cyrus-imapd312: Update to Cyrus IMAPd 3.12.4.
____________________________________________________________________________________________
Cyrus IMAP 3.12.4 Release Notes
Changes since 3.12.3
Security fixes
* CVE-2026-61907: JMAP snooze bypasses destination-mailbox ACL
An authenticated user with insert permissions on another user's snoozed mailbox could cause
insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to
the user, despite having no insert permissions to the target mailbox.
Reported by: Michael Lynch (mtlynch.io).
* CVE-2026-61908: JMAP email-header blob ID out-of-bounds index
An authenticated user could attempt to download a specially crafted JMAP blob ID of the form
H<emailid>-<index>, which could read past the end of the internal blob_headers array during
download, exposing adjacent heap memory.
[136 lines not shown]
Update to 0.000005
Upstream changes:
0.000005 2026-04-17 11:29:35-07:00 America/Los_Angeles
- Require Importer 0.025+ so `use Importer Importer => 'import'` works
(older Importer versions like 0.014 lack 'import' in IMPORTER_MENU,
causing "Importer does not export &import" at load time)
0.000004 2026-04-15 14:34:09-07:00 America/Los_Angeles
- Add havejump() to check if a named jump point is currently set
Update to 3.101
Upstream changes:
3.101 2026-04-13 13:31:24-04:00 America/New_York
- fix auto-using of Log::Fmt::XS, which was straight up broken
3.100 2026-04-01 10:35:56-04:00 America/New_York
- when present, use Log::Fmt::XS for emitting logfmt
- abstract out logfmt tests for use in both Log::Fmt and Log::Fmt::XS
test suites (but don't consider this public yet)
3.013 2025-10-15 10:12:50-04:00 America/New_York
- typo fixes and spec clarifications
3.012 2025-10-14 12:39:48-04:00 America/New_York
- [ BREAKING CHANGE (BARELY) ]
Log::Fmt now includes a formal specification of the logfmt grammar we
implement, as well as a description of algorithmns to correctly
encode strings. The code has been updated to fall in line, meaning:
[4 lines not shown]
Update to 1.19
Upstream changes:
1.19 2026-07-06
- Fix mass CPAN tester FAILs on OpenBSD (29 of 32 reports for 1.18): the
smoker host's 10 SysV semaphore-set slots (kern.seminfo.semmni=10) were
pre-exhausted by stale sets leaked from previously crashed runs, so
nearly every tie died with semget ENOSPC ("Could not create semaphore
set: No space left on device"), and each failing run leaked further
resources
- _tie(): an IPC_PRIVATE segment is now removed when semaphore-set
creation (or the initial lock) fails. shmget(IPC_PRIVATE) always
creates a fresh segment regardless of the 'create' attribute, and a
private segment is unreachable by key after the croak, so it leaked
invisibly (~4 segments per failed suite run on the wedged smoker)
- clean_up_testing(): added a second pass that reclaims orphaned
testing-tagged semaphore sets whose segment is already gone; these pin
a SEMMNI slot forever and were invisible to the ipcs -m based scan.
New regression test t/82-stale-ipc-reclaim.t
[261 lines not shown]
Update to Cyrus IMAPd 3.10.4.
Cyrus IMAP 3.10.4 Release Notes
Changes since 3.10.3
Security fixes
* CVE-2026-61907: JMAP snooze bypasses destination-mailbox ACL
An authenticated user with insert permissions on another user's snoozed mailbox could cause
insertion of mail to that user's inbox, or any other of their mailboxes whose id was known to
the user, despite having no insert permissions to the target mailbox.
Reported by: Michael Lynch (mtlynch.io).
* CVE-2026-61908: JMAP email-header blob ID out-of-bounds index
An authenticated user could attempt to download a specially crafted JMAP blob ID of the form
H<emailid>-<index>, which could read past the end of the internal blob_headers array during
download, exposing adjacent heap memory.
Reported by: Ahmed Said.
* CVE-2026-61909: CalDAV/CardDAV multiget bypasses per-href ACL
[35 lines not shown]
Update to 20260402.0
Upstream changes:
20260402.0 Thu Apr 2 2026
Bug fixes:
- GH #271, GH #164 - Detect undefined command in arrayref at harness parse
time instead of deferring to start() (PR #272)
- pipe_writer drops input when data is the string "0" due to redundant
boolean test on input buffer (PR #264)
- Callback filter evaluates return in list context to distinguish empty
return from the string "0", preventing infinite loop on Win32 (PR #264)
- GH #240 - Skip pty output assertions on BSD/Darwin due to known pty
drain timing issues on short-lived children (PR #274)
- Implement proper Windows command-line parsing per Microsoft C/C++ rules,
fixing argument parsing failures with single-quoted strings containing
whitespace (PR #273)
Maintenance:
- Add shebang to eg/synopsis_scripting (PR #275)
20260401.0 Wed Apr 1 2026
[108 lines not shown]
Update to 1.31
Upstream changes:
1.31 2026-05-24 Todd Rinaldo <toddr at cpan.org>
Bug Fixes:
* GH #91, PR #94 - Fix v1.27 regression where _open_tty() always passed
O_NOCTTY, preventing make_slave_controlling_terminal() from acquiring
a controlling terminal via the POSIX-standard open-without-O_NOCTTY
mechanism (it was forced to fall through to an explicit TIOCSCTTY
ioctl). _open_tty() now takes an optional noctty flag (default 1 for
backward compatibility); make_slave_controlling_terminal() passes 0.
* GH #92, PR #93 - Fix openpty() detection on Fedora 33-34 / glibc
2.32-2.33 where LTO flags (-flto=auto) caused the libc-only compile
probe to falsely succeed, producing "undefined symbol: openpty" at
runtime. Try -lutil before libc; harmless on systems where openpty
lives in libc (glibc 2.34+, musl) and necessary where it doesn't.
Maintenance:
* PR #90 - Address CPANTS kwalitee issues: add LICENSE, SECURITY.md,
and CONTRIBUTING.md; add META `provides` for IO::Tty, IO::Pty, and
[172 lines not shown]
Update to 0.08
Upstream changes:
0.08 Thu Apr 02 2026
Bug fixes:
- Fix Perl 5.8 compatibility: replace // (defined-or) operator with
ternary equivalent. The // operator requires Perl 5.10 but
MIN_PERL_VERSION is 5.008. (GH #28, GH #29, PR #30, PR #31)
- Implement crterase alias (was documented but never coded) and
correct dec/crt combination documentation to match actual behavior.
(PR #33)
- Add exta, extb, and 134.5 baud rate aliases that were documented
but silently rejected. (PR #32)
- Use _POSIX_VDISABLE for disabling special characters instead of
hardcoded 0, fixing 'undef'/'^-' on macOS/BSD where VDISABLE is
255. Also fix sane/cooked combos to use 'undef' for eol. (PR #37)
- Handle VEOF/VMIN and VEOL/VTIME shared cc slots on Solaris/SVR4
systems where these overlap in the termios cc array. (GH #38,
PR #42)
[96 lines not shown]
Update to 1.07
Upstream changes:
version 1.07: Mon 26 Jan 14:24:32 CET 2026
Fixes:
- Tie::StdHash needs to be compiled via Tie::Hash.
version 1.06: Mon 26 Jan 11:29:04 CET 2026
Changes:
- require Perl 5.16 (2015)
Improvements:
- convert Makefile.PL to OODoc 3.06.
- convert code and syntax to new preferences.
- add .gitignore
- add README.md
- improve documentation
prometheus: update to 3.13.4.
[SECURITY] Bump google.golang.org/grpc to v1.83.1 to fix HTTP/2
DATA frame fragmentation memory exhaustion (GO-2026-6348). #19834
[SECURITY] UI: Update vulnerable npm dependencies. #19834
[BUGFIX] Agent: Ignore unknown WAL record types to allow rolling
back from newer versions. #19814
[BUGFIX] Federation: Fix corruption of float native histograms.
#19679
[BUGFIX] Scrape: Fix failing scrapes of protobuf float histograms
with zero sample, zero and bucket counts, such as the result of
recording rate(x[1m]) over a constant histogram. #19682