[compiler-rt][msan] Ignore addrinfo padding in getaddrinfo interceptor (#219124)
Avoid checking padding bytes in `struct addrinfo` in the `getaddrinfo`
interceptor.
The interceptor used a single `COMMON_INTERCEPTOR_READ_RANGE` for the
whole structure, which caused MSan to report uninitialized padding even
when all
named members were initialized.
Check each member separately instead.
Testing
- Added `getaddrinfo-padding.cpp` to cover the padding case
- Verified the new test fails before the fix and passes after the change
- Verified `getaddrinfo-positive.cpp` still reports uninitialized fields
- Ran `ninja -C build/runtimes/runtimes-bins check-msan` on AArch64
Linux
Fixes #162216
security/libdecaf: Update to v1.0.5
Changes since v1.0.3:
September 21, 2026:
* Fix a git snafu. Tagged as v1.0.4a. But on second thought (and
thoughts by Johan Pascal) maybe this version number will confuse
version control tools. Let's call it v1.0.5.
September 20, 2026:
* Fix an RFC compliance mistake reported by Ryan Culpepper.
RFC 7748 mandates that the last bit of an x25519 public key
u-coordinate be masked off, in case the protocol is using this for
something else. I have fixed this bug and added a test to verify
that it is fixed.
* Release v1.0.4.
py-setproctitle: updated to 1.3.8
1.3.8
- Add support for Python 3.15.
- Fix segfault calling setproctitle() after clearenv() on Python 3.15.
- Add support for riscv64.
py-meson_python: updated to 0.22.1
0.22.1
- Do not remove absolute build RPATH entries, unless pointing within the
build directory. Fixes an issue when using system compilers in a conda
environment.
patchelf: updated to 0.19.2
0.19.2
A bug fix release for rewriting executables after stripping.
Bug fixes
Fix executable corruption when patching again after strip removes padding between load segments, as seen when bootstrapping GHC. Rewritten sections and program headers now use the address mapping of the load segment covering the ELF header.
Avoid allocating an unnecessary extra page when growing executable sections, while keeping split load segments from overlapping after page alignment.
[clang][bytecode] Skip `emitInitScope` for `EvalEmitter` (#228092)
The opcode ultimately doesn't do anything in `EvalEmitter`, so try to
skip it as early as possible.
[CIR] Upstream missing support for floating point unary operator (#193215)
- Add Support for `__bf16/Float16/bfloat16/float128` scalar pre/post
increment and decrement.
- Add support for float vector increment and decrement, and add test
cases for both float vector and integer vector.
- Add test case for __bf16/Float16/bfloat16/double/long double/
float128 scalar unary operator with target `x86_64`.
- Part of task https://github.com/llvm/llvm-project/issues/192316
httpd: add header block/drop rules for request filtering
With this incoming requests can also be rejected based on the value of a
request header. Valid options are:
header block name value code [arg]
Close the connection with an error response when a
request header matches. Both name and value are shell-
style patterns and are matched case-insensitively against
the header name and value. code must be a valid HTTP
status code. For codes in the 3xx range, arg is required
and sent as the "Location" header. It must start with
"http://" or "https://". For all other codes, arg is
optional and used as the log message identifying the
rule.
header drop name value
Silently close the connection without sending a response
when a request header matches, using the same pattern
[10 lines not shown]
sys/param.h: Welcome to 11.99.9!
This version arises out of an abundance of caution in the slim chance
that anything is affected by the change in the signature of
sbappendcontrol to return void instead of a boolean indicating
success or failure; the caller is now (and, really, was already)
responsible for checking buffer sizes.
PR kern/60832: AF_LOCAL stream: sendmsg() with SCM_RIGHTS silently
drops data and descriptors but reports success
[llvm-profdata] Propagate Error in loadInput and mergeWriterContexts
Propagate Error from loadInput and mergeWriterContexts in mergeInstrProfile,
supplementInstrProfile, and overlapInstrProfile. In mergeInstrProfile's
ThreadPool, catch errors from worker threads, stop scheduling new jobs,
and return the first encountered fatal error.
Ensure ~WriterContext() consumes any pending unhandled errors in
WriterContext::Errors upon destruction.
Not NFC as destructors are run on the stack and ThreadPool workers exit
earlier on error.
With all subcommands propagating llvm::Error to main, exitWithError,
exitWithErrorCode, and the LSan leak suppression workaround are no
longer needed.
Assisted-by: Gemini
[NFCI][llvm-profdata] Propagate Error in merge subcommand (#228157)
Change merge_main and its helpers to return Error and handle it
with reportError in main.
Not NFC as destructors are run on the stack.
Assisted-by: Gemini
relayd: apply the header length limit to chunk size and trailer lines
Chunk size and trailer lines were not limited, so a line without line
ending could be buffered without bound. Limit each chunk size line and
the whole trailer to the configured header length and close the
session if they exceed it.
Spotted by Acts1631 (with diff), OK kirill@
[compiler-rt] Remove dlsym interceptor and support `-shared-libsan` for CSan
Summary:
Follow the UBSan offload runtime. Offload now resolves HSA through the
global scope, so the `dlsym` interceptor is no longer needed. The real
HSA entry points are still taken from the loaded HSA library rather than
`RTLD_NEXT`, since every DSO with a static runtime exports the same
wrappers and they would otherwise chain back into each other.
Build `libclang_rt.csan.so` with the offload objects folded in. The
exported HSA wrappers report failure when HSA is absent and warn when HSA
was loaded ahead of the runtime. The preinit hook moves to a separate
`csan_offload-preinit` archive for executables.
[compiler-rt] Add 'csan' library for the concurrency sanitizer
Summary:
Adds the runtime for the concurrency sanitizer, both CPU and GPU.
Fundamentally, this works using the following pseudocode:
```c
static u64 watchpoints[N]; // Hash-indexed, zero is empty.
// Emitted before the access, so we never trip on our own write.
void check_access(volatile void *addr, u32 size, u32 type) {
// Every access probes. A read conflicts only with a watched write, a
// write conflicts with either.
if (u64 *wp = find_watchpoint(addr, size, type))
consume(wp, this_pc()); // Hand our location to the owner.
if (!should_sample()) // Wave-uniform, 1-in-N chance.
return;
[17 lines not shown]
[Clang] Support `-shared-libsan` for offload CSan
Summary:
Follow the UBSan handling. The shared runtime embeds the HSA
interceptors, so `csan_offload` is only linked with static runtimes and
executables pull in `csan_offload-preinit` to initialize early.