LLVM/project 29e6b15 — compiler-rt/lib/sanitizer_common sanitizer_common_interceptors.inc, compiler-rt/test/msan getaddrinfo-positive.cpp getaddrinfo-padding.cpp

[compiler-rt][msan] Ignore addrinfo padding in getaddrinfo interceptor (#219124)

Avoid checking padding bytes in `struct addrinfo` in the `getaddrinfo`
interceptor.

The interceptor used a single `COMMON_INTERCEPTOR_READ_RANGE` for the
whole structure, which caused MSan to report uninitialized padding even
when all
named members were initialized.

Check each member separately instead.

Testing
- Added `getaddrinfo-padding.cpp` to cover the padding case
- Verified the new test fails before the fix and passes after the change
- Verified `getaddrinfo-positive.cpp` still reports uninitialized fields
- Ran `ninja -C build/runtimes/runtimes-bins check-msan` on AArch64
Linux

Fixes #162216
DeltaFile
+27-0compiler-rt/test/msan/getaddrinfo-padding.cpp
+24-2compiler-rt/lib/sanitizer_common/sanitizer_common_interceptors.inc
+25-0compiler-rt/test/sanitizer_common/TestCases/getaddrinfo.cpp
+1-1compiler-rt/test/msan/getaddrinfo-positive.cpp
+77-34 files

NetBSD/pkgsrc ZXKokqM — doc CHANGES-2026

   doc: Updated security/libdecaf to 1.0.5
VersionDeltaFile
1.6584+6-1doc/CHANGES-2026
+6-11 files

NetBSD/pkgsrc Ddpksec — doc CHANGES-2026

   Updated devel/patchelf, devel/py-meson_python, time/py-tempora, sysutils/py-setproctitle
VersionDeltaFile
1.6583+5-1doc/CHANGES-2026
+5-11 files

NetBSD/pkgsrc ZrXdQdD — security/libdecaf Makefile distinfo

   security/libdecaf: Update to v1.0.5

   Changes since v1.0.3:

   September 21, 2026:

     * Fix a git snafu.  Tagged as v1.0.4a.  But on second thought (and
       thoughts by Johan Pascal) maybe this version number will confuse
       version control tools.  Let's call it v1.0.5.

   September 20, 2026:

     * Fix an RFC compliance mistake reported by Ryan Culpepper.

       RFC 7748 mandates that the last bit of an x25519 public key
       u-coordinate be masked off, in case the protocol is using this for
       something else.  I have fixed this bug and added a test to verify
       that it is fixed.

     * Release v1.0.4.
VersionDeltaFile
1.7+4-4security/libdecaf/distinfo
1.11+2-2security/libdecaf/Makefile
+6-62 files

NetBSD/pkgsrc vxJcZ8k — sysutils/py-setproctitle Makefile distinfo

   py-setproctitle: updated to 1.3.8

   1.3.8
   - Add support for Python 3.15.
   - Fix segfault calling setproctitle() after clearenv() on Python 3.15.
   - Add support for riscv64.
VersionDeltaFile
1.19+4-4sysutils/py-setproctitle/distinfo
1.19+3-3sysutils/py-setproctitle/Makefile
+7-72 files

NetBSD/pkgsrc T3OWFpY — time/py-tempora PLIST Makefile

   py-tempora: updated to 5.13.0

   5.13.0
   Unknown changes
VersionDeltaFile
1.21+4-4time/py-tempora/distinfo
1.13+2-2time/py-tempora/PLIST
1.32+2-2time/py-tempora/Makefile
+8-83 files

NetBSD/pkgsrc PKvDRFv — devel/py-meson_python Makefile distinfo

   py-meson_python: updated to 0.22.1

   0.22.1

   - Do not remove absolute build RPATH entries, unless pointing within the
     build directory. Fixes an issue when using system compilers in a conda
     environment.
VersionDeltaFile
1.14+4-4devel/py-meson_python/distinfo
1.15+3-3devel/py-meson_python/Makefile
+7-72 files

NetBSD/pkgsrc jBp79KC — devel/patchelf Makefile distinfo

   patchelf: updated to 0.19.2

   0.19.2

   A bug fix release for rewriting executables after stripping.

   Bug fixes

   Fix executable corruption when patching again after strip removes padding between load segments, as seen when bootstrapping GHC. Rewritten sections and program headers now use the address mapping of the load segment covering the ELF header.
   Avoid allocating an unnecessary extra page when growing executable sections, while keeping split load segments from overlapping after page alignment.
VersionDeltaFile
1.18+4-4devel/patchelf/distinfo
1.21+2-2devel/patchelf/Makefile
+6-62 files

LLVM/project 5b5d81c — clang/lib/AST/ByteCode Compiler.cpp

[clang][bytecode] Skip `emitInitScope` for `EvalEmitter` (#228092)

The opcode ultimately doesn't do anything in `EvalEmitter`, so try to
skip it as early as possible.
DeltaFile
+5-2clang/lib/AST/ByteCode/Compiler.cpp
+5-21 files

FreeBSD/ports aa93431 — math/R-cran-psych Makefile distinfo

math/R-cran-psych: Update to 2.6.9

Changelog: https://cran.r-project.org/web/packages/psych/news.html
DeltaFile
+3-3math/R-cran-psych/distinfo
+1-1math/R-cran-psych/Makefile
+4-42 files

LLVM/project d6db026 — clang/lib/CIR/CodeGen CIRGenExprScalar.cpp, clang/lib/CIR/Lowering/DirectToLLVM LowerToLLVM.cpp

[CIR] Upstream missing support for floating point unary operator (#193215)

- Add Support for `__bf16/Float16/bfloat16/float128` scalar pre/post
   increment and decrement.
- Add support for float vector increment and decrement, and add test
  cases for both float vector and integer vector.
- Add test case for __bf16/Float16/bfloat16/double/long double/
  float128 scalar unary operator with target `x86_64`.
- Part of task https://github.com/llvm/llvm-project/issues/192316
DeltaFile
+1,936-182clang/test/CIR/CodeGen/unary.cpp
+43-29clang/lib/CIR/CodeGen/CIRGenExprScalar.cpp
+8-10clang/test/CIR/CodeGen/long-double-inc-dec.cpp
+5-10clang/lib/CodeGen/CGExprScalar.cpp
+3-2clang/lib/CIR/Lowering/DirectToLLVM/LowerToLLVM.cpp
+2-2clang/test/CIR/CodeGenOpenACC/atomic-update.cpp
+1,997-2356 files

LLVM/project 1aeecf7 — clang/lib/AST/ByteCode Compiler.cpp

[clang][bytecode][NFC] Remove unnecessary std::move call (#228083)
DeltaFile
+1-1clang/lib/AST/ByteCode/Compiler.cpp
+1-11 files

LLVM/project f10d96f —

[bazel] Replace various genrules with bazel_skylib rules (#228170)
DeltaFile
+0-00 files

OpenBSD/src i6ugJKo — usr.sbin/httpd server.c httpd.conf.5

   httpd: add header block/drop rules for request filtering

   With this incoming requests can also be rejected based on the value of a
   request header. Valid options are:

   header block name value code [arg]
           Close the connection with an error response when a
           request header matches.  Both name and value are shell-
           style patterns and are matched case-insensitively against
           the header name and value.  code must be a valid HTTP
           status code.  For codes in the 3xx range, arg is required
           and sent as the "Location" header.  It must start with
           "http://" or "https://".  For all other codes, arg is
           optional and used as the log message identifying the
           rule.

   header drop name value
           Silently close the connection without sending a response
           when a request header matches, using the same pattern

    [10 lines not shown]
VersionDeltaFile
1.78+126-1usr.sbin/httpd/config.c
1.139+102-1usr.sbin/httpd/parse.y
1.172+50-1usr.sbin/httpd/server_http.c
1.137+35-2usr.sbin/httpd/httpd.conf.5
1.185+36-1usr.sbin/httpd/httpd.h
1.140+21-1usr.sbin/httpd/server.c
+370-71 files not shown
+390-87 files

OpenBSD/src ROswo2p — regress/usr.sbin/relayd args-http-chunked-trailer-unterminated.pl

   Test unterminated chunk trailer lines against the header length limit
VersionDeltaFile
1.1+29-0regress/usr.sbin/relayd/args-http-chunked-trailer-unterminated.pl
+29-01 files

NetBSD/src qEp63w8 — sys/sys param.h

   sys/param.h: Welcome to 11.99.9!

   This version arises out of an abundance of caution in the slim chance
   that anything is affected by the change in the signature of
   sbappendcontrol to return void instead of a boolean indicating
   success or failure; the caller is now (and, really, was already)
   responsible for checking buffer sizes.

   PR kern/60832: AF_LOCAL stream: sendmsg() with SCM_RIGHTS silently
   drops data and descriptors but reports success
VersionDeltaFile
1.748+2-2sys/sys/param.h
+2-21 files

NetBSD/pkgsrc-wip 8e2aec8 — rust-beta Makefile distinfo, rust-beta/patches patch-vendor_libc-0.2.168_src_unix_bsd_netbsdlike_netbsd_mod.rs patch-src_bootstrap_src_lib.rs

rust-beta: update to 1.100.0 beta.1
DeltaFile
+0-40rust-beta/patches/patch-src_bootstrap_src_lib.rs
+40-0rust-beta/patches/patch-src_bootstrap_src_core_session.rs
+10-11rust-beta/distinfo
+0-15rust-beta/patches/patch-vendor_libc-0.2.168_src_unix_bsd_netbsdlike_netbsd_mod.rs
+4-3rust-beta/Makefile
+54-695 files

LLVM/project d6c1811 — llvm/tools/llvm-profdata llvm-profdata.cpp

[llvm-profdata] Propagate Error in loadInput and mergeWriterContexts

Propagate Error from loadInput and mergeWriterContexts in mergeInstrProfile,
supplementInstrProfile, and overlapInstrProfile. In mergeInstrProfile's
ThreadPool, catch errors from worker threads, stop scheduling new jobs,
and return the first encountered fatal error.

Ensure ~WriterContext() consumes any pending unhandled errors in
WriterContext::Errors upon destruction.

Not NFC as destructors are run on the stack and ThreadPool workers exit
earlier on error.

With all subcommands propagating llvm::Error to main, exitWithError,
exitWithErrorCode, and the LSan leak suppression workaround are no
longer needed.

Assisted-by: Gemini
DeltaFile
+64-41llvm/tools/llvm-profdata/llvm-profdata.cpp
+64-411 files

LLVM/project 9f8331d — llvm/tools/llvm-profdata llvm-profdata.cpp

[NFCI][llvm-profdata] Propagate Error in merge subcommand (#228157)

Change merge_main and its helpers to return Error and handle it
with reportError in main.

Not NFC as destructors are run on the stack.

Assisted-by: Gemini
DeltaFile
+146-127llvm/tools/llvm-profdata/llvm-profdata.cpp
+146-1271 files

NetBSD/src uqNxBeF — usr.sbin/cpuctl/arch i386.c

   Update Cyrix CPU models.

   Joshua was never released,  but some working samples exist in the wild.
VersionDeltaFile
1.151+4-4usr.sbin/cpuctl/arch/i386.c
+4-41 files

OpenBSD/src amMY1R3 — usr.sbin/relayd relay_http.c

   relayd: apply the header length limit to chunk size and trailer lines

   Chunk size and trailer lines were not limited, so a line without line
   ending could be buffered without bound. Limit each chunk size line and
   the whole trailer to the configured header length and close the
   session if they exceed it.

   Spotted by Acts1631 (with diff), OK kirill@
VersionDeltaFile
1.106+22-1usr.sbin/relayd/relay_http.c
+22-11 files

LLVM/project a22dd47 — compiler-rt/lib/csan csan.cpp, compiler-rt/test/csan access-sizes.cpp

Use unaligned loads when snapshotting watched values
DeltaFile
+22-0compiler-rt/test/csan/access-sizes.cpp
+3-3compiler-rt/lib/csan/csan.cpp
+25-32 files

LLVM/project 5771c0f — compiler-rt/lib/csan csan_gpu.cpp csan.cpp, compiler-rt/test/csan volatile.cpp

Remove separate volatile entry points
DeltaFile
+49-0compiler-rt/test/csan/volatile.cpp
+22-0compiler-rt/test/csan/AMDGPU/volatile.hip
+0-4compiler-rt/lib/csan/csan_gpu.cpp
+0-4compiler-rt/lib/csan/csan.cpp
+71-84 files

LLVM/project 4d1d7ce — compiler-rt/lib/csan CMakeLists.txt, compiler-rt/lib/csan/offload csan_offload_preinit.cpp CMakeLists.txt

[compiler-rt] Remove dlsym interceptor and support `-shared-libsan` for CSan

Summary:
Follow the UBSan offload runtime. Offload now resolves HSA through the
global scope, so the `dlsym` interceptor is no longer needed. The real
HSA entry points are still taken from the loaded HSA library rather than
`RTLD_NEXT`, since every DSO with a static runtime exports the same
wrappers and they would otherwise chain back into each other.

Build `libclang_rt.csan.so` with the offload objects folded in. The
exported HSA wrappers report failure when HSA is absent and warn when HSA
was loaded ahead of the runtime. The preinit hook moves to a separate
`csan_offload-preinit` archive for executables.
DeltaFile
+34-98compiler-rt/lib/csan/offload/csan_offload_hsa_interceptors.cpp
+84-9compiler-rt/lib/csan/CMakeLists.txt
+35-0compiler-rt/test/csan/hsa-load-order.cpp
+22-4compiler-rt/lib/csan/offload/CMakeLists.txt
+24-0compiler-rt/test/csan/hsa-missing.cpp
+22-0compiler-rt/lib/csan/offload/csan_offload_preinit.cpp
+221-1115 files not shown
+241-11111 files

LLVM/project cdbaef0 — compiler-rt/cmake config-ix.cmake, compiler-rt/cmake/Modules AllSupportedArchDefs.cmake

comments
DeltaFile
+13-9compiler-rt/lib/csan/csan_gpu.cpp
+3-3compiler-rt/cmake/config-ix.cmake
+2-2compiler-rt/lib/csan/CMakeLists.txt
+1-1compiler-rt/test/csan/CMakeLists.txt
+1-1compiler-rt/lib/csan/offload/CMakeLists.txt
+1-0compiler-rt/cmake/Modules/AllSupportedArchDefs.cmake
+21-166 files

LLVM/project 9007828 — compiler-rt/lib/csan csan_watch.h csan_report.cpp, compiler-rt/lib/csan/offload csan_offload_report.cpp csan_offload_hsa_interceptors.cpp

[compiler-rt] Add 'csan' library for the concurrency sanitizer

Summary:
Adds the runtime for the concurrency sanitizer, both CPU and GPU.
Fundamentally, this works using the following pseudocode:

```c
static u64 watchpoints[N]; // Hash-indexed, zero is empty.

// Emitted before the access, so we never trip on our own write.
void check_access(volatile void *addr, u32 size, u32 type) {
    // Every access probes. A read conflicts only with a watched write, a
    // write conflicts with either.
    if (u64 *wp = find_watchpoint(addr, size, type))
        consume(wp, this_pc()); // Hand our location to the owner.

    if (!should_sample()) // Wave-uniform, 1-in-N chance.
        return;


    [17 lines not shown]
DeltaFile
+456-0compiler-rt/lib/csan/csan_gpu.cpp
+370-0compiler-rt/lib/csan/offload/csan_offload_hsa_interceptors.cpp
+334-0compiler-rt/lib/csan/csan.cpp
+279-0compiler-rt/lib/csan/csan_report.cpp
+184-0compiler-rt/lib/csan/offload/csan_offload_report.cpp
+163-0compiler-rt/lib/csan/csan_watch.h
+1,786-044 files not shown
+2,940-250 files

LLVM/project c8a0ebb — clang/lib/Driver/ToolChains CommonArgs.cpp, clang/test/Driver fsanitize.c fsanitize-concurrency-offload.c

[Clang] Support `-shared-libsan` for offload CSan

Summary:
Follow the UBSan handling. The shared runtime embeds the HSA
interceptors, so `csan_offload` is only linked with static runtimes and
executables pull in `csan_offload-preinit` to initialize early.
DeltaFile
+38-0clang/test/Driver/fsanitize-concurrency-offload.c
+9-4clang/lib/Driver/ToolChains/CommonArgs.cpp
+3-1clang/test/Driver/fsanitize.c
+50-53 files

LLVM/project 6767083 — clang/test/CodeGen sanitize-concurrency.c, clang/test/CodeGen/Inputs sanitize-concurrency-ignorelist.txt

ignore
DeltaFile
+29-0clang/test/CodeGen/sanitize-concurrency.c
+2-0clang/test/CodeGen/Inputs/sanitize-concurrency-ignorelist.txt
+31-02 files

LLVM/project 1ddebe8 — llvm/lib/Transforms/Instrumentation ConcurrencySanitizer.cpp

enum class and return Res
DeltaFile
+20-14llvm/lib/Transforms/Instrumentation/ConcurrencySanitizer.cpp
+20-141 files

LLVM/project caa7bd0 — clang/lib/Driver SanitizerArgs.cpp, clang/lib/Driver/ToolChains AMDGPU.cpp CommonArgs.cpp

Comments
DeltaFile
+48-0clang/test/Driver/fsanitize-concurrency-offload.c
+27-0clang/test/Driver/fsanitize.c
+16-7clang/lib/Driver/ToolChains/Clang.cpp
+11-4clang/lib/Driver/SanitizerArgs.cpp
+5-6clang/lib/Driver/ToolChains/CommonArgs.cpp
+3-2clang/lib/Driver/ToolChains/AMDGPU.cpp
+110-195 files not shown
+112-2111 files