From patchwork Wed Oct 7 10:56:53 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Adolf Belka X-Patchwork-Id: 10315 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4j097H5cYtz3wrJ for ; Wed, 07 Oct 2026 10:57:15 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [172.28.1.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE2" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4j097H32DXz84h for ; Wed, 07 Oct 2026 10:57:15 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4j097F0v68z377s for ; Wed, 07 Oct 2026 10:57:13 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4j09796TKfz32Y2 for ; Wed, 07 Oct 2026 10:57:09 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4j09790104z85J; Wed, 07 Oct 2026 10:57:08 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1791370629; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=gxSCsZPRtyRkTzMSMWNBe1okBKNmiyO+MNrt5FyRiWM=; b=pCFiHkK6ZTD6rRsY1HMDKMWjO1ow9W0V936U4WULcgD28i4PC/kHUJuvVRQXq9nDCpyYGr oDttzEiksFak9KDQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1791370629; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=gxSCsZPRtyRkTzMSMWNBe1okBKNmiyO+MNrt5FyRiWM=; b=WCKAVUU5PBHLH9uagXou+D3D0NbuSfe8JI6Nn0Qyl7JUbi/DWjpyCJFsoBP6nJ2iqm9guY 3ZlANYYfrcfPNC7wttGNS9xzwOe21fGLmyWGh1u0rqWQTw3iZBUfixQSiuGICEJmFqrP6M ZyrqIYypVMwLnGsucfxxZMtjejB7/+NDo1/OBjrufk1Xi8vP9uMxz7vlSNN6rXZV+trYLK gz1XmPefRAWTgw87D0e576AZMfAvsv375BcOZ8uYlqfPi/E5VS1dEocCH9mhqKwuDF1UaY MTxiWIyrcXvEqOhpsPy8GYEIvtNoFhtLJ6r7f+ICi/iHD6vE1MMyHUIdHf5sMQ== From: Adolf Belka To: development@lists.ipfire.org Cc: Adolf Belka Subject: [PATCH] expat: Update to version 2.9.0 Date: Wed, 7 Oct 2026 12:56:53 +0200 Message-ID: <20261007105658.104404-5-adolf.belka@ipfire.org> In-Reply-To: <20261007105658.104404-1-adolf.belka@ipfire.org> References: <20261007105658.104404-1-adolf.belka@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 - Update from version 2.8.5 to 2.9.0 - Update of rootfile - 2 CVE fixes - Changelog 2.9.0 Security fixes: (#1392) CVE-2026-102633 -- Integer overflow in function expat_realloc on 32bit platforms (#1393) CVE-2026-77214 -- Validate parameter `len` against available buffer capacity in XML_ParseBuffer Bug fixes: (#1387) lib: Handle OOM when copying encodingName in XML_ParserReset New features: (#1327) lib: Introduce new "Properties API" to get and set scalar properties for a single parser instance. There are six new functions: - XML_GetPropertyBool - XML_GetPropertyDouble - XML_GetPropertyUInt64 - XML_SetPropertyBool - XML_SetPropertyDouble - XML_SetPropertyUInt64 And two new enums: - XML_Prop_Error - XML_Parser_Property (#1323) lib: Introduce five new 64bit location API functions: - XML_GetCurrentByteCount64 - XML_GetCurrentByteIndex64 - XML_GetCurrentColumnNumber64 - XML_GetCurrentLineNumber64 - XML_GetInputContext64 These five functions closely mirror their predecessors but are not prone to 32bit integer wrap-around. Other changes: (#1391) docs: Document the scope of function XML_GetErrorCode (#1395) docs: Document length expectations for XML_ParseBuffer (#1394) lib: Call unknown encoding release before parser teardown (#1370 #1373) lib: Drop (disabled-by-default) attribute info feature These things are now gone: - Public function XML_GetAttributeInfo - Public struct XML_AttrInfo - Macro XML_ATTR_INFO These things are now causing build errors: - Configure option --enable-xml-attr-info - CMake option -DEXPAT_ATTR_INFO=ON (#1379 #1382) lib: Drop (disabled-by-default) minimum size feature These things are now gone: - Macro XML_MIN_SIZE These things are now causing build errors: - Configuring with -DXML_MIN_SIZE for CPPFLAGS/CFLAGS - CMake option -DEXPAT_MIN_SIZE=ON (#1323 #1411) lib: Deprecate macro XML_LARGE_SIZE (use the new 64bit location API functions instead please) (#1323) lib: Deprecate five location API functions that are cursed with integer wrap-around: - XML_GetCurrentByteCount - XML_GetCurrentByteIndex - XML_GetCurrentColumnNumber - XML_GetCurrentLineNumber - XML_GetInputContext (#1399) lib: Guard against out-of-handler use of XML_DefaultCurrent (#1400) lib: Use size_t for bytesAllocated and peakBytesAllocated (#1401 #1402) .. (#1404 #1405) lib|xmlwf|tests: Unify use of xcslen, xcscmp and xcsncmp (#1406) xmlwf: Add missing `#include "expat.h"` (#1389 #1396) Version info bumped from 13:5:12 (libexpat*.so.1.12.5) to 14:0:13 (libexpat*.so.1.13.0); see https://verbump.de/ for what these numbers do Infrastructure: (#1386) CI: Bump MinGW Clang from 23.1.1 to 23.1.2 (#1410) CI: Bump Fil-C from 0.685 to 0.686 (#1388) CI: Adapt to breaking changes regarding windows-11-arm image (#1403) CI: Limit package cache download runtime Signed-off-by: Adolf Belka --- config/rootfiles/common/expat | 20 ++++++++++---------- lfs/expat | 4 ++-- 2 files changed, 12 insertions(+), 12 deletions(-) diff --git a/config/rootfiles/common/expat b/config/rootfiles/common/expat index a32adc876..f0ef98fe7 100644 --- a/config/rootfiles/common/expat +++ b/config/rootfiles/common/expat @@ -2,21 +2,21 @@ #usr/include/expat.h #usr/include/expat_config.h #usr/include/expat_external.h -#usr/lib/cmake/expat-2.8.5 -#usr/lib/cmake/expat-2.8.5/expat-config-version.cmake -#usr/lib/cmake/expat-2.8.5/expat-config.cmake -#usr/lib/cmake/expat-2.8.5/expat-noconfig.cmake -#usr/lib/cmake/expat-2.8.5/expat.cmake +#usr/lib/cmake/expat-2.9.0 +#usr/lib/cmake/expat-2.9.0/expat-config-version.cmake +#usr/lib/cmake/expat-2.9.0/expat-config.cmake +#usr/lib/cmake/expat-2.9.0/expat-noconfig.cmake +#usr/lib/cmake/expat-2.9.0/expat.cmake #usr/lib/libexpat.la #usr/lib/libexpat.so usr/lib/libexpat.so.1 -usr/lib/libexpat.so.1.12.5 +usr/lib/libexpat.so.1.13.0 #usr/lib/pkgconfig/expat.pc #usr/share/doc/expat -#usr/share/doc/expat-2.8.5 -#usr/share/doc/expat-2.8.5/ok.min.css -#usr/share/doc/expat-2.8.5/reference.html -#usr/share/doc/expat-2.8.5/style.css +#usr/share/doc/expat-2.9.0 +#usr/share/doc/expat-2.9.0/ok.min.css +#usr/share/doc/expat-2.9.0/reference.html +#usr/share/doc/expat-2.9.0/style.css #usr/share/doc/expat/AUTHORS #usr/share/doc/expat/changelog #usr/share/man/man1/xmlwf.1 diff --git a/lfs/expat b/lfs/expat index b5f9466e4..d47d3833f 100644 --- a/lfs/expat +++ b/lfs/expat @@ -24,7 +24,7 @@ include Config -VER = 2.8.5 +VER = 2.9.0 THISAPP = expat-$(VER) DL_FILE = $(THISAPP).tar.xz @@ -40,7 +40,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 7d10459714722c6e4e858da92d3f7def6950240275ad5054b97f5d7612524f2813b8add75d6693698c8e7cdb4a64f73750346783e438ff6271dbc80643d51ee7 +$(DL_FILE)_BLAKE2 = b029962cd2ea06fbbe922837e6c708512a5c77a4617ee399779788ffe91537533d8c66e0ca63e0b92b76da8e84c10fa82216f27a6e48b16b898905b06e116562 install : $(TARGET)