chat/matrix-synapse: Update to 1.161.0
Tested on NetBSD 10 amd64 with 2026Q3 environment.
Packaging changes:
- use maturin's tool.mk, to get the part that respects MAKE_JOBS
- patch mio, which had a pre-NetBSD10 type for kevent.udata, a
latent bug apparently exposed by a new libc crate, but fixable on
its own merits by code inspection.
# Synapse 1.162.0 (2026-09-29)
## Features
- Raise default room version to "12". Contributed by @jason-famedly @famedly. ([\#20130](https://github.com/element-hq/synapse/issues/20130))
- Limit the number of end-to-end encryption one-time keys stored per device to 500 per algorithm, rejecting uploads which would exceed the limit with a `400 Bad Request`. ([\#20162](https://github.com/element-hq/synapse/issues/20162))
- Add support for configuring a `username` for Redis connections, for Redis 6+ ACL authentication. ([\#20187](https://github.com/element-hq/synapse/issues/20187))
- Add a rate limit on the client profile lookup endpoints, configurable via `rc_profile`. ([\#20218](https://github.com/element-hq/synapse/issues/20218))
www/monolith: update to 2.11.2
v2.11.2
- separate GUI binary to compliment CLI
v2.11.1
- concurrent retrieval of remote assets
- libssl is no longer a required dependency
v2.11.0
- MHTML output format (-m CLI flag)
- -D / --create-dirs CLI flag to automatically create non-existing directories
- bugfixes related to unwrapping of NOSCRIPT elements
- proper escaping of </script> tags within embedded JS
- fixed a bug related to not sending all Cookies
- webmanifest now gets embedded into the document
- SVG symbols no longer can embed the entire image
- properly handle module and importmap script types
sysutils/mirador: update to 1.21.0
1.21.0 - 2026-10-08
Changed
The Windows build carries the default config with the same line endings as every other build. It used to embed the file as the build machine's checkout wrote it, which on Windows is CRLF, so --print-config and the first-run config differed from macOS and Linux for no reason in the code. The repository now asks for LF everywhere. A config already on disk is untouched, and edits keep whatever endings it has.
Every dialog punches its title into the border. The w picker's PANELS and a prompt's label — ADD A CLOCK, WEATHER LOCATION, AGENDA FILE — were laid on the border bare, where the theme picker, the key map and every panel draw ┤TITLE├. All four dialogs now draw it the same way, and one too narrow for its title cuts it with … rather than letting the corner take the closing ├.
Fixed
An absurd pomodoro length is refused instead of overflowing. The three [pomodoro] lengths were checked only for being above zero, and the panel turns minutes into seconds unchecked, so a hand-edited length too large for that sum crashed a debug build and gave a release build a phase of some other length nobody wrote. Like the weather, markets and news refresh settings, each now stops at a year, and a config past it is refused with the key named.
--migrate-config no longer overwrites an earlier backup. It copied the original to config.toml.bak whether or not that name was taken, so the config a --reset-config had set aside there, or an earlier migration's backup, was replaced for good. It now takes the next free number, as the resets do.
The error for a key from an older version points at --migrate-config exactly when the migration would fix the file. The error kept its own list of those keys, and the list had three of the four the migration fixes, so a pre-0.1.0 [notes] side_by_side_min_width was told to read --print-config instead. It went by the key's name alone, where the migration also needs the right table, so forecast_days under [clocks] was sent to a migration that then refused it. And it promised an update in place wherever the key matched, though the migration writes nothing when the result would still not load: a forecast_hours added beside the stale forecast_days was refused as a duplicate. The error now asks the migration about the line the parser stopped on and whether it would finish. When it would, the error says what it will change; when it would not, it says what the line becomes and the first problem that stops the migration, by line.
The theme picker draws the theme it is previewing on a short terminal. Its list kept a twelve-row window in a dialog sixteen rows tall, so on a terminal under sixteen rows the foot of the window was cut, footer first, and End or ↓ previewed a theme whose name was nowhere on screen. The list now scrolls within the rows the terminal leaves it, as the w picker's does, the footer gives way to nothing but the row of the theme being previewed, and a page moves as far as the rows drawn.
A dialog's keys drop whole on a narrow terminal, and Esc goes last. The w and t pickers drew their key rows at full width and the terminal cut them wherever the edge fell — Esc put with no back, and narrower still the keep hint whole and Esc gone without a mark. The key map's row dropped from the end, so a narrow one said how to reload and not how to leave, and a prompt on a screen under twenty columns measured its help for the twenty it asked for. Every dialog's keys now drop whole, the way out last, and Esc on its own and still too wide ends in …, as a prompt's help already did.
The w picker says when it has cut a message. The line under its list gives way to what was just refused or why the config could not be written, and most of those are longer than the dialog's forty columns — the edited config does not describe the requested layout — so the terminal cut them at every size, with nothing to show the rest was missing. They now end in …, and so does the usual line on a narrow terminal.
One refresh of the watchlist asks for each symbol once. An r, or an added symbol, while the markets panel waited out the minute it leaves between rounds was answered by the next round and then again a minute later, so it cost two requests a symbol against a source that blocks by address. Removing a symbol also threw away an r pressed just before it, and the board waited out the whole interval instead.
The markets panel copies its board when a price lands, not every frame. It cloned every quote with its intraday series once a second, for numbers that change once a minute, and redrew each sparkline from the whole series. Both happen when a quote lands now. A quote also keeps at most a thousand intraday prices, averaged down rather than cut: the request asks for 78, and nothing stopped an answer carrying two million.
A long task or note list builds only the rows on screen. Every task and every note in the list was turned into a row on every frame, through an index of the whole store rebuilt each time, for a panel that drew the twenty that fit. Scrolling, the selection and clicks are as they were.
[94 lines not shown]
sysutils/lla: update to 0.6.6
[0.6.6] - 2026-10-07
Added
lla --license prints the full MIT license embedded in the executable,
including Windows releases. Windows usage documentation and release smoke
checks cover the license and all five supported completion shells.
Fixed
Shell completion generation now prints scripts to stdout by default for Bash,
Fish, Zsh, PowerShell, and Elvish. Use --output or --path to save a script
to a file.
jj: update to 0.46.0.
### Release highlights
* Jujutsu can now colocate workspaces besides the default one by creating Git
worktrees. Use `jj workspace add --[no-]colocate` and the setting
`git.colocate` to control this.
### Breaking changes
* The minimum supported `git` command version is now 2.42.0, up from 2.41.0.
`jj workspace add` uses `git worktree add --orphan`, which was added in
2.42.0.
* The minimum supported Rust version (MSRV) is now 1.97.1.
* `jj bisect run` now runs some consistency checks before proceeding to bisect.
This helps ensure that the command can tell good and bad revisions apart,
and that the working copy does go from bad to good over the provided revset.
[117 lines not shown]
PR kern/60861
don't change nvlist name for the route interface,
let old userland still be able to access it.
also update current to use it.
No functional change intended in current.
tor: update to 0.4.9.14.
Changes in version 0.4.9.14 - 2026-10-07
Another week, another security release. This again contains major bugfixes
related to high severity issues. The fixes affect all Tor components: relay,
client, onion service and authority. We strongly recommend upgrading as soon
as possible.
o Major bugfixes (conflux, relay, security):
- Only accept a CONFLUX_LINK cell on a plain OR circuit, and refuse
to turn a (pending) conflux leg into an introduction or rendezvous
point. Previously a client could link a rendezvous-point circuit
into a conflux set and then, with a forged sequence number in the
LINK cell, make the relay tear the set down from inside the
rendezvous splice, triggering a fatal assertion in
assert_circuit_ok(). Also reject a LINK/LINKED cell whose
last_seqno_recv is above what we ever sent on the set. Fixes bug
41328; bugfix on 0.4.8.1-alpha.
[114 lines not shown]