From dc60daf249f86b896aaab79b5b5d344a77dd82f3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Fri, 11 Sep 2026 08:51:50 -0700 Subject: [PATCH 001/110] python3Packages.pyjwt: 2.13.0 -> 2.14.0 Diff: https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0 Changelog: https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst (cherry picked from commit 70a62b6872a488804d7f63ff8e310f56d9a0b8ad) --- pkgs/development/python-modules/pyjwt/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/pyjwt/default.nix b/pkgs/development/python-modules/pyjwt/default.nix index 74754630a145..ae8a5353a84d 100644 --- a/pkgs/development/python-modules/pyjwt/default.nix +++ b/pkgs/development/python-modules/pyjwt/default.nix @@ -13,14 +13,14 @@ buildPythonPackage rec { pname = "pyjwt"; - version = "2.13.0"; + version = "2.14.0"; pyproject = true; src = fetchFromGitHub { owner = "jpadilla"; repo = "pyjwt"; tag = version; - hash = "sha256-q4ynXCJVDsyZh70439dloyWgRTLVm+elDOahUVOT5vA="; + hash = "sha256-SxJ2GQt1pfm8iAeTB2RmH2kliGeQ6whkM5nuesI1s/U="; }; outputs = [ From 03f28d01ac8d8ba7cba1c01ca9d641c07808d7ec Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Fri, 11 Sep 2026 08:54:39 -0700 Subject: [PATCH 002/110] python3Packages.pyjwt: use finalAttrs (cherry picked from commit 409bbcafb75e03c239eea5364254d736ed1bac5b) --- pkgs/development/python-modules/pyjwt/default.nix | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/pkgs/development/python-modules/pyjwt/default.nix b/pkgs/development/python-modules/pyjwt/default.nix index ae8a5353a84d..d1267cf08628 100644 --- a/pkgs/development/python-modules/pyjwt/default.nix +++ b/pkgs/development/python-modules/pyjwt/default.nix @@ -11,7 +11,7 @@ oauthlib, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "pyjwt"; version = "2.14.0"; pyproject = true; @@ -19,7 +19,7 @@ buildPythonPackage rec { src = fetchFromGitHub { owner = "jpadilla"; repo = "pyjwt"; - tag = version; + tag = finalAttrs.version; hash = "sha256-SxJ2GQt1pfm8iAeTB2RmH2kliGeQ6whkM5nuesI1s/U="; }; @@ -38,7 +38,10 @@ buildPythonPackage rec { optional-dependencies.crypto = [ cryptography ]; - nativeCheckInputs = [ pytestCheckHook ] ++ (lib.concatAttrValues optional-dependencies); + nativeCheckInputs = [ + pytestCheckHook + ] + ++ (lib.concatAttrValues finalAttrs.passthru.optional-dependencies); disabledTests = [ # requires internet connection @@ -52,10 +55,10 @@ buildPythonPackage rec { }; meta = { - changelog = "https://github.com/jpadilla/pyjwt/blob/${version}/CHANGELOG.rst"; + changelog = "https://github.com/jpadilla/pyjwt/blob/${finalAttrs.src.tag}/CHANGELOG.rst"; description = "JSON Web Token implementation in Python"; homepage = "https://github.com/jpadilla/pyjwt"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ prikhi ]; }; -} +}) From 3692fe63c183d50cf4468b8bf766ceded4674461 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 003/110] llvmPackages_{18,19,20,21,22}.libllvm: backport Darwin triple parsing MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This fixes breakage on triples for macOS 27, which aligned the Darwin version with the OS version (darwin26 is macOS 27, but so is darwin27, which will be incorrectly interpreted as macOS 28 without this patch). This is probably harmless in most cases, but it causes a test failure in LLVM’s test suite when running under macOS 27. (cherry picked from commit 6fb7a4dc0c9ba446ba0968bd046601a2e5903571) --- .../llvm/backport-darwin-triple-parsing.patch | 34 +++++++++++++++++++ .../llvm/backport-darwin-triple-parsing.patch | 31 +++++++++++++++++ .../compilers/llvm/common/llvm/default.nix | 9 ++++- .../compilers/llvm/common/patches.nix | 11 ++++++ 4 files changed, 84 insertions(+), 1 deletion(-) create mode 100644 pkgs/development/compilers/llvm/18/llvm/backport-darwin-triple-parsing.patch create mode 100644 pkgs/development/compilers/llvm/21/llvm/backport-darwin-triple-parsing.patch diff --git a/pkgs/development/compilers/llvm/18/llvm/backport-darwin-triple-parsing.patch b/pkgs/development/compilers/llvm/18/llvm/backport-darwin-triple-parsing.patch new file mode 100644 index 000000000000..9426f99512b7 --- /dev/null +++ b/pkgs/development/compilers/llvm/18/llvm/backport-darwin-triple-parsing.patch @@ -0,0 +1,34 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Tue, 11 Aug 2026 20:12:42 -0400 +Subject: [PATCH] backport-darwin-triple-parsing + +--- + lib/TargetParser/Triple.cpp | 10 ++++++++-- + 1 file changed, 8 insertions(+), 2 deletions(-) + +diff --git a/lib/TargetParser/Triple.cpp b/lib/TargetParser/Triple.cpp +index 0bbe8a3cedfd..4143c3eac05d 100644 +--- a/lib/TargetParser/Triple.cpp ++++ b/lib/TargetParser/Triple.cpp +@@ -1253,9 +1253,15 @@ bool Triple::getMacOSXVersion(VersionTuple &Version) const { + } + if (Version.getMajor() <= 19) { + Version = VersionTuple(10, Version.getMajor() - 4); +- } else { +- // darwin20+ corresponds to macOS 11+. ++ } else if (Version.getMajor() < 25) { ++ // darwin20-24 corresponds to macOS 11-15. + Version = VersionTuple(11 + Version.getMajor() - 20); ++ } else if ((Version.getMajor() == 25) || (Version.getMajor() == 26)) { ++ // darwin25-26 corresponds to macOS 26-27. ++ Version = VersionTuple(Version.getMajor() + 1); ++ } else { ++ // Starting with darwin27, it naturally corresponds to the same macOS ++ // version. + } + break; + case MacOSX: +-- +2.54.0 + diff --git a/pkgs/development/compilers/llvm/21/llvm/backport-darwin-triple-parsing.patch b/pkgs/development/compilers/llvm/21/llvm/backport-darwin-triple-parsing.patch new file mode 100644 index 000000000000..7f2cc06b51d4 --- /dev/null +++ b/pkgs/development/compilers/llvm/21/llvm/backport-darwin-triple-parsing.patch @@ -0,0 +1,31 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Tue, 11 Aug 2026 20:19:29 -0400 +Subject: [PATCH] backport-darwin-triple-parsing + +--- + lib/TargetParser/Triple.cpp | 7 +++++-- + 1 file changed, 5 insertions(+), 2 deletions(-) + +diff --git a/lib/TargetParser/Triple.cpp b/lib/TargetParser/Triple.cpp +index 0584c941d2e6..30cf78dbaabc 100644 +--- a/lib/TargetParser/Triple.cpp ++++ b/lib/TargetParser/Triple.cpp +@@ -1449,9 +1449,12 @@ bool Triple::getMacOSXVersion(VersionTuple &Version) const { + } else if (Version.getMajor() < 25) { + // darwin20-24 corresponds to macOS 11-15. + Version = VersionTuple(11 + Version.getMajor() - 20); +- } else { +- // darwin25 corresponds with macOS26+. ++ } else if ((Version.getMajor() == 25) || (Version.getMajor() == 26)) { ++ // darwin25-26 corresponds to macOS 26-27. + Version = VersionTuple(Version.getMajor() + 1); ++ } else { ++ // Starting with darwin27, it naturally corresponds to the same macOS ++ // version. + } + break; + case MacOSX: +-- +2.54.0 + diff --git a/pkgs/development/compilers/llvm/common/llvm/default.nix b/pkgs/development/compilers/llvm/common/llvm/default.nix index d5dcd4d58cce..222f7fb6e54d 100644 --- a/pkgs/development/compilers/llvm/common/llvm/default.nix +++ b/pkgs/development/compilers/llvm/common/llvm/default.nix @@ -222,7 +222,14 @@ stdenv.mkDerivation ( hash = "sha256-3hkbYPUVRAtWpo5qBmc2jLZLivURMx8T0GQomvNZesc="; stripLen = 1; } - ); + ) + ++ lib.optionals (lib.versionOlder release_version "23") [ + # As of macOS 27 (and iOS 27, etc), the Darwin version number is the same as the OS version number. + # This change breaks target parsing because `darwin27` is incorrectly interpreted as macOS 28. + # This patch is a backport of the target parsing changes in LLVM 23, which fixes the problem. + # Hopefully, Apple does not change the version number scheme again any time soon. + (getVersionFile "llvm/backport-darwin-triple-parsing.patch") + ]; nativeBuildInputs = [ cmake diff --git a/pkgs/development/compilers/llvm/common/patches.nix b/pkgs/development/compilers/llvm/common/patches.nix index 76ae90c3aaa7..5ea9faa3d2e2 100644 --- a/pkgs/development/compilers/llvm/common/patches.nix +++ b/pkgs/development/compilers/llvm/common/patches.nix @@ -20,6 +20,17 @@ path = ../18; } ]; + "llvm/backport-darwin-triple-parsing.patch" = [ + { + after = "18"; + before = "21"; + path = ../18; + } + { + after = "21"; + path = ../21; + } + ]; "llvm/gnu-install-dirs.patch" = [ { after = "23"; From 9c847cd37c2c2fbf1e4298fe1c6f6bb9ea87055b Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 004/110] llvmPackages_{18,19,20}.libllvm: reenable disabled test This test works again after the patch in 26945241a1586b4f5218e7f35d06e80ca323d232 is applied. (cherry picked from commit dca5964503eceb5695619b2ee84b94536e5028ee) --- .../development/compilers/llvm/common/llvm/default.nix | 10 ---------- 1 file changed, 10 deletions(-) diff --git a/pkgs/development/compilers/llvm/common/llvm/default.nix b/pkgs/development/compilers/llvm/common/llvm/default.nix index 222f7fb6e54d..b82840833426 100644 --- a/pkgs/development/compilers/llvm/common/llvm/default.nix +++ b/pkgs/development/compilers/llvm/common/llvm/default.nix @@ -304,16 +304,6 @@ stdenv.mkDerivation ( substituteInPlace unittests/Support/VirtualFileSystemTest.cpp \ --replace-fail "PhysicalFileSystemWorkingDirFailure" "DISABLED_PhysicalFileSystemWorkingDirFailure" '' - + - # Fails on macOS ≥ 26 due to the changed OS version scheme. - # - # This was fixed upstream in LLVM 21 with - # 88f041f3e05e26617856cc096d2e2864dfaa1c7b, but it’s too - # painful to backport all the way. - lib.optionalString (lib.versionOlder release_version "21") '' - substituteInPlace unittests/TargetParser/Host.cpp \ - --replace-fail "getMacOSHostVersion" "DISABLED_getMacOSHostVersion" - '' + # This test fails with a `dysmutil` crash; have not yet dug into what's # going on here (TODO(@rrbutani)). From 51db35b37cac0f240b6a2add73ebd47f096ff8b8 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 005/110] lldb: backport export trie fixes to LLDB 22 and older MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Older versions of LLDB crash on macOS 27 when starting a debugging session on macOS 27 due to a stack overflow in `ParseExportTries`. The fixes from LLVM 23 can’t be cherry-picked due to other changes. They have been manually backported and squashed into a single patch. (cherry picked from commit 53b813b1660e8ae9f62a5334a7bd89b42c7ea752) --- .../backport-ParseTrieEntries-fixes.patch | 124 +++++++++++++++++ .../backport-ParseTrieEntries-fixes.patch | 125 ++++++++++++++++++ .../compilers/llvm/common/lldb/default.nix | 4 + .../compilers/llvm/common/patches.nix | 11 ++ 4 files changed, 264 insertions(+) create mode 100644 pkgs/development/compilers/llvm/18/lldb/backport-ParseTrieEntries-fixes.patch create mode 100644 pkgs/development/compilers/llvm/22/lldb/backport-ParseTrieEntries-fixes.patch diff --git a/pkgs/development/compilers/llvm/18/lldb/backport-ParseTrieEntries-fixes.patch b/pkgs/development/compilers/llvm/18/lldb/backport-ParseTrieEntries-fixes.patch new file mode 100644 index 000000000000..f165c7e9ebbe --- /dev/null +++ b/pkgs/development/compilers/llvm/18/lldb/backport-ParseTrieEntries-fixes.patch @@ -0,0 +1,124 @@ +diff --git a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +index 2c7005449f..e0c426afa0 100644 +--- a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp ++++ b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +@@ -137,6 +137,14 @@ + using namespace lldb_private; + using namespace llvm::MachO; + ++/// Upper bound on the length of a symbol name assembled from export-trie edge ++/// labels. A corrupt trie can encode an edge label whose terminator is far ++/// away in the trie data, so a single label is many megabytes long; appending ++/// it to the running name would otherwise request an unbounded allocation. No ++/// legitimate symbol name comes close to this size. Also 1 MiB is the ++/// symbol length limit in ld. ++static constexpr size_t kMaxTrieSymbolNameLength = 1 << 20; // 1 MiB ++ + LLDB_PLUGIN_DEFINE(ObjectFileMachO) + + static void PrintRegisterValue(RegisterContext *reg_ctx, const char *name, +@@ -2050,15 +2058,21 @@ + } + }; + +-static bool ParseTrieEntries(DataExtractor &data, lldb::offset_t offset, +- const bool is_arm, addr_t text_seg_base_addr, +- std::vector &nameSlices, +- std::set &resolver_addresses, +- std::vector &reexports, +- std::vector &ext_symbols) { ++static bool ParseTrieEntriesImpl(DataExtractor &data, lldb::offset_t offset, ++ const bool is_arm, addr_t text_seg_base_addr, ++ std::string &prefix, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols, ++ std::set &visited_nodes) { + if (!data.ValidOffset(offset)) + return true; + ++ // Every node in a well-formed trie is reached by exactly one path, so a node ++ // offset seen twice means the trie is corrupt. ++ if (!visited_nodes.insert(offset).second) ++ return false; ++ + // Terminal node -- end of a branch, possibly add this to + // the symbol table or resolver table. + const uint64_t terminalSize = data.GetULEB128(&offset); +@@ -2098,14 +2112,9 @@ + add_this_entry = true; + } + if (add_this_entry) { +- std::string name; +- if (!nameSlices.empty()) { +- for (auto name_slice : nameSlices) +- name.append(name_slice.data(), name_slice.size()); +- } +- if (name.size() > 1) { ++ if (prefix.size() > 1) { + // Skip the leading '_' +- e.entry.name.SetCStringWithLength(name.c_str() + 1, name.size() - 1); ++ e.entry.name.SetString(llvm::StringRef(prefix).drop_front()); + } + if (import_name) { + // Skip the leading '_' +@@ -2126,23 +2135,36 @@ + const uint8_t childrenCount = data.GetU8(&children_offset); + for (uint8_t i = 0; i < childrenCount; ++i) { + const char *cstr = data.GetCStr(&children_offset); +- if (cstr) +- nameSlices.push_back(llvm::StringRef(cstr)); +- else ++ if (!cstr) + return false; // Corrupt data ++ if (prefix.size() + llvm::StringRef(cstr).size() > kMaxTrieSymbolNameLength) ++ return false; // Corrupt data: implausibly long symbol name. ++ const size_t prevSize = prefix.size(); ++ prefix.append(cstr); + lldb::offset_t childNodeOffset = data.GetULEB128(&children_offset); +- if (childNodeOffset) { +- if (!ParseTrieEntries(data, childNodeOffset, is_arm, text_seg_base_addr, +- nameSlices, resolver_addresses, reexports, +- ext_symbols)) { +- return false; +- } +- } +- nameSlices.pop_back(); ++ // A child offset of 0 points back at the root; like any other repeated ++ // offset it is a cycle, which ParseTrieEntriesImpl rejects as corrupt. ++ if (!ParseTrieEntriesImpl(data, childNodeOffset, is_arm, text_seg_base_addr, ++ prefix, resolver_addresses, reexports, ++ ext_symbols, visited_nodes)) ++ return false; ++ prefix.resize(prevSize); + } + return true; + } + ++static bool ParseTrieEntries( ++ DataExtractor &data, const bool is_arm, lldb::addr_t text_seg_base_addr, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols) { ++ lldb::offset_t offset = 0; ++ std::set visited_nodes; ++ std::string prefix; ++ return ParseTrieEntriesImpl(data, offset, is_arm, text_seg_base_addr, prefix, ++ resolver_addresses, reexports, ext_symbols, ++ visited_nodes); ++} + static SymbolType GetSymbolType(const char *&symbol_name, + bool &demangled_is_synthesized, + const SectionSP &text_section_sp, +@@ -2666,9 +2688,8 @@ + lldb::addr_t text_segment_file_addr = LLDB_INVALID_ADDRESS; + if (text_segment_sp) + text_segment_file_addr = text_segment_sp->GetFileAddress(); +- std::vector nameSlices; +- ParseTrieEntries(dyld_trie_data, 0, is_arm, text_segment_file_addr, +- nameSlices, resolver_addresses, reexport_trie_entries, ++ ParseTrieEntries(dyld_trie_data, is_arm, text_segment_file_addr, ++ resolver_addresses, reexport_trie_entries, + external_sym_trie_entries); + } + diff --git a/pkgs/development/compilers/llvm/22/lldb/backport-ParseTrieEntries-fixes.patch b/pkgs/development/compilers/llvm/22/lldb/backport-ParseTrieEntries-fixes.patch new file mode 100644 index 000000000000..312be42ec2fb --- /dev/null +++ b/pkgs/development/compilers/llvm/22/lldb/backport-ParseTrieEntries-fixes.patch @@ -0,0 +1,125 @@ +diff --git a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +index 0be7b4c6f8..f9d9a05920 100644 +--- a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp ++++ b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +@@ -137,6 +137,14 @@ + static constexpr llvm::StringLiteral g_loader_path = "@loader_path"; + static constexpr llvm::StringLiteral g_executable_path = "@executable_path"; + ++/// Upper bound on the length of a symbol name assembled from export-trie edge ++/// labels. A corrupt trie can encode an edge label whose terminator is far ++/// away in the trie data, so a single label is many megabytes long; appending ++/// it to the running name would otherwise request an unbounded allocation. No ++/// legitimate symbol name comes close to this size. Also 1 MiB is the ++/// symbol length limit in ld. ++static constexpr size_t kMaxTrieSymbolNameLength = 1 << 20; // 1 MiB ++ + LLDB_PLUGIN_DEFINE(ObjectFileMachO) + + static void PrintRegisterValue(RegisterContext *reg_ctx, const char *name, +@@ -1994,15 +2002,21 @@ + } + }; + +-static bool ParseTrieEntries(DataExtractor &data, lldb::offset_t offset, +- const bool is_arm, addr_t text_seg_base_addr, +- std::vector &nameSlices, +- std::set &resolver_addresses, +- std::vector &reexports, +- std::vector &ext_symbols) { ++static bool ParseTrieEntriesImpl(DataExtractor &data, lldb::offset_t offset, ++ const bool is_arm, addr_t text_seg_base_addr, ++ std::string &prefix, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols, ++ std::set &visited_nodes) { + if (!data.ValidOffset(offset)) + return true; + ++ // Every node in a well-formed trie is reached by exactly one path, so a node ++ // offset seen twice means the trie is corrupt. ++ if (!visited_nodes.insert(offset).second) ++ return false; ++ + // Terminal node -- end of a branch, possibly add this to + // the symbol table or resolver table. + const uint64_t terminalSize = data.GetULEB128(&offset); +@@ -2042,14 +2056,9 @@ + add_this_entry = true; + } + if (add_this_entry) { +- std::string name; +- if (!nameSlices.empty()) { +- for (auto name_slice : nameSlices) +- name.append(name_slice.data(), name_slice.size()); +- } +- if (name.size() > 1) { ++ if (prefix.size() > 1) { + // Skip the leading '_' +- e.entry.name.SetCStringWithLength(name.c_str() + 1, name.size() - 1); ++ e.entry.name.SetString(llvm::StringRef(prefix).drop_front()); + } + if (import_name) { + // Skip the leading '_' +@@ -2070,23 +2079,37 @@ + const uint8_t childrenCount = data.GetU8(&children_offset); + for (uint8_t i = 0; i < childrenCount; ++i) { + const char *cstr = data.GetCStr(&children_offset); +- if (cstr) +- nameSlices.push_back(llvm::StringRef(cstr)); +- else ++ if (!cstr) + return false; // Corrupt data ++ if (prefix.size() + llvm::StringRef(cstr).size() > kMaxTrieSymbolNameLength) ++ return false; // Corrupt data: implausibly long symbol name. ++ const size_t prevSize = prefix.size(); ++ prefix.append(cstr); + lldb::offset_t childNodeOffset = data.GetULEB128(&children_offset); +- if (childNodeOffset) { +- if (!ParseTrieEntries(data, childNodeOffset, is_arm, text_seg_base_addr, +- nameSlices, resolver_addresses, reexports, +- ext_symbols)) { +- return false; +- } +- } +- nameSlices.pop_back(); ++ // A child offset of 0 points back at the root; like any other repeated ++ // offset it is a cycle, which ParseTrieEntriesImpl rejects as corrupt. ++ if (!ParseTrieEntriesImpl(data, childNodeOffset, is_arm, text_seg_base_addr, ++ prefix, resolver_addresses, reexports, ++ ext_symbols, visited_nodes)) ++ return false; ++ prefix.resize(prevSize); + } + return true; + } + ++static bool ParseTrieEntries( ++ DataExtractor &data, const bool is_arm, lldb::addr_t text_seg_base_addr, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols) { ++ lldb::offset_t offset = 0; ++ std::set visited_nodes; ++ std::string prefix; ++ return ParseTrieEntriesImpl(data, offset, is_arm, text_seg_base_addr, prefix, ++ resolver_addresses, reexports, ext_symbols, ++ visited_nodes); ++} ++ + static bool + TryParseV2ObjCMetadataSymbol(const char *&symbol_name, + const char *&symbol_name_non_abi_mangled, +@@ -2659,9 +2682,8 @@ + lldb::addr_t text_segment_file_addr = LLDB_INVALID_ADDRESS; + if (text_segment_sp) + text_segment_file_addr = text_segment_sp->GetFileAddress(); +- std::vector nameSlices; +- ParseTrieEntries(dyld_trie_data, 0, is_arm, text_segment_file_addr, +- nameSlices, resolver_addresses, reexport_trie_entries, ++ ParseTrieEntries(dyld_trie_data, is_arm, text_segment_file_addr, ++ resolver_addresses, reexport_trie_entries, + external_sym_trie_entries); + } + diff --git a/pkgs/development/compilers/llvm/common/lldb/default.nix b/pkgs/development/compilers/llvm/common/lldb/default.nix index e146f1d896b8..8bca8f4edc1f 100644 --- a/pkgs/development/compilers/llvm/common/lldb/default.nix +++ b/pkgs/development/compilers/llvm/common/lldb/default.nix @@ -77,6 +77,10 @@ stdenv.mkDerivation ( # Fix build with gcc15 # https://github.com/llvm/llvm-project/commit/bb59f04e7e75dcbe39f1bf952304a157f0035314 ./lldb-add-include-cstdint.patch + ] + ++ lib.optionals (lib.versionOlder (lib.versions.major release_version) "23") [ + # Backports several fixes to export trie parsing. Otherwise, LLDB crashes when starting a debugging session on macOS 27. + (getVersionFile "lldb/backport-ParseTrieEntries-fixes.patch") ]; nativeBuildInputs = [ diff --git a/pkgs/development/compilers/llvm/common/patches.nix b/pkgs/development/compilers/llvm/common/patches.nix index 5ea9faa3d2e2..a2ecc75785c9 100644 --- a/pkgs/development/compilers/llvm/common/patches.nix +++ b/pkgs/development/compilers/llvm/common/patches.nix @@ -20,6 +20,17 @@ path = ../18; } ]; + "lldb/backport-ParseTrieEntries-fixes.patch" = [ + { + before = "22"; + path = ../18; + } + { + after = "22"; + before = "23"; + path = ../22; + } + ]; "llvm/backport-darwin-triple-parsing.patch" = [ { after = "18"; From c41a0b44c1212c5bd8ebeeecbdd2dd86ee894f5e Mon Sep 17 00:00:00 2001 From: sh0uv1 Date: Mon, 7 Sep 2026 15:40:57 +0000 Subject: [PATCH 006/110] perlPackages.AuthenSASL: 2.1900 -> 2.2100 (cherry picked from commit 55c902a0a0524a2bedc6105f3d8997605638f95a) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 80754256cb66..4d2d09fed4cb 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -2096,10 +2096,10 @@ with self; AuthenSASL = buildPerlPackage { pname = "Authen-SASL"; - version = "2.1900"; + version = "2.2100"; src = fetchurl { - url = "mirror://cpan/authors/id/E/EH/EHUELS/Authen-SASL-2.1900.tar.gz"; - hash = "sha256-vjUzpokbLmdxULR5waDUvxHIu+6+0+e466NAU+k5I7A="; + url = "mirror://cpan/authors/id/E/EH/EHUELS/Authen-SASL-2.2100.tar.gz"; + hash = "sha256-Tw8QCu7TS1KXepS335c+fwuPktFnsJ8rJJurgehZDlc="; }; propagatedBuildInputs = [ CryptURandom From 9c490c4f47789cd4af338251b9728cd7e239520d Mon Sep 17 00:00:00 2001 From: Oleksandr Usov Date: Sun, 16 Aug 2026 04:14:12 +0100 Subject: [PATCH 007/110] git: fix interpreter paths in contrib scripts (cherry picked from commit 1e8e68e5a934df7f6591f969aae9918a59d0ff4b) --- pkgs/by-name/gi/git/package.nix | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/gi/git/package.nix b/pkgs/by-name/gi/git/package.nix index bf2f58e2b90e..75a1dd0a6345 100644 --- a/pkgs/by-name/gi/git/package.nix +++ b/pkgs/by-name/gi/git/package.nix @@ -85,6 +85,11 @@ let AuthenSASL DigestHMAC ]; + gitJumpBinPath = lib.makeBinPath [ + "$out" + perlPackages.perl + coreutils + ]; in stdenv.mkDerivation (finalAttrs: { @@ -207,6 +212,7 @@ stdenv.mkDerivation (finalAttrs: { (if stdenv.hostPlatform.isFreeBSD then libiconvReal else libiconv) bash ] + ++ lib.optionals pythonSupport [ python3 ] ++ lib.optionals perlSupport [ perlPackages.perl ] ++ lib.optionals guiSupport [ tcl @@ -393,9 +399,11 @@ stdenv.mkDerivation (finalAttrs: { # Also put git-http-backend into $PATH, so that we can use smart # HTTP(s) transports for pushing ln -s $out/libexec/git-core/git-http-backend${stdenv.hostPlatform.extensions.executable} $out/bin/git-http-backend - ln -s $out/share/git/contrib/git-jump/git-jump $out/bin/git-jump '' + lib.optionalString perlSupport '' + makeWrapper $out/share/git/contrib/git-jump/git-jump $out/bin/git-jump \ + --prefix PATH : "${gitJumpBinPath}" + # wrap perl commands makeWrapper "$out/share/git/contrib/credential/netrc/git-credential-netrc.perl" $out/libexec/git-core/git-credential-netrc \ --set PERL5LIB "$out/${perlPackages.perl.libPrefix}:${perlPackages.makePerlPath perlLibs}" @@ -422,6 +430,10 @@ stdenv.mkDerivation (finalAttrs: { done '' + + lib.optionalString pythonSupport '' + patchShebangs $out/share/git/contrib/fast-import/import-zips.py + '' + + ( if svnSupport then '' From 5305288da78174ef0c9f269d11dd293c82596188 Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Sat, 25 Apr 2026 10:15:21 +0100 Subject: [PATCH 008/110] libmicrohttpd: 1.0.2 -> 1.0.5 (cherry picked from commit a0329b88aed371b01b272c79b63f7097e66f8315) --- pkgs/development/libraries/libmicrohttpd/1.0.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/libmicrohttpd/1.0.nix b/pkgs/development/libraries/libmicrohttpd/1.0.nix index 8070e78356c7..138f80ca444c 100644 --- a/pkgs/development/libraries/libmicrohttpd/1.0.nix +++ b/pkgs/development/libraries/libmicrohttpd/1.0.nix @@ -1,10 +1,10 @@ { callPackage, fetchurl }: callPackage ./generic.nix rec { - version = "1.0.2"; + version = "1.0.5"; src = fetchurl { url = "mirror://gnu/libmicrohttpd/libmicrohttpd-${version}.tar.gz"; - hash = "sha256-3zJPzQg0F12rB0gxM5Atl3SmBb+imAJfaYgyiP0gqMc="; + hash = "sha256-tG0A9Y76b0l7l9LngsTuZjAdQS3dhV3TBoUYs6LNPqI="; }; } From dbb3a6dc5531960272cfa43ffd0a70b8950ff81f Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Wed, 22 Jul 2026 22:40:53 +0100 Subject: [PATCH 009/110] libmicrohttpd: 1.0.5 -> 1.0.6 (cherry picked from commit 75eca02672c5bae157b63971690528ec5ff5620c) --- pkgs/development/libraries/libmicrohttpd/1.0.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/libmicrohttpd/1.0.nix b/pkgs/development/libraries/libmicrohttpd/1.0.nix index 138f80ca444c..9248819673c6 100644 --- a/pkgs/development/libraries/libmicrohttpd/1.0.nix +++ b/pkgs/development/libraries/libmicrohttpd/1.0.nix @@ -1,10 +1,10 @@ { callPackage, fetchurl }: callPackage ./generic.nix rec { - version = "1.0.5"; + version = "1.0.6"; src = fetchurl { url = "mirror://gnu/libmicrohttpd/libmicrohttpd-${version}.tar.gz"; - hash = "sha256-tG0A9Y76b0l7l9LngsTuZjAdQS3dhV3TBoUYs6LNPqI="; + hash = "sha256-u1z8rfxS29XrUS1uKZXgNhNRwz6XqHq6Qm06Snumz3A="; }; } From 9bf33ae846ec1a30e78e8de49e95d2d11d6c05d0 Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Wed, 19 Aug 2026 22:01:58 +0100 Subject: [PATCH 010/110] libmicrohttpd: 1.0.6 -> 1.0.10 (cherry picked from commit 5f16fc985c621df34e30cee1c56aee1f06a2b550) --- pkgs/development/libraries/libmicrohttpd/1.0.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/libmicrohttpd/1.0.nix b/pkgs/development/libraries/libmicrohttpd/1.0.nix index 9248819673c6..cf9879dccee9 100644 --- a/pkgs/development/libraries/libmicrohttpd/1.0.nix +++ b/pkgs/development/libraries/libmicrohttpd/1.0.nix @@ -1,10 +1,10 @@ { callPackage, fetchurl }: callPackage ./generic.nix rec { - version = "1.0.6"; + version = "1.0.10"; src = fetchurl { url = "mirror://gnu/libmicrohttpd/libmicrohttpd-${version}.tar.gz"; - hash = "sha256-u1z8rfxS29XrUS1uKZXgNhNRwz6XqHq6Qm06Snumz3A="; + hash = "sha256-BL/o73XbfWKaM952dZl2XOytxWJ0o5gi1dCBAw1XdoU="; }; } From 19e70d495b5848d3a578f694c910372204eba3fa Mon Sep 17 00:00:00 2001 From: whispers Date: Fri, 28 Aug 2026 17:15:50 -0400 Subject: [PATCH 011/110] libgcrypt: 1.12.2 -> 1.12.4 https://lists.gnu.org/archive/html/info-gnu/2026-08/msg00007.html https://lists.gnu.org/archive/html/info-gnu/2026-09/msg00002.html (cherry picked from commit ae02526138c4334d86b87255fc20b722708ec341) --- pkgs/by-name/li/libgcrypt/package.nix | 15 ++------------- 1 file changed, 2 insertions(+), 13 deletions(-) diff --git a/pkgs/by-name/li/libgcrypt/package.nix b/pkgs/by-name/li/libgcrypt/package.nix index 20f8cad0a141..dbbe1f4d0686 100644 --- a/pkgs/by-name/li/libgcrypt/package.nix +++ b/pkgs/by-name/li/libgcrypt/package.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchurl, - fetchpatch, gettext, libgpg-error, enableCapabilities ? false, @@ -18,23 +17,13 @@ assert enableCapabilities -> stdenv.hostPlatform.isLinux; stdenv.mkDerivation rec { pname = "libgcrypt"; - version = "1.12.2"; + version = "1.12.4"; src = fetchurl { url = "mirror://gnupg/libgcrypt/${pname}-${version}.tar.bz2"; - hash = "sha256-fOM8JJIiGgQ2+WqFACFenz49y1/SanV81BXnqEO6vV4="; + hash = "sha256-139o9Ih5UQ55ovZZd8zGiYF4HqCSPlvf+sKhk+o9Zg4="; }; - patches = lib.optionals stdenv.hostPlatform.isRiscV64 [ - # Remove in next release - # https://github.com/gpg/libgcrypt/commit/3f684fc6ab3ac98320e245a06b3563ad37ec56f5 - # zvkned AES corrupts CBC/CFB/CTR/OCB/XTS output on VLEN>128 hardware - (fetchpatch { - url = "https://github.com/gpg/libgcrypt/commit/3f684fc6ab3ac98320e245a06b3563ad37ec56f5.patch"; - hash = "sha256-1LSrIwsN0n5IBRDZ+9MJTEjzY+/T6LQO6hX1ke8hSuc="; - }) - ]; - outputs = [ "bin" "lib" From c567535f4011275e3ccf1b7ce850a27d792d12e7 Mon Sep 17 00:00:00 2001 From: Julian Stecklina Date: Wed, 16 Sep 2026 09:47:48 +0200 Subject: [PATCH 012/110] systemd: 260.4 -> 260.5 This fixes a number of issues, some looking security relevant: - off-by-one read in TAR code - DoS in DNS code I regenerated the patches according to the documentation in package.nix. Not-cherry-picked-because: Unstable is already on systemd v261 --- ...1-Don-t-try-to-unmount-nix-or-nix-store.patch | 2 +- ...ange-usr-share-zoneinfo-to-etc-zoneinfo.patch | 16 ++++++++-------- pkgs/os-specific/linux/systemd/default.nix | 4 ++-- 3 files changed, 11 insertions(+), 11 deletions(-) diff --git a/pkgs/os-specific/linux/systemd/0001-Don-t-try-to-unmount-nix-or-nix-store.patch b/pkgs/os-specific/linux/systemd/0001-Don-t-try-to-unmount-nix-or-nix-store.patch index 138b8c92dba2..7c3d9cc01821 100644 --- a/pkgs/os-specific/linux/systemd/0001-Don-t-try-to-unmount-nix-or-nix-store.patch +++ b/pkgs/os-specific/linux/systemd/0001-Don-t-try-to-unmount-nix-or-nix-store.patch @@ -14,7 +14,7 @@ Original-Author: Eelco Dolstra 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/src/shared/fstab-util.c b/src/shared/fstab-util.c -index 25e229bf3e..b9af1c3b13 100644 +index a4f5e348ab..d506b5598e 100644 --- a/src/shared/fstab-util.c +++ b/src/shared/fstab-util.c @@ -76,6 +76,8 @@ bool fstab_is_extrinsic(const char *mount, const char *opts) { diff --git a/pkgs/os-specific/linux/systemd/0002-Change-usr-share-zoneinfo-to-etc-zoneinfo.patch b/pkgs/os-specific/linux/systemd/0002-Change-usr-share-zoneinfo-to-etc-zoneinfo.patch index a9ec66f9dd3d..e12f00b328b6 100644 --- a/pkgs/os-specific/linux/systemd/0002-Change-usr-share-zoneinfo-to-etc-zoneinfo.patch +++ b/pkgs/os-specific/linux/systemd/0002-Change-usr-share-zoneinfo-to-etc-zoneinfo.patch @@ -35,10 +35,10 @@ index 3a13e04a27..4fd58068a1 100644 Etc/UTC. The resulting link should lead to the corresponding binary diff --git a/src/basic/time-util.c b/src/basic/time-util.c -index 5dd00af952..b97a41f6ac 100644 +index 6873017bf5..7455aa30ae 100644 --- a/src/basic/time-util.c +++ b/src/basic/time-util.c -@@ -1443,7 +1443,7 @@ static int get_timezones_from_zone1970_tab(char ***ret) { +@@ -1446,7 +1446,7 @@ static int get_timezones_from_zone1970_tab(char ***ret) { assert(ret); @@ -47,7 +47,7 @@ index 5dd00af952..b97a41f6ac 100644 if (!f) return -errno; -@@ -1488,7 +1488,7 @@ static int get_timezones_from_tzdata_zi(char ***ret) { +@@ -1491,7 +1491,7 @@ static int get_timezones_from_tzdata_zi(char ***ret) { assert(ret); @@ -56,7 +56,7 @@ index 5dd00af952..b97a41f6ac 100644 if (!f) return -errno; -@@ -1603,7 +1603,7 @@ int verify_timezone(const char *name, int log_level) { +@@ -1606,7 +1606,7 @@ int verify_timezone(const char *name, int log_level) { if (p - name >= PATH_MAX) return -ENAMETOOLONG; @@ -65,7 +65,7 @@ index 5dd00af952..b97a41f6ac 100644 fd = open(t, O_RDONLY|O_CLOEXEC); if (fd < 0) -@@ -1675,7 +1675,7 @@ int get_timezone(char **ret) { +@@ -1678,7 +1678,7 @@ int get_timezone(char **ret) { if (r < 0) return r; /* Return EINVAL if not a symlink */ @@ -75,7 +75,7 @@ index 5dd00af952..b97a41f6ac 100644 return -EINVAL; if (!timezone_is_valid(e, LOG_DEBUG)) diff --git a/src/firstboot/firstboot.c b/src/firstboot/firstboot.c -index ae1899593c..20d3071114 100644 +index ba96a749c6..f64e22faf1 100644 --- a/src/firstboot/firstboot.c +++ b/src/firstboot/firstboot.c @@ -584,7 +584,7 @@ static int prompt_timezone(int rfd, sd_varlink **mute_console_link) { @@ -103,7 +103,7 @@ index ae1899593c..20d3071114 100644 return log_error_errno(r, "Failed to create /etc/localtime symlink: %m"); diff --git a/src/nspawn/nspawn.c b/src/nspawn/nspawn.c -index 84e94e845a..8e1f1a6ea2 100644 +index d9bde47c8e..8c32e3ae99 100644 --- a/src/nspawn/nspawn.c +++ b/src/nspawn/nspawn.c @@ -1856,8 +1856,8 @@ int userns_mkdir(const char *root, const char *path, mode_t mode, uid_t uid, gid @@ -118,7 +118,7 @@ index 84e94e845a..8e1f1a6ea2 100644 static bool etc_writable(void) { diff --git a/src/timedate/timedated.c b/src/timedate/timedated.c -index 43cf3fddb9..dc23550500 100644 +index 5478666ca0..7e2ea196f5 100644 --- a/src/timedate/timedated.c +++ b/src/timedate/timedated.c @@ -268,7 +268,7 @@ static int context_read_data(Context *c) { diff --git a/pkgs/os-specific/linux/systemd/default.nix b/pkgs/os-specific/linux/systemd/default.nix index 3bc724c8338d..66cec5f951f3 100644 --- a/pkgs/os-specific/linux/systemd/default.nix +++ b/pkgs/os-specific/linux/systemd/default.nix @@ -201,13 +201,13 @@ let in stdenv.mkDerivation (finalAttrs: { inherit pname; - version = "260.4"; + version = "260.5"; src = fetchFromGitHub { owner = "systemd"; repo = "systemd"; rev = "v${finalAttrs.version}"; - hash = "sha256-n+wzn+1W82YooRxzIEJHm4CsVPFBGlQUIy9TatxlbaU="; + hash = "sha256-QLQad4pKkaf99k+ABOaooKi5TSX0iHH9XtMn/fy1rfE="; }; # PATCH POLICY From 27760cd7c62f70cfa30190422be30906958ebd6b Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Tue, 25 Aug 2026 21:34:09 +0100 Subject: [PATCH 013/110] gdk-pixbuf: 2.44.7 -> 2.44.8 Changes: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/compare/2.44.7...2.44.8 (cherry picked from commit 77e807267494e63bd8d256a4567c8c8d5ef14095) --- pkgs/by-name/gd/gdk-pixbuf/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gd/gdk-pixbuf/package.nix b/pkgs/by-name/gd/gdk-pixbuf/package.nix index a55bfa0909c6..618f24b74f4b 100644 --- a/pkgs/by-name/gd/gdk-pixbuf/package.nix +++ b/pkgs/by-name/gd/gdk-pixbuf/package.nix @@ -28,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gdk-pixbuf"; - version = "2.44.7"; + version = "2.44.8"; outputs = [ "out" @@ -40,7 +40,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/gdk-pixbuf/${lib.versions.majorMinor finalAttrs.version}/gdk-pixbuf-${finalAttrs.version}.tar.xz"; - hash = "sha256-Fy+A42JuwxUgqXBADxo2lOBHGPbCzSiF91JQ+1pplaQ="; + hash = "sha256-kZ9SlRKWGhLoHNS0tGakjDkzRp5/mjEMZRPNT7JSujw="; }; patches = [ From 34dffea30c3ed98525cf0a9d06972ed1821d7047 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Mon, 21 Sep 2026 06:28:02 +0200 Subject: [PATCH 014/110] Revert "nixos/systemd: patch to avoid failure during systemd reexec" This reverts commit 4ecabf5d48e80d2abe3847353b4471ee6cf2aea7. It shouldn't be needed (and should conflict) after f278f3ff193. --- nixos/modules/system/boot/systemd.nix | 16 +--------------- 1 file changed, 1 insertion(+), 15 deletions(-) diff --git a/nixos/modules/system/boot/systemd.nix b/nixos/modules/system/boot/systemd.nix index 85693da630c6..f48256a599a5 100644 --- a/nixos/modules/system/boot/systemd.nix +++ b/nixos/modules/system/boot/systemd.nix @@ -244,21 +244,7 @@ in options.systemd = { - package = mkPackageOption pkgs "systemd" { } // { - apply = - pkg: - pkg.overrideAttrs (prevAttrs: { - patches = prevAttrs.patches or [ ] ++ [ - # Remove this with v261.5; it fixes an issue with switch-to-configuration - # https://github.com/NixOS/nixpkgs/pull/558350#issuecomment-5740583354 - (pkgs.fetchpatch { - name = "postpone-d-bus-queue-dispatch.patch"; - url = "https://github.com/systemd/systemd/commit/266b3e50218e2b27cd67d2371c165bf53ad3bf00.patch"; - hash = "sha256-dEEzZUqicnmgDuXVBV1y0BxzgKbb6Q47Dmxj+O71bFE="; - }) - ]; - }); - }; + package = mkPackageOption pkgs "systemd" { }; enableStrictShellChecks = mkEnableOption "" // { description = '' From e178b0a9d394f1b3620ca11fd6b2b862f33d88ae Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sun, 13 Sep 2026 17:01:00 -0700 Subject: [PATCH 015/110] cups: patch CVE-2026-87875 and CVE-2026-87876 (cherry picked from commit 721870b2a6b45718df1c52ae2b4fb8595d3a394a) --- pkgs/by-name/cu/cups/package.nix | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/pkgs/by-name/cu/cups/package.nix b/pkgs/by-name/cu/cups/package.nix index dd12a5dcef57..bc7e13d02f1f 100644 --- a/pkgs/by-name/cu/cups/package.nix +++ b/pkgs/by-name/cu/cups/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchurl, + fetchpatch, pkg-config, removeReferencesTo, zlib, @@ -42,6 +43,29 @@ stdenv.mkDerivation (finalAttrs: { "man" ]; + patches = [ + (fetchpatch { + name = "CVE-2026-87875.patch"; + url = "https://github.com/OpenPrinting/cups/commit/2b1dc178a2d2325135b855142e384f4e8c42d8e4.patch"; + excludes = [ "CHANGES.md" ]; + hash = "sha256-WHw/UWyUuYEBC6TRADpw+BBCaCts9Nd0jS9qsQHTBMo="; + }) + (fetchpatch { + url = "https://github.com/OpenPrinting/cups/commit/76b515154ce6264dae6d7cc44915d85e0e5fa0f4.patch"; + hash = "sha256-KtwcB4KrFmsLbtAz6u593qxbnozW2Vb/I9yX36gZTd0="; + }) + (fetchpatch { + url = "https://github.com/OpenPrinting/cups/commit/526adb34fe87f7f0cf5f63ae26751c1afa36a5d6.patch"; + hash = "sha256-Pg2xbCXalbvDvv5iI19MrjpOTW03XLKfEHN+lhImG1U="; + }) + (fetchpatch { + name = "CVE-2026-87876.patch"; + url = "https://github.com/OpenPrinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8.patch"; + excludes = [ "CHANGES.md" ]; + hash = "sha256-gohcRO93JE2ldF5uPbR0re9NYxb13AeVn4b/qYsQGaE="; + }) + ]; + postPatch = '' substituteInPlace cups/testfile.c \ --replace 'cupsFileFind("cat", "/bin' 'cupsFileFind("cat", "${coreutils}/bin' From 1a0c0fe8ff37b1673b8666d6a9d89663dc71420c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 6 Sep 2026 12:59:40 +0000 Subject: [PATCH 016/110] libpcap: 1.10.6 -> 1.10.7 Taken from history of PR #560539 (cherry picked from commit 9e15d22f16ef2e8c6db2a826517736cc11d8b2ed) --- pkgs/by-name/li/libpcap/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libpcap/package.nix b/pkgs/by-name/li/libpcap/package.nix index fefde4c82aa9..b91b49c22865 100644 --- a/pkgs/by-name/li/libpcap/package.nix +++ b/pkgs/by-name/li/libpcap/package.nix @@ -28,13 +28,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "libpcap"; - version = "1.10.6"; + version = "1.10.7"; __structuredAttrs = true; src = fetchurl { url = "https://www.tcpdump.org/release/libpcap-${finalAttrs.version}.tar.gz"; - hash = "sha256-hy3REzf+GrAq2dT+4EfJ2iRNaVxt3zTi67cz79Ttiqk="; + hash = "sha256-CzlKyQ28Cpg4/5dGjgXJyaPoc97CUUzVjbZdhZ0pbjE="; }; outputs = [ From 22f8def6ad973528213870b8fe71b9684411a487 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 12 Jul 2026 06:27:58 +0000 Subject: [PATCH 017/110] memcached: 1.6.42 -> 1.6.45 (cherry picked from commit 9c06a6653d95e38ad3cd5bbecc7f0891963e137e) --- pkgs/by-name/me/memcached/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/me/memcached/package.nix b/pkgs/by-name/me/memcached/package.nix index e0b63e959ece..60dbfce191c3 100644 --- a/pkgs/by-name/me/memcached/package.nix +++ b/pkgs/by-name/me/memcached/package.nix @@ -8,12 +8,12 @@ }: stdenv.mkDerivation (finalAttrs: { - version = "1.6.42"; + version = "1.6.45"; pname = "memcached"; src = fetchurl { url = "https://memcached.org/files/memcached-${finalAttrs.version}.tar.gz"; - sha256 = "sha256-UPCLh51PnTbeqdkF6eqt4Vxwjjjbfppz/CHci0U5Xec="; + sha256 = "sha256-02LGTm2NUocVNQHqv3yFtKdhQy+/U/XXsIXQuxZTwd0="; }; configureFlags = [ From 8ec0ae1d40066d21d3023e967bff4c7ae87f6ea1 Mon Sep 17 00:00:00 2001 From: Xesxen Date: Sat, 19 Sep 2026 00:05:29 +0200 Subject: [PATCH 018/110] unbound: 1.26.0 -> 1.26.1 (cherry picked from commit 102ab2b7932aa494ccacd0e7be28741641f8486d) --- pkgs/by-name/un/unbound/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/un/unbound/package.nix b/pkgs/by-name/un/unbound/package.nix index 2dba1d12c66d..a2fecbd1921d 100644 --- a/pkgs/by-name/un/unbound/package.nix +++ b/pkgs/by-name/un/unbound/package.nix @@ -63,13 +63,13 @@ assert lib.assertMsg ( ) "unbound: withDoQ requires OpenSSL with QUIC support (OpenSSL >= 3.5)"; stdenv.mkDerivation (finalAttrs: { pname = "unbound"; - version = "1.26.0"; + version = "1.26.1"; src = fetchFromGitHub { owner = "NLnetLabs"; repo = "unbound"; tag = "release-${finalAttrs.version}"; - hash = "sha256-ESRboc5vwsNZ/Yynl2JGRWhH1QEYZumoTzgSvN3NbSU="; + hash = "sha256-gf4vASdB6XzSGhJ2GKbUhgs0wpR32Du2ARx4bBQ+vJA="; }; outputs = [ From c5e897bba50a64db40f63241e0eb5d13b0bae6da Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sun, 13 Sep 2026 07:12:00 +0200 Subject: [PATCH 019/110] gnupg: update freepg patches to source-2.4.9-freepg-1 Assisted-by: Claude Code (Claude Fable 5.1) (cherry picked from commit ff4e29c8ac1c51ca22c5ca8df29753810bebdfaf) --- pkgs/tools/security/gnupg/24.nix | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/security/gnupg/24.nix b/pkgs/tools/security/gnupg/24.nix index 06a1d0967a8e..0e6270238406 100644 --- a/pkgs/tools/security/gnupg/24.nix +++ b/pkgs/tools/security/gnupg/24.nix @@ -86,8 +86,8 @@ stdenv.mkDerivation rec { freepgPatches = fetchFromGitLab { owner = "freepg"; repo = "gnupg"; - tag = "source-2.4.9-freepg"; - hash = "sha256-wF+iR0OgnU8VI90NlFOXtN5aCRC0YY/X7sPiDXjJm5M="; + tag = "source-2.4.9-freepg-1"; + hash = "sha256-hoSuIrq7Epco1LLlc77tGr/YZdp2w04Eq0rGbBCurWU="; }; patches = [ @@ -128,6 +128,15 @@ stdenv.mkDerivation rec { "0033-Support-large-RSA-keygen-in-non-batch-mode.patch" "0034-gpg-Verify-Text-mode-Signatures-over-binary-Literal-.patch" "0039-gpg-Do-not-use-a-default-when-asking-for-another-out.patch" + "0040-Add-missing-test-files-to-EXTRA_DIST.patch" + "0045-gpg-Fix-edge-case-in-refresh-keys.patch" + "0046-gpgsm-Require-a-minimum-tag-length-for-GCM-decryptio.patch" + "0047-gpg-Fix-handling-with-no-CRC-armor.patch" + "0048-gpg-Fix-armored-input-parsing.patch" + "0049-gpg-Fix-armor-parsing-when-no-CRC-is-found.patch" + "0050-tpm-Fix-possible-buffer-overflow-in-PKDECRYPT.patch" + "0051-agent-Fix-the-regression-in-pkdecrypt-with-TPM-RSA.patch" + "0052-dirmngr-Fix-a-call-of-calloc.patch" ]; postPatch = From 1de5264fbbd02b4d7396d19c90f1208853f63a5a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Tue, 22 Sep 2026 17:59:32 +0200 Subject: [PATCH 020/110] libheif: 1.23.4 -> 1.23.5 https://github.com/strukturag/libheif/releases/tag/v1.23.5 (cherry picked from commit fb971edc63a705c30d8b642932723d6c515546b1) --- pkgs/by-name/li/libheif/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libheif/package.nix b/pkgs/by-name/li/libheif/package.nix index e8febed52bae..e1a009bf666b 100644 --- a/pkgs/by-name/li/libheif/package.nix +++ b/pkgs/by-name/li/libheif/package.nix @@ -24,7 +24,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "libheif"; - version = "1.23.4"; + version = "1.23.5"; outputs = [ "bin" @@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "strukturag"; repo = "libheif"; rev = "v${finalAttrs.version}"; - hash = "sha256-bxN3YB/nKjrsHa/dM3sTAnWR+wOHk5a6ku6NF+8moQ0="; + hash = "sha256-+nrUIAclVgkj4N5U3wQ1L6qpZuF3fuzHFDUT+X39h04="; }; nativeBuildInputs = [ From 494eebc257e7ae02684dc4cc721df77c2b43ba49 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 15 Jul 2026 17:47:14 +0000 Subject: [PATCH 021/110] thrift: 0.22.0 -> 0.24.0 (cherry picked from commit 77e36bcb9d326eb05c9d25a2d8cdd9580450c5f9) --- pkgs/by-name/th/thrift/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/th/thrift/package.nix b/pkgs/by-name/th/thrift/package.nix index 319c2413d96a..187720580203 100644 --- a/pkgs/by-name/th/thrift/package.nix +++ b/pkgs/by-name/th/thrift/package.nix @@ -17,13 +17,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "thrift"; - version = "0.22.0"; + version = "0.24.0"; src = fetchFromGitHub { owner = "apache"; repo = "thrift"; tag = "v${finalAttrs.version}"; - hash = "sha256-gGAO+D0A/hEoHMm6OvRBc1Mks9y52kfd0q/Sg96pdW4="; + hash = "sha256-+o/2exHsunjQBGjXrNQ1pQ5TKV53++qCxIMeVyOh5QY="; }; # Workaround to make the Python wrapper not drop this package: From 88b19765b384b1cd02192f7c9199dae30c104c11 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 11 Aug 2026 12:22:42 +0000 Subject: [PATCH 022/110] xdg-dbus-proxy: 0.1.7 -> 0.1.8 (cherry picked from commit e59c1c0c42bd6f25c2b25e7c7430fba9f8883a32) --- pkgs/by-name/xd/xdg-dbus-proxy/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/xd/xdg-dbus-proxy/package.nix b/pkgs/by-name/xd/xdg-dbus-proxy/package.nix index 098785d5556c..e580314238f5 100644 --- a/pkgs/by-name/xd/xdg-dbus-proxy/package.nix +++ b/pkgs/by-name/xd/xdg-dbus-proxy/package.nix @@ -14,11 +14,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "xdg-dbus-proxy"; - version = "0.1.7"; + version = "0.1.8"; src = fetchurl { url = "https://github.com/flatpak/xdg-dbus-proxy/releases/download/${finalAttrs.version}/xdg-dbus-proxy-${finalAttrs.version}.tar.xz"; - hash = "sha256-OtPSe6V04XisteTUOLo2rOJeNWT4mcNvMcVvgsetu+c="; + hash = "sha256-tmML0k+BYbDiVG0qy7AUo7Mkn1wNdfKoY63omLkDTT0="; }; nativeBuildInputs = [ From 8e4f9b07d199602bfe5ed37ab941382ecba58ca3 Mon Sep 17 00:00:00 2001 From: SandaruKasa Date: Sat, 18 Jul 2026 20:45:42 +0300 Subject: [PATCH 023/110] libaom: 3.12.1 -> 3.14.1 Changelog: https://aomedia.googlesource.com/aom/+/refs/tags/v3.14.1/CHANGELOG (cherry picked from commit a090aae6c103b8ab8d14c51d2fc8d79da27f97fb) --- pkgs/by-name/li/libaom/outputs.patch | 25 +++++++++++++------------ pkgs/by-name/li/libaom/package.nix | 4 ++-- 2 files changed, 15 insertions(+), 14 deletions(-) diff --git a/pkgs/by-name/li/libaom/outputs.patch b/pkgs/by-name/li/libaom/outputs.patch index 7b34338403f2..d7a6cafba539 100644 --- a/pkgs/by-name/li/libaom/outputs.patch +++ b/pkgs/by-name/li/libaom/outputs.patch @@ -1,8 +1,8 @@ -diff --git a/build/cmake/aom_install.cmake b/build/cmake/aom_install.cmake -index 0bd2bf035..5cf5acea8 100644 ---- a/build/cmake/aom_install.cmake -+++ b/build/cmake/aom_install.cmake -@@ -42,8 +42,8 @@ macro(setup_aom_install_targets) +diff --git a/cmake/aom_install.cmake b/cmake/aom_install.cmake +index a8f6d64361..c5223462ed 100644 +--- a/cmake/aom_install.cmake ++++ b/cmake/aom_install.cmake +@@ -45,8 +45,8 @@ macro(setup_aom_install_targets) -DAOM_ROOT=${AOM_ROOT} -DCMAKE_INSTALL_PREFIX=${CMAKE_INSTALL_PREFIX} -DCMAKE_INSTALL_BINDIR=${CMAKE_INSTALL_BINDIR} @@ -11,9 +11,9 @@ index 0bd2bf035..5cf5acea8 100644 + -DCMAKE_INSTALL_FULL_INCLUDEDIR=${CMAKE_INSTALL_FULL_INCLUDEDIR} + -DCMAKE_INSTALL_FULL_LIBDIR=${CMAKE_INSTALL_FULL_LIBDIR} -DCMAKE_PROJECT_NAME=${CMAKE_PROJECT_NAME} + -DCMAKE_THREAD_LIBS_INIT=${CMAKE_THREAD_LIBS_INIT} -DCONFIG_MULTITHREAD=${CONFIG_MULTITHREAD} - -DCONFIG_TUNE_VMAF=${CONFIG_TUNE_VMAF} -@@ -84,12 +84,12 @@ macro(setup_aom_install_targets) +@@ -115,13 +115,13 @@ macro(setup_aom_install_targets) # Setup the install rules. install() will automatically prepend # CMAKE_INSTALL_PREFIX to relative paths install(FILES ${AOM_INSTALL_INCS} @@ -23,6 +23,7 @@ index 0bd2bf035..5cf5acea8 100644 - DESTINATION "${CMAKE_INSTALL_LIBDIR}/pkgconfig") + DESTINATION "${CMAKE_INSTALL_FULL_LIBDIR}/pkgconfig") install(TARGETS ${AOM_INSTALL_LIBS};${AOM_INSTALL_BINS} + EXPORT "${AOM_TARGETS_EXPORT_NAME}" - RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}" - LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" - ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}") @@ -31,12 +32,12 @@ index 0bd2bf035..5cf5acea8 100644 + ARCHIVE DESTINATION "${CMAKE_INSTALL_FULL_LIBDIR}") endif() endmacro() -diff --git a/build/cmake/pkg_config.cmake b/build/cmake/pkg_config.cmake -index e8fff2e77..b8a73aad4 100644 ---- a/build/cmake/pkg_config.cmake -+++ b/build/cmake/pkg_config.cmake +diff --git a/cmake/pkg_config.cmake b/cmake/pkg_config.cmake +index ad3cf77009..1b46040cd1 100644 +--- a/cmake/pkg_config.cmake ++++ b/cmake/pkg_config.cmake @@ -11,8 +11,8 @@ - cmake_minimum_required(VERSION 3.5) + cmake_minimum_required(VERSION 3.16) set(REQUIRED_ARGS "AOM_ROOT" "AOM_CONFIG_DIR" "CMAKE_INSTALL_PREFIX" - "CMAKE_INSTALL_BINDIR" "CMAKE_INSTALL_INCLUDEDIR" diff --git a/pkgs/by-name/li/libaom/package.nix b/pkgs/by-name/li/libaom/package.nix index c8296dd90fb8..739ac4320eaa 100644 --- a/pkgs/by-name/li/libaom/package.nix +++ b/pkgs/by-name/li/libaom/package.nix @@ -23,11 +23,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "libaom"; - version = "3.12.1"; + version = "3.14.1"; src = fetchzip { url = "https://aomedia.googlesource.com/aom/+archive/v${finalAttrs.version}.tar.gz"; - hash = "sha256-AAS6wfq4rZ4frm6+gwKoIS3+NVzPhhfW428WXJQ2tQ8="; + hash = "sha256-ddMrDkWV5jUbpPGKsMQl7s4r43205WbBtCEYtZNgwAM="; stripRoot = false; }; From d4eba5801e8ba6aded349d4eedf400489a5bc5eb Mon Sep 17 00:00:00 2001 From: SandaruKasa Date: Sat, 18 Jul 2026 20:50:26 +0300 Subject: [PATCH 024/110] libaom: strictDeps, __structuredAttrs (cherry picked from commit c5898aaf4154cffe9fd936307c8c8b5911102ec5) --- pkgs/by-name/li/libaom/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/li/libaom/package.nix b/pkgs/by-name/li/libaom/package.nix index 739ac4320eaa..9dfe847d606a 100644 --- a/pkgs/by-name/li/libaom/package.nix +++ b/pkgs/by-name/li/libaom/package.nix @@ -96,6 +96,9 @@ stdenv.mkDerivation (finalAttrs: { ln -s $static $out ''; + __structuredAttrs = true; + strictDeps = true; + outputs = [ "out" "bin" From 0ef35e8f35d0bc67168472b5f75ed2a0e17d9867 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Tue, 22 Sep 2026 15:57:25 +0200 Subject: [PATCH 025/110] libaom: 3.14.1 -> 3.15.0 https://aomedia.googlesource.com/aom/+/refs/tags/v3.15.0 Fixes: CVE-2026-56209 CVE-2026-13906 (cherry picked from commit 2aef6e14b531d263160f63eb678c652da3c2db2c) --- pkgs/by-name/li/libaom/package.nix | 28 ++++++++++++---------------- 1 file changed, 12 insertions(+), 16 deletions(-) diff --git a/pkgs/by-name/li/libaom/package.nix b/pkgs/by-name/li/libaom/package.nix index 9dfe847d606a..6af569faf2b2 100644 --- a/pkgs/by-name/li/libaom/package.nix +++ b/pkgs/by-name/li/libaom/package.nix @@ -23,25 +23,16 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "libaom"; - version = "3.14.1"; + version = "3.15.0"; src = fetchzip { url = "https://aomedia.googlesource.com/aom/+archive/v${finalAttrs.version}.tar.gz"; - hash = "sha256-ddMrDkWV5jUbpPGKsMQl7s4r43205WbBtCEYtZNgwAM="; + hash = "sha256-TixZQP06TEZPtpHvWVOEagzHtXW9hqXWweO2yimBDG4="; stripRoot = false; }; patches = [ ./outputs.patch - ] - ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ - # This patch defines `_POSIX_C_SOURCE`, which breaks system headers - # on Darwin. - (fetchurl { - name = "musl.patch"; - url = "https://gitweb.gentoo.org/repo/gentoo.git/plain/media-libs/libaom/files/libaom-3.4.0-posix-c-source-ftello.patch?id=50c7c4021e347ee549164595280cf8a23c960959"; - hash = "sha256-6+u7GTxZcSNJgN7D+s+XAVwbMnULufkTcQ0s7l+Ydl0="; - }) ]; nativeBuildInputs = [ @@ -54,11 +45,16 @@ stdenv.mkDerivation (finalAttrs: { propagatedBuildInputs = lib.optional enableVmaf libvmaf; - env = lib.optionalAttrs stdenv.hostPlatform.isFreeBSD { - # This can be removed when we switch to libcxx from llvm 20 - # https://github.com/llvm/llvm-project/pull/122361 - NIX_CFLAGS_COMPILE = "-D_XOPEN_SOURCE=700"; - }; + env = + lib.optionalAttrs stdenv.hostPlatform.isFreeBSD { + # This can be removed when we switch to libcxx from llvm 20 + # https://github.com/llvm/llvm-project/pull/122361 + NIX_CFLAGS_COMPILE = "-D_XOPEN_SOURCE=700"; + } + // lib.optionalAttrs stdenv.hostPlatform.isLinux { + # _POSIX_C_SOURCE breaks system headers on Darwin; it's required on musl + NIX_CFLAGS_COMPILE = "-D_POSIX_C_SOURCE=200112L"; + }; preConfigure = '' # build uses `git describe` to set the build version From d7053997ba984934fb86fe4136b03aaad10961ef Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Wed, 23 Sep 2026 08:28:03 +0200 Subject: [PATCH 026/110] libaom: fixup outputs in *.cmake Now libheif builds for me with this atop nixpkgs master. (cherry picked from commit 99db7938f54a64d95ce56a885082c507486db31c) --- pkgs/by-name/li/libaom/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/li/libaom/package.nix b/pkgs/by-name/li/libaom/package.nix index 6af569faf2b2..c8cf959b9bf0 100644 --- a/pkgs/by-name/li/libaom/package.nix +++ b/pkgs/by-name/li/libaom/package.nix @@ -87,6 +87,9 @@ stdenv.mkDerivation (finalAttrs: { postFixup = '' moveToOutput lib/libaom.a "$static" + substituteInPlace "$dev"/lib/cmake/*/*.cmake \ + --replace-quiet "$out/lib/libaom.a" "$static/lib/libaom.a" \ + --replace-quiet "$"'{_IMPORT_PREFIX}/include' "$dev/include" '' + lib.optionalString stdenv.hostPlatform.isStatic '' ln -s $static $out From a905e4a4c152a1e6d86e8c1d95c4fdca326993e7 Mon Sep 17 00:00:00 2001 From: Ryan Hendrickson Date: Thu, 24 Sep 2026 05:20:17 -0400 Subject: [PATCH 027/110] sudo: fix CVE-2026-96512 (cherry picked from commit ce287a157dc15a3aae83c0012540efb5c45910c0) --- pkgs/by-name/su/sudo/package.nix | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/su/sudo/package.nix b/pkgs/by-name/su/sudo/package.nix index 781761698db3..b7cf22098efb 100644 --- a/pkgs/by-name/su/sudo/package.nix +++ b/pkgs/by-name/su/sudo/package.nix @@ -1,6 +1,7 @@ { lib, stdenv, + fetchpatch2, fetchurl, buildPackages, coreutils, @@ -31,9 +32,22 @@ stdenv.mkDerivation (finalAttrs: { prePatch = '' # do not set sticky bit in nix store - substituteInPlace src/Makefile.in --replace 04755 0755 + substituteInPlace src/Makefile.in --replace-fail 04755 0755 ''; + patches = [ + (fetchpatch2 { + name = "CVE-2026-96512_1.patch"; + url = "https://github.com/sudo-project/sudo/commit/db669167ca599f2a94cd8a4c5fae9e473c81a2fd.patch?full_index=1"; + hash = "sha256-VqfWo/z7CQCtgefzE8xAehjgKn2h1It6GkEt5BUn/OQ="; + }) + (fetchpatch2 { + name = "CVE-2026-96512_2.patch"; + url = "https://github.com/sudo-project/sudo/commit/1820a349687522f51023d1ae5925125f59679a8c.patch?full_index=1"; + hash = "sha256-guOdOaIqmXAftpj9gpsRFaAS5g2cS4j7o5DQFqyLZv8="; + }) + ]; + configureFlags = [ "--with-env-editor" "--with-editor=/run/current-system/sw/bin/nano" From cf4cb44ce0ad1396d7026e35a42652e07e73bae5 Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Sat, 18 Jul 2026 20:43:59 -0400 Subject: [PATCH 028/110] expat: make version easily overridable MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Previously, doing e.g. ``` expat.overrideAttrs (old: { version = "2.8.1"; src = old.src.overrideAttrs { hash = ""; }; }) ``` would not work since `tag` was created outside `mkDerivation` using `version`, not `finalAttrs.version`. Most sensible perhaps would be to move it inside (e.g. `mkDerivation (finalAttrs: let tag = … in …`), however then `nix fmt` wants to indent everything. So instead keep it outside but make it a fn that takes the version, and always use `finalAttrs.version`. (cherry picked from commit 5c8bac0971dd2895c0989b3b8c3392e812b54e39) --- pkgs/by-name/ex/expat/package.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/ex/expat/package.nix b/pkgs/by-name/ex/expat/package.nix index 44df814f0746..ed2fdf1a711e 100644 --- a/pkgs/by-name/ex/expat/package.nix +++ b/pkgs/by-name/ex/expat/package.nix @@ -18,17 +18,17 @@ # files. let - version = "2.8.4"; - tag = "R_${lib.replaceStrings [ "." ] [ "_" ] version}"; + tagFor = version: "R_${lib.replaceStrings [ "." ] [ "_" ] version}"; in + stdenv.mkDerivation (finalAttrs: { pname = "expat"; - inherit version; + version = "2.8.4"; src = fetchurl { url = with finalAttrs; - "https://github.com/libexpat/libexpat/releases/download/${tag}/${pname}-${version}.tar.xz"; + "https://github.com/libexpat/libexpat/releases/download/${tagFor version}/${pname}-${version}.tar.xz"; hash = "sha256-ZWrhzI2jtOpRO7TiVPM+YkOTgITA7GI52oczdrCZhac="; }; @@ -73,7 +73,7 @@ stdenv.mkDerivation (finalAttrs: { }; meta = { - changelog = "https://github.com/libexpat/libexpat/blob/${tag}/expat/Changes"; + changelog = "https://github.com/libexpat/libexpat/blob/${tagFor finalAttrs.version}/expat/Changes"; homepage = "https://libexpat.github.io/"; description = "Stream-oriented XML parser library written in C"; mainProgram = "xmlwf"; From b55f541023122ed91594cdc56c53219e9a31cb62 Mon Sep 17 00:00:00 2001 From: K900 Date: Tue, 22 Sep 2026 17:22:26 +0300 Subject: [PATCH 029/110] expat: 2.8.4 -> 2.8.5 (cherry picked from commit b2e5a7c32ef5cfda49a88303612c10e8babcbf74) --- pkgs/by-name/ex/expat/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ex/expat/package.nix b/pkgs/by-name/ex/expat/package.nix index ed2fdf1a711e..3eec4f483a8d 100644 --- a/pkgs/by-name/ex/expat/package.nix +++ b/pkgs/by-name/ex/expat/package.nix @@ -23,13 +23,13 @@ in stdenv.mkDerivation (finalAttrs: { pname = "expat"; - version = "2.8.4"; + version = "2.8.5"; src = fetchurl { url = with finalAttrs; "https://github.com/libexpat/libexpat/releases/download/${tagFor version}/${pname}-${version}.tar.xz"; - hash = "sha256-ZWrhzI2jtOpRO7TiVPM+YkOTgITA7GI52oczdrCZhac="; + hash = "sha256-HnJ7iTPsUad6mp2a/PjmiLzkXZB8E+Nqtzk/425wMYI="; }; strictDeps = true; From 748dc3144004b6da51bd1dcccc432c48fecb875f Mon Sep 17 00:00:00 2001 From: FliegendeWurst Date: Thu, 24 Sep 2026 10:02:18 +0200 Subject: [PATCH 030/110] ghostscript: 10.07.1 -> 10.08.0 https://ghostscript.readthedocs.io/en/gs10.08.0/News.html (cherry picked from commit e909f2a01d67cdeeed13d9ae470934ce48c1dae2) --- pkgs/by-name/gh/ghostscript/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gh/ghostscript/package.nix b/pkgs/by-name/gh/ghostscript/package.nix index 6cd7c4b18ed1..f879a04b18ef 100644 --- a/pkgs/by-name/gh/ghostscript/package.nix +++ b/pkgs/by-name/gh/ghostscript/package.nix @@ -67,13 +67,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "ghostscript${lib.optionalString x11Support "-with-X"}"; - version = "10.07.1"; + version = "10.08.0"; src = fetchurl { url = "https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/download/gs${ lib.replaceStrings [ "." ] [ "" ] finalAttrs.version }/ghostscript-${finalAttrs.version}.tar.xz"; - hash = "sha256-HNt2bejbjx5YnIF/CcWFXqX2XfyFQORlpprBTBhBYCU="; + hash = "sha256-wgSSvI67lsh/ouUqCSbhzajN6V1mFF4BiscT/tXaOM8="; }; patches = [ From 193892ebb1d45a4b484d7bfb0efeb6883ddeb2d2 Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Sat, 12 Sep 2026 02:55:32 +0200 Subject: [PATCH 031/110] ibus: fix crashes with latest gtk GTK issue: https://gitlab.gnome.org/GNOME/gtk/-/work_items/8341 Upstream PR: https://github.com/ibus/ibus/pull/2929 (cherry picked from commit 2fbdf98fbc09900ecc2526e8c0aa134e43745de2) --- pkgs/by-name/ib/ibus/package.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/by-name/ib/ibus/package.nix b/pkgs/by-name/ib/ibus/package.nix index 4437b30dc434..4ca3dd5608f4 100644 --- a/pkgs/by-name/ib/ibus/package.nix +++ b/pkgs/by-name/ib/ibus/package.nix @@ -3,6 +3,7 @@ stdenv, replaceVars, fetchFromGitHub, + fetchpatch, autoreconfHook, gettext, makeWrapper, @@ -90,6 +91,15 @@ stdenv.mkDerivation (finalAttrs: { ./build-without-dbus-launch.patch # https://github.com/NixOS/nixpkgs/issues/230290 ./vala-parallelism.patch + + # Fix crashes in `gtk_im_multicontext_set_delegate` with latest GTK + # GTK issue: https://gitlab.gnome.org/GNOME/gtk/-/work_items/8341 + # Upstream PR: https://github.com/ibus/ibus/pull/2929 + (fetchpatch { + name = "fix-gtk-crashes.patch"; + url = "https://github.com/ibus/ibus/commit/c534999a9dbea2666864250d74e058ecfb46e76f.patch"; + hash = "sha256-1h48hvdrDh2Qh4+SufL147CxlfiwvP/Jv509X0WnbrA="; + }) ]; outputs = [ From 95015fc3deb4c4419534ccf2c1da938886004ccc Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sun, 27 Sep 2026 10:42:36 +0200 Subject: [PATCH 032/110] glibc: 2.42-84 -> 2.42-100 Fixes CVE-2026-19499, CVE-2026-19542, CVE-2026-8674, CVE-2026-80489, CVE-2026-77117. Does NOT contain patches for "AT_SECURE program buffer overflow via $ORIGIN processing" (CVE-2026-95818), as that isn't backported yet. --- .../libraries/glibc/2.42-master.patch | 1072 +++++++++++++++++ pkgs/development/libraries/glibc/common.nix | 4 +- 2 files changed, 1074 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/glibc/2.42-master.patch b/pkgs/development/libraries/glibc/2.42-master.patch index 8abd567ee32b..7b9c5db6c0cf 100644 --- a/pkgs/development/libraries/glibc/2.42-master.patch +++ b/pkgs/development/libraries/glibc/2.42-master.patch @@ -11172,3 +11172,1075 @@ index 731d1650e9..50b0d7a256 100644 - *pwordexp = old_word; return error; } + +commit 2ea357280d82dab462851419a2338d940516a37e +Author: Florian Weimer +Date: Fri Aug 14 13:41:16 2026 +0200 + + misc: Fix out-of-bounds array write in tdelete (bug 34506) + + Allocate the maximum array sizes directly, instead of resizing + the arrays as needed. This eliminates alloca usage from the + function, and fixes the out-of-bounds accesses. The asserts + guard against the bug coming back if the balancing of the tree + turns out not to work correctly. + + Reviewed-by: Adhemerval Zanella + (cherry picked from commit e2789c46e3bfdcd67a82bea9946b315c179e83d3) + +diff --git a/misc/tsearch.c b/misc/tsearch.c +index d15260baed..350fe15bf0 100644 +--- a/misc/tsearch.c ++++ b/misc/tsearch.c +@@ -85,6 +85,7 @@ + #include + #include + #include ++#include + #include + #include + #include +@@ -406,12 +407,13 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + int cmp; + node *rootp = (node *) vrootp; + node root, unchained; +- /* Stack of nodes so we remember the parents without recursion. It's +- _very_ unlikely that there are paths longer than 40 nodes. The tree +- would need to have around 250.000 nodes. */ +- int stacksize = 40; ++ /* Stack of nodes so we remember the parents without recursion. The ++ stack size is a conservative approximation of the maximum height ++ of a red-black tree, based on size of the address space. ++ Actual numbers are closer to 57 (32 bit) and 117 (63 bit). */ ++ enum { stacksize = 2 * UINTPTR_WIDTH }; + int sp = 0; +- node **nodestack = alloca (sizeof (node *) * stacksize); ++ node *nodestack[stacksize]; + + if (rootp == NULL) + return NULL; +@@ -424,14 +426,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + root = DEREFNODEPTR(rootp); + while ((cmp = (*compar) (key, root->key)) != 0) + { +- if (sp == stacksize) +- { +- node **newstack; +- stacksize += 20; +- newstack = alloca (sizeof (node *) * stacksize); +- nodestack = memcpy (newstack, nodestack, sp * sizeof (node *)); +- } +- ++ assert (sp < stacksize); + nodestack[sp++] = rootp; + p = DEREFNODEPTR(rootp); + if (cmp < 0) +@@ -470,13 +465,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + node upn; + for (;;) + { +- if (sp == stacksize) +- { +- node **newstack; +- stacksize += 20; +- newstack = alloca (sizeof (node *) * stacksize); +- nodestack = memcpy (newstack, nodestack, sp * sizeof (node *)); +- } ++ assert (sp < stacksize); + nodestack[sp++] = parentp; + parentp = up; + upn = DEREFNODEPTR(up); +@@ -541,6 +530,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + SETNODEPTR(pp,q); + /* Make sure pp is right if the case below tries to use + it. */ ++ assert (sp < stacksize); + nodestack[sp++] = pp = LEFTPTR(q); + q = RIGHT(p); + } +@@ -625,6 +615,7 @@ __tdelete (const void *key, void **vrootp, __compar_fn_t compar) + SETLEFT(p,RIGHT(q)); + SETRIGHT(q,p); + SETNODEPTR(pp,q); ++ assert (sp < stacksize); + nodestack[sp++] = pp = RIGHTPTR(q); + q = LEFT(p); + } + +commit 893379d4ed263d483505a66a437df37d02d12e9d +Author: Adhemerval Zanella +Date: Thu Aug 13 08:53:06 2026 -0300 + + posix: Remove unnecessary overflow check in wordexp (BZ 34090) + + The WRDE_APPEND path duplicates the caller's we_wordv array, which + already holds we_offs + we_wordc + 1 pointers. Follow-up to commit + e2cefe16c37. + + Checked on x86_64-linux-gnu and i686-linux-gnu. + + (cherry picked from commit 53ec26f1736aee747b353aaea0667b1ebdd5cae7) + +diff --git a/posix/wordexp.c b/posix/wordexp.c +index 50b0d7a256..09c20cf5d4 100644 +--- a/posix/wordexp.c ++++ b/posix/wordexp.c +@@ -35,7 +35,6 @@ + #include + #include <_itoa.h> + #include +-#include + + /* + * This is a recursive-descent-style word expansion routine. +@@ -2269,16 +2268,14 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) + { + /* WRDE_APPEND with an existing word list: duplicate the array so that + realloc during parsing does not invalidate the caller's pointer. The +- strings themselves are shared. */ +- size_t num_p; +- char **dup; +- if (INT_ADD_WRAPV (pwordexp->we_offs, pwordexp->we_wordc, &num_p) +- || INT_ADD_WRAPV (num_p, 1, &num_p)) +- return WRDE_NOSPACE; +- dup = __libc_reallocarray (NULL, num_p, sizeof *dup); ++ strings themselves are shared an the array already holds ++ 'we_offs + we_wordc + 1 pointers' (so the size computation cannot ++ overflow). */ ++ size_t num_p = pwordexp->we_offs + pwordexp->we_wordc + 1; ++ char **dup = malloc (num_p * sizeof (char *)); + if (dup == NULL) + return WRDE_NOSPACE; +- memcpy (dup, pwordexp->we_wordv, num_p * sizeof *dup); ++ memcpy (dup, pwordexp->we_wordv, num_p * sizeof (char *)); + saved_wordv = pwordexp->we_wordv; + pwordexp->we_wordv = dup; + } + +commit 6ad255db1dad9f2761935d3125b5bc7fa0e6128f +Author: Florian Weimer +Date: Thu Aug 27 13:34:54 2026 +0200 + + stdlib: Fix right-justification in strfmon (bug 34510, CVE-2026-19499) + + The memmove call did not take into account that __printf_buffer_pad + updated the buffer pointers. + + Fixes commit e88b9f0e5cc50cab57a299dc7efe1a4eb385161d + ("stdio-common: Convert vfprintf and related functions to buffers"), + which went into glibc 2.37. + + Reviewed-by: Adhemerval Zanella + (cherry picked from commit b090cf226ff65b913e41536f1f573f500855615c) + +diff --git a/stdlib/Makefile b/stdlib/Makefile +index 25f777e1a5..0f3183268a 100644 +--- a/stdlib/Makefile ++++ b/stdlib/Makefile +@@ -343,6 +343,7 @@ tests := \ + tst-stdc_leading_zeros \ + tst-stdc_trailing_ones \ + tst-stdc_trailing_zeros \ ++ tst-strfmon-bug34510 \ + tst-strfmon_l \ + tst-strfrom \ + tst-strfrom-locale \ +diff --git a/stdlib/strfmon_l.c b/stdlib/strfmon_l.c +index 5e22aac750..bd849ff470 100644 +--- a/stdlib/strfmon_l.c ++++ b/stdlib/strfmon_l.c +@@ -549,7 +549,8 @@ __vstrfmon_l_buffer (struct __printf_buffer *buf, locale_t loc, + /* Now test whether the output width is filled. */ + if (buf->write_ptr - startp < width) + { +- size_t pad_width = width - (buf->write_ptr - startp); ++ size_t written_width = buf->write_ptr - startp; ++ size_t pad_width = width - written_width; + __printf_buffer_pad (buf, ' ', pad_width); + if (__printf_buffer_has_failed (buf)) + /* Implies length check. */ +@@ -558,7 +559,7 @@ __vstrfmon_l_buffer (struct __printf_buffer *buf, locale_t loc, + Otherwise move the field contents in place. */ + if (!left) + { +- memmove (startp + pad_width, startp, buf->write_ptr - startp); ++ memmove (startp + pad_width, startp, written_width); + memset (startp, ' ', pad_width); + } + } +diff --git a/stdlib/tst-strfmon-bug34510.c b/stdlib/tst-strfmon-bug34510.c +new file mode 100644 +index 0000000000..b187bde1f4 +--- /dev/null ++++ b/stdlib/tst-strfmon-bug34510.c +@@ -0,0 +1,33 @@ ++/* Test handling of right-padding in strfmon (bug 34510, CVE-2026-19499). ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++#include ++#include ++#include ++#include ++ ++static int ++do_test (void) ++{ ++ struct support_next_to_fault ntf = support_next_to_fault_allocate (100); ++ TEST_COMPARE (strfmon (ntf.buffer, ntf.length, "%100n", 1.23), -1); ++ TEST_COMPARE (errno, E2BIG); ++ return 0; ++} ++ ++#include + +commit 67db60ee152d221782d2ae915268871d3e06a007 +Author: Florian Weimer +Date: Fri Aug 28 10:26:07 2026 +0200 + + iconvdata: SHIFT_JISX0213 decoding lacks pending character reset (CVE-2026-77117) + + This fixes bug 34556. + + Reviewed-by: Carlos O'Donell + (cherry picked from commit 68d94bbe50b7577d48998107d632ef3a0df050e3) + +diff --git a/iconvdata/shift_jisx0213.c b/iconvdata/shift_jisx0213.c +index 364298dcff..834fa81322 100644 +--- a/iconvdata/shift_jisx0213.c ++++ b/iconvdata/shift_jisx0213.c +@@ -226,6 +226,9 @@ + STANDARD_FROM_LOOP_ERR_HANDLER (1); \ + } \ + } \ ++ else \ ++ /* There was a pending character. Clear it. */ \ ++ *statep = 0; \ + \ + put32 (outptr, ch); \ + outptr += 4; \ + +commit 87c2795cf6a7584e351036ab43e74b03ccc54a83 +Author: Florian Weimer +Date: Fri Aug 28 10:26:07 2026 +0200 + + iconvdata: EUC_JISX0213 decoding lacks pending character reset (CVE-2026-80489) + + This fixes bug 34568. + + Reviewed-by: Carlos O'Donell + (cherry picked from commit 4dafa087ff5fe7df45bd37dc727e988da6b8c935) + +diff --git a/iconvdata/euc-jisx0213.c b/iconvdata/euc-jisx0213.c +index 9c3f28da2d..f0305c113a 100644 +--- a/iconvdata/euc-jisx0213.c ++++ b/iconvdata/euc-jisx0213.c +@@ -224,6 +224,9 @@ + STANDARD_FROM_LOOP_ERR_HANDLER (1); \ + } \ + } \ ++ else \ ++ /* There was a pending character. Clear it. */ \ ++ *statep = 0; \ + \ + put32 (outptr, ch); \ + outptr += 4; \ + +commit 0afd4d5feb591512629d5f46ceab310b54a06034 +Author: Florian Weimer +Date: Fri Aug 28 10:26:07 2026 +0200 + + iconvdata: Test case for bug 34556, bug 34568 + + Assisted-by: LLM + Reviewed-by: Carlos O'Donell + (cherry picked from commit 35efcffa97553df071bc37ab31fd7dc2c634e7da) + +diff --git a/iconvdata/Makefile b/iconvdata/Makefile +index cc689f63e9..36f48749d2 100644 +--- a/iconvdata/Makefile ++++ b/iconvdata/Makefile +@@ -76,7 +76,8 @@ tests = bug-iconv1 bug-iconv2 tst-loading tst-e2big tst-iconv4 bug-iconv4 \ + tst-iconv6 bug-iconv5 bug-iconv6 tst-iconv7 bug-iconv8 bug-iconv9 \ + bug-iconv10 bug-iconv11 bug-iconv12 tst-iconv-big5-hkscs-to-2ucs4 \ + bug-iconv13 bug-iconv14 bug-iconv15 \ +- tst-iconv-iso-2022-cn-ext tst-bug33980 ++ tst-iconv-iso-2022-cn-ext tst-bug33980 \ ++ tst-jisx0213-progress + ifeq ($(have-thread-library),yes) + tests += bug-iconv3 + endif +@@ -335,6 +336,8 @@ $(objpfx)tst-iconv-iso-2022-cn-ext.out: $(addprefix $(objpfx), $(gconv-modules)) + $(addprefix $(objpfx),$(modules.so)) + $(objpfx)tst-bug33980.out: $(addprefix $(objpfx), $(gconv-modules)) \ + $(addprefix $(objpfx),$(modules.so)) ++$(objpfx)tst-jisx0213-progress.out: \ ++ $(addprefix $(objpfx), $(gconv-modules)) $(addprefix $(objpfx),$(modules.so)) + + $(objpfx)iconv-test.out: run-iconv-test.sh \ + $(addprefix $(objpfx), $(gconv-modules)) \ +diff --git a/iconvdata/tst-jisx0213-progress.c b/iconvdata/tst-jisx0213-progress.c +new file mode 100644 +index 0000000000..7b2073be1f +--- /dev/null ++++ b/iconvdata/tst-jisx0213-progress.c +@@ -0,0 +1,124 @@ ++/* Test JISX0213 combining character conversion progress (bug 34556, bug 34568). ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++/* Certain JISX0213 byte sequences map to a combining sequence, for ++ example U+304B (HIRAGANA LETTER KA) followed by U+309A (COMBINING ++ SEMI-VOICED SOUND MARK). When converting to internal encoding ++ (actually UTF-32) with a small output buffer, the first code point ++ is emitted and the second is queued in the converter state. This ++ test verifies that the queued code point is consumed exactly once ++ on retry, so that the conversion makes progress and terminates. */ ++ ++#include ++#include ++#include ++#include ++ ++#include ++#include ++ ++static void ++test_one (const char *charset, const char *input, size_t outbufsize) ++{ ++ printf ("info: %s: testing output buffer size %zu\n", charset, outbufsize); ++ ++ /* Expected UTF-32 output. */ ++ static const wchar_t expected[] = { 0x304b, 0x309a, 'A' }; ++ ++ /* Use WCHAR_T encoding to avoid the BOM. */ ++ iconv_t cd = iconv_open ("WCHAR_T", charset); ++ TEST_VERIFY_EXIT (cd != (iconv_t) -1); ++ ++ char result[64]; ++ size_t result_len = 0; ++ ++ char *inptr = (char *) input; ++ size_t inleft = strlen (input); ++ ++ char outbuf[64]; ++ ++ int iterations = 0; ++ while (inleft > 0) ++ { ++ char *outptr = outbuf; ++ size_t outleft = outbufsize; ++ size_t inleft_before = inleft; ++ ++ size_t ret = iconv (cd, &inptr, &inleft, &outptr, &outleft); ++ size_t produced = outptr - outbuf; ++ ++ TEST_VERIFY_EXIT (result_len + produced <= sizeof (result)); ++ memcpy (result + result_len, outbuf, produced); ++ result_len += produced; ++ ++ if (ret == (size_t) -1 && errno == E2BIG) ++ { ++ if (produced == 0 && inleft == inleft_before) ++ { ++ /* Output buffer too small for a single code point. */ ++ TEST_VERIFY_EXIT (outbufsize < 4); ++ break; ++ } ++ /* Bound iterations to detect non-progress bugs. */ ++ if (++iterations < 10) ++ continue; ++ else ++ { ++ FAIL ("%s: no progress", charset); ++ goto out; ++ } ++ } ++ if (ret == (size_t) -1) ++ FAIL_EXIT1 ("outbufsize %zu: iconv: %m", outbufsize); ++ break; ++ } ++ ++ /* Flush pending converter state. */ ++ { ++ char *outptr = outbuf; ++ size_t outleft = outbufsize; ++ size_t ret = iconv (cd, NULL, NULL, &outptr, &outleft); ++ TEST_VERIFY (ret == 0); ++ size_t produced = outptr - outbuf; ++ memcpy (result + result_len, outbuf, produced); ++ result_len += produced; ++ } ++ ++ if (outbufsize >= 4) ++ { ++ TEST_COMPARE (inleft, 0); ++ TEST_COMPARE_BLOB (result, result_len, ++ expected, sizeof (expected)); ++ } ++ ++ out: ++ TEST_VERIFY_EXIT (iconv_close (cd) == 0); ++} ++ ++static int ++do_test (void) ++{ ++ for (size_t outbufsize = 1; outbufsize <= 16; outbufsize++) ++ { ++ test_one ("EUC-JISX0213", "\244\367A", outbufsize); ++ test_one ("SHIFT_JISX0213", "\202\365A", outbufsize); ++ } ++ return 0; ++} ++ ++#include + +commit 2ba6f4c063e9b2d451e25e758d704f33b5d958a6 +Author: Dongkyun Son +Date: Fri Sep 4 21:28:41 2026 +0900 + + libio: Fix CVE-2026-18374 heap buffer overflow in ccs= handling + + When fopen() is called with a ,ccs= parameter whose value becomes empty + after strip(), the code must reject it with EINVAL instead of attempting + to use it. The original upstr() fallback could read past the ',' delimiter + and cause a heap buffer overflow. + + The fix checks if the charset specification is empty after strip() and + returns EINVAL immediately, preventing the overflow and following the + approach described in BZ #34574. + + CVE-2026-18374 - CVSS 4.9 (AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L) + + Reported-by: AISLE in partnership with Red Hat + Signed-off-by: Dongkyun Son + Reviewed-by: Florian Weimer + (cherry picked from commit 9765a538ebf8661a6e5578e01e35a3dd30db7eb4) + +diff --git a/libio/fileops.c b/libio/fileops.c +index 0cce828859..3e2ac36d48 100644 +--- a/libio/fileops.c ++++ b/libio/fileops.c +@@ -339,12 +339,14 @@ _IO_new_file_fopen (FILE *fp, const char *filename, const char *mode, + *((char *) __mempcpy (ccs, cs + 5, endp - (cs + 5))) = '\0'; + strip (ccs, ccs); + +- if (__wcsmbs_named_conv (&fcts, ccs[2] == '\0' +- ? upstr (ccs, cs + 5) : ccs) != 0) ++ /* After stripping, ccs[2] == '\0' means the charset name is empty. ++ This is not a valid charset and would cause problems downstream. ++ Reject it with EINVAL (BZ #34574, CVE-2026-18374). */ ++ if (ccs[2] == '\0' || __wcsmbs_named_conv (&fcts, ccs) != 0) + { +- /* Something went wrong, we cannot load the conversion modules. +- This means we cannot proceed since the user explicitly asked +- for these. */ ++ /* Either the charset name is empty after strip(), or conversion ++ modules cannot be loaded. This means we cannot proceed since ++ the user explicitly asked for character conversion. */ + (void) _IO_file_close_it (fp); + free (ccs); + __set_errno (EINVAL); + +commit 552849c43c8f14b35af3c0496502748b9c549a2a +Author: Shamil Abdulaev +Date: Thu Sep 3 20:19:42 2026 +0300 + + libio: Add test for fopen with an empty ", ccs=" value [BZ #34574] + + This goes on top of the fix for CVE-2026-18374. The test runs the + reproducer from the bug report, plus "w,ccs=" and "w,ccs=,", and + expects NULL with errno set to EINVAL. + + Signed-off-by: Shamil Abdulaev + Reviewed-by: Florian Weimer + (cherry picked from commit cca93e5d88d3d4ed073c03100467696f652269e7) + +diff --git a/libio/Makefile b/libio/Makefile +index fa2b8ae791..c6728d8552 100644 +--- a/libio/Makefile ++++ b/libio/Makefile +@@ -107,6 +107,7 @@ tests = \ + tst-fgetc-after-eof \ + tst-fgetwc \ + tst-fgetws \ ++ tst-fopen-ccs-empty \ + tst-fopenloc2 \ + tst-fputws \ + tst-freopen \ +diff --git a/libio/tst-fopen-ccs-empty.c b/libio/tst-fopen-ccs-empty.c +new file mode 100644 +index 0000000000..64723965e1 +--- /dev/null ++++ b/libio/tst-fopen-ccs-empty.c +@@ -0,0 +1,62 @@ ++/* Test fopen with an empty ",ccs=" value in the mode string (bug 34574). ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++#include ++ ++static void ++check_fopen_fails (const char *path, const char *mode) ++{ ++ errno = 0; ++ FILE *fp = fopen (path, mode); ++ TEST_VERIFY (fp == NULL); ++ TEST_COMPARE (errno, EINVAL); ++ if (fp != NULL) ++ fclose (fp); ++} ++ ++static int ++do_test (void) ++{ ++ char *path; ++ xclose (create_temp_file ("tst-fopen-ccs-empty", &path)); ++ ++ /* The value is blank and the mode string continues well past it. */ ++ enum { size = 1024 * 1024 }; ++ char *mode = xmalloc (size); ++ memset (mode, 'X', size); ++ mode[size - 1] = '\0'; ++ static const char prefix[] = "w,ccs= ,"; ++ memcpy (mode, prefix, sizeof (prefix) - 1); ++ check_fopen_fails (path, mode); ++ free (mode); ++ ++ check_fopen_fails (path, "w,ccs="); ++ check_fopen_fails (path, "w,ccs=,"); ++ ++ free (path); ++ return 0; ++} ++ ++#include + +commit bc76f2aa9b26b8d15bf8bb5cb13d5564cba517e8 +Author: Andreas Schwab +Date: Tue May 19 11:39:15 2026 +0200 + + nss_files: fix swapped arguments in service parser + + The port number in the service file is a decimal number followed by a + single slash. + + (cherry picked from commit 66efdda2f8bce2680f5984a6bd5e488a9b528ead) + +diff --git a/nss/nss_files/files-service.c b/nss/nss_files/files-service.c +index a6503f7571..7b152b61a4 100644 +--- a/nss/nss_files/files-service.c ++++ b/nss/nss_files/files-service.c +@@ -32,7 +32,7 @@ struct servent_data {}; + LINE_PARSER + ("#", + STRING_FIELD (result->s_name, isspace, 1); +- INT_FIELD (result->s_port, ISSLASH, 10, 0, htons); ++ INT_FIELD (result->s_port, ISSLASH, 0, 10, htons); + STRING_FIELD (result->s_proto, isspace, 1); + ) + + +commit a27376f0dc77ba6eb8848d1ff2808510507b31d7 +Author: Andreas Schwab +Date: Tue May 19 11:45:41 2026 +0200 + + nss_files: use booleans in parser macro calls + + The swallow argument in the INT_FIELD and STRING_FIELD macros is used as a + boolean, change all callers to use false and true instead of 0 and 1. + + (cherry picked from commit aa56ccb98b701680ad48431fea2a1966bac7fa31) + +diff --git a/nss/nss_files/files-ethers.c b/nss/nss_files/files-ethers.c +index 3c8715133d..c9604f0f87 100644 +--- a/nss/nss_files/files-ethers.c ++++ b/nss/nss_files/files-ethers.c +@@ -36,16 +36,16 @@ LINE_PARSER + unsigned int number; + + if (cnt < 5) +- INT_FIELD (number, ISCOLON , 0, 16, (unsigned int)) ++ INT_FIELD (number, ISCOLON , false, 16, (unsigned int)) + else +- INT_FIELD (number, isspace, 1, 16, (unsigned int)) ++ INT_FIELD (number, isspace, true, 16, (unsigned int)) + + if (number > 0xff) + return 0; + result->e_addr.ether_addr_octet[cnt] = number; + } + }; +- STRING_FIELD (result->e_name, isspace, 1); ++ STRING_FIELD (result->e_name, isspace, true); + ) + + +diff --git a/nss/nss_files/files-hosts.c b/nss/nss_files/files-hosts.c +index d8987c723a..ce1f20302c 100644 +--- a/nss/nss_files/files-hosts.c ++++ b/nss/nss_files/files-hosts.c +@@ -53,7 +53,7 @@ LINE_PARSER + { + char *addr; + +- STRING_FIELD (addr, isspace, 1); ++ STRING_FIELD (addr, isspace, true); + + /* Parse address. */ + if (__inet_pton (af == AF_UNSPEC ? AF_INET : af, addr, entdata->host_addr) +@@ -96,7 +96,7 @@ LINE_PARSER + entdata->h_addr_ptrs[1] = NULL; + result->h_addr_list = entdata->h_addr_ptrs; + +- STRING_FIELD (result->h_name, isspace, 1); ++ STRING_FIELD (result->h_name, isspace, true); + }) + + #define EXTRA_ARGS_VALUE , AF_INET, 0 +diff --git a/nss/nss_files/files-network.c b/nss/nss_files/files-network.c +index f08daaf55f..4fafdb2110 100644 +--- a/nss/nss_files/files-network.c ++++ b/nss/nss_files/files-network.c +@@ -38,9 +38,9 @@ LINE_PARSER + char *cp; + int n = 1; + +- STRING_FIELD (result->n_name, isspace, 1); ++ STRING_FIELD (result->n_name, isspace, true); + +- STRING_FIELD (addr, isspace, 1); ++ STRING_FIELD (addr, isspace, true); + /* 'inet_network' does not add zeroes at the end if the network number + does not contain four byte values. We shift result ourselves if + necessary. */ +diff --git a/nss/nss_files/files-parse.c b/nss/nss_files/files-parse.c +index 3ebd61f6e2..ed268f849d 100644 +--- a/nss/nss_files/files-parse.c ++++ b/nss/nss_files/files-parse.c +@@ -20,6 +20,7 @@ + #include + #include + #include ++#include + #include + #include + +diff --git a/nss/nss_files/files-proto.c b/nss/nss_files/files-proto.c +index e10255ebaf..8bbbc6e0cb 100644 +--- a/nss/nss_files/files-proto.c ++++ b/nss/nss_files/files-proto.c +@@ -29,8 +29,8 @@ struct protoent_data {}; + #include "files-parse.c" + LINE_PARSER + ("#", +- STRING_FIELD (result->p_name, isspace, 1); +- INT_FIELD (result->p_proto, isspace, 1, 10,); ++ STRING_FIELD (result->p_name, isspace, true); ++ INT_FIELD (result->p_proto, isspace, true, 10,); + ) + + #include GENERIC +diff --git a/nss/nss_files/files-rpc.c b/nss/nss_files/files-rpc.c +index 79ae72c2dd..1aaaad5d18 100644 +--- a/nss/nss_files/files-rpc.c ++++ b/nss/nss_files/files-rpc.c +@@ -29,8 +29,8 @@ struct rpcent_data {}; + #include "files-parse.c" + LINE_PARSER + ("#", +- STRING_FIELD (result->r_name, isspace, 1); +- INT_FIELD (result->r_number, isspace, 1, 10,); ++ STRING_FIELD (result->r_name, isspace, true); ++ INT_FIELD (result->r_number, isspace, true, 10,); + ) + + #include GENERIC +diff --git a/nss/nss_files/files-service.c b/nss/nss_files/files-service.c +index 7b152b61a4..81b4ef726b 100644 +--- a/nss/nss_files/files-service.c ++++ b/nss/nss_files/files-service.c +@@ -31,9 +31,9 @@ struct servent_data {}; + #define ISSLASH(c) ((c) == '/') + LINE_PARSER + ("#", +- STRING_FIELD (result->s_name, isspace, 1); +- INT_FIELD (result->s_port, ISSLASH, 0, 10, htons); +- STRING_FIELD (result->s_proto, isspace, 1); ++ STRING_FIELD (result->s_name, isspace, true); ++ INT_FIELD (result->s_port, ISSLASH, false, 10, htons); ++ STRING_FIELD (result->s_proto, isspace, true); + ) + + #include GENERIC + +commit 5e45e86fed68c24cd1ba94056e77275e2eab5fae +Author: Adhemerval Zanella +Date: Thu May 28 17:30:07 2026 -0300 + + hesiod: fix swapped arguments in service parser + + The port number in the service file is a decimal number followed by a + single slash. + + Reviewed-by: H.J. Lu + (cherry picked from commit 41e9457c53610c6c79a7e036f61de032686e9ef0) + +diff --git a/hesiod/nss_hesiod/hesiod-service.c b/hesiod/nss_hesiod/hesiod-service.c +index ae3b51fa28..525af1e6ce 100644 +--- a/hesiod/nss_hesiod/hesiod-service.c ++++ b/hesiod/nss_hesiod/hesiod-service.c +@@ -41,7 +41,7 @@ LINE_PARSER + ("#", + STRING_FIELD (result->s_name, ISSC_OR_SPACE, 1); + STRING_FIELD (result->s_proto, ISSC_OR_SPACE, 1); +- INT_FIELD (result->s_port, ISSC_OR_SPACE, 10, 0, htons); ++ INT_FIELD (result->s_port, ISSC_OR_SPACE, 0, 10, htons); + ) + + enum nss_status + +commit d407ace6e19304d740a1d0ded7920f49ab5c9820 +Author: Adhemerval Zanella +Date: Thu May 28 17:30:08 2026 -0300 + + hesiod: use booleans in parser macro calls + + The swallow argument in the INT_FIELD and STRING_FIELD macros is used as a + boolean, change all callers to use false and true instead of 0 and 1. + + Reviewed-by: H.J. Lu + (cherry picked from commit 7052455f0e85673abebad5d5814e73e22287c081) + +diff --git a/hesiod/nss_hesiod/hesiod-proto.c b/hesiod/nss_hesiod/hesiod-proto.c +index 751b9c0219..9518cf3d0f 100644 +--- a/hesiod/nss_hesiod/hesiod-proto.c ++++ b/hesiod/nss_hesiod/hesiod-proto.c +@@ -39,8 +39,8 @@ struct protoent_data {}; + #include + LINE_PARSER + ("#", +- STRING_FIELD (result->p_name, isspace, 1); +- INT_FIELD (result->p_proto, isspace, 1, 10,); ++ STRING_FIELD (result->p_name, isspace, true); ++ INT_FIELD (result->p_proto, isspace, true, 10,); + ) + + enum nss_status +diff --git a/hesiod/nss_hesiod/hesiod-service.c b/hesiod/nss_hesiod/hesiod-service.c +index 525af1e6ce..748e1db505 100644 +--- a/hesiod/nss_hesiod/hesiod-service.c ++++ b/hesiod/nss_hesiod/hesiod-service.c +@@ -39,9 +39,9 @@ struct servent_data {}; + #define ISSC_OR_SPACE(c) ((c) == ';' || isspace (c)) + LINE_PARSER + ("#", +- STRING_FIELD (result->s_name, ISSC_OR_SPACE, 1); +- STRING_FIELD (result->s_proto, ISSC_OR_SPACE, 1); +- INT_FIELD (result->s_port, ISSC_OR_SPACE, 0, 10, htons); ++ STRING_FIELD (result->s_name, ISSC_OR_SPACE, true); ++ STRING_FIELD (result->s_proto, ISSC_OR_SPACE, true); ++ INT_FIELD (result->s_port, ISSC_OR_SPACE, false, 10, htons); + ) + + enum nss_status + +commit 6c453bb60669c9612bfe18f7f211d2dc28cad943 +Author: Hemanth Kumar M D +Date: Mon Sep 7 01:59:06 2026 -0700 + + nptl: Skip pretty-printer tests without python3 [BZ #34507] + + The tests-printers-out rule in Rules wraps $(PYTHON) through + $(test-wrapper-env). Unlike ordinary tests, which wrap a freshly built + target binary, this wraps python3, a build-host tool. When cross-testing + with test-wrapper set (e.g. via scripts/cross-test-ssh.sh) the whole + command is forwarded to the target; if the target lacks python3 the shell + returns 127 and evaluate-test.sh reports the six nptl pretty-printer + tests as FAIL instead of UNSUPPORTED. + + scripts/test_printers_common.py already exits UNSUPPORTED (77) when its + dependencies are missing, but that is unreachable when python3 itself is + absent. + + Guard the invocation with a "command -v" check so the recipe exits 77 + (UNSUPPORTED) when python3 is not found. Native builds are unaffected, + as configure requires python3. + + Signed-off-by: Hemanth Kumar M D + Suggested-by: Adhemerval Zanella Netto + Reviewed-by: Adhemerval Zanella + (cherry picked from commit c958d789db3bd8dbfb93868d8a975d13a3d66396) + +diff --git a/NEWS b/NEWS +index 7e7e1930dd..df9b76f44e 100644 +--- a/NEWS ++++ b/NEWS +@@ -18,6 +18,8 @@ The following bugs were resolved with this release: + [33361] nss: Group merge does not react to ERANGE during merge + [33814] glob: wordexp with WRDE_REUSE and WRDE_APPEND may return + uninitialized memory ++ [34507] nptl: Pretty-printer tests FAIL instead of UNSUPPORTED when ++ cross-testing without python3 on target + + Version 2.42 + +diff --git a/Rules b/Rules +index 44c041c491..0087a772f6 100644 +--- a/Rules ++++ b/Rules +@@ -423,8 +423,9 @@ py-env := PYTHONPATH=$(py-const-dir):$(..)scripts:$${PYTHONPATH} + # The pretty printer files and test_common_printers.py must be present for all. + $(tests-printers-out): $(objpfx)%.out: $(objpfx)% %.py %.c $(pretty-printers) \ + $(..)scripts/test_printers_common.py +- $(test-wrapper-env) $(py-env) \ +- $(PYTHON) $*.py $*.c $(objpfx)$* $(pretty-printers) > $@; \ ++ $(test-wrapper-env) $(py-env) sh -c \ ++ 'command -v $(firstword $(PYTHON)) > /dev/null 2>&1 || exit 77; \ ++ exec $(PYTHON) $*.py $*.c $(objpfx)$* $(pretty-printers)' > $@; \ + $(evaluate-test) + endif + + +commit 1bab8b37dc20bcae733d4310345aae08cab13dfa +Author: Paul Eggert +Date: Wed Sep 9 15:47:44 2026 -0700 + + zic: keep needed last transition to new type (bug 34618) + + Do not mishandle tzdata 2026b+'s temporary hacks that work around + bugs in the Unicode CLDR project when localizing recent + timekeeping changes in western Canada. Unfortunately, the hacks + run afoul of a zic bug in glibc 2.40 through 2.43, + corresponding to tzcode 2023d through 2024a. + + The bug causes zic in its default -b slim mode to generate TZif + files that do not conform to Internet RFC 9636 section 3.3, and + these buggy files in turn cause some TZif readers, including + tzcode itself, to ignore the 2026-11-01 timekeeping transitions in + America/Vancouver and elsewhere in western Canada. + + * timezone/zic.c (outzone): Omit an incorrect use of ‘useuntil’. + This fixes a bug introduced in “Fix zic bug with Palestine after + 2075” (tz commit 35c116b7536a36c43eb7cd36bff71ad0c5ecf071 dated + 2023-10-15), which caused zic to mess up if the last transition is + to a new time type. + + This artificial input illustrates the bug: + Rule Canada 2007 max - Mar Sun>=8 2:00 1:00 D + Rule Canada 2007 max - Nov Sun>=1 2:00 0 S + Zone America/Vancouver -8:00 - PST 2026 Mar 9 + -8:00 Canada P%sT 2026 Nov 1 02:00 + -7:00 - MST + Without the fix, zic generates a nonconforming TZif file that omits + the last transition even though the trailing TZ string is "MST7". + + (cherry picked from 2026-03-07 tz commit + ) + +diff --git a/timezone/zic.c b/timezone/zic.c +index d5d30163b0..17c6f906b2 100644 +--- a/timezone/zic.c ++++ b/timezone/zic.c +@@ -3234,7 +3234,7 @@ outzone(const struct zone *zpfirst, ptrdiff_t zonecount) + startttisut); + if (usestart) { + addtt(starttime, type); +- if (useuntil && nonTZlimtime < starttime) { ++ if (nonTZlimtime < starttime) { + nonTZlimtime = starttime; + nonTZlimtype = type; + } + +commit c0c8a45dee30c8089822d859575a3ad4324b15ff +Author: Adhemerval Zanella +Date: Mon Sep 14 17:08:03 2026 -0300 + + resolv: Fix assertion failure on search list truncation [BZ 31026, CVE-2026-8674] + + update_from_conf copies the search list into the 256-byte + resp->defdname and truncates it when an entry does not fit, then + asserts that resolv_conf_matches accepts the result. + + The truncation check there compared the accumulated size against + sizeof (resp->dnsrch) (the pointer array) instead of resp->defdname, + and the empty-list case did not account for a first entry that does + not fit at all. A long search domain in resolv.conf or LOCALDOMAIN + thus aborts any process using the resolver. + + Check whether the entry fits in the remaining defdname space, matching + alloc_buffer_copy_string, and also accept an empty resp->dnsrch when + the first entry is too long. Add tests covering both cases through + the search and domain directives. + + Checked on x86_64-linux-gnu and i686-linux-gnu. + Reviewed-by: Florian Weimer + + (cherry picked from commit 506ea57086bfb9ce3daff1c14246a1cb532aba0a) + +diff --git a/resolv/resolv_conf.c b/resolv/resolv_conf.c +index dcf92ee90e..0418267044 100644 +--- a/resolv/resolv_conf.c ++++ b/resolv/resolv_conf.c +@@ -281,8 +281,12 @@ resolv_conf_matches (const struct __res_state *resp, + { + if (resp->dnsrch[0] == NULL) + { +- /* Empty search list. No default domain name. */ +- return conf->search_list_size == 0 && resp->defdname[0] == '\0'; ++ /* Empty search list, or the first entry does not fit in ++ resp->defdname. No default domain name. */ ++ return resp->defdname[0] == '\0' ++ && (conf->search_list_size == 0 ++ || (strlen (conf->search_list[0]) + 1 ++ > sizeof (resp->defdname))); + } + + if (resp->dnsrch[0] != resp->defdname) +@@ -309,11 +313,12 @@ resolv_conf_matches (const struct __res_state *resp, + } + else + { +- /* resp->dnsrch is truncated if the number of elements +- exceeds MAXDNSRCH, or if the combined storage space for +- the search list exceeds what can be stored in +- resp->defdname. */ +- if (i == MAXDNSRCH || search_list_size > sizeof (resp->dnsrch)) ++ /* resp->dnsrch is truncated if the number of elements exceeds ++ MAXDNSRCH, or if conf->search_list[i] does not fit in the ++ remaining space of resp->defdname. */ ++ if (i == MAXDNSRCH ++ || (search_list_size + strlen (conf->search_list[i]) + 1 ++ > sizeof (resp->defdname))) + break; + /* Otherwise, a mismatch indicates a match failure. */ + return false; +diff --git a/resolv/tst-resolv-res_init-skeleton.c b/resolv/tst-resolv-res_init-skeleton.c +index 3ccbe71db9..4e9c57f3cb 100644 +--- a/resolv/tst-resolv-res_init-skeleton.c ++++ b/resolv/tst-resolv-res_init-skeleton.c +@@ -724,6 +724,41 @@ struct test_case test_cases[] = + "nameserver 192.0.2.1\n" + "; nameserver[0]: [192.0.2.1]:53\n" + }, ++/* Search list entries which do not fit in the legacy 256-byte ++ resp->defdname buffer (bug 31026). LONG244 is 244 characters long, ++ so it does not fit after "example.com\0" (12 bytes). LONG256 is 256 ++ characters long, so it does not fit even as the first entry. */ ++#define LBL63 "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" ++#define LONG244 LBL63 "." LBL63 "." LBL63 "." \ ++ "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb" ++#define LONG256 LBL63 "." LBL63 "." LBL63 "." LBL63 "a" ++ {.name = "search list truncated at long entry after short entry", ++ .conf = "nameserver 192.0.2.1\n" ++ "search example.com " LONG244 "\n", ++ .expected = "search example.com\n" ++ "; search[0]: example.com\n" ++ "; search[1]: " LONG244 "\n" ++ "nameserver 192.0.2.1\n" ++ "; nameserver[0]: [192.0.2.1]:53\n" ++ }, ++ {.name = "search list truncated at long first entry", ++ .conf = "nameserver 192.0.2.1\n" ++ "search " LONG256 " example.com\n", ++ .expected = "; search[0]: " LONG256 "\n" ++ "; search[1]: example.com\n" ++ "nameserver 192.0.2.1\n" ++ "; nameserver[0]: [192.0.2.1]:53\n" ++ }, ++ {.name = "long first entry from the domain directive", ++ .conf = "nameserver 192.0.2.1\n" ++ "domain " LONG256 "\n", ++ .expected = "; search[0]: " LONG256 "\n" ++ "nameserver 192.0.2.1\n" ++ "; nameserver[0]: [192.0.2.1]:53\n" ++ }, ++#undef LONG256 ++#undef LONG244 ++#undef LBL63 + {.name = "trust-ad flag", + .conf = "options trust-ad\n" + "nameserver 192.0.2.1\n", + +commit c7169c068453a95f104f47a4eb79a902721712dd +Author: Mark Wielaard +Date: Fri Sep 18 00:24:34 2026 +0200 + + stdlib: Don't call clearenv from __libc_setenv_freemem + + Since commit 7a61e7f557a9 ("stdlib: Make getenv thread-safe in more + cases") clearenv doesn't call any deallocation functions anymore. + __libc_setenv_freemem (called from __libc_freeres) now clears all + backing arrays. So there is no reason anymore to call clearenv from + __libc_setenv_freemem. + + Tested against valgrind memcheck with --run-libc-freeres=yes which is + the default. + + Reviewed-by: Florian Weimer + (cherry picked from commit b837aae83df8fe80c8977b5ed5c538aebd2b152a) + +diff --git a/stdlib/setenv.c b/stdlib/setenv.c +index 0ef5dde373..e25fbff351 100644 +--- a/stdlib/setenv.c ++++ b/stdlib/setenv.c +@@ -394,9 +394,6 @@ clearenv (void) + void + __libc_setenv_freemem (void) + { +- /* Remove all traces. */ +- clearenv (); +- + /* Clear all backing arrays. */ + while (__environ_array_list != NULL) + { diff --git a/pkgs/development/libraries/glibc/common.nix b/pkgs/development/libraries/glibc/common.nix index 6b98f5a3a889..8b2d7f83f950 100644 --- a/pkgs/development/libraries/glibc/common.nix +++ b/pkgs/development/libraries/glibc/common.nix @@ -51,7 +51,7 @@ let version = "2.42"; - patchSuffix = "-84"; + patchSuffix = "-100"; sha256 = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; in @@ -69,7 +69,7 @@ stdenv.mkDerivation ( /* No tarballs for stable upstream branch, only https://sourceware.org/git/glibc.git and using git would complicate bootstrapping. $ git fetch --all -p && git checkout origin/release/2.42/master && git describe - glibc-2.42-67-g4ebd33dd77 + glibc-2.42-100-gc7169c0684 $ git show --minimal --reverse glibc-2.42.. ':!ADVISORIES' > 2.42-master.patch To compare the archive contents zdiff can be used. From 1d9b0a6dc602eb7682e21959a32b11bd31c5b4c5 Mon Sep 17 00:00:00 2001 From: whoomee Date: Sun, 27 Sep 2026 10:04:24 +0200 Subject: [PATCH 033/110] fribidi: 1.0.16 -> 1.0.17 (cherry picked from commit 0866ba5e215f6043db4efdc9f59889ad4f926a4e) --- pkgs/by-name/fr/fribidi/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/fr/fribidi/package.nix b/pkgs/by-name/fr/fribidi/package.nix index f8fd5f3171c9..5ba9a58fbfb0 100644 --- a/pkgs/by-name/fr/fribidi/package.nix +++ b/pkgs/by-name/fr/fribidi/package.nix @@ -13,7 +13,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "fribidi"; - version = "1.0.16"; + version = "1.0.17"; outputs = [ "out" @@ -26,7 +26,7 @@ stdenv.mkDerivation (finalAttrs: { url = with finalAttrs; "https://github.com/fribidi/fribidi/releases/download/v${version}/${pname}-${version}.tar.xz"; - sha256 = "sha256-GxzeWyNdQEeekb4vDoijCeMhTIq0cOyKJ0TYKlqeoFw="; + sha256 = "sha256-aUnc3ifUHOutH9dB/K/DbVWhAg0thy1KbrORTKq7raI="; }; postPatch = '' From 78de0904d9df40f36d20d302e496385d71220f55 Mon Sep 17 00:00:00 2001 From: whoomee Date: Sun, 27 Sep 2026 10:13:23 +0200 Subject: [PATCH 034/110] fribidi: add pango/libass in passthru.tests (cherry picked from commit 3b39b2d0dab31bd72cb1d851df4c923a181fd6b5) --- pkgs/by-name/fr/fribidi/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/fr/fribidi/package.nix b/pkgs/by-name/fr/fribidi/package.nix index 5ba9a58fbfb0..6d36dd5cb5f1 100644 --- a/pkgs/by-name/fr/fribidi/package.nix +++ b/pkgs/by-name/fr/fribidi/package.nix @@ -9,6 +9,10 @@ fixDarwinDylibNames, python3, testers, + + # for passthru.tests + pango, + libass, }: stdenv.mkDerivation (finalAttrs: { @@ -49,6 +53,7 @@ stdenv.mkDerivation (finalAttrs: { pkg-config = testers.hasPkgConfigModules { package = finalAttrs.finalPackage; }; + inherit pango libass; }; meta = { From d4bedbb5759d763a903fc8def533c0e61c4077a3 Mon Sep 17 00:00:00 2001 From: whoomee Date: Sun, 27 Sep 2026 10:13:41 +0200 Subject: [PATCH 035/110] fribidi: modernize (cherry picked from commit 7b9d55b6272476983ccc9a0239edc8279c7d4a82) --- pkgs/by-name/fr/fribidi/package.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/by-name/fr/fribidi/package.nix b/pkgs/by-name/fr/fribidi/package.nix index 6d36dd5cb5f1..ebf1a65970c7 100644 --- a/pkgs/by-name/fr/fribidi/package.nix +++ b/pkgs/by-name/fr/fribidi/package.nix @@ -19,6 +19,9 @@ stdenv.mkDerivation (finalAttrs: { pname = "fribidi"; version = "1.0.17"; + __structuredAttrs = true; + strictDeps = true; + outputs = [ "out" "dev" @@ -46,6 +49,13 @@ stdenv.mkDerivation (finalAttrs: { depsBuildBuild = [ buildPackages.stdenv.cc ]; + mesonFlags = lib.mapAttrsToList lib.mesonBool { + tests = finalAttrs.finalPackage.doCheck; + docs = true; + bin = true; + deprecated = true; + }; + doCheck = true; nativeCheckInputs = [ python3 ]; From 0a494bb70113fb14c6096ad680d8d0d7cbc4ff3c Mon Sep 17 00:00:00 2001 From: whoomee Date: Sun, 27 Sep 2026 10:13:58 +0200 Subject: [PATCH 036/110] fribidi: add maintainer tmarkus (cherry picked from commit 5c51fed8c5123fb774009b429b7c11e41f9de8ad) --- pkgs/by-name/fr/fribidi/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/fr/fribidi/package.nix b/pkgs/by-name/fr/fribidi/package.nix index ebf1a65970c7..2e751e25a0fa 100644 --- a/pkgs/by-name/fr/fribidi/package.nix +++ b/pkgs/by-name/fr/fribidi/package.nix @@ -73,5 +73,6 @@ stdenv.mkDerivation (finalAttrs: { license = lib.licenses.lgpl21; platforms = lib.platforms.unix; pkgConfigModules = [ "fribidi" ]; + maintainers = with lib.maintainers; [ tmarkus ]; }; }) From 169e090ce96a7b2ba702e3dbc83f409a1f79a0fb Mon Sep 17 00:00:00 2001 From: whoomee Date: Sun, 27 Sep 2026 10:14:14 +0200 Subject: [PATCH 037/110] fribidi: specify meta.changelog (cherry picked from commit b231de7d5563d412a8d61ba49ee1ea11d8375ee6) --- pkgs/by-name/fr/fribidi/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/fr/fribidi/package.nix b/pkgs/by-name/fr/fribidi/package.nix index 2e751e25a0fa..5231148cdc5c 100644 --- a/pkgs/by-name/fr/fribidi/package.nix +++ b/pkgs/by-name/fr/fribidi/package.nix @@ -68,6 +68,7 @@ stdenv.mkDerivation (finalAttrs: { meta = { homepage = "https://github.com/fribidi/fribidi"; + changelog = "https://github.com/fribidi/fribidi/releases/tag/v${finalAttrs.version}"; description = "GNU implementation of the Unicode Bidirectional Algorithm (bidi)"; mainProgram = "fribidi"; license = lib.licenses.lgpl21; From 8c23ee12e5689005a5c61ede128612f14b0e4caf Mon Sep 17 00:00:00 2001 From: whoomee Date: Sun, 27 Sep 2026 10:38:09 +0200 Subject: [PATCH 038/110] fribidi: add comment about depsBuildBuild (cherry picked from commit a82a2223107ebc112d76c44b4897466a03ef9779) --- pkgs/by-name/fr/fribidi/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/fr/fribidi/package.nix b/pkgs/by-name/fr/fribidi/package.nix index 5231148cdc5c..e477ea043979 100644 --- a/pkgs/by-name/fr/fribidi/package.nix +++ b/pkgs/by-name/fr/fribidi/package.nix @@ -47,6 +47,8 @@ stdenv.mkDerivation (finalAttrs: { ] ++ lib.optional stdenv.hostPlatform.isDarwin fixDarwinDylibNames; + # necessary to compile helper which runs during build to generate tables + # see gen.tab/meson.build for details depsBuildBuild = [ buildPackages.stdenv.cc ]; mesonFlags = lib.mapAttrsToList lib.mesonBool { From 20de8ed50891b4d464bc4bd9eabb4fa4a37a6b47 Mon Sep 17 00:00:00 2001 From: whoomee Date: Sun, 27 Sep 2026 10:57:02 +0200 Subject: [PATCH 039/110] fribidi: specify identifiers.cpeParts (cherry picked from commit 48ba5d38f2ae5b71ad7f53f68d5ee8aec40ac857) --- pkgs/by-name/fr/fribidi/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/fr/fribidi/package.nix b/pkgs/by-name/fr/fribidi/package.nix index e477ea043979..fa1e16a936fd 100644 --- a/pkgs/by-name/fr/fribidi/package.nix +++ b/pkgs/by-name/fr/fribidi/package.nix @@ -77,5 +77,6 @@ stdenv.mkDerivation (finalAttrs: { platforms = lib.platforms.unix; pkgConfigModules = [ "fribidi" ]; maintainers = with lib.maintainers; [ tmarkus ]; + identifiers.cpeParts = lib.meta.cpeFullVersionWithVendor "gnu" finalAttrs.version; }; }) From 42c8d144261f3fe3dc76e901eacc7700e981c432 Mon Sep 17 00:00:00 2001 From: codgician <15964984+codgician@users.noreply.github.com> Date: Wed, 27 May 2026 13:36:21 +0800 Subject: [PATCH 040/110] perlPackages.XMLTwig: 3.52 -> 3.54 (cherry picked from commit 34edde092d44cde945ea0c860a581e7bda8af11c) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 47e3e1035ddc..39589412dbc2 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -39196,10 +39196,10 @@ with self; XMLTwig = buildPerlPackage { pname = "XML-Twig"; - version = "3.52"; + version = "3.54"; src = fetchurl { - url = "mirror://cpan/authors/id/M/MI/MIROD/XML-Twig-3.52.tar.gz"; - hash = "sha256-/vdYJsJPK4d9Cg0mRSEvxPuXVu1NJxFhSsFcSX6GgK0="; + url = "mirror://cpan/authors/id/M/MI/MIROD/XML-Twig-3.54.tar.gz"; + hash = "sha256-C3RKlzegcPlcMhVK/VJr9evnaln+uLwfXbxs2qXg5Sk="; }; postInstall = '' mkdir -p $out/bin From 039795cedd40f9e10abfc65282ccd25c5215590d Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Mon, 28 Sep 2026 08:31:52 +0000 Subject: [PATCH 041/110] at-spi2-core: 2.60.6 -> 2.60.7 https://gitlab.gnome.org/GNOME/at-spi2-core/-/compare/2.60.6...2.60.7 Not-cherry-picked-because: GNOME 50.5 will only reach stable --- pkgs/by-name/at/at-spi2-core/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/at/at-spi2-core/package.nix b/pkgs/by-name/at/at-spi2-core/package.nix index ed43f5c35993..2aaac993d15a 100644 --- a/pkgs/by-name/at/at-spi2-core/package.nix +++ b/pkgs/by-name/at/at-spi2-core/package.nix @@ -29,7 +29,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "at-spi2-core"; - version = "2.60.6"; + version = "2.60.7"; outputs = [ "out" @@ -39,7 +39,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/at-spi2-core/${lib.versions.majorMinor finalAttrs.version}/at-spi2-core-${finalAttrs.version}.tar.xz"; - hash = "sha256-qJtkqLIXqAQr3w41y/q2Kc7uNWQNunXfV4r96ap4nVc="; + hash = "sha256-kok8gYg1UmS6Y5yj0nlDQ3sm7waZceqfqksg3kBZW5o="; }; nativeBuildInputs = [ From 51e2aab1e1d985bf82aca1d85e383b5c9b35662a Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Mon, 28 Sep 2026 08:49:34 +0000 Subject: [PATCH 042/110] gtk4: 4.22.4 -> 4.22.5 https://gitlab.gnome.org/GNOME/gtk/-/compare/4.22.4...4.22.5 Not-cherry-picked-because: GNOME 50.5 will only reach stable --- pkgs/by-name/gt/gtk4/package.nix | 13 ++----------- 1 file changed, 2 insertions(+), 11 deletions(-) diff --git a/pkgs/by-name/gt/gtk4/package.nix b/pkgs/by-name/gt/gtk4/package.nix index 9b7807508a35..bf8eb18cc801 100644 --- a/pkgs/by-name/gt/gtk4/package.nix +++ b/pkgs/by-name/gt/gtk4/package.nix @@ -4,7 +4,6 @@ buildPackages, replaceVars, fetchurl, - fetchpatch, pkg-config, docutils, gettext, @@ -76,7 +75,7 @@ in stdenv.mkDerivation (finalAttrs: { pname = "gtk4"; - version = "4.22.4"; + version = "4.22.5"; outputs = [ "out" @@ -92,17 +91,9 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/gtk/${lib.versions.majorMinor finalAttrs.version}/gtk-${finalAttrs.version}.tar.xz"; - hash = "sha256-Ub2fYMfSOmZaVWxzZMIfsuTiglZrPn4JJFXo+RAzCJM="; + hash = "sha256-f9cl3rLLP43CGK2GLFBW/4VI9J07DkCBeW5ETCLRloY="; }; - patches = [ - (fetchpatch { - name = "fix-32bit-VkImage-null.patch"; - url = "https://gitlab.gnome.org/GNOME/gtk/-/commit/10d43de8f4f942cb591ada3103474bd7213425f1.patch"; - hash = "sha256-DJIL6M3XcsjBoMO77OxNi84d1DxAphAfot3N7Nq1QqQ="; - }) - ]; - depsBuildBuild = [ pkg-config ]; From 79157dc0aad0bd622e1519f1ff88ee83d2161889 Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Mon, 28 Sep 2026 08:50:50 +0000 Subject: [PATCH 043/110] libadwaita: 1.9.3 -> 1.9.4 https://gitlab.gnome.org/GNOME/libadwaita/-/compare/1.9.3...1.9.4 Not-cherry-picked-because: GNOME 50.5 will only reach stable --- pkgs/by-name/li/libadwaita/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libadwaita/package.nix b/pkgs/by-name/li/libadwaita/package.nix index c158da4ee9af..800cb225a32a 100644 --- a/pkgs/by-name/li/libadwaita/package.nix +++ b/pkgs/by-name/li/libadwaita/package.nix @@ -23,7 +23,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "libadwaita"; - version = "1.9.3"; + version = "1.9.4"; outputs = [ "out" @@ -37,7 +37,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "GNOME"; repo = "libadwaita"; tag = finalAttrs.version; - hash = "sha256-1V3L10YgRnOoJud/lybfSj2AYOY0kRAJdfamJg+S1fo="; + hash = "sha256-EhMwaZe+nzHNNakVKKXCBbFScavOb6c6anmVIvvjUvg="; }; depsBuildBuild = [ From e21d5637162e83ec75a19a1e74565a330be1560b Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Mon, 28 Sep 2026 10:55:23 +0200 Subject: [PATCH 044/110] librsvg: 2.62.3 -> 2.62.4 https://gitlab.gnome.org/GNOME/librsvg/-/compare/2.62.3...2.62.4 Not-cherry-picked-because: GNOME 50.5 will only reach stable --- pkgs/by-name/li/librsvg/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/li/librsvg/package.nix b/pkgs/by-name/li/librsvg/package.nix index 297c1a0eae32..4dc903987a67 100644 --- a/pkgs/by-name/li/librsvg/package.nix +++ b/pkgs/by-name/li/librsvg/package.nix @@ -50,7 +50,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "librsvg"; - version = "2.62.3"; + version = "2.62.4"; outputs = [ "out" @@ -62,13 +62,13 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/librsvg/${lib.versions.majorMinor finalAttrs.version}/librsvg-${finalAttrs.version}.tar.xz"; - hash = "sha256-frRJsnIqdoAhNW9m3+4yAsIptU7U5qcM5AwJDpf/FvI="; + hash = "sha256-yYK4FXoFS4A0k7+ZTTHlAQXrlI3Y2mtKuXNOjTknEqM="; }; cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) src; name = "librsvg-deps-${finalAttrs.version}"; - hash = "sha256-9ubfIl9R2BdcAWn7i050KBbb4cMdlakvrKdnjpZCQjA="; + hash = "sha256-8kFJQD3QQRFoQ1L+/pWwA0Tb8TQ4Zar2uvKrXywuW8E="; dontConfigure = true; }; From a7abfe70afefea9aab815d78c09745337fc8136b Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Mon, 28 Sep 2026 08:56:09 +0000 Subject: [PATCH 045/110] libsecret: 0.21.7 -> 0.21.8.2 https://gitlab.gnome.org/GNOME/libsecret/-/compare/0.21.7...0.21.8.2 Not-cherry-picked-because: GNOME 50.5 will only reach stable --- pkgs/by-name/li/libsecret/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libsecret/package.nix b/pkgs/by-name/li/libsecret/package.nix index 92ab2fa2f8c1..ebaba034861d 100644 --- a/pkgs/by-name/li/libsecret/package.nix +++ b/pkgs/by-name/li/libsecret/package.nix @@ -71,7 +71,7 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "libsecret"; - version = "0.21.7"; + version = "0.21.8.2"; outputs = [ "out" @@ -81,7 +81,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/libsecret/${lib.versions.majorMinor finalAttrs.version}/libsecret-${finalAttrs.version}.tar.xz"; - hash = "sha256-a0UuR1BZCitWF63EACbyjS9JA94V8SUOHRxAv9aO1V4="; + hash = "sha256-FClIM5xblx2PaoxwmVIfb9MZtv5z0mlLTm0zEO0otuY="; }; depsBuildBuild = [ From 7a147d4004864f0f3cca385bdaebaaacdb53fb7a Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:04:00 +0200 Subject: [PATCH 046/110] perlPackages.CpanelJSONXS: 4.37 -> 4.42 Fixes CVE-2026-9334, CVE-2026-9516. Supersedes the in-tree CVE-2025-40929 patch. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 66e7adfa8f255bff2e1ec8c12b888a8514aad48c) --- .../Cpanel-JSON-XS-CVE-2025-40929.patch | 47 ------------------- pkgs/top-level/perl-packages.nix | 7 ++- 2 files changed, 3 insertions(+), 51 deletions(-) delete mode 100644 pkgs/development/perl-modules/Cpanel-JSON-XS-CVE-2025-40929.patch diff --git a/pkgs/development/perl-modules/Cpanel-JSON-XS-CVE-2025-40929.patch b/pkgs/development/perl-modules/Cpanel-JSON-XS-CVE-2025-40929.patch deleted file mode 100644 index 0f76f7313fde..000000000000 --- a/pkgs/development/perl-modules/Cpanel-JSON-XS-CVE-2025-40929.patch +++ /dev/null @@ -1,47 +0,0 @@ -From 5592bfb58eb8d1c8a644e67c9bba795d1384a995 Mon Sep 17 00:00:00 2001 -From: Marc Lehmann -Date: Sat, 6 Sep 2025 11:31:36 +0200 -Subject: [PATCH 1/2] fix json_atof_scan1 overflows - -with fuzzed overlong numbers. CVE-2025-40928 -Really the comparisons were wrong. ---- - XS.xs | 8 ++++---- - 1 file changed, 4 insertions(+), 4 deletions(-) - -diff --git a/XS.xs b/XS.xs -index 9b1ce2b..94ab0d6 100755 ---- a/XS.xs -+++ b/XS.xs -@@ -710,16 +710,16 @@ json_atof_scan1 (const char *s, NV *accum, int *expo, int postdp, int maxdepth) - /* if we recurse too deep, skip all remaining digits */ - /* to avoid a stack overflow attack */ - if (UNLIKELY(--maxdepth <= 0)) -- while (((U8)*s - '0') < 10) -+ while ((U8)(*s - '0') < 10) - ++s; - - for (;;) - { -- U8 dig = (U8)*s - '0'; -+ U8 dig = (U8)(*s - '0'); - - if (UNLIKELY(dig >= 10)) - { -- if (dig == (U8)((U8)'.' - (U8)'0')) -+ if (dig == (U8)('.' - '0')) - { - ++s; - json_atof_scan1 (s, accum, expo, 1, maxdepth); -@@ -739,7 +739,7 @@ json_atof_scan1 (const char *s, NV *accum, int *expo, int postdp, int maxdepth) - else if (*s == '+') - ++s; - -- while ((dig = (U8)*s - '0') < 10) -+ while ((dig = (U8)(*s - '0')) < 10) - exp2 = exp2 * 10 + *s++ - '0'; - - *expo += neg ? -exp2 : exp2; --- -2.50.1 - diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 47e3e1035ddc..a112470336b0 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -6691,12 +6691,11 @@ with self; CpanelJSONXS = buildPerlPackage { pname = "Cpanel-JSON-XS"; - version = "4.37"; + version = "4.42"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RU/RURBAN/Cpanel-JSON-XS-4.37.tar.gz"; - hash = "sha256-wkFhWg4X/3Raqoa79Gam4pzSQFFeZfBqegUBe2GebUs="; + url = "mirror://cpan/authors/id/R/RU/RURBAN/Cpanel-JSON-XS-4.42.tar.gz"; + hash = "sha256-4awvqx46bS2ZjTRAxgAGc2W9x9vwyPKyBZy85LTIMXM="; }; - patches = [ ../development/perl-modules/Cpanel-JSON-XS-CVE-2025-40929.patch ]; meta = { description = "CPanel fork of JSON::XS, fast and correct serializing"; license = with lib.licenses; [ From 09bbf90e12da63cc2eae23b4a1b71f3910a29e39 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:06:54 +0200 Subject: [PATCH 047/110] perlPackages.HTMLParser: 3.81 -> 3.85 Fixes CVE-2026-8829. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 7a4c9efd01e0980532edff7245f49768ad1deb01) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index a112470336b0..dd180aaf582f 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -16302,10 +16302,10 @@ with self; HTMLParser = buildPerlPackage { pname = "HTML-Parser"; - version = "3.81"; + version = "3.85"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/HTML-Parser-3.81.tar.gz"; - hash = "sha256-wJEKXI+S+IF+3QbM/SJLocLr6MEPVR8DJYeh/IPWL/I="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/HTML-Parser-3.85.tar.gz"; + hash = "sha256-/UK6ar4HJBzwrVe+JGw5gAZfaD5EZeWbRq+e/ryODHE="; }; propagatedBuildInputs = [ HTMLTagset From 5be34527fc67abdd8b142b3878ee24ef851d739a Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:07:12 +0200 Subject: [PATCH 048/110] perlPackages.NetStatsd: 0.12 -> 0.13 Fixes CVE-2026-46739. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 9020587aa04036671788a5745f2ea63df581b064) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index dd180aaf582f..0fb71ea2d892 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -26403,10 +26403,10 @@ with self; NetStatsd = buildPerlPackage { pname = "Net-Statsd"; - version = "0.12"; + version = "0.13"; src = fetchurl { - url = "mirror://cpan/authors/id/C/CO/COSIMO/Net-Statsd-0.12.tar.gz"; - hash = "sha256-Y+RTYD2hZbxtHEygtV7aPSIE8EDFkwSkd4LFqniGVlw="; + url = "mirror://cpan/authors/id/C/CO/COSIMO/Net-Statsd-0.13.tar.gz"; + hash = "sha256-xKYP9dP002ompqR3YxGI7HnNzp4wUMZ6NOm1rikgoQA="; }; meta = { description = "Perl client for Etsy's statsd daemon"; From 4e17ae400bf0caabf37e2664a50167f9ab3a2c86 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:07:28 +0200 Subject: [PATCH 049/110] perlPackages.ProtocolHTTP2: 1.11 -> 1.13 Fixes CVE-2026-10725. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 0002e3ea35b952f747cc1cd19657f729422b7f42) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 0fb71ea2d892..36d24240eb0b 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -29136,10 +29136,10 @@ with self; ProtocolHTTP2 = buildPerlModule { pname = "Protocol-HTTP2"; - version = "1.11"; + version = "1.13"; src = fetchurl { - url = "mirror://cpan/authors/id/C/CR/CRUX/Protocol-HTTP2-1.11.tar.gz"; - hash = "sha256-Vp8Fsavpl7UHyCUVMMyB0e6WvZMsxoJTS2zkhlNQCRM="; + url = "mirror://cpan/authors/id/C/CR/CRUX/Protocol-HTTP2-1.13.tar.gz"; + hash = "sha256-LsO0oYpkqGHgKYHO/Y7W8iOHUTj75e/us0DvF5ZVMGI="; }; buildInputs = [ AnyEvent From eec0b58b304cd433944b8c6d6f3163487a7fe692 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:08:56 +0200 Subject: [PATCH 050/110] perlPackages.CryptPBKDF2: 0.161520 -> 0.261630 Fixes CVE-2017-20240, CVE-2026-9638, CVE-2026-9641. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit f1ec9089c3939acbba18a7e3c1650eff87cdf9c4) --- pkgs/top-level/perl-packages.nix | 14 +++++++++----- 1 file changed, 9 insertions(+), 5 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 36d24240eb0b..5616a7db40a0 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -7747,15 +7747,19 @@ with self; }; }; - CryptPBKDF2 = buildPerlPackage { + CryptPBKDF2 = buildPerlModule { pname = "Crypt-PBKDF2"; - version = "0.161520"; + version = "0.261630"; src = fetchurl { - url = "mirror://cpan/authors/id/A/AR/ARODLAND/Crypt-PBKDF2-0.161520.tar.gz"; - hash = "sha256-l9+nmjCaCG4YSk5hBH+KEP+z2wUQJefSIqJfGRMLpBc="; + url = "mirror://cpan/authors/id/A/AR/ARODLAND/Crypt-PBKDF2-0.261630.tar.gz"; + hash = "sha256-GHVxiWOJMrMJs0xFu4EKo+SFbj7VgBAAF9reZXk/RsA="; }; - buildInputs = [ TestFatal ]; + buildInputs = [ + ModuleBuildTiny + TestFatal + ]; propagatedBuildInputs = [ + CryptURandom DigestHMAC DigestSHA3 Moo From 87965eb13e26b3f90c95076aa59767ad08d54366 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 16:25:39 +0200 Subject: [PATCH 051/110] perlPackages.ExtUtilsHelpers: 0.026 -> 0.028 Required by ExtUtils::Builder. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 32536524aff1b490a54ec6d4e60c89f6f2252423) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 5616a7db40a0..fb2be124c1ef 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -12697,10 +12697,10 @@ with self; ExtUtilsHelpers = buildPerlPackage { pname = "ExtUtils-Helpers"; - version = "0.026"; + version = "0.028"; src = fetchurl { - url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Helpers-0.026.tar.gz"; - hash = "sha256-3pAbZ5CkVXz07JCBSeA1eDsSW/EV65ZA/rG8HCTDNBY="; + url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Helpers-0.028.tar.gz"; + hash = "sha256-yFdIdczgc+fcU0WnsG1QLlIETWiJT5FgID/KqzeVFP4="; }; meta = { description = "Various portability utilities for module builders"; From 1a4bd417df97c4b1205596405b8465bca0127388 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 16:25:40 +0200 Subject: [PATCH 052/110] perlPackages.ExtUtilsConfig: 0.008 -> 0.010 Required by ExtUtils::Builder. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit f57d979624839d4840d60f6c134a24b83dd95ecb) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index fb2be124c1ef..73ee1abff8cc 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -12606,10 +12606,10 @@ with self; ExtUtilsConfig = buildPerlPackage { pname = "ExtUtils-Config"; - version = "0.008"; + version = "0.010"; src = fetchurl { - url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Config-0.008.tar.gz"; - hash = "sha256-rlEE9jRlDc6KebftE/tZ1no5whOmd2z9qj7nSeYvGow="; + url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Config-0.010.tar.gz"; + hash = "sha256-gufk6Qy+OA4VL13m4+QDdGmC1QLdMBl6EjZS5GYQxm0="; }; meta = { description = "Wrapper for perl's configuration"; From 5d2b277dd51dab0817271f81912713610d58a347 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 16:25:40 +0200 Subject: [PATCH 053/110] perlPackages.ExtUtilsBuilder: init at 0.020 Dependency of Dist::Build. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 5ebb6bf806f336e1a44479bcfc65ae10c7284a79) --- pkgs/top-level/perl-packages.nix | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 73ee1abff8cc..8a5f11bce9e3 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -12587,6 +12587,27 @@ with self; }; }; + ExtUtilsBuilder = buildPerlPackage { + pname = "ExtUtils-Builder"; + version = "0.020"; + src = fetchurl { + url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Builder-0.020.tar.gz"; + hash = "sha256-UtZR46oDJyUOR5h9Rf9I6cyQtbe9L7D/P3h4PlMq/8w="; + }; + propagatedBuildInputs = [ + ExtUtilsConfig + ExtUtilsHelpers + ]; + meta = { + description = "Abstract representation of build processes"; + homepage = "https://github.com/Leont/extutils-builder-plan"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + ExtUtilsCChecker = buildPerlModule { pname = "ExtUtils-CChecker"; version = "0.11"; From a3dbc7030277744e8670bfa7564f8c63a9572542 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 16:25:40 +0200 Subject: [PATCH 054/110] perlPackages.ExtUtilsBuilderCompiler: init at 0.037 Dependency of Dist::Build. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 47c2f1daf9350d321fe5a41ef4fa550f3f8a7d85) --- pkgs/top-level/perl-packages.nix | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 8a5f11bce9e3..6be02308f145 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -12608,6 +12608,27 @@ with self; }; }; + ExtUtilsBuilderCompiler = buildPerlPackage { + pname = "ExtUtils-Builder-Compiler"; + version = "0.037"; + src = fetchurl { + url = "mirror://cpan/authors/id/L/LE/LEONT/ExtUtils-Builder-Compiler-0.037.tar.gz"; + hash = "sha256-s5VNaI45gDkoUnkWfG6+7nVX8Q6VYBzj/baBkyY2h7g="; + }; + propagatedBuildInputs = [ + ExtUtilsBuilder + ExtUtilsConfig + ]; + meta = { + description = "Interface around different compilers"; + homepage = "https://github.com/Leont/extutils-builder-compiler"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + ExtUtilsCChecker = buildPerlModule { pname = "ExtUtils-CChecker"; version = "0.11"; From 74643a5f7056ddec7eed40ec7beb6d5ac7ea8d2d Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:21:35 +0200 Subject: [PATCH 055/110] perlPackages.DistBuild: init at 0.028 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Build dependency of Crypt::Argon2. Co-authored-by: Robert Schütz Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 46324ed6bb63470975f19e9e4ba58e9ceadf268c) --- pkgs/top-level/perl-packages.nix | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 6be02308f145..a9a96fd3b507 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -11039,6 +11039,31 @@ with self; }; }; + DistBuild = buildPerlModule { + pname = "Dist-Build"; + version = "0.028"; + src = fetchurl { + url = "mirror://cpan/authors/id/L/LE/LEONT/Dist-Build-0.028.tar.gz"; + hash = "sha256-JPFLFA4Tq3x1PU25bI0zbQnepcb1H+1IvA92Khyhgx8="; + }; + propagatedBuildInputs = [ + ExtUtilsBuilder + ExtUtilsBuilderCompiler + ExtUtilsConfig + ExtUtilsHelpers + ExtUtilsInstallPaths + ]; + meta = { + changelog = "https://github.com/Leont/dist-build/blob/v0.028/Changes"; + description = "Modern module builder, author tools not included"; + homepage = "https://github.com/Leont/dist-build"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + DistributionMetadata = buildPerlModule { pname = "Distribution-Metadata"; version = "0.10"; From e7eb5dc94473eec5e104fd2fe61a281c7f857c1f Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:21:35 +0200 Subject: [PATCH 056/110] perlPackages.CryptArgon2: 0.019 -> 0.031 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Fixes CVE-2026-8463. Co-authored-by: Robert Schütz Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit de1d803f4387e8afbccf6a7650b8a8ff0c45b2fc) --- pkgs/top-level/perl-packages.nix | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index a9a96fd3b507..d64d048b6516 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -6889,13 +6889,15 @@ with self; CryptArgon2 = buildPerlModule { pname = "Crypt-Argon2"; - version = "0.019"; + version = "0.031"; src = fetchurl { - url = "mirror://cpan/authors/id/L/LE/LEONT/Crypt-Argon2-0.019.tar.gz"; - hash = "sha256-+Fm+6NL2tAf11EZFwiOu4hL+AFkd/YLlBlrhvnio5Dg="; + url = "mirror://cpan/authors/id/L/LE/LEONT/Crypt-Argon2-0.031.tar.gz"; + hash = "sha256-1l5RoZQ+6AglEkUNw1KuUpUQZswJI/u38uYK+l8WTi0="; }; nativeBuildInputs = [ pkgs.ld-is-cc-hook ]; + buildInputs = [ DistBuild ]; meta = { + changelog = "https://github.com/Leont/crypt-argon2/blob/v0.031/Changes"; description = "Perl interface to the Argon2 key derivation functions"; license = with lib.licenses; [ cc0 ]; }; From 2810eba39c0ca0bca96bb03cfc6a50227a25146b Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:25:57 +0200 Subject: [PATCH 057/110] perlPackages.ClassErrorHandler: init at 0.04 Dependency of Convert::PEM. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 9f61f7a1b02416d738b87a5c97d586d8fe3dd250) --- pkgs/top-level/perl-packages.nix | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index d64d048b6516..f5f4cc443cb7 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -5092,6 +5092,22 @@ with self; }; }; + ClassErrorHandler = buildPerlPackage { + pname = "Class-ErrorHandler"; + version = "0.04"; + src = fetchurl { + url = "mirror://cpan/authors/id/T/TO/TOKUHIROM/Class-ErrorHandler-0.04.tar.gz"; + hash = "sha256-NC0tz8eXogvugXmxuWuFwK56W0iCc1lSPNjHTD5wRQI="; + }; + meta = { + description = "Base class for error handling"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + ClassInspector = buildPerlPackage { pname = "Class-Inspector"; version = "1.36"; From 8e84248b5f6e0510f6b52f4c29d659200f942300 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:26:10 +0200 Subject: [PATCH 058/110] perlPackages.CryptDESEDE3: init at 0.03 Dependency of Convert::PEM. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit b7bd8c9e93c0cab35230863db815c3cafaa9bd41) --- pkgs/top-level/perl-packages.nix | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index f5f4cc443cb7..a507c4652731 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -7034,6 +7034,23 @@ with self; }; }; + CryptDESEDE3 = buildPerlPackage { + pname = "Crypt-DES_EDE3"; + version = "0.03"; + src = fetchurl { + url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Crypt-DES_EDE3-0.03.tar.gz"; + hash = "sha256-KFktt7njR0WqkfPhnl27uDqvRyop5we5eR0NArPiJ/U="; + }; + propagatedBuildInputs = [ CryptDES ]; + meta = { + description = "Triple-DES EDE encryption/decryption"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + CryptDH = buildPerlPackage { pname = "Crypt-DH"; version = "0.07"; From 61b61bd6d4ed3c07d981de6392539dad299c5483 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:26:22 +0200 Subject: [PATCH 059/110] perlPackages.ConvertPEM: init at 0.13 Dependency of Crypt::DSA. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit f098e09528a436b2119e1bdee879d12079b8567f) --- pkgs/top-level/perl-packages.nix | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index a507c4652731..6d7eaace2b45 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -6413,6 +6413,29 @@ with self; }; }; + ConvertPEM = buildPerlPackage { + pname = "Convert-PEM"; + version = "0.13"; + src = fetchurl { + url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Convert-PEM-0.13.tar.gz"; + hash = "sha256-eZ+jLCcAgfTmKSsN31GAlScQqKS+Ey6Qe9oxdqe9HCM="; + }; + buildInputs = [ TestException ]; + propagatedBuildInputs = [ + ClassErrorHandler + ConvertASN1 + CryptDESEDE3 + CryptX + ]; + meta = { + description = "Read/write encrypted ASN.1 PEM files"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + ConvertUU = buildPerlPackage { pname = "Convert-UU"; version = "0.5201"; From 80de9e17dd592349724623c9e7767632aff5b9ee Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:27:45 +0200 Subject: [PATCH 060/110] perlPackages.CryptDSA: 1.17 -> 1.21 Fixes CVE-2026-8700, CVE-2026-8704, CVE-2026-12205. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit e86a4b4e44855be1d7c7ba081f2d057c98ebb928) --- pkgs/top-level/perl-packages.nix | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 6d7eaace2b45..acf816995432 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -7116,14 +7116,17 @@ with self; CryptDSA = buildPerlPackage { pname = "Crypt-DSA"; - version = "1.17"; + version = "1.21"; src = fetchurl { - url = "mirror://cpan/authors/id/A/AD/ADAMK/Crypt-DSA-1.17.tar.gz"; - hash = "sha256-0bhYX2v3RvduXcXaNkHTJe1la8Ll80S1RRS1XDEAmgM="; + url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Crypt-DSA-1.21.tar.gz"; + hash = "sha256-pGIB6DkOi6O75RER12SJ8x2v2g9qYLCrkxndUr0rMrA="; }; propagatedBuildInputs = [ + ConvertASN1 + ConvertPEM + CryptSysRandom + CryptURandom DataBuffer - DigestSHA1 FileWhich ]; meta = { From ea711b89bb5ce52d130b2e01b69173b99103abb0 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:31:40 +0200 Subject: [PATCH 061/110] perlPackages.Sereal: 5.004 -> 5.006 Fixes CVE-2026-8796. Covers Sereal, Sereal::Decoder and Sereal::Encoder. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 261df4c82cbef82eff433195316c3222c9dd5873) --- pkgs/top-level/perl-packages.nix | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index acf816995432..c42733e3d8f3 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -30712,10 +30712,10 @@ with self; SerealDecoder = buildPerlPackage { pname = "Sereal-Decoder"; - version = "5.004"; + version = "5.006"; src = fetchurl { - url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Decoder-5.004.tar.gz"; - hash = "sha256-aO8DFNh9Gm5guw9m/PQ+ssrN6xdUQy9eJeeE450+Z4Q="; + url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Decoder-5.006.tar.gz"; + hash = "sha256-eZGFXpGBo3nJsBIv6PwvaONEnJFhaow1eSbxFh9oR2g="; }; buildInputs = [ TestDeep @@ -30737,10 +30737,10 @@ with self; SerealEncoder = buildPerlPackage { pname = "Sereal-Encoder"; - version = "5.004"; + version = "5.006"; src = fetchurl { - url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Encoder-5.004.tar.gz"; - hash = "sha256-XlqGzNMtrjTtgJMuy+XGjil1K13g6bCnk6t+sspVyxs="; + url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-Encoder-5.006.tar.gz"; + hash = "sha256-kLQsyHdZgq4MdJno9ZLOeu+ug0M1g+EKWtVxKBHRcK0="; }; buildInputs = [ SerealDecoder @@ -30762,10 +30762,10 @@ with self; Sereal = buildPerlPackage { pname = "Sereal"; - version = "5.004"; + version = "5.006"; src = fetchurl { - url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-5.004.tar.gz"; - hash = "sha256-nCW7euS9c20ksa0dk9dzlbDGXKh0HiZr/Ay+VCJh128="; + url = "mirror://cpan/authors/id/Y/YV/YVES/Sereal-5.006.tar.gz"; + hash = "sha256-uwXnY+1ry+pEx5IX/vCy05GKwVRxlHIwOMbER+5vWd4="; }; buildInputs = [ TestDeep From 222035703574b49d298862f3ed4269861461c57d Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:36:58 +0200 Subject: [PATCH 062/110] perlPackages.XMLLibXML: 2.0210 -> 2.0213 Fixes CVE-2026-8177. Drops the libxml-2.13 test patch, now included upstream. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 5fb740257c36a83351b79b1dc15d8056a1533976) --- .../XML-LibXML-fix-tests-libxml-2.13.0.patch | 242 ------------------ pkgs/top-level/perl-packages.nix | 10 +- 2 files changed, 3 insertions(+), 249 deletions(-) delete mode 100644 pkgs/development/perl-modules/XML-LibXML-fix-tests-libxml-2.13.0.patch diff --git a/pkgs/development/perl-modules/XML-LibXML-fix-tests-libxml-2.13.0.patch b/pkgs/development/perl-modules/XML-LibXML-fix-tests-libxml-2.13.0.patch deleted file mode 100644 index 5433d3afd934..000000000000 --- a/pkgs/development/perl-modules/XML-LibXML-fix-tests-libxml-2.13.0.patch +++ /dev/null @@ -1,242 +0,0 @@ -From bee8338fd1cbd7aad4bf60c2965833343b6ead6f Mon Sep 17 00:00:00 2001 -From: Nick Wellnhofer -Date: Tue, 21 May 2024 15:17:30 +0200 -Subject: [PATCH 1/3] Fix test suite with libxml2 2.13.0 - ---- - t/02parse.t | 7 ++++++- - t/08findnodes.t | 8 +++++++- - t/19die_on_invalid_utf8_rt_58848.t | 2 +- - t/25relaxng.t | 4 ++-- - t/26schema.t | 4 ++-- - t/60error_prev_chain.t | 8 ++++---- - 6 files changed, 22 insertions(+), 11 deletions(-) - -diff --git a/t/02parse.t b/t/02parse.t -index b111507b..40aa5f13 100644 ---- a/t/02parse.t -+++ b/t/02parse.t -@@ -884,7 +884,12 @@ EOXML - eval { - $doc2 = $parser->parse_string( $xmldoc ); - }; -- isnt($@, '', "error parsing $xmldoc"); -+ # https://gitlab.gnome.org/GNOME/libxml2/-/commit/b717abdd -+ if (XML::LibXML::LIBXML_RUNTIME_VERSION() < 21300) { -+ isnt($@, '', "error parsing $xmldoc"); -+ } else { -+ is( $doc2->documentElement()->firstChild()->nodeName(), "foo" ); -+ } - - $parser->validation(1); - -diff --git a/t/08findnodes.t b/t/08findnodes.t -index 016c85a1..e9417bc5 100644 ---- a/t/08findnodes.t -+++ b/t/08findnodes.t -@@ -123,7 +123,13 @@ my $docstring = q{ - my @ns = $root->findnodes('namespace::*'); - # TEST - --is(scalar(@ns), 2, ' TODO : Add test name' ); -+# https://gitlab.gnome.org/GNOME/libxml2/-/commit/aca16fb3 -+# fixed xmlCopyNamespace with XML namespace. -+if (XML::LibXML::LIBXML_RUNTIME_VERSION() < 21300) { -+ is(scalar(@ns), 2, ' TODO : Add test name' ); -+} else { -+ is(scalar(@ns), 3, ' TODO : Add test name' ); -+} - - # bad xpaths - # TEST:$badxpath=4; -diff --git a/t/19die_on_invalid_utf8_rt_58848.t b/t/19die_on_invalid_utf8_rt_58848.t -index aa8ad105..4160cb27 100644 ---- a/t/19die_on_invalid_utf8_rt_58848.t -+++ b/t/19die_on_invalid_utf8_rt_58848.t -@@ -16,7 +16,7 @@ use XML::LibXML; - my $err = $@; - - # TEST -- like ("$err", qr{parser error : Input is not proper UTF-8}, -+ like ("$err", qr{not proper UTF-8|Invalid bytes in character encoding}, - 'Parser error.', - ); - } -diff --git a/t/25relaxng.t b/t/25relaxng.t -index 93e61883..71383b2a 100644 ---- a/t/25relaxng.t -+++ b/t/25relaxng.t -@@ -132,7 +132,7 @@ print "# 6 check that no_network => 1 works\n"; - { - my $rng = eval { XML::LibXML::RelaxNG->new( location => $netfile, no_network => 1 ) }; - # TEST -- like( $@, qr{I/O error : Attempt to load network entity}, 'RNG from file location with external import and no_network => 1 throws an exception.' ); -+ like( $@, qr{Attempt to load network entity}, 'RNG from file location with external import and no_network => 1 throws an exception.' ); - # TEST - ok( !defined $rng, 'RNG from file location with external import and no_network => 1 is not loaded.' ); - } -@@ -152,7 +152,7 @@ print "# 6 check that no_network => 1 works\n"; - - EOF - # TEST -- like( $@, qr{I/O error : Attempt to load network entity}, 'RNG from buffer with external import and no_network => 1 throws an exception.' ); -+ like( $@, qr{Attempt to load network entity}, 'RNG from buffer with external import and no_network => 1 throws an exception.' ); - # TEST - ok( !defined $rng, 'RNG from buffer with external import and no_network => 1 is not loaded.' ); - } -diff --git a/t/26schema.t b/t/26schema.t -index 17f641e4..c404cedd 100644 ---- a/t/26schema.t -+++ b/t/26schema.t -@@ -117,7 +117,7 @@ EOF - { - my $schema = eval { XML::LibXML::Schema->new( location => $netfile, no_network => 1 ) }; - # TEST -- like( $@, qr{I/O error : Attempt to load network entity}, 'Schema from file location with external import and no_network => 1 throws an exception.' ); -+ like( $@, qr{Attempt to load network entity}, 'Schema from file location with external import and no_network => 1 throws an exception.' ); - # TEST - ok( !defined $schema, 'Schema from file location with external import and no_network => 1 is not loaded.' ); - } -@@ -129,7 +129,7 @@ EOF - - EOF - # TEST -- like( $@, qr{I/O error : Attempt to load network entity}, 'Schema from buffer with external import and no_network => 1 throws an exception.' ); -+ like( $@, qr{Attempt to load network entity}, 'Schema from buffer with external import and no_network => 1 throws an exception.' ); - # TEST - ok( !defined $schema, 'Schema from buffer with external import and no_network => 1 is not loaded.' ); - } -diff --git a/t/60error_prev_chain.t b/t/60error_prev_chain.t -index e48215c4..55ac0b2e 100644 ---- a/t/60error_prev_chain.t -+++ b/t/60error_prev_chain.t -@@ -16,13 +16,11 @@ use XML::LibXML; - - { - my $parser = XML::LibXML->new(); -- $parser->validation(0); -- $parser->load_ext_dtd(0); - - eval - { - local $^W = 0; -- $parser->parse_file('example/JBR-ALLENtrees.htm'); -+ $parser->parse_string('“ ”'); - }; - - my $err = $@; -@@ -31,7 +29,7 @@ use XML::LibXML; - if( $err && !ref($err) ) { - plan skip_all => 'The local libxml library does not support errors as objects to $@'; - } -- plan tests => 1; -+ plan tests => 2; - - while (defined($err) && $count < 200) - { -@@ -44,6 +42,8 @@ use XML::LibXML; - - # TEST - ok ((!$err), "Reached the end of the chain."); -+ # TEST -+ is ($count, 3, "Correct number of errors reported") - } - - =head1 COPYRIGHT & LICENSE - -From c9f9c2fe51173b0a00969f01b577399f1098aa47 Mon Sep 17 00:00:00 2001 -From: Nick Wellnhofer -Date: Thu, 13 Feb 2025 19:50:35 +0100 -Subject: [PATCH 2/3] Fix test suite with libxml2 2.14.0 - ---- - t/16docnodes.t | 7 ++++++- - t/49_load_html.t | 8 +++++++- - 2 files changed, 13 insertions(+), 2 deletions(-) - -diff --git a/t/16docnodes.t b/t/16docnodes.t -index db7bc1fc..0b0ae005 100644 ---- a/t/16docnodes.t -+++ b/t/16docnodes.t -@@ -60,7 +60,12 @@ for my $time (0 .. 2) { - $doc->setDocumentElement($node); - - # TEST -- is( $node->serialize(), '', 'Node serialise works.' ); -+ # libxml2 2.14 avoids unnecessary escaping of attribute values. -+ if (XML::LibXML::LIBXML_VERSION() >= 21400) { -+ is( $node->serialize(), "", 'Node serialise works.' ); -+ } else { -+ is( $node->serialize(), '', 'Node serialise works.' ); -+ } - - $doc->setEncoding('utf-8'); - # Second output -diff --git a/t/49_load_html.t b/t/49_load_html.t -index 70d26607..3861edf8 100644 ---- a/t/49_load_html.t -+++ b/t/49_load_html.t -@@ -52,7 +52,13 @@ use XML::LibXML; - - EOS - -- { -+ SKIP: { -+ # libxml2 2.14 tokenizes HTML according to HTML5 where -+ # this isn't an error, see "13.2.5.73 Named character -+ # reference state". -+ skip("libxml2 version >= 21400", 1) -+ if XML::LibXML::LIBXML_VERSION >= 21400; -+ - my $buf = ''; - open my $fh, '>', \$buf; - # redirect STDERR there - -From ecbebc2f33fecb66b3d5487c6e48bea353e374f9 Mon Sep 17 00:00:00 2001 -From: Nick Wellnhofer -Date: Fri, 16 May 2025 19:11:12 +0200 -Subject: [PATCH 3/3] Remove tests that disable line numbers - -Line numbers are always enabled since libxml2 2.15.0. ---- - t/02parse.t | 13 ++----------- - 1 file changed, 2 insertions(+), 11 deletions(-) - -diff --git a/t/02parse.t b/t/02parse.t -index 40aa5f13..17419f8f 100644 ---- a/t/02parse.t -+++ b/t/02parse.t -@@ -14,7 +14,7 @@ use locale; - - POSIX::setlocale(LC_ALL, "C"); - --use Test::More tests => 533; -+use Test::More tests => 531; - use IO::File; - - use XML::LibXML::Common qw(:libxml); -@@ -25,7 +25,7 @@ use constant XML_DECL => "\n"; - - use Errno qw(ENOENT); - --# TEST*533 -+# TEST*531 - - ## - # test values -@@ -773,15 +773,6 @@ EOXML - - my $newkid = $root->appendChild( $doc->createElement( "bar" ) ); - is( $newkid->line_number(), 0, "line number is 0"); -- -- $parser->line_numbers(0); -- eval { $doc = $parser->parse_string( $goodxml ); }; -- -- $root = $doc->documentElement(); -- is( $root->line_number(), 0, "line number is 0"); -- -- @kids = $root->childNodes(); -- is( $kids[1]->line_number(), 0, "line number is 0"); - } - - SKIP: { diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index c42733e3d8f3..f9ba00aa2e18 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -38923,10 +38923,10 @@ with self; XMLLibXML = buildPerlPackage { pname = "XML-LibXML"; - version = "2.0210"; + version = "2.0213"; src = fetchurl { - url = "mirror://cpan/authors/id/S/SH/SHLOMIF/XML-LibXML-2.0210.tar.gz"; - hash = "sha256-opvz8Aq5ye4EIYFU4K/I95m/I2dOuZwantTeH0BZpI0="; + url = "mirror://cpan/authors/id/T/TO/TODDR/XML-LibXML-2.0213.tar.gz"; + hash = "sha256-KvIcXWGsNOompfq/FbpaWEHmSPcYnbPjO28otUiYAqs="; }; env.SKIP_SAX_INSTALL = 1; buildInputs = [ @@ -38940,10 +38940,6 @@ with self; zlib ] ); - patches = [ - # https://github.com/shlomif/perl-XML-LibXML/pull/87 - ../development/perl-modules/XML-LibXML-fix-tests-libxml-2.13.0.patch - ]; propagatedBuildInputs = [ XMLSAX ]; meta = { description = "Perl Binding for libxml2"; From f4a185f99482b489b32e1e2a0dcde35162019eed Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:37:47 +0200 Subject: [PATCH 063/110] perlPackages.CryptPasswdMD5: 1.42 -> 1.43 Fixes CVE-2026-6659. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 62e6ec8536bbdb987df446af821549d619a10aca) --- pkgs/top-level/perl-packages.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index f9ba00aa2e18..09f88f90ebc2 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -7320,11 +7320,12 @@ with self; CryptPasswdMD5 = buildPerlPackage { pname = "Crypt-PasswdMD5"; - version = "1.42"; + version = "1.43"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RS/RSAVAGE/Crypt-PasswdMD5-1.42.tgz"; - hash = "sha256-/Tlubn9E7rkj6TyZOUC49nqa7Vb8dKrK8Dj8QFPvO1k="; + url = "mirror://cpan/authors/id/R/RS/RSAVAGE/Crypt-PasswdMD5-1.43.tgz"; + hash = "sha256-Qr+Sk0UQlYXUlWkCVX7ONdBh7aQ454lPhucHV0EoB1k="; }; + propagatedBuildInputs = [ CryptURandom ]; meta = { description = "Provide interoperable MD5-based crypt() functions"; license = with lib.licenses; [ From 2cb06e584c3a695bc47304c69eef9d9ef0fab340 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:38:37 +0200 Subject: [PATCH 064/110] perlPackages.CryptScryptKDF: 0.010 -> 0.011 Fixes CVE-2026-8647. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 4b37127ec079734d0201385a0f3f96e1c6c20f45) --- pkgs/top-level/perl-packages.nix | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 09f88f90ebc2..38eb57275a15 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -7558,12 +7558,15 @@ with self; CryptScryptKDF = buildPerlModule { pname = "Crypt-ScryptKDF"; - version = "0.010"; + version = "0.011"; src = fetchurl { - url = "mirror://cpan/authors/id/M/MI/MIK/Crypt-ScryptKDF-0.010.tar.gz"; - hash = "sha256-fRbulczj61TBdGc6cpn0wIb7o6yF+EfQ4TT+7V93YBc="; + url = "mirror://cpan/authors/id/M/MI/MIK/Crypt-ScryptKDF-0.011.tar.gz"; + hash = "sha256-IZLJ8E8rX/cHN/XNrz9PZ6VXE8MeoIVAOMvzXjttFrQ="; }; - propagatedBuildInputs = [ CryptOpenSSLRandom ]; + propagatedBuildInputs = [ + CryptOpenSSLRandom + CryptX + ]; meta = { description = "Scrypt password based key derivation function"; homepage = "https://github.com/DCIT/perl-Crypt-ScryptKDF"; From d2859e330de02fd57588b1e737b5956cb69c9c09 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:40:15 +0200 Subject: [PATCH 065/110] perlPackages.Starlet: 0.31 -> 0.32 Fixes CVE-2026-40561. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit d22c1175af2ad1614c19f547a34677bc9250618d) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 38eb57275a15..bb2db1caf486 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -31543,10 +31543,10 @@ with self; Starlet = buildPerlPackage { pname = "Starlet"; - version = "0.31"; + version = "0.32"; src = fetchurl { - url = "mirror://cpan/authors/id/K/KA/KAZUHO/Starlet-0.31.tar.gz"; - hash = "sha256-uWA7jmKIDLRYL2p5Oer+xl5u/T2QDyx900Ll9MaNYtg="; + url = "mirror://cpan/authors/id/K/KA/KAZUHO/Starlet-0.32.tar.gz"; + hash = "sha256-gZI9OmCX3YHH4Og9SBvuof89ZejgHY0f59yziFV1vY8="; }; buildInputs = [ LWP From af88ec17296e66e552bc2aaf5a0ffa8eb4d1960c Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:41:21 +0200 Subject: [PATCH 066/110] perlPackages.GD: 2.78 -> 2.86 Fixes CVE-2026-11526. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 55c68fd7a07225921f12f09c3fca242c5335dd53) --- pkgs/top-level/perl-packages.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index bb2db1caf486..6110e19498b7 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -14802,10 +14802,10 @@ with self; GD = buildPerlPackage { pname = "GD"; - version = "2.78"; + version = "2.86"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RU/RURBAN/GD-2.78.tar.gz"; - hash = "sha256-aDEFS/VCS09cI9NifT0UhEgPb5wsZmMiIpFfKFG+buQ="; + url = "mirror://cpan/authors/id/R/RU/RURBAN/GD-2.86.tar.gz"; + hash = "sha256-bWTTvhQpzB606IqPICL+yRDqPgeS2k/ljT7fdpXEbKI="; }; nativeBuildInputs = [ @@ -14820,6 +14820,7 @@ with self; pkgs.fontconfig pkgs.libxpm ExtUtilsPkgConfig + FileWhich TestFork TestNoWarnings ]; From d89874815f7ffb8d4b14fd51fee960e43dd35973 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:41:41 +0200 Subject: [PATCH 067/110] perlPackages.ConfigIniFiles: 3.000003 -> 3.002000 Fixes CVE-2026-11527. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 02ee43b56f68a424ce31e1c986b9fe4dccb1cb2f) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 6110e19498b7..dca50236ff70 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -6061,10 +6061,10 @@ with self; ConfigIniFiles = buildPerlPackage { pname = "Config-IniFiles"; - version = "3.000003"; + version = "3.002000"; src = fetchurl { - url = "mirror://cpan/authors/id/S/SH/SHLOMIF/Config-IniFiles-3.000003.tar.gz"; - hash = "sha256-PEV7ZdmOX/QL25z4FLDVmD6wxT+4aWvaO6A1rSrNaAI="; + url = "mirror://cpan/authors/id/S/SH/SHLOMIF/Config-IniFiles-3.002000.tar.gz"; + hash = "sha256-Bmke17QZl+hQxOfGs05cOWFF4M0FCvGUSiDQaMOlpAs="; }; propagatedBuildInputs = [ IOStringy ]; meta = { From f94ec895737077ffc264c516510533cb43153624 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:44:06 +0200 Subject: [PATCH 068/110] perlPackages.CookieBaker: 0.11 -> 0.12 Required by Plack::Middleware::Session 0.36. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 3cb2e3221aacd925b9a2ff29b2f7ba60a0517bad) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index dca50236ff70..f9f1892642a7 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -6519,10 +6519,10 @@ with self; CookieBaker = buildPerlModule { pname = "Cookie-Baker"; - version = "0.11"; + version = "0.12"; src = fetchurl { - url = "mirror://cpan/authors/id/K/KA/KAZEBURO/Cookie-Baker-0.11.tar.gz"; - hash = "sha256-WSdfR04HwKo2EePmhLiU59uRMzPYIUQgvmPxLsGM16s="; + url = "mirror://cpan/authors/id/K/KA/KAZEBURO/Cookie-Baker-0.12.tar.gz"; + hash = "sha256-mwTfXUfc1FrEKZYmoQ7JkPtAyU7lpjAMOoi9+zV17Ck="; }; buildInputs = [ ModuleBuildTiny From 4be4476bea7ed41db973c743848097be4a91d05b Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:44:58 +0200 Subject: [PATCH 069/110] perlPackages.PlackMiddlewareSession: 0.33 -> 0.36 Fixes CVE-2025-40923, CVE-2013-10031. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 02bfa3d8bc458884286314b9b12121c5578e34f1) --- pkgs/top-level/perl-packages.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index f9f1892642a7..506037e746ff 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -28713,12 +28713,13 @@ with self; PlackMiddlewareSession = buildPerlModule { pname = "Plack-Middleware-Session"; - version = "0.33"; + version = "0.36"; src = fetchurl { - url = "mirror://cpan/authors/id/M/MI/MIYAGAWA/Plack-Middleware-Session-0.33.tar.gz"; - hash = "sha256-T/miydGK2ASbRd/ze5vdQSIeLC8eFrr7gb/tyIxRpO4="; + url = "mirror://cpan/authors/id/M/MI/MIYAGAWA/Plack-Middleware-Session-0.36.tar.gz"; + hash = "sha256-kqWDFliBDSNzLm47rnpEofpafYpqbm3NdbkcapwktGY="; }; propagatedBuildInputs = [ + CryptSysRandom DigestHMAC Plack ]; From fc7097d2f99496d59a60fb24f3cca3afcecf2639 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:46:07 +0200 Subject: [PATCH 070/110] perlPackages.YAMLLibYAML: 0.89 -> 0.907.0 Fixes CVE-2025-40908. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 2c79c8f23a6b7a61195c7f53622ef68ed3a84e9f) --- pkgs/top-level/perl-packages.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 506037e746ff..c5c00e60419a 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -39540,11 +39540,12 @@ with self; YAMLLibYAML = buildPerlPackage { pname = "YAML-LibYAML"; - version = "0.89"; + version = "0.907.0"; src = fetchurl { - url = "mirror://cpan/authors/id/T/TI/TINITA/YAML-LibYAML-0.89.tar.gz"; - hash = "sha256-FVq4NnU0XFCt0DMRrPndkVlVcH+Qmiq9ixfXeShZsuw="; + url = "mirror://cpan/authors/id/T/TI/TINITA/YAML-LibYAML-v0.907.0.tar.gz"; + hash = "sha256-a6CHIkkROJ52+hmLFJzsg/BlsKx13cUmGPNJCULNlQY="; }; + buildInputs = [ TestWarnings ]; meta = { description = "Perl YAML Serialization using XS and libyaml"; license = with lib.licenses; [ From 7b3f2aa4a1aed512ee53eca47216d298abda6e93 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:47:18 +0200 Subject: [PATCH 071/110] perlPackages.CryptCBC: 2.33 -> 3.07 Fixes CVE-2025-2814. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 49ef24302dabf5edc456c4ed56af2133cac0b48c) --- pkgs/top-level/perl-packages.nix | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index c5c00e60419a..1562852baadc 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -6990,11 +6990,16 @@ with self; CryptCBC = buildPerlPackage { pname = "Crypt-CBC"; - version = "2.33"; + version = "3.07"; src = fetchurl { - url = "mirror://cpan/authors/id/L/LD/LDS/Crypt-CBC-2.33.tar.gz"; - hash = "sha256-anDeIbbMfysQAGfo4Yjblm6agAG122+pdufLWylK5kU="; + url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Crypt-CBC-3.07.tar.gz"; + hash = "sha256-9N37TdasUBPfg0G/pzTZye4PEOLnEhXsj+W/eAt8kSc="; }; + propagatedBuildInputs = [ + CryptPBKDF2 + CryptURandom + CryptX + ]; meta = { description = "Encrypt Data with Cipher Block Chaining Mode"; license = with lib.licenses; [ From e8a22292980672133624eedb73a93612ee73298f Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 14:48:14 +0200 Subject: [PATCH 072/110] perlPackages.Mojolicious: 9.39 -> 9.46 Fixes CVE-2024-58135. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 5b6275f4054ef7e0c374079db3bfd761b710aad4) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 1562852baadc..bc3f97886d79 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -22846,10 +22846,10 @@ with self; Mojolicious = buildPerlPackage { pname = "Mojolicious"; - version = "9.39"; + version = "9.46"; src = fetchurl { - url = "mirror://cpan/authors/id/S/SR/SRI/Mojolicious-9.39.tar.gz"; - hash = "sha256-EwpJDXfXYTn3NM4biU1Fm64DgF+x89/dWPxE/oKvPP0="; + url = "mirror://cpan/authors/id/S/SR/SRI/Mojolicious-9.46.tar.gz"; + hash = "sha256-/kc9LK5tLe/pUBgCggc2VoJa0F20TwvIxIQhXi1xaqw="; }; meta = { description = "Real-time web framework"; From 3cadb4dafa9032d3e9251283a4e3550a5812e250 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 15:21:30 +0200 Subject: [PATCH 073/110] perlPackages.IOCompress: 2.220 -> 2.221 Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit a06c0268f6fadd8d6a070df7f3bf30cec3ee0237) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index bc3f97886d79..e247acf9f7f1 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -17720,10 +17720,10 @@ with self; IOCompress = buildPerlPackage { pname = "IO-Compress"; - version = "2.220"; + version = "2.221"; src = fetchurl { - url = "mirror://cpan/authors/id/P/PM/PMQS/IO-Compress-2.220.tar.gz"; - hash = "sha256-nZbqKR8sVO82fHOWuFfZO6GsHEsvG84T7Yo+Xz7rtic="; + url = "mirror://cpan/authors/id/P/PM/PMQS/IO-Compress-2.221.tar.gz"; + hash = "sha256-r0LJyRBK3313LSVcDZpASjRi6kXnvELQbaCgtR3j0K4="; }; propagatedBuildInputs = [ CompressRawBzip2 From cb699ed771166c9959ec00646784c5b2b30a9037 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 15:22:08 +0200 Subject: [PATCH 074/110] perlPackages.HTTPMessage: 6.45 -> 7.02 Required by libwww-perl 6.83. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit d95a5e6344e6e7b308e6c6e35cadfd37da5229a9) --- pkgs/top-level/perl-packages.nix | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index e247acf9f7f1..69aa8fd91985 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -17042,10 +17042,10 @@ with self; HTTPMessage = buildPerlPackage { pname = "HTTP-Message"; - version = "6.45"; + version = "7.02"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Message-6.45.tar.gz"; - hash = "sha256-AcuEBmEqP3OIQtHpcxOuTYdIcNG41tZjMfFgAJQ9TL4="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Message-7.02.tar.gz"; + hash = "sha256-eKvvHYMxRrSNF9shmxsD1Ty743oozNrQ79zFgzylxgw="; }; buildInputs = [ TestNeeds @@ -17053,8 +17053,11 @@ with self; ]; propagatedBuildInputs = [ Clone + CompressRawBzip2 + CompressRawZlib EncodeLocale HTTPDate + IOCompress IOHTML LWPMediaTypes URI From 42b4bd40255c39b30549ef53c5c28854bcdc979d Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Thu, 18 Jun 2026 15:23:31 +0200 Subject: [PATCH 075/110] perlPackages.libwwwperl: 6.72 -> 6.83 Fixes CVE-2026-8368. Covers both the libwwwperl and LWP attributes. Assisted-by: Claude Code (Claude Opus 4.8) Signed-off-by: Stig Palmquist (cherry picked from commit 03a06252a45713863ded5d69ef44e0a738281389) --- pkgs/top-level/perl-packages.nix | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 69aa8fd91985..0cb6c6e5b7e0 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -18961,10 +18961,10 @@ with self; libwwwperl = buildPerlPackage { pname = "libwww-perl"; - version = "6.72"; + version = "6.83"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.72.tar.gz"; - hash = "sha256-6bg1T9XiC+IHr+I93VhPzVm/gpmNwHfez2hLodrloF0="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.83.tar.gz"; + hash = "sha256-518PqdPG8Nr1pacvqfixycDSPjqEqFIsy0+DUjK5VQU="; }; buildInputs = [ HTTPDaemon @@ -20218,10 +20218,10 @@ with self; LWP = buildPerlPackage { pname = "libwww-perl"; - version = "6.72"; + version = "6.83"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.72.tar.gz"; - hash = "sha256-6bg1T9XiC+IHr+I93VhPzVm/gpmNwHfez2hLodrloF0="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/libwww-perl-6.83.tar.gz"; + hash = "sha256-518PqdPG8Nr1pacvqfixycDSPjqEqFIsy0+DUjK5VQU="; }; propagatedBuildInputs = [ FileListing From f5395dd66d93957344b2e60bb535398a6977a2fe Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sat, 8 Aug 2026 15:45:13 +0000 Subject: [PATCH 076/110] perlPackages.CSSMinifierXS: 0.13 -> 0.15 Fixes CVE-2026-13593. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit f8629eeb4bd1f78b65bad68576a6d560a10f47ce) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 0cb6c6e5b7e0..6534e5e0d670 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -7969,10 +7969,10 @@ with self; CSSMinifierXS = buildPerlPackage { pname = "CSS-Minifier-XS"; - version = "0.13"; + version = "0.15"; src = fetchurl { - url = "mirror://cpan/authors/id/G/GT/GTERMARS/CSS-Minifier-XS-0.13.tar.gz"; - hash = "sha256-xBnjCM3IKvHCXWuNB7L/JjR6Yit6Y+wghWq+jbQFH4I="; + url = "mirror://cpan/authors/id/G/GT/GTERMARS/CSS-Minifier-XS-0.15.tar.gz"; + hash = "sha256-iprSIxYtpGceP4EsSlXyl3OUg70xar2kH0wn6K3XhVM="; }; buildInputs = [ TestDiagINC ]; meta = { From a5467ee151248992341d7065a77b70e15a3bd9e0 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sat, 8 Aug 2026 15:47:39 +0000 Subject: [PATCH 077/110] perlPackages.CGISession: 4.48 -> 4.49 Fixes CVE-2026-56016 in CGI::Session::ID::md5. The fix replaces rand() with Crypt::SysRandom. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit 27574bbdf94ffde412ac7343ae367dca5785e4d8) --- pkgs/top-level/perl-packages.nix | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 6534e5e0d670..4fe2c974d06d 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -4627,12 +4627,15 @@ with self; CGISession = buildPerlModule { pname = "CGI-Session"; - version = "4.48"; + version = "4.49"; src = fetchurl { - url = "mirror://cpan/authors/id/M/MA/MARKSTOS/CGI-Session-4.48.tar.gz"; - hash = "sha256-RnVkYcJM52ZrgQjduW26thJpnfMBLIDvEQFmGf4VVPc="; + url = "mirror://cpan/authors/id/M/MA/MARKSTOS/CGI-Session-4.49.tar.gz"; + hash = "sha256-X9iKgwo19UUmeH8DauXkp9FLYcQUzSmthjG/RuaXEgc="; }; - propagatedBuildInputs = [ CGI ]; + propagatedBuildInputs = [ + CGI + CryptSysRandom + ]; meta = { description = "Persistent session data in CGI applications"; license = with lib.licenses; [ artistic1 ]; From 2a6bc9b9d96a5bc37937fa493199c286f79aa2d8 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sat, 8 Aug 2026 15:48:17 +0000 Subject: [PATCH 078/110] perlPackages.HTMLGumbo: 0.18 -> 0.20 Fixes CVE-2025-15646. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit aa5e047da036ff9e1165a1323e09e49b438537c8) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 4fe2c974d06d..3f482acfcb11 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -16383,10 +16383,10 @@ with self; HTMLGumbo = buildPerlModule { pname = "HTML-Gumbo"; - version = "0.18"; + version = "0.20"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RU/RUZ/HTML-Gumbo-0.18.tar.gz"; - hash = "sha256-v1C2HCRlbMP8lYYC2AqcfQFyR6842Nv6Dp3sW3VCXV8="; + url = "mirror://cpan/authors/id/B/BP/BPS/HTML-Gumbo-0.20.tar.gz"; + hash = "sha256-ImEK+8bIfgZ92E9/EZo9J4Ie1kEwNFU8Ga694iEdiDU="; }; propagatedBuildInputs = [ AlienLibGumbo ]; meta = { From 378f4a92b30d857eaa52668b2c0c95ca70154377 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sat, 8 Aug 2026 15:49:28 +0000 Subject: [PATCH 079/110] perlPackages.StringUtil: 1.34 -> 1.36 Fixes CVE-2026-14895. Upstream switched from Module::Build to ExtUtils::MakeMaker in 1.35. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit 11acdf3f307c8aa708e62655b7eab4832ac732eb) --- pkgs/top-level/perl-packages.nix | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 3f482acfcb11..0270b649ae85 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -32180,14 +32180,13 @@ with self; }; }; - StringUtil = buildPerlModule { + StringUtil = buildPerlPackage { pname = "String-Util"; - version = "1.34"; + version = "1.36"; src = fetchurl { - url = "mirror://cpan/authors/id/B/BA/BAKERSCOT/String-Util-1.34.tar.gz"; - hash = "sha256-MZzozWZTQeVlIfoVXZYqGTKOkNn3A2dlklzN4mclxGk="; + url = "mirror://cpan/authors/id/B/BA/BAKERSCOT/String-Util-1.36.tar.gz"; + hash = "sha256-UXsasyVm/U1ei+I9mTOc47/+4pEsX/KfXclYcP9Pyw4="; }; - buildInputs = [ ModuleBuildTiny ]; meta = { description = "String processing utility functions"; homepage = "https://github.com/scottchiefbaker/String-Util"; From 364774f0c37c16d0bb97d0a0b3b26b1ab701a358 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sat, 8 Aug 2026 15:51:10 +0000 Subject: [PATCH 080/110] perlPackages.CryptDSA: 1.21 -> 1.24 Fixes CVE-2026-14570. 1.24 uses Crypt::SysRandom and no longer requires Crypt::URandom. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit 079bcf2560f70325dfcf937984fd4ac85f3f7e80) --- pkgs/top-level/perl-packages.nix | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 0270b649ae85..2aaf4d4dd15b 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -7124,16 +7124,15 @@ with self; CryptDSA = buildPerlPackage { pname = "Crypt-DSA"; - version = "1.21"; + version = "1.24"; src = fetchurl { - url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Crypt-DSA-1.21.tar.gz"; - hash = "sha256-pGIB6DkOi6O75RER12SJ8x2v2g9qYLCrkxndUr0rMrA="; + url = "mirror://cpan/authors/id/T/TI/TIMLEGGE/Crypt-DSA-1.24.tar.gz"; + hash = "sha256-ChY4tvK07+ktbuL0kBzKAtenBWf2uw9Iapu19pvnZ2Y="; }; propagatedBuildInputs = [ ConvertASN1 ConvertPEM CryptSysRandom - CryptURandom DataBuffer FileWhich ]; From def3f6771d02a5b35b6c396b0fd12d407cf8c9d9 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sat, 8 Aug 2026 15:52:53 +0000 Subject: [PATCH 081/110] perlPackages.DevelDeprecate: init at 0.01 New runtime dependency of Data::Entropy 0.010. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit b3b347504e08b7e453dcf4fe8c58e7fa36a3aeef) --- pkgs/top-level/perl-packages.nix | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 2aaf4d4dd15b..1900d6c447ba 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -9679,6 +9679,24 @@ with self; }; }; + DevelDeprecate = buildPerlPackage { + pname = "Devel-Deprecate"; + version = "0.01"; + src = fetchurl { + url = "mirror://cpan/authors/id/O/OV/OVID/Devel-Deprecate-0.01.tar.gz"; + hash = "sha256-xQLEGoL+JU6XFRJ3ytOk8KQHrTydP2I9J3sDA6PhoS8="; + }; + buildInputs = [ SubOverride ]; + propagatedBuildInputs = [ DateTime ]; + meta = { + description = "Create deprecation schedules in your code"; + license = with lib.licenses; [ + artistic1 + gpl1Plus + ]; + }; + }; + DevelDeprecationsEnvironmental = buildPerlPackage { pname = "Devel-Deprecations-Environmental"; version = "1.101"; From fd630b74c1969791fa32c6ba960e91a7e6d9a3e8 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sat, 8 Aug 2026 15:54:58 +0000 Subject: [PATCH 082/110] perlPackages.DataEntropy: 0.008 -> 0.010 Fixes CVE-2026-18536. 0.010 removes the Random.org sources, which were the only consumers of HTTP::Lite, and requires Devel::Deprecate. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit 26c50f57329a0da8224b771b36d1aa9f5ee1c015) --- pkgs/top-level/perl-packages.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 1900d6c447ba..74ed3fcfeb35 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -8232,16 +8232,16 @@ with self; DataEntropy = buildPerlPackage { pname = "Data-Entropy"; - version = "0.008"; + version = "0.010"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RR/RRWO/Data-Entropy-0.008.tar.gz"; - hash = "sha256-GKUrE4boLGuM2zhKOYYdYCIKRCp5DgdwEL5y3YU7Z7M="; + url = "mirror://cpan/authors/id/R/RR/RRWO/Data-Entropy-0.010.tar.gz"; + hash = "sha256-0M8s2wKCAuidw2K42Qtw00WFApOwGQDZoYgqDG8g+Dc="; }; propagatedBuildInputs = [ CryptRijndael CryptURandom DataFloat - HTTPLite + DevelDeprecate ParamsClassify ]; meta = { From 1fdb0b868b9695181e36ac774542118b6dbdca8c Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sat, 8 Aug 2026 15:55:50 +0000 Subject: [PATCH 083/110] perlPackages.MojoJWT: 0.09 -> 1.02 Fixes CVE-2026-9537. 1.02 requires CryptX at runtime. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit b2a490b6534095408f0449fcc565f626df639935) --- pkgs/top-level/perl-packages.nix | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 74ed3fcfeb35..82d708c62443 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -23234,13 +23234,16 @@ with self; MojoJWT = buildPerlModule { pname = "Mojo-JWT"; - version = "0.09"; + version = "1.02"; src = fetchurl { - url = "mirror://cpan/authors/id/J/JB/JBERGER/Mojo-JWT-0.09.tar.gz"; - hash = "sha256-wE4DmD4MbyvORdCOoucph5yWee+mNLDmjLa4t7SoWIY="; + url = "mirror://cpan/authors/id/J/JB/JBERGER/Mojo-JWT-1.02.tar.gz"; + hash = "sha256-yBHXkoWMJBFQNyDxJDbjNDZ0k2dUO/vCqV1PgDzmCHQ="; }; buildInputs = [ ModuleBuildTiny ]; - propagatedBuildInputs = [ Mojolicious ]; + propagatedBuildInputs = [ + CryptX + Mojolicious + ]; meta = { description = "JSON Web Token the Mojo way"; homepage = "https://github.com/jberger/Mojo-JWT"; From 8824ac460ee9a21f630ef22daf85c651fe9fff8c Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sat, 8 Aug 2026 15:56:26 +0000 Subject: [PATCH 084/110] perlPackages.ack: 3.9.0 -> 3.10.0 Fixes CVE-2026-49146. CVE-2026-49145 and CVE-2026-49147 remain unfixed in 3.10.0. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit 2f2c8475756fe4a204a20a2d400a68a7d911bfb0) --- pkgs/top-level/perl-packages.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 82d708c62443..5a9b7cec28a2 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -116,11 +116,11 @@ with self; ack = buildPerlPackage rec { pname = "ack"; - version = "3.9.0"; + version = "3.10.0"; src = fetchurl { url = "mirror://cpan/authors/id/P/PE/PETDANCE/ack-v${version}.tar.gz"; - hash = "sha256-lO1Hfjs/lNEmzscynw6DmfHQzoLHxNiCqUrbFQ5//JA="; + hash = "sha256-Zeg8+zinH8pyXpoUqCAe6HHmKfxrECMeEwPdNQG6Vjo="; }; outputs = [ From f993762d71a35500bf106a1d5b0d2edbfef4cfe3 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sat, 8 Aug 2026 15:59:57 +0000 Subject: [PATCH 085/110] perlPackages.HTTPDate: 6.06 -> 6.08 Fixes CVE-2026-14741. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit 0d1907cd9fc18179000472f036fff8b23b7ffa42) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 5a9b7cec28a2..8738332ae73f 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -16932,10 +16932,10 @@ with self; HTTPDate = buildPerlPackage { pname = "HTTP-Date"; - version = "6.06"; + version = "6.08"; src = fetchurl { - url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Date-6.06.tar.gz"; - hash = "sha256-e2hRkcasw+dz0fwCyV7h+frpT3d4MXX154wYHMktK1I="; + url = "mirror://cpan/authors/id/O/OA/OALDERS/HTTP-Date-6.08.tar.gz"; + hash = "sha256-tX2Aym2CHGlJykiydGfUWrp6nHc0ZWIwb6zKeBoAPkQ="; }; propagatedBuildInputs = [ TimeDate ]; meta = { From 57e11a11fea1af058be1063dbd07e9e9688f811e Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sat, 8 Aug 2026 16:38:53 +0000 Subject: [PATCH 086/110] perlPackages.Mojolicious: 9.46 -> 9.48 Fixes CVE-2026-14803 in Mojo::JSON and CVE-2026-15747. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit dda5a5d9a982a1b411fdbdf96afdf364140f49db) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 8738332ae73f..0a943dd63d32 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -22869,10 +22869,10 @@ with self; Mojolicious = buildPerlPackage { pname = "Mojolicious"; - version = "9.46"; + version = "9.48"; src = fetchurl { - url = "mirror://cpan/authors/id/S/SR/SRI/Mojolicious-9.46.tar.gz"; - hash = "sha256-/kc9LK5tLe/pUBgCggc2VoJa0F20TwvIxIQhXi1xaqw="; + url = "mirror://cpan/authors/id/S/SR/SRI/Mojolicious-9.48.tar.gz"; + hash = "sha256-Jv8EFSgR/VsaNrR9mewhnFiZW6jnsVugKzPQdwpe7pg="; }; meta = { description = "Real-time web framework"; From f5e9e9b4be0326bcb9daade7543cf31a96bbcc38 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sat, 8 Aug 2026 16:51:31 +0000 Subject: [PATCH 087/110] perlPackages.DBI: 1.648 -> 1.651 Fixes CVE-2026-14380, CVE-2026-14739 and CVE-2026-14740 (1.650), and CVE-2026-15043, CVE-2026-15392, CVE-2026-60081 and CVE-2026-60082 (1.651). Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit d56e5a7696268bcaa4678acf321a758f9baa3221) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 0a943dd63d32..b634f0e3f075 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -10137,11 +10137,11 @@ with self; DBI = buildPerlPackage { pname = "DBI"; - version = "1.648"; + version = "1.651"; src = fetchurl { - url = "mirror://cpan/authors/id/H/HM/HMBRAND/DBI-1.648.tgz"; - hash = "sha256-7yZqrWAQzi6rt+Rl69c8owILxYFQ9pib2Jwrj5usaoY="; + url = "mirror://cpan/authors/id/H/HM/HMBRAND/DBI-1.651.tgz"; + hash = "sha256-2mIaI/po4eBPrIJM/T1B6P+6sqs+umQqEkmSQui+UlM="; }; env = lib.optionalAttrs stdenv.cc.isGNU { From 6004c4f5d2c9237baa455e10dcc2a025e2096e08 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sat, 8 Aug 2026 16:56:10 +0000 Subject: [PATCH 088/110] perlPackages.JSONXS: 4.03 -> 4.04 4.04 contains the upstream fix for CVE-2025-40928. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit eb5ca223180217b72d0b28da37f8f41e241ff9bc) --- .../perl-modules/JSON-XS-CVE-2025-40928.patch | 31 ------------------- pkgs/top-level/perl-packages.nix | 7 ++--- 2 files changed, 3 insertions(+), 35 deletions(-) delete mode 100644 pkgs/development/perl-modules/JSON-XS-CVE-2025-40928.patch diff --git a/pkgs/development/perl-modules/JSON-XS-CVE-2025-40928.patch b/pkgs/development/perl-modules/JSON-XS-CVE-2025-40928.patch deleted file mode 100644 index f1d258c12a3d..000000000000 --- a/pkgs/development/perl-modules/JSON-XS-CVE-2025-40928.patch +++ /dev/null @@ -1,31 +0,0 @@ ---- a/XS.xs 2025-09-06 08:34:51.376455632 -0300 -+++ b/XS.xs 2025-09-06 08:35:30.725873619 -0300 -@@ -253,16 +253,16 @@ - // if we recurse too deep, skip all remaining digits - // to avoid a stack overflow attack - if (expect_false (--maxdepth <= 0)) -- while (((U8)*s - '0') < 10) -+ while ((U8)(*s - '0') < 10) - ++s; - - for (;;) - { -- U8 dig = (U8)*s - '0'; -+ U8 dig = *s - '0'; - - if (expect_false (dig >= 10)) - { -- if (dig == (U8)((U8)'.' - (U8)'0')) -+ if (dig == (U8)('.' - '0')) - { - ++s; - json_atof_scan1 (s, accum, expo, 1, maxdepth); -@@ -282,7 +282,7 @@ - else if (*s == '+') - ++s; - -- while ((dig = (U8)*s - '0') < 10) -+ while ((dig = (U8)(*s - '0')) < 10) - exp2 = exp2 * 10 + *s++ - '0'; - - *expo += neg ? -exp2 : exp2; diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index b634f0e3f075..703f003d4e09 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -18668,12 +18668,11 @@ with self; JSONXS = buildPerlPackage { pname = "JSON-XS"; - version = "4.03"; + version = "4.04"; src = fetchurl { - url = "mirror://cpan/authors/id/M/ML/MLEHMANN/JSON-XS-4.03.tar.gz"; - hash = "sha256-UVU29F8voafojIgkUzdY0BIdJnq5y0U6G1iHyKVrkGg="; + url = "mirror://cpan/authors/id/M/ML/MLEHMANN/JSON-XS-4.04.tar.gz"; + hash = "sha256-jv8enzBMViW1mre0IlhBX20+NoHB3atrclUYoBin9eA="; }; - patches = [ ../development/perl-modules/JSON-XS-CVE-2025-40928.patch ]; propagatedBuildInputs = [ TypesSerialiser ]; buildInputs = [ CanaryStability ]; meta = { From 7a77df36a8dbd0b2f079a6f811866362f6f097ca Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sun, 9 Aug 2026 00:51:03 +0000 Subject: [PATCH 089/110] perlPackages.FileFindRule: 0.34 -> 0.35 0.35 contains the upstream fix for CVE-2011-10007. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit 61d5a4891aaa93359e2d1105282f84d7f960d10d) --- .../FileFindRule-CVE-2011-10007.patch | 25 ------------------- pkgs/top-level/perl-packages.nix | 9 +++---- 2 files changed, 3 insertions(+), 31 deletions(-) delete mode 100644 pkgs/development/perl-modules/FileFindRule-CVE-2011-10007.patch diff --git a/pkgs/development/perl-modules/FileFindRule-CVE-2011-10007.patch b/pkgs/development/perl-modules/FileFindRule-CVE-2011-10007.patch deleted file mode 100644 index dd8492c60f21..000000000000 --- a/pkgs/development/perl-modules/FileFindRule-CVE-2011-10007.patch +++ /dev/null @@ -1,25 +0,0 @@ -From ca70a73bb147549e62e74751d924b1dbb59d1707 Mon Sep 17 00:00:00 2001 -From: Stig Palmquist -Date: Thu, 5 Jun 2025 03:45:50 +0200 -Subject: [PATCH] Fix CVE-2011-10007 - ---- - lib/File/Find/Rule.pm | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/lib/File/Find/Rule.pm b/lib/File/Find/Rule.pm -index feccc76..d4dc475 100644 ---- a/lib/File/Find/Rule.pm -+++ b/lib/File/Find/Rule.pm -@@ -420,7 +420,7 @@ sub grep { - - $self->exec( sub { - local *FILE; -- open FILE, $_ or return; -+ open FILE, '<', $_ or return; - local ($_, $.); - while () { - for my $p (@pattern) { --- -2.49.0 - diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 703f003d4e09..c57e9dba4619 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -13638,14 +13638,11 @@ with self; FileFindRule = buildPerlPackage { pname = "File-Find-Rule"; - version = "0.34"; + version = "0.35"; src = fetchurl { - url = "mirror://cpan/authors/id/R/RC/RCLAMP/File-Find-Rule-0.34.tar.gz"; - hash = "sha256-fm8WzDPrHyn/Jb7lHVE/S4qElHu/oY7bLTzECi1kyv4="; + url = "mirror://cpan/authors/id/R/RC/RCLAMP/File-Find-Rule-0.35.tar.gz"; + hash = "sha256-K9VWKJptRK0u50gDJYuwsAUNJG8egcqrCyY8MDrPDII="; }; - patches = [ - ../development/perl-modules/FileFindRule-CVE-2011-10007.patch - ]; propagatedBuildInputs = [ NumberCompare TextGlob From 592db207a643e3d53804848f4822e20a9358a0f3 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sun, 9 Aug 2026 00:56:50 +0000 Subject: [PATCH 090/110] perlPackages.CatalystAuthenticationCredentialHTTP: 1.018 -> 1.019 1.019 contains the upstream fix for CVE-2025-40920, which uses Crypt::SysRandom instead of Data::UUID. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit d3a1694c8f48ccce9932b5b10a4c914ff82ec4e5) --- pkgs/top-level/perl-packages.nix | 14 +++----------- 1 file changed, 3 insertions(+), 11 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index c57e9dba4619..b04946fe8991 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -3352,18 +3352,11 @@ with self; CatalystAuthenticationCredentialHTTP = buildPerlModule { pname = "Catalyst-Authentication-Credential-HTTP"; - version = "1.018"; + version = "1.019"; src = fetchurl { - url = "mirror://cpan/authors/id/E/ET/ETHER/Catalyst-Authentication-Credential-HTTP-1.018.tar.gz"; - hash = "sha256-b6GBbe5kSw216gzBXF5xHcLO0gg2JavOcJZSHx1lpSk="; + url = "mirror://cpan/authors/id/A/AB/ABRAXXA/Catalyst-Authentication-Credential-HTTP-1.019.tar.gz"; + hash = "sha256-7IHpbCo/ZYbqQdCI6o6AGx80ABqxnMmmXe+KOMOaW9o="; }; - patches = [ - (fetchpatch { - name = "CVE-2025-40920.patch"; - url = "https://github.com/perl-catalyst/Catalyst-Authentication-Credential-HTTP/commit/ad2c03aad95406db4ce35dfb670664ebde004c18.patch"; - hash = "sha256-WI6JwvY6i3KkQO9HbbSvHPX8mgM8I2cF0UTjF1D14T4="; - }) - ]; buildInputs = [ ModuleBuildTiny TestException @@ -3374,7 +3367,6 @@ with self; CatalystPluginAuthentication ClassAccessor CryptSysRandom - DataUUID StringEscape ]; meta = { From 149fb526e84c8ce912b4af22b93fc2b668c25721 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sun, 9 Aug 2026 02:51:18 +0000 Subject: [PATCH 091/110] perl: 5.42.0 -> 5.42.3 5.42.3 ships the interpreter fixes and the updated dual-life modules, so the CVE-2026-8376 patch and every vendoredPerlDistributions entry are dropped. perl-cross 1.6.4 has no patch set for 5.42.3, so the perl5-5.42.0 set, which applies unchanged, is vendored under the name perl-cross expects. - perl: CVE-2026-13221, CVE-2026-57432, CVE-2026-8376 https://metacpan.org/release/SHAY/perl-5.42.3/view/pod/perldelta.pod - HTTP-Tiny 0.096: CVE-2026-7010, CVE-2026-7017 https://metacpan.org/release/HAARG/HTTP-Tiny-0.096/changes - Socket 2.041: CVE-2026-12087 https://metacpan.org/release/PEVANS/Socket-2.041/changes - Storable 3.37_01: CVE-2026-57433 - Archive-Tar 3.12, Compress-Raw-Bzip2 2.218, Compress-Raw-Zlib 2.222, IO-Compress 2.223 Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit 7b1e682245c0c05aae0541b1697b472c7f74d578) --- .../interpreters/perl/CVE-2026-8376.patch | 20 ----- .../development/interpreters/perl/default.nix | 4 +- .../interpreters/perl/interpreter.nix | 47 +--------- .../perl/perl-cross-1.6.4--5.42.3.patch | 86 +++++++++++++++++++ 4 files changed, 91 insertions(+), 66 deletions(-) delete mode 100644 pkgs/development/interpreters/perl/CVE-2026-8376.patch create mode 100644 pkgs/development/interpreters/perl/perl-cross-1.6.4--5.42.3.patch diff --git a/pkgs/development/interpreters/perl/CVE-2026-8376.patch b/pkgs/development/interpreters/perl/CVE-2026-8376.patch deleted file mode 100644 index c8ad72298178..000000000000 --- a/pkgs/development/interpreters/perl/CVE-2026-8376.patch +++ /dev/null @@ -1,20 +0,0 @@ -Targeted patch for CVE-2026-8376, based on 5e7f119eb2bb1181be908701f22bf7068e722f1c but avoids changes to t/re/pat_psycho.t as they do not apply cleanly. - -diff --git a/regcomp_study.c b/regcomp_study.c -index b513454a4258..1602663f4b26 100644 ---- a/regcomp_study.c -+++ b/regcomp_study.c -@@ -2784,6 +2784,13 @@ Perl_study_chunk(pTHX_ - (U8 *) SvEND(data->last_found)) - - (U8*)s; - l -= old; -+ -+ if (l > 0 && -+ (mincount >= SSize_t_MAX / (SSize_t)l -+ || old > SSize_t_MAX - mincount * (SSize_t)l)) { -+ FAIL("Regexp out of space"); -+ } -+ - /* Get the added string: */ - last_str = newSVpvn_utf8(s + old, l, UTF); - last_chrs = UTF ? utf8_length((U8*)(s + old), diff --git a/pkgs/development/interpreters/perl/default.nix b/pkgs/development/interpreters/perl/default.nix index cab0ea1a2268..6cc6f5755ac4 100644 --- a/pkgs/development/interpreters/perl/default.nix +++ b/pkgs/development/interpreters/perl/default.nix @@ -73,8 +73,8 @@ in rec { perl5 = callPackage ./interpreter.nix { self = perl5; - version = "5.42.0"; - sha256 = "sha256-4JPvGE1/mhuXl+JGUpb1VRCtttq4hCsMPtUzKWYwltw="; + version = "5.42.3"; + sha256 = "sha256-ETd0CYWDe1zfFfDPq5Miedy0NS+RL+1vwUTotPCCNic="; inherit passthruFun; }; } diff --git a/pkgs/development/interpreters/perl/interpreter.nix b/pkgs/development/interpreters/perl/interpreter.nix index cdb03912b517..4b308c156f02 100644 --- a/pkgs/development/interpreters/perl/interpreter.nix +++ b/pkgs/development/interpreters/perl/interpreter.nix @@ -36,8 +36,6 @@ let commonPatches = [ # Do not look in /usr etc. for dependencies. ./no-sys-dirs.patch - - ./CVE-2026-8376.patch ] # Fix build on Solaris on x86_64 @@ -83,48 +81,7 @@ let # Inject fixed CPAN releases for bundled dual-life distributions until the # next perl maintenance release includes them. - vendoredPerlDistributions = [ - { - # CVE-2026-7010 - path = "cpan/HTTP-Tiny"; - src = fetchurl { - url = "mirror://cpan/authors/id/H/HA/HAARG/HTTP-Tiny-0.094.tar.gz"; - hash = "sha256-poQemfwbVdFd6VlHzL17dnvsxRxxAhl/qPBE333cB0M="; - }; - } - { - # CVE-2026-3381, CVE-2026-4176 - path = "cpan/Compress-Raw-Zlib"; - src = fetchurl { - url = "mirror://cpan/authors/id/P/PM/PMQS/Compress-Raw-Zlib-2.222.tar.gz"; - hash = "sha256-Hf19URplVifIGBXTDTurwo+luIRV/wP4sECZ3LUShrg="; - }; - } - { - # Runtime dependency of IO-Compress 2.220. - path = "cpan/Compress-Raw-Bzip2"; - src = fetchurl { - url = "mirror://cpan/authors/id/P/PM/PMQS/Compress-Raw-Bzip2-2.218.tar.gz"; - hash = "sha256-iRU+ai69pSNJSTsHT6S3VJ/x+QU952E8GKXgXFtBX6g="; - }; - } - { - # CVE-2026-48962, CVE-2026-48961, CVE-2026-48959 - path = "cpan/IO-Compress"; - src = fetchurl { - url = "mirror://cpan/authors/id/P/PM/PMQS/IO-Compress-2.220.tar.gz"; - hash = "sha256-nZbqKR8sVO82fHOWuFfZO6GsHEsvG84T7Yo+Xz7rtic="; - }; - } - { - # CVE-2026-42496, CVE-2026-42497, CVE-2026-9538 - path = "cpan/Archive-Tar"; - src = fetchurl { - url = "mirror://cpan/authors/id/B/BI/BINGOS/Archive-Tar-3.12.tar.gz"; - hash = "sha256-ARTvObZfSfiWgoOrR3Gdfoj5jXNg/jZJvjMcf1PVgyw="; - }; - } - ]; + vendoredPerlDistributions = [ ]; replaceVendoredPerlDistributions = lib.concatMapStringsSep "\n" (d: '' rm -rf ${d.path} @@ -440,6 +397,8 @@ stdenv.mkDerivation ( # fixes build failure due to missing d_fdopendir/HAS_FDOPENDIR configure option # https://github.com/arsv/perl-cross/pull/159 ./cross-fdopendir.patch + + ./perl-cross-1.6.4--5.42.3.patch ]; depsBuildBuild = [ diff --git a/pkgs/development/interpreters/perl/perl-cross-1.6.4--5.42.3.patch b/pkgs/development/interpreters/perl/perl-cross-1.6.4--5.42.3.patch new file mode 100644 index 000000000000..853fb8a667a2 --- /dev/null +++ b/pkgs/development/interpreters/perl/perl-cross-1.6.4--5.42.3.patch @@ -0,0 +1,86 @@ +perl-cross 1.6.4 ships no patch set for perl 5.42.3. The perl5-5.42.0 set +applies unchanged, so link it under the name perl-cross looks for. The +links are per-file because `find cnf/diffs/perl5-$version`, which +perl-cross uses to collect them, does not descend into a symlinked +directory. + +diff --git a/cnf/diffs/perl5-5.42.3/constant.patch b/cnf/diffs/perl5-5.42.3/constant.patch +new file mode 120000 +index 0000000..61f792a +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/constant.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/constant.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/dynaloader.patch b/cnf/diffs/perl5-5.42.3/dynaloader.patch +new file mode 120000 +index 0000000..543415e +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/dynaloader.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/dynaloader.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/findext.patch b/cnf/diffs/perl5-5.42.3/findext.patch +new file mode 120000 +index 0000000..94ed668 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/findext.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/findext.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/installscripts.patch b/cnf/diffs/perl5-5.42.3/installscripts.patch +new file mode 120000 +index 0000000..6f715b4 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/installscripts.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/installscripts.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/liblist.patch b/cnf/diffs/perl5-5.42.3/liblist.patch +new file mode 120000 +index 0000000..5037380 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/liblist.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/liblist.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/makemaker.patch b/cnf/diffs/perl5-5.42.3/makemaker.patch +new file mode 120000 +index 0000000..cf9fc6c +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/makemaker.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/makemaker.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/posix-makefile.patch b/cnf/diffs/perl5-5.42.3/posix-makefile.patch +new file mode 120000 +index 0000000..072ba89 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/posix-makefile.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/posix-makefile.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/test-checkcase.patch b/cnf/diffs/perl5-5.42.3/test-checkcase.patch +new file mode 120000 +index 0000000..6ecc9bc +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/test-checkcase.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/test-checkcase.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/test-makemaker.patch b/cnf/diffs/perl5-5.42.3/test-makemaker.patch +new file mode 120000 +index 0000000..fc6bcda +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/test-makemaker.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/test-makemaker.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/xconfig.patch b/cnf/diffs/perl5-5.42.3/xconfig.patch +new file mode 120000 +index 0000000..87ac501 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/xconfig.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/xconfig.patch +\ No newline at end of file From f700426a5eed7f8b068696e3bf7a98c9a51abfd7 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sun, 9 Aug 2026 05:58:49 +0000 Subject: [PATCH 092/110] perlPackages.Yancy: skip tests broken by Mojolicious 9.48 Mojolicious 9.48 enforces CSRF token validation (CVE-2026-15747); these tests drive forms without a token and fail with 400 "CSRF token failure". Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit d4db41d8bfa5e92019bdf43e5a932f600224afef) --- pkgs/top-level/perl-packages.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index b04946fe8991..60cf3a89f31d 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -39609,6 +39609,11 @@ with self; MojoliciousPluginOpenAPI RoleTiny ]; + # Mojolicious 9.48 enforces CSRF token validation (CVE-2026-15747); these + # tests drive forms without a token and fail with 400 "CSRF token failure". + preCheck = '' + rm t/plugin/auth/github.t t/plugin/form/bootstrap4.t + ''; meta = { homepage = "http://preaction.me/yancy/"; description = "Best Web Framework Deserves the Best CMS"; From 0db31ab897e7cfb87530330abc229b88790b6084 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sun, 9 Aug 2026 18:59:53 +0000 Subject: [PATCH 093/110] perl: fix CVE-2026-15534 Apply upstream commits 568e6fd238867bb9e99fa3f47cba3169009239e0 and 54cf3d44cbbedd17d774e9a37921963e8fd5d0cb. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit 709e8699ab3e17bfdaf02e11cf0e8e2996491360) --- .../interpreters/perl/CVE-2026-15534-1.patch | 39 ++++++++++++ .../interpreters/perl/CVE-2026-15534-2.patch | 59 +++++++++++++++++++ .../interpreters/perl/interpreter.nix | 3 + 3 files changed, 101 insertions(+) create mode 100644 pkgs/development/interpreters/perl/CVE-2026-15534-1.patch create mode 100644 pkgs/development/interpreters/perl/CVE-2026-15534-2.patch diff --git a/pkgs/development/interpreters/perl/CVE-2026-15534-1.patch b/pkgs/development/interpreters/perl/CVE-2026-15534-1.patch new file mode 100644 index 000000000000..fc8ee2f29ea9 --- /dev/null +++ b/pkgs/development/interpreters/perl/CVE-2026-15534-1.patch @@ -0,0 +1,39 @@ +CVE-2026-15534, upstream commit +568e6fd238867bb9e99fa3f47cba3169009239e0. + +diff --git a/regexec.c b/regexec.c +index 35a727459c4a..29aa73c13cb9 100644 +--- a/regexec.c ++++ b/regexec.c +@@ -9211,7 +9211,8 @@ NULL + reginfo->poscache_iter = reginfo->poscache_maxiter; + } + +- if (reginfo->poscache_iter-- == 0) { ++ if (reginfo->poscache_iter == 1) { ++ reginfo->poscache_iter--; + /* initialise cache */ + const SSize_t size = (reginfo->poscache_maxiter + 7)/8; + regmatch_info_aux *const aux = reginfo->info_aux; +@@ -9232,11 +9233,10 @@ NULL + ); + } + +- if (reginfo->poscache_iter < 0) { ++ if (reginfo->poscache_iter == 0) { + /* have we already failed at this position? */ + SSize_t offset, mask; + +- reginfo->poscache_iter = -1; /* stop eventual underflow */ + offset = (FLAGS(scan) & 0xf) - 1 + + (locinput - reginfo->strbeg) + * (FLAGS(scan)>>4); +@@ -9252,6 +9252,8 @@ NULL + ST.cache_offset = offset; + ST.cache_mask = mask; + } ++ else ++ reginfo->poscache_iter--; + } + + /* Prefer B over A for minimal matching. */ diff --git a/pkgs/development/interpreters/perl/CVE-2026-15534-2.patch b/pkgs/development/interpreters/perl/CVE-2026-15534-2.patch new file mode 100644 index 000000000000..b5d0ff5ed3d0 --- /dev/null +++ b/pkgs/development/interpreters/perl/CVE-2026-15534-2.patch @@ -0,0 +1,59 @@ +CVE-2026-15534, upstream commit +54cf3d44cbbedd17d774e9a37921963e8fd5d0cb. + +diff --git a/regexec.c b/regexec.c +index 29aa73c13cb9..66e0c0924059 100644 +--- a/regexec.c ++++ b/regexec.c +@@ -9202,22 +9202,27 @@ NULL + if (!reginfo->poscache_maxiter) { + /* start the countdown: Postpone detection until we + * know the match is not *that* much linear. */ +- reginfo->poscache_maxiter +- = (reginfo->strend - reginfo->strbeg + 1) +- * (FLAGS(scan)>>4); +- /* possible overflow for long strings and many CURLYX's */ +- if (reginfo->poscache_maxiter < 0) +- reginfo->poscache_maxiter = I32_MAX; +- reginfo->poscache_iter = reginfo->poscache_maxiter; ++ STRLEN len = reginfo->strend - reginfo->strbeg; ++ /* number of participating WHILEMs */ ++ U8 n = (FLAGS(scan)>>4); ++ ++ /* Only do the calculations and enable the cache if it ++ * won't overflow. This test is equivalent to: ++ * ((len + 1) * n + 7) <= max(STRLEN) ++ */ ++ if (len < ((~(STRLEN)0) - 7)/n) { ++ reginfo->poscache_maxiter = (len + 1) * n; ++ reginfo->poscache_iter = reginfo->poscache_maxiter; ++ } + } + + if (reginfo->poscache_iter == 1) { + reginfo->poscache_iter--; + /* initialise cache */ +- const SSize_t size = (reginfo->poscache_maxiter + 7)/8; ++ const STRLEN size = (reginfo->poscache_maxiter + 7)/8; + regmatch_info_aux *const aux = reginfo->info_aux; + if (aux->poscache) { +- if ((SSize_t)reginfo->poscache_size < size) { ++ if (reginfo->poscache_size < size) { + Renew(aux->poscache, size, char); + reginfo->poscache_size = size; + } +diff --git a/regexp.h b/regexp.h +index 057d9ac5011b..d5d40e0a5618 100644 +--- a/regexp.h ++++ b/regexp.h +@@ -839,8 +839,8 @@ typedef struct { + char *cutpoint; /* (*COMMIT) position (if any) */ + regmatch_info_aux *info_aux; /* extra fields that need cleanup */ + regmatch_info_aux_eval *info_aux_eval; /* extra saved state for (?{}) */ +- I32 poscache_maxiter; /* how many whilems todo before S-L cache kicks in */ +- I32 poscache_iter; /* current countdown from _maxiter to zero */ ++ STRLEN poscache_maxiter; /* how many whilems todo before S-L cache kicks in */ ++ STRLEN poscache_iter; /* current countdown from _maxiter to zero */ + STRLEN poscache_size; /* size of regmatch_info_aux.poscache */ + bool intuit; /* re_intuit_start() is the top-level caller */ + bool is_utf8_pat; /* regex is utf8 */ diff --git a/pkgs/development/interpreters/perl/interpreter.nix b/pkgs/development/interpreters/perl/interpreter.nix index 4b308c156f02..ae75db2ead90 100644 --- a/pkgs/development/interpreters/perl/interpreter.nix +++ b/pkgs/development/interpreters/perl/interpreter.nix @@ -36,6 +36,9 @@ let commonPatches = [ # Do not look in /usr etc. for dependencies. ./no-sys-dirs.patch + + ./CVE-2026-15534-1.patch + ./CVE-2026-15534-2.patch ] # Fix build on Solaris on x86_64 From da49bdf5c98bf3af169666755589ffa902724379 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Mon, 14 Sep 2026 22:57:43 +0000 Subject: [PATCH 094/110] perlPackages.DBI: 1.651 -> 1.653 Fixes CVE-2026-73193, CVE-2026-73194 and CVE-2026-78030. Assisted-by: Codex (GPT-6) (cherry picked from commit 489a75f613fd13643b77e58217512120be1aff5e) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 60cf3a89f31d..87fc7a42efe2 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -10129,11 +10129,11 @@ with self; DBI = buildPerlPackage { pname = "DBI"; - version = "1.651"; + version = "1.653"; src = fetchurl { - url = "mirror://cpan/authors/id/H/HM/HMBRAND/DBI-1.651.tgz"; - hash = "sha256-2mIaI/po4eBPrIJM/T1B6P+6sqs+umQqEkmSQui+UlM="; + url = "mirror://cpan/authors/id/H/HM/HMBRAND/DBI-1.653.tgz"; + hash = "sha256-qYwh/Tfu2PhBFyh10XXZcv6H8GPX0NKjt3ZZCLsl61g="; }; env = lib.optionalAttrs stdenv.cc.isGNU { From 148318bfe61b8a8aa3088394aa039eb0439dd529 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Mon, 14 Sep 2026 23:02:07 +0000 Subject: [PATCH 095/110] perlPackages.HTMLFormHandler: 0.40068 -> 0.410002 Fixes CVE-2022-4993, CVE-2026-19872, CVE-2026-85484, CVE-2026-85485 and CVE-2026-85630. Assisted-by: Codex (GPT-6) (cherry picked from commit 9ffd40254c14f0a08bf49eb4ff07527dfa948684) --- pkgs/top-level/perl-packages.nix | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 87fc7a42efe2..ddffe9c13a9a 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -16350,19 +16350,18 @@ with self; HTMLFormHandler = buildPerlPackage { pname = "HTML-FormHandler"; - version = "0.40068"; + version = "0.410002"; src = fetchurl { - url = "mirror://cpan/authors/id/G/GS/GSHANK/HTML-FormHandler-0.40068.tar.gz"; - hash = "sha256-63t43aMSV1LMi8wDltOXf70o2jPS1ExQQq1tNdbN6Cc="; + url = "mirror://cpan/authors/id/A/AB/ABRAXXA/HTML-FormHandler-0.410002.tar.gz"; + hash = "sha256-wT3n5PLDmV5QR1xilSm2VM+eLGJ73WLifqSMfG1jqeU="; }; - # a single test is failing on perl 5.20 - doCheck = false; buildInputs = [ FileShareDirInstall PadWalker TestDifferences TestException TestMemoryCycle + TestNeeds TestWarn ]; propagatedBuildInputs = [ From e4a1627c2a581b658e5379179e8ff801ea2e067c Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Mon, 14 Sep 2026 23:02:58 +0000 Subject: [PATCH 096/110] perlPackages.NetDNS: 1.56 -> 1.57 Fixes CVE-2026-81928. Assisted-by: Codex (GPT-6) (cherry picked from commit c71af76b99b9063b6de90bbc33147ea9cb0afd38) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index ddffe9c13a9a..af21c58b3ab4 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -25683,10 +25683,10 @@ with self; NetDNS = buildPerlPackage { pname = "Net-DNS"; - version = "1.56"; + version = "1.57"; src = fetchurl { - url = "mirror://cpan/authors/id/N/NL/NLNETLABS/Net-DNS-1.56.tar.gz"; - hash = "sha256-WTDjn3aJWzgMfKEfwINS0VrXHEH+hMEt+2oyLRf2aUY="; + url = "mirror://cpan/authors/id/N/NL/NLNETLABS/Net-DNS-1.57.tar.gz"; + hash = "sha256-fJjeMpy11qmau7A6qtKGbLBBCS7Zk2pyRpCOFwAFsFg="; }; propagatedBuildInputs = [ DigestHMAC ]; makeMakerFlags = [ "--noonline-tests" ]; From 6f13895f8125f0450c11fc0a86c934c8322d729e Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Mon, 14 Sep 2026 23:03:34 +0000 Subject: [PATCH 097/110] perlPackages.ProtocolHTTP2: 1.13 -> 1.14 Fixes CVE-2026-16028. Assisted-by: Codex (GPT-6) (cherry picked from commit e27c8da168cb998fce2b106098fc3c1170ad2f4e) --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index af21c58b3ab4..3ffa626191e6 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -29292,10 +29292,10 @@ with self; ProtocolHTTP2 = buildPerlModule { pname = "Protocol-HTTP2"; - version = "1.13"; + version = "1.14"; src = fetchurl { - url = "mirror://cpan/authors/id/C/CR/CRUX/Protocol-HTTP2-1.13.tar.gz"; - hash = "sha256-LsO0oYpkqGHgKYHO/Y7W8iOHUTj75e/us0DvF5ZVMGI="; + url = "mirror://cpan/authors/id/C/CR/CRUX/Protocol-HTTP2-1.14.tar.gz"; + hash = "sha256-pT8n6i+6wVakzUmB2O90nBvvNmwpCRNLTTHaIWRLSW4="; }; buildInputs = [ AnyEvent From 824ca0e7c5c74109f841bf6a9d31e9630bbccc3a Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Mon, 14 Sep 2026 23:06:51 +0000 Subject: [PATCH 098/110] perlPackages.CatalystPluginStaticSimple: 0.37 -> 0.38 Fixes CVE-2026-15743. Refreshes the existing ETag patch for 0.38. Assisted-by: Codex (GPT-6) (cherry picked from commit 8d26ff3a4025049a87bcb52fd7eba3e879e0cea0) --- .../catalyst-plugin-static-simple-etag.patch | 27 ++++--------------- pkgs/top-level/perl-packages.nix | 15 ++++++++--- 2 files changed, 16 insertions(+), 26 deletions(-) diff --git a/pkgs/development/perl-modules/catalyst-plugin-static-simple-etag.patch b/pkgs/development/perl-modules/catalyst-plugin-static-simple-etag.patch index 06207a8b7334..31b21f5cb768 100644 --- a/pkgs/development/perl-modules/catalyst-plugin-static-simple-etag.patch +++ b/pkgs/development/perl-modules/catalyst-plugin-static-simple-etag.patch @@ -1,36 +1,19 @@ Send an ETag header, and honour the If-None-Match request header -diff -ru -x '*~' Catalyst-Plugin-Static-Simple-0.30-orig/lib/Catalyst/Plugin/Static/Simple.pm Catalyst-Plugin-Static-Simple-0.30/lib/Catalyst/Plugin/Static/Simple.pm ---- Catalyst-Plugin-Static-Simple-0.30-orig/lib/Catalyst/Plugin/Static/Simple.pm 2012-05-04 18:49:30.000000000 +0200 -+++ Catalyst-Plugin-Static-Simple-0.30/lib/Catalyst/Plugin/Static/Simple.pm 2013-02-25 22:57:18.667150181 +0100 -@@ -187,16 +187,27 @@ - my $type = $c->_ext_to_type( $full_path ); - my $stat = stat $full_path; +--- a/lib/Catalyst/Plugin/Static/Simple.pm ++++ b/lib/Catalyst/Plugin/Static/Simple.pm +@@ -223,6 +223,15 @@ -- $c->res->headers->content_type( $type ); -- $c->res->headers->content_length( $stat->size ); -- $c->res->headers->last_modified( $stat->mtime ); - # Tell Firefox & friends its OK to cache, even over SSL: -- $c->res->headers->header('Cache-control' => 'public'); -+ #$c->res->headers->header('Cache-control' => 'public'); -+ -+ $c->res->headers->last_modified( $stat->mtime ); - # Optionally, set a fixed expiry time: - if ($config->{expires}) { - $c->res->headers->expires(time() + $config->{expires}); - } + $c->res->headers->header('Cache-Control' => $cache_control); + if ($config->{send_etag}) { -+ my $etag = '"' . $stat->mtime . '-' . $stat->ino . '-'. $stat->size . '"'; ++ my $etag = '"' . $stat->mtime . '-' . $stat->ino . '-' . $stat->size . '"'; + $c->res->headers->header('ETag' => $etag); + if (($c->req->header('If-None-Match') // "") eq $etag) { + $c->res->status(304); + return 1; + } + } -+ -+ $c->res->headers->content_type( $type ); -+ $c->res->headers->content_length( $stat->size ); + my $fh = IO::File->new( $full_path, 'r' ); if ( defined $fh ) { diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 3ffa626191e6..cf165c7b161a 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -4108,12 +4108,19 @@ with self; CatalystPluginStaticSimple = buildPerlPackage { pname = "Catalyst-Plugin-Static-Simple"; - version = "0.37"; + version = "0.38"; src = fetchurl { - url = "mirror://cpan/authors/id/I/IL/ILMARI/Catalyst-Plugin-Static-Simple-0.37.tar.gz"; - hash = "sha256-Wk2Fo1iM1Og/GwAlgUEufXG31X9mBW5dh6Nvk9icnnw="; + url = "mirror://cpan/authors/id/E/ET/ETHER/Catalyst-Plugin-Static-Simple-0.38.tar.gz"; + hash = "sha256-BOtn69x4cyf3fvLHOXar7Pk/mu/KCnGFIv6YuMpSOLA="; }; - patches = [ ../development/perl-modules/catalyst-plugin-static-simple-etag.patch ]; + patches = [ + (fetchpatch { + url = "https://security.metacpan.org/patches/C/Catalyst-Plugin-Static-Simple/0.38/CVE-2026-15743-r1.patch"; + hash = "sha256-dNJOz7X7i03kisrf+lhqAaL6lYeTlt1NJZnJWNM7bgQ="; + }) + ../development/perl-modules/catalyst-plugin-static-simple-etag.patch + ]; + postPatch = "rm -f lib/Catalyst/Plugin/Static/Simple.pm.orig"; propagatedBuildInputs = [ CatalystRuntime MIMETypes From baa8915bed76d98a9ee4c8aaf19819d7471f98c4 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Mon, 14 Sep 2026 23:12:45 +0000 Subject: [PATCH 099/110] perlPackages.HTMLFormFu: fix CVE-2026-19873 Assisted-by: Codex (GPT-6) (cherry picked from commit c2c93af85319583946edd86b77dcae616c2a2bca) --- pkgs/top-level/perl-packages.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index cf165c7b161a..3c8a22d1f34e 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -16296,6 +16296,12 @@ with self; url = "mirror://cpan/authors/id/C/CF/CFRANKS/HTML-FormFu-2.07.tar.gz"; hash = "sha256-Ty8Bf3qHVPu26RIGyI7RPHVqFOO+oXgYjDuXdGNm6zI="; }; + patches = [ + (fetchpatch { + url = "https://security.metacpan.org/patches/H/HTML-FormFu/2.08/CVE-2026-19873-r1.patch"; + hash = "sha256-1QquxDl/NuNJe6MFbeEH49hYA8agXXeWm1Q23fOM+Nc="; + }) + ]; buildInputs = [ CGI FileShareDirInstall From 90f960fa33b8a76c8fd3724a93153b0160161edb Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Mon, 14 Sep 2026 23:15:48 +0000 Subject: [PATCH 100/110] perlPackages.CryptURandomMonkeyPatch: init at 0.1.4 Assisted-by: Codex (GPT-6) (cherry picked from commit da210312f7c8df3b1bd0ffe121fde2900abcf392) --- pkgs/top-level/perl-packages.nix | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 3c8a22d1f34e..8cec4266417d 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -7562,6 +7562,21 @@ with self; }; }; + CryptURandomMonkeyPatch = buildPerlPackage { + pname = "Crypt-URandom-MonkeyPatch"; + version = "0.1.4"; + src = fetchurl { + url = "mirror://cpan/authors/id/R/RR/RRWO/Crypt-URandom-MonkeyPatch-v0.1.4.tar.gz"; + hash = "sha256-eydufcxL7TnZW/+dnTemlTkycVaPTarMrFBowLQcKsk="; + }; + buildInputs = [ TestOutput ]; + propagatedBuildInputs = [ CryptURandom ]; + meta = { + description = "Override core rand function to use system random sources"; + license = lib.licenses.artistic2; + }; + }; + CryptScryptKDF = buildPerlModule { pname = "Crypt-ScryptKDF"; version = "0.011"; From 13e02ee4638dec752b752dc9af45566b81907036 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Mon, 14 Sep 2026 23:17:28 +0000 Subject: [PATCH 101/110] perlPackages.GDSecurityImage: fix CVE-2026-13082 Assisted-by: Codex (GPT-6) (cherry picked from commit ab5e75490032e8eb4d943f69ae90fbf5f35d4c27) --- pkgs/top-level/perl-packages.nix | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 8cec4266417d..2a2e4fa3cb30 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -14911,7 +14911,16 @@ with self; url = "mirror://cpan/authors/id/B/BU/BURAK/GD-SecurityImage-1.75.tar.gz"; hash = "sha256-Pd4k2ay6lRzd5bVp0eQsrZRs/bUSgORGnzNv1f4MjqY="; }; - propagatedBuildInputs = [ GD ]; + patches = [ + (fetchpatch { + url = "https://security.metacpan.org/patches/G/GD-SecurityImage/1.75/CVE-2026-13082-r1.patch"; + hash = "sha256-xIMPQD2JYuHdsYnW1ojqG3xgV7VWEKyJ6sEqNRUdNdQ="; + }) + ]; + propagatedBuildInputs = [ + CryptURandomMonkeyPatch + GD + ]; meta = { description = "Security image (captcha) generator"; license = with lib.licenses; [ From 80044e238072a0e70387d1c5b5be0504ca0d6ba2 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Tue, 15 Sep 2026 01:15:08 +0000 Subject: [PATCH 102/110] perlPackages.Imager: 1.034 -> 1.035 Fixes CVE-2026-73639. Drops two CVE-2026-73638 patches included in 1.035. Assisted-by: Codex (GPT-6) (cherry picked from commit 3629b02a8aa90b24c7b918d6188ccaafb7ba8b21) --- pkgs/top-level/perl-packages.nix | 19 ++----------------- 1 file changed, 2 insertions(+), 17 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 2a2e4fa3cb30..536ab009195e 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -17387,26 +17387,11 @@ with self; Imager = buildPerlPackage rec { pname = "Imager"; - version = "1.034"; + version = "1.035"; src = fetchurl { url = "mirror://cpan/authors/id/T/TO/TONYC/Imager-${version}.tar.gz"; - hash = "sha256-hrWizXGna4QJJJFSGl1WI4Qo8sN1AYMsmVxaMxJg+AM="; + hash = "sha256-W6BYrMmLtb+QK6/XTNKwepS7GVrmYWxEC1RwFIBv6xc="; }; - # Remove when updating to the first release containing both fixes. - patches = [ - (fetchpatch2 { - name = "fix-32-bit-exif-ifd-offset-checks.patch"; - url = "https://github.com/tonycoz/imager/commit/48ba8ac0749f89466b6e6681fb88cbdb51086ebd.patch?full_index=1"; - includes = [ "imexif.c" ]; - hash = "sha256-rpUeTsgSkCdzJsy3Ny0rU+KNL6xkSosfkDqzFb813Wo="; - }) - (fetchpatch2 { - name = "fix-32-bit-exif-limit-checks.patch"; - url = "https://github.com/tonycoz/imager/commit/6f1fd003a8e48c7e6e58b7019a04cc71bbfec2c3.patch?full_index=1"; - includes = [ "imexif.c" ]; - hash = "sha256-Ct7T/JHuxAIAjjuzoUhdAPlp0qPYKRQQqejsrcGXPko="; - }) - ]; buildInputs = [ pkgs.freetype pkgs.fontconfig From 2b068ab681292de93e00a47b184f87b08cb60726 Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Thu, 28 May 2026 21:32:04 +0100 Subject: [PATCH 103/110] libavif: 1.4.1 -> 1.4.2 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit (Additional cherry-pick notes) This change ends-up being required since the update to `libaom` causes a test in `libavif` to now fail. Upstream, which is the same upstream for both, “fixed” it in v1.4.2 - https://github.com/AOMediaCodec/libavif/commit/74bd32ef873024213b37f19a94f30d7b155f2514 Changes: https://github.com/AOMediaCodec/libavif/releases/tag/v1.4.2 (cherry picked from commit aa0e627f6e00f52ca5ca10cf48f71f73fb2f49a9) --- pkgs/by-name/li/libavif/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libavif/package.nix b/pkgs/by-name/li/libavif/package.nix index c778d78d66a7..8ec16503feee 100644 --- a/pkgs/by-name/li/libavif/package.nix +++ b/pkgs/by-name/li/libavif/package.nix @@ -31,7 +31,7 @@ in stdenv.mkDerivation (finalAttrs: { pname = "libavif"; - version = "1.4.1"; + version = "1.4.2"; outputs = [ "out" @@ -42,7 +42,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "AOMediaCodec"; repo = "libavif"; rev = "v${finalAttrs.version}"; - hash = "sha256-035SoxHfN121mp3LGwGykReCi1WJbl2/nZH8c/VwABU="; + hash = "sha256-AMQ1TRPGpuBBW7tJ8xuLEVTAeOsLWTHuE0dFJjI7+W4="; }; postPatch = '' From 0fc120861401f9d4fa21de5a435be6960645d93e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Sep 2026 18:00:07 +0000 Subject: [PATCH 104/110] pcre2: 10.48 -> 10.49 (cherry picked from commit 5df01aab7548b01cea51855deff775ff5134da3e) --- pkgs/by-name/pc/pcre2/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pc/pcre2/package.nix b/pkgs/by-name/pc/pcre2/package.nix index d828285dfa9b..ee476090840f 100644 --- a/pkgs/by-name/pc/pcre2/package.nix +++ b/pkgs/by-name/pc/pcre2/package.nix @@ -10,11 +10,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "pcre2"; - version = "10.48"; + version = "10.49"; src = fetchurl { url = "https://github.com/PCRE2Project/pcre2/releases/download/pcre2-${finalAttrs.version}/pcre2-${finalAttrs.version}.tar.bz2"; - hash = "sha256-tsaP3286wxOItQqon/D8ScAMmHwW57UUZJHRIAPyyO0="; + hash = "sha256-U8FW4bpBaiDajmU5XaoTLaDYDnaRBCTKyj/Nrngx04Q="; }; nativeBuildInputs = [ updateAutotoolsGnuConfigScriptsHook ]; From 75f0ba7a0333ebde59a983a3e598c23cf265c417 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Fri, 11 Sep 2026 14:03:46 +0200 Subject: [PATCH 105/110] python3Packages.gitpython: 3.1.58 -> 3.1.62 Diff: https://github.com/gitpython-developers/GitPython/compare/3.1.58...3.1.62 Changelog: https://github.com/gitpython-developers/GitPython/blob/3.1.62/doc/source/changes.rst (cherry picked from commit 753ec2f3b69645c77ee45d2a2d074504351eacc9) --- pkgs/development/python-modules/gitpython/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/gitpython/default.nix b/pkgs/development/python-modules/gitpython/default.nix index 2b5b14a297b5..6af9bc013850 100644 --- a/pkgs/development/python-modules/gitpython/default.nix +++ b/pkgs/development/python-modules/gitpython/default.nix @@ -10,14 +10,14 @@ buildPythonPackage (finalAttrs: { pname = "gitpython"; - version = "3.1.58"; + version = "3.1.62"; pyproject = true; src = fetchFromGitHub { owner = "gitpython-developers"; repo = "GitPython"; tag = finalAttrs.version; - hash = "sha256-C6hrN7SRWngwkD/NYvsoEVQUagdurkxzWbnn42EJOHE="; + hash = "sha256-g7qZSFFWAa7iJSn+HAxCTfNZfrYZsZRJGUIZGYQjoUI="; }; postPatch = '' From 5b7eba2431a7793b43c99a488d3778826fd23b25 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Sep 2026 21:44:15 +0000 Subject: [PATCH 106/110] imagemagick: 7.1.2-31 -> 7.1.2-32 (cherry picked from commit ab6ffe5aa36dc9c58e37853decd2da6a3682e88d) --- pkgs/by-name/im/imagemagick/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/im/imagemagick/package.nix b/pkgs/by-name/im/imagemagick/package.nix index 9add255e855d..7df382f27ad7 100644 --- a/pkgs/by-name/im/imagemagick/package.nix +++ b/pkgs/by-name/im/imagemagick/package.nix @@ -88,13 +88,13 @@ in stdenv.mkDerivation (finalAttrs: { pname = "imagemagick"; - version = "7.1.2-31"; + version = "7.1.2-32"; src = fetchFromGitHub { owner = "ImageMagick"; repo = "ImageMagick"; tag = finalAttrs.version; - hash = "sha256-RQpvpWSEMIIGIDLk5X9BwsWgD0AKPBgJ2m9dSipq8Lc="; + hash = "sha256-/8U47oVkzU6VeYec6ZND+wAAJonsmwlcgeBvQ+M7hk8="; }; outputs = [ From 98e5764a7a723c5976f92ca8aea73790457c7954 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Mon, 28 Sep 2026 08:09:14 +0200 Subject: [PATCH 107/110] thrift: disable tests on darwin for now https://hydra.nixos.org/build/346751725/step/6/log (cherry picked from commit 9d087851f0da050221d90ad3fe86c3c4efd2b502) I have no better way forward so far, I'm afraid. --- pkgs/by-name/th/thrift/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/th/thrift/package.nix b/pkgs/by-name/th/thrift/package.nix index 187720580203..75cfb84a482d 100644 --- a/pkgs/by-name/th/thrift/package.nix +++ b/pkgs/by-name/th/thrift/package.nix @@ -103,7 +103,7 @@ stdenv.mkDerivation (finalAttrs: { "StressTestNonBlocking" ]; - doCheck = !static; + doCheck = !static && !stdenv.hostPlatform.isDarwin; # FIXME darwin? enableParallelChecking = false; From 6a215dec0d617115f69736933bc15c99fa1f11a3 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sun, 9 Aug 2026 02:51:18 +0000 Subject: [PATCH 108/110] perl: 5.42.0 -> 5.42.3 5.42.3 ships the interpreter fixes and the updated dual-life modules, so the CVE-2026-8376 patch and every vendoredPerlDistributions entry are dropped. perl-cross 1.6.4 has no patch set for 5.42.3, so the perl5-5.42.0 set, which applies unchanged, is vendored under the name perl-cross expects. - perl: CVE-2026-13221, CVE-2026-57432, CVE-2026-8376 https://metacpan.org/release/SHAY/perl-5.42.3/view/pod/perldelta.pod - HTTP-Tiny 0.096: CVE-2026-7010, CVE-2026-7017 https://metacpan.org/release/HAARG/HTTP-Tiny-0.096/changes - Socket 2.041: CVE-2026-12087 https://metacpan.org/release/PEVANS/Socket-2.041/changes - Storable 3.37_01: CVE-2026-57433 - Archive-Tar 3.12, Compress-Raw-Bzip2 2.218, Compress-Raw-Zlib 2.222, IO-Compress 2.223 Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit 7b1e682245c0c05aae0541b1697b472c7f74d578) --- .../interpreters/perl/CVE-2026-8376.patch | 20 ----- .../development/interpreters/perl/default.nix | 4 +- .../interpreters/perl/interpreter.nix | 47 +--------- .../perl/perl-cross-1.6.4--5.42.3.patch | 86 +++++++++++++++++++ 4 files changed, 91 insertions(+), 66 deletions(-) delete mode 100644 pkgs/development/interpreters/perl/CVE-2026-8376.patch create mode 100644 pkgs/development/interpreters/perl/perl-cross-1.6.4--5.42.3.patch diff --git a/pkgs/development/interpreters/perl/CVE-2026-8376.patch b/pkgs/development/interpreters/perl/CVE-2026-8376.patch deleted file mode 100644 index c8ad72298178..000000000000 --- a/pkgs/development/interpreters/perl/CVE-2026-8376.patch +++ /dev/null @@ -1,20 +0,0 @@ -Targeted patch for CVE-2026-8376, based on 5e7f119eb2bb1181be908701f22bf7068e722f1c but avoids changes to t/re/pat_psycho.t as they do not apply cleanly. - -diff --git a/regcomp_study.c b/regcomp_study.c -index b513454a4258..1602663f4b26 100644 ---- a/regcomp_study.c -+++ b/regcomp_study.c -@@ -2784,6 +2784,13 @@ Perl_study_chunk(pTHX_ - (U8 *) SvEND(data->last_found)) - - (U8*)s; - l -= old; -+ -+ if (l > 0 && -+ (mincount >= SSize_t_MAX / (SSize_t)l -+ || old > SSize_t_MAX - mincount * (SSize_t)l)) { -+ FAIL("Regexp out of space"); -+ } -+ - /* Get the added string: */ - last_str = newSVpvn_utf8(s + old, l, UTF); - last_chrs = UTF ? utf8_length((U8*)(s + old), diff --git a/pkgs/development/interpreters/perl/default.nix b/pkgs/development/interpreters/perl/default.nix index cab0ea1a2268..6cc6f5755ac4 100644 --- a/pkgs/development/interpreters/perl/default.nix +++ b/pkgs/development/interpreters/perl/default.nix @@ -73,8 +73,8 @@ in rec { perl5 = callPackage ./interpreter.nix { self = perl5; - version = "5.42.0"; - sha256 = "sha256-4JPvGE1/mhuXl+JGUpb1VRCtttq4hCsMPtUzKWYwltw="; + version = "5.42.3"; + sha256 = "sha256-ETd0CYWDe1zfFfDPq5Miedy0NS+RL+1vwUTotPCCNic="; inherit passthruFun; }; } diff --git a/pkgs/development/interpreters/perl/interpreter.nix b/pkgs/development/interpreters/perl/interpreter.nix index cdb03912b517..4b308c156f02 100644 --- a/pkgs/development/interpreters/perl/interpreter.nix +++ b/pkgs/development/interpreters/perl/interpreter.nix @@ -36,8 +36,6 @@ let commonPatches = [ # Do not look in /usr etc. for dependencies. ./no-sys-dirs.patch - - ./CVE-2026-8376.patch ] # Fix build on Solaris on x86_64 @@ -83,48 +81,7 @@ let # Inject fixed CPAN releases for bundled dual-life distributions until the # next perl maintenance release includes them. - vendoredPerlDistributions = [ - { - # CVE-2026-7010 - path = "cpan/HTTP-Tiny"; - src = fetchurl { - url = "mirror://cpan/authors/id/H/HA/HAARG/HTTP-Tiny-0.094.tar.gz"; - hash = "sha256-poQemfwbVdFd6VlHzL17dnvsxRxxAhl/qPBE333cB0M="; - }; - } - { - # CVE-2026-3381, CVE-2026-4176 - path = "cpan/Compress-Raw-Zlib"; - src = fetchurl { - url = "mirror://cpan/authors/id/P/PM/PMQS/Compress-Raw-Zlib-2.222.tar.gz"; - hash = "sha256-Hf19URplVifIGBXTDTurwo+luIRV/wP4sECZ3LUShrg="; - }; - } - { - # Runtime dependency of IO-Compress 2.220. - path = "cpan/Compress-Raw-Bzip2"; - src = fetchurl { - url = "mirror://cpan/authors/id/P/PM/PMQS/Compress-Raw-Bzip2-2.218.tar.gz"; - hash = "sha256-iRU+ai69pSNJSTsHT6S3VJ/x+QU952E8GKXgXFtBX6g="; - }; - } - { - # CVE-2026-48962, CVE-2026-48961, CVE-2026-48959 - path = "cpan/IO-Compress"; - src = fetchurl { - url = "mirror://cpan/authors/id/P/PM/PMQS/IO-Compress-2.220.tar.gz"; - hash = "sha256-nZbqKR8sVO82fHOWuFfZO6GsHEsvG84T7Yo+Xz7rtic="; - }; - } - { - # CVE-2026-42496, CVE-2026-42497, CVE-2026-9538 - path = "cpan/Archive-Tar"; - src = fetchurl { - url = "mirror://cpan/authors/id/B/BI/BINGOS/Archive-Tar-3.12.tar.gz"; - hash = "sha256-ARTvObZfSfiWgoOrR3Gdfoj5jXNg/jZJvjMcf1PVgyw="; - }; - } - ]; + vendoredPerlDistributions = [ ]; replaceVendoredPerlDistributions = lib.concatMapStringsSep "\n" (d: '' rm -rf ${d.path} @@ -440,6 +397,8 @@ stdenv.mkDerivation ( # fixes build failure due to missing d_fdopendir/HAS_FDOPENDIR configure option # https://github.com/arsv/perl-cross/pull/159 ./cross-fdopendir.patch + + ./perl-cross-1.6.4--5.42.3.patch ]; depsBuildBuild = [ diff --git a/pkgs/development/interpreters/perl/perl-cross-1.6.4--5.42.3.patch b/pkgs/development/interpreters/perl/perl-cross-1.6.4--5.42.3.patch new file mode 100644 index 000000000000..853fb8a667a2 --- /dev/null +++ b/pkgs/development/interpreters/perl/perl-cross-1.6.4--5.42.3.patch @@ -0,0 +1,86 @@ +perl-cross 1.6.4 ships no patch set for perl 5.42.3. The perl5-5.42.0 set +applies unchanged, so link it under the name perl-cross looks for. The +links are per-file because `find cnf/diffs/perl5-$version`, which +perl-cross uses to collect them, does not descend into a symlinked +directory. + +diff --git a/cnf/diffs/perl5-5.42.3/constant.patch b/cnf/diffs/perl5-5.42.3/constant.patch +new file mode 120000 +index 0000000..61f792a +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/constant.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/constant.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/dynaloader.patch b/cnf/diffs/perl5-5.42.3/dynaloader.patch +new file mode 120000 +index 0000000..543415e +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/dynaloader.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/dynaloader.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/findext.patch b/cnf/diffs/perl5-5.42.3/findext.patch +new file mode 120000 +index 0000000..94ed668 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/findext.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/findext.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/installscripts.patch b/cnf/diffs/perl5-5.42.3/installscripts.patch +new file mode 120000 +index 0000000..6f715b4 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/installscripts.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/installscripts.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/liblist.patch b/cnf/diffs/perl5-5.42.3/liblist.patch +new file mode 120000 +index 0000000..5037380 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/liblist.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/liblist.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/makemaker.patch b/cnf/diffs/perl5-5.42.3/makemaker.patch +new file mode 120000 +index 0000000..cf9fc6c +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/makemaker.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/makemaker.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/posix-makefile.patch b/cnf/diffs/perl5-5.42.3/posix-makefile.patch +new file mode 120000 +index 0000000..072ba89 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/posix-makefile.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/posix-makefile.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/test-checkcase.patch b/cnf/diffs/perl5-5.42.3/test-checkcase.patch +new file mode 120000 +index 0000000..6ecc9bc +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/test-checkcase.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/test-checkcase.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/test-makemaker.patch b/cnf/diffs/perl5-5.42.3/test-makemaker.patch +new file mode 120000 +index 0000000..fc6bcda +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/test-makemaker.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/test-makemaker.patch +\ No newline at end of file +diff --git a/cnf/diffs/perl5-5.42.3/xconfig.patch b/cnf/diffs/perl5-5.42.3/xconfig.patch +new file mode 120000 +index 0000000..87ac501 +--- /dev/null ++++ b/cnf/diffs/perl5-5.42.3/xconfig.patch +@@ -0,0 +1 @@ ++../perl5-5.42.0/xconfig.patch +\ No newline at end of file From 49e4c945fa5ddfdc0b4ceb730cc8349ee7a0c7e7 Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sun, 9 Aug 2026 18:59:53 +0000 Subject: [PATCH 109/110] perl: fix CVE-2026-15534 Apply upstream commits 568e6fd238867bb9e99fa3f47cba3169009239e0 and 54cf3d44cbbedd17d774e9a37921963e8fd5d0cb. Assisted-by: Claude Code (Claude Opus 5) Signed-off-by: Stig Palmquist (cherry picked from commit 709e8699ab3e17bfdaf02e11cf0e8e2996491360) --- .../interpreters/perl/CVE-2026-15534-1.patch | 39 ++++++++++++ .../interpreters/perl/CVE-2026-15534-2.patch | 59 +++++++++++++++++++ .../interpreters/perl/interpreter.nix | 3 + 3 files changed, 101 insertions(+) create mode 100644 pkgs/development/interpreters/perl/CVE-2026-15534-1.patch create mode 100644 pkgs/development/interpreters/perl/CVE-2026-15534-2.patch diff --git a/pkgs/development/interpreters/perl/CVE-2026-15534-1.patch b/pkgs/development/interpreters/perl/CVE-2026-15534-1.patch new file mode 100644 index 000000000000..fc8ee2f29ea9 --- /dev/null +++ b/pkgs/development/interpreters/perl/CVE-2026-15534-1.patch @@ -0,0 +1,39 @@ +CVE-2026-15534, upstream commit +568e6fd238867bb9e99fa3f47cba3169009239e0. + +diff --git a/regexec.c b/regexec.c +index 35a727459c4a..29aa73c13cb9 100644 +--- a/regexec.c ++++ b/regexec.c +@@ -9211,7 +9211,8 @@ NULL + reginfo->poscache_iter = reginfo->poscache_maxiter; + } + +- if (reginfo->poscache_iter-- == 0) { ++ if (reginfo->poscache_iter == 1) { ++ reginfo->poscache_iter--; + /* initialise cache */ + const SSize_t size = (reginfo->poscache_maxiter + 7)/8; + regmatch_info_aux *const aux = reginfo->info_aux; +@@ -9232,11 +9233,10 @@ NULL + ); + } + +- if (reginfo->poscache_iter < 0) { ++ if (reginfo->poscache_iter == 0) { + /* have we already failed at this position? */ + SSize_t offset, mask; + +- reginfo->poscache_iter = -1; /* stop eventual underflow */ + offset = (FLAGS(scan) & 0xf) - 1 + + (locinput - reginfo->strbeg) + * (FLAGS(scan)>>4); +@@ -9252,6 +9252,8 @@ NULL + ST.cache_offset = offset; + ST.cache_mask = mask; + } ++ else ++ reginfo->poscache_iter--; + } + + /* Prefer B over A for minimal matching. */ diff --git a/pkgs/development/interpreters/perl/CVE-2026-15534-2.patch b/pkgs/development/interpreters/perl/CVE-2026-15534-2.patch new file mode 100644 index 000000000000..b5d0ff5ed3d0 --- /dev/null +++ b/pkgs/development/interpreters/perl/CVE-2026-15534-2.patch @@ -0,0 +1,59 @@ +CVE-2026-15534, upstream commit +54cf3d44cbbedd17d774e9a37921963e8fd5d0cb. + +diff --git a/regexec.c b/regexec.c +index 29aa73c13cb9..66e0c0924059 100644 +--- a/regexec.c ++++ b/regexec.c +@@ -9202,22 +9202,27 @@ NULL + if (!reginfo->poscache_maxiter) { + /* start the countdown: Postpone detection until we + * know the match is not *that* much linear. */ +- reginfo->poscache_maxiter +- = (reginfo->strend - reginfo->strbeg + 1) +- * (FLAGS(scan)>>4); +- /* possible overflow for long strings and many CURLYX's */ +- if (reginfo->poscache_maxiter < 0) +- reginfo->poscache_maxiter = I32_MAX; +- reginfo->poscache_iter = reginfo->poscache_maxiter; ++ STRLEN len = reginfo->strend - reginfo->strbeg; ++ /* number of participating WHILEMs */ ++ U8 n = (FLAGS(scan)>>4); ++ ++ /* Only do the calculations and enable the cache if it ++ * won't overflow. This test is equivalent to: ++ * ((len + 1) * n + 7) <= max(STRLEN) ++ */ ++ if (len < ((~(STRLEN)0) - 7)/n) { ++ reginfo->poscache_maxiter = (len + 1) * n; ++ reginfo->poscache_iter = reginfo->poscache_maxiter; ++ } + } + + if (reginfo->poscache_iter == 1) { + reginfo->poscache_iter--; + /* initialise cache */ +- const SSize_t size = (reginfo->poscache_maxiter + 7)/8; ++ const STRLEN size = (reginfo->poscache_maxiter + 7)/8; + regmatch_info_aux *const aux = reginfo->info_aux; + if (aux->poscache) { +- if ((SSize_t)reginfo->poscache_size < size) { ++ if (reginfo->poscache_size < size) { + Renew(aux->poscache, size, char); + reginfo->poscache_size = size; + } +diff --git a/regexp.h b/regexp.h +index 057d9ac5011b..d5d40e0a5618 100644 +--- a/regexp.h ++++ b/regexp.h +@@ -839,8 +839,8 @@ typedef struct { + char *cutpoint; /* (*COMMIT) position (if any) */ + regmatch_info_aux *info_aux; /* extra fields that need cleanup */ + regmatch_info_aux_eval *info_aux_eval; /* extra saved state for (?{}) */ +- I32 poscache_maxiter; /* how many whilems todo before S-L cache kicks in */ +- I32 poscache_iter; /* current countdown from _maxiter to zero */ ++ STRLEN poscache_maxiter; /* how many whilems todo before S-L cache kicks in */ ++ STRLEN poscache_iter; /* current countdown from _maxiter to zero */ + STRLEN poscache_size; /* size of regmatch_info_aux.poscache */ + bool intuit; /* re_intuit_start() is the top-level caller */ + bool is_utf8_pat; /* regex is utf8 */ diff --git a/pkgs/development/interpreters/perl/interpreter.nix b/pkgs/development/interpreters/perl/interpreter.nix index 4b308c156f02..ae75db2ead90 100644 --- a/pkgs/development/interpreters/perl/interpreter.nix +++ b/pkgs/development/interpreters/perl/interpreter.nix @@ -36,6 +36,9 @@ let commonPatches = [ # Do not look in /usr etc. for dependencies. ./no-sys-dirs.patch + + ./CVE-2026-15534-1.patch + ./CVE-2026-15534-2.patch ] # Fix build on Solaris on x86_64 From 3d8fc7e7e759e7fb52a632591ac985a7ed694fe2 Mon Sep 17 00:00:00 2001 From: Alexis Hildebrandt Date: Tue, 29 Sep 2026 11:33:39 +0200 Subject: [PATCH 110/110] groff: 1.24.1 -> 1.24.2 (cherry picked from commit 2c88b1a65180fec77da4bbcd3067a3cbf9a53aca) --- pkgs/by-name/gr/groff/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gr/groff/package.nix b/pkgs/by-name/gr/groff/package.nix index 083b1493dcf6..5f9658967baf 100644 --- a/pkgs/by-name/gr/groff/package.nix +++ b/pkgs/by-name/gr/groff/package.nix @@ -41,11 +41,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "groff"; - version = "1.24.1"; + version = "1.24.2"; src = fetchurl { url = "mirror://gnu/groff/groff-${finalAttrs.version}.tar.gz"; - hash = "sha256-dOKBl5W2r/QxrqyYPWOpyJaO6roqLrp9+LpMe0Hnz9g="; + hash = "sha256-+cHv1b6743/G4QY9t0c86N8ePgvk/w9DzgT85X6cXdk="; }; patches = [