tor: update to 0.4.9.14.
Changes in version 0.4.9.14 - 2026-10-07
Another week, another security release. This again contains major bugfixes
related to high severity issues. The fixes affect all Tor components: relay,
client, onion service and authority. We strongly recommend upgrading as soon
as possible.
o Major bugfixes (conflux, relay, security):
- Only accept a CONFLUX_LINK cell on a plain OR circuit, and refuse
to turn a (pending) conflux leg into an introduction or rendezvous
point. Previously a client could link a rendezvous-point circuit
into a conflux set and then, with a forged sequence number in the
LINK cell, make the relay tear the set down from inside the
rendezvous splice, triggering a fatal assertion in
assert_circuit_ok(). Also reject a LINK/LINKED cell whose
last_seqno_recv is above what we ever sent on the set. Fixes bug
41328; bugfix on 0.4.8.1-alpha.
[114 lines not shown]
nodejs: updated to 26.11.1
26.11.1 (Current)
- Revert "build: toggle doc-kit verbosity based on V" (Antoine du Hamel)
- Revert "build, doc: move to redesign" (Antoine du Hamel)
- Revert "tools: bump the doc group in /tools/doc with 4 updates" (Antoine du Hamel)
cargo-nextest: updated to 0.9.148
0.9.148
Changed
For setup scripts, slow-timeout no longer accepts on-timeout = "pass", and nextest now reports a configuration error if it is specified. A setup script that times out always fails the run. Previously, this setting was accepted but handled inconsistently: the timed-out script was counted as a failure, but the run was not cancelled.
Internal dependency updates: guppy updated to 0.19.1, and target-spec updated to 3.7.0, updating built-in targets to Rust 1.98.
Fixed
Stress runs now exit with a non-zero code if any iteration failed. Previously, with fail-fast disabled, the exit code reflected only the last iteration, so a stress run with failures in earlier iterations exited with code 0 if the last iteration passed.
Stress runs now always run at least one iteration. Previously, --stress-duration with a very short duration (such as 1ns) could finish without running any tests.
Runs stopped by immediate fail-fast (--max-fail N:immediate) are now treated as failed rather than cancelled. Previously, in stress runs, the summary read 0 passed; cancelled due to test failure and the failing iteration was not counted as failed.
When the global timeout fires with immediate fail-fast enabled, nextest now reports the global timeout as the reason the run was cancelled. Previously, the tests terminated by the timeout counted as failures, so nextest printed a second Cancelling due to test failure line and reported a test failure as the reason.
[11 lines not shown]
net/dnscap: Update dnscap from version 1.4.1 (from 2015) to 2.5.1
Prompted by jperkin's MacOS 27 bulk build results
10+ years of changes are too many to summarise here, but TL;DR is that
+ there are a lot more dependencies (on a lot of archivers/compression
libraries), openssl, and ldns,
+ the package name in pkgsrc is now dnscap2,
+ and dnscap now supports plugins (${PREFIX}/bin/dnscap-rssm-rssac002
is one such).
tinyproxy: have rc.d script create /var/run/tinyproxy if missing
Have the example tinyproxy rc.d script in files/tinyproxy.sh create
the pid directory (@VARBASE@/run/tinyproxy) if it is not present
using start_precmd (e.g. as is done in /etc/rc.d/mdnsd). Needed
for cases where we reboot and /etc/rc.d/clearcritlocal deletes
the old pid directory from /var/run.
flawfinder: updated to 2.0.20
2.0.20
Fix unlikely vulnerabilities (involving malicious filenames/text
in analyzed systems) and implement various improvements
* Fix security vulnerabilities found by Gemini:
- Terminal injection in standard output: apply strip_controls() to
level and category in show().
- Terminal injection in CSV output: apply strip_controls() to all
untrusted fields in show_csv() (category, name, warning,
suggestion, note, context_text).
- XML injection in SonarQube output: use quoteattr() for all XML
attributes in output_sonar().
- Defense-in-depth: restrict setattr in Hit.__init__ to an allowlist
of known keys used by rule definitions, countering pickle attacks.
We previously warned to not load untrusted pickle files, but
completely preventing attacks is better.
- Shell injection in CI/CD file entrypoint.sh:
quoted args with "$@" and moved output filename to
[86 lines not shown]
py-cachetools: updated to 7.2.1
v7.2.1 (2026-10-05)
- Improve error handling for ``RRCache.popitem()`` when the cache is
empty.
- Minor style and documentation improvements.
- Update CI environment.
v7.2.0 (2026-09-16)
- Deprecate use of ``cache=None`` to suppress caching with the
``@cached`` decorator.
- Add support for Python 3.15.
- Minor test improvements.
- Minor documentation updates.