diff --git a/nixos/modules/system/boot/systemd.nix b/nixos/modules/system/boot/systemd.nix index 85693da630c6..f48256a599a5 100644 --- a/nixos/modules/system/boot/systemd.nix +++ b/nixos/modules/system/boot/systemd.nix @@ -244,21 +244,7 @@ in options.systemd = { - package = mkPackageOption pkgs "systemd" { } // { - apply = - pkg: - pkg.overrideAttrs (prevAttrs: { - patches = prevAttrs.patches or [ ] ++ [ - # Remove this with v261.5; it fixes an issue with switch-to-configuration - # https://github.com/NixOS/nixpkgs/pull/558350#issuecomment-5740583354 - (pkgs.fetchpatch { - name = "postpone-d-bus-queue-dispatch.patch"; - url = "https://github.com/systemd/systemd/commit/266b3e50218e2b27cd67d2371c165bf53ad3bf00.patch"; - hash = "sha256-dEEzZUqicnmgDuXVBV1y0BxzgKbb6Q47Dmxj+O71bFE="; - }) - ]; - }); - }; + package = mkPackageOption pkgs "systemd" { }; enableStrictShellChecks = mkEnableOption "" // { description = '' diff --git a/pkgs/by-name/at/at-spi2-core/package.nix b/pkgs/by-name/at/at-spi2-core/package.nix index ed43f5c35993..2aaac993d15a 100644 --- a/pkgs/by-name/at/at-spi2-core/package.nix +++ b/pkgs/by-name/at/at-spi2-core/package.nix @@ -29,7 +29,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "at-spi2-core"; - version = "2.60.6"; + version = "2.60.7"; outputs = [ "out" @@ -39,7 +39,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/at-spi2-core/${lib.versions.majorMinor finalAttrs.version}/at-spi2-core-${finalAttrs.version}.tar.xz"; - hash = "sha256-qJtkqLIXqAQr3w41y/q2Kc7uNWQNunXfV4r96ap4nVc="; + hash = "sha256-kok8gYg1UmS6Y5yj0nlDQ3sm7waZceqfqksg3kBZW5o="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/cu/cups/package.nix b/pkgs/by-name/cu/cups/package.nix index dd12a5dcef57..bc7e13d02f1f 100644 --- a/pkgs/by-name/cu/cups/package.nix +++ b/pkgs/by-name/cu/cups/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchurl, + fetchpatch, pkg-config, removeReferencesTo, zlib, @@ -42,6 +43,29 @@ stdenv.mkDerivation (finalAttrs: { "man" ]; + patches = [ + (fetchpatch { + name = "CVE-2026-87875.patch"; + url = "https://github.com/OpenPrinting/cups/commit/2b1dc178a2d2325135b855142e384f4e8c42d8e4.patch"; + excludes = [ "CHANGES.md" ]; + hash = "sha256-WHw/UWyUuYEBC6TRADpw+BBCaCts9Nd0jS9qsQHTBMo="; + }) + (fetchpatch { + url = "https://github.com/OpenPrinting/cups/commit/76b515154ce6264dae6d7cc44915d85e0e5fa0f4.patch"; + hash = "sha256-KtwcB4KrFmsLbtAz6u593qxbnozW2Vb/I9yX36gZTd0="; + }) + (fetchpatch { + url = "https://github.com/OpenPrinting/cups/commit/526adb34fe87f7f0cf5f63ae26751c1afa36a5d6.patch"; + hash = "sha256-Pg2xbCXalbvDvv5iI19MrjpOTW03XLKfEHN+lhImG1U="; + }) + (fetchpatch { + name = "CVE-2026-87876.patch"; + url = "https://github.com/OpenPrinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8.patch"; + excludes = [ "CHANGES.md" ]; + hash = "sha256-gohcRO93JE2ldF5uPbR0re9NYxb13AeVn4b/qYsQGaE="; + }) + ]; + postPatch = '' substituteInPlace cups/testfile.c \ --replace 'cupsFileFind("cat", "/bin' 'cupsFileFind("cat", "${coreutils}/bin' diff --git a/pkgs/by-name/ex/expat/package.nix b/pkgs/by-name/ex/expat/package.nix index 44df814f0746..3eec4f483a8d 100644 --- a/pkgs/by-name/ex/expat/package.nix +++ b/pkgs/by-name/ex/expat/package.nix @@ -18,18 +18,18 @@ # files. let - version = "2.8.4"; - tag = "R_${lib.replaceStrings [ "." ] [ "_" ] version}"; + tagFor = version: "R_${lib.replaceStrings [ "." ] [ "_" ] version}"; in + stdenv.mkDerivation (finalAttrs: { pname = "expat"; - inherit version; + version = "2.8.5"; src = fetchurl { url = with finalAttrs; - "https://github.com/libexpat/libexpat/releases/download/${tag}/${pname}-${version}.tar.xz"; - hash = "sha256-ZWrhzI2jtOpRO7TiVPM+YkOTgITA7GI52oczdrCZhac="; + "https://github.com/libexpat/libexpat/releases/download/${tagFor version}/${pname}-${version}.tar.xz"; + hash = "sha256-HnJ7iTPsUad6mp2a/PjmiLzkXZB8E+Nqtzk/425wMYI="; }; strictDeps = true; @@ -73,7 +73,7 @@ stdenv.mkDerivation (finalAttrs: { }; meta = { - changelog = "https://github.com/libexpat/libexpat/blob/${tag}/expat/Changes"; + changelog = "https://github.com/libexpat/libexpat/blob/${tagFor finalAttrs.version}/expat/Changes"; homepage = "https://libexpat.github.io/"; description = "Stream-oriented XML parser library written in C"; mainProgram = "xmlwf"; diff --git a/pkgs/by-name/fr/fribidi/package.nix b/pkgs/by-name/fr/fribidi/package.nix index f8fd5f3171c9..fa1e16a936fd 100644 --- a/pkgs/by-name/fr/fribidi/package.nix +++ b/pkgs/by-name/fr/fribidi/package.nix @@ -9,11 +9,18 @@ fixDarwinDylibNames, python3, testers, + + # for passthru.tests + pango, + libass, }: stdenv.mkDerivation (finalAttrs: { pname = "fribidi"; - version = "1.0.16"; + version = "1.0.17"; + + __structuredAttrs = true; + strictDeps = true; outputs = [ "out" @@ -26,7 +33,7 @@ stdenv.mkDerivation (finalAttrs: { url = with finalAttrs; "https://github.com/fribidi/fribidi/releases/download/v${version}/${pname}-${version}.tar.xz"; - sha256 = "sha256-GxzeWyNdQEeekb4vDoijCeMhTIq0cOyKJ0TYKlqeoFw="; + sha256 = "sha256-aUnc3ifUHOutH9dB/K/DbVWhAg0thy1KbrORTKq7raI="; }; postPatch = '' @@ -40,8 +47,17 @@ stdenv.mkDerivation (finalAttrs: { ] ++ lib.optional stdenv.hostPlatform.isDarwin fixDarwinDylibNames; + # necessary to compile helper which runs during build to generate tables + # see gen.tab/meson.build for details depsBuildBuild = [ buildPackages.stdenv.cc ]; + mesonFlags = lib.mapAttrsToList lib.mesonBool { + tests = finalAttrs.finalPackage.doCheck; + docs = true; + bin = true; + deprecated = true; + }; + doCheck = true; nativeCheckInputs = [ python3 ]; @@ -49,14 +65,18 @@ stdenv.mkDerivation (finalAttrs: { pkg-config = testers.hasPkgConfigModules { package = finalAttrs.finalPackage; }; + inherit pango libass; }; meta = { homepage = "https://github.com/fribidi/fribidi"; + changelog = "https://github.com/fribidi/fribidi/releases/tag/v${finalAttrs.version}"; description = "GNU implementation of the Unicode Bidirectional Algorithm (bidi)"; mainProgram = "fribidi"; license = lib.licenses.lgpl21; platforms = lib.platforms.unix; pkgConfigModules = [ "fribidi" ]; + maintainers = with lib.maintainers; [ tmarkus ]; + identifiers.cpeParts = lib.meta.cpeFullVersionWithVendor "gnu" finalAttrs.version; }; }) diff --git a/pkgs/by-name/gd/gdk-pixbuf/package.nix b/pkgs/by-name/gd/gdk-pixbuf/package.nix index a55bfa0909c6..618f24b74f4b 100644 --- a/pkgs/by-name/gd/gdk-pixbuf/package.nix +++ b/pkgs/by-name/gd/gdk-pixbuf/package.nix @@ -28,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gdk-pixbuf"; - version = "2.44.7"; + version = "2.44.8"; outputs = [ "out" @@ -40,7 +40,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/gdk-pixbuf/${lib.versions.majorMinor finalAttrs.version}/gdk-pixbuf-${finalAttrs.version}.tar.xz"; - hash = "sha256-Fy+A42JuwxUgqXBADxo2lOBHGPbCzSiF91JQ+1pplaQ="; + hash = "sha256-kZ9SlRKWGhLoHNS0tGakjDkzRp5/mjEMZRPNT7JSujw="; }; patches = [ diff --git a/pkgs/by-name/gh/ghostscript/package.nix b/pkgs/by-name/gh/ghostscript/package.nix index 6cd7c4b18ed1..f879a04b18ef 100644 --- a/pkgs/by-name/gh/ghostscript/package.nix +++ b/pkgs/by-name/gh/ghostscript/package.nix @@ -67,13 +67,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "ghostscript${lib.optionalString x11Support "-with-X"}"; - version = "10.07.1"; + version = "10.08.0"; src = fetchurl { url = "https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/download/gs${ lib.replaceStrings [ "." ] [ "" ] finalAttrs.version }/ghostscript-${finalAttrs.version}.tar.xz"; - hash = "sha256-HNt2bejbjx5YnIF/CcWFXqX2XfyFQORlpprBTBhBYCU="; + hash = "sha256-wgSSvI67lsh/ouUqCSbhzajN6V1mFF4BiscT/tXaOM8="; }; patches = [ diff --git a/pkgs/by-name/gi/git/package.nix b/pkgs/by-name/gi/git/package.nix index bf2f58e2b90e..75a1dd0a6345 100644 --- a/pkgs/by-name/gi/git/package.nix +++ b/pkgs/by-name/gi/git/package.nix @@ -85,6 +85,11 @@ let AuthenSASL DigestHMAC ]; + gitJumpBinPath = lib.makeBinPath [ + "$out" + perlPackages.perl + coreutils + ]; in stdenv.mkDerivation (finalAttrs: { @@ -207,6 +212,7 @@ stdenv.mkDerivation (finalAttrs: { (if stdenv.hostPlatform.isFreeBSD then libiconvReal else libiconv) bash ] + ++ lib.optionals pythonSupport [ python3 ] ++ lib.optionals perlSupport [ perlPackages.perl ] ++ lib.optionals guiSupport [ tcl @@ -393,9 +399,11 @@ stdenv.mkDerivation (finalAttrs: { # Also put git-http-backend into $PATH, so that we can use smart # HTTP(s) transports for pushing ln -s $out/libexec/git-core/git-http-backend${stdenv.hostPlatform.extensions.executable} $out/bin/git-http-backend - ln -s $out/share/git/contrib/git-jump/git-jump $out/bin/git-jump '' + lib.optionalString perlSupport '' + makeWrapper $out/share/git/contrib/git-jump/git-jump $out/bin/git-jump \ + --prefix PATH : "${gitJumpBinPath}" + # wrap perl commands makeWrapper "$out/share/git/contrib/credential/netrc/git-credential-netrc.perl" $out/libexec/git-core/git-credential-netrc \ --set PERL5LIB "$out/${perlPackages.perl.libPrefix}:${perlPackages.makePerlPath perlLibs}" @@ -422,6 +430,10 @@ stdenv.mkDerivation (finalAttrs: { done '' + + lib.optionalString pythonSupport '' + patchShebangs $out/share/git/contrib/fast-import/import-zips.py + '' + + ( if svnSupport then '' diff --git a/pkgs/by-name/gr/groff/package.nix b/pkgs/by-name/gr/groff/package.nix index 083b1493dcf6..5f9658967baf 100644 --- a/pkgs/by-name/gr/groff/package.nix +++ b/pkgs/by-name/gr/groff/package.nix @@ -41,11 +41,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "groff"; - version = "1.24.1"; + version = "1.24.2"; src = fetchurl { url = "mirror://gnu/groff/groff-${finalAttrs.version}.tar.gz"; - hash = "sha256-dOKBl5W2r/QxrqyYPWOpyJaO6roqLrp9+LpMe0Hnz9g="; + hash = "sha256-+cHv1b6743/G4QY9t0c86N8ePgvk/w9DzgT85X6cXdk="; }; patches = [ diff --git a/pkgs/by-name/gt/gtk4/package.nix b/pkgs/by-name/gt/gtk4/package.nix index 9b7807508a35..bf8eb18cc801 100644 --- a/pkgs/by-name/gt/gtk4/package.nix +++ b/pkgs/by-name/gt/gtk4/package.nix @@ -4,7 +4,6 @@ buildPackages, replaceVars, fetchurl, - fetchpatch, pkg-config, docutils, gettext, @@ -76,7 +75,7 @@ in stdenv.mkDerivation (finalAttrs: { pname = "gtk4"; - version = "4.22.4"; + version = "4.22.5"; outputs = [ "out" @@ -92,17 +91,9 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/gtk/${lib.versions.majorMinor finalAttrs.version}/gtk-${finalAttrs.version}.tar.xz"; - hash = "sha256-Ub2fYMfSOmZaVWxzZMIfsuTiglZrPn4JJFXo+RAzCJM="; + hash = "sha256-f9cl3rLLP43CGK2GLFBW/4VI9J07DkCBeW5ETCLRloY="; }; - patches = [ - (fetchpatch { - name = "fix-32bit-VkImage-null.patch"; - url = "https://gitlab.gnome.org/GNOME/gtk/-/commit/10d43de8f4f942cb591ada3103474bd7213425f1.patch"; - hash = "sha256-DJIL6M3XcsjBoMO77OxNi84d1DxAphAfot3N7Nq1QqQ="; - }) - ]; - depsBuildBuild = [ pkg-config ]; diff --git a/pkgs/by-name/ib/ibus/package.nix b/pkgs/by-name/ib/ibus/package.nix index 4437b30dc434..4ca3dd5608f4 100644 --- a/pkgs/by-name/ib/ibus/package.nix +++ b/pkgs/by-name/ib/ibus/package.nix @@ -3,6 +3,7 @@ stdenv, replaceVars, fetchFromGitHub, + fetchpatch, autoreconfHook, gettext, makeWrapper, @@ -90,6 +91,15 @@ stdenv.mkDerivation (finalAttrs: { ./build-without-dbus-launch.patch # https://github.com/NixOS/nixpkgs/issues/230290 ./vala-parallelism.patch + + # Fix crashes in `gtk_im_multicontext_set_delegate` with latest GTK + # GTK issue: https://gitlab.gnome.org/GNOME/gtk/-/work_items/8341 + # Upstream PR: https://github.com/ibus/ibus/pull/2929 + (fetchpatch { + name = "fix-gtk-crashes.patch"; + url = "https://github.com/ibus/ibus/commit/c534999a9dbea2666864250d74e058ecfb46e76f.patch"; + hash = "sha256-1h48hvdrDh2Qh4+SufL147CxlfiwvP/Jv509X0WnbrA="; + }) ]; outputs = [ diff --git a/pkgs/by-name/im/imagemagick/package.nix b/pkgs/by-name/im/imagemagick/package.nix index 9add255e855d..7df382f27ad7 100644 --- a/pkgs/by-name/im/imagemagick/package.nix +++ b/pkgs/by-name/im/imagemagick/package.nix @@ -88,13 +88,13 @@ in stdenv.mkDerivation (finalAttrs: { pname = "imagemagick"; - version = "7.1.2-31"; + version = "7.1.2-32"; src = fetchFromGitHub { owner = "ImageMagick"; repo = "ImageMagick"; tag = finalAttrs.version; - hash = "sha256-RQpvpWSEMIIGIDLk5X9BwsWgD0AKPBgJ2m9dSipq8Lc="; + hash = "sha256-/8U47oVkzU6VeYec6ZND+wAAJonsmwlcgeBvQ+M7hk8="; }; outputs = [ diff --git a/pkgs/by-name/li/libadwaita/package.nix b/pkgs/by-name/li/libadwaita/package.nix index c158da4ee9af..800cb225a32a 100644 --- a/pkgs/by-name/li/libadwaita/package.nix +++ b/pkgs/by-name/li/libadwaita/package.nix @@ -23,7 +23,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "libadwaita"; - version = "1.9.3"; + version = "1.9.4"; outputs = [ "out" @@ -37,7 +37,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "GNOME"; repo = "libadwaita"; tag = finalAttrs.version; - hash = "sha256-1V3L10YgRnOoJud/lybfSj2AYOY0kRAJdfamJg+S1fo="; + hash = "sha256-EhMwaZe+nzHNNakVKKXCBbFScavOb6c6anmVIvvjUvg="; }; depsBuildBuild = [ diff --git a/pkgs/by-name/li/libaom/outputs.patch b/pkgs/by-name/li/libaom/outputs.patch index 7b34338403f2..d7a6cafba539 100644 --- a/pkgs/by-name/li/libaom/outputs.patch +++ b/pkgs/by-name/li/libaom/outputs.patch @@ -1,8 +1,8 @@ -diff --git a/build/cmake/aom_install.cmake b/build/cmake/aom_install.cmake -index 0bd2bf035..5cf5acea8 100644 ---- a/build/cmake/aom_install.cmake -+++ b/build/cmake/aom_install.cmake -@@ -42,8 +42,8 @@ macro(setup_aom_install_targets) +diff --git a/cmake/aom_install.cmake b/cmake/aom_install.cmake +index a8f6d64361..c5223462ed 100644 +--- a/cmake/aom_install.cmake ++++ b/cmake/aom_install.cmake +@@ -45,8 +45,8 @@ macro(setup_aom_install_targets) -DAOM_ROOT=${AOM_ROOT} -DCMAKE_INSTALL_PREFIX=${CMAKE_INSTALL_PREFIX} -DCMAKE_INSTALL_BINDIR=${CMAKE_INSTALL_BINDIR} @@ -11,9 +11,9 @@ index 0bd2bf035..5cf5acea8 100644 + -DCMAKE_INSTALL_FULL_INCLUDEDIR=${CMAKE_INSTALL_FULL_INCLUDEDIR} + -DCMAKE_INSTALL_FULL_LIBDIR=${CMAKE_INSTALL_FULL_LIBDIR} -DCMAKE_PROJECT_NAME=${CMAKE_PROJECT_NAME} + -DCMAKE_THREAD_LIBS_INIT=${CMAKE_THREAD_LIBS_INIT} -DCONFIG_MULTITHREAD=${CONFIG_MULTITHREAD} - -DCONFIG_TUNE_VMAF=${CONFIG_TUNE_VMAF} -@@ -84,12 +84,12 @@ macro(setup_aom_install_targets) +@@ -115,13 +115,13 @@ macro(setup_aom_install_targets) # Setup the install rules. install() will automatically prepend # CMAKE_INSTALL_PREFIX to relative paths install(FILES ${AOM_INSTALL_INCS} @@ -23,6 +23,7 @@ index 0bd2bf035..5cf5acea8 100644 - DESTINATION "${CMAKE_INSTALL_LIBDIR}/pkgconfig") + DESTINATION "${CMAKE_INSTALL_FULL_LIBDIR}/pkgconfig") install(TARGETS ${AOM_INSTALL_LIBS};${AOM_INSTALL_BINS} + EXPORT "${AOM_TARGETS_EXPORT_NAME}" - RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}" - LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" - ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}") @@ -31,12 +32,12 @@ index 0bd2bf035..5cf5acea8 100644 + ARCHIVE DESTINATION "${CMAKE_INSTALL_FULL_LIBDIR}") endif() endmacro() -diff --git a/build/cmake/pkg_config.cmake b/build/cmake/pkg_config.cmake -index e8fff2e77..b8a73aad4 100644 ---- a/build/cmake/pkg_config.cmake -+++ b/build/cmake/pkg_config.cmake +diff --git a/cmake/pkg_config.cmake b/cmake/pkg_config.cmake +index ad3cf77009..1b46040cd1 100644 +--- a/cmake/pkg_config.cmake ++++ b/cmake/pkg_config.cmake @@ -11,8 +11,8 @@ - cmake_minimum_required(VERSION 3.5) + cmake_minimum_required(VERSION 3.16) set(REQUIRED_ARGS "AOM_ROOT" "AOM_CONFIG_DIR" "CMAKE_INSTALL_PREFIX" - "CMAKE_INSTALL_BINDIR" "CMAKE_INSTALL_INCLUDEDIR" diff --git a/pkgs/by-name/li/libaom/package.nix b/pkgs/by-name/li/libaom/package.nix index c8296dd90fb8..c8cf959b9bf0 100644 --- a/pkgs/by-name/li/libaom/package.nix +++ b/pkgs/by-name/li/libaom/package.nix @@ -23,25 +23,16 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "libaom"; - version = "3.12.1"; + version = "3.15.0"; src = fetchzip { url = "https://aomedia.googlesource.com/aom/+archive/v${finalAttrs.version}.tar.gz"; - hash = "sha256-AAS6wfq4rZ4frm6+gwKoIS3+NVzPhhfW428WXJQ2tQ8="; + hash = "sha256-TixZQP06TEZPtpHvWVOEagzHtXW9hqXWweO2yimBDG4="; stripRoot = false; }; patches = [ ./outputs.patch - ] - ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ - # This patch defines `_POSIX_C_SOURCE`, which breaks system headers - # on Darwin. - (fetchurl { - name = "musl.patch"; - url = "https://gitweb.gentoo.org/repo/gentoo.git/plain/media-libs/libaom/files/libaom-3.4.0-posix-c-source-ftello.patch?id=50c7c4021e347ee549164595280cf8a23c960959"; - hash = "sha256-6+u7GTxZcSNJgN7D+s+XAVwbMnULufkTcQ0s7l+Ydl0="; - }) ]; nativeBuildInputs = [ @@ -54,11 +45,16 @@ stdenv.mkDerivation (finalAttrs: { propagatedBuildInputs = lib.optional enableVmaf libvmaf; - env = lib.optionalAttrs stdenv.hostPlatform.isFreeBSD { - # This can be removed when we switch to libcxx from llvm 20 - # https://github.com/llvm/llvm-project/pull/122361 - NIX_CFLAGS_COMPILE = "-D_XOPEN_SOURCE=700"; - }; + env = + lib.optionalAttrs stdenv.hostPlatform.isFreeBSD { + # This can be removed when we switch to libcxx from llvm 20 + # https://github.com/llvm/llvm-project/pull/122361 + NIX_CFLAGS_COMPILE = "-D_XOPEN_SOURCE=700"; + } + // lib.optionalAttrs stdenv.hostPlatform.isLinux { + # _POSIX_C_SOURCE breaks system headers on Darwin; it's required on musl + NIX_CFLAGS_COMPILE = "-D_POSIX_C_SOURCE=200112L"; + }; preConfigure = '' # build uses `git describe` to set the build version @@ -91,11 +87,17 @@ stdenv.mkDerivation (finalAttrs: { postFixup = '' moveToOutput lib/libaom.a "$static" + substituteInPlace "$dev"/lib/cmake/*/*.cmake \ + --replace-quiet "$out/lib/libaom.a" "$static/lib/libaom.a" \ + --replace-quiet "$"'{_IMPORT_PREFIX}/include' "$dev/include" '' + lib.optionalString stdenv.hostPlatform.isStatic '' ln -s $static $out ''; + __structuredAttrs = true; + strictDeps = true; + outputs = [ "out" "bin" diff --git a/pkgs/by-name/li/libavif/package.nix b/pkgs/by-name/li/libavif/package.nix index c778d78d66a7..8ec16503feee 100644 --- a/pkgs/by-name/li/libavif/package.nix +++ b/pkgs/by-name/li/libavif/package.nix @@ -31,7 +31,7 @@ in stdenv.mkDerivation (finalAttrs: { pname = "libavif"; - version = "1.4.1"; + version = "1.4.2"; outputs = [ "out" @@ -42,7 +42,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "AOMediaCodec"; repo = "libavif"; rev = "v${finalAttrs.version}"; - hash = "sha256-035SoxHfN121mp3LGwGykReCi1WJbl2/nZH8c/VwABU="; + hash = "sha256-AMQ1TRPGpuBBW7tJ8xuLEVTAeOsLWTHuE0dFJjI7+W4="; }; postPatch = '' diff --git a/pkgs/by-name/li/libgcrypt/package.nix b/pkgs/by-name/li/libgcrypt/package.nix index 43f789b255f3..97c14ff90ccf 100644 --- a/pkgs/by-name/li/libgcrypt/package.nix +++ b/pkgs/by-name/li/libgcrypt/package.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchurl, - fetchpatch, gettext, libgpg-error, enableCapabilities ? false, @@ -18,23 +17,13 @@ assert enableCapabilities -> stdenv.hostPlatform.isLinux; stdenv.mkDerivation rec { pname = "libgcrypt"; - version = "1.12.2"; + version = "1.12.4"; src = fetchurl { url = "mirror://gnupg/libgcrypt/${pname}-${version}.tar.bz2"; - hash = "sha256-fOM8JJIiGgQ2+WqFACFenz49y1/SanV81BXnqEO6vV4="; + hash = "sha256-139o9Ih5UQ55ovZZd8zGiYF4HqCSPlvf+sKhk+o9Zg4="; }; - patches = lib.optionals stdenv.hostPlatform.isRiscV64 [ - # Remove in next release - # https://github.com/gpg/libgcrypt/commit/3f684fc6ab3ac98320e245a06b3563ad37ec56f5 - # zvkned AES corrupts CBC/CFB/CTR/OCB/XTS output on VLEN>128 hardware - (fetchpatch { - url = "https://github.com/gpg/libgcrypt/commit/3f684fc6ab3ac98320e245a06b3563ad37ec56f5.patch"; - hash = "sha256-1LSrIwsN0n5IBRDZ+9MJTEjzY+/T6LQO6hX1ke8hSuc="; - }) - ]; - outputs = [ "bin" "lib" diff --git a/pkgs/by-name/li/libheif/package.nix b/pkgs/by-name/li/libheif/package.nix index e8febed52bae..e1a009bf666b 100644 --- a/pkgs/by-name/li/libheif/package.nix +++ b/pkgs/by-name/li/libheif/package.nix @@ -24,7 +24,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "libheif"; - version = "1.23.4"; + version = "1.23.5"; outputs = [ "bin" @@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "strukturag"; repo = "libheif"; rev = "v${finalAttrs.version}"; - hash = "sha256-bxN3YB/nKjrsHa/dM3sTAnWR+wOHk5a6ku6NF+8moQ0="; + hash = "sha256-+nrUIAclVgkj4N5U3wQ1L6qpZuF3fuzHFDUT+X39h04="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/li/libpcap/package.nix b/pkgs/by-name/li/libpcap/package.nix index fefde4c82aa9..b91b49c22865 100644 --- a/pkgs/by-name/li/libpcap/package.nix +++ b/pkgs/by-name/li/libpcap/package.nix @@ -28,13 +28,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "libpcap"; - version = "1.10.6"; + version = "1.10.7"; __structuredAttrs = true; src = fetchurl { url = "https://www.tcpdump.org/release/libpcap-${finalAttrs.version}.tar.gz"; - hash = "sha256-hy3REzf+GrAq2dT+4EfJ2iRNaVxt3zTi67cz79Ttiqk="; + hash = "sha256-CzlKyQ28Cpg4/5dGjgXJyaPoc97CUUzVjbZdhZ0pbjE="; }; outputs = [ diff --git a/pkgs/by-name/li/librsvg/package.nix b/pkgs/by-name/li/librsvg/package.nix index 297c1a0eae32..4dc903987a67 100644 --- a/pkgs/by-name/li/librsvg/package.nix +++ b/pkgs/by-name/li/librsvg/package.nix @@ -50,7 +50,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "librsvg"; - version = "2.62.3"; + version = "2.62.4"; outputs = [ "out" @@ -62,13 +62,13 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/librsvg/${lib.versions.majorMinor finalAttrs.version}/librsvg-${finalAttrs.version}.tar.xz"; - hash = "sha256-frRJsnIqdoAhNW9m3+4yAsIptU7U5qcM5AwJDpf/FvI="; + hash = "sha256-yYK4FXoFS4A0k7+ZTTHlAQXrlI3Y2mtKuXNOjTknEqM="; }; cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) src; name = "librsvg-deps-${finalAttrs.version}"; - hash = "sha256-9ubfIl9R2BdcAWn7i050KBbb4cMdlakvrKdnjpZCQjA="; + hash = "sha256-8kFJQD3QQRFoQ1L+/pWwA0Tb8TQ4Zar2uvKrXywuW8E="; dontConfigure = true; }; diff --git a/pkgs/by-name/li/libsecret/package.nix b/pkgs/by-name/li/libsecret/package.nix index 92ab2fa2f8c1..ebaba034861d 100644 --- a/pkgs/by-name/li/libsecret/package.nix +++ b/pkgs/by-name/li/libsecret/package.nix @@ -71,7 +71,7 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "libsecret"; - version = "0.21.7"; + version = "0.21.8.2"; outputs = [ "out" @@ -81,7 +81,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/libsecret/${lib.versions.majorMinor finalAttrs.version}/libsecret-${finalAttrs.version}.tar.xz"; - hash = "sha256-a0UuR1BZCitWF63EACbyjS9JA94V8SUOHRxAv9aO1V4="; + hash = "sha256-FClIM5xblx2PaoxwmVIfb9MZtv5z0mlLTm0zEO0otuY="; }; depsBuildBuild = [ diff --git a/pkgs/by-name/me/memcached/package.nix b/pkgs/by-name/me/memcached/package.nix index e0b63e959ece..60dbfce191c3 100644 --- a/pkgs/by-name/me/memcached/package.nix +++ b/pkgs/by-name/me/memcached/package.nix @@ -8,12 +8,12 @@ }: stdenv.mkDerivation (finalAttrs: { - version = "1.6.42"; + version = "1.6.45"; pname = "memcached"; src = fetchurl { url = "https://memcached.org/files/memcached-${finalAttrs.version}.tar.gz"; - sha256 = "sha256-UPCLh51PnTbeqdkF6eqt4Vxwjjjbfppz/CHci0U5Xec="; + sha256 = "sha256-02LGTm2NUocVNQHqv3yFtKdhQy+/U/XXsIXQuxZTwd0="; }; configureFlags = [ diff --git a/pkgs/by-name/pc/pcre2/package.nix b/pkgs/by-name/pc/pcre2/package.nix index d828285dfa9b..ee476090840f 100644 --- a/pkgs/by-name/pc/pcre2/package.nix +++ b/pkgs/by-name/pc/pcre2/package.nix @@ -10,11 +10,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "pcre2"; - version = "10.48"; + version = "10.49"; src = fetchurl { url = "https://github.com/PCRE2Project/pcre2/releases/download/pcre2-${finalAttrs.version}/pcre2-${finalAttrs.version}.tar.bz2"; - hash = "sha256-tsaP3286wxOItQqon/D8ScAMmHwW57UUZJHRIAPyyO0="; + hash = "sha256-U8FW4bpBaiDajmU5XaoTLaDYDnaRBCTKyj/Nrngx04Q="; }; nativeBuildInputs = [ updateAutotoolsGnuConfigScriptsHook ]; diff --git a/pkgs/by-name/su/sudo/package.nix b/pkgs/by-name/su/sudo/package.nix index 781761698db3..b7cf22098efb 100644 --- a/pkgs/by-name/su/sudo/package.nix +++ b/pkgs/by-name/su/sudo/package.nix @@ -1,6 +1,7 @@ { lib, stdenv, + fetchpatch2, fetchurl, buildPackages, coreutils, @@ -31,9 +32,22 @@ stdenv.mkDerivation (finalAttrs: { prePatch = '' # do not set sticky bit in nix store - substituteInPlace src/Makefile.in --replace 04755 0755 + substituteInPlace src/Makefile.in --replace-fail 04755 0755 ''; + patches = [ + (fetchpatch2 { + name = "CVE-2026-96512_1.patch"; + url = "https://github.com/sudo-project/sudo/commit/db669167ca599f2a94cd8a4c5fae9e473c81a2fd.patch?full_index=1"; + hash = "sha256-VqfWo/z7CQCtgefzE8xAehjgKn2h1It6GkEt5BUn/OQ="; + }) + (fetchpatch2 { + name = "CVE-2026-96512_2.patch"; + url = "https://github.com/sudo-project/sudo/commit/1820a349687522f51023d1ae5925125f59679a8c.patch?full_index=1"; + hash = "sha256-guOdOaIqmXAftpj9gpsRFaAS5g2cS4j7o5DQFqyLZv8="; + }) + ]; + configureFlags = [ "--with-env-editor" "--with-editor=/run/current-system/sw/bin/nano" diff --git a/pkgs/by-name/th/thrift/package.nix b/pkgs/by-name/th/thrift/package.nix index 319c2413d96a..75cfb84a482d 100644 --- a/pkgs/by-name/th/thrift/package.nix +++ b/pkgs/by-name/th/thrift/package.nix @@ -17,13 +17,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "thrift"; - version = "0.22.0"; + version = "0.24.0"; src = fetchFromGitHub { owner = "apache"; repo = "thrift"; tag = "v${finalAttrs.version}"; - hash = "sha256-gGAO+D0A/hEoHMm6OvRBc1Mks9y52kfd0q/Sg96pdW4="; + hash = "sha256-+o/2exHsunjQBGjXrNQ1pQ5TKV53++qCxIMeVyOh5QY="; }; # Workaround to make the Python wrapper not drop this package: @@ -103,7 +103,7 @@ stdenv.mkDerivation (finalAttrs: { "StressTestNonBlocking" ]; - doCheck = !static; + doCheck = !static && !stdenv.hostPlatform.isDarwin; # FIXME darwin? enableParallelChecking = false; diff --git a/pkgs/by-name/un/unbound/package.nix b/pkgs/by-name/un/unbound/package.nix index 2dba1d12c66d..a2fecbd1921d 100644 --- a/pkgs/by-name/un/unbound/package.nix +++ b/pkgs/by-name/un/unbound/package.nix @@ -63,13 +63,13 @@ assert lib.assertMsg ( ) "unbound: withDoQ requires OpenSSL with QUIC support (OpenSSL >= 3.5)"; stdenv.mkDerivation (finalAttrs: { pname = "unbound"; - version = "1.26.0"; + version = "1.26.1"; src = fetchFromGitHub { owner = "NLnetLabs"; repo = "unbound"; tag = "release-${finalAttrs.version}"; - hash = "sha256-ESRboc5vwsNZ/Yynl2JGRWhH1QEYZumoTzgSvN3NbSU="; + hash = "sha256-gf4vASdB6XzSGhJ2GKbUhgs0wpR32Du2ARx4bBQ+vJA="; }; outputs = [ diff --git a/pkgs/by-name/xd/xdg-dbus-proxy/package.nix b/pkgs/by-name/xd/xdg-dbus-proxy/package.nix index 098785d5556c..e580314238f5 100644 --- a/pkgs/by-name/xd/xdg-dbus-proxy/package.nix +++ b/pkgs/by-name/xd/xdg-dbus-proxy/package.nix @@ -14,11 +14,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "xdg-dbus-proxy"; - version = "0.1.7"; + version = "0.1.8"; src = fetchurl { url = "https://github.com/flatpak/xdg-dbus-proxy/releases/download/${finalAttrs.version}/xdg-dbus-proxy-${finalAttrs.version}.tar.xz"; - hash = "sha256-OtPSe6V04XisteTUOLo2rOJeNWT4mcNvMcVvgsetu+c="; + hash = "sha256-tmML0k+BYbDiVG0qy7AUo7Mkn1wNdfKoY63omLkDTT0="; }; nativeBuildInputs = [ diff --git a/pkgs/development/compilers/llvm/18/lldb/backport-ParseTrieEntries-fixes.patch b/pkgs/development/compilers/llvm/18/lldb/backport-ParseTrieEntries-fixes.patch new file mode 100644 index 000000000000..f165c7e9ebbe --- /dev/null +++ b/pkgs/development/compilers/llvm/18/lldb/backport-ParseTrieEntries-fixes.patch @@ -0,0 +1,124 @@ +diff --git a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +index 2c7005449f..e0c426afa0 100644 +--- a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp ++++ b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +@@ -137,6 +137,14 @@ + using namespace lldb_private; + using namespace llvm::MachO; + ++/// Upper bound on the length of a symbol name assembled from export-trie edge ++/// labels. A corrupt trie can encode an edge label whose terminator is far ++/// away in the trie data, so a single label is many megabytes long; appending ++/// it to the running name would otherwise request an unbounded allocation. No ++/// legitimate symbol name comes close to this size. Also 1 MiB is the ++/// symbol length limit in ld. ++static constexpr size_t kMaxTrieSymbolNameLength = 1 << 20; // 1 MiB ++ + LLDB_PLUGIN_DEFINE(ObjectFileMachO) + + static void PrintRegisterValue(RegisterContext *reg_ctx, const char *name, +@@ -2050,15 +2058,21 @@ + } + }; + +-static bool ParseTrieEntries(DataExtractor &data, lldb::offset_t offset, +- const bool is_arm, addr_t text_seg_base_addr, +- std::vector &nameSlices, +- std::set &resolver_addresses, +- std::vector &reexports, +- std::vector &ext_symbols) { ++static bool ParseTrieEntriesImpl(DataExtractor &data, lldb::offset_t offset, ++ const bool is_arm, addr_t text_seg_base_addr, ++ std::string &prefix, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols, ++ std::set &visited_nodes) { + if (!data.ValidOffset(offset)) + return true; + ++ // Every node in a well-formed trie is reached by exactly one path, so a node ++ // offset seen twice means the trie is corrupt. ++ if (!visited_nodes.insert(offset).second) ++ return false; ++ + // Terminal node -- end of a branch, possibly add this to + // the symbol table or resolver table. + const uint64_t terminalSize = data.GetULEB128(&offset); +@@ -2098,14 +2112,9 @@ + add_this_entry = true; + } + if (add_this_entry) { +- std::string name; +- if (!nameSlices.empty()) { +- for (auto name_slice : nameSlices) +- name.append(name_slice.data(), name_slice.size()); +- } +- if (name.size() > 1) { ++ if (prefix.size() > 1) { + // Skip the leading '_' +- e.entry.name.SetCStringWithLength(name.c_str() + 1, name.size() - 1); ++ e.entry.name.SetString(llvm::StringRef(prefix).drop_front()); + } + if (import_name) { + // Skip the leading '_' +@@ -2126,23 +2135,36 @@ + const uint8_t childrenCount = data.GetU8(&children_offset); + for (uint8_t i = 0; i < childrenCount; ++i) { + const char *cstr = data.GetCStr(&children_offset); +- if (cstr) +- nameSlices.push_back(llvm::StringRef(cstr)); +- else ++ if (!cstr) + return false; // Corrupt data ++ if (prefix.size() + llvm::StringRef(cstr).size() > kMaxTrieSymbolNameLength) ++ return false; // Corrupt data: implausibly long symbol name. ++ const size_t prevSize = prefix.size(); ++ prefix.append(cstr); + lldb::offset_t childNodeOffset = data.GetULEB128(&children_offset); +- if (childNodeOffset) { +- if (!ParseTrieEntries(data, childNodeOffset, is_arm, text_seg_base_addr, +- nameSlices, resolver_addresses, reexports, +- ext_symbols)) { +- return false; +- } +- } +- nameSlices.pop_back(); ++ // A child offset of 0 points back at the root; like any other repeated ++ // offset it is a cycle, which ParseTrieEntriesImpl rejects as corrupt. ++ if (!ParseTrieEntriesImpl(data, childNodeOffset, is_arm, text_seg_base_addr, ++ prefix, resolver_addresses, reexports, ++ ext_symbols, visited_nodes)) ++ return false; ++ prefix.resize(prevSize); + } + return true; + } + ++static bool ParseTrieEntries( ++ DataExtractor &data, const bool is_arm, lldb::addr_t text_seg_base_addr, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols) { ++ lldb::offset_t offset = 0; ++ std::set visited_nodes; ++ std::string prefix; ++ return ParseTrieEntriesImpl(data, offset, is_arm, text_seg_base_addr, prefix, ++ resolver_addresses, reexports, ext_symbols, ++ visited_nodes); ++} + static SymbolType GetSymbolType(const char *&symbol_name, + bool &demangled_is_synthesized, + const SectionSP &text_section_sp, +@@ -2666,9 +2688,8 @@ + lldb::addr_t text_segment_file_addr = LLDB_INVALID_ADDRESS; + if (text_segment_sp) + text_segment_file_addr = text_segment_sp->GetFileAddress(); +- std::vector nameSlices; +- ParseTrieEntries(dyld_trie_data, 0, is_arm, text_segment_file_addr, +- nameSlices, resolver_addresses, reexport_trie_entries, ++ ParseTrieEntries(dyld_trie_data, is_arm, text_segment_file_addr, ++ resolver_addresses, reexport_trie_entries, + external_sym_trie_entries); + } + diff --git a/pkgs/development/compilers/llvm/18/llvm/backport-darwin-triple-parsing.patch b/pkgs/development/compilers/llvm/18/llvm/backport-darwin-triple-parsing.patch new file mode 100644 index 000000000000..9426f99512b7 --- /dev/null +++ b/pkgs/development/compilers/llvm/18/llvm/backport-darwin-triple-parsing.patch @@ -0,0 +1,34 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Tue, 11 Aug 2026 20:12:42 -0400 +Subject: [PATCH] backport-darwin-triple-parsing + +--- + lib/TargetParser/Triple.cpp | 10 ++++++++-- + 1 file changed, 8 insertions(+), 2 deletions(-) + +diff --git a/lib/TargetParser/Triple.cpp b/lib/TargetParser/Triple.cpp +index 0bbe8a3cedfd..4143c3eac05d 100644 +--- a/lib/TargetParser/Triple.cpp ++++ b/lib/TargetParser/Triple.cpp +@@ -1253,9 +1253,15 @@ bool Triple::getMacOSXVersion(VersionTuple &Version) const { + } + if (Version.getMajor() <= 19) { + Version = VersionTuple(10, Version.getMajor() - 4); +- } else { +- // darwin20+ corresponds to macOS 11+. ++ } else if (Version.getMajor() < 25) { ++ // darwin20-24 corresponds to macOS 11-15. + Version = VersionTuple(11 + Version.getMajor() - 20); ++ } else if ((Version.getMajor() == 25) || (Version.getMajor() == 26)) { ++ // darwin25-26 corresponds to macOS 26-27. ++ Version = VersionTuple(Version.getMajor() + 1); ++ } else { ++ // Starting with darwin27, it naturally corresponds to the same macOS ++ // version. + } + break; + case MacOSX: +-- +2.54.0 + diff --git a/pkgs/development/compilers/llvm/21/llvm/backport-darwin-triple-parsing.patch b/pkgs/development/compilers/llvm/21/llvm/backport-darwin-triple-parsing.patch new file mode 100644 index 000000000000..7f2cc06b51d4 --- /dev/null +++ b/pkgs/development/compilers/llvm/21/llvm/backport-darwin-triple-parsing.patch @@ -0,0 +1,31 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Tue, 11 Aug 2026 20:19:29 -0400 +Subject: [PATCH] backport-darwin-triple-parsing + +--- + lib/TargetParser/Triple.cpp | 7 +++++-- + 1 file changed, 5 insertions(+), 2 deletions(-) + +diff --git a/lib/TargetParser/Triple.cpp b/lib/TargetParser/Triple.cpp +index 0584c941d2e6..30cf78dbaabc 100644 +--- a/lib/TargetParser/Triple.cpp ++++ b/lib/TargetParser/Triple.cpp +@@ -1449,9 +1449,12 @@ bool Triple::getMacOSXVersion(VersionTuple &Version) const { + } else if (Version.getMajor() < 25) { + // darwin20-24 corresponds to macOS 11-15. + Version = VersionTuple(11 + Version.getMajor() - 20); +- } else { +- // darwin25 corresponds with macOS26+. ++ } else if ((Version.getMajor() == 25) || (Version.getMajor() == 26)) { ++ // darwin25-26 corresponds to macOS 26-27. + Version = VersionTuple(Version.getMajor() + 1); ++ } else { ++ // Starting with darwin27, it naturally corresponds to the same macOS ++ // version. + } + break; + case MacOSX: +-- +2.54.0 + diff --git a/pkgs/development/compilers/llvm/22/lldb/backport-ParseTrieEntries-fixes.patch b/pkgs/development/compilers/llvm/22/lldb/backport-ParseTrieEntries-fixes.patch new file mode 100644 index 000000000000..312be42ec2fb --- /dev/null +++ b/pkgs/development/compilers/llvm/22/lldb/backport-ParseTrieEntries-fixes.patch @@ -0,0 +1,125 @@ +diff --git a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +index 0be7b4c6f8..f9d9a05920 100644 +--- a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp ++++ b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +@@ -137,6 +137,14 @@ + static constexpr llvm::StringLiteral g_loader_path = "@loader_path"; + static constexpr llvm::StringLiteral g_executable_path = "@executable_path"; + ++/// Upper bound on the length of a symbol name assembled from export-trie edge ++/// labels. A corrupt trie can encode an edge label whose terminator is far ++/// away in the trie data, so a single label is many megabytes long; appending ++/// it to the running name would otherwise request an unbounded allocation. No ++/// legitimate symbol name comes close to this size. Also 1 MiB is the ++/// symbol length limit in ld. ++static constexpr size_t kMaxTrieSymbolNameLength = 1 << 20; // 1 MiB ++ + LLDB_PLUGIN_DEFINE(ObjectFileMachO) + + static void PrintRegisterValue(RegisterContext *reg_ctx, const char *name, +@@ -1994,15 +2002,21 @@ + } + }; + +-static bool ParseTrieEntries(DataExtractor &data, lldb::offset_t offset, +- const bool is_arm, addr_t text_seg_base_addr, +- std::vector &nameSlices, +- std::set &resolver_addresses, +- std::vector &reexports, +- std::vector &ext_symbols) { ++static bool ParseTrieEntriesImpl(DataExtractor &data, lldb::offset_t offset, ++ const bool is_arm, addr_t text_seg_base_addr, ++ std::string &prefix, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols, ++ std::set &visited_nodes) { + if (!data.ValidOffset(offset)) + return true; + ++ // Every node in a well-formed trie is reached by exactly one path, so a node ++ // offset seen twice means the trie is corrupt. ++ if (!visited_nodes.insert(offset).second) ++ return false; ++ + // Terminal node -- end of a branch, possibly add this to + // the symbol table or resolver table. + const uint64_t terminalSize = data.GetULEB128(&offset); +@@ -2042,14 +2056,9 @@ + add_this_entry = true; + } + if (add_this_entry) { +- std::string name; +- if (!nameSlices.empty()) { +- for (auto name_slice : nameSlices) +- name.append(name_slice.data(), name_slice.size()); +- } +- if (name.size() > 1) { ++ if (prefix.size() > 1) { + // Skip the leading '_' +- e.entry.name.SetCStringWithLength(name.c_str() + 1, name.size() - 1); ++ e.entry.name.SetString(llvm::StringRef(prefix).drop_front()); + } + if (import_name) { + // Skip the leading '_' +@@ -2070,23 +2079,37 @@ + const uint8_t childrenCount = data.GetU8(&children_offset); + for (uint8_t i = 0; i < childrenCount; ++i) { + const char *cstr = data.GetCStr(&children_offset); +- if (cstr) +- nameSlices.push_back(llvm::StringRef(cstr)); +- else ++ if (!cstr) + return false; // Corrupt data ++ if (prefix.size() + llvm::StringRef(cstr).size() > kMaxTrieSymbolNameLength) ++ return false; // Corrupt data: implausibly long symbol name. ++ const size_t prevSize = prefix.size(); ++ prefix.append(cstr); + lldb::offset_t childNodeOffset = data.GetULEB128(&children_offset); +- if (childNodeOffset) { +- if (!ParseTrieEntries(data, childNodeOffset, is_arm, text_seg_base_addr, +- nameSlices, resolver_addresses, reexports, +- ext_symbols)) { +- return false; +- } +- } +- nameSlices.pop_back(); ++ // A child offset of 0 points back at the root; like any other repeated ++ // offset it is a cycle, which ParseTrieEntriesImpl rejects as corrupt. ++ if (!ParseTrieEntriesImpl(data, childNodeOffset, is_arm, text_seg_base_addr, ++ prefix, resolver_addresses, reexports, ++ ext_symbols, visited_nodes)) ++ return false; ++ prefix.resize(prevSize); + } + return true; + } + ++static bool ParseTrieEntries( ++ DataExtractor &data, const bool is_arm, lldb::addr_t text_seg_base_addr, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols) { ++ lldb::offset_t offset = 0; ++ std::set visited_nodes; ++ std::string prefix; ++ return ParseTrieEntriesImpl(data, offset, is_arm, text_seg_base_addr, prefix, ++ resolver_addresses, reexports, ext_symbols, ++ visited_nodes); ++} ++ + static bool + TryParseV2ObjCMetadataSymbol(const char *&symbol_name, + const char *&symbol_name_non_abi_mangled, +@@ -2659,9 +2682,8 @@ + lldb::addr_t text_segment_file_addr = LLDB_INVALID_ADDRESS; + if (text_segment_sp) + text_segment_file_addr = text_segment_sp->GetFileAddress(); +- std::vector nameSlices; +- ParseTrieEntries(dyld_trie_data, 0, is_arm, text_segment_file_addr, +- nameSlices, resolver_addresses, reexport_trie_entries, ++ ParseTrieEntries(dyld_trie_data, is_arm, text_segment_file_addr, ++ resolver_addresses, reexport_trie_entries, + external_sym_trie_entries); + } + diff --git a/pkgs/development/compilers/llvm/common/lldb/default.nix b/pkgs/development/compilers/llvm/common/lldb/default.nix index a36f3efab0a0..fb1de5ef2b30 100644 --- a/pkgs/development/compilers/llvm/common/lldb/default.nix +++ b/pkgs/development/compilers/llvm/common/lldb/default.nix @@ -77,6 +77,10 @@ stdenv.mkDerivation ( # Fix build with gcc15 # https://github.com/llvm/llvm-project/commit/bb59f04e7e75dcbe39f1bf952304a157f0035314 ./lldb-add-include-cstdint.patch + ] + ++ lib.optionals (lib.versionOlder (lib.versions.major release_version) "23") [ + # Backports several fixes to export trie parsing. Otherwise, LLDB crashes when starting a debugging session on macOS 27. + (getVersionFile "lldb/backport-ParseTrieEntries-fixes.patch") ]; nativeBuildInputs = [ diff --git a/pkgs/development/compilers/llvm/common/llvm/default.nix b/pkgs/development/compilers/llvm/common/llvm/default.nix index d5dcd4d58cce..b82840833426 100644 --- a/pkgs/development/compilers/llvm/common/llvm/default.nix +++ b/pkgs/development/compilers/llvm/common/llvm/default.nix @@ -222,7 +222,14 @@ stdenv.mkDerivation ( hash = "sha256-3hkbYPUVRAtWpo5qBmc2jLZLivURMx8T0GQomvNZesc="; stripLen = 1; } - ); + ) + ++ lib.optionals (lib.versionOlder release_version "23") [ + # As of macOS 27 (and iOS 27, etc), the Darwin version number is the same as the OS version number. + # This change breaks target parsing because `darwin27` is incorrectly interpreted as macOS 28. + # This patch is a backport of the target parsing changes in LLVM 23, which fixes the problem. + # Hopefully, Apple does not change the version number scheme again any time soon. + (getVersionFile "llvm/backport-darwin-triple-parsing.patch") + ]; nativeBuildInputs = [ cmake @@ -297,16 +304,6 @@ stdenv.mkDerivation ( substituteInPlace unittests/Support/VirtualFileSystemTest.cpp \ --replace-fail "PhysicalFileSystemWorkingDirFailure" "DISABLED_PhysicalFileSystemWorkingDirFailure" '' - + - # Fails on macOS ≥ 26 due to the changed OS version scheme. - # - # This was fixed upstream in LLVM 21 with - # 88f041f3e05e26617856cc096d2e2864dfaa1c7b, but it’s too - # painful to backport all the way. - lib.optionalString (lib.versionOlder release_version "21") '' - substituteInPlace unittests/TargetParser/Host.cpp \ - --replace-fail "getMacOSHostVersion" "DISABLED_getMacOSHostVersion" - '' + # This test fails with a `dysmutil` crash; have not yet dug into what's # going on here (TODO(@rrbutani)). diff --git a/pkgs/development/compilers/llvm/common/patches.nix b/pkgs/development/compilers/llvm/common/patches.nix index 76ae90c3aaa7..a2ecc75785c9 100644 --- a/pkgs/development/compilers/llvm/common/patches.nix +++ b/pkgs/development/compilers/llvm/common/patches.nix @@ -20,6 +20,28 @@ path = ../18; } ]; + "lldb/backport-ParseTrieEntries-fixes.patch" = [ + { + before = "22"; + path = ../18; + } + { + after = "22"; + before = "23"; + path = ../22; + } + ]; + "llvm/backport-darwin-triple-parsing.patch" = [ + { + after = "18"; + before = "21"; + path = ../18; + } + { + after = "21"; + path = ../21; + } + ]; "llvm/gnu-install-dirs.patch" = [ { after = "23"; diff --git a/pkgs/development/interpreters/perl/CVE-2026-15534-1.patch b/pkgs/development/interpreters/perl/CVE-2026-15534-1.patch new file mode 100644 index 000000000000..fc8ee2f29ea9 --- /dev/null +++ b/pkgs/development/interpreters/perl/CVE-2026-15534-1.patch @@ -0,0 +1,39 @@ +CVE-2026-15534, upstream commit +568e6fd238867bb9e99fa3f47cba3169009239e0. + +diff --git a/regexec.c b/regexec.c +index 35a727459c4a..29aa73c13cb9 100644 +--- a/regexec.c ++++ b/regexec.c +@@ -9211,7 +9211,8 @@ NULL + reginfo->poscache_iter = reginfo->poscache_maxiter; + } + +- if (reginfo->poscache_iter-- == 0) { ++ if (reginfo->poscache_iter == 1) { ++ reginfo->poscache_iter--; + /* initialise cache */ + const SSize_t size = (reginfo->poscache_maxiter + 7)/8; + regmatch_info_aux *const aux = reginfo->info_aux; +@@ -9232,11 +9233,10 @@ NULL + ); + } + +- if (reginfo->poscache_iter < 0) { ++ if (reginfo->poscache_iter == 0) { + /* have we already failed at this position? */ + SSize_t offset, mask; + +- reginfo->poscache_iter = -1; /* stop eventual underflow */ + offset = (FLAGS(scan) & 0xf) - 1 + + (locinput - reginfo->strbeg) + * (FLAGS(scan)>>4); +@@ -9252,6 +9252,8 @@ NULL + ST.cache_offset = offset; + ST.cache_mask = mask; + } ++ else ++ reginfo->poscache_iter--; + } + + /* Prefer B over A for minimal matching. */ diff --git a/pkgs/development/interpreters/perl/CVE-2026-15534-2.patch b/pkgs/development/interpreters/perl/CVE-2026-15534-2.patch new file mode 100644 index 000000000000..b5d0ff5ed3d0 --- /dev/null +++ b/pkgs/development/interpreters/perl/CVE-2026-15534-2.patch @@ -0,0 +1,59 @@ +CVE-2026-15534, upstream commit +54cf3d44cbbedd17d774e9a37921963e8fd5d0cb. + +diff --git a/regexec.c b/regexec.c +index 29aa73c13cb9..66e0c0924059 100644 +--- a/regexec.c ++++ b/regexec.c +@@ -9202,22 +9202,27 @@ NULL + if (!reginfo->poscache_maxiter) { + /* start the countdown: Postpone detection until we + * know the match is not *that* much linear. */ +- reginfo->poscache_maxiter +- = (reginfo->strend - reginfo->strbeg + 1) +- * (FLAGS(scan)>>4); +- /* possible overflow for long strings and many CURLYX's */ +- if (reginfo->poscache_maxiter < 0) +- reginfo->poscache_maxiter = I32_MAX; +- reginfo->poscache_iter = reginfo->poscache_maxiter; ++ STRLEN len = reginfo->strend - reginfo->strbeg; ++ /* number of participating WHILEMs */ ++ U8 n = (FLAGS(scan)>>4); ++ ++ /* Only do the calculations and enable the cache if it ++ * won't overflow. This test is equivalent to: ++ * ((len + 1) * n + 7) <= max(STRLEN) ++ */ ++ if (len < ((~(STRLEN)0) - 7)/n) { ++ reginfo->poscache_maxiter = (len + 1) * n; ++ reginfo->poscache_iter = reginfo->poscache_maxiter; ++ } + } + + if (reginfo->poscache_iter == 1) { + reginfo->poscache_iter--; + /* initialise cache */ +- const SSize_t size = (reginfo->poscache_maxiter + 7)/8; ++ const STRLEN size = (reginfo->poscache_maxiter + 7)/8; + regmatch_info_aux *const aux = reginfo->info_aux; + if (aux->poscache) { +- if ((SSize_t)reginfo->poscache_size < size) { ++ if (reginfo->poscache_size < size) { + Renew(aux->poscache, size, char); + reginfo->poscache_size = size; + } +diff --git a/regexp.h b/regexp.h +index 057d9ac5011b..d5d40e0a5618 100644 +--- a/regexp.h ++++ b/regexp.h +@@ -839,8 +839,8 @@ typedef struct { + char *cutpoint; /* (*COMMIT) position (if any) */ + regmatch_info_aux *info_aux; /* extra fields that need cleanup */ + regmatch_info_aux_eval *info_aux_eval; /* extra saved state for (?{}) */ +- I32 poscache_maxiter; /* how many whilems todo before S-L cache kicks in */ +- I32 poscache_iter; /* current countdown from _maxiter to zero */ ++ STRLEN poscache_maxiter; /* how many whilems todo before S-L cache kicks in */ ++ STRLEN poscache_iter; /* current countdown from _maxiter to zero */ + STRLEN poscache_size; /* size of regmatch_info_aux.poscache */ + bool intuit; /* re_intuit_start() is the top-level caller */ + bool is_utf8_pat; /* regex is utf8 */ diff --git a/pkgs/development/interpreters/perl/CVE-2026-8376.patch b/pkgs/development/interpreters/perl/CVE-2026-8376.patch deleted file mode 100644 index c8ad72298178..000000000000 --- a/pkgs/development/interpreters/perl/CVE-2026-8376.patch +++ /dev/null @@ -1,20 +0,0 @@ -Targeted patch for CVE-2026-8376, based on 5e7f119eb2bb1181be908701f22bf7068e722f1c but avoids changes to t/re/pat_psycho.t as they do not apply cleanly. - -diff --git a/regcomp_study.c b/regcomp_study.c -index b513454a4258..1602663f4b26 100644 ---- a/regcomp_study.c -+++ b/regcomp_study.c -@@ -2784,6 +2784,13 @@ Perl_study_chunk(pTHX_ - (U8 *) SvEND(data->last_found)) - - (U8*)s; - l -= old; -+ -+ if (l > 0 && -+ (mincount >= SSize_t_MAX / (SSize_t)l -+ || old > SSize_t_MAX - mincount * (SSize_t)l)) { -+ FAIL("Regexp out of space"); -+ } -+ - /* Get the added string: */ - last_str = newSVpvn_utf8(s + old, l, UTF); - last_chrs = UTF ? utf8_length((U8*)(s + old), diff --git a/pkgs/development/interpreters/perl/default.nix b/pkgs/development/interpreters/perl/default.nix index cab0ea1a2268..6cc6f5755ac4 100644 --- a/pkgs/development/interpreters/perl/default.nix +++ b/pkgs/development/interpreters/perl/default.nix @@ -73,8 +73,8 @@ in rec { perl5 = callPackage ./interpreter.nix { self = perl5; - version = "5.42.0"; - sha256 = "sha256-4JPvGE1/mhuXl+JGUpb1VRCtttq4hCsMPtUzKWYwltw="; + version = "5.42.3"; + sha256 = "sha256-ETd0CYWDe1zfFfDPq5Miedy0NS+RL+1vwUTotPCCNic="; inherit passthruFun; }; } diff --git a/pkgs/development/interpreters/perl/interpreter.nix b/pkgs/development/interpreters/perl/interpreter.nix index cdb03912b517..ae75db2ead90 100644 --- a/pkgs/development/interpreters/perl/interpreter.nix +++ b/pkgs/development/interpreters/perl/interpreter.nix @@ -37,7 +37,8 @@ let # Do not look in /usr etc. for dependencies. ./no-sys-dirs.patch - ./CVE-2026-8376.patch + ./CVE-2026-15534-1.patch + ./CVE-2026-15534-2.patch ] # Fix build on Solaris on x86_64 @@ -83,48 +84,7 @@ let # Inject fixed CPAN releases for bundled dual-life distributions until the # next perl maintenance release includes them. - vendoredPerlDistributions = [ - { - # CVE-2026-7010 - path = "cpan/HTTP-Tiny"; - src = fetchurl { - url = "mirror://cpan/authors/id/H/HA/HAARG/HTTP-Tiny-0.094.tar.gz"; - hash = "sha256-poQemfwbVdFd6VlHzL17dnvsxRxxAhl/qPBE333cB0M="; - }; - } - { - # CVE-2026-3381, CVE-2026-4176 - path = "cpan/Compress-Raw-Zlib"; - src = fetchurl { - url = "mirror://cpan/authors/id/P/PM/PMQS/Compress-Raw-Zlib-2.222.tar.gz"; - hash = "sha256-Hf19URplVifIGBXTDTurwo+luIRV/wP4sECZ3LUShrg="; - }; - } - { - # Runtime dependency of IO-Compress 2.220. - path = "cpan/Compress-Raw-Bzip2"; - src = fetchurl { - url = "mirror://cpan/authors/id/P/PM/PMQS/Compress-Raw-Bzip2-2.218.tar.gz"; - hash = "sha256-iRU+ai69pSNJSTsHT6S3VJ/x+QU952E8GKXgXFtBX6g="; - }; - } - { - # CVE-2026-48962, CVE-2026-48961, CVE-2026-48959 - path = "cpan/IO-Compress"; - src = fetchurl { - url = "mirror://cpan/authors/id/P/PM/PMQS/IO-Compress-2.220.tar.gz"; - hash = "sha256-nZbqKR8sVO82fHOWuFfZO6GsHEsvG84T7Yo+Xz7rtic="; - }; - } - { - # CVE-2026-42496, CVE-2026-42497, CVE-2026-9538 - path = "cpan/Archive-Tar"; - src = fetchurl { - url = "mirror://cpan/authors/id/B/BI/BINGOS/Archive-Tar-3.12.tar.gz"; - hash = "sha256-ARTvObZfSfiWgoOrR3Gdfoj5jXNg/jZJvjMcf1PVgyw="; - }; - } - ]; + vendoredPerlDistributions = [ ]; replaceVendoredPerlDistributions = lib.concatMapStringsSep "\n" (d: '' rm -rf ${d.path} @@ -440,6 +400,8 @@ stdenv.mkDerivation ( # fixes build failure due to missing d_fdopendir/HAS_FDOPENDIR configure option # https://github.com/arsv/perl-cross/pull/159 ./cross-fdopendir.patch + + ./perl-cross-1.6.4--5.42.3.patch ]; depsBuildBuild = [ diff --git a/pkgs/development/interpreters/perl/perl-cross-1.6.4--5.42.3.patch b/pkgs/development/interpreters/perl/perl-cross-1.6.4--5.42.3.patch new file mode 100644 index 000000000000..853fb8a667a2 --- /dev/null +++ b/pkgs/development/interpreters/perl/perl-cross-1.6.4--5.42.3.patch @@ -0,0 +1,86 @@ +perl-cross 1.6.4 ships no patch set for perl 5.42.3. The perl5-5.42.0 set +applies unchanged, so link it under the name perl-cross looks for. The +links are per-file because `find cnf/diffs/perl5-$version`, which +perl-cross uses to collect them, does not descend into a symlinked +directory. + +diff --git a/cnf/diffs/perl5-5.42.3/constant.patch b/cnf/diffs/perl5-5.42.3/constant.patch +new file mode 120000 +index 0000000..61f792a +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/constant.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/constant.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/dynaloader.patch b/cnf/diffs/perl5-5.42.3/dynaloader.patch +new file mode 120000 +index 0000000..543415e +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/dynaloader.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/dynaloader.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/findext.patch b/cnf/diffs/perl5-5.42.3/findext.patch +new file mode 120000 +index 0000000..94ed668 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/findext.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/findext.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/installscripts.patch b/cnf/diffs/perl5-5.42.3/installscripts.patch +new file mode 120000 +index 0000000..6f715b4 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/installscripts.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/installscripts.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/liblist.patch b/cnf/diffs/perl5-5.42.3/liblist.patch +new file mode 120000 +index 0000000..5037380 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/liblist.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/liblist.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/makemaker.patch b/cnf/diffs/perl5-5.42.3/makemaker.patch +new file mode 120000 +index 0000000..cf9fc6c +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/makemaker.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/makemaker.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/posix-makefile.patch b/cnf/diffs/perl5-5.42.3/posix-makefile.patch +new file mode 120000 +index 0000000..072ba89 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/posix-makefile.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/posix-makefile.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/test-checkcase.patch b/cnf/diffs/perl5-5.42.3/test-checkcase.patch +new file mode 120000 +index 0000000..6ecc9bc +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/test-checkcase.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/test-checkcase.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/test-makemaker.patch b/cnf/diffs/perl5-5.42.3/test-makemaker.patch +new file mode 120000 +index 0000000..fc6bcda +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/test-makemaker.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/test-makemaker.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/xconfig.patch b/cnf/diffs/perl5-5.42.3/xconfig.patch +new file mode 120000 +index 0000000..87ac501 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/xconfig.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/xconfig.patch +\ No newline at end of file diff --git a/pkgs/development/libraries/glibc/2.42-master.patch b/pkgs/development/libraries/glibc/2.42-master.patch index 8abd567ee32b..7b9c5db6c0cf 100644 --- a/pkgs/development/libraries/glibc/2.42-master.patch +++ b/pkgs/development/libraries/glibc/2.42-master.patch @@ -11172,3 +11172,1075 @@ index 731d1650e9..50b0d7a256 100644 - *pwordexp = old_word; return error; } + +commit 2ea357280d82dab462851419a2338d940516a37e +Author: Florian Weimer +Date: Fri Aug 14 13:41:16 2026 +0200 + + misc: Fix out-of-bounds array write in tdelete (bug 34506) + + Allocate the maximum array sizes directly, instead of resizing + the arrays as needed. This eliminates alloca usage from the + function, and fixes the out-of-bounds accesses. The asserts + guard against the bug coming back if the balancing of the tree + turns out not to work correctly. + + Reviewed-by: Adhemerval Zanella + (cherry picked from commit e2789c46e3bfdcd67a82bea9946b315c179e83d3) + +diff --git a/misc/tsearch.c b/misc/tsearch.c +index d15260baed..350fe15bf0 100644 +--- a/misc/tsearch.c ++++ b/misc/tsearch.c +@@ -85,6 +85,7 @@ + #include + #include + #include ++#include + #include + #include + #include +@@ -406,12 +407,13 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + int cmp; + node *rootp = (node *) vrootp; + node root, unchained; +- /* Stack of nodes so we remember the parents without recursion. It's +- _very_ unlikely that there are paths longer than 40 nodes. The tree +- would need to have around 250.000 nodes. */ +- int stacksize = 40; ++ /* Stack of nodes so we remember the parents without recursion. The ++ stack size is a conservative approximation of the maximum height ++ of a red-black tree, based on size of the address space. ++ Actual numbers are closer to 57 (32 bit) and 117 (63 bit). */ ++ enum { stacksize = 2 * UINTPTR_WIDTH }; + int sp = 0; +- node **nodestack = alloca (sizeof (node *) * stacksize); ++ node *nodestack[stacksize]; + + if (rootp == NULL) + return NULL; +@@ -424,14 +426,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + root = DEREFNODEPTR(rootp); + while ((cmp = (*compar) (key, root->key)) != 0) + { +- if (sp == stacksize) +- { +- node **newstack; +- stacksize += 20; +- newstack = alloca (sizeof (node *) * stacksize); +- nodestack = memcpy (newstack, nodestack, sp * sizeof (node *)); +- } +- ++ assert (sp < stacksize); + nodestack[sp++] = rootp; + p = DEREFNODEPTR(rootp); + if (cmp < 0) +@@ -470,13 +465,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + node upn; + for (;;) + { +- if (sp == stacksize) +- { +- node **newstack; +- stacksize += 20; +- newstack = alloca (sizeof (node *) * stacksize); +- nodestack = memcpy (newstack, nodestack, sp * sizeof (node *)); +- } ++ assert (sp < stacksize); + nodestack[sp++] = parentp; + parentp = up; + upn = DEREFNODEPTR(up); +@@ -541,6 +530,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + SETNODEPTR(pp,q); + /* Make sure pp is right if the case below tries to use + it. */ ++ assert (sp < stacksize); + nodestack[sp++] = pp = LEFTPTR(q); + q = RIGHT(p); + } +@@ -625,6 +615,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + SETLEFT(p,RIGHT(q)); + SETRIGHT(q,p); + SETNODEPTR(pp,q); ++ assert (sp < stacksize); + nodestack[sp++] = pp = RIGHTPTR(q); + q = LEFT(p); + } + +commit 893379d4ed263d483505a66a437df37d02d12e9d +Author: Adhemerval Zanella +Date: Thu Aug 13 08:53:06 2026 -0300 + + posix: Remove unnecessary overflow check in wordexp (BZ 34090) + + The WRDE_APPEND path duplicates the caller's we_wordv array, which + already holds we_offs + we_wordc + 1 pointers. Follow-up to commit + e2cefe16c37. + + Checked on x86_64-linux-gnu and i686-linux-gnu. + + (cherry picked from commit 53ec26f1736aee747b353aaea0667b1ebdd5cae7) + +diff --git a/posix/wordexp.c b/posix/wordexp.c +index 50b0d7a256..09c20cf5d4 100644 +--- a/posix/wordexp.c ++++ b/posix/wordexp.c +@@ -35,7 +35,6 @@ + #include + #include <_itoa.h> + #include +-#include + + /* + * This is a recursive-descent-style word expansion routine. +@@ -2269,16 +2268,14 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) + { + /* WRDE_APPEND with an existing word list: duplicate the array so that + realloc during parsing does not invalidate the caller's pointer. The +- strings themselves are shared. */ +- size_t num_p; +- char **dup; +- if (INT_ADD_WRAPV (pwordexp->we_offs, pwordexp->we_wordc, &num_p) +- || INT_ADD_WRAPV (num_p, 1, &num_p)) +- return WRDE_NOSPACE; +- dup = __libc_reallocarray (NULL, num_p, sizeof *dup); ++ strings themselves are shared an the array already holds ++ 'we_offs + we_wordc + 1 pointers' (so the size computation cannot ++ overflow). */ ++ size_t num_p = pwordexp->we_offs + pwordexp->we_wordc + 1; ++ char **dup = malloc (num_p * sizeof (char *)); + if (dup == NULL) + return WRDE_NOSPACE; +- memcpy (dup, pwordexp->we_wordv, num_p * sizeof *dup); ++ memcpy (dup, pwordexp->we_wordv, num_p * sizeof (char *)); + saved_wordv = pwordexp->we_wordv; + pwordexp->we_wordv = dup; + } + +commit 6ad255db1dad9f2761935d3125b5bc7fa0e6128f +Author: Florian Weimer +Date: Thu Aug 27 13:34:54 2026 +0200 + + stdlib: Fix right-justification in strfmon (bug 34510, CVE-2026-19499) + + The memmove call did not take into account that __printf_buffer_pad + updated the buffer pointers. + + Fixes commit e88b9f0e5cc50cab57a299dc7efe1a4eb385161d + ("stdio-common: Convert vfprintf and related functions to buffers"), + which went into glibc 2.37. + + Reviewed-by: Adhemerval Zanella + (cherry picked from commit b090cf226ff65b913e41536f1f573f500855615c) + +diff --git a/stdlib/Makefile b/stdlib/Makefile +index 25f777e1a5..0f3183268a 100644 +--- a/stdlib/Makefile ++++ b/stdlib/Makefile +@@ -343,6 +343,7 @@ tests := \ + tst-stdc_leading_zeros \ + tst-stdc_trailing_ones \ + tst-stdc_trailing_zeros \ ++ tst-strfmon-bug34510 \ + tst-strfmon_l \ + tst-strfrom \ + tst-strfrom-locale \ +diff --git a/stdlib/strfmon_l.c b/stdlib/strfmon_l.c +index 5e22aac750..bd849ff470 100644 +--- a/stdlib/strfmon_l.c ++++ b/stdlib/strfmon_l.c +@@ -549,7 +549,8 @@ __vstrfmon_l_buffer (struct __printf_buffer *buf, locale_t loc, + /* Now test whether the output width is filled. */ + if (buf->write_ptr - startp < width) + { +- size_t pad_width = width - (buf->write_ptr - startp); ++ size_t written_width = buf->write_ptr - startp; ++ size_t pad_width = width - written_width; + __printf_buffer_pad (buf, ' ', pad_width); + if (__printf_buffer_has_failed (buf)) + /* Implies length check. */ +@@ -558,7 +559,7 @@ __vstrfmon_l_buffer (struct __printf_buffer *buf, locale_t loc, + Otherwise move the field contents in place. */ + if (!left) + { +- memmove (startp + pad_width, startp, buf->write_ptr - startp); ++ memmove (startp + pad_width, startp, written_width); + memset (startp, ' ', pad_width); + } + } +diff --git a/stdlib/tst-strfmon-bug34510.c b/stdlib/tst-strfmon-bug34510.c +new file mode 100644 +index 0000000000..b187bde1f4 +--- /dev/null ++++ b/stdlib/tst-strfmon-bug34510.c +@@ -0,0 +1,33 @@ ++/* Test handling of right-padding in strfmon (bug 34510, CVE-2026-19499). ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++#include ++#include ++#include ++#include ++ ++static int ++do_test (void) ++{ ++ struct support_next_to_fault ntf = support_next_to_fault_allocate (100); ++ TEST_COMPARE (strfmon (ntf.buffer, ntf.length, "%100n", 1.23), -1); ++ TEST_COMPARE (errno, E2BIG); ++ return 0; ++} ++ ++#include + +commit 67db60ee152d221782d2ae915268871d3e06a007 +Author: Florian Weimer +Date: Fri Aug 28 10:26:07 2026 +0200 + + iconvdata: SHIFT_JISX0213 decoding lacks pending character reset (CVE-2026-77117) + + This fixes bug 34556. + + Reviewed-by: Carlos O'Donell + (cherry picked from commit 68d94bbe50b7577d48998107d632ef3a0df050e3) + +diff --git a/iconvdata/shift_jisx0213.c b/iconvdata/shift_jisx0213.c +index 364298dcff..834fa81322 100644 +--- a/iconvdata/shift_jisx0213.c ++++ b/iconvdata/shift_jisx0213.c +@@ -226,6 +226,9 @@ + STANDARD_FROM_LOOP_ERR_HANDLER (1); \ + } \ + } \ ++ else \ ++ /* There was a pending character. Clear it. */ \ ++ *statep = 0; \ + \ + put32 (outptr, ch); \ + outptr += 4; \ + +commit 87c2795cf6a7584e351036ab43e74b03ccc54a83 +Author: Florian Weimer +Date: Fri Aug 28 10:26:07 2026 +0200 + + iconvdata: EUC_JISX0213 decoding lacks pending character reset (CVE-2026-80489) + + This fixes bug 34568. + + Reviewed-by: Carlos O'Donell + (cherry picked from commit 4dafa087ff5fe7df45bd37dc727e988da6b8c935) + +diff --git a/iconvdata/euc-jisx0213.c b/iconvdata/euc-jisx0213.c +index 9c3f28da2d..f0305c113a 100644 +--- a/iconvdata/euc-jisx0213.c ++++ b/iconvdata/euc-jisx0213.c +@@ -224,6 +224,9 @@ + STANDARD_FROM_LOOP_ERR_HANDLER (1); \ + } \ + } \ ++ else \ ++ /* There was a pending character. Clear it. */ \ ++ *statep = 0; \ + \ + put32 (outptr, ch); \ + outptr += 4; \ + +commit 0afd4d5feb591512629d5f46ceab310b54a06034 +Author: Florian Weimer +Date: Fri Aug 28 10:26:07 2026 +0200 + + iconvdata: Test case for bug 34556, bug 34568 + + Assisted-by: LLM + Reviewed-by: Carlos O'Donell + (cherry picked from commit 35efcffa97553df071bc37ab31fd7dc2c634e7da) + +diff --git a/iconvdata/Makefile b/iconvdata/Makefile +index cc689f63e9..36f48749d2 100644 +--- a/iconvdata/Makefile ++++ b/iconvdata/Makefile +@@ -76,7 +76,8 @@ tests = bug-iconv1 bug-iconv2 tst-loading tst-e2big tst-iconv4 bug-iconv4 \ + tst-iconv6 bug-iconv5 bug-iconv6 tst-iconv7 bug-iconv8 bug-iconv9 \ + bug-iconv10 bug-iconv11 bug-iconv12 tst-iconv-big5-hkscs-to-2ucs4 \ + bug-iconv13 bug-iconv14 bug-iconv15 \ +- tst-iconv-iso-2022-cn-ext tst-bug33980 ++ tst-iconv-iso-2022-cn-ext tst-bug33980 \ ++ tst-jisx0213-progress + ifeq ($(have-thread-library),yes) + tests += bug-iconv3 + endif +@@ -335,6 +336,8 @@ $(objpfx)tst-iconv-iso-2022-cn-ext.out: $(addprefix $(objpfx), $(gconv-modules)) + $(addprefix $(objpfx),$(modules.so)) + $(objpfx)tst-bug33980.out: $(addprefix $(objpfx), $(gconv-modules)) \ + $(addprefix $(objpfx),$(modules.so)) ++$(objpfx)tst-jisx0213-progress.out: \ ++ $(addprefix $(objpfx), $(gconv-modules)) $(addprefix $(objpfx),$(modules.so)) + + $(objpfx)iconv-test.out: run-iconv-test.sh \ + $(addprefix $(objpfx), $(gconv-modules)) \ +diff --git a/iconvdata/tst-jisx0213-progress.c b/iconvdata/tst-jisx0213-progress.c +new file mode 100644 +index 0000000000..7b2073be1f +--- /dev/null ++++ b/iconvdata/tst-jisx0213-progress.c +@@ -0,0 +1,124 @@ ++/* Test JISX0213 combining character conversion progress (bug 34556, bug 34568). ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++/* Certain JISX0213 byte sequences map to a combining sequence, for ++ example U+304B (HIRAGANA LETTER KA) followed by U+309A (COMBINING ++ SEMI-VOICED SOUND MARK). When converting to internal encoding ++ (actually UTF-32) with a small output buffer, the first code point ++ is emitted and the second is queued in the converter state. This ++ test verifies that the queued code point is consumed exactly once ++ on retry, so that the conversion makes progress and terminates. */ ++ ++#include ++#include ++#include ++#include ++ ++#include ++#include ++ ++static void ++test_one (const char *charset, const char *input, size_t outbufsize) ++{ ++ printf ("info: %s: testing output buffer size %zu\n", charset, outbufsize); ++ ++ /* Expected UTF-32 output. */ ++ static const wchar_t expected[] = { 0x304b, 0x309a, 'A' }; ++ ++ /* Use WCHAR_T encoding to avoid the BOM. */ ++ iconv_t cd = iconv_open ("WCHAR_T", charset); ++ TEST_VERIFY_EXIT (cd != (iconv_t) -1); ++ ++ char result[64]; ++ size_t result_len = 0; ++ ++ char *inptr = (char *) input; ++ size_t inleft = strlen (input); ++ ++ char outbuf[64]; ++ ++ int iterations = 0; ++ while (inleft > 0) ++ { ++ char *outptr = outbuf; ++ size_t outleft = outbufsize; ++ size_t inleft_before = inleft; ++ ++ size_t ret = iconv (cd, &inptr, &inleft, &outptr, &outleft); ++ size_t produced = outptr - outbuf; ++ ++ TEST_VERIFY_EXIT (result_len + produced <= sizeof (result)); ++ memcpy (result + result_len, outbuf, produced); ++ result_len += produced; ++ ++ if (ret == (size_t) -1 && errno == E2BIG) ++ { ++ if (produced == 0 && inleft == inleft_before) ++ { ++ /* Output buffer too small for a single code point. */ ++ TEST_VERIFY_EXIT (outbufsize < 4); ++ break; ++ } ++ /* Bound iterations to detect non-progress bugs. */ ++ if (++iterations < 10) ++ continue; ++ else ++ { ++ FAIL ("%s: no progress", charset); ++ goto out; ++ } ++ } ++ if (ret == (size_t) -1) ++ FAIL_EXIT1 ("outbufsize %zu: iconv: %m", outbufsize); ++ break; ++ } ++ ++ /* Flush pending converter state. */ ++ { ++ char *outptr = outbuf; ++ size_t outleft = outbufsize; ++ size_t ret = iconv (cd, NULL, NULL, &outptr, &outleft); ++ TEST_VERIFY (ret == 0); ++ size_t produced = outptr - outbuf; ++ memcpy (result + result_len, outbuf, produced); ++ result_len += produced; ++ } ++ ++ if (outbufsize >= 4) ++ { ++ TEST_COMPARE (inleft, 0); ++ TEST_COMPARE_BLOB (result, result_len, ++ expected, sizeof (expected)); ++ } ++ ++ out: ++ TEST_VERIFY_EXIT (iconv_close (cd) == 0); ++} ++ ++static int ++do_test (void) ++{ ++ for (size_t outbufsize = 1; outbufsize <= 16; outbufsize++) ++ { ++ test_one ("EUC-JISX0213", "\244\367A", outbufsize); ++ test_one ("SHIFT_JISX0213", "\202\365A", outbufsize); ++ } ++ return 0; ++} ++ ++#include + +commit 2ba6f4c063e9b2d451e25e758d704f33b5d958a6 +Author: Dongkyun Son +Date: Fri Sep 4 21:28:41 2026 +0900 + + libio: Fix CVE-2026-18374 heap buffer overflow in ccs= handling + + When fopen() is called with a ,ccs= parameter whose value becomes empty + after strip(), the code must reject it with EINVAL instead of attempting + to use it. The original upstr() fallback could read past the ',' delimiter + and cause a heap buffer overflow. + + The fix checks if the charset specification is empty after strip() and + returns EINVAL immediately, preventing the overflow and following the + approach described in BZ #34574. + + CVE-2026-18374 - CVSS 4.9 (AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L) + + Reported-by: AISLE in partnership with Red Hat + Signed-off-by: Dongkyun Son + Reviewed-by: Florian Weimer + (cherry picked from commit 9765a538ebf8661a6e5578e01e35a3dd30db7eb4) + +diff --git a/libio/fileops.c b/libio/fileops.c +index 0cce828859..3e2ac36d48 100644 +--- a/libio/fileops.c ++++ b/libio/fileops.c +@@ -339,12 +339,14 @@ _IO_new_file_fopen (FILE *fp, const char *filename, const char *mode, + *((char *) __mempcpy (ccs, cs + 5, endp - (cs + 5))) = '\0'; + strip (ccs, ccs); + +- if (__wcsmbs_named_conv (&fcts, ccs[2] == '\0' +- ? upstr (ccs, cs + 5) : ccs) != 0) ++ /* After stripping, ccs[2] == '\0' means the charset name is empty. ++ This is not a valid charset and would cause problems downstream. ++ Reject it with EINVAL (BZ #34574, CVE-2026-18374). */ ++ if (ccs[2] == '\0' || __wcsmbs_named_conv (&fcts, ccs) != 0) + { +- /* Something went wrong, we cannot load the conversion modules. +- This means we cannot proceed since the user explicitly asked +- for these. */ ++ /* Either the charset name is empty after strip(), or conversion ++ modules cannot be loaded. This means we cannot proceed since ++ the user explicitly asked for character conversion. */ + (void) _IO_file_close_it (fp); + free (ccs); + __set_errno (EINVAL); + +commit 552849c43c8f14b35af3c0496502748b9c549a2a +Author: Shamil Abdulaev +Date: Thu Sep 3 20:19:42 2026 +0300 + + libio: Add test for fopen with an empty ", ccs=" value [BZ #34574] + + This goes on top of the fix for CVE-2026-18374. The test runs the + reproducer from the bug report, plus "w,ccs=" and "w,ccs=,", and + expects NULL with errno set to EINVAL. + + Signed-off-by: Shamil Abdulaev + Reviewed-by: Florian Weimer + (cherry picked from commit cca93e5d88d3d4ed073c03100467696f652269e7) + +diff --git a/libio/Makefile b/libio/Makefile +index fa2b8ae791..c6728d8552 100644 +--- a/libio/Makefile ++++ b/libio/Makefile +@@ -107,6 +107,7 @@ tests = \ + tst-fgetc-after-eof \ + tst-fgetwc \ + tst-fgetws \ ++ tst-fopen-ccs-empty \ + tst-fopenloc2 \ + tst-fputws \ + tst-freopen \ +diff --git a/libio/tst-fopen-ccs-empty.c b/libio/tst-fopen-ccs-empty.c +new file mode 100644 +index 0000000000..64723965e1 +--- /dev/null ++++ b/libio/tst-fopen-ccs-empty.c +@@ -0,0 +1,62 @@ ++/* Test fopen with an empty ",ccs=" value in the mode string (bug 34574). ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++ ++static void ++check_fopen_fails (const char *path, const char *mode) ++{ ++ errno = 0; ++ FILE *fp = fopen (path, mode); ++ TEST_VERIFY (fp == NULL); ++ TEST_COMPARE (errno, EINVAL); ++ if (fp != NULL) ++ fclose (fp); ++} ++ ++static int ++do_test (void) ++{ ++ char *path; ++ xclose (create_temp_file ("tst-fopen-ccs-empty", &path)); ++ ++ /* The value is blank and the mode string continues well past it. */ ++ enum { size = 1024 * 1024 }; ++ char *mode = xmalloc (size); ++ memset (mode, 'X', size); ++ mode[size - 1] = '\0'; ++ static const char prefix[] = "w,ccs= ,"; ++ memcpy (mode, prefix, sizeof (prefix) - 1); ++ check_fopen_fails (path, mode); ++ free (mode); ++ ++ check_fopen_fails (path, "w,ccs="); ++ check_fopen_fails (path, "w,ccs=,"); ++ ++ free (path); ++ return 0; ++} ++ ++#include + +commit bc76f2aa9b26b8d15bf8bb5cb13d5564cba517e8 +Author: Andreas Schwab +Date: Tue May 19 11:39:15 2026 +0200 + + nss_files: fix swapped arguments in service parser + + The port number in the service file is a decimal number followed by a + single slash. + + (cherry picked from commit 66efdda2f8bce2680f5984a6bd5e488a9b528ead) + +diff --git a/nss/nss_files/files-service.c b/nss/nss_files/files-service.c +index a6503f7571..7b152b61a4 100644 +--- a/nss/nss_files/files-service.c ++++ b/nss/nss_files/files-service.c +@@ -32,7 +32,7 @@ struct servent_data {}; + LINE_PARSER + ("#", + STRING_FIELD (result->s_name, isspace, 1); +- INT_FIELD (result->s_port, ISSLASH, 10, 0, htons); ++ INT_FIELD (result->s_port, ISSLASH, 0, 10, htons); + STRING_FIELD (result->s_proto, isspace, 1); + ) + + +commit a27376f0dc77ba6eb8848d1ff2808510507b31d7 +Author: Andreas Schwab +Date: Tue May 19 11:45:41 2026 +0200 + + nss_files: use booleans in parser macro calls + + The swallow argument in the INT_FIELD and STRING_FIELD macros is used as a + boolean, change all callers to use false and true instead of 0 and 1. + + (cherry picked from commit aa56ccb98b701680ad48431fea2a1966bac7fa31) + +diff --git a/nss/nss_files/files-ethers.c b/nss/nss_files/files-ethers.c +index 3c8715133d..c9604f0f87 100644 +--- a/nss/nss_files/files-ethers.c ++++ b/nss/nss_files/files-ethers.c +@@ -36,16 +36,16 @@ LINE_PARSER + unsigned int number; + + if (cnt < 5) +- INT_FIELD (number, ISCOLON , 0, 16, (unsigned int)) ++ INT_FIELD (number, ISCOLON , false, 16, (unsigned int)) + else +- INT_FIELD (number, isspace, 1, 16, (unsigned int)) ++ INT_FIELD (number, isspace, true, 16, (unsigned int)) + + if (number > 0xff) + return 0; + result->e_addr.ether_addr_octet[cnt] = number; + } + }; +- STRING_FIELD (result->e_name, isspace, 1); ++ STRING_FIELD (result->e_name, isspace, true); + ) + + +diff --git a/nss/nss_files/files-hosts.c b/nss/nss_files/files-hosts.c +index d8987c723a..ce1f20302c 100644 +--- a/nss/nss_files/files-hosts.c ++++ b/nss/nss_files/files-hosts.c +@@ -53,7 +53,7 @@ LINE_PARSER + { + char *addr; + +- STRING_FIELD (addr, isspace, 1); ++ STRING_FIELD (addr, isspace, true); + + /* Parse address. */ + if (__inet_pton (af == AF_UNSPEC ? AF_INET : af, addr, entdata->host_addr) +@@ -96,7 +96,7 @@ LINE_PARSER + entdata->h_addr_ptrs[1] = NULL; + result->h_addr_list = entdata->h_addr_ptrs; + +- STRING_FIELD (result->h_name, isspace, 1); ++ STRING_FIELD (result->h_name, isspace, true); + }) + + #define EXTRA_ARGS_VALUE , AF_INET, 0 +diff --git a/nss/nss_files/files-network.c b/nss/nss_files/files-network.c +index f08daaf55f..4fafdb2110 100644 +--- a/nss/nss_files/files-network.c ++++ b/nss/nss_files/files-network.c +@@ -38,9 +38,9 @@ LINE_PARSER + char *cp; + int n = 1; + +- STRING_FIELD (result->n_name, isspace, 1); ++ STRING_FIELD (result->n_name, isspace, true); + +- STRING_FIELD (addr, isspace, 1); ++ STRING_FIELD (addr, isspace, true); + /* 'inet_network' does not add zeroes at the end if the network number + does not contain four byte values. We shift result ourselves if + necessary. */ +diff --git a/nss/nss_files/files-parse.c b/nss/nss_files/files-parse.c +index 3ebd61f6e2..ed268f849d 100644 +--- a/nss/nss_files/files-parse.c ++++ b/nss/nss_files/files-parse.c +@@ -20,6 +20,7 @@ + #include + #include + #include ++#include + #include + #include + +diff --git a/nss/nss_files/files-proto.c b/nss/nss_files/files-proto.c +index e10255ebaf..8bbbc6e0cb 100644 +--- a/nss/nss_files/files-proto.c ++++ b/nss/nss_files/files-proto.c +@@ -29,8 +29,8 @@ struct protoent_data {}; + #include "files-parse.c" + LINE_PARSER + ("#", +- STRING_FIELD (result->p_name, isspace, 1); +- INT_FIELD (result->p_proto, isspace, 1, 10,); ++ STRING_FIELD (result->p_name, isspace, true); ++ INT_FIELD (result->p_proto, isspace, true, 10,); + ) + + #include GENERIC +diff --git a/nss/nss_files/files-rpc.c b/nss/nss_files/files-rpc.c +index 79ae72c2dd..1aaaad5d18 100644 +--- a/nss/nss_files/files-rpc.c ++++ b/nss/nss_files/files-rpc.c +@@ -29,8 +29,8 @@ struct rpcent_data {}; + #include "files-parse.c" + LINE_PARSER + ("#", +- STRING_FIELD (result->r_name, isspace, 1); +- INT_FIELD (result->r_number, isspace, 1, 10,); ++ STRING_FIELD (result->r_name, isspace, true); ++ INT_FIELD (result->r_number, isspace, true, 10,); + ) + + #include GENERIC +diff --git a/nss/nss_files/files-service.c b/nss/nss_files/files-service.c +index 7b152b61a4..81b4ef726b 100644 +--- a/nss/nss_files/files-service.c ++++ b/nss/nss_files/files-service.c +@@ -31,9 +31,9 @@ struct servent_data {}; + #define ISSLASH(c) ((c) == '/') + LINE_PARSER + ("#", +- STRING_FIELD (result->s_name, isspace, 1); +- INT_FIELD (result->s_port, ISSLASH, 0, 10, htons); +- STRING_FIELD (result->s_proto, isspace, 1); ++ STRING_FIELD (result->s_name, isspace, true); ++ INT_FIELD (result->s_port, ISSLASH, false, 10, htons); ++ STRING_FIELD (result->s_proto, isspace, true); + ) + + #include GENERIC + +commit 5e45e86fed68c24cd1ba94056e77275e2eab5fae +Author: Adhemerval Zanella +Date: Thu May 28 17:30:07 2026 -0300 + + hesiod: fix swapped arguments in service parser + + The port number in the service file is a decimal number followed by a + single slash. + + Reviewed-by: H.J. Lu + (cherry picked from commit 41e9457c53610c6c79a7e036f61de032686e9ef0) + +diff --git a/hesiod/nss_hesiod/hesiod-service.c b/hesiod/nss_hesiod/hesiod-service.c +index ae3b51fa28..525af1e6ce 100644 +--- a/hesiod/nss_hesiod/hesiod-service.c ++++ b/hesiod/nss_hesiod/hesiod-service.c +@@ -41,7 +41,7 @@ LINE_PARSER + ("#", + STRING_FIELD (result->s_name, ISSC_OR_SPACE, 1); + STRING_FIELD (result->s_proto, ISSC_OR_SPACE, 1); +- INT_FIELD (result->s_port, ISSC_OR_SPACE, 10, 0, htons); ++ INT_FIELD (result->s_port, ISSC_OR_SPACE, 0, 10, htons); + ) + + enum nss_status + +commit d407ace6e19304d740a1d0ded7920f49ab5c9820 +Author: Adhemerval Zanella +Date: Thu May 28 17:30:08 2026 -0300 + + hesiod: use booleans in parser macro calls + + The swallow argument in the INT_FIELD and STRING_FIELD macros is used as a + boolean, change all callers to use false and true instead of 0 and 1. + + Reviewed-by: H.J. Lu + (cherry picked from commit 7052455f0e85673abebad5d5814e73e22287c081) + +diff --git a/hesiod/nss_hesiod/hesiod-proto.c b/hesiod/nss_hesiod/hesiod-proto.c +index 751b9c0219..9518cf3d0f 100644 +--- a/hesiod/nss_hesiod/hesiod-proto.c ++++ b/hesiod/nss_hesiod/hesiod-proto.c +@@ -39,8 +39,8 @@ struct protoent_data {}; + #include + LINE_PARSER + ("#", +- STRING_FIELD (result->p_name, isspace, 1); +- INT_FIELD (result->p_proto, isspace, 1, 10,); ++ STRING_FIELD (result->p_name, isspace, true); ++ INT_FIELD (result->p_proto, isspace, true, 10,); + ) + + enum nss_status +diff --git a/hesiod/nss_hesiod/hesiod-service.c b/hesiod/nss_hesiod/hesiod-service.c +index 525af1e6ce..748e1db505 100644 +--- a/hesiod/nss_hesiod/hesiod-service.c ++++ b/hesiod/nss_hesiod/hesiod-service.c +@@ -39,9 +39,9 @@ struct servent_data {}; + #define ISSC_OR_SPACE(c) ((c) == ';' || isspace (c)) + LINE_PARSER + ("#", +- STRING_FIELD (result->s_name, ISSC_OR_SPACE, 1); +- STRING_FIELD (result->s_proto, ISSC_OR_SPACE, 1); +- INT_FIELD (result->s_port, ISSC_OR_SPACE, 0, 10, htons); ++ STRING_FIELD (result->s_name, ISSC_OR_SPACE, true); ++ STRING_FIELD (result->s_proto, ISSC_OR_SPACE, true); ++ INT_FIELD (result->s_port, ISSC_OR_SPACE, false, 10, htons); + ) + + enum nss_status + +commit 6c453bb60669c9612bfe18f7f211d2dc28cad943 +Author: Hemanth Kumar M D +Date: Mon Sep 7 01:59:06 2026 -0700 + + nptl: Skip pretty-printer tests without python3 [BZ #34507] + + The tests-printers-out rule in Rules wraps $(PYTHON) through + $(test-wrapper-env). Unlike ordinary tests, which wrap a freshly built + target binary, this wraps python3, a build-host tool. When cross-testing + with test-wrapper set (e.g. via scripts/cross-test-ssh.sh) the whole + command is forwarded to the target; if the target lacks python3 the shell + returns 127 and evaluate-test.sh reports the six nptl pretty-printer + tests as FAIL instead of UNSUPPORTED. + + scripts/test_printers_common.py already exits UNSUPPORTED (77) when its + dependencies are missing, but that is unreachable when python3 itself is + absent. + + Guard the invocation with a "command -v" check so the recipe exits 77 + (UNSUPPORTED) when python3 is not found. Native builds are unaffected, + as configure requires python3. + + Signed-off-by: Hemanth Kumar M D + Suggested-by: Adhemerval Zanella Netto + Reviewed-by: Adhemerval Zanella + (cherry picked from commit c958d789db3bd8dbfb93868d8a975d13a3d66396) + +diff --git a/NEWS b/NEWS +index 7e7e1930dd..df9b76f44e 100644 +--- a/NEWS ++++ b/NEWS +@@ -18,6 +18,8 @@ The following bugs were resolved with this release: + [33361] nss: Group merge does not react to ERANGE during merge + [33814] glob: wordexp with WRDE_REUSE and WRDE_APPEND may return + uninitialized memory ++ [34507] nptl: Pretty-printer tests FAIL instead of UNSUPPORTED when ++ cross-testing without python3 on target + + Version 2.42 + +diff --git a/Rules b/Rules +index 44c041c491..0087a772f6 100644 +--- a/Rules ++++ b/Rules +@@ -423,8 +423,9 @@ py-env := PYTHONPATH=$(py-const-dir):$(..)scripts:$${PYTHONPATH} + # The pretty printer files and test_common_printers.py must be present for all. + $(tests-printers-out): $(objpfx)%.out: $(objpfx)% %.py %.c $(pretty-printers) \ + $(..)scripts/test_printers_common.py +- $(test-wrapper-env) $(py-env) \ +- $(PYTHON) $*.py $*.c $(objpfx)$* $(pretty-printers) > $@; \ ++ $(test-wrapper-env) $(py-env) sh -c \ ++ 'command -v $(firstword $(PYTHON)) > /dev/null 2>&1 || exit 77; \ ++ exec $(PYTHON) $*.py $*.c $(objpfx)$* $(pretty-printers)' > $@; \ + $(evaluate-test) + endif + + +commit 1bab8b37dc20bcae733d4310345aae08cab13dfa +Author: Paul Eggert +Date: Wed Sep 9 15:47:44 2026 -0700 + + zic: keep needed last transition to new type (bug 34618) + + Do not mishandle tzdata 2026b+'s temporary hacks that work around + bugs in the Unicode CLDR project when localizing recent + timekeeping changes in western Canada. Unfortunately, the hacks + run afoul of a zic bug in glibc 2.40 through 2.43, + corresponding to tzcode 2023d through 2024a. + + The bug causes zic in its default -b slim mode to generate TZif + files that do not conform to Internet RFC 9636 section 3.3, and + these buggy files in turn cause some TZif readers, including + tzcode itself, to ignore the 2026-11-01 timekeeping transitions in + America/Vancouver and elsewhere in western Canada. + + * timezone/zic.c (outzone): Omit an incorrect use of ‘useuntil’. + This fixes a bug introduced in “Fix zic bug with Palestine after + 2075” (tz commit 35c116b7536a36c43eb7cd36bff71ad0c5ecf071 dated + 2023-10-15), which caused zic to mess up if the last transition is + to a new time type. + + This artificial input illustrates the bug: + Rule Canada 2007 max - Mar Sun>=8 2:00 1:00 D + Rule Canada 2007 max - Nov Sun>=1 2:00 0 S + Zone America/Vancouver -8:00 - PST 2026 Mar 9 + -8:00 Canada P%sT 2026 Nov 1 02:00 + -7:00 - MST + Without the fix, zic generates a nonconforming TZif file that omits + the last transition even though the trailing TZ string is "MST7". + + (cherry picked from 2026-03-07 tz commit + ) + +diff --git a/timezone/zic.c b/timezone/zic.c +index d5d30163b0..17c6f906b2 100644 +--- a/timezone/zic.c ++++ b/timezone/zic.c +@@ -3234,7 +3234,7 @@ outzone(const struct zone *zpfirst, ptrdiff_t zonecount) + startttisut); + if (usestart) { + addtt(starttime, type); +- if (useuntil && nonTZlimtime < starttime) { ++ if (nonTZlimtime < starttime) { + nonTZlimtime = starttime; + nonTZlimtype = type; + } + +commit c0c8a45dee30c8089822d859575a3ad4324b15ff +Author: Adhemerval Zanella +Date: Mon Sep 14 17:08:03 2026 -0300 + + resolv: Fix assertion failure on search list truncation [BZ 31026, CVE-2026-8674] + + update_from_conf copies the search list into the 256-byte + resp->defdname and truncates it when an entry does not fit, then + asserts that resolv_conf_matches accepts the result. + + The truncation check there compared the accumulated size against + sizeof (resp->dnsrch) (the pointer array) instead of resp->defdname, + and the empty-list case did not account for a first entry that does + not fit at all. A long search domain in resolv.conf or LOCALDOMAIN + thus aborts any process using the resolver. + + Check whether the entry fits in the remaining defdname space, matching + alloc_buffer_copy_string, and also accept an empty resp->dnsrch when + the first entry is too long. Add tests covering both cases through + the search and domain directives. + + Checked on x86_64-linux-gnu and i686-linux-gnu. + Reviewed-by: Florian Weimer + + (cherry picked from commit 506ea57086bfb9ce3daff1c14246a1cb532aba0a) + +diff --git a/resolv/resolv_conf.c b/resolv/resolv_conf.c +index dcf92ee90e..0418267044 100644 +--- a/resolv/resolv_conf.c ++++ b/resolv/resolv_conf.c +@@ -281,8 +281,12 @@ resolv_conf_matches (const struct __res_state *resp, + { + if (resp->dnsrch[0] == NULL) + { +- /* Empty search list. No default domain name. */ +- return conf->search_list_size == 0 && resp->defdname[0] == '\0'; ++ /* Empty search list, or the first entry does not fit in ++ resp->defdname. No default domain name. */ ++ return resp->defdname[0] == '\0' ++ && (conf->search_list_size == 0 ++ || (strlen (conf->search_list[0]) + 1 ++ > sizeof (resp->defdname))); + } + + if (resp->dnsrch[0] != resp->defdname) +@@ -309,11 +313,12 @@ resolv_conf_matches (const struct __res_state *resp, + } + else + { +- /* resp->dnsrch is truncated if the number of elements +- exceeds MAXDNSRCH, or if the combined storage space for +- the search list exceeds what can be stored in +- resp->defdname. */ +- if (i == MAXDNSRCH || search_list_size > sizeof (resp->dnsrch)) ++ /* resp->dnsrch is truncated if the number of elements exceeds ++ MAXDNSRCH, or if conf->search_list[i] does not fit in the ++ remaining space of resp->defdname. */ ++ if (i == MAXDNSRCH ++ || (search_list_size + strlen (conf->search_list[i]) + 1 ++ > sizeof (resp->defdname))) + break; + /* Otherwise, a mismatch indicates a match failure. */ + return false; +diff --git a/resolv/tst-resolv-res_init-skeleton.c b/resolv/tst-resolv-res_init-skeleton.c +index 3ccbe71db9..4e9c57f3cb 100644 +--- a/resolv/tst-resolv-res_init-skeleton.c ++++ b/resolv/tst-resolv-res_init-skeleton.c +@@ -724,6 +724,41 @@ struct test_case test_cases[] = + "nameserver 192.0.2.1\n" + "; nameserver[0]: [192.0.2.1]:53\n" + }, ++/* Search list entries which do not fit in the legacy 256-byte ++ resp->defdname buffer (bug 31026). LONG244 is 244 characters long, ++ so it does not fit after "example.com\0" (12 bytes). LONG256 is 256 ++ characters long, so it does not fit even as the first entry. */ ++#define LBL63 "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" ++#define LONG244 LBL63 "." LBL63 "." LBL63 "." \ ++ "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb" ++#define LONG256 LBL63 "." LBL63 "." LBL63 "." LBL63 "a" ++ {.name = "search list truncated at long entry after short entry", ++ .conf = "nameserver 192.0.2.1\n" ++ "search example.com " LONG244 "\n", ++ .expected = "search example.com\n" ++ "; search[0]: example.com\n" ++ "; search[1]: " LONG244 "\n" ++ "nameserver 192.0.2.1\n" ++ "; nameserver[0]: [192.0.2.1]:53\n" ++ }, ++ {.name = "search list truncated at long first entry", ++ .conf = "nameserver 192.0.2.1\n" ++ "search " LONG256 " example.com\n", ++ .expected = "; search[0]: " LONG256 "\n" ++ "; search[1]: example.com\n" ++ "nameserver 192.0.2.1\n" ++ "; nameserver[0]: [192.0.2.1]:53\n" ++ }, ++ {.name = "long first entry from the domain directive", ++ .conf = "nameserver 192.0.2.1\n" ++ "domain " LONG256 "\n", ++ .expected = "; search[0]: " LONG256 "\n" ++ "nameserver 192.0.2.1\n" ++ "; nameserver[0]: [192.0.2.1]:53\n" ++ }, ++#undef LONG256 ++#undef LONG244 ++#undef LBL63 + {.name = "trust-ad flag", + .conf = "options trust-ad\n" + "nameserver 192.0.2.1\n", + +commit c7169c068453a95f104f47a4eb79a902721712dd +Author: Mark Wielaard +Date: Fri Sep 18 00:24:34 2026 +0200 + + stdlib: Don't call clearenv from __libc_setenv_freemem + + Since commit 7a61e7f557a9 ("stdlib: Make getenv thread-safe in more + cases") clearenv doesn't call any deallocation functions anymore. + __libc_setenv_freemem (called from __libc_freeres) now clears all + backing arrays. So there is no reason anymore to call clearenv from + __libc_setenv_freemem. + + Tested against valgrind memcheck with --run-libc-freeres=yes which is + the default. + + Reviewed-by: Florian Weimer + (cherry picked from commit b837aae83df8fe80c8977b5ed5c538aebd2b152a) + +diff --git a/stdlib/setenv.c b/stdlib/setenv.c +index 0ef5dde373..e25fbff351 100644 +--- a/stdlib/setenv.c ++++ b/stdlib/setenv.c +@@ -394,9 +394,6 @@ clearenv (void) + void + __libc_setenv_freemem (void) + { +- /* Remove all traces. */ +- clearenv (); +- + /* Clear all backing arrays. */ + while (__environ_array_list != NULL) + { diff --git a/pkgs/development/libraries/glibc/common.nix b/pkgs/development/libraries/glibc/common.nix index 6b98f5a3a889..8b2d7f83f950 100644 --- a/pkgs/development/libraries/glibc/common.nix +++ b/pkgs/development/libraries/glibc/common.nix @@ -51,7 +51,7 @@ let version = "2.42"; - patchSuffix = "-84"; + patchSuffix = "-100"; sha256 = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; in @@ -69,7 +69,7 @@ stdenv.mkDerivation ( /* No tarballs for stable upstream branch, only https://sourceware.org/git/glibc.git and using git would complicate bootstrapping. $ git fetch --all -p && git checkout origin/release/2.42/master && git describe - glibc-2.42-67-g4ebd33dd77 + glibc-2.42-100-gc7169c0684 $ git show --minimal --reverse glibc-2.42.. ':!ADVISORIES' > 2.42-master.patch To compare the archive contents zdiff can be used. diff --git a/pkgs/development/libraries/libmicrohttpd/1.0.nix b/pkgs/development/libraries/libmicrohttpd/1.0.nix index 8070e78356c7..cf9879dccee9 100644 --- a/pkgs/development/libraries/libmicrohttpd/1.0.nix +++ b/pkgs/development/libraries/libmicrohttpd/1.0.nix @@ -1,10 +1,10 @@ { callPackage, fetchurl }: callPackage ./generic.nix rec { - version = "1.0.2"; + version = "1.0.10"; src = fetchurl { url = "mirror://gnu/libmicrohttpd/libmicrohttpd-${version}.tar.gz"; - hash = "sha256-3zJPzQg0F12rB0gxM5Atl3SmBb+imAJfaYgyiP0gqMc="; + hash = "sha256-BL/o73XbfWKaM952dZl2XOytxWJ0o5gi1dCBAw1XdoU="; }; } diff --git a/pkgs/development/perl-modules/Cpanel-JSON-XS-CVE-2025-40929.patch b/pkgs/development/perl-modules/Cpanel-JSON-XS-CVE-2025-40929.patch deleted file mode 100644 index 0f76f7313fde..000000000000 --- a/pkgs/development/perl-modules/Cpanel-JSON-XS-CVE-2025-40929.patch +++ /dev/null @@ -1,47 +0,0 @@ -From 5592bfb58eb8d1c8a644e67c9bba795d1384a995 Mon Sep 17 00:00:00 2001 -From: Marc Lehmann -Date: Sat, 6 Sep 2025 11:31:36 +0200 -Subject: [PATCH 1/2] fix json_atof_scan1 overflows - -with fuzzed overlong numbers. CVE-2025-40928 -Really the comparisons were wrong. ---- - XS.xs | 8 ++++---- - 1 file changed, 4 insertions(+), 4 deletions(-) - -diff --git a/XS.xs b/XS.xs -index 9b1ce2b..94ab0d6 100755 ---- a/XS.xs -+++ b/XS.xs -@@ -710,16 +710,16 @@ json_atof_scan1 (const char *s, NV *accum, int *expo, int postdp, int maxdepth) - /* if we recurse too deep, skip all remaining digits */ - /* to avoid a stack overflow attack */ - if (UNLIKELY(--maxdepth <= 0)) -- while (((U8)*s - '0') < 10) -+ while ((U8)(*s - '0') < 10) - ++s; - - for (;;) - { -- U8 dig = (U8)*s - '0'; -+ U8 dig = (U8)(*s - '0'); - - if (UNLIKELY(dig >= 10)) - { -- if (dig == (U8)((U8)'.' - (U8)'0')) -+ if (dig == (U8)('.' - '0')) - { - ++s; - json_atof_scan1 (s, accum, expo, 1, maxdepth); -@@ -739,7 +739,7 @@ json_atof_scan1 (const char *s, NV *accum, int *expo, int postdp, int maxdepth) - else if (*s == '+') - ++s; - -- while ((dig = (U8)*s - '0') < 10) -+ while ((dig = (U8)(*s - '0')) < 10) - exp2 = exp2 * 10 + *s++ - '0'; - - *expo += neg ? -exp2 : exp2; --- -2.50.1 - diff --git a/pkgs/development/perl-modules/FileFindRule-CVE-2011-10007.patch b/pkgs/development/perl-modules/FileFindRule-CVE-2011-10007.patch deleted file mode 100644 index dd8492c60f21..000000000000 --- a/pkgs/development/perl-modules/FileFindRule-CVE-2011-10007.patch +++ /dev/null @@ -1,25 +0,0 @@ -From ca70a73bb147549e62e74751d924b1dbb59d1707 Mon Sep 17 00:00:00 2001 -From: Stig Palmquist -Date: Thu, 5 Jun 2025 03:45:50 +0200 -Subject: [PATCH] Fix CVE-2011-10007 - ---- - lib/File/Find/Rule.pm | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/lib/File/Find/Rule.pm b/lib/File/Find/Rule.pm -index feccc76..d4dc475 100644 ---- a/lib/File/Find/Rule.pm -+++ b/lib/File/Find/Rule.pm -@@ -420,7 +420,7 @@ sub grep { - - $self->exec( sub { - local *FILE; -- open FILE, $_ or return; -+ open FILE, '<', $_ or return; - local ($_, $.); - while () { - for my $p (@pattern) { --- -2.49.0 - diff --git a/pkgs/development/perl-modules/JSON-XS-CVE-2025-40928.patch b/pkgs/development/perl-modules/JSON-XS-CVE-2025-40928.patch deleted file mode 100644 index f1d258c12a3d..000000000000 --- a/pkgs/development/perl-modules/JSON-XS-CVE-2025-40928.patch +++ /dev/null @@ -1,31 +0,0 @@ ---- a/XS.xs 2025-09-06 08:34:51.376455632 -0300 -+++ b/XS.xs 2025-09-06 08:35:30.725873619 -0300 -@@ -253,16 +253,16 @@ - // if we recurse too deep, skip all remaining digits - // to avoid a stack overflow attack - if (expect_false (--maxdepth <= 0)) -- while (((U8)*s - '0') < 10) -+ while ((U8)(*s - '0') < 10) - ++s; - - for (;;) - { -- U8 dig = (U8)*s - '0'; -+ U8 dig = *s - '0'; - - if (expect_false (dig >= 10)) - { -- if (dig == (U8)((U8)'.' - (U8)'0')) -+ if (dig == (U8)('.' - '0')) - { - ++s; - json_atof_scan1 (s, accum, expo, 1, maxdepth); -@@ -282,7 +282,7 @@ - else if (*s == '+') - ++s; - -- while ((dig = (U8)*s - '0') < 10) -+ while ((dig = (U8)(*s - '0')) < 10) - exp2 = exp2 * 10 + *s++ - '0'; - - *expo += neg ? -exp2 : exp2; diff --git a/pkgs/development/perl-modules/XML-LibXML-fix-tests-libxml-2.13.0.patch b/pkgs/development/perl-modules/XML-LibXML-fix-tests-libxml-2.13.0.patch deleted file mode 100644 index 5433d3afd934..000000000000 --- a/pkgs/development/perl-modules/XML-LibXML-fix-tests-libxml-2.13.0.patch +++ /dev/null @@ -1,242 +0,0 @@ -From bee8338fd1cbd7aad4bf60c2965833343b6ead6f Mon Sep 17 00:00:00 2001 -From: Nick Wellnhofer -Date: Tue, 21 May 2024 15:17:30 +0200 -Subject: [PATCH 1/3] Fix test suite with libxml2 2.13.0 - ---- - t/02parse.t | 7 ++++++- - t/08findnodes.t | 8 +++++++- - t/19die_on_invalid_utf8_rt_58848.t | 2 +- - t/25relaxng.t | 4 ++-- - t/26schema.t | 4 ++-- - t/60error_prev_chain.t | 8 ++++---- - 6 files changed, 22 insertions(+), 11 deletions(-) - -diff --git a/t/02parse.t b/t/02parse.t -index b111507b..40aa5f13 100644 ---- a/t/02parse.t -+++ b/t/02parse.t -@@ -884,7 +884,12 @@ EOXML - eval { - $doc2 = $parser->parse_string( $xmldoc ); - }; -- isnt($@, '', "error parsing $xmldoc"); -+ # https://gitlab.gnome.org/GNOME/libxml2/-/commit/b717abdd -+ if (XML::LibXML::LIBXML_RUNTIME_VERSION() < 21300) { -+ isnt($@, '', "error parsing $xmldoc"); -+ } else { -+ is( $doc2->documentElement()->firstChild()->nodeName(), "foo" ); -+ } - - $parser->validation(1); - -diff --git a/t/08findnodes.t b/t/08findnodes.t -index 016c85a1..e9417bc5 100644 ---- a/t/08findnodes.t -+++ b/t/08findnodes.t -@@ -123,7 +123,13 @@ my $docstring = q{ - my @ns = $root->findnodes('namespace::*'); - # TEST - --is(scalar(@ns), 2, ' TODO : Add test name' ); -+# https://gitlab.gnome.org/GNOME/libxml2/-/commit/aca16fb3 -+# fixed xmlCopyNamespace with XML namespace. -+if (XML::LibXML::LIBXML_RUNTIME_VERSION() < 21300) { -+ is(scalar(@ns), 2, ' TODO : Add test name' ); -+} else { -+ is(scalar(@ns), 3, ' TODO : Add test name' ); -+} - - # bad xpaths - # TEST:$badxpath=4; -diff --git a/t/19die_on_invalid_utf8_rt_58848.t b/t/19die_on_invalid_utf8_rt_58848.t -index aa8ad105..4160cb27 100644 ---- a/t/19die_on_invalid_utf8_rt_58848.t -+++ b/t/19die_on_invalid_utf8_rt_58848.t -@@ -16,7 +16,7 @@ use XML::LibXML; - my $err = $@; - - # TEST -- like ("$err", qr{parser error : Input is not proper UTF-8}, -+ like ("$err", qr{not proper UTF-8|Invalid bytes in character encoding}, - 'Parser error.', - ); - } -diff --git a/t/25relaxng.t b/t/25relaxng.t -index 93e61883..71383b2a 100644 ---- a/t/25relaxng.t -+++ b/t/25relaxng.t -@@ -132,7 +132,7 @@ print "# 6 check that no_network => 1 works\n"; - { - my $rng = eval { XML::LibXML::RelaxNG->new( location => $netfile, no_network => 1 ) }; - # TEST -- like( $@, qr{I/O error : Attempt to load network entity}, 'RNG from file location with external import and no_network => 1 throws an exception.' ); -+ like( $@, qr{Attempt to load network entity}, 'RNG from file location with external import and no_network => 1 throws an exception.' ); - # TEST - ok( !defined $rng, 'RNG from file location with external import and no_network => 1 is not loaded.' ); - } -@@ -152,7 +152,7 @@ print "# 6 check that no_network => 1 works\n"; - - EOF - # TEST -- like( $@, qr{I/O error : Attempt to load network entity}, 'RNG from buffer with external import and no_network => 1 throws an exception.' ); -+ like( $@, qr{Attempt to load network entity}, 'RNG from buffer with external import and no_network => 1 throws an exception.' ); - # TEST - ok( !defined $rng, 'RNG from buffer with external import and no_network => 1 is not loaded.' ); - } -diff --git a/t/26schema.t b/t/26schema.t -index 17f641e4..c404cedd 100644 ---- a/t/26schema.t -+++ b/t/26schema.t -@@ -117,7 +117,7 @@ EOF - { - my $schema = eval { XML::LibXML::Schema->new( location => $netfile, no_network => 1 ) }; - # TEST -- like( $@, qr{I/O error : Attempt to load network entity}, 'Schema from file location with external import and no_network => 1 throws an exception.' ); -+ like( $@, qr{Attempt to load network entity}, 'Schema from file location with external import and no_network => 1 throws an exception.' ); - # TEST - ok( !defined $schema, 'Schema from file location with external import and no_network => 1 is not loaded.' ); - } -@@ -129,7 +129,7 @@ EOF - - EOF - # TEST -- like( $@, qr{I/O error : Attempt to load network entity}, 'Schema from buffer with external import and no_network => 1 throws an exception.' ); -+ like( $@, qr{Attempt to load network entity}, 'Schema from buffer with external import and no_network => 1 throws an exception.' ); - # TEST - ok( !defined $schema, 'Schema from buffer with external import and no_network => 1 is not loaded.' ); - } -diff --git a/t/60error_prev_chain.t b/t/60error_prev_chain.t -index e48215c4..55ac0b2e 100644 ---- a/t/60error_prev_chain.t -+++ b/t/60error_prev_chain.t -@@ -16,13 +16,11 @@ use XML::LibXML; - - { - my $parser = XML::LibXML->new(); -- $parser->validation(0); -- $parser->load_ext_dtd(0); - - eval - { - local $^W = 0; -- $parser->parse_file('example/JBR-ALLENtrees.htm'); -+ $parser->parse_string('“ ”'); - }; - - my $err = $@; -@@ -31,7 +29,7 @@ use XML::LibXML; - if( $err && !ref($err) ) { - plan skip_all => 'The local libxml library does not support errors as objects to $@'; - } -- plan tests => 1; -+ plan tests => 2; - - while (defined($err) && $count < 200) - { -@@ -44,6 +42,8 @@ use XML::LibXML; - - # TEST - ok ((!$err), "Reached the end of the chain."); -+ # TEST -+ is ($count, 3, "Correct number of errors reported") - } - - =head1 COPYRIGHT & LICENSE - -From c9f9c2fe51173b0a00969f01b577399f1098aa47 Mon Sep 17 00:00:00 2001 -From: Nick Wellnhofer -Date: Thu, 13 Feb 2025 19:50:35 +0100 -Subject: [PATCH 2/3] Fix test suite with libxml2 2.14.0 - ---- - t/16docnodes.t | 7 ++++++- - t/49_load_html.t | 8 +++++++- - 2 files changed, 13 insertions(+), 2 deletions(-) - -diff --git a/t/16docnodes.t b/t/16docnodes.t -index db7bc1fc..0b0ae005 100644 ---- a/t/16docnodes.t -+++ b/t/16docnodes.t -@@ -60,7 +60,12 @@ for my $time (0 .. 2) { - $doc->setDocumentElement($node); - - # TEST -- is( $node->serialize(), '', 'Node serialise works.' ); -+ # libxml2 2.14 avoids unnecessary escaping of attribute values. -+ if (XML::LibXML::LIBXML_VERSION() >= 21400) { -+ is( $node->serialize(), "", 'Node serialise works.' ); -+ } else { -+ is( $node->serialize(), '', 'Node serialise works.' ); -+ } - - $doc->setEncoding('utf-8'); - # Second output -diff --git a/t/49_load_html.t b/t/49_load_html.t -index 70d26607..3861edf8 100644 ---- a/t/49_load_html.t -+++ b/t/49_load_html.t -@@ -52,7 +52,13 @@ use XML::LibXML; - - EOS - -- { -+ SKIP: { -+ # libxml2 2.14 tokenizes HTML according to HTML5 where -+ # this isn't an error, see "13.2.5.73 Named character -+ # reference state". -+ skip("libxml2 version >= 21400", 1) -+ if XML::LibXML::LIBXML_VERSION >= 21400; -+ - my $buf = ''; - open my $fh, '>', \$buf; - # redirect STDERR there - -From ecbebc2f33fecb66b3d5487c6e48bea353e374f9 Mon Sep 17 00:00:00 2001 -From: Nick Wellnhofer -Date: Fri, 16 May 2025 19:11:12 +0200 -Subject: [PATCH 3/3] Remove tests that disable line numbers - -Line numbers are always enabled since libxml2 2.15.0. ---- - t/02parse.t | 13 ++----------- - 1 file changed, 2 insertions(+), 11 deletions(-) - -diff --git a/t/02parse.t b/t/02parse.t -index 40aa5f13..17419f8f 100644 ---- a/t/02parse.t -+++ b/t/02parse.t -@@ -14,7 +14,7 @@ use locale; - - POSIX::setlocale(LC_ALL, "C"); - --use Test::More tests => 533; -+use Test::More tests => 531; - use IO::File; - - use XML::LibXML::Common qw(:libxml); -@@ -25,7 +25,7 @@ use constant XML_DECL => "\n"; - - use Errno qw(ENOENT); - --# TEST*533 -+# TEST*531 - - ## - # test values -@@ -773,15 +773,6 @@ EOXML - - my $newkid = $root->appendChild( $doc->createElement( "bar" ) ); - is( $newkid->line_number(), 0, "line number is 0"); -- -- $parser->line_numbers(0); -- eval { $doc = $parser->parse_string( $goodxml ); }; -- -- $root = $doc->documentElement(); -- is( $root->line_number(), 0, "line number is 0"); -- -- @kids = $root->childNodes(); -- is( $kids[1]->line_number(), 0, "line number is 0"); - } - - SKIP: { diff --git a/pkgs/development/perl-modules/catalyst-plugin-static-simple-etag.patch b/pkgs/development/perl-modules/catalyst-plugin-static-simple-etag.patch index 06207a8b7334..31b21f5cb768 100644 --- a/pkgs/development/perl-modules/catalyst-plugin-static-simple-etag.patch +++ b/pkgs/development/perl-modules/catalyst-plugin-static-simple-etag.patch @@ -1,36 +1,19 @@ Send an ETag header, and honour the If-None-Match request header -diff -ru -x '*~' Catalyst-Plugin-Static-Simple-0.30-orig/lib/Catalyst/Plugin/Static/Simple.pm Catalyst-Plugin-Static-Simple-0.30/lib/Catalyst/Plugin/Static/Simple.pm ---- Catalyst-Plugin-Static-Simple-0.30-orig/lib/Catalyst/Plugin/Static/Simple.pm 2012-05-04 18:49:30.000000000 +0200 -+++ Catalyst-Plugin-Static-Simple-0.30/lib/Catalyst/Plugin/Static/Simple.pm 2013-02-25 22:57:18.667150181 +0100 -@@ -187,16 +187,27 @@ - my $type = $c->_ext_to_type( $full_path ); - my $stat = stat $full_path; +--- a/lib/Catalyst/Plugin/Static/Simple.pm ++++ b/lib/Catalyst/Plugin/Static/Simple.pm +@@ -223,6 +223,15 @@ -- $c->res->headers->content_type( $type ); -- $c->res->headers->content_length( $stat->size ); -- $c->res->headers->last_modified( $stat->mtime ); - # Tell Firefox & friends its OK to cache, even over SSL: -- $c->res->headers->header('Cache-control' => 'public'); -+ #$c->res->headers->header('Cache-control' => 'public'); -+ -+ $c->res->headers->last_modified( $stat->mtime ); - # Optionally, set a fixed expiry time: - if ($config->{expires}) { - $c->res->headers->expires(time() + $config->{expires}); - } + $c->res->headers->header('Cache-Control' => $cache_control); + if ($config->{send_etag}) { -+ my $etag = '"' . $stat->mtime . '-' . $stat->ino . '-'. $stat->size . '"'; ++ my $etag = '"' . $stat->mtime . '-' . $stat->ino . '-' . $stat->size . '"'; + $c->res->headers->header('ETag' => $etag); + if (($c->req->header('If-None-Match') // "") eq $etag) { + $c->res->status(304); + return 1; + } + } -+ -+ $c->res->headers->content_type( $type ); -+ $c->res->headers->content_length( $stat->size ); + my $fh = IO::File->new( $full_path, 'r' ); if ( defined $fh ) { diff --git a/pkgs/development/python-modules/gitpython/default.nix b/pkgs/development/python-modules/gitpython/default.nix index 2b5b14a297b5..6af9bc013850 100644 --- a/pkgs/development/python-modules/gitpython/default.nix +++ b/pkgs/development/python-modules/gitpython/default.nix @@ -10,14 +10,14 @@ buildPythonPackage (finalAttrs: { pname = "gitpython"; - version = "3.1.58"; + version = "3.1.62"; pyproject = true; src = fetchFromGitHub { owner = "gitpython-developers"; repo = "GitPython"; tag = finalAttrs.version; - hash = "sha256-C6hrN7SRWngwkD/NYvsoEVQUagdurkxzWbnn42EJOHE="; + hash = "sha256-g7qZSFFWAa7iJSn+HAxCTfNZfrYZsZRJGUIZGYQjoUI="; }; postPatch = '' diff --git a/pkgs/development/python-modules/pyjwt/default.nix b/pkgs/development/python-modules/pyjwt/default.nix index 74754630a145..d1267cf08628 100644 --- a/pkgs/development/python-modules/pyjwt/default.nix +++ b/pkgs/development/python-modules/pyjwt/default.nix @@ -11,16 +11,16 @@ oauthlib, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "pyjwt"; - version = "2.13.0"; + version = "2.14.0"; pyproject = true; src = fetchFromGitHub { owner = "jpadilla"; repo = "pyjwt"; - tag = version; - hash = "sha256-q4ynXCJVDsyZh70439dloyWgRTLVm+elDOahUVOT5vA="; + tag = finalAttrs.version; + hash = "sha256-SxJ2GQt1pfm8iAeTB2RmH2kliGeQ6whkM5nuesI1s/U="; }; outputs = [ @@ -38,7 +38,10 @@ buildPythonPackage rec { optional-dependencies.crypto = [ cryptography ]; - nativeCheckInputs = [ pytestCheckHook ] ++ (lib.concatAttrValues optional-dependencies); + nativeCheckInputs = [ + pytestCheckHook + ] + ++ (lib.concatAttrValues finalAttrs.passthru.optional-dependencies); disabledTests = [ # requires internet connection @@ -52,10 +55,10 @@ buildPythonPackage rec { }; meta = { - changelog = "https://github.com/jpadilla/pyjwt/blob/${version}/CHANGELOG.rst"; + changelog = "https://github.com/jpadilla/pyjwt/blob/${finalAttrs.src.tag}/CHANGELOG.rst"; description = "JSON Web Token implementation in Python"; homepage = "https://github.com/jpadilla/pyjwt"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ prikhi ]; }; -} +}) diff --git a/pkgs/os-specific/linux/systemd/0001-Don-t-try-to-unmount-nix-or-nix-store.patch b/pkgs/os-specific/linux/systemd/0001-Don-t-try-to-unmount-nix-or-nix-store.patch index 138b8c92dba2..7c3d9cc01821 100644 --- a/pkgs/os-specific/linux/systemd/0001-Don-t-try-to-unmount-nix-or-nix-store.patch +++ b/pkgs/os-specific/linux/systemd/0001-Don-t-try-to-unmount-nix-or-nix-store.patch @@ -14,7 +14,7 @@ Original-Author: Eelco Dolstra 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/src/shared/fstab-util.c b/src/shared/fstab-util.c -index 25e229bf3e..b9af1c3b13 100644 +index a4f5e348ab..d506b5598e 100644 --- a/src/shared/fstab-util.c +++ b/src/shared/fstab-util.c @@ -76,6 +76,8 @@ bool fstab_is_extrinsic(const char *mount, const char *opts) { diff --git a/pkgs/os-specific/linux/systemd/0002-Change-usr-share-zoneinfo-to-etc-zoneinfo.patch b/pkgs/os-specific/linux/systemd/0002-Change-usr-share-zoneinfo-to-etc-zoneinfo.patch index a9ec66f9dd3d..e12f00b328b6 100644 --- a/pkgs/os-specific/linux/systemd/0002-Change-usr-share-zoneinfo-to-etc-zoneinfo.patch +++ b/pkgs/os-specific/linux/systemd/0002-Change-usr-share-zoneinfo-to-etc-zoneinfo.patch @@ -35,10 +35,10 @@ index 3a13e04a27..4fd58068a1 100644 Etc/UTC. The resulting link should lead to the corresponding binary diff --git a/src/basic/time-util.c b/src/basic/time-util.c -index 5dd00af952..b97a41f6ac 100644 +index 6873017bf5..7455aa30ae 100644 --- a/src/basic/time-util.c +++ b/src/basic/time-util.c -@@ -1443,7 +1443,7 @@ static int get_timezones_from_zone1970_tab(char ***ret) { +@@ -1446,7 +1446,7 @@ static int get_timezones_from_zone1970_tab(char ***ret) { assert(ret); @@ -47,7 +47,7 @@ index 5dd00af952..b97a41f6ac 100644 if (!f) return -errno; -@@ -1488,7 +1488,7 @@ static int get_timezones_from_tzdata_zi(char ***ret) { +@@ -1491,7 +1491,7 @@ static int get_timezones_from_tzdata_zi(char ***ret) { assert(ret); @@ -56,7 +56,7 @@ index 5dd00af952..b97a41f6ac 100644 if (!f) return -errno; -@@ -1603,7 +1603,7 @@ int verify_timezone(const char *name, int log_level) { +@@ -1606,7 +1606,7 @@ int verify_timezone(const char *name, int log_level) { if (p - name >= PATH_MAX) return -ENAMETOOLONG; @@ -65,7 +65,7 @@ index 5dd00af952..b97a41f6ac 100644 fd = open(t, O_RDONLY|O_CLOEXEC); if (fd < 0) -@@ -1675,7 +1675,7 @@ int get_timezone(char **ret) { +@@ -1678,7 +1678,7 @@ int get_timezone(char **ret) { if (r < 0) return r; /* Return EINVAL if not a symlink */ @@ -75,7 +75,7 @@ index 5dd00af952..b97a41f6ac 100644 return -EINVAL; if (!timezone_is_valid(e, LOG_DEBUG)) diff --git a/src/firstboot/firstboot.c b/src/firstboot/firstboot.c -index ae1899593c..20d3071114 100644 +index ba96a749c6..f64e22faf1 100644 --- a/src/firstboot/firstboot.c +++ b/src/firstboot/firstboot.c @@ -584,7 +584,7 @@ static int prompt_timezone(int rfd, sd_varlink **mute_console_link) { @@ -103,7 +103,7 @@ index ae1899593c..20d3071114 100644 return log_error_errno(r, "Failed to create /etc/localtime symlink: %m"); diff --git a/src/nspawn/nspawn.c b/src/nspawn/nspawn.c -index 84e94e845a..8e1f1a6ea2 100644 +index d9bde47c8e..8c32e3ae99 100644 --- a/src/nspawn/nspawn.c +++ b/src/nspawn/nspawn.c @@ -1856,8 +1856,8 @@ int userns_mkdir(const char *root, const char *path, mode_t mode, uid_t uid, gid @@ -118,7 +118,7 @@ index 84e94e845a..8e1f1a6ea2 100644 static bool etc_writable(void) { diff --git a/src/timedate/timedated.c b/src/timedate/timedated.c -index 43cf3fddb9..dc23550500 100644 +index 5478666ca0..7e2ea196f5 100644 --- a/src/timedate/timedated.c +++ b/src/timedate/timedated.c @@ -268,7 +268,7 @@ static int context_read_data(Context *c) { diff --git a/pkgs/os-specific/linux/systemd/default.nix b/pkgs/os-specific/linux/systemd/default.nix index 3bc724c8338d..66cec5f951f3 100644 --- a/pkgs/os-specific/linux/systemd/default.nix +++ b/pkgs/os-specific/linux/systemd/default.nix @@ -201,13 +201,13 @@ let in stdenv.mkDerivation (finalAttrs: { inherit pname; - version = "260.4"; + version = "260.5"; src = fetchFromGitHub { owner = "systemd"; repo = "systemd"; rev = "v${finalAttrs.version}"; - hash = "sha256-n+wzn+1W82YooRxzIEJHm4CsVPFBGlQUIy9TatxlbaU="; + hash = "sha256-QLQad4pKkaf99k+ABOaooKi5TSX0iHH9XtMn/fy1rfE="; }; # PATCH POLICY diff --git a/pkgs/tools/security/gnupg/24.nix b/pkgs/tools/security/gnupg/24.nix index 06a1d0967a8e..0e6270238406 100644 --- a/pkgs/tools/security/gnupg/24.nix +++ b/pkgs/tools/security/gnupg/24.nix @@ -86,8 +86,8 @@ stdenv.mkDerivation rec { freepgPatches = fetchFromGitLab { owner = "freepg"; repo = "gnupg"; - tag = "source-2.4.9-freepg"; - hash = "sha256-wF+iR0OgnU8VI90NlFOXtN5aCRC0YY/X7sPiDXjJm5M="; + tag = "source-2.4.9-freepg-1"; + hash = "sha256-hoSuIrq7Epco1LLlc77tGr/YZdp2w04Eq0rGbBCurWU="; }; patches = [ @@ -128,6 +128,15 @@ stdenv.mkDerivation rec { "0033-Support-large-RSA-keygen-in-non-batch-mode.patch" "0034-gpg-Verify-Text-mode-Signatures-over-binary-Literal-.patch" "0039-gpg-Do-not-use-a-default-when-asking-for-another-out.patch" + "0040-Add-missing-test-files-to-EXTRA_DIST.patch" + "0045-gpg-Fix-edge-case-in-refresh-keys.patch" + "0046-gpgsm-Require-a-minimum-tag-length-for-GCM-decryptio.patch" + "0047-gpg-Fix-handling-with-no-CRC-armor.patch" + "0048-gpg-Fix-armored-input-parsing.patch" + "0049-gpg-Fix-armor-parsing-when-no-CRC-is-found.patch" + "0050-tpm-Fix-possible-buffer-overflow-in-PKDECRYPT.patch" + "0051-agent-Fix-the-regression-in-pkdecrypt-with-TPM-RSA.patch" + "0052-dirmngr-Fix-a-call-of-calloc.patch" ]; postPatch = diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index cc58357a0e46..9ae74d3ab59d 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -116,11 +116,11 @@ with self; ack = buildPerlPackage rec { pname = "ack"; - version = "3.9.0"; + version = "3.10.0"; src = fetchurl { url = "mirror://cpan/authors/id/P/PE/PETDANCE/ack-v${version}.tar.gz"; - hash = "sha256-lO1Hfjs/lNEmzscynw6DmfHQzoLHxNiCqUrbFQ5//JA="; + hash = "sha256-Zeg8+zinH8pyXpoUqCAe6HHmKfxrECMeEwPdNQG6Vjo="; }; outputs = [ @@ -2096,10 +2096,10 @@ with self; AuthenSASL = buildPerlPackage { pname = "Authen-SASL"; - version = "2.1900"; + version = "2.2100"; src = fetchurl { - url = "mirror://cpan/authors/id/E/EH/EHUELS/Authen-SASL-2.1900.tar.gz"; - hash = "sha256-vjUzpokbLmdxULR5waDUvxHIu+6+0+e466NAU+k5I7A="; + url = "mirror://cpan/authors/id/E/EH/EHUELS/Authen-SASL-2.2100.tar.gz"; + hash = "sha256-Tw8QCu7TS1KXepS335c+fwuPktFnsJ8rJJurgehZDlc="; }; propagatedBuildInputs = [ CryptURandom @@ -3352,18 +3352,11 @@ with self; CatalystAuthenticationCredentialHTTP = buildPerlModule { pname = "Catalyst-Authentication-Credential-HTTP"; - version = "1.018"; + version = "1.019"; src = fetchurl { - url = "mirror://cpan/authors/id/E/ET/ETHER/Catalyst-Authentication-Credential-HTTP-1.018.tar.gz"; - hash = "sha256-b6GBbe5kSw216gzBXF5xHcLO0gg2JavOcJZSHx1lpSk="; + url = "mirror://cpan/authors/id/A/AB/ABRAXXA/Catalyst-Authentication-Credential-HTTP-1.019.tar.gz"; + hash = "sha256-7IHpbCo/ZYbqQdCI6o6AGx80ABqxnMmmXe+KOMOaW9o="; }; - patches = [ - (fetchpatch { - name = "CVE-2025-40920.patch"; - url = "https://github.com/perl-catalyst/Catalyst-Authentication-Credential-HTTP/commit/ad2c03aad95406db4ce35dfb670664ebde004c18.patch"; - hash = "sha256-WI6JwvY6i3KkQO9HbbSvHPX8mgM8I2cF0UTjF1D14T4="; - }) - ]; buildInputs = [ ModuleBuildTiny TestException @@ -3374,7 +3367,6 @@ with self; CatalystPluginAuthentication ClassAccessor CryptSysRandom - DataUUID StringEscape ]; meta = { @@ -4116,12 +4108,19 @@ with self; CatalystPluginStaticSimple = buildPerlPackage { pname = "Catalyst-Plugin-Static-Simple"; - version = "0.37"; + version = "0.38"; src = fetchurl { - url = "mirror://cpan/authors/id/I/IL/ILMARI/Catalyst-Plugin-Static-Simple-0.37.tar.gz"; - hash = "sha256-Wk2Fo1iM1Og/GwAlgUEufXG31X9mBW5dh6Nvk9icnnw="; + url = "mirror://cpan/authors/id/E/ET/ETHER/Catalyst-Plugin-Static-Simple-0.38.tar.gz"; + hash = "sha256-BOtn69x4cyf3fvLHOXar7Pk/mu/KCnGFIv6YuMpSOLA="; }; - patches = [ ../development/perl-modules/catalyst-plugin-static-simple-etag.patch ]; + patches = [ + (fetchpatch { + url = "https://security.metacpan.org/patches/C/Catalyst-Plugin-Static-Simple/0.38/CVE-2026-15743-r1.patch"; + hash = "sha256-dNJOz7X7i03kisrf+lhqAaL6lYeTlt1NJZnJWNM7bgQ="; + }) + ../development/perl-modules/catalyst-plugin-static-simple-etag.patch + ]; + postPatch = "rm -f lib/Catalyst/Plugin/Static/Simple.pm.orig"; propagatedBuildInputs = [ CatalystRuntime MIMETypes @@ -4627,12 +4626,15 @@ with self; CGISession = buildPerlModule { pname = "CGI-Session"; - version = "4.48"; + version = "4.49"; src = fetchurl { - url = "mirror://cpan/authors/id/M/MA/MARKSTOS/CGI-Session-4.48.tar.gz"; - hash = "sha256-RnVkYcJM52ZrgQjduW26thJpnfMBLIDvEQFmGf4VVPc="; + url = "mirror://cpan/authors/id/M/MA/MARKSTOS/CGI-Session-4.49.tar.gz"; + hash = "sha256-X9iKgwo19UUmeH8DauXkp9FLYcQUzSmthjG/RuaXEgc="; }; - propagatedBuildInputs = [ CGI ]; + propagatedBuildInputs = [ + CGI + CryptSysRandom + ]; meta = { description = "Persistent session data in CGI applications"; license = with lib.licenses; [ artistic1 ]; @@ -5092,6 +5094,22 @@ with self; }; }; + ClassErrorHandler = buildPerlPackage { + pname = "Class-ErrorHandler"; + version = "0.04"; + src = fetchurl { + url = "mirror://cpan/authors/id/T/TO/TOKUHIROM/Class-ErrorHandler-0.04.tar.gz"; + hash = "sha256-NC0tz8eXogvugXmxuWuFwK56W0iCc1lSPNjHTD5wRQI="; + }; + meta = { + description = "Base class for error handling"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + ClassInspector = buildPerlPackage { pname = "Class-Inspector"; version = "1.36"; @@ -6045,10 +6063,10 @@ with self; ConfigIniFiles = buildPerlPackage { pname = "Config-IniFiles"; - version = "3.000003"; + version = "3.002000"; src = fetchurl { - url = "mirror://cpan/authors/id/S/SH/SHLOMIF/Config-IniFiles-3.000003.tar.gz"; - hash = "sha256-PEV7ZdmOX/QL25z4FLDVmD6wxT+4aWvaO6A1rSrNaAI="; + url = "mirror://cpan/authors/id/S/SH/SHLOMIF/Config-IniFiles-3.002000.tar.gz"; + hash = "sha256-Bmke17QZl+hQxOfGs05cOWFF4M0FCvGUSiDQaMOlpAs="; }; propagatedBuildInputs = [ IOStringy ]; meta = { @@ -6397,6 +6415,29 @@ with self; }; }; + ConvertPEM = buildPerlPackage { + pname = "Convert-PEM"; + version = "0.13"; + src = fetchurl { + url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Convert-PEM-0.13.tar.gz"; + hash = "sha256-eZ+jLCcAgfTmKSsN31GAlScQqKS+Ey6Qe9oxdqe9HCM="; + }; + buildInputs = [ TestException ]; + propagatedBuildInputs = [ + ClassErrorHandler + ConvertASN1 + CryptDESEDE3 + CryptX + ]; + meta = { + description = "Read/write encrypted ASN.1 PEM files"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + ConvertUU = buildPerlPackage { pname = "Convert-UU"; version = "0.5201"; @@ -6480,10 +6521,10 @@ with self; CookieBaker = buildPerlModule { pname = "Cookie-Baker"; - version = "0.11"; + version = "0.12"; src = fetchurl { - url = "mirror://cpan/authors/id/K/KA/KAZEBURO/Cookie-Baker-0.11.tar.gz"; - hash = "sha256-WSdfR04HwKo2EePmhLiU59uRMzPYIUQgvmPxLsGM16s="; + url = "mirror://cpan/authors/id/K/KA/KAZEBURO/Cookie-Baker-0.12.tar.gz"; + hash = "sha256-mwTfXUfc1FrEKZYmoQ7JkPtAyU7lpjAMOoi9+zV17Ck="; }; buildInputs = [ ModuleBuildTiny @@ -6691,12 +6732,11 @@ with self; CpanelJSONXS = buildPerlPackage { pname = "Cpanel-JSON-XS"; - version = "4.37"; + version = "4.42"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RU/RURBAN/Cpanel-JSON-XS-4.37.tar.gz"; - hash = "sha256-wkFhWg4X/3Raqoa79Gam4pzSQFFeZfBqegUBe2GebUs="; + url = "mirror://cpan/authors/id/R/RU/RURBAN/Cpanel-JSON-XS-4.42.tar.gz"; + hash = "sha256-4awvqx46bS2ZjTRAxgAGc2W9x9vwyPKyBZy85LTIMXM="; }; - patches = [ ../development/perl-modules/Cpanel-JSON-XS-CVE-2025-40929.patch ]; meta = { description = "CPanel fork of JSON::XS, fast and correct serializing"; license = with lib.licenses; [ @@ -6890,13 +6930,15 @@ with self; CryptArgon2 = buildPerlModule { pname = "Crypt-Argon2"; - version = "0.019"; + version = "0.031"; src = fetchurl { - url = "mirror://cpan/authors/id/L/LE/LEONT/Crypt-Argon2-0.019.tar.gz"; - hash = "sha256-+Fm+6NL2tAf11EZFwiOu4hL+AFkd/YLlBlrhvnio5Dg="; + url = "mirror://cpan/authors/id/L/LE/LEONT/Crypt-Argon2-0.031.tar.gz"; + hash = "sha256-1l5RoZQ+6AglEkUNw1KuUpUQZswJI/u38uYK+l8WTi0="; }; nativeBuildInputs = [ pkgs.ld-is-cc-hook ]; + buildInputs = [ DistBuild ]; meta = { + changelog = "https://github.com/Leont/crypt-argon2/blob/v0.031/Changes"; description = "Perl interface to the Argon2 key derivation functions"; license = with lib.licenses; [ cc0 ]; }; @@ -6950,11 +6992,16 @@ with self; CryptCBC = buildPerlPackage { pname = "Crypt-CBC"; - version = "2.33"; + version = "3.07"; src = fetchurl { - url = "mirror://cpan/authors/id/L/LD/LDS/Crypt-CBC-2.33.tar.gz"; - hash = "sha256-anDeIbbMfysQAGfo4Yjblm6agAG122+pdufLWylK5kU="; + url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Crypt-CBC-3.07.tar.gz"; + hash = "sha256-9N37TdasUBPfg0G/pzTZye4PEOLnEhXsj+W/eAt8kSc="; }; + propagatedBuildInputs = [ + CryptPBKDF2 + CryptURandom + CryptX + ]; meta = { description = "Encrypt Data with Cipher Block Chaining Mode"; license = with lib.licenses; [ @@ -7017,6 +7064,23 @@ with self; }; }; + CryptDESEDE3 = buildPerlPackage { + pname = "Crypt-DES_EDE3"; + version = "0.03"; + src = fetchurl { + url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Crypt-DES_EDE3-0.03.tar.gz"; + hash = "sha256-KFktt7njR0WqkfPhnl27uDqvRyop5we5eR0NArPiJ/U="; + }; + propagatedBuildInputs = [ CryptDES ]; + meta = { + description = "Triple-DES EDE encryption/decryption"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + CryptDH = buildPerlPackage { pname = "Crypt-DH"; version = "0.07"; @@ -7059,14 +7123,16 @@ with self; CryptDSA = buildPerlPackage { pname = "Crypt-DSA"; - version = "1.17"; + version = "1.24"; src = fetchurl { - url = "mirror://cpan/authors/id/A/AD/ADAMK/Crypt-DSA-1.17.tar.gz"; - hash = "sha256-0bhYX2v3RvduXcXaNkHTJe1la8Ll80S1RRS1XDEAmgM="; + url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Crypt-DSA-1.24.tar.gz"; + hash = "sha256-ChY4tvK07+ktbuL0kBzKAtenBWf2uw9Iapu19pvnZ2Y="; }; propagatedBuildInputs = [ + ConvertASN1 + ConvertPEM + CryptSysRandom DataBuffer - DigestSHA1 FileWhich ]; meta = { @@ -7260,11 +7326,12 @@ with self; CryptPasswdMD5 = buildPerlPackage { pname = "Crypt-PasswdMD5"; - version = "1.42"; + version = "1.43"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RS/RSAVAGE/Crypt-PasswdMD5-1.42.tgz"; - hash = "sha256-/Tlubn9E7rkj6TyZOUC49nqa7Vb8dKrK8Dj8QFPvO1k="; + url = "mirror://cpan/authors/id/R/RS/RSAVAGE/Crypt-PasswdMD5-1.43.tgz"; + hash = "sha256-Qr+Sk0UQlYXUlWkCVX7ONdBh7aQ454lPhucHV0EoB1k="; }; + propagatedBuildInputs = [ CryptURandom ]; meta = { description = "Provide interoperable MD5-based crypt() functions"; license = with lib.licenses; [ @@ -7495,14 +7562,32 @@ with self; }; }; + CryptURandomMonkeyPatch = buildPerlPackage { + pname = "Crypt-URandom-MonkeyPatch"; + version = "0.1.4"; + src = fetchurl { + url = "mirror://cpan/authors/id/R/RR/RRWO/Crypt-URandom-MonkeyPatch-v0.1.4.tar.gz"; + hash = "sha256-eydufcxL7TnZW/+dnTemlTkycVaPTarMrFBowLQcKsk="; + }; + buildInputs = [ TestOutput ]; + propagatedBuildInputs = [ CryptURandom ]; + meta = { + description = "Override core rand function to use system random sources"; + license = lib.licenses.artistic2; + }; + }; + CryptScryptKDF = buildPerlModule { pname = "Crypt-ScryptKDF"; - version = "0.010"; + version = "0.011"; src = fetchurl { - url = "mirror://cpan/authors/id/M/MI/MIK/Crypt-ScryptKDF-0.010.tar.gz"; - hash = "sha256-fRbulczj61TBdGc6cpn0wIb7o6yF+EfQ4TT+7V93YBc="; + url = "mirror://cpan/authors/id/M/MI/MIK/Crypt-ScryptKDF-0.011.tar.gz"; + hash = "sha256-IZLJ8E8rX/cHN/XNrz9PZ6VXE8MeoIVAOMvzXjttFrQ="; }; - propagatedBuildInputs = [ CryptOpenSSLRandom ]; + propagatedBuildInputs = [ + CryptOpenSSLRandom + CryptX + ]; meta = { description = "Scrypt password based key derivation function"; homepage = "https://github.com/DCIT/perl-Crypt-ScryptKDF"; @@ -7748,15 +7833,19 @@ with self; }; }; - CryptPBKDF2 = buildPerlPackage { + CryptPBKDF2 = buildPerlModule { pname = "Crypt-PBKDF2"; - version = "0.161520"; + version = "0.261630"; src = fetchurl { - url = "mirror://cpan/authors/id/A/AR/ARODLAND/Crypt-PBKDF2-0.161520.tar.gz"; - hash = "sha256-l9+nmjCaCG4YSk5hBH+KEP+z2wUQJefSIqJfGRMLpBc="; + url = "mirror://cpan/authors/id/A/AR/ARODLAND/Crypt-PBKDF2-0.261630.tar.gz"; + hash = "sha256-GHVxiWOJMrMJs0xFu4EKo+SFbj7VgBAAF9reZXk/RsA="; }; - buildInputs = [ TestFatal ]; + buildInputs = [ + ModuleBuildTiny + TestFatal + ]; propagatedBuildInputs = [ + CryptURandom DigestHMAC DigestSHA3 Moo @@ -7896,10 +7985,10 @@ with self; CSSMinifierXS = buildPerlPackage { pname = "CSS-Minifier-XS"; - version = "0.13"; + version = "0.15"; src = fetchurl { - url = "mirror://cpan/authors/id/G/GT/GTERMARS/CSS-Minifier-XS-0.13.tar.gz"; - hash = "sha256-xBnjCM3IKvHCXWuNB7L/JjR6Yit6Y+wghWq+jbQFH4I="; + url = "mirror://cpan/authors/id/G/GT/GTERMARS/CSS-Minifier-XS-0.15.tar.gz"; + hash = "sha256-iprSIxYtpGceP4EsSlXyl3OUg70xar2kH0wn6K3XhVM="; }; buildInputs = [ TestDiagINC ]; meta = { @@ -8157,16 +8246,16 @@ with self; DataEntropy = buildPerlPackage { pname = "Data-Entropy"; - version = "0.008"; + version = "0.010"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RR/RRWO/Data-Entropy-0.008.tar.gz"; - hash = "sha256-GKUrE4boLGuM2zhKOYYdYCIKRCp5DgdwEL5y3YU7Z7M="; + url = "mirror://cpan/authors/id/R/RR/RRWO/Data-Entropy-0.010.tar.gz"; + hash = "sha256-0M8s2wKCAuidw2K42Qtw00WFApOwGQDZoYgqDG8g+Dc="; }; propagatedBuildInputs = [ CryptRijndael CryptURandom DataFloat - HTTPLite + DevelDeprecate ParamsClassify ]; meta = { @@ -9604,6 +9693,24 @@ with self; }; }; + DevelDeprecate = buildPerlPackage { + pname = "Devel-Deprecate"; + version = "0.01"; + src = fetchurl { + url = "mirror://cpan/authors/id/O/OV/OVID/Devel-Deprecate-0.01.tar.gz"; + hash = "sha256-xQLEGoL+JU6XFRJ3ytOk8KQHrTydP2I9J3sDA6PhoS8="; + }; + buildInputs = [ SubOverride ]; + propagatedBuildInputs = [ DateTime ]; + meta = { + description = "Create deprecation schedules in your code"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + DevelDeprecationsEnvironmental = buildPerlPackage { pname = "Devel-Deprecations-Environmental"; version = "1.101"; @@ -10044,11 +10151,11 @@ with self; DBI = buildPerlPackage { pname = "DBI"; - version = "1.648"; + version = "1.653"; src = fetchurl { - url = "mirror://cpan/authors/id/H/HM/HMBRAND/DBI-1.648.tgz"; - hash = "sha256-7yZqrWAQzi6rt+Rl69c8owILxYFQ9pib2Jwrj5usaoY="; + url = "mirror://cpan/authors/id/H/HM/HMBRAND/DBI-1.653.tgz"; + hash = "sha256-qYwh/Tfu2PhBFyh10XXZcv6H8GPX0NKjt3ZZCLsl61g="; }; env = lib.optionalAttrs stdenv.cc.isGNU { @@ -11036,6 +11143,31 @@ with self; }; }; + DistBuild = buildPerlModule { + pname = "Dist-Build"; + version = "0.028"; + src = fetchurl { + url = "mirror://cpan/authors/id/L/LE/LEONT/Dist-Build-0.028.tar.gz"; + hash = "sha256-JPFLFA4Tq3x1PU25bI0zbQnepcb1H+1IvA92Khyhgx8="; + }; + propagatedBuildInputs = [ + ExtUtilsBuilder + ExtUtilsBuilderCompiler + ExtUtilsConfig + ExtUtilsHelpers + ExtUtilsInstallPaths + ]; + meta = { + changelog = "https://github.com/Leont/dist-build/blob/v0.028/Changes"; + description = "Modern module builder, author tools not included"; + homepage = "https://github.com/Leont/dist-build"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + DistributionMetadata = buildPerlModule { pname = "Distribution-Metadata"; version = "0.10"; @@ -12584,6 +12716,48 @@ with self; }; }; + ExtUtilsBuilder = buildPerlPackage { + pname = "ExtUtils-Builder"; + version = "0.020"; + src = fetchurl { + url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Builder-0.020.tar.gz"; + hash = "sha256-UtZR46oDJyUOR5h9Rf9I6cyQtbe9L7D/P3h4PlMq/8w="; + }; + propagatedBuildInputs = [ + ExtUtilsConfig + ExtUtilsHelpers + ]; + meta = { + description = "Abstract representation of build processes"; + homepage = "https://github.com/Leont/extutils-builder-plan"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + + ExtUtilsBuilderCompiler = buildPerlPackage { + pname = "ExtUtils-Builder-Compiler"; + version = "0.037"; + src = fetchurl { + url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Builder-Compiler-0.037.tar.gz"; + hash = "sha256-s5VNaI45gDkoUnkWfG6+7nVX8Q6VYBzj/baBkyY2h7g="; + }; + propagatedBuildInputs = [ + ExtUtilsBuilder + ExtUtilsConfig + ]; + meta = { + description = "Interface around different compilers"; + homepage = "https://github.com/Leont/extutils-builder-compiler"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + ExtUtilsCChecker = buildPerlModule { pname = "ExtUtils-CChecker"; version = "0.11"; @@ -12603,10 +12777,10 @@ with self; ExtUtilsConfig = buildPerlPackage { pname = "ExtUtils-Config"; - version = "0.008"; + version = "0.010"; src = fetchurl { - url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Config-0.008.tar.gz"; - hash = "sha256-rlEE9jRlDc6KebftE/tZ1no5whOmd2z9qj7nSeYvGow="; + url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Config-0.010.tar.gz"; + hash = "sha256-gufk6Qy+OA4VL13m4+QDdGmC1QLdMBl6EjZS5GYQxm0="; }; meta = { description = "Wrapper for perl's configuration"; @@ -12694,10 +12868,10 @@ with self; ExtUtilsHelpers = buildPerlPackage { pname = "ExtUtils-Helpers"; - version = "0.026"; + version = "0.028"; src = fetchurl { - url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Helpers-0.026.tar.gz"; - hash = "sha256-3pAbZ5CkVXz07JCBSeA1eDsSW/EV65ZA/rG8HCTDNBY="; + url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Helpers-0.028.tar.gz"; + hash = "sha256-yFdIdczgc+fcU0WnsG1QLlIETWiJT5FgID/KqzeVFP4="; }; meta = { description = "Various portability utilities for module builders"; @@ -13478,14 +13652,11 @@ with self; FileFindRule = buildPerlPackage { pname = "File-Find-Rule"; - version = "0.34"; + version = "0.35"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RC/RCLAMP/File-Find-Rule-0.34.tar.gz"; - hash = "sha256-fm8WzDPrHyn/Jb7lHVE/S4qElHu/oY7bLTzECi1kyv4="; + url = "mirror://cpan/authors/id/R/RC/RCLAMP/File-Find-Rule-0.35.tar.gz"; + hash = "sha256-K9VWKJptRK0u50gDJYuwsAUNJG8egcqrCyY8MDrPDII="; }; - patches = [ - ../development/perl-modules/FileFindRule-CVE-2011-10007.patch - ]; propagatedBuildInputs = [ NumberCompare TextGlob @@ -14667,10 +14838,10 @@ with self; GD = buildPerlPackage { pname = "GD"; - version = "2.78"; + version = "2.86"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RU/RURBAN/GD-2.78.tar.gz"; - hash = "sha256-aDEFS/VCS09cI9NifT0UhEgPb5wsZmMiIpFfKFG+buQ="; + url = "mirror://cpan/authors/id/R/RU/RURBAN/GD-2.86.tar.gz"; + hash = "sha256-bWTTvhQpzB606IqPICL+yRDqPgeS2k/ljT7fdpXEbKI="; }; nativeBuildInputs = [ @@ -14685,6 +14856,7 @@ with self; pkgs.fontconfig pkgs.libxpm ExtUtilsPkgConfig + FileWhich TestFork TestNoWarnings ]; @@ -14739,7 +14911,16 @@ with self; url = "mirror://cpan/authors/id/B/BU/BURAK/GD-SecurityImage-1.75.tar.gz"; hash = "sha256-Pd4k2ay6lRzd5bVp0eQsrZRs/bUSgORGnzNv1f4MjqY="; }; - propagatedBuildInputs = [ GD ]; + patches = [ + (fetchpatch { + url = "https://security.metacpan.org/patches/G/GD-SecurityImage/1.75/CVE-2026-13082-r1.patch"; + hash = "sha256-xIMPQD2JYuHdsYnW1ojqG3xgV7VWEKyJ6sEqNRUdNdQ="; + }) + ]; + propagatedBuildInputs = [ + CryptURandomMonkeyPatch + GD + ]; meta = { description = "Security image (captcha) generator"; license = with lib.licenses; [ @@ -16139,6 +16320,12 @@ with self; url = "mirror://cpan/authors/id/C/CF/CFRANKS/HTML-FormFu-2.07.tar.gz"; hash = "sha256-Ty8Bf3qHVPu26RIGyI7RPHVqFOO+oXgYjDuXdGNm6zI="; }; + patches = [ + (fetchpatch { + url = "https://security.metacpan.org/patches/H/HTML-FormFu/2.08/CVE-2026-19873-r1.patch"; + hash = "sha256-1QquxDl/NuNJe6MFbeEH49hYA8agXXeWm1Q23fOM+Nc="; + }) + ]; buildInputs = [ CGI FileShareDirInstall @@ -16200,19 +16387,18 @@ with self; HTMLFormHandler = buildPerlPackage { pname = "HTML-FormHandler"; - version = "0.40068"; + version = "0.410002"; src = fetchurl { - url = "mirror://cpan/authors/id/G/GS/GSHANK/HTML-FormHandler-0.40068.tar.gz"; - hash = "sha256-63t43aMSV1LMi8wDltOXf70o2jPS1ExQQq1tNdbN6Cc="; + url = "mirror://cpan/authors/id/A/AB/ABRAXXA/HTML-FormHandler-0.410002.tar.gz"; + hash = "sha256-wT3n5PLDmV5QR1xilSm2VM+eLGJ73WLifqSMfG1jqeU="; }; - # a single test is failing on perl 5.20 - doCheck = false; buildInputs = [ FileShareDirInstall PadWalker TestDifferences TestException TestMemoryCycle + TestNeeds TestWarn ]; propagatedBuildInputs = [ @@ -16239,10 +16425,10 @@ with self; HTMLGumbo = buildPerlModule { pname = "HTML-Gumbo"; - version = "0.18"; + version = "0.20"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RU/RUZ/HTML-Gumbo-0.18.tar.gz"; - hash = "sha256-v1C2HCRlbMP8lYYC2AqcfQFyR6842Nv6Dp3sW3VCXV8="; + url = "mirror://cpan/authors/id/B/BP/BPS/HTML-Gumbo-0.20.tar.gz"; + hash = "sha256-ImEK+8bIfgZ92E9/EZo9J4Ie1kEwNFU8Ga694iEdiDU="; }; propagatedBuildInputs = [ AlienLibGumbo ]; meta = { @@ -16303,10 +16489,10 @@ with self; HTMLParser = buildPerlPackage { pname = "HTML-Parser"; - version = "3.81"; + version = "3.85"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/HTML-Parser-3.81.tar.gz"; - hash = "sha256-wJEKXI+S+IF+3QbM/SJLocLr6MEPVR8DJYeh/IPWL/I="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/HTML-Parser-3.85.tar.gz"; + hash = "sha256-/UK6ar4HJBzwrVe+JGw5gAZfaD5EZeWbRq+e/ryODHE="; }; propagatedBuildInputs = [ HTMLTagset @@ -16771,10 +16957,10 @@ with self; HTTPDate = buildPerlPackage { pname = "HTTP-Date"; - version = "6.06"; + version = "6.08"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Date-6.06.tar.gz"; - hash = "sha256-e2hRkcasw+dz0fwCyV7h+frpT3d4MXX154wYHMktK1I="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Date-6.08.tar.gz"; + hash = "sha256-tX2Aym2CHGlJykiydGfUWrp6nHc0ZWIwb6zKeBoAPkQ="; }; propagatedBuildInputs = [ TimeDate ]; meta = { @@ -16901,10 +17087,10 @@ with self; HTTPMessage = buildPerlPackage { pname = "HTTP-Message"; - version = "6.45"; + version = "7.02"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Message-6.45.tar.gz"; - hash = "sha256-AcuEBmEqP3OIQtHpcxOuTYdIcNG41tZjMfFgAJQ9TL4="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Message-7.02.tar.gz"; + hash = "sha256-eKvvHYMxRrSNF9shmxsD1Ty743oozNrQ79zFgzylxgw="; }; buildInputs = [ TestNeeds @@ -16912,8 +17098,11 @@ with self; ]; propagatedBuildInputs = [ Clone + CompressRawBzip2 + CompressRawZlib EncodeLocale HTTPDate + IOCompress IOHTML LWPMediaTypes URI @@ -17198,26 +17387,11 @@ with self; Imager = buildPerlPackage rec { pname = "Imager"; - version = "1.034"; + version = "1.035"; src = fetchurl { url = "mirror://cpan/authors/id/T/TO/TONYC/Imager-${version}.tar.gz"; - hash = "sha256-hrWizXGna4QJJJFSGl1WI4Qo8sN1AYMsmVxaMxJg+AM="; + hash = "sha256-W6BYrMmLtb+QK6/XTNKwepS7GVrmYWxEC1RwFIBv6xc="; }; - # Remove when updating to the first release containing both fixes. - patches = [ - (fetchpatch2 { - name = "fix-32-bit-exif-ifd-offset-checks.patch"; - url = "https://github.com/tonycoz/imager/commit/48ba8ac0749f89466b6e6681fb88cbdb51086ebd.patch?full_index=1"; - includes = [ "imexif.c" ]; - hash = "sha256-rpUeTsgSkCdzJsy3Ny0rU+KNL6xkSosfkDqzFb813Wo="; - }) - (fetchpatch2 { - name = "fix-32-bit-exif-limit-checks.patch"; - url = "https://github.com/tonycoz/imager/commit/6f1fd003a8e48c7e6e58b7019a04cc71bbfec2c3.patch?full_index=1"; - includes = [ "imexif.c" ]; - hash = "sha256-Ct7T/JHuxAIAjjuzoUhdAPlp0qPYKRQQqejsrcGXPko="; - }) - ]; buildInputs = [ pkgs.freetype pkgs.fontconfig @@ -17579,10 +17753,10 @@ with self; IOCompress = buildPerlPackage { pname = "IO-Compress"; - version = "2.220"; + version = "2.221"; src = fetchurl { - url = "mirror://cpan/authors/id/P/PM/PMQS/IO-Compress-2.220.tar.gz"; - hash = "sha256-nZbqKR8sVO82fHOWuFfZO6GsHEsvG84T7Yo+Xz7rtic="; + url = "mirror://cpan/authors/id/P/PM/PMQS/IO-Compress-2.221.tar.gz"; + hash = "sha256-r0LJyRBK3313LSVcDZpASjRi6kXnvELQbaCgtR3j0K4="; }; propagatedBuildInputs = [ CompressRawBzip2 @@ -18504,12 +18678,11 @@ with self; JSONXS = buildPerlPackage { pname = "JSON-XS"; - version = "4.03"; + version = "4.04"; src = fetchurl { - url = "mirror://cpan/authors/id/M/ML/MLEHMANN/JSON-XS-4.03.tar.gz"; - hash = "sha256-UVU29F8voafojIgkUzdY0BIdJnq5y0U6G1iHyKVrkGg="; + url = "mirror://cpan/authors/id/M/ML/MLEHMANN/JSON-XS-4.04.tar.gz"; + hash = "sha256-jv8enzBMViW1mre0IlhBX20+NoHB3atrclUYoBin9eA="; }; - patches = [ ../development/perl-modules/JSON-XS-CVE-2025-40928.patch ]; propagatedBuildInputs = [ TypesSerialiser ]; buildInputs = [ CanaryStability ]; meta = { @@ -18817,10 +18990,10 @@ with self; libwwwperl = buildPerlPackage { pname = "libwww-perl"; - version = "6.72"; + version = "6.83"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.72.tar.gz"; - hash = "sha256-6bg1T9XiC+IHr+I93VhPzVm/gpmNwHfez2hLodrloF0="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.83.tar.gz"; + hash = "sha256-518PqdPG8Nr1pacvqfixycDSPjqEqFIsy0+DUjK5VQU="; }; buildInputs = [ HTTPDaemon @@ -20074,10 +20247,10 @@ with self; LWP = buildPerlPackage { pname = "libwww-perl"; - version = "6.72"; + version = "6.83"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.72.tar.gz"; - hash = "sha256-6bg1T9XiC+IHr+I93VhPzVm/gpmNwHfez2hLodrloF0="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.83.tar.gz"; + hash = "sha256-518PqdPG8Nr1pacvqfixycDSPjqEqFIsy0+DUjK5VQU="; }; propagatedBuildInputs = [ FileListing @@ -22705,10 +22878,10 @@ with self; Mojolicious = buildPerlPackage { pname = "Mojolicious"; - version = "9.39"; + version = "9.48"; src = fetchurl { - url = "mirror://cpan/authors/id/S/SR/SRI/Mojolicious-9.39.tar.gz"; - hash = "sha256-EwpJDXfXYTn3NM4biU1Fm64DgF+x89/dWPxE/oKvPP0="; + url = "mirror://cpan/authors/id/S/SR/SRI/Mojolicious-9.48.tar.gz"; + hash = "sha256-Jv8EFSgR/VsaNrR9mewhnFiZW6jnsVugKzPQdwpe7pg="; }; meta = { description = "Real-time web framework"; @@ -23070,13 +23243,16 @@ with self; MojoJWT = buildPerlModule { pname = "Mojo-JWT"; - version = "0.09"; + version = "1.02"; src = fetchurl { - url = "mirror://cpan/authors/id/J/JB/JBERGER/Mojo-JWT-0.09.tar.gz"; - hash = "sha256-wE4DmD4MbyvORdCOoucph5yWee+mNLDmjLa4t7SoWIY="; + url = "mirror://cpan/authors/id/J/JB/JBERGER/Mojo-JWT-1.02.tar.gz"; + hash = "sha256-yBHXkoWMJBFQNyDxJDbjNDZ0k2dUO/vCqV1PgDzmCHQ="; }; buildInputs = [ ModuleBuildTiny ]; - propagatedBuildInputs = [ Mojolicious ]; + propagatedBuildInputs = [ + CryptX + Mojolicious + ]; meta = { description = "JSON Web Token the Mojo way"; homepage = "https://github.com/jberger/Mojo-JWT"; @@ -25529,10 +25705,10 @@ with self; NetDNS = buildPerlPackage { pname = "Net-DNS"; - version = "1.56"; + version = "1.57"; src = fetchurl { - url = "mirror://cpan/authors/id/N/NL/NLNETLABS/Net-DNS-1.56.tar.gz"; - hash = "sha256-WTDjn3aJWzgMfKEfwINS0VrXHEH+hMEt+2oyLRf2aUY="; + url = "mirror://cpan/authors/id/N/NL/NLNETLABS/Net-DNS-1.57.tar.gz"; + hash = "sha256-fJjeMpy11qmau7A6qtKGbLBBCS7Zk2pyRpCOFwAFsFg="; }; propagatedBuildInputs = [ DigestHMAC ]; makeMakerFlags = [ "--noonline-tests" ]; @@ -26404,10 +26580,10 @@ with self; NetStatsd = buildPerlPackage { pname = "Net-Statsd"; - version = "0.12"; + version = "0.13"; src = fetchurl { - url = "mirror://cpan/authors/id/C/CO/COSIMO/Net-Statsd-0.12.tar.gz"; - hash = "sha256-Y+RTYD2hZbxtHEygtV7aPSIE8EDFkwSkd4LFqniGVlw="; + url = "mirror://cpan/authors/id/C/CO/COSIMO/Net-Statsd-0.13.tar.gz"; + hash = "sha256-xKYP9dP002ompqR3YxGI7HnNzp4wUMZ6NOm1rikgoQA="; }; meta = { description = "Perl client for Etsy's statsd daemon"; @@ -28577,12 +28753,13 @@ with self; PlackMiddlewareSession = buildPerlModule { pname = "Plack-Middleware-Session"; - version = "0.33"; + version = "0.36"; src = fetchurl { - url = "mirror://cpan/authors/id/M/MI/MIYAGAWA/Plack-Middleware-Session-0.33.tar.gz"; - hash = "sha256-T/miydGK2ASbRd/ze5vdQSIeLC8eFrr7gb/tyIxRpO4="; + url = "mirror://cpan/authors/id/M/MI/MIYAGAWA/Plack-Middleware-Session-0.36.tar.gz"; + hash = "sha256-kqWDFliBDSNzLm47rnpEofpafYpqbm3NdbkcapwktGY="; }; propagatedBuildInputs = [ + CryptSysRandom DigestHMAC Plack ]; @@ -29137,10 +29314,10 @@ with self; ProtocolHTTP2 = buildPerlModule { pname = "Protocol-HTTP2"; - version = "1.11"; + version = "1.14"; src = fetchurl { - url = "mirror://cpan/authors/id/C/CR/CRUX/Protocol-HTTP2-1.11.tar.gz"; - hash = "sha256-Vp8Fsavpl7UHyCUVMMyB0e6WvZMsxoJTS2zkhlNQCRM="; + url = "mirror://cpan/authors/id/C/CR/CRUX/Protocol-HTTP2-1.14.tar.gz"; + hash = "sha256-pT8n6i+6wVakzUmB2O90nBvvNmwpCRNLTTHaIWRLSW4="; }; buildInputs = [ AnyEvent @@ -30581,10 +30758,10 @@ with self; SerealDecoder = buildPerlPackage { pname = "Sereal-Decoder"; - version = "5.004"; + version = "5.006"; src = fetchurl { - url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Decoder-5.004.tar.gz"; - hash = "sha256-aO8DFNh9Gm5guw9m/PQ+ssrN6xdUQy9eJeeE450+Z4Q="; + url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Decoder-5.006.tar.gz"; + hash = "sha256-eZGFXpGBo3nJsBIv6PwvaONEnJFhaow1eSbxFh9oR2g="; }; buildInputs = [ TestDeep @@ -30606,10 +30783,10 @@ with self; SerealEncoder = buildPerlPackage { pname = "Sereal-Encoder"; - version = "5.004"; + version = "5.006"; src = fetchurl { - url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Encoder-5.004.tar.gz"; - hash = "sha256-XlqGzNMtrjTtgJMuy+XGjil1K13g6bCnk6t+sspVyxs="; + url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Encoder-5.006.tar.gz"; + hash = "sha256-kLQsyHdZgq4MdJno9ZLOeu+ug0M1g+EKWtVxKBHRcK0="; }; buildInputs = [ SerealDecoder @@ -30631,10 +30808,10 @@ with self; Sereal = buildPerlPackage { pname = "Sereal"; - version = "5.004"; + version = "5.006"; src = fetchurl { - url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-5.004.tar.gz"; - hash = "sha256-nCW7euS9c20ksa0dk9dzlbDGXKh0HiZr/Ay+VCJh128="; + url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-5.006.tar.gz"; + hash = "sha256-uwXnY+1ry+pEx5IX/vCy05GKwVRxlHIwOMbER+5vWd4="; }; buildInputs = [ TestDeep @@ -31408,10 +31585,10 @@ with self; Starlet = buildPerlPackage { pname = "Starlet"; - version = "0.31"; + version = "0.32"; src = fetchurl { - url = "mirror://cpan/authors/id/K/KA/KAZUHO/Starlet-0.31.tar.gz"; - hash = "sha256-uWA7jmKIDLRYL2p5Oer+xl5u/T2QDyx900Ll9MaNYtg="; + url = "mirror://cpan/authors/id/K/KA/KAZUHO/Starlet-0.32.tar.gz"; + hash = "sha256-gZI9OmCX3YHH4Og9SBvuof89ZejgHY0f59yziFV1vY8="; }; buildInputs = [ LWP @@ -32032,14 +32209,13 @@ with self; }; }; - StringUtil = buildPerlModule { + StringUtil = buildPerlPackage { pname = "String-Util"; - version = "1.34"; + version = "1.36"; src = fetchurl { - url = "mirror://cpan/authors/id/B/BA/BAKERSCOT/String-Util-1.34.tar.gz"; - hash = "sha256-MZzozWZTQeVlIfoVXZYqGTKOkNn3A2dlklzN4mclxGk="; + url = "mirror://cpan/authors/id/B/BA/BAKERSCOT/String-Util-1.36.tar.gz"; + hash = "sha256-UXsasyVm/U1ei+I9mTOc47/+4pEsX/KfXclYcP9Pyw4="; }; - buildInputs = [ ModuleBuildTiny ]; meta = { description = "String processing utility functions"; homepage = "https://github.com/scottchiefbaker/String-Util"; @@ -38792,10 +38968,10 @@ with self; XMLLibXML = buildPerlPackage { pname = "XML-LibXML"; - version = "2.0210"; + version = "2.0213"; src = fetchurl { - url = "mirror://cpan/authors/id/S/SH/SHLOMIF/XML-LibXML-2.0210.tar.gz"; - hash = "sha256-opvz8Aq5ye4EIYFU4K/I95m/I2dOuZwantTeH0BZpI0="; + url = "mirror://cpan/authors/id/T/TO/TODDR/XML-LibXML-2.0213.tar.gz"; + hash = "sha256-KvIcXWGsNOompfq/FbpaWEHmSPcYnbPjO28otUiYAqs="; }; env.SKIP_SAX_INSTALL = 1; buildInputs = [ @@ -38809,10 +38985,6 @@ with self; zlib ] ); - patches = [ - # https://github.com/shlomif/perl-XML-LibXML/pull/87 - ../development/perl-modules/XML-LibXML-fix-tests-libxml-2.13.0.patch - ]; propagatedBuildInputs = [ XMLSAX ]; meta = { description = "Perl Binding for libxml2"; @@ -39196,10 +39368,10 @@ with self; XMLTwig = buildPerlPackage { pname = "XML-Twig"; - version = "3.52"; + version = "3.54"; src = fetchurl { - url = "mirror://cpan/authors/id/M/MI/MIROD/XML-Twig-3.52.tar.gz"; - hash = "sha256-/vdYJsJPK4d9Cg0mRSEvxPuXVu1NJxFhSsFcSX6GgK0="; + url = "mirror://cpan/authors/id/M/MI/MIROD/XML-Twig-3.54.tar.gz"; + hash = "sha256-C3RKlzegcPlcMhVK/VJr9evnaln+uLwfXbxs2qXg5Sk="; }; postInstall = '' mkdir -p $out/bin @@ -39407,11 +39579,12 @@ with self; YAMLLibYAML = buildPerlPackage { pname = "YAML-LibYAML"; - version = "0.89"; + version = "0.907.0"; src = fetchurl { - url = "mirror://cpan/authors/id/T/TI/TINITA/YAML-LibYAML-0.89.tar.gz"; - hash = "sha256-FVq4NnU0XFCt0DMRrPndkVlVcH+Qmiq9ixfXeShZsuw="; + url = "mirror://cpan/authors/id/T/TI/TINITA/YAML-LibYAML-v0.907.0.tar.gz"; + hash = "sha256-a6CHIkkROJ52+hmLFJzsg/BlsKx13cUmGPNJCULNlQY="; }; + buildInputs = [ TestWarnings ]; meta = { description = "Perl YAML Serialization using XS and libyaml"; license = with lib.licenses; [ @@ -39457,6 +39630,11 @@ with self; MojoliciousPluginOpenAPI RoleTiny ]; + # Mojolicious 9.48 enforces CSRF token validation (CVE-2026-15747); these + # tests drive forms without a token and fail with 400 "CSRF token failure". + preCheck = '' + rm t/plugin/auth/github.t t/plugin/form/bootstrap4.t + ''; meta = { homepage = "http://preaction.me/yancy/"; description = "Best Web Framework Deserves the Best CMS";