git: 1dc191dd5837 - stable/15 - contrib/expat: import expat 2.8.5

From: Philip Paeps <philip_at_FreeBSD.org>
Date: Sat, 26 Sep 2026 00:40:44 UTC
The branch stable/15 has been updated by philip:

URL: https://cgit.FreeBSD.org/src/commit/?id=1dc191dd5837cac9514128e5ee4b250ba44180c5

commit 1dc191dd5837cac9514128e5ee4b250ba44180c5
Author:     Philip Paeps <philip@FreeBSD.org>
AuthorDate: 2026-09-23 04:27:57 +0000
Commit:     Philip Paeps <philip@FreeBSD.org>
CommitDate: 2026-09-26 00:31:39 +0000

    contrib/expat: import expat 2.8.5
    
    Changes: https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/Changes
    
    Security:       CVE-2026-93990
    
    (cherry picked from commit c7b67985633c408cae69703ca443cbfd84d326a8)
---
 contrib/expat/Changes                       |  87 ++++++-
 contrib/expat/Makefile.am                   |   7 -
 contrib/expat/Makefile.in                   | 153 ++++++++----
 contrib/expat/README.md                     |   2 +-
 contrib/expat/configure.ac                  |  18 +-
 contrib/expat/doc/Makefile.in               |  12 +-
 contrib/expat/doc/reference.html            |  32 ++-
 contrib/expat/doc/xmlwf.1                   |   2 +-
 contrib/expat/doc/xmlwf.xml                 |   2 +-
 contrib/expat/examples/Makefile.in          |  27 ++-
 contrib/expat/fuzz/xml_lpm_fuzzer.cpp       |   5 +-
 contrib/expat/fuzz/xml_parse_fuzzer.c       |  14 +-
 contrib/expat/fuzz/xml_parsebuffer_fuzzer.c |  13 +-
 contrib/expat/lib/Makefile.am               |   1 +
 contrib/expat/lib/Makefile.in               |  28 ++-
 contrib/expat/lib/expat.h                   |   8 +-
 contrib/expat/lib/expat_external.h          |  12 +
 contrib/expat/lib/hash_table.h              |  78 ++++++
 contrib/expat/lib/internal.h                | 169 ++++++-------
 contrib/expat/lib/xmlparse.c                | 225 ++++++++----------
 contrib/expat/lib/xmlrole.c                 | 113 +++++----
 contrib/expat/lib/xmlrole.h                 |  14 +-
 contrib/expat/lib/xmltok.c                  | 203 +++++++++++-----
 contrib/expat/lib/xmltok.h                  |  58 ++---
 contrib/expat/lib/xmltok_impl.c             |  63 +++--
 contrib/expat/lib/xmltok_ns.c               |   6 +-
 contrib/expat/tests/Makefile.am             |   8 +-
 contrib/expat/tests/Makefile.in             |  52 ++--
 contrib/expat/tests/acc_tests.h             |  12 +-
 contrib/expat/tests/alloc_tests.h           |  12 +-
 contrib/expat/tests/basic_tests.c           | 354 +++++++++++++++++++++++++++-
 contrib/expat/tests/basic_tests.h           |  12 +-
 contrib/expat/tests/benchmark/Makefile.in   |  27 ++-
 contrib/expat/tests/chardata.h              |  10 +-
 contrib/expat/tests/common.h                |  88 ++++---
 contrib/expat/tests/dummy.h                 |  50 ++--
 contrib/expat/tests/handlers.h              |  43 ++--
 contrib/expat/tests/hash_tests.c            | 157 ++++++++++++
 contrib/expat/tests/hash_tests.h            |  41 ++++
 contrib/expat/tests/memcheck.c              |   3 +-
 contrib/expat/tests/memcheck.h              |  12 +-
 contrib/expat/tests/minicheck.h             |  76 +++---
 contrib/expat/tests/misc_tests.c            |   2 +-
 contrib/expat/tests/misc_tests.h            |  12 +-
 contrib/expat/tests/ns_tests.h              |  12 +-
 contrib/expat/tests/nsalloc_tests.c         |   2 +
 contrib/expat/tests/nsalloc_tests.h         |  12 +-
 contrib/expat/tests/runtests.c              |   4 +-
 contrib/expat/tests/structdata.h            |   9 +-
 contrib/expat/tests/xmltest.sh              |   2 +
 contrib/expat/xmlwf/Makefile.in             |  27 ++-
 contrib/expat/xmlwf/unixfilemap.c           |   4 +-
 contrib/expat/xmlwf/xmlfile.c               |   6 +-
 contrib/expat/xmlwf/xmlfile.h               |   8 +-
 contrib/expat/xmlwf/xmlmime.h               |  10 +-
 contrib/expat/xmlwf/xmlwf.c                 |  25 +-
 contrib/expat/xmlwf/xmlwf_helpgen.py        |   7 +-
 contrib/expat/xmlwf/xmlwf_helpgen.sh        |   8 +-
 lib/libexpat/expat_config.h                 |   6 +-
 lib/libexpat/libbsdxml.3                    |   4 +-
 60 files changed, 1612 insertions(+), 857 deletions(-)

diff --git a/contrib/expat/Changes b/contrib/expat/Changes
index af91a67dd5ce..bf94e9db5616 100644
--- a/contrib/expat/Changes
+++ b/contrib/expat/Changes
@@ -13,9 +13,94 @@
 !! will be funded by the City of Munich as part of their                     !!
 !! Open Source Sabbatical (https://opensource.muenchen.de/sabbatical.html)   !!
 !! — thank you!                                                              !!
-!!                                   Sebastian Pipping -- Berlin, 2026-08-03 !!
+!!                                                                           !!
+!! If your business relies on Expat beyond January 2027, please consider     !!
+!! funding the maintenance of Expat to ensure its health and security for    !!
+!! you and others. Thank you!                                                !!
+!!                                                                           !!
+!!                                   Sebastian Pipping -- Berlin, 2026-09-22 !!
 !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
 
+Release 2.8.5 Tue September 22 2026
+        Security fixes:
+           #1282  CVE-2026-93990 -- Reject high surrogates not followed by a
+                    low surrogate during UTF-16 decoding; previously, malformed
+                    UTF-16 could be smuggled into the application using Expat
+                    and could cause arbitrary damage there, depending on how
+                    malformed UTF-16 was handled inside the application;
+                    validation was not their job but Expat's. This is similar
+                    to past vulnerability CVE-2022-25235.
+                    Upstream CVSS 3.1 vector:
+                    AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (CVSS score: 9.8)
+
+///////////////////////////////////////////////////////////////////////////////
+// The next release will drop two (disabled-by-default) features:            //
+//                                                                           //
+// - ATTR_INFO (-DXML_ATTR_INFO, -DEXPAT_ATTR_INFO, --enable-xml-attr-info,  //
+//              function XML_GetAttributeInfo, struct XML_AttrInfo)          //
+// - MIN_SIZE (-DXML_MIN_SIZE, -DEXPAT_MIN_SIZE)                             //
+//                                                                           //
+// If you need them in 2026 and beyond, please share your scenario at        //
+// GitHub issues #1370 (for ATTR_INFO) and/or #1379 (for MIN_SIZE). Thanks!  //
+///////////////////////////////////////////////////////////////////////////////
+
+        Bug fixes:
+           #1346  lib: Fix OOM-related memory leak on a failed overflow check
+           #1371  lib: Fix memory alignment for architectures with 128bit
+                    pointers like CHERI-RISC-V
+           #1367  xmlwf: Handle errors when closing output files
+
+        Other changes:
+           #1354  lib: Reject an XML declaration version other than `1.[0-9]+`
+                    (which is less strict than XML 1.0r4 (fourth edition)
+                    and matches XML 1.0r5 (fifth edition))
+           #1362  lib: Make Clang, GCC and MSVC warn about use of function
+                    XML_SetHashSalt that is deprecated since Expat 2.8.0
+           #1357  lib: Drop internal macros FASTCALL, PTRCALL, PTRFASTCALL
+           #1367  xmlwf: Document that with `-k` the last error determines the
+                    xmlwf exit code in `--help` output
+           #1367  xmlwf: Make exit code 3 documentation match exit code 2 more
+                    closely in `--help` output
+     #1352 #1353  CMake|Windows: Refrain from adding `/source-charset:utf-8`
+                    for MSVC
+     #1366 #1374  Autotools: Be explicit about the minimum required version of
+                    GNU Automake, currently version 1.13 of 2012-12-28
+           #1351  Autotools|macOS: Sync CMake templates with CMake 4.4.3
+           #1349  Replace some internal use of XML_Bool with standard bool
+           #1364  tests: Propagate xmltest.sh failures via exit status
+           #1360  tests|xmlwf: Add `#include "expat_config.h"` where missing
+           #1355  tests: Start covering hash table operation
+     #1350 #1369  tests: Drop __cplusplus leftovers
+           #1378  tests: Fix tail pointer when unlinking the last tracked
+                    allocation
+           #1376  docs: Emphasize that XML_StopParser is not immediate
+           #1381  docs: Sync XML_FeatureEnum value list in doc/reference.html
+     #1356 #1361  Version info bumped from 13:4:12 (libexpat*.so.1.12.4)
+                    to 13:5:12 (libexpat*.so.1.12.5); see https://verbump.de/
+                    for what these numbers do
+
+        Infrastructure:
+           #1347  Add missing .gitignore entries
+           #1360  CI: Detect missing `#include "expat_config.h"`
+           #1368  CI: Bump MinGW Clang from 23.0.1 to 23.1.1
+           #1377  CI: Bump Fil-C from 0.684 to 0.685
+           #1380  CI: Bump Cppcheck from 2.21.0 to 2.22.0
+           #1372  CI: Extract helper script `apply-htmltidy.sh`
+     #1366 #1374  Autotools: Start to also produce .tar.bz3 release tarballs
+
+        Special thanks to:
+            Afonso Januário
+            Braian Plaku
+            Florian Schmaus
+            Huang Wenbin
+            Kamila Szewczyk
+            Kartik Kenchi
+            Leo Camus
+            Matthew Fernandez
+            Stan Ulbrych
+                 and
+            City of Munich Open Source Sabbatical
+
 Release 2.8.4 Mon August 31 2026
         Security fixes:
      #1321 #1331  CVE-2026-66046, CVE-2026-76641 -- Fix quadratic runtime from
diff --git a/contrib/expat/Makefile.am b/contrib/expat/Makefile.am
index 09b88f315165..fbc03d85f474 100644
--- a/contrib/expat/Makefile.am
+++ b/contrib/expat/Makefile.am
@@ -33,13 +33,6 @@
 # OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE
 # USE OR OTHER DEALINGS IN THE SOFTWARE.
 
-AUTOMAKE_OPTIONS = \
-    dist-bzip2 \
-    dist-lzip \
-    dist-xz \
-    foreign \
-    subdir-objects
-
 ACLOCAL_AMFLAGS = -I m4
 LIBTOOLFLAGS = --verbose
 
diff --git a/contrib/expat/Makefile.in b/contrib/expat/Makefile.in
index 0f9a441aa882..c0a0eefc47ac 100644
--- a/contrib/expat/Makefile.in
+++ b/contrib/expat/Makefile.in
@@ -1,7 +1,7 @@
-# Makefile.in generated by automake 1.18.1 from Makefile.am.
+# Makefile.in generated by automake 1.19 from Makefile.am.
 # @configure_input@
 
-# Copyright (C) 1994-2025 Free Software Foundation, Inc.
+# Copyright (C) 1994-2026 Free Software Foundation, Inc.
 
 # This Makefile.in is free software; the Free Software Foundation
 # gives unlimited permission to copy and/or distribute it,
@@ -261,7 +261,13 @@ am__remove_distdir = \
       ; rm -rf "$(distdir)" \
       || { sleep 5 && rm -rf "$(distdir)"; }; \
   else :; fi
-am__post_remove_distdir = $(am__remove_distdir)
+am__post_remove_distdir = \
+  $(am__is_gnu_make) || rm -f am__distdir.tar; \
+  $(am__remove_distdir)
+am__ensure_distdir_tar = \
+  test -f am__distdir.tar || $(MAKE) $(AM_MAKEFLAGS) am__distdir.tar
+am__dist_compress_failed = \
+  am__rc=$$?; rm -f $$am__archive am__distdir.tar; exit $$am__rc
 am__relativize = \
   dir0=`pwd`; \
   sed_first='s,^\([^/]*\)/.*$$,\1,'; \
@@ -287,10 +293,13 @@ am__relativize = \
     dir1=`echo "$$dir1" | sed -e "$$sed_rest"`; \
   done; \
   reldir="$$dir2"
-DIST_ARCHIVES = $(distdir).tar.gz $(distdir).tar.bz2 $(distdir).tar.lz \
-	$(distdir).tar.xz
+# Exists only to be overridden by the user if desired.
+AM_DIST_TAR_IGNORE_STDERR = $(am__tar_ignore_stderr)
+DIST_ARCHIVES = $(distdir).tar.gz $(distdir).tar.bz2 \
+	$(distdir).tar.bz3 $(distdir).tar.lz $(distdir).tar.xz
 GZIP_ENV = -9
-DIST_TARGETS = dist-lzip dist-xz dist-bzip2 dist-gzip
+DIST_TARGETS = am--dist-lzip am--dist-xz am--dist-bzip2 am--dist-bzip3 \
+	am--dist-gzip
 # Exists only to be overridden by the user if desired.
 AM_DISTCHECK_DVI_TARGET = dvi
 distuninstallcheck_listfiles = find . -type f -print
@@ -411,6 +420,7 @@ am__leading_dot = @am__leading_dot@
 am__quote = @am__quote@
 am__rm_f_notfound = @am__rm_f_notfound@
 am__tar = @am__tar@
+am__tar_ignore_stderr = @am__tar_ignore_stderr@
 am__untar = @am__untar@
 am__xargs_n = @am__xargs_n@
 bindir = @bindir@
@@ -454,13 +464,6 @@ target_alias = @target_alias@
 top_build_prefix = @top_build_prefix@
 top_builddir = @top_builddir@
 top_srcdir = @top_srcdir@
-AUTOMAKE_OPTIONS = \
-    dist-bzip2 \
-    dist-lzip \
-    dist-xz \
-    foreign \
-    subdir-objects
-
 ACLOCAL_AMFLAGS = -I m4
 LIBTOOLFLAGS = --verbose
 SUBDIRS = lib $(am__append_1) $(am__append_2) $(am__append_3)
@@ -748,13 +751,14 @@ distdir-am: $(DISTFILES)
 	$(AM_V_at)$(MKDIR_P) "$(distdir)"
 	@srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
 	topsrcdirstrip=`echo "$(top_srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
+	am__distdir="$(distdir)"; \
 	list='$(DISTFILES)'; \
 	  dist_files=`for file in $$list; do echo $$file; done | \
 	  sed -e "s|^$$srcdirstrip/||;t" \
 	      -e "s|^$$topsrcdirstrip/|$(top_builddir)/|;t"`; \
 	case $$dist_files in \
 	  */*) $(MKDIR_P) `echo "$$dist_files" | \
-			   sed '/\//!d;s|^|$(distdir)/|;s,/[^/]*$$,,' | \
+			   sed "/\//!d;s|^|$$am__distdir/|;s,/[^/]*$$,," | \
 			   sort -u` ;; \
 	esac; \
 	for file in $$dist_files; do \
@@ -807,55 +811,96 @@ distdir-am: $(DISTFILES)
 	  ! -type d ! -perm -400 -exec chmod a+r {} \; -o \
 	  ! -type d ! -perm -444 -exec $(install_sh) -c -m a+r {} {} \; \
 	|| chmod -R a+r "$(distdir)"
-dist-gzip: distdir
-	tardir=$(distdir) && $(am__tar) | eval GZIP= gzip $(GZIP_ENV) -c >$(distdir).tar.gz
+
+am__distdir.tar: distdir
+	am__distdir="$(distdir)"; \
+	am__tar_msg=`tardir=$$am__distdir && $(am__tar) 2>&1 >am__distdir.tar`; \
+	am__tar_rc=$$?; \
+	test -z "$$am__tar_msg" || { printf '%s\n' "$$am__tar_msg" >&2; \
+	  test x"$(AM_DIST_TAR_IGNORE_STDERR)" = xyes || am__tar_rc=1; }; \
+	test $$am__tar_rc -eq 0 || { rm -f am__distdir.tar; \
+	  echo "$(distdir).tar: cannot create the distribution archive" >&2; exit 1; }
+
+.INTERMEDIATE: am__distdir.tar
+dist-gzip: am--dist-gzip
 	$(am__post_remove_distdir)
-dist-bzip2: distdir
-	tardir=$(distdir) && $(am__tar) | BZIP2=$${BZIP2--9} bzip2 -c >$(distdir).tar.bz2
+am--dist-gzip: am__distdir.tar
+	@$(am__ensure_distdir_tar)
+	am__archive=$(distdir).tar.gz; \
+	eval GZIP= gzip $(GZIP_ENV) -c <am__distdir.tar >$$am__archive \
+	  || { $(am__dist_compress_failed); }
+dist-bzip2: am--dist-bzip2
 	$(am__post_remove_distdir)
-
-dist-bzip3: distdir
-	tardir=$(distdir) && $(am__tar) | bzip3 -c >$(distdir).tar.bz3
+am--dist-bzip2: am__distdir.tar
+	@$(am__ensure_distdir_tar)
+	am__archive=$(distdir).tar.bz2; \
+	BZIP2=$${BZIP2--9} bzip2 -c <am__distdir.tar >$$am__archive \
+	  || { $(am__dist_compress_failed); }
+dist-bzip3: am--dist-bzip3
 	$(am__post_remove_distdir)
-dist-lzip: distdir
-	tardir=$(distdir) && $(am__tar) | lzip -c $${LZIP_OPT--9} >$(distdir).tar.lz
+am--dist-bzip3: am__distdir.tar
+	@$(am__ensure_distdir_tar)
+	am__archive=$(distdir).tar.bz3; \
+	bzip3 -c <am__distdir.tar >$$am__archive \
+	  || { $(am__dist_compress_failed); }
+dist-lzip: am--dist-lzip
 	$(am__post_remove_distdir)
-dist-xz: distdir
-	tardir=$(distdir) && $(am__tar) | XZ_OPT=$${XZ_OPT--e} xz -c >$(distdir).tar.xz
+am--dist-lzip: am__distdir.tar
+	@$(am__ensure_distdir_tar)
+	am__archive=$(distdir).tar.lz; \
+	lzip -c $${LZIP_OPT--9} <am__distdir.tar >$$am__archive \
+	  || { $(am__dist_compress_failed); }
+dist-xz: am--dist-xz
 	$(am__post_remove_distdir)
+am--dist-xz: am__distdir.tar
+	@$(am__ensure_distdir_tar)
+	am__archive=$(distdir).tar.xz; \
+	XZ_OPT=$${XZ_OPT--e} xz -c <am__distdir.tar >$$am__archive \
+	  || { $(am__dist_compress_failed); }
 
-dist-zstd: distdir
-	tardir=$(distdir) && $(am__tar) | zstd -c $${ZSTD_CLEVEL-$${ZSTD_OPT--19}} >$(distdir).tar.zst
+dist-zstd: am--dist-zstd
 	$(am__post_remove_distdir)
+am--dist-zstd: am__distdir.tar
+	@$(am__ensure_distdir_tar)
+	am__archive=$(distdir).tar.zst; \
+	zstd -c $${ZSTD_CLEVEL-$${ZSTD_OPT--19}} <am__distdir.tar >$$am__archive \
+	  || { $(am__dist_compress_failed); }
 
-dist-tarZ: distdir
+dist-tarZ: am--dist-tarZ
+	$(am__post_remove_distdir)
+am--dist-tarZ: am__distdir.tar
+	@$(am__ensure_distdir_tar)
 	@echo WARNING: "Support for distribution archives compressed with" \
 		       "legacy program 'compress' is deprecated." >&2
 	@echo WARNING: "It will be removed altogether in Automake 2.0" >&2
-	tardir=$(distdir) && $(am__tar) | compress -c >$(distdir).tar.Z
-	$(am__post_remove_distdir)
+	am__archive=$(distdir).tar.Z; \
+	compress -c <am__distdir.tar >$$am__archive \
+	  || { $(am__dist_compress_failed); }
 
-dist-shar: distdir
+dist-shar: am--dist-shar
+	$(am__post_remove_distdir)
+am--dist-shar: distdir
 	@echo WARNING: "Support for shar distribution archives is" \
 	               "deprecated." >&2
 	@echo WARNING: "It will be removed altogether in Automake 2.0" >&2
-	shar $(distdir) | eval GZIP= gzip $(GZIP_ENV) -c >$(distdir).shar.gz
-	$(am__post_remove_distdir)
+	shar $(distdir) >$(distdir).shar || { rm -f $(distdir).shar; exit 1; }
+	eval GZIP= gzip $(GZIP_ENV) -f $(distdir).shar
 
-dist-zip: distdir
+dist-zip: am--dist-zip
+	$(am__post_remove_distdir)
+am--dist-zip: distdir
 	-rm -f $(distdir).zip
 	zip -rq $(distdir).zip $(distdir)
-	$(am__post_remove_distdir)
 
 dist dist-all:
-	$(MAKE) $(AM_MAKEFLAGS) $(DIST_TARGETS) am__post_remove_distdir='@:'
+	$(MAKE) $(AM_MAKEFLAGS) $(DIST_TARGETS)
 	$(am__post_remove_distdir)
 
 # This target untars the dist file and tries a VPATH configuration.  Then
 # it guarantees that the distribution is self-contained by making another
 # tarfile.
 distcheck: dist
-	case '$(DIST_ARCHIVES)' in \
+	case "$(DIST_ARCHIVES)" in \
 	*.tar.gz*) \
 	  eval GZIP= gzip -dc $(distdir).tar.gz | $(am__untar) ;;\
 	*.tar.bz2*) \
@@ -879,11 +924,13 @@ distcheck: dist
 	chmod u+w $(distdir)
 	mkdir $(distdir)/_build $(distdir)/_build/sub $(distdir)/_inst
 	chmod a-w $(distdir)
-	test -d $(distdir)/_build || exit 0; \
-	dc_install_base=`$(am__cd) $(distdir)/_inst && pwd | sed -e 's,^[^:\\/]:[\\/],/,'` \
+	am__distdir="$(distdir)"; \
+	am__distarchives="$(DIST_ARCHIVES)"; \
+	test -d "$$am__distdir/_build" || exit 0; \
+	dc_install_base=`$(am__cd) "$$am__distdir/_inst" && pwd | sed -e 's,^[^:\\/]:[\\/],/,'` \
 	  && dc_destdir="$${TMPDIR-/tmp}/am-dc-$$$$/" \
 	  && am__cwd=`pwd` \
-	  && $(am__cd) $(distdir)/_build/sub \
+	  && $(am__cd) "$$am__distdir/_build/sub" \
 	  && ../../configure \
 	    $(AM_DISTCHECK_CONFIGURE_FLAGS) \
 	    $(DISTCHECK_CONFIGURE_FLAGS) \
@@ -906,13 +953,13 @@ distcheck: dist
 	      } || { rm -rf "$$dc_destdir"; exit 1; }) \
 	  && rm -rf "$$dc_destdir" \
 	  && $(MAKE) $(AM_MAKEFLAGS) dist \
-	  && rm -rf $(DIST_ARCHIVES) \
+	  && rm -rf $$am__distarchives \
 	  && $(MAKE) $(AM_MAKEFLAGS) distcleancheck \
 	  && cd "$$am__cwd" \
 	  || exit 1
 	$(am__post_remove_distdir)
 	@(echo "$(distdir) archives ready for distribution: "; \
-	  list='$(DIST_ARCHIVES)'; for i in $$list; do echo $$i; done) | \
+	  list="$(DIST_ARCHIVES)"; for i in $$list; do echo $$i; done) | \
 	  sed -e 1h -e 1s/./=/g -e 1p -e 1x -e '$$p' -e '$$x'
 distuninstallcheck:
 	@test -n '$(distuninstallcheck_dir)' || { \
@@ -1051,16 +1098,18 @@ uninstall-am: uninstall-nodist_cmakeDATA uninstall-pkgconfigDATA
 .MAKE: $(am__recursive_targets) all install-am install-strip
 
 .PHONY: $(am__recursive_targets) CTAGS GTAGS TAGS all all-am \
-	am--refresh check check-am clean clean-cscope clean-generic \
-	clean-libtool cscope cscopelist-am ctags ctags-am dist \
-	dist-all dist-bzip2 dist-bzip3 dist-gzip dist-lzip dist-shar \
-	dist-tarZ dist-xz dist-zip dist-zstd distcheck distclean \
-	distclean-generic distclean-hdr distclean-libtool \
-	distclean-tags distcleancheck distdir distuninstallcheck dvi \
-	dvi-am html html-am info info-am install install-am \
-	install-data install-data-am install-dvi install-dvi-am \
-	install-exec install-exec-am install-html install-html-am \
-	install-info install-info-am install-man \
+	am--dist-bzip2 am--dist-bzip3 am--dist-gzip am--dist-lzip \
+	am--dist-shar am--dist-tarZ am--dist-xz am--dist-zip \
+	am--dist-zstd am--refresh check check-am clean clean-cscope \
+	clean-generic clean-libtool cscope cscopelist-am ctags \
+	ctags-am dist dist-all dist-bzip2 dist-bzip3 dist-gzip \
+	dist-lzip dist-shar dist-tarZ dist-xz dist-zip dist-zstd \
+	distcheck distclean distclean-generic distclean-hdr \
+	distclean-libtool distclean-tags distcleancheck distdir \
+	distuninstallcheck dvi dvi-am html html-am info info-am \
+	install install-am install-data install-data-am install-dvi \
+	install-dvi-am install-exec install-exec-am install-html \
+	install-html-am install-info install-info-am install-man \
 	install-nodist_cmakeDATA install-pdf install-pdf-am \
 	install-pkgconfigDATA install-ps install-ps-am install-strip \
 	installcheck installcheck-am installdirs installdirs-am \
diff --git a/contrib/expat/README.md b/contrib/expat/README.md
index ae43ed3cc663..36e46a90fd23 100644
--- a/contrib/expat/README.md
+++ b/contrib/expat/README.md
@@ -17,7 +17,7 @@
 > Thank you! :heart: :pray:
 
 
-# Expat, Release 2.8.4
+# Expat, Release 2.8.5
 
 This is Expat, a C99 library for parsing
 [XML 1.0 Fourth Edition](https://www.w3.org/TR/2006/REC-xml-20060816/), started by
diff --git a/contrib/expat/configure.ac b/contrib/expat/configure.ac
index be6b8b289197..e8562dbc5fc1 100644
--- a/contrib/expat/configure.ac
+++ b/contrib/expat/configure.ac
@@ -74,7 +74,21 @@ AC_CONFIG_SRCDIR([Makefile.in])
 AC_CONFIG_AUX_DIR([conftools])
 AC_CONFIG_MACRO_DIR([m4])
 AC_CANONICAL_HOST
-AM_INIT_AUTOMAKE
+
+dnl NOTE: Macro `AM_OPTIONAL_AUTOMAKE` is available with Automake >=1.19
+dnl       and serves as a proxy for robust Automake >=1.19 detection here.
+dnl       `dist-bzip3` was introduced with Automake 1.18 already but there
+dnl       is no robust way of checking precisely for Automake >=1.18.
+dnl       Automake >=1.13 is needed for (1) our use of LOG_DRIVER and
+dnl       (2) making it work without asking for parallel tests, explicitly.
+m4_ifdef([AM_OPTIONAL_AUTOMAKE], [
+  AM_INIT_AUTOMAKE([1.19 dist-bzip2 dist-bzip3 dist-lzip dist-xz foreign subdir-objects])
+
+  dnl NOTE: Without this dummy call in the file the `m4_ifdef` above never hits true.
+  AM_OPTIONAL_AUTOMAKE([])
+], [
+  AM_INIT_AUTOMAKE([1.13 dist-bzip2            dist-lzip dist-xz foreign subdir-objects])
+])
 AM_MAINTAINER_MODE([enable])  # to allow argument --disable-maintainer-mode
 
 
@@ -90,7 +104,7 @@ dnl If the API changes incompatibly set LIBAGE back to 0
 dnl
 
 LIBCURRENT=13  # sync
-LIBREVISION=4  # with
+LIBREVISION=5  # with
 LIBAGE=12      # CMakeLists.txt!
 
 AC_CONFIG_HEADERS([expat_config.h])
diff --git a/contrib/expat/doc/Makefile.in b/contrib/expat/doc/Makefile.in
index 0bda758420f0..52a18ffb673f 100644
--- a/contrib/expat/doc/Makefile.in
+++ b/contrib/expat/doc/Makefile.in
@@ -1,7 +1,7 @@
-# Makefile.in generated by automake 1.18.1 from Makefile.am.
+# Makefile.in generated by automake 1.19 from Makefile.am.
 # @configure_input@
 
-# Copyright (C) 1994-2025 Free Software Foundation, Inc.
+# Copyright (C) 1994-2026 Free Software Foundation, Inc.
 
 # This Makefile.in is free software; the Free Software Foundation
 # gives unlimited permission to copy and/or distribute it,
@@ -309,6 +309,7 @@ am__leading_dot = @am__leading_dot@
 am__quote = @am__quote@
 am__rm_f_notfound = @am__rm_f_notfound@
 am__tar = @am__tar@
+am__tar_ignore_stderr = @am__tar_ignore_stderr@
 am__untar = @am__untar@
 am__xargs_n = @am__xargs_n@
 bindir = @bindir@
@@ -372,9 +373,9 @@ $(srcdir)/Makefile.in: @MAINTAINER_MODE_TRUE@ $(srcdir)/Makefile.am  $(am__confi
 	      exit 1;; \
 	  esac; \
 	done; \
-	echo ' cd $(top_srcdir) && $(AUTOMAKE) --gnu doc/Makefile'; \
+	echo ' cd $(top_srcdir) && $(AUTOMAKE) --foreign doc/Makefile'; \
 	$(am__cd) $(top_srcdir) && \
-	  $(AUTOMAKE) --gnu doc/Makefile
+	  $(AUTOMAKE) --foreign doc/Makefile
 Makefile: $(srcdir)/Makefile.in $(top_builddir)/config.status
 	@case '$?' in \
 	  *config.status*) \
@@ -455,13 +456,14 @@ distdir: $(BUILT_SOURCES)
 distdir-am: $(DISTFILES)
 	@srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
 	topsrcdirstrip=`echo "$(top_srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
+	am__distdir="$(distdir)"; \
 	list='$(DISTFILES)'; \
 	  dist_files=`for file in $$list; do echo $$file; done | \
 	  sed -e "s|^$$srcdirstrip/||;t" \
 	      -e "s|^$$topsrcdirstrip/|$(top_builddir)/|;t"`; \
 	case $$dist_files in \
 	  */*) $(MKDIR_P) `echo "$$dist_files" | \
-			   sed '/\//!d;s|^|$(distdir)/|;s,/[^/]*$$,,' | \
+			   sed "/\//!d;s|^|$$am__distdir/|;s,/[^/]*$$,," | \
 			   sort -u` ;; \
 	esac; \
 	for file in $$dist_files; do \
diff --git a/contrib/expat/doc/reference.html b/contrib/expat/doc/reference.html
index e54c7be2965a..5bd9150ea78a 100644
--- a/contrib/expat/doc/reference.html
+++ b/contrib/expat/doc/reference.html
@@ -53,7 +53,7 @@
   <body>
     <div>
       <h1>
-        The Expat XML Parser <small>Release 2.8.4</small>
+        The Expat XML Parser <small>Release 2.8.5</small>
       </h1>
     </div>
 
@@ -1763,12 +1763,16 @@ XML_StopParser(XML_Parser p,
 </pre>
       <div class="fcndef">
         <p>
-          Stops parsing, causing <code><a href="#XML_Parse">XML_Parse</a></code> or
-          <code><a href="#XML_ParseBuffer">XML_ParseBuffer</a></code> to return. Must be
-          called from within a call-back handler, except when aborting (when
-          <code>resumable</code> is <code>XML_FALSE</code>) an already suspended parser.
-          Some call-backs may still follow because they would otherwise get lost,
-          including
+          Stops parsing as soon as possible, causing <code><a href=
+          "#XML_Parse">XML_Parse</a></code> or <code><a href=
+          "#XML_ParseBuffer">XML_ParseBuffer</a></code> to return. Must be called from
+          within a call-back handler, except when aborting (when <code>resumable</code>
+          is <code>XML_FALSE</code>) an already suspended parser.
+        </p>
+
+        <p>
+          <strong>Note:</strong> Some call-backs may still follow because they would
+          otherwise get lost, including
         </p>
 
         <ul>
@@ -3709,8 +3713,20 @@ enum XML_FeatureEnum {
   XML_FEATURE_MIN_SIZE,
   XML_FEATURE_SIZEOF_XML_CHAR,
   XML_FEATURE_SIZEOF_XML_LCHAR,
+  /* Added in Expat 2.0.0. */
   XML_FEATURE_NS,
-  XML_FEATURE_LARGE_SIZE
+  /* Added in Expat 2.0.1. */
+  XML_FEATURE_LARGE_SIZE,
+  /* Added in Expat 2.1.0. */
+  XML_FEATURE_ATTR_INFO,
+  /* Added in Expat 2.4.0. */
+  XML_FEATURE_BILLION_LAUGHS_ATTACK_PROTECTION_MAXIMUM_AMPLIFICATION_DEFAULT,
+  XML_FEATURE_BILLION_LAUGHS_ATTACK_PROTECTION_ACTIVATION_THRESHOLD_DEFAULT,
+  /* Added in Expat 2.6.0. */
+  XML_FEATURE_GE,
+  /* Added in Expat 2.7.2. */
+  XML_FEATURE_ALLOC_TRACKER_MAXIMUM_AMPLIFICATION_DEFAULT,
+  XML_FEATURE_ALLOC_TRACKER_ACTIVATION_THRESHOLD_DEFAULT,
 };
 
 typedef struct {
diff --git a/contrib/expat/doc/xmlwf.1 b/contrib/expat/doc/xmlwf.1
index 7177cbf19c49..e9b6a2fe4610 100644
--- a/contrib/expat/doc/xmlwf.1
+++ b/contrib/expat/doc/xmlwf.1
@@ -5,7 +5,7 @@
 \\$2 \(la\\$1\(ra\\$3
 ..
 .if \n(.g .mso www.tmac
-.TH XMLWF 1 "August 31, 2026" "" ""
+.TH XMLWF 1 "September 22, 2026" "" ""
 .SH NAME
 xmlwf \- Determines if an XML document is well-formed
 .SH SYNOPSIS
diff --git a/contrib/expat/doc/xmlwf.xml b/contrib/expat/doc/xmlwf.xml
index 93a67c407563..e7a2664b7e42 100644
--- a/contrib/expat/doc/xmlwf.xml
+++ b/contrib/expat/doc/xmlwf.xml
@@ -21,7 +21,7 @@
           "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd" [
   <!ENTITY dhfirstname "<firstname>Scott</firstname>">
   <!ENTITY dhsurname   "<surname>Bronson</surname>">
-  <!ENTITY dhdate      "<date>August 31, 2026</date>">
+  <!ENTITY dhdate      "<date>September 22, 2026</date>">
   <!-- Please adjust this^^ date whenever cutting a new release. -->
   <!ENTITY dhsection   "<manvolnum>1</manvolnum>">
   <!ENTITY dhemail     "<email>bronson@rinspin.com</email>">
diff --git a/contrib/expat/examples/Makefile.in b/contrib/expat/examples/Makefile.in
index 56a6f69c07b7..4ef878f7867c 100644
--- a/contrib/expat/examples/Makefile.in
+++ b/contrib/expat/examples/Makefile.in
@@ -1,7 +1,7 @@
-# Makefile.in generated by automake 1.18.1 from Makefile.am.
+# Makefile.in generated by automake 1.19 from Makefile.am.
 # @configure_input@
 
-# Copyright (C) 1994-2025 Free Software Foundation, Inc.
+# Copyright (C) 1994-2026 Free Software Foundation, Inc.
 
 # This Makefile.in is free software; the Free Software Foundation
 # gives unlimited permission to copy and/or distribute it,
@@ -337,6 +337,7 @@ am__leading_dot = @am__leading_dot@
 am__quote = @am__quote@
 am__rm_f_notfound = @am__rm_f_notfound@
 am__tar = @am__tar@
+am__tar_ignore_stderr = @am__tar_ignore_stderr@
 am__untar = @am__untar@
 am__xargs_n = @am__xargs_n@
 bindir = @bindir@
@@ -399,9 +400,9 @@ $(srcdir)/Makefile.in: @MAINTAINER_MODE_TRUE@ $(srcdir)/Makefile.am  $(am__confi
 	      exit 1;; \
 	  esac; \
 	done; \
-	echo ' cd $(top_srcdir) && $(AUTOMAKE) --gnu examples/Makefile'; \
+	echo ' cd $(top_srcdir) && $(AUTOMAKE) --foreign examples/Makefile'; \
 	$(am__cd) $(top_srcdir) && \
-	  $(AUTOMAKE) --gnu examples/Makefile
+	  $(AUTOMAKE) --foreign examples/Makefile
 Makefile: $(srcdir)/Makefile.in $(top_builddir)/config.status
 	@case '$?' in \
 	  *config.status*) \
@@ -453,22 +454,25 @@ $(am__depfiles_remade):
 am--depfiles: $(am__depfiles_remade)
 
 .c.o:
-@am__fastdepCC_TRUE@	$(AM_V_CC)$(COMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ $<
-@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Po
+@am__fastdepCC_TRUE@	$(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.o$$||'`;\
+@am__fastdepCC_TRUE@	$(COMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ $< &&\
+@am__fastdepCC_TRUE@	$(am__mv) $$depbase.Tpo $$depbase.Po
 @AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='$<' object='$@' libtool=no @AMDEPBACKSLASH@
 @AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
 @am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(COMPILE) -c -o $@ $<
 
 .c.obj:
-@am__fastdepCC_TRUE@	$(AM_V_CC)$(COMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ `$(CYGPATH_W) '$<'`
-@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Po
+@am__fastdepCC_TRUE@	$(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.obj$$||'`;\
+@am__fastdepCC_TRUE@	$(COMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ `$(CYGPATH_W) '$<'` &&\
+@am__fastdepCC_TRUE@	$(am__mv) $$depbase.Tpo $$depbase.Po
 @AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='$<' object='$@' libtool=no @AMDEPBACKSLASH@
 @AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
 @am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(COMPILE) -c -o $@ `$(CYGPATH_W) '$<'`
 
 .c.lo:
-@am__fastdepCC_TRUE@	$(AM_V_CC)$(LTCOMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ $<
-@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Plo
+@am__fastdepCC_TRUE@	$(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.lo$$||'`;\
+@am__fastdepCC_TRUE@	$(LTCOMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ $< &&\
+@am__fastdepCC_TRUE@	$(am__mv) $$depbase.Tpo $$depbase.Plo
 @AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='$<' object='$@' libtool=yes @AMDEPBACKSLASH@
 @AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
 @am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(LTCOMPILE) -c -o $@ $<
@@ -537,13 +541,14 @@ distdir: $(BUILT_SOURCES)
 distdir-am: $(DISTFILES)
 	@srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
 	topsrcdirstrip=`echo "$(top_srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
+	am__distdir="$(distdir)"; \
 	list='$(DISTFILES)'; \
 	  dist_files=`for file in $$list; do echo $$file; done | \
 	  sed -e "s|^$$srcdirstrip/||;t" \
 	      -e "s|^$$topsrcdirstrip/|$(top_builddir)/|;t"`; \
 	case $$dist_files in \
 	  */*) $(MKDIR_P) `echo "$$dist_files" | \
-			   sed '/\//!d;s|^|$(distdir)/|;s,/[^/]*$$,,' | \
+			   sed "/\//!d;s|^|$$am__distdir/|;s,/[^/]*$$,," | \
 			   sort -u` ;; \
 	esac; \
 	for file in $$dist_files; do \
diff --git a/contrib/expat/fuzz/xml_lpm_fuzzer.cpp b/contrib/expat/fuzz/xml_lpm_fuzzer.cpp
index 719629a6b547..190b34f74d98 100644
--- a/contrib/expat/fuzz/xml_lpm_fuzzer.cpp
+++ b/contrib/expat/fuzz/xml_lpm_fuzzer.cpp
@@ -8,6 +8,7 @@
 
    Copyright (c) 2022 Mark Brand <markbrand@google.com>
    Copyright (c) 2025 Sebastian Pipping <sebastian@pipping.org>
+   Copyright (c) 2026 Braian Plaku <braianplaku@gmail.com>
    Licensed under the MIT license:
 
    Permission is  hereby granted,  free of charge,  to any  person obtaining
@@ -383,7 +384,9 @@ UnknownEncodingHandler(void *encodingHandlerData, const XML_Char *name,
 void
 InitializeParser(XML_Parser parser) {
   XML_SetUserData(parser, (void *)parser);
-  XML_SetHashSalt(parser, 0x41414141);
+  const uint8_t entropy[16] = {0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41,
+                               0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41};
+  XML_SetHashSalt16Bytes(parser, entropy);
   XML_SetParamEntityParsing(parser, XML_PARAM_ENTITY_PARSING_ALWAYS);
 
   XML_SetElementDeclHandler(parser, ElementDeclHandler);
diff --git a/contrib/expat/fuzz/xml_parse_fuzzer.c b/contrib/expat/fuzz/xml_parse_fuzzer.c
index 29ab33ff79d9..1eb0ad299628 100644
--- a/contrib/expat/fuzz/xml_parse_fuzzer.c
+++ b/contrib/expat/fuzz/xml_parse_fuzzer.c
@@ -17,6 +17,7 @@
 #include <assert.h>
 #include <limits.h> // for INT_MAX
 #include <stdint.h>
+#include <string.h>
 
 #include "expat.h"
 #include "siphash.h"
@@ -34,7 +35,8 @@
 #endif
 
 // 16-byte deterministic hash key.
-static unsigned char hash_key[16] = "FUZZING IS FUN!";
+static unsigned char hash_key_1[16] = "FUZZING IS FUN?";
+static unsigned char hash_key_2[16] = "FUZZING IS FUN!";
 
 static void XMLCALL
 start(void *userData, const XML_Char *name, const XML_Char **atts) {
@@ -59,8 +61,14 @@ may_stop_character_handler(void *userData, const XML_Char *s, int len) {
 static void
 ParseOneInput(XML_Parser p, const uint8_t *data, size_t size) {
   // Set the hash salt using siphash to generate a deterministic hash.
-  struct sipkey *key = sip_keyof(hash_key);
-  XML_SetHashSalt(p, (unsigned long)siphash24(data, size, key));
+  // The salt is 16 bytes and siphash24 produces 8, so the input is hashed
+  // under two keys.
+  const uint64_t first = siphash24(data, size, sip_keyof(hash_key_1));
+  const uint64_t second = siphash24(data, size, sip_keyof(hash_key_2));
+  uint8_t entropy[16];
+  memcpy(entropy, &first, sizeof(first));
+  memcpy(entropy + sizeof(first), &second, sizeof(second));
+  XML_SetHashSalt16Bytes(p, entropy);
   (void)sip24_valid;
 
   XML_SetUserData(p, p);
diff --git a/contrib/expat/fuzz/xml_parsebuffer_fuzzer.c b/contrib/expat/fuzz/xml_parsebuffer_fuzzer.c
index 38b9981b0b50..a854f6706396 100644
--- a/contrib/expat/fuzz/xml_parsebuffer_fuzzer.c
+++ b/contrib/expat/fuzz/xml_parsebuffer_fuzzer.c
@@ -35,7 +35,8 @@
 #endif
 
 // 16-byte deterministic hash key.
-static unsigned char hash_key[16] = "FUZZING IS FUN!";
+static unsigned char hash_key_1[16] = "FUZZING IS FUN?";
+static unsigned char hash_key_2[16] = "FUZZING IS FUN!";
 
 static void XMLCALL
 start(void *userData, const XML_Char *name, const XML_Char **atts) {
@@ -60,8 +61,14 @@ may_stop_character_handler(void *userData, const XML_Char *s, int len) {
 static void
 ParseOneInput(XML_Parser p, const uint8_t *data, size_t size) {
   // Set the hash salt using siphash to generate a deterministic hash.
-  struct sipkey *key = sip_keyof(hash_key);
-  XML_SetHashSalt(p, (unsigned long)siphash24(data, size, key));
+  // The salt is 16 bytes and siphash24 produces 8, so the input is hashed
+  // under two keys.
+  const uint64_t first = siphash24(data, size, sip_keyof(hash_key_1));
+  const uint64_t second = siphash24(data, size, sip_keyof(hash_key_2));
+  uint8_t entropy[16];
+  memcpy(entropy, &first, sizeof(first));
+  memcpy(entropy + sizeof(first), &second, sizeof(second));
+  XML_SetHashSalt16Bytes(p, entropy);
   (void)sip24_valid;
 
   XML_SetUserData(p, p);
diff --git a/contrib/expat/lib/Makefile.am b/contrib/expat/lib/Makefile.am
index 2b6aec2e6bdc..6b0d0af4e3c5 100644
--- a/contrib/expat/lib/Makefile.am
+++ b/contrib/expat/lib/Makefile.am
@@ -115,6 +115,7 @@ EXTRA_DIST = \
     expat_external.h \
     expat.h \
     fallthrough.h \
+    hash_table.h \
     iasciitab.h \
     internal.h \
     latin1tab.h \
diff --git a/contrib/expat/lib/Makefile.in b/contrib/expat/lib/Makefile.in
index 73db0e584705..58b19912b596 100644
--- a/contrib/expat/lib/Makefile.in
+++ b/contrib/expat/lib/Makefile.in
@@ -1,7 +1,7 @@
-# Makefile.in generated by automake 1.18.1 from Makefile.am.
+# Makefile.in generated by automake 1.19 from Makefile.am.
 # @configure_input@
 
-# Copyright (C) 1994-2025 Free Software Foundation, Inc.
+# Copyright (C) 1994-2026 Free Software Foundation, Inc.
 
 # This Makefile.in is free software; the Free Software Foundation
 # gives unlimited permission to copy and/or distribute it,
@@ -444,6 +444,7 @@ am__leading_dot = @am__leading_dot@
 am__quote = @am__quote@
 am__rm_f_notfound = @am__rm_f_notfound@
 am__tar = @am__tar@
+am__tar_ignore_stderr = @am__tar_ignore_stderr@
 am__untar = @am__untar@
 am__xargs_n = @am__xargs_n@
 bindir = @bindir@
@@ -511,6 +512,7 @@ EXTRA_DIST = \
     expat_external.h \
     expat.h \
     fallthrough.h \
+    hash_table.h \
     iasciitab.h \
     internal.h \
     latin1tab.h \
@@ -540,9 +542,9 @@ $(srcdir)/Makefile.in: @MAINTAINER_MODE_TRUE@ $(srcdir)/Makefile.am  $(am__confi
 	      exit 1;; \
 	  esac; \
 	done; \
-	echo ' cd $(top_srcdir) && $(AUTOMAKE) --gnu lib/Makefile'; \
+	echo ' cd $(top_srcdir) && $(AUTOMAKE) --foreign lib/Makefile'; \
 	$(am__cd) $(top_srcdir) && \
-	  $(AUTOMAKE) --gnu lib/Makefile
+	  $(AUTOMAKE) --foreign lib/Makefile
 Makefile: $(srcdir)/Makefile.in $(top_builddir)/config.status
 	@case '$?' in \
 	  *config.status*) \
@@ -643,22 +645,25 @@ $(am__depfiles_remade):
 am--depfiles: $(am__depfiles_remade)
 
 .c.o:
-@am__fastdepCC_TRUE@	$(AM_V_CC)$(COMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ $<
-@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Po
+@am__fastdepCC_TRUE@	$(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.o$$||'`;\
+@am__fastdepCC_TRUE@	$(COMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ $< &&\
+@am__fastdepCC_TRUE@	$(am__mv) $$depbase.Tpo $$depbase.Po
 @AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='$<' object='$@' libtool=no @AMDEPBACKSLASH@
 @AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
 @am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(COMPILE) -c -o $@ $<
 
 .c.obj:
-@am__fastdepCC_TRUE@	$(AM_V_CC)$(COMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ `$(CYGPATH_W) '$<'`
-@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Po
+@am__fastdepCC_TRUE@	$(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.obj$$||'`;\
+@am__fastdepCC_TRUE@	$(COMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ `$(CYGPATH_W) '$<'` &&\
+@am__fastdepCC_TRUE@	$(am__mv) $$depbase.Tpo $$depbase.Po
 @AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='$<' object='$@' libtool=no @AMDEPBACKSLASH@
 @AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
 @am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(COMPILE) -c -o $@ `$(CYGPATH_W) '$<'`
 
 .c.lo:
-@am__fastdepCC_TRUE@	$(AM_V_CC)$(LTCOMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ $<
-@am__fastdepCC_TRUE@	$(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Plo
+@am__fastdepCC_TRUE@	$(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.lo$$||'`;\
+@am__fastdepCC_TRUE@	$(LTCOMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ $< &&\
+@am__fastdepCC_TRUE@	$(am__mv) $$depbase.Tpo $$depbase.Plo
 @AMDEP_TRUE@@am__fastdepCC_FALSE@	$(AM_V_CC)source='$<' object='$@' libtool=yes @AMDEPBACKSLASH@
 @AMDEP_TRUE@@am__fastdepCC_FALSE@	DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@
 @am__fastdepCC_FALSE@	$(AM_V_CC@am__nodep@)$(LTCOMPILE) -c -o $@ $<
@@ -832,13 +837,14 @@ distdir: $(BUILT_SOURCES)
 distdir-am: $(DISTFILES)
 	@srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
 	topsrcdirstrip=`echo "$(top_srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \
+	am__distdir="$(distdir)"; \
 	list='$(DISTFILES)'; \
 	  dist_files=`for file in $$list; do echo $$file; done | \
 	  sed -e "s|^$$srcdirstrip/||;t" \
 	      -e "s|^$$topsrcdirstrip/|$(top_builddir)/|;t"`; \
 	case $$dist_files in \
 	  */*) $(MKDIR_P) `echo "$$dist_files" | \
-			   sed '/\//!d;s|^|$(distdir)/|;s,/[^/]*$$,,' | \
+			   sed "/\//!d;s|^|$$am__distdir/|;s,/[^/]*$$,," | \
 			   sort -u` ;; \
 	esac; \
 	for file in $$dist_files; do \
diff --git a/contrib/expat/lib/expat.h b/contrib/expat/lib/expat.h
index b296be9dbad2..4c3851d50a5f 100644
--- a/contrib/expat/lib/expat.h
+++ b/contrib/expat/lib/expat.h
@@ -20,6 +20,7 @@
    Copyright (c) 2023      Sony Corporation / Snild Dolkow <snild@sony.com>
    Copyright (c) 2024      Taichi Haradaguchi <20001722@ymail.ne.jp>
    Copyright (c) 2025      Matthew Fernandez <matthew.fernandez@gmail.com>
+   Copyright (c) 2026      Braian Plaku <braianplaku@gmail.com>
    Licensed under the MIT license:
 
    Permission is  hereby granted,  free of charge,  to any  person obtaining
@@ -921,7 +922,9 @@ XML_SetParamEntityParsing(XML_Parser parser,
    Returns 1 if successful, 0 when called after parsing has started.
    Note: If parser == NULL, the function will do nothing and return 0.
    DEPRECATED since Expat 2.8.0.
+   Please use XML_SetHashSalt16Bytes instead.
 */
+XML_ATTR_DEPRECATED("please use XML_SetHashSalt16Bytes instead")
 XMLPARSEAPI(int)
 XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt);
 
@@ -1040,8 +1043,11 @@ enum XML_FeatureEnum {
   XML_FEATURE_MIN_SIZE,
   XML_FEATURE_SIZEOF_XML_CHAR,
   XML_FEATURE_SIZEOF_XML_LCHAR,
+  /* Added in Expat 2.0.0. */
   XML_FEATURE_NS,
+  /* Added in Expat 2.0.1. */
   XML_FEATURE_LARGE_SIZE,
+  /* Added in Expat 2.1.0. */
   XML_FEATURE_ATTR_INFO,
   /* Added in Expat 2.4.0. */
   XML_FEATURE_BILLION_LAUGHS_ATTACK_PROTECTION_MAXIMUM_AMPLIFICATION_DEFAULT,
@@ -1096,7 +1102,7 @@ XML_SetReparseDeferralEnabled(XML_Parser parser, XML_Bool enabled);
 */
 #  define XML_MAJOR_VERSION 2
 #  define XML_MINOR_VERSION 8
-#  define XML_MICRO_VERSION 4
+#  define XML_MICRO_VERSION 5
 
 #  ifdef __cplusplus
 }
diff --git a/contrib/expat/lib/expat_external.h b/contrib/expat/lib/expat_external.h
index 4cd1f3a49c35..cf80f960d6e1 100644
--- a/contrib/expat/lib/expat_external.h
+++ b/contrib/expat/lib/expat_external.h
@@ -16,6 +16,7 @@
    Copyright (c) 2017      Rhodri James <rhodri@wildebeest.org.uk>
    Copyright (c) 2018      Yury Gribov <tetra2005@gmail.com>
    Copyright (c) 2026      Matthew Fernandez <matthew.fernandez@gmail.com>
+   Copyright (c) 2026      Braian Plaku <braianplaku@gmail.com>
    Licensed under the MIT license:
 
    Permission is  hereby granted,  free of charge,  to any  person obtaining
@@ -125,6 +126,17 @@
 #    define XML_ATTR_ALLOC_SIZE(x)
 #  endif
 
+/* Marks a function that Expat still provides but that callers should move off
+   of. */
+#  if defined(__clang__) || defined(__GNUC__)
+#    define XML_ATTR_DEPRECATED(message)                                       \
*** 4697 LINES SKIPPED ***