From nobody Sat Sep 26 00:40:44 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hs7z54kQ9z6sxdD for ; Sat, 26 Sep 2026 00:40:49 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hs7z53BJQz4Xph for ; Sat, 26 Sep 2026 00:40:49 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790383249; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=gdNXXy6o6NFX+Cs1DvlwKEues9pXF4tqwdx8IJeky2Q=; b=IXV/jS2uoWNGRYDBHZyCQkVB4hFJon7lLQChM7AsxmnBD1j4vwlLIE1B75Mt52L6owrRDP sTPA09vOtGcXgLL/qqfiBxSmmlp+t2JI7jqvBGZoP+yZDqyntS4lfmOIsyLOZZUF18tOZT 56IAA/KXHyEW4eYj3FPm810U9e/w1BSBXrAL5OnAvZ56Np+1tHGCFodpxh74gEzSTEWrSb qHjtEIzFMdIMLrojaU87kU895MdGgj7aJ/hLa7kqpC3l7qzi8U0UjxWEXu1m6tRhYb3Qiy YIxiBhMtWsOV4kwJtelx7nQsNQgj8Jas/ywR4sjqp5A0W5+OFqhKfme/wTVDeQ== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790383249; b=nrC9gDrqQo3qrsMhNsy1+ZGJodszPXM/dOjiOjEg60K5mD4XP1lF+zT+Lw1tM5vv9Nb41F yAXACzrlQts02LzhczzBesW4u3B06sprs/261uNnCLc5F+vpNYy2mHY4rX5lM+ZJbE0ENY QfrMngNAys8YljWyzhBeUIs21G3flKdkxagjIU+gu2kQBASCg2gQehNwGZ3hALRpfkskde uQf7Po8BPPJe7JlDjSbik7U2yTlqmRWZiprc9L1lfl6tTYcmuYPBSBZEDOCCNqYJTERvpf Z7g26d4GUDyZRhCUF8Ni2WN5DoWlMPJJZasT8ZUvU8sSV5oUFqrX1u4x3jzRLg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790383249; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=gdNXXy6o6NFX+Cs1DvlwKEues9pXF4tqwdx8IJeky2Q=; b=kLE7ruqZKf6ts8l+cfGg3ELdD6orx60IKy42f87hR4dVbbKcVvNG5Q/WGtlKIl4e2yzxf2 NZVfmlNna6HfnN832DFtvo+LuF0f5bHxMVKXGIrXJx9bVQfc8SntwzVVUoa+m8Tt4lLcD+ O2ICYR+TwDEpvygoHAAApElvLGuWJhElv1RpdTdpXd1eYiBwmvrD2Pg6KmSuFDVDwowLMs Wa9V2hP6+I2LR23e9vrTljl0Z5AppbhA4YayOW5HIzjdeb2xYkFLmPRuechGmMd9iyr+SY tiaFfqDFtm83ybhmVbKjkESM/Cn8mfx/cvLYIxPtrZw1zEQ3NOxqaEG6hyz5Fw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hs7z52FYHzYYF for ; Sat, 26 Sep 2026 00:40:49 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 2625f by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Sat, 26 Sep 2026 00:40:44 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Philip Paeps Subject: git: 1dc191dd5837 - stable/15 - contrib/expat: import expat 2.8.5 List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: philip X-Git-Repository: src X-Git-Refname: refs/heads/stable/15 X-Git-Reftype: branch X-Git-Commit: 1dc191dd5837cac9514128e5ee4b250ba44180c5 Auto-Submitted: auto-generated Date: Sat, 26 Sep 2026 00:40:44 +0000 Message-Id: <6ab7148c.2625f.7e7cc5ef@gitrepo.freebsd.org> The branch stable/15 has been updated by philip: URL: https://cgit.FreeBSD.org/src/commit/?id=1dc191dd5837cac9514128e5ee4b250ba44180c5 commit 1dc191dd5837cac9514128e5ee4b250ba44180c5 Author: Philip Paeps AuthorDate: 2026-09-23 04:27:57 +0000 Commit: Philip Paeps CommitDate: 2026-09-26 00:31:39 +0000 contrib/expat: import expat 2.8.5 Changes: https://github.com/libexpat/libexpat/blob/R_2_8_5/expat/Changes Security: CVE-2026-93990 (cherry picked from commit c7b67985633c408cae69703ca443cbfd84d326a8) --- contrib/expat/Changes | 87 ++++++- contrib/expat/Makefile.am | 7 - contrib/expat/Makefile.in | 153 ++++++++---- contrib/expat/README.md | 2 +- contrib/expat/configure.ac | 18 +- contrib/expat/doc/Makefile.in | 12 +- contrib/expat/doc/reference.html | 32 ++- contrib/expat/doc/xmlwf.1 | 2 +- contrib/expat/doc/xmlwf.xml | 2 +- contrib/expat/examples/Makefile.in | 27 ++- contrib/expat/fuzz/xml_lpm_fuzzer.cpp | 5 +- contrib/expat/fuzz/xml_parse_fuzzer.c | 14 +- contrib/expat/fuzz/xml_parsebuffer_fuzzer.c | 13 +- contrib/expat/lib/Makefile.am | 1 + contrib/expat/lib/Makefile.in | 28 ++- contrib/expat/lib/expat.h | 8 +- contrib/expat/lib/expat_external.h | 12 + contrib/expat/lib/hash_table.h | 78 ++++++ contrib/expat/lib/internal.h | 169 ++++++------- contrib/expat/lib/xmlparse.c | 225 ++++++++---------- contrib/expat/lib/xmlrole.c | 113 +++++---- contrib/expat/lib/xmlrole.h | 14 +- contrib/expat/lib/xmltok.c | 203 +++++++++++----- contrib/expat/lib/xmltok.h | 58 ++--- contrib/expat/lib/xmltok_impl.c | 63 +++-- contrib/expat/lib/xmltok_ns.c | 6 +- contrib/expat/tests/Makefile.am | 8 +- contrib/expat/tests/Makefile.in | 52 ++-- contrib/expat/tests/acc_tests.h | 12 +- contrib/expat/tests/alloc_tests.h | 12 +- contrib/expat/tests/basic_tests.c | 354 +++++++++++++++++++++++++++- contrib/expat/tests/basic_tests.h | 12 +- contrib/expat/tests/benchmark/Makefile.in | 27 ++- contrib/expat/tests/chardata.h | 10 +- contrib/expat/tests/common.h | 88 ++++--- contrib/expat/tests/dummy.h | 50 ++-- contrib/expat/tests/handlers.h | 43 ++-- contrib/expat/tests/hash_tests.c | 157 ++++++++++++ contrib/expat/tests/hash_tests.h | 41 ++++ contrib/expat/tests/memcheck.c | 3 +- contrib/expat/tests/memcheck.h | 12 +- contrib/expat/tests/minicheck.h | 76 +++--- contrib/expat/tests/misc_tests.c | 2 +- contrib/expat/tests/misc_tests.h | 12 +- contrib/expat/tests/ns_tests.h | 12 +- contrib/expat/tests/nsalloc_tests.c | 2 + contrib/expat/tests/nsalloc_tests.h | 12 +- contrib/expat/tests/runtests.c | 4 +- contrib/expat/tests/structdata.h | 9 +- contrib/expat/tests/xmltest.sh | 2 + contrib/expat/xmlwf/Makefile.in | 27 ++- contrib/expat/xmlwf/unixfilemap.c | 4 +- contrib/expat/xmlwf/xmlfile.c | 6 +- contrib/expat/xmlwf/xmlfile.h | 8 +- contrib/expat/xmlwf/xmlmime.h | 10 +- contrib/expat/xmlwf/xmlwf.c | 25 +- contrib/expat/xmlwf/xmlwf_helpgen.py | 7 +- contrib/expat/xmlwf/xmlwf_helpgen.sh | 8 +- lib/libexpat/expat_config.h | 6 +- lib/libexpat/libbsdxml.3 | 4 +- 60 files changed, 1612 insertions(+), 857 deletions(-) diff --git a/contrib/expat/Changes b/contrib/expat/Changes index af91a67dd5ce..bf94e9db5616 100644 --- a/contrib/expat/Changes +++ b/contrib/expat/Changes @@ -13,9 +13,94 @@ !! will be funded by the City of Munich as part of their !! !! Open Source Sabbatical (https://opensource.muenchen.de/sabbatical.html) !! !! — thank you! !! -!! Sebastian Pipping -- Berlin, 2026-08-03 !! +!! !! +!! If your business relies on Expat beyond January 2027, please consider !! +!! funding the maintenance of Expat to ensure its health and security for !! +!! you and others. Thank you! !! +!! !! +!! Sebastian Pipping -- Berlin, 2026-09-22 !! !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! +Release 2.8.5 Tue September 22 2026 + Security fixes: + #1282 CVE-2026-93990 -- Reject high surrogates not followed by a + low surrogate during UTF-16 decoding; previously, malformed + UTF-16 could be smuggled into the application using Expat + and could cause arbitrary damage there, depending on how + malformed UTF-16 was handled inside the application; + validation was not their job but Expat's. This is similar + to past vulnerability CVE-2022-25235. + Upstream CVSS 3.1 vector: + AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (CVSS score: 9.8) + +/////////////////////////////////////////////////////////////////////////////// +// The next release will drop two (disabled-by-default) features: // +// // +// - ATTR_INFO (-DXML_ATTR_INFO, -DEXPAT_ATTR_INFO, --enable-xml-attr-info, // +// function XML_GetAttributeInfo, struct XML_AttrInfo) // +// - MIN_SIZE (-DXML_MIN_SIZE, -DEXPAT_MIN_SIZE) // +// // +// If you need them in 2026 and beyond, please share your scenario at // +// GitHub issues #1370 (for ATTR_INFO) and/or #1379 (for MIN_SIZE). Thanks! // +/////////////////////////////////////////////////////////////////////////////// + + Bug fixes: + #1346 lib: Fix OOM-related memory leak on a failed overflow check + #1371 lib: Fix memory alignment for architectures with 128bit + pointers like CHERI-RISC-V + #1367 xmlwf: Handle errors when closing output files + + Other changes: + #1354 lib: Reject an XML declaration version other than `1.[0-9]+` + (which is less strict than XML 1.0r4 (fourth edition) + and matches XML 1.0r5 (fifth edition)) + #1362 lib: Make Clang, GCC and MSVC warn about use of function + XML_SetHashSalt that is deprecated since Expat 2.8.0 + #1357 lib: Drop internal macros FASTCALL, PTRCALL, PTRFASTCALL + #1367 xmlwf: Document that with `-k` the last error determines the + xmlwf exit code in `--help` output + #1367 xmlwf: Make exit code 3 documentation match exit code 2 more + closely in `--help` output + #1352 #1353 CMake|Windows: Refrain from adding `/source-charset:utf-8` + for MSVC + #1366 #1374 Autotools: Be explicit about the minimum required version of + GNU Automake, currently version 1.13 of 2012-12-28 + #1351 Autotools|macOS: Sync CMake templates with CMake 4.4.3 + #1349 Replace some internal use of XML_Bool with standard bool + #1364 tests: Propagate xmltest.sh failures via exit status + #1360 tests|xmlwf: Add `#include "expat_config.h"` where missing + #1355 tests: Start covering hash table operation + #1350 #1369 tests: Drop __cplusplus leftovers + #1378 tests: Fix tail pointer when unlinking the last tracked + allocation + #1376 docs: Emphasize that XML_StopParser is not immediate + #1381 docs: Sync XML_FeatureEnum value list in doc/reference.html + #1356 #1361 Version info bumped from 13:4:12 (libexpat*.so.1.12.4) + to 13:5:12 (libexpat*.so.1.12.5); see https://verbump.de/ + for what these numbers do + + Infrastructure: + #1347 Add missing .gitignore entries + #1360 CI: Detect missing `#include "expat_config.h"` + #1368 CI: Bump MinGW Clang from 23.0.1 to 23.1.1 + #1377 CI: Bump Fil-C from 0.684 to 0.685 + #1380 CI: Bump Cppcheck from 2.21.0 to 2.22.0 + #1372 CI: Extract helper script `apply-htmltidy.sh` + #1366 #1374 Autotools: Start to also produce .tar.bz3 release tarballs + + Special thanks to: + Afonso Januário + Braian Plaku + Florian Schmaus + Huang Wenbin + Kamila Szewczyk + Kartik Kenchi + Leo Camus + Matthew Fernandez + Stan Ulbrych + and + City of Munich Open Source Sabbatical + Release 2.8.4 Mon August 31 2026 Security fixes: #1321 #1331 CVE-2026-66046, CVE-2026-76641 -- Fix quadratic runtime from diff --git a/contrib/expat/Makefile.am b/contrib/expat/Makefile.am index 09b88f315165..fbc03d85f474 100644 --- a/contrib/expat/Makefile.am +++ b/contrib/expat/Makefile.am @@ -33,13 +33,6 @@ # OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE # USE OR OTHER DEALINGS IN THE SOFTWARE. -AUTOMAKE_OPTIONS = \ - dist-bzip2 \ - dist-lzip \ - dist-xz \ - foreign \ - subdir-objects - ACLOCAL_AMFLAGS = -I m4 LIBTOOLFLAGS = --verbose diff --git a/contrib/expat/Makefile.in b/contrib/expat/Makefile.in index 0f9a441aa882..c0a0eefc47ac 100644 --- a/contrib/expat/Makefile.in +++ b/contrib/expat/Makefile.in @@ -1,7 +1,7 @@ -# Makefile.in generated by automake 1.18.1 from Makefile.am. +# Makefile.in generated by automake 1.19 from Makefile.am. # @configure_input@ -# Copyright (C) 1994-2025 Free Software Foundation, Inc. +# Copyright (C) 1994-2026 Free Software Foundation, Inc. # This Makefile.in is free software; the Free Software Foundation # gives unlimited permission to copy and/or distribute it, @@ -261,7 +261,13 @@ am__remove_distdir = \ ; rm -rf "$(distdir)" \ || { sleep 5 && rm -rf "$(distdir)"; }; \ else :; fi -am__post_remove_distdir = $(am__remove_distdir) +am__post_remove_distdir = \ + $(am__is_gnu_make) || rm -f am__distdir.tar; \ + $(am__remove_distdir) +am__ensure_distdir_tar = \ + test -f am__distdir.tar || $(MAKE) $(AM_MAKEFLAGS) am__distdir.tar +am__dist_compress_failed = \ + am__rc=$$?; rm -f $$am__archive am__distdir.tar; exit $$am__rc am__relativize = \ dir0=`pwd`; \ sed_first='s,^\([^/]*\)/.*$$,\1,'; \ @@ -287,10 +293,13 @@ am__relativize = \ dir1=`echo "$$dir1" | sed -e "$$sed_rest"`; \ done; \ reldir="$$dir2" -DIST_ARCHIVES = $(distdir).tar.gz $(distdir).tar.bz2 $(distdir).tar.lz \ - $(distdir).tar.xz +# Exists only to be overridden by the user if desired. +AM_DIST_TAR_IGNORE_STDERR = $(am__tar_ignore_stderr) +DIST_ARCHIVES = $(distdir).tar.gz $(distdir).tar.bz2 \ + $(distdir).tar.bz3 $(distdir).tar.lz $(distdir).tar.xz GZIP_ENV = -9 -DIST_TARGETS = dist-lzip dist-xz dist-bzip2 dist-gzip +DIST_TARGETS = am--dist-lzip am--dist-xz am--dist-bzip2 am--dist-bzip3 \ + am--dist-gzip # Exists only to be overridden by the user if desired. AM_DISTCHECK_DVI_TARGET = dvi distuninstallcheck_listfiles = find . -type f -print @@ -411,6 +420,7 @@ am__leading_dot = @am__leading_dot@ am__quote = @am__quote@ am__rm_f_notfound = @am__rm_f_notfound@ am__tar = @am__tar@ +am__tar_ignore_stderr = @am__tar_ignore_stderr@ am__untar = @am__untar@ am__xargs_n = @am__xargs_n@ bindir = @bindir@ @@ -454,13 +464,6 @@ target_alias = @target_alias@ top_build_prefix = @top_build_prefix@ top_builddir = @top_builddir@ top_srcdir = @top_srcdir@ -AUTOMAKE_OPTIONS = \ - dist-bzip2 \ - dist-lzip \ - dist-xz \ - foreign \ - subdir-objects - ACLOCAL_AMFLAGS = -I m4 LIBTOOLFLAGS = --verbose SUBDIRS = lib $(am__append_1) $(am__append_2) $(am__append_3) @@ -748,13 +751,14 @@ distdir-am: $(DISTFILES) $(AM_V_at)$(MKDIR_P) "$(distdir)" @srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \ topsrcdirstrip=`echo "$(top_srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \ + am__distdir="$(distdir)"; \ list='$(DISTFILES)'; \ dist_files=`for file in $$list; do echo $$file; done | \ sed -e "s|^$$srcdirstrip/||;t" \ -e "s|^$$topsrcdirstrip/|$(top_builddir)/|;t"`; \ case $$dist_files in \ */*) $(MKDIR_P) `echo "$$dist_files" | \ - sed '/\//!d;s|^|$(distdir)/|;s,/[^/]*$$,,' | \ + sed "/\//!d;s|^|$$am__distdir/|;s,/[^/]*$$,," | \ sort -u` ;; \ esac; \ for file in $$dist_files; do \ @@ -807,55 +811,96 @@ distdir-am: $(DISTFILES) ! -type d ! -perm -400 -exec chmod a+r {} \; -o \ ! -type d ! -perm -444 -exec $(install_sh) -c -m a+r {} {} \; \ || chmod -R a+r "$(distdir)" -dist-gzip: distdir - tardir=$(distdir) && $(am__tar) | eval GZIP= gzip $(GZIP_ENV) -c >$(distdir).tar.gz + +am__distdir.tar: distdir + am__distdir="$(distdir)"; \ + am__tar_msg=`tardir=$$am__distdir && $(am__tar) 2>&1 >am__distdir.tar`; \ + am__tar_rc=$$?; \ + test -z "$$am__tar_msg" || { printf '%s\n' "$$am__tar_msg" >&2; \ + test x"$(AM_DIST_TAR_IGNORE_STDERR)" = xyes || am__tar_rc=1; }; \ + test $$am__tar_rc -eq 0 || { rm -f am__distdir.tar; \ + echo "$(distdir).tar: cannot create the distribution archive" >&2; exit 1; } + +.INTERMEDIATE: am__distdir.tar +dist-gzip: am--dist-gzip $(am__post_remove_distdir) -dist-bzip2: distdir - tardir=$(distdir) && $(am__tar) | BZIP2=$${BZIP2--9} bzip2 -c >$(distdir).tar.bz2 +am--dist-gzip: am__distdir.tar + @$(am__ensure_distdir_tar) + am__archive=$(distdir).tar.gz; \ + eval GZIP= gzip $(GZIP_ENV) -c $$am__archive \ + || { $(am__dist_compress_failed); } +dist-bzip2: am--dist-bzip2 $(am__post_remove_distdir) - -dist-bzip3: distdir - tardir=$(distdir) && $(am__tar) | bzip3 -c >$(distdir).tar.bz3 +am--dist-bzip2: am__distdir.tar + @$(am__ensure_distdir_tar) + am__archive=$(distdir).tar.bz2; \ + BZIP2=$${BZIP2--9} bzip2 -c $$am__archive \ + || { $(am__dist_compress_failed); } +dist-bzip3: am--dist-bzip3 $(am__post_remove_distdir) -dist-lzip: distdir - tardir=$(distdir) && $(am__tar) | lzip -c $${LZIP_OPT--9} >$(distdir).tar.lz +am--dist-bzip3: am__distdir.tar + @$(am__ensure_distdir_tar) + am__archive=$(distdir).tar.bz3; \ + bzip3 -c $$am__archive \ + || { $(am__dist_compress_failed); } +dist-lzip: am--dist-lzip $(am__post_remove_distdir) -dist-xz: distdir - tardir=$(distdir) && $(am__tar) | XZ_OPT=$${XZ_OPT--e} xz -c >$(distdir).tar.xz +am--dist-lzip: am__distdir.tar + @$(am__ensure_distdir_tar) + am__archive=$(distdir).tar.lz; \ + lzip -c $${LZIP_OPT--9} $$am__archive \ + || { $(am__dist_compress_failed); } +dist-xz: am--dist-xz $(am__post_remove_distdir) +am--dist-xz: am__distdir.tar + @$(am__ensure_distdir_tar) + am__archive=$(distdir).tar.xz; \ + XZ_OPT=$${XZ_OPT--e} xz -c $$am__archive \ + || { $(am__dist_compress_failed); } -dist-zstd: distdir - tardir=$(distdir) && $(am__tar) | zstd -c $${ZSTD_CLEVEL-$${ZSTD_OPT--19}} >$(distdir).tar.zst +dist-zstd: am--dist-zstd $(am__post_remove_distdir) +am--dist-zstd: am__distdir.tar + @$(am__ensure_distdir_tar) + am__archive=$(distdir).tar.zst; \ + zstd -c $${ZSTD_CLEVEL-$${ZSTD_OPT--19}} $$am__archive \ + || { $(am__dist_compress_failed); } -dist-tarZ: distdir +dist-tarZ: am--dist-tarZ + $(am__post_remove_distdir) +am--dist-tarZ: am__distdir.tar + @$(am__ensure_distdir_tar) @echo WARNING: "Support for distribution archives compressed with" \ "legacy program 'compress' is deprecated." >&2 @echo WARNING: "It will be removed altogether in Automake 2.0" >&2 - tardir=$(distdir) && $(am__tar) | compress -c >$(distdir).tar.Z - $(am__post_remove_distdir) + am__archive=$(distdir).tar.Z; \ + compress -c $$am__archive \ + || { $(am__dist_compress_failed); } -dist-shar: distdir +dist-shar: am--dist-shar + $(am__post_remove_distdir) +am--dist-shar: distdir @echo WARNING: "Support for shar distribution archives is" \ "deprecated." >&2 @echo WARNING: "It will be removed altogether in Automake 2.0" >&2 - shar $(distdir) | eval GZIP= gzip $(GZIP_ENV) -c >$(distdir).shar.gz - $(am__post_remove_distdir) + shar $(distdir) >$(distdir).shar || { rm -f $(distdir).shar; exit 1; } + eval GZIP= gzip $(GZIP_ENV) -f $(distdir).shar -dist-zip: distdir +dist-zip: am--dist-zip + $(am__post_remove_distdir) +am--dist-zip: distdir -rm -f $(distdir).zip zip -rq $(distdir).zip $(distdir) - $(am__post_remove_distdir) dist dist-all: - $(MAKE) $(AM_MAKEFLAGS) $(DIST_TARGETS) am__post_remove_distdir='@:' + $(MAKE) $(AM_MAKEFLAGS) $(DIST_TARGETS) $(am__post_remove_distdir) # This target untars the dist file and tries a VPATH configuration. Then # it guarantees that the distribution is self-contained by making another # tarfile. distcheck: dist - case '$(DIST_ARCHIVES)' in \ + case "$(DIST_ARCHIVES)" in \ *.tar.gz*) \ eval GZIP= gzip -dc $(distdir).tar.gz | $(am__untar) ;;\ *.tar.bz2*) \ @@ -879,11 +924,13 @@ distcheck: dist chmod u+w $(distdir) mkdir $(distdir)/_build $(distdir)/_build/sub $(distdir)/_inst chmod a-w $(distdir) - test -d $(distdir)/_build || exit 0; \ - dc_install_base=`$(am__cd) $(distdir)/_inst && pwd | sed -e 's,^[^:\\/]:[\\/],/,'` \ + am__distdir="$(distdir)"; \ + am__distarchives="$(DIST_ARCHIVES)"; \ + test -d "$$am__distdir/_build" || exit 0; \ + dc_install_base=`$(am__cd) "$$am__distdir/_inst" && pwd | sed -e 's,^[^:\\/]:[\\/],/,'` \ && dc_destdir="$${TMPDIR-/tmp}/am-dc-$$$$/" \ && am__cwd=`pwd` \ - && $(am__cd) $(distdir)/_build/sub \ + && $(am__cd) "$$am__distdir/_build/sub" \ && ../../configure \ $(AM_DISTCHECK_CONFIGURE_FLAGS) \ $(DISTCHECK_CONFIGURE_FLAGS) \ @@ -906,13 +953,13 @@ distcheck: dist } || { rm -rf "$$dc_destdir"; exit 1; }) \ && rm -rf "$$dc_destdir" \ && $(MAKE) $(AM_MAKEFLAGS) dist \ - && rm -rf $(DIST_ARCHIVES) \ + && rm -rf $$am__distarchives \ && $(MAKE) $(AM_MAKEFLAGS) distcleancheck \ && cd "$$am__cwd" \ || exit 1 $(am__post_remove_distdir) @(echo "$(distdir) archives ready for distribution: "; \ - list='$(DIST_ARCHIVES)'; for i in $$list; do echo $$i; done) | \ + list="$(DIST_ARCHIVES)"; for i in $$list; do echo $$i; done) | \ sed -e 1h -e 1s/./=/g -e 1p -e 1x -e '$$p' -e '$$x' distuninstallcheck: @test -n '$(distuninstallcheck_dir)' || { \ @@ -1051,16 +1098,18 @@ uninstall-am: uninstall-nodist_cmakeDATA uninstall-pkgconfigDATA .MAKE: $(am__recursive_targets) all install-am install-strip .PHONY: $(am__recursive_targets) CTAGS GTAGS TAGS all all-am \ - am--refresh check check-am clean clean-cscope clean-generic \ - clean-libtool cscope cscopelist-am ctags ctags-am dist \ - dist-all dist-bzip2 dist-bzip3 dist-gzip dist-lzip dist-shar \ - dist-tarZ dist-xz dist-zip dist-zstd distcheck distclean \ - distclean-generic distclean-hdr distclean-libtool \ - distclean-tags distcleancheck distdir distuninstallcheck dvi \ - dvi-am html html-am info info-am install install-am \ - install-data install-data-am install-dvi install-dvi-am \ - install-exec install-exec-am install-html install-html-am \ - install-info install-info-am install-man \ + am--dist-bzip2 am--dist-bzip3 am--dist-gzip am--dist-lzip \ + am--dist-shar am--dist-tarZ am--dist-xz am--dist-zip \ + am--dist-zstd am--refresh check check-am clean clean-cscope \ + clean-generic clean-libtool cscope cscopelist-am ctags \ + ctags-am dist dist-all dist-bzip2 dist-bzip3 dist-gzip \ + dist-lzip dist-shar dist-tarZ dist-xz dist-zip dist-zstd \ + distcheck distclean distclean-generic distclean-hdr \ + distclean-libtool distclean-tags distcleancheck distdir \ + distuninstallcheck dvi dvi-am html html-am info info-am \ + install install-am install-data install-data-am install-dvi \ + install-dvi-am install-exec install-exec-am install-html \ + install-html-am install-info install-info-am install-man \ install-nodist_cmakeDATA install-pdf install-pdf-am \ install-pkgconfigDATA install-ps install-ps-am install-strip \ installcheck installcheck-am installdirs installdirs-am \ diff --git a/contrib/expat/README.md b/contrib/expat/README.md index ae43ed3cc663..36e46a90fd23 100644 --- a/contrib/expat/README.md +++ b/contrib/expat/README.md @@ -17,7 +17,7 @@ > Thank you! :heart: :pray: -# Expat, Release 2.8.4 +# Expat, Release 2.8.5 This is Expat, a C99 library for parsing [XML 1.0 Fourth Edition](https://www.w3.org/TR/2006/REC-xml-20060816/), started by diff --git a/contrib/expat/configure.ac b/contrib/expat/configure.ac index be6b8b289197..e8562dbc5fc1 100644 --- a/contrib/expat/configure.ac +++ b/contrib/expat/configure.ac @@ -74,7 +74,21 @@ AC_CONFIG_SRCDIR([Makefile.in]) AC_CONFIG_AUX_DIR([conftools]) AC_CONFIG_MACRO_DIR([m4]) AC_CANONICAL_HOST -AM_INIT_AUTOMAKE + +dnl NOTE: Macro `AM_OPTIONAL_AUTOMAKE` is available with Automake >=1.19 +dnl and serves as a proxy for robust Automake >=1.19 detection here. +dnl `dist-bzip3` was introduced with Automake 1.18 already but there +dnl is no robust way of checking precisely for Automake >=1.18. +dnl Automake >=1.13 is needed for (1) our use of LOG_DRIVER and +dnl (2) making it work without asking for parallel tests, explicitly. +m4_ifdef([AM_OPTIONAL_AUTOMAKE], [ + AM_INIT_AUTOMAKE([1.19 dist-bzip2 dist-bzip3 dist-lzip dist-xz foreign subdir-objects]) + + dnl NOTE: Without this dummy call in the file the `m4_ifdef` above never hits true. + AM_OPTIONAL_AUTOMAKE([]) +], [ + AM_INIT_AUTOMAKE([1.13 dist-bzip2 dist-lzip dist-xz foreign subdir-objects]) +]) AM_MAINTAINER_MODE([enable]) # to allow argument --disable-maintainer-mode @@ -90,7 +104,7 @@ dnl If the API changes incompatibly set LIBAGE back to 0 dnl LIBCURRENT=13 # sync -LIBREVISION=4 # with +LIBREVISION=5 # with LIBAGE=12 # CMakeLists.txt! AC_CONFIG_HEADERS([expat_config.h]) diff --git a/contrib/expat/doc/Makefile.in b/contrib/expat/doc/Makefile.in index 0bda758420f0..52a18ffb673f 100644 --- a/contrib/expat/doc/Makefile.in +++ b/contrib/expat/doc/Makefile.in @@ -1,7 +1,7 @@ -# Makefile.in generated by automake 1.18.1 from Makefile.am. +# Makefile.in generated by automake 1.19 from Makefile.am. # @configure_input@ -# Copyright (C) 1994-2025 Free Software Foundation, Inc. +# Copyright (C) 1994-2026 Free Software Foundation, Inc. # This Makefile.in is free software; the Free Software Foundation # gives unlimited permission to copy and/or distribute it, @@ -309,6 +309,7 @@ am__leading_dot = @am__leading_dot@ am__quote = @am__quote@ am__rm_f_notfound = @am__rm_f_notfound@ am__tar = @am__tar@ +am__tar_ignore_stderr = @am__tar_ignore_stderr@ am__untar = @am__untar@ am__xargs_n = @am__xargs_n@ bindir = @bindir@ @@ -372,9 +373,9 @@ $(srcdir)/Makefile.in: @MAINTAINER_MODE_TRUE@ $(srcdir)/Makefile.am $(am__confi exit 1;; \ esac; \ done; \ - echo ' cd $(top_srcdir) && $(AUTOMAKE) --gnu doc/Makefile'; \ + echo ' cd $(top_srcdir) && $(AUTOMAKE) --foreign doc/Makefile'; \ $(am__cd) $(top_srcdir) && \ - $(AUTOMAKE) --gnu doc/Makefile + $(AUTOMAKE) --foreign doc/Makefile Makefile: $(srcdir)/Makefile.in $(top_builddir)/config.status @case '$?' in \ *config.status*) \ @@ -455,13 +456,14 @@ distdir: $(BUILT_SOURCES) distdir-am: $(DISTFILES) @srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \ topsrcdirstrip=`echo "$(top_srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \ + am__distdir="$(distdir)"; \ list='$(DISTFILES)'; \ dist_files=`for file in $$list; do echo $$file; done | \ sed -e "s|^$$srcdirstrip/||;t" \ -e "s|^$$topsrcdirstrip/|$(top_builddir)/|;t"`; \ case $$dist_files in \ */*) $(MKDIR_P) `echo "$$dist_files" | \ - sed '/\//!d;s|^|$(distdir)/|;s,/[^/]*$$,,' | \ + sed "/\//!d;s|^|$$am__distdir/|;s,/[^/]*$$,," | \ sort -u` ;; \ esac; \ for file in $$dist_files; do \ diff --git a/contrib/expat/doc/reference.html b/contrib/expat/doc/reference.html index e54c7be2965a..5bd9150ea78a 100644 --- a/contrib/expat/doc/reference.html +++ b/contrib/expat/doc/reference.html @@ -53,7 +53,7 @@

- The Expat XML Parser Release 2.8.4 + The Expat XML Parser Release 2.8.5

@@ -1763,12 +1763,16 @@ XML_StopParser(XML_Parser p,

- Stops parsing, causing XML_Parse or - XML_ParseBuffer to return. Must be - called from within a call-back handler, except when aborting (when - resumable is XML_FALSE) an already suspended parser. - Some call-backs may still follow because they would otherwise get lost, - including + Stops parsing as soon as possible, causing XML_Parse or XML_ParseBuffer to return. Must be called from + within a call-back handler, except when aborting (when resumable + is XML_FALSE) an already suspended parser. +

+ +

+ Note: Some call-backs may still follow because they would + otherwise get lost, including

    @@ -3709,8 +3713,20 @@ enum XML_FeatureEnum { XML_FEATURE_MIN_SIZE, XML_FEATURE_SIZEOF_XML_CHAR, XML_FEATURE_SIZEOF_XML_LCHAR, + /* Added in Expat 2.0.0. */ XML_FEATURE_NS, - XML_FEATURE_LARGE_SIZE + /* Added in Expat 2.0.1. */ + XML_FEATURE_LARGE_SIZE, + /* Added in Expat 2.1.0. */ + XML_FEATURE_ATTR_INFO, + /* Added in Expat 2.4.0. */ + XML_FEATURE_BILLION_LAUGHS_ATTACK_PROTECTION_MAXIMUM_AMPLIFICATION_DEFAULT, + XML_FEATURE_BILLION_LAUGHS_ATTACK_PROTECTION_ACTIVATION_THRESHOLD_DEFAULT, + /* Added in Expat 2.6.0. */ + XML_FEATURE_GE, + /* Added in Expat 2.7.2. */ + XML_FEATURE_ALLOC_TRACKER_MAXIMUM_AMPLIFICATION_DEFAULT, + XML_FEATURE_ALLOC_TRACKER_ACTIVATION_THRESHOLD_DEFAULT, }; typedef struct { diff --git a/contrib/expat/doc/xmlwf.1 b/contrib/expat/doc/xmlwf.1 index 7177cbf19c49..e9b6a2fe4610 100644 --- a/contrib/expat/doc/xmlwf.1 +++ b/contrib/expat/doc/xmlwf.1 @@ -5,7 +5,7 @@ \\$2 \(la\\$1\(ra\\$3 .. .if \n(.g .mso www.tmac -.TH XMLWF 1 "August 31, 2026" "" "" +.TH XMLWF 1 "September 22, 2026" "" "" .SH NAME xmlwf \- Determines if an XML document is well-formed .SH SYNOPSIS diff --git a/contrib/expat/doc/xmlwf.xml b/contrib/expat/doc/xmlwf.xml index 93a67c407563..e7a2664b7e42 100644 --- a/contrib/expat/doc/xmlwf.xml +++ b/contrib/expat/doc/xmlwf.xml @@ -21,7 +21,7 @@ "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd" [ Scott"> Bronson"> - August 31, 2026"> + September 22, 2026"> 1"> bronson@rinspin.com"> diff --git a/contrib/expat/examples/Makefile.in b/contrib/expat/examples/Makefile.in index 56a6f69c07b7..4ef878f7867c 100644 --- a/contrib/expat/examples/Makefile.in +++ b/contrib/expat/examples/Makefile.in @@ -1,7 +1,7 @@ -# Makefile.in generated by automake 1.18.1 from Makefile.am. +# Makefile.in generated by automake 1.19 from Makefile.am. # @configure_input@ -# Copyright (C) 1994-2025 Free Software Foundation, Inc. +# Copyright (C) 1994-2026 Free Software Foundation, Inc. # This Makefile.in is free software; the Free Software Foundation # gives unlimited permission to copy and/or distribute it, @@ -337,6 +337,7 @@ am__leading_dot = @am__leading_dot@ am__quote = @am__quote@ am__rm_f_notfound = @am__rm_f_notfound@ am__tar = @am__tar@ +am__tar_ignore_stderr = @am__tar_ignore_stderr@ am__untar = @am__untar@ am__xargs_n = @am__xargs_n@ bindir = @bindir@ @@ -399,9 +400,9 @@ $(srcdir)/Makefile.in: @MAINTAINER_MODE_TRUE@ $(srcdir)/Makefile.am $(am__confi exit 1;; \ esac; \ done; \ - echo ' cd $(top_srcdir) && $(AUTOMAKE) --gnu examples/Makefile'; \ + echo ' cd $(top_srcdir) && $(AUTOMAKE) --foreign examples/Makefile'; \ $(am__cd) $(top_srcdir) && \ - $(AUTOMAKE) --gnu examples/Makefile + $(AUTOMAKE) --foreign examples/Makefile Makefile: $(srcdir)/Makefile.in $(top_builddir)/config.status @case '$?' in \ *config.status*) \ @@ -453,22 +454,25 @@ $(am__depfiles_remade): am--depfiles: $(am__depfiles_remade) .c.o: -@am__fastdepCC_TRUE@ $(AM_V_CC)$(COMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ $< -@am__fastdepCC_TRUE@ $(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Po +@am__fastdepCC_TRUE@ $(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.o$$||'`;\ +@am__fastdepCC_TRUE@ $(COMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ $< &&\ +@am__fastdepCC_TRUE@ $(am__mv) $$depbase.Tpo $$depbase.Po @AMDEP_TRUE@@am__fastdepCC_FALSE@ $(AM_V_CC)source='$<' object='$@' libtool=no @AMDEPBACKSLASH@ @AMDEP_TRUE@@am__fastdepCC_FALSE@ DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@ @am__fastdepCC_FALSE@ $(AM_V_CC@am__nodep@)$(COMPILE) -c -o $@ $< .c.obj: -@am__fastdepCC_TRUE@ $(AM_V_CC)$(COMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ `$(CYGPATH_W) '$<'` -@am__fastdepCC_TRUE@ $(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Po +@am__fastdepCC_TRUE@ $(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.obj$$||'`;\ +@am__fastdepCC_TRUE@ $(COMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ `$(CYGPATH_W) '$<'` &&\ +@am__fastdepCC_TRUE@ $(am__mv) $$depbase.Tpo $$depbase.Po @AMDEP_TRUE@@am__fastdepCC_FALSE@ $(AM_V_CC)source='$<' object='$@' libtool=no @AMDEPBACKSLASH@ @AMDEP_TRUE@@am__fastdepCC_FALSE@ DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@ @am__fastdepCC_FALSE@ $(AM_V_CC@am__nodep@)$(COMPILE) -c -o $@ `$(CYGPATH_W) '$<'` .c.lo: -@am__fastdepCC_TRUE@ $(AM_V_CC)$(LTCOMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ $< -@am__fastdepCC_TRUE@ $(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Plo +@am__fastdepCC_TRUE@ $(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.lo$$||'`;\ +@am__fastdepCC_TRUE@ $(LTCOMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ $< &&\ +@am__fastdepCC_TRUE@ $(am__mv) $$depbase.Tpo $$depbase.Plo @AMDEP_TRUE@@am__fastdepCC_FALSE@ $(AM_V_CC)source='$<' object='$@' libtool=yes @AMDEPBACKSLASH@ @AMDEP_TRUE@@am__fastdepCC_FALSE@ DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@ @am__fastdepCC_FALSE@ $(AM_V_CC@am__nodep@)$(LTCOMPILE) -c -o $@ $< @@ -537,13 +541,14 @@ distdir: $(BUILT_SOURCES) distdir-am: $(DISTFILES) @srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \ topsrcdirstrip=`echo "$(top_srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \ + am__distdir="$(distdir)"; \ list='$(DISTFILES)'; \ dist_files=`for file in $$list; do echo $$file; done | \ sed -e "s|^$$srcdirstrip/||;t" \ -e "s|^$$topsrcdirstrip/|$(top_builddir)/|;t"`; \ case $$dist_files in \ */*) $(MKDIR_P) `echo "$$dist_files" | \ - sed '/\//!d;s|^|$(distdir)/|;s,/[^/]*$$,,' | \ + sed "/\//!d;s|^|$$am__distdir/|;s,/[^/]*$$,," | \ sort -u` ;; \ esac; \ for file in $$dist_files; do \ diff --git a/contrib/expat/fuzz/xml_lpm_fuzzer.cpp b/contrib/expat/fuzz/xml_lpm_fuzzer.cpp index 719629a6b547..190b34f74d98 100644 --- a/contrib/expat/fuzz/xml_lpm_fuzzer.cpp +++ b/contrib/expat/fuzz/xml_lpm_fuzzer.cpp @@ -8,6 +8,7 @@ Copyright (c) 2022 Mark Brand Copyright (c) 2025 Sebastian Pipping + Copyright (c) 2026 Braian Plaku Licensed under the MIT license: Permission is hereby granted, free of charge, to any person obtaining @@ -383,7 +384,9 @@ UnknownEncodingHandler(void *encodingHandlerData, const XML_Char *name, void InitializeParser(XML_Parser parser) { XML_SetUserData(parser, (void *)parser); - XML_SetHashSalt(parser, 0x41414141); + const uint8_t entropy[16] = {0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, + 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41}; + XML_SetHashSalt16Bytes(parser, entropy); XML_SetParamEntityParsing(parser, XML_PARAM_ENTITY_PARSING_ALWAYS); XML_SetElementDeclHandler(parser, ElementDeclHandler); diff --git a/contrib/expat/fuzz/xml_parse_fuzzer.c b/contrib/expat/fuzz/xml_parse_fuzzer.c index 29ab33ff79d9..1eb0ad299628 100644 --- a/contrib/expat/fuzz/xml_parse_fuzzer.c +++ b/contrib/expat/fuzz/xml_parse_fuzzer.c @@ -17,6 +17,7 @@ #include #include // for INT_MAX #include +#include #include "expat.h" #include "siphash.h" @@ -34,7 +35,8 @@ #endif // 16-byte deterministic hash key. -static unsigned char hash_key[16] = "FUZZING IS FUN!"; +static unsigned char hash_key_1[16] = "FUZZING IS FUN?"; +static unsigned char hash_key_2[16] = "FUZZING IS FUN!"; static void XMLCALL start(void *userData, const XML_Char *name, const XML_Char **atts) { @@ -59,8 +61,14 @@ may_stop_character_handler(void *userData, const XML_Char *s, int len) { static void ParseOneInput(XML_Parser p, const uint8_t *data, size_t size) { // Set the hash salt using siphash to generate a deterministic hash. - struct sipkey *key = sip_keyof(hash_key); - XML_SetHashSalt(p, (unsigned long)siphash24(data, size, key)); + // The salt is 16 bytes and siphash24 produces 8, so the input is hashed + // under two keys. + const uint64_t first = siphash24(data, size, sip_keyof(hash_key_1)); + const uint64_t second = siphash24(data, size, sip_keyof(hash_key_2)); + uint8_t entropy[16]; + memcpy(entropy, &first, sizeof(first)); + memcpy(entropy + sizeof(first), &second, sizeof(second)); + XML_SetHashSalt16Bytes(p, entropy); (void)sip24_valid; XML_SetUserData(p, p); diff --git a/contrib/expat/fuzz/xml_parsebuffer_fuzzer.c b/contrib/expat/fuzz/xml_parsebuffer_fuzzer.c index 38b9981b0b50..a854f6706396 100644 --- a/contrib/expat/fuzz/xml_parsebuffer_fuzzer.c +++ b/contrib/expat/fuzz/xml_parsebuffer_fuzzer.c @@ -35,7 +35,8 @@ #endif // 16-byte deterministic hash key. -static unsigned char hash_key[16] = "FUZZING IS FUN!"; +static unsigned char hash_key_1[16] = "FUZZING IS FUN?"; +static unsigned char hash_key_2[16] = "FUZZING IS FUN!"; static void XMLCALL start(void *userData, const XML_Char *name, const XML_Char **atts) { @@ -60,8 +61,14 @@ may_stop_character_handler(void *userData, const XML_Char *s, int len) { static void ParseOneInput(XML_Parser p, const uint8_t *data, size_t size) { // Set the hash salt using siphash to generate a deterministic hash. - struct sipkey *key = sip_keyof(hash_key); - XML_SetHashSalt(p, (unsigned long)siphash24(data, size, key)); + // The salt is 16 bytes and siphash24 produces 8, so the input is hashed + // under two keys. + const uint64_t first = siphash24(data, size, sip_keyof(hash_key_1)); + const uint64_t second = siphash24(data, size, sip_keyof(hash_key_2)); + uint8_t entropy[16]; + memcpy(entropy, &first, sizeof(first)); + memcpy(entropy + sizeof(first), &second, sizeof(second)); + XML_SetHashSalt16Bytes(p, entropy); (void)sip24_valid; XML_SetUserData(p, p); diff --git a/contrib/expat/lib/Makefile.am b/contrib/expat/lib/Makefile.am index 2b6aec2e6bdc..6b0d0af4e3c5 100644 --- a/contrib/expat/lib/Makefile.am +++ b/contrib/expat/lib/Makefile.am @@ -115,6 +115,7 @@ EXTRA_DIST = \ expat_external.h \ expat.h \ fallthrough.h \ + hash_table.h \ iasciitab.h \ internal.h \ latin1tab.h \ diff --git a/contrib/expat/lib/Makefile.in b/contrib/expat/lib/Makefile.in index 73db0e584705..58b19912b596 100644 --- a/contrib/expat/lib/Makefile.in +++ b/contrib/expat/lib/Makefile.in @@ -1,7 +1,7 @@ -# Makefile.in generated by automake 1.18.1 from Makefile.am. +# Makefile.in generated by automake 1.19 from Makefile.am. # @configure_input@ -# Copyright (C) 1994-2025 Free Software Foundation, Inc. +# Copyright (C) 1994-2026 Free Software Foundation, Inc. # This Makefile.in is free software; the Free Software Foundation # gives unlimited permission to copy and/or distribute it, @@ -444,6 +444,7 @@ am__leading_dot = @am__leading_dot@ am__quote = @am__quote@ am__rm_f_notfound = @am__rm_f_notfound@ am__tar = @am__tar@ +am__tar_ignore_stderr = @am__tar_ignore_stderr@ am__untar = @am__untar@ am__xargs_n = @am__xargs_n@ bindir = @bindir@ @@ -511,6 +512,7 @@ EXTRA_DIST = \ expat_external.h \ expat.h \ fallthrough.h \ + hash_table.h \ iasciitab.h \ internal.h \ latin1tab.h \ @@ -540,9 +542,9 @@ $(srcdir)/Makefile.in: @MAINTAINER_MODE_TRUE@ $(srcdir)/Makefile.am $(am__confi exit 1;; \ esac; \ done; \ - echo ' cd $(top_srcdir) && $(AUTOMAKE) --gnu lib/Makefile'; \ + echo ' cd $(top_srcdir) && $(AUTOMAKE) --foreign lib/Makefile'; \ $(am__cd) $(top_srcdir) && \ - $(AUTOMAKE) --gnu lib/Makefile + $(AUTOMAKE) --foreign lib/Makefile Makefile: $(srcdir)/Makefile.in $(top_builddir)/config.status @case '$?' in \ *config.status*) \ @@ -643,22 +645,25 @@ $(am__depfiles_remade): am--depfiles: $(am__depfiles_remade) .c.o: -@am__fastdepCC_TRUE@ $(AM_V_CC)$(COMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ $< -@am__fastdepCC_TRUE@ $(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Po +@am__fastdepCC_TRUE@ $(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.o$$||'`;\ +@am__fastdepCC_TRUE@ $(COMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ $< &&\ +@am__fastdepCC_TRUE@ $(am__mv) $$depbase.Tpo $$depbase.Po @AMDEP_TRUE@@am__fastdepCC_FALSE@ $(AM_V_CC)source='$<' object='$@' libtool=no @AMDEPBACKSLASH@ @AMDEP_TRUE@@am__fastdepCC_FALSE@ DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@ @am__fastdepCC_FALSE@ $(AM_V_CC@am__nodep@)$(COMPILE) -c -o $@ $< .c.obj: -@am__fastdepCC_TRUE@ $(AM_V_CC)$(COMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ `$(CYGPATH_W) '$<'` -@am__fastdepCC_TRUE@ $(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Po +@am__fastdepCC_TRUE@ $(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.obj$$||'`;\ +@am__fastdepCC_TRUE@ $(COMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ `$(CYGPATH_W) '$<'` &&\ +@am__fastdepCC_TRUE@ $(am__mv) $$depbase.Tpo $$depbase.Po @AMDEP_TRUE@@am__fastdepCC_FALSE@ $(AM_V_CC)source='$<' object='$@' libtool=no @AMDEPBACKSLASH@ @AMDEP_TRUE@@am__fastdepCC_FALSE@ DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@ @am__fastdepCC_FALSE@ $(AM_V_CC@am__nodep@)$(COMPILE) -c -o $@ `$(CYGPATH_W) '$<'` .c.lo: -@am__fastdepCC_TRUE@ $(AM_V_CC)$(LTCOMPILE) -MT $@ -MD -MP -MF $(DEPDIR)/$*.Tpo -c -o $@ $< -@am__fastdepCC_TRUE@ $(AM_V_at)$(am__mv) $(DEPDIR)/$*.Tpo $(DEPDIR)/$*.Plo +@am__fastdepCC_TRUE@ $(AM_V_CC)depbase=`echo $@ | sed 's|[^/]*$$|$(DEPDIR)/&|;s|\.lo$$||'`;\ +@am__fastdepCC_TRUE@ $(LTCOMPILE) -MT $@ -MD -MP -MF $$depbase.Tpo -c -o $@ $< &&\ +@am__fastdepCC_TRUE@ $(am__mv) $$depbase.Tpo $$depbase.Plo @AMDEP_TRUE@@am__fastdepCC_FALSE@ $(AM_V_CC)source='$<' object='$@' libtool=yes @AMDEPBACKSLASH@ @AMDEP_TRUE@@am__fastdepCC_FALSE@ DEPDIR=$(DEPDIR) $(CCDEPMODE) $(depcomp) @AMDEPBACKSLASH@ @am__fastdepCC_FALSE@ $(AM_V_CC@am__nodep@)$(LTCOMPILE) -c -o $@ $< @@ -832,13 +837,14 @@ distdir: $(BUILT_SOURCES) distdir-am: $(DISTFILES) @srcdirstrip=`echo "$(srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \ topsrcdirstrip=`echo "$(top_srcdir)" | sed 's/[].[^$$\\*]/\\\\&/g'`; \ + am__distdir="$(distdir)"; \ list='$(DISTFILES)'; \ dist_files=`for file in $$list; do echo $$file; done | \ sed -e "s|^$$srcdirstrip/||;t" \ -e "s|^$$topsrcdirstrip/|$(top_builddir)/|;t"`; \ case $$dist_files in \ */*) $(MKDIR_P) `echo "$$dist_files" | \ - sed '/\//!d;s|^|$(distdir)/|;s,/[^/]*$$,,' | \ + sed "/\//!d;s|^|$$am__distdir/|;s,/[^/]*$$,," | \ sort -u` ;; \ esac; \ for file in $$dist_files; do \ diff --git a/contrib/expat/lib/expat.h b/contrib/expat/lib/expat.h index b296be9dbad2..4c3851d50a5f 100644 --- a/contrib/expat/lib/expat.h +++ b/contrib/expat/lib/expat.h @@ -20,6 +20,7 @@ Copyright (c) 2023 Sony Corporation / Snild Dolkow Copyright (c) 2024 Taichi Haradaguchi <20001722@ymail.ne.jp> Copyright (c) 2025 Matthew Fernandez + Copyright (c) 2026 Braian Plaku Licensed under the MIT license: Permission is hereby granted, free of charge, to any person obtaining @@ -921,7 +922,9 @@ XML_SetParamEntityParsing(XML_Parser parser, Returns 1 if successful, 0 when called after parsing has started. Note: If parser == NULL, the function will do nothing and return 0. DEPRECATED since Expat 2.8.0. + Please use XML_SetHashSalt16Bytes instead. */ +XML_ATTR_DEPRECATED("please use XML_SetHashSalt16Bytes instead") XMLPARSEAPI(int) XML_SetHashSalt(XML_Parser parser, unsigned long hash_salt); @@ -1040,8 +1043,11 @@ enum XML_FeatureEnum { XML_FEATURE_MIN_SIZE, XML_FEATURE_SIZEOF_XML_CHAR, XML_FEATURE_SIZEOF_XML_LCHAR, + /* Added in Expat 2.0.0. */ XML_FEATURE_NS, + /* Added in Expat 2.0.1. */ XML_FEATURE_LARGE_SIZE, + /* Added in Expat 2.1.0. */ XML_FEATURE_ATTR_INFO, /* Added in Expat 2.4.0. */ XML_FEATURE_BILLION_LAUGHS_ATTACK_PROTECTION_MAXIMUM_AMPLIFICATION_DEFAULT, @@ -1096,7 +1102,7 @@ XML_SetReparseDeferralEnabled(XML_Parser parser, XML_Bool enabled); */ # define XML_MAJOR_VERSION 2 # define XML_MINOR_VERSION 8 -# define XML_MICRO_VERSION 4 +# define XML_MICRO_VERSION 5 # ifdef __cplusplus } diff --git a/contrib/expat/lib/expat_external.h b/contrib/expat/lib/expat_external.h index 4cd1f3a49c35..cf80f960d6e1 100644 --- a/contrib/expat/lib/expat_external.h +++ b/contrib/expat/lib/expat_external.h @@ -16,6 +16,7 @@ Copyright (c) 2017 Rhodri James Copyright (c) 2018 Yury Gribov Copyright (c) 2026 Matthew Fernandez + Copyright (c) 2026 Braian Plaku Licensed under the MIT license: Permission is hereby granted, free of charge, to any person obtaining @@ -125,6 +126,17 @@ # define XML_ATTR_ALLOC_SIZE(x) # endif +/* Marks a function that Expat still provides but that callers should move off + of. */ +# if defined(__clang__) || defined(__GNUC__) +# define XML_ATTR_DEPRECATED(message) \ *** 4697 LINES SKIPPED ***