + -D'PREFIX="$(prefix)"' \ diff --git a/elf/dl-diagnostics.c b/elf/dl-diagnostics.c -index bef224b3..8e166b12 100644 +index 21311178c7..719e02f8e6 100644 --- a/elf/dl-diagnostics.c +++ b/elf/dl-diagnostics.c -@@ -205,7 +205,7 @@ print_paths (void) +@@ -204,7 +204,7 @@ print_paths (void) { _dl_diagnostics_print_labeled_string ("path.prefix", PREFIX); _dl_diagnostics_print_labeled_string ("path.rtld", RTLD); - _dl_diagnostics_print_labeled_string ("path.sysconfdir", SYSCONFDIR); + _dl_diagnostics_print_labeled_string ("path.sysconfdir", PREFIX "/etc"); - + unsigned int index = 0; static const char *system_dirs = SYSTEM_DIRS "\0"; diff --git a/elf/ldconfig.c b/elf/ldconfig.c -index 28ed637a..6f07b79a 100644 +index a39f3ecfcd..b5f12d0760 100644 --- a/elf/ldconfig.c +++ b/elf/ldconfig.c -@@ -57,7 +57,7 @@ - #define TLS_HWCAP_BIT 63 +@@ -48,11 +48,11 @@ + #ifndef LD_SO_CONF -# define LD_SO_CONF SYSCONFDIR "/ld.so.conf" +# define LD_SO_CONF PREFIX "/etc/ld.so.conf" #endif + #ifndef TUNABLES_CONF +-# define TUNABLES_CONF SYSCONFDIR "/tunables.conf" ++# define TUNABLES_CONF PREFIX "/etc/tunables.conf" + #endif + /* Get libc version number. */ diff --git a/sysdeps/generic/dl-cache.h b/sysdeps/generic/dl-cache.h -index 964d50a4..2224d651 100644 +index 972ab32b86..a0e0775506 100644 --- a/sysdeps/generic/dl-cache.h +++ b/sysdeps/generic/dl-cache.h @@ -35,7 +35,7 @@ From 67bbac951c1c9c08ae87b0c471f67d245eb68f7a Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 31 Aug 2026 21:19:31 +0200 Subject: [PATCH 13/82] libfaketime: fix build w/ glibc-2.44 Failing Hydra Build: https://hydra.nixos.org/build/344162647 I'm aware that there's a 0.9.13 containing this patch, but given the fallout according to the comment, i.e. > 0.9.10 break dict-db-wiktionary and quartus-prime-lite on linux, > and 0.9.11 break everything on darwin I'm not going to look into this and pick the easy route for now, i.e. fixing the fallout of glibc which is what I'm here for. --- pkgs/by-name/li/libfaketime/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/li/libfaketime/package.nix b/pkgs/by-name/li/libfaketime/package.nix index 1e9667b83fba..7bc9995e09d8 100644 --- a/pkgs/by-name/li/libfaketime/package.nix +++ b/pkgs/by-name/li/libfaketime/package.nix @@ -34,6 +34,11 @@ stdenv.mkDerivation (finalAttrs: { patches = [ ./nix-store-date.patch + # Fixes build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/wolfcw/libfaketime/commit/dbe865dfdba0145d993d70b7fd4ec88b2f47554b.patch"; + hash = "sha256-pn9MInefa4ZKuOorGEpi/sDQOQamCakjdYOkFSNA2VQ="; + }) ] ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ # GCC 16's unused variable analysis is more advanced than previous From 342e877fdd502ef884fd6067d887162f410c883b Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 17:14:33 +0200 Subject: [PATCH 14/82] aerospike: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344139672 --- pkgs/by-name/ae/aerospike/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/ae/aerospike/package.nix b/pkgs/by-name/ae/aerospike/package.nix index b90753491800..1818ad0f0e60 100644 --- a/pkgs/by-name/ae/aerospike/package.nix +++ b/pkgs/by-name/ae/aerospike/package.nix @@ -33,6 +33,9 @@ stdenv.mkDerivation (finalAttrs: { zlib ]; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + dontUseCmakeConfigure = true; preBuild = '' From 4b4ab898550e64635ba64c5ad3cb5d8bacfa2029 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 17:17:23 +0200 Subject: [PATCH 15/82] tayga: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344210014 --- pkgs/by-name/ta/tayga/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/ta/tayga/package.nix b/pkgs/by-name/ta/tayga/package.nix index c153319c1677..5efecdef4648 100644 --- a/pkgs/by-name/ta/tayga/package.nix +++ b/pkgs/by-name/ta/tayga/package.nix @@ -24,6 +24,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/apalrd/tayga/commit/b41bd030846451d72b277854678b58370b1d5c8f.patch?full_index=1"; hash = "sha256-vFQTlZs9ghxdx4k/iODDOUBAglyll1OxUdTjzDtcwB0="; }) + + # Fix build w/ glibc-2.44 + (fetchpatch2 { + url = "https://github.com/apalrd/tayga/commit/807fe4e4510e697fef6916cd76d393a8ab8e495e.patch?full_index=1"; + hash = "sha256-JqRKv5ZAlypQxYvhctBKPdWgC6Opxo1IV1niS5v2CfY="; + }) ]; makeFlags = [ From facdfe4daba09ebed4e4a3ae1eaad9915e119617 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 17:19:06 +0200 Subject: [PATCH 16/82] target-isns: fix build w/ glibc-2.44 ChangeLog: https://hydra.nixos.org/build/344209981 --- pkgs/by-name/ta/target-isns/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/ta/target-isns/package.nix b/pkgs/by-name/ta/target-isns/package.nix index b7c9d8f9eba1..cedaf1f35604 100644 --- a/pkgs/by-name/ta/target-isns/package.nix +++ b/pkgs/by-name/ta/target-isns/package.nix @@ -32,6 +32,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/open-iscsi/target-isns/commit/e209821423f936d1cc9b946fb8f7a8979b8e751b.patch?full_index=1"; hash = "sha256-86nl8wTiI9WSZ+Hhw/a9VtgS8OLqoFwiot5iU5IK0f8="; }) + + # Fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/open-iscsi/target-isns/commit/d3645f0c357b2b14fb682fa2cd4ba3621efc4cea.patch"; + hash = "sha256-/ew+B4WDF2s5bjfPLZ7glHW+o/pRTI7zPHLTDh+n4lY="; + }) ]; cmakeFlags = [ "-DSUPPORT_SYSTEMD=ON" ]; From ce4117f12e8a0e343ca6181f3aeac2d3aad520e6 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 17:23:26 +0200 Subject: [PATCH 17/82] ucode: fix build w/ glibc-2.44 Also apply two more bugfixes to correctly apply the patch fixing the issue. Failing Hydra build: https://hydra.nixos.org/build/344213888 --- pkgs/by-name/uc/ucode/package.nix | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/pkgs/by-name/uc/ucode/package.nix b/pkgs/by-name/uc/ucode/package.nix index a8309fbc4e26..ed014133c91d 100644 --- a/pkgs/by-name/uc/ucode/package.nix +++ b/pkgs/by-name/uc/ucode/package.nix @@ -5,6 +5,7 @@ cmake, pkg-config, json_c, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -18,6 +19,22 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-V8WGd4rSuCtGIA5oTfnagp0Dmh5FNG87/MJSeILtbM4="; }; + patches = [ + (fetchpatch { + url = "https://github.com/jow-/ucode/commit/4d81e6c13506599261208786cfe4ee068f346dcd.patch"; + hash = "sha256-RZhD422ue00bqam4n7jAynPDJdOzOFJnf34YbT2wH/s="; + }) + (fetchpatch { + url = "https://github.com/jow-/ucode/commit/a7ead3169ebf355e66b399aca1dd3a5ce29e1e5b.patch"; + hash = "sha256-sc+jSAlix1jE9Cb4MMuqI7VHG6h+zpCL7UZ84awOL6M="; + }) + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/jow-/ucode/commit/beafcff845fcdbb46308ee54422661e80300079d.patch"; + hash = "sha256-JcBk8kJHDlHLRuVR2fmsSfWqVmbFZMPF16+nPp6QFf4="; + }) + ]; + buildInputs = [ json_c ]; From 52724515a3fd6a4c59ac4cd28698bcc67359292b Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 17:25:44 +0200 Subject: [PATCH 18/82] termpaint: fix build w/ glibc-2.44 ChangeLog: https://hydra.nixos.org/build/344210222 --- pkgs/by-name/te/termpaint/package.nix | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/te/termpaint/package.nix b/pkgs/by-name/te/termpaint/package.nix index b9cc6217119d..9656eb68d8e9 100644 --- a/pkgs/by-name/te/termpaint/package.nix +++ b/pkgs/by-name/te/termpaint/package.nix @@ -6,6 +6,7 @@ ninja, pkg-config, python3, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { pname = "termpaint"; @@ -18,7 +19,15 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-7mfGTC5vJ4806bDbrPMSVthtW05a+M3vgUlHGbtaI4Q="; }; - patches = [ ./0001-meson.build-use-prefix.patch ]; + patches = [ + ./0001-meson.build-use-prefix.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/termpaint/termpaint/commit/6164fb5ff17fd3d05bf44e942539082aa71a2ff3.patch"; + hash = "sha256-rTI0ZdJ6Q/a7M73igihd+4EZT9l6l+7oHGUnKmB5n0o="; + }) + ]; nativeBuildInputs = [ meson From 80c900a82e14162f93fc5f3326a68fd1bd5fd2a1 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 17:46:07 +0200 Subject: [PATCH 19/82] libbpf_0: drop Doesn't build with glibc 2.44 and hasn't seen a release in four years. Suricata builds fine with pkgs.libbpf. --- pkgs/by-name/su/suricata/package.nix | 4 +- pkgs/os-specific/linux/libbpf/0.x.nix | 70 --------------------------- pkgs/top-level/aliases.nix | 1 + pkgs/top-level/all-packages.nix | 1 - 4 files changed, 3 insertions(+), 73 deletions(-) delete mode 100644 pkgs/os-specific/linux/libbpf/0.x.nix diff --git a/pkgs/by-name/su/suricata/package.nix b/pkgs/by-name/su/suricata/package.nix index b4c2782e8eb2..5dac04bb6ed9 100644 --- a/pkgs/by-name/su/suricata/package.nix +++ b/pkgs/by-name/su/suricata/package.nix @@ -8,7 +8,7 @@ elfutils, file, jansson, - libbpf_0, + libbpf, libcap_ng, libevent, libmaxminddb, @@ -67,7 +67,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ elfutils jansson - libbpf_0 + libbpf libcap_ng libevent libmagic diff --git a/pkgs/os-specific/linux/libbpf/0.x.nix b/pkgs/os-specific/linux/libbpf/0.x.nix deleted file mode 100644 index 7d5676be8c0a..000000000000 --- a/pkgs/os-specific/linux/libbpf/0.x.nix +++ /dev/null @@ -1,70 +0,0 @@ -{ - fetchFromGitHub, - elfutils, - pkg-config, - stdenv, - zlib, - lib, - nixosTests, -}: - -# update bot does not seem to limit updates here to 0.8.x despite -# the all-packages derivation being libbpf_0 as the libbpf base alias -# is still present: just disable it for 0.x: -# nixpkgs-update: no auto update - -stdenv.mkDerivation rec { - pname = "libbpf"; - version = "0.8.3"; - - src = fetchFromGitHub { - owner = "libbpf"; - repo = "libbpf"; - rev = "v${version}"; - sha256 = "sha256-J5cUvfUYc+uLdkFa2jx/2bqBoZg/eSzc6SWlgKqcfIc="; - }; - - nativeBuildInputs = [ pkg-config ]; - buildInputs = [ - elfutils - zlib - ]; - - enableParallelBuilding = true; - makeFlags = [ - "PREFIX=$(out)" - "-C src" - ]; - - passthru.tests = { - bpf = nixosTests.bpf; - }; - - postInstall = '' - # install linux's libbpf-compatible linux/btf.h - install -Dm444 include/uapi/linux/*.h -t $out/include/linux - ''; - - # FIXME: Multi-output requires some fixes to the way the pkg-config file is - # constructed (it gets put in $out instead of $dev for some reason, with - # improper paths embedded). Don't enable it for now. - - # outputs = [ "out" "dev" ]; - - meta = { - description = "Upstream mirror of libbpf"; - homepage = "https://github.com/libbpf/libbpf"; - license = with lib.licenses; [ - lgpl21 # or - bsd2 - ]; - maintainers = with lib.maintainers; [ - thoughtpolice - vcunat - saschagrunert - martinetd - ]; - platforms = lib.platforms.linux; - identifiers.cpeParts = lib.meta.cpeFullVersionWithVendor "libbpf_project" version; - }; -} diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index e2eea662635f..79b886d1de47 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -1331,6 +1331,7 @@ mapAliases { libayatana-indicator-gtk3 = throw "'libayatana-indicator-gtk3' has been renamed to/replaced by 'libayatana-indicator'"; # Converted to throw 2025-10-27 libbaseencode = throw "'libbaseencode' has been removed because it was deprecated and archived upstream. Consider using 'libcotp' instead"; # Added 2026-01-15 libbencodetools = throw "'libbencodetools' has been renamed to/replaced by 'bencodetools'"; # Converted to throw 2025-10-27 + libbpf_0 = throw "'libbpf_0' has been removed since it's EOL for four years"; # Added 2026-09-03 libbpf_1 = throw "'libbpf_1' has been renamed to/replaced by 'libbpf'"; # Converted to throw 2025-10-27 libbson = throw "'libbson' has been renamed to/replaced by 'mongoc'"; # Converted to throw 2025-10-27 libcanberra-gtk2 = throw "'libcanberra-gtk2' has been removed as it depended on the deprecated GTK 2 engine. Consider using 'libcanberra-gtk3' instead."; # Added 2026-08-10 diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 7822c324636a..029cc1a77247 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -4909,7 +4909,6 @@ with pkgs; }; libbpf = callPackage ../os-specific/linux/libbpf { }; - libbpf_0 = callPackage ../os-specific/linux/libbpf/0.x.nix { }; bundlewrap = with python3.pkgs; toPythonApplication bundlewrap; From 2036e92086bb90fdc15c271ae3cb4f2b128c2025 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:10:52 +0200 Subject: [PATCH 20/82] mir_2_15: mark as broken It's deeply questionable that this exists in the first place, this release is three years old now. For the sake of not ripping out a full desktop environment[1], I'm leaving it in for now. Failing Hydra build: https://hydra.nixos.org/build/344169110 [1] Lomiri and the build fails with `pkgs.mir` --- pkgs/servers/mir/common.nix | 2 ++ pkgs/servers/mir/default.nix | 1 + 2 files changed, 3 insertions(+) diff --git a/pkgs/servers/mir/common.nix b/pkgs/servers/mir/common.nix index 28a2d5f566bf..8693a3027011 100644 --- a/pkgs/servers/mir/common.nix +++ b/pkgs/servers/mir/common.nix @@ -53,6 +53,7 @@ { version, pinned ? false, + broken ? false, hash, cargoHash ? null, patches ? [ ], @@ -298,6 +299,7 @@ stdenv.mkDerivation ( }; meta = { + inherit broken; description = "Display server and Wayland compositor developed by Canonical"; homepage = "https://mir-server.io"; changelog = "https://github.com/canonical/mir/releases/tag/v${finalAttrs.version}"; diff --git a/pkgs/servers/mir/default.nix b/pkgs/servers/mir/default.nix index 873dca525581..e3044d42d221 100644 --- a/pkgs/servers/mir/default.nix +++ b/pkgs/servers/mir/default.nix @@ -11,6 +11,7 @@ in }; mir_2_15 = common { + broken = true; # doesn't build with glibc 2.44 version = "2.15.0"; pinned = true; hash = "sha256-c1+gxzLEtNCjR/mx76O5QElQ8+AO4WsfcG7Wy1+nC6E="; From ac80cd0e95571b5427d70234a8e9ea4caa185498 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:18:28 +0200 Subject: [PATCH 21/82] trurl: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344213650 --- ...build-constify-strchr-memchr-results.patch | 146 ++++++++++++++++++ pkgs/by-name/tr/trurl/package.nix | 9 +- 2 files changed, 154 insertions(+), 1 deletion(-) create mode 100644 pkgs/by-name/tr/trurl/0001-build-constify-strchr-memchr-results.patch diff --git a/pkgs/by-name/tr/trurl/0001-build-constify-strchr-memchr-results.patch b/pkgs/by-name/tr/trurl/0001-build-constify-strchr-memchr-results.patch new file mode 100644 index 000000000000..eb43174b2f28 --- /dev/null +++ b/pkgs/by-name/tr/trurl/0001-build-constify-strchr-memchr-results.patch @@ -0,0 +1,146 @@ +From f081fc506e0e53f671f02ebac8b324f3fd421ee8 Mon Sep 17 00:00:00 2001 +From: Viktor Szakats +Date: Sun, 1 Mar 2026 11:39:41 +0100 +Subject: [PATCH] build: constify `strchr()`/`memchr()` results + +To fix building with glibc-2.43. +(also seen with gcc 16 on Fedora rawhide/f44) + +Also: +- scope a variable while there. +- fix altering the const format buffer on bad syntax. + +Reported-by: Gustavo Costa +Fixes #430 +Reported-by: Michael Ablassmeier +Fixes #431 + +Closes #432 +--- + trurl.c | 37 +++++++++++++++++++------------------ + 1 file changed, 19 insertions(+), 18 deletions(-) + +diff --git a/trurl.c b/trurl.c +index b5a716c..d150a93 100644 +--- a/trurl.c ++++ b/trurl.c +@@ -483,7 +483,7 @@ static void pathadd(struct option *o, const char *path) + + static char *encodeassign(const char *query) + { +- char *p = strchr(query, '='); ++ const char *p = strchr(query, '='); + char *urle; + if(p) { + /* URL encode the left and the right side of the '=' separately */ +@@ -600,7 +600,7 @@ static int getarg(struct option *o, + gap = false; + } + else if((flag[0] == '-') && (flag[1] == '-')) { +- char *equals = strchr(&flag[2], '='); ++ const char *equals = strchr(&flag[2], '='); + if(equals) { + arg = (char *)&equals[1]; + gap = false; +@@ -861,9 +861,10 @@ static void get(struct option *o, CURLU *uh) + else { + /* this is meant as a variable to output */ + const char *start = ptr; +- char *end; +- char *cl; ++ const char *end; ++ const char *cl; + size_t vlen; ++ size_t badlen = 0; + bool isquery = false; + bool queryall = false; + bool strict = false; /* strict mode, fail on URL decode problems */ +@@ -923,7 +924,7 @@ static void get(struct option *o, CURLU *uh) + else { + /* syntax error */ + vlen = 0; +- end[1] = '\0'; ++ badlen = end - start + 1; + } + break; + } +@@ -938,7 +939,7 @@ static void get(struct option *o, CURLU *uh) + queryall); + } + else if(!vlen) +- errorf(o, ERROR_GET, "Bad --get syntax: %s", start); ++ errorf(o, ERROR_GET, "Bad --get syntax: %.*s", (int)badlen, start); + else if(!strncmp(ptr, "url", vlen)) + showurl(stream, o, mods, uh); + else { +@@ -1022,7 +1023,7 @@ static void get(struct option *o, CURLU *uh) + static const struct var *setone(CURLU *uh, const char *setline, + struct option *o) + { +- char *ptr = strchr(setline, '='); ++ const char *ptr = strchr(setline, '='); + const struct var *v = NULL; + if(ptr && (ptr > setline)) { + size_t vlen = ptr - setline; +@@ -1269,9 +1270,9 @@ static bool trim(struct option *o) + inslen--; + } + +- for(i = 0 ; i < nqpairs; i++) { +- char *q = qpairs[i].str; +- char *sep = strchr(q, '='); ++ for(i = 0; i < nqpairs; i++) { ++ const char *q = qpairs[i].str; ++ const char *sep = strchr(q, '='); + size_t qlen; + if(sep) + qlen = sep - q; +@@ -1546,10 +1547,9 @@ static bool extractqpairs(CURLU *uh, struct option *o) + /* extract the query */ + if(!curl_url_get(uh, CURLUPART_QUERY, &q, 0)) { + char *p = q; +- char *amp; + while(*p) { + size_t len; +- amp = strchr(p, o->qsep[0]); ++ char *amp = strchr(p, o->qsep[0]); + if(!amp) + len = strlen(p); + else +@@ -1684,7 +1684,7 @@ static char *canonical_path(const char *path) + { + /* split the path per slash, URL decode + encode, then put together again */ + size_t len = strlen(path); +- char *sl; ++ const char *sl; + char *dupe = NULL; + + do { +@@ -1810,7 +1810,8 @@ static void singleurl(struct option *o, + size_t plen; + const char *w; + size_t wlen; +- char *sep; ++ const char *sep; ++ char *sepw; + bool urlencode = true; + const struct var *v; + +@@ -1852,10 +1853,10 @@ static void singleurl(struct option *o, + w = iinfo->ptr; + } + +- sep = strchr(w, ' '); +- if(sep) { +- wlen = sep - w; +- iinfo->ptr = sep + 1; /* next word is here */ ++ sepw = strchr(w, ' '); ++ if(sepw) { ++ wlen = sepw - w; ++ iinfo->ptr = sepw + 1; /* next word is here */ + } + else { + /* last word */ +-- +2.54.0 + diff --git a/pkgs/by-name/tr/trurl/package.nix b/pkgs/by-name/tr/trurl/package.nix index 5cddcd00a35e..bd2e932fd697 100644 --- a/pkgs/by-name/tr/trurl/package.nix +++ b/pkgs/by-name/tr/trurl/package.nix @@ -6,7 +6,6 @@ curl, python3, perl, - trurl, versionCheckHook, }: @@ -22,6 +21,14 @@ stdenv.mkDerivation rec { }; patches = [ + # fix build w/ glibc-2.44 + # https://github.com/curl/trurl/commit/6e1479cc3bdece8d9a7602e6f8f799305d5a5b7d, but rebased + ./0001-build-constify-strchr-memchr-results.patch + (fetchpatch { + url = "https://github.com/curl/trurl/commit/b3c2faf7ee519e4686248957ee079a2452741d61.patch"; + hash = "sha256-khA77XHPVF+2Vn492UuPrhVAEUijRBA2P8lvPlKYSQM="; + }) + (fetchpatch { url = "https://github.com/curl/trurl/commit/f22a2c45956f35702e437fb83ac05376f1956ec5.patch"; hash = "sha256-7CkUs5tMk77WKc7SlgE2NslHtU5cViKSGhHj3IBlpWo="; From 829921e643c27178cd565b76ef0e3df44f0e28af Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:21:11 +0200 Subject: [PATCH 22/82] dragmap: drop Failing Hydra build: https://hydra.nixos.org/build/344145730 Repo is archived as well. --- .../dr/dragmap/boost-iterator-range.patch | 12 --- pkgs/by-name/dr/dragmap/cstdint.patch | 73 ----------------- pkgs/by-name/dr/dragmap/getHostVersion.patch | 11 --- pkgs/by-name/dr/dragmap/package.nix | 82 ------------------- pkgs/by-name/dr/dragmap/stdio-pclose.patch | 12 --- pkgs/top-level/aliases.nix | 1 + 6 files changed, 1 insertion(+), 190 deletions(-) delete mode 100644 pkgs/by-name/dr/dragmap/boost-iterator-range.patch delete mode 100644 pkgs/by-name/dr/dragmap/cstdint.patch delete mode 100644 pkgs/by-name/dr/dragmap/getHostVersion.patch delete mode 100644 pkgs/by-name/dr/dragmap/package.nix delete mode 100644 pkgs/by-name/dr/dragmap/stdio-pclose.patch diff --git a/pkgs/by-name/dr/dragmap/boost-iterator-range.patch b/pkgs/by-name/dr/dragmap/boost-iterator-range.patch deleted file mode 100644 index bd70eab43f49..000000000000 --- a/pkgs/by-name/dr/dragmap/boost-iterator-range.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff --git a/src/lib/map/Mapper.cpp b/src/lib/map/Mapper.cpp -index 6eaa2c5..781988c 100644 ---- a/src/lib/map/Mapper.cpp -+++ b/src/lib/map/Mapper.cpp -@@ -22,6 +22,7 @@ - //#include "common/Crc32Hw.hpp" - #include "common/DragenLogger.hpp" - #include "map/Mapper.hpp" -+#include - - namespace dragenos { - namespace map { diff --git a/pkgs/by-name/dr/dragmap/cstdint.patch b/pkgs/by-name/dr/dragmap/cstdint.patch deleted file mode 100644 index 6004510d2999..000000000000 --- a/pkgs/by-name/dr/dragmap/cstdint.patch +++ /dev/null @@ -1,73 +0,0 @@ -diff --git a/src/include/map/SeedPosition.hpp b/src/include/map/SeedPosition.hpp -index 30a7d47..c05af16 100644 ---- a/src/include/map/SeedPosition.hpp -+++ b/src/include/map/SeedPosition.hpp -@@ -16,6 +16,7 @@ - #define MAP_SEED_POSITION_HPP - - #include -+#include - - #include "sequences/Seed.hpp" - -diff --git a/src/include/sequences/Read.hpp b/src/include/sequences/Read.hpp -index 460c1cb..c7ff619 100644 ---- a/src/include/sequences/Read.hpp -+++ b/src/include/sequences/Read.hpp -@@ -16,6 +16,7 @@ - #define SEQUENCES_READ_HPP - - #include -+#include - #include - #include - -diff --git a/src/include/sequences/Seed.hpp b/src/include/sequences/Seed.hpp -index a242153..dd4d23b 100644 ---- a/src/include/sequences/Seed.hpp -+++ b/src/include/sequences/Seed.hpp -@@ -16,6 +16,7 @@ - #define SEQUENCES_SEED_HPP - - #include -+#include - #include - - #include "sequences/Read.hpp" -diff --git a/src/lib/sequences/tests/unit/CrcHasherMocks.hpp b/src/lib/sequences/tests/unit/CrcHasherMocks.hpp -index 1866be7..5d9b7d7 100644 ---- a/src/lib/sequences/tests/unit/CrcHasherMocks.hpp -+++ b/src/lib/sequences/tests/unit/CrcHasherMocks.hpp -@@ -2,6 +2,7 @@ - - #include - #include -+#include - #include - #include - -diff --git a/stubs/dragen/src/host/dragen_api/read_group_list.hpp b/stubs/dragen/src/host/dragen_api/read_group_list.hpp -index eefb9ae..623a77f 100644 ---- a/stubs/dragen/src/host/dragen_api/read_group_list.hpp -+++ b/stubs/dragen/src/host/dragen_api/read_group_list.hpp -@@ -14,6 +14,7 @@ - #define __READ_GROUP_LIST_HPP__ - - #include "dragen_exception.hpp" -+#include - class ReadGroupList { - public: - const std::string &getReadGroupName(const uint16_t idx) const { - -diff --git a/stubs/dragen/src/host/metrics/public/run_stats.hpp b/stubs/dragen/src/host/metrics/public/run_stats.hpp -index 998fe4e..9561b0b 100644 ---- a/stubs/dragen/src/host/metrics/public/run_stats.hpp -+++ b/stubs/dragen/src/host/metrics/public/run_stats.hpp -@@ -10,6 +10,7 @@ - #include - #include - #include -+#include - // - // RP: HA! HA! HA! That's what you get when you write code logging to cout all - // over the place! diff --git a/pkgs/by-name/dr/dragmap/getHostVersion.patch b/pkgs/by-name/dr/dragmap/getHostVersion.patch deleted file mode 100644 index ba769c9b09a3..000000000000 --- a/pkgs/by-name/dr/dragmap/getHostVersion.patch +++ /dev/null @@ -1,11 +0,0 @@ -diff --git a/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c b/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c -index cdca3df..5a55699 100644 ---- a/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c -+++ b/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c -@@ -249,7 +249,7 @@ void setDefaultHashParams(hashTableConfig_t* defConfig, const char* destDir, Has - free(dir); - } - -- defConfig->hostVersion = (char*)getHostVersion(0); -+ defConfig->hostVersion = (char*)getHostVersion(); - } diff --git a/pkgs/by-name/dr/dragmap/package.nix b/pkgs/by-name/dr/dragmap/package.nix deleted file mode 100644 index 8f554102db65..000000000000 --- a/pkgs/by-name/dr/dragmap/package.nix +++ /dev/null @@ -1,82 +0,0 @@ -{ - lib, - stdenv, - fetchFromGitHub, - boost, - gtest, - zlib, -}: - -stdenv.mkDerivation (finalAttrs: { - pname = "dragmap"; - version = "1.3.0"; - - src = fetchFromGitHub { - owner = "Illumina"; - repo = "DRAGMAP"; - tag = finalAttrs.version; - fetchSubmodules = true; - hash = "sha256-f1jsOErriS1I/iUS4CzJ3+Dz8SMUve/ccb3KaE+L7U8="; - }; - - nativeBuildInputs = [ boost ]; - buildInputs = [ - gtest - zlib - ]; - - # Latest boost do not need system as a linking flag - postPatch = '' - sed -i 's/system filesystem/filesystem/' config.mk - ''; - - patches = [ - # getHostVersion use an empty parameter list. This is now an error for GC - ./getHostVersion.patch - - # pclose is called on a NULL value. This is no longer allowed since - # https://github.com/bminor/glibc/commit/64b1a44183a3094672ed304532bedb9acc707554 - ./stdio-pclose.patch - - # Add missing include cstdint. Upstream does not accept PR. Issue opened at - # https://github.com/Illumina/DRAGMAP/issues/63 - ./cstdint.patch - - # Missing import in Mapper.cpp - # Issue opened upstream https://github.com/Illumina/DRAGMAP/pull/66 - ./boost-iterator-range.patch - ]; - - env = { - GTEST_INCLUDEDIR = "${gtest.dev}/include"; - CPPFLAGS = "-I ${boost.dev}/include"; - LDFLAGS = "-L ${boost.out}/lib"; - }; - - installPhase = '' - runHook preInstall - - mkdir -p $out/bin - cp build/release/dragen-os $out/bin/ - - runHook postInstall - ''; - - # Tests are launched by default from makefile - doCheck = false; - - meta = { - description = "Open Source version of Dragen mapper for genomics"; - mainProgram = "dragen-os"; - longDescription = '' - DRAGMAP is an open-source software implementation of the DRAGEN mapper, - which the Illumina team created to produce the same results as their - proprietary DRAGEN hardware. - ''; - homepage = "https://github.com/Illumina/DRAGMAP"; - changelog = "https://github.com/Illumina/DRAGMAP/releases/tag/${finalAttrs.version}"; - license = lib.licenses.gpl3; - platforms = [ "x86_64-linux" ]; - maintainers = with lib.maintainers; [ apraga ]; - }; -}) diff --git a/pkgs/by-name/dr/dragmap/stdio-pclose.patch b/pkgs/by-name/dr/dragmap/stdio-pclose.patch deleted file mode 100644 index 74e8d57e9fa5..000000000000 --- a/pkgs/by-name/dr/dragmap/stdio-pclose.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff --git a/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp b/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp -index cd02cd4..c26e9cf 100644 ---- a/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp -+++ b/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp -@@ -57,7 +57,6 @@ int GetDmiValue(const std::string& label, std::string& value) - FILE* dmiOutput = popen("sudo /usr/sbin/dmidecode -t 2", "r"); - if (dmiOutput == NULL) { - perror("dmidecode popen"); -- pclose(dmiOutput); - return -1; - } - diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index 79b886d1de47..f6d9491bcce4 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -722,6 +722,7 @@ mapAliases { dotnetfx40 = throw "'dotnetfx40' has been removed because it was unmaintained in Nixpkgs"; # Added 2026-01-27 dotty = throw "'dotty' has been renamed to/replaced by 'scala_3'"; # Converted to throw 2025-10-27 dovecot_fts_xapian = throw "'dovecot_fts_xapian' has been removed because it was unmaintained in Nixpkgs. Consider using dovecot-fts-flatcurve instead"; # Added 2025-08-16 + dragmap = throw "'dragmap' doesn't build with latest glibc anymore and upstream repo is archived"; # Added 2026-09-03 drone-runner-exec = throw "'drone-runner-exec' has been removed as it was deprecated and archived upstream."; # Added 2026-07-20 dsd = throw "dsd has been removed, as it was broken and lack of upstream maintenance"; # Added 2025-08-25 dtv-scan-tables_linuxtv = throw "'dtv-scan-tables_linuxtv' has been renamed to/replaced by 'dtv-scan-tables'"; # Converted to throw 2025-10-27 From 6d100550410c87c302979c9ce0c632a61e15b8b6 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:24:04 +0200 Subject: [PATCH 23/82] cowsql: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344144419 --- pkgs/by-name/co/cowsql/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/co/cowsql/package.nix b/pkgs/by-name/co/cowsql/package.nix index d672b987265c..d524cd0a16db 100644 --- a/pkgs/by-name/co/cowsql/package.nix +++ b/pkgs/by-name/co/cowsql/package.nix @@ -9,6 +9,7 @@ sqlite, incus, nix-update-script, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -22,6 +23,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-7djVcozWklI/0KhDC20df+H3YQbodUZaXBnQT4Ug8oI="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/cowsql/cowsql/commit/7c4d73151969ead4f81077ae243d81396ce67988.patch"; + hash = "sha256-aJkf3egKbF23KNC0feDkxh8gIEupsyDBY3PTKuT6lcQ="; + }) + ]; + nativeBuildInputs = [ autoreconfHook pkg-config From a0654321884be9a926fbb60f4ab128ed61fc2409 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:26:51 +0200 Subject: [PATCH 24/82] criu: fix build w/ glibc-2.44 ChangeLog: https://hydra.nixos.org/build/344144517 --- pkgs/by-name/cr/criu/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/cr/criu/package.nix b/pkgs/by-name/cr/criu/package.nix index f96504b19735..f4e0b527fd66 100644 --- a/pkgs/by-name/cr/criu/package.nix +++ b/pkgs/by-name/cr/criu/package.nix @@ -45,6 +45,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/checkpoint-restore/criu/commit/3f3acc3200a23140abaa32a2017ae159d3c2d02c.patch?full_index=1"; hash = "sha256-J8n4TjqjzJLLULnpJdR/6YWa/8moFQMn+wNo4a0otgE="; }) + + # fix build w/ glibc-2.44 + (fetchpatch2 { + url = "https://github.com/checkpoint-restore/criu/commit/a810faba33f43d61372741ed196eafd485546f83.patch?full_index=1"; + hash = "sha256-UHSSC3qI6dvtUAiXNnKXTtuXZYGE0SXpUnQ917SXFaU="; + }) ]; enableParallelBuilding = true; From 6d1f6ca228cdde95ffbc4aa94109d4f62bcbdc43 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:32:19 +0200 Subject: [PATCH 25/82] links2: mark as broken MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Failing Hydra build: https://hydra.nixos.org/build/344163770 Code-golfing to do if (strchr(cast_const_char ud, POST_CHAR)) *strchr(cast_const_char ud, POST_CHAR) = 0; means we can't workaround the failure with -Wno-error=discarded-qualifiers like we did for every other package. Also, upstream doesn't use any forge, so I'm not going to bother patching this 🤷 --- pkgs/by-name/li/links2/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/li/links2/package.nix b/pkgs/by-name/li/links2/package.nix index d63aab7bc04b..885bfb3c1158 100644 --- a/pkgs/by-name/li/links2/package.nix +++ b/pkgs/by-name/li/links2/package.nix @@ -76,5 +76,6 @@ stdenv.mkDerivation (finalAttrs: { mainProgram = "links"; license = lib.licenses.gpl2Plus; platforms = lib.platforms.unix; + broken = true; }; }) From 58dc9df41cd7efe162629205a2f9dd4e4f9f0680 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:35:29 +0200 Subject: [PATCH 26/82] libbladeRF: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344162454 --- pkgs/by-name/li/libbladeRF/package.nix | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pkgs/by-name/li/libbladeRF/package.nix b/pkgs/by-name/li/libbladeRF/package.nix index cb340b8bad73..c022cc7b3a34 100644 --- a/pkgs/by-name/li/libbladeRF/package.nix +++ b/pkgs/by-name/li/libbladeRF/package.nix @@ -12,6 +12,7 @@ libusb1, curl, udev, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -29,6 +30,12 @@ stdenv.mkDerivation (finalAttrs: { patches = [ # fix clang build: https://github.com/Nuand/bladeRF/pull/1045 ./clang-fix.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/Nuand/bladeRF/commit/87bdb1a4bbbc45b749bb90db504fe9cf8fe7a595.patch"; + hash = "sha256-/sB18hwBSIqMkjaC7J0rb4STUrq4BWlJKnyy0Szac9c="; + }) ]; nativeBuildInputs = [ From 852dab931ef1ff2223843e6cdc2921b7dd766280 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:40:34 +0200 Subject: [PATCH 27/82] convimg: mark as broken MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Failing Hydra build: https://hydra.nixos.org/build/344144152 The culprit is in a 10 years old git submodule 🫠 --- pkgs/by-name/co/convimg/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/co/convimg/package.nix b/pkgs/by-name/co/convimg/package.nix index 505ac4ff7dc7..f148bfc9d3d0 100644 --- a/pkgs/by-name/co/convimg/package.nix +++ b/pkgs/by-name/co/convimg/package.nix @@ -42,5 +42,6 @@ stdenv.mkDerivation (finalAttrs: { maintainers = [ ]; platforms = lib.platforms.linux; mainProgram = "convimg"; + broken = true; }; }) From f6b4893f16188cddc0d04225ef903c86d47e9d0a Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:43:33 +0200 Subject: [PATCH 28/82] urweb: fix build w/ glibc-2.44 ChangeLog: https://hydra.nixos.org/build/344214226 --- pkgs/by-name/ur/urweb/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/ur/urweb/package.nix b/pkgs/by-name/ur/urweb/package.nix index 445c01cec8f0..e79a09bfda7a 100644 --- a/pkgs/by-name/ur/urweb/package.nix +++ b/pkgs/by-name/ur/urweb/package.nix @@ -64,6 +64,7 @@ stdenv.mkDerivation rec { env.NIX_CFLAGS_COMPILE = toString [ # Needed with GCC 12 "-Wno-error=use-after-free" + "-Wno-error=discarded-qualifiers" ]; # Be sure to keep the statically linked libraries From 815ed5f9a7768cb1f34ab23d8c4b5c18f440b658 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:50:02 +0200 Subject: [PATCH 29/82] cdecl: mark as broken Failing Hydra build: https://hydra.nixos.org/build/344142755 --- pkgs/by-name/cd/cdecl/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/cd/cdecl/package.nix b/pkgs/by-name/cd/cdecl/package.nix index 8295f1653575..494604a65625 100644 --- a/pkgs/by-name/cd/cdecl/package.nix +++ b/pkgs/by-name/cd/cdecl/package.nix @@ -73,5 +73,6 @@ stdenv.mkDerivation (finalAttrs: { maintainers = with lib.maintainers; [ sigmanificient ]; platforms = lib.platforms.unix; mainProgram = "cdecl"; + broken = true; }; }) From d80776b6f10dad03d77cc94271399c0001cc8925 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:54:23 +0200 Subject: [PATCH 30/82] loudmouth: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344166707 --- pkgs/by-name/lo/loudmouth/package.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/lo/loudmouth/package.nix b/pkgs/by-name/lo/loudmouth/package.nix index 91155e474d41..a64d6e61f16a 100644 --- a/pkgs/by-name/lo/loudmouth/package.nix +++ b/pkgs/by-name/lo/loudmouth/package.nix @@ -20,7 +20,10 @@ stdenv.mkDerivation (finalAttrs: { configureFlags = [ "--with-ssl=openssl" ]; - env.NIX_CFLAGS_COMPILE = "-Wno-error=deprecated-declarations"; + env.NIX_CFLAGS_COMPILE = toString [ + "-Wno-error=deprecated-declarations" + "-Wno-error=discarded-qualifiers" + ]; propagatedBuildInputs = [ openssl From cb312659e04d931243c55f630d37aef646547b5e Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 19:00:14 +0200 Subject: [PATCH 31/82] vboot-utils: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344214375 --- pkgs/by-name/vb/vboot-utils/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/vb/vboot-utils/package.nix b/pkgs/by-name/vb/vboot-utils/package.nix index 981202ea1fa0..d04f8a109aaf 100644 --- a/pkgs/by-name/vb/vboot-utils/package.nix +++ b/pkgs/by-name/vb/vboot-utils/package.nix @@ -36,6 +36,9 @@ stdenv.mkDerivation (finalAttrs: { ] ++ lib.optional withFlashrom finalAttrs.passthru.flashromChromeos; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + enableParallelBuilding = true; postPatch = '' From e82ce26603da9fa9051c1385fdd2c6cad8893c78 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 19:04:11 +0200 Subject: [PATCH 32/82] ngn-k: drop Upstream's readme claims: > this k implementation is no longer supported Failing Hydra build: https://hydra.nixos.org/build/344170285 --- pkgs/by-name/ng/ngn-k/package.nix | 64 ------------------- pkgs/by-name/ng/ngn-k/repl-argv-1.patch | 13 ---- pkgs/by-name/ng/ngn-k/repl-license-path.patch | 13 ---- pkgs/top-level/aliases.nix | 1 + 4 files changed, 1 insertion(+), 90 deletions(-) delete mode 100644 pkgs/by-name/ng/ngn-k/package.nix delete mode 100644 pkgs/by-name/ng/ngn-k/repl-argv-1.patch delete mode 100644 pkgs/by-name/ng/ngn-k/repl-license-path.patch diff --git a/pkgs/by-name/ng/ngn-k/package.nix b/pkgs/by-name/ng/ngn-k/package.nix deleted file mode 100644 index 92ab2e867624..000000000000 --- a/pkgs/by-name/ng/ngn-k/package.nix +++ /dev/null @@ -1,64 +0,0 @@ -{ - lib, - stdenv, - fetchFromCodeberg, - runtimeShell, -}: - -stdenv.mkDerivation { - pname = "ngn-k"; - version = "0-unstable-2025-11-17"; - - src = fetchFromCodeberg { - owner = "ngn"; - repo = "k"; - rev = "717063f24921d5aff405a39cf7643efedb5bb365"; - hash = "sha256-rUMi+VetQc139PjbFJXlSkmYEuK5wtM6LpQ/f1tcB1s="; - }; - - patches = [ - ./repl-license-path.patch - ./repl-argv-1.patch - ]; - - postPatch = '' - # don't use hardcoded /bin/sh - for f in repl.k m.c;do - substituteInPlace "$f" --replace-fail "/bin/sh" "${runtimeShell}" - done - ''; - - makeFlags = [ "-e" ]; - buildFlags = [ - "k" - "libk.so" - ]; - checkTarget = "t"; - doCheck = true; - - outputs = [ - "out" - "dev" - "lib" - ]; - - # TODO(@sternenseemann): package bulgarian translation - installPhase = '' - runHook preInstall - install -Dm755 k "$out/bin/k" - install -Dm755 repl.k "$out/bin/k-repl" - install -Dm755 libk.so "$lib/lib/libk.so" - install -Dm644 k.h "$dev/include/k.h" - install -Dm644 LICENSE -t "$out/share/ngn-k" - substituteInPlace "$out/bin/k-repl" --replace-fail "#!k" "#!$out/bin/k" - runHook postInstall - ''; - - meta = { - description = "Simple fast vector programming language"; - homepage = "https://codeberg.org/ngn/k"; - license = lib.licenses.agpl3Only; - maintainers = [ lib.maintainers.sternenseemann ]; - platforms = lib.platforms.linux ++ lib.platforms.freebsd; - }; -} diff --git a/pkgs/by-name/ng/ngn-k/repl-argv-1.patch b/pkgs/by-name/ng/ngn-k/repl-argv-1.patch deleted file mode 100644 index 0e54a0845e4a..000000000000 --- a/pkgs/by-name/ng/ngn-k/repl-argv-1.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/repl.k b/repl.k -index dc89832c..33780850 100755 ---- a/repl.k -+++ b/repl.k -@@ -28,7 +28,7 @@ joinpath:{$[x~,".";y;"/"~*|x;x,y;x,"/",y]} - line0:{c:{0x07~*-2#*x}{(l;r):x;(1:1;r,,(-2_l))}/(x;());"\n"/(*|c),,*c} - line1:{$[#x;;:0];x:-1_x;$[(3>#x)&("\\"=*x)&~^(!cmds)?x 1;cmds[x 1]x 1;.[`1:(fmt;fmtx)[" "~*x]@.:;,x;{`0:`err[]}]];`1:prompt;1} - line:line1@line0@ --$["repl.k"~basename`argv 1;{cmds::@[cmds;x[1]1;:;{y;`0:x}2_x]}'{(&x~\:80#"-")_x:(1+*&x~\:,"/")_-1_x}@0:`argv 1;]; -+$["k-repl"~basename`argv 1;{cmds::@[cmds;x[1]1;:;{y;`0:x}2_x]}'{(&x~\:80#"-")_x:(1+*&x~\:,"/")_-1_x}@0:`argv 1;]; - run:{`1:banner,prompt;{line@1:`}::/`;} - \d . - diff --git a/pkgs/by-name/ng/ngn-k/repl-license-path.patch b/pkgs/by-name/ng/ngn-k/repl-license-path.patch deleted file mode 100644 index d3cd8c781b6b..000000000000 --- a/pkgs/by-name/ng/ngn-k/repl-license-path.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/repl.k b/repl.k -index dc89832c..7a6e0dcf 100755 ---- a/repl.k -+++ b/repl.k -@@ -21,7 +21,7 @@ tbl:{[w;u;x]h:`k'!x;d:`k''.x;W:(#'h)|/'#''d - r,par'dd[w-2]'sem/'+@[W;&~^`i`d?_@'.x;-:]$'d} - cell:{$[|/`i`d=@y;-x;x]$z} - par:{opn,x,cls} --cmds:(,"a")!{`1:1:joinpath[dirname`argv 0]"LICENSE";} -+cmds:(,"a")!{`1:1:joinpath[dirname`argv 0]"../share/ngn-k/LICENSE";} - basename:{*|"/"\x} - dirname:{$[#x:"/"/-1_"/"\x;x;,"."]} - joinpath:{$[x~,".";y;"/"~*|x;x,y;x,"/",y]} diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index f6d9491bcce4..e885c9b0bb95 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -1829,6 +1829,7 @@ mapAliases { nextcloud31Packages = throw "Nextcloud 31 is EOL!"; # Added 2026-02-20 nfstrace = throw "nfstrace has been removed, as it was broken"; # Added 2025-08-25 nginxQuic = throw "'nginxQuic' has been removed. QUIC support is now available in the default nginx builds."; + ngn-k = throw "'ngn-k' doesn't build with glibc 2.44 and upstream claims that the implementation is no longer supported"; # Added 2026-09-03 ngrid = throw "'ngrid' has been removed as it has been unmaintained upstream and broken"; # Added 2025-11-15 nightfox-gtk-theme = throw "'nightfox-gtk-theme' has been removed because it depended on 'gtk-engine-murrine', which was removed because it was unmaintained upstream and depended on GTK 2."; # Added 2026-07-22 nim1 = throw "'nim1' has reached EOL, please use 'nim'"; # Added 2026-03-06 From 2b9386ea4358dde808b9cbbb9c175a9da3cc1a98 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:05:19 +0200 Subject: [PATCH 33/82] beanstalkd: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344141671 --- pkgs/by-name/be/beanstalkd/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/be/beanstalkd/package.nix b/pkgs/by-name/be/beanstalkd/package.nix index bca64619cf03..45228640a9ee 100644 --- a/pkgs/by-name/be/beanstalkd/package.nix +++ b/pkgs/by-name/be/beanstalkd/package.nix @@ -28,6 +28,9 @@ stdenv.mkDerivation (finalAttrs: { hardeningDisable = [ "fortify" ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + makeFlags = [ "PREFIX=${placeholder "out"}" ]; nativeBuildInputs = [ installShellFiles ]; From 5f33626ac66bc82c5c5455bed56c5bbc9f927759 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:05:54 +0200 Subject: [PATCH 34/82] diod: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344145191 --- pkgs/by-name/di/diod/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/di/diod/package.nix b/pkgs/by-name/di/diod/package.nix index 32b3748bed52..a3127d32ab80 100644 --- a/pkgs/by-name/di/diod/package.nix +++ b/pkgs/by-name/di/diod/package.nix @@ -9,6 +9,7 @@ libcap, perl, ncurses, + fetchpatch, }: let lua = lua5_1; @@ -24,6 +25,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-Fz+qvgw5ipyAcZlWBGkmSHuGrZ95i5OorLN3dkdsYKU="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/chaos/diod/commit/d56db0c55012c8a9ea2d3c72749022292c0f65b8.patch"; + hash = "sha256-wuPok3D3VKiao9NmHYLcccsL+91xVbhUeSDExw17X/E="; + }) + ]; + postPatch = '' sed -i configure.ac -e '/git describe/c ${finalAttrs.version})' ''; From 75cda6b87dfbf1e16d5f0fd0fde26ede030905f5 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:06:14 +0200 Subject: [PATCH 35/82] fyi: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344147678 --- pkgs/by-name/fy/fyi/package.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/by-name/fy/fyi/package.nix b/pkgs/by-name/fy/fyi/package.nix index e1ea4eaed3e9..f30b86444430 100644 --- a/pkgs/by-name/fy/fyi/package.nix +++ b/pkgs/by-name/fy/fyi/package.nix @@ -7,6 +7,7 @@ ninja, dbus, scdoc, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -19,6 +20,15 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-UGkShHziREQTkQUlbFXT1144BiBApFVbCvu5A1DuoMI="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://codeberg.org/dnkl/fyi/commit/0a663c5230f756d1161a11080d1a113664e79c21.patch"; + hash = "sha256-B4RkenK4pDAl0jYCgoZH27yUDt3evAHaYnassLaFvB4="; + excludes = [ "CHANGELOG.md" ]; + }) + ]; + depsBuildBuild = [ pkg-config ]; nativeBuildInputs = [ From b50f76ac403dad1ba3c171a1ca8fefe5cb32fbe9 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:06:46 +0200 Subject: [PATCH 36/82] spice-vdagent: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344209099 --- pkgs/by-name/sp/spice-vdagent/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/sp/spice-vdagent/package.nix b/pkgs/by-name/sp/spice-vdagent/package.nix index 7c7633f86f2c..48ca54f12f46 100644 --- a/pkgs/by-name/sp/spice-vdagent/package.nix +++ b/pkgs/by-name/sp/spice-vdagent/package.nix @@ -56,6 +56,9 @@ stdenv.mkDerivation (finalAttrs: { systemd ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + meta = { description = "Enhanced SPICE integration for linux QEMU guest"; longDescription = '' From e78e07e06158e59963420353cf1a2e14be5952a5 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:30:15 +0200 Subject: [PATCH 37/82] futility: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344147650 --- pkgs/by-name/fu/futility/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/fu/futility/package.nix b/pkgs/by-name/fu/futility/package.nix index 41416f226c2d..061c0ac54249 100644 --- a/pkgs/by-name/fu/futility/package.nix +++ b/pkgs/by-name/fu/futility/package.nix @@ -27,6 +27,8 @@ stdenv.mkDerivation { nss ]; + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + postPatch = '' patchShebangs ./scripts substituteInPlace ./scripts/getversion.sh \ From c90629a83180730f32b075fc371baa59bfb14ca5 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:30:35 +0200 Subject: [PATCH 38/82] ocf-resource-agents: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344173775 --- pkgs/by-name/oc/ocf-resource-agents/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/oc/ocf-resource-agents/package.nix b/pkgs/by-name/oc/ocf-resource-agents/package.nix index 0807b266aafb..f86d1bb1e9d5 100644 --- a/pkgs/by-name/oc/ocf-resource-agents/package.nix +++ b/pkgs/by-name/oc/ocf-resource-agents/package.nix @@ -63,6 +63,9 @@ let # Needed with GCC 12 but breaks on darwin (with clang) or older gcc "-Wno-error=maybe-uninitialized" ] + ++ [ + "-Wno-error=discarded-qualifiers" + ] ); meta = { From 137f6183e14f6b2f47edb32a53c269605d2bee0a Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:31:02 +0200 Subject: [PATCH 39/82] orcania: fix build w/ glibc-2.44 ChangeLog: https://hydra.nixos.org/build/344174427 --- pkgs/by-name/or/orcania/package.nix | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/pkgs/by-name/or/orcania/package.nix b/pkgs/by-name/or/orcania/package.nix index e034e574341f..be2bc176a70b 100644 --- a/pkgs/by-name/or/orcania/package.nix +++ b/pkgs/by-name/or/orcania/package.nix @@ -5,6 +5,7 @@ cmake, check, subunit, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { pname = "orcania"; @@ -17,6 +18,18 @@ stdenv.mkDerivation (finalAttrs: { sha256 = "sha256-Cz3IE5UrfoWjMxQ/+iR1bLsYxf5DVN+7aJqLBcPjduA="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/babelouest/orcania/commit/ee2f45b5da8b7fb2c747419c17880ccdca14521d.patch"; + hash = "sha256-BNGL2Q5STrrAO8/OKMS4S5GqlikGnvg4hgBwKTMulgU="; + }) + (fetchpatch { + url = "https://github.com/babelouest/orcania/commit/f261393b4dd1b4f50aca389916407e0dfa5f2e55.patch"; + hash = "sha256-KyRedPj5gBFPZmefmjLL49OY8eJNmMyd5jsFsQByTUE="; + }) + ]; + nativeBuildInputs = [ cmake ]; nativeCheckInputs = [ From 758a42843e20d40120c5bbdc4aec9805fd248382 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:31:24 +0200 Subject: [PATCH 40/82] x16-emulator: fix build w/ glibc-2.44 --- pkgs/by-name/x1/x16/package.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/by-name/x1/x16/package.nix b/pkgs/by-name/x1/x16/package.nix index b1114d51b5fe..f1226c2f2bc9 100644 --- a/pkgs/by-name/x1/x16/package.nix +++ b/pkgs/by-name/x1/x16/package.nix @@ -7,6 +7,7 @@ callPackage, zlib, nix-update-script, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -30,6 +31,9 @@ stdenv.mkDerivation (finalAttrs: { }) ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + postPatch = '' substituteInPlace Makefile \ --replace-fail '/bin/echo' 'echo' From cd8332cd8045e62ac2fad4fc9b27ce160cf1aa87 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:31:35 +0200 Subject: [PATCH 41/82] pacemaker: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344174583 --- pkgs/by-name/pa/pacemaker/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/pa/pacemaker/package.nix b/pkgs/by-name/pa/pacemaker/package.nix index 7d670749fe05..ff6d8fc48a7b 100644 --- a/pkgs/by-name/pa/pacemaker/package.nix +++ b/pkgs/by-name/pa/pacemaker/package.nix @@ -111,6 +111,9 @@ stdenv.mkDerivation (finalAttrs: { "-Wno-error=strict-prototypes" "-Wno-error=deprecated-declarations" ] + ++ [ + "-Wno-error=discarded-qualifiers" + ] ); enableParallelBuilding = true; From e563ad1ecd70ea0818c6ad31272af6d9267d5df6 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:31:59 +0200 Subject: [PATCH 42/82] surge-xt: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344209629 --- pkgs/by-name/su/surge-xt/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/su/surge-xt/package.nix b/pkgs/by-name/su/surge-xt/package.nix index bad3fc26ea66..f31724aed58d 100644 --- a/pkgs/by-name/su/surge-xt/package.nix +++ b/pkgs/by-name/su/surge-xt/package.nix @@ -39,6 +39,9 @@ stdenv.mkDerivation (finalAttrs: { ./clap-option.diff ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + postPatch = '' # see https://github.com/NixOS/nixpkgs/pull/149487#issuecomment-991747333 export XDG_DOCUMENTS_DIR=$(mktemp -d) From 8594a5e0d89f0c168872669ef00521b03f2912e1 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:41:14 +0200 Subject: [PATCH 43/82] firefox-esr-140: mark as broken Failing Hydra build: https://hydra.nixos.org/build/344146962 Fixing that is a can of worms: * There's a patch for the original compiler error[1], however the source hashes in the source-tree must be updated manually since that's a one-line JSON and that part of the patch doesn't apply. * Only to discover that there's subsequent breakage. Given that this is EOL by the end of month[2], fixing that doesn't seem like well-invested time to me. [1] https://bugzilla.mozilla.org/show_bug.cgi?id=2030493 [2] https://endoflife.date/firefox --- .../networking/browsers/firefox/packages/firefox-esr-140.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix b/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix index 3750111eba50..766225ea1da7 100644 --- a/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix +++ b/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix @@ -37,6 +37,7 @@ buildMozillaMach rec { spec = "firefox@${lib.removeSuffix "esr" version}"; }; }; + broken = true; # doesn't build on glibc 2.44 }; tests = { inherit (nixosTests) firefox-esr-140; From c6497b9e94849d4d1b3667fd60a9f3fcb7b18ae4 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:43:18 +0200 Subject: [PATCH 44/82] bees: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344141697 --- pkgs/by-name/be/bees/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/be/bees/package.nix b/pkgs/by-name/be/bees/package.nix index c29b5c0545fa..88c237730baf 100644 --- a/pkgs/by-name/be/bees/package.nix +++ b/pkgs/by-name/be/bees/package.nix @@ -3,6 +3,7 @@ fetchFromGitHub, makeWrapper, nixosTests, + fetchpatch, stdenv, # Build inputs @@ -25,6 +26,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-qaiRWRd9+ElJ40QGOS3AxT2NvF3phQCyPnVz6RfTt8c="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/Zygo/bees/commit/14c82dce8a7e9714d6f9cd03229e0fb55460aa25.patch"; + hash = "sha256-bAYacaS3u01XdlM/8+baD+sMuCOyYDtSis4NvTkx8jk="; + }) + ]; + buildInputs = [ btrfs-progs # for btrfs/ioctl.h util-linux # for uuid.h From 705c45b2125db9ef98b1b9d658acc0c44f66daee Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:51:24 +0200 Subject: [PATCH 45/82] libmongocrypt: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344162914 --- pkgs/by-name/li/libmongocrypt/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/li/libmongocrypt/package.nix b/pkgs/by-name/li/libmongocrypt/package.nix index 98efd633bdee..808c8b4d97e7 100644 --- a/pkgs/by-name/li/libmongocrypt/package.nix +++ b/pkgs/by-name/li/libmongocrypt/package.nix @@ -29,6 +29,9 @@ stdenv.mkDerivation (finalAttrs: { }) ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ cmake pkg-config From 315030e076982e8dbd72db7ad8cd52d193c615ea Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:53:25 +0200 Subject: [PATCH 46/82] vg: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344214471 --- pkgs/by-name/vg/vg/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/vg/vg/package.nix b/pkgs/by-name/vg/vg/package.nix index b0c38d6c3cd5..5cc0fb425efb 100644 --- a/pkgs/by-name/vg/vg/package.nix +++ b/pkgs/by-name/vg/vg/package.nix @@ -133,6 +133,7 @@ stdenv.mkDerivation (finalAttrs: { NIX_CFLAGS_COMPILE = toString [ "-Wno-error=stringop-overflow" "-Wno-error=unterminated-string-initialization" + "-Wno-error=discarded-qualifiers" ]; }; From 1eff3c1301963c0a1d32aae326093f1799e0e46c Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 14:03:10 +0200 Subject: [PATCH 47/82] thunderbird-140: mark as broken Failing Hydra build: https://hydra.nixos.org/build/344212797 Same issue as with Firefox 140 esr and likely equally painful to fix, however the new ESR 153 is out already and it's an ESR for 5 out of 12 weeks when 140 is likely being put EOL[1]. [1] https://support.mozilla.org/en-US/kb/thunderbird-esr --- .../networking/mailreaders/thunderbird/packages.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix index 8c2d5732e16f..83af3fbafeab 100644 --- a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix +++ b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix @@ -15,6 +15,7 @@ let sha512, updateScript, applicationName ? "Thunderbird", + broken ? stdenv.buildPlatform.is32bit, }: (buildMozillaMach rec { pname = "thunderbird"; @@ -49,6 +50,7 @@ let ''; meta = { + inherit broken; changelog = "https://www.thunderbird.net/en-US/thunderbird/${version}/releasenotes/"; description = "Full-featured e-mail client"; homepage = "https://www.thunderbird.net/"; @@ -61,7 +63,6 @@ let vcunat ]; platforms = lib.platforms.unix; - broken = stdenv.buildPlatform.is32bit; # since Firefox 60, build on 32-bit platforms fails with "out of memory". # not in `badPlatforms` because cross-compilation on 64-bit machine might work. license = lib.licenses.mpl20; @@ -120,6 +121,8 @@ rec { versionPrefix = "140"; versionSuffix = "esr"; }; + + broken = true; }; } // lib.optionalAttrs config.allowAliases { From d288e330d60018adb088a106009d4418d84e64ba Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 14:04:28 +0200 Subject: [PATCH 48/82] ipv6calc: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344160376 --- pkgs/by-name/ip/ipv6calc/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/ip/ipv6calc/package.nix b/pkgs/by-name/ip/ipv6calc/package.nix index fa460738f960..533ca9257a5d 100644 --- a/pkgs/by-name/ip/ipv6calc/package.nix +++ b/pkgs/by-name/ip/ipv6calc/package.nix @@ -6,6 +6,7 @@ ip2location-c, openssl, perl, + fetchpatch, libmaxminddb ? null, geolite-legacy ? null, }: @@ -30,6 +31,14 @@ stdenv.mkDerivation (finalAttrs: { perl ]; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/pbiering/ipv6calc/commit/9b6aebd3690d93b6c2f9efa9346ec72540b1a718.patch"; + hash = "sha256-Y/XBMWdG2/Pfr/vZ2+RGYGj2JS3mWJwQGkXnKvXHArg="; + }) + ]; + postPatch = '' patchShebangs *.sh */*.sh for i in {,databases/}lib/Makefile.in; do From d097fa8774f83326a877adcd6668907f741d5657 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 14:07:18 +0200 Subject: [PATCH 49/82] odhcp6c: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344173898 --- pkgs/by-name/od/odhcp6c/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/od/odhcp6c/package.nix b/pkgs/by-name/od/odhcp6c/package.nix index 2ddedb629ebb..a149d7597435 100644 --- a/pkgs/by-name/od/odhcp6c/package.nix +++ b/pkgs/by-name/od/odhcp6c/package.nix @@ -18,6 +18,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-IDBbVWs017JcrApJ3s8fjEQghWCwrK1d+E6Wp5eHNX4="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ cmake ]; buildInputs = [ libubox ]; From 48484b56c78ce70e94bfad2efa56c8a94017d3df Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 14:28:21 +0200 Subject: [PATCH 50/82] tuxpaint: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344213768 While the same patch is also upstream[1], I didn't really get how to extract .patch files from sourceforge, so I used the Gentoo vendored patch instead, contents are the same. [1] https://sourceforge.net/p/tuxpaint/tuxpaint/ci/6271edececef2a3720e5a5b4e245407cf909f034/ --- pkgs/by-name/tu/tuxpaint/package.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/by-name/tu/tuxpaint/package.nix b/pkgs/by-name/tu/tuxpaint/package.nix index 3152be909715..5e81c3583ef4 100644 --- a/pkgs/by-name/tu/tuxpaint/package.nix +++ b/pkgs/by-name/tu/tuxpaint/package.nix @@ -23,6 +23,7 @@ SDL2_Pango, SDL2_ttf, netpbm, + fetchpatch, }: let @@ -50,6 +51,15 @@ stdenv.mkDerivation (finalAttrs: { strictDeps = true; + patches = [ + # Fix build w/ glibc-2.44 + # https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=51c28b814990551897631be7a222af2d922030a9 + (fetchpatch { + url = "https://gitweb.gentoo.org/repo/gentoo.git/plain/media-gfx/tuxpaint/files/tuxpaint-0.9.35-glibc-2.43.patch?id=51c28b814990551897631be7a222af2d922030a9"; + hash = "sha256-xkV73GoCd/epeyWfLHq2MNmRNfKaledoFsukwVKiZSI="; + }) + ]; + nativeBuildInputs = [ gettext gperf From ba0ad70bd449b73d8c9115efd525ede9d6dc3270 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 14:35:56 +0200 Subject: [PATCH 51/82] ntp: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344170903 --- pkgs/by-name/nt/ntp/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/nt/ntp/package.nix b/pkgs/by-name/nt/ntp/package.nix index e36dad33bf80..a5ec68840827 100644 --- a/pkgs/by-name/nt/ntp/package.nix +++ b/pkgs/by-name/nt/ntp/package.nix @@ -7,6 +7,7 @@ perl, pps-tools, libcap, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -18,6 +19,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-z4TF8/saKVKElCYk2CP/+mNBROCWz8T5lprJjvX0aOU="; }; + patches = [ + # Fix build w/ glibc-2.44 + (fetchpatch { + url = "https://gitlab.archlinux.org/archlinux/packaging/packages/ntp/-/raw/8513bf75be3c0425318475e30f5725a03d8fb067/ntp-4.2.8.p18-glib-2.43.patch"; + hash = "sha256-20ztNAnirijKt8rgaMz6FGoHubBOskNL5ynXte3NTvM="; + }) + ]; + # fix for gcc-14 compile failure postPatch = '' substituteInPlace sntp/m4/openldap-thread-check.m4 \ From e3d7bc3b834320fa7003edc746c56c2b074c1cc6 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 17:44:39 +0200 Subject: [PATCH 52/82] ctx: drop Unmaintained and not updated in three years. Also doesn't build with latest glibc anymore. Failing Hydra build: https://hydra.nixos.org/build/344144642 --- pkgs/by-name/ct/ctx/0001-fix-detections.diff | 67 ---------------- pkgs/by-name/ct/ctx/package.nix | 83 -------------------- pkgs/top-level/aliases.nix | 1 + 3 files changed, 1 insertion(+), 150 deletions(-) delete mode 100644 pkgs/by-name/ct/ctx/0001-fix-detections.diff delete mode 100644 pkgs/by-name/ct/ctx/package.nix diff --git a/pkgs/by-name/ct/ctx/0001-fix-detections.diff b/pkgs/by-name/ct/ctx/0001-fix-detections.diff deleted file mode 100644 index d2580d0fde1d..000000000000 --- a/pkgs/by-name/ct/ctx/0001-fix-detections.diff +++ /dev/null @@ -1,67 +0,0 @@ -diff -Naur --no-dereference ctx-source-old/configure.sh ctx-source-new/configure.sh ---- ctx-source-old/configure.sh 1969-12-31 21:00:01.000000000 -0300 -+++ ctx-source-new/configure.sh 2023-09-27 19:26:05.403569888 -0300 -@@ -42,15 +42,18 @@ - ENABLE_SWITCH_DISPATCH=1 - - pkg-config sdl2 && HAVE_SDL=1 --pkg-config babl && HAVE_BABL=1 -+ -+pkg-config babl-0.1 && { HAVE_BABL=1; BABL_NAME=babl-0.1; } -+if [ $HAVE_BABL != 1 ]; then -+ pkg-config babl && { HAVE_BABL=1; BABL_NAME=babl; } -+fi -+ - pkg-config libcurl && HAVE_LIBCURL=1 - pkg-config alsa && HAVE_ALSA=1 - pkg-config libdrm && HAVE_KMS=1 - #pkg-config harfbuzz && HAVE_HARFBUZZ=1 - -- -- --ARCH=`uname -m` -+: "${ARCH:="$(uname -m)"}" - - case "$ARCH" in - "x86_64") HAVE_SIMD=1 ;; -@@ -224,8 +227,8 @@ - if [ $HAVE_BABL = 1 ];then - echo "#define CTX_BABL 1 " >> local.conf - echo "#define CTX_ENABLE_CM 1 " >> local.conf -- echo "CTX_CFLAGS+= `pkg-config babl --cflags`" >> build.conf -- echo "CTX_LIBS+= `pkg-config babl --libs` " >> build.conf -+ echo "CTX_CFLAGS+= `pkg-config "${BABL_NAME}" --cflags`" >> build.conf -+ echo "CTX_LIBS+= `pkg-config "${BABL_NAME}" --libs` " >> build.conf - else - echo "#define CTX_BABL 0 " >> local.conf - echo "#define CTX_ENABLE_CM 0 " >> local.conf -@@ -335,7 +338,7 @@ - #echo "Generating build.deps" - #make build.deps 2>/dev/null - --echo -n "configuration summary, architecture $(arch)" -+echo -n "configuration summary, architecture $ARCH" - [ $HAVE_SIMD = 1 ] && echo " SIMD multi-pass" - echo "" - echo "Backends:" -diff -Naur --no-dereference ctx-source-old/Makefile ctx-source-new/Makefile ---- ctx-source-old/Makefile 1969-12-31 21:00:01.000000000 -0300 -+++ ctx-source-new/Makefile 2023-09-27 19:37:23.779830320 -0300 -@@ -206,8 +206,8 @@ - libctx.a: itk.o deps.o $(CTX_OBJS) build.conf Makefile - $(AR) rcs $@ $(CTX_OBJS) deps.o itk.o - libctx.so: $(CTX_OBJS) deps.o itk.o build.conf Makefile -- $(LD) -shared $(LIBS) $(CTX_OBJS) deps.o itk.o $(CTX_LIBS) -o $@ -- #$(LD) --retain-symbols-file=symbols -shared $(LIBS) $? $(CTX_LIBS) -o $@ -+ $(CCC) -shared $(LIBS) $(CTX_OBJS) deps.o itk.o $(CTX_LIBS) -o $@ -+ #$(CCC) --retain-symbols-file=symbols -shared $(LIBS) $? $(CTX_LIBS) -o $@ - - ctx: main.c ctx.h build.conf Makefile $(TERMINAL_OBJS) $(MEDIA_HANDLERS_OBJS) libctx.a - $(CCC) main.c $(TERMINAL_OBJS) $(MEDIA_HANDLERS_OBJS) -o $@ $(CFLAGS) libctx.a $(LIBS) $(CTX_CFLAGS) $(OFLAGS_LIGHT) -lpthread $(CTX_LIBS) -@@ -277,5 +277,5 @@ - for a in `cat itk/css.h | tr ';' ' ' | tr ',' ' ' | tr ')' ' '|tr ':' ' ' | tr '{' ' ' | tr ' ' '\n' | grep 'SQZ_[a-z][0-9a-zA-Z_]*'| sort | uniq`;do b=`echo $$a|tail -c+5|tr '_' '-'`;echo "#define $$a `./squoze/squoze -33 $$b`u // \"$$b\"";done \ - >> $@ - echo '#endif' >> $@ --static.inc: static/* static/*/* tools/gen_fs.sh -+static.inc: static/* tools/gen_fs.sh - ./tools/gen_fs.sh static > $@ diff --git a/pkgs/by-name/ct/ctx/package.nix b/pkgs/by-name/ct/ctx/package.nix deleted file mode 100644 index 37e3ac1582db..000000000000 --- a/pkgs/by-name/ct/ctx/package.nix +++ /dev/null @@ -1,83 +0,0 @@ -{ - lib, - stdenv, - fetchgit, - SDL2, - alsa-lib, - babl, - bash, - curl, - libdrm, # Not documented - pkg-config, - xxd, - enableFb ? false, - nixosTests, -}: - -stdenv.mkDerivation (finalAttrs: { - pname = "ctx"; - version = "0-unstable-2023-09-03"; - - src = fetchgit { - name = "ctx-source"; # because of a dash starting the directory - url = "https://ctx.graphics/.git/"; - rev = "1bac18c152eace3ca995b3c2b829a452085d46fb"; - hash = "sha256-fOcQJ2XCeomdtAUmy0A+vU7Vt325OSwrb1+ccW+gZ38="; - }; - - patches = [ - # Many problematic things fixed - it should be upstreamed somehow: - # - babl changed its name in pkg-config files - # - arch detection made optional - # - LD changed to CCC - # - remove inexistent reference to static/*/* - ./0001-fix-detections.diff - ]; - - postPatch = '' - patchShebangs ./tools/gen_fs.sh - ''; - - nativeBuildInputs = [ - pkg-config - xxd - ]; - - buildInputs = [ - SDL2 - alsa-lib - babl - bash # for ctx-audioplayer - curl - libdrm - ]; - - strictDeps = true; - - env.ARCH = stdenv.hostPlatform.parsed.cpu.arch or stdenv.hostPlatform.parsed.cpu.name; - - configureScript = "./configure.sh"; - configureFlags = lib.optional enableFb "--enable-fb"; - configurePlatforms = [ ]; - dontAddPrefix = true; - dontDisableStatic = true; - - installFlags = [ - "PREFIX=${placeholder "out"}" - ]; - - passthru.tests.test = nixosTests.terminal-emulators.ctx; - - meta = { - homepage = "https://ctx.graphics/"; - description = "Vector graphics terminal"; - longDescription = '' - ctx is an interactive 2D vector graphics, audio, text- canvas and - terminal, with escape sequences that enable a 2D vector drawing API using - a vector graphics protocol. - ''; - license = lib.licenses.gpl3Plus; - maintainers = [ ]; - platforms = lib.platforms.unix; - }; -}) diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index e885c9b0bb95..602a5a5cbf30 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -640,6 +640,7 @@ mapAliases { csslint = throw "'csslint' has been removed as upstream considers it abandoned."; # Added 2025-11-07 cstore_fdw = throw "'cstore_fdw' has been removed. Use 'postgresqlPackages.cstore_fdw' instead."; # Added 2025-07-19 ctpp2 = throw "'ctpp2' has been removed due to lack of maintenance."; # Added 2025-12-31 + ctx = throw "'ctx' was unmaintained and not updated for three years"; # Added 2026-09-08 cudaPackages_11 = throw "CUDA 11 has been removed from Nixpkgs, as it is unmaintained upstream and depends on unsupported compilers"; # Added 2025-08-08 cudaPackages_11_0 = throw "CUDA 11.0 has been removed from Nixpkgs, as it is unmaintained upstream and depends on unsupported compilers"; # Added 2025-08-08 cudaPackages_11_1 = throw "CUDA 11.1 has been removed from Nixpkgs, as it is unmaintained upstream and depends on unsupported compilers"; # Added 2025-08-08 From a71a62a7b09bdf38ae96eb1d85778d969e98b4ef Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 17:45:27 +0200 Subject: [PATCH 53/82] zookeeper_mt: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344217319 --- pkgs/by-name/zo/zookeeper_mt/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/zo/zookeeper_mt/package.nix b/pkgs/by-name/zo/zookeeper_mt/package.nix index 44dc1fdf8cd8..4d7d4eaf5986 100644 --- a/pkgs/by-name/zo/zookeeper_mt/package.nix +++ b/pkgs/by-name/zo/zookeeper_mt/package.nix @@ -21,6 +21,9 @@ stdenv.mkDerivation rec { sourceRoot = "apache-${zookeeper.pname}-${version}/zookeeper-client/zookeeper-client-c"; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ autoreconfHook pkg-config From f2926847c4af5b0ccab1665971717bdd9e31f48c Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 18:01:08 +0200 Subject: [PATCH 54/82] livegrep: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344166092 --- pkgs/by-name/li/livegrep/package.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/li/livegrep/package.nix b/pkgs/by-name/li/livegrep/package.nix index f2b8d4a47463..3fc784850bae 100644 --- a/pkgs/by-name/li/livegrep/package.nix +++ b/pkgs/by-name/li/livegrep/package.nix @@ -94,7 +94,10 @@ buildBazelPackage { "file://${registry}" ]; - env = lib.optionalAttrs stdenv.hostPlatform.isDarwin { + env = { + NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + } + // lib.optionalAttrs stdenv.hostPlatform.isDarwin { LIBTOOL = "${cctools}/bin/libtool"; }; From 744a98d733a4d05e41bb92c5573d7c07f621631f Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 18:01:44 +0200 Subject: [PATCH 55/82] odyssey: fix build w/ glibc-2.44 --- pkgs/by-name/od/odyssey/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/od/odyssey/package.nix b/pkgs/by-name/od/odyssey/package.nix index f776d973e23f..69cfacd289d9 100644 --- a/pkgs/by-name/od/odyssey/package.nix +++ b/pkgs/by-name/od/odyssey/package.nix @@ -25,6 +25,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/yandex/odyssey/commit/51c0e777aa45157f4f03fbd036113ce6d11ca41f.patch?full_index=1"; hash = "sha256-yytyA2K62v7XwJQ+WJnBGh87AVyeOv0cuzlQ7oYnhFg="; }) + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/yandex/odyssey/commit/1edf6bfd05dc34324162fda1b4ca4bc38b1b581c.patch"; + hash = "sha256-Rd/dqmvpY2gJMqg3hX5rXMu3vRjOG5V3QXV/S1M625Q="; + }) ]; nativeBuildInputs = [ cmake ]; From 9a4883041bbf28b2fb2878d38a9f5145ab8ff053 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 18:01:56 +0200 Subject: [PATCH 56/82] virt-viewer: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344467073 --- pkgs/by-name/vi/virt-viewer/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/vi/virt-viewer/package.nix b/pkgs/by-name/vi/virt-viewer/package.nix index 56a1962294ab..c599d66504ed 100644 --- a/pkgs/by-name/vi/virt-viewer/package.nix +++ b/pkgs/by-name/vi/virt-viewer/package.nix @@ -49,6 +49,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://gitlab.com/virt-viewer/virt-viewer/-/commit/98d9f202ef768f22ae21b5c43a080a1aa64a7107.patch"; sha256 = "sha256-3AbnkbhWOh0aNjUkmVoSV/9jFQtvTllOr7plnkntb2o="; }) + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://gitlab.com/virt-viewer/virt-viewer/-/commit/a634fa8d9fbc59b093f2f07110b2c867f622599d.patch"; + hash = "sha256-xNwpuVwYajlfQUbT6aDrTBqwa61Je8EhD0C9+PL/qx0="; + }) ]; nativeBuildInputs = [ From 9266a746c18e231668883ff2baabd25be64df6be Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 18:12:11 +0200 Subject: [PATCH 57/82] xbps: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344216369 --- pkgs/by-name/xb/xbps/package.nix | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/pkgs/by-name/xb/xbps/package.nix b/pkgs/by-name/xb/xbps/package.nix index 6f3e1ef231ea..b343f27c4909 100644 --- a/pkgs/by-name/xb/xbps/package.nix +++ b/pkgs/by-name/xb/xbps/package.nix @@ -7,6 +7,7 @@ zlib, openssl, libarchive, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -33,6 +34,23 @@ stdenv.mkDerivation (finalAttrs: { patches = [ ./cert-paths.patch + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/7d02b79d3d7e0bf644adf8b412e76dba1b1fdce1.patch"; + hash = "sha256-iUNBmkkfR02/EFDkax/ZpE7oM+5IVDMmD0FYz7p0dQ4="; + }) + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/9a8002c5688c3cdda700b022bf432b4426d64042.patch"; + hash = "sha256-/94HKeyv9LaQv6QHE0CqmM1ajBOSNt9Sfh0XKV0RLMQ="; + }) + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/7f2f10300f235639c5880bea1e4b14245fd5fbda.patch"; + hash = "sha256-iZXiNYrSFaP55qyzefc3hqJ+SoIOsFILqnra6u5iGpM="; + }) + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/84f6a1be26348c265afedebe9cea958424b0aabf.patch"; + hash = "sha256-WDsGkI+3JnJskM+UKjI/UZP6ypMCd5+3rYtlQgQEr40="; + }) ]; env.NIX_CFLAGS_COMPILE = "-Wno-error=unused-result -Wno-error=deprecated-declarations"; From ceec2dc3b9154c655bbf0d204b36bc8be7db67ad Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 21:47:09 +0200 Subject: [PATCH 58/82] hexcurse: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344158921 --- pkgs/by-name/he/hexcurse/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/he/hexcurse/package.nix b/pkgs/by-name/he/hexcurse/package.nix index b8863337e7bf..7c72389a47e2 100644 --- a/pkgs/by-name/he/hexcurse/package.nix +++ b/pkgs/by-name/he/hexcurse/package.nix @@ -21,6 +21,7 @@ stdenv.mkDerivation (finalAttrs: { env.NIX_CFLAGS_COMPILE = toString [ "-Wno-error=stringop-overflow" "-Wno-error=stringop-truncation" + "-Wno-error=discarded-qualifiers" ]; patches = [ # gcc7 compat From 8929e07ea1a44ff09bc15858fe9a4dea9ac92b6a Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 21:47:47 +0200 Subject: [PATCH 59/82] pesign: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344178917 --- pkgs/by-name/pe/pesign/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/pe/pesign/package.nix b/pkgs/by-name/pe/pesign/package.nix index 7fd597e164a8..989062b68f41 100644 --- a/pkgs/by-name/pe/pesign/package.nix +++ b/pkgs/by-name/pe/pesign/package.nix @@ -30,6 +30,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/rhboot/pesign/commit/1f9e2fa0b4d872fdd01ca3ba81b04dfb1211a187.patch?full_index=1"; hash = "sha256-viVM4Z0jAEAWC3EdJVHcWe21aQskH5XE85lOd6Xd/qU="; }) + + # fix build w/ glibc-2.44 + (fetchpatch2 { + url = "https://github.com/rhboot/pesign/commit/419d63a8b6434f94b57730bb8a58a32a0bb199aa.patch?full_index=1"; + hash = "sha256-/o0QknZ1IDFwmsQAt1IENx7tr8WRNJS3wl84cHzprzA="; + }) ]; # nss-util is missing because it is already contained in nss From 03a5c683bff81df17b50feed3ffc72e5570cd904 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 21:48:23 +0200 Subject: [PATCH 60/82] mysql-shell_{8,9}: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344169786 --- pkgs/development/tools/mysql-shell/8.nix | 7 +++++++ pkgs/development/tools/mysql-shell/9.nix | 7 +++++++ 2 files changed, 14 insertions(+) diff --git a/pkgs/development/tools/mysql-shell/8.nix b/pkgs/development/tools/mysql-shell/8.nix index 238742bd3ebf..7c6b7680e282 100644 --- a/pkgs/development/tools/mysql-shell/8.nix +++ b/pkgs/development/tools/mysql-shell/8.nix @@ -29,6 +29,7 @@ cyrus_sasl, openldap, antlr, + fetchpatch, }: let @@ -66,6 +67,12 @@ stdenv.mkDerivation (finalAttrs: { # No openssl bundling on macOS. It's not working. # See https://github.com/mysql/mysql-shell/blob/5b84e0be59fc0e027ef3f4920df15f7be97624c1/cmake/ssl.cmake#L53 ./no-openssl-bundling.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/mysql/mysql-shell/commit/4ce8746d8a7eecf9ae66d4d500c84d57cc4fbdbb.patch"; + hash = "sha256-LUGC7gnNQ3zhmWUm2xogsOAmx8QSngQBHVJMWHFtWz0="; + }) ]; postPatch = '' diff --git a/pkgs/development/tools/mysql-shell/9.nix b/pkgs/development/tools/mysql-shell/9.nix index 14843a23f189..5f68b885640e 100644 --- a/pkgs/development/tools/mysql-shell/9.nix +++ b/pkgs/development/tools/mysql-shell/9.nix @@ -29,6 +29,7 @@ cyrus_sasl, openldap, antlr, + fetchpatch, }: let @@ -66,6 +67,12 @@ stdenv.mkDerivation (finalAttrs: { # No openssl bundling on macOS. It's not working. # See https://github.com/mysql/mysql-shell/blob/5b84e0be59fc0e027ef3f4920df15f7be97624c1/cmake/ssl.cmake#L53 ./no-openssl-bundling.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/mysql/mysql-shell/commit/4ce8746d8a7eecf9ae66d4d500c84d57cc4fbdbb.patch"; + hash = "sha256-LUGC7gnNQ3zhmWUm2xogsOAmx8QSngQBHVJMWHFtWz0="; + }) ]; postPatch = '' From 0706a24d11d06f9536ae573f5159ca328253f077 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 21:51:41 +0200 Subject: [PATCH 61/82] mitscheme: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344290710 _POSIX_C_SOURCE is defined in an already imported glibc header. Since that's used to enable newer C extensions and the code is still building fine, we're just removing the definition from the package's source-code. --- pkgs/by-name/mi/mitscheme/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/mi/mitscheme/package.nix b/pkgs/by-name/mi/mitscheme/package.nix index 8f311d6c15ce..b0be6a25077b 100644 --- a/pkgs/by-name/mi/mitscheme/package.nix +++ b/pkgs/by-name/mi/mitscheme/package.nix @@ -44,6 +44,11 @@ stdenv.mkDerivation { sha256 = "035f92vni0vqmgj9hq2i7vwasz7crx52wll4823vhfkm1qdv5ywc"; }; + postPatch = '' + substituteInPlace "src/microcode/chacha.i" \ + --replace-fail "#define _POSIX_C_SOURCE 200809L" "" + ''; + patches = [ (fetchDebianPatch { pname = "mit-scheme"; From bc0eb86a1aa62a8a893b3c40595d10be793c25e6 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 21:52:48 +0200 Subject: [PATCH 62/82] open-vm-tools: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344174037 This package builds fine on the base of this branch, so it's somehow related to the glibc change, I'm just not understanding how. Anyways, the issue is that `g_free` is a macro in glib (NOT glibc) and was expanded in here leading to a syntax error. Removing this line entirely fixes the issue for us. --- pkgs/by-name/op/open-vm-tools/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/op/open-vm-tools/package.nix b/pkgs/by-name/op/open-vm-tools/package.nix index 5835333ae557..06e87eeeb82c 100644 --- a/pkgs/by-name/op/open-vm-tools/package.nix +++ b/pkgs/by-name/op/open-vm-tools/package.nix @@ -150,6 +150,9 @@ stdenv.mkDerivation (finalAttrs: { substituteInPlace udev/99-vmware-scsi-udev.rules \ --replace-fail "/bin/sh" "${bash}/bin/sh" + + substituteInPlace lib/rpcChannel/glib_stubs.c \ + --replace-fail "void g_free(void *p) { free(p); }" "" ''; configureFlags = [ From 9e2084eb155f358cc02ab7b39caca755793a5412 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 21:54:11 +0200 Subject: [PATCH 63/82] xfstests: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344216601 --- pkgs/by-name/xf/xfstests/package.nix | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/xf/xfstests/package.nix b/pkgs/by-name/xf/xfstests/package.nix index 0ab3874adbed..3151f71d3387 100644 --- a/pkgs/by-name/xf/xfstests/package.nix +++ b/pkgs/by-name/xf/xfstests/package.nix @@ -10,6 +10,7 @@ coreutils, e2fsprogs, fetchzip, + fetchpatch, fio, gawk, keyutils, @@ -45,6 +46,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-b2bL8t1I+kOryAvq3pYTVhx+LwIDf26xdHl7Wdq+Mw8="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://lore.kernel.org/fstests/20260813150846.280498-1-zlang@kernel.org/raw"; + hash = "sha256-NOPMo0cdKKoPMwG53BdTe+G+vDXb+2ICGYFRs4g+edQ="; + }) + ]; + nativeBuildInputs = [ autoconf automake @@ -65,7 +74,7 @@ stdenv.mkDerivation (finalAttrs: { hardeningDisable = [ "format" ]; enableParallelBuilding = true; - patchPhase = '' + postPatch = '' substituteInPlace Makefile \ --replace-fail "cp include/install-sh ." "cp -f include/install-sh ." From 3e6711e17867f8a8266951819d7845140a971b30 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:05:00 +0200 Subject: [PATCH 64/82] ats2: fix build w/ glibc-2.42 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Failing Hydra build: https://hydra.nixos.org/build/344140882 `bsearch` is a macro now, so the `extern`-definition leads to a syntax error. Not going to find out how to use sourceforge to send that though 🤷 --- .../at/ats2/fix-build-glibc-2.44.patch | 20 +++++++++++++++++++ pkgs/by-name/at/ats2/package.nix | 4 ++++ 2 files changed, 24 insertions(+) create mode 100644 pkgs/by-name/at/ats2/fix-build-glibc-2.44.patch diff --git a/pkgs/by-name/at/ats2/fix-build-glibc-2.44.patch b/pkgs/by-name/at/ats2/fix-build-glibc-2.44.patch new file mode 100644 index 000000000000..5cc48100c380 --- /dev/null +++ b/pkgs/by-name/at/ats2/fix-build-glibc-2.44.patch @@ -0,0 +1,20 @@ +diff --git a/prelude/CATS/array.cats b/prelude/CATS/array.cats +index 70c7e3e..cec3b1d 100644 +--- a/prelude/CATS/array.cats ++++ b/prelude/CATS/array.cats +@@ -56,6 +56,7 @@ void qsort + void *base, size_t nmemb, size_t size + , int(*compar)(const void *, const void *) + ) ; // end of [qsort] ++#ifndef bsearch + extern + void *bsearch + ( +@@ -64,6 +65,7 @@ void *bsearch + , size_t nmemb, size_t size + , int (*compar)(const void *, const void *) + ) ; // end of [bsearch] ++#endif + // + #define atspre_array_qsort qsort + #define atspre_array_bsearch bsearch diff --git a/pkgs/by-name/at/ats2/package.nix b/pkgs/by-name/at/ats2/package.nix index ea804a173894..4f1e7287ec16 100644 --- a/pkgs/by-name/at/ats2/package.nix +++ b/pkgs/by-name/at/ats2/package.nix @@ -49,6 +49,10 @@ stdenv.mkDerivation rec { sed -i 's/gcc/clang/g' utils/*/DATS/atscc_util.dats ''; + patches = [ + ./fix-build-glibc-2.44.patch + ]; + buildInputs = [ gmp ]; # Disable parallel build, errors: From 01aced593b61b75b6c9cc5a805e142e58ae429b4 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:09:06 +0200 Subject: [PATCH 65/82] j: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344160462 --- pkgs/by-name/j/j/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/j/j/package.nix b/pkgs/by-name/j/j/package.nix index dd4ed59c1fe4..72b5523589ba 100644 --- a/pkgs/by-name/j/j/package.nix +++ b/pkgs/by-name/j/j/package.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-fW6Tc0UEPYFTgEFMUxZaVm2NU5LNFqszifqOqfdFJZY="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ which ]; buildInputs = [ gmp ]; From bae8a721d98b1b4ede0f6c04cec505dcf6a691ac Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:09:25 +0200 Subject: [PATCH 66/82] ulfius: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344467071 --- pkgs/by-name/ul/ulfius/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/ul/ulfius/package.nix b/pkgs/by-name/ul/ulfius/package.nix index 21542df0d6ad..6db5cbc75f7d 100644 --- a/pkgs/by-name/ul/ulfius/package.nix +++ b/pkgs/by-name/ul/ulfius/package.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation (finalAttrs: { cmake ]; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + propagatedBuildInputs = [ libmicrohttpd orcania From 09d8101a4f93956ee920a308c8dde6f11ca68764 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:09:45 +0200 Subject: [PATCH 67/82] pspp: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344181613 --- pkgs/by-name/ps/pspp/fix-glibc-2.42.patch | 29 +++++++++++++++++++++++ pkgs/by-name/ps/pspp/package.nix | 7 ++++++ 2 files changed, 36 insertions(+) create mode 100644 pkgs/by-name/ps/pspp/fix-glibc-2.42.patch diff --git a/pkgs/by-name/ps/pspp/fix-glibc-2.42.patch b/pkgs/by-name/ps/pspp/fix-glibc-2.42.patch new file mode 100644 index 000000000000..8bf84cc53a94 --- /dev/null +++ b/pkgs/by-name/ps/pspp/fix-glibc-2.42.patch @@ -0,0 +1,29 @@ +diff --git a/gl/stdlib.in.h b/gl/stdlib.in.h +index bef0aaa..b2e19c3 100644 +--- a/gl/stdlib.in.h ++++ b/gl/stdlib.in.h +@@ -223,7 +223,7 @@ _GL_INLINE_HEADER_BEGIN + + + /* Declarations for ISO C N3322. */ +-#if defined __GNUC__ && __GNUC__ >= 15 && !defined __clang__ ++#if defined __GNUC__ && __GNUC__ >= 15 && !defined __clang__ && !defined(bsearch) + _GL_EXTERN_C void *bsearch (const void *__key, + const void *__base, size_t __nmemb, size_t __size, + int (*__compare) (const void *, const void *)) +diff --git a/gl/wchar.in.h b/gl/wchar.in.h +index ab602a2..a2aa597 100644 +--- a/gl/wchar.in.h ++++ b/gl/wchar.in.h +@@ -301,9 +301,11 @@ _GL_EXTERN_C int wcsncmp (const wchar_t *__s1, const wchar_t *__s2, size_t __n) + _GL_ATTRIBUTE_NONNULL_IF_NONZERO (1, 3) + _GL_ATTRIBUTE_NONNULL_IF_NONZERO (2, 3); + # ifndef __cplusplus ++# if !defined(wmemchr) + _GL_EXTERN_C wchar_t *wmemchr (const wchar_t *__s, wchar_t __wc, size_t __n) + _GL_ATTRIBUTE_NONNULL_IF_NONZERO (1, 3); + # endif ++# endif + _GL_EXTERN_C wchar_t *wmemset (wchar_t *__s, wchar_t __wc, size_t __n) + # if __GLIBC__ + (__GLIBC_MINOR__ >= 2) > 2 + _GL_ATTRIBUTE_NOTHROW diff --git a/pkgs/by-name/ps/pspp/package.nix b/pkgs/by-name/ps/pspp/package.nix index 7585269dc3d5..0cfad65068fd 100644 --- a/pkgs/by-name/ps/pspp/package.nix +++ b/pkgs/by-name/ps/pspp/package.nix @@ -55,10 +55,17 @@ stdenv.mkDerivation rec { iconv ]; + patches = [ + ./fix-glibc-2.42.patch + ]; + env = { C_INCLUDE_PATH = "${libxml2.dev}/include/libxml2/:" + lib.makeSearchPathOutput "dev" "include" buildInputs; LIBRARY_PATH = lib.makeLibraryPath buildInputs; + + # fix build w/ glibc-2.44 + NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; }; doCheck = false; From ada787547fccec71df54d565ddb901c1a10b219d Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:10:08 +0200 Subject: [PATCH 68/82] picolibc: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344179652 --- pkgs/by-name/pi/picolibc/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/pi/picolibc/package.nix b/pkgs/by-name/pi/picolibc/package.nix index 0bffb8ddd2e9..d9bf1a174531 100644 --- a/pkgs/by-name/pi/picolibc/package.nix +++ b/pkgs/by-name/pi/picolibc/package.nix @@ -1,5 +1,6 @@ { stdenvNoLibc, + fetchpatch, buildPackages, fetchFromGitHub, lib, @@ -34,6 +35,14 @@ stdenvNoLibc.mkDerivation (finalAttrs: { hash = "sha256-FhTNgffsnHbzIXOOwCMe6O1FGkEtqWfw+e30RW+Y4K4="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/picolibc/picolibc/commit/11a46b6ed03c4dca64e0534435da9841e837b160.patch"; + hash = "sha256-i1dKW1L5si0gf0/Sn4sU/BuIof778tvHgCCCY1TxMME="; + }) + ]; + depsBuildBuild = lib.optionals canExecute [ buildPackages.stdenv.cc ]; From 743f1ebcddaac34f54040de298caa47637baf78c Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:13:33 +0200 Subject: [PATCH 69/82] helix.tree-sitter-grammars.tree-sitter-perl: fix build w/ glibc-2.44 `bsearch` being a macro causes a syntax error on compilation. I'm letting the maintainers do an upgrade, for now we remove the custom bsearch implementation and let it use the glibc-provided one. Failing Hydra build: https://hydra.nixos.org/build/344158900/step/91/log --- pkgs/by-name/he/helix/package.nix | 18 +++++++++++++++++- 1 file changed, 17 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/he/helix/package.nix b/pkgs/by-name/he/helix/package.nix index e301693489f6..dd0f7662cab0 100644 --- a/pkgs/by-name/he/helix/package.nix +++ b/pkgs/by-name/he/helix/package.nix @@ -68,7 +68,23 @@ let helixTreeSitterGrammars = lib.filterAttrs (drvName: _: lib.hasAttr (lib.removePrefix "tree-sitter-" drvName) lockedGrammars) - (tree-sitter-grammars.overrideScope (lib.composeExtensions lockedVersionsOverlay grammarsOverlay)); + ( + tree-sitter-grammars.overrideScope ( + lib.composeManyExtensions [ + lockedVersionsOverlay + grammarsOverlay + (self: super: { + tree-sitter-perl = super.tree-sitter-perl.overrideAttrs { + postPatch = '' + rm src/bsearch.c + substituteInPlace src/tsp_unicode.h \ + --replace-fail '#include "bsearch.c"' "" + ''; + }; + }) + ] + ) + ); # Dynamic libraries for the grammars always use the `.so` extension, also on Darwin (should use `.dylib`) # See here: https://github.com/helix-editor/helix/pull/14982 From 056088250265813c5ab0b0c30cc10ca52c3acd6a Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:43:52 +0200 Subject: [PATCH 70/82] alsa-scarlett-gui: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344140166 --- pkgs/by-name/al/alsa-scarlett-gui/package.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/al/alsa-scarlett-gui/package.nix b/pkgs/by-name/al/alsa-scarlett-gui/package.nix index e96089a715c6..2215e090c31a 100644 --- a/pkgs/by-name/al/alsa-scarlett-gui/package.nix +++ b/pkgs/by-name/al/alsa-scarlett-gui/package.nix @@ -22,7 +22,10 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-DkfpMK0T67B4mnriignf4hx6Ifddls0rN0SxyfEsPZg="; }; - env.NIX_CFLAGS_COMPILE = toString [ "-Wno-error=deprecated-declarations" ]; + env.NIX_CFLAGS_COMPILE = toString [ + "-Wno-error=deprecated-declarations" + "-Wno-error=discarded-qualifiers" + ]; makeFlags = [ "DESTDIR=\${out}" From 26da0e8d57d830648f4c52435d48e89716a582ee Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:44:16 +0200 Subject: [PATCH 71/82] odp-dpdk: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344173889 --- pkgs/by-name/od/odp-dpdk/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/od/odp-dpdk/package.nix b/pkgs/by-name/od/odp-dpdk/package.nix index 76b5a869b4e4..c11143fa6c1f 100644 --- a/pkgs/by-name/od/odp-dpdk/package.nix +++ b/pkgs/by-name/od/odp-dpdk/package.nix @@ -34,6 +34,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-L6lF8VaycAz7PcFArAgLhI8+sc0jnAHY3gum/uDIYz4="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ autoreconfHook pkg-config From b4cd20c95b4ef2105b515efd5de86dc80241d008 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:45:04 +0200 Subject: [PATCH 72/82] openvas-scanner: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344174370 --- pkgs/by-name/op/openvas-scanner/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/op/openvas-scanner/package.nix b/pkgs/by-name/op/openvas-scanner/package.nix index 8868ea132e0d..72637f8f05f4 100644 --- a/pkgs/by-name/op/openvas-scanner/package.nix +++ b/pkgs/by-name/op/openvas-scanner/package.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-ggmex/BmAVgdE1JNM3kybEmr/uKqrIl8JdSoBnsg+40="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ cmake git From c3ff0d031367898743f6f7f2427c2f8f4fd43fba Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 9 Sep 2026 09:10:19 +0200 Subject: [PATCH 73/82] fnc: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344147213 --- pkgs/by-name/fn/fnc/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/fn/fnc/package.nix b/pkgs/by-name/fn/fnc/package.nix index 2e6b2abcde37..20fcea12bbca 100644 --- a/pkgs/by-name/fn/fnc/package.nix +++ b/pkgs/by-name/fn/fnc/package.nix @@ -28,6 +28,8 @@ stdenv.mkDerivation (finalAttrs: { lib.optionals stdenv.cc.isGNU [ # Needed with GCC 12 "-Wno-error=maybe-uninitialized" + # Fix build w/ glibc-2.44 + "-Wno-error=discarded-qualifiers" ] ); From b9cbf8617f196a3c4c44a55b564d9e7d44d84432 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 9 Sep 2026 09:10:42 +0200 Subject: [PATCH 74/82] orbuculum: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344174435 --- pkgs/by-name/or/orbuculum/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/or/orbuculum/package.nix b/pkgs/by-name/or/orbuculum/package.nix index 80ce39a2c83f..055a5051937e 100644 --- a/pkgs/by-name/or/orbuculum/package.nix +++ b/pkgs/by-name/or/orbuculum/package.nix @@ -39,6 +39,9 @@ stdenv.mkDerivation (finalAttrs: { popd ''; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ meson ninja From 6e4c64d6deb09965e0c6994b605095222494467f Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 9 Sep 2026 09:11:23 +0200 Subject: [PATCH 75/82] liquidwar: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344166064 --- pkgs/by-name/li/liquidwar/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/li/liquidwar/package.nix b/pkgs/by-name/li/liquidwar/package.nix index 8da0022a3421..35761a6e8d8d 100644 --- a/pkgs/by-name/li/liquidwar/package.nix +++ b/pkgs/by-name/li/liquidwar/package.nix @@ -96,6 +96,8 @@ stdenv.mkDerivation (finalAttrs: { "-Wno-error=address" "-Wno-error=use-after-free" "-std=gnu17" + # Fix build w/ glibc-2.44 + "-Wno-error=discarded-qualifiers" ] ++ [ "-Wno-error=deprecated-declarations" From f5757270ac1ba0a30e1505128ab70c5c6747ac17 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 9 Sep 2026 09:11:47 +0200 Subject: [PATCH 76/82] papi: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344174835/log --- pkgs/by-name/pa/papi/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/pa/papi/package.nix b/pkgs/by-name/pa/papi/package.nix index 96c0ee99f1ab..164a7b46104a 100644 --- a/pkgs/by-name/pa/papi/package.nix +++ b/pkgs/by-name/pa/papi/package.nix @@ -13,6 +13,9 @@ stdenv.mkDerivation (finalAttrs: { sha256 = "sha256-qb/4nM85kV1yngiuCgxqcc4Ou+mEEemi6zyDyNsK85w="; }; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + setSourceRoot = '' sourceRoot=$(echo */src) ''; From 19863a81d5d517028cdb38a091774ba3f366786d Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 9 Sep 2026 09:12:16 +0200 Subject: [PATCH 77/82] mimic: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344168963 --- pkgs/by-name/mi/mimic/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/mi/mimic/package.nix b/pkgs/by-name/mi/mimic/package.nix index 931460357fb8..5b158b89ee77 100644 --- a/pkgs/by-name/mi/mimic/package.nix +++ b/pkgs/by-name/mi/mimic/package.nix @@ -55,6 +55,8 @@ stdenv.mkDerivation (finalAttrs: { env.NIX_CFLAGS_COMPILE = toString [ # Needed with GCC 12 "-Wno-error=free-nonheap-object" + # Fix build w/ glibc-2.44 + "-Wno-error=discarded-qualifiers" ]; postInstall = '' From ee3cffdbb7e3d4bad12c32a6b6ff94e8700ec23e Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 9 Sep 2026 09:15:35 +0200 Subject: [PATCH 78/82] guacamole-server: 1.6.0-unstable-2025-06-29 -> 1.6.0-unstable-2026-08-16 Fixes build w/ glibc-2.44. Failing Hydra build: https://hydra.nixos.org/build/344150990 --- pkgs/by-name/gu/guacamole-server/package.nix | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/gu/guacamole-server/package.nix b/pkgs/by-name/gu/guacamole-server/package.nix index c79a68bdc5f7..89634c3bc25a 100644 --- a/pkgs/by-name/gu/guacamole-server/package.nix +++ b/pkgs/by-name/gu/guacamole-server/package.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchFromGitHub, - fetchpatch2, pkg-config, autoPatchelfHook, autoreconfHook, @@ -28,13 +27,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "guacamole-server"; - version = "1.6.0-unstable-2025-06-29"; + version = "1.6.0-unstable-2026-08-16"; src = fetchFromGitHub { owner = "apache"; repo = "guacamole-server"; - rev = "f3f5b9d76649ccc24f551cb166c81078f4b5e236"; - hash = "sha256-OjTwAQzKUuXfwZXLsL9XjrJc/0be38CmAGG+CoCeNwk="; + rev = "d3b7828977c63a5b197158d6cbbdaf1846b579fb"; + hash = "sha256-sxZLzF6m35EtfLRHb1+aqR3RF+piOuvPT9w9Hs3cor0="; }; env.NIX_CFLAGS_COMPILE = toString [ From 256511bd011ccca65cb19d0509c560716cc71213 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 9 Sep 2026 11:50:57 +0200 Subject: [PATCH 79/82] clickhouse: fix build w/ glibc-2.44 `struct open_how` is actually defined now, even though the value is set to false. Failing Hydra build: https://hydra.nixos.org/build/344143757 --- pkgs/by-name/cl/clickhouse/generic.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/cl/clickhouse/generic.nix b/pkgs/by-name/cl/clickhouse/generic.nix index 4616222f3363..ec64d528972a 100644 --- a/pkgs/by-name/cl/clickhouse/generic.nix +++ b/pkgs/by-name/cl/clickhouse/generic.nix @@ -130,6 +130,9 @@ llvmStdenv.mkDerivation (finalAttrs: { postPatch = '' patchShebangs src/ utils/ + + substituteInPlace contrib/liburing-cmake/CMakeLists.txt \ + --replace-fail "set (LIBURING_CONFIG_HAS_OPEN_HOW FALSE)" "set (LIBURING_CONFIG_HAS_OPEN_HOW TRUE)" '' + lib.optionalString stdenv.hostPlatform.isDarwin '' substituteInPlace cmake/tools.cmake \ From 12773d25e799cb948d94f198392036ba41fafaf2 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sat, 19 Sep 2026 15:27:54 +0200 Subject: [PATCH 80/82] linux_6_1: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344163800 The full commit[1] doesn't apply on 6.1, so I ported the only relevant portion to it. Backport is currently pending[2] (as I've noticed after hand-rolling this patch), so for now we're only applying what we actually need. [1] https://lore.kernel.org/r/20251206092825.1471385-1-mikhail.v.gavrilov@gmail.com [2] https://lore.kernel.org/all/2026051315-engorge-agreed-39cb@gregkh/ --- pkgs/os-specific/linux/kernel/C23-compat-6.1.patch | 13 +++++++++++++ pkgs/os-specific/linux/kernel/patches.nix | 5 +++++ pkgs/top-level/linux-kernels.nix | 1 + 3 files changed, 19 insertions(+) create mode 100644 pkgs/os-specific/linux/kernel/C23-compat-6.1.patch diff --git a/pkgs/os-specific/linux/kernel/C23-compat-6.1.patch b/pkgs/os-specific/linux/kernel/C23-compat-6.1.patch new file mode 100644 index 000000000000..73c268b8b615 --- /dev/null +++ b/pkgs/os-specific/linux/kernel/C23-compat-6.1.patch @@ -0,0 +1,13 @@ +diff --git a/tools/lib/bpf/libbpf.c b/tools/lib/bpf/libbpf.c +index 7bd6aff6e260..33b214a91338 100644 +--- a/tools/lib/bpf/libbpf.c ++++ b/tools/lib/bpf/libbpf.c +@@ -10748,7 +10748,7 @@ static int resolve_full_path(const char *file, char *result, size_t result_sz) + if (!search_paths[i]) + continue; + for (s = search_paths[i]; s != NULL; s = strchr(s, ':')) { +- char *next_path; ++ const char *next_path; + int seg_len; + + if (s[0] == ':') diff --git a/pkgs/os-specific/linux/kernel/patches.nix b/pkgs/os-specific/linux/kernel/patches.nix index db617c867064..12cf001b6503 100644 --- a/pkgs/os-specific/linux/kernel/patches.nix +++ b/pkgs/os-specific/linux/kernel/patches.nix @@ -27,4 +27,9 @@ name = "request-key-helper"; patch = ./request-key-helper.patch; }; + + libbpf_C23_compat = { + name = "c23-compat-libbpf"; + patch = ./C23-compat-6.1.patch; + }; } diff --git a/pkgs/top-level/linux-kernels.nix b/pkgs/top-level/linux-kernels.nix index d3fa965d9516..3baabf4a14b5 100644 --- a/pkgs/top-level/linux-kernels.nix +++ b/pkgs/top-level/linux-kernels.nix @@ -65,6 +65,7 @@ in kernelPatches = [ kernelPatches.bridge_stp_helper kernelPatches.request_key_helper + kernelPatches.libbpf_C23_compat ]; }; From 85f87c51d67caf1c13de83a949801efa6373ee63 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sat, 19 Sep 2026 15:51:30 +0200 Subject: [PATCH 81/82] electron_42: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344146127 Electron 43+ have a Chromium codebase that is new enough to contain the patch in question. --- pkgs/development/tools/electron/common.nix | 3 +- .../electron/fix-electron42-glibc-2.43.patch | 67 +++++++++++++++++++ 2 files changed, 69 insertions(+), 1 deletion(-) create mode 100644 pkgs/development/tools/electron/fix-electron42-glibc-2.43.patch diff --git a/pkgs/development/tools/electron/common.nix b/pkgs/development/tools/electron/common.nix index 5b72914afc4c..1d63d94bb7c4 100644 --- a/pkgs/development/tools/electron/common.nix +++ b/pkgs/development/tools/electron/common.nix @@ -111,7 +111,8 @@ in ++ # Restore fake libGLESv2.so which is patchelf'd by the chromium derivation lib.optional (lib.versionAtLeast info.version "44") - ./0001-Revert-build-stop-shipping-dummy-ANGLE-libs-in-Linux.patch; + ./0001-Revert-build-stop-shipping-dummy-ANGLE-libs-in-Linux.patch + ++ lib.optional (lib.versionOlder info.version "43") ./fix-electron42-glibc-2.43.patch; postPatch = '' mkdir -p third_party/jdk/current/bin diff --git a/pkgs/development/tools/electron/fix-electron42-glibc-2.43.patch b/pkgs/development/tools/electron/fix-electron42-glibc-2.43.patch new file mode 100644 index 000000000000..27ca436c2b52 --- /dev/null +++ b/pkgs/development/tools/electron/fix-electron42-glibc-2.43.patch @@ -0,0 +1,67 @@ +From 83a9ccb1265dcdeeb8bf17205e00b751f86641d3 Mon Sep 17 00:00:00 2001 +From: Ho Cheung +Date: Tue, 21 Apr 2026 08:19:53 -0700 +Subject: [PATCH] [sandbox] Fix SYS_SECCOMP conflict with newer glibc + +glibc now exposes SYS_SECCOMP in signal headers, which conflicts with +Chromium's fallback macro in linux_seccomp.h. + +Stop defining SYS_SECCOMP in the public compat header and use a local +fallback in trap.cc instead. + +Test: Tested on an Ubuntu 26.04 container using use_sysroot = false. +Bug: 456218403 +Change-Id: I73ddfa85453dd9d524b64b4c1bca4f95b82c9f2b +Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7781604 +Reviewed-by: Elly +Commit-Queue: Aaron Teo +Cr-Commit-Position: refs/heads/main@{#1618207} +--- + +diff --git a/sandbox/linux/seccomp-bpf/trap.cc b/sandbox/linux/seccomp-bpf/trap.cc +index 1316786d..212e80e 100644 +--- a/sandbox/linux/seccomp-bpf/trap.cc ++++ b/sandbox/linux/seccomp-bpf/trap.cc +@@ -29,6 +29,12 @@ + + namespace { + ++#if defined(SYS_SECCOMP) ++constexpr int kSigsysSeccompCode = SYS_SECCOMP; ++#else ++constexpr int kSigsysSeccompCode = 1; ++#endif ++ + struct arch_sigsys { + // RAW_PTR_EXCLUSION: Points to a code address given to us by the kernel. + RAW_PTR_EXCLUSION void* ip; +@@ -151,7 +157,7 @@ + // Various sanity checks to make sure we actually received a signal + // triggered by a BPF filter. If something else triggered SIGSYS + // (e.g. kill()), there is really nothing we can do with this signal. +- if (nr != LINUX_SIGSYS || info->si_code != SYS_SECCOMP || !ctx || ++ if (nr != LINUX_SIGSYS || info->si_code != kSigsysSeccompCode || !ctx || + info->si_errno <= 0 || + static_cast(info->si_errno) > trap_array_size_) { + // ATI drivers seem to send SIGSYS, so this cannot be FATAL. +@@ -162,7 +168,6 @@ + return; + } + +- + // Obtain the siginfo information that is specific to SIGSYS. + struct arch_sigsys sigsys; + #if defined(si_call_addr) +diff --git a/sandbox/linux/system_headers/linux_seccomp.h b/sandbox/linux/system_headers/linux_seccomp.h +index 8690a96..8ebf4045 100644 +--- a/sandbox/linux/system_headers/linux_seccomp.h ++++ b/sandbox/linux/system_headers/linux_seccomp.h +@@ -214,8 +214,4 @@ + #define SECCOMP_RET_INVALID 0x00010000U // Illegal return value + #endif + +-#ifndef SYS_SECCOMP +-#define SYS_SECCOMP 1 +-#endif +- + #endif // SANDBOX_LINUX_SYSTEM_HEADERS_LINUX_SECCOMP_H_ From 91c3fb7d5a389a5a4b1b17a2dc30429046089d57 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sat, 19 Sep 2026 16:06:45 +0200 Subject: [PATCH 82/82] zutty: mark as broken Failing Hydra build: https://hydra.nixos.org/build/344291345 No upstream fix available. --- pkgs/by-name/zu/zutty/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/zu/zutty/package.nix b/pkgs/by-name/zu/zutty/package.nix index 06f975b68420..5a6f7ebfb87d 100644 --- a/pkgs/by-name/zu/zutty/package.nix +++ b/pkgs/by-name/zu/zutty/package.nix @@ -57,5 +57,6 @@ stdenv.mkDerivation (finalAttrs: { license = lib.licenses.gpl3Plus; maintainers = [ lib.maintainers.rolfschr ]; platforms = lib.platforms.linux; + broken = true; # Added 2026-09-19, fails with latest glibc }; })