This fixes:
error: assignment to 'ICalDuration *' from 'int' makes pointer from integer without a cast [-Wint-conversion]
Evolution-Data-Server 3.60.2 2026-05-22
---------------------------------------
Bug Fixes:
I#637 - IMAPx: Sent folder reverts to default with iCloud email and Quick Resync
evo-I#3302 - Truncated file stored in the (mail) cache
Miscellaneous:
e-ms-oapxbc: Simplify error handling in MS-OAPXBC OIDC extension
e-ms-oapxbc: Fix error handling of broker response
e-ms-oapxbc: Align D-Bus parameters with sso-mib (Felix Moessbauer)
e-ms-oapxbc: Add support for broker versions > 2.0.1 (Felix Moessbauer)
Do not lock SExp object in data book/cal views start
e-book-meta-backend: Handle data: URI-s in PHOTO/LOGO
Calendar: Use icaldurationtype_as_utc_seconds() for libical 4.x (Antonio Rojas)
OAuth2: Use its own error domain and add camel_util_is_network_error()
Translations:
Christian Kirbach (de)
Evolution-Data-Server 3.60.1 2026-04-10
---------------------------------------
Bug Fixes:
I#632 - nntp: Fix GSocket ref leak in stream timeout helpers (Mikhail Gavrilov)
Miscellaneous:
nntp: Rename nntp_get_stream_socket() to nntp_ref_stream_socket()
ESoupSession: Correct e_soup_session_get_authentication_requires_credentials()
Evolution-Data-Server 3.60.0 2026-03-13
---------------------------------------
Bug Fixes:
I#489 - Backends: Do not block views' start by slow connection
Miscellaneous:
Correct ICalGLib reference in gir when building against version 4
docs: Update libical-glib online documentation link
Translations:
Asier Saratsua Garmendia (eu)
Aurimas Aurimas Černius (lt)
Balázs Úr (hu)
Baurzhan Muftakhidinov (kk)
Bruce Cowan (en_GB)
Daniel Rusek (cs)
Evolution-Data-Server 3.59.3 2026-02-27
---------------------------------------
Bug Fixes:
I#444 - Make credential prompt dialog non-modal
I#625 - camel-sasl-ntlm: Check for integer overflow in ntlm_get_string()
I#626 - camel-pop3-store: Compute APOP response without string allocation
I#627 - Canonicalize path before local cache file removal
I#628 - e-cal-recur: Check interval intersect always as date-time value
evo-I#3257 - NNTP: Subscription dialog does not show all groups
Miscellaneous:
e-collection-backend: Fix possible memory leak
Use GHashTable's `replace()` instead of `insert()` on some places
e-name-western: Crash due to double quotes in the name
camel-network-service: Move static variable to read-only area
credential-prompters: Add some spacing around widgets in the dialog (gtk4)
camel-store-search: Minimize hold of the folder and folder summary locks
camel-debug: Include object address in ref/unref backtraces
Increase default connection timeout to 30 seconds
Translations:
Alan Mortensen (da)
Anders Jonsson (sv)
Christian Kirbach (de)
Jean-Marc TISSIERES (fr)
Jordi Mas (ca)
Miloš Popović (sr)
Miloš Popović (sr@latin)
Sabri Ünal (tr)
twlvnn kraftwerk (bg)
Evolution-Data-Server 3.59.2 2026-01-30
---------------------------------------
Bug Fixes:
I#617 - Calendar: Prepare to support build with libical 4.x
M!206 - docs: Document libical-glib as dependency (Juan Luis Cano Rodríguez)
Miscellaneous:
Correct few developer comments
Calendar: Correct typo in error message
Fix a compiler warning in camel-network-service.c
e-book-utils: Correct read of a certificate from a vCard attribute
Add ESourceConflictSearch from Evolution
Translations:
Aurimas Aurimas Černius (lt)
Ekaterine Papava (ka)
Juliano de Souza Camargo (pt_BR)
Martin (sl)
Yuri Chornoivan (uk)
Evolution-Data-Server 3.59.1 2026-01-02
---------------------------------------
Bug Fixes:
I#8 - Support vCard v4.0 (RFC 6350)
I#554 - CalDAV: Provide a date limit for information sync
I#609 - Camel: Encrypt Recipient Alias Configuration
I#612 - Calendar: Multiple detached instances cause duplicates
I#613 - Camel: Message info changes do not propagate sometimes
I#614 - CamelSearchFolder: Add "not_all" "match-threads" kind
I#616 - Crash when reading broken multipart/signed
I#618 - Calendar: Free/busy not exported without set calendar mail
I#620 - alarm-notify: Snooze "until X minutes before start" wrongly reminds "X min after start"
I#621 - addressbook-export: Fails with "Invalid query" error
M!201 - Camel: Remove camel_session_ref_service_by_url (Corentin Noël)
M!203 - Remove several migration functions from Evolution Source Registry (Corentin Noël)
evo-I#3157 - Broken multipart/signed shown as raw MIME data
Miscellaneous:
org.gnome.EvolutionDataServer.Devel.json: Build also gweather-locations
Lower default connection timeout to 15 seconds
evolution-source-registry: Remove unused variable (reported by compiler)
CamelGpgContext: Improve error messages
WebDAV: Default to no download limit
CamelStoreDB: Keep 'sqlite_sequence' table during migration
CamelDB: Correct return value and repeated function call arguments
CamelStoreSearch: Unlock summary and folder when save or prepare_fetch_all fails
IMAPx: Avoid Junk/Trash folder open when saving changes
ERemindersWidget: Workaround too large gap between action buttons
CamelFolderSummary: Reload from DB could leak already loaded infos
Correct developer comment of e_source_webdav_set_limit_download_days()
addressbook: Prefer vCard "take" functions
CamelDataCache: Rephrase "Empty cache file" error message
Camel: Unread count for virtual Trash/Junk folder not updated properly
CamelStoreSearch: Ignore all errors when a message cannot be opened
CamelStore: Speed up open folders with virtual Trash or Junk folder
EContactAddress: Add helper functions to read, write and clear the structure
EContact: Add EContactGeo functions to convert to/from string
EVCard: Add conversion code for GEO attribute
EVCard: Correct PHOTO/LOGO data: URI conversion
EContact: Add 'timezone' field
EVCard: Add conversion code for KEY attribute
EContactCert: Add helper functions to work with attributes
ECertificateWidget: Add a function to check whether any certificate data is shown
flatpak: Add gettext ACLOCAL workaround
EBookSqlite: Correct mutex unlock in e_book_sqlite_lock()
EVCard: Add RFC 2739 properties into the list of known vCard 3.0 properties
Translations:
Asier Saratsua Garmendia (eu)
Aurimas Černius (lt)
Daniel Rusek (cs)
Ekaterine Papava (ka)
Emin Tufan Çetin (tr)
Juliano de Souza Camargo (pt_BR)
Martin (sl)
Sabri Ünal (tr)
twlvnn kraftwerk (bg)
Yuri Chornoivan (uk)
Evolution-Data-Server 3.58.0 2025-09-12
---------------------------------------
Bug Fixes:
I#607 - test-cal-component-bag: Fails to run with source tree only
Miscellaneous:
IMAP: Disable PREVIEW fetch on FETCH error
Translations:
Balázs Úr (hu)
Daniel Rusek (cs)
Evolution-Data-Server 3.57.3 2025-08-29
---------------------------------------
Bug Fixes:
I#555 - Calendar: Deleting "This and Future Occurrences" instances can duplicate events
I#602 - IMAP: Sometimes removes message from local summary in error
I#604 - CamelGpgContext: Provide information about encrypted content
I#605 - Camel: MH account busy-loops when reading directory content
M!188 - EDataServer: Use g_object_notify_by_pspec when possible (Corentin Noël)
M!193 - EBookContacts: Use g_object_notify_by_pspec when possible (Corentin Noël)
M!198 - alarm-notify: Add a systemd service (Adrian Vovk)
M!198 - data: Conditionalize installation of alarm-notify (Adrian Vovk)
M!199 - cmake: Specify GLib minimal version to gdbus-codegen (Corentin Noël)
M!200 - data: Set desktop directory outside the condition (Hari Rana)
M!202 - build: Conditionally install org.gnome.Evolution-alarm-notify.desktop (Georges Basile Stavracas Neto)
Miscellaneous:
CamelDB: Do not error out on SQLITE_ABORT
CamelVeeFolder: Fix runtime warning when rebuilding folder content
CamelVeeSummary: Reference subfolder in the internal hash table
Translations:
Anders Jonsson (sv)
Artur S0 (ru)
Asier Saratsua Garmendia (eu)
Jordi Mas (ca)
Juliano de Souza Camargo (pt_BR)
Piotr Drąg (pl)
Evolution-Data-Server 3.57.2 2025-08-01
---------------------------------------
* The libcamel API dropped CamelObject, it was not needed anymore.
Bug Fixes:
I#449 - alarm-notify: Rework snooze options
I#591 - alarm-notify: Sometimes uses original reminder time for modified instance
evo-I#3089 - Camel: App freezes often when performing various threaded tasks
evo-I#3093 - EContact: Consider also FullName as FileAs
Miscellaneous:
CamelVeeSummary: Fix dub-subfolders annotations (Corentin Noël)
CamelFolder: Add state saving API directly (Corentin Noël)
Camel: Remove CamelObject (Corentin Noël)
Camel: Remove index of deprecated symbols (Corentin Noël)
CamelStoreSearch: Make it possible to search for a hashed message ID
CamelFolder: Fix a memory leak
EReminderWatcher: Debug-print what changes had been received from the calendars
ERemindersWidget: Change gap around description text view
CamelNetworkService: Cache the GQuark locally for the private data (Corentin Noël)
Camel: Use g_object_notify_by_pspec when possible (Corentin Noël)
ECal: Use g_object_notify_by_pspec when possible (Corentin Noël)
EDataServerUI: Use g_object_notify_by_pspec when possible (Corentin Noël)
EBook: Use g_object_notify_by_pspec when possible (Corentin Noël)
EBackend: Use g_object_notify_by_pspec when possible (Corentin Noël)
EDataBook: Use g_object_notify_by_pspec when possible (Corentin Noël)
EDataCal: Use g_object_notify_by_pspec when possible (Corentin Noël)
Camel: Use GParamSpec consistently to create properties (Corentin Noël)
CamelVeeFolder: Fix a runtime warning when rebuilding the folder
CamelFolderSummary: Notify about flag changes on idle
ECalClient: Improve performance of generate_instances() function
Translations:
Martin (sl)
Yuri Chornoivan (uk)
Evolution-Data-Server 3.57.1 2025-06-27
---------------------------------------
* The libcamel API had been changed in several ways, some deprecated
symbols had been removed, some API functions renamed and their return
values changed (mostly from "transfer full" to "transfer container").
Bug Fixes:
I#592 - Handle changed server pool in WebDAV collection sources
I#593 - CamelDataWrapper: Correct return value of size calculate functions (dagosuhn)
I#597 - GOA EWS: Fallback to likely EWS host URL when autodicovery fails
M!170 - docs: Update URL to libsoup docs (Simon McVittie)
M!176 - docs: Add docs_url argument (Corentin Noël)
evo-I#2434 - alarm-notify: Should show a visual notification to accompany notification sounds (John Lorentzson)
Miscellaneous:
e-data-server-util: Fix a compiler warning about 'const' qualifier discard
libecal: Add utility functions to read and convert time to given timezone
test-cal-utils: Add a simple additional check
libecal: Add an ECalComponentBag object
ESourceRegistry: Reject to create an instance when D-Bus service is not available
Misc: Correct developer documentation annotations
CamelService: Add private construct-only "with-proxy-resolver" property
Camel: Add CamelStoreDB and CamelStoreSearch and use them
Camel: Rework Search folders
CamelFilterDriver: Remove unused "global variables"
Camel: Rename camel_folder_summary_get_array() to camel_folder_summary_dup_uids()
Camel: Rename camel_folder_get_uids() to camel_folder_dup_uids()
Camel: Remove camel_folder_get_summary()
Camel: Rename camel_folder_get_uncached_uids() to camel_folder_dup_uncached_uids()
Camel: Rename camel_folder_summary_get_changed() to camel_folder_summary_dup_changed()
Camel: Rename camel_uid_cache_get_new_uids() to camel_uid_cache_dup_new_uids()
Camel: Rename CAMEL_DB_FILE to CAMEL_STORE_DB_FILE
CamelDB: Remove unneeded public defines
CamelProvider: Remove autodetect function (Corentin Noël)
lib-camel-test-utils: Reference CamelProvider struct members by name in initialization
Camel: Remove deprecated symbols from CamelStoreSummary (Corentin Noël)
Camel: Remove deprecated symbols from CamelOfflineSettings (Corentin Noël)
CamelStoreDB: Allow empty folder names
CamelStoreGetFolderFlags: Remove deprecated and unused flag (Corentin Noël)
CamelFolder: Undeprecate get/set_message_flags (Corentin Noël)
CamelFolder: Remove deprecated functions (Corentin Noël)
CamelFolderThread: Use the oldest message as a parent of a leaf-only subthread
CamelFolder: Add nullable annotation to camel_folder_get_folder_summary (Corentin Noël)
CamelFolder: Use g_object_notify_by_pspec when possible (Corentin Noël)
CamelFolderSummary: Use g_object_notify_by_pspec when possible (Corentin Noël)
CamelMessageInfo: Use g_object_notify_by_pspec when possible (Corentin Noël)
CamelMimePart: Use g_object_notify_by_pspec when possible (Corentin Noël)
CamelIMAPXMessageInfo: Use g_object_notify_by_pspec when possible (Corentin Noël)
CamelFolderThread: Fix a crash caused by the previous commit
Camel: Remove extra camel_pstring_free() calls
vala: Fix several warnings thrown by Camel (Corentin Noël)
CamelFolderSummary: Remove prepare-fetch-all signal (Corentin Noël)
alarm-notify: Skip reminders for cancelled components
CamelURL: Add glib-object to the header (Corentin Noël)
CamelService: Rebase on GObject (Corentin Noël)
CamelVeeStore: Remove unused property (Corentin Noël)
CamelIMAPXCommand: Remove leftover assignation to CamelObject (Corentin Noël)
Translations:
Asier Saratsua Garmendia (eu)
Álvaro Burns (pt_BR)
Balázs Meskó (hu)
Boyuan Yang (zh_CN)
Ekaterine Papava (ka)
Emin Tufan Çetin (tr)
Jordi Mas (ca)
Jose Riha (sk)
Martin (sl)
Yuri Chornoivan (uk)
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
oe-core merged systemd-systemctl-native into systemd-tools-native and moved
the PACKAGE_WRITE_DEPS on the native systemctl out of systemd.bbclass into
systemd itself. As a result:
- The PACKAGECONFIG[systemd] dependency on systemd-systemctl-native no longer
resolves ("Nothing PROVIDES systemd-systemctl-native"). systemctl is a
rootfs-time tool and was never needed to build postgresql, so drop it from
the build dependencies.
- The pkg_postinst runs systemctl at rootfs time when both systemd and
sysvinit are enabled. Since systemd.bbclass no longer adds the native tool
to PACKAGE_WRITE_DEPS, declare it explicitly (as systemd-tools-native),
guarded by the same DISTRO_FEATURES condition, mirroring how oe-core's
keymaps/initscripts recipes handle it.
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The license was changed from MIT to BSL-1.0 in release 4.0.0.
Also set SUMMARY instead of DESCRIPTION, and fix some whitespace.
Signed-off-by: Peter Kjellerstedt <peter.kjellerstedt@axis.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The target build runs uim-module-manager (from uim-native, via PATH) to
generate scm/installed-modules.scm. Module registration makes the tool
uim_init() and dlopen the uim C plugins found in LIBUIM_PLUGIN_LIB_DIR,
which scm/Makefile hardcodes to the target build's uim/.libs. The native
uim-module-manager therefore loads target objects (and, transitively, the
target libuim) into the native process, which crashes do_compile when the
build host ABI differs from the target:
make[1]: *** [Makefile:869: installed-modules.scm] Segmentation fault
seen building for x86-64-v3-poky-linux on an x86-64 host.
Make LIBUIM_PLUGIN_LIB_DIR overridable in scm/Makefile.am and point it at
the native plugin directory (${STAGING_LIBDIR_NATIVE}/uim/plugin) for the
target build, so the native tool loads compatible native plugins. The
generated installed-modules.scm is architecture independent, so the result
is unchanged. The native build is unaffected (the patch and override are
class-target only).
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
FEX-2607 formats std::byte spans via fmt::join, which its pinned bundled
fmt 12.1.0 supports but oe-core's fmt 12.2.0 rejects, breaking do_compile:
fmt/base.h: error: implicit instantiation of undefined template
'fmt::detail::type_is_unformattable_for<fmt::join_view<...std::byte*...>, char>'
ninja: build stopped: subcommand failed.
The recipe already dropped fmt from DEPENDS to build the bundled copy, but
FEX only falls back to External/fmt when find_package(fmt) fails. fmt-native
is still pulled in as a transitive native dependency, and OE's
CMAKE_FIND_ROOT_PATH includes the native sysroot for packages, so
find_package(fmt) resolves against recipe-sysroot-native and the target
compile picks up the incompatible fmt 12.2.0 headers.
Set CMAKE_DISABLE_FIND_PACKAGE_fmt=ON so find_package(fmt) reports not-found
and FEX builds the bundled fmt 12.1.0.
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Inherit ptest, include tests for wand and run the relevant
test cases. Add imagemagick as a runtime dependency.
This work was sponsored by GOVCERT.LU.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Inherit ptest, include tests for rarfile and run the relevant
test cases.
This work was sponsored by GOVCERT.LU.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
FUSE filesystem that serves archives (zip, tar, 7z, iso, ...) read-only,
mounting them without extracting to disk first.
Signed-off-by: Alex Kiernan <alex.kiernan@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
PipeWire 1.6.8 (2026-07-09)
This is a bugfix release that is API and ABI compatible with the previous
1.6.x releases.
Highlights
- Fix a data race in JACK that could cause lost MIDI events in ardour.
- Fix some unbounded memory allocations.
- Various small fixes.
PipeWire
- Avoid some graph recalcs, which fixes a bug when suspending a node
while it is active.
Modules
- Do Content-Length and allocation check in RAOP to avoid OOM errors.
- Fix a potential memory leak in the error path of client-node. (#5348)
SPA
- Fix filter-graph dynamic graph updates.
- Avoid 100% when unplugging a card.
- Fix filter-graph volumes when the filter is loaded inside a node with
hardware volume. (#5344)
- Add normalize and latency options to the SOFA filter. (#5322)
Bluetooth
- Fix a potential leak when transport fails to start.
Pulse-server
- Avoid stack exhaustion via unbounded alloca.
JACK
- Fix a data race in jack_port_get_buffer() when called from concurrent
threads, like in ardour. (#5324)
GStreamer
- Skip invalid crop metadata.
- Avoid crash because metadata listener was registered twice.
Signed-off-by: Markus Volk <f_l_k@t-online.de>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
- Disallow extraction outside extraction path, in case of existing
symlink.
- Disallow creating symlinks to outside of extraction path.
- Apply length limit to passwords, so too long password give same
result as for unrar.
This work was sponsored by GOVCERT.LU.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Inherit ptest and include tests for pyppmd.
Add a patch to fix SIGABRT OutputBuffer_Grow() from
src/ext/_ppmdmodule.c which was detected with the tests.
This work was sponsored by GOVCERT.LU.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Inherit ptest and include tests for jsbeautifier.
This work was sponsored by GOVCERT.LU.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Bump the FEX srcrev to the FEX-2607 tag and resync the vendored externals
to that release's submodule pointers: drop jemalloc (non-glibc) and
robin-map, which upstream replaced with rpmalloc and unordered_dense.
Additional build fixes required by this release:
- Disable FEX's internal ccache (-DENABLE_CCACHE=OFF); it collides with
OE's ccache class and double-wraps the compiler.
- Build fmt from the bundled External/fmt submodule instead of the system
copy. FEX-2607 formats std::byte spans via fmt::join, which its pinned
fmt 12.1.0 supports but oe-core's newer fmt 12.2.0 rejects.
- Stop FEX from stripping binaries at link time so OE can split out debug
information and the already-stripped QA check passes.
Built for qemuarm64.
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
do_compile failed to find ninja, and after providing it CMake's C++20
module dependency scanning (clang-scan-deps) failed in the cross
environment with "'cstddef' file not found".
Add ninja-native and python3-scikit-build-core-native to DEPENDS so the
--no-isolation build finds its build tools, and disable C++20 module
scanning via CMAKE_ARGS since pikepdf uses the C++20 language but no
named modules.
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The upstream pyproject.toml caps setuptools at <83.0, but OE builds with
--no-isolation against the native setuptools (now 83.0.0), so the build
fails with "Missing dependencies: setuptools<83.0,>=65.6". Drop the
spurious upper bound.
Fold this into the existing wheel-version relaxation so pyproject.toml is
adjusted by a single patch.
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The upstream pyproject.toml caps setuptools at <82.1, but OE builds with
--no-isolation against the native setuptools (now 83.0.0), so the build
fails with "Missing dependencies: setuptools<82.1,>=68". Drop the
spurious upper bound.
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
The upstream pyproject.toml caps setuptools at <=82.0.1, but OE builds
with --no-isolation against the native setuptools (now 83.0.0), so the
build fails with "Missing dependencies: setuptools<=82.0.1,>=80.9.0".
Drop the spurious upper bound.
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Upgrade to release 10.9.1:
- Fixed a crash (SIGABRT via std::terminate) that could occur when
a file-backed {class}pikepdf.Pdf was deallocated while a Python
exception was already propagating -- for example when
pikepdf.open(filename) appears as a transient element of a
list/tuple literal whose later element raises. Opening from a
filename closes the file in the input source destructor, which
calls back into Python; with an exception already in flight that
call raised an error that escaped the destructor. The in-flight
exception is now preserved and propagates normally. Added a guard
for a likely non-reproducible related case with DecimalPrecision.
This work was sponsored by GOVCERT.LU.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Upgrade to release 3.0.4:
- Fixed test builds with installed Eigen 5 by improving Eigen3
CMake package detection.
- Fixed move semantics of scoped_ostream_redirect to preserve
buffered output and avoid crashes when moved redirects restore
stream buffers.
- Fixed py::dynamic_attr() traversal on Python 3.13+ to correctly
propagate PyObject_VisitManagedDict() results.
- Fixed std::shared_ptr<T> fallback casting to avoid unnecessary
copy-constructor instantiation in reference_internal paths.
- Updated setup-uv to the maintained GitHub Action tag scheme.
- Updated pre-commit hooks.
- Updated GitHub Actions dependencies, including actions-setup-cmake
and cibuildwheel.
This work was sponsored by GOVCERT.LU.
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Changelog:
============
- Fixed a 'TypeError' on PHP 8 when 'Security::$static_classes' was set to a
non-array value (e.g. the string ''none'') to disable static class access;
any non-array value now cleanly denies access. Use 'Security::$static_classes =
null' to disable access to all static classes.
- Security: the built-in 'stream:' resource type now validates the nested
stream wrapper against the security policy, so a template such as
'stream:php://filter/...' can no longer bypass 'Security::$streams' (including
'Security::$streams = null') to read local files
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Changelog:
===========
- Fix size_t overflow in 'amqp_decode_bytes' bounds check leading to
out-of-bounds read (GHSA-jgjf-7fwf-f3c7, #888)
- Fix heap buffer overflow in 'amqp_frame_to_bytes' for oversized body frames
(GHSA-hfjv-vcp3-39wh, #892)
- 'librabbitmq-tools' fall back to the 'AMQP_URL' environment variable when no
connection options are given on the command line (#887)
- Fix undefined behavior in 'amqp_decode_properties' when decoding
content-header property flags (#883, #885)
- Fix 'ioctlsocket' type mismatch on Windows (#890)
- Document buffer lifetime requirement of 'amqp_decode_table''s encoded buffer
to prevent use-after-free misuse (#895)
- 'librabbitmq-tools' now enable default SSL certificate verification paths
unless '--no-default-cert-paths' is passed (fixes#868, #893)
- Building the tools now requires POPT v1.14 or newer
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Changelog:
============
* Default headers (such as "Content-Type", "Date" and "Server") are now stripped
from recorded files regardless of header name case. Previously, responses recorded from
servers that send lowercase header names (for example over HTTP/2) kept these redundant
headers in the generated file.
* Fixed 'query_param_matcher' mutating the caller's params dict when numeric
values are provided.
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Changelog:
============
- Add Latvian language localization
- Add i18n support for naturalsize() and French translation
- Performance improvements: 1.07x - 8.4x
- Lazy imports for Python 3.15+
- Drop experimental Python 3.13 free-threaded
- Refactor: simplify scientific() and extract _SUPERSCRIPT_MAP constant
- Fix naturalsize() rounding rollover at unit boundaries
- Carry metric() to the next SI prefix when rounding reaches 1000
- Stop printing two minus signs in fractional for a negative mixed number
- Return an empty string from natural_list() for an empty list
- Handle tz-aware datetimes in naturalday() and naturaldate()
- Fix Arabic translation
- Fix Spanish large number translations to use long scale
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Changelog:
============
- Ensure we use a safe name for long postgres queue names. PG has a 63 byte
limit on the channel name.
- Ensure recycled worker threads no longer leak their LISTEN connections
w/Postgres.
- Add first-class Postgres support: PostgresHuey. Workers use LISTEN/NOTIFY
when a task is enqueued, giving Redis-like dequeue latency without polling,
and dequeues use select ... for update skip locked so any number of consumers
can share one database (requires psycopg 3.2+).
- The django.tasks backend is now also compatible with the django-tasks
backport package, extending support to pre-6.0 Django.
- Use an explicit fork multiprocessing context for process workers, rather than
setting the global start-method from the consumer entry-points. Fixes -k
process on MacOS 3.8+ / Linux 3.14+ when the consumer is started via the
huey_consumer console-script or a programmatic create_consumer().run().
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Changelog:
===========
- Fix: compute valid ISO 7064 Mod 11,10 check digit for de_DE vat_id
- Add es_MX automotive license plate provider
- Add sr_BA SSN provider
- Update providers job, phone_number, bank and ssn
- Update phone number test regex
- Update outdated Korean locale names
- Fix: prevent infinite recursion in _safe_random_int when both bounds collapse to the same integer
- Add mk_MK (Macedonian) locale
- CI: run PR checks against PR code instead of base branch.
- Fix: raise NotImplementedError in bank() for locales without banks data
- Fix outdated links in README credits section
- Bump actions/cache from 5 to 6
- Bump actions/checkout from 6 to 7
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Changelog:
============
- Fixed the decoder registering 6-byte strings in the string reference
namespace at indices 65536–4294967295 where the encoder does not,
desynchronising the namespace and resolving later string references to the
wrong value
- Fixed the IPv4/IPv6 network decoders (tags 52 and 54) silently truncating an
address byte string that is longer than the address size instead of rejecting
it as malformed
- Fixed quadratic decoding time for indefinite-length and large definite-length
byte and text strings, caused by concatenating each chunk onto the
accumulated result with + instead of building the result once
- Fixed datetime_as_timestamp encoding whole-second datetimes before 1970 or
after 2106 as floats instead of integers, because the timestamp was narrowed
through an unsigned 32-bit integer
- Fixed the encoder measuring text strings by code point count instead of UTF-8
byte length when deciding whether to add them to the string reference
namespace, desynchronising it from the decoder (which counts bytes) and
corrupting later string references for non-ASCII strings
- Fixed the decoder rejecting scoped IPv6 addresses (tag 54) with a
CBORDecodeError reading invalid types in input array; the encoder emits them
as [address, null, zone id] but the decoder only handled the network and
interface array forms, so a scoped ~ipaddress.IPv6Address could not be decoded
back
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Changelog:
===========
- Use defaultdict to help with performance
- Simplify _interleave_addrinfos family grouping
- Collapse collect-then-remove pattern in utils helpers
- Merge identical except blocks in _connect_sock cleanup
- Add python 3.14 support
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
0001-trivial-httpd-Fix-const-correctness-of-slash-pointer.patch
removed since it's included in 2026.2
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>